Scip
scip AG is a Zurich-based, self-financed cybersecurity boutique founded in 2002, providing offensive (Red Team), defensive (Blue Team), and research (Titanium Team) professional services to enterprise clients, plus coordinated vulnerability disclosure to major technology vendors.
- Company typePrivate
- Founded2002
- HeadquartersZürich, Switzerland
- Headcount1–10
- GTM typeB2B
- OfferingServices
What Scip does
scip AG is a Zurich-based cybersecurity professional services firm founded in 2002 and operating as a self-financed, vendor-independent boutique. The company organizes its capabilities into three specialist divisions: the Red Team (offensive security testing including red team, purple team, attack simulation, and penetration testing engagements), the Blue Team (defensive services including detection engineering, SOC validation, and security monitoring assistance), and the Titanium Team (security research and vulnerability discovery). Engagements are customized, project-based assessments ranging from 5-day Baseline Security Assessments to 60-day Red Team Assessments, delivered by a small senior team of 1–10 employees. Beyond paid assessments, the firm runs a coordinated vulnerability disclosure program, acts as a CVE Numbering Authority via VulDB, and operates a bug bounty program with Hall of Fame recognition.
The firm builds and maintains proprietary internal tooling to support its service delivery. This includes an in-house Gitea-based CI/CD pipeline for automating malware obfuscation across C#/.NET and PowerShell payloads with validation against AV/EDR solutions, an in-house Secure Transfer Server hosted on Zurich servers for encrypted file exchange with clients, and HeaderMate, an open-source Burp Suite extension. Thought leadership is delivered through a long-running Labs blog archive (2003–2026), the free monthly scip Security Summary (smSS) magazine in German, and a Blog Digest published bilingually.
Revenue is generated entirely through professional services: security assessments, red/blue/purple team engagements, vulnerability disclosure coordination with vendors such as Microsoft, Apple, Cisco, IBM, Oracle, and Mozilla, and paid media/expert services to outlets including ZDF, WDR, RTL, Schweizer Fernsehen, NZZ, and Tages-Anzeiger. Pricing is not publicly disclosed and varies by scope and complexity. Distribution is fully direct — clients engage via website inquiry, email, or phone — with no intermediaries or self-service purchasing. The company is privately held, founder-owned, and has never taken external capital.
Scip firmographics
Firmographics- Name
- Scip
- Legal name
- scip AG
- Website
- https://scip.ch
- Company type
- Private
- Founded year
- 2002
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- scip AG is a Zurich-based, self-financed cybersecurity boutique founded in 2002, providing offensive (Red Team), defensive (Blue Team), and research (Titanium Team) professional services to enterprise clients, plus coordinated vulnerability disclosure to major technology vendors.
- Ownership category
- akta.pro rank
Scip industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Other Computer Related Services (541519), Other Scientific and Technical Consulting Services (54169), Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Threat Intelligence Services (BPAEADAC)
- akta.pro secondary industries
- Enterprise Security Strategy & Program Advisory (BPAKADAA), Penetration Testing, Red Team & Ethical Hacking (EDAOAIAH)
Keywords
Where Scip is headquartered
LocationHeadquarters
- HQ city
- Zürich
- HQ country
- Switzerland
- HQ region
- Europe
Offices1 record
Markets served
Scip business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales
Revenue model
- Security Assessments and Testing: Professional services including penetration testing, security reviews, baseline security assessments, attack simulations, red team assessments, and purple team assessments. Pricing varies by scope, duration (5-60 days depending on assessment type), and complexity.
- Offensive Security Services: Red team engagements simulating real-world attacks to test organization's security posture. Includes use of open-source tools, custom developments, and identification of attack paths.
- Defensive Security Services: Blue team services including detection engineering, SOC validation, and security monitoring assistance.
- Vulnerability Disclosure Services: Coordinated vulnerability disclosure services where scip identifies vulnerabilities, contacts vendors, establishes 90-day deadlines, and discloses issues to defensive community. May include additional technical verification requiring monetary compensation negotiated beforehand.
- Research and Publications: Cybersecurity research, articles, and the monthly Security Summary (smSS) magazine. Some research outputs lead to publications in academic venues like Cambridge University Press.
- Media and Expert Services: Professional information exchange, recordings, interviews, and studio/live appearances with journalists from TV, radio, magazines, and newspapers. Expert commentary on cybersecurity incidents and trends.
Go-to-market motion1 record
Distribution channels1 record
Marketing channels9 records
Scip product offering
Product offeringCore offering
scip AG provides cybersecurity professional services through three divisions: Red Team (offensive security testing, attack simulations, red/purple team assessments), Blue Team (defensive security, detection engineering, SOC validation), and Titanium Team (security research, vulnerability discovery). Additional offerings include coordinated vulnerability disclosure services, the monthly scip Security Summary (smSS) magazine, and open-source security tooling.
