X41 D-Sec
X41 D-Sec is a boutique application security firm founded in 2015 in Aachen, Germany, providing penetration testing, source code audits, red teaming, fuzzing, and custom security research to enterprise and institutional clients across software, government, healthcare, and VPN sectors.
- Company typePrivate
- Founded2015
- HeadquartersAachen, Germany
- Headcount1–10
- GTM typeB2B
- OfferingServices
What X41 D-Sec does
X41 D-Sec GmbH is a boutique application security firm headquartered in Aachen, Germany (Soerser Weg 20, 52070 Aachen; HRB19989), founded in 2015 by Markus Vervier, who continues to serve as Managing Director. The company delivers specialized security research and application security services to enterprise and institutional clients across software, financial, government, healthcare, robotics, and VPN verticals. Named customers include Aspera, Avira, GSI (Gesellschaft für Schwerionenforschung), Klinikum Darmstadt, Mullvad VPN, Malwarebytes, SoftBank Robotics, and SecureDrop/Freedom of the Press Foundation. The firm operates with a deliberately flat, small team (1-10 employees) and is privately held with no disclosed institutional funding.
The company's service portfolio spans six core professional offerings — penetration testing, AppSec/source code audits, red teaming, purple teaming, fuzzing, and custom security research — delivered as per-project engagements, either remotely or on-site, with detailed CVSS- and CWE-scored reports and direct developer briefings. Underlying technical assets include a proprietary custom fuzzing framework used in smartcard driver and YARA-classifier research, and internally developed research tools such as BeanStack (a Java stacktrace fingerprinting database released publicly) and AnyZone (a delegated DNS testing tool). GTM is sales-led and enterprise-direct: prospective clients initiate engagement via [email protected] or the website contact form, and a significant share of demand is channeled through a strategic partnership with the Open Source Technology Improvement Fund (OSTIF), which has commissioned audits of CRI-O, Ruby on Rails, nghttp3/ngtcp2, RSTUF, Hickory DNS, libjpeg-turbo, Go TUF, in-toto, c-ares, libcap, simplejson, Envoy, Git, TUF, BIND9, and others.
X41 monetizes exclusively through professional services on a per-engagement basis; no productized SaaS or platform revenue exists and pricing is not publicly disclosed. Demand generation is content-led via the firm's public research blog, lab advisories, downloadable public audit reports, conference presentations at DEF CON/CCC/TROOPERS/Hack.lu/Pass The Salt, and active social presence on GitHub, Twitter/X, LinkedIn, and Mastodon. The firm has accumulated a substantial reputational track record through high-impact vulnerability disclosures, including CVE-2016-2851 in libotr, Signal Private Messenger vulnerabilities (2016), Wire Secure Messenger vulnerabilities (2018), Microsoft Exchange CVE-2020-16875 (2020), YARA integer overflow and buffer overflow findings (2021), Chilkat PRNG CVE-2024-26329 (2024), a CVSS 8.7 LiteLLM sandbox escape (April 2026), and CVE-2026-48710 in the Starlette ASGI framework affecting an estimated 400,000+ dependent projects (May 2026). The company has also authored notable research artifacts such as the Browser Security White Paper commissioned by Google.
X41 D-Sec firmographics
Firmographics- Name
- X41 D-Sec
- Legal name
- X41 D-Sec GmbH
- Website
- https://x41-dsec.de
- Company type
- Private
- Founded year
- 2015
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- X41 D-Sec is a boutique application security firm founded in 2015 in Aachen, Germany, providing penetration testing, source code audits, red teaming, fuzzing, and custom security research to enterprise and institutional clients across software, government, healthcare, and VPN sectors.
