7ASecurity
7ASecurity is a Dublin-based penetration testing and security audit consultancy founded in 2011, delivering manual web, mobile, desktop, AI/LLM, cloud, and code security assessments alongside professional training and certifications for enterprise technology firms, open source foundations, government agencies, and privacy-focused organizations globally.
- Company typePrivate
- Founded2011
- HeadquartersBydgoszcz, Poland
- Headcount11–50
- GTM typeB2B
- OfferingServices
What 7ASecurity does
7ASecurity is a Dublin-headquartered, EU-based penetration testing and security audit consultancy founded by Abraham Aranguren in 2011 and operating under 7ASecurity Ltd. (Ireland, Reg. No. 754736). The firm delivers manual, expert-led security assessments across web applications, mobile and desktop apps, internal and external networks, cloud environments, and source code, plus specialized AI/LLM security testing, incident management, and pre-build security analysis and advice. Its core technology approach emphasizes manual attack techniques, reverse engineering, and code-level review designed to surface vulnerabilities that automated scanners miss, supported by a 100% quality guarantee and free fix verification. The firm also develops and maintains the OWASP OWTF (Offensive Web Testing Framework), an OWASP flagship project.
The business model is professional services-led. Primary revenue comes from project-based penetration testing and code audit engagements with custom, quote-based pricing and multi-year contract cadence. A secondary revenue stream is generated through a training business that includes self-paced online courses (Hacking Modern Web Apps; Hacking Android, iOS and IoT Apps; Hacking JavaScript Desktop Apps) sold via store.7asecurity.com, private instructor-led training, and two proprietary certifications (7CMP, 7CWP). The firm is bootstrapped and founder-owned, with no disclosed outside funding, and is certified to ISO 27001 and SOC 2 with OWASP Platinum Corporate Supporter status.
Customer base spans enterprise technology companies (Google, Microsoft, Twitter/X, Facebook, PayPal, GitHub, eBay, Salesforce), open source foundations (Mozilla, Linux Foundation, OSTIF), government and EU agencies (ENISA), privacy-focused startups (Bridgefy, ArgoVPN, Psiphon), and media/regulated organizations (The Guardian, DHL). Distribution is direct and event-driven, leveraging DEF CON, Black Hat, OWASP Global AppSec, Nullcon, LASCON, and BruCON presence alongside published pentest reports and security research for top-of-funnel demand generation. The firm claims delivery capability across Europe, EMEA, North America, and Asia.
7ASecurity firmographics
Firmographics- Name
- 7ASecurity
- Legal name
- 7ASecurity Ltd.
- Website
- https://7asecurity.com
- Company type
- Private
- Founded year
- 2011
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- 7ASecurity is a Dublin-based penetration testing and security audit consultancy founded in 2011, delivering manual web, mobile, desktop, AI/LLM, cloud, and code security assessments alongside professional training and certifications for enterprise technology firms, open source foundations, government agencies, and privacy-focused organizations globally.
- Ownership category
- akta.pro rank
7ASecurity industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Computer Systems Design and Related Services (54151), Business Schools and Computer and Management Training (6114)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Services-Educational Services (8200)
- akta.pro primary industry
- Cybersecurity Architecture & Security Integration (BPAEAAAL)
- akta.pro secondary industries
- Cybersecurity Training & Awareness Programs (BPAEANAF), Information Technology (IT) & Cybersecurity Certifications (EDAAANAA)
Keywords
Where 7ASecurity is headquartered
LocationHeadquarters
- HQ city
- Bydgoszcz
- HQ country
- Poland
- HQ region
- Europe
Offices1 record
Markets served
7ASecurity business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel
Revenue model
- Penetration Testing Services: Core revenue stream from various penetration testing services including web application, mobile/desktop app, internal, external, AI/LLM, and cloud security testing. Project-based engagements with customized scope.
- Code Audits: Source code review services for web, mobile, and desktop applications. Identifies security vulnerabilities, cryptography implementation flaws, and backdoors at the code level.
