Vaadata
Vaadata is a French offensive security consultancy offering penetration testing, Red Team audits, and Assumed Breach exercises. Founded in 2013 and headquartered in Lyon, the firm serves over 800 enterprise and mid-market clients across France and internationally with certified human consultants.
- Company typePrivate
- Founded2016
- HeadquartersLyon, France
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Vaadata does
Vaadata is a French offensive security services firm headquartered in Lyon (VAADATA SARL, RCS 797 558 590 LYON) that delivers human-led penetration testing, Red Team audits, and Assumed Breach exercises to enterprise and mid-market clients. Its portfolio spans six specialized pentest modules covering web applications, mobile apps, cloud environments (AWS, Azure, GCP), infrastructure and networks (including Active Directory), IoT devices, and social engineering, delivered in black-box, grey-box, or white-box configurations. Advanced offerings include Red Team simulations aligned with MITRE ATT&CK and Cyber Threat Intelligence methodologies (APT profiling, threat-led penetration testing consistent with TIBER-EU and DORA), and Assumed Breach post-compromise exercises that test detection and response.
The business model is pure professional services: engagements are proposal-based, scope-driven, and typically structured as multi-year contracts with annual or recurring cadences. Pricing is quote-based and not publicly disclosed, and the firm does not sell software, an API, or automated tooling — all services are delivered by certified consultants. The GTM is sales-led, combining direct outreach, a website contact channel, and content-driven inbound via an extensive technical blog, ebooks, webinars, and event participation. The firm has not raised external funding and operates as a privately held SARL with €36,000 registered capital. It holds regulated credentials (PASSI, ISO 27001, ISO 27701, CREST) and its consultants hold OSCP, CPTS, CRTP, CREST CPSA, and Fortinet certifications.
Vaadata firmographics
Firmographics- Name
- Vaadata
- Legal name
- VAADATA SARL
- Website
- https://vaadata.com
- Company type
- Private
- Founded year
- 2016
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Vaadata is a French offensive security consultancy offering penetration testing, Red Team audits, and Assumed Breach exercises. Founded in 2013 and headquartered in Lyon, the firm serves over 800 enterprise and mid-market clients across France and internationally with certified human consultants.
- Ownership category
- akta.pro rank
Vaadata industry classification
Industry- Product category
- Cybersecurity Consulting
- NAICS
- Testing Laboratories and Services (54138), Security Systems Services (56162)
- SIC
- Services-Testing Laboratories (8734)
- akta.pro primary industry
- Vulnerability Management & Penetration Testing Services (BPAEADAD)
- akta.pro secondary industries
- Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG), Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
Keywords
Where Vaadata is headquartered
LocationHeadquarters
- HQ city
- Lyon
- HQ country
- France
- HQ region
- Europe
Offices2 records
Markets served
Vaadata business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Marketing or Sales, Technology or R&D, Operations
Revenue model
- Penetration Testing Services: Professional services revenue from conducting penetration tests across multiple domains (web, mobile, infrastructure, IoT, cloud, social engineering). These are typically project-based engagements scoped to client requirements, conducted in black box, grey box, or white box configurations.
- Red Team Audits: Advanced security assessments simulating realistic attack scenarios against organizations, evaluating detection and response capabilities, processes, and teams across the entire security posture.
- Assumed Breach Exercises: Post-compromise security exercises evaluating an organization's ability to detect and respond to ongoing attacks when initial defenses have been breached, testing incident response procedures.
- Training Services: The company is a registered training organization (Organisme de formation registered under number 82 69 13662 69) offering cybersecurity training programs.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom Proposal-Based Engagement |
Go-to-market motion1 record
Distribution channels2 records
Marketing channels7 records
Vaadata product offering
Product offeringCore offering
Vaadata is a French offensive cybersecurity firm offering human-delivered penetration testing, Red Team audits, and Assumed Breach exercises to identify technical and logical vulnerabilities across web applications, mobile apps, cloud environments (AWS, Azure, GCP), network infrastructure, IoT devices, and human attack surfaces (social engineering). All engagements are conducted by certified consultants applying recognized methodologies such as OWASP Top 10, MITRE ATT&CK, TIBER-EU, and DORA frameworks, with the company holding PASSI, ISO 27001, ISO 27701, and CREST qualifications.
Product overview
Vaadata is a specialized offensive cybersecurity firm offering a portfolio of human-delivered penetration testing and red team services. The core offering consists of six specialized pentest modules — Pentest Web, Pentest Mobile, Pentest Infrastructure et Réseau, Pentest IoT, Pentest Cloud, and Pentest Ingénierie Sociale — which identify and remediate technical and logical vulnerabilities across customer environments. These are complemented by two advanced offensive assessments: Red Team, which simulates full adversary attack chains using real attacker TTPs to evaluate detection and response, and Assumed Breach, which evaluates post-compromise detection capabilities assuming an attacker has already gained initial access. Vaadata also publishes educational content through its Blog, Ebooks & Livres blancs, and Webinars. The company does not offer a software platform, automated tooling, or API — all services are delivered by certified human consultants. The portfolio supports black-box, grey-box, and white-box testing methodologies across web applications, mobile apps, cloud environments (AWS, Azure, GCP), networks, IoT devices, and human attack surfaces.
Differentiator
Problem solved
Functional benefit
Products and services
- Pentest Web Penetration testing for web applications including SaaS platforms, e-commerce sites, web APIs, and web servers to identify and remediate technical and logical vulnerabilities. Targets enterprise and mid-market organizations seeking third-party validation of web security.
- Pentest Mobile Security testing for iOS and Android mobile applications and mobile APIs, including static and dynamic analysis as well as reverse engineering. Targets organizations with mobile application portfolios.
