EVA Information Security
E.V.A Information Security is an Israeli boutique offensive-security consultancy, founded 2018, providing penetration testing, red-team operations, cloud security, and AI red-team assessments to global enterprises across financial, gaming, e-commerce, and technology sectors.
- Company typePrivate
- Founded2018
- HeadquartersGiv'atayim, Israel
- Headcount1–10
- GTM typeB2B
- OfferingServices
What EVA Information Security does
E.V.A Information Security is an Israeli offensive-security consultancy founded in 2018 and headquartered in Giv'atayim, with 11-50 employees. The firm offers six core services: Assessments and Penetration Testing (web, mobile, infrastructure, Wi-Fi using OWASP and NIST methodologies), Red Team Activity (threat-actor simulation, OSINT, social engineering, lateral movement), AI Red Team (security testing of agentic workflows, MCP servers, chatbots, and LLM-connected applications), Cloud Security (cloud penetration testing), Network Security (post-breach threat actor detection), and Application Security (secure SDLC, design reviews, and proactive vulnerability mitigation). The technical foundation rests on standardized penetration testing methodologies, multi-vector testing approaches (black box, grey box, white box), and ongoing proprietary vulnerability research that has yielded disclosed CVEs in CocoaPods (CVE-2024-38368, CVE-2024-38366, CVE-2024-38367) and original research identifying approximately 3,000 misconfigured publicly available Argo Workflows instances.
The firm operates a pure project-based professional services model under quote-based, scope-defined engagements with no publicly disclosed pricing. Distribution is direct: enterprise clients reach the firm through its website contact form and are engaged via consultative, field-style sales without disclosed partnerships or resellers. Marketing relies on a research blog and social channels (X, LinkedIn) that serve as top-of-funnel thought leadership. The disclosed customer base spans Israeli and global technology firms across gaming (Moonactive, Playtika, Mishloha), cybersecurity (Check Point, Silverfort), e-commerce/marketing (Yotpo, StoreMaven, SKAI), payments (Salt, Nayax), transportation (Moovit), mobile attribution (AppsFlyer), freelance marketplaces (Fiverr), project management (Monday.com), and social media (Meta) — an unusually strong logo set for a boutique consultancy.
Financially, E.V.A operates as a privately held, bootstrapped firm with no disclosed institutional funding, revenue, or headcount growth metrics. There is no documented management team, M&A, or partnership activity in the input data; all visible traction must be inferred from logo quality, published research output, and product portfolio breadth.
EVA Information Security firmographics
Firmographics- Name
- EVA Information Security
- Legal name
- E.V.A Information Security
- Website
- https://evasec.io
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- E.V.A Information Security is an Israeli boutique offensive-security consultancy, founded 2018, providing penetration testing, red-team operations, cloud security, and AI red-team assessments to global enterprises across financial, gaming, e-commerce, and technology sectors.
- Ownership category
- akta.pro rank
EVA Information Security industry classification
Industry- Product category
- Offensive Cybersecurity Services
- NAICS
- Other Computer Related Services (541519), Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Integrated Systems Design (7373), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Vulnerability Management & Penetration Testing Services (BPAEADAD)
- akta.pro secondary industry
- Threat Intelligence Services (BPAEADAC)
Keywords
Where EVA Information Security is headquartered
LocationHeadquarters
- HQ city
- Giv'atayim
- HQ country
- Israel
- HQ region
- Middle East
Markets served
EVA Information Security business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Professional Security Services: The company generates revenue through professional services including penetration testing engagements, red team operations, application security assessments, cloud security testing, AI red team assessments, and security training services. Engagements appear to be project-based and tailored to client needs across various security testing methodologies (black box, grey box, white box).
Go-to-market motion1 record
Distribution channels1 record
Marketing channels3 records
EVA Information Security product offering
Product offeringCore offering
E.V.A Information Security is an offensive-security consultancy providing project-based penetration testing, red team operations, AI red team assessments, cloud and network security testing, and application security services to enterprise clients. Engagements are tailored per client and executed using OWASP and NIST methodologies, with research-driven expertise spanning web, mobile, infrastructure, cloud, and AI/LLM systems.
Product overview
E.V.A Information Security is an offensive-security services company offering a unified portfolio of cybersecurity assessment services. Founded in 2018, the company provides six core service offerings: Assessments and Penetration Testing (covering web, mobile, infrastructure, and Wi-Fi), Red Team Activity (simulating real-world threat actors), AI Red Team (specialized AI system security testing), Cloud Security, Network Security, and Application Security (end-to-end secure development lifecycle services). These services work together to help organizations decrease their attack surface by identifying and exploiting vulnerabilities before malicious actors can.
Differentiator
Problem solved
Functional benefit
Products and services
- Assessments and Penetration Testing Security evaluation service that exploits vulnerabilities in web applications, mobile applications (Android & iOS), infrastructure, and Wi-Fi using OWASP and NIST methodologies. Targeted at enterprise organizations seeking to identify exploitable weaknesses across diverse asset classes.
