Invicti Security
A DAST-first web and API application security platform, formed from the 2018 merger of Netsparker and Acunetix, now majority-owned by Summit Partners.
Visit Website ↗Overview
Invicti Security was formed in 2018 by combining Netsparker (founded 2009) and Acunetix (founded 2005) under common ownership, headquartered in Austin, Texas. The platform is built around DAST, scanning running web applications and APIs the way an attacker would, layering on SAST, SCA, and ASPM. Its signature technical claim is ‘Proof-Based Scanning,’ which automatically re-confirms exploitability to cut false positives.
Summit Partners acquired a majority stake for a reported $625 million in 2021. The company is private-equity backed, reflecting a roll-up-and-scale strategy typical of a maturing AppSec category.
Invicti says more than 3,600 organizations use its products, with a customer list including AWS, Cisco, Deloitte, EY, KPMG, NASA, and Verizon. Gartner placed Invicti as a Challenger in its 2022 Magic Quadrant.
Innovation Matrix Assessment
Recent development has largely been integration of ASPM and consolidation of the merged Netsparker/Acunetix engines rather than new detection paradigms.
Proof-Based Scanning targets false-positive reduction, a real DAST pain point, though the accuracy figure is vendor-stated and unaudited.
3,600+ claimed customers and a $625M PE deal show scale, but no funding events reported since 2021 and Gartner rates it a Challenger, not a Leader.
DAST is one of the most conventional AppSec categories, and proof-based verification is an incremental refinement, not a new model.
Large, named enterprise customer list and active Gartner Peer Insights presence, though not top-tier analyst placement.
Web/API DAST remains a baseline compliance need, but is a more mature, less forward-looking category than runtime or supply-chain approaches.
Why CISOs Should Care
Consolidates DAST, SAST, SCA, and API testing into one platform with automated exploit confirmation, cutting the manual triage load DAST tools are notorious for.
What Makes It Different
Invicti's differentiation is largely operational — proof-based verification layered onto a merged, mature DAST engine — not a structurally new detection model.
The Matrix Verdict
55/100 — INCREMENTAL INNOVATOR
Incremental Innovator (~55/100), low end: a solid, scaled DAST platform with real enterprise adoption, but a conventional technical approach and Challenger (not Leader) Gartner position.
Editorial Note: Claims vs. Verified Findings
The proof-based-scanning accuracy figure and customer logo list are vendor-published and not independently verified; the Summit Partners deal and 2022 Gartner Challenger placement are corroborated independently.
Sources
Alternatives to Invicti Security
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Snyk
Developer-first application security platform combining SAST, SCA, container, IaC, and API/DAST scanning inside the developer workflow.
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Sonar
Code quality and security platform built around SonarQube's static analysis engine, widely adopted via a free Community Edition…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…