Risk Hunter
Risk Hunter is a Paris-based, French-founded software company that sells an AI-native Cyber GRC (Governance, Risk, and Compliance) Operating System to EU-regulated enterprises. The platform unifies four proprietary engines (ODYSSY, QANTIX, YOKAY, Core) and 11 modules to help CISOs, CIOs, AI leaders, and compliance officers prioritize cyber, AI, and third-party risks under NIS2, DORA, and the AI Act.
- Company typePrivate
- Founded2024
- HeadquartersParis, France
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Risk Hunter does
Risk Hunter is a Paris-based, French-incorporated (SASU) software company founded in 2024 that markets an AI-native Cyber GRC (Governance, Risk, and Compliance) Operating System. The platform is built around four proprietary engines: ODYSSY (detection and exposure via a modular scanner and a Risk Graph that correlates vulnerabilities to business risk), QANTIX (a fine-tuned business LLM trained on cyber and GRC data that produces decisions in a single pass), YOKAY (action orchestration and methodology-aware automation), and CORE (the underlying GRC and risk structuring layer). On top of these engines, the platform exposes 11 natively interconnected modules covering Cyber Risk Management, Internal Audit, Internal Control, GDPR, ERM, TPRM, Incident Management, IS Mapping, Architecture Audit, Project Security, and Documentary Audit, with claimed outcomes such as EBIOS RM risk analysis reduced from 32 days to under 30 minutes and compliance operating cost reductions of 80-95%.
The company's revenue model is a SaaS subscription segmented by customer size (Scale-up, ETI 250-5,000 employees, Large Enterprise 5,000+ employees), with a ROI calculator and a free 30-minute diagnostic as the lead-generation mechanisms. Go-to-market is direct enterprise field sales targeting CISOs, CIOs, AI leaders, compliance officers, and board-level buyers in EU-regulated sectors — financial services (DORA), critical infrastructure (NIS2), healthcare, telecom, rail, and defense — with EU/France data hosting to support sovereignty requirements. Named customers include SNCF, SFR Business, Pierre Fabre, Laboratoires Théa, Abivax, KBP Biomak, ACRIM Medical Imaging, Unéo, Synchrone, Sequence Cyber, Teragone Solutions, and Université d'Ingénierie, alongside claimed alignment with ISO 27001, ISO 42001, the EU AI Act, NIS2, DORA, the Cyber Resilience Act, and GDPR.
Risk Hunter is privately held, founder-owned (Gérald Aroulanda is the listed publication responsible and primary contact), and operates with 1-10 employees and a share capital of €1,000. The company has not disclosed any institutional funding, revenue, or headcount growth figures, and all performance metrics (97% QANTIX accuracy, 95% analysis-time reduction, 23/23 native criteria benchmark vs. 0-3/23 for legacy GRC/TPRM/Audit tools) are first-party self-reports without independent third-party validation. Patents have been filed on the vulnerability-to-risk correlation methodology, which is the primary defensive IP asset, and the platform's brand architecture spans four sub-brands (ODYSSY, QANTIX, YOKAY, Core) marketed as a unified AI Cyber GRC category.
Risk Hunter firmographics
Firmographics- Name
- Risk Hunter
- Legal name
- Risk Hunter
- Website
- https://riskhunter.io
- Company type
- Private
- Founded year
- 2024
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Risk Hunter is a Paris-based, French-founded software company that sells an AI-native Cyber GRC (Governance, Risk, and Compliance) Operating System to EU-regulated enterprises. The platform unifies four proprietary engines (ODYSSY, QANTIX, YOKAY, Core) and 11 modules to help CISOs, CIOs, AI leaders, and compliance officers prioritize cyber, AI, and third-party risks under NIS2, DORA, and the AI Act.
