Compass Security AG
Compass Security AG is a Swiss offensive cybersecurity firm (founded 1999) providing penetration testing, red teaming, incident response, MDR, and industrial cybersecurity services to enterprise and regulated organizations across Europe, complemented by proprietary tools including EntraFalcon and RAPTR.
- Company typePrivate
- Founded1999
- HeadquartersJona, Switzerland
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Compass Security AG does
Compass Security AG (legal entity Compass Security Network Computing AG) is a Swiss-headquartered offensive cybersecurity firm founded in 1999, providing penetration testing, red teaming, purple teaming, security reviews, bug bounty management, managed detection and response (24/7), incident response and digital forensics, and industrial cybersecurity (IEC 62443 and EU Cyber Resilience Act compliance). It serves large enterprises and regulated organizations primarily in Switzerland and Europe, with additional presence in Germany (Compass Security Deutschland GmbH, Berlin) and Canada. Its customer segments include enterprise security buyers, industrial manufacturers/integrators, and educational institutions using its Hacking-Lab platform for cybersecurity training and Capture-the-Flag events.
The company's core technology stack combines a professional services delivery platform with proprietary and open-source security tooling. Notable proprietary and open-source assets include EntraFalcon (a PowerShell-based Microsoft Entra ID assessment and enumeration tool with 60+ automated checks), RAPTR (a FastAPI-driven open-source collaboration platform for red and purple team engagements with OpenAPI documentation and Jinja-templatable reporting), Managed Security Content for Microsoft Defender XDR, FileBox (secure file transfer and storage, cloud and on-prem appliance), and Hacking-Lab (online ethical hacking and CTF platform, operated via wholly-owned Hacking-Lab AG). The technology differentiator is domain specialization and customizability rather than AI/ML or platform-scale dynamics.
Commercially, Compass Security operates a B2B, sales-led, direct enterprise engagement model with no disclosed channel or reseller network. Pricing is quote-based and not publicly disclosed, structured around custom enterprise engagements with multi-year contract cadence. Revenue derives from four streams: professional cybersecurity services (project or retainer), managed services (MDR and Bug Bounty Managed Service), security training programs (instructor-led across topics including DFIR, OSINT, web application security, social engineering, IoT, mobile, and crisis management tabletop exercises), and product revenue from FileBox and Managed Security Content for Microsoft Defender XDR. The holding company structure (Compass Security Network Computing AG with subsidiaries Compass Security Schweiz AG, Compass Security Cyber Defense AG, Hacking-Lab AG, and Compass Security Deutschland GmbH) is wholly founder/management-owned with no external funding disclosed.
Compass Security AG firmographics
Firmographics- Name
- Compass Security AG
- Legal name
- Compass Security Network Computing AG
- Website
- https://compass-security.com
- Company type
- Private
- Founded year
- 1999
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Compass Security AG is a Swiss offensive cybersecurity firm (founded 1999) providing penetration testing, red teaming, incident response, MDR, and industrial cybersecurity services to enterprise and regulated organizations across Europe, complemented by proprietary tools including EntraFalcon and RAPTR.
- Ownership category
- akta.pro rank
Compass Security AG industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Other Scientific and Technical Consulting Services (54169), Investigation and Security Services (5616)
- SIC
- Services-Engineering, Accounting, Research, Management (8700)
- akta.pro primary industry
- Vulnerability Management & Penetration Testing Services (BPAEADAD)
- akta.pro secondary industries
- Penetration Testing, Red Team & Ethical Hacking (EDAOAIAH), Cybersecurity & Identity Consulting (BPAHAEAG), Data Security & Privacy Services (DLP, Encryption, Privacy Ops) (BPAKAHAM), Network Security Managed Services (Firewall/IDS/IPS/SASE) (BPAEADAG)
Keywords
Where Compass Security AG is headquartered
LocationHeadquarters
- HQ city
- Jona
- HQ country
- Switzerland
- HQ region
- Europe
Offices2 records
Markets served
Compass Security AG business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Professional Cybersecurity Services: Revenue generated through consulting engagements including penetration testing, security reviews, red teaming, purple teaming, incident response, digital forensics, and industrial cybersecurity services. Billed as project-based or retainer engagements.
