SecStrike
- Company typePrivate
- Founded-
- HeadquartersPhra Khanong, Thailand
- Headcount11–50
- GTM typeB2B
- OfferingServices
What SecStrike does
SecStrike is a private offensive security firm headquartered in Bangkok, Thailand, with a UK operating entity (SecStrike UK Ltd.) based at Oxford Science Park. The company delivers penetration testing, vulnerability assessment, red teaming, phishing simulation, source code review, and cyber incident response services — including ransomware crisis response, compromised assessment, digital forensics, and threat response drills — to enterprise organizations with significant digital attack surfaces across web applications, APIs, cloud environments, and internal networks. Its primary customer segment is enterprises that need continuous visibility into exploitable risk beyond periodic assessments, supported by compliance-driven testing use cases (PDPA, OWASP, NIST).
The firm's core technology is EchoStrike, an AI-native pentest platform that SecStrike designed, patented, and operates in-house. EchoStrike applies AI-assisted evidence triage, pattern correlation, and remediation drafting, with human experts validating findings and assessing real-world exploitability — a model SecStrike describes as 'Symbiotic Security.' A second platform, PTX (SecStrike PTX), provides Pentest-as-a-Service delivery with real-time vulnerability dashboards, remediation tracking, retest workflows, and authenticated portal-based reporting, replacing static PDF-only reporting. Engagements are delivered by a team holding over 20 internationally recognized certifications (OSCP, OSWE, OSEP, OSED, OSCE, CISSP, CISM, CISA, and others), and SecStrike is certified under ISO/IEC 27001 and ISO 9001.
SecStrike's business model combines project-based and retainer-based professional services with an emerging recurring PtaaS subscription layer via PTX. Pricing is quote-based and consultative, with multi-year engagement contracts available and ransomware crisis support offered as a pre-arranged retainer. Go-to-market is direct enterprise sales through inbound content marketing (bilingual Thai/English SEO-driven blog, 'Speak to an Expert' CTAs), targeting enterprise buyers and IT/security decision-makers worldwide. The company closed a funding round in late November 2025 and has not publicly disclosed revenue.
SecStrike firmographics
Firmographics- Name
- SecStrike
- Legal name
- SecStrike UK Ltd.
- Website
- https://secstrike.ai
- Company type
- Private
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Ownership category
- akta.pro rank
SecStrike industry classification
Industry- Product category
- Offensive Security Services
- NAICS
- Computer Systems Design and Related Services (5415), Computer Systems Design and Related Services (54151)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Penetration Testing & Red Teaming (BPAKAHAF)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Penetration Testing & Red Teaming (BPAKADAE)
Keywords
Where SecStrike is headquartered
LocationHeadquarters
- HQ city
- Phra Khanong
- HQ country
- Thailand
- HQ region
- Asia
Offices2 records
Markets served
SecStrike business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Offensive Security Professional Services: Project-based and retainer-based engagements for penetration testing, vulnerability assessment, red teaming, phishing simulation, source code review, ransomware crisis response, compromised assessment, digital forensics, and cyber threat response drills. Services are powered by the EchoStrike AI platform and delivered by certified specialists.
- Pentest as a Service (PtaaS) via PTX Platform: On-demand platform-based security testing delivery enabling organizations to engage specialists, track findings in real time, request retests, and manage remediation workflows through a secure authenticated portal. Continuous validation model.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Quote-based / project scoping — no public pricing tiers listed |
Distribution channels1 record
Marketing channels4 records
SecStrike product offering
Product offeringCore offering
SecStrike is an offensive security practice that builds and operates its own proprietary EchoStrike AI pentest platform and delivers expert-led penetration testing, vulnerability assessment, red teaming, phishing simulation, source code review, and cyber incident response services (ransomware crisis response, compromised assessment, digital forensics, threat response drills, credential leak checks). Engagements are powered by the EchoStrike platform and delivered through the PTX platform, which provides Pentest-as-a-Service with real-time vulnerability visibility, remediation tracking, retest workflows, and authenticated portal delivery of findings.
Product overview
SecStrike is an offensive security practice that operates two interconnected products: EchoStrike, an AI-native pentest platform that the team designed and patented in-house, and the PTX Platform, which provides Pentest as a Service with real-time vulnerability visibility, expert-reviewed findings, remediation tracking, and retest workflows. These platforms are paired with certified cybersecurity specialists to deliver continuous security validation across web applications, APIs, networks, cloud infrastructure, and human attack surfaces. SecStrike offers offensive services (Penetration Testing, Vulnerability Assessment, Red Teaming, Phishing Simulation, Source Code Review) and cyber incident response services (Ransomware Crisis Response, Compromised Assessment, Digital Forensics, Cyber Threat Response Drill, Credential Leaked Check).
Differentiator
Problem solved
Functional benefit
Brands
- EchoStrike: AI-native pentest platform built and operated by SecStrike for continuous security validation, powering all SecStrike engagements.
Products and services
- Penetration Testing Expert-led penetration testing services identifying exploitable vulnerabilities in web applications, APIs, cloud infrastructure, internal networks, and identity systems for enterprise organizations.
- Vulnerability Assessment Vulnerability assessment services that evaluate exploitable risk across enterprise digital attack surfaces, complementing penetration testing.
- Red Teaming Adversary simulation and red team engagements that evaluate how organizations stand up against realistic attacker behavior through expert-led offensive testing.
- Phishing Attack Simulation Phishing simulation services that test human attack surfaces and improve employee detection and response to social engineering attacks.
- Source Code Review Manual and expert-led source code review to identify security weaknesses in application code beyond automated scanning.
