Investors
Wiz bought Dazz. Armis bought Silk. Zafran raised a Series C from Menlo. Three proof points for the same thesis in eighteen months, and every one of them is cloud native, enterprise priced, and sold direct to a Fortune 500 security team. None of them run inside a plant with no internet. None of them are packaged so a single managed provider can serve every client in its book from one console. CVEasy is the local first version of the capability the market just paid three times for, and it reaches its buyer through the channel that already owns the relationship.
Your materials
Everything below is already unlocked for you. Nothing else to request.
The thesis
Three things have to be true for this to be a large company rather than a good product. All three are true today, and only the third one needs capital.
We are not asking anyone to believe a new category exists, or to take a bet on whether security teams will eventually want their findings turned into verified fixes. Two acquisitions and a Series C in eighteen months already settled that question, with other people's money and other people's diligence.
What those transactions did not settle is who serves the companies underneath the Fortune 500. The acquirers all moved upmarket, because that is where their pricing already worked. The answer for everyone else is currently nobody.
Risk retired: does anyone want this
A 900 person manufacturer has the same CVE backlog as a bank and none of the staff. Enterprise exposure platforms price per asset and assume a cloud estate, so the quote arrives at a number the buyer will not pay for a tool that still hands them a list.
They also cannot send vulnerability data off site, because the plant floor, the hospital, and the defense supplier all say no. Local first is not a preference for this buyer. It is the entry requirement.
Risk retired: can we build for them
Selling mid market direct is a customer acquisition cost problem nobody has solved elegantly. Selling through the managed providers who already run security for those companies is a different business: the relationship, the trust, and the renewal already exist, and we arrive as margin rather than as another line item.
Tenant workspaces, per client isolation, and white labelable reporting are already shipped, so a single operator runs a whole portfolio from one console. Each signed provider is distribution that compounds, not a logo that churns.
Risk remaining: this is what the raise funds
Read the three together and the shape of the company is clear. The technology risk is behind us, the market risk was retired by other people's acquisitions, and what is left is a distribution problem with a known channel and a product already packaged for it. That is the specific thing seed capital is good at buying.
The evidence
Exposure management stopped being a feature request and became an acquisition target. Cyber venture funding rose 47 percent in 2025 to roughly 14 billion dollars across 392 rounds. The specific wedge inside it, turning findings into fixes, is where the money moved.
Reported near 450 million dollars. The largest cloud security platform decided remediation was worth buying rather than building.
Reported 150 million dollars on roughly 12.5 million raised. Exposure prioritization as the missing layer of an asset platform.
60 million dollar round in December 2025, roughly 130 million total, tripled ARR, around 120 employees. The standalone path is funded and working.
Every one of those companies is cloud native and enterprise priced. None of them run inside a building with no internet. None of them are sold in a shape an MSSP can resell across 40 clients. That is the opening.
What we built
Most companies in this category picked one side. The scanners tell you what is wrong and stop. The prioritization startups sit on top of somebody else's scan data and have no product without it. CVEasy does both, which means a customer can rip out their scanner or keep it, and either way we are the exposure management layer.
Credentialed collection over LDAP, WMI, SSH, and SNMP pulls installed software, patch levels, and configuration off every asset, then matches it against a 330,000 CVE corpus enriched with KEV, EPSS, and OSV. On top of that: network and port discovery, web application testing, Active Directory attack paths, 204 CIS checks across AWS, Azure, and GCP, software composition analysis, container image scanning, and secrets detection. 147 modules across 32 categories.
The average enterprise runs three to six scanners concurrently and gets six different answers about the same host. Our correlation engine resolves asset identity across hostname, IP, MAC, and serial, then collapses duplicate findings from Tenable, Qualys, Rapid7, and Wiz into one canonical record with every source attached. It is fed by 121 integrations across 16 categories: 27 live API pulls, 57 file formats, 14 push endpoints, 6 feeds, and 15 outbound paths that push the fix back into ServiceNow, Jira, and the patch tooling. All of them work today. The customer keeps the tools they already paid for and finally gets one number.
