Halo Security
Small, San Francisco-originated EASM platform combining external asset discovery with penetration-testing services, descended from the earlier ScanAlert/TrustedSite lineage.
Visit Website ↗Overview
Halo Security launched at Black Hat USA in August 2022, led by a team with backgrounds at Intel and McAfee, tracing its lineage back to ScanAlert, one of the earliest commercial website vulnerability scanners, which later operated as McAfee SECURE and then TrustedSite under different corporate ownership before the Halo Security brand was introduced. The company is small — public sources describe a team of roughly 30 people — and now operates fully remote.
The platform combines external asset discovery and continuous vulnerability scanning with penetration-testing services, aiming to give organizations both automated, ongoing visibility into internet-facing assets and human-verified testing on the same platform, rather than treating scanning and pentesting as separate engagements.
Innovation Matrix Assessment
A small team (roughly 30 people) with steady, incremental feature development since its 2022 relaunch.
Combining automated EASM scanning with human penetration-testing services on one platform addresses a real practitioner need to validate automated findings.
No independently confirmed funding round was found for Halo Security specifically; the company's small size and lack of publicized growth metrics suggest modest momentum relative to venture-backed peers.
Bundles EASM scanning with pentesting services, which is a useful combination but not a fundamentally new discovery methodology.
The founding team's long lineage in web vulnerability scanning (dating to ScanAlert) lends credibility, but independent third-party efficacy evidence for the current Halo Security product specifically was limited in available sources.
The pairing of continuous scanning with human-verified pentesting remains a relevant model for organizations wanting both breadth and validated depth.
Why CISOs Should Care
A CISO on a smaller security team gets both automated attack surface scanning and human penetration testing from one vendor, reducing the coordination overhead of separate scanning and pentest engagements.
What Makes It Different
Rather than positioning as a pure discovery platform, Halo Security pairs continuous automated scanning with human-delivered penetration testing on the same platform.
The Matrix Verdict
52/100 — INCREMENTAL INNOVATOR
A small, credible-lineage EASM-plus-pentesting vendor without the funding scale or independent momentum evidence of larger competitors — a niche option best suited to smaller teams wanting a combined automated-and-human offering.
Editorial Note: Claims vs. Verified Findings
Company history, founding team background, and August 2022 relaunch are corroborated by Dark Reading and Help Net Security coverage; a funding figure attributed to Bishop Fox appeared in search results but Bishop Fox is a separate, unrelated penetration-testing firm, so that figure has been excluded here as unreliable — Halo Security's own funding status is marked Undisclosed pending direct verification.
Sources
Alternatives to Halo Security
Axonius
New York-based CAASM pioneer that aggregates data from hundreds of existing tools to build a unified, agentless asset…
watchTowr
Singapore-based platform combining external attack surface management with continuous automated red teaming to validate whether exposures are actually…
CyCognito
Agentless attack surface management platform that maps organizations' entire external footprint, including subsidiaries and shadow assets, using graph-based…
IONIX
EASM vendor, formerly Cyberpion, that maps not just an organization's own internet-facing assets but the chain of third-party…
Assetnote (Searchlight Cyber)
Offensive-security-researcher-built EASM platform from Brisbane, profitable and self-funded until its 2025 acquisition by dark-web intelligence firm Searchlight Cyber.
Detectify
Stockholm-based EASM and DAST platform that feeds its scanner with vulnerability research crowdsourced from a network of ethical…