Code White
Code White GmbH is a German offensive cybersecurity boutique founded in 2014 that provides Red Team Assessments and continuous Attack Surface Management to enterprise clients worldwide from offices in Ulm and Mannheim.
- Company typePrivate
- Founded2014
- HeadquartersUlm, Germany
- Headcount51–100
- GTM typeB2B
- OfferingServices
What Code White does
Code White GmbH is a privately held German offensive cybersecurity boutique headquartered in Ulm with a secondary office in Mannheim. Founded in 2014, the firm employs between 51 and 100 permanent internal staff — not contractors — and serves enterprise clients worldwide with two core services: the Initial Assessment (INI), a holistic Red Team engagement simulating a real-world cyber attack across the client's full internet footprint; and the Security Intelligence Service (SIS), a continuous partnership combining External Attack Surface Management with Proactive Threat Intelligence. INI engagements are explicitly designed to convert into long-term SIS partnerships, embedding Code White's specialists as a sustained offensive capability within the client.
The firm's competitive basis is human expertise: the team reports 388+ years of combined hands-on experience and holds elite offensive security certifications (OSCP, CRTO, OSCE, OSWE, OSEE). Code White also publishes original vulnerability research through a public vulnerability list and a technical blog, with disclosed CVEs and 0-day findings across products including NetSupport Manager, WSUS, Ivanti DSM, MailEnable, SmarterMail, and ABL90 FLEX PLUS, and releases supporting tools on GitHub. Thought-leadership content distributed across Mastodon, LinkedIn, X, Bluesky, and RSS functions as the primary go-to-market mechanism in lieu of named customer logos or disclosed pricing.
Revenue is generated through a mix of project-based professional services (INI) and recurring subscription engagements (SIS), with the SIS layer explicitly positioned to convert one-time red-team assessments into long-duration retainers. The company is privately held with no disclosed venture or private equity backing; ownership appears to be founder/management-led, with David Elze serving as CEO. Markets served are described as global, anchored in the DACH region. There is no public disclosure of revenue, funding history, customer concentration, or pricing.
Code White firmographics
Firmographics- Name
- Code White
- Legal name
- CODE WHITE GmbH
- Website
- https://code-white.com
- Company type
- Private
- Founded year
- 2014
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- Code White GmbH is a German offensive cybersecurity boutique founded in 2014 that provides Red Team Assessments and continuous Attack Surface Management to enterprise clients worldwide from offices in Ulm and Mannheim.
- Ownership category
- akta.pro rank
Code White industry classification
Industry- Product category
- Offensive Cybersecurity Services
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Penetration Testing & Red Teaming (BPAKADAE)
- akta.pro secondary industry
- Attack Surface Management (EASM/CAASM) (HDADAHAC)
Keywords
Where Code White is headquartered
LocationHeadquarters
- HQ city
- Ulm
- HQ country
- Germany
- HQ region
- Europe
Offices2 records
Markets served
Code White business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure, Others
Revenue model
- Red Team Assessment Services: Professional services revenue from Initial Assessment (INI) engagements that simulate real cyber attacks to evaluate client security posture and resilience
- Security Intelligence Service (SIS): Ongoing continuous support partnerships providing external attack surface management, proactive threat intelligence, and extended security services including penetration tests, product security reviews, and customized training
Go-to-market motion1 record
Distribution channels1 record
Marketing channels5 records
Code White product offering
Product offeringCore offering
CODE WHITE is an offensive cybersecurity boutique that delivers the Initial Assessment (INI), a holistic Red Team engagement simulating real-world cyber attacks across an enterprise's full internet footprint, and the Security Intelligence Service (SIS), a continuous partnership combining External Attack Surface Management with Proactive Threat Intelligence. Engagements are performed by permanent, in-house Red Team experts holding elite offensive security certifications, and are scoped to enterprise clients worldwide.
Product overview
Code White is an offensive cybersecurity boutique (not a product company) offering two primary services: the Initial Assessment (INI) for holistic Red Team assessments simulating real cyber attacks, and the Security Intelligence Service (SIS) for continuous Attack Surface Management. These services are delivered by technically outstanding, certified Red Team experts who combine offensive security skills with threat intelligence capabilities. The company also publishes its vulnerability research through a Public Vulnerability List and Technical Blog, demonstrating expertise in areas such as deserialization vulnerabilities, authentication bypasses, and remote code execution.
Differentiator
Problem solved
Functional benefit
Products and services
- Initial Assessment (INI) Holistic Red Team engagement that simulates a real cyber attack against an enterprise's complete internet footprint, including phishing, lateral movement, persistence, and data exfiltration, and delivers extensive attack documentation with strategic recommendations to improve resilience against real threat actors.
