CQR
CQR is a private cybersecurity services firm offering penetration testing, smart contract audits across 15+ blockchains, AI/LLM security, and compliance advisory to enterprise clients globally, supported by proprietary tools (Insomnia Scanner, CryEye) and offices in six countries.
- Company typePrivate
- Founded2008
- HeadquartersSan Francisco, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What CQR does
CQR Company is a private cybersecurity services firm headquartered in San Francisco with legal domicile in Ukraine and operational offices in six countries (USA, UK, Kazakhstan, Canada, Ukraine, Qatar). Founded approximately 2008–2009, the firm offers a comprehensive offensive and defensive security portfolio that includes penetration testing, vulnerability assessment, red-team operations, SOC services, incident response, social engineering, and compliance advisory across standards such as SOC 2, HIPAA, PCI DSS, ISO 27001, GDPR, and ISO 21434.
The company's technical core rests on two proprietary tools: the CryEye platform — an all-in-one cybersecurity platform used in 1,500+ audits for cloud-based continuous auditing and security monitoring — and the Insomnia Security Scanner, launched in 2025, which combines 1,200+ vulnerability modules with an AI-powered autonomous pentest agent, SAST engine across 15+ programming languages, OSINT module, and structured PDF reporting. CQR also maintains deep specialization in Web3 and AI/LLM security, offering smart contract audits across 15+ blockchain platforms (Ethereum, Solana, Polygon, Arbitrum, Optimism, zkSync, Avalanche, Polkadot, Cosmos, Near, Aptos, Sui, Fantom, BSC) and AI-security services including LLM penetration testing, prompt injection protection, and an LLM Firewall-as-a-Service. An ecosystem of sub-brands (exploit.company, attack.company, CQR-Wiki, CQR-Tools) and proprietary training programs (SSDE, SSDB courses, CSAS certification) supports the practitioner's brand and talent pipeline.
CQR operates a sales-led, quote-based enterprise go-to-market model, delivering services directly through its distributed bench of security specialists. Revenue is generated primarily through professional services engagements, with no publicly disclosed pricing or contract values. Cumulative reported metrics include 300+ secured companies and 2,000+ projects over 15+ years; the company is privately held with no disclosed external funding.
CQR firmographics
Firmographics- Name
- CQR
- Legal name
- CQR Company
- Website
- https://cqr.company
- Company type
- Private
- Founded year
- 2008
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- CQR is a private cybersecurity services firm offering penetration testing, smart contract audits across 15+ blockchains, AI/LLM security, and compliance advisory to enterprise clients globally, supported by proprietary tools (Insomnia Scanner, CryEye) and offices in six countries.
- Ownership category
- akta.pro rank
CQR industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Security Systems Services (except Locksmiths) (561621), Security Systems Services (56162)
- SIC
- Services-Computer Programming Services (7371), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Bug Bounty, Vulnerability Disclosure & Security Services (FSAPAJAL)
Keywords
Where CQR is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Offices6 records
Markets served
CQR business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Cybersecurity Professional Services: CQR generates revenue through professional cybersecurity services including penetration testing, vulnerability assessments, incident response, smart contract audits, and compliance consulting. Services are offered to enterprise clients globally with quote-based pricing.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom enterprise pricing based on scope and requirements |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels6 records
CQR product offering
Product offeringCore offering
CQR provides enterprise cybersecurity services including penetration testing, vulnerability assessment, incident response, SOC, social engineering, and cloud/mobile/IoT security audits, supplemented by proprietary AI-powered tools (Insomnia Security Scanner and CryEye platform). The company also offers Web3 smart contract audits across 15+ blockchain networks, AI/LLM security services (prompt injection protection, AI penetration testing, LLM firewall), and compliance consulting for SOC 2, HIPAA, PCI DSS, ISO 27001, GDPR, and ISO 21434.
