vamisec
VamiSec GmbH is a Bonn-based cybersecurity and GRC consulting firm serving regulated enterprises across DACH with AI-native platforms, managed services, and compliance implementation for NIS2, DORA, EU AI Act, CRA, GDPR and ISO standards.
- Company typePrivate
- Founded2025
- HeadquartersBonn, Germany
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What vamisec does
VamiSec GmbH is a Bonn-based, founder-controlled cybersecurity and Governance-Risk-Compliance (GRC) consulting firm serving regulated enterprises in the DACH region and broader EU. It delivers implementation, managed services, training and certification programs around NIS2, DORA, EU AI Act, CRA, GDPR, ISO/IEC 27001, ISO/IEC 42001, ISO/IEC 27701, ISO 22301, TISAX and BSI C5. CEO Valeri Milke also leads softScheck GmbH (announced April 2026) — a sister company covering product security, pentest, source-code security, fuzzing and SSDLC — so that the combined group covers regulation-side and technical-validation-side needs under one strategic hand. Headcount is reported at 11–50 with 70+ clients and 150+ projects cited.
The core technical asset is a portfolio of nine proprietary AI-native SaaS platforms anchored by VamiGRC, described as Europe's first fully AI-native, agentic GRC platform, which unifies five management systems (ISMS, AIMS, PIMS, BCMS, CSMS) in a single queryable graph and ships 22 Tier-1 regulations as OSCAL profiles driven by VamiAI with four autonomy levels (L0 Manual to L3 Autonomous). Surrounding products include VamiRedteam (autonomous pentesting with six AI agents, CVSS v4 and AIVSS/ATLAS scoring), VamiThreat (STRIDE + MAESTRO 7-layer threat modelling), VamiAppSec (orchestrated Semgrep/Gitleaks/Checkov/Syft/Grype/Claude Code Security Reviewer pipeline), VamiGuard (Apache-2.0 browser DLP for ChatGPT/Claude/Copilot/Gemini/Grok/DeepSeek), VamiSet (asset discovery + CIS/ISO/NIS2/SOC2/GDPR/PCI/HIPAA continuous compliance), VamiDAST, VamiReverse and VamiAcademy. All platforms are Software Made in Germany and hosted on Open Telekom Cloud.
Revenue is generated through a mix of professional services (consulting, GRC-as-a-Service, vCISO/AI Officer services), recurring managed security services (24/7 SOC, MDR, vulnerability management, bug bounty, cloud security via Wiz, dark web monitoring), tiered SaaS subscriptions and PECB/OffSec/KnowBe4 training delivery. Pricing is quote-based; VamiGuard is free open-source. Distribution is enterprise field sales (Outlook 'Book an Appointment' conversion) plus channel partnerships with PECB, KnowBe4, OffSec and Wiz (the latter covering EMEA reseller, implementation and MSSP motions). The firm is privately held with no disclosed institutional funding; awards include Software Made in Germany 2025 (BITMi) and ISO/IEC 27001 + ISO/IEC 42001 certifications (Proks, 2025).
vamisec firmographics
Firmographics- Name
- vamisec
- Legal name
- VamiSec GmbH
- Website
- https://vamisec.com
- Company type
- Private
- Founded year
- 2025
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- VamiSec GmbH is a Bonn-based cybersecurity and GRC consulting firm serving regulated enterprises across DACH with AI-native platforms, managed services, and compliance implementation for NIS2, DORA, EU AI Act, CRA, GDPR and ISO standards.
- Ownership category
- akta.pro rank
vamisec industry classification
Industry- Product category
- Cybersecurity & GRC Software
- NAICS
- Security Systems Services (56162), Other Computer Related Services (541519), Custom Computer Programming Services (541511), Computer Training (611420)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Vulnerability Management & Penetration Testing Services (BPAEADAD)
- akta.pro secondary industries
- Cybersecurity Technical Skills (Security Engineering, SOC, Pen Testing) (EDABAFAF), Security Awareness, Training & Compliance Attestation (HDADAIAJ), Serverless & PaaS Security (Function/App Service Runtime) (HDADADAL)
Keywords
Where vamisec is headquartered
LocationHeadquarters
- HQ city
- Bonn
- HQ country
- Germany
- HQ region
- Europe
Offices1 record
Markets served
vamisec business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- Consulting Services: Professional consulting for IT security, GRC, NIS2, DORA, EU AI Act, CRA implementation, ISMS setup, penetration testing, threat modeling, and compliance audits. Billed as project-based engagements or retainer arrangements.
