Armadin Security
Armadin Security is an AI-native offensive cybersecurity company that sells an agentic red-teaming platform (Armadin Red) to large enterprise and Fortune 100 customers, delivered via direct sales and integrations with Palo Alto Networks Unit 42 and CrowdStrike Falcon.
- Company typePrivate
- Founded2024
- HeadquartersMenlo Park, United States
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What Armadin Security does
Armadin Security is an AI-native offensive cybersecurity company that builds and sells an agentic red-teaming and remediation platform marketed as "The Ultimate Attacker" and productized as "Armadin Red." The platform deploys swarms of autonomous AI agents that perform continuous, multi-step attack simulation across an organization's full attack surface, executing three phases — Reconnaissance (enumerating hosts, people, and defenses), Adaptive Scouting (parallel probing that learns from each attempt), and Precision Strike (validated kill chains with prioritized remediation guidance). It leverages more than 50,000 attack templates, blends frontier and proprietary security models, and uses LLM-assisted vulnerability research to triage large code diffs, draft proof-of-concept exploits, and weaponize vulnerabilities end-to-end. The product is delivered with purpose-built guardrails, scoped execution, and human-in-the-loop controls to ensure safe deployment in production enterprise environments.
The company was founded in 2024 by Kevin Mandia (founder of Mandiant, former CEO of FireEye) alongside Travis Lanham (ex-Google Cloud Security), Evan Peña (former leader of Mandiant's 200+ consultant red team), and David Slater (ex-Google SecOps), and is operationally headquartered in Palo Alto, California. It is a private Delaware-incorporated company that emerged from stealth in March 2026 with a $189.9M combined Seed and Series A round led by Accel (the largest early-stage security raise on record), at a valuation exceeding $600M, with participation from GV, Kleiner Perkins, Menlo Ventures, 8VC, Ballistic Ventures, and In-Q-Tel.
Armadin serves large enterprise and Fortune 100 customers through direct enterprise field sales, professional services engagements, and channel partnerships, with Armadin Red natively integrated into Palo Alto Networks' Unit 42 Frontier AI Defense service and CrowdStrike's Falcon platform via Project QuiltWorks. Revenue is generated via subscription (Order Form), SOW-based professional services, and a 30-day evaluation period; a Canadian subsidiary (Armadin Canada, Inc.) was established in 2026 to target federally regulated financial institutions and critical infrastructure. Pricing is quote-based and not publicly disclosed.
Armadin Security firmographics
Firmographics- Name
- Armadin Security
- Legal name
- Armadin, Inc.
- Website
- https://armadin.com
- Company type
- Private
- Founded year
- 2024
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- Armadin Security is an AI-native offensive cybersecurity company that sells an agentic red-teaming platform (Armadin Red) to large enterprise and Fortune 100 customers, delivered via direct sales and integrations with Palo Alto Networks Unit 42 and CrowdStrike Falcon.
- Ownership category
- akta.pro rank
Armadin Security industry classification
Industry- Product category
- AI-Native Offensive Cybersecurity Platform
- NAICS
- Security Systems Services (except Locksmiths) (561621), Investigation, Guard, and Armored Car Services (56161), Security Systems Services (56162)
- akta.pro primary industry
- Intrusion Detection & Prevention Systems (IDS/IPS) (HDAFAFAD)
- akta.pro secondary industries
- Intrusion Prevention/Detection Systems (IPS/IDS) (HDADABAH), Prompt Security & Injection Defense (HDAAAKAE)
Keywords
Where Armadin Security is headquartered
LocationHeadquarters
- HQ city
- Menlo Park
- HQ country
- United States
- HQ region
- North America
Offices3 records
Markets served
Armadin Security business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Subscription Services (Armadin Red platform): Recurring access to the Armadin continuous, agentic red-teaming and remediation platform granted under Order Form, with usage rights to AI Tools and accompanying Documentation. EULA references 'Subscription to the Services' and an Order Form-driven commercial model, indicating a recurring subscription basis for the core platform.
- Professional Services (Red Team Consulting): Statement-of-Work (SOW)-driven integration, onboarding, training, and bespoke offensive security / incident response engagements. Performed by Armadin's red team consultants who deliver 'unmatched offensive security and incident response for the most complex and targeted environments.' Travel and lodging expenses are reimbursable per SOW.