- Ownership category
- akta.pro rank
X41 D-Sec industry classification
Industry- Product category
- Application Security Services
- NAICS
- Computer Systems Design and Related Services (54151), Other Computer Related Services (541519)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Penetration Testing, Red Team & Ethical Hacking (EDAOAIAH)
- akta.pro secondary industries
- Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX) (BPAKADAC), Application Security & Secure Software (DevSecOps) (EDAOAIAK)
Keywords
Where X41 D-Sec is headquartered
LocationHeadquarters
- HQ city
- Aachen
- HQ country
- Germany
- HQ region
- Europe
Offices1 record
Markets served
X41 D-Sec business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Penetration Testing: Security penetration testing services against networks, services, and systems. Includes black-box, grey-box, and white-box testing approaches. Deliverables include detailed reports with CVSS scores, CWE classifications, and remediation advice.
- Source Code Audits: Security-focused code reviews conducted on source code with threat modeling and developer briefings. Includes static and dynamic analysis, fuzzing, and CVSS/CWE reporting.
- Red Teaming: Goal-oriented security assessments including technical hacking, phishing, and physical security testing over extended periods, limited by legal bounds.
- Purple Teaming Exercises: Collaborative practical exercises where red and blue teams work together. Includes tabletop exercises and real attack simulations in controlled environments.
- Fuzzing Services: Automated dynamic analysis for flaw-finding, continuous security testing, and custom analysis implementations for infrastructure, software, and hardware components.
- Security Research: Custom security research and analysis of attack surface and technical mitigations. Includes published whitepapers such as Browser Security White Paper for Google.
Go-to-market motion2 records
Distribution channels3 records
Marketing channels7 records
X41 D-Sec product offering
Product offeringCore offering
X41 D-Sec is a boutique application security firm that delivers professional security services including penetration testing, source code audits, red teaming, purple teaming, fuzzing, and custom security research. Engagements scope vulnerabilities in software and infrastructure, produce detailed CVSS/CWE-classified reports with remediation advice, and include threat modeling workshops and coordinated vulnerability disclosure. The firm also publishes public audit reports for transparency and develops internal research tools such as the BeanStack Java stacktrace fingerprinting database and AnyZone DNS testing utility.
Product overview
X41 D-Sec is a security auditing and research firm offering a portfolio of professional services rather than a unified software product. Core offerings include AppSec/Code Audits, Red Teaming, Penetration Testing, Fuzzing, Purple Teaming, and Security Research services. Additionally, the company develops internal research tools such as BeanStack (Java fingerprinting database) and AnyZone (DNS testing tool). The company also maintains a public advisories lab documenting discovered vulnerabilities.
Differentiator
Problem solved
Functional benefit
Products and services
- AppSec / Code Audits Security source code audits that identify weaknesses in software products through design workshops, threat modeling, and manual code review, using a blend of automated and manual methods with CVSS and CWE reporting.
- Penetration Testing Manual penetration testing of network-connected systems that mimics real attacks using white-box, grey-box, or black-box approaches, delivered remotely or on-site with detailed CVSS and CWE-scored reports and remediation guidance.
- Red Teaming Goal-based security testing performed over longer periods with open scope, including technical hacking, phishing, and physical security components to achieve defined objectives.
- Purple Teaming Collaborative exercises combining Red and Blue team activities, including tabletop exercises and practical attack simulations conducted together with client staff in controlled environments.
- Fuzzing Automated dynamic analysis for flaw-finding, regression testing, and custom static/dynamic analysis implementations applied to infrastructure, software, and hardware components.
- Security Research Custom security research and analysis of attack surface and technical mitigations, including commissioned whitepapers such as the Browser Security White Paper produced for Google.
- BeanStack Java stacktrace fingerprinting service and database that extracts version information from Java stack traces for security analysis.
- AnyZone Tool providing delegated DNS zones for testing purposes without requiring manual zone file management.
Quantifiable outcome
- Found no vulnerabilities in CRI-O runtime audit - only informational findings about outdated dependencies
- +3 more outcomes
Companies that use X41 D-Sec
Customer profileNamed customers8 records
Segments4 records
Ideal customer profiles3 records
X41 D-Sec technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
X41 D-Sec partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- Open Source Technology Improvement Fund (OSTIF)coreOSTIF is a non-profit organization that sponsors security audits of critical open source projects. X41 has conducted multiple audits for OSTIF including CRI-O, Ruby on Rails, nghttp3/ngtcp2, RSTUF, Hickory DNS, libjpeg-turbo, Go TUF, in-toto, c-ares, libcap, simplejson, and Envoy fuzzing improvements.
