Developer docs
API playgroundTry for free, no card

Search company profiles

Aftra

Full company profile

uuid00qorfz

Namestring
Aftra
Legal namestring
Aftra ehf.
Websiteurl
aftra.io
Company typeenum
Private
Founded yearint
2024
Descriptiontext

Aftra ehf. is an Icelandic-headquartered cybersecurity software company that provides an External Attack Surface Management (EASM) platform. The company, headquartered in Reykjavík at Borgartún 37, emerged as an independent entity in May 2024 after operating as a unit inside the cybersecurity consultancy Syndis; both Aftra and Syndis remain subsidiaries of the holding company Skyggnir. The platform continuously discovers an organization's external digital assets, including domains, subdomains, shadow IT, employee accounts on third-party services, and exposed credentials, then maps findings to vulnerabilities using a combination of web vulnerability scanners, a proprietary always-running scanner, and integrated Nessus network scanning. The core platform is augmented by add-on modules: an Internal Vulnerability Scanner that simulates insider or USB-borne threats beyond the firewall, an API Scanner for API endpoint discovery, a PCI Scanner for PCI DSS compliance, and Security Campaigns that surface employee-level digital footprint and breach exposure.

Aftra serves three primary personas within a customer organization: C-suite executives who need business-centric KPIs and security scores in light of new EU personal-liability regulations (NIS2, DORA), IT teams that need prioritized vulnerability remediation, and security teams that need continuous threat and anomaly detection. Named customers include Vodafone, Veritas, Securitas, Landspítali (Icelandic National Hospital), Innnes, Dominoes, Sýn, Verne Global, Embla Medical, Byko, Hagar, Origo, GoGift, and Blue Car Rental, spanning telecom, healthcare, retail, food wholesale, and security services. The platform integrates with Microsoft Defender, Slack, Jira, and Microsoft Teams for workflow handoff.

Short descriptiontext

Aftra is an Icelandic cybersecurity company offering an External Attack Surface Management platform that continuously maps external assets, employee digital footprints, and vulnerabilities, serving C-suite, IT, and security teams primarily across European mid-market and enterprise customers.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
11–50
akta.pro rankint
HeadquartersReykjavík, Iceland
HQ citystring
Reykjavík
HQ countrystring
Iceland
HQ regionstring
Europe
Markets served

Serves global market

Offices1 record

Each record includes

City, Country, Type, Description, Source

Keyword5 values
attack surface management, vulnerability monitoring, cybersecurity platform, digital footprint analysis, employee risk scoring
Industry3 codes
1Attack Surface Management (EASM/CAASM)
CodeHDADAHACPrimaryYes
2SaaS Security Posture Management (SSPM)
CodeHDADADAIPrimaryNo
3Access Security & Identity Threat Detection (ITDR, UEBA for Identity)
CodeHDADAAAIPrimaryNo
NAICS code1 code
  • Computer Systems Design and Related Services54151
SIC code1 code
  • Services-Prepackaged Software7372
Product category
Cybersecurity / Attack Surface Management
Social media profiles3 records
GTM motion2 records

Each record includes

Type, Description, Source

Revenue model1 record
1SaaS Subscription
TypeSubscription Recurring
Description

Subscription-based pricing model tailored to the size of the organization's digital footprint and specific features required. Pricing starts at 490 EUR per month and is quote-based for enterprise customers.

aftra.io
Marketing channels7 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels3 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Pricing details1 tier
1Starting tier at 490 EUR/month
ModelSubscriptionBilling cadenceMonthly
Notes

Starting at 490 EUR per month, pricing scales based on organization size and digital footprint complexity. Personalized quotes available through sales team.

aftra.io
GTM typeB2B
B2B
Offering typeSoftware
Software
Core offering1 text field

Aftra provides an External Attack Surface Management (EASM) SaaS platform that continuously discovers exposed digital assets, employee risks, shadow IT, and vulnerabilities from a hacker's perspective, then converts findings into prioritized, actionable insights and security KPIs. The core platform is sold as a subscription (starting at 490 EUR/month) and supplemented by add-on modules including an Internal Vulnerability Scanner, API Scanner, PCI Scanner, and Security Campaigns for employee risk management.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 2 values shown
  • IBM Cost of Data Breach Report 2025: Attack surface management tools decreased the average cost of a data breach by $160,547
+1 more record
Product overview1 text field