- Training and Education: Revenue from self-paced online courses and live/private training sessions covering Android, iOS, Node.js, Electron, secure development, and security awareness topics. Includes certification programs (7CMP, 7CWP).
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom engagement-based pricing |
Go-to-market motion3 records
Distribution channels3 records
Marketing channels8 records
7ASecurity product offering
Product offeringCore offering
7ASecurity is a boutique cybersecurity consultancy that delivers manual penetration testing, code audits, and security assessments across web applications, mobile and desktop apps, cloud infrastructure, AI/LLM systems, and internal/external networks. Its portfolio is complemented by a training division that offers self-paced courses and professional certifications (7CMP, 7CWP) covering mobile and web application security.
Product overview
7ASecurity is a penetration testing and security audit firm offering a portfolio of professional services and training products. Core services include Web Application Penetration Testing, Mobile/Desktop App Penetration Testing, Code Audits, AI & LLM Security Testing, Cloud Audits, Internal/External Penetration Tests, Incident Management, and Security Analysis. The company complements its testing services with a training division offering self-paced and instructor-led courses (Hacking Modern Web Apps, Hacking Android/iOS/IoT Apps, Hacking JavaScript Desktop Apps) and professional certifications (7CMP, 7CWP). Additionally, 7ASecurity developed the open-source OWASP OWTF tool. Founded in 2011 and headquartered in Dublin, Ireland, the company serves clients ranging from small organizations to major technology companies and government agencies.
Differentiator
Problem solved
Functional benefit
Products and services
- Web Application Penetration Test Manual penetration testing service that identifies web security flaws such as SQL injection, XSS, and access control vulnerabilities using controlled attack techniques, frequently finding issues that automated tools miss. Targeted at organizations seeking depth beyond automated scanning.
- Mobile or Desktop App Penetration Test Security testing service for mobile and desktop applications that identifies anti-patterns such as insecure data storage and communication vulnerabilities before attackers can exploit them.
- Code Audit Source code review service that identifies security vulnerabilities, cryptography implementation flaws, and backdoors at the code level, providing greater insight when combined with penetration testing.
- AI & LLM Security Testing Specialized security testing service for AI systems and Large Language Models to identify vulnerabilities specific to AI-powered applications.
- Cloud Audit Cloud security assessment service that identifies vulnerabilities, assesses risks, and ensures cloud environments (including AWS and Kubernetes) are resilient against potential security threats.
- Internal Penetration Test Security testing service that identifies internal network vulnerabilities and helps secure networks from rogue employees and compromised computers.
- External Penetration Test Security testing service that identifies and secures the attack surface an organization exposes to the internet, including servers and data leaked by employees.
- Incident Management Post-breach analysis service that reviews source code and server logs to determine how a website was breached and ensures backdoors have been removed.
- Security Analysis and Advice
Quantifiable outcome
- Found critical vulnerabilities in LeaveHomeSafe COVID tracing app that official audits missed, including face recognition libraries and security flaws
- +2 more outcomes
Companies that use 7ASecurity
Customer profileNamed customers22 records
Segments4 records
Ideal customer profiles4 records
7ASecurity technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature1 record
7ASecurity partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered core and minor.
- Hong Kong Democracy Council (HKDC)coreHKDC coordinated the LeaveHomeSafe security and privacy audit project with 7ASecurity. Provided project coordination, support, and assistance throughout the assignment.
- eLearnSecurityminor7ASecurity developed a unique course for eLearnSecurity called Practical Web Defense (eWDP) focusing on both attacking and defending web applications.
Scale indicators4 records
Recent moves6 records
Expansion highlights6 records
7ASecurity competitors and assessment
Company assessmentDirect peers
- Cure53: Cure53 is a Berlin-based boutique security consultancy offering web, mobile, and browser security testing with public pentest reports. It is the closest comparable firm to 7ASecurity in size, geography (EU), service mix, and thought-leadership-driven GTM.