- Ownership category
- akta.pro rank
Risk Hunter industry classification
Industry- Product category
- Cyber GRC Software
- NAICS
- Computer Systems Design Services (541512)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Enterprise AI Governance, Risk & Compliance Platforms (Model Risk, Audit, Policies) (HDAEANAE)
- akta.pro secondary industries
- AI Governance, Risk & Compliance (GRC) Platforms (HDAAAMAA), Risk, Controls & Governance (GRC) Platforms (FSAFAOAG), IT Governance, Risk & Compliance (IT GRC) Platforms (HDAEALAK)
Keywords
Where Risk Hunter is headquartered
LocationHeadquarters
- HQ city
- Paris
- HQ country
- France
- HQ region
- Europe
Offices1 record
Markets served
Risk Hunter business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Infrastructure, Operations
Revenue model
- SaaS Subscription (AI Cyber GRC Platform): Risk Hunter operates as a SaaS/platform subscription model. The platform is offered as an integrated AI Cyber GRC Operating System covering 11 interconnected modules (Cyber Risk Management, Internal Audit, Internal Control, GDPR Compliance, ERM, TPRM, Incident Management, IS Mapping, Architecture Audit, Project Security, Documentary Audit). Pricing tiers are segmented by company size (Scale-up ≤250 employees, ETI 250–5,000 employees, Large Enterprise 5,000+ employees), with indicative estimated annual savings ranging from €84,784 (Scale-up) to €1,256,800 (ETI) to €14,383,680 (Large Enterprise). The ROI model is driven by dramatic reductions in manual effort: EBIOS RM analysis from 32 days to under 30 minutes, internal audits from 24 days to under 30 minutes, TPRM from 10 days to 5 minutes, and compliance operating cost reductions of 80–95%. The platform also provides a free 30-minute diagnostic as an initial engagement.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Scale-up (≤250 employees) — entry-tier estimated savings |
| Subscription | Annual | ETI (250–5,000 employees) — mid-market estimated savings |
| Subscription | Annual | Large Enterprise (5,000+ employees) — enterprise-tier estimated savings |
Go-to-market motion1 record
Distribution channels2 records
Marketing channels7 records
Risk Hunter product offering
Product offeringCore offering
Risk Hunter provides an AI-native Cyber GRC Operating System that unifies detection, risk structuring, AI reasoning, and action orchestration across cyber, AI, third-party, compliance, controls, audits, and evidence functions. The platform is built on four proprietary engines — ODYSSY (detection and exposure), QANTIX (AI reasoning and decision engine), YOKAY (action orchestration), and Risk Hunter Core (foundational GRC platform) — and is delivered as a SaaS subscription to regulated enterprises primarily in France and the EU.
Product overview
Risk Hunter is an AI-native Cyber GRC Operating System that unifies detection, context, and AI reasoning for sovereign governance. The platform operates as a unified platform-plus-engines architecture combining four core engines (ODYSSY for detection and exposure, QANTIX for AI decision-making, YOKAY for action orchestration, and Risk Hunter Core as the foundational GRC platform) to connect cyber, AI, third parties, compliance, controls, audits, and evidence in a single cockpit. The platform includes 11 interconnected modules covering Cyber Risk Management, Maturity Audit and Certification, Internal Control, Documentary Audit and Legal Compliance, GDPR Compliance, ERM, TPRM, Incident Management, IS Mapping, Architecture Audit, and Security in Projects. Risk Hunter serves multiple roles including CISO and Cyber teams, CIO and IT, AI and Data Leadership, Compliance, Risk and Audit, and Executive and Board members. The platform enables organizations to move from scattered risk data to prioritized, tracked, and proven actions with continuous compliance demonstration.
Differentiator
Problem solved
Functional benefit
Brands
- ODYSSY: Exposure and Detection Engine — a modular risk-driven scanner powered by frugal AI and native correlation via Risk Graph for real-time exploration, correlation and mapping of organizational risk.
- QANTIX
- YOKAY
- ODYSSY
Products and services
- ODYSSY
- QANTIX
- YOKAY
- Risk Hunter Core
- Cyber Risk Management Module
- Maturity Audit, Certification and Accreditation Module
- Internal Control and Permanent Control Module
- Documentary Audit and Legal Compliance Module
- GDPR Compliance Module
- Enterprise Risk Management (ERM) Module
- Third Party Risk Management (TPRM) Module
- Incident Management Module
- IS and Dependencies Mapping Module
- Architecture and Configuration Audit Module
- Security in Projects Module
Quantifiable outcome
- EBIOS RM risk analysis: 32 days → under 30 minutes (99.8% reduction)
- +12 more outcomes
Companies that use Risk Hunter
Customer profileNamed customers12 records
Segments6 records
Ideal customer profiles3 records
Risk Hunter technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability10 records
Feature7 records
Risk Hunter partnerships and signals
Strategic signalScale indicators8 records
Recent moves6 records
Expansion highlights5 records
Risk Hunter competitors and assessment
Company assessmentDirect peers
- Vanta: AI-augmented compliance automation platform serving mid-market and enterprise with continuous control monitoring and audit-ready evidence. Most directly comparable in GTM motion, AI-native framing, and horizontal compliance positioning.
