Vaddy
VAddy, operated by Tokyo-based Bitforest Co., Ltd., is a cloud-based web application vulnerability scanner that integrates with CI/CD pipelines to automate security testing for developers, DevOps teams, and enterprise/mid-market/SMB organizations across 58 countries.
- Company typePrivate
- Founded2002
- HeadquartersTokyo, Japan
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Vaddy does
VAddy is a cloud-based automated web application vulnerability scanner operated by Bitforest Co., Ltd., a privately held Japanese software company headquartered in Tokyo and founded in February 2002. Bitforest launched VAddy as a beta in October 2014 as a continuous web security testing service that integrates with developer CI/CD pipelines. The same development team created Scutum, which has held the No. 1 market share in Japan's SaaS-based Web Application Firewall market for 12 consecutive years since 2009. VAddy is positioned for developers, DevOps teams, and security-conscious organizations across SMB, mid-market, and enterprise segments, with active users in 58 countries and 2,000+ registered developers.
VAddy's core technology combines a proprietary machine learning-based scanning engine with deep CI/CD-native integration. Supported integrations include Jenkins (via official plugin), CircleCI, TravisCI, Drone, and Bitbucket; an open WebAPI plus official CLI clients (Go, Ruby) and a Chrome/Edge browser extension enable automated crawl creation, IDaaS-aware authentication (Auth0, Cognito, Azure AD B2C), REST API/JSON scanning for mobile apps and SPAs, multi-FQDN coverage, IP-based server verification, and a PrivateNet variant for intranet environments. Detection coverage includes SQL injection, stored XSS, SSRF (CWE-918), unauthorized file access, eval injection, and IPA "Safe Website Creation" checklist items. The service is hosted on AWS VPC with data stored in Japan; the company holds ISO/IEC 27001:2022, ISO/IEC 27017:2015 ISMS-CLS, and JIS Q 15001:2017 Privacy Mark certifications.
Revenue is generated through tiered monthly SaaS subscriptions: Professional (¥19,800/month, ~¥198,000/year), Enterprise (¥59,800/month, ~¥598,000/year), and Advanced (¥99,800/month, ~¥998,000/year), with an annual billing discount of two months and a 7-day free trial on the Professional tier. Distribution combines product-led growth via self-service online signup, an active sales partner program (notably Beyond Corporation reselling to MSPs), direct enterprise sales and online consultation, and event-driven developer marketing through sponsorships of regional PHP conferences across Japan. Bitforest also operates the related Loggol web attack log analysis tool (launched October 2024) and continues to run Scutum, sharing R&D and brand credibility across the portfolio.
Vaddy firmographics
Firmographics- Name
- Vaddy
- Legal name
- 株式会社ビットフォレスト (Bitforest Co., Ltd.)
- Website
- https://vaddy.net
- Company type
- Private
- Founded year
- 2002
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- VAddy, operated by Tokyo-based Bitforest Co., Ltd., is a cloud-based web application vulnerability scanner that integrates with CI/CD pipelines to automate security testing for developers, DevOps teams, and enterprise/mid-market/SMB organizations across 58 countries.
- Ownership category
- akta.pro rank
Vaddy industry classification
Industry- Product category
- Application Security (Web Vulnerability Scanning)
- NAICS
- Other Computer Related Services (541519)
- SIC
- Services-Computer Programming Services (7371), Services-Testing Laboratories (8734)
- akta.pro primary industry
- Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Data Security & Privacy for Cloud (DLP, DSPM, Tokenization) (HDABAHAK)
Keywords
Where Vaddy is headquartered
LocationHeadquarters
- HQ city
- Tokyo
- HQ country
- Japan
- HQ region
- Asia
Offices1 record
Markets served
Vaddy business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- SaaS Subscription - Professional Plan: Monthly subscription at ¥19,800/month (¥198,000/year) offering 5 vulnerability check items. Fixed-rate unlimited scans.
- SaaS Subscription - Enterprise Plan: Monthly subscription at ¥59,800/month (¥598,000/year) offering 11 check items with additional organization management features. Fixed-rate unlimited scans.
- SaaS Subscription - Advanced Plan: Monthly subscription at ¥99,800/month (¥998,000/year) offering 18 check items compliant with IPA 'Safe Website Creation' guidelines. Fixed-rate unlimited scans.
