Veramine
Veramine is a private U.S. cybersecurity company that sells a Windows endpoint detection-and-response platform for enterprise security teams and government/military organizations, offered via a freemium SaaS or self-hosted deployment.
- Company typePrivate
- Founded2018
- HeadquartersBothell, United States
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Veramine does
Veramine Inc. is a private U.S. cybersecurity company founded in 2018 by a five-person team of former Microsoft security engineers, headquartered in Bothell, Washington. It sells a Windows-focused endpoint detection and response (EDR) platform built around a lightweight host sensor (consuming under 1% CPU after initial enumeration) that streams enriched event data to either a Veramine-hosted cloud server or a customer-self-hosted server. The detection engine combines rule-based detections with machine-learning–enabled process profiling, network data exfiltration detection, and user logon anomaly detection, targeting kernel-mode exploitation (including unknown/zero-day), Mimikatz-style credential dumping, process injection, and lateral movement. Supporting capabilities include a searchable event repository, central-console response actions (process termination, registry key deletion, YARA-based process-memory search), and open-platform integrations via inbound API, outbound syslog, and streaming to Apache Hadoop or Spark.
The company operates a two-tier commercial model: a free version capped at 20 hosts per organization with only four rule-based detections and same-day search, and a paid subscription whose price scales with host count and data retention duration and unlocks the full ML-enabled detection suite and historical search. Go-to-market blends product-led growth via the free tier with direct enterprise sales targeting enterprise security teams and government/military organizations, acquired primarily through a website contact form and email ([email protected]). Marketing is deliberately low-touch, relying on the company website (available in English and Japanese), technical documentation, and an FAQ rather than broad demand-generation activity. No external funding, institutional investors, parent company, named customers, patents, or revenue figures have been disclosed.
Veramine firmographics
Firmographics- Name
- Veramine
- Legal name
- Veramine Inc.
- Website
- https://veramine.com
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Veramine is a private U.S. cybersecurity company that sells a Windows endpoint detection-and-response platform for enterprise security teams and government/military organizations, offered via a freemium SaaS or self-hosted deployment.
- Ownership category
- akta.pro rank
Veramine industry classification
Industry- Product category
- Endpoint Detection and Response (EDR) Software
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Endpoint Detection & Response (EDR) (HDADAEAA)
- akta.pro secondary industries
- Extended Detection & Response (XDR) (HDADAEAB), Endpoint Forensics & Incident Response (DFIR) (HDADAEAJ)
Keywords
Where Veramine is headquartered
LocationHeadquarters
- HQ city
- Bothell
- HQ country
- United States
- HQ region
- North America
Markets served
Veramine business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Infrastructure, Marketing or Sales, Operations
Revenue model
- Subscription - Paid Tier: Paid product uses more extensive rule-based detections and additional advanced machine-learning enabled process profiling, network data exfiltration detection, and user logon anomaly detection. Subscription priced based on number of hosts on which client is installed and duration for data retention for search and browse.
- Freemium - Free Tier: Free version offers same collection client as paid product. Detection limited to four rule-based detections. Events collected from up to 20 hosts per organization. Browse and search over current day's collected events. Serves as acquisition funnel for paid product.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Others | Free - Limited detection for up to 20 hosts, current day data only |
| Subscription | Multi-year contract | Paid - Full detection suite with ML capabilities, configurable retention |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels4 records
Veramine product offering
Product offeringCore offering
Veramine sells an endpoint detection and response (EDR) platform that uses a lightweight Windows host-based sensor to collect security-relevant events and forwards them to a cloud-hosted or self-hosted server. The platform combines rule-based detections with machine-learning algorithms to identify kernel-mode exploitation, process injection, credential dumping, lateral movement, and data exfiltration, while also providing a searchable discovery layer, YARA-based process memory search, and centralized response actions. It is sold as a subscription for enterprise, government, and large academic environments with a free tier available for up to 20 hosts.
Product overview
Veramine is a unified cyberdefense detection and response platform comprising the Veramine Platform core product with four integrated modules (Collection, Detection, Discovery, and Response), offered in two tiers: Veramine Free (limited to 20 hosts, 4 rule-based detections, same-day data only) and Veramine Paid (advanced ML-based detection, extended data retention, and full feature set). The platform provides continuous security monitoring for Windows-based hosts with lightweight sensor agent (<1% CPU) forwarding data to cloud-based or self-hosted servers.
Differentiator
Problem solved
Functional benefit
Products and services
- Veramine Platform Cyberdefense detection and response platform for Windows hosts, combining a lightweight (<1% CPU) host-based sensor, an advanced rule-based and machine-learning detection engine, contextualized discovery search, and centralized response actions. Supports cloud-hosted or self-hosted deployment, inbound API access, and outbound syslog streaming to Hadoop or Spark. The platform is offered in a free tier (limited to 20 hosts and four rule-based detections, current-day data only) and a paid subscription tier with ML-enabled process profiling, network data exfiltration detection, and user logon anomaly detection, priced per host and retention duration.
