PlexTrac
A Boise, Idaho-based continuous threat exposure management platform that aggregates pentest, red-team, and vulnerability-scan findings into a single remediation-tracking workflow.
Visit Website ↗ + Add to CompareOverview
PlexTrac started as a penetration-test reporting tool and has grown into a broader continuous threat exposure management (CTEM) platform: it aggregates findings from pentests, red-team engagements, and vulnerability scanners into one system, tracks remediation across teams, and gives security leaders a single view of exposure over time instead of a pile of disconnected PDF reports. The reporting-automation piece remains its core wedge — consultancies and internal red teams use it to cut the hours spent manually writing up findings — while the exposure-management layer on top targets the CISO who needs to prioritize what actually gets fixed first.
Launched in 2016 and headquartered in Boise, Idaho, PlexTrac raised a $70 million Series B in February 2022 led by Insight Partners, following a $10 million Series A earlier that year, for total disclosed funding of roughly $82 million. The 2022 round came on the heels of the company quadrupling headcount and tripling recurring revenue in 2021, concrete growth signals from a credible institutional lead investor.
PlexTrac competes in an increasingly crowded exposure-management category against both dedicated CTEM vendors and the reporting/workflow features larger vulnerability-management platforms are adding natively, meaning its differentiation increasingly rests on breadth of integrations (vulnerability scanners, ticketing systems, and pentest tooling) rather than the reporting automation that originally set it apart.
Innovation Matrix Assessment
PlexTrac has expanded from a pentest-reporting tool into a broader continuous threat exposure management platform, adding integrations across vulnerability scanners and ticketing systems, a meaningful product expansion since its 2016 launch.
The company reported quadrupling headcount and tripling recurring revenue in 2021 ahead of its Series B, and is used by both internal red teams and third-party pentest consultancies, indicating real multi-tenant operational scale.
An $82.1M total raise, including a $70M Series B led by Insight Partners in 2022, is a concrete, independently reported institutional-investor signal, though no funding round has been publicly disclosed since.
PlexTrac's original reporting-automation wedge was a genuine improvement over manual pentest report writing, but the exposure-management layer it has built on top now competes in a category with several well-funded competitors and features native vulnerability-management platforms are adding themselves.
Adoption by pentest consultancies and enterprise red teams and a credible institutional Series B lead (Insight Partners) support real-world use, but no independent third-party benchmark or named breach/incident case study specific to PlexTrac's exposure-management claims was found.
Consolidating pentest, red-team, and vulnerability-scan findings into a single prioritized remediation workflow addresses a persistent, well-documented pain point (fragmented reporting, slow remediation tracking) for security teams.
Why CISOs Should Care
PlexTrac gives a CISO one place to see pentest, red-team, and scanner findings together with remediation status, replacing a stack of disconnected PDF reports with a workflow that shows what is actually getting fixed.
What Makes It Different
PlexTrac's differentiation started with best-in-class pentest report automation for consultancies and has extended into broader exposure-management integrations, a path some competitors are approaching from the opposite direction (scanner-first, reporting-second).
The Matrix Verdict
55/100 — INCREMENTAL INNOVATOR
A well-funded, credibly backed player that has successfully expanded from a reporting-automation niche into broader exposure management; solid and evidence-backed, though it now competes in a crowded category on integration breadth rather than a unique technical edge.
Editorial Note: Claims vs. Verified Findings
The 2021 headcount-quadrupling and revenue-tripling figures come from PlexTrac's own funding announcement and are not independently audited, though the underlying Series A and Series B amounts and lead investors are independently reported by multiple outlets (PR Newswire, BoiseDev). No independent third-party evaluation of PlexTrac's exposure-prioritization accuracy was found.
Sources
Alternatives to PlexTrac
Unknown Cyber Inc.
Malware genomics platform using automated deep static analysis and code-lineage comparison to identify unseen malware, variants, and supply-chain…
Synack Inc
A penetration-testing-as-a-service platform pairing a vetted researcher community with AI-driven attack surface discovery for continuous security validation.
Horizon3.ai
Autonomous penetration testing company whose NodeZero platform self-attacks networks without persistent agents, aiming to replace annual manual pentests…
Airlock Digital
Application allowlisting (deny-by-default) platform that blocks unapproved executables, scripts, and processes to prevent ransomware and malware execution.
Cogent Security
Agentic AI platform that autonomously triages, investigates, and remediates vulnerabilities as a force multiplier for security teams.
ReversingLabs
Software supply chain security and binary analysis vendor that inspects compiled software and packages for malware and unauthorized…