Include Security, LLC
Application security consulting firm founded in 2010 in Brooklyn, delivering expert penetration testing, vulnerability research, and security assessments across mobile, web, IoT, server, and client applications for enterprise and consumer technology clients worldwide.
- Company typePrivate
- Founded2010
- HeadquartersBrooklyn, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Include Security, LLC does
Include Security, LLC is a Brooklyn, New York-headquartered application security consulting firm founded in 2010 by Erik Cabetas that delivers expert penetration testing, vulnerability research, and security assessments for enterprise and consumer technology clients. The firm operates with a distributed team across North America, South America, and the EU and explicitly markets senior expertise: every team member is stated to have at least five years of application hacking experience, and staffing decisions are driven by technical fit rather than geography or availability.
Service offerings span nine practice areas: mobile application assessments, web application assessments, IoT device assessments, server application assessments, client application assessments, web services assessments, fuzzing and dynamic analysis tool creation, software reverse engineering, and exploit development. The firm serves customers across at least eight verticals including B2B and B2C technology, social networks, streaming services, consumer hardware, healthcare, automotive, and independent software vendors. Notable public research includes coordinated disclosures on the Allen & Heath SQ-6 audio mixer (October 2025), authenticated RCE findings in open-source C2 frameworks Sliver and Havoc (September 2024), and an analysis of Bright Data's SDK turning consumer smart TVs into residential proxy nodes for AI web scraping (June 2026). The firm has also released open-source tools including SafeURL (SSRF protection libraries for PHP, Python, and Scala) and RTSPhuzz (RTSP server fuzzer).
Revenue is generated exclusively through B2B professional services: custom-scoped assessment engagements priced based on codebase size, language, attack surface, and security assurance requirements, with multi-year contract cadences available. The go-to-market is consultative and direct, with clients engaging the firm via email and phone; markets served include the firm's NYC and SF primary hubs plus global engagements from the Brooklyn headquarters.
Include Security, LLC firmographics
Firmographics- Name
- Include Security, LLC
- Legal name
- Include Security LLC
- Website
- https://includesecurity.com
- Company type
- Private
- Founded year
- 2010
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Application security consulting firm founded in 2010 in Brooklyn, delivering expert penetration testing, vulnerability research, and security assessments across mobile, web, IoT, server, and client applications for enterprise and consumer technology clients worldwide.
- Ownership category
- akta.pro rank
Include Security, LLC industry classification
Industry- Product category
- Application Security Services
- NAICS
- Other Computer Related Services (541519)
- SIC
- Services-Management Consulting Services (8742)
- akta.pro primary industry
- Application Security Engineering (DevSecOps, AppSec Remediation) (BPAEAFAI)
Keywords
Where Include Security, LLC is headquartered
LocationHeadquarters
- HQ city
- Brooklyn
- HQ country
- United States
- HQ region
- North America
Offices3 records
Markets served
Include Security, LLC business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales
Revenue model
- Security Assessment Services: Professional services revenue from conducting application security assessments, penetration testing, and security research for enterprise and consumer technology clients. Pricing is custom-scoped based on assessment size and complexity.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom-scoped security assessments based on project complexity and client requirements |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels3 records
Include Security, LLC product offering
Product offeringCore offering
Include Security delivers expert application security assessment and penetration testing services to enterprise and consumer technology companies. Engagements are custom-scoped based on codebase size, language, attack surface area, and security assurance requirements, and are staffed by senior security researchers each with at least five years of application hacking experience. Practice areas cover mobile applications, web applications, IoT devices, server applications, client applications, web services, fuzzing and dynamic analysis tool creation, software reverse engineering, and exploit development.
Product overview
Include Security, LLC is a security consulting firm (not a product company) offering expert application security assessments and penetration testing services. Their core offerings are professional security assessment services rather than commercial software products. The assessment portfolio includes Mobile App Assessments, Web Application Assessments, IoT Device Assessments, Server Application Assessments, Client Application Assessments, Web Services Assessments, Fuzzing and Dynamic Analysis Tool Creation, Software Reverse Engineering, and Exploit Development. Additionally, they have released open-source security tools including SafeURL (SSRF protection libraries for PHP, Python, and Scala) and RTSPhuzz (RTSP Server Fuzzer). The firm serves clients across multiple industries including B2B/B2C technologies, social networks, streaming services, consumer hardware, healthcare, automotive, and independent software vendors.
Differentiator
Problem solved
Functional benefit
Brands
- Include Security Research Blog: The company's technical security research blog featuring vulnerability disclosures, security assessments methodology, and tool releases.
Products and services
- Mobile App Assessments Security assessments of mobile applications across iOS and Android platforms, identifying vulnerabilities in native apps, APIs, and companion applications. Targeted at enterprise and consumer technology companies needing pre-release or production mobile app testing.
- Web Application Assessments Comprehensive security testing of web applications, including penetration testing, vulnerability identification, and remediation guidance aligned with OWASP standards. For enterprise and consumer technology companies with web-facing applications.
- IoT Device Assessments Security evaluations of Internet of Things devices, including hardware hacking, firmware analysis, and assessment of embedded system vulnerabilities. For consumer hardware manufacturers and IoT product companies.
- Server Application Assessments Security assessments of server-side applications and backend infrastructure to identify vulnerabilities in APIs, databases, and server configurations. For technology companies with backend services.
- Client Application Assessments Security testing of desktop and client-side applications to identify vulnerabilities in client software, including browser-based and standalone applications. For software vendors and enterprises shipping client applications.