- Managed Detection and Response (MDR): Ongoing managed security services providing real-time monitoring, threat detection, and incident management with 24/7 support capabilities.
- Security Training Programs: Revenue from instructor-led training programs covering topics such as crisis management, cybersecurity tabletop exercises, digital forensics, network security, IoT security, OSINT, mobile app security, social engineering, and web application security.
- Bug Bounty Managed Service: Managed service connecting organizations with global security researchers for continuous vulnerability assessment according to client-defined rules.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Multi-year contract | Custom enterprise engagements |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels6 records
Compass Security AG product offering
Product offeringCore offering
Compass Security AG provides offensive cybersecurity services including penetration testing, red teaming, purple teaming, security reviews, and 24/7 managed detection and response (MDR) with incident response and digital forensics. The company also sells proprietary products such as FileBox (secure file transfer), Hacking-Lab (ethical hacking platform), Managed Security Content for Microsoft Defender XDR, EntraFalcon (Entra ID assessment tool), and RAPTR (red/purple team collaboration platform), and delivers structured cybersecurity training programs.
Product overview
Compass Security AG is an international IT security company offering a comprehensive portfolio of offensive security services, cybersecurity products, and professional training. The core offering consists of penetration testing, red teaming, purple teaming, and incident response services. Their product portfolio includes FileBox (secure file transfer), Hacking-Lab (ethical hacking platform), Managed Security Content for Microsoft Defender XDR, EntraFalcon (Entra ID assessment tool), RAPTR (red/purple team collaboration platform), and SSH Labs (SSH security training). The company provides professional training programs covering topics from web application security to digital forensics, delivered both in their security lab and at client sites.
Differentiator
Problem solved
Functional benefit
Brands
- Hacking-Lab: Online platform for ethical hacking and security challenges, including Capture the Flag events, university training, and employee trainings.
- FileBox
- EntraFalcon
- RAPTR
- Managed Security Content for Microsoft Defender XDR
Products and services
- Penetration Tests
- Security Review
- Red Teaming
- Purple Teaming
- Bug Bounty Managed Service
- Managed Detection and Response (MDR)
- Incident Response and Forensics
- Industrial Cybersecurity
- Managed Security Content for Microsoft Defender XDR
- FileBox
- Hacking-Lab
- EntraFalcon
- RAPTR
- SSH Labs
- Crisis Management & Cybersecurity Tabletop Exercise (TTX) Training
- Digital Forensics and Incident Response (DFIR) Training
- Security Boot Camp
Quantifiable outcome
- Organizations can identify and remediate vulnerabilities before exploitation through comprehensive penetration testing and security reviews
Companies that use Compass Security AG
Customer profileSegments3 records
Ideal customer profiles3 records
Compass Security AG technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration1 record
AI capability2 records
Feature5 records
Compass Security AG partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- MicrosoftcoreDeep integration partnership with Microsoft including development of Managed Security Content for Microsoft Defender XDR. Research collaboration producing security advisories on Microsoft Entra ID including Entra Agent ID security analysis. EntraFalcon tool specifically designed for Microsoft Entra ID security assessment.
Scale indicators1 record
Recent moves6 records
Expansion highlights6 records
Compass Security AG competitors and assessment
Company assessmentBroad incumbents
- Mandiant (Google Cloud): Now part of Google Cloud, Mandiant is a broad incumbent in incident response, threat intelligence, and offensive security consulting — overlaps Compass Security's IR/forensics and red teaming services at a much larger scale.
- Deloitte Cyber: Big 4 cyber practice offering enterprise-scale penetration testing, red teaming, and managed security services — competes for the same enterprise pentesting RFPs as Compass Security but as part of a broader consulting portfolio.
Direct peers
- NCC Group: UK-headquartered, publicly listed cybersecurity consulting firm with a global offensive security practice spanning penetration testing, red teaming, and managed detection — the closest scaled public-market comparable to Compass Security's service mix.
- TrustedSec: US-based offensive security consultancy offering penetration testing, red teaming, and incident response services — directly comparable service portfolio and consulting-led delivery model.
- Cobalt: Pentesting-as-a-service platform connecting enterprises with a vetted researcher network — overlaps with Compass Security's bug bounty managed service and crowdsourced testing offerings.
- HackerOne: Global bug bounty and vulnerability disclosure platform — competes with Compass Security's Bug Bounty Managed Service offering and serves overlapping enterprise security buyer personas.
- Bishop Fox: US-based offensive security firm specializing in penetration testing, red teaming, and adversary emulation services — a direct competitor in the same product category targeting enterprise clients with similar solutions.
- NetSPI: US-based penetration testing and attack surface management firm with a strong enterprise focus — comparable to Compass Security in service breadth (pentesting, red teaming, MDR-adjacent services) and B2B enterprise GTM motion.
- SecAlliance: UK-based offensive security consultancy (formerly Secarma) offering penetration testing, red teaming, and managed security services — closely aligned service portfolio and European market overlap.
Regional players
- YesWeHack: European (French-headquartered) bug bounty and crowdsourced security platform — strongest direct competitor in the DACH/Western European region for managed bug bounty services.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights6 records
Customer concentration
Compass Security AG social profiles
Digital presenceCompass Security AG financial estimates
Financial estimateRevenue estimate
Valuation estimate
Compass Security AG leadership team
Management profileNumber of profiles
Profiles1 record
Compass Security AG subsidiaries and ownership
Company hierarchySubsidiaries4 records
Compass Security AG funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Compass Security AG M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Compass Security AG
What does Compass Security AG do?
Compass Security AG provides offensive cybersecurity services including penetration testing, red teaming, purple teaming, security reviews, and 24/7 managed detection and response (MDR) with incident response and digital forensics. The company also sells proprietary products such as FileBox (secure file transfer), Hacking-Lab (ethical hacking platform), Managed Security Content for Microsoft Defender XDR, EntraFalcon (Entra ID assessment tool), and RAPTR (red/purple team collaboration platform), and delivers structured cybersecurity training programs.
Is Compass Security AG a public or private company?
Compass Security AG is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Compass Security AG founded?
Compass Security AG was founded in 1999. It employs 11 to 50 people.
Where is Compass Security AG based?
Compass Security AG is headquartered in Jona, Switzerland, in the Europe region.
How does Compass Security AG make money?
Four revenue lines are on record. Professional Cybersecurity Services are the primary driver. The others are managed Detection and Response (MDR), security Training Programs and bug Bounty Managed Service.
Who are Compass Security AG's main competitors?
Broad incumbents on record are Mandiant (Google Cloud) and Deloitte Cyber. Direct peers are NCC Group, TrustedSec, Cobalt, HackerOne, Bishop Fox, NetSPI and SecAlliance. YesWeHack is listed as a regional player.
Does Compass Security AG have an API?
Yes. RAPTR is a fully open source, API driven collaboration platform built specifically for red and purple team engagements. The backend is built on FastAPI and includes auto-generated OpenAPI documentation. Every feature available in the platform is accessible through the REST API, making it easy to wire into existing automation and tooling. Developer documentation is at sandbox.raptr.app/docs.
What industry is Compass Security AG in?
Compass Security AG's product category is Cybersecurity Services. Its primary akta.pro industry code is BPAEADAD, Vulnerability Management & Penetration Testing Services, with a secondary code of EDAOAIAH, Penetration Testing, Red Team & Ethical Hacking. Its NAICS code is 54169 and its SIC code is 8700.