Skip to content

Detack GmbH

Detack GmbH builds EPAS, a password and credential security auditing tool that simulates real cracking attacks rather than relying on policy checklists.

Visit Website ↗ + Add to Compare
47/100Emerging / Unranked

Overview

Detack GmbH is a German IT security company founded in 2000 and headquartered in Ludwigsburg, near Stuttgart. For 25 years the company has focused on a specific, persistent problem: weak, reused, and compromised passwords, which remain one of the most common initial-access vectors in real-world breaches despite two decades of industry talk about passwordless authentication.

The company’s flagship product, EPAS (Enterprise Password Analytics Solution), performs automated, large-scale password strength assessment and enforcement by simulating real password-cracking attacks against an organization’s actual credential stores, rather than relying on policy checklists such as length and complexity rules that don’t reflect how passwords actually get broken. EPAS is deployed, according to the company, in more than 30 countries, spanning use cases from mainframe and midrange systems to IoT and industrial systems, ATMs, retail banking, and SAP environments. Detack’s team holds recognized offensive-security certifications, including OSCP and OSWP, and the company itself carries ISO/IEC 27001:2022 certification; it also offers penetration testing and red-teaming consulting alongside its EPAS product.

Detack is a small, privately held company that has stayed narrowly focused rather than expanding into a broader identity or access-management platform, which is both its strength, deep specialization in password and credential risk, and its limit, a niche product category as passwordless and phishing-resistant MFA adoption slowly grows. Its longevity and technical certifications are real, independently verifiable signals; specific deployment-scale claims come from the company itself.

Innovation Matrix Assessment

Innovation Velocity 4/10

EPAS has evolved incrementally over 25 years, with recent materials referencing AI and high-performance-computing-driven credential assessment, reflecting steady rather than fast-paced product evolution.

Operational Value 5/10

As a small, ISO/IEC 27001:2022-certified team that has expanded strategic presence into the U.S., Singapore, Australia, Romania, and Switzerland over 25 years, Detack shows stable execution for its size.

Market Momentum 3/10

No major funding events, acquisitions, or public growth metrics were found; the company presents as a stable, long-running niche business rather than one with visible new momentum.

Category Disruption 5/10

Simulating real password-cracking attacks against actual credential stores, rather than relying on policy-checklist compliance, is a genuinely more realistic approach to credential risk than most compliance-driven password auditing tools.

Real-World Efficacy 5/10

ISO 27001 certification and OSCP/OSWP-certified staff are independently verifiable technical credibility signals; the specific '30+ countries' deployment claim and detailed effectiveness statistics are vendor-stated and were not independently corroborated.

Enduring Relevance 6/10

Credential-based attacks remain one of the top initial-access vectors in industry breach reporting, keeping password and credential risk auditing relevant even as passwordless authentication slowly gains adoption.

Why CISOs Should Care

Detack gives CISOs a way to test password and credential strength against actual cracking techniques rather than relying on policy checklists, directly addressing one of the most persistent initial-access vectors in real breaches.

What Makes It Different

Unlike generic password-policy compliance tools, EPAS simulates real attack techniques against an organization's actual credential stores to find genuinely weak or compromised passwords, spanning everything from mainframes to ATMs and industrial systems.

The Matrix Verdict

47/100 — EMERGING / UNRANKED

A credible, narrowly-focused credential security specialist with real technical certifications and a 25-year track record, but a small company in a niche category whose growth and broader market momentum are thin on public evidence.

Editorial Note: Claims vs. Verified Findings

Detack's 2000 founding, Ludwigsburg headquarters, ISO/IEC 27001:2022 certification, and staff OSCP/OSWP certifications are independently verifiable through the company's own site and industry directories. The specific claim of EPAS deployment in '30+ countries' and detailed effectiveness statistics come from Detack's own materials and were not independently corroborated by a third party.

Sources