softScheck
softScheck is a German cybersecurity consultancy, founded 1998, delivering penetration testing, fuzzing, threat modeling, and AI/LLM security testing to enterprise clients across Europe and APAC via direct sales and a five-step Security Testing Process methodology.
- Company typePrivate
- Founded1998
- HeadquartersSankt Augustin, Germany
- Headcount11–50
- GTM typeB2B
- OfferingServices
What softScheck does
softScheck GmbH is a privately held German cybersecurity consulting firm founded in 1998 and headquartered in Sankt Augustin, Germany, with wholly-owned regional subsidiaries in Singapore (APAC headquarters), Malaysia, and Indonesia. The firm sells B2B professional security testing services to enterprise clients across industries including security software, reinsurance, healthcare IT, telecommunications, medical technology, and energy. Named customers include Ergon Informatik AG, Hannover Re, InterComponentWare AG, Allianz, NetCologne, Storz Medical, and Juice.
The company's core offering is a five-step Security Testing Process that integrates six security testing services — Threat Modeling, Static Source Code Analysis, Fuzzing, Vulnerability Assessment, Penetration Testing, and AI & LLM Pentesting — with broader consulting including compliance services for NIS2, DORA, EU AI Act, and BSI IT-Grundschutz, as well as workshops, forensics, requirements analysis, and incident response support. Proprietary technology includes the softScheck Cloud Fuzzer Framework (sCFF), a Python-based distributed fuzzing system built on American fuzzy lop and AWS EC2, plus open-source contributions such as Log4Shell detection tooling and TP-Link reverse engineering utilities. The firm also issues a market-differentiated ISO 27034-based Security Certificate with a 2-year validity period.
The business model is sales-led professional services with project-based and time-and-materials contracts priced via consultant day rates, supplemented by fixed-price engagements and 2-year recurring revenue from Security Certificate renewals. Go-to-market relies entirely on direct enterprise sales, inbound inquiries, referrals, and a partner channel that includes VamiSec GmbH, Labrador Labs, DEKRA, and infinIT Services. Marketing emphasizes thought leadership via technical blog content, open-source tool releases, and documented zero-day vulnerability discoveries (tcpdump, Log4j, Zammad CVE-2022-35487, TP-Link products). Revenue is not publicly disclosed and the firm operates without disclosed external institutional funding.
softScheck firmographics
Firmographics- Name
- softScheck
- Legal name
- softScheck GmbH
- Website
- https://softscheck.com
- Company type
- Private
- Founded year
- 1998
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- softScheck is a German cybersecurity consultancy, founded 1998, delivering penetration testing, fuzzing, threat modeling, and AI/LLM security testing to enterprise clients across Europe and APAC via direct sales and a five-step Security Testing Process methodology.
- Ownership category
- akta.pro rank
softScheck industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Other Computer Related Services (541519), Computer Systems Design and Related Services (54151)
- SIC
- Services-Testing Laboratories (8734)
- akta.pro primary industry
- Vulnerability Management & Penetration Testing Services (BPAEADAD)
- akta.pro secondary industries
- Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG), Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
Keywords
Where softScheck is headquartered
LocationHeadquarters
- HQ city
- Sankt Augustin
- HQ country
- Germany
- HQ region
- Europe
Offices4 records
Markets served
softScheck business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales
Revenue model
- Security Testing Services: Professional services revenue generated from delivering security assessments including penetration testing, vulnerability assessments, threat modeling, static/dynamic code analysis, and fuzzing. Services are priced based on day rates for consultants with fixed or time-and-materials contracts. Each project involves a 5-step Security Testing Process methodology.
- Security Consulting: Advisory services covering security strategy, compliance requirements (NIS2, DORA, BSI IT-Grundschutz), and security architecture development. Consulting engagements follow structured methodologies and are delivered by experienced security professionals.
- Security Workshops: Training and workshop services delivered both online and in-person covering various IT security topics. Conducted by company security experts for client teams.
- Security Certificates: ISO 27034-based Security Certificate issuance following the softScheck Security Testing Process. Certificates are valid for 2 years and include testing against at least 6 methods. Pricing depends on complexity and scope of the tested product or system.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Consulting day rates based on consultant expertise level |
| One time/ perpetual license | Multi-year contract | Fixed-price project contracts for defined deliverables |
| Other | Multi-year contract | Security certification fees based on product scope |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels4 records
softScheck product offering
Product offeringCore offering
softScheck delivers cybersecurity consulting and security testing services for enterprise clients, covering six integrated security testing methods (Penetration Testing, Threat Modeling, Static Source Code Analysis, Fuzzing, Vulnerability Assessment, and AI & LLM Pentesting). The company also offers Security Consulting, Workshops, Forensics, Requirements Analysis, Cyber Risk Assessment, Compliance Services (NIS2, DORA, EU AI Act, BSI IT-Grundschutz), and an ISO 27034-based Security Certificate for product certification.