Product overview
Scip AG is a cybersecurity services company offering a portfolio of specialized security services organized into three main divisions: Red Team (offensive security testing), Blue Team (defensive security and monitoring), and Titanium Team (security research). The company provides structured security assessments including Red Team Assessments, Purple Team Assessments, Attack Simulations, and Baseline Security Assessments. Supporting products include the Secure Transfer Server for encrypted file exchange, the monthly Security Summary magazine (smSS), a Bug Bounty Program, Vulnerability Disclosure Service, and open-source tooling such as HeaderMate for Burp Suite. The company publishes extensive research through its Labs blog covering topics like malware obfuscation pipelines, C2 architecture, and AI applications in security.
Differentiator
Problem solved
Functional benefit
Products and services
- Red Team (Offense Services) Offensive security services simulating attacker techniques to identify vulnerabilities and weaknesses in client infrastructure. Includes Red Team Assessments, Attack Simulations, and malware obfuscation capabilities. Targeted at enterprise clients seeking to validate their security posture against real-world threats.
- Blue Team (Defense Services) Defensive security services focused on detection capabilities, monitoring, incident response, and improving organizational security posture. Includes Purple Team Assessments for collaborative testing between offense and defense. Targeted at organizations seeking to strengthen their security monitoring and response capabilities.
- Titanium Team (Research) Research division conducting security research, vulnerability discovery, and publishing findings. Responsible for identifying new vulnerabilities and weaknesses in customer projects and vendor products. Targeted at organizations requiring deep security research and vulnerability discovery expertise.
- Vulnerability Disclosure Service
Quantifiable outcome
- Organizations have demonstrably increased resilience against targeted and sophisticated cyberattacks through red and purple team projects
- +1 more outcomes
Companies that use Scip
Customer profileSegments4 records
Ideal customer profiles2 records
Scip technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
Scip partnerships and signals
Strategic signalPartnerships
Nine partnerships are on record, tiered minor and core.
- MicrosoftminorCoordinated vulnerability disclosure partner. scip AG has worked with Microsoft to analyze, mitigate, and disclose security vulnerabilities following responsible disclosure practices with 90-day deadlines.
- AppleminorCoordinated vulnerability disclosure partner. scip AG has worked with Apple to analyze, mitigate, and disclose security vulnerabilities following responsible disclosure practices.
- CiscominorCoordinated vulnerability disclosure partner. scip AG has worked with Cisco on vulnerability disclosure for networking and security products.
- MozillaminorCoordinated vulnerability disclosure partner for Firefox and related products.
- Facebook (Meta)minorCoordinated vulnerability disclosure partner for social media and related platforms.
- DropboxminorCoordinated vulnerability disclosure partner for cloud storage services.
- GE HealthcareminorCoordinated vulnerability disclosure partner in healthcare technology sector.
- VulDBcorePrimary vulnerability database partner. scip AG participates as CNA (CVE Numbering Authority), uses VulDB for bug bounty rewards, and publishes advisories through the platform. Security.txt references VulDB for coordinated disclosure.
- ENISAminorFollows ENISA Coordinated Vulnerability Disclosure Policies established in the EU as part of industry best practices.
Scale indicators4 records
Recent moves6 records
Expansion highlights5 records
Scip competitors and assessment
Company assessmentMarket position
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
Scip social profiles
Digital presenceScip compliance and trust
Trust signalCompliance2 records
Scip financial estimates
Financial estimateRevenue estimate
Valuation estimate
Scip leadership team
Management profileNumber of profiles
Profiles1 record
Scip funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Scip M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Scip
What does Scip do?
scip AG provides cybersecurity professional services through three divisions: Red Team (offensive security testing, attack simulations, red/purple team assessments), Blue Team (defensive security, detection engineering, SOC validation), and Titanium Team (security research, vulnerability discovery). Additional offerings include coordinated vulnerability disclosure services, the monthly scip Security Summary (smSS) magazine, and open-source security tooling.
Is Scip a public or private company?
Scip is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Scip founded?
Scip was founded in 2002. It employs 1 to 10 people.
Where is Scip based?
Scip is headquartered in Zürich, Switzerland, in the Europe region.
How does Scip make money?
Six revenue lines are on record. Security Assessments and Testing is the primary driver. The others are offensive Security Services, defensive Security Services, vulnerability Disclosure Services, research and Publications and media and Expert Services.
Does Scip have an API?
No public API is recorded for Scip.
What industry is Scip in?
Scip's product category is Cybersecurity Services. Its primary akta.pro industry code is BPAEADAC, Threat Intelligence Services, with a secondary code of BPAKADAA, Enterprise Security Strategy & Program Advisory. Its NAICS code is 541519 and its SIC code is 7370.