YSecurity
YSecurity is an on-demand cybersecurity services firm delivering SOC 2, ISO 42001, penetration testing, and AI red teaming to startups and enterprises by embedding operators directly into client teams via Slack and sales calls.
- Company typePrivate
- Founded-
- Headquarters—
- Headcount—
- GTM typeB2B
- OfferingServices
What YSecurity does
YSecurity is an on-demand cybersecurity services firm that delivers SOC 2 Type 2, ISO 42001, penetration testing, AI red teaming, and sales-call security support to startups and growth-stage technology companies. The company was founded in 2022 by Jon McLachlan and Sasha Sinkevich, both veterans who previously built security functions at Apple, Robinhood, Pure Storage, UnifyID, Yugabyte, and Symphony. Headquartered in San Francisco and structured as a private U.S. LLC, YSecurity operates with a lean core team supplemented by a network of named fractional CISOs, compliance leaders, AI red teamers, and offensive security engineers drawn from Apple, Tesla, Atlassian, Intel, and Johnson & Johnson.
Rather than selling a software platform, YSecurity sells embedded operator time. Services are delivered by joining client Slack channels, attending stand-ups, participating in sales calls, and handling DDQs and RFPs as part of the client's internal team. The service catalog spans compliance (SOC 2, ISO 42001, HIPAA, HITRUST, ITAR, CMMC Level 2, FedRAMP), penetration testing across application, API, cloud, AI, network, and physical/social layers, AI Red Team coverage of the OWASP LLM Top 10, product security (SSO, OAuth, customer-managed keys, E2E encryption), 24/7 monitoring and response, and pre-sales security support. Pricing is usage-based, billed in 15-minute increments with optional monthly caps and no retainers or minimums, with a free 15-minute discovery call as the top-of-funnel entry point.
YSecurity's go-to-market is sales-led and consultative, targeting pre-seed to Series B startups that need enterprise-grade security without an in-house team, alongside mid-market and enterprise buyers undergoing M&A due diligence or AI security reviews. Marquee proof points include facilitating Robust Intelligence's $400M acquisition by Cisco, certifying Augment Code to ISO 42001 in 93 days, and securing a 5.0 Gartner Peer Insights and 4.8 G2 rating. Distribution is primarily direct via a cal.com booking funnel, supplemented by The Security Podcast of Silicon Valley, conference presence at BSides and Black Hat, and earned-media case studies. No external venture funding, acquisitions, or parent company structure is disclosed.
YSecurity firmographics
Firmographics- Name
- YSecurity
- Legal name
- YSecurity LLC
- Website
- https://ysecurity.io
- Company type
- Private
- Operating status
- Operating
- Short description
- YSecurity is an on-demand cybersecurity services firm delivering SOC 2, ISO 42001, penetration testing, and AI red teaming to startups and enterprises by embedding operators directly into client teams via Slack and sales calls.
- Ownership category
- akta.pro rank
YSecurity industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Computer Facilities Management Services (541513), Computer Systems Design and Related Services (5415)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Services-Computer Programming Services (7371)
- akta.pro primary industry
- Cybersecurity Operations Outsourcing (SOC / SecOps) (BPAEAMAG)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Security Awareness, Training & Compliance Attestation (HDADAIAJ)
Keywords
YSecurity business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Marketing or Sales, Technology or R&D, Others
Revenue model
- On-demand Cybersecurity Services: Billed in 15-minute increments with clear task descriptions. Optional monthly cap for predictable costs. No retainers or minimums. Services include SOC 2 preparation, ISO 42001 certification, penetration testing, AI red teaming, and ongoing security programs. Revenue is usage-based and consumption-driven, aligned with the on-demand staffing model.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Usage-based | Pay-as-you-go | On-demand usage-based pricing |
Go-to-market motion3 records
Distribution channels1 record
Marketing channels6 records
YSecurity product offering
Product offeringCore offering
YSecurity is an on-demand cybersecurity team for startups and enterprises, delivering services rather than software. Its core offerings include SOC 2 Type 2 and ISO 42001 certification preparation, AI Red Team and full-scope penetration testing, product security implementation, ITAR/CMMC/FedRAMP readiness, HIPAA and HITRUST compliance, 24/7 monitoring and response, and embedded sales security support (DDQs, RFPs, security review handling). Operators embed directly into client teams via Slack and stand-ups, billed in transparent 15-minute increments with optional monthly caps and no retainers or minimums.
Product overview
YSecurity is an on-demand cybersecurity team for startups and enterprises, offering a unified portfolio of compliance and security services rather than a software product. The core offering includes SOC 2 Type 2 and ISO 42001 certification services, AI Red Team/AI Penetration Testing, and full-scope Penetration Testing. These are complemented by Product Security (SSO, OAuth, Okta implementation), ITAR Compliance, CMMC Level 2, FedRAMP Readiness, 24/7 Monitoring & Response, Sales Support (DDQs, RFPs, sales call participation), HIPAA Compliance, and HITRUST Certification. Services are delivered by embedding operators directly into client teams via Slack and stand-ups, with transparent 15-minute billing and optional monthly caps. The company is staffed by veterans from Apple, Netflix, Robinhood, Uber, and Intel.
Differentiator
Problem solved
Functional benefit
Products and services
- SOC 2 Type 2 Compliance End-to-end SOC 2 Type 2 certification delivery including preparation, execution, and audit response for startups that need to demonstrate enterprise-grade security controls. Delivered in as little as 5 months versus an industry standard of 18 months.
- ISO 42001 Certification End-to-end ISO 42001 (AI management system) certification for AI startups and vendors that need to satisfy enterprise AI committee and procurement requirements, run by YSecurity with its own internal auditor.
- AI Red Team / AI Penetration Testing Adversarial testing of LLM applications, copilots, agents, and RAG pipelines covering all 10 OWASP LLM Top 10 categories including prompt injection, data exfiltration, agent misuse, RAG poisoning, guardrail bypass, and system prompt leakage. Delivered with a verified red-team report for enterprise buyers.
- Penetration Testing Full-scope penetration testing covering application and API, cloud and infrastructure, AI systems, network and database, and physical and social layers, delivered by specialist operators including offensive security engineers trusted by Apple, Tesla, and Atlassian.
- Product Security Product-layer security implementation covering login flows (SSO, OAuth, Okta), customer-managed keys, end-to-end encryption, fraud detection, and abuse prevention for SaaS and AI applications.
- ITAR Compliance Preparation of systems, data flows, and access controls for U.S. International Traffic in Arms Regulations (ITAR) requirements, targeting defense-readiness in under six months.
- CMMC Level 2 Readiness Mapping of NIST 800-171 controls, gap closure, and assessor preparation to achieve Cybersecurity Maturity Model Certification (CMMC) Level 2 readiness for defense suppliers.
- FedRAMP Readiness Documentation build, 3PAO coordination, and Authority to Operate (ATO) preparation for FedRAMP Moderate or Low-Impact Software-as-a-Service (LI-SaaS) authorization for SaaS vendors selling to the U.S. federal government.
- 24/7 Monitoring and Response Real-time threat detection across cloud, network, endpoints, and mobile environments with automated alerts and hands-on triage, delivered as an outsourced Security Operations Center function.
- Sales Security Support Embedded sales-cycle security support where YSecurity operators join client sales calls, handle security questions, prepare Due Diligence Questionnaires (DDQs) and RFPs, and write security documents to help clients close enterprise deals.
- HIPAA Compliance Design of HIPAA-aligned architectures including encryption, Business Associate Agreements (BAAs), and risk assessments to meet the HIPAA Security Rule for healthcare-adjacent technology companies.
- HITRUST Certification Mapping of SOC 2, ISO, and HIPAA controls into the HITRUST Common Security Framework (CSF), with readiness management and streamlined certification delivery targeting up to 40% time reduction.
Quantifiable outcome
- SOC 2 Type 2 in 5 months (industry standard is 18 months)
- +7 more outcomes
Companies that use YSecurity
Customer profileNamed customers12 records
Segments2 records
Ideal customer profiles2 records
YSecurity technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
YSecurity partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered minor.
- CoalfireminorThird-party audit firm used for ISO 42001 certifications. Coalfire conducted the first open audit slot for Augment Code's certification, completing Stage 1 documentation and Stage 2 audit on day 93.
- AppleminorApple is mentioned as a prior employer of YSecurity team members (Jon McLachlan started in security at Apple; operators trusted by Apple). Not a commercial partnership.
- TeslaminorTesla is mentioned as a client trust reference for YSecurity's offensive security operators. Not a commercial partnership.
- AtlassianminorAtlassian is mentioned as a client trust reference for YSecurity's offensive security operators. Not a commercial partnership.
- RobinhoodminorRobinhood is mentioned as a prior employer of YSecurity team members (Sasha Sinkevich built security at Robinhood). Not a commercial partnership.
Scale indicators11 records
Recent moves6 records
Expansion highlights6 records
YSecurity competitors and assessment
Company assessmentDirect peers
- A-LIGN: A-LIGN is a cybersecurity and compliance services firm specializing in SOC 2, ISO 27001, HITRUST, PCI, and penetration testing for technology companies. It is one of the closest direct peers to YSecurity in delivering audit-ready compliance and security services to SaaS and AI startups.
- Schellman: Schellman is a top-tier SOC 2, ISO, HITRUST, and FedRAMP assessment and cybersecurity advisory firm serving technology and regulated clients. It competes directly with YSecurity on SOC 2/ISO compliance services for startups and enterprises, with similar focus on speed-to-certification.
- Coalfire: Coalfire is a cybersecurity advisory and audit firm with deep SOC 2, ISO, FedRAMP, HITRUST, and CMMC practices, and is actually cited as YSecurity's third-party audit partner for ISO 42001. Comparable as a cybersecurity services firm serving tech and regulated customers, and a partial channel partner.
- Bishop Fox: Bishop Fox is an offensive security firm specializing in penetration testing, red teaming, and security assessments for Fortune 500 and high-growth tech companies. Directly comparable to YSecurity's multi-layer penetration testing and AI red team offerings.
- Cobalt: Cobalt is a penetration testing-as-a-service platform connecting companies to vetted offensive security testers. Directly comparable to YSecurity's pentest delivery model, with a similar focus on speed, transparency, and serving SaaS / tech companies.
- HackerOne: HackerOne operates a crowdsourced security testing platform offering penetration testing, bug bounty, and vulnerability disclosure programs. Comparable as an offensive-security provider serving tech-forward customers, though with a platform-mediated model rather than embedded operators.
- Trail of Bits: Trail of Bits is a security research and consulting firm specializing in application security, cryptography, blockchain, and AI/LLM security audits. Comparable to YSecurity's specialized AI red teaming and product security work, particularly for AI-native clients.
Broad incumbents
- NCC Group: NCC Group is a global cybersecurity consultancy providing penetration testing, red teaming, compliance, and managed security services. It is a broad incumbent that competes with YSecurity on offensive security and compliance work, with greater resources and global reach.
Emerging players
- Lakera: Lakera is an AI security startup focused on protecting LLM applications from prompt injection, data leakage, and other LLM-specific threats. It is an emerging player with direct overlap to YSecurity's AI red teaming and LLM Top 10 coverage, but positioned as a software product rather than embedded services.
- Adversa AI: Adversa AI is an AI security firm focused on adversarial testing, red teaming, and hardening of AI/ML systems. It overlaps with YSecurity's OWASP LLM Top 10–based AI red team service for AI-native startups.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights6 records
Customer concentration
YSecurity social profiles
Digital presenceYSecurity financial estimates
Financial estimateRevenue estimate
Valuation estimate
YSecurity leadership team
Management profileNumber of profiles
Profiles6 records
YSecurity funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
YSecurity M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about YSecurity
What does YSecurity do?
YSecurity is an on-demand cybersecurity team for startups and enterprises, delivering services rather than software. Its core offerings include SOC 2 Type 2 and ISO 42001 certification preparation, AI Red Team and full-scope penetration testing, product security implementation, ITAR/CMMC/FedRAMP readiness, HIPAA and HITRUST compliance, 24/7 monitoring and response, and embedded sales security support (DDQs, RFPs, security review handling). Operators embed directly into client teams via Slack and stand-ups, billed in transparent 15-minute increments with optional monthly caps and no retainers or minimums.
Is YSecurity a public or private company?
YSecurity is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was YSecurity founded?
YSecurity was founded in -1.
How does YSecurity make money?
One revenue line is on record: on-demand Cybersecurity Services.
Who are YSecurity's main competitors?
Direct peers on record are A-LIGN, Schellman, Coalfire, Bishop Fox, Cobalt, HackerOne and Trail of Bits. NCC Group is listed as a broad incumbent. Emerging players are Lakera and Adversa AI.
Does YSecurity have an API?
No public API is recorded for YSecurity.
What industry is YSecurity in?
YSecurity's product category is Cybersecurity Services. Its primary akta.pro industry code is BPAEAMAG, Cybersecurity Operations Outsourcing (SOC / SecOps), with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 541513 and its SIC code is 7370.