- OSS Community Support (Free): Free Professional plan provided to qualifying open-source software projects meeting certain criteria
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Monthly | Advanced Plan - ¥99,800/month - 18 vulnerability check items |
| Subscription | Monthly | Enterprise Plan - ¥59,800/month - 11 vulnerability check items |
| Subscription | Monthly | Professional Plan - ¥19,800/month - 5 vulnerability check items |
Go-to-market motion3 records
Distribution channels3 records
Marketing channels6 records
Vaddy product offering
Product offeringCore offering
VAddy is a cloud-based, automated web application vulnerability scanner that integrates with CI/CD pipelines to perform continuous security testing on every code commit. It uses a proprietary machine learning scanning engine to detect OWASP Top 10 issues such as SQL injection, XSS, SSRF, and eval injection without requiring developers to have specialized security expertise. The service is sold in three monthly subscription tiers (Professional, Enterprise, Advanced) and is used by over 2,000 developers across 58 countries.
Product overview
VAddy is a Japanese cloud-based web vulnerability scanner designed for DevOps teams, developed and operated by Bitforest Co., Ltd. The product portfolio consists of the core VAddy vulnerability scanning service (with Professional, Enterprise, and Advanced tiered plans), paired with related Bitforest products including Scutum (cloud-based WAF with 12+ years of domestic market leadership) and Loggol (web attack log analysis tool). VAddy integrates with AI test automation platform MagicPod. The service enables developers to perform automated security testing without specialized security expertise, integrates with CI/CD pipelines, and has been used by over 2,000 developers across 58 countries since its 2014 beta launch.
Differentiator
Problem solved
Functional benefit
Products and services
- VAddy (Web Vulnerability Scanner) Cloud-based, automated web application vulnerability scanner that integrates with CI/CD pipelines to perform continuous security testing on every code change. Detects SQL injection, XSS, SSRF, eval injection and other OWASP Top 10 issues without requiring specialized security expertise. Sold in three monthly subscription tiers (Professional ¥19,800/mo, Enterprise ¥59,800/mo, Advanced ¥99,800/mo) for developers, DevOps teams, and enterprises.
- Scutum (Cloud-based WAF) Cloud-based Web Application Firewall (WAF) developed and operated by Bitforest Co., Ltd. The first SaaS-type WAF in the world and No.1 in Japan's SaaS-type WAF market for 12 consecutive years. Sells separately from VAddy as a complementary runtime web security product from the same company.
- Loggol (Web Attack Log Analysis) Cloud-based web attack log analysis tool released October 2024 by Bitforest. Analyzes website access logs to detect cyber attack traces and is commonly used together with VAddy for comprehensive web security monitoring.
Quantifiable outcome
- Used by 2,000+ developers across 58 countries
- +2 more outcomes
Companies that use Vaddy
Customer profileNamed customers12 records
Segments1 record
Ideal customer profiles4 records
Vaddy technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration16 records
AI capability2 records
Feature6 records
Vaddy partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core and minor.
- NPO Baser Foundation / baserCMScoreFirst OSS project receiving free VAddy Professional plan. baserCMS integrates VAddy into their development process, requiring all releases to pass VAddy security checks. Feedback from baserCMS helps improve VAddy's scanning capabilities.
- Beyond (株式会社ビヨンド)coreOfficial sales partner that resells VAddy and provides diagnostic proxy services to their MSP (Managed Service Provider) customers. Beyond uses VAddy for their own diagnostic services and recommends it to clients.
- SHIFT SECURITY (株式会社SHIFT SECURITY)minorManual vulnerability diagnosis service partner for VAddy's Platinum+ plan (now ended). Provides expert manual security assessment complementing VAddy's automated scanning.
Scale indicators3 records
Recent moves6 records
Expansion highlights6 records
Vaddy competitors and assessment
Company assessmentBroad incumbents
- Rapid7 (InsightAppSec): Security analytics platform offering DAST through InsightAppSec alongside broader vulnerability management and SIEM. Comparable to VAddy on web application vulnerability scanning but operating as a broad incumbent with much wider portfolio.
