Red Kite Solutions Inc.

Canada · owned by Independent (Canada) · red-kite.io · 8 vendors

Red Kite Solutions Inc. is a Canadian cybersecurity company specializing in External Attack Surface Management (EASM). Their platform provides full visibility into internet-facing assets, delivers actionable risk insights, and automates reconnaissance workflows for MSSPs, MSPs, and enterprises. The core product is open-source and emphasizes transparency, allowing users to audit, inspect, and customize all scanning logic and test cases.

Resilience scores

Disruption prediction

Red Kite Solutions Inc. has an estimated 17% probability of disruption in the next 6 months.

5 of Red Kite Solutions Inc.'s 8 vendors monitored for disruptions.

Technology vendors

Insights

Last updated 2026-09-09 · revision 3

8 direct vendors, 149 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Red Kite Solutions Inc. demonstrates medium to high migration readiness, primarily driven by its highly modern and portable technology stack. The extensive use of Kubernetes and Docker signifies a strong foundation for containerization and cloud-native principles, enabling flexible deployment across various infrastructures, including on-premise and cloud environments. The availability of an open-source, self-hosted edition and an on-premise deployment option for its Enterprise plan further underscores its technical adaptability. However, several critical data gaps introduce significant challenges and risks to a potential migration. The lack of information regarding regulatory environment, data residency requirements, and financial stability (which would impact the ability to fund a migration) creates substantial unknowns. While vendor relationships show some geographic diversity, the specific number of unique vendors for the 9 services and the associated vendor lock-in risks are unknown, which could complicate migration efforts. Despite these unknowns, the inherent portability of its core technologies positions Red Kite favorably for migration, provided the regulatory, data residency, and financial aspects can be adequately addressed.

Compliance

7 in-scope frameworks identified; showing 3.

GDPR (source) — Assessment Required

Red Kite Solutions Inc. is headquartered in Canada (Montréal, QC), not in the EU/EEA, so GDPR does not apply by virtue of location. However, as a cybersecurity SaaS/EASM platform serving MSSPs, MSPs, and enterprises globally, it is plausible — though not confirmed — that the company processes personal data of EU/EEA residents (e.g., EU-based customers, employees, or data subjects whose internet-facing assets are scanned). If EU/EEA personal data is processed, GDPR applies under Article 3(2) (extraterritorial scope). Risk is Medium because: (1) the company is small (startup-stage, two known founders), reducing enforcement likelihood; (2) no confirmed EU customer base or EU data processing has been evidenced; (3) GDPR fines can reach €20M or 4% of global annual turnover, which is significant even for small companies. Enforcement against non-EU companies has increased since 2021.

Evidence: https://red-kite.io, https://red-kite.io/about-us, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679

SOC 2 (source) — Assessment Required

Red Kite Solutions Inc. is a cloud-based SaaS cybersecurity platform (EASM tool) that processes customer data including internet-facing asset information, scan results, and potentially sensitive security findings. SOC 2 is not a legal requirement but is a widely expected industry standard for cloud service providers, particularly when serving enterprise clients, MSSPs, and MSPs. The absence of a SOC 2 report may be a commercial barrier to enterprise sales and could represent a trust/risk gap for customers. Risk is Medium because: (1) the company explicitly targets enterprise customers and MSSPs/MSPs who typically require SOC 2 attestation from vendors; (2) no SOC 2 report or certification was found; (3) as a small startup, the cost and effort of SOC 2 may not yet have been prioritized. Lack of SOC 2 could result in lost enterprise deals rather than regulatory penalties.

Evidence: https://red-kite.io, https://red-kite.io/enterprise, https://github.com/red-kite-solutions/stalker, https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services

CPRA — Assessment Required

The CCPA/CPRA applies to for-profit businesses that collect personal information of California residents and meet one of three thresholds: (1) annual gross revenues exceeding $25M; (2) annually buy, sell, or share personal information of 100,000+ consumers or households; (3) derive 50%+ of annual revenues from selling/sharing personal information. Red Kite Solutions Inc. is a small Canadian startup and is unlikely to meet these thresholds currently. However, if the company serves US-based customers (including California residents) and collects their personal data, CCPA applicability should be monitored as the company grows. Risk is Low given the company's current apparent size and stage.

Evidence: https://red-kite.io, https://oag.ca.gov/privacy/ccpa

Financials

Three-year financials

Financial Resilience Score: 3/10

Red Kite Solutions is a pre-disclosure, early-stage private Québec cybersecurity startup in the External Attack Surface Management (EASM) segment. There is insufficient public financial information to compute revenue, profitability, or equity metrics, or to model YoY growth. As a private Canadian corporation, it is not required to file public financial statements, and no funding rounds, grants, or audited financials could be verified. Despite the financial opacity, the company shows several qualitative strengths: backing from credible ecosystem partners (Propolys, CyberEco, PME MTL, Rogers Cybersecure Catalyst), founder domain expertise (co-founder Simon Lacasse holds OSCP, OSWE, OSEP certifications and has worked in major Canadian banks), an open-source flywheel with the Stalker product (88 GitHub stars, 7 forks), and a defined multi-tier SaaS commercial model (Free trial, Managed Services at $415/month base + $50/project, Enterprise custom). However, the risks are substantial: very small team (likely single-digit to low-double-digit employees), key-person concentration on two founders, zero external financial validation, a crowded competitive market dominated by well-funded incumbents (CrowdStrike, Palo Alto, Microsoft, Censys, Rapid7), and potential open-source cannibalization risk from GPL-3.0 licensing. The resilience score reflects the early-stage nature and absence of any financial safety net that can be verified externally.

Key strengths: Backed by credible ecosystem partners (Propolys, CyberEco, PME MTL, Rogers Cybersecure Catalyst), Founder domain expertise with elite offensive security certifications (OSCP, OSWE, OSEP), Open-source Stalker product with 88 GitHub stars and 7 forks providing developer traction, Defined multi-tier SaaS commercial model (Free/Managed Services/Enterprise), Bilingual (English/French) positioning for Canadian and francophone markets

Risk factors: Zero public disclosure of revenue, cash runway, funding raised, or burn rate, Early-stage scale with very small team and limited ARR, Key-person concentration risk with only two publicly identified founders, Highly competitive EASM market dominated by well-funded incumbents (CrowdStrike, Palo Alto, Microsoft, Censys, Rapid7), Open-source cannibalization risk from GPL-3.0 licensing of core product, No external validation of financial resilience for counterparties

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report