All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
GreyNoise sells security teams and governments what its own machines see. It runs a worldwide fleet of decoys that imitate vulnerable software and classifies the scanning and exploitation traffic they attract. Customers get that as searchable intelligence, hourly firewall blocklists, and detail on what attackers did after breaking in. The CVE record for a camera flaw credits a GreyNoise researcher as finder. CISA points defenders at GreyNoise research in one advisory and thanks the company in another. The Treasury signed a $518,844 subscription order in December 2025 that covered GreyNoise alongside Censys, urlscan.io, Google, Shodan and ZetaLytics. That order describes all six as data to profile attackers, so GreyNoise is one of six subscriptions a single buyer funds for that job.
| Description | GreyNoise runs a global fleet of sensors that watch internet scanning and exploitation aimed at edge devices, then sells the resulting classifications as searchable intelligence, dynamic firewall blocklists, and post-compromise session detail. | [f1] |
|---|---|---|
| Founded | 2017 | [f2] |
| HQ | Washington, District of Columbia, United States | [f3] |
| Latest funding | $15M Series A led by Radian Capital (Jun 2022) | [f3] |
| Product | What it does |
|---|---|
| GreyNoise Platform | Searchable intelligence on any internet address or vulnerability, sensors the customer deploys to watch its own perimeter, and feeds that push verdicts into other security tools. |
| GreyNoise Block | Self-service product that turns a saved query over GreyNoise data into a hosted blocklist URL a firewall pulls and refreshes every hour. |
| GreyNoise Tactics | Maps attacker sessions captured by a customer deception sensor to the MITRE ATT&CK framework and shows the commands, files, and connections that followed the break-in. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
The sensors classify scanning and exploitation at the network edge, Block turns those verdicts into firewall blocklists, compromise signals flag edge devices calling command-and-control hosts, and the vulnerability module ranks patching from observed exploitation. Mapped to the Cyber Defense Matrix. [f4]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | The buyer and the problem are stated precisely: analysts who cannot tell traffic aimed at them from indiscriminate internet scanning, and edge appliances that cannot run endpoint agents. Two outlets describe the pain in their own words. SecurityWeek says detection systems produce many alerts, most of them false positives, all needing triage, and TechCrunch calls the alerts endless and often pointless. The one quantified figure, a 25 percent cut in alerts, comes from the founder, so how large the pain is rests on the company's own measurement. [s11, s12, s1] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | The product pages carry mechanism rather than slogans: sensors that imitate vulnerable software to draw attackers into a full session, packet-level forensics with capture export, protocol fingerprinting across JA3, JA4, JA4H and HASSH, and a query language whose blocklist syntax the Block page prints in full. Three outside records bear on that same collection work. MITRE credits a GreyNoise researcher as finder of CVE-2024-8956, CISA sends defenders to a GreyNoise post for detecting Citrix exploitation, and a second CISA advisory names the company among its contributors. [s3, s4, s6, s20, s16, s15] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | Buyer-side demand is documented but runs to one kind of signal. Federal award records show the Treasury signing a subscription order covering GreyNoise in December 2025 and the Department of Transportation buying a named GreyNoise tier in June 2024, which is purchasing rather than vendor argument. The rung above asks for several kinds of buyer-side signal inside about a year, and the reviewed record carries procurement and nothing else current: no analyst category note, no regulation requiring this class of data, no budget-line study. [s21, s22] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 | Founder Andrew Morris is now chief architect and Ash Devata is chief executive, and TechCrunch records that Morris worked in research and development at the endpoint security company Endgame before starting GreyNoise. The company's research carries outside recognition: MITRE names Konstantin Lazarev of GreyNoise as the finder of a camera vulnerability, and CISA lists the company among contributors to a joint advisory. What the reviewed record does not carry is a prior product either founder built or sold, or a personal publication