Product overview
softScheck is a cybersecurity consulting company offering a comprehensive portfolio of security testing and consulting services. The core offerings include six integrated security testing services: Threat Modeling, Static Code Analysis, Fuzzing, Vulnerability Assessment, Penetration Testing, and AI & LLM Pentesting. These are complemented by consulting services including Security Consulting, Workshops, Forensics, Requirements Analysis, Cyber Risk Assessment, Compliance Services, Compliance Self-Assessment, CyberRisikoCheck, and IT-Grundschutz. The company also provides an ISO 27034-based Security Certificate for product certification. Together, these services cover the entire security lifecycle from Secure by Design through to AI model testing and certification.
Differentiator
Problem solved
Functional benefit
Products and services
- Penetration Testing Manual and automated penetration testing for web and mobile applications, internal/external infrastructure, IoT products, and Red Teaming, including vulnerability assessment and zero-day vulnerability identification. Targeted at enterprise organizations and technology companies.
- Threat Modeling Individual threat modeling for trusted system design in early development phases, following a 9-step methodology including documentation analysis, DFD creation, threat identification, and mitigation strategies.
- Static Source Code Analysis Tool-based and semi-automated static code analysis technique that examines source code without execution (white box testing) using style-checking, semantic analysis, and deep flow static analysis tools.
- Fuzzing Dynamic analysis method for identifying previously unknown vulnerabilities (Zero-Day and Less-Than-Zero-Day) in software and firmware using semi-automated fuzzing tools with malformed input data.
- Vulnerability Assessment Identification, classification, and prioritization of security vulnerabilities in computer systems, applications, and network infrastructure using a four-step process: Asset Discovery, Vulnerability Scanning, Risk Evaluation, and Mitigation.
- AI & LLM Pentesting Adversarial testing of AI systems and LLM applications covering Prompt Injection, model attacks, and supply-chain risks in AI implementations.
- Security Consulting IT security consulting based on a five-step Security Testing Process, covering all aspects of IT security including strategy, compliance, and architecture.
- Workshops Online and in-person workshops on various IT security topics, designed and conducted by softScheck's expert consultants for client teams and security professionals.
- Forensics Forensic investigation services to support incident response and analyze digital evidence.
- Requirements Analysis Security requirements analysis to identify and define security needs for projects and systems.
- Cyber Risk Assessment Assessment of cyber risks to identify, evaluate, and prioritize security threats and vulnerabilities.
- Compliance Services Compliance consulting covering regulatory requirements including NIS2, DORA, EU AI Act, and other security standards.
- Compliance Self-Assessment Self-assessment tools and guidance for evaluating compliance with security standards and regulations.
- CyberRisikoCheck Cyber risk check service for quick assessment of organizational security posture.
- IT-Grundschutz Consulting IT security consulting based on BSI IT-Grundschutz (German Federal Office for Information Security) standards and methodology.
- softScheck ISO 27034-based Security Certificate Security certification service based on ISO 27034 standards, certifying product security quality against softScheck's Security Testing Process criteria. Certificate is valid for 2 years and references at least 6 testing methods.
Quantifiable outcome
- Identified tcpdump 4.9 vulnerability using cloud fuzzing in approximately 5 hours total (110 minutes fuzzing phase) at ~$0.25 EC2 cost
- +2 more outcomes
Companies that use softScheck
Customer profileNamed customers7 records
Segments3 records
Ideal customer profiles3 records
softScheck technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability2 records
Feature4 records
softScheck partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered core and minor.
- VamiSec GmbHcoreInformation security consulting firm based in Bonn, Germany with extensive experience developing and implementing IT security strategies across more than 100 completed projects. Core competencies include securing cloud and on-premises environments to ISO 27001, TISAX, and BSI IT-Grundschutz, as well as implementing NIS2, DORA, and EU AI Act requirements from strategy through certification.
- Labrador LabscoreCybersecurity company focused on developing automated solutions for software vulnerability detection. Leverages innovative technologies in cybersecurity, AI, and software engineering to help businesses protect software against potential threats. Committed to creating a safer digital ecosystem through automated vulnerability detection.
- infoteam Software AGminorEstablished provider of software solutions and services for industry, life science, and medical technology since 1983. Offers certified quality management systems according to ISO 9001 and ISO 13485, as well as certified development processes for safety-oriented software according to IEC 61508.
- infinIT Services GmbHminorProvides services, solutions, and products for modern, secure, and reliable communication in networked environments. With approximately 550 employees in Germany, Netherlands, and Poland, offers customer experience, network communication solutions, custom software development, testing productivity, and web portal solutions.
