Penumbra Security
Penumbra Security is a NIST NVLAP accredited cryptographic security testing laboratory providing FIPS 140-3 conformance testing, postal security evaluations, and penetration testing primarily to government postal entities and large enterprises across North America and Europe.
- Company typePrivate
- Founded2011
- HeadquartersClackamas, United States
- Headcount1–10
- GTM typeB2B
- OfferingServices
What Penumbra Security does
Penumbra Security, Inc. is a NIST NVLAP accredited Cryptographic Security Testing Laboratory (CSTL) headquartered in Clackamas, Oregon, operating as a specialized professional services firm focused on security conformance testing and certification for government and enterprise clients. Its core offering is accredited cryptographic security testing under FIPS 140-3 Security Levels 1-4 (NVLAP Laboratory Code 200983-0), supplemented by postal security systems evaluations, network and web application penetration testing, SAFE-IT certification for network-connected peripherals, physical security assessments, and IT infrastructure audits.
The company serves two primary verticals: government and postal entities as the main segment (with named customers including USPS, Canada Post, UK Royal Mail, and Deutsche Post), and large enterprises as a secondary segment. Penumbra self-describes as the world leader in postal security testing, with an established geographic footprint across North America and Europe despite its small 1-10 employee footprint.
The business model is project-based professional services with quote-based, multi-year contracts and direct enterprise sales motion; revenue is generated through custom testing engagements rather than a software product. Distribution is direct (website inquiry, email, and field sales), with no apparent channel partners, marketplace presence, or self-serve product offering. No funding rounds, acquisitions, or leadership changes are documented in the available data.
Penumbra Security firmographics
Firmographics- Name
- Penumbra Security
- Legal name
- Penumbra Security, Inc.
- Website
- https://pensec.org
- Company type
- Private
- Founded year
- 2011
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Penumbra Security is a NIST NVLAP accredited cryptographic security testing laboratory providing FIPS 140-3 conformance testing, postal security evaluations, and penetration testing primarily to government postal entities and large enterprises across North America and Europe.
- Ownership category
- akta.pro rank
Penumbra Security industry classification
Industry- Product category
- Security Testing Services
- NAICS
- Testing Laboratories and Services (54138)
- SIC
- Services-Detective, Guard & Armored Car Services (7381)
- akta.pro primary industry
- Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG)
- akta.pro secondary industries
- Penetration Testing & Red Teaming (BPAKAHAF), Vulnerability Management & Penetration Testing Services (BPAEADAD)
Keywords
Where Penumbra Security is headquartered
LocationHeadquarters
- HQ city
- Clackamas
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Penumbra Security business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales
Revenue model
- Security Testing and Certification Services: Professional services revenue from providing security testing, conformance certification, and compliance auditing. Includes FIPS 140-3 testing, PEN testing, postal security assessments, and IT infrastructure audits. Revenue model based on project-based engagements with government and enterprise clients requiring certification and compliance verification.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom enterprise engagement |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels2 records
Penumbra Security product offering
Product offeringCore offering
Penumbra Security is a NIST NVLAP-accredited Cryptographic Security Testing Laboratory (CSTL, Laboratory Code 200983-0) that provides information security conformance testing to government standards and regulatory compliance. Its core offerings include FIPS 140-3 cryptographic module testing across Security Levels 1-4, postal security systems evaluations, network and web application penetration testing, SAFE-IT peripheral certification, physical security assessments, and IT infrastructure audits.
Product overview
Penumbra Security is a NIST NVLAP-accredited Cryptographic Security Testing Laboratory (CSTL) offering a portfolio of security testing and certification services. The company operates as a single-service platform providing specialized conformance testing rather than a software product company. Its core offerings include FIPS 140-3 cryptographic testing (accredited for Security Levels 1-4), postal security systems evaluations (serving USPS, Canada Post, UK Royal Mail, Deutsche Post), PEN testing (network and web application), SAFE-IT peripheral certification, web application testing, physical security assessments, and IT infrastructure audits. These services are delivered by security experts proficient in cryptographic security techniques and regulatory compliance.
Differentiator
Problem solved
Functional benefit
Brands
- SAFE-IT: Testing and certification service that provides assurance of the security, functionality, and interoperability of network-connected peripherals.
Products and services
- FIPS 140-3 Testing Cryptographic security testing services accredited under NVLAP (Laboratory Code 200983-0) for FIPS 140-3 Security Levels 1-4, providing conformance testing to government cryptographic standards for module vendors and government agencies.
- Postal Security Testing World-leading postal security systems evaluations and assessments for major global postal entities including USPS, Canada Post, UK Royal Mail, and Deutsche Post, covering testing, compliance, and conformance for postal infrastructure.
- PEN Testing Network and web application penetration testing services including architecture reviews, security assessments, and vulnerability analysis conducted by security professionals for enterprise and government clients.
