VORNAC GmbH
VORNAC GmbH is a Heidelberg-based cybersecurity company providing continuous autonomous penetration testing as a SaaS service for regulated enterprises in the DACH region across critical infrastructure, financial services, insurance, automotive, and broader enterprise verticals, with full German data sovereignty.
- Company typePrivate
- Founded2026
- HeadquartersHeidelberg, Germany
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What VORNAC GmbH does
VORNAC GmbH is a Heidelberg-headquartered, privately held cybersecurity company co-founded by André Feigenbutz and Arthur Raess that delivers continuous, autonomous penetration testing as an alternative to traditional annual manual pentests. The company operates with 1–10 employees, no disclosed external funding, and a commercial footprint concentrated in the DACH region, with all customer data processed and stored in German data centers under BDSG/GDPR — explicitly with no US cloud and no non-EU subprocessors.
The core product is the VORNAC Continuous Penetration Testing Platform, which simulates full adversarial attack chains (Reconnaissance → Initial Access → Privilege Escalation → Lateral Movement → Excitation) against live customer estates using production-safe, evidence-backed exploits. Differentiating technical components include automated cross-system attack path detection (attack chaining), an iterative Observation → Enumeration → Vulnerability Research → Exploitation → Documentation loop, CI/CD webhook triggers across GitHub Actions, GitLab CI, Jenkins, Azure DevOps, Bitbucket Pipelines, and CircleCI, and native integration with Jira for developer ticket routing. The platform produces a single audit-ready report admissible under NIS2, DORA, KRITIS, TISAX, VAIT/BAIT, and ISO/IEC 27001, and is delivered with BSI-qualified pentesters as named customer contacts.
Commercially, VORNAC operates a direct enterprise sales motion targeting CISOs, CIOs, and security decision-makers in regulated verticals — Critical Infrastructure (KRITIS), Financial Services and Insurance (DORA/VAIT/BAIT), Automotive (TISAX), and broader Enterprise (NIS2) — with pricing licensed per in-scope target system on multi-year contracts that include unlimited test runs. Demand generation is primarily content-led through an eight-domain research index, a 155-term bilingual EN/DE glossary, the 2026 Continuous Validation Methodology whitepaper, and direct demo booking via Zeeg.me. Visible customer logos span a broad mix including Carl Zeiss, Hetzner Online, Penny / REWE Group, GitHub, OWASP, and TKOM alongside a larger set of German SME technology firms.
VORNAC GmbH firmographics
Firmographics- Name
- VORNAC GmbH
- Legal name
- VORNAC GmbH
- Website
- https://vornac.com
- Company type
- Private
- Founded year
- 2026
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- VORNAC GmbH is a Heidelberg-based cybersecurity company providing continuous autonomous penetration testing as a SaaS service for regulated enterprises in the DACH region across critical infrastructure, financial services, insurance, automotive, and broader enterprise verticals, with full German data sovereignty.
- Ownership category
- akta.pro rank
VORNAC GmbH industry classification
Industry- Product category
- Continuous Security Validation / Autonomous Penetration Testing
- akta.pro primary industry
- Penetration Testing & Red Teaming (BPAKAHAF)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Breach & Attack Simulation (BAS) (HDADAHAD), Penetration Testing & Red Teaming (BPAKADAE)
Keywords
Where VORNAC GmbH is headquartered
LocationHeadquarters
- HQ city
- Heidelberg
- HQ country
- Germany
- HQ region
- Europe
Offices1 record
Markets served
VORNAC GmbH business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Infrastructure, Operations, Marketing or Sales
Revenue model
- Continuous Pentesting License (Per Target System): Licensed per target system, not per engagement and not per pentest. The fee depends on the number of in-scope systems, independent of their complexity, and includes unlimited test runs over the contract period: every release, every infrastructure change, on-demand via web interface or API. Customers report up to 75% lower external testing costs compared to manual annual pentests while running tests every week instead of once a year.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Multi-year contract | Per target system — unlimited test runs included |
Go-to-market motion2 records
Distribution channels2 records
Marketing channels5 records
VORNAC GmbH product offering
Product offeringCore offering
VORNAC delivers continuous, autonomous penetration testing that simulates full adversarial attack chains (Reconnaissance → Initial Access → Privilege Escalation → Lateral Movement → Exfiltration) against live customer estates. Tests are triggered on every release via CI/CD webhook or API, produce exploit-proven findings with reproducible proof-of-concepts in 2–5 hours, and are packaged as audit-ready reports admissible under NIS2, DORA, KRITIS, TISAX, VAIT/BAIT, and ISO/IEC 27001. All data is processed exclusively in German data centers under BDSG/GDPR.