- Managed Security Services: Recurring managed services including SOC 24/7 monitoring, MDR, vulnerability management, bug bounty programs, cloud security monitoring (CNAPP/CSPM via Wiz), deception technologies, incident response retainer, GRC as a Service, vCISO/vISO services, and AI Officer as a Service.
- SaaS Platform Subscriptions: Subscription-based access to proprietary AI-native platforms (VamiGRC, VamiRedteam, VamiThreat, VamiAppSec, Vamiset, VamiDAST, VamiReverse, VamiAcademy). Tiered plans with autonomy levels and feature differentiation. Software Made in Germany, hosted on Open Telekom Cloud.
- Training & Certification Delivery: PECB-accredited training programs delivering 300+ internationally recognized certifications (ISO 27001, 42001, 27701, 22301, NIS2, DORA, CRA, EU AI Act). Also OffSec certification training and KnowBe4 security awareness programs. Billed per course or as bundled training packages.
- VamiGuard (Free/Open Source): Free browser extension (Apache-2.0 licensed) with no telemetry. Acts as customer acquisition channel and complementary product to the enterprise security suite.
Go-to-market motion1 record
Distribution channels7 records
Marketing channels7 records
vamisec product offering
Product offeringCore offering
VamiSec delivers AI-driven cybersecurity consulting, GRC platform subscriptions (VamiGRC and eight other AI-native SaaS products), and managed security services for organizations in regulated industries. Its core platform, VamiGRC, unifies five management systems (ISMS, AIMS, PIMS, BCMS, CSMS) using an OSCAL-based queryable graph powered by VamiAI, complemented by VamiRedteam for autonomous pentesting, VamiThreat for AI threat modeling, VamiAppSec for AppSec orchestration, VamiGuard for GenAI DLP, Vamiset for asset discovery, VamiDAST for dynamic application testing, VamiReverse for binary analysis, and VamiAcademy for AI-assisted training.
Product overview
VamiSec is a platform-plus-services portfolio comprising nine proprietary AI-native software products and an integrated framework (VamiIMS), complemented by 20+ managed and consulting services. The core platform is VamiGRC — Europe's first fully AI-native, agentic GRC platform — which unifies five management systems (ISMS, AIMS, PIMS, BCMS, CSMS) in one queryable graph powered by VamiAI with four autonomy levels. Surrounding VamiGRC are eight specialized AI-driven security tools: VamiRedteam (autonomous pentesting with six AI agents), VamiThreat (AI threat modeling), VamiAppSec (LLM-powered AppSec orchestration), VamiGuard (GenAI DLP browser extension), Vamiset (asset discovery & continuous compliance), VamiDAST (AI-powered DAST), VamiReverse (AI-assisted reverse engineering), and VamiAcademy (AI e-learning). The VamiIMS Framework provides the underlying conceptual structure unifying four ISO management systems. All nine platforms are Software Made in Germany with hosting on Open Telekom Cloud; VamiGuard is open source (Apache-2.0). The portfolio is further extended by managed services including MDR, vulnerability management, bug bounty, cloud security (Wiz), dark web monitoring, incident response, GRC/Compliance as a Service, vCISO, AI Officer, supplier risk management, GRC tool migration, SBOM management, and a full training & certification program.
Differentiator
Problem solved
Functional benefit
Brands
- VamiGRC: Agentic GRC Platform - Europe's first fully AI-native, agentic GRC platform with six management systems, OSCAL-based controls, and a queryable graph.
