Sandline
Sandline is a Bucharest-based European cybersecurity firm providing offensive security services and Centraleyezer, its proprietary RBVM platform, to regulated EU enterprises in banking, healthcare, energy, government, telecoms and manufacturing.
- Company typePrivate
- Founded2017
- HeadquartersBucharest, Romania
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Sandline does
Sandline is a European cybersecurity firm headquartered in Bucharest, Romania, providing offensive security services and audit-ready compliance evidence to regulated EU enterprises. The firm runs red team exercises, penetration tests, vulnerability management programmes, human-vulnerability assessments, cyber threat intelligence, incident response retainers and security training for organisations subject to NIS2, DORA, ISO 27001, PCI-DSS, the EU Cyber Resilience Act and GDPR. Its stated positioning is that of a small, senior-only team — every engagement is led end-to-end by an engineer with 10+ years of relevant experience, with no junior subcontracting.
Sandline builds and operates Centraleyezer, its proprietary Risk-Based Vulnerability Management (RBVM) SaaS platform. Centraleyezer's six-factor contextual risk scoring model — combining DREAD, asset criticality, network exposure, in-environment exploitability, sector-specific cyber threat intelligence signals and a Human-AI feedback loop — is the same model used to score findings across all Sandline service engagements, ensuring consistent prioritisation between product and delivery. The platform integrates with major vulnerability scanners (Nessus, Tenable, Qualys, Rapid7, Burp Suite Enterprise, Acunetix, AWS Inspector, Trivy, OpenVAS) plus custom REST API sources, deduplicates findings into a single prioritised backlog, and maps each finding to specific article and sub-clause references across multiple regulatory frameworks.
Revenue is generated through two streams: fixed-price professional services engagements (no hourly billing, written scope delivered within three working days of the first call) and recurring Centraleyezer SaaS subscriptions, with a 90-day free Engagement Workspace bundled into every services engagement to seed SaaS conversion. Go-to-market is direct, senior engineer-led, with no channel or reseller partners, targeting six regulated verticals — Banking & Finance, Healthcare, Energy & Utilities, Government & Defence, Telecommunications, and Manufacturing — plus a fixed-scope offering for regulated SMBs. The company is privately held and founder-controlled, with no disclosed external funding and no M&A history.
Sandline firmographics
Firmographics- Name
- Sandline
- Legal name
- Sandline SRL
- Website
- https://sandline.ro
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Sandline is a Bucharest-based European cybersecurity firm providing offensive security services and Centraleyezer, its proprietary RBVM platform, to regulated EU enterprises in banking, healthcare, energy, government, telecoms and manufacturing.
- Ownership category
- akta.pro rank
Sandline industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Computer Systems Design and Related Services (5415), Other Computer Related Services (541519), Other Scientific and Technical Consulting Services (54169)
- SIC
- Services-Management Consulting Services (8742), Services-Prepackaged Software (7372)
- akta.pro primary industry
- Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG)
- akta.pro secondary industries
- Governance, Risk & Compliance (GRC) Advisory & Assessments (BPAKAHAH), Security Awareness, Training & Compliance Attestation (HDADAIAJ)
Keywords
Where Sandline is headquartered
LocationHeadquarters
- HQ city
- Bucharest
- HQ country
- Romania
- HQ region
- Europe
Offices1 record
Markets served
Sandline business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Professional Security Services: Fixed-price professional services engagements covering red team, penetration testing, vulnerability assessment, human vulnerability (phishing/social engineering), cyber threat intelligence, incident response, and cybersecurity training. Pricing is agreed per written scope with no hourly billing and no end-of-engagement surprises. Standard lead time of 2–3 weeks from SOW signature for pentests or vulnerability assessments. Incident response retainers kick off within 5 working days.
- Centraleyezer SaaS Subscription: After the 90-day free Engagement Workspace included with every engagement, clients can extend Centraleyezer as a paid SaaS subscription for ongoing managed vulnerability programmes. Self-hosted deployment is also available. Revenue is subscription-based (recurring).