- Bishop Fox: Bishop Fox is a US-based offensive security consultancy specializing in application, mobile, and network penetration testing with similar manual-testing philosophy. It is larger than 7ASecurity but competes for the same enterprise pentest RFPs.
- Trail of Bits: Trail of Bits is a US-based security research and consulting firm offering application audits, cryptography reviews, and security tooling. It overlaps directly with 7ASecurity's code audit and research-driven positioning, and also publishes substantial open-source security work.
- NetSPI: NetSPI is a penetration testing service provider offering application, network, and cloud pentesting with a platform-enabled delivery model. It is comparable in core service mix but materially larger and more productized than 7ASecurity.
- MDSec: MDSec is a UK-based offensive security consultancy offering web, mobile, and infrastructure penetration testing along with security training courses. It is a direct boutique peer in the same UK/EU corridor as 7ASecurity.
- Pen Test Partners: Pen Test Partners is a UK-based penetration testing firm covering web, mobile, infrastructure, and IoT. It is comparable to 7ASecurity in boutique scale and customer base, and overlaps strongly in IoT and connected-device testing.
- Secarma: Secarma is a UK-based cybersecurity consultancy offering penetration testing, red teaming, and training. It is a comparable boutique competitor serving similar enterprise customers in EMEA.
Broad incumbents
- NCC Group: NCC Group is a global cybersecurity services firm with a large dedicated penetration testing and managed security practice. It is a scaled incumbent competing for enterprise security testing budgets alongside boutique firms like 7ASecurity.
Emerging players
- HackerOne: HackerOne operates a bug bounty and pentest platform connecting customers to a global researcher community. It is not a direct service peer but represents the platform-based alternative that 7ASecurity's manual boutique model competes against for enterprise testing budget.
Others
- PortSwigger (Burp Suite): PortSwigger is the maker of Burp Suite, the dominant web application security testing toolkit. It is adjacent rather than directly competitive, but its training platform (Web Security Academy) competes with 7ASecurity's web security training courses for the same practitioner audience.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights6 records
Customer concentration
7ASecurity social profiles
Digital presence7ASecurity financial estimates
Financial estimateRevenue estimate
Valuation estimate
7ASecurity leadership team
Management profileNumber of profiles
Profiles6 records
7ASecurity funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
7ASecurity M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about 7ASecurity
What does 7ASecurity do?
7ASecurity is a boutique cybersecurity consultancy that delivers manual penetration testing, code audits, and security assessments across web applications, mobile and desktop apps, cloud infrastructure, AI/LLM systems, and internal/external networks. Its portfolio is complemented by a training division that offers self-paced courses and professional certifications (7CMP, 7CWP) covering mobile and web application security.
Is 7ASecurity a public or private company?
7ASecurity is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was 7ASecurity founded?
7ASecurity was founded in 2011. It employs 11 to 50 people.
Where is 7ASecurity based?
7ASecurity is headquartered in Bydgoszcz, Poland, in the Europe region.
How does 7ASecurity make money?
Three revenue lines are on record. Penetration Testing Services are the primary driver. The others are code Audits and training and Education.
Who are 7ASecurity's main competitors?
Direct peers on record are Cure53, Bishop Fox, Trail of Bits, NetSPI, MDSec, Pen Test Partners and Secarma. NCC Group is listed as a broad incumbent. HackerOne is listed as an emerging player. PortSwigger (Burp Suite) is listed as an others.
Does 7ASecurity have an API?
No public API is recorded for 7ASecurity.
What industry is 7ASecurity in?
7ASecurity's product category is Cybersecurity Services. Its primary akta.pro industry code is BPAEAAAL, Cybersecurity Architecture & Security Integration, with a secondary code of BPAEANAF, Cybersecurity Training & Awareness Programs. Its NAICS code is 54151 and its SIC code is 7370.