- Evaluation / Proof-of-Concept Engagements: 30-day Evaluation Services may be provided for trial, testing, or evaluation purposes at no charge, used to convert prospects into subscription customers. Armadin reserves the right to terminate Evaluation Services at any time.
- Reseller Channel Distribution: EULA explicitly references a Reseller authorized by Armadin to enter into Order Forms with Customers for Armadin products and services, indicating a channel/partner-led revenue motion in addition to direct sales.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Multi-year contract | Subscription to the Armadin Services per Order Form |
| Other | Multi-year contract | Professional Services / SOW-based engagements |
| Freemium | Pay-as-you-go | 30-day Evaluation / Proof-of-Concept |
Go-to-market motion4 records
Distribution channels5 records
Marketing channels9 records
Armadin Security product offering
Product offeringCore offering
Armadin Security provides an AI-native, agentic offensive cybersecurity platform that deploys autonomous AI agents to continuously perform reconnaissance, adaptive scouting, and precision-strike phases against an organization's full attack surface. The platform, branded as Armadin Red, produces validated kill chains and prioritized remediation guidance to expose exploitable risk. The company also delivers SOW-based professional services from its red team consultants for incident response and bespoke offensive engagements.
Product overview
Armadin Security offers a single unified AI-native cybersecurity platform (marketed under the brand "Armadin" and tagged "The Ultimate Attacker") that is architected around one core productized component — Armadin Red, the agentic attack platform — which is the specific surface that integrates with partner platforms such as CrowdStrike Falcon (via Project QuiltWorks) and Palo Alto Networks Unit 42 Frontier AI Defense. Together, the Armadin Platform and Armadin Red form the company's continuous, agentic red-teaming and remediation offering: Armadin Red runs the autonomous external attack campaigns and produces validated kill chains, while the broader Armadin Platform wraps that capability with human red-team consulting, threat intelligence, multi-modal attack-surface coverage, and actionable remediation guidance for Fortune 100/enterprise customers.
Differentiator
Problem solved
Functional benefit
Brands
- Armadin Red: Armadin's agentic AI-driven attack platform used for continuous, autonomous red teaming and remediation, deployed in partnership with Palo Alto Networks Unit 42 and CrowdStrike Falcon.
Products and services
- Armadin Platform (The Ultimate Attacker) Armadin's flagship enterprise-grade AI-native cybersecurity platform, marketed as 'The Ultimate Attacker.' It is the industry's first continuous, agentic red-teaming and remediation platform that identifies and proves exploitable risk across the entire external and internal attack surface. The platform deploys swarms of AI agents that run the Reconnaissance, Adaptive Scouting, and Precision Strike phases of an attack, with human-in-the-loop controls, scoped execution, and enterprise-grade scale. Architected for Fortune 100 and the most complex organizations, it bundles red-team consulting, threat intelligence, AI experience, and systems engineering expertise.
- Armadin Red Armadin Red is the company-named agentic attack platform component of the Armadin Platform. It is the specific surface that integrates with CrowdStrike's Falcon platform through Project QuiltWorks and with Palo Alto Networks' Unit 42 Frontier AI Defense service. It performs autonomous, AI-driven external attack validation and produces validated kill chains showing exploitable risk on customer environments.
- Armadin Red Team Consulting (Professional Services) Statement-of-Work (SOW)-driven professional services including integration, onboarding, training, and bespoke offensive security and incident response engagements performed by Armadin's red team consultants who deliver offensive security and incident response for the most complex and targeted environments. Travel and lodging expenses are reimbursable per SOW.
Quantifiable outcome
- Fortune 100 EY customer identified nearly 45 million vulnerabilities within hours of using the Project QuiltWorks platform (of which Armadin is a technology partner)
- +2 more outcomes
Companies that use Armadin Security
Customer profileNamed customers7 records
Segments4 records
Ideal customer profiles4 records
Armadin Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration2 records
AI capability10 records
Feature8 records
Armadin Security partnerships and signals
Strategic signalPartnerships
14 partnerships are on record, tiered core, minor (co-coalition) and flagship.
