Skip to content

SixMap

Attack surface management startup using computational internet mapping to discover an organization's internet-facing assets across all 65,535 ports on both IPv4 and IPv6 from just an enterprise name.

Visit Website ↗ + Add to Compare
58/100Incremental Innovator

Overview

SixMap provides attack surface management built around large-scale, zero-touch computational mapping of the internet. Rather than requiring customers to manually inventory assets or install agents, the platform starts from just an organization’s name and works outward, scanning all 65,535 ports across both IPv4 and IPv6 address space to surface internet-facing assets, including shadow IT and unmanaged infrastructure that traditional asset-discovery tools and manually maintained CMDBs typically miss.

The company’s name is a reference to IPv6, and that dual-stack focus is a specific technical differentiator: many attack surface management tools built earlier in the category’s history focused primarily on IPv4 discovery, leaving a growing IPv6 blind spot as organizations adopt it. SixMap’s continuous monitoring model is aimed at closing that gap and at supporting continuous threat exposure management (CTEM) programs that need up-to-date visibility rather than periodic point-in-time scans.

Founded in 2020 and based in San Francisco, SixMap raised a $7 million round in April 2025 led by IAG Capital Partners with participation from TRE Advisors and returning investors DataTribe and California Innovation Fund, bringing its total disclosed funding to $23.5 million across four rounds. The company has also been awarded a Phase I Small Business Innovation Research (SBIR) contract from the US Air Force to extend its continuous threat exposure management capabilities, an independently competitive government validation point, and reports Fortune 500 companies and federal agencies among its customers.

Innovation Matrix Assessment

Innovation Velocity 6/10

A $7M funding round in April 2025 following prior rounds, plus a newly awarded Air Force SBIR contract to extend CTEM capabilities, indicate active, funded product development rather than a stalled early-stage effort.

Operational Value 6/10

The zero-touch, name-only scanning model (no agents, no manual asset input required) is designed for low deployment friction, and full-port scanning across both IPv4 and IPv6 is a genuinely more complete operational approach than IPv4-only competitors.

Market Momentum 6/10

$23.5M raised across four rounds with a fresh $7M close in 2025 from both new (IAG Capital Partners, TRE Advisors) and returning investors (DataTribe, California Innovation Fund) is a concrete, independently reported funding trajectory for a company still only five years old.

Category Disruption 5/10

Full dual-stack IPv4/IPv6 computational mapping addresses a real, underserved blind spot in a fairly mature attack surface management category, though ASM itself is well established with several funded competitors.

Real-World Efficacy 5/10

A Phase I SBIR contract from the US Air Force is a competitively awarded, independently verifiable government validation point; broader efficacy claims (Fortune 500 and federal agency customers) are vendor-reported without named references or independent benchmark results.

Enduring Relevance 7/10

IPv6 adoption is steadily growing and shadow-IT/unmanaged asset exposure remains a persistent breach vector, keeping comprehensive, dual-stack attack surface visibility highly relevant to current CTEM and exposure-management priorities.

Why CISOs Should Care

Closes a specific and growing blind spot, IPv6 asset discovery, that many attack surface management tools still handle poorly, while requiring no agents or manual asset input to get initial visibility.

What Makes It Different

Full computational mapping across all 65,535 ports on both IPv4 and IPv6, starting from just an organization's name, versus the IPv4-centric focus of many earlier attack surface management tools.

The Matrix Verdict

58/100 — INCREMENTAL INNOVATOR

A well-funded, technically differentiated ASM startup with a credible government validation point (Air Force SBIR) and a real, growing gap (IPv6 visibility) to address; still small and early-stage relative to established ASM incumbents.

Editorial Note: Claims vs. Verified Findings

The $7M funding round, investor list, and total $23.5M raised are independently reported in funding-tracking outlets (SiliconANGLE, citybiz, PitchBook/Crunchbase); the Air Force Phase I SBIR award is a competitively granted government contract and independently verifiable. Fortune 500 and federal-agency customer claims are vendor-reported without named references.

Sources