Product overview
CQR is a comprehensive cybersecurity services company offering a platform-plus-products portfolio. The core offerings include proprietary AI-powered security tools (Insomnia Security Scanner, CryEye platform) combined with extensive professional services across offensive security (penetration testing, red teaming, social engineering), defensive security (SOC services, incident response, vulnerability assessment), Web3/blockchain security (smart contract audits across 14+ blockchain networks), compliance services (SOC 2, HIPAA, PCI DSS, ISO 27001, GDPR), and specialized AI security services (LLM penetration testing, prompt injection protection). The company also operates complementary sub-brands including exploit.company (exploit library), attack.company (red team squad), CQR-Tools, and CQR-Wiki, along with training programs (SSDE Courses, CSAS Certification).
Differentiator
Problem solved
Functional benefit
Brands
- exploit.company: Large, constantly updated library of exploits.
- CryEye
- CQR - Tools
- CQR - Wiki
- attack.company
- Insomnia Security Scanner
Products and services
- Insomnia Security Scanner AI-powered web, API, and network security scanner built by the CQR team with 1,200+ vulnerability modules, AI Exploit Verification, SAST engine across 15+ programming languages, and detailed PDF reports. Targets enterprise security teams and penetration testers; available cross-platform with a free trial.
- CryEye Platform Cloud-based enterprise information security platform providing continuous auditing and security monitoring. Used by CQR experts and has been applied in over 1,500 security audits.
- Penetration Testing Services Ethical hacking engagement that identifies vulnerabilities in client infrastructure before adversaries can exploit them, with customized cybersecurity recommendations. Targets enterprise organizations seeking pre-emptive security validation.
- Smart Contract Audit Services Blockchain and smart contract security audits covering 15+ networks, including formal verification and manual code review to detect reentrancy, overflow, and logic flaws. Targets Web3 projects, DeFi protocols, and blockchain development teams.
- Social Engineering Services Staff security awareness training and personalized social engineering engagements including phishing, spear phishing, malicious attachments, and system vulnerability exploitation simulations. Targets enterprise organizations seeking to reduce human-factor risk.
- Vulnerability Assessment Services AI-powered vulnerability discovery, prioritization, and remediation across digital assets, intended to be faster and more accurate than traditional scanners. Targets enterprise security teams needing continuous visibility into their attack surface.
- SOC Services Security Operations Center offerings including real-time monitoring, searching, and analyzing of system breaches, along with threat mitigation and proactive prevention measures. Targets enterprise clients needing 24/7 security monitoring.
- Incident Response Services Rapid response technology for security breaches including evidence collection, malware analysis, attacker timeline reconstruction, and remediation recommendations. Targets organizations experiencing or preparing for active security incidents.
- API Penetration Testing In-depth testing of REST, GraphQL, and SOAP APIs for authentication flaws, authorization bypasses, injection vulnerabilities, and data leakage risks. Targets organizations with significant API surface area.
- Red Team Operations Advanced adversary simulation using real attacker TTPs aligned to MITRE ATT&CK to test detection, response, and overall security posture under realistic conditions. Operated through the dedicated attack.company sub-brand.
- Cloud Security Audit Comprehensive security review of AWS, GCP, and Azure environments covering IAM policies, network controls, data exposure, and misconfigurations. Targets enterprises with multi-cloud or single-cloud footprints.
- Mobile Application Penetration Testing Manual and automated security testing for iOS and Android apps including reverse engineering, runtime analysis, traffic interception, and backend API assessment. Targets enterprises shipping consumer or enterprise mobile applications.
- IoT Security Assessment Security evaluation of firmware, communication protocols, cloud backends, and physical interfaces of IoT devices to identify vulnerabilities before attackers. Targets IoT manufacturers, integrators, and enterprise IoT operators.
- AI & GenAI Penetration Testing Specialized penetration testing services for AI and Generative AI systems including prompt injection protection and LLM vulnerability assessment. Targets organizations deploying or integrating AI/LLM systems.
- AI LLM Firewall Firewall service for LLM protection that safeguards AI systems from prompt injection attacks and other LLM-specific vulnerabilities. Targets enterprises deploying LLM-backed applications and AI agents.
- SSDE Courses Cybersecurity training courses covering advanced penetration testing methodologies and techniques. Targets security professionals seeking structured upskilling.
- CSAS Certification Cybersecurity certification program validating expertise in security assessment methodologies. Targets security professionals seeking credentialed validation of assessment skills.
