AttackForge
AttackForge is a bootstrapped offensive security management platform serving 500+ organizations across 50+ countries, providing PTaaS delivery, automated reporting, workflow automation, and vulnerability lifecycle management for security consultancies, MSSPs, and enterprise offensive security programs.
- Company typePrivate
- Founded2014
- HeadquartersMelbourne, Australia
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What AttackForge does
AttackForge is an offensive security management platform that centralizes the complete penetration testing lifecycle from planning and execution to reporting and remediation tracking. Founded in 2014 by Fil Filiposki and Stas Filshtinskiy, the company is headquartered in Melbourne, Australia, and serves over 500 organizations across 50+ countries. The platform consists of two main product lines: AttackForge Enterprise for organizations running internal pentest programs, and AttackForge Core (a PTaaS delivery platform) for consultancies and MSSPs. Core functionality includes centralized vulnerability management, automated report generation (ReportGen engine), workflow automation (Flows), and proprietary scripting (AFScript), supported by 150+ REST API endpoints and native integrations with major vulnerability scanners (Nessus, Burp Suite, Qualys, Tenable, Rapid7, Checkmarx, OWASP ZAP, NMAP), ticketing systems (Jira, ServiceNow, Azure DevOps), communication tools (Slack, Teams), and GRC platforms (RSA Archer, MetricStream, OneTrust, LogicGate).
The company operates on a hybrid go-to-market model combining product-led growth (free trial, instant deployment, self-serve purchase of Core tiers priced $50-$800/month) with enterprise field sales (custom pricing, dedicated infrastructure, professional services, SLA-backed support). Revenue is generated through recurring subscription contracts, with the highest-tier SME plan ($800/month) bundling all add-on modules and Enterprise plans offering unlimited users, SSO, white-labelling, and self-hosted deployment options. SOC 2 Type II certification and flexible deployment options (cloud SaaS, self-hosted, air-gapped) address regulated industry requirements. The platform incorporates AI via Model Context Protocol (MCP) integration connecting third-party AI assistants for executive reporting and vulnerability analysis, and recently introduced custom UI workflow automation via Actions in March 2026.
AttackForge is bootstrapped and founder-led with no external venture funding, operating with 1-10 employees. The company has achieved significant enterprise adoption with logos spanning Fortune 500 companies in financial services (PayPal, Lloyds, Rabobank, Danske Bank, Saudi Aramco, GE), healthcare (UnitedHealth Group, IU Health), retail (CVS, Walgreens, Lowe's), telecommunications (T-Mobile, Telstra), and consulting (Accenture, BDO). Notable customer outcomes include 85% reduction in vulnerability SLA breaches for a Fortune 100 bank, 70% faster report delivery, and 94% client retention for a top global consultancy.
AttackForge firmographics
Firmographics- Name
- AttackForge
- Legal name
- AttackForge
- Website
- https://attackforge.com
- Company type
- Private
- Founded year
- 2014
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- AttackForge is a bootstrapped offensive security management platform serving 500+ organizations across 50+ countries, providing PTaaS delivery, automated reporting, workflow automation, and vulnerability lifecycle management for security consultancies, MSSPs, and enterprise offensive security programs.
- Ownership category
- akta.pro rank
AttackForge industry classification
Industry- Product category
- Offensive Security Management Software
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Vulnerability Management & Penetration Testing Services (BPAEADAD)
- akta.pro secondary industries
- Threat Intelligence, Hunting & Adversary Emulation (BPAKAHAE), Vulnerability Intelligence & Exploit Prediction (HDADAHAI), Application Security Engineering (DevSecOps, AppSec Remediation) (BPAEAFAI)
Keywords
Where AttackForge is headquartered
LocationHeadquarters
- HQ city
- Melbourne
- HQ country
- Australia
- HQ region
- Oceania
Offices1 record
Markets served
AttackForge business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Infrastructure, Marketing or Sales, Operations
Revenue model
- Subscription Revenue - Core Plans: AttackForge generates recurring subscription revenue through tiered Core plans (Pro, Team, Consultancy, SME) priced monthly. Each tier offers different team sizes, project limits, and feature access. Core SME plan ($800/month) includes all add-ons as standard. Enterprise tier uses custom pricing based on organizational scale and infrastructure requirements.
