Whirly Labs
Whirly Labs is a bootstrapped South African cybersecurity consultancy delivering researcher-led threat modeling, penetration testing, code review, and security automation. Founded by the Code Property Graph and Joern creators, it serves Fortune 500 firms, government agencies, and SMBs.
- Company typePrivate
- Founded2023
- HeadquartersCape Town, South Africa
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Whirly Labs does
Whirly Labs is a privately-held cybersecurity consultancy headquartered in Cape Town, South Africa, with a secondary office in Centurion, Gauteng. Founded in 2023 by Fabian Yamaguchi (CEO) and Kate Yamaguchi (CMO), the firm delivers researcher-led security services to enterprise clients, government agencies, and small-to-medium businesses, and explicitly characterizes itself as independent and bootstrapped with no external institutional investment.
The firm's service portfolio spans threat modeling, penetration testing, code review, continuous reviews, developer training, security automation, and security team-building advisory. Underpinning these services is the Code Property Graph, a data structure invented by CEO Fabian Yamaguchi during his PhD thesis at the University of Göttingen, which unified program code, control flow, and data flow into a single graph representation. This research foundation powers Joern (joern.io), the industry-standard open-source platform for code analysis and vulnerability discovery, which the team continues to maintain. Proprietary extensions built on this platform include scalable language-agnostic taint tracking (published at SOAP'25), learning-based type inference for dataflow analysis (ESORICS'23), and bespoke semi-automated code analysis pipelines for detecting business-logic vulnerabilities that commercial scanners miss.
Revenue is generated exclusively through professional services engagements, with quote-based pricing tied to engagement scope and billed predominantly via multi-year contracts. Go-to-market combines enterprise field sales driven by direct inbound contact through the company website, event-driven visibility through conference presentations at BlackHat, DefCon, RSA, BSides, and the regional 0xcon (where Yamaguchi delivered the 2024 Johannesburg keynote), and community-led credibility built through Joern's open-source developer base. Customers include Fortune 500 enterprises, government agencies, and SMBs across finance, transportation, FMCG, and healthcare verticals, with both CTO Suchakra Sharma and CEO Yamaguchi bringing prior founding-team experience from Qwiet.ai (formerly ShiftLeft).
Whirly Labs firmographics
Firmographics- Name
- Whirly Labs
- Legal name
- Whirly Labs
- Website
- https://whirlylabs.com
- Company type
- Private
- Founded year
- 2023
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Whirly Labs is a bootstrapped South African cybersecurity consultancy delivering researcher-led threat modeling, penetration testing, code review, and security automation. Founded by the Code Property Graph and Joern creators, it serves Fortune 500 firms, government agencies, and SMBs.
- Ownership category
- akta.pro rank
Where Whirly Labs is headquartered
LocationHeadquarters
- HQ city
- Cape Town
- HQ country
- South Africa
- HQ region
- Africa
Offices2 records
Markets served
Whirly Labs business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Infrastructure
Revenue model
- Cybersecurity Consulting Services: Professional services revenue generated through specialized security engagements including penetration testing, code review, threat modeling, developer training, continuous security reviews, security automation, and building security teams. Services are delivered by expert security researchers with deep technical expertise, typically through project-based or retainer engagements with enterprise clients.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom enterprise engagements |
Go-to-market motion3 records
Distribution channels2 records
Marketing channels5 records
Whirly Labs product offering
Product offeringCore offering
Whirly Labs is a cybersecurity consultancy that delivers expert security services to enterprise and government clients. Core offerings include Threat Modeling, Penetration Testing, Code Review, Security Automation (custom semi-automated analysis tools), Continuous Reviews, Developer Training, and Building Security Teams. All engagements are led by security researchers and grounded in the firm's proprietary Code Property Graph and open-source Joern code analysis platform.
Product overview
Whirly Labs is an independent cybersecurity consultancy offering a portfolio of expert security services. The core offerings include Threat Modeling (proactive design-phase security), Penetration Testing (researcher-led attack simulation), Code Review (white-box vulnerability assessment), Security Automation (semi-automated analysis using custom tools), Continuous Reviews (ongoing security oversight), Developer Training (hands-on secure coding education), and Building Security Teams (strategic capability development). These services are delivered by security researchers and can be engaged individually or as an integrated security program. The company also contributed to the open-source Joern code analysis platform.
Differentiator
Problem solved
Functional benefit
Products and services
- Threat Modeling Proactive security service that helps clients identify architectural flaws and potential attack vectors during the design phase, moving security upstream before code is deployed. Aimed at engineering and security leaders planning new systems or major architectural changes.
- Penetration Testing Researcher-led security testing that simulates real-world attacks to identify weaknesses in web applications, cloud infrastructure, internal networks, and mobile applications before adversaries can exploit them. Targeted at enterprise organizations needing deep, non-automated security assessments.
- Building Security Teams Advisory service for assembling world-class internal security teams, including defining mission and structure, staffing, training, and long-term technical performance evaluation. Aimed at organizations establishing or maturing in-house security functions.
- Code Review White-box security assessment using custom tools for in-depth code and configuration review to uncover vulnerabilities that penetration tests may miss. Targeted at engineering organizations with significant custom codebases.
- Developer Training Tailored security training focused on specific languages and tech stack, teaching developers to recognize and fix vulnerabilities from the IDE with hands-on workshops. Aimed at engineering teams seeking to upskill developers in secure coding practices.
