Security Startups
← All categories

Offensive and exposure

CTEM, attack-surface, pentest-platform, and continuous-exposure startups. Not a services firm with a PDF report.

13 companies. Catalog last reviewed 2026-08-23. Page copy reviewed 2026-08-23. Next review by 2026-09-23. Ordered by name. No paid placement.

This is the live catalog slice for the Offensive and exposure category. A company appears here only when its primary category matches, and every entry carries a 2024 to 2026 proof-of-life signal recorded with a source link. A full page-unique intro for this category ships in a later polish pass.

How order works. Listings are the full live catalog slice for this primary category, sorted alphabetically by name. This is not a scored quality ranking and there is no paid placement. Aevral is a disclosed house listing under the same rules (coming soon, no pin). See /transparency.

AttackIQ

Los Altos, USA

Series C

Security control validation platform built around MITRE ATT&CK and purple-team testing.

Named among 2026 CTEM and BAS alternatives in independent vendor comparisons

Censys

Ann Arbor, USA

Series D

Internet-wide map of exposed infrastructure used for ASM, threat hunting, and exposure management.

Raised $40M Series D plus $30M debt led by Morgan Stanley Expansion Capital, March 2026

Offensive and exposure$198M raisedFounded 2017

Cymulate

Tel Aviv, Israel

Series D

BAS-born exposure validation that now pushes findings into automated control updates.

Shipped Vero AI for agentic cyber defense engineering on the live platform, 2026

Offensive and exposure$141M raisedFounded 2016

Detectify

Stockholm, Sweden

Series B

Hacker-powered surface monitoring for domains, apps, and APIs, now with an MCP server for AI workflows.

Launched a Detectify MCP server for AI security workflows, 2026

Hadrian

Amsterdam, Netherlands

Seed

Outside-in autonomous hacker that discovers, exploits, and validates external exposure continuously.

Shipped Sense, Plan, Attack AI agents to operationalize CTEM, November 2025

Offensive and exposure$14M raisedFounded 2021

Horizon3.ai

San Francisco, USA

Series E

NodeZero autonomous pentest that exploits live networks the way an attacker would, continuously.

Raised $250M Series E at a $2B-plus valuation, August 2026

Offensive and exposure$429M raisedFounded 2019

Pentera

Burlington, USA

Series D

Automated security validation that actually exploits attack paths inside the customer's network.

Raised $60M Series D led by Evolution Equity Partners, March 2025

Offensive and exposure$250M raisedFounded 2015

Picus Security

San Francisco, USA

Series C

Breach-and-attack simulation plus autonomous pentest that scores whether controls actually stop the attack.

Raised $45M Series C to lead adversarial exposure validation, September 2024

SAFE

Palo Alto, USA

Series C

Cyber risk quantification platform that added an agentic CTEM loop on top of CRQ and TPRM.

Raised $70M Series C and launched a fully autonomous CTEM offering, July 2025

Offensive and exposure$170M raisedFounded 2012

SixMap

Columbia, USA

Series A

Internet-scale IPv4/IPv6 discovery that maps what an attacker can actually see of you.

Launched new product capabilities for AI-driven attack-surface change, December 2025

Offensive and exposure$24M raisedFounded 2020

Terra Security

Tel Aviv, Israel

Seed

Agentic pentest platform with a human in the loop across web, API, network, and AI surfaces.

Raised $8M (Q2 2025) to scale agentic continuous pentesting

Offensive and exposure$8M raisedFounded 2024

XM Cyber

Tel Aviv, Israel

Series B

Hybrid attack-path graph that shows how an identity, cloud, or on-prem foothold becomes a breach.

Named a Challenger in the first Gartner Magic Quadrant for Exposure Assessment Platforms, 2025

Offensive and exposure$49M raisedFounded 2016

Zafran

New York, USA

Series C

CTEM that proves which CVEs are exploitable, then mitigates with the controls you already own.

Raised $60M Series C led by Menlo Ventures, December 2025

Offensive and exposure$130M raisedFounded 2022