Assetnote (Searchlight Cyber)
Offensive-security-researcher-built EASM platform from Brisbane, profitable and self-funded until its 2025 acquisition by dark-web intelligence firm Searchlight Cyber.
Visit Website ↗Overview
Assetnote was founded in 2018 in Brisbane, Australia, by offensive security researchers Michael Gianarakis and Shubham Shah, and built its reputation with high-profile technology customers including Atlassian, Canva, and Qantas — organizations with sophisticated internal security engineering that are unusually discerning about tooling. The company was reportedly profitable from early on and was acquired by UK-based Searchlight Cyber in January 2025 for more than $100 million.
Its core differentiator was cadence and depth: because it was built by practicing offensive security researchers, Assetnote emphasized frequent, deep re-scanning of an organization’s attack surface to catch newly deployed or changed assets quickly, rather than periodic point-in-time snapshots. Post-acquisition, it is being integrated with Searchlight’s dark-web monitoring capabilities into a combined Continuous Threat Exposure Management (CTEM) platform.
Innovation Matrix Assessment
Built and maintained by an active offensive-security research team with a track record of frequent re-scanning cadence rather than periodic snapshots.
Adoption by security-sophisticated customers like Atlassian and Canva — organizations with strong internal security engineering — is a meaningful signal of practical operational quality.
A greater-than-$100 million acquisition by Searchlight Cyber in January 2025, from a company that was reportedly profitable and largely self-funded, is a strong market validation signal.
An offensive-security-researcher-built engine with unusually high scan frequency represents a meaningfully different operating cadence than typical periodic EASM scanning.
Reported profitability without heavy external funding, combined with adoption by technically sophisticated customers, suggests genuine product-market fit rather than funding-driven growth.
Now being integrated into a broader CTEM platform with dark-web monitoring, extending its relevance beyond pure asset discovery.
Why CISOs Should Care
A CISO gets attack surface data from a tool built and maintained by practicing offensive security researchers, with an unusually high re-scanning cadence that catches newly exposed assets quickly.
What Makes It Different
The platform was built and is maintained by an active offensive security research team rather than a purely product-engineering organization, and emphasizes scan frequency and depth over broad but shallow coverage.
The Matrix Verdict
73/100 — MEANINGFUL INNOVATOR
A technically credible, researcher-built EASM platform validated by both sophisticated customer adoption and a substantial acquisition exit — one of the stronger smaller entrants in this list, now entering a new phase as part of a combined CTEM offering.
Editorial Note: Claims vs. Verified Findings
Founding, customer names, and the Searchlight Cyber acquisition price are corroborated by Business News Australia, GovInfoSecurity, and Searchlight Cyber's own press release; the company's profitability claim is reported in press coverage but not independently audited.
Sources
- Searchlight Cyber press release — https://slcyber.io/press/searchlight-cyber-acquires-assetnote/
- Business News Australia — https://www.businessnewsaustralia.com/articles/brisbane-based-cyber-security-firm-assetnote-acquired-by-searchlight-cyber-for--100m.html
- GovInfoSecurity — https://www.govinfosecurity.com/searchlight-cyber-bolsters-threat-intel-assetnote-buy-a-27399
Alternatives to Assetnote (Searchlight Cyber)
Axonius
New York-based CAASM pioneer that aggregates data from hundreds of existing tools to build a unified, agentless asset…
watchTowr
Singapore-based platform combining external attack surface management with continuous automated red teaming to validate whether exposures are actually…
CyCognito
Agentless attack surface management platform that maps organizations' entire external footprint, including subsidiaries and shadow assets, using graph-based…
IONIX
EASM vendor, formerly Cyberpion, that maps not just an organization's own internet-facing assets but the chain of third-party…
Detectify
Stockholm-based EASM and DAST platform that feeds its scanner with vulnerability research crowdsourced from a network of ethical…
Palo Alto Networks Cortex Xpanse
DARPA-derived internet scanning platform, now Palo Alto Networks' EASM module, that continuously maps and attributes internet-facing assets.