Aftra is a cybersecurity platform built around External Attack Surface Management (EASM). The core Aftra platform provides continuous external vulnerability scanning and monitoring, discovering exposed assets and turning findings into prioritized actions. The platform is designed for both C-suite executives (providing simplified dashboards and KPIs) and IT/security teams (providing technical vulnerability management). The product portfolio includes the core Aftra EASM platform plus add-on modules: Internal Vulnerability Scanner (scans beyond the firewall for internal threats), Security Campaigns (employee security awareness through digital footprint visualization), API Scanner (discovers and secures API attack surface), and PCI Scanner (PCI DSS compliance scanning). Additional features include Dashboard Metrics, Performance Reports with AI-driven insights, Intelligent Suggestions for remediation, and Employee Risk Scoring.

Product and service5 records
1Aftra Core Platform (EASM)
CategoryCore Platform
Description

External Attack Surface Management (EASM) SaaS platform that continuously discovers exposed digital assets, employee risks, shadow IT, and vulnerabilities from a hacker's perspective and converts findings into prioritized actions, security scoring, and executive-ready KPIs for security, IT, and leadership teams.

2Internal Vulnerability Scanner
3API Scanner
CategoryAdd-on Module
Description

Scanner that discovers and secures hidden API attack surfaces within an organization's digital footprint, identifying API endpoints as part of overall attack surface management.

4PCI Scanner
CategoryAdd-on Module
Description

Specialized scanner designed to help organizations with PCI DSS compliance requirements through targeted scanning for payment card industry security.

5Security Campaigns
CategoryAdd-on Module
Description

Module that enables IT managers to create campaigns showing employees their digital footprint, where company accounts are registered online, and whether their passwords have been leaked, with individual employee risk scores to reduce account takeover risk.

Scale indicator4 records

Each record includes

Type, Value, Description, Source

Partnership3 partners
1NIC (Nordic Internet Exchange)
Strategic tierCoreTypeChannel Partner/ Reseller/ DistributorAnnounced on2026-04-30
Description

Partnership with NIC (Nordic Internet Exchange) to expand into the Swedish market, bridging the gap between compliance and cybersecurity exposure. NIC provides internet exchange and related services in the Nordic region.

aftra.io
Strategic tierCoreTypeChannel Partner/ Reseller/ DistributorAnnounced on2024-10-18
Description

Strategic partnership with Finnish technology firm Abero Technologies OY to expand into the Finnish market. Ben Bergman, COO at Abero, contributed Zero Trust expertise and recommendations for Aftra's thought leadership content. Abero specializes in helping organizations adopt Zero Trust architecture.

Strategic tierCoreTypeImplementation/ SI/ Consulting Partner
Description

Aftra's sister company and former parent company. Syndis is an Icelandic cybersecurity consulting firm specializing in security management including compliance, prevention, and post-incident mitigation. Syndis works closely with Aftra to deliver cybersecurity software and services to Icelandic and foreign markets. Both companies are subsidiaries of Skyggnir holding.

Recent move9 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeDirect peer
Description

Microsoft's Defender EASM, integrated into the Defender suite, targets the same enterprise external attack surface use case as Aftra, often bundled with broader Microsoft security commitments.

TypeBroad incumbent
Description

Mandiant's ASM offering, now part of Google Cloud, provides enterprise-grade continuous external monitoring and is a broader-incumbent alternative for the same EASM use case Aftra targets.

TypeBroad incumbent
Description

Bitsight delivers security ratings and attack surface analytics for enterprises and third-party risk programs, competing with Aftra's KPI-driven posture scoring and continuous exposure monitoring at a larger scale.

TypeBroad incumbent
Description

SecurityScorecard provides enterprise security ratings plus attack surface intelligence, overlapping with Aftra's executive-facing security scoring and continuous monitoring but on a much larger scale and with a broader vendor risk offering.

TypeDirect peer
Description

Detectify is a Sweden-based EASM and dynamic application security testing platform with a strong Nordic presence, competing directly with Aftra for the same regional enterprise and mid-market security buyers.