- Red Team Activity Offensive security service simulating real-world threat actors to identify breach points, lateral movement paths, and potential damage to organizational assets. Leverages OSINT, social networks, external asset mapping, and social engineering techniques, including proprietary methods.
- AI Red Team In-depth assessment of AI systems, integrations, and supporting infrastructure across the enterprise. Testing targets agentic workflows, MCP servers, chatbots, and LLM-connected applications to expose prompt injection, data exfiltration, privilege misuse, and insecure runtime contexts, while also evaluating model pipelines, APIs, and development tools for misconfigurations, dependency risks, and supply-chain vulnerabilities.
- Cloud Security Cloud penetration testing service assessing cloud system security posture to identify risks, vulnerabilities, gaps, impact of exploitable vulnerabilities, and how any access obtained via exploitation could be leveraged.
- Network Security Security assessment service focused on detecting threat actors who have gained environment access and are disguising themselves as legitimate corporate users to access sensitive internal applications and databases.
- Application Security End-to-end secure software development lifecycle service including security design reviews, application security consultancy, and proactive vulnerability mitigation integrated into development cycles.
Companies that use EVA Information Security
Customer profileNamed customers16 records
Segments5 records
Ideal customer profiles4 records
EVA Information Security technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability3 records
Feature6 records
EVA Information Security partnerships and signals
Strategic signalScale indicators1 record
Recent moves4 records
Expansion highlights4 records
EVA Information Security competitors and assessment
Company assessmentDirect peers
- Bishop Fox: US-based offensive-security consultancy specializing in penetration testing, red teaming, and attack-surface management for enterprise clients — directly overlapping EVA's core service lines and target buyer profile.
- NetSPI: Enterprise offensive-security firm offering penetration testing as a service, red team operations, and attack-surface management with a hybrid platform — comparable to EVA on services with added product leverage.
- NCC Group: Global cybersecurity consultancy with a large offensive-security practice covering penetration testing, red team, and AI security assessments — a directly comparable full-service adversary-simulation firm.
- Cobalt Labs: Pentest-as-a-service platform connecting enterprises to a global network of vetted offensive-security testers — overlapping the manual pentest service EVA provides but with a crowdsourced delivery model.
Emerging players
- AttackIQ: Breach-and-attack-simulation platform with adversary emulation and purple-teaming offerings — an emerging productized alternative to EVA's manual red team engagements.
- HackerOne: Bug-bounty and penetration-testing platform offering continuous offensive testing services — adjacent competitor for proactive vulnerability-discovery engagements.
- Cymulate: Israel-based breach-and-attack-simulation vendor addressing similar offensive-validation use cases as EVA's red team services, with a SaaS platform model.
- Pentera: Automated security-validation platform focused on continuous penetration testing and adversary simulation — competes for the same enterprise budget pool but with a productized rather than services-led model. Notably, Pentera is linked from EVA's website as a partner/affiliate.
Broad incumbents
- Rapid7: Public security vendor with a professional-services arm offering penetration testing, red team, and managed detection — a broader incumbent overlapping with EVA's testing practice.
- Trustwave: Large MSSP offering penetration testing and red team services as part of a broad cybersecurity portfolio — competes for the same enterprise clients with deeper breadth but less boutique specialization.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat2 records
Key risks5 records
Key highlights5 records
Customer concentration
EVA Information Security social profiles
Digital presenceEVA Information Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
EVA Information Security leadership team
Management profileNumber of profiles
EVA Information Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
EVA Information Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about EVA Information Security
What does EVA Information Security do?
E.V.A Information Security is an offensive-security consultancy providing project-based penetration testing, red team operations, AI red team assessments, cloud and network security testing, and application security services to enterprise clients. Engagements are tailored per client and executed using OWASP and NIST methodologies, with research-driven expertise spanning web, mobile, infrastructure, cloud, and AI/LLM systems.
Is EVA Information Security a public or private company?
EVA Information Security is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was EVA Information Security founded?
EVA Information Security was founded in 2018. It employs 1 to 10 people.
Where is EVA Information Security based?
EVA Information Security is headquartered in Giv'atayim, Israel, in the Middle East region.
How does EVA Information Security make money?
One revenue line is on record: professional Security Services.
Who are EVA Information Security's main competitors?
Direct peers on record are Bishop Fox, NetSPI, NCC Group and Cobalt Labs. Emerging players are AttackIQ, HackerOne, Cymulate and Pentera. Broad incumbents are Rapid7 and Trustwave.
Does EVA Information Security have an API?
No public API is recorded for EVA Information Security.
What industry is EVA Information Security in?
EVA Information Security's product category is Offensive Cybersecurity Services. Its primary akta.pro industry code is BPAEADAD, Vulnerability Management & Penetration Testing Services, with a secondary code of BPAEADAC, Threat Intelligence Services. Its NAICS code is 541519 and its SIC code is 7373.