LocateRisk
LocateRisk GmbH is a Darmstadt-based External Attack Surface Management (EASM) platform, founded in 2020, that delivers automated, KPI-based IT security ratings, continuous monitoring, vendor/third-party risk management, and benchmarking for DACH enterprises, municipalities, critical infrastructure operators, and system integrators.
- Company typePrivate
- Founded2020
- HeadquartersDarmstadt, Germany
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What LocateRisk does
LocateRisk GmbH is a German External Attack Surface Management (EASM) vendor headquartered in Darmstadt, founded in 2020. The platform performs automated, non-invasive external scans of organizations' IT environments and translates findings into standardized, KPI-based security ratings that can be benchmarked against peers and tracked over time. Core modules include IT risk analysis, business-partner/third-party risk management with automated GDPR compliance checks, KRITIS compliance evidence, vendor risk management, cybersecurity compliance mapping, Konzernreporting (group reporting), SOC data feeds, and a Preemptive Intelligence offering. The company also publishes case studies in managed security services for system integrators and offers dedicated IT security consulting. Underlying technology covers app security, infections, network security, patch management, data-breach detection, DNS configuration, and encryption; output is dual-formatted as an executive management report and a technical vulnerability dashboard, with automatic email notifications on newly disclosed CVEs affecting a customer's external footprint.
LocateRisk firmographics
Firmographics- Name
- LocateRisk
- Legal name
- LocateRisk GmbH
- Website
- https://LocateRisk.com
- Company type
- Private
- Founded year
- 2020
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- LocateRisk GmbH is a Darmstadt-based External Attack Surface Management (EASM) platform, founded in 2020, that delivers automated, KPI-based IT security ratings, continuous monitoring, vendor/third-party risk management, and benchmarking for DACH enterprises, municipalities, critical infrastructure operators, and system integrators.
- Ownership category
- akta.pro rank
LocateRisk industry classification
Industry- Product category
- Cybersecurity Software / Attack Surface Management
- NAICS
- Computer Systems Design Services (541512), Computer Systems Design and Related Services (54151), Security Systems Services (56162)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Attack Surface Management (EASM/CAASM) (HDADAHAC)
- akta.pro secondary industries
- Vulnerability Assessment & Scanning (HDADAHAA), Secure Industrial Gateways, Data Diodes & Unidirectional Security (HDADAJAM)
Keywords
Where LocateRisk is headquartered
LocationHeadquarters
- HQ city
- Darmstadt
- HQ country
- Germany
- HQ region
- Europe
Offices1 record
Markets served
LocateRisk business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- SaaS Subscription (Security Rating Platform): Annual or multi-year subscription-based access to the LocateRisk EASM platform, providing ongoing scanning, monitoring, benchmarking, and reporting capabilities. Pricing is quote-based and tiered by organization size, scope, and feature set.
- Free Security Rating (Lead Generation): A free, entry-level security rating is offered to attract prospects into the funnel, with conversion to paid subscription tiers for full platform access.
- Professional Services (IT Security Consulting): Additional consulting services for IT security advisory, managed security services, and cybersecurity compliance mapping, complementing the automated platform.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Monthly | Free Rating — entry-level security scan |
| Subscription | Annual | Paid Plans — full platform access |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels6 records
LocateRisk product offering
Product offeringCore offering
LocateRisk provides a SaaS-based External Attack Surface Management (EASM) platform that continuously scans organizations' externally observable IT assets (domains, IPs, subdomains, certificates, services) from an attacker's perspective and produces standardized, KPI-based IT security ratings. The offering is delivered as a subscription product, supplemented by free ratings for lead generation and by professional IT security consulting and managed security services for system integrators.
Product overview
LocateRisk offers an External Attack Surface Management platform that provides automated, non-invasive IT risk analysis and continuous monitoring of organizational attack surfaces. The platform employs automated CVE detection and scanning capabilities to assess IT systems from an external attacker perspective, evaluating app security, network security, patch management, data breaches, DNS configuration, and encryption. Results are delivered in two formats: management-friendly reports with clear graphics and vulnerability dashboards with detailed information for IT professionals. The platform includes modules for third-party risk management, vendor risk management, SOC data feeds, KRITIS compliance, cybersecurity compliance mapping, and group reporting, enabling organizations to measure, compare, and continuously improve their IT security posture.