Findings flow in from the tools they already run
A sample of 121 integrations across 16 categories. Logos are the property of their respective owners and denote an integration, not a partnership or endorsement.
Gartner defined the five stages of exposure management in 2022. Most vendors sell one or two and partner for the rest. We run all five in a single application, on the customer's hardware, with no cloud in between.
Twelve layer threat and risk scoring that reranks findings against the customer's actual environment, exploit reality, and threat actor activity. CVSS says 63 percent of CVEs are high or critical. TRIS tells a team which of them can actually be reached in their building.
158,271 attack simulation payloads across 120 categories and 242 intruder sets, plus around 150 attack modules and 17 threat actor emulation profiles. They prove whether a finding is exploitable in the environment and whether the fix actually held. Validation is a native stage, not a separate vendor and a separate invoice.
A quantized model on the endpoint writes the OS specific fix, groups vulnerabilities into single work orders, and never sends customer vulnerability data anywhere. That last part is why regulated, defense, and air gapped buyers can say yes.
The obvious objection
This is the first hard question in every meeting, so here is the answer up front. It is not that we are faster. It is that following us costs them the three things a public company will not give up to chase a smaller customer.
Their product is a cloud console. Ours installs on the customer's hardware and never phones home. Shipping a real air gapped build means a second product line with its own release train, its own support model, and no telemetry to run it on. That is a rebuild, not a feature flag.
Their analytics, their benchmarking, and increasingly their AI features all assume customer data pooled in their tenant. Our entire promise is that it never leaves the building. They cannot offer both without undermining the one they already sold to the enterprise.
Per asset pricing is how they hit their number, and it is exactly what prices them out of the mid market. Moving to flat annual pricing for smaller accounts cannibalizes the enterprise book and invites every existing customer to renegotiate. Public companies do not do that voluntarily.
The market has already run this experiment. When the largest cloud security company on earth wanted remediation, it did not build it, it bought Dazz. When Armis wanted exposure prioritization, it bought Silk. The incumbents in this category demonstrably prefer to acquire this capability rather than build it, which is the same reason we can win the segment they will not reach and the reason the eventual exit path is well established.
Original invention
We do not present these as the moat, because no seed company is defended by a provisional filing. We present them as evidence that the methods above are genuinely novel rather than assembled from open source, and as the asset that sets the price if this company is acquired the way Dazz and Silk were. Filed 2026 07 24 with the USPTO. These are application numbers, not intentions.
Where we actually are
You are going to ask these questions in the first meeting. Here are the answers before you ask.
Who we work with today
Named references available under NDA
Live purple team and vulnerability management engagements, running now. These are the accounts our paid pilots convert from, and we will introduce you to them once there is mutual interest and the client consents.
Signed desktop application, 204 cloud compliance checks, MSSP tenant workspaces, and all 121 integrations live: 27 live API pulls, 57 file import formats, 14 push endpoints, 6 data feeds, and 15 outbound dispatch paths for ticketing, patching, and webhooks. Every one of them resolves to real code, enforced by a test suite that fails the build otherwise. This is not a prototype seeking build capital.
Those engagements pay us today and they are the reason the product is shaped the way it is. Every feature above came out of a real environment, not a roadmap workshop. They are also the warmest pipeline we have: the buyer already trusts us and has seen the output on their own data.
Licensing is built and verified end to end but was intentionally held dormant while the platform finished. Stripe, key issuance, and delivery all tested. We are switching monetization on and converting service clients into paid pilots. The first revenue dollar is a switch flip rather than a build, but it has not been switched yet and we will not present ARR history we do not have.
Everything above was built with no outside capital, which is the capital efficiency argument and the key person risk in the same sentence. We are not going to dress that up: the raise is what takes the founding team full time and funds the first commercial hires. Timing, the services business transition, and what full time looks like for each of us is a conversation we will have with you directly and in writing.