record, which is what the next rung asks for. [s2, s12, s20, s15] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | Named references and independent purchase records both exist. Morris told SecurityWeek in 2021 that customers included Airbus, Lumen and the Defense Innovation Unit, and TechCrunch reported more than 100 paying customers including the Department of Defense in 2022. Federal award records add evidence no vendor controls: a Treasury order signed in December 2025 and a Department of Transportation order signed in June 2024, each naming GreyNoise. The customer counts are four and five years old and no third party reports revenue, so current scale is not independently established. [s11, s12, s21, s22] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | GreyNoise raised $4.8 million in seed money and $15 million in a Series A led by Radian Capital, and its Form D filings show $4,380,000 sold to seven investors in the 2020 offering. In-Q-Tel invested on terms SecurityWeek reported as undisclosed. The raise matches the motion, and the company was shipping through it: headcount went from seven to 50 between 2020 and 2022 while paying customers went from 40 to more than 100. Efficiency itself is unconfirmed. No revenue, margin or growth figure appears in the reviewed record, and the last disclosed round was in June 2022. [s12, s13, s18, s11] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 | The category is real, but the company's own label runs ahead of the record. A Treasury order files GreyNoise in one subscription line with Censys, urlscan.io, Google, Shodan and ZetaLytics, described as data to profile attackers. That is one buyer placing the product without vendor help, and no second record does so. The Department of Transportation order names a tier and its quantities rather than a category. The CISA advisory groups contributors without saying what they sell. GreyNoise leads its own pages with edge detection and response, a label no reviewed source uses. [s21, s22, s15, s1] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | What slows an imitator is deployment rather than code. Morris described collectors in hundreds of data centres in 2020, TechCrunch reported 5,000 sensors in 2022, and four granted United States patents cover the data, the query language and the classification work. None of that is a structural moat. The Treasury order names five other attacker-profiling data subscriptions beside GreyNoise, and a platform that already carries traffic for many customers could build a comparable view without deploying sensors. [s12, s8, s21, s13] |
Two independent outlets describe the problem in their own editorial voice rather than repeating a pitch. SecurityWeek opens its 2021 article by saying that modern detection systems produce a large number of alerts, most of them false positives, all of which require triage by hard-pressed analysts. TechCrunch made the same point in 2022, calling the alerts endless and often pointless and attributing most of them to benign internet background noise.
GreyNoise frames a second problem that follows from where the traffic lands. Its own pages say edge devices cannot run endpoint agents, so a compromised firewall or VPN gateway surfaces late, and it calls edge devices the most exploited technology category in 2026.
What the reviewed record does not settle is how large the pain is. The one quantified figure, an average 25 percent reduction in security alerts, comes from the founder in a TechCrunch interview. No independent study, customer measurement or analyst estimate of the cost appears in the reviewed sources. [s11, s12, s1]
The collection is the product. Sensors placed in data centres worldwide imitate vulnerable software so attackers engage them, and GreyNoise captures and analyses the resulting sessions. The platform turns that into a first-hand verdict on any address, a behavioural history mapped to the vulnerabilities that address has attacked, and packet-level forensics with full capture export.
Two purchase routes carry it. The Platform serves enterprise and government subscribers, who pick a tier that sets data freshness and lookback and then add intelligence modules named Triage, Investigate and Hunt. Block is a standalone self-service product for organisations under 2,500 employees that publishes hourly-refreshed blocklists to a URL a firewall pulls, and GreyNoise calls Block and the Platform's own blocklists the same blocking capability sold two ways. Tactics, launched on 31 July 2026, comes with any deployed sensor: it maps attacker sessions on that sensor to the MITRE ATT&CK framework and shows the commands, files and outbound connections that followed.
