All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Qualys runs a cash-generative vulnerability-management business, reporting a 47 percent adjusted EBITDA margin and a 53 percent free-cash-flow margin for Q1 2026. Its platform serves more than 10,000 subscription customers, folding vulnerability, cloud, web-app, and compliance findings into a single TruRisk score, and it also offers AI-workload assessment and protection. Its TotalCloud platform page displays a KuppingerCole 2025 CNAPP Leader recognition. Larger platform vendors can fold similar scanning into suites buyers already own. Against that pressure, the installed agent base, more than any single scanner, is what makes Qualys costly to replace.
| Description | Qualys runs the Enterprise TruRisk Platform, a cloud-based suite for vulnerability and exposure management (VMDR), cloud security (TotalCloud CNAPP), web application scanning, IT policy compliance, and AI-workload security, unifying findings into one risk score. | [f1] |
|---|---|---|
| Founded | 1999 | [f2] |
| HQ | Foster City, California, USA | [f3] |
| Latest funding | IPO, $12.00/share (September 2012), Nasdaq: QLYS | [f4] |
| Deployment | SaaS, Self-hosted | [f5] |
| Compliance | FedRAMP Moderate | [f5] |
| Product | What it does |
|---|---|
| Qualys VMDR | Vulnerability Management, Detection and Response: scans assets, prioritizes with TruRisk threat intelligence, and runs built-in patching to reduce risk. |
| Qualys TotalCloud | Cloud-native application protection platform (CNAPP) covering cloud, container, Kubernetes, CIEM, and DSPM posture across AWS, Azure, and GCP with TruRisk prioritization. |
| Qualys Policy Compliance | Automates IT configuration and policy compliance with mandate-based controls, automated evidence collection, and audit-ready dashboards across the asset estate. |
| Qualys Web Application Scanning | Discovers, scans, and prioritizes web application and API risk including the OWASP Top 10, with AI-powered TruRisk prioritization. |
| Qualys TotalAI | Discovers and inventories AI and LLM workloads, then scans models for jailbreak, prompt injection, and other OWASP LLM Top 10 risks. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Qualys TotalAI discovers and inventories AI and LLM workloads, then scans models for jailbreak, prompt injection, and other OWASP LLM Top 10 risks. It is mapped to the AI Defense Matrix. [f6]
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Qualys VMDR finds known and unknown assets on premises, in the cloud, or internet-facing, and scans them within a single platform. This product line is mapped to the Cyber Defense Matrix. [f7]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 4/5 | Qualys defines the exposure-management problem precisely for security and risk buyers, and a paying base across more than 130 countries corroborates that unprioritized vulnerability and compliance pain is real and widespread. The clarity sits at platform generality rather than one sharply bounded persona. [s1, s2, s3, s4] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | Detailed live product pages span VMDR with 25-plus real-time threat-intelligence sources, TotalCloud CNAPP across cloud, container, and identity, policy compliance, and web-app scanning, and an independent KuppingerCole CNAPP evaluation covers Qualys among its vendors to watch, an external signal beyond marketing. The depth is strong and multi-domain rather than a single independently benchmarked capability. [s3, s4, s5, s6, s7] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 | Sustained double-digit revenue growth to $669 million in 2025 is an independently reported buyer-side signal that demand for exposure management keeps expanding, and independent analyst coverage of Qualys in the CNAPP category shows active cloud-security procurement. Qualys founded 1999 is not timing-eligible, so this reads present tense. [s3, s5, s12] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | Qualys launched QualysGuard in 2000, went public on Nasdaq in 2012, and is run by Sumedh Thakar, who joined in 2003 and rose from engineer to chief executive, a verifiable long-run build in the company's own domain. SEC filings confirm Qualys, Inc. as a Nasdaq-listed Delaware company still filing annual reports, with its most recent 10-K filed in February 2026. [s8, s11, s13] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 5/5 | Publicly reported revenue of $669 million in 2025 and more than 10,000 subscription customers across 130-plus countries, including 74 percent of the Forbes Global 50, are own-voice scale metrics corroborated by independent financial reporting and the company's SEC filing record, clearing the at-scale bar for a 5 the same way the Tenable and Rapid7 gtm_proof did. [s2, s3, s9, s12, s13] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 5/5 | Qualys turns about $222 million of operating income on $669 million of revenue, a 33 percent operating margin, and its Q1 2026 earnings report adds a 47 percent adjusted EBITDA margin and a 53 percent free-cash-flow margin, with SEC filings confirming the public reporter behind the numbers. That confirmable profitability, without any operating loss or revenue decline to cap it, earns the exceptional score. [s3, s12, s13] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Vulnerability and exposure management plus CNAPP and application security are established categories buyers and analysts place without vendor coaching, and an independent KuppingerCole CNAPP Leadership Compass includes Qualys among the vendors it covers. That outside recognition is real but short of the headline analyst leadership the company markets, and short of the wire-reported analyst placements that would lift it higher. [s3, s5, s7, s14] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | A single Cloud Agent on more than 10,000 enterprises, a 25-plus-year detection corpus, and a unified TruRisk score raise switching cost, but the core scanning value is contestable by platform vendors such as Microsoft and Palo Alto Networks, and Qualys holds no de-facto reference scanner like Tenable's Nessus, so the moat is adequate rather than the structural 4 Tenable earns. That agent footprint is also a surface to keep hardened, as a vendor-disclosed local privilege-escalation flaw in the Cloud Agent for Windows underscores. [s1, s4, s5, s15] |
Qualys sells to security and risk teams that need to find, prioritize, and remediate exposures across a large and mixed asset base, then prove compliance on the same platform. The company frames the work as measuring, communicating, and eliminating cyber risk rather than running disconnected scanners.