- Pentest Infrastructure et Réseau Penetration testing for servers, Wi-Fi, VLANs, Active Directory, workstations, internal services, and network infrastructure to evaluate internal and external security posture. Targets enterprise IT environments.
- Pentest IoT Security testing for IoT devices covering hardware, firmware, communication protocols, web and mobile interfaces, and APIs. Targets manufacturers and operators of connected devices.
- Pentest Cloud Penetration testing for cloud environments including AWS, Azure, and GCP, covering configuration analysis and storage security. Targets organizations operating cloud workloads.
- Pentest Ingénierie Sociale Social engineering penetration testing including phishing campaigns, vishing, SMiShing, and physical intrusion testing to evaluate human vulnerability. Targets organizations seeking to assess employee security awareness.
- Red Team Advanced offensive security audit simulating real-world attack scenarios by reproducing attacker tactics, techniques, and procedures (TTPs) to evaluate detection, response capabilities, processes, and organizational resilience. Targets enterprises and regulated organizations requiring comprehensive adversary simulation.
- Assumed Breach Post-compromise exercises simulating a compromised user account or server to evaluate the organization's ability to detect and respond to an active attack, improving incident response procedures and security posture. Targets mature security organizations.
Quantifiable outcome
- More than 800 organizations rely on Vaadata's services
- +1 more outcomes
Companies that use Vaadata
Customer profileNamed customers9 records
Segments3 records
Ideal customer profiles3 records
Vaadata technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature5 records
Vaadata partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered minor.
- Google AnalyticsminorAnalytics service provider for measuring website traffic and audience. Data processing agreement includes Standard Contractual Clauses for data transfers.
- KinstaminorWebsite hosting provider for vaadata.com. Located at 8605 Santa Monica Blvd #92581, West Hollywood, CA 90069, USA.
Scale indicators2 records
Recent moves5 records
Expansion highlights2 records
Vaadata competitors and assessment
Company assessmentRegional players
- Sekoia.io: French cybersecurity firm offering CTI and SOC services, often adjacent to offensive engagements. Comparable French-market positioning with similar regulatory familiarity.
Broad incumbents
- Trustwave: Global MSSP and offensive security provider with CREST-accredited pentesting services. Overlaps with Vaadata on enterprise pentesting, particularly for regulated buyers.
- Devoteam Cyber Trust: European consulting group with substantial cybersecurity practice covering pentesting, red team, and managed security. Frequently competes in mid-market and large enterprise French RFPs.
- NCC Group: UK-listed cybersecurity consulting firm with strong European presence offering CREST-accredited pentesting, red team, and threat intelligence services. Comparable on certification stack and regulatory alignment.
- Orange Cyberdefense: The cybersecurity arm of Orange, one of France's largest MSSPs and offensive security providers. Offers a broad portfolio including pentesting, red team, and managed detection, competing with Vaadata especially in French enterprise and regulated RFPs.
Emerging players
- Cobalt: Pentesting-as-a-service platform connecting enterprises with a curated tester community. Direct competitor on standard pentest engagements, particularly attractive to mid-market and tech-forward buyers.
- HackerOne: Bug bounty and vulnerability disclosure platform serving enterprise security teams. Disrupts traditional pentest models by crowdsourcing vulnerability discovery at scale.
- Synack: US-based on-demand pentesting platform combining vetted researchers with automated tooling. Competes with boutique pentest firms on speed, scale, and pricing for web/infrastructure assessments.
Direct peers
- Bishop Fox: US-based boutique offensive security firm specializing in pentesting, red team, and attack surface management. Closest international peer in operating model and service breadth.
- Wavestone: French-headquartered consulting firm with a dedicated cybersecurity practice offering pentesting, red team, and security advisory. Closest direct peer in size and service mix within France.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
Vaadata social profiles
Digital presenceVaadata compliance and trust
Trust signalCompliance8 records
Vaadata financial estimates
Financial estimateRevenue estimate
Valuation estimate
Vaadata leadership team
Management profileNumber of profiles
Profiles2 records
Vaadata funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Vaadata M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Vaadata
What does Vaadata do?
Vaadata is a French offensive cybersecurity firm offering human-delivered penetration testing, Red Team audits, and Assumed Breach exercises to identify technical and logical vulnerabilities across web applications, mobile apps, cloud environments (AWS, Azure, GCP), network infrastructure, IoT devices, and human attack surfaces (social engineering). All engagements are conducted by certified consultants applying recognized methodologies such as OWASP Top 10, MITRE ATT&CK, TIBER-EU, and DORA frameworks, with the company holding PASSI, ISO 27001, ISO 27701, and CREST qualifications.
Is Vaadata a public or private company?
Vaadata is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Vaadata founded?
Vaadata was founded in 2016. It employs 11 to 50 people.
Where is Vaadata based?
Vaadata is headquartered in Lyon, France, in the Europe region.
How does Vaadata make money?
Four revenue lines are on record. Penetration Testing Services are the primary driver. The others are red Team Audits, assumed Breach Exercises and training Services.
Who are Vaadata's main competitors?
Sekoia.io is listed as a regional player. Broad incumbents are Trustwave, Devoteam Cyber Trust, NCC Group and Orange Cyberdefense. Emerging players are Cobalt, HackerOne and Synack. Direct peers are Bishop Fox and Wavestone.
Does Vaadata have an API?
No public API is recorded for Vaadata.
What industry is Vaadata in?
Vaadata's product category is Cybersecurity Consulting. Its primary akta.pro industry code is BPAEADAD, Vulnerability Management & Penetration Testing Services, with a secondary code of BPAKAHAG, Vulnerability Assessment, Security Audits & Compliance Testing. Its NAICS code is 54138 and its SIC code is 8734.