- Ransomware Crisis Response Pre-arranged response service offering immediate expert support during ransomware events, including containment, root cause analysis, threat artefact removal, and recovery coordination.
- Compromised Assessment Post-breach investigation services for organizations with suspected or confirmed compromised systems, identifying attacker entry vectors and persistence mechanisms.
- Digital Forensics Digital forensics services supporting post-incident investigation, root cause analysis, and recovery coordination following cyber incidents.
- Cyber Threat Response Drill Scenario-based exercises and drills that test how organizational teams respond to realistic cyber incident scenarios including ransomware, data breaches, and executive decision-making.
- Credential Leaked Check Credential exposure check service identifying leaked or compromised credentials associated with an organization, part of SecStrike's cyber incident response offerings.
- EchoStrike (AI Pentest Platform) AI-native pentest platform designed, patented, and operated in-house by SecStrike. EchoStrike powers SecStrike's offensive security engagements, accelerating collaboration, evidence triage, pattern correlation, remediation drafting, and real-time vulnerability visibility.
- PTX Platform (Pentest as a Service) Pentest-as-a-Service delivery platform providing secure report delivery, real-time finding dashboards, severity breakdown, remediation tracking, retest status, and executive/technical visibility for vulnerability assessments, penetration testing, API testing, web application testing, and security configuration reviews.
Companies that use SecStrike
Customer profileSegments3 records
Ideal customer profiles3 records
SecStrike technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability4 records
Feature4 records
SecStrike partnerships and signals
Strategic signalScale indicators3 records
Recent moves6 records
Expansion highlights6 records
SecStrike competitors and assessment
Company assessmentBroad incumbents
- NCC Group: NCC Group is a large, established cybersecurity firm offering pentesting, red teaming, and incident response globally. It represents the broad-incumbent competitor SecStrike must displace to win enterprise mandates.
- Trustwave: Trustwave is an MSSP with offensive security services including pentesting, threat detection, and incident response — overlapping with SecStrike's offensive and cyber-incident-response offerings.
Emerging players
- VerSprite: VerSprite is a specialized offensive security firm offering application security testing, red teaming, and threat modeling — closely comparable to SecStrike's offensive services portfolio.
- Pentera: Pentera offers automated security validation as a continuous pentest alternative. While SecStrike emphasizes human expert judgment, Pentera's automated approach to continuous validation competes for the same buyer budget category.
Direct peers
- Bugcrowd: Bugcrowd runs crowdsourced pentest and bug bounty programs through its platform with AI-augmented triage — a comparable model of platform-driven offensive security delivery with expert validation.
- NetSPI: NetSPI is an enterprise-focused offensive security firm offering penetration testing, red teaming, and vulnerability management through its Resolve platform — comparable to SecStrike's PTX/EchoStrike-driven engagements.
- Synack: Synack delivers crowdsourced pentesting through a platform with vetted-talent curation and continuous testing programs. Its hybrid of AI-augmented triage and human expert reviewers mirrors SecStrike's Symbiotic Security approach.
- HackerOne: HackerOne operates a bug bounty and security testing platform combining crowdsourced researchers with AI and managed services. It overlaps with SecStrike's vulnerability discovery and continuous validation positioning.
- Bishop Fox: Bishop Fox is a well-established offensive security firm specializing in pentesting, red teaming, and adversary simulation, with COSMOS as a proprietary testing platform — comparable to SecStrike's expert-led offensive security positioning.
- Cobalt: Cobalt pioneered the Pentest-as-a-Service model, offering on-demand access to vetted pentesters through a platform with real-time findings dashboards and retest workflows — directly comparable to SecStrike's PTX platform and EchoStrike delivery model.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks5 records
Key highlights7 records
Customer concentration
SecStrike social profiles
Digital presenceSecStrike compliance and trust
Trust signalCompliance2 records
SecStrike financial estimates
Financial estimateRevenue estimate
Valuation estimate
SecStrike leadership team
Management profileNumber of profiles
SecStrike funding detail
Funding detailFunding overview
Funding rounds1 record
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
SecStrike M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about SecStrike
What does SecStrike do?
SecStrike is an offensive security practice that builds and operates its own proprietary EchoStrike AI pentest platform and delivers expert-led penetration testing, vulnerability assessment, red teaming, phishing simulation, source code review, and cyber incident response services (ransomware crisis response, compromised assessment, digital forensics, threat response drills, credential leak checks). Engagements are powered by the EchoStrike platform and delivered through the PTX platform, which provides Pentest-as-a-Service with real-time vulnerability visibility, remediation tracking, retest workflows, and authenticated portal delivery of findings.
Is SecStrike a public or private company?
SecStrike is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was SecStrike founded?
SecStrike was founded in -1. It employs 11 to 50 people.
Where is SecStrike based?
SecStrike is headquartered in Phra Khanong, Thailand, in the Asia region.
How does SecStrike make money?
Two revenue lines are on record. Offensive Security Professional Services are the primary driver. The others are pentest as a Service (PtaaS) via PTX Platform.
Who are SecStrike's main competitors?
Broad incumbents on record are NCC Group and Trustwave. Emerging players are VerSprite and Pentera. Direct peers are Bugcrowd, NetSPI, Synack, HackerOne, Bishop Fox and Cobalt.
Does SecStrike have an API?
No public API is recorded for SecStrike.
What industry is SecStrike in?
SecStrike's product category is Offensive Security Services. Its primary akta.pro industry code is BPAKAHAF, Penetration Testing & Red Teaming, with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 5415 and its SIC code is 7373.