Product overview
VORNAC offers a single unified platform for continuous security validation through autonomous penetration testing. The core product is the VORNAC Continuous Penetration Testing Platform, which delivers full-cycle pentesting (Reconnaissance → Initial Access → Privilege Escalation → Lateral Movement → Exfiltration) on every code release and infrastructure change. VORNAC is licensed per target system and includes unlimited test runs over the contract period, with all findings delivered as audit-ready reports admissible under TISAX, KRITIS, NIS2, DORA, VAIT/BAIT, and ISO/IEC 27001.
Differentiator
Problem solved
Functional benefit
Products and services
- VORNAC Continuous Penetration Testing Platform An autonomous, continuous penetration testing platform licensed per target system that simulates real-world attacks without putting systems at risk. Runs on every release across the full attack surface (cloud, on-premises, APIs, behind-VPN systems), with working exploits and reproducible PoCs delivered in 2–5 hours. Designed for regulated enterprises (insurance, financial services, critical infrastructure, automotive) needing audit-ready evidence for NIS2, DORA, KRITIS, TISAX, VAIT/BAIT, and ISO/IEC 27001.
Quantifiable outcome
- 84% less cyber risk across the validated attack surface
- +4 more outcomes
Companies that use VORNAC GmbH
Customer profileNamed customers21 records
Segments5 records
Ideal customer profiles5 records
VORNAC GmbH technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration7 records
Feature5 records
VORNAC GmbH partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- Allianz für Cyber-Sicherheit (German Cyber Security Alliance)minorVORNAC is a Partner of the Allianz für Cyber-Sicherheit, a BSI-associated initiative that brings together companies committed to improving cyber security in Germany. The partnership signals alignment with German regulatory priorities and provides a trusted industry reference.
Scale indicators5 records
Recent moves5 records
Expansion highlights6 records
VORNAC GmbH competitors and assessment
Company assessmentMarket position
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
VORNAC GmbH social profiles
Digital presenceVORNAC GmbH compliance and trust
Trust signalCompliance6 records
VORNAC GmbH financial estimates
Financial estimateRevenue estimate
Valuation estimate
VORNAC GmbH leadership team
Management profileNumber of profiles
Profiles2 records
VORNAC GmbH funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
VORNAC GmbH M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about VORNAC GmbH
What does VORNAC GmbH do?
VORNAC delivers continuous, autonomous penetration testing that simulates full adversarial attack chains (Reconnaissance → Initial Access → Privilege Escalation → Lateral Movement → Exfiltration) against live customer estates. Tests are triggered on every release via CI/CD webhook or API, produce exploit-proven findings with reproducible proof-of-concepts in 2–5 hours, and are packaged as audit-ready reports admissible under NIS2, DORA, KRITIS, TISAX, VAIT/BAIT, and ISO/IEC 27001. All data is processed exclusively in German data centers under BDSG/GDPR.
Is VORNAC GmbH a public or private company?
VORNAC GmbH is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was VORNAC GmbH founded?
VORNAC GmbH was founded in 2026. It employs 1 to 10 people.
Where is VORNAC GmbH based?
VORNAC GmbH is headquartered in Heidelberg, Germany, in the Europe region.
How does VORNAC GmbH make money?
One revenue line is on record: continuous Pentesting License (Per Target System).
Does VORNAC GmbH have an API?
Yes. VORNAC offers an API for on-demand pentest triggering and integration. Pentests can be triggered via API on every release, infrastructure change, or scheduled cadence. Findings are pushed back into the developer's ticketing system (e.g. Jira) with severity, reproducible proof-of-concept, and remediation guidance.
What industry is VORNAC GmbH in?
VORNAC GmbH's product category is Continuous Security Validation / Autonomous Penetration Testing. Its primary akta.pro industry code is BPAKAHAF, Penetration Testing & Red Teaming, with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services.