TypeBroad incumbent
Description

Wiz is a leading CNAPP platform whose external attack surface and exposure modules increasingly overlap with EASM, making it a credible broader-incumbent alternative for cloud-forward enterprise buyers comparing solutions to Aftra.

TypeDirect peer
Description

Censys provides internet-wide asset discovery and external attack surface management used by security teams, overlapping directly with Aftra's asset mapping and exposure monitoring capabilities.

TypeDirect peer
Description

CyCognito is an external attack surface management and risk prioritization platform sold to enterprises and security teams, directly comparable to Aftra's continuous EASM and prioritization workflow.

TypeDirect peer
Description

CrowdStrike's external attack surface management module, Falcon Surface, is part of the Falcon platform and competes head-on with Aftra's core EASM offering for enterprise security buyers, with similar asset discovery and exposure prioritization.

TypeDirect peer
Description

Tenable's attack surface management product competes directly with Aftra, combining external ASM with Tenable's Nessus vulnerability data (which Aftra also integrates with), targeting similar IT and security personas.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat5 records

Each record includes

Type, Details

Key risks5 records

Each record includes

Headline, Details, Source

Key highlights6 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers6 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment3 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile3 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
No

Docs URL, Description

Integration4 records

Each record includes

Title, Type, Description, Source

AI capability5 records

Each record includes

Type, Description, Source

AI maturity
App detail

Has app

Feature11 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles5 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
No data
Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Aftra

Cybersecurity / Attack Surface Managementaftra.io

Aftra is an Icelandic cybersecurity company offering an External Attack Surface Management platform that continuously maps external assets, employee digital footprints, and vulnerabilities, serving C-suite, IT, and security teams primarily across European mid-market and enterprise customers.

What Aftra does

Aftra ehf. is an Icelandic-headquartered cybersecurity software company that provides an External Attack Surface Management (EASM) platform. The company, headquartered in Reykjavík at Borgartún 37, emerged as an independent entity in May 2024 after operating as a unit inside the cybersecurity consultancy Syndis; both Aftra and Syndis remain subsidiaries of the holding company Skyggnir. The platform continuously discovers an organization's external digital assets, including domains, subdomains, shadow IT, employee accounts on third-party services, and exposed credentials, then maps findings to vulnerabilities using a combination of web vulnerability scanners, a proprietary always-running scanner, and integrated Nessus network scanning. The core platform is augmented by add-on modules: an Internal Vulnerability Scanner that simulates insider or USB-borne threats beyond the firewall, an API Scanner for API endpoint discovery, a PCI Scanner for PCI DSS compliance, and Security Campaigns that surface employee-level digital footprint and breach exposure.

Aftra serves three primary personas within a customer organization: C-suite executives who need business-centric KPIs and security scores in light of new EU personal-liability regulations (NIS2, DORA), IT teams that need prioritized vulnerability remediation, and security teams that need continuous threat and anomaly detection. Named customers include Vodafone, Veritas, Securitas, Landspítali (Icelandic National Hospital), Innnes, Dominoes, Sýn, Verne Global, Embla Medical, Byko, Hagar, Origo, GoGift, and Blue Car Rental, spanning telecom, healthcare, retail, food wholesale, and security services. The platform integrates with Microsoft Defender, Slack, Jira, and Microsoft Teams for workflow handoff.

Aftra firmographics

Firmographics
Name
Aftra
Legal name
Aftra ehf.
Website
https://aftra.io
Company type
Private
Founded year
2024
Operating status
Operating
Headcount range
11–50 employees
Short description
Aftra is an Icelandic cybersecurity company offering an External Attack Surface Management platform that continuously maps external assets, employee digital footprints, and vulnerabilities, serving C-suite, IT, and security teams primarily across European mid-market and enterprise customers.
Ownership category
akta.pro rank

Aftra industry classification

Industry
Product category
Cybersecurity / Attack Surface Management
NAICS
Computer Systems Design and Related Services (54151)
SIC
Services-Prepackaged Software (7372)
akta.pro primary industry
Attack Surface Management (EASM/CAASM) (HDADAHAC)
akta.pro secondary industries
SaaS Security Posture Management (SSPM) (HDADADAI), Access Security & Identity Threat Detection (ITDR, UEBA for Identity) (HDADAAAI)

Keywords

  • Attack surface management
  • Vulnerability monitoring
  • Cybersecurity platform
  • Digital footprint analysis
  • Employee risk scoring

Where Aftra is headquartered

Location

Headquarters

HQ city
Reykjavík
HQ country
Iceland
HQ region
Europe

Offices1 record

Markets served

Aftra business model

Business model
GTM type
B2B
Offering type
Software
Cost components
Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure

Revenue model

  1. SaaS Subscription: Subscription-based pricing model tailored to the size of the organization's digital footprint and specific features required. Pricing starts at 490 EUR per month and is quote-based for enterprise customers.