The market for this work is large and active. More than 10,000 subscription customers across 130-plus countries pay for the platform, including 74 percent of the Forbes Global 50, and that scale is independent corroboration that unprioritized vulnerabilities and audit burden are a widespread, budgeted pain rather than a niche concern. [s1, s2, s9]
Qualys ships a broad suite on one platform rather than a single tool. VMDR handles scanning and risk-based prioritization with 25-plus real-time threat-intelligence sources and built-in patching, while TotalCloud covers cloud, container, Kubernetes, identity, and data posture as a CNAPP across AWS, Azure, and GCP.
The platform extends across audit and application surfaces. Policy Compliance automates mandate-based controls and audit-ready evidence collection, Web Application Scanning covers web apps and APIs including the OWASP Top 10, and TotalAI extends scanning to AI and LLM workloads, all rolling into one TruRisk score the customer acts on. [s4, s5, s6, s7]
Qualys competes as a profitable incumbent in a category that both startups and platform vendors are crowding. Its single-agent footprint, long-running detection corpus, and compliance positioning raise switching cost for embedded customers.
The core scanning-and-remediation value is contestable. Cloud-native exposure startups compete on coverage of modern workloads, and larger platform vendors can fold risk-based vulnerability management into suites their customers already license. Qualys lacks the de-facto reference-scanner standing Tenable's Nessus holds, so by this read Qualys leans on installed-base embedding rather than a singular content asset to hold accounts. [s1, s4, s5]
Qualys runs a proven enterprise go-to-market motion at scale. Revenue reached $669 million in 2025, up about 10 percent year over year from $607 million, and the paying base exceeds 10,000 customers across 130-plus countries.
The financial profile is the standout traction signal. Operating income of roughly $222 million, a 33 percent operating margin, means the company funds product expansion and acquisitions from profit, a position independently visible in its public financial reporting and one the loss-making same-asset public peer cannot match. [s2, s3]
Qualys was founded in 1999, launched QualysGuard in 2000, and went public on Nasdaq in 2012. The company has built and operated that vulnerability-management franchise for more than two decades, and its SEC filing history records a still-active public reporter.
Leadership is long-tenured rather than parachuted in. President and chief executive Sumedh Thakar joined in 2003, shortly after the founding, and rose from engineer to chief executive, so the platform strategy is directed by an operator steeped in the core scanning business. Sustained profitable operation through multiple market cycles is the credibility signal the public record supports. [s8, s11, s13]
Qualys carries the trust posture expected of an established public security vendor serving regulated buyers, and it documents that posture publicly. The TotalCloud page lists FedRAMP High Authorization, and the platform automates the full spectrum of auditing and compliance for IT systems and web applications, so procurement teams can see federal validation rather than a marketing claim. The customer base spans heavily regulated industries across more than 130 countries.
Compliance is also a product the company sells. Policy Compliance maps mandate-based controls and collects audit-ready evidence, and TotalCloud proves compliance against frameworks such as PCI DSS, HIPAA, and NIST, so the same posture buyers demand of Qualys is the capability Qualys delivers to them. [s5, s6, s10]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Tenable | competes with | Direct vulnerability and exposure-management rival with an overlapping scanning and prioritization franchise built on Nessus. | |
| Rapid7 | competes with | Vulnerability management, exposure, and detection vendor competing for the same risk-based exposure buyers. | |
| Microsoft | competes with | Defender vulnerability management ships inside licensing bundles many Qualys prospects already own. | N/AMicrosoft is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product. |
| Palo Alto Networks | competes with | Platform vendor whose Cortex and Prisma Cloud lines overlap Qualys VMDR and TotalCloud in larger accounts. | N/AWe scored these companies at different scopes, so the totals measure different things. |
| Wiz | competes with | Cloud-native exposure and posture vendor competing with the Qualys TotalCloud CNAPP line. |
Add analyzed competitors to compare them side by side with Qualys.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
Qualys sells software the customer configures and runs itself, and the TruRisk score is that software's output rather than a risk judgment Qualys is paid to stand behind. No reviewed source names a rule mandating Qualys specifically. A funded rival could rebuild the detection catalog, since the public record names no non-public dataset behind it. The durable part is the installed footprint. A customer running Cloud Agent must remove that footprint, deploy a rival's sensors, and recreate its scan configurations, and the platform behind that agent serves more than 10,000 subscription customers. Matching scanning across vulnerability, cloud, web-app, and AI surfaces takes years of specialized engineering. FedRAMP High authorization eases federal procurement without requiring Qualys.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Qualys sells software the customer configures, runs, and acts on, with TruRisk scoring and evidence-backed findings as algorithmic output rather than a service in which Qualys accepts accountability for the risk judgment. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Customers that deploy Cloud Agent, configure Qualys scan settings, and run governance on the unified TruRisk score wire the platform into their estate, so replacing it means removing that footprint, deploying a rival's sensors, and recreating those configurations, while other deployments may face lower switching friction. That is meaningful friction short of network effects or mandated residency. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 2/3 | TotalCloud carries FedRAMP High Authorization that procurement reviews value, above a bare table-stakes posture, though federal authorization eases deployment rather than mandating this product, so a determined operator could clear the same gates. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Vulnerability scanning with real-time threat intelligence, CNAPP across cloud, container, and identity, and web-app and API testing correlated into one risk model, alongside AI-workload scanning, sit in machine-learning and real-time territory that takes years of specialized engineering. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | The buyers are large enterprises with strict procurement reviews, a base the company says reaches 74 percent of the Forbes Global 50, and TotalCloud carries FedRAMP High Authorization that makes the platform eligible for public-sector procurement, so the population Qualys sells into is one whose legal and security review sits between the vendor and replacement. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | The Enterprise TruRisk Platform is an assessment and control plane that discovers, scans, and rates the estate rather than infrastructure that customer traffic is forced through inline, a platform with application features rather than infrastructure others build on. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | The accumulating detection catalog and TruRisk scoring intelligence are an accumulating catalog a funded rival could reproduce over time, and the record names no non-public cross-customer dataset, so it is reproducible content rather than an irreplaceable asset. |
Qualys sells to security and risk teams inside large organizations, including regulated and public-sector buyers, that have to find, test, remediate, and prove compliance on exposures across a mixed asset base. The about page reports more than 10,000 subscription customers in more than 130 countries and deep penetration of the Forbes Global 50 at 74 percent, so the platform rides an enterprise base the company has served for two decades rather than a single emerging segment.
The platform addresses several budget owners from one estate. VMDR serves the vulnerability-management team, TotalCloud serves the cloud-security team, Policy Compliance serves audit and GRC, and Web App Scanning serves application security, so Qualys sells multiple lines into one account rather than a point product.
The segmentation also reaches the public sector. TotalCloud carries FedRAMP High Authorization, which supports federal procurement and widens the addressable set beyond the commercial enterprise.
The platform spans discovery, assessment, and remediation across several surfaces rather than a single control point. VMDR measures risk with 25-plus real-time threat-intelligence sources through TruRisk and runs built-in patching, while TotalCloud covers cloud, container, Kubernetes, CIEM, and DSPM posture across AWS, Azure, and GCP.
Coverage extends to applications and compliance. Web Application Scanning assesses web apps and APIs including the OWASP Top 10, Policy Compliance automates mandate-based controls and audit evidence, and a TotalAI line offers assessment and protection for AI workloads. The vulnerability, cloud, web-app, and compliance surfaces map to the same risk model.
The structural advantage is reuse of the existing sensor estate. The single agent and integrated apps deliver findings that roll into one TruRisk score. Supported endpoint and hybrid capabilities can reuse the Cloud Agent where applicable, while other surfaces may require separate sensors, connectors, or setup.
Go-to-market runs through the installed enterprise base and an expanding channel. Qualys reported first-quarter 2026 revenue of $175.6 million, up 10 percent, with channel partners responsible for 52 percent of revenue compared to 49 percent previously, so the motion is shifting toward partner-driven distribution rather than direct sales alone.
The integrated apps give Qualys a route into that installed base. The company describes the Enterprise TruRisk Platform and its integrated apps as one set of apps on a shared platform, so a customer already running one line can take on another from the same vendor. Federal authorization opens a procurement path that eases regulated and federal sales.
The breadth is also the dependency the platform sells against. Standardizing discovery, scanning, and scoring on one vendor concentrates the loop, which is the consolidation Qualys offers and the single-vendor reliance a cautious buyer weighs against it.
No public rate card for the platform lines appears in the reviewed sources, consistent with a vendor selling to large accounts rather than through self-serve subscriptions. The reviewed sources show no standalone advertised price for any individual line.
The reported numbers point to expansion within the installed base. The company reports a net dollar expansion rate above 100 percent, and its integrated apps sit on one platform, so revenue growth comes partly from customers it already serves rather than from new logos alone.
That structure fits the installed enterprise buyer and raises a predictability question for smaller teams. An existing customer can extend a relationship it has, while a buyer without that footprint faces a negotiated purchase with no published price to scope against a single use case.
The platform is delivered from the Qualys cloud and built to run on the single agent and scanners a customer already operates. Where a supported endpoint or hybrid capability reuses the Cloud Agent, a customer with that footprint configures policy and scan settings rather than standing up new scanning infrastructure, while other surfaces may require separate sensors, connectors, or setup. The same agent continuously delivers security intelligence across on-premises, cloud, container, and endpoint assets, which is the sensor estate those modules attach to.
Operations center on repeatable, configurable scanning. Qualys says its Cloud