- VamiRedteam
- VamiThreat
- VamiAppSec
- VamiGuard
- VamiSet
- VamiDAST
- VamiReverse
- VamiAcademy
Products and services
- VamiGRC Europe's first fully AI-native, agentic GRC platform covering five management systems (ISMS, AIMS, PIMS, BCMS, CSMS) in one queryable graph, driven by VamiAI with four autonomy levels. Implements 22 Tier-1 regulations via OSCAL-based controls with role-specific lenses for CISO, DPO, AI Officer, TPRM, Auditor, and SecOps. Eliminates 80–95% of manual compliance work and reduces time-to-report from 2–5 days to real time.
- VamiRedteam AI-native, agentic pentesting platform with six modules (Web, Mobile, AI, Infrastructure, OSINT, TLPT) driven by six autonomous agents (Scout, Cartograph, Strike, Phantom, Witness, Brief), operating within a signed authorization cage with CVSS v4 and AIVSS scoring, MITRE ATLAS mapping, and four autonomy levels including 24/7 zero-day vulnerability management. Time-to-finding under 30 minutes.
- VamiThreat AI-native threat modeling platform that maps system architecture, identifies threat actors, and generates prioritised remediation plans conversationally using STRIDE for classic applications and MAESTRO for agentic AI across 7 layers, with automatic MITRE ATT&CK v15 mapping and auto-ingestion of Mermaid, draw.io, C4, and Architecture-as-Code.
- VamiAppSec LLM-powered application security platform orchestrating six scanners (Semgrep, Gitleaks, Checkov, Syft, Grype, Claude Code Security Reviewer) in one pipeline with unified findings schema, 93% duplicate collapse, per-finding LLM enrichment (plain-language explanation, exploitability score, stack-aware fix), CI/CD quality gates, SARIF IDE output, and 54% median triage time reduction.
- VamiGuard Browser extension for DLP and Shadow AI governance that locally detects PII (email, IBAN, credit cards, passport numbers, IPs) and secrets (AWS keys, JWT, bearer tokens, GitHub tokens, OpenAI keys, Stripe keys, high-entropy strings) in prompts before they reach chatbots, replacing values with placeholders and restoring originals in responses. Open source (Apache-2.0), free, no telemetry. Supports ChatGPT, Claude, Microsoft Copilot, Gemini, Grok, and DeepSeek.
- Vamiset Asset discovery and continuous compliance monitoring platform that automatically discovers assets across cloud accounts, code repositories, and identity systems (AWS, Azure, GCP, GitHub, GitLab, BambooHR, External Attack Surface) and continuously checks them against six pre-mapped frameworks (ISO 27001: 93 controls; SOC 2: 61 controls; GDPR: 34 controls; NIS2: 29 controls; PCI-DSS: 78 controls; HIPAA: 42 controls) plus 200+ CIS benchmark checks.
- VamiDAST AI-powered dynamic application security testing (DAST) platform that tests running applications from the outside as a black box, exposing runtime vulnerabilities (injection, broken authentication, misconfigurations) in web apps and APIs using machine learning to improve detection and reduce false positives, running continuously in CI/CD pipelines.
- VamiReverse AI-assisted reverse-engineering platform supporting analysts in binary, firmware, and malware analysis, helping make sense of decompiled and disassembled code by naming functions, explaining control flow, and summarising behaviour in plain language, accelerating triage from hours to minutes across incident response, threat intelligence, and vulnerability research.
- VamiAcademy AI-assisted e-learning platform for IT security and compliance training delivering audience-specific learning paths (management, IT, Legal, HR) aligned to NIS2, DORA, AI Act, and GDPR with auditable progress and certificates, available as SaaS or self-hosted in the customer's own data centre. Software Made in Germany with hosting in Germany.
- Managed Detection & Response (MDR) 24/7 SOC monitoring, threat analysis, and rapid incident response with MITRE ATT&CK mapping, threat-intelligence feeds, custom use-case engineering, integration with Splunk/Microsoft Sentinel/Elastic/CrowdStrike/SentinelOne, and court-admissible forensic reporting.