- Enterprise Infrastructure & Support: Enterprise deployments include dedicated infrastructure options (self-hosted or Azure regions), professional services for implementation and integration, dedicated customer success management, and SLA-backed support. These are bundled into custom enterprise contracts.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Monthly | Pro - For individual offensive security practitioners |
| Subscription | Monthly | Team - For small pentest teams and startups |
| Subscription | Monthly | Consultancy - For medium-sized pentest teams and boutique consultancies |
| Subscription | Monthly | SME - For large consultancies and growing enterprises |
| Subscription | Multi-year contract | Enterprise - For organizations running internal offensive security programs |
Go-to-market motion2 records
Distribution channels4 records
Marketing channels8 records
AttackForge product offering
Product offeringCore offering
AttackForge is an offensive security management platform that enables organizations and consultancies to plan, execute, report on, and remediate penetration tests in one centralized system. The platform provides automated vulnerability lifecycle management, branded report generation, workflow automation, and program-level analytics, with deployments available as cloud SaaS, on-premises, or air-gapped installations.
Product overview
AttackForge is an offensive security management platform offered in two main product lines: Enterprise for organizations running internal pentesting programs, and Core (PTaaS) for consultancies and security practices. The platform consists of a unified core with several add-on modules including ReportGen for on-demand report generation, Flows for workflow automation, AFScript for custom scripting, Self-Service API (150+ endpoints), Assets Module, AI MCP for AI assistant integration, Portfolios for program-level reporting, and Premium Notifications. Enterprise includes all modules with dedicated infrastructure and SLA-backed support, while Core is available in tiered plans (Pro through SME) with optional add-ons.
Differentiator
Problem solved
Functional benefit
Brands
- AttackForge Core: Platform for consultancies and security practices delivering testing services, featuring PTaaS delivery in under 10 minutes, client portal with real-time testing visibility, and utilization tracking.
- AttackForge Enterprise
Products and services
- AttackForge Enterprise Enterprise-grade offensive security management platform for organizations running internal pentesting programs. Provides full lifecycle management, client-facing portal with custom branding and SSO, AI assistants for dashboards and board reporting, enterprise integrations (Jira, ServiceNow, Azure DevOps, GRC platforms), and deploys on-premises, isolated, or in an Azure region. SOC 2 Type II certified infrastructure.
- AttackForge Core PTaaS (Pentest-as-a-Service) delivery platform for consultancies and security practices. Includes client portal with real-time testing visibility, utilization tracking, team performance analytics, built-in frameworks, methodologies, and vulnerability libraries. Sold in Pro ($50/month), Team ($150/month), Consultancy ($300/month), and SME ($800/month) tiers.
- ReportGen Report generation engine that produces polished, branded reports on demand. Supports CLI, templates, and full customization via DOCX templates with 200+ dynamic data tags for projects, vulnerabilities, assets, and custom fields. Includes conditional logic, charts, graphs, and dynamic tables.
- Flows Workflow Automation Engine Built-in workflow automation engine that connects AttackForge to ticketing systems, security tools, and enterprise platforms. Supports event-triggered, time-triggered, and button-triggered automations with HTTP requests, conditional logic, and bi-directional sync. Includes pre-built templates on GitHub.
- Self-Service API 150+ REST API endpoints with OpenAPI v3 documentation covering projects, vulnerabilities, writeups, assets, test cases, users, groups, and portfolios. Includes Events API for real-time push notifications and client libraries in Node.js, Python, .NET, Java, and Go.
- Assets Module
Quantifiable outcome
- 85% reduction in vulnerability SLA breaches for Fortune 100 bank (40-person team)
- +10 more outcomes
Companies that use AttackForge
Customer profileNamed customers32 records
Segments4 records
Ideal customer profiles3 records
AttackForge technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration25 records
AI capability5 records
Feature7 records
AttackForge partnerships and signals
Strategic signalScale indicators16 records
Recent moves6 records
Expansion highlights5 records
AttackForge competitors and assessment
Company assessmentDirect peers
- Synack: Synack provides a platform-driven PTaaS model combining AI and human testers, targeting enterprise offensive security programs — overlapping with AttackForge Enterprise on Fortune 500 buyer profiles.