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| One time/ perpetual license | Multi-year contract | Professional Services — Fixed-scope per engagement |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels4 records
Sandline product offering
Product offeringCore offering
Sandline delivers seven professional cybersecurity services to regulated EU organisations — Red Team operations, Penetration Testing, Vulnerability Assessment, Human Vulnerability (phishing, vishing, physical), Cyber Threat Intelligence, Incident Response & Recovery, and Cybersecurity Training — together with Centraleyezer, its proprietary Risk-Based Vulnerability Management SaaS platform that applies a six-factor contextual risk scoring model. Every engagement is led end-to-end by a senior engineer (10+ years experience), priced on a fixed-scope basis, and ships findings pre-mapped to NIS2, DORA, ISO 27001, PCI-DSS, CRA and GDPR by article and sub-clause so clients receive reusable audit evidence rather than separate per-framework reports.
Product overview
Sandline's product portfolio centers on the Centraleyezer RBVM platform, supplemented by a bundled Engagement Workspace (90-day free SaaS deployment included with every service engagement). Seven discrete services — Red Team, Penetration Testing, Vulnerability Assessment, Human Vulnerability, Cyber Threat Intelligence, Incident Response & Recovery, and Cybersecurity Training — operate independently while being powered by and feeding into the Centraleyezer platform. Centraleyezer scores all findings using the same six-factor contextual model for both the platform and service delivery, ensuring consistent risk-based prioritization across the portfolio.
Differentiator
Problem solved
Functional benefit
Brands
- Centraleyezer: Risk-Based Vulnerability Management (RBVM) platform built and operated by Sandline. Scores findings by real business risk using a six-factor contextual model.
Products and services
- Red Team Realistic adversary simulation that measures how a client's detection, response and people behave under a sustained attack, for organisations that must evidence offensive-security testing under NIS2, DORA, ISO 27001, PCI-DSS, CRA and GDPR.
- Penetration Testing Targeted, scope-bounded penetration testing of an application, network segment, cloud account or product, including DORA/TLPT and PCI-DSS 4.0 pentests, producing audit evidence and a prioritised fix plan for regulated EU organisations.
- Vulnerability Assessment Continuous, contextual vulnerability management across infrastructure, web estate and code, powered by the Centraleyezer RBVM platform, for organisations needing NIS2 Article 21, DORA Article 9, PCI-DSS Requirement 6 and ISO 27001 Annex A.8.8 evidence.
- Human Vulnerability Phishing simulation, vishing and physical-access exercises that measure how an organisation's people behave under realistic social-engineering pressure, supporting awareness programmes for regulated entities.
- Cyber Threat Intelligence Sector-specific threat intelligence that feeds detection content, vulnerability prioritisation and incident response playbooks, focused on active actor TTPs relevant to EU sectors (banking, energy, healthcare, government, telecom, manufacturing).
- Incident Response & Recovery On-retainer or on-demand response to confirmed incidents, covering containment, forensics, recovery and regulatory notification packages aligned with NIS2 (24h/72h/1-month), GDPR (72h) and DORA Article 17 timelines. Standard kick-off within 5 working days and median sub-24h containment on retainer.
- Cybersecurity Training Role-based cybersecurity training for engineers, security teams and boards, including hands-on labs rather than slide decks, supporting awareness programmes aligned with NIS2 and DNSC requirements.
- Centraleyezer Risk-Based Vulnerability Management (RBVM) SaaS platform that scores findings by real business risk using a six-factor contextual model (DREAD, asset criticality, network exposure, exploitability, CTI signals, Human-AI feedback loop), integrates with Nessus, Tenable, Qualys, Rapid7, Burp Suite Enterprise, Acunetix, AWS Inspector, Trivy and OpenVAS, tracks remediation against SLAs, and produces audit evidence mapped to NIS2, DORA, ISO 27001, PCI-DSS, CRA and GDPR by article and sub-clause.
Quantifiable outcome
- 60% reduction in critical-risk findings after a Sandline-led remediation cycle, typically within the first six months
- +3 more outcomes
Companies that use Sandline
Customer profileNamed customers6 records
Segments7 records
Ideal customer profiles2 records
Sandline technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration10 records
AI capability3 records
Feature5 records
Sandline partnerships and signals
Strategic signalScale indicators5 records
Recent moves6 records
Expansion highlights6 records
Sandline competitors and assessment
Company assessmentDirect peers
- Bishop Fox: US boutique offensive security firm focused on continuous pentesting, red team and adversary simulation for enterprise CISOs - closely mirrors Sandline's senior-engineer boutique positioning.
