Skip to content

Cossack Labs

UK-headquartered data security firm building open-source and commercial cryptographic tools, including the Acra database encryption proxy and the Themis crypto library.

Visit Website ↗ + Add to Compare
55/100Incremental Innovator

Overview

Cossack Labs builds application-layer encryption and data security tooling for organizations that need to protect sensitive data without re-architecting their applications. Its flagship product, Acra, is a database security proxy that adds field-level encryption, SQL-injection detection, and intrusion-detection honeypots in front of a database with minimal changes to application code. The company also maintains Themis, an open-source cryptographic library used by developers to add authenticated encryption and secure data exchange to their own software, and Hermes, a framework for multi-user end-to-end encrypted data storage.

Founded in 2014, Cossack Labs is headquartered in London with its engineering and research team based in Kyiv, Ukraine. The company has operated continuously for over a decade without a large publicly disclosed funding round, growing instead through direct enterprise and services engagements with fintech, healthcare, critical-infrastructure, and decentralized-finance customers who need to encrypt sensitive data in distributed systems.

The company’s approach — positioning encryption as a transparent proxy layer rather than a software development kit developers must integrate line by line — sets it apart from vendors that require heavier application-side rework. Its open-source libraries have visible, actively maintained repositories on GitHub, giving outside engineers a way to inspect the underlying cryptography directly rather than relying solely on vendor claims.

Innovation Matrix Assessment

Innovation Velocity 6/10

Cossack Labs has kept shipping and maintaining its open-source Acra and Themis libraries continuously since 2015, with active public GitHub repositories, though a small team limits the pace of new feature delivery compared to venture-scale competitors.

Operational Value 5/10

The company has sustained more than a decade of continuous operation with a small (11-50 person) team and no large disclosed funding round, suggesting a lean, services-supported business model rather than venture-scale operational infrastructure.

Market Momentum 4/10

No public funding announcements, revenue figures, or major recent enterprise wins were found; growth appears organic and gradual rather than accelerating, and evidence of current market momentum is limited.

Category Disruption 7/10

Acra's transparent proxy-based field-level encryption, combined with built-in SQL-injection detection and intrusion honeypots, is a materially different architecture than the SDK-integration model used by most competing encryption vendors.

Real-World Efficacy 5/10

Themis and Acra have visible, actively maintained open-source adoption on GitHub, which is a real signal the tools are used in practice, but no independently verified named enterprise case study or third-party security audit was found in available research.

Enduring Relevance 6/10

Field-level data encryption remains a persistent compliance and risk requirement for fintech, healthcare, and critical-infrastructure operators under regimes like GDPR and PCI-DSS, though the company is not positioned as a leader in newer categories like AI-specific data protection.

Why CISOs Should Care

CISOs needing to encrypt sensitive data across distributed systems get proven, independently inspectable open-source cryptographic building blocks plus a proxy-based database encryption layer that avoids invasive application rework.

What Makes It Different

Acra sits transparently in front of a database rather than requiring an SDK integrated line-by-line into application code, adding field-level encryption, SQL-injection detection, and honeypot-based intrusion detection with minimal app-side changes.

The Matrix Verdict

55/100 — INCREMENTAL INNOVATOR

A credible, engineering-led data security shop with genuinely differentiated open-source cryptographic tooling and a decade of continuous operation, but thin on independently verifiable enterprise traction data.

Editorial Note: Claims vs. Verified Findings

Cossack Labs' claims about ease of integration, performance overhead, and named customer segments (fintech, healthcare, critical infrastructure) are vendor-stated and were not independently benchmarked here. Independently verifiable: its open-source repositories (Themis, Acra) are public on GitHub with visible, active commit history and community usage, confirming real, maintained products rather than vaporware.

Sources