Skip to content

Edgescan

A Dublin-based, Series B-funded continuous exposure validation platform combining external attack surface management, risk-based vulnerability management, and penetration-testing-as-a-service in one product.

Visit Website ↗ + Add to Compare
60/100Incremental Innovator

Overview

Edgescan sells continuous exposure validation, built on the premise that periodic point-in-time vulnerability scans and annual pentests leave organizations blind for most of the year. Founded in Dublin in 2016 by Eoin Keary — previously OWASP global board chair — the platform combines external attack surface management (EASM), risk-based vulnerability management, application and API security testing, and penetration-testing-as-a-service (PTaaS) into a single continuously-running service, rather than selling each as a separate scanner or one-off engagement.

The core mechanic that differentiates Edgescan from many pure-automation ASM tools is human validation: findings from its scanning layer are reviewed by a security engineering team before being surfaced, which is intended to cut down the false-positive noise that plagues fully automated vulnerability and exposure tools and to let risk-based prioritization reflect exploitability rather than raw CVSS scores. That validation layer is also the company’s main scaling constraint relative to fully automated competitors, since coverage growth requires analyst capacity alongside engineering.

Edgescan has raised $11.9M in a Series B round from BGF, a relatively modest capital base for a company competing against better-funded EASM and PTaaS platforms, but it has built a decade of continuous operating history and an annual State of Exposure Management report that is cited across the industry as a benchmarking source for time-to-remediate and vulnerability-density statistics. It is a credible, if capital-constrained, alternative to platform-only ASM and vulnerability management vendors for organizations that want validated findings rather than raw scanner output.

Innovation Matrix Assessment

Innovation Velocity 6/10

Edgescan has steadily broadened from vulnerability management into API security testing and full PTaaS over roughly a decade, a consistent if not especially rapid platform expansion pace for a company operating on modest funding.

Operational Value 7/10

By combining EASM, risk-based vulnerability management, and PTaaS with human-validated findings in one continuous service, it reduces the operational burden of stitching together separate scanners and manually triaging false positives, which is a genuine workflow improvement over point-tool approaches.

Market Momentum 5/10

Total disclosed funding is $11.9M in a single Series B round from BGF -- modest for a company approaching a decade of operation and competing against far better-capitalized ASM and PTaaS vendors, suggesting slower capital-driven growth even if the business itself is self-sustaining.

Category Disruption 5/10

Its differentiation is a hybrid model -- automated scanning plus human security-engineer validation of every finding -- rather than a novel detection technology; this is a meaningful quality improvement over pure-automation competitors but not a structurally new approach to exposure management.

Real-World Efficacy 6/10

The analyst-validation layer is a credible, verifiable mechanism for reducing false positives (reviewable via product demos and customer reviews on G2), and its annual State of Exposure Management report is independently cited across the industry as a benchmarking source, though the report itself is Edgescan's own data set rather than third-party audited research.

Enduring Relevance 7/10

Continuous exposure validation sits at the center of the industry's shift toward continuous threat exposure management (CTEM) away from point-in-time scanning and annual pentests, keeping Edgescan's core positioning well aligned with current buyer priorities.

Why CISOs Should Care

CISOs tired of vulnerability scanner output flooded with false positives get findings that have already been triaged by a human security engineer before hitting their queue, which changes the economics of remediation prioritization.

What Makes It Different

Most EASM and vulnerability management vendors compete on automation and coverage breadth; Edgescan competes on validated accuracy by keeping human security engineers in the review loop for every finding.

The Matrix Verdict

60/100 — INCREMENTAL INNOVATOR

A credible, decade-tested continuous exposure validation platform whose human-in-the-loop model is a genuine differentiator on accuracy, constrained mainly by a comparatively small capital base against better-funded category peers.

Editorial Note: Claims vs. Verified Findings

Independently verifiable: founding year, founder background (Eoin Keary's prior OWASP global board chair role), and the $11.9M Series B funding round from BGF (consistent across Crunchbase, PitchBook, and Dealroom). The State of Exposure Management report's statistics are Edgescan's own proprietary data set, not independently audited, so figures drawn from it should be treated as vendor-sourced industry commentary rather than third-party-verified benchmarks.

Sources