Differentiator
Problem solved
Functional benefit
Products and services
- External Attack Surface Management Platform (LocateRisk Platform)
- IT Risk Analysis (IT-Risikoanalyse) IT risk analysis offering that applies LocateRisk's KPI-based security rating methodology to deliver a continuous, external view of an organization's IT risk posture for security and risk management teams.
- Business Partner Risk Management Solution within the LocateRisk platform for monitoring and rating the external security posture of business partners and suppliers, enabling risk teams to track third-party cyber risk on an ongoing basis.
- Third Party Risk Management English-language equivalent of the Business Partner Risk Management offering, providing external attack-surface-based third-party cyber risk monitoring and rating for international enterprise buyers.
- Vendor Risk Management Solution within the LocateRisk platform for vendor/supplier external security risk assessment, giving procurement and security teams a standardized, ongoing view of vendor cyber risk.
- Cybersecurity Compliance Solution within the LocateRisk platform that uses external attack-surface scanning and standardized rating to support compliance with major cybersecurity frameworks and standards such as ISO 27001, NIST, CIS, and PCI-DSS.
- KRITIS Compliance Solution Solution within the LocateRisk platform tailored for German critical infrastructure (KRITIS) operators, providing continuous external attack-surface monitoring and KPI-based security ratings to support regulatory compliance under the BSI-Kritisverordnung and IT-Sicherheitsgesetz 2.0.
- Due Diligence Solution Solution within the LocateRisk platform for performing external cyber due-diligence assessments of target companies in M&A and investment scenarios, leveraging the standardized security rating methodology.
- Konzern (Group) Reporting Solution Solution within the LocateRisk platform that provides group-level (Konzern) security reporting and benchmarking across parent, subsidiaries, and group entities using standardized KPI-based security ratings.
- Preemptive Intelligence Solution within the LocateRisk platform that provides attacker-perspective intelligence on external exposure to enable proactive remediation before exploitation, combining external scanning with CVE awareness.
- SOC Analysis Data Feeds Data-feed offering within the LocateRisk platform that delivers external attack-surface analysis data and security rating information into customer Security Operations Centers (SOCs) for integration with existing security monitoring workflows.
- IT Security Consulting (IT-Sicherheitsberatung) Professional IT security consulting services offered alongside the LocateRisk platform, combining the company's external attack-surface data and standardized rating methodology with expert advisory engagements for enterprise customers.
- Managed Security Services Managed security service offering built on the LocateRisk platform, designed for system integrators and MSSPs that want to deliver continuous external attack surface management and KPI-based security rating to their own end customers without building their own scanning infrastructure.
Quantifiable outcome
- 4,000,000+ servers measured since 2020/21
- +4 more outcomes
Companies that use LocateRisk
Customer profileNamed customers14 records
Segments6 records
Ideal customer profiles5 records
LocateRisk technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability2 records
Feature6 records
LocateRisk partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered minor and core.
- Deutsche Telekom (TechBoost)minorLocateRisk was selected for Deutsche Telekom's TechBoost startup programme in 2022, providing go-to-market support and access to Deutsche Telekom's enterprise customer network.
- Allianz für Cybersicherheit (BSI)coreLocateRisk is a member of the German Alliance for Cybersecurity (Allianz für Cybersicherheit), an initiative of the Federal Office for Information Security (BSI). Membership provides access to the broader cybersecurity community, threat intelligence sharing, and official recognition within the German cybersecurity ecosystem.
- Bundesverband IT-Sicherheit (TeleTrusT)coreLocateRisk carries the 'IT Security made in Germany' quality mark from TeleTrusT (Bundesverband IT-Sicherheit), the German IT Security Association. This certification signals compliance with German data sovereignty and security standards.
- PwC (NextLevel Scale)minorLocateRisk was selected for PwC's NextLevel Scale programme in 2021, which provides business development support, mentorship, and market access for high-growth startups.
- Fraunhofer SITcoreLocateRisk maintains an ongoing exchange with cybersecurity experts at Fraunhofer SIT (Institute for Computer Technology), leveraging academic research expertise to develop and enhance its EASM platform technologies.
