modzero
modzero is a Swiss-German independent cybersecurity consultancy delivering bespoke application, cloud, and red team pentesting, hardware/software reviews, and design advisory for enterprise clients, backed by a published vulnerability research program.
- Company typePrivate
- Founded2011
- HeadquartersWinterthur, Switzerland
- Headcount1–10
- GTM typeB2B
- OfferingServices
What modzero does
modzero is an independent, boutique cybersecurity consultancy that delivers in-depth, bespoke technical security assessments of concepts, software, and hardware components. Founded in Switzerland in early 2011 by Max Moser and Thorsten Schröder, the firm operates across two legal entities — modzero AG (Winterthur, Canton of Zurich) and modzero GmbH (Berlin) — serving enterprise clients primarily in the DACH region but with documented global delivery capability. The service portfolio spans application pentesting, cloud pentesting, red teaming, hardware/software review, and design & concept advisory, with every engagement scoped as custom consulting work rather than a packaged or productized offering. The client base is horizontal by sector: organizations of varying industries that need realistic, attack-path-driven analysis of complex information systems rather than compliance-driven checkbox work.
Underpinning these services is technical depth signaled through a long-running security research program. modzero researchers publish detailed technical write-ups on offensive security topics — ARM exploitation with ROP chains, ASLR bypass without information leakage, IoT firmware reverse engineering, Spring Boot Server-Side Template Injection, .NET BinaryFormatter deserialization, AFL++-based fuzzing, and embedded systems analysis — and operate a coordinated vulnerability disclosure process that has produced public advisories against major vendors including Cisco, Netgear, TeamSpeak, Synology, INSTAR, Poly, Trend Micro, MailCleaner, and Passwordstate since 2019. Proprietary internal tooling (e.g., NetGadget for scanning .dll/.exe binaries for BinaryFormatter deserialization gadgets) accompanies the firm's consulting practice and is openly referenced on GitHub alongside proof-of-concept exploits. This research output is not ancillary marketing but a core component of how the firm demonstrates expertise and qualifies clients.
modzero's revenue model is professional services on a bespoke, per-engagement basis: pricing is quote-based and negotiated, with no public rate card, no standardized service tiers, and no self-serve channel. Go-to-market is direct enterprise sales conducted by the firm's founders and senior practitioners, with no resellers, partner channels, marketplace presence, or OEM relationships. Distribution runs through the firm's website and a content-led research strategy — blog, public advisories, GitHub repositories — that operates as the top-of-funnel qualifier rather than paid marketing. Headcount is small (1–10 employees), no external institutional investment has been identified, and both co-founders continue as CEOs of both legal entities. The firm describes itself as non-corporate and independent, indicating an owner-operated operating posture rather than a growth-stage or venture-backed trajectory.
modzero firmographics
Firmographics- Name
- modzero
- Legal name
- modzero AG / modzero GmbH
- Website
- https://modzero.com
- Company type
- Private
- Founded year
- 2011
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- modzero is a Swiss-German independent cybersecurity consultancy delivering bespoke application, cloud, and red team pentesting, hardware/software reviews, and design advisory for enterprise clients, backed by a published vulnerability research program.
- Ownership category
- akta.pro rank
Where modzero is headquartered
LocationHeadquarters
- HQ city
- Winterthur
- HQ country
- Switzerland
- HQ region
- Europe
Offices2 records
Markets served
modzero business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Security Consulting and Assessment Services: modzero generates revenue through bespoke professional security consulting engagements. Services include application pentesting, cloud pentesting, red teaming, hardware/software review, and design & concept advisory. As a non-corporate, independent consultancy, they tailor services to each client's specific requirements rather than selling standardized packages. Engagements span the entire project lifecycle from scoping and technical preparation through reporting and presenting findings to clients.
Go-to-market motion1 record
Distribution channels1 record
Marketing channels4 records
modzero product offering
Product offeringCore offering
modzero provides individually customized, detailed, and transparent security analyses of concepts, software, and hardware components as a service. Its core offerings include Application Pentesting, Cloud Pentesting, Red Teaming, Hardware/Software Review, and Design & Concept Advisory, delivered as bespoke consulting engagements from offices in Winterthur (Switzerland) and Berlin (Germany) to enterprise clients across Europe. The firm combines offensive security testing, vulnerability research, and hardware/software reverse engineering with published security advisories demonstrating real-world discoveries.
Product overview
modzero is an independent, privately held cybersecurity company offering specialized technical security assessment services rather than a software product portfolio. Their service offerings include Application Pentesting, Cloud Pentesting, Red Teaming, Hardware/Software Review, and Design & Concept Advisory. The company operates from Switzerland and Germany, focusing on deep technical security analyses across complex information systems. They also publish security research and advisories on vulnerabilities discovered in third-party products.