- vCISO as a Service Virtual Chief Information Security Officer service providing experienced CISO leadership on demand — strategic security leadership without a full-time headcount for SMEs and enterprises, covering role & responsibility, steering of security program, regulatory compliance, and audit support.
- AI Officer as a Service External AI Officer service providing experienced AI experts who take on the role of an internal AI officer — flexibly, scalably, and without additional fixed costs — for EU AI Act compliance, risk classification, governance & policy development, and regulatory interface.
- Penetration Testing Simulating targeted attacks to identify technical vulnerabilities in applications, networks, and systems, covering Web App & API Testing, Mobile App Pentesting (iOS & Android), IoT Pentesting, Embedded Security & Industrial Pentesting, Automotive Pentesting, Red Teaming, TLPT per DORA, and Social Engineering & Phishing Simulations.
- GRC as a Service Managed GRC service providing an ISMS per ISO/IEC 27001 with a vCISO or vISB carrying operational responsibility, continuous compliance monitoring across all frameworks, and optional VamiGRC as the agentic GRC platform with AI agents supporting evidence management and multi-framework mapping.
- PECB Certification Training Accredited PECB Training Partner delivering 300+ internationally recognized certifications (ISO/IEC 27001, 42001, 27701, 22301, NIS2, DORA, CRA, EU AI Act) taught by active Lead Auditors who use these standards in client projects daily.
- Agentic AI Pentesting Offensive security testing of autonomous AI agents covering prompt injection, jailbreak, tool abuse, memory/context manipulation, and agentic exploits following OWASP methodology for agentic applications and MAESTRO threat modeling.
- Vami Bug Bounty Fully curated private 24/7 bug bounty programme exclusively with vetted, certified VamiSec researchers, individually defined policy, hosted in the T Cloud in Germany, with rewards paid per validated vulnerability by CVSS (no cure, no pay model).
- Cloud Security Monitoring (Wiz-based CNAPP/CSPM) CNAPP and CSPM managed service via official Wiz partnership with agentless visibility across cloud resources, context-based prioritization, compliance scanning (CIS, ISO 27001, BSI C5, NIST 800-53, DORA, NIS2), DevSecOps integration, and CNAPP managed service with strategic GRC embedding.
- OffSec Offensive Security Training Authorized OffSec partner for DACH delivering official offensive security trainings, live labs, and certifications (OSCP, OSEP, OSWE, OSDA, OSIR, OSTH) with German-speaking guidance.
- KnowBe4 Security Awareness Training Authorized KnowBe4 partner and reseller for DACH providing security awareness training, phishing simulations, and human risk management — from licensing to fully managed awareness program, achieving phish-prone rate reduction from 33% to 4% in 12 months.
- External Attack Surface Management (EASM) Continuous discovery and monitoring of externally exposed attack surface — domains, services, certificates, and cloud assets — from the attacker's perspective.
- Dark Web Monitoring Managed service monitoring the dark web for leaked credentials, infostealer logs, and organisation mentions within ~5 minutes with triage by VamiSec analysts, powered by Paranoid Lab platform.
- SBOM Management CRA-compliant SBOM management covering creation, validation, and distribution of SBOMs across the product lifecycle using Exodos Labs, syft, Sonatype, Fossa, Dependency Track, and CycloneDX formats, providing audit-ready documentation for CRA compliance and customer reliability.
- Supplier Risk Management Managed supplier risk service covering classification & criticality analysis, continuous monitoring via SecurityScorecard/BitSight/UpGuard, questionnaires (TISAX, VDA ISA, VdS 10000, CAIQ), contract design & security requirements, and integration into ServiceNow/Ariba/Jira/Power Platform.
- MCP Security Assessment Assessment, server pentest, threat modeling and governance for Model Context Protocol (MCP) deployments — the interfaces through which AI agents access tools and data — covering servers, clients, OAuth 2.1 authorisation, and least-privilege configuration.
