Detectify
Stockholm-based EASM and DAST platform that feeds its scanner with vulnerability research crowdsourced from a network of ethical hackers.
Visit Website ↗Overview
Detectify was founded in 2013 in Stockholm by Fredrik Nordberg Almroth and Rickard Carlsson and has raised roughly $42 million across several rounds, including a €21.5 million Series B led by Balderton Capital. The company combines external attack surface management with dynamic application security testing (DAST), continuously exposing internet-facing assets and testing them for exploitable web vulnerabilities.
Its structural differentiator is Detectify Crowdsource: a network of ethical hackers who research and submit novel vulnerability techniques, which Detectify’s team turns into automated tests fed into the scanning engine. This gives the platform access to attacker-grade research that a purely in-house research team would take longer to accumulate, and keeps its detection logic closer to real-world exploitation techniques rather than only known CVEs.
Innovation Matrix Assessment
The Crowdsource model continuously feeds new attacker-grade research into the scanning engine, giving it a faster research-to-detection pipeline than teams relying solely on internal researchers.
Combining EASM with DAST is well suited to web-application-heavy organizations that need both asset discovery and exploitability testing in one tool.
Series B funding and roughly $42M total raised is modest compared to more heavily funded EASM competitors, reflecting steady rather than explosive growth.
The crowdsourced ethical-hacker research pipeline is a genuinely different sourcing model for vulnerability detection logic compared to purely in-house research teams.
Ethical-hacker-sourced techniques feeding directly into automated scans is a credible mechanism for finding real, exploitable issues rather than only known CVE matches.
The combined EASM plus DAST approach remains relevant as organizations' externally exposed web application footprint continues to expand.
Why CISOs Should Care
A CISO gets exploitability testing informed by real ethical-hacker research techniques, not just asset discovery, which reduces false positives on "is this actually exploitable."
What Makes It Different
Detection logic is sourced from a crowdsourced network of ethical hackers rather than solely an internal research team, keeping the scanner closer to current real-world attacker techniques.
The Matrix Verdict
70/100 — MEANINGFUL INNOVATOR
A focused, research-driven player whose crowdsourcing model is a genuine structural differentiator, though its funding and scale remain modest relative to the largest EASM incumbents.
Editorial Note: Claims vs. Verified Findings
Founding, funding amounts, and the Crowdsource program are corroborated by TechCrunch, SecurityWeek, and Detectify's own materials; specific vulnerability counts or named discoveries attributed to Crowdsource were not independently verified in this research pass.
Sources
Alternatives to Detectify
Axonius
New York-based CAASM pioneer that aggregates data from hundreds of existing tools to build a unified, agentless asset…
watchTowr
Singapore-based platform combining external attack surface management with continuous automated red teaming to validate whether exposures are actually…
CyCognito
Agentless attack surface management platform that maps organizations' entire external footprint, including subsidiaries and shadow assets, using graph-based…
IONIX
EASM vendor, formerly Cyberpion, that maps not just an organization's own internet-facing assets but the chain of third-party…
Assetnote (Searchlight Cyber)
Offensive-security-researcher-built EASM platform from Brisbane, profitable and self-funded until its 2025 acquisition by dark-web intelligence firm Searchlight Cyber.
Palo Alto Networks Cortex Xpanse
DARPA-derived internet scanning platform, now Palo Alto Networks' EASM module, that continuously maps and attributes internet-facing assets.