Skip to content

Menaya

Menaya (the rebranded GamaSec) runs an AI-powered external attack surface management platform that discovers and continuously scores an organization's internet-facing assets and vulnerabilities.

Visit Website ↗ + Add to Compare
45/100Emerging / Unranked

Overview

Menaya is the current name for GamaSec, an Israeli company founded in 2006 in Herzliya Pituach that originally built a website vulnerability scanner (GamaScan) using what it called “virtual hacker” simulated-attack technology to find SQL injection, cross-site scripting, and malware on customer web properties. Under the Menaya name, the company has repositioned around external attack surface management (EASM): continuously discovering an organization’s internet-facing assets from an attacker’s vantage point, scoring the risk each one presents, and prioritizing remediation with AI-assisted guidance, primarily for small and mid-sized enterprises that lack a dedicated attack-surface-management program.

The rebrand and repositioning track a broader industry shift from point-in-time vulnerability scanning toward continuous, attacker’s-eye-view asset discovery, which has become table stakes as organizations’ external footprints sprawl across cloud services, forgotten subdomains, and shadow IT. Menaya’s roots in nearly two decades of web vulnerability detection give it a longer operating history than many EASM entrants, even though the current product framing is comparatively recent.

Menaya is best suited to SMEs that need external exposure visibility but don’t have the budget or headcount for enterprise-grade EASM platforms like CyCognito or Randori; its long-running heritage in website-specific vulnerability detection is a genuine differentiator versus EASM vendors built from scratch on generic asset-discovery techniques.

Innovation Matrix Assessment

Innovation Velocity 4/10

The GamaSec-to-Menaya repositioning from web vulnerability scanning to EASM shows the company adapting its product to market shifts, but there is little public evidence of a fast release cadence on the current EASM platform specifically.

Operational Value 5/10

Nearly two decades of continuous operation since 2006, plus offices spanning Israel, the US, APAC, LATAM, and MEA per company materials, indicate an established but modestly sized operation with a small reported headcount (LinkedIn lists 11-50).

Market Momentum 4/10

No funding rounds, headcount growth, or major new customer wins were found in public sources; the rebrand itself is the most concrete recent signal of change, and momentum is difficult to independently verify beyond that.

Category Disruption 4/10

External attack surface management is now a mature, well-populated category with established leaders (CyCognito, Censys, Randori); Menaya's approach does not appear to introduce a novel detection technique relative to category peers.

Real-World Efficacy 4/10

No independent benchmark or named customer case study documenting detection accuracy was found for either the legacy GamaSec scanner or the current Menaya EASM platform; efficacy claims are vendor-described.

Enduring Relevance 6/10

External attack surface visibility remains a persistent, real gap for SMEs specifically, which is the segment Menaya targets, making the core use case relevant even where the vendor's independent differentiation is limited.

Why CISOs Should Care

Smaller organizations without a dedicated attack-surface-management function get a long-running vendor (formerly GamaSec, now Menaya) offering continuous external asset discovery and vulnerability scoring at a price point aimed at the SME segment.

What Makes It Different

Menaya's differentiation is tenure — nearly 20 years of web vulnerability detection heritage under the GamaSec name — combined with SME-focused pricing, rather than a technically novel EASM detection method.

The Matrix Verdict

45/100 — EMERGING / UNRANKED

A long-tenured, low-profile vendor that has repositioned from web vulnerability scanning to EASM; a reasonable budget option for SMEs, though it lacks the independent validation and market visibility of category leaders.

Editorial Note: Claims vs. Verified Findings

Vendor-sourced and unverified: all specific efficacy, detection-accuracy, and platform-capability claims — no independent third-party evaluation of either the legacy GamaSec scanner or current Menaya platform was found. The GamaSec-to-Menaya name history and 2006 founding date are corroborated across multiple independent listings (CB Insights, Startup Nation Finder, CyberDB).

Sources