- Web Services Assessments Security assessments of web services, including REST APIs, SOAP services, and other networked service architectures. For technology companies operating networked service architectures.
- Fuzzing and Dynamic Analysis Tool Creation Custom fuzzing harness development and dynamic analysis tool creation to uncover memory corruption vulnerabilities and complex security flaws in target software. For technology companies needing advanced vulnerability discovery that off-the-shelf tooling cannot achieve.
- Software Reverse Engineering Reverse engineering of software to understand functionality, identify vulnerabilities, and analyze proprietary protocols and systems. For hardware, software, and firmware companies requiring deep technical analysis.
- Exploit Development Development of proof-of-concept exploits to demonstrate the feasibility and impact of identified vulnerabilities for clients. For technology companies that need to understand real-world risk severity.
- SafeURL Set of SSRF protection libraries developed by Include Security for PHP, Python, and Scala, helping developers protect against Server-Side Request Forgery vulnerabilities by validating URLs against white and black lists before making requests. Open-source release on GitHub.
- RTSPhuzz An open-source RTSP Server Fuzzer created by Include Security for identifying faults and memory corruption vulnerabilities in servers implementing RFC-defined protocols. Open-source release on GitHub.
Quantifiable outcome
- Technical report delivered within a week after assessment conclusion to keep deals and compliance projects on track
- +1 more outcomes
Companies that use Include Security, LLC
Customer profileNamed customers8 records
Segments8 records
Ideal customer profiles2 records
Include Security, LLC technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature5 records
Include Security, LLC partnerships and signals
Strategic signalScale indicators1 record
Recent moves5 records
Expansion highlights4 records
Include Security, LLC competitors and assessment
Company assessmentDirect peers
- Trail of Bits: Trail of Bits is a closely comparable application security consultancy offering penetration testing, security assessments, and security research with a strong research/engineering culture and open-source contributions. Directly competes for the same enterprise B2B/B2C tech clients and talent pool.
- Bishop Fox: Bishop Fox is a leading offensive security firm providing application, network, and IoT security assessments with a similar high-expertise, research-driven brand positioning. Directly competes for enterprise application security testing engagements.
- NetSPI: NetSPI is a large application and network security testing firm with a platform-enabled delivery model (Resolve), competing in the same enterprise penetration testing market with a broader service portfolio.
- TrustedSec: TrustedSec is an application and network security consultancy offering penetration testing and adversary simulation, with similar expertise-led positioning and consultant-driven service delivery.
- Cobalt: Cobalt is a Pentest-as-a-Service platform that combines crowdsourced security researchers with workflow tooling, competing in the same application security assessment market but with a tech-enabled delivery model.
Broad incumbents
- NCC Group: NCC Group is a global cybersecurity services firm with a large application security practice, offering a much broader portfolio including managed security, software resilience, and escrow services alongside pen testing.
- Rapid7: Rapid7 offers AppSec services (acquired through various security testing capabilities) as part of a broader security operations and analytics platform. Represents a much larger, publicly traded incumbent with overlapping service lines.
Others
- PortSwigger (Burp Suite): PortSwigger is the developer of Burp Suite, the dominant web application security testing tool used by application security consultants. While not a direct competitor, its tooling ecosystem shapes Include Security's delivery practices and buyer expectations.
- Offensive Security (OffSec): OffSec is best known for OSCP certification and Kali Linux, but its consulting practice also provides application and network security assessments. Adjacent to Include Security's market through shared offensive security talent pipeline and credentials.
Emerging players
- HackerOne: HackerOne operates a bug bounty and vulnerability disclosure platform that overlaps with traditional pen testing as an alternative way for clients to discover application vulnerabilities. Represents a different delivery model competing for the same client budget.
Market position
Competitive moat2 records
Key risks6 records
Key highlights6 records
Customer concentration
Include Security, LLC social profiles
Digital presenceInclude Security, LLC financial estimates
Financial estimateRevenue estimate
Valuation estimate
Include Security, LLC leadership team
Management profileNumber of profiles
Profiles1 record
Include Security, LLC funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Include Security, LLC M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Include Security, LLC
What does Include Security, LLC do?
Include Security delivers expert application security assessment and penetration testing services to enterprise and consumer technology companies. Engagements are custom-scoped based on codebase size, language, attack surface area, and security assurance requirements, and are staffed by senior security researchers each with at least five years of application hacking experience. Practice areas cover mobile applications, web applications, IoT devices, server applications, client applications, web services, fuzzing and dynamic analysis tool creation, software reverse engineering, and exploit development.
Is Include Security, LLC a public or private company?
Include Security, LLC is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Include Security, LLC founded?
Include Security, LLC was founded in 2010. It employs 11 to 50 people.
Where is Include Security, LLC based?
Include Security, LLC is headquartered in Brooklyn, United States, in the North America region.
How does Include Security, LLC make money?
One revenue line is on record: security Assessment Services.
Who are Include Security, LLC's main competitors?
Direct peers on record are Trail of Bits, Bishop Fox, NetSPI, TrustedSec and Cobalt. Broad incumbents are NCC Group and Rapid7. Others are PortSwigger (Burp Suite) and Offensive Security (OffSec). HackerOne is listed as an emerging player.
Does Include Security, LLC have an API?
No public API is recorded for Include Security, LLC.
What industry is Include Security, LLC in?
Include Security, LLC's product category is Application Security Services. Its primary akta.pro industry code is BPAEAFAI, Application Security Engineering (DevSecOps, AppSec Remediation). Its NAICS code is 541519 and its SIC code is 8742.