- Plextrac: Plextrac is a pentest reporting and management platform aimed at MSSPs and security teams, the closest 1:1 competitor to AttackForge on pentest workflow management, vulnerability tracking, and report generation.
- Cobalt: Cobalt runs a global PTaaS marketplace connecting customers with vetted pentesters through its platform; it competes head-to-head with AttackForge Core in the PTaaS delivery model.
- Pentera: Pentera offers automated security validation and continuous pentesting, addressing a related subset of AttackForge's offensive security testing market from an automation-first angle.
Emerging players
- Cyver: Cyver (formerly Cyberion) is a pentest management platform targeting consultancies and MSSPs, a smaller direct competitor in the same workflow/niche as AttackForge Core.
- HackerOne: HackerOne operates the largest bug bounty and vulnerability disclosure platform. AttackForge consolidates HackerOne-style submissions into its workflow, making it a complementary and partially overlapping peer for offensive security programs.
- Bugcrowd: Bugcrowd runs a crowdsourced security testing platform including bug bounty and PTaaS offerings. It competes in the offensive security services layer and integrates into similar vulnerability management workflows.
Broad incumbents
- Rapid7: Rapid7 provides vulnerability management, SIEM, and offensive security services including penetration testing through InsightConnect/Metasploit — a broad incumbent that overlaps with parts of AttackForge's workflow.
- Tenable: Tenable is a leading vulnerability management platform (Nessus/Tenable.sc) consumed by similar CISOs and offensive security programs; it competes broadly with AttackForge's vulnerability import and lifecycle features.
Others
- Snyk: Snyk focuses on developer security (SAST/SCA) and remediation workflows, adjacent to AttackForge's remediation-tracking module and competing for the same CISO budget lines around application security posture.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks5 records
Key highlights6 records
Customer concentration
AttackForge social profiles
Digital presenceAttackForge compliance and trust
Trust signalCompliance2 records
AttackForge financial estimates
Financial estimateRevenue estimate
Valuation estimate
AttackForge leadership team
Management profileNumber of profiles
Profiles2 records
AttackForge funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
AttackForge M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about AttackForge
What does AttackForge do?
AttackForge is an offensive security management platform that enables organizations and consultancies to plan, execute, report on, and remediate penetration tests in one centralized system. The platform provides automated vulnerability lifecycle management, branded report generation, workflow automation, and program-level analytics, with deployments available as cloud SaaS, on-premises, or air-gapped installations.
Is AttackForge a public or private company?
AttackForge is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was AttackForge founded?
AttackForge was founded in 2014. It employs 1 to 10 people.
Where is AttackForge based?
AttackForge is headquartered in Melbourne, Australia, in the Oceania region.
How does AttackForge make money?
Two revenue lines are on record. Subscription Revenue - Core Plans are the primary driver. The others are enterprise Infrastructure & Support.
Who are AttackForge's main competitors?
Direct peers on record are Synack, Plextrac, Cobalt and Pentera. Emerging players are Cyver, HackerOne and Bugcrowd. Broad incumbents are Rapid7 and Tenable. Snyk is listed as an others.
Does AttackForge have an API?
Yes. AttackForge offers a Self-Service RESTful API with 150+ endpoints covering projects, vulnerabilities, writeups, assets, test cases, users, groups, portfolios, and more. The API is OpenAPI v3 compliant with per-endpoint access control, advanced query filters, and JSON request/response bodies. Events API delivers real-time push notifications for activities like vulnerability creation, project updates, and retest completions. Client libraries available in Node.js, Python, .NET, Java, and Go. Authentication via User API Key (X-SSAPI-KEY header). Developer documentation is at attackforge.com/integrations.
What industry is AttackForge in?
AttackForge's product category is Offensive Security Management Software. Its primary akta.pro industry code is BPAEADAD, Vulnerability Management & Penetration Testing Services, with a secondary code of BPAKAHAE, Threat Intelligence, Hunting & Adversary Emulation. Its NAICS code is 54151 and its SIC code is 7372.