Scale indicators3 records
Recent moves6 records
Expansion highlights5 records
X41 D-Sec competitors and assessment
Company assessmentDirect peers
- Cure53: Berlin-based boutique application security firm offering penetration tests, code audits, and security research. Direct peer to X41 with comparable boutique size, public audit reports, and AppSec focus.
- Trail of Bits: New York-based boutique security research and consulting firm offering application security audits, cryptography review, and vulnerability research, with a similar high-profile CVE publication profile.
- ERNW Research: Heidelberg-based independent security research firm offering penetration testing, code reviews, and security consulting; comparable boutique German competitor with overlapping public research output.
- Quarkslab: Paris-based security research and consulting firm specializing in binary analysis, reverse engineering, and application security audits; a closely comparable boutique peer in Europe.
- Recurity Labs: Berlin-based boutique security firm focused on vulnerability research, code auditing, and reverse engineering, with similar public CVEs and a comparable target market.
- Bishop Fox: US-based boutique offensive security firm offering penetration testing, red teaming, and application security services; comparable service mix and premium positioning.
- Insinuator: German independent security researcher and consultancy performing source code audits, penetration tests, and vulnerability research; very small peer operating in X41's geographic and product segment.
- n.runs AG: German boutique IT security firm offering application security, reverse engineering, and penetration testing with similar service catalog and customer overlap.
Broad incumbents
- NCC Group: Large UK-listed security consultancy offering application security, penetration testing, and red teaming at global scale; not boutique but the dominant incumbent in the same services categories.
- SEC Consult: European cybersecurity consultancy offering penetration testing, code review, and managed security services; larger incumbent serving enterprise clients in DACH and across Europe.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat3 records
Key risks6 records
Key highlights7 records
Customer concentration
X41 D-Sec social profiles
Digital presenceX41 D-Sec financial estimates
Financial estimateRevenue estimate
Valuation estimate
X41 D-Sec leadership team
Management profileNumber of profiles
Profiles1 record
X41 D-Sec funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
X41 D-Sec M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about X41 D-Sec
What does X41 D-Sec do?
X41 D-Sec is a boutique application security firm that delivers professional security services including penetration testing, source code audits, red teaming, purple teaming, fuzzing, and custom security research. Engagements scope vulnerabilities in software and infrastructure, produce detailed CVSS/CWE-classified reports with remediation advice, and include threat modeling workshops and coordinated vulnerability disclosure. The firm also publishes public audit reports for transparency and develops internal research tools such as the BeanStack Java stacktrace fingerprinting database and AnyZone DNS testing utility.
Is X41 D-Sec a public or private company?
X41 D-Sec is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was X41 D-Sec founded?
X41 D-Sec was founded in 2015. It employs 1 to 10 people.
Where is X41 D-Sec based?
X41 D-Sec is headquartered in Aachen, Germany, in the Europe region.
How does X41 D-Sec make money?
Six revenue lines are on record. Penetration Testing is the primary driver. The others are source Code Audits, red Teaming, purple Teaming Exercises, fuzzing Services and security Research.
Who are X41 D-Sec's main competitors?
Direct peers on record are Cure53, Trail of Bits, ERNW Research, Quarkslab, Recurity Labs, Bishop Fox, Insinuator and n.runs AG. Broad incumbents are NCC Group and SEC Consult.
Does X41 D-Sec have an API?
No public API is recorded for X41 D-Sec.
What industry is X41 D-Sec in?
X41 D-Sec's product category is Application Security Services. Its primary akta.pro industry code is EDAOAIAH, Penetration Testing, Red Team & Ethical Hacking, with a secondary code of BPAKADAC, Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX). Its NAICS code is 54151 and its SIC code is 7370.