SEWORKS
A San Francisco-based application security firm founded by former competitive white-hat hackers, offering AI-driven penetration testing (Pentoma), mobile app hardening (AppSolid), and breach-password screening (LeakJar).
Visit Website ↗ + Add to CompareOverview
SEWORKS is a San Francisco-based application security company founded in 2013 by members of WOWHACKER, a Korean white-hat hacking collective with multiple DEF CON CTF finals appearances. Its flagship product, Pentoma, is an AI-driven penetration-testing platform built on a proprietary engine (branded GAMAN) that scans web applications, APIs, source code, and now AI/LLM systems, returning what the company calls human-validated findings with reproducible proof-of-concept evidence rather than a raw automated-scanner report.
The company also sells AppSolid, a mobile app-hardening and anti-tampering product for Android and iOS, and LeakJar, a breach-password screening service that uses k-anonymity techniques to check credentials against known-compromised password sets at signup, login, and password-reset points. Separately, SEWORKS resells SOC 2 and ISO 27001 audit support as a Drata-authorized partner.
SEWORKS raised roughly $10.2M across three rounds between 2013 and 2016, with investors including Qualcomm Ventures, Samsung Ventures, and WONIK Investment Partners, and has not disclosed further funding since. Publicly named customers include Sendbird, Mercari, and Kolon.
The company’s repositioning of Pentoma around AI-driven testing, including scanning of AI/LLM systems themselves, is a credible response to current demand, but it now competes with several newer, better-capitalized entrants in the pentesting-as-a-service space.
Innovation Matrix Assessment
Has kept shipping distinct products (Pentoma, AppSolid, LeakJar) over more than a decade and recently repositioned Pentoma explicitly around AI-driven pentesting and AI-system scanning, showing continued technical investment despite no funding news since 2016.
Pentoma is delivered as a scanning platform with 'human-validated' findings, indicating a hybrid automated-plus-managed delivery model; no independent deployment benchmark was found to verify ease of integration.
The last disclosed funding round was in 2016; no subsequent funding, acquisition, or public headcount-growth signal was found, suggesting slow or flat growth for a company now over a decade old.
AI-driven pentesting with 'human-validated' results targets the false-positive problem inherent to pure automated scanners, but the pentesting-as-a-service and AI-pentest space now has several well-funded competitors pursuing similar approaches.
Named customers (Sendbird, Mercari, Kolon) and a founding team with a documented competitive hacking pedigree (WOWHACKER, DEF CON CTF finals) support credibility, though no independent third-party test result for Pentoma specifically was found.
AI-assisted penetration testing and AI/LLM system security scanning sit squarely in current enterprise demand as organizations rush to secure AI-based applications.
Why CISOs Should Care
For CISOs wary of noisy automated scanners, Pentoma's human-validated, reproducible-findings model, now extended to scanning AI/LLM systems, addresses a real gap, though buyers should weigh that against a company with no disclosed funding in roughly a decade.
What Makes It Different
A founding team from a competitive white-hat hacking collective (WOWHACKER) applying a human-validated AI-pentest model rather than a pure automated vulnerability scanner.
The Matrix Verdict
57/100 — INCREMENTAL INNOVATOR
A credible, long-running application security shop with real named customers and a distinctive AI-pentest angle, but its lack of disclosed funding or major public milestones since 2016 raises questions about growth relative to newer, better-capitalized PTaaS entrants.
Editorial Note: Claims vs. Verified Findings
Customer names (Sendbird, Mercari, Kolon), funding history, and founder background (WOWHACKER, DEF CON CTF) are independently corroborable via Crunchbase and press coverage; specific performance claims about the GAMAN engine and 'human-validated' accuracy are vendor-stated and were not independently benchmarked in this review.
Sources
Alternatives to SEWORKS
Adaptive Security
AI-driven platform that simulates deepfake, voice, and multichannel social-engineering attacks to train and test organizations against next-generation phishing.
Quilr
Early-stage agentic AI security startup building a 'Service-as-Software' platform to guard against human-related breaches and secure AI agent…
Zenity
Governance and security platform for AI agents and low-code/no-code development, securing agent identity, permissions and behavior across the…
Tenzai
An agentic AI penetration testing startup building autonomous 'AI hackers' to find and validate exploitable vulnerabilities at a…
Alice (formerly ActiveFence)
Israeli AI security company (rebranded from ActiveFence in January 2026) offering a lifecycle platform to test, guard, and…
Reco
Reco secures the "agentic ecosystem" — mapping what AI agents can access across SaaS and enterprise apps, detecting…