- AnthropiccoreFrontier AI model provider. Anthropic's Claude / Opus 4.7 models are integrated across the CrowdStrike Falcon platform and Armadin's offensive security tooling via Project QuiltWorks, used to enhance vulnerability discovery and simulate controlled hyperattack scenarios. The platform page also references the November 2025 Anthropic disclosure of China-based threat actors using Claude Code to orchestrate cyberattacks (80–90% autonomous, 4–6 human decisions per campaign) as a motivating example.
- OpenAIcoreFrontier AI model provider whose models are used within the CrowdStrike Project QuiltWorks coalition (alongside Anthropic) to discover and prioritize vulnerabilities at enterprise scale.
- Accentureminor (co-coalition)Global systems integrator member of CrowdStrike's Project QuiltWorks coalition. Developed autonomous security agents on the Falcon platform to automate vulnerability assessment. Listed as a co-coalition partner with Armadin but no direct Armadin-Accenture relationship is documented in the source.
- EYminor (co-coalition)Global consulting firm and member of CrowdStrike's Project QuiltWorks coalition. A Fortune 100 customer working with EY identified nearly 45 million vulnerabilities within hours.
- IBMminor (co-coalition)Consulting partner within CrowdStrike's Project QuiltWorks coalition (alongside Accenture, EY, and others).
- Cognizantminor (co-coalition)Global systems integrator added to CrowdStrike's Project QuiltWorks AI security coalition as one of eight new partners alongside Armadin.
- HCLTechminor (co-coalition)Global systems integrator added to CrowdStrike's Project QuiltWorks AI security coalition as one of eight new partners alongside Armadin.
- Infosysminor (co-coalition)Global systems integrator added to CrowdStrike's Project QuiltWorks AI security coalition as one of eight new partners alongside Armadin.
- KPMGminor (co-coalition)Global consulting firm added to CrowdStrike's Project QuiltWorks AI security coalition as one of eight new partners alongside Armadin.
- NTT DATAminor (co-coalition)Global systems integrator added to CrowdStrike's Project QuiltWorks AI security coalition as one of eight new partners alongside Armadin.
- Tata Consultancy Services (TCS)minor (co-coalition)Global systems integrator added to CrowdStrike's Project QuiltWorks AI security coalition as one of eight new partners alongside Armadin.
- Wiprominor (co-coalition)Global systems integrator added to CrowdStrike's Project QuiltWorks AI security coalition as one of eight new partners alongside Armadin.
- CrowdStrikeflagshipMulti-faceted strategic partnership. (1) CrowdStrike founder/CEO George Kurtz joined Armadin's Board of Directors as an independent member (announced April 27, 2026). (2) CrowdStrike expanded Project QuiltWorks — an industry-wide AI coalition that uses frontier AI from OpenAI and Anthropic to discover and prioritize vulnerabilities — and added Armadin as a technology partner alongside Cognizant, HCLTech, Infosys, KPMG, NTT DATA, TCS, and Wipro (announced May 2026). (3) Armadin Red is integrated into the CrowdStrike Falcon platform so organizations can move from autonomous offensive assessment directly into defensive action. Early outcome: an EY Fortune 100 customer identified ~45 million vulnerabilities in hours.
- Palo Alto Networks (Unit 42)flagshipPartnership integrates Armadin's autonomous external attack platform into Palo Alto Networks' Unit 42 Frontier AI Defense service. When a Unit 42 engagement includes external perimeter validation, the service runs a machine-speed Armadin-powered attack campaign using 50,000+ attack templates against the customer's internet-facing assets, producing validated kill chains showing where an AI-equipped adversary could exploit vulnerabilities. Joint lockup marketing asset on armadin.com.
Scale indicators11 records
Recent moves7 records
Expansion highlights7 records
Armadin Security competitors and assessment
Company assessmentDirect peers
- SafeBreach: SafeBreach operates a breach-and-attack-simulation (BAS) platform that continuously runs simulated attack scenarios against enterprise environments to validate security controls. Like Armadin, it serves Fortune 500 security teams seeking validated kill chains rather than theoretical findings, and is sold via subscription plus professional services.
- Pentera: Pentera is the closest direct competitor in automated security validation, offering an agentless platform that continuously emulates real attacker behavior against enterprise networks. Both Armadin Red and Pentera target Fortune 100/500 CISOs seeking to replace point-in-time pentests with continuous, machine-speed validation of exploitable risk.
- Picus Security: Picus Security delivers a continuous security validation platform that combines breach-and-attack simulation with automated security control assessment. Like Armadin, it targets enterprise CISOs with validated exposure data and remediation guidance.