- Qualys (Web App Scanning): Broad cloud security and compliance platform offering web application scanning as part of a wider vulnerability management portfolio. Comparable to VAddy on DAST functionality though positioned as a broader incumbent rather than a DevOps-native tool.
Direct peers
- Checkmarx: Enterprise application security platform offering SAST, DAST, SCA, and API security with developer tooling integrations. Overlaps with VAddy on the DAST and CI/CD integration use cases for web applications.
- Snyk: Developer-first application security platform offering DAST, SAST, SCA, and container security integrated into CI/CD pipelines. Directly comparable to VAddy on developer-led DAST workflow, multi-language support, and CI-native integration model.
- Detectify: Crowdsourced DAST platform with continuous web application scanning and asset monitoring. Comparable to VAddy on SaaS-based continuous vulnerability testing for web applications.
- StackHawk: Developer-centric DAST platform purpose-built for CI/CD pipelines with strong shift-left positioning. Comparable to VAddy on developer-first UX, CI integration, and SaaS delivery model for web app scanning.
- Veracode: Enterprise application security testing platform providing DAST, SAST, and software composition analysis with pipeline integration. Comparable to VAddy on web application vulnerability scanning use case and enterprise compliance positioning.
- PortSwigger (Burp Suite): Provider of Burp Suite, the dominant web vulnerability scanner used by security professionals and pen testers. Comparable to VAddy on core web application security testing capability, though more pen-tester oriented.
- Invicti (formerly Netsparker): DAST-focused web application security scanner with proof-based scanning and CI/CD integrations. Directly competes with VAddy in automated web vulnerability detection for DevOps teams.
Emerging players
- OWASP ZAP: Open-source web application security scanner maintained by the OWASP Foundation. Used by VAddy customers (e.g., GMO Pepabo) alongside VAddy for multi-layered security, representing both a complementary tool and a free-tier competitor for budget-conscious buyers.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
Vaddy social profiles
Digital presenceVaddy compliance and trust
Trust signalCompliance4 records
Vaddy financial estimates
Financial estimateRevenue estimate
Valuation estimate
Vaddy leadership team
Management profileNumber of profiles
Profiles3 records
Vaddy funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Vaddy M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Vaddy
What does Vaddy do?
VAddy is a cloud-based, automated web application vulnerability scanner that integrates with CI/CD pipelines to perform continuous security testing on every code commit. It uses a proprietary machine learning scanning engine to detect OWASP Top 10 issues such as SQL injection, XSS, SSRF, and eval injection without requiring developers to have specialized security expertise. The service is sold in three monthly subscription tiers (Professional, Enterprise, Advanced) and is used by over 2,000 developers across 58 countries.
Is Vaddy a public or private company?
Vaddy is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Vaddy founded?
Vaddy was founded in 2002. It employs 1 to 10 people.
Where is Vaddy based?
Vaddy is headquartered in Tokyo, Japan, in the Asia region.
How does Vaddy make money?
Four revenue lines are on record. SaaS Subscription - Professional Plan is the primary driver. The others are saaS Subscription - Enterprise Plan, saaS Subscription - Advanced Plan and OSS Community Support (Free).
Who are Vaddy's main competitors?
Broad incumbents on record are Rapid7 (InsightAppSec) and Qualys (Web App Scanning). Direct peers are Checkmarx, Snyk, Detectify, StackHawk, Veracode, PortSwigger (Burp Suite) and Invicti (formerly Netsparker). OWASP ZAP is listed as an emerging player.
Does Vaddy have an API?
Yes. VAddy provides a WebAPI that allows developers to programmatically control vulnerability scanning functions. The API enables integration with CI/CD pipelines for automated security testing. Available operations include starting scans, retrieving scan results, and managing crawl data. VAddy offers official CLI tools (go-vaddy command-line tool in Go, VAddy Ruby client library) and Jenkins plugin for CI integration via the API. Developer documentation is at support.vaddy.net/hc/ja/sections/115001726188.
What industry is Vaddy in?
Vaddy's product category is Application Security (Web Vulnerability Scanning). Its primary akta.pro industry code is HDADACAC, Application Security Testing (SAST/DAST/IAST/SCA), with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 541519 and its SIC code is 7371.