The deepest technical detail sits in the Hunt module and the query language. Hunt adds protocol behaviour analysis across TLS, SSH and TCP, fingerprinting across JA3, JA4, JA4H and HASSH, and web traffic detail down to HTTP paths and headers. Every blocklist is a live query in that language, and the Block page prints the queries its templates run. [s3, s4, s5, s6]
The most useful competitive evidence is a purchase order rather than a vendor comparison. A Treasury delivery order signed on 5 December 2025, worth $518,844, describes subscription services that provide access to data to profile attackers and inform risk assessments, and names GreyNoise, Censys, urlscan.io, Google, Shodan and ZetaLytics together. That is one federal buyer paying for six data subscriptions in a single line.
Recognition from government sits alongside that. CISA credited GreyNoise with contributing to a 2025 advisory on Chinese state-sponsored intrusions, in a list that also names Amazon Web Services, Cisco Talos, CrowdStrike, Google Mandiant, Microsoft and PwC. A 2023 CISA advisory points defenders to a GreyNoise post for detecting exploitation of a Citrix vulnerability.
GreyNoise's own positioning has moved. SecurityWeek and TechCrunch both described it as a self-styled anti-threat intelligence company, and the site now leads with edge detection and response. No source in the reviewed record uses that newer label, so a buyer meets a category name the independent record has not adopted. [s21, s15, s16, s11, s12, s1]
The independent traction evidence is procurement. Federal award records show the Treasury signing a subscription order covering GreyNoise in December 2025 and the Department of Transportation buying a tier described as 500,000 searches a day with 15 alerts and 10 blocklists in June 2024 for $123,669.77. Those records come from the buyer's own reporting rather than the vendor's.
The named customers are older. SecurityWeek reported in 2021 that GreyNoise had 73 paying customers and 2,000 companies on the free tier, with Morris naming Airbus, Lumen and the Defense Innovation Unit. TechCrunch reported more than 100 paying customers including the Department of Defense in 2022. No newer customer count appears in the reviewed record.
Distribution runs through other people's tools and through a free tier. GreyNoise counts more than 80 integrations pushing its data into security information and event management systems, orchestration platforms, threat intelligence platforms and firewalls, and every paid tier includes all of them with no per-user licensing. Its own pages claim more than 400 government agencies and 60 percent of the Fortune 1000, figures no reviewed source outside the company confirms. [s21, s22, s11, s12, s1, s6]
The leadership page names seven people and gives titles rather than biographies. Andrew Morris founded the company and is now chief architect, Ash Devata is chief executive, and the bench includes a chief product officer, a chief marketing officer, a senior vice president of adversary operations, a vice president of finance and operations, and a director of intelligence.
The one background the reviewed record verifies is Morris's. TechCrunch records that he worked in research and development at the endpoint security company Endgame before founding GreyNoise, and both SEC filings list him as the executive officer and a director. The 2020 filing adds three more directors: Justin Label, Michael Sutton and Reid Christian.
Outside recognition attaches to the research rather than to individual careers. MITRE's record for CVE-2024-8956 credits Konstantin Lazarev of GreyNoise as the finder, and CISA lists the company among contributors to a joint advisory beside Mandiant, CrowdStrike and Microsoft. No prior product either founder built or sold appears in the reviewed sources. [s2, s12, s18, s20, s15]
GreyNoise runs a trust portal on HyperComply, linked from the footer of every page. It lists a 2025 SOC 2 Type II report, a 2025 ISO 27001 report and a 2025 third-party penetration test, each available on request, and publishes its security policies openly, including an AI governance policy. No United States federal authorization appears on it.
The licence terms carry one clause worth a buyer's attention. Customers may not use GreyNoise data to train, fine-tune or otherwise improve any machine learning model or artificial intelligence system, whether their own or licensed from a third party. The agreement is governed by Delaware law and was last modified on 7 May 2025.
