Detack GmbH
Detack GmbH builds EPAS, a password and credential security auditing tool that simulates real cracking attacks rather than relying on policy checklists.
Visit Website ↗ + Add to CompareOverview
Detack GmbH is a German IT security company founded in 2000 and headquartered in Ludwigsburg, near Stuttgart. For 25 years the company has focused on a specific, persistent problem: weak, reused, and compromised passwords, which remain one of the most common initial-access vectors in real-world breaches despite two decades of industry talk about passwordless authentication.
The company’s flagship product, EPAS (Enterprise Password Analytics Solution), performs automated, large-scale password strength assessment and enforcement by simulating real password-cracking attacks against an organization’s actual credential stores, rather than relying on policy checklists such as length and complexity rules that don’t reflect how passwords actually get broken. EPAS is deployed, according to the company, in more than 30 countries, spanning use cases from mainframe and midrange systems to IoT and industrial systems, ATMs, retail banking, and SAP environments. Detack’s team holds recognized offensive-security certifications, including OSCP and OSWP, and the company itself carries ISO/IEC 27001:2022 certification; it also offers penetration testing and red-teaming consulting alongside its EPAS product.
Detack is a small, privately held company that has stayed narrowly focused rather than expanding into a broader identity or access-management platform, which is both its strength, deep specialization in password and credential risk, and its limit, a niche product category as passwordless and phishing-resistant MFA adoption slowly grows. Its longevity and technical certifications are real, independently verifiable signals; specific deployment-scale claims come from the company itself.
Innovation Matrix Assessment
EPAS has evolved incrementally over 25 years, with recent materials referencing AI and high-performance-computing-driven credential assessment, reflecting steady rather than fast-paced product evolution.
As a small, ISO/IEC 27001:2022-certified team that has expanded strategic presence into the U.S., Singapore, Australia, Romania, and Switzerland over 25 years, Detack shows stable execution for its size.
No major funding events, acquisitions, or public growth metrics were found; the company presents as a stable, long-running niche business rather than one with visible new momentum.
Simulating real password-cracking attacks against actual credential stores, rather than relying on policy-checklist compliance, is a genuinely more realistic approach to credential risk than most compliance-driven password auditing tools.
ISO 27001 certification and OSCP/OSWP-certified staff are independently verifiable technical credibility signals; the specific '30+ countries' deployment claim and detailed effectiveness statistics are vendor-stated and were not independently corroborated.
Credential-based attacks remain one of the top initial-access vectors in industry breach reporting, keeping password and credential risk auditing relevant even as passwordless authentication slowly gains adoption.
Why CISOs Should Care
Detack gives CISOs a way to test password and credential strength against actual cracking techniques rather than relying on policy checklists, directly addressing one of the most persistent initial-access vectors in real breaches.
What Makes It Different
Unlike generic password-policy compliance tools, EPAS simulates real attack techniques against an organization's actual credential stores to find genuinely weak or compromised passwords, spanning everything from mainframes to ATMs and industrial systems.
The Matrix Verdict
47/100 — EMERGING / UNRANKED
A credible, narrowly-focused credential security specialist with real technical certifications and a 25-year track record, but a small company in a niche category whose growth and broader market momentum are thin on public evidence.
Editorial Note: Claims vs. Verified Findings
Detack's 2000 founding, Ludwigsburg headquarters, ISO/IEC 27001:2022 certification, and staff OSCP/OSWP certifications are independently verifiable through the company's own site and industry directories. The specific claim of EPAS deployment in '30+ countries' and detailed effectiveness statistics come from Detack's own materials and were not independently corroborated by a third party.
Sources
Alternatives to Detack GmbH
Teleport
An identity-based infrastructure access platform issuing short-lived cryptographic identities for humans, machines, and AI agents in place of…
SpecterOps
Identity attack-path security specialist behind BloodHound, the widely used open-source tool for mapping Active Directory and Entra ID…
Astrix Security
Non-human identity security platform that discovers and governs API keys, OAuth tokens, service accounts, and AI-agent credentials across…
Socure
AI-driven identity verification and fraud platform used by banks, fintechs, and government agencies to validate identities during digital…
Keyfactor
Machine identity and PKI management platform helping enterprises secure certificates, keys, and post-quantum cryptography readiness at scale.
Silverfort
Agentless unified identity protection platform that extends MFA, ITDR, and access policy to legacy and unmanaged systems traditional…