Skip to content

Theori

Theori is an offensive security research firm, founded by former CTF champions, that productizes its vulnerability-hunting expertise into AI-assisted vulnerability detection and offers offensive security consulting to large enterprises and governments.

Visit Website ↗ + Add to Compare
70/100Meaningful Innovator

Overview

Theori was founded in 2016 by a team of hackers with a competitive pedigree in DEF CON CTF and other elite hacking competitions, several with Carnegie Mellon backgrounds. It operates out of Austin, Texas, with a significant Korea presence (Theori Korea, established 2017), and has built its business by converting world-class offensive security talent into both consulting services and, more recently, software products. The company’s client roster reportedly includes Google, Microsoft, and Samsung Electronics, and its researchers have a track record of publicly disclosed work: they discovered vulnerabilities in South Korean mandatory financial security software (published jointly with KAIST, Korea University, and Sungkyunkwan University, accepted to USENIX Security 2025) and identified critical Apple OS vulnerabilities that triggered an emergency patch.

On the product side, Theori has moved from pure services into AI-driven security tooling: Xint, launched at RSAC 2024, is described as an automated vulnerability detection and unified security posture management platform built on the same methodology its human researchers use manually. The company also runs Dreamhack, a training and competition platform for developing offensive security talent, and αprism, aimed at AI system protection — both extensions of its core research capability into adjacent commercial products.

Theori has raised roughly $15.5M in seed funding, with investors including DARPA (through a research/challenge relationship rather than pure equity investment in some cases), Asia2G Capital, Dunamu, and Hana Bank, and is ISO/IEC 27001:2022 certified. Its most externally validated credential is competitive: in 2024 it was a semi-finalist, and in 2025 placed third in the finals, of DARPA’s AI Cyber Challenge (AIxCC), a closely watched public benchmark of automated vulnerability-finding capability, alongside numerous CTF wins through 2025 (DEF CON 33, LINE CTF, Operation Cloudfall, among others).

Innovation Matrix Assessment

Innovation Velocity 7/10

Theori has moved from pure offensive-security consulting into a multi-product line (Xint for automated vulnerability detection, Dreamhack for training, αprism for AI protection) within a few years, launching Xint publicly at RSAC 2024.

Operational Value 6/10

The company runs dual US/Korea operations (Theori Inc. and Theori Korea), holds ISO/IEC 27001:2022 certification, and reports enterprise clients including Google, Microsoft and Samsung Electronics, indicating a functioning services-plus-product operation, though headcount and revenue scale are not independently disclosed.

Market Momentum 7/10

Theori has stacked up concrete external validation through 2025: a USENIX Security 2025 paper co-authored with three Korean universities, discovery of critical Apple OS vulnerabilities prompting an emergency patch, and a string of 2025 CTF wins (DEF CON 33, LINE CTF, Operation Cloudfall, HACKSIUM BUSAN, among others), showing sustained output rather than a one-off.

Category Disruption 7/10

Productizing elite manual vulnerability-research methodology into an automated tool (Xint) that competed at DARPA's AI Cyber Challenge is a genuine attempt to scale offensive security expertise beyond a services model, differentiating it from firms that only sell human pentester time.

Real-World Efficacy 8/10

Theori's efficacy claims are unusually well externally verified for a company this size: a documented Apple vulnerability disclosure leading to an emergency patch, a peer-reviewed USENIX Security 2025 paper, and a third-place finish in DARPA's AIxCC finals against a competitive field -- independent, checkable outcomes rather than self-reported statistics.

Enduring Relevance 7/10

Automated vulnerability discovery and AI-assisted offensive security are directly aligned with where both attackers and defenders are investing, and Theori's demonstrated results in a DARPA-run public benchmark give it more credible relevance than most vendors making similar AI-security claims.

Why CISOs Should Care

CISOs evaluating AI-assisted vulnerability discovery or needing high-end offensive security assessments get a vendor whose claims are backed by public, third-party-verifiable results (DARPA AIxCC placement, USENIX publication, disclosed CVEs) rather than marketing collateral alone.

What Makes It Different

Unlike most pentest/offensive-security firms that sell only human researcher time, Theori has built and publicly benchmarked an automated vulnerability-detection product (Xint) derived from its research team's own methodology.

The Matrix Verdict

70/100 — MEANINGFUL INNOVATOR

Theori stands out in a crowded offensive-security market because its capability claims are unusually well corroborated by independent, public evidence -- DARPA competition results, an academic publication, and a named CVE disclosure -- making it one of the more credibly evidenced vendors in this batch despite being a relatively young, modestly funded company.

Editorial Note: Claims vs. Verified Findings

Vendor-sourced and unverified: the maturity and false-positive rate of the Xint product in production enterprise environments, and the scope of the Google/Microsoft/Samsung client relationships (services vs. product). Independently verified: the DARPA AIxCC 2024 semifinal and 2025 third-place finish, the USENIX Security 2025 paper, the Apple vulnerability disclosure and emergency patch, and multiple 2025 CTF competition wins.

Sources