Secodis GmbH
Secodis GmbH is a Hamburg-based application security consulting firm providing vendor-neutral advisory, security testing (SAST, IAST, code review), threat modeling, and SSDLC implementation services to enterprise software development organizations in the DACH region, supported by open-source tools including TSS-WEB and Secure Coding Guidelines.
- Company typePrivate
- Founded2013
- HeadquartersHamburg, Germany
- Headcount1–10
- GTM typeB2B
- OfferingServices
What Secodis GmbH does
Secodis GmbH is a Hamburg-based application security consulting and solutions provider founded in 2013 by Matthias Rohr, a co-founder of the German OWASP chapter holding ISSAP, CISSP, and CSSLP certifications. The firm operates as a vendor-neutral advisor to enterprise organizations developing custom software, primarily across the DACH region, helping clients embed security into their software development lifecycle through consulting, security testing, threat modeling, and training engagements.
The company's service portfolio spans the application security lifecycle: SSDLC implementation consulting, OWASP SAMM-based maturity assessments, DevSecOps and Agile Security integration, security architecture consulting, cloud security advisory (BSI C5, ISO 27017), and operational project support via security champions and project security officers. Testing services cover SAST, IAST, manual security code review, and tool selection guidance across commercial vendors (Checkmarx, Fortify, Veracode) and open-source alternatives, with integration into CI/CD pipelines (Jenkins, Azure DevOps) and IDEs (Eclipse). Differentiated content assets include the free TSS-WEB open web security standard template (mapped to OWASP, Microsoft SDL, NIST SSDF, SAFECode, ISO/IEC 27002), Secure Coding Guidelines with a 60+ threat catalog, and a Springer-published book in two editions.
The business model is professional services-led with quote-based, multi-year engagements and no public pricing. Distribution is direct, supported by founder-led thought leadership (matthiasrohr.de blog since 2014), recurring conference presence at heise devSec, OWASP events, JAX, and GFFT-Insights, and minor licensing/royalty revenue from guidelines and threat catalog exports. The firm is privately held, founder-owned, with 1–10 employees and no external funding or parent company disclosed.
Secodis GmbH firmographics
Firmographics- Name
- Secodis GmbH
- Legal name
- Secodis GmbH
- Website
- https://secodis.com
- Company type
- Private
- Founded year
- 2013
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Secodis GmbH is a Hamburg-based application security consulting firm providing vendor-neutral advisory, security testing (SAST, IAST, code review), threat modeling, and SSDLC implementation services to enterprise software development organizations in the DACH region, supported by open-source tools including TSS-WEB and Secure Coding Guidelines.
- Ownership category
- akta.pro rank
Secodis GmbH industry classification
Industry- Product category
- Application Security Consulting
- NAICS
- Computer Systems Design and Related Services (54151), Management, Scientific, and Technical Consulting Services (5416)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Application Security & Secure Software (DevSecOps) (EDAOAIAK)
- akta.pro secondary industries
- Security Governance, Risk & Compliance (GRC) Advisory (BPAKADAG), Secure Software & DevOps Awareness (Secure Coding Basics) (EDABAGAN), Vulnerability Management & Penetration Testing Services (BPAEADAD)
Keywords
Where Secodis GmbH is headquartered
LocationHeadquarters
- HQ city
- Hamburg
- HQ country
- Germany
- HQ region
- Europe
Offices3 records
Markets served
Secodis GmbH business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Marketing or Sales, Operations, Technology or R&D, Others
Revenue model
- Security Consulting Services: Project-based consulting engagements for Secure SDLC implementation, security architecture, threat modeling, and application security program development. Includes vendor-neutral advisory for tool selection and integration.
- Security Testing Services: Security testing including SAST, IAST, manual code reviews, and penetration testing services. Can be delivered on-site or as a managed service.
- Training and Workshops: Security training programs including Secure Coding, Agile Security, Threat Modeling, and tool-specific training. Offered as in-house or public workshops.
- Guidelines and Standards Distribution: Distribution of security guidelines and threat catalogs as exports for Atlassian Confluence or SharePoint integration, with customization services.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom professional services engagement |
Go-to-market motion2 records
Distribution channels1 record
Marketing channels7 records
Secodis GmbH product offering
Product offeringCore offering
Secodis GmbH is a Hamburg-based consulting and solutions provider specializing in application security. The company helps enterprise customers sustainably embed security measures into their software development processes (SSDLC) through vendor-neutral consulting, security code scanning (SAST, IAST), manual security code reviews, threat modeling, security architecture advisory, DevSecOps integration, and training. It also publishes the open-source TSS-WEB web application security standard template and provides Secure Coding Guidelines with a threat catalog.
