SEKOST
Sekost is a French cybersecurity SaaS company providing 100% remote external attack surface audits for SMEs, accounting firms, and local governments, distributed primarily via MSPs. It was acquired by YesWeHack in September 2025.
- Company typePrivate
- Founded2021
- HeadquartersRennes, France
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
SEKOST firmographics
Firmographics- Name
- SEKOST
- Legal name
- SEKOST S.A.S.
- Website
- https://sekost.fr
- Company type
- Private
- Founded year
- 2021
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Sekost is a French cybersecurity SaaS company providing 100% remote external attack surface audits for SMEs, accounting firms, and local governments, distributed primarily via MSPs. It was acquired by YesWeHack in September 2025.
- Ownership category
- akta.pro rank
SEKOST industry classification
Industry- Product category
- Attack Surface Management
- NAICS
- Other Computer Related Services (541519)
- akta.pro primary industry
- Third-Party/Vendor Risk Management (TPRM) & Due Diligence (BPAKADAH)
- akta.pro secondary industry
- Third-Party & Supply Chain Exposure Monitoring (HDADAHAJ)
Keywords
Where SEKOST is headquartered
LocationHeadquarters
- HQ city
- Rennes
- HQ country
- France
- HQ region
- Europe
Offices3 records
Markets served
SEKOST business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Cyber Diagnostic Services: Sekost generates revenue through cybersecurity diagnostic services including Flash (free), Diagnostic Cyber, and Check-up Cyber. The Diagnostic Cyber and Check-up Cyber are priced according to client perimeter and needs, with pricing personalized based on scope.
- Partner/Reseller Revenue: Revenue generated through channel partners including MSPs and IT service providers who resell Sekost's diagnostic solutions to their end customers, creating recurring revenue opportunities for partners.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Monthly | Flash Cyber - Free entry-level diagnostic |
| Subscription | Multi-year contract | Diagnostic Cyber - One-time security audit |
| Subscription | Multi-year contract | Check-up Cyber - Recurring monitoring service |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels5 records
SEKOST product offering
Product offeringCore offering
SEKOST provides 100% remote, non-intrusive cybersecurity diagnostic services that map organizations' external attack surface starting from a domain name or IP address, without requiring installation or access to internal systems. The company offers three service tiers — Flash Cyber (free prospection), Diagnostic Cyber (one-time audit with prioritized action plan), and Check-up Cyber (recurring exposure monitoring) — designed to make cyber risk visible and actionable for non-technical decision-makers such as SMEs, accounting firms, local governments, and their IT service partners.
Product overview
SEKOST is a French cybersecurity SaaS platform offering three tiered audit products delivered 100% remotely, without installation or internal access. Flash Cyber serves as a free entry-point/sensitization tool; Diagnostic Cyber is the core paid one-time audit that maps external attack surface, scores risk, and delivers prioritized recommendations; and Check-up Cyber is the recurring monitoring subscription that tracks posture changes over time. All three services are designed for non-technical decision-makers and are primarily distributed through MSPs, IT providers, and resellers as a plug-and-play offering.
Differentiator
Problem solved
Functional benefit
Products and services
- Flash Cyber Free, rapid prospection/sensitization service that provides a quick overview of an entity's online exposure based on the perimeter (domain or IP) provided by the client. Automated, 100% remote analysis conducted without installation or access to internal systems; intended as a teaser for SMEs and their partners before moving to paid diagnostic or recurring monitoring services.
- Diagnostic Cyber One-time audit of the public attack surface and security hygiene, conducted remotely from the client-provided perimeter (domain/IP). Delivers automated analysis with scoring and a prioritized action plan in a clear PDF report designed to be actionable by non-technical business decision-makers. Quote-based pricing personalized to perimeter and needs.
- Check-up Cyber Recurring exposure and cyber risk level monitoring service that re-runs external exposure analysis from the same perimeters over time to detect new exposures or configuration regressions. Supplemented by scoring and prioritized action recommendations; designed as a multi-year subscription for ongoing posture tracking.
Quantifiable outcome
- Revenue growth
- +1 more outcomes
Companies that use SEKOST
Customer profileNamed customers2 records
Segments4 records
Ideal customer profiles4 records
SEKOST technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
SEKOST partnerships and signals
Strategic signalPartnerships
Seven partnerships are on record, tiered core, flagship and minor.
- ImsCloudcoreImsCloud is Sekost's first distribution partner, a 100% indirect MSP distributor. ImsCloud enables its network of MSP partners to propose Sekost's cybersecurity diagnostics without technical prerequisites. Commercial deployment began January 2026 with joint presence at IT Partners 2026.
- YesWeHackcoreYesWeHack acquired Sekost in September 2025 in its first-ever external growth operation. YesWeHack is a global Bug Bounty and vulnerability management platform founded by ethical hackers in 2015. CTO Christophe Hauquiert was a historical ethical hacker on the YesWeHack platform before founding Sekost. The acquisition provides Sekost with international commercial reach, operational expertise, and access to YesWeHack's enterprise customer base.