- Agentic AI Detection & Response (ADR) Runtime detection and response for AI agents with telemetry across prompts, tool calls, and agent identities, detection use cases against goal hijacking, and rehearsed response playbooks integrated with the SOC.
- AI & LLM Security CTF Hands-on Capture The Flag platform for AI & LLM security covering Prompt Injection, Tool and Agent Abuse, Insecure Output Handling, and Data Exfiltration — a realistic, controlled, enterprise-ready training environment.
- Deception Technologies / Honeypots Deception security service deploying honeypots, honeynets, honeytokens, canary tokens, decoy services (SSH, RDP, HTTP), and adaptive deception systems with ML-based topology mutation, threat actor profiling, and high-fidelity alerting integrated with SOAR.
Quantifiable outcome
- 80–95% manual compliance work eliminated through VamiGRC automation
- +4 more outcomes
Companies that use vamisec
Customer profileNamed customers10 records
Segments12 records
Ideal customer profiles5 records
vamisec technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration106 records
AI capability12 records
Feature12 records
vamisec partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered core and minor.
- KnowBe4coreVamiSec is an authorized KnowBe4 partner & reseller for Germany, Austria and Switzerland (DACH). Brings the world's largest security awareness training (SAT) platform to the DACH region — from licensing to a fully managed awareness program linked to the ISMS. KnowBe4 achieves phish-prone rate reduction from 33% to 4% in 12 months.
- PECBcoreVamiSec GmbH is an accredited PECB Training Partner, delivering 300+ internationally recognized certifications (ISO 27001, 42001, 27701, 22301, NIS 2, DORA, CRA, EU AI Act), taught by active Lead Auditors who live these standards in client projects every day.
- OffSeccoreVamiSec GmbH is an authorized OffSec partner for the DACH region, bringing official offensive security trainings, live labs and certifications (OSCP, OSEP, OSWE, OSDA, OSIR, OSTH) with German-speaking guidance to companies in Germany, Austria and Switzerland.
- WizcoreVamiSec GmbH is an official member of the Wiz Partner Alliance for the EMEA region, listed in the Wiz Partner Alliance Directory, holding the Wiz Partner Technical Foundations Badge and Wiz Partner Demo Accreditation. VamiSec is German-speaking Wiz Reseller, Implementation and MSSP partner offering cloud security from licensing through PoC to 24/7 managed service with incident-response retainer.
- softScheck GmbHcoreStrategic step announced April 2026: Valeri Milke, founder and CEO of VamiSec, additionally takes over as CEO of softScheck GmbH — the company where he began his IT security career. VamiSec remains the strategic home for GRC, ISMS, AIMS, and regulatory matters. softScheck brings 20+ years of expertise in threat modeling, pentest, source code security, fuzzing, and SSDLC. The ecosystem combining regulation (VamiSec) and technical validation (softScheck) addresses the CRA, MDR, and IEC 62443 era under one strategic hand.
- BitkomminorVamiSec is a member of Bitkom (Bundesverband Informationswirtschaft, Telekommunikation und neue Medien e.V.), Germany's digital industry association.
- BITMi – Bundesverband IT-MittelstandminorVamiSec is a member of BITMi (Bundesverband IT-Mittelstand), the German SME IT industry association.
- JUN LegalminorVamiSec developed the CRA Navigator tool in strategic collaboration with JUN Legal. JUN Legal provides legally binding assessment for CRA compliance while VamiSec advises on technical implementation.
Scale indicators8 records
Recent moves7 records
Expansion highlights6 records
vamisec competitors and assessment
Company assessmentDirect peers
- Drata: Drata is a GRC automation platform that continuously monitors controls across SOC 2, ISO 27001, HIPAA, and similar frameworks. It directly competes with VamiGRC's value proposition of automated evidence collection and continuous compliance posture.
- Orange Cyberdefense: Orange Cyberdefense is a European MSSP and security services provider offering MDR, pentesting, threat intelligence, and consulting. It overlaps directly with VamiSec's managed services and pentesting book (and is also a current VamiSec customer).