Pricing tiers

ModelBillingPrice
SubscriptionMonthlyStarting tier at 490 EUR/month

Go-to-market motion2 records

Distribution channels3 records

Marketing channels7 records

Aftra product offering

Product offering

Core offering

Aftra provides an External Attack Surface Management (EASM) SaaS platform that continuously discovers exposed digital assets, employee risks, shadow IT, and vulnerabilities from a hacker's perspective, then converts findings into prioritized, actionable insights and security KPIs. The core platform is sold as a subscription (starting at 490 EUR/month) and supplemented by add-on modules including an Internal Vulnerability Scanner, API Scanner, PCI Scanner, and Security Campaigns for employee risk management.

Product overview

Aftra is a cybersecurity platform built around External Attack Surface Management (EASM). The core Aftra platform provides continuous external vulnerability scanning and monitoring, discovering exposed assets and turning findings into prioritized actions. The platform is designed for both C-suite executives (providing simplified dashboards and KPIs) and IT/security teams (providing technical vulnerability management). The product portfolio includes the core Aftra EASM platform plus add-on modules: Internal Vulnerability Scanner (scans beyond the firewall for internal threats), Security Campaigns (employee security awareness through digital footprint visualization), API Scanner (discovers and secures API attack surface), and PCI Scanner (PCI DSS compliance scanning). Additional features include Dashboard Metrics, Performance Reports with AI-driven insights, Intelligent Suggestions for remediation, and Employee Risk Scoring.

Differentiator

Problem solved

Functional benefit

Products and services

  • Aftra Core Platform (EASM) External Attack Surface Management (EASM) SaaS platform that continuously discovers exposed digital assets, employee risks, shadow IT, and vulnerabilities from a hacker's perspective and converts findings into prioritized actions, security scoring, and executive-ready KPIs for security, IT, and leadership teams.
  • Internal Vulnerability Scanner
  • API Scanner Scanner that discovers and secures hidden API attack surfaces within an organization's digital footprint, identifying API endpoints as part of overall attack surface management.
  • PCI Scanner Specialized scanner designed to help organizations with PCI DSS compliance requirements through targeted scanning for payment card industry security.
  • Security Campaigns Module that enables IT managers to create campaigns showing employees their digital footprint, where company accounts are registered online, and whether their passwords have been leaked, with individual employee risk scores to reduce account takeover risk.

Quantifiable outcome

  • IBM Cost of Data Breach Report 2025: Attack surface management tools decreased the average cost of a data breach by $160,547
  • +1 more outcomes

Companies that use Aftra

Customer profile

Named customers6 records

Segments3 records

Ideal customer profiles3 records

Aftra technology and API

Technology

Technology focussed Yes

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

Integration4 records

AI capability5 records

Feature11 records

Aftra partnerships and signals

Strategic signal

Partnerships

Three partnerships are on record, tiered core.

  • NIC (Nordic Internet Exchange)coreChannel Partner/ Reseller/ Distributor · 30 April 2026Partnership with NIC (Nordic Internet Exchange) to expand into the Swedish market, bridging the gap between compliance and cybersecurity exposure. NIC provides internet exchange and related services in the Nordic region.
  • Abero Technologies OYcoreChannel Partner/ Reseller/ Distributor · 18 October 2024Strategic partnership with Finnish technology firm Abero Technologies OY to expand into the Finnish market. Ben Bergman, COO at Abero, contributed Zero Trust expertise and recommendations for Aftra's thought leadership content. Abero specializes in helping organizations adopt Zero Trust architecture.
  • SyndiscoreImplementation/ SI/ Consulting PartnerAftra's sister company and former parent company. Syndis is an Icelandic cybersecurity consulting firm specializing in security management including compliance, prevention, and post-incident mitigation. Syndis works closely with Aftra to deliver cybersecurity software and services to Icelandic and foreign markets. Both companies are subsidiaries of Skyggnir holding.

