Radically Open Security
Radically Open Security is an Amsterdam-based non-profit computer security consultancy founded in 2014, delivering 14 security services including penetration testing, code audits, incident response, and ISO 27001 compliance to 150+ clients across enterprise, government, NGO, and open-source sectors, with 90% of profits donated to the NLnet Foundation.
- Company typePrivate
- Founded2014
- HeadquartersAmsterdam, Netherlands
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Radically Open Security does
Radically Open Security (ROS) is a non-profit computer security consultancy founded in 2014 and headquartered in Amsterdam, the Netherlands. It operates as a Dutch 'Fiscaal Fondswervende Instelling' (Fiscal Fundraising Institution) that donates 90% of its profits tax-free to the NLnet Foundation, a charitable organization supporting open-source, internet research, and digital rights. The company is the world's first non-profit computer security consultancy, and it markets itself under a 'Post-Growth Entrepreneurship' thesis articulated by co-founder and CEO Dr. Melanie Rieback.
ROS delivers a portfolio of 14 professional security services including web and mobile penetration testing, code audits, network/infrastructure/cloud assessments, hardware/embedded/IoT testing, cryptographic and protocol audits, social engineering and phishing simulations, red team and purple team exercises, incident response, ISO 27001 compliance and risk assessments, DDoS testing, physical/mystery guest assessments, security training and workshops, and custom R&D projects. Services are human-delivered by a distributed team of more than 50 security researchers located across Western Europe, Canada, the United States, Peru, South Africa, Australia, and India.
The company serves a diversified client base of 150+ organizations across verticals including technology, finance and insurance, healthcare, education, government, utilities, NGOs, and open-source projects. Named clients include Google, Mozilla, the European Commission, the Dutch Ministry of Health, Mullvad VPN, F-Droid, Homebrew, Ushahidi, and Tauri. Go-to-market is sales-led via direct outreach, referrals, and word-of-mouth within the security and open-source communities, with thought leadership (TedX, podcasts, press) and a public audit report portfolio serving as inbound demand drivers. Pricing is quote-based per engagement with no publicly disclosed rates. The only disclosed funding is a 2014 ACE Incubator grant; the company has since operated as a bootstrapped non-profit with no external venture capital.
Radically Open Security firmographics
Firmographics- Name
- Radically Open Security
- Legal name
- Radically Open Security
- Website
- https://radicallyopensecurity.com
- Company type
- Private
- Founded year
- 2014
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Radically Open Security is an Amsterdam-based non-profit computer security consultancy founded in 2014, delivering 14 security services including penetration testing, code audits, incident response, and ISO 27001 compliance to 150+ clients across enterprise, government, NGO, and open-source sectors, with 90% of profits donated to the NLnet Foundation.
- Ownership category
- akta.pro rank
Radically Open Security industry classification
Industry- Product category
- Cybersecurity Consulting
- NAICS
- Computer Systems Design and Related Services (5415), Other Computer Related Services (541519)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Vulnerability Management & Penetration Testing Services (BPAEADAD)
- akta.pro secondary industries
- Penetration Testing, Red Team & Ethical Hacking (EDAOAIAH), Secure Software & DevOps Awareness (Secure Coding Basics) (EDABAGAN)
Keywords
Where Radically Open Security is headquartered
LocationHeadquarters
- HQ city
- Amsterdam
- HQ country
- Netherlands
- HQ region
- Europe
Offices1 record
Markets served
Radically Open Security business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure
Revenue model
- Security Consulting Services: Professional security consulting services including pentesting, code audits, infrastructure security, red teaming, incident response, and security training. Revenue generated through project-based engagements with clients ranging from governments and enterprises to NGOs and SMBs.
Go-to-market motion1 record
Distribution channels2 records
Marketing channels8 records
Radically Open Security product offering
Product offeringCore offering
Radically Open Security is a non-profit computer security consultancy providing project-based security assessment services to organizations. Its portfolio includes penetration testing of web, mobile, network, infrastructure, and cloud systems, as well as code audits, hardware/embedded/IoT testing, cryptographic and protocol audits, red/purple team exercises, incident response, ISO 27001 compliance assessments, social engineering and phishing simulations, DDoS and physical security testing, and security training. Clients range from large multinationals and governments to NGOs, open-source projects, and SMBs.