Quantifiable outcome
- Sensor consumes <1% CPU after initial enumeration period
- +1 more outcomes
Companies that use Veramine
Customer profileSegments2 records
Ideal customer profiles2 records
Veramine technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration3 records
AI capability3 records
Feature6 records
Veramine partnerships and signals
Strategic signalRecent moves5 records
Expansion highlights5 records
Veramine competitors and assessment
Company assessmentDirect peers
- CrowdStrike: CrowdStrike Falcon is the leading cloud-native EDR/XDR platform with ML-based detection and a global endpoint sensor — the canonical direct competitor to Veramine in Windows host-based detection and response.
- SentinelOne: SentinelOne Singularity delivers autonomous EDR/XDR with behavioral AI detection for endpoints, competing head-to-head with Veramine on ML-driven threat detection and automated response.
- VMware Carbon Black: Carbon Black EDR provides Windows endpoint data collection, behavioral detection, and response — directly comparable to Veramine's collection-and-detection architecture.
- Cybereason: Cybereason's Defense Platform uses behavioral analysis on endpoint telemetry to detect ransomware, credential theft, and lateral movement — closely aligned with Veramine's detection focus.
- Elastic Security: Elastic Security combines endpoint protection with SIEM-style search and analytics; competes with Veramine on endpoint telemetry collection, ML detection, and analyst-driven investigation workflows.
Broad incumbents
- Microsoft Defender for Endpoint: Defender for Endpoint is Microsoft's bundled EDR platform with kernel-level telemetry and behavioral detection — a direct competitor and the most important incumbent to beat, given the founders' Microsoft pedigree.
- Palo Alto Networks Cortex XDR: Cortex XDR combines endpoint, network, and cloud data for detection and response; overlaps with Veramine on endpoint behavioral detection while offering a much broader integrated platform.
- Sophos Intercept X: Sophos Intercept X is a mainstream endpoint protection platform with anti-exploit and behavioral detection capabilities, overlapping with Veramine's kernel and credential-theft detection use cases.
- Trend Micro Vision One: Trend Micro Vision One delivers XDR across endpoints, email, and cloud, competing with Veramine on behavioral detection and threat hunting for Windows endpoints.
Emerging players
- LimaCharlie: LimaCharlie offers an API-first EDR platform with self-hosting and raw telemetry access — closely aligned architecturally with Veramine's open-platform, self-hosted, syslog/Hadoop-friendly design.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks7 records
Key highlights7 records
Customer concentration
Veramine social profiles
Digital presenceVeramine financial estimates
Financial estimateRevenue estimate
Valuation estimate
Veramine leadership team
Management profileNumber of profiles
Profiles5 records
Veramine funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Veramine M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Veramine
What does Veramine do?
Veramine sells an endpoint detection and response (EDR) platform that uses a lightweight Windows host-based sensor to collect security-relevant events and forwards them to a cloud-hosted or self-hosted server. The platform combines rule-based detections with machine-learning algorithms to identify kernel-mode exploitation, process injection, credential dumping, lateral movement, and data exfiltration, while also providing a searchable discovery layer, YARA-based process memory search, and centralized response actions. It is sold as a subscription for enterprise, government, and large academic environments with a free tier available for up to 20 hosts.
Is Veramine a public or private company?
Veramine is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Veramine founded?
Veramine was founded in 2018. It employs 1 to 10 people.
Where is Veramine based?
Veramine is headquartered in Bothell, United States, in the North America region.
How does Veramine make money?
Two revenue lines are on record. Subscription - Paid Tier is the primary driver. The others are freemium - Free Tier.
Who are Veramine's main competitors?
Direct peers on record are CrowdStrike, SentinelOne, VMware Carbon Black, Cybereason and Elastic Security. Broad incumbents are Microsoft Defender for Endpoint, Palo Alto Networks Cortex XDR, Sophos Intercept X and Trend Micro Vision One. LimaCharlie is listed as an emerging player.
Does Veramine have an API?
Yes. Veramine provides raw or contextualized collected data to analysts for bespoke search or analysis operations via inbound API access or outbound syslog. Analysts can connect their own Apache Hadoop or Spark analysis frameworks to process Veramine data streamed in real time.
What industry is Veramine in?
Veramine's product category is Endpoint Detection and Response (EDR) Software. Its primary akta.pro industry code is HDADAEAA, Endpoint Detection & Response (EDR), with a secondary code of HDADAEAB, Extended Detection & Response (XDR). Its NAICS code is 54151 and its SIC code is 7372.