Detectify AB

Sweden · detectify.com · 16 vendors

Detectify AB is a cybersecurity company that provides an external attack surface management (EASM) platform and dynamic application security testing (DAST) solutions. The platform automates continuous, real-world, payload-based attacks, crowdsourced through a global community of ethical hackers, to identify and remediate security vulnerabilities across internet-facing assets. It helps organizations discover, classify, and scan all assets to expose critical security weaknesses.

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 16 sub-vendors.

Insights

Last updated 2026-04-29 · revision 2

16 direct vendors, 194 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Detectify AB exhibits very high migration readiness, largely attributable to its highly modern, cloud-native, and containerized technology stack. The extensive use of Amazon Web Services (AWS), Kubernetes for container orchestration, Docker for containerization, and Infrastructure as Code (Terraform) indicates a mature and agile infrastructure that is inherently designed for portability and easy migration across cloud environments or within different regions. The adoption of microservices-friendly languages like Go and Python further supports modularity and ease of refactoring if needed. The absence of specified data residency requirements provides significant flexibility for data placement during a migration. While financial stability and the specific regulatory environment are unknown, which could pose potential challenges if strict requirements or funding limitations exist, the technical foundation is exceptionally strong. The vendor lock-in risk is also unknown, but the use of open-source technologies like Kubernetes and a major cloud provider like AWS generally suggests a lower risk of being tied to proprietary systems, enhancing migration flexibility. The geographic diversity of vendors also suggests a distributed supply chain that might be less prone to single-vendor dependencies.

Compliance

4 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

NIS2 applicability depends on Detectify's specific industry sector and size. Without knowing their exact business activities, they could potentially fall under 'digital providers' or 'ICT service management' categories if they provide cybersecurity services. The risk is medium because if applicable, non-compliance can result in significant fines and operational restrictions, but applicability is uncertain without industry confirmation.

ISO 27001 (source) — Assessment Required

ISO 27001 is highly relevant for cybersecurity companies as it demonstrates information security management capabilities. While not legally mandatory, it's often required by enterprise customers and regulatory frameworks. Risk is medium because lack of certification could impact business opportunities and customer trust in the cybersecurity sector.

SOC 2 (source) — Assessment Required

SOC2 is relevant for service providers, especially in technology sectors. If Detectify provides cloud-based cybersecurity services, SOC2 compliance would be important for customer trust and competitive positioning. Risk is medium because while not legally mandatory, it's often required by enterprise customers and affects business opportunities.

Financials

Three-year financials

Financial Resilience Score: 5/10

Detectify AB operates a recurring SaaS revenue model with estimated gross margins of 70–80%, which is characteristic of high-quality software businesses and provides a strong foundation for financial resilience. The company benefits from a differentiated product offering through its crowdsourced ethical hacker community, a growing EASM market, and backing from a reputable global growth-equity investor (Insight Partners), all of which support its ability to continue operating and raising capital. However, the company has historically operated at a sustained operating loss, with estimated annual losses in the range of SEK 50–150M, funded by equity raises totalling approximately USD 30–35M. In the post-2022 tighter funding environment, this creates meaningful refinancing risk if growth decelerates or investor appetite for unprofitable growth-stage companies diminishes further. No new funding round has been publicly announced since 2021. Competitive dynamics pose an additional structural risk. The EASM market has attracted well-capitalised incumbents including Microsoft, Google/Mandiant, and Rapid7, all of which have significant distribution advantages over a mid-market-focused independent vendor of Detectify's scale. The company's relatively modest total funding (~USD 30–35M) limits its ability to compete aggressively on sales and marketing against these larger players. Overall, the resilience score reflects a business with solid unit economics and a defensible niche, but meaningful execution and financing risk given sustained losses, a competitive market, and limited disclosed financial transparency. The score would improve materially if audited Bolagsverket filings confirmed a path toward profitability or a new capital raise.

Key strengths: Recurring SaaS subscription revenue model with high predictability, Estimated gross margins of 70–80%, typical of SaaS businesses, Crowdsourced ethical hacker community creates proprietary vulnerability intelligence moat, Backed by Insight Partners, a major global growth-equity firm, Growing EASM market with strong enterprise demand, GDPR-compliant EU positioning is a competitive advantage for European customers, Established customer base including Spotify, King, and Atlassian (Trello)

Risk factors: Sustained operating losses estimated at SEK 50–150M annually, creating cash burn risk, No new funding round publicly announced since 2021 Series C extension, Intense competition from well-funded players including Microsoft, Google/Mandiant, Rapid7, and CyCognito, Refinancing risk in tighter post-2022 venture capital environment, Concentration in SME/mid-market segment; upmarket enterprise expansion requires significant investment, FX exposure between international customer revenues (EUR/USD) and SEK-denominated costs, High personnel costs in competitive Stockholm tech talent market, No disclosed IPO or M&A exit path, limiting future capital-raising optionality, Limited public financial transparency makes independent credit/investment assessment difficult

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report