Product overview
Radically Open Security is a non-profit computer security consultancy offering a comprehensive portfolio of 14 distinct security assessment services. The services are provided as a unified consultancy offering rather than a software platform or modular product suite. Core offerings include penetration testing across web applications, mobile apps, networks, and infrastructure; code and cryptographic audits; hardware and embedded systems security; social engineering and phishing simulations; Red Team/Purple Team exercises; incident response; and compliance assessments. The company also provides security training and custom R&D projects. All services are delivered by a team of over 50 security researchers located across Western Europe, North America, South America, Africa, and Asia-Pacific, with the company's non-profit structure directing 90% of profits to the NLnet Foundation charitable foundation.
Differentiator
Problem solved
Functional benefit
Products and services
- Web Pentesting
- Mobile App Pentesting Security assessment of mobile applications across iOS and Android platforms, including the back-end infrastructure supporting them, to uncover vulnerabilities. Targeted at mobile app developers and publishers needing pre-release or post-deployment security testing.
- Code Audits Comprehensive security review of source code to identify security flaws, vulnerabilities, and compliance issues before deployment. Targeted at software engineering teams requiring pre-release or open-source code security assurance.
- Network + Infrastructure + Cloud Security Testing Security testing and assessment of network infrastructure, cloud environments (AWS, Azure, GCP), and system configurations. Targeted at organizations with on-premise, hybrid, or cloud-native infrastructure needing independent security validation.
- Hardware + Embedded + IoT Security Testing Security evaluation of hardware devices, embedded systems, and Internet of Things (IoT) products, including firmware analysis and physical testing. Targeted at hardware vendors, embedded device manufacturers, and IoT product teams.
- Crypto + Protocol Audits Security review and analysis of cryptographic implementations, cryptographic protocols, and communication protocols for weaknesses. Targeted at organizations building or operating cryptographic and protocol-level systems.
- Social Engineering + Phishing Assessments Controlled testing of organizational security through simulated phishing campaigns and social engineering attacks to assess human security awareness. Targeted at organizations seeking to evaluate and improve employee security posture.
- Security Trainings + Workshops Educational programs and hands-on training sessions to help organizations build security knowledge and improve security culture among employees. Targeted at security and engineering teams seeking skill uplift.
- Red Team + Purple Team Exercises Adversarial security exercises in which ROS acts as a Red Team to simulate real-world attacks and works with internal Blue Teams in Purple Team exercises. Targeted at organizations with mature security operations seeking to validate detection and response capabilities.
- Incident Response Rapid response and forensic analysis services to help organizations investigate and respond to security incidents and breaches. Targeted at organizations experiencing or preparing for active security incidents.
- Compliance + Risk Assessments (ISO 27001) Security assessments and compliance evaluations aligned with ISO 27001 and other regulatory frameworks to help organizations meet compliance requirements. Targeted at organizations pursuing or maintaining ISO 27001 certification.
- DDoS Testing Controlled testing of systems and networks to assess resilience against distributed denial-of-service attacks. Targeted at organizations with internet-facing infrastructure needing to validate DDoS defenses.
- Physical + Mystery Guest Security Assessments Physical security assessments including on-site inspections, facility access testing, and mystery guest exercises to evaluate physical security controls. Targeted at organizations with physical premises needing to test physical security posture.
- Custom R&D Projects Tailored security research and development projects addressing unique or specialized security challenges not covered by standard service offerings. Targeted at organizations with novel or specialized security research needs.