Pricing is public at the small end and negotiated above it. Block lists at $9,999 a year for organisations under 2,500 employees, with a 14-day free trial, while the Platform tiers publish their freshness, lookback and alert quantities but not their prices. [s7, s10, s9, s6]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Censys | adjacent | Named in the same Treasury subscription order as GreyNoise, in a line the buyer describes as data to profile attackers and inform risk assessments. | |
| Shodan | adjacent | Named in the same Treasury subscription order as GreyNoise, so one federal buyer funds both in its single line for attacker-profiling data. | |
| urlscan.io | adjacent | Named in the same Treasury subscription order as GreyNoise, in the buyer's single line for attacker-profiling data. | |
| ZetaLytics | adjacent | Named in the same Treasury subscription order as GreyNoise, in the buyer's single line for attacker-profiling data. | |
| Thinkst | adjacent | Adjacent on deception spending, because GreyNoise's sensors are placed to watch internet-wide traffic rather than to sit inside a customer's own network. | |
| CounterCraft | adjacent | Adjacent to the deception spending GreyNoise Tactics and Project Swarm enter, because GreyNoise's main business is selling observations from its own sensors. | |
| Bitsight | adjacent | Adjacent in the budget for security data drawn from internet observation, which is the same raw material GreyNoise classifies for attacker behaviour. | |
| Corelight | adjacent | Adjacent on network detection spending, because GreyNoise sells an outside view of the internet rather than analysis of traffic inside a customer's network. | |
| Rapid7 | adjacent | Adjacent to the vulnerability-management budget GreyNoise's prioritisation module enters, because GreyNoise ranks patching from exploitation it observes rather than from a customer scan. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
Add analyzed competitors to compare them side by side with GreyNoise.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
press the advantage
GreyNoise's strongest asset is its collection rather than its code. Morris described collectors in hundreds of data centres in 2020, and TechCrunch counted 5,000 sensors across the world in 2022. Duplicating that means placing machines and waiting, which is the part a rival cannot produce by writing software alone. Four granted United States patents apply to the data, GNQL and the classification products named on the patents page. That is a head start rather than an exclusive position. The Treasury bought GreyNoise inside one order that also covered Censys, urlscan.io, Google, Shodan and ZetaLytics, all described as data to profile attackers. Its assurance package is a 2025 SOC 2 Type II report and a 2025 ISO 27001 report, both of which a funded competitor can earn.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 2/3 | What a customer licenses is the classification, not the interface. The platform returns a first-hand verdict of malicious, benign or suspicious on any address, the tag library behind those verdicts is signature work GreyNoise maintains, and the plans page prices access by which data fields a module exposes rather than by feature. A senior vice president of adversary operations and a director of intelligence sit on the leadership page, so analyst work stands behind the labelling. Code and expertise blend. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | The mechanism is documented and the exit is not sized. Customers write queries in GreyNoise's own language, wire the feed into more than 80 security tools, and point firewalls at blocklist URLs. Each of those is ordinary integration work: blocklists ship as standard external dynamic lists over HTTPS, and the Block page offers a drag-and-drop builder for people who do not write queries. The cited record does not state what leaving would cost in duration, parties or complexity, so the migration stays unsized. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | The trust portal lists a 2025 SOC 2 Type II report, a 2025 ISO 27001 report and a 2025 third-party penetration test, each available on request. All three are ordinary enterprise-market preparation a funded competitor can obtain. No United States federal authorization appears on the portal, and both federal orders in the reviewed record were awarded to intermediaries, FCN, Inc. and MicroTechnologies LLC, rather than resting on an authorization GreyNoise itself holds. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | The work is real-time systems at internet scale. GreyNoise runs sensors worldwide that imitate vulnerable software, captures whole sessions, and classifies the traffic against a tag library of thousands of signature-based detections. The Hunt module analyses protocol behaviour across TLS, SSH and TCP and fingerprints clients with JA3, JA4, JA4H and HASSH. An internal tool the company calls Sift flagged the exploit attempt that led its researchers to two camera vulnerabilities, one of which the CVE record credits to a named GreyNoise researcher. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | Federal award records document government buyers of the product itself. A Treasury delivery order signed in December 2025 covers a GreyNoise subscription, and a Department of Transportation order signed in June 2024 names a GreyNoise tier with its search, alert and blocklist quantities. TechCrunch reported the Department of Defense among paying customers in 2022. GreyNoise also sells Block to organisations under 2,500 employees, so the base spans both, with the government side the part the record documents. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | GreyNoise sits between a data source and an application. More than 80 integrations push its verdicts into security information and event management systems, orchestration platforms, threat intelligence platforms and firewalls, and every paid tier includes all of them, so other tools consume it programmatically. It is also an application in its own right, where analysts search addresses and vulnerabilities and build blocklists on a canvas. Nothing in the reviewed record shows a dependent system failing without the feed. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 2/3 | The data accrues to GreyNoise rather than to each customer. Its own sensors collect the traffic, TechCrunch reported 5,000 of them across data centres worldwide in 2022, and the module catalogue lists more than 156 million verified business addresses beside a tag library of thousands of detections. Four granted United States patents cover the data, the query language and the classification work. The corpus is accumulated collection rather than an artefact nobody else could gather, so it sits below the top rung. |
GreyNoise splits its market by size and by mission. The Platform serves enterprise and government subscribers, and Block is sold separately to organisations under 2,500 employees, with the pricing page saying the full platform is for organisations above that line or for managed security providers.
The government half is the better documented one. Federal award records show a Treasury order signed in December 2025, awarded through the reseller FCN, Inc. and running to December 2026, and a Department of Transportation order signed in June 2024 through MicroTechnologies LLC. TechCrunch reported the Department of Defense among paying customers in 2022, and SecurityWeek reported the Defense Innovation Unit in 2021.
The company's own segment claims are larger than what the reviewed record confirms. Its pages state five Five Eyes nations, fourteen NATO member states, more than 400 government agencies, 60 percent of the Fortune 1000 and more than 100,000 security professionals. No source outside the company in the reviewed record carries any of those figures.
The advantage begins with where the machines sit. Sensors placed in data centres worldwide imitate vulnerable software so attackers engage them, and GreyNoise captures and analyses every packet of the resulting session. TechCrunch reported 5,000 passive sensors in 2022, and in 2020 Morris described collectors in hundreds of data centres.
Artificial intelligence appears as a tool inside the collection rather than as the product. SecurityWeek reported in November 2024 that an internal system GreyNoise calls Sift flagged an unusual exploit attempt against its sensors, which led its researchers to two camera vulnerabilities; MITRE's record for the more severe of the two credits Konstantin Lazarev of GreyNoise as finder. In 2020 Morris told TechCrunch the company was not using machine learning and applied rules to sensor traffic instead.
The deepest technical detail is in the Hunt module and the query language. Hunt adds protocol behaviour analysis across TLS, SSH and TCP, fingerprinting with JA3, JA4, JA4H and HASSH, and web traffic detail down to HTTP paths and headers. Tactics, launched on 31 July 2026, maps attacker sessions on a customer's own sensor to the MITRE ATT&CK framework and shows the commands, files and outbound connections that followed.
Two purchase routes and a free tier reach different buyers. The Platform is sold by a quoted enterprise motion with no published price, Block is a standalone self-service product with a 14-day free trial and a listed annual price, and the free community tier offers basic address lookups without payment.
The federal route runs through resellers. The Treasury order in the reviewed record was awarded to FCN, Inc. and the Federal Aviation Administration order to MicroTechnologies LLC, so the buying happens on existing government contract vehicles rather than directly with GreyNoise. The company also publishes partner programmes for resellers, managed security providers, technical alliances and original equipment manufacturers.
Distribution otherwise runs through other people's consoles. GreyNoise counts more than 80 integrations pushing its data into security information and event management systems, orchestration platforms, threat intelligence platforms and firewalls, and every paid tier includes all of them with no per-user licensing, which removes a reason to ration who uses it inside a customer.