Scale indicators4 records

Recent moves9 records

Expansion highlights6 records

Aftra competitors and assessment

Company assessment

Direct peers

  • Microsoft Defender External Attack Surface Management: Microsoft's Defender EASM, integrated into the Defender suite, targets the same enterprise external attack surface use case as Aftra, often bundled with broader Microsoft security commitments.
  • Detectify: Detectify is a Sweden-based EASM and dynamic application security testing platform with a strong Nordic presence, competing directly with Aftra for the same regional enterprise and mid-market security buyers.
  • Censys: Censys provides internet-wide asset discovery and external attack surface management used by security teams, overlapping directly with Aftra's asset mapping and exposure monitoring capabilities.
  • CyCognito: CyCognito is an external attack surface management and risk prioritization platform sold to enterprises and security teams, directly comparable to Aftra's continuous EASM and prioritization workflow.
  • CrowdStrike Falcon Surface: CrowdStrike's external attack surface management module, Falcon Surface, is part of the Falcon platform and competes head-on with Aftra's core EASM offering for enterprise security buyers, with similar asset discovery and exposure prioritization.
  • Tenable ASM (Tenable.io): Tenable's attack surface management product competes directly with Aftra, combining external ASM with Tenable's Nessus vulnerability data (which Aftra also integrates with), targeting similar IT and security personas.

Broad incumbents

  • Mandiant (Google Cloud) Attack Surface Management: Mandiant's ASM offering, now part of Google Cloud, provides enterprise-grade continuous external monitoring and is a broader-incumbent alternative for the same EASM use case Aftra targets.
  • Bitsight: Bitsight delivers security ratings and attack surface analytics for enterprises and third-party risk programs, competing with Aftra's KPI-driven posture scoring and continuous exposure monitoring at a larger scale.
  • SecurityScorecard: SecurityScorecard provides enterprise security ratings plus attack surface intelligence, overlapping with Aftra's executive-facing security scoring and continuous monitoring but on a much larger scale and with a broader vendor risk offering.
  • Wiz: Wiz is a leading CNAPP platform whose external attack surface and exposure modules increasingly overlap with EASM, making it a credible broader-incumbent alternative for cloud-forward enterprise buyers comparing solutions to Aftra.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat5 records

Key risks5 records

Key highlights6 records

Customer concentration

Aftra social profiles

Digital presence

Aftra financial estimates

Financial estimate

Revenue estimate

Valuation estimate

Aftra leadership team

Management profile

Number of profiles

Profiles5 records

Aftra funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

Aftra M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about Aftra

What does Aftra do?

Aftra provides an External Attack Surface Management (EASM) SaaS platform that continuously discovers exposed digital assets, employee risks, shadow IT, and vulnerabilities from a hacker's perspective, then converts findings into prioritized, actionable insights and security KPIs. The core platform is sold as a subscription (starting at 490 EUR/month) and supplemented by add-on modules including an Internal Vulnerability Scanner, API Scanner, PCI Scanner, and Security Campaigns for employee risk management.

Is Aftra a public or private company?

Aftra is a private company. It is classified as corporate owned and is currently operating.

When was Aftra founded?

Aftra was founded in 2024. It employs 11 to 50 people.

Where is Aftra based?

Aftra is headquartered in Reykjavík, Iceland, in the Europe region.

How does Aftra make money?

One revenue line is on record: saaS Subscription.

Who are Aftra's main competitors?

Direct peers on record are Microsoft Defender External Attack Surface Management, Detectify, Censys, CyCognito, CrowdStrike Falcon Surface and Tenable ASM (Tenable.io). Broad incumbents are Mandiant (Google Cloud) Attack Surface Management, Bitsight, SecurityScorecard and Wiz.

Does Aftra have an API?

No public API is recorded for Aftra.

What industry is Aftra in?

Aftra's product category is Cybersecurity / Attack Surface Management. Its primary akta.pro industry code is HDADAHAC, Attack Surface Management (EASM/CAASM), with a secondary code of HDADADAI, SaaS Security Posture Management (SSPM). Its NAICS code is 54151 and its SIC code is 7372.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales