NDAY Security
NDAY Security is a US-based, AI-native offensive cybersecurity platform delivering continuous threat exposure management, autonomous AI penetration testing (AttackBench), attack surface intelligence (DiscoverN), and AI LLM red teaming. It sells via MSSP/white-label channels, direct enterprise sales, and Carahsoft to federal/state, enterprise, and Latin American SME customers.
- Company typePrivate
- Founded2023
- HeadquartersMiami, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What NDAY Security does
NDAY Security is a US-based offensive cybersecurity company, founded in August 2023 by former Trustwave executives Mark Whitehead and John Cartrett and headquartered in Dover, Delaware (with a Miami presence). The company operates an AI-powered continuous threat exposure management (CTEM) platform built around three core products: AttackN (orchestration platform executing 52 categories of attacks across network, application, cloud, API, AI and OSINT surfaces with continuous exploitability testing), AttackBench (an autonomous AI agent running 65,000+ web and network exploits and simulating full compromise in under 10 minutes), and DiscoverN (attack surface discovery spanning 30B+ compromised credentials, 75M+ devices, and 100+ OSINT feeds). Adjacent offerings include AI LLM Red Teaming powered by NVIDIA's Garak technology (free through end of 2026), PhishN/SmishN social engineering tools, Deepfake Assessments, and human-reviewed signed reports in 43 languages.
The company's go-to-market is channel-first. A multi-tenant MSSP/white-label platform lets partners resell or rebrand the technology under their own label at fixed wholesale per-test pricing, with white-labeled reports and client portals. Direct enterprise sales run on a demo-driven motion against AttackN, DiscoverN, and AttackBench. Government (Federal, DoD, SLED) procurement is enabled through Carahsoft, and Latin American market reach is delivered via the WPS.Digital partnership. End customers span MSSPs/channel partners (primary), enterprises, federal/state agencies, critical infrastructure operators, and Latin American SMEs. Revenue is primarily subscription-recurring via the AttackN platform and MSSP multi-tenant licensing, supplemented by one-time pentest engagements for compliance-driven work (PCI-DSS, HIPAA, ISO 27001, SOC 2, CMMC) and a freemium LLM Red Teaming tier used as a product-led growth funnel. The company is privately held and bootstrapped, with no disclosed institutional funding.
NDAY is a member of the NVIDIA Inception Program (the first offensive security company admitted) and has assembled a senior advisory board including former CIA CTO Rusty Byrne, former AIG CISO Gary McAlum, LevelBlue CSTO Kory Daniels, and CMU SEI CERT's Michael McCord. Customers cited on the website are anonymized (Global Enterprise CISO, Enterprise Executive, Lead Red Team Tester), and partner ecosystem includes Carahsoft, SHI, Spry Methods, ThunderCat, GoSecure, Datasec, Kaiju, OnDefend, and others. The company recently integrated weaponized exploit intelligence via a partnership with CrowdFense (Q2 2026).
NDAY Security firmographics
Firmographics- Name
- NDAY Security
- Legal name
- Nday Security, Inc
- Website
- https://ndaysecurity.com
- Company type
- Private
- Founded year
- 2023
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- NDAY Security is a US-based, AI-native offensive cybersecurity platform delivering continuous threat exposure management, autonomous AI penetration testing (AttackBench), attack surface intelligence (DiscoverN), and AI LLM red teaming. It sells via MSSP/white-label channels, direct enterprise sales, and Carahsoft to federal/state, enterprise, and Latin American SME customers.
- Ownership category
- akta.pro rank
NDAY Security industry classification
Industry- Product category
- Offensive Security Software
- NAICS
- Computer Systems Design and Related Services (5415)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Vulnerability Intelligence & Exploit Prediction (HDADAHAI)
- akta.pro secondary industries
- Model Security Testing & Red Teaming (adversarial ML, jailbreaks) (HDAAAKAC), Security Analytics & Detection Engineering (HDADAGAE), Threat Intelligence Services (BPAEADAC), Prompt Security & Injection Defense (HDAAAKAE)
Keywords
Where NDAY Security is headquartered
LocationHeadquarters
- HQ city
- Miami
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
NDAY Security business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Operations, Infrastructure
Revenue model
- AttackN Platform Subscription: Continuous threat exposure management platform with annual subscription model. Supports single-tenant and multi-tenant deployments for MSSPs.