- TU DarmstadtcoreLocateRisk maintains an ongoing exchange with researchers at TU Darmstadt (Technical University of Darmstadt), supporting the development of new security technologies and accessing top academic talent in the cybersecurity field.
Scale indicators6 records
Recent moves6 records
Expansion highlights6 records
LocateRisk competitors and assessment
Company assessmentRegional players
- Holm Security: Swedish-based vulnerability and attack surface management provider serving Northern European mid-market customers - the regional peer analog to LocateRisk's DACH focus, with a similar outside-in scanning approach for SMBs and enterprises.
Direct peers
- SecurityScorecard: Global leader in security ratings and attack surface management, offering continuous external scanning, vendor risk management, and KPI-based cyber risk scoring - the same core proposition as LocateRisk's EASM platform, just at global scale.
- Bitsight: Pioneer of security ratings with continuous external attack surface monitoring, third-party/vendor risk management, and benchmarkable cyber risk scores - closest direct competitor to LocateRisk on product, business model, and customer use cases.
- UpGuard: External attack surface and third-party risk management platform with continuous scanning, vendor risk assessments, and security questionnaires - directly overlapping with LocateRisk's business partner risk management module.
- RiskRecon (Mastercard): External cyber risk ratings platform acquired by Mastercard, providing continuous external scanning and third-party risk scoring comparable to LocateRisk's value proposition, particularly in financial services underwriting.
- Panorays: Third-party cyber risk management platform combining external attack surface scans with questionnaire-based assessments and business context - directly comparable to LocateRisk's third-party/vendor risk management module.
- Black Kite: Supply chain and third-party cyber risk intelligence platform delivering external ratings, ransomware susceptibility scores, and financial quantification - a direct competitor in third-party risk and the same cyber insurance underwriting ecosystem LocateRisk targets.
Broad incumbents
- Tenable: Enterprise vulnerability management leader whose Tenable One platform adds external attack surface management to a much broader exposure management suite - a broader incumbent that bundles ASM alongside VM, cloud, and identity exposure.
- CrowdStrike (Falcon Surface): Endpoint security leader that has added Falcon Surface external attack surface management as a module within its broader Falcon platform - a broader incumbent competing for the same external scanning budget from a wider platform sale.
- Wiz: Cloud security platform with significant attack surface management capabilities aimed at cloud-first enterprises; represents a newer style of broad incumbent that combines cloud security posture with external attack surface scanning.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
LocateRisk social profiles
Digital presenceLocateRisk compliance and trust
Trust signalCompliance3 records
LocateRisk financial estimates
Financial estimateRevenue estimate
Valuation estimate
LocateRisk leadership team
Management profileNumber of profiles
Profiles1 record
LocateRisk funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
LocateRisk M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about LocateRisk
What does LocateRisk do?
LocateRisk provides a SaaS-based External Attack Surface Management (EASM) platform that continuously scans organizations' externally observable IT assets (domains, IPs, subdomains, certificates, services) from an attacker's perspective and produces standardized, KPI-based IT security ratings. The offering is delivered as a subscription product, supplemented by free ratings for lead generation and by professional IT security consulting and managed security services for system integrators.
Is LocateRisk a public or private company?
LocateRisk is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was LocateRisk founded?
LocateRisk was founded in 2020. It employs 11 to 50 people.
Where is LocateRisk based?
LocateRisk is headquartered in Darmstadt, Germany, in the Europe region.
How does LocateRisk make money?
Three revenue lines are on record. SaaS Subscription (Security Rating Platform) is the primary driver. The others are free Security Rating (Lead Generation) and professional Services (IT Security Consulting).
Who are LocateRisk's main competitors?
Holm Security is listed as a regional player. Direct peers are SecurityScorecard, Bitsight, UpGuard, RiskRecon (Mastercard), Panorays and Black Kite. Broad incumbents are Tenable, CrowdStrike (Falcon Surface) and Wiz.
Does LocateRisk have an API?
No public API is recorded for LocateRisk.
What industry is LocateRisk in?
LocateRisk's product category is Cybersecurity Software / Attack Surface Management. Its primary akta.pro industry code is HDADAHAC, Attack Surface Management (EASM/CAASM), with a secondary code of HDADAHAA, Vulnerability Assessment & Scanning. Its NAICS code is 541512 and its SIC code is 7370.