- Horizon3.ai: Horizon3.ai offers an autonomous penetration testing platform (NodeZero) that continuously identifies and verifies exploitable attack paths in enterprise environments. It is a direct functional competitor to Armadin Red, focused on autonomous, AI-driven offensive validation rather than checklist-based scanning.
- AttackIQ: AttackIQ provides a continuous security validation platform built on the MITRE ATT&CK framework, emulating adversary behaviors against enterprise environments. It is one of the most established direct peers in the breach-and-attack-simulation category that Armadin is targeting with its agentic red-teaming platform.
Broad incumbents
- CrowdStrike: CrowdStrike is both a flagship distribution partner (Falcon / Project QuiltWorks) and a broad incumbent that could internalize agentic red-teaming capabilities within Falcon. George Kurtz (CrowdStrike CEO) sits on Armadin's board, illustrating the overlap between Armadin's offensive platform and CrowdStrike's defensive platform.
- Palo Alto Networks: Palo Alto Networks integrates Armadin Red into its Unit 42 Frontier AI Defense service and is therefore both a flagship partner and a broad incumbent in cybersecurity. Expanse (an ASM company acquired by Palo Alto for $1.2B) was co-founded by Armadin's VP of Product Greg Heon, illustrating the deep technical overlap.
- Mandiant (Google Cloud): Mandiant is the global leader in incident response and offensive security services, founded by Armadin CEO Kevin Mandia and now part of Google Cloud. It is a broad incumbent whose red-team and incident-response practices overlap with Armadin's continuous agentic offering, and is the spiritual and personnel predecessor to Armadin.
Emerging players
- Scythe: Scythe is an emerging adversary-emulation platform built by veteran red-team operators that lets enterprises simulate real-world attack scenarios. It overlaps with Armadin's tradecraft-driven offensive approach but is smaller in scale and earlier in commercial maturity.
- Bishop Fox: Bishop Fox is an offensive-security services firm specializing in pentesting, red teaming, and attack-surface management for Fortune 500 customers. It is a comparably sized emerging player in the same offensive-security buyer segment that Armadin targets, with overlapping services-led delivery.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks7 records
Key highlights7 records
Customer concentration
Armadin Security social profiles
Digital presenceArmadin Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Armadin Security leadership team
Management profileNumber of profiles
Profiles10 records
Armadin Security subsidiaries and ownership
Company hierarchySubsidiaries1 record
Armadin Security funding detail
Funding detailFunding overview
Funding rounds3 records
Investors8 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Armadin Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Armadin Security
What does Armadin Security do?
Armadin Security provides an AI-native, agentic offensive cybersecurity platform that deploys autonomous AI agents to continuously perform reconnaissance, adaptive scouting, and precision-strike phases against an organization's full attack surface. The platform, branded as Armadin Red, produces validated kill chains and prioritized remediation guidance to expose exploitable risk. The company also delivers SOW-based professional services from its red team consultants for incident response and bespoke offensive engagements.
Is Armadin Security a public or private company?
Armadin Security is a private company. It is classified as venture growth investor backed and is currently operating.
When was Armadin Security founded?
Armadin Security was founded in 2024. It employs 51 to 100 people.
Where is Armadin Security based?
Armadin Security is headquartered in Menlo Park, United States, in the North America region.
How does Armadin Security make money?
Four revenue lines are on record. Subscription Services (Armadin Red platform) is the primary driver. The others are professional Services (Red Team Consulting), evaluation / Proof-of-Concept Engagements and reseller Channel Distribution.
Who are Armadin Security's main competitors?
Direct peers on record are SafeBreach, Pentera, Picus Security, Horizon3.ai and AttackIQ. Broad incumbents are CrowdStrike, Palo Alto Networks and Mandiant (Google Cloud). Emerging players are Scythe and Bishop Fox.
Does Armadin Security have an API?
No public API is recorded for Armadin Security.
What industry is Armadin Security in?
Armadin Security's product category is AI-Native Offensive Cybersecurity Platform. Its primary akta.pro industry code is HDAFAFAD, Intrusion Detection & Prevention Systems (IDS/IPS), with a secondary code of HDADABAH, Intrusion Prevention/Detection Systems (IPS/IDS). Its NAICS code is 561621.