Blaze Information Security
Blaze Information Security is a CREST-accredited, ISO 27001-certified boutique penetration testing firm founded in 2016 in Porto, Portugal, delivering manual web, mobile, SaaS, network, cloud, and red team offensive security services to enterprises, scaleups, and startups across banking, technology, healthcare, energy, and iGaming verticals in 25+ countries.
- Company typePrivate
- Founded2016
- HeadquartersPorto, Portugal
- Headcount1–10
- GTM typeB2B
- OfferingServices
What Blaze Information Security does
Blaze Information Security is a boutique penetration testing firm founded in 2016 and headquartered in Porto, Portugal, with additional offices in Berlin (Germany), Kraków (Poland), and Recife (Brazil). The company delivers manual offensive security services — web, mobile, SaaS, network, and cloud pentesting, as well as MITRE ATT&CK-aligned red team engagements — augmented by automated scanners and proprietary custom tools. Its methodology framework draws on OWASP, PTES, OSSTMM, and MITRE ATT&CK. The company is CREST accredited and maintains ISO 27001 and ISO 9001 certifications; individual consultants hold OSCP, OSWE, OSCE, and CREST CRT credentials. Blaze also maintains €5,000,000 of professional liability insurance with Hiscox.
The firm serves enterprises, scaleups, and startups across verticals including banking and fintech, technology, healthcare and life sciences, energy/oil and gas, e-commerce, and iGaming, with named customers including Reebok, Relativity, Kaia Health, Hiya, FluidStack, WorkMotion, and Bitcoin. Revenue is generated on a project-based professional services model with pentests starting at $4,999 for SOC 2, ISO 27001, and SaaS assessments, plus higher-value engagements reaching above $100,000. The company is increasingly layering recurring revenue through managed offerings including Managed Bug Bounty (via Yogosha) and Managed Security Scanning, and sells specialized compliance-aligned solutions for SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, DiGA/DiPA, SWIFT CSP, MPA/TPN, and M&A cybersecurity due diligence.
Distribution occurs through direct enterprise sales via website inquiry, a referral and reseller partner program, and technology integration partnerships with compliance platforms Drata, Vanta, Secfix, and the strategic Yogosha partnership for managed bug bounties. Content marketing via the company blog and Blaze Labs R&D group functions as the primary top-of-funnel motion for thought leadership. The firm has cumulatively served over 300 companies across 25 countries, while keeping its direct employee headcount in the 1–10 range, implying heavy reliance on a partner/contractor delivery model.
Blaze Information Security firmographics
Firmographics- Name
- Blaze Information Security
- Legal name
- Blaze Information Security
- Website
- https://blazeinfosec.com
- Company type
- Private
- Founded year
- 2016
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Blaze Information Security is a CREST-accredited, ISO 27001-certified boutique penetration testing firm founded in 2016 in Porto, Portugal, delivering manual web, mobile, SaaS, network, cloud, and red team offensive security services to enterprises, scaleups, and startups across banking, technology, healthcare, energy, and iGaming verticals in 25+ countries.
- Ownership category
- akta.pro rank
Blaze Information Security industry classification
Industry- Product category
- Penetration Testing Services
- NAICS
- Investigation and Security Services (5616), Testing Laboratories and Services (541380)
- SIC
- Services-Detective, Guard & Armored Car Services (7381)
- akta.pro primary industry
- Penetration Testing & Red Teaming (BPAKADAE)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG), Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX) (BPAKADAC)
Keywords
Where Blaze Information Security is headquartered
LocationHeadquarters
- HQ city
- Porto
- HQ country
- Portugal
- HQ region
- Europe
Offices4 records
Markets served
Blaze Information Security business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Others
Revenue model
- Professional Penetration Testing Services: Project-based professional services revenue from conducting penetration tests, security assessments, red team exercises, and related cybersecurity consulting engagements. Services are priced based on scope, complexity, and estimated budget tiers ranging from under $10,000 to above $100,000.
- Managed Security Services: Ongoing managed services including managed bug bounty programs and security scanning. These provide recurring revenue through continuous assessment engagements.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Pay-as-you-go | Pentests for SOC 2, ISO 27001 and SaaS starting at $4,999 |
Go-to-market motion1 record
Distribution channels3 records
Marketing channels6 records
Blaze Information Security product offering
Product offeringCore offering
Blaze Information Security is a boutique penetration testing provider that delivers manual offensive cybersecurity services across application, network, cloud, and red team engagements. The company offers an integrated portfolio of CREST-accredited penetration testing services, supplemented by managed bug bounty programs, security scanning, threat modeling, and secure development lifecycle consulting for compliance frameworks including SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, SWIFT CSP, and DiGA/DiPA.
Product overview
Blaze Information Security is a pure-play boutique penetration testing provider offering an integrated portfolio of offensive cybersecurity services. The core offerings span four pillars: Application Security (web app, mobile app, and SaaS penetration testing), Network Security (internal and external pentests), Cloud Security (cloud pentest and configuration reviews for AWS/GCP/Azure), and Red Teaming (adversary simulation). Supporting services include Managed Bug Bounty, Managed Security Scanning, Security Development Lifecycle, Threat Modeling, and specialized industry/compliance solutions covering fintech, healthcare, energy, e-commerce, iGaming, and technology sectors. Compliance-focused solutions address SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, DiGA/DiPA, SWIFT CSP, and MPA/TPN requirements. The company operates a referral and reseller partner program but does not offer a public API. Founded in 2016 and headquartered in Porto, Portugal, with additional offices in Berlin, Kraków, and Recife, Blaze serves over 200 organizations across 25 countries.
