Skip to content

Virgil Security

Small, long-running developer-focused encryption and PKI SDK vendor; no new funding since a 2019 bridge round but still shipping incremental SDK updates.

Visit Website ↗ + Add to Compare
35/100Emerging / Unranked

Overview

Virgil Security sells developer SDKs and a hosted public key infrastructure that let engineering teams add end-to-end encryption and passwordless, key-based authentication to an application without building cryptographic infrastructure from scratch. Its flagship SDK, E3Kit, and a broader Secure Communications Platform wrap key generation, storage, and identity verification behind a small API surface, targeting developers who would otherwise need deep cryptography expertise to implement the same protections correctly.

Founded in 2014 and based in Manassas, Virginia, Virgil Security raised a total of roughly $5.66 million across angel, seed, Series A, and bridge rounds, with the most recent disclosed round, a $1 million bridge, closing in 2019. The company remains small, with around 13 employees.

Virgil continues limited but steady development, including SDK updates through 2024 and a WordPress plugin release in 2025 for encrypting stored user passwords, and has explored post-quantum algorithms (Falcon, Round5) for future-proofing its cryptographic stack. Its trajectory since 2019 has been one of maintenance and incremental extension of an existing product line rather than renewed fundraising or major new customer announcements.

Innovation Matrix Assessment

Innovation Velocity 4/10

Virgil shipped SDK updates through 2024 and a new WordPress password-encryption plugin in 2025, showing it is still actively maintained, but there have been no major product launches in several years.

Operational Value 5/10

The SDKs cover a reasonable range of platforms (iOS, Android, PHP, web) with a functioning hosted PKI backend, a real but modest technical scope compared to larger encryption and identity platforms.

Market Momentum 2/10

No funding round has been disclosed since a $1 million bridge round in 2019, the team remains at roughly 13 employees, and no major partnership or customer announcements were found in recent years.

Category Disruption 3/10

Packaging PKI and end-to-end encryption as easy developer SDKs was a distinctive pitch around Virgil's 2014-2016 founding period, but the market has since filled in with alternative encryption SDKs and cloud KMS offerings, eroding its original differentiation.

Real-World Efficacy 3/10

No independent third-party security audit of Virgil's cryptographic libraries was found in public sources; the SDKs are functional and open-source on GitHub, but their real-world security assurance rests on code availability rather than a documented independent review.

Enduring Relevance 4/10

Developer-friendly end-to-end encryption remains a relevant need for privacy-conscious applications, but Virgil's minimal recent commercial traction limits how relevant it is as a going-concern vendor choice today.

Why CISOs Should Care

For engineering teams that want to add end-to-end encryption or passwordless authentication without building PKI from scratch, Virgil offers ready-made SDKs, though its small team and lack of funding since 2019 are worth weighing against more actively growing alternatives.

What Makes It Different

Packages PKI, identity verification, and encryption as developer SDKs across multiple languages and platforms, rather than requiring teams to assemble cryptographic primitives themselves.

The Matrix Verdict

35/100 — EMERGING / UNRANKED

A small, long-running developer-crypto shop with real but modest technology and no fresh funding since 2019; usable for teams already on its SDKs, but not showing signs of renewed growth or independent security validation.

Editorial Note: Claims vs. Verified Findings

Employee count (13) and total funding (~$5.66M, last round a 2019 bridge) are Crunchbase estimates, not company-disclosed figures. No independent security audit of Virgil's cryptographic libraries was found, so efficacy here is assessed on functional scope and code availability rather than verified security assurance.

Sources