Product overview
Secodis GmbH is a Hamburg-based application security consulting and solutions provider with over 18 years of experience. The company offers a comprehensive portfolio of security consulting services, tool-based security testing solutions, and open-source security standards. Their core offerings include SSDLC (Secure Software Development Lifecycle) consulting to embed security into development processes, and Security Code Scanning services covering SAST, IAST, and manual Security Code Reviews. They provide the open-source TSS-WEB template for web application security standards, along with Secure Coding Guidelines and Threat Catalogs available as Atlassian Confluence exports. Additional services include Threat Modeling, Security Architecture Consulting, Cloud Security, DevSecOps, Agile Security integration, and Security Training programs. The company operates as a vendor-neutral advisor, working with both commercial tools (Checkmarx, Fortify, Veracode) and open-source solutions.
Differentiator
Problem solved
Functional benefit
Brands
- TSS-WEB: A free template for a technical-organizational security standard for web applications, developed as a supplement to the book 'Sicherheit von Webanwendungen in der Praxis' by Matthias Rohr.
Products and services
- SSDLC (Secure Software Development Lifecycle) Consulting Consulting service that helps enterprise organizations embed application security sustainably into their development processes through tailored requirements, processes, tools, and employee qualification programs.
- SAST (Static Application Security Testing) Services Static code analysis service that inspects source code or compiled byte/binary code for security vulnerabilities such as XSS, SQL Injection, and insecure API calls.
- IAST (Interactive Application Security Testing) Services Dynamic code analysis during application runtime on the test server, combining benefits of SAST and DAST with very low false positive rates.
- Security Code Review Manual security code analysis for high-protection applications, complementing automated tools by identifying issues requiring code-level understanding.
- Threat Modeling Conceptual analysis technique to identify potential security weaknesses early in development and derive required security measures, applicable to traditional and agile projects.
- Security Architecture Consulting Project-accompanying security architect services for projects with high security requirements, including security architecture development and reviews.
- Cloud Security Services Cloud security support including cloud service provider selection, security requirements for cloud environments, and compliance with BSI C5 and ISO 27017.
- DevSecOps Services Integration of security into DevOps processes and pipelines.
- Agile Security Services
Companies that use Secodis GmbH
Customer profileSegments2 records
Ideal customer profiles1 record
Secodis GmbH technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration8 records
Feature5 records
Secodis GmbH partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- CheckmarxminorCheckmarx partnered with Secodis for the Application Security Forum in Erlangen on May 12, 2016. Secodis founder Matthias Rohr represented Secodis at this event discussing experiences with integrating security into software development processes.
Scale indicators2 records
Recent moves6 records
Expansion highlights5 records
Secodis GmbH competitors and assessment
Company assessmentMarket position
Competitive moat3 records
Key risks6 records
Key highlights6 records
Customer concentration
Secodis GmbH social profiles
Digital presenceSecodis GmbH financial estimates
Financial estimateRevenue estimate
Valuation estimate
Secodis GmbH leadership team
Management profileNumber of profiles
Profiles1 record
Secodis GmbH funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Secodis GmbH M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Secodis GmbH
What does Secodis GmbH do?
Secodis GmbH is a Hamburg-based consulting and solutions provider specializing in application security. The company helps enterprise customers sustainably embed security measures into their software development processes (SSDLC) through vendor-neutral consulting, security code scanning (SAST, IAST), manual security code reviews, threat modeling, security architecture advisory, DevSecOps integration, and training. It also publishes the open-source TSS-WEB web application security standard template and provides Secure Coding Guidelines with a threat catalog.
Is Secodis GmbH a public or private company?
Secodis GmbH is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Secodis GmbH founded?
Secodis GmbH was founded in 2013. It employs 1 to 10 people.
Where is Secodis GmbH based?
Secodis GmbH is headquartered in Hamburg, Germany, in the Europe region.
How does Secodis GmbH make money?
Four revenue lines are on record. Security Consulting Services are the primary driver. The others are security Testing Services, training and Workshops and guidelines and Standards Distribution.
Does Secodis GmbH have an API?
No public API is recorded for Secodis GmbH.
What industry is Secodis GmbH in?
Secodis GmbH's product category is Application Security Consulting. Its primary akta.pro industry code is EDAOAIAK, Application Security & Secure Software (DevSecOps), with a secondary code of BPAKADAG, Security Governance, Risk & Compliance (GRC) Advisory. Its NAICS code is 54151 and its SIC code is 7373.