Software Secured
Software Secured is a Canadian penetration testing firm that delivers manual, AI-assisted security testing and a continuous PTaaS subscription to high-growth SaaS, healthcare, fintech, and compliance-driven organizations, anchored by a proprietary portal with developer workflow integrations.
- Company typePrivate
- Founded2006
- HeadquartersOttawa, Canada
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Software Secured does
Software Secured is a Canadian penetration testing firm headquartered in Ottawa that delivers manual, exploit-driven security testing to high-growth SaaS companies, healthcare providers, fintech firms, and security- and compliance-driven organizations. The firm combines human-led pentesting with AI-assisted tooling and a proprietary Software Secured Portal that provides real-time tracking, remediation management, SLA monitoring, audit-ready reporting, component-level security reporting, and native integrations with Jira, Azure DevOps, Linear, Slack, Microsoft Teams, Drata, and Vanta. The portfolio spans web application, API, and mobile application pentesting, secure code review, external and internal network pentesting, secure cloud review across AWS, Azure, and GCP, specialized AI and LLM pentesting, IoT and hardware testing, red teaming, social engineering, threat modeling, and OWASP-aligned secure code training.
The core go-to-market offering is Penetration Testing as a Service (PTaaS), structured as a subscription with multi-year contracts aligned to customer release cycles and inclusive of built-in retesting. Pricing is scope-based and tiered: external network pentests start at approximately $5,400, authenticated web application pentests start at $10,000, and PTaaS subscriptions are priced per attack surface and compliance mapping needs, with custom quotes returned within 48 hours. The GTM motion is sales-led, with consultation booking as the primary conversion path, augmented by inside sales for mid-market, enterprise deal support for complex procurements, and content marketing, SEO, webinars, guides, and competitive comparison pages targeting enterprise and mid-market buyers. Disclosed scale metrics include 350+ customers, 2,000+ pentests completed in the prior five years, an average of 26 vulnerabilities per pentest, and 20% of findings classified as critical or high severity.
The company is privately held and founder-led by Sherif Koussa, who established the firm in 2006 alongside the OWASP Ottawa Chapter and employs full-time OSCP-, OSWE-, and GWAPT-certified North American pentesters rather than contractors. The legal entity is SSCI, headquartered at 301 Moodie Dr., Unit 108, Ottawa. The firm holds an SOC 2 Type 1 Report issued November 21, 2023, is GDPR-compliant, supports audit readiness for SOC 2, HIPAA, PCI DSS, and ISO 27001, and received 2026 industry recognition including Clutch Top Penetration Testing Company and GBHackers Top 10 Cloud Penetration Testing Providers.
Software Secured firmographics
Firmographics- Name
- Software Secured
- Legal name
- SSCI
- Website
- https://softwaresecured.com
- Company type
- Private
- Founded year
- 2006
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Software Secured is a Canadian penetration testing firm that delivers manual, AI-assisted security testing and a continuous PTaaS subscription to high-growth SaaS, healthcare, fintech, and compliance-driven organizations, anchored by a proprietary portal with developer workflow integrations.
- Ownership category
- akta.pro rank
Software Secured industry classification
Industry- Product category
- Penetration Testing Services
- NAICS
- Testing Laboratories and Services (541380), Computer Systems Design and Related Services (5415)
- SIC
- Services-Testing Laboratories (8734), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Penetration Testing Platforms (PTaaS) (HDADAHAG)
- akta.pro secondary industry
- Vulnerability Management & Penetration Testing Services (BPAEADAD)
Keywords
Where Software Secured is headquartered
LocationHeadquarters
- HQ city
- Ottawa
- HQ country
- Canada
- HQ region
- North America
Offices1 record
Markets served
Software Secured business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Penetration Testing as a Service (PTaaS): Subscription-based model providing continuous, ongoing manual pentests aligned to release cycles. Includes unlimited retesting, portal access, and compliance mappings. Available as project-based or subscription PTaaS.
- One-Time Pentest Engagements: Scoped penetration testing engagements for specific applications, networks, or compliance requirements (SOC 2, HIPAA, PCI DSS, ISO 27001). Fixed pricing based on attack surface scope.
