ONYPHE
- Company typePrivate
- Founded2017
- HeadquartersRennes, France
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
ONYPHE firmographics
Firmographics- Name
- ONYPHE
- Legal name
- Société ONYPHE SAS
- Website
- https://onyphe.io
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Ownership category
- akta.pro rank
ONYPHE industry classification
Industry- Product category
- Cybersecurity Intelligence Software
- NAICS
- Web Search Portals and All Other Information Services (519290), Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (5182), Web Search Portals, Libraries, Archives, and Other Information Services (5192)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Services-Computer Processing & Data Preparation (7374)
- akta.pro primary industry
- Attack Surface Management (EASM/CAASM) (HDADAHAC)
Keywords
Where ONYPHE is headquartered
LocationHeadquarters
- HQ city
- Rennes
- HQ country
- France
- HQ region
- Europe
Offices2 records
Markets served
ONYPHE business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Infrastructure, Personnel, Marketing or Sales, Operations
Revenue model
- API/SaaS Subscription: ONYPHE generates revenue through tiered subscription licensing for API access to their cyber defense search engine. Tiers include Free View (limited search capabilities), Butterfly View (full search filters without device classification), and Enterprise Views (complete access to all filters and data categories including vulnscan, riskscan, and historical data). Pricing is quote-based for enterprise tiers.
- On-Demand Scanning APIs: Revenue is generated through specialized on-demand scanning APIs (Scope IP, Scope Port, Scope Domain, Resolver Domain) that allow customers to request specific scans beyond the continuous baseline scanning. These are likely consumed on a usage or subscription basis.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Others | Free View - Limited search access for discovery and evaluation |
| Subscription | Annual | Butterfly View - Full search capabilities without device classification |
| Subscription | Annual | Enterprise Views - Complete access to all data and capabilities |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels8 records
ONYPHE product offering
Product offeringCore offering
ONYPHE operates a Big Data cyber defense search engine that continuously scans the Internet (IPv4/IPv6) and Dark Web using a net-neutral, dual-scanner (IP + web crawling) architecture. The platform provides three integrated solutions — Attack Surface Discovery (ASD), Attack Surface Management (ASM), and Cyber Threat Intelligence (CTI) — delivered primarily through a REST API returning JSON data, and is used by enterprise security teams and government agencies to discover exposed assets, monitor critical vulnerabilities, and conduct forensic investigations.
Product overview
ONYPHE is a unified cyber defense platform providing Big Data for Cyber Defense. The platform consists of three core integrated solutions: Attack Surface Discovery (ASD) for discovering Internet-exposed assets using a domain-based approach, Attack Surface Management (ASM) for monitoring and managing risks on discovered assets, and Cyber Threat Intelligence (CTI) for historical analysis and threat investigation. These core products are complemented by multiple API products including Search API, Ondemand APIs, ASD APIs, and Alert API for programmatic access and automation. The platform collects over 20 billion banners monthly, scans 2,100+ ports, and maintains 48 months of DNS historical data. Data is accessible via REST API with JSON output, and a CLI tool is available for command-line access.
Differentiator
Problem solved
Functional benefit
Products and services
- Attack Surface Discovery (ASD) Discovers and inventories all Internet-exposed assets of an organization using a domain-based approach. Performs DNS enumeration, IP and URL scanning, and pivot-based discovery (e.g., TLS certificate organization pivots) to surface known and unknown assets bound to domain names.
- Attack Surface Management (ASM) Manages identified attack surface by performing risk assessment on discovered assets, focusing on exposed RDP/VNC services, VPN vulnerabilities, and critical vulnerabilities drawn from the CISA Known Exploited Vulnerabilities catalog. Exposed via vulnscan and riskscan data categories.
- Cyber Threat Intelligence (CTI) Provides threat intelligence capabilities including time-travel analysis using 48 months of historical DNS data and 7 months of historical scan data, enabling forensic analysis, DNS enumeration, and threat investigation across clear and Dark Web sources.
- ONYPHE Search API
Quantifiable outcome
- Scans full IPv4 Internet for approximately 200 ports monthly at scale
- +4 more outcomes
Companies that use ONYPHE
Customer profileNamed customers10 records
Segments4 records
Ideal customer profiles4 records
ONYPHE technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration2 records
Feature10 records
ONYPHE partnerships and signals
Strategic signalScale indicators7 records
Recent moves6 records
Expansion highlights5 records
ONYPHE competitors and assessment
Company assessmentDirect peers
- BinaryEdge: BinaryEdge is an API-first cyber threat intelligence and attack surface platform offering continuous internet scanning data. It mirrors ONYPHE's model of exposing scanner data through search APIs to security teams, and competes directly on similar use cases (asset discovery, exposed service identification, threat hunting).
- GreyNoise: GreyNoise collects, classifies, and labels internet-wide scan and attack traffic to help defenders distinguish targeted threats from background noise. It overlaps with ONYPHE's threat intelligence capabilities and shares the API-first delivery model serving SOC, threat intel, and ASM practitioners.
- SecurityTrails: SecurityTrails specializes in DNS and domain intelligence with deep historical passive DNS data. It overlaps with ONYPHE's 48-month historical DNS positioning and its focus on DNS enumeration as a starting point for attack surface discovery. Comparable API-first data product for security researchers and enterprise teams.