- Security Intelligence Service (SIS) Continuous Preemptive Exposure Management service for enterprise clients, providing ongoing attack surface surveillance, actionable vulnerability notifications, threat intelligence, and access to specialized services such as Red Team assessments, threat intelligence, penetration tests, product security reviews, and customized training for the duration of the partnership.
Quantifiable outcome
- Clients gain transparency about current enterprise vulnerability levels through holistic red team assessments
- +1 more outcomes
Companies that use Code White
Customer profileNamed customers2 records
Segments2 records
Ideal customer profiles1 record
Code White technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature5 records
Code White partnerships and signals
Strategic signalScale indicators3 records
Recent moves5 records
Expansion highlights5 records
Code White competitors and assessment
Company assessmentDirect peers
- NCC Group: UK-based publicly listed cybersecurity firm offering Red Team assessments, penetration testing, and attack surface management to enterprise clients globally. Most directly comparable in service portfolio and boutique-to-mid-market positioning, with broader geographic scale.
- MDSec: UK-based offensive security research firm offering Red Team engagements, penetration testing, and tool development (e.g., Nighthawk C2). Comparable as a boutique research-led offensive security firm with deep CVE discovery and elite consultant base.
- Bishop Fox: US-based offensive security boutique specializing in Red Team operations, penetration testing, and attack surface management for large enterprises. Closely aligned with Code White on talent-led boutique model and research-driven thought leadership.
- SRLabs: Berlin-based offensive security boutique (acquired by Bosch in 2022) specializing in Red Team, penetration testing, and security research for enterprise and industrial clients. Most direct German/European peer in boutique positioning and research-led offensive services.
- TrustedSec: US-based offensive security consultancy delivering Red Team assessments, penetration testing, and incident response to enterprise clients. Comparable boutique, research-led model with strong community brand (e.g., TrustedSec community editions).
Broad incumbents
- Mandiant (Google Cloud): Global leader in incident response, threat intelligence, and Red Team/Adversary Simulation services, now part of Google Cloud. Competes with Code White for large enterprise red team mandates but operates as a much broader portfolio incumbent.
- Orange Cyberdefense: European cybersecurity services arm of Orange, providing penetration testing, Red Team, and managed detection & response across multiple geographies. Comparable on European enterprise offensive security, but at much larger scale and broader portfolio.
- CrowdStrike Services: CrowdStrike's professional services arm delivers Red Team operations, adversary emulation, and penetration testing as part of its broader endpoint and XDR platform. Overlaps Code White on offensive services but bundles them into a wider platform offering.
- Coalfire: US-based cybersecurity advisory firm offering Red Team, penetration testing, and attack surface management alongside broader compliance and advisory services. Comparable offensive security offerings within a wider consulting portfolio.
- WithSecure (formerly F-Secure): Nordic-headquartered cybersecurity firm with a dedicated offensive security and Red Team services arm serving European enterprises. Comparable on European enterprise offensive security positioning, with broader product portfolio.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights6 records
Customer concentration
Code White social profiles
Digital presenceCode White financial estimates
Financial estimateRevenue estimate
Valuation estimate
Code White leadership team
Management profileNumber of profiles
Profiles2 records
Code White funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Code White M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Code White
What does Code White do?
CODE WHITE is an offensive cybersecurity boutique that delivers the Initial Assessment (INI), a holistic Red Team engagement simulating real-world cyber attacks across an enterprise's full internet footprint, and the Security Intelligence Service (SIS), a continuous partnership combining External Attack Surface Management with Proactive Threat Intelligence. Engagements are performed by permanent, in-house Red Team experts holding elite offensive security certifications, and are scoped to enterprise clients worldwide.
Is Code White a public or private company?
Code White is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Code White founded?
Code White was founded in 2014. It employs 51 to 100 people.
Where is Code White based?
Code White is headquartered in Ulm, Germany, in the Europe region.
How does Code White make money?
Two revenue lines are on record. Red Team Assessment Services are the primary driver. The others are security Intelligence Service (SIS).
Who are Code White's main competitors?
Direct peers on record are NCC Group, MDSec, Bishop Fox, SRLabs and TrustedSec. Broad incumbents are Mandiant (Google Cloud), Orange Cyberdefense, CrowdStrike Services, Coalfire and WithSecure (formerly F-Secure).
Does Code White have an API?
No public API is recorded for Code White.
What industry is Code White in?
Code White's product category is Offensive Cybersecurity Services. Its primary akta.pro industry code is BPAKADAE, Penetration Testing & Red Teaming, with a secondary code of HDADAHAC, Attack Surface Management (EASM/CAASM). Its SIC code is 7370.