Skip to content

Halo Security

Small, San Francisco-originated EASM platform combining external asset discovery with penetration-testing services, descended from the earlier ScanAlert/TrustedSite lineage.

Visit Website ↗
52/100Incremental Innovator

Overview

Halo Security launched at Black Hat USA in August 2022, led by a team with backgrounds at Intel and McAfee, tracing its lineage back to ScanAlert, one of the earliest commercial website vulnerability scanners, which later operated as McAfee SECURE and then TrustedSite under different corporate ownership before the Halo Security brand was introduced. The company is small — public sources describe a team of roughly 30 people — and now operates fully remote.

The platform combines external asset discovery and continuous vulnerability scanning with penetration-testing services, aiming to give organizations both automated, ongoing visibility into internet-facing assets and human-verified testing on the same platform, rather than treating scanning and pentesting as separate engagements.

Innovation Matrix Assessment

Innovation Velocity 5/10

A small team (roughly 30 people) with steady, incremental feature development since its 2022 relaunch.

Operational Value 6/10

Combining automated EASM scanning with human penetration-testing services on one platform addresses a real practitioner need to validate automated findings.

Market Momentum 4/10

No independently confirmed funding round was found for Halo Security specifically; the company's small size and lack of publicized growth metrics suggest modest momentum relative to venture-backed peers.

Category Disruption 5/10

Bundles EASM scanning with pentesting services, which is a useful combination but not a fundamentally new discovery methodology.

Real-World Efficacy 5/10

The founding team's long lineage in web vulnerability scanning (dating to ScanAlert) lends credibility, but independent third-party efficacy evidence for the current Halo Security product specifically was limited in available sources.

Enduring Relevance 6/10

The pairing of continuous scanning with human-verified pentesting remains a relevant model for organizations wanting both breadth and validated depth.

Why CISOs Should Care

A CISO on a smaller security team gets both automated attack surface scanning and human penetration testing from one vendor, reducing the coordination overhead of separate scanning and pentest engagements.

What Makes It Different

Rather than positioning as a pure discovery platform, Halo Security pairs continuous automated scanning with human-delivered penetration testing on the same platform.

The Matrix Verdict

52/100 — INCREMENTAL INNOVATOR

A small, credible-lineage EASM-plus-pentesting vendor without the funding scale or independent momentum evidence of larger competitors — a niche option best suited to smaller teams wanting a combined automated-and-human offering.

Editorial Note: Claims vs. Verified Findings

Company history, founding team background, and August 2022 relaunch are corroborated by Dark Reading and Help Net Security coverage; a funding figure attributed to Bishop Fox appeared in search results but Bishop Fox is a separate, unrelated penetration-testing firm, so that figure has been excluded here as unreliable — Halo Security's own funding status is marked Undisclosed pending direct verification.

Sources