Quantifiable outcome
- 300+ companies secured, 2000+ projects completed, 1500+ audits using proprietary CryEye tool, 15+ years in market
Companies that use CQR
Customer profileNamed customers1 record
Segments1 record
Ideal customer profiles1 record
CQR technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability8 records
Feature4 records
CQR partnerships and signals
Strategic signalScale indicators4 records
Recent moves5 records
Expansion highlights6 records
CQR competitors and assessment
Company assessmentDirect peers
- Trail of Bits: Trail of Bits is a cybersecurity firm specializing in smart contract audits, blockchain security, and applied research. Directly comparable to CQR's Web3 audit and offensive security offerings, with similar depth across Ethereum, Solana, and other chains.
- CertiK: CertiK is a leading blockchain security firm offering smart contract audits, formal verification, and penetration testing for Web3 projects. Directly comparable to CQR's smart contract audit service across multiple blockchain platforms.
- Bishop Fox: Bishop Fox is a penetration testing and offensive security firm offering red teaming, application security, and security consulting. Directly comparable to CQR's core penetration testing and red team service portfolio for enterprise clients.
- IOActive: IOActive is a cybersecurity services firm specializing in penetration testing, hardware/IoT security audits, and red team engagements. Directly comparable to CQR's offensive security and IoT security assessment offerings.
- Halborn: Halborn is a blockchain cybersecurity firm providing smart contract audits, penetration testing, and security advisory for DeFi and Web3. Directly comparable to CQR's Web3 audit and blockchain penetration testing services.
- Atredis Partners: Atredis Partners is a boutique cybersecurity research and consulting firm offering penetration testing, red teaming, and security assessments. Directly comparable to CQR's offensive security and assessment service portfolio.
- Hacken: Hacken is a blockchain security auditor offering smart contract audits, penetration testing, and bug bounties for Web3 projects. Comparable to CQR's Web3 service portfolio with similar multi-chain audit focus.
Broad incumbents
- Trustwave: Trustwave is a global cybersecurity company offering penetration testing, managed detection and response, and compliance services. Comparable as a broader incumbent in the same enterprise cybersecurity services market as CQR.
- Kudelski Security: Kudelski Security is a managed security services provider offering penetration testing, incident response, and SOC services to enterprise clients. Comparable as a broader incumbent offering overlapping managed and offensive security services to CQR's target market.
- NCC Group: NCC Group is a global cybersecurity consultancy offering penetration testing, threat intelligence, and managed security services. Comparable as a broader incumbent offering overlapping services, though at significantly larger scale than CQR.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights6 records
Customer concentration
CQR social profiles
Digital presenceCQR compliance and trust
Trust signalCompliance6 records
CQR financial estimates
Financial estimateRevenue estimate
Valuation estimate
CQR leadership team
Management profileNumber of profiles
CQR subsidiaries and ownership
Company hierarchySubsidiaries6 records
CQR funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
CQR M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about CQR
What does CQR do?
CQR provides enterprise cybersecurity services including penetration testing, vulnerability assessment, incident response, SOC, social engineering, and cloud/mobile/IoT security audits, supplemented by proprietary AI-powered tools (Insomnia Security Scanner and CryEye platform). The company also offers Web3 smart contract audits across 15+ blockchain networks, AI/LLM security services (prompt injection protection, AI penetration testing, LLM firewall), and compliance consulting for SOC 2, HIPAA, PCI DSS, ISO 27001, GDPR, and ISO 21434.
Is CQR a public or private company?
CQR is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was CQR founded?
CQR was founded in 2008. It employs 11 to 50 people.
Where is CQR based?
CQR is headquartered in San Francisco, United States, in the North America region.
How does CQR make money?
One revenue line is on record: cybersecurity Professional Services.
Who are CQR's main competitors?
Direct peers on record are Trail of Bits, CertiK, Bishop Fox, IOActive, Halborn, Atredis Partners and Hacken. Broad incumbents are Trustwave, Kudelski Security and NCC Group.
Does CQR have an API?
No public API is recorded for CQR.
What industry is CQR in?
CQR's product category is Cybersecurity Services. Its primary akta.pro industry code is FSAPAJAL, Bug Bounty, Vulnerability Disclosure & Security Services. Its NAICS code is 561621 and its SIC code is 7371.