- Business Future ConsultingminorConsultancy company active in DACH region combining digitalization and demographic change with megatrend Future Work. Core competency is holistic concept of individual FUTURE WORKFORCE for SMEs and design of FUTURE WORKSPACES for enterprise development.
- FSPminorProvides software and services to create secure digital customer and business processes. Since 2001, FSP has specialized in identity and access management consulting from requirements analysis through introduction and operation. Products cover authentication and authorization requirements for B2C, B2B, B2E, and IoT areas.
- DEKRA Business Assurance Service GmbHminorEnsures people's security when dealing with technology and environment. Creates more security in traffic, work, and home environments through experienced expert services.
- University Of Digital ScienceminorEurope's first 100% digitally designed, platform-based university. Stands for unique approach to teaching, learning, and research, empowering graduates and leaders to create value through deep digital understanding and rigorous analysis with action, experimentation, and creativity.
Scale indicators2 records
Recent moves1 record
Expansion highlights5 records
softScheck competitors and assessment
Company assessmentDirect peers
- Bishop Fox: US-based offensive-security firm offering penetration testing, red teaming, and security research. Closely comparable service portfolio to softScheck's testing practice and similar research-led brand positioning.
- Secarma: UK-based penetration testing and red-team consultancy offering similar web, mobile, infrastructure, and IoT testing services as softScheck, often competing for European enterprise contracts.
- Trail of Bits: Security consulting and research firm focused on software audits, cryptography reviews, and tooling (e.g., fuzzing frameworks). Directly comparable to softScheck's combination of expert services plus proprietary tooling like sCFF.
- SRLabs (Security Research Labs): Berlin-based security research and consulting firm with comparable mix of expert services, vulnerability research, and published disclosures — a research-driven boutique competitor to softScheck in DACH.
- Cure53: Berlin-based boutique cybersecurity firm specializing in penetration testing, code audits, and security research. Closest German competitor to softScheck in scope (web/mobile/firmware testing), team size, and customer profile.
- RedTeam Security: US firm focused on penetration testing, red team operations, and security assessments. Similar boutique scale and service mix to softScheck's pen testing practice.
Broad incumbents
- Trustwave: Global cybersecurity firm offering managed security testing, MDR, and consulting. Competes with softScheck on enterprise penetration testing but operates at significantly larger scale with a broader portfolio.
- NCC Group: Global cybersecurity consulting and assurance firm offering penetration testing, red teaming, and software security services at much larger scale. Competes with softScheck for enterprise testing mandates but with a far broader portfolio.
Emerging players
- HackerOne: Bug bounty and vulnerability disclosure platform that competes for part of the same security-testing budget softScheck targets, particularly around vulnerability identification and disclosure workflows.
- Code Intelligence: German startup commercializing automated fuzz testing (CI Fuzz) for developer pipelines. Overlaps with softScheck's fuzzing service line but is productizing it as a SaaS/dev tool rather than a service.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks5 records
Key highlights6 records
Customer concentration
softScheck social profiles
Digital presencesoftScheck compliance and trust
Trust signalCompliance1 record
softScheck financial estimates
Financial estimateRevenue estimate
Valuation estimate
softScheck leadership team
Management profileNumber of profiles
Profiles4 records
softScheck subsidiaries and ownership
Company hierarchySubsidiaries3 records
softScheck funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
softScheck M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about softScheck
What does softScheck do?
softScheck delivers cybersecurity consulting and security testing services for enterprise clients, covering six integrated security testing methods (Penetration Testing, Threat Modeling, Static Source Code Analysis, Fuzzing, Vulnerability Assessment, and AI & LLM Pentesting). The company also offers Security Consulting, Workshops, Forensics, Requirements Analysis, Cyber Risk Assessment, Compliance Services (NIS2, DORA, EU AI Act, BSI IT-Grundschutz), and an ISO 27034-based Security Certificate for product certification.
Is softScheck a public or private company?
softScheck is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was softScheck founded?
softScheck was founded in 1998. It employs 11 to 50 people.
Where is softScheck based?
softScheck is headquartered in Sankt Augustin, Germany, in the Europe region.
How does softScheck make money?
Four revenue lines are on record. Security Testing Services are the primary driver. The others are security Consulting, security Workshops and security Certificates.
Who are softScheck's main competitors?
Direct peers on record are Bishop Fox, Secarma, Trail of Bits, SRLabs (Security Research Labs), Cure53 and RedTeam Security. Broad incumbents are Trustwave and NCC Group. Emerging players are HackerOne and Code Intelligence.
Does softScheck have an API?
No public API is recorded for softScheck.
What industry is softScheck in?
softScheck's product category is Cybersecurity Services. Its primary akta.pro industry code is BPAEADAD, Vulnerability Management & Penetration Testing Services, with a secondary code of BPAKAHAG, Vulnerability Assessment, Security Audits & Compliance Testing. Its NAICS code is 541519 and its SIC code is 8734.