All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This analysis draws mostly on the vendor's own published materials, with limited outside corroboration.
ProjectDiscovery has strong evidence for free adoption and little for paid revenue. Its open-source Nuclei scanner has more than a million active users, a global community maintains over 10,000 detection templates, and the company won the 2025 RSAC Innovation Sandbox on that open-source story. The paid side is far less proven. The public record names Elastic and Vercel as users but not as confirmed paying references, and shows no named paying customer for Neo, the autonomous AI agents its homepage now leads with. That free community is the asset the company must convert into enterprise revenue, and the public record does not yet show that conversion.
| Description | Open-source-powered security testing company whose Nuclei scanner and cloud platform find exploitable vulnerabilities across web apps, APIs, networks, and cloud, now extended by Neo, autonomous AI agents that pentest apps and review pull requests. | [f1] |
|---|---|---|
| Founded | 2020 | [f1] |
| HQ | San Francisco, California, USA | [f2] |
| Funding | $26.7M total | [f1] |
| Latest funding | Series A, $25M (August 2023), led by CRV | [f2] |
| Product | What it does |
|---|---|
| Nuclei | Fast, customizable open-source vulnerability scanner built on a YAML-based DSL, with a community-maintained detection-template library across apps, APIs, networks, DNS, and cloud configurations. |
| ProjectDiscovery Cloud Platform | Managed SaaS built on the open-source tools for attack surface management, application and API pentesting, code and PR review, and vulnerability triage, priced by credits. |
| Neo | Platform of autonomous AI agents that pentest applications, review pull requests, manage the vulnerability backlog, and retest fixes, chaining attack steps to surface zero-days. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Nuclei, the cloud platform, and the Neo agents discover internet-facing assets and detect exploitable vulnerabilities in conventional web apps, APIs, networks, and cloud, so the company is mapped to the Cyber Defense Matrix. [f1]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score |
|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs, demos, and third-party validation. | 4/5 |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
pivot urgently
| Dimension | Score |
|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | ProjectDiscovery homepage | official | 2026-06-21 |
| f2 | PRNewswire: ProjectDiscovery $25M Series A | press | 2026-06-21 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | ProjectDiscovery homepage “Neo chains multiple attack steps, verifies out-of-band interactions, and tests complex business logic. The classes of vulnerabilities that scanners just entirely miss.” | official | 2026-06-21 |
| s2 | Nuclei on GitHub “Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL” | official | 2026-06-21 |
| s3 | Exa company research, ProjectDiscovery “Trusted by teams at Elastic, Vercel, and thousands more. Founded Year: 2020. Headquartered in San Francisco.” | research | 2026-06-21 |
| s4 | PRNewswire: ProjectDiscovery wins RSAC 2025 Innovation Sandbox “Named Most Innovative Startup 2025, ProjectDiscovery was selected by a panel of esteemed judges for equipping security teams with open-source tools to find and fix vulnerabilities fast.” | press | 2026-06-21 |
| s5 | ProjectDiscovery blog: Solving Vulnerability Management “Legacy scanners like Tenable and Qualys, built over 20 years ago, have not evolved to detect today's security risks. Nuclei is one of the most widely adopted open-source security tools with over one million active users. We now have over 10,000 Nuclei detection templates.” | official | 2026-06-21 |
| s6 | ProjectDiscovery pricing “50 credits per seat, top-up at $5 per credit. Application and API pentesting. Attack surface management. Code and PR review. Red teaming.” | official | 2026-06-21 |
| s7 | PRNewswire: ProjectDiscovery $25M Series A “raised $25 million in a Series A financing round led by CRV, with participation from Point72 Ventures, SignalFire, Rain Capital, Mango Capital, Accel, Lightspeed” | press | 2026-06-21 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | ProjectDiscovery homepage (Neo agents, security testing platform) “Introducing Neo by ProjectDiscovery, a platform of autonomous AI agents that pentest every app, review every PR, manage your vulnerability backlog, and retest every fix. Neo chains multiple attack steps, verifies out-of-band interactions, and tests complex business logic.” | official | 2026-06-21 |
| s2 | Nuclei on GitHub (open-source scanner, YAML DSL) “Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet.” | official | 2026-06-21 |
| s3 | ProjectDiscovery pricing (credits, pay-as-you-go, enterprise) “50 credits per seat, top-up at $5 per credit. Application and API pentesting. Attack surface management. Code and PR review. Github and Slack native apps. AWS, GCP, Azure, Cloudflare, Vercel integrations. Enterprise: BYOK, SSO and SAML, dedicated VPC and static egress IPs.” | official | 2026-06-21 |
| s4 | ProjectDiscovery blog: Solving Vulnerability Management (RSA win) “Nuclei, an open-source vulnerability scanner that thinks like an attacker. It is one of the most widely adopted open-source security tools in the world with over one million active users. We now have over 10,000 Nuclei detection templates, many of them contributed by security researchers.” | official | 2026-06-21 |
| s5 | PRNewswire: ProjectDiscovery wins RSAC 2025 Innovation Sandbox “ProjectDiscovery has been named the winner of the 20th annual RSAC Innovation Sandbox contest. Each of the Top 10 Finalists were awarded a $5M investment. Powered by Nuclei, the platform automates attack surface monitoring and vulnerability management.” | press | 2026-06-21 |
| s6 | PRNewswire: ProjectDiscovery $25M Series A (Cloud Platform launch) “Rishiraj Sharma, Co-Founder and Chief Executive Officer of ProjectDiscovery, said. Raised $25 million in a Series A led by CRV, with participation from Point72 Ventures, SignalFire, Rain Capital, Mango Capital, Accel, Lightspeed.” | press | 2026-06-21 |
| s7 | ProjectDiscovery homepage, 2026-07-14 fetch: SOC 2 badge in footer, Neo testimonial from Elastic analyst “Neo validated cross-account authorization across every role with actionable PoCs.” | official | 2026-07-14 |
| s8 | ProjectDiscovery Trust Center (SafeBase, security.projectdiscovery.io): SOC 2 Type 2 listed, audit and pentest reports gated behind access request “Here, you can explore how we safeguard information and request access to detailed resources such as audit reports and penetration test results.” | official | 2026-07-14 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Do not republish its content or share access without the operator's permission.