OnSecurity
A CREST-accredited UK penetration-testing-as-a-service platform that bootstrapped to 400+ customers before taking its first outside funding round in 2024.
Visit Website ↗ + Add to CompareOverview
OnSecurity delivers penetration testing as a service (PTaaS): a CREST-accredited platform that lets customers scope, book, schedule, and receive reports for web application, network, cloud, mobile, and phishing-simulation testing through a self-serve interface rather than a slow, manually negotiated statement-of-work process. The pitch is speed and continuity — testing that fits an agile release cadence instead of the once-a-year pentest cycle common with traditional consultancies.
Founded in Bristol, England in 2018, OnSecurity grew for six years without external investment, reaching roughly 400 customers and around 50-60 employees before raising its first institutional round: a £5.5 million Series A in June 2024 led by Gresham House Ventures. That bootstrapped run to real scale, followed by growth capital rather than seed-stage funding, is a reasonably strong signal of organic commercial traction.
CREST accreditation is a genuine independent quality bar in the UK testing market, covering both the firm’s methodology and its individual testers’ certifications, which gives OnSecurity more third-party-verifiable credibility than unaccredited PTaaS platforms. It competes in an increasingly crowded PTaaS field, though, and specific claims about testing speed or outcome quality beyond the CREST baseline remain vendor-reported.
Innovation Matrix Assessment
Continued platform development over six bootstrapped years before its first funding round, reflecting steady but not explosively fast iteration.
CREST accreditation is an independently audited quality bar covering methodology and tester certification, giving genuine assurance of operational testing capability beyond self-reported claims.
Reaching roughly 400 customers and ~50-60 employees before taking its first institutional round (a growth-stage £5.5M Series A rather than seed capital) in 2024 is a credible organic-traction signal.
A self-serve scheduling and reporting layer wrapped around human-led testing meaningfully reduces the friction of traditional multi-week pentest procurement cycles.
CREST accreditation provides genuine third-party quality assurance on testing methodology and staff certification; effectiveness of individual engagements beyond that baseline is otherwise vendor-reported.
Continuous, on-demand penetration testing fits increasingly frequent software release cycles better than the once-a-year testing model many organizations still default to.
Why CISOs Should Care
Lets CISOs book and manage CREST-accredited penetration tests on a fast, continuous cadence instead of the slow, manually scoped procurement cycles typical of traditional pentest firms.
What Makes It Different
CREST accreditation combined with a self-serve scheduling and reporting platform differentiates it from both unaccredited PTaaS upstarts and traditional consultancies that lack a SaaS delivery layer.
The Matrix Verdict
53/100 — INCREMENTAL INNOVATOR
A credible, independently accredited PTaaS provider that bootstrapped to real scale before taking outside capital; a solid, evidence-backed player in an increasingly crowded PTaaS field.
Editorial Note: Claims vs. Verified Findings
CREST accreditation is independently verifiable through CREST's own marketplace listing, and the £5.5M Series A (2024) is independently reported by multiple outlets. Customer counts (400+) and revenue figures come from company and founder statements and were not independently audited.
Sources
Alternatives to OnSecurity
Unknown Cyber Inc.
Malware genomics platform using automated deep static analysis and code-lineage comparison to identify unseen malware, variants, and supply-chain…
Synack Inc
A penetration-testing-as-a-service platform pairing a vetted researcher community with AI-driven attack surface discovery for continuous security validation.
Horizon3.ai
Autonomous penetration testing company whose NodeZero platform self-attacks networks without persistent agents, aiming to replace annual manual pentests…
Airlock Digital
Application allowlisting (deny-by-default) platform that blocks unapproved executables, scripts, and processes to prevent ransomware and malware execution.
Cogent Security
Agentic AI platform that autonomously triages, investigates, and remediates vulnerabilities as a force multiplier for security teams.
ReversingLabs
Software supply chain security and binary analysis vendor that inspects compiled software and packages for malware and unauthorized…