Differentiator
Problem solved
Functional benefit
Products and services
- Application Pentesting Security assessment of web applications, APIs, and software to identify vulnerabilities and misconfigurations through manual and automated testing techniques, targeted at enterprise clients with complex application stacks.
- Cloud Pentesting Security evaluation of cloud environments including AWS, Azure, and GCP infrastructures to assess configurations, access controls, and potential attack vectors for enterprise clients operating cloud workloads.
- Red Teaming Adversarial simulation exercises that emulate real-world attack scenarios across web, cloud, AI, and Active Directory environments to test organizational security defenses and identify realistic attack paths for enterprise clients.
- Hardware/Software Review In-depth technical analysis of hardware components and embedded software systems to identify security vulnerabilities and assess overall security posture, targeted at organizations with embedded or IoT products.
- Design & Concept Advisory Security consulting during design and development phases to minimize subsequent risks and ensure products are built with security considerations from the outset, supporting enterprise clients building new hardware or software products.
Quantifiable outcome
- Over 20 security advisories published since 2019 covering critical vulnerabilities in products from Cisco, Netgear, TeamSpeak, Synology, INSTAR, Poly, Trend Micro, MailCleaner, Passwordstate, Meeting Owl, Via Browser, and others.
- +1 more outcomes
Companies that use modzero
Customer profileSegments2 records
Ideal customer profiles1 record
modzero technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
modzero partnerships and signals
Strategic signalScale indicators2 records
Recent moves3 records
Expansion highlights3 records
modzero competitors and assessment
Company assessmentDirect peers
- Bishop Fox: Bishop Fox is a US-based boutique offensive security firm offering penetration testing, red teaming, and security research — comparable to modzero in boutique positioning and research-led brand, though larger in scale.
- Recurity Labs: Recurity Labs is a Berlin-based independent cybersecurity consultancy focused on offensive security, vulnerability research, and reverse engineering — a near-identical operating profile to modzero in terms of size, location, and technical depth.
- Trail of Bits: Trail of Bits is a US-based boutique security consultancy with deep offensive security research, published tooling, and high-profile CVE work — the closest US analog to modzero's research-driven boutique model.
- Cure53: Cure53 is a Berlin-based boutique cybersecurity consultancy offering web, mobile, and infrastructure penetration testing — the closest geographic and operating-model peer to modzero, with comparable size, research-driven reputation, and bespoke engagement model.
- SEC Consult: SEC Consult is a DACH-rooted cybersecurity consultancy offering penetration testing, red teaming, and security advisory services — larger than modzero but operating in the same regional market with comparable service lines.
- Code White: Code White is a German boutique security firm specializing in penetration testing and red team engagements — directly comparable in service mix, boutique scale, and DACH focus.
- SektionEins: SektionEins is a German boutique security research firm specializing in penetration testing, reverse engineering, and vulnerability research — directly comparable to modzero's red teaming and hardware/software review practices in the DACH region.
- n.runs: n.runs is a German boutique penetration testing and application security firm — comparable to modzero in service specialization, boutique scale, and DACH customer base.
Broad incumbents
- NCC Group: NCC Group is a global cybersecurity services incumbent offering penetration testing and red teaming as part of a broader portfolio — overlaps with modzero in core offensive services but serves a much wider enterprise market and productized capability set.
Emerging players
- HackerOne: HackerOne operates a bug bounty and pentest-as-a-service platform that competes for offensive security budgets — not a boutique consultancy but a channel that increasingly disintermediates traditional pentest boutiques like modzero.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat2 records
Customer concentration
modzero social profiles
Digital presencemodzero financial estimates
Financial estimateRevenue estimate
Valuation estimate
modzero leadership team
Management profileNumber of profiles
Profiles2 records
modzero funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
modzero M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about modzero
What does modzero do?
modzero provides individually customized, detailed, and transparent security analyses of concepts, software, and hardware components as a service. Its core offerings include Application Pentesting, Cloud Pentesting, Red Teaming, Hardware/Software Review, and Design & Concept Advisory, delivered as bespoke consulting engagements from offices in Winterthur (Switzerland) and Berlin (Germany) to enterprise clients across Europe. The firm combines offensive security testing, vulnerability research, and hardware/software reverse engineering with published security advisories demonstrating real-world discoveries.
Is modzero a public or private company?
modzero is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was modzero founded?
modzero was founded in 2011. It employs 1 to 10 people.
Where is modzero based?
modzero is headquartered in Winterthur, Switzerland, in the Europe region.
How does modzero make money?
One revenue line is on record: security Consulting and Assessment Services.
Who are modzero's main competitors?
Direct peers on record are Bishop Fox, Recurity Labs, Trail of Bits, Cure53, SEC Consult, Code White, SektionEins and n.runs. NCC Group is listed as a broad incumbent. HackerOne is listed as an emerging player.
Does modzero have an API?
No public API is recorded for modzero.