We do not have an ARR chart yet, so we are not going to wave a static number at you instead. These are the four measures we instrument from day one, and they are the ones we expect to be held to.
Team
This product exists because one of us does vulnerability management at Fortune 100 scale every week and got tired of the tooling.
Runs the company, the commercial motion, and the partner and MSSP relationships. Owns pricing, packaging, and the path from services engagement to platform contract.
Architect of CVEasy, TRIS, and BASzy. MS in Cybersecurity and Information Assurance, 20 plus security certifications, named inventor on all twelve provisional filings. Works threat and vulnerability management at a Fortune 100 retailer, which is where the product requirements come from.
Investor FAQ
We are in conversations with angels, syndicates, and seed funds who invest in security infrastructure. Round structure, size, and terms are discussed directly and are not published here. Submit the form and we will tell you exactly where we are.
Two answers, because we compete with them on two fronts. On scanning, we collect the same credentialed inventory they do, over the same protocols, without an agent, and match it against a 330,000 CVE corpus. We are not claiming a decade of vendor advisory content depth, and we do not need to, because a scanner that finds 100 percent of your problems and ranks them by CVSS still leaves the team guessing. On everything after the scan, they are not really in the fight: they do not simulate the attack to prove exploitability, they do not write the fix, and they do not verify the fix held. And a customer running Tenable and Qualys and Rapid7 at the same time, which is most enterprises, gets three answers from them and one from us.
It is the right question, and it is the one that kills most security startups. Two things make it survivable here. First, bundling works when the feature is a checkbox on a renewal, and validation is not: proving exploitability requires an attack corpus, a simulation engine, and a safety model that took us years and 158,271 payloads to build, so a bundled version is a worse version and the buyer can tell in a single scan. Second, and more important, they can only bundle it to customers they already have. The mid market and MSSP segment we sell into is not on their renewal list, because their pricing never got them in the door. You cannot give something away for free to someone who was never your customer.
The channel is the answer. Direct mid market sales cap out at whatever the founding team can personally close, which is a nice services company and not a venture return. Each managed provider we sign carries its whole client book, expands on its own as that book grows, and renews on the provider's contract cycle rather than ours. The comparable exits are already on the board: Silk sold for a reported 150 million dollars having raised roughly 12.5 million, and Dazz sold for a reported figure near 450 million dollars. We are building the same capability for the segment those companies never addressed, with the IP position to price an acquisition and the option to stay standalone the way Zafran has.
Not yet, and we are not going to pretend otherwise. Everything on this page was built alongside other work, with no outside capital, which we think says something useful about the team. The raise is what takes the founding team full time and funds the first commercial hires. We will give you the specific timing and the plan for the services business directly, in writing, before you commit anything.
Go to market. The product is built. Capital buys sales motion into the MSSP channel, design partner conversion, and the compliance work, SOC 2 and FedRAMP path, that unlocks the regulated buyers our architecture is already suited for.
We run live engagements across manufacturing, construction, architecture, healthcare and pharmacy, and managed service providers. We do not publish their names, because we have not asked them for that and we are not going to spend a client relationship on a marketing page. Under NDA and with the client's consent we will make direct introductions, and reference calls are part of how we expect you to diligence us. Logo and reference rights are something we are negotiating into the paid pilot conversions now.
If you are reading this page you already have access to all of it: the investor deck, the one page overview, and the data room covering patent filings, integration matrix, architecture, security posture, and the TRIS methodology paper. A live 3 minute product demo is available on request.
Investor inquiry
The materials are already open to you above, so this form is not a gate. It tells us who we are talking to, so the first reply is a real answer about the round rather than a calendar link. Both founders read every submission personally. No mailing list, no drip sequence, no gated webinar.
What happens next
This page is provided for informational purposes only. It is not an offer to sell, or a solicitation of an offer to buy, any security, and it does not constitute investment advice. Any securities offering would be made only to qualified investors through definitive offering documents. Third party funding and acquisition figures cited above are as publicly reported and are provided as market context only. Forward looking statements reflect current expectations and are subject to change.