- Training Services: Secure Code Training - interactive labs teaching real exploits, fixes, and prevention techniques aligned to OWASP Top 10.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| One time/ perpetual license | Pay-as-you-go | External Network Pentesting |
| One time/ perpetual license | Pay-as-you-go | Authenticated Web Application Pentesting |
| Subscription | Multi-year contract | PTaaS Subscription |
Go-to-market motion1 record
Distribution channels4 records
Marketing channels7 records
Software Secured product offering
Product offeringCore offering
Software Secured provides manual, exploit-driven penetration testing services delivered through a Penetration Testing as a Service (PTaaS) subscription model. The portfolio covers web, API, mobile, internal/external network, cloud (AWS/Azure/GCP), AI/LLM, IoT, and hardware security testing, along with red teaming, social engineering, threat modeling, secure code review, and OWASP-aligned developer training. Engagements include built-in retesting, a zero-false-positive guarantee, and a purpose-built Portal for real-time tracking, remediation, audit-ready reporting, and integrations with developer and compliance tools.
Product overview
Software Secured is a B2B manual penetration testing provider offering a portfolio of security testing services anchored by its core Penetration Testing as a Service (PTaaS) platform. The PTaaS offering combines ongoing manual pentests with a purpose-built Portal for scheduling, tracking, and audit-ready reporting, supported by built-in retesting. Complementing the PTaaS core, the portfolio includes distinct service modules across web/API/mobile security, infrastructure and cloud security, and specialized testing for AI/IoT/hardware, plus advanced adversary simulation services (red teaming, social engineering, threat modeling) and secure code training. All services leverage full-time, certified North American pentesters to deliver human-led, exploit-driven testing with zero false positives and actionable remediation guidance.
Differentiator
Problem solved
Functional benefit
Products and services
- Penetration Testing as a Service (PTaaS) Subscription-based continuous penetration testing service aligned to release cycles. Includes unlimited retesting, access to the Software Secured Portal, and compliance mappings for SOC 2, HIPAA, PCI DSS, and ISO 27001.
- Web Application Pentesting Manual penetration testing of web applications that uncovers business logic flaws, chained exploits, authentication bypasses, and data leaks that automated scanners miss. Targets auth flows and hidden vulnerabilities.
- Mobile Application Pentesting Mobile security testing that identifies insecure storage, weak cryptography, and insecure inter-app communication in iOS and Android applications.
- API Pentesting Manual API security testing that targets authentication flows, business logic flaws, and chained exploits that automated scanners miss.
- Secure Code Review Deep-dive manual security review of source code that identifies insecure coding patterns, logic flaws, cryptographic failures, and backdoors.
- External Network Pentesting Penetration testing of internet-facing perimeter assets to identify exposed hosts, open ports, and exploitable services. Starting from $5,400.
- Internal Network Pentesting Penetration testing from an internal-network perspective to uncover lateral movement paths, segmentation gaps, and insecure internal services.
- Secure Cloud Review Cloud security assessment that identifies misconfigurations, excessive permissions, and insecure trust relationships across AWS, Azure, and GCP environments.
- AI Pentesting Specialized penetration testing of AI and LLM systems that exposes model manipulation, prompt injection vulnerabilities, and data leakage.
- IoT Pentesting Penetration testing of Internet of Things devices that uncovers weak firmware, unsafe protocols, and device takeover vulnerabilities.
- Hardware Pentesting Security review of hardware systems that detects side-channel leaks, insecure interfaces, and physical tampering risks.
- Red Teaming Adversary simulation service that mimics real attackers to test detection, response, and organizational resilience against advanced threats.
- Social Engineering Testing Testing that evaluates human trust, phishing resilience, and security awareness gaps through simulated social engineering attacks.
- Threat Modeling Structured analysis that maps critical assets, identifies attack paths, and assesses business-critical risks for executive audiences.
- Enterprise Deal Support / Urgent Penetration Test Specialized accelerated pentest offering for urgent enterprise deals or complex requirements. Provides executive summaries, customer-facing letters, and remediation evidence to unblock stalled enterprise sales.
- Secure Code Training Interactive developer training with hands-on labs that teach real exploits, fixes, and prevention techniques aligned to OWASP Top 10.
Quantifiable outcome
- 26 vulnerabilities found on average per pentest, 4X more than leading competitors
- +4 more outcomes
Companies that use Software Secured
Customer profileNamed customers3 records
Segments5 records
Ideal customer profiles5 records
Software Secured technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration6 records
Feature3 records
Software Secured partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core.
- JiracoreIntegration with Jira for ticket creation and remediation tracking. Findings can be synced directly into developer workflows, enabling teams to address vulnerabilities within their existing sprint processes.
- Azure DevOpscoreIntegration with Azure DevOps for seamless DevSecOps workflows. Enables security findings to be tracked alongside code changes and deployments.
- LinearcoreIntegration with Linear for issue tracking and project management. Security findings are automatically synced to Linear for streamlined remediation workflows.