- AuditBoard: Audit, risk, and compliance platform purpose-built for internal audit and SOX teams. Strongly comparable in audit automation, evidence collection, and regulated-industry customer base.
- Drata: Continuous compliance and GRC automation SaaS targeting fast-growing technology companies. Closely comparable in AI-augmented automation, horizontal customer base, and self-serve plus sales-assisted GTM.
- LogicGate: Risk and compliance workflow automation platform with no-code GRC applications. Closely comparable in modular GRC coverage, customizable workflows, and mid-to-large enterprise focus.
Emerging players
- Hyperproof: GRC operations platform focused on continuous control monitoring and evidence collection for security and compliance teams. Comparable in evidence-driven, continuous-compliance framing and mid-market enterprise focus.
- Protecht Group: Integrated risk management platform covering operational risk, compliance, and vendor risk with AI enhancements. Comparable in risk-and-control-centric GRC scope and enterprise buyer profile, with stronger presence in Australia/UK than continental Europe.
Broad incumbents
- ServiceNow GRC: Enterprise IT GRC module inside the ServiceNow platform, deeply integrated with ITSM, SecOps, and CMDB. Comparable in target buyer (large regulated enterprises) and IT-risk use cases, but positioned as an incumbent suite rather than an AI-native challenger.
- RSA Archer: Long-standing enterprise GRC suite used by large banks and regulated entities for operational risk, IT risk, and compliance. Comparable in heavy-regulated buyer profile (DORA, NIS2 equivalents) but positioned as a legacy incumbent.
- Diligent (Galvanize): GRC platform with strong audit and board reporting heritage, expanded into enterprise risk and compliance. Comparable in board/executive reporting workflows and continuous monitoring, but a broader governance suite.
- OneTrust: Broad privacy, GRC, and ethics platform with AI capabilities covering consent, third-party risk, and ESG. Overlaps with Risk Hunter in TPRM, GDPR, and ethics/governance workflows, but operates as a much larger portfolio vendor.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat6 records
Key risks6 records
Key highlights6 records
Customer concentration
Risk Hunter social profiles
Digital presenceRisk Hunter compliance and trust
Trust signalCompliance7 records
Risk Hunter financial estimates
Financial estimateRevenue estimate
Valuation estimate
Risk Hunter leadership team
Management profileNumber of profiles
Profiles1 record
Risk Hunter funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Risk Hunter M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Risk Hunter
What does Risk Hunter do?
Risk Hunter provides an AI-native Cyber GRC Operating System that unifies detection, risk structuring, AI reasoning, and action orchestration across cyber, AI, third-party, compliance, controls, audits, and evidence functions. The platform is built on four proprietary engines — ODYSSY (detection and exposure), QANTIX (AI reasoning and decision engine), YOKAY (action orchestration), and Risk Hunter Core (foundational GRC platform) — and is delivered as a SaaS subscription to regulated enterprises primarily in France and the EU.
Is Risk Hunter a public or private company?
Risk Hunter is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Risk Hunter founded?
Risk Hunter was founded in 2024. It employs 1 to 10 people.
Where is Risk Hunter based?
Risk Hunter is headquartered in Paris, France, in the Europe region.
How does Risk Hunter make money?
One revenue line is on record: saaS Subscription (AI Cyber GRC Platform).
Who are Risk Hunter's main competitors?
Direct peers on record are Vanta, AuditBoard, Drata and LogicGate. Emerging players are Hyperproof and Protecht Group. Broad incumbents are ServiceNow GRC, RSA Archer, Diligent (Galvanize) and OneTrust.
Does Risk Hunter have an API?
No public API is recorded for Risk Hunter.
What industry is Risk Hunter in?
Risk Hunter's product category is Cyber GRC Software. Its primary akta.pro industry code is HDAEANAE, Enterprise AI Governance, Risk & Compliance Platforms (Model Risk, Audit, Policies), with a secondary code of HDAAAMAA, AI Governance, Risk & Compliance (GRC) Platforms. Its NAICS code is 541512 and its SIC code is 7373.