- One-Time Penetration Testing: Point-in-time penetration testing services available to support regulatory and compliance requirements (PCI-DSS, HIPAA, ISO 27001, SOC 2, CMMC).
- MSSP/White-Label: Multi-tenant MSSP mode with wholesale pricing. Partners set their own margins with fixed-price per test. Fully white-labeled deliverables including reports and client portals.
- AI LLM Red Teaming (Free Tier): Free platform access through end of 2026 with BYOK/BYOT model. No platform fees, no commitment required.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Pay-as-you-go | AI LLM Red Teaming - Free |
| Unit Pricing | Pay-as-you-go | Fixed Price Penetration Testing |
| Subscription | Monthly | AttackN Plus - Adversarial Exposure Validation |
| Subscription | Annual | MSSP/Whitelabel |
Go-to-market motion3 records
Distribution channels5 records
Marketing channels6 records
NDAY Security product offering
Product offeringCore offering
NDAY Security provides an AI-powered continuous threat exposure management (CTEM) and offensive security platform built around AttackN (orchestration platform spanning 52 attack categories across network, application, cloud, API, AI, and OSINT surfaces), AttackBench (autonomous AI penetration testing agent executing 65,000+ exploit types with full compromise simulation in under 10 minutes), and DiscoverN (attack surface discovery and credential intelligence across 30B+ compromised credentials and 58K+ dark web channels). The offering includes AI LLM red teaming powered by NVIDIA's Garak technology, MSSP/white-label multi-tenant deployment, expert-driven AttackN Plus reviews, and PhishN/SmishN social engineering campaigns, with automated reporting in 43 languages.
Product overview
NDAY Security offers a unified AI-powered offensive security platform combining three core products: AttackBench (autonomous AI penetration testing agent), AttackN (continuous exploitability orchestration platform), and DiscoverN (attack surface discovery and intelligence). The platform supports over 50 attack types across network, application, cloud, API, AI, and OSINT surfaces. Additional offerings include AI LLM Red Teaming powered by NVIDIA's Garak technology, PhishN/SmishN social engineering tools, MSSP white-label capabilities, and human expert review services. The portfolio enables continuous threat exposure management (CTEM) with fixed-price penetration testing, available via portal or AI prompt interface, with reporting in 43 languages.
Differentiator
Problem solved
Functional benefit
Brands
- AttackN: AI-powered continuous exploitability platform and penetration testing orchestration platform covering network, application, cloud, API, AI, and OSINT surfaces.
- AttackBench
- DiscoverN
- PhishN
- SmishN
Products and services
- AttackBench Semi-autonomous and fully autonomous AI agent that executes over 65,000 web and network exploit types, chains attacks, and validates defense evasion to perform full compromise simulation in under 10 minutes. Designed for MSSPs, red teams, and enterprise security teams needing AI-augmented offensive validation with real-time reporting in 43 languages.
- AttackN AI-powered continuous exploitability platform and penetration testing orchestration covering 52 categories of attacks across network, application, cloud, API, AI, and OSINT surfaces with human-in-the-loop validation, automated reporting, and API integrations for SIEMs and ticketing systems. Built for enterprises and MSSPs running continuous threat exposure management (CTEM).
- DiscoverN Attack surface discovery and intelligence platform providing continuous asset discovery, leaked credential intelligence, and attack surface mapping across 30B+ compromised credentials, 75M+ infected devices, 50M+ leaked secrets, 950+ breach sources, 58K+ dark web channels, and 100+ OSINT feeds. Consolidates approximately 80 hours of manual OSINT analysis into one click for security teams and MSSPs.
- AI LLM Red Teaming Self-service AI red teaming platform powered by NVIDIA's Garak technology that runs thousands of adversarial probes including jailbreaks, prompt injection, data leakage, and hallucination testing against OpenAI-compatible, Azure OpenAI, OpenRouter, and local AI models. Free through end of 2026 with no platform fees and no commitment required.
- MSSP/White Label Platform Multi-tenant platform enabling MSSPs and channel partners to deliver AI-powered penetration testing, attack surface management, and AI LLM red teaming under their own brand. Includes fully white-labeled reports, client portals, and centralized billing with over 50 attack types and fixed-price wholesale pricing that lets partners set their own margins.
- AttackN Plus Expert-driven adversarial exposure validation combining CTEM and penetration testing with human expert reviews and signed reports in 43 languages. Cancel-anytime monthly plans available for SMB and enterprise customers requiring hassle-free security validation and regulatory attestation.
- PhishN Fully automated phishing campaign service delivering targeted 7-day campaigns with customizable emails and comprehensive HTML Phishing Insight Reports. Used by security teams for phishing awareness and social engineering assessments.
- SmishN Automated smishing (SMS phishing) campaign service with comprehensive Smishing Insight Reports for social engineering assessments. Used by security teams to evaluate workforce resilience against SMS-based phishing.
- One-Time Penetration Testing Point-in-time penetration testing services available to support regulatory and compliance requirements including PCI-DSS, HIPAA, ISO 27001, SOC 2, and CMMC. Delivered as fixed-price engagements by NDAY's offensive security team.
Quantifiable outcome
- Full compromise simulation in under 10 minutes with AttackBench
- +2 more outcomes
Companies that use NDAY Security
Customer profileNamed customers3 records
Segments5 records
Ideal customer profiles4 records
NDAY Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration6 records
AI capability8 records
Feature4 records
NDAY Security partnerships and signals
Strategic signalPartnerships
17 partnerships are on record, tiered core and minor.
- CrowdFensecoreStrategic partnership integrating CrowdFense N-Day Vulnerability Feed into NDAY's continuous exploitability platform and AttackBench. Provides real-world weaponized exploits comparable to those used by APT groups and nation-state operators. Combined offering available to select customers beginning Q2 2026.
- WPS.DigitalcorePartnership to provide offensive cybersecurity solutions to Latin American markets, focusing on digital transformation and security enhancement. Targets SMEs, critical infrastructure, and public institutions in the region.
- Sleuth Kit LabsminorCybersecurity bundle partnership combining point-in-time or continual penetration testing with Rapid Endpoint Investigation for threat-led detection and rapid response to compromises.
- Spry MethodscoreStrategic alliance delivering AI-driven Continuous Threat Exposure Management and real-time threat detection for government cybersecurity needs.
- Identify SecurityminorPartnership transforming cyber defense economics with continuous external penetration testing services.
- CarahsoftcoreCarahsoft is The Trusted Public Sector IT Solutions Provider supporting Federal, State, Local Government agencies and Education and Healthcare markets. Enables government procurement for NDAY Security solutions.
- NVIDIAcoreNVIDIA Inception Program member enabling businesses to evolve faster through cutting-edge technologies, opportunities to connect, and access to latest technical resources from NVIDIA. NDAY is the first offensive security company in the program.
- DatasecminorDatasec provides comprehensive proactive cybersecurity solutions, helping companies evolve IT management techniques and mitigate cyber attack risks.
- Distributed Technology Group (DTG)minorService-Disabled Veteran-Owned Small Business (SDVOSB) helping clients digitally transform their business to achieve exceptional outcomes.
- GoSecureminorCybersecurity leader and innovator for over 20 years, helping customers understand security gaps and improve organizational risk and security maturity.
- Identify SecurityminorNiche IT recruiting firm applying highly talented IT professionals to solve technology and security related business challenges.
- Kaiju SecurityminorSecurity services backed by a network of real world ethical hackers to provide best-in-industry expertise.
- OnDefendminorEmpowers organizations globally to proactively combat real-world cyber threats, from compliance to building mature security programs.
- SHIminorPersonal technology concierge connecting teams with IT solutions and services to support organizational growth.
- Simple SolutionsminorEmpowers organizations through integrated business analysis, IT Solutions, Staffing services, and proposal writing solutions.
- SpryminorMission-focused company with 20+ years in Mission IT, National Security, Intelligence Analysis, and Cyber Security.
- ThunderCat TechnologyminorService-Disabled Veteran-Owned Small Business (SDVOSB) delivering technology products and services to government organizations, educational institutions, and commercial companies.
Scale indicators6 records
Recent moves6 records
Expansion highlights6 records
NDAY Security competitors and assessment
Company assessmentDirect peers
- AttackIQ: Breach-and-attack-simulation (BAS) platform for continuous security validation, aligned to MITRE ATT&CK. Overlaps with NDAY's continuous-exploitability and red-teaming orchestration.
- SafeBreach: BAS platform that simulates real-world attacks against security controls. Comparable continuous-validation positioning to AttackN's orchestration layer.
- Bishop Fox: Offensive-security services and continuous-pentest platform (Cosmos). Closely aligned to NDAY's combination of human-led red teaming and platform-driven continuous testing.
- Pentera: Automated security-validation platform running safe, continuous attack simulations across enterprise networks. Closest direct competitor to NDAY's AttackBench/AttackN, serving CISOs with breach-and-attack-simulation and exploitability validation.
- Horizon3.ai: Autonomous AI-driven penetration-testing platform (NodeZero) that identifies exploitable attack paths and prioritizes remediation. Directly comparable to AttackBench on autonomous pentesting and exploit-chaining.
- Cobalt.io: Pentesting-as-a-service platform connecting customers to a global tester community. Comparable use cases for one-time and continuous pentest buyers overlapping with AttackN.
- NetSPI: Offensive-security services platform offering pentesting, red-teaming, and attack-surface management with enterprise delivery model similar to NDAY's enterprise motion.
Broad incumbents
- NCC Group: Large global cybersecurity services firm offering offensive security, red-team, and managed testing at scale. Overlaps NDAY's pentesting and red-teaming services for enterprise and regulated buyers.
- Rapid7: Broad security platform with Metasploit, InsightVM, and managed pentest services. A larger incumbent that competes for vulnerability management and offensive security budget alongside NDAY.
Emerging players
- Protect AI: AI/ML security platform covering model scanning, red-teaming, and supply-chain risk. Adjacent emerging competitor in the AI-security niche where NDAY's GARAK-based LLM red-teaming plays.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
NDAY Security social profiles
Digital presenceNDAY Security compliance and trust
Trust signalCompliance10 records
NDAY Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
NDAY Security leadership team
Management profileNumber of profiles
Profiles8 records
NDAY Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
NDAY Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about NDAY Security
What does NDAY Security do?
NDAY Security provides an AI-powered continuous threat exposure management (CTEM) and offensive security platform built around AttackN (orchestration platform spanning 52 attack categories across network, application, cloud, API, AI, and OSINT surfaces), AttackBench (autonomous AI penetration testing agent executing 65,000+ exploit types with full compromise simulation in under 10 minutes), and DiscoverN (attack surface discovery and credential intelligence across 30B+ compromised credentials and 58K+ dark web channels). The offering includes AI LLM red teaming powered by NVIDIA's Garak technology, MSSP/white-label multi-tenant deployment, expert-driven AttackN Plus reviews, and PhishN/SmishN social engineering campaigns, with automated reporting in 43 languages.
Is NDAY Security a public or private company?
NDAY Security is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was NDAY Security founded?
NDAY Security was founded in 2023. It employs 11 to 50 people.
Where is NDAY Security based?
NDAY Security is headquartered in Miami, United States, in the North America region.
How does NDAY Security make money?
Four revenue lines are on record. AttackN Platform Subscription is the primary driver. The others are one-Time Penetration Testing, MSSP/White-Label and AI LLM Red Teaming (Free Tier).
Who are NDAY Security's main competitors?
Direct peers on record are AttackIQ, SafeBreach, Bishop Fox, Pentera, Horizon3.ai, Cobalt.io and NetSPI. Broad incumbents are NCC Group and Rapid7. Protect AI is listed as an emerging player.
Does NDAY Security have an API?
Yes. NDAY Security provides API access for real-time defender integration, enabling communication with SIEMs, ticketing systems, and other AI agents. The AttackBench AI agent can be accessed via prompt for API testing and security posture queries. Reports available via API export in 43 languages. MSSP partners receive full API documentation for integration purposes.
What industry is NDAY Security in?
NDAY Security's product category is Offensive Security Software. Its primary akta.pro industry code is HDADAHAI, Vulnerability Intelligence & Exploit Prediction, with a secondary code of HDAAAKAC, Model Security Testing & Red Teaming (adversarial ML, jailbreaks). Its NAICS code is 5415 and its SIC code is 7372.