- Censys: Censys is a venture-backed internet scanning and Attack Surface Management platform. Both companies perform continuous IPv4 scanning, provide API-first access, and target enterprise security teams for ASM and threat intelligence use cases. Censys's larger funding base and broader enterprise sales coverage make it a primary head-to-head competitor.
- FOFA: FOFA is an internet asset search engine (also by Knownsec) that indexes IP, port, protocol, and component data at scale. Direct comparison point to ONYPHE's continuous IP/port scanning and API-first asset search; overlaps on device classification and exposure discovery for enterprise and government security teams.
- LeakIX: LeakIX is an open-data platform that indexes exposed services, misconfigurations, and leaked credentials discovered via continuous internet scanning. It competes with ONYPHE on ASM-style discovery of exposed assets, with comparable API exposure and overlap in serving security researchers and enterprise defenders.
- Shodan: Shodan is the original internet-wide scanning search engine and ONYPHE's most direct competitor. Both operate continuous IP/port scanning infrastructure and expose data through search and APIs; ONYPHE explicitly benchmarks against Shodan (e.g., 67,000+ open databases discovery comparison) and positions its domain-based, port-agnostic approach as a differentiator.
- ZoomEye: ZoomEye is a cybersecurity search engine operated by Knownsec that scans internet-exposed assets and surfaces device, service, and vulnerability information. It competes with ONYPHE in the search-engine-for-internet-assets category, with comparable API-driven delivery and a focus on enterprise and government security users.
Broad incumbents
- Palo Alto Cortex Xpanse (formerly Expanse): Xpanse (acquired by Palo Alto Networks) is a leading enterprise Attack Surface Management platform bundled inside the broader Cortex security suite. It competes with ONYPHE's ASM product but operates as part of a multi-billion-dollar security portfolio with much larger sales coverage, distribution, and integration into adjacent Palo Alto products.
- Microsoft Defender Threat Intelligence (formerly RiskIQ): Microsoft Defender Threat Intelligence (built on the RiskIQ acquisition) provides external attack surface and threat intelligence capabilities inside the Microsoft Defender ecosystem. It competes with ONYPHE's ASD/ASM/CTI offerings as part of a much broader enterprise security portfolio with native distribution to the Microsoft customer base.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks7 records
Key highlights7 records
Customer concentration
ONYPHE social profiles
Digital presenceONYPHE financial estimates
Financial estimateRevenue estimate
Valuation estimate
ONYPHE leadership team
Management profileNumber of profiles
Profiles1 record
ONYPHE funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
ONYPHE M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about ONYPHE
What does ONYPHE do?
ONYPHE operates a Big Data cyber defense search engine that continuously scans the Internet (IPv4/IPv6) and Dark Web using a net-neutral, dual-scanner (IP + web crawling) architecture. The platform provides three integrated solutions — Attack Surface Discovery (ASD), Attack Surface Management (ASM), and Cyber Threat Intelligence (CTI) — delivered primarily through a REST API returning JSON data, and is used by enterprise security teams and government agencies to discover exposed assets, monitor critical vulnerabilities, and conduct forensic investigations.
Is ONYPHE a public or private company?
ONYPHE is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was ONYPHE founded?
ONYPHE was founded in 2017. It employs 1 to 10 people.
Where is ONYPHE based?
ONYPHE is headquartered in Rennes, France, in the Europe region.
How does ONYPHE make money?
Two revenue lines are on record. API/SaaS Subscription is the primary driver. The others are on-Demand Scanning APIs.
Who are ONYPHE's main competitors?
Direct peers on record are BinaryEdge, GreyNoise, SecurityTrails, Censys, FOFA, LeakIX, Shodan and ZoomEye. Broad incumbents are Palo Alto Cortex Xpanse (formerly Expanse) and Microsoft Defender Threat Intelligence (formerly RiskIQ).
Does ONYPHE have an API?
Yes. REST API that renders JSON content. Provides multiple API versions: General APIs (User APIv2, Search APIv2, Export APIv2, Discovery APIv2, Alert APIv2, Summary APIv2, Bulk Summary APIv2, Simple APIv2, Bulk Simple APIv2, Simple Best APIv2, Bulk Simple Best APIv2); Ondemand APIs (Scope Ip APIv3, Scope Port APIv3, Scope Domain APIv3, Scope Hostname APIv3, Scope IP Bulk APIv3, Scope Domain Bulk APIv3, Scope Hostname Bulk APIv3, Scope Result APIv3, Resolver Domain APIv3, Resolver Domain Bulk APIv3, Resolver Result APIv3); ASD APIs (Pivot Query APIv1, Domain Tld APIv1, Domain Certso APIv1, Domain Wildcard APIv1, Certso Domain APIv1, Certso Wildcard APIv1, Dns Domain Ns APIv1, Dns Domain Mx APIv1, Dns Domain Soa APIv1, Dns Domain Exist APIv1). ONYPHE CLI tool available for command-line access. Developer documentation is at search.onyphe.io/docs.
What industry is ONYPHE in?
ONYPHE's product category is Cybersecurity Intelligence Software. Its primary akta.pro industry code is HDADAHAC, Attack Surface Management (EASM/CAASM). Its NAICS code is 519290 and its SIC code is 7370.