The unit of value is data access rather than seats. A customer buys one platform tier that sets how fresh the data is, how far back it reaches and how many alerts, feeds and blocklists it may run, then adds at least one intelligence module from Triage, Investigate and Hunt that decides which fields are visible. Add-on modules cover command-and-control detection, vulnerability prioritisation and known-good business infrastructure.
Only the small end is public. Block lists at $9,999 a year for organisations under 2,500 employees, a price the page says saves 17 percent against monthly billing. Every paid Platform tier says to contact sales, so the enterprise and government business is negotiated.
The tier table is unusually specific about what money buys. Data freshness moves from every eight hours on the free tier to hourly on Elite, historical lookback from ten days to ninety, and blocklists from one to unlimited. Users and integrations are not metered on any paid tier.
Everything is delivered as a service the customer queries. Analysts work in a hosted visualiser, machines call an API, and blocklists arrive as a URL the firewall fetches on a schedule. Nothing runs on the customer's estate except the optional deception sensors they choose to deploy.
Those sensors are the one operational commitment. A customer that wants to see attacks aimed at its own perimeter deploys GreyNoise sensors running emulation profiles, and Tactics only populates once a sensor is running a vulnerable profile and an attacker has compromised it.
The service commitments scale with the tier. Support availability runs eight hours a day on the free, Standard and Advanced tiers and twelve on Elite, response targets move from none on the free tier to four hours on Elite, and blocklists provision in minutes and refresh hourly regardless.
The published trust record is thin but real. A HyperComply portal carries 2025 SOC 2 Type II, ISO 27001 and penetration-test reports on request, and no United States federal authorization appears on it.
The licence carries one clause a buyer should read before planning internal automation, because it forbids using GreyNoise data to train or otherwise improve any machine learning model.
Government recognition is the strongest outside signal. CISA credited GreyNoise with contributing to a 2025 joint advisory on Chinese state-sponsored intrusions, in a list that also names Amazon Web Services, Cisco Talos, CrowdStrike, Google Mandiant, Microsoft and PwC, and a 2023 CISA advisory points defenders to a GreyNoise post for detecting Citrix exploitation.
GreyNoise is built to be consumed by other software. More than 80 integrations carry its verdicts into security information and event management systems, orchestration platforms, threat intelligence platforms and firewalls, and the company frames that as avoiding a rip and replace. Blocklists use standard external dynamic lists over HTTPS, which is why they work with firewalls and cloud network controls a customer already runs.
That same design makes GreyNoise replaceable at the interface. A firewall pulling a list from a URL can be pointed at a different URL, and the Treasury order shows one buyer funding five other attacker-profiling data subscriptions in the same line.
The community programme is the part that compounds. Project Swarm opened the deception platform to anyone willing to run a sensor, which extends the collection surface beyond the company's own footprint at the participants' expense rather than its own.
The team grew from seven people in August 2020 to 50 by June 2022, and no newer headcount appears in the reviewed record. The leadership page names seven people with titles and no biographies, so the bench is visible by role rather than by track record.
Morris is the one background the reviewed record verifies. TechCrunch records that he worked in research and development at the endpoint security company Endgame before founding GreyNoise. Both Form D filings list him as executive officer and director, and the 2020 filing adds Justin Label, Michael Sutton and Reid Christian as directors.
Outside recognition attaches to the research rather than to individual careers: MITRE credits a named GreyNoise researcher with finding a camera vulnerability, and CISA lists the company among contributors to a joint advisory.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | https://www.greynoise.io/ | official | 2026-09-04 |
| f2 | SecurityWeek: article on the In-Q-Tel investment in GreyNoise | press | 2026-09-04 |
| f3 | TechCrunch: article on the GreyNoise Series A round | press | 2026-09-04 |
| f4 | https://www.greynoise.io/products/platform | official | 2026-09-04 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.