Devoile

devoile.ai · 22 vendors

A human attack surface scanner that reveals what AI-powered attackers could learn about your people.

Resilience scores

Technology vendors

Insights

Last updated 2026-09-01 · revision 43

21 direct vendors, 253 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Devoile demonstrates medium migration readiness, primarily driven by its modern technical foundation but significantly hampered by compliance and data governance complexities. The internal tech stack, featuring React, Vite, and an AI app builder (Lovable.dev), suggests a modern, flexible, and potentially cloud-native architecture, which is a strong enabler for technical migration. However, the regulatory environment presents substantial challenges. Devoile faces a complex landscape of unaddressed compliance requirements, with numerous 'Assessment Required' statuses for critical regulations such as GDPR, SOC2, ISO 27001, and the EU AI Act. Addressing these gaps would add significant complexity, cost, and potential delays to any migration effort. Data residency requirements are also a major hurdle, with critical gaps in publicly available information regarding privacy policies, data processing agreements, sub-processor lists, and infrastructure hosting locations. Given the sensitive nature of the data Devoile processes (human exposure modeling, AI red teaming results), establishing and proving data residency compliance would be a complex undertaking during migration. Financially, the 100% revenue concentration on a single product could limit the resources available to fund a major migration. Regarding vendor relationships, while there is geographic diversity among vendor HQ countries (6 unique countries for 44 services), the actual number of distinct vendors and the extent of vendor lock-in are unknown, which could introduce unforeseen complexities or dependencies during a migration.

Compliance

7 in-scope frameworks identified; showing 3.

SOC 2 (source) — Assessment Required

SOC2 is highly relevant for Devoile as a cybersecurity SaaS/platform provider. Enterprise customers — particularly in regulated industries — routinely require SOC2 Type II reports before procuring security services. The risk is HIGH because: (1) Devoile's services involve deep access to client environments, systems, and potentially sensitive data; (2) without SOC2 certification, Devoile may be unable to win enterprise contracts; (3) the nature of red teaming means Devoile holds highly sensitive client vulnerability data, making trust assurance critical. Absence of SOC2 is a significant commercial and security risk for a cybersecurity vendor.

Evidence: https://devoile.ai, https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services

EU AI Act (source) — Assessment Required

The EU AI Act is directly and critically relevant to Devoile. Risk is HIGH because: (1) Devoile explicitly provides AI red teaming services including 'prompt injection, data leakage, and unsafe agent tool use' testing — placing them at the intersection of AI system development and AI security testing; (2) if Devoile's platform itself uses AI systems, those systems may be subject to AI Act requirements; (3) Devoile's clients using AI systems in high-risk categories will need AI red teaming as part of their conformity assessments, making Devoile a key compliance enabler; (4) the AI Act's provisions on prohibited AI practices and high-risk AI systems took effect in 2024-2025. Non-compliance or failure to align services with AI Act requirements could exclude Devoile from EU market opportunities.

Evidence: https://devoile.ai, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1689, https://artificialintelligenceact.eu/

GDPR (source) — Assessment Required

GDPR carries fines of up to €20 million or 4% of global annual turnover for serious violations. Devoile operates in cybersecurity/red teaming, which inherently involves processing personal data (employee behavioral data, human exposure modeling, customer data). The company's 'Human & AI Red Teaming' service explicitly involves modeling human behavior and exposure, which is highly likely to involve personal data processing. Without confirmed HQ location, if any EU/EEA customers or employees exist, GDPR applies. The risk is HIGH because: (1) the nature of their service (human exposure modeling) almost certainly involves personal data; (2) cybersecurity companies are increasingly scrutinized by EU regulators; (3) no public GDPR compliance documentation was found. Missing information: confirmed HQ country, DPO appointment, privacy policy details, and whether EU customers are served.

Evidence: https://devoile.ai, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679

Financials

Financial Resilience Score: 2/10

Devoile appears to be a very early-stage cybersecurity startup with no public financial disclosure available. The company's landing page at devoile.ai is built on Lovable, an AI web-app builder frequently used for MVPs and prototypes, strongly indicating a founder-led, pre-seed or seed-stage venture. No revenue, EBIT, equity, funding announcements, or customer base could be verified through public sources. Potential strengths include topical positioning in the emerging AI-driven OSINT / human-risk / social-engineering exposure segment of cybersecurity, which is a hot theme in 2024-2025. Lean operations with a Lovable-built site suggest very low burn on infrastructure. However, these are inferred rather than verified. Risks are substantial: no visible funding, revenue, or customers; typical runway risk for pre-seed/seed-stage startups; crowded competitive space with established vendors like Recorded Future, ZeroFox, Constella, KnowBe4, and Hoxhunt; long enterprise cybersecurity sales cycles of 12-24 months; regulatory/privacy risk under GDPR/CCPA given the nature of scanning personal exposure; and brand/trust risk since cybersecurity buyers heavily weight vendor maturity and certifications like SOC 2 and ISO 27001. Absent additional inputs, the honest conclusion is that Devoile is almost certainly a pre-seed or seed-stage startup with no public financials, making financial resilience essentially unassessable but presumed weak given stage.

Key strengths: Topical product category in AI-driven OSINT/human-risk cybersecurity, Lean operations with Lovable-built MVP site suggesting low burn, Founder-led small team enabling rapid pivots

Risk factors: No visible funding, revenue, or customers, Runway risk typical of pre-seed/seed-stage cybersecurity startups, Crowded competitive space with established vendors (Recorded Future, ZeroFox, Constella, KnowBe4, Hoxhunt), Long enterprise cybersecurity sales cycles (12-24 months to first meaningful deals), Regulatory/privacy risk under GDPR, CCPA given nature of scanning personal exposure, Brand/trust risk without SOC 2, ISO 27001 certifications and customer references

Revenue by product/service

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report