Differentiator
Problem solved
Functional benefit
Brands
- Blaze Labs: R&D group of Blaze Information Security focused on technical insights and cybersecurity research.
Products and services
- Application Security Penetration Testing
- Network Penetration Testing
- Cloud Security Assessments
- Red Teaming
- Managed Bug Bounty
- Managed Security Scanning
- Threat Modeling
- Security Development Lifecycle (SDL)
- Blaze Labs
Quantifiable outcome
- Trusted by 300+ companies across 25 countries
- +1 more outcomes
Companies that use Blaze Information Security
Customer profileNamed customers8 records
Segments9 records
Ideal customer profiles6 records
Blaze Information Security technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
Blaze Information Security partnerships and signals
Strategic signalPartnerships
Seven partnerships are on record, tiered minor, core and flagship.
- BeliominorPartner listed in Blaze's partner directory, providing cybersecurity services integration and collaboration.
- Bosch CyberCompareminorPartner providing cybersecurity comparison and advisory services, part of Bosch ecosystem.
- DratacoreIntegration partner providing continuous compliance automation. Blaze pentest reports can be used within Drata's compliance platform for SOC 2, ISO 27001 and other compliance frameworks.
- M4 VenturesminorVenture capital partner providing strategic connections and growth support for Blaze.
- SecfixcoreIntegration partner providing continuous compliance monitoring and automated security validation that works alongside Blaze's penetration testing services.
- VantacoreTrust management platform partner enabling automated compliance verification that can incorporate Blaze's pentest results for SOC 2, HIPAA, and other frameworks.
- YogoshaflagshipFully-managed bug bounty solution partner. Yogosha provides the bug bounty platform and vetted hacker community while Blaze manages program setup, vulnerability triage and ongoing optimization. This is a strategic partnership for delivering managed bug bounty services.
Scale indicators3 records
Recent moves6 records
Expansion highlights5 records
Blaze Information Security competitors and assessment
Company assessmentEmerging players
- Cobalt: Pentest-as-a-service platform connecting clients with vetted security researchers for on-demand pentests. Comparable buyer profile (startups, scaleups needing SOC 2/ISO 27001 evidence) but delivered via a marketplace model.
Direct peers
- NetSPI: Pentest-focused cybersecurity firm offering application, network, and cloud penetration testing alongside managed security testing services. Comparable in scope, recurring service model, and enterprise client base.
- Bishop Fox: Boutique offensive-security firm specializing in penetration testing, red teaming, and attack-surface management for enterprise clients. Closely comparable in service mix, methodology, and target customer profile to Blaze.
- Rhino Security Labs: Boutique penetration testing firm offering cloud, network, application, and red team services. Closely comparable in boutique positioning and offensive-security specialization.
- Pentest People: UK-based CREST-accredited penetration testing provider offering application, network, and cloud testing with compliance alignment (ISO 27001, PCI DSS, SOC 2). Closely comparable boutique competitor in the European market.
Broad incumbents
- Rapid7: Public cybersecurity vendor with penetration testing services alongside its broader product portfolio. Competes with Blaze for enterprise pentest budgets while offering additional vulnerability management and SIEM solutions.
- NCC Group: Global cybersecurity consultancy offering penetration testing, red teaming, and compliance services. Larger and more diversified than Blaze but directly competes for enterprise pentest and CREST-accredited engagements.
- Trustwave: Global MSSP and cybersecurity consultancy with a substantial penetration testing practice. Overlaps with Blaze on enterprise compliance-driven pentest work but offers a much broader managed security portfolio.
Regional players
- Securitum: Polish-based penetration testing boutique serving European enterprises with web, mobile, and infrastructure pentests. Comparable in service catalog, certification stack, and EMEA focus.
Others
- Yogosha: European bug bounty platform and Blaze's strategic partner. Adjacent in offering (managed bug bounty, vulnerability disclosure) and shares overlapping customers, but operates a platform model rather than a services model.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
Blaze Information Security social profiles
Digital presenceBlaze Information Security compliance and trust
Trust signalCompliance11 records
Blaze Information Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Blaze Information Security leadership team
Management profileNumber of profiles
Profiles3 records
Blaze Information Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Blaze Information Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Blaze Information Security
What does Blaze Information Security do?
Blaze Information Security is a boutique penetration testing provider that delivers manual offensive cybersecurity services across application, network, cloud, and red team engagements. The company offers an integrated portfolio of CREST-accredited penetration testing services, supplemented by managed bug bounty programs, security scanning, threat modeling, and secure development lifecycle consulting for compliance frameworks including SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, SWIFT CSP, and DiGA/DiPA.
Is Blaze Information Security a public or private company?
Blaze Information Security is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Blaze Information Security founded?
Blaze Information Security was founded in 2016. It employs 1 to 10 people.
Where is Blaze Information Security based?
Blaze Information Security is headquartered in Porto, Portugal, in the Europe region.
How does Blaze Information Security make money?
Two revenue lines are on record. Professional Penetration Testing Services are the primary driver. The others are managed Security Services.
Who are Blaze Information Security's main competitors?
Cobalt is listed as an emerging player. Direct peers are NetSPI, Bishop Fox, Rhino Security Labs and Pentest People. Broad incumbents are Rapid7, NCC Group and Trustwave. Securitum is listed as a regional player. Yogosha is listed as an others.
Does Blaze Information Security have an API?
No public API is recorded for Blaze Information Security.
What industry is Blaze Information Security in?
Blaze Information Security's product category is Penetration Testing Services. Its primary akta.pro industry code is BPAKADAE, Penetration Testing & Red Teaming, with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 5616 and its SIC code is 7381.