- NCC Group: UK-listed cybersecurity firm with a comparable senior-engineer-led offensive security (pentest, red team), vulnerability management, and GRC advisory practice serving regulated UK/EU enterprises. Closely aligned business model to Sandline.
- SEC Consult: Austrian-headquartered boutique offensive security firm conducting pentests, red team, vulnerability management, and ISO 27001 advisory across DACH and EU - same boutique European offensive security model as Sandline.
- Orange Cyberdefense: European MSSP and offensive security arm of Orange, providing pentest, threat intelligence, IR and managed vulnerability services across EU regulated industries - directly comparable European competitor.
- NetSPI: US-based offensive security firm specializing in pentesting, red team, attack surface management and vulnerability management for regulated enterprises - directly comparable service offering to Sandline.
- WithSecure: Finnish-headquartered European cybersecurity firm offering offensive security, vulnerability management, and managed detection - a direct European competitor with similar regulatory-driven positioning.
- Coalfire: US-based offensive security and cyber risk advisory firm delivering pentesting, red team and compliance (PCI-DSS, ISO 27001, HITRUST) services for regulated enterprises - comparable delivery model and regulatory focus.
Broad incumbents
- Qualys: Public US VMDR platform vendor whose Qualys VMDR product Centraleyezer integrates with and against which Centraleyezer competes as a contextual RBVM alternative.
- Rapid7: Public US cybersecurity firm combining InsightVM (RBVM, integrated with Centraleyezer) with managed security services, representing a broader incumbent alternative for the same buyers.
- Tenable: Public US company and market-leading RBVM platform (Nessus/Tenable.io) whose scanner products Centraleyezer integrates with. Competes with Centraleyezer on the platform layer and operates a much larger services/MSSP practice as a broad incumbent.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks7 records
Key highlights7 records
Customer concentration
Sandline social profiles
Digital presenceSandline compliance and trust
Trust signalCompliance16 records
Sandline financial estimates
Financial estimateRevenue estimate
Valuation estimate
Sandline leadership team
Management profileNumber of profiles
Sandline funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Sandline M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Sandline
What does Sandline do?
Sandline delivers seven professional cybersecurity services to regulated EU organisations — Red Team operations, Penetration Testing, Vulnerability Assessment, Human Vulnerability (phishing, vishing, physical), Cyber Threat Intelligence, Incident Response & Recovery, and Cybersecurity Training — together with Centraleyezer, its proprietary Risk-Based Vulnerability Management SaaS platform that applies a six-factor contextual risk scoring model. Every engagement is led end-to-end by a senior engineer (10+ years experience), priced on a fixed-scope basis, and ships findings pre-mapped to NIS2, DORA, ISO 27001, PCI-DSS, CRA and GDPR by article and sub-clause so clients receive reusable audit evidence rather than separate per-framework reports.
Is Sandline a public or private company?
Sandline is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Sandline founded?
Sandline was founded in 2017. It employs 11 to 50 people.
Where is Sandline based?
Sandline is headquartered in Bucharest, Romania, in the Europe region.
How does Sandline make money?
Two revenue lines are on record. Professional Security Services are the primary driver. The others are centraleyezer SaaS Subscription.
Who are Sandline's main competitors?
Direct peers on record are Bishop Fox, NCC Group, SEC Consult, Orange Cyberdefense, NetSPI, WithSecure and Coalfire. Broad incumbents are Qualys, Rapid7 and Tenable.
Does Sandline have an API?
No public API is recorded for Sandline.
What industry is Sandline in?
Sandline's product category is Cybersecurity Services. Its primary akta.pro industry code is BPAKAHAG, Vulnerability Assessment, Security Audits & Compliance Testing, with a secondary code of BPAKAHAH, Governance, Risk & Compliance (GRC) Advisory & Assessments. Its NAICS code is 5415 and its SIC code is 8742.