- SlackcoreIntegration with Slack for automated notifications, communication with pentesters, and real-time updates on testing progress and remediation status.
Scale indicators4 records
Recent moves5 records
Expansion highlights6 records
Software Secured competitors and assessment
Company assessmentDirect peers
- Cobalt: Cobalt is a leading PTaaS platform that connects organizations to a crowdsourced community of vetted pentesters via an on-demand workflow. It directly competes with Software Secured in the same product category (PTaaS) for SaaS and enterprise customers.
- Synack: Synack operates a hybrid PTaaS platform combining a vetted researcher network with AI-driven vulnerability intelligence, serving enterprise and government customers. It is directly comparable to Software Secured in manual pentesting delivery and PTaaS subscription model.
- HackerOne: HackerOne provides crowdsourced security testing through its platform and researcher community, including pentest offerings. It overlaps with Software Secured in delivering vulnerability assessments to enterprise and SaaS customers, though at much larger scale.
- NetSPI: NetSPI delivers penetration testing as a service alongside vulnerability management and attack surface management for enterprise clients. It is a direct competitor in PTaaS, with similar full-time consultant and PTaaS platform positioning.
- Bishop Fox: Bishop Fox is an offensive security firm offering web, mobile, network, and cloud penetration testing services with a continuous testing platform (Cosmos). It directly competes with Software Secured in manual pentest delivery and PTaaS offerings for enterprise customers.
- Praetorian: Praetorian offers offensive security services including penetration testing, red teaming, and attack surface management for enterprise clients. It is comparable to Software Secured across the manual pentesting service portfolio and continuous testing platform.
Broad incumbents
- NCC Group: NCC Group is a global cybersecurity consultancy with extensive penetration testing, red teaming, and security advisory practices. It serves enterprise and regulated-industry customers across multiple geographies, comparable to Software Secured's enterprise penetration testing work but at significantly larger scale.
- Rapid7: Rapid7 provides a broad security platform spanning vulnerability management, application security, and managed detection, and offers professional penetration testing services. It is comparable as a broader incumbent serving similar SaaS and enterprise customers with overlapping security testing offerings.
- Secureworks: Secureworks, a Dell Technologies company, delivers managed security services, offensive security testing, and consulting to enterprise customers. It overlaps with Software Secured in penetration testing and red team services while operating a much larger, broader portfolio.
- Trustwave: Trustwave provides managed security services, penetration testing, and cybersecurity consulting to enterprise and government clients. It competes with Software Secured in pentest delivery for regulated industries while offering a much wider portfolio of services.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat3 records
Key risks7 records
Key highlights7 records
Customer concentration
Software Secured social profiles
Digital presenceSoftware Secured compliance and trust
Trust signalCompliance5 records
Software Secured financial estimates
Financial estimateRevenue estimate
Valuation estimate
Software Secured leadership team
Management profileNumber of profiles
Profiles2 records
Software Secured funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Software Secured M&A and investment
M&A and investmentM&A
Investments1 record
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Software Secured
What does Software Secured do?
Software Secured provides manual, exploit-driven penetration testing services delivered through a Penetration Testing as a Service (PTaaS) subscription model. The portfolio covers web, API, mobile, internal/external network, cloud (AWS/Azure/GCP), AI/LLM, IoT, and hardware security testing, along with red teaming, social engineering, threat modeling, secure code review, and OWASP-aligned developer training. Engagements include built-in retesting, a zero-false-positive guarantee, and a purpose-built Portal for real-time tracking, remediation, audit-ready reporting, and integrations with developer and compliance tools.
Is Software Secured a public or private company?
Software Secured is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Software Secured founded?
Software Secured was founded in 2006. It employs 11 to 50 people.
Where is Software Secured based?
Software Secured is headquartered in Ottawa, Canada, in the North America region.
How does Software Secured make money?
Three revenue lines are on record. Penetration Testing as a Service (PTaaS) is the primary driver. The others are one-Time Pentest Engagements and training Services.
Who are Software Secured's main competitors?
Direct peers on record are Cobalt, Synack, HackerOne, NetSPI, Bishop Fox and Praetorian. Broad incumbents are NCC Group, Rapid7, Secureworks and Trustwave.
Does Software Secured have an API?
No public API is recorded for Software Secured.
What industry is Software Secured in?
Software Secured's product category is Penetration Testing Services. Its primary akta.pro industry code is HDADAHAG, Penetration Testing Platforms (PTaaS), with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 541380 and its SIC code is 8734.