Quantifiable outcome
- Worked with over 150 clients since 2014
- +2 more outcomes
Companies that use Radically Open Security
Customer profileNamed customers11 records
Segments8 records
Ideal customer profiles3 records
Radically Open Security technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Radically Open Security partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- NLnet FoundationcoreStichting NLnet is the charitable foundation that receives 90% of Radically Open Security's profits tax-free. NLnet has supported open-source, Internet research, and digital rights organizations for almost 20 years. This is a fundamental part of ROS's non-profit business model, allowing them to channel commercial revenue into charitable causes while maintaining competitive wages for staff.
Scale indicators4 records
Recent moves6 records
Expansion highlights6 records
Radically Open Security competitors and assessment
Company assessmentDirect peers
- Cure53: Berlin-based, similarly-sized boutique security consultancy offering web, mobile, and infrastructure penetration testing plus code audits. Closely comparable to ROS in scope of services, FOSS community engagement, and open report publishing model.
- Trail of Bits: US-based security consultancy specializing in code audits, cryptography, and applied research for high-assurance software systems. Comparable to ROS in deep technical focus, open-source ecosystem involvement, and research-driven culture.
- Coalfire: US-based cybersecurity advisory and testing firm providing penetration testing, compliance assessments (PCI, HITRUST, FedRAMP), and risk advisory. Comparable to ROS in assessment-heavy service mix and enterprise/government client base.
- Bishop Fox: US offensive-security consultancy offering penetration testing, red teaming, and attack-surface management. Directly comparable service portfolio to ROS, though with a commercial (rather than non-profit) structure and larger US enterprise footprint.
- Praetorian: US offensive-security firm offering penetration testing, red teaming, and attack-surface management as a managed platform. Directly competes with ROS in adversarial security services, with a more productized delivery model.
Emerging players
- HackerOne: Bug-bounty and vulnerability disclosure platform connecting organizations with ethical hackers. Partially overlaps with ROS in vulnerability identification but uses a crowdsourced, platform-based model rather than a dedicated consultancy.
- Bugcrowd: Crowdsourced cybersecurity platform offering bug bounty, vulnerability disclosure, and penetration testing as a service. Comparable to ROS on the testing side, but with a fundamentally different delivery and pricing model.
Broad incumbents
- NCC Group: Global, publicly-listed cybersecurity consultancy offering penetration testing, managed security services, and software resilience products. Overlaps with ROS in pentesting and code review, but operates at much greater scale and scope.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Radically Open Security social profiles
Digital presenceRadically Open Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Radically Open Security leadership team
Management profileNumber of profiles
Profiles9 records
Radically Open Security funding detail
Funding detailFunding overview
Funding rounds1 record
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Radically Open Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Radically Open Security
What does Radically Open Security do?
Radically Open Security is a non-profit computer security consultancy providing project-based security assessment services to organizations. Its portfolio includes penetration testing of web, mobile, network, infrastructure, and cloud systems, as well as code audits, hardware/embedded/IoT testing, cryptographic and protocol audits, red/purple team exercises, incident response, ISO 27001 compliance assessments, social engineering and phishing simulations, DDoS and physical security testing, and security training. Clients range from large multinationals and governments to NGOs, open-source projects, and SMBs.
Is Radically Open Security a public or private company?
Radically Open Security is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was Radically Open Security founded?
Radically Open Security was founded in 2014. It employs 11 to 50 people.
Where is Radically Open Security based?
Radically Open Security is headquartered in Amsterdam, Netherlands, in the Europe region.
How does Radically Open Security make money?
One revenue line is on record: security Consulting Services.
Who are Radically Open Security's main competitors?
Direct peers on record are Cure53, Trail of Bits, Coalfire, Bishop Fox and Praetorian. Emerging players are HackerOne and Bugcrowd. NCC Group is listed as a broad incumbent.
Does Radically Open Security have an API?
No public API is recorded for Radically Open Security.
What industry is Radically Open Security in?
Radically Open Security's product category is Cybersecurity Consulting. Its primary akta.pro industry code is BPAEADAD, Vulnerability Management & Penetration Testing Services, with a secondary code of EDAOAIAH, Penetration Testing, Red Team & Ethical Hacking. Its NAICS code is 5415 and its SIC code is 7370.