- Breizh CyberflagshipBreizh Cyber is the regional CSIRT for Brittany, created with support from ANSSI and the Brittany Region. Sekost's Diagnostic Cyber is available through Breizh Cyber's DENN offer, providing Breton organizations access to cybersecurity assessment services backed by the regional CSIRT.
- DimoodminorStrategic partnership with Dimood Group announced September 2024 to strengthen cybersecurity for SMEs and mid-sized companies (ETI). Dimood is a technology group positioned alongside Microsoft, KPMG, and other partners at the Breton Economic Forum.
- YesWeHack (Initial Partnership)coreYesWeHack and Sekost signed a strategic partnership in March 2024, integrating Sekost services into the YesWeHack platform. This partnership preceded the September 2025 acquisition and included technological integration of Sekost's diagnostic capabilities.
- SF2iminorSF2i, a company specializing in IT services, partnered with Sekost to strengthen digital security for businesses. Partnership announced in 2023.
- Anticipa (Incubator)minorAnticipa is a technology business incubator based in Lannion, Brittany. Sekost was accompanied by Anticipa and selected by Cyber booster national incubator for startup support.
Scale indicators3 records
Recent moves8 records
Expansion highlights7 records
SEKOST competitors and assessment
Company assessmentDirect peers
- UpGuard: Australia/US-based continuous attack surface monitoring and third-party risk management platform. Comparable to Sekost in delivering externally observable security ratings and prioritized risk findings via automated scanning.
- ImmuniWeb: Swiss AI-based application security and attack surface management platform. Comparable to Sekost in providing automated, externally-driven security testing with prioritized remediation guidance for organizations of varied sizes.
- Censys: US-based internet-wide scanning and attack surface management platform. Directly comparable to Sekost in delivering intelligence on externally exposed assets, services, and configurations used by enterprise security teams.
- Intruder: UK-based continuous vulnerability and attack surface scanner focused on SMEs and MSSPs. Directly comparable to Sekost: both deliver cloud-based, no-install vulnerability scanning with prioritized remediation aimed at smaller organizations and channel resellers.
- SecurityScorecard: US-based security ratings and attack surface management platform serving enterprises and channel partners. Comparable in delivering externally scored cybersecurity posture for organizations across supply chains, with similar segmentation supporting SME-tier use cases.
- Detectify: Swedish external attack surface management platform continuously scanning internet-exposed assets. Directly comparable to Sekost's Diagnostic Cyber and Check-up Cyber products for ASM, vulnerability detection, and prioritized remediation workflow.
Broad incumbents
- BitSight: US-based security ratings and attack surface analytics platform focused on enterprises. Comparable to Sekost in externally observable security ratings, but operating at much greater scale and portfolio breadth.
- Tenable: US-based vulnerability management leader (Nessus, Tenable.io, Tenable.asm). Offers Sekost's external ASM as part of a much broader vulnerability management suite serving enterprises and MSSPs across large global customer bases.
Others
- YesWeHack: French bug bounty and vulnerability management platform, parent company of Sekost since September 2025. Operates in the same vulnerability management space and provides Sekost with international reach plus access to a 135,000-strong ethical hacker community.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks7 records
Key highlights7 records
Customer concentration
SEKOST social profiles
Digital presenceSEKOST financial estimates
Financial estimateRevenue estimate
Valuation estimate
SEKOST leadership team
Management profileNumber of profiles
Profiles2 records
SEKOST funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
SEKOST M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about SEKOST
What does SEKOST do?
SEKOST provides 100% remote, non-intrusive cybersecurity diagnostic services that map organizations' external attack surface starting from a domain name or IP address, without requiring installation or access to internal systems. The company offers three service tiers — Flash Cyber (free prospection), Diagnostic Cyber (one-time audit with prioritized action plan), and Check-up Cyber (recurring exposure monitoring) — designed to make cyber risk visible and actionable for non-technical decision-makers such as SMEs, accounting firms, local governments, and their IT service partners.
Is SEKOST a public or private company?
SEKOST is a private company. It is classified as corporate owned and is currently operating.
When was SEKOST founded?
SEKOST was founded in 2021. It employs 1 to 10 people.
Where is SEKOST based?
SEKOST is headquartered in Rennes, France, in the Europe region.
How does SEKOST make money?
Two revenue lines are on record. Cyber Diagnostic Services are the primary driver. The others are partner/Reseller Revenue.
Who are SEKOST's main competitors?
Direct peers on record are UpGuard, ImmuniWeb, Censys, Intruder, SecurityScorecard and Detectify. Broad incumbents are BitSight and Tenable. YesWeHack is listed as an others.
Does SEKOST have an API?
No public API is recorded for SEKOST.
What industry is SEKOST in?
SEKOST's product category is Attack Surface Management. Its primary akta.pro industry code is BPAKADAH, Third-Party/Vendor Risk Management (TPRM) & Due Diligence, with a secondary code of HDADAHAJ, Third-Party & Supply Chain Exposure Monitoring. Its NAICS code is 541519.