- Continuous Reviews Ongoing code and design reviews integrated into the development lifecycle, providing persistent security oversight through incremental reviews of pull requests and architectural changes. Targeted at organizations seeking continuous security partnership rather than point-in-time assessments.
- Security Automation Semi-automated code review service using custom analysis tools built on program analysis expertise to identify complex vulnerabilities specific to the client's technology stack. Aimed at engineering organizations needing tailored automated analysis beyond off-the-shelf scanners.
Companies that use Whirly Labs
Customer profileNamed customers5 records
Segments3 records
Ideal customer profiles3 records
Whirly Labs technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
Whirly Labs partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered core and minor.
- Stellenbosch UniversitycoreWhirly Labs is closely connected to Stellenbosch University's Computer Science Department. Fabian Yamaguchi serves as Adjunct Professor for Computer Security at the university. The company is advised by the department head, Brink van der Merwe. Collaborative relationship supporting academic research and talent development.
- Secfault SecurityminorSecurity consulting firm partner for research and client projects collaboration.
- KMSECminorSecurity consulting partner collaborating on research and client projects.
- Recurity LabsminorSecurity consulting partner collaborating on research and client projects.
- Qwiet.ai (formerly ShiftLeft Inc.)minorFabian Yamaguchi served as founding team member and Chief Scientist at Qwiet.ai (formerly ShiftLeft Inc.), where he built and led the R&D team. Suchakra Sharma was also a founding member. The company's technology was based on Yamaguchi's award-winning PhD thesis on pattern-based vulnerability discovery.
Scale indicators6 records
Recent moves5 records
Expansion highlights5 records
Whirly Labs competitors and assessment
Company assessmentBroad incumbents
- HackerOne: Bug bounty and vulnerability disclosure platform connecting organizations with a global researcher community. Adjacent business model that competes for enterprise security assessment budgets that Whirly Labs also targets.
- NCC Group: Global cybersecurity consultancy providing penetration testing, code review, threat intelligence, and managed security services. Comparable in service offering to Whirly Labs but far larger in scale, geographic reach, and breadth of services.
Regional players
- Recurity Labs: Berlin-based security research firm listed as a Whirly Labs partner. Comparable in researcher-led vulnerability discovery and consulting services, focused on European clients.
- Secfault Security: Listed as a Whirly Labs partner and UK-based security consultancy offering penetration testing and research services. Comparable in scope but operates primarily in the UK market.
Direct peers
- Cure53: Berlin-based security consultancy known for researcher-led web application penetration testing and code audits. Comparable in size, technical depth, and global client base, with similar academic-leaning research culture.
- Bishop Fox: US-based offensive security firm specializing in penetration testing, red teaming, and security assessments for Fortune 500 enterprises. Directly comparable in researcher-led, enterprise-focused security consulting with custom tooling.
- Trail of Bits: US-based cybersecurity research firm offering researcher-led security assessments, code audits, and custom tooling. Highly comparable to Whirly Labs in positioning: small team of elite researchers, custom tools (e.g., Slither, Echidna), and a research-first brand.
Emerging players
- PortSwigger: Creator of Burp Suite, the dominant web application security testing tool. Comparable in building best-in-class security tooling used by practitioners worldwide, with a researcher-led culture anchored in the UK.
- Privado.ai: Privacy-focused static code analysis platform where CTO Suchakra Sharma served as Chief Scientist. Comparable in applying code analysis to a specific security domain (privacy), and an adjacent peer given Whirly Labs' custom semi-automated analysis capabilities.
- Qwiet.ai (formerly ShiftLeft): Application security platform built on the Code Property Graph and Fabian Yamaguchi's prior research. Highly comparable technology lineage; Whirly Labs' founders were founding members, making this a directly adjacent peer in code-analysis-driven security.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights6 records
Customer concentration
Whirly Labs social profiles
Digital presenceWhirly Labs financial estimates
Financial estimateRevenue estimate
Valuation estimate
Whirly Labs leadership team
Management profileNumber of profiles
Profiles4 records
Whirly Labs funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Whirly Labs M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Whirly Labs
What does Whirly Labs do?
Whirly Labs is a cybersecurity consultancy that delivers expert security services to enterprise and government clients. Core offerings include Threat Modeling, Penetration Testing, Code Review, Security Automation (custom semi-automated analysis tools), Continuous Reviews, Developer Training, and Building Security Teams. All engagements are led by security researchers and grounded in the firm's proprietary Code Property Graph and open-source Joern code analysis platform.
Is Whirly Labs a public or private company?
Whirly Labs is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Whirly Labs founded?
Whirly Labs was founded in 2023. It employs 11 to 50 people.
Where is Whirly Labs based?
Whirly Labs is headquartered in Cape Town, South Africa, in the Africa region.
How does Whirly Labs make money?
One revenue line is on record: cybersecurity Consulting Services.
Who are Whirly Labs's main competitors?
Broad incumbents on record are HackerOne and NCC Group. Regional players are Recurity Labs and Secfault Security. Direct peers are Cure53, Bishop Fox and Trail of Bits. Emerging players are PortSwigger, Privado.ai and Qwiet.ai (formerly ShiftLeft).
Does Whirly Labs have an API?
No public API is recorded for Whirly Labs.