- Secureframe: Secureframe provides compliance automation for SOC 2, ISO 27001, HIPAA, PCI, and more, with auditing built in. It overlaps closely with VamiGRC's automation-led, multi-framework positioning.
- Pentera: Pentera offers an automated, agentic security validation platform that continuously emulates real attacks against enterprise environments. It is the closest direct competitor to VamiRedteam's autonomous pentesting and L4 continuous-adversary mode.
- Vanta: Vanta is a leading automated compliance and GRC SaaS platform targeting SOC 2, ISO 27001, HIPAA, and other frameworks. It is the most direct competitor to VamiGRC's continuous-compliance, multi-framework automation wedge into regulated buyers.
- WithSecure (formerly F-Secure): WithSecure is a European cybersecurity company providing managed detection and response, consulting, and offensive security services. It competes directly with VamiSec across MSSP delivery and pentesting in the DACH and broader EU markets.
- NCC Group: NCC Group is a global cybersecurity services firm specializing in source-code review, penetration testing, and managed security. It is comparable to VamiSec in its services-led security testing and assurance practice for regulated enterprises.
- Hyperproof: Hyperproof is a compliance and GRC operations platform that automates evidence collection and control monitoring across multiple frameworks. It competes with VamiGRC's multi-framework mapping and continuous compliance monitoring.
Emerging players
- Adversa AI: Adversa AI specializes in security and red-teaming for AI/ML systems, including LLMs and autonomous agents. It is a focused emerging peer to VamiSec's Agentic AI Pentesting, MAESTRO threat modeling, and SBOM-for-AI services.
Broad incumbents
- CrowdStrike: CrowdStrike is a large cybersecurity incumbent offering an XDR/EDR platform, MDR services, and a broad security portfolio. It overlaps with VamiSec's MDR, vulnerability management, and SOC services from a broad-incumbent angle rather than a specialized GRC niche.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
vamisec social profiles
Digital presencevamisec compliance and trust
Trust signalCompliance27 records
vamisec financial estimates
Financial estimateRevenue estimate
Valuation estimate
vamisec leadership team
Management profileNumber of profiles
Profiles1 record
vamisec funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
vamisec M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about vamisec
What does vamisec do?
VamiSec delivers AI-driven cybersecurity consulting, GRC platform subscriptions (VamiGRC and eight other AI-native SaaS products), and managed security services for organizations in regulated industries. Its core platform, VamiGRC, unifies five management systems (ISMS, AIMS, PIMS, BCMS, CSMS) using an OSCAL-based queryable graph powered by VamiAI, complemented by VamiRedteam for autonomous pentesting, VamiThreat for AI threat modeling, VamiAppSec for AppSec orchestration, VamiGuard for GenAI DLP, Vamiset for asset discovery, VamiDAST for dynamic application testing, VamiReverse for binary analysis, and VamiAcademy for AI-assisted training.
Is vamisec a public or private company?
vamisec is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was vamisec founded?
vamisec was founded in 2025. It employs 11 to 50 people.
Where is vamisec based?
vamisec is headquartered in Bonn, Germany, in the Europe region.
How does vamisec make money?
Five revenue lines are on record. Consulting Services are the primary driver. The others are managed Security Services, saaS Platform Subscriptions, training & Certification Delivery and vamiGuard (Free/Open Source).
Who are vamisec's main competitors?
Direct peers on record are Drata, Orange Cyberdefense, Secureframe, Pentera, Vanta, WithSecure (formerly F-Secure), NCC Group and Hyperproof. Adversa AI is listed as an emerging player. CrowdStrike is listed as a broad incumbent.
Does vamisec have an API?
No public API is recorded for vamisec.
What industry is vamisec in?
vamisec's product category is Cybersecurity & GRC Software. Its primary akta.pro industry code is BPAEADAD, Vulnerability Management & Penetration Testing Services, with a secondary code of EDABAFAF, Cybersecurity Technical Skills (Security Engineering, SOC, Pen Testing). Its NAICS code is 56162 and its SIC code is 7372.