- SAFE-IT Testing and certification service providing assurance of the security, functionality, and interoperability of network-connected peripherals for vendors and government agencies.
- Web Application Testing Security testing services for web applications, identifying vulnerabilities and providing security assessment reporting for organizations deploying web-based systems.
- Physical Security Physical security assessment and evaluation services for organizations requiring evaluation of physical access controls, facility security, and related protective measures.
- IT Infrastructure Audits IT infrastructure auditing services for various industries, providing independent assessment of security controls, configurations, and compliance posture across enterprise environments.
Companies that use Penumbra Security
Customer profileNamed customers4 records
Segments2 records
Ideal customer profiles2 records
Penumbra Security technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
Penumbra Security partnerships and signals
Strategic signalScale indicators2 records
Recent moves4 records
Expansion highlights4 records
Penumbra Security competitors and assessment
Company assessmentBroad incumbents
- Trustwave: Global cybersecurity services and testing provider offering penetration testing, vulnerability assessments, and compliance audits. Broad incumbent with overlapping services in PEN testing and security auditing segments.
- Leidos: Large federal contractor with cybersecurity services including FIPS validation, PEN testing, and security compliance for government agencies. A broad incumbent competing for the same federal and postal security testing budgets.
- Booz Allen Hamilton: Major management and technology consulting firm with a significant federal cybersecurity practice that includes FIPS testing, vulnerability assessments, and PEN testing. Competes for the same government and enterprise security services engagements.
- ICSA Labs (Intertek): Long-established security testing and certification division of Intertek providing FIPS, Common Criteria, and product security testing. A larger incumbent with overlapping accredited testing capabilities targeting similar government and enterprise customers.
- UL Verification Services: Global safety and security testing/certification arm of UL offering FIPS 140-3 and Common Criteria evaluation services. A broad incumbent with accredited labs competing for the same module vendor and government customers.
Direct peers
- IOActive: Specialized cybersecurity services firm providing penetration testing, security assessments, and vulnerability analysis for hardware and software products. Comparable in its PEN testing and security assessment offerings to Penumbra's non-FIPS service lines.
- Acumen Security: NVLAP-accredited Cryptographic and Security Testing laboratory that performs FIPS 140-3 validation and security testing for cryptographic modules. Operates as a direct competitor in the same CSTL niche serving federal and enterprise customers.
- EWA-Canada: Canadian-based IT security testing laboratory offering FIPS 140-3 conformance testing, Common Criteria evaluation, and cryptographic security assessments. Directly competes with Penumbra in accredited cryptographic module testing services.
- Serma Safety & Security: European security evaluation laboratory providing FIPS 140-3 testing, Common Criteria, and embedded security assessments. Directly competes in cryptographic and security conformance testing for module vendors globally.
Regional players
- TÜV Informationstechnik (TÜViT): German-based testing and certification body offering FIPS 140-3, Common Criteria, and product security evaluation. Provides comparable accredited security testing services, primarily serving European customers with overlap to Penumbra's postal and enterprise accounts in EMEA.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
Penumbra Security social profiles
Digital presencePenumbra Security compliance and trust
Trust signalCompliance1 record
Penumbra Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Penumbra Security leadership team
Management profileNumber of profiles
Penumbra Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Penumbra Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Penumbra Security
What does Penumbra Security do?
Penumbra Security is a NIST NVLAP-accredited Cryptographic Security Testing Laboratory (CSTL, Laboratory Code 200983-0) that provides information security conformance testing to government standards and regulatory compliance. Its core offerings include FIPS 140-3 cryptographic module testing across Security Levels 1-4, postal security systems evaluations, network and web application penetration testing, SAFE-IT peripheral certification, physical security assessments, and IT infrastructure audits.
Is Penumbra Security a public or private company?
Penumbra Security is a private company. It is classified as unknown and is currently operating.
When was Penumbra Security founded?
Penumbra Security was founded in 2011. It employs 1 to 10 people.
Where is Penumbra Security based?
Penumbra Security is headquartered in Clackamas, United States, in the North America region.
How does Penumbra Security make money?
One revenue line is on record: security Testing and Certification Services.
Who are Penumbra Security's main competitors?
Broad incumbents on record are Trustwave, Leidos, Booz Allen Hamilton, ICSA Labs (Intertek) and UL Verification Services. Direct peers are IOActive, Acumen Security, EWA-Canada and Serma Safety & Security. TÜV Informationstechnik (TÜViT) is listed as a regional player.
Does Penumbra Security have an API?
No public API is recorded for Penumbra Security.
What industry is Penumbra Security in?
Penumbra Security's product category is Security Testing Services. Its primary akta.pro industry code is BPAKAHAG, Vulnerability Assessment, Security Audits & Compliance Testing, with a secondary code of BPAKAHAF, Penetration Testing & Red Teaming. Its NAICS code is 54138 and its SIC code is 7381.