Latka logo

Top 37 Penetration Testing Software SaaS Companies in May 2026

As of May 2026, there are 37 SaaS companies in Penetration Testing Software. They have combined revenues of $840.3M and employ 6.6K people. They have raised $837.8M and serve 2.8K customers combined.

Penetration Testing Software is designed to assess the security of computing systems and networks through simulated cyber attacks. These tools enable organizations to identify and remediate vulnerabilities before they can be exploited by malicious actors. Conducting penetration testing helps organizations verify the effectiveness of their security measures and compliance with regulatory requirements. The primary use cases for penetration testing software include testing web applications, APIs, networked systems, and mobile applications. Typical features often include vulnerability scanning, reporting dashboards, and automated testing capabilities to streamline the assessment process. Users of these solutions typically belong to IT security teams, compliance officers, and risk management professionals, each aiming to enhance their organization's overall security posture and protect sensitive data from threats.

Companies
37
Revenue
$840.3M
Funding
$837.8M
Employees
6.6K

Filters

Sorting: Highest -> Lowest

Filters

Top Penetration Testing Software Companies

Showing 10 of 11 companies ranked by annual revenue.

1
Intigriti

United States

Intigriti is the trusted leader in crowdsourced security. Since 2016, we’ve empowered the world’s largest organizations to proactively identify and address vulnerabilities before they're exploited by cybercriminals. Harnessing the expertise of our 100,000+ researchers, businesses can detect vulnerabilities as soon as they surface, avoiding the costly damage of security breaches. Through our meticulous triaging process, commitment to legal compliance, and unparalleled customer service, we deliver the utmost reliability for our customers. Intigriti is proud to help industry leaders safeguard their digital assets and thrive in an ever-evolving threat landscape.

Revenue
$53.9M
Customers
-
Year founded
2016
Funding
-
Team size
490
Growth
-
2
Cobalt

Boston, Massachusetts, United States

Pen Testing as a Service (PTaaS) platform

Revenue
$51M
Customers
600
Year founded
2013
Funding
$506.5M
Team size
497
Growth
81.96%
3
Horizon3.ai

San Francisco, California, United States

Horizon3.ai is a cybersecurity company specializing in autonomous penetration testing and vulnerability management. Its flagship platform, NodeZero™, helps enterprises prioritize defensive efforts against actual threats.

Revenue
$50.7M
Customers
-
Year founded
2019
Funding
-
Team size
258
Growth
-
4
YesWeHack

United States

YesWeHack is a leading Bug Bounty and Vulnerability Management Platform. Founded by ethical hackers in 2015, YesWeHack connects organisations worldwide to tens of thousands of ethical hackers, who uncover vulnerabilities in websites, mobile apps, connected devices and digital infrastructure. Bug Bounty programs benefit from in-house triage, personalised support, a customisable model and results-based pricing. Clients include Tencent, Swiss Post, Orange France and the French Ministry of Armed Forces. The YesWeHack platform offers a range of integrated, API-based solutions: Bug Bounty (crowdsourcing vulnerability discovery); Vulnerability Disclosure Policy (creating and managing a secure channel for external vulnerability reporting); Pentest Management (managing pentest reports from all sources); Attack Surface Management (continuously mapping online exposure and detecting attack vectors); and ‘Dojo’ (ethical hacking training). YesWeHack complies with strict security, financial traceability and privacy requirements. YesWeHack’s services are ISO 27001- and ISO 2701-certified and accredited by CREST. YesWeHack’s infrastructure uses EU-based, GDPR-compliant private hosting that meets the most stringent standards: ISO 27001, ISO 27017, ISO 27018, ISO 27701 and SOC II Type 2. The YesWeHack platform is also permanently subject to a public Bug Bounty Program. Find out more at www.yeswehack.com

Revenue
$38.2M
Customers
-
Year founded
2015
Funding
-
Team size
347
Growth
-
5
PortSwigger

Knutsford, Cheshire, United Kingdom

PortSwigger is a global leader in cybersecurity, specializing in web application security testing. They created Burp Suite, the leading toolkit for web application security testing.

Revenue
$35.7M
Customers
-
Year founded
2008
Funding
-
Team size
254
Growth
-
6
Yogosha

Paris, France

Yogosha is a french bug bounty platform.

Revenue
$27M
Customers
100
Year founded
2015
Funding
$2.2M
Team size
210
Growth
115.19%
7
CyberSmart

London, United Kingdom

cybersecurity company

Revenue
$16.2M
Customers
-
Year founded
2016
Funding
-
Team size
67
Growth
24.73%
8
Ioactive, Inc

Seattle, Washington, United States

IOActive is a security consultancy with a global presence and deep expertise spanning hardware, software, and wetware.

Revenue
$15.1M
Customers
-
Year founded
1998
Funding
-
Team size
154
Growth
-
9
UnderDefense Cybersecurity

New York, New York, United States

UnderDefense is a leading global cybersecurity company widely recognized by industry experts, such as Gartner and Clutch. The perfect combination of our expertise and sophisticated technologies allows us to predict, detect, and respond to the most advanced & aggressive cyber threats. Our offering includes: - UnderDefense no-code Security-as-a-Service platform - a comprehensive solution to effectively defend against cybercrime and meet compliance standards for companies lacking dedicated security personnel. It automates routine security tasks, detects potential threats, ensures compliance with industry regulations, and generates detailed reports covering all aspects of network security, data privacy, risk management, and compliance from a single window; - 24х7х365 Managed Detection & Response services provide an extra layer of security and help organizations to protect against the latest cyber threats. With our vendor-agnostic MDR (works with all major EDR/SIEM/Cloud providers), you get the most advanced security approach that incorporates human expertise and technology to perform monitoring, advanced threat detection, and response in real time; - Incident Response, which aims to help businesses to investigate, remediate, and get back to normal operations faster because every minute of downtime costs a lot for companies that have fallen victim to attackers. The combination of cost-effectiveness, superior forensic expertise, and speed of remediation help us to stay ahead of the competition; - Penetration Testing. Our expertise in this field is recognized by many industry leaders. Our specialists are capable of penetrating almost any network. They will help to discover security vulnerabilities in your environment, provide recommendations on how to fix those vulnerabilities, and confirm that all defects were fixed for free. To learn more about us, our products & services, please visit our website or contact us to get a quote.

Revenue
$13.3M
Customers
-
Year founded
2017
Funding
-
Team size
121
Growth
-
10
OnSecurity

Bristol, England, United Kingdom

OnSecurity is a leading CREST-accredited penetration testing vendor based in the UK, dedicated to delivering high-impact, high-intelligence penetration testing services to businesses of all sizes.

Revenue
$11.4M
Customers
-
Year founded
2018
Funding
-
Team size
57
Growth
-

Inclusion Criteria

- The software must provide functionality for simulating real-world cyber attack scenarios. - It should identify vulnerabilities across various platforms, including web applications and networks. - The solution must include comprehensive reporting tools to document findings and recommendations. - It should facilitate remediation tracking to ensure vulnerabilities are addressed. - Not just a scanning tool; it must also support active exploitation techniques to assess security measures.