ETHIACK
A Portuguese vendor running continuous, AI-driven autonomous pentesting alongside human ethical hackers to validate exploitable vulnerabilities across an organization's external attack surface.
Visit Website ↗ + Add to CompareOverview
ETHIACK runs continuous, AI-driven pentesting through what it calls an agentic AI pentesting engine (branded Hackian), combined with a network of human ethical hackers, to map an organization’s attack surface, chain exploitation paths, and deliver proof-of-exploit on confirmed findings rather than a static list of theoretical vulnerabilities. The platform is positioned around Continuous Threat Exposure Management (CTEM), running tests continuously and integrating into CI/CD pipelines instead of relying on point-in-time annual pentests.
Founded in 2022 in Coimbra, Portugal by ethical hackers Andre Baptista, Jorge Monteiro, and Vitor Pinho, ETHIACK won WebSummit’s Most Promising Startup award in 2023 and Portugal’s National Innovation Award before closing a 4 million euro funding round in late 2024 led by Explorer Investments, Portugal’s largest private equity fund. The company cites case studies with named customers including airport operator ANA Aeroportos, pharmaceutical company Bluepharma, and Universidade do Porto.
ETHIACK competes with both traditional pentesting-as-a-service vendors (Cobalt, Synack) and external attack surface management platforms. Its differentiation is combining autonomous AI exploitation with human validation to reduce false positives while running continuously rather than periodically. Reported outcomes — including a claimed 650% ROI for one customer and 2 million euros in prevented risk for another — are vendor-published case studies tied to named organizations rather than independently audited figures, and no third-party benchmark of Hackian’s detection accuracy against competing engines was found.
Innovation Matrix Assessment
ETHIACK has expanded from core autonomous pentesting into attack surface management, exposure validation, and compliance reporting within about three years, alongside a growing set of named customer deployments, indicating an active build-and-ship pace.
Founded in 2022 with roughly 11-50 employees and 4 million euros raised, ETHIACK has moved from startup to a company with named enterprise and public-sector customers (ANA Aeroportos, Universidade do Porto) in a few years, though it remains small relative to established pentesting-as-a-service vendors.
Award recognition (WebSummit Most Promising Startup 2023, Portugal's National Innovation Award) followed by a 4 million euro round led by Portugal's largest PE fund in late 2024 signals sustained external validation and growing institutional confidence.
Combining an autonomous AI exploitation engine with human ethical-hacker validation to run continuous, CI/CD-integrated testing is a genuine shift from traditional point-in-time pentesting, though the category (PTaaS/continuous attack surface validation) already has established competitors.
ETHIACK publishes named-customer case studies with specific figures (650% ROI for one customer, 2M euros in prevented risk for another), which is more concrete than generic marketing claims, but these remain vendor-published rather than independently audited, and no third-party benchmark of detection accuracy was found.
Continuous attack surface validation addresses a widely recognized gap left by infrequent, point-in-time pentests, making the category highly relevant as organizations' external-facing footprints change faster than annual testing cycles can cover.
Why CISOs Should Care
For a CISO who only gets a pentest once or twice a year, ETHIACK offers continuous, always-on validation of exploitable exposures with proof-of-exploit evidence, closing the gap between periodic testing and a constantly changing attack surface.
What Makes It Different
ETHIACK pairs an autonomous AI exploitation engine with human ethical hackers rather than relying on either pure automation or pure manual testing alone, aiming for continuous coverage with lower false-positive rates than automated-only scanners.
The Matrix Verdict
63/100 — INCREMENTAL INNOVATOR
A fast-growing, well-recognized European PTaaS/CTEM vendor with real named customers and credible institutional backing; a reasonable evaluation candidate for continuous exposure validation, though its efficacy claims rest on vendor-published case studies rather than independent benchmarks.
Editorial Note: Claims vs. Verified Findings
Vendor-sourced and unverified: specific ROI and prevented-risk figures (650% ROI, 2M euros prevented risk) come from ETHIACK's own published case studies naming real customers, but were not corroborated by an independent audit or the named customers directly. Independently verified: founding year, founder names, funding amount, and award recognition (WebSummit, Portugal's National Innovation Award) are corroborated across Gartner Peer Insights, Crunchbase/Tracxn, and EU-Startups coverage.
Sources
Alternatives to ETHIACK
watchTowr
Singapore-based platform combining external attack surface management with continuous automated red teaming to validate whether exposures are actually…
CyCognito
Agentless attack surface management platform that maps organizations' entire external footprint, including subsidiaries and shadow assets, using graph-based…
Armis (a ServiceNow company)
Agentless asset intelligence platform discovering and assessing every connected IT, OT, IoT and medical device, now part of…
CybelAngel
External attack surface management and digital risk protection platform that scans the open, deep, and dark web for…
Axonius
New York-based CAASM pioneer that aggregates data from hundreds of existing tools to build a unified, agentless asset…
Doppel
San Francisco AI-native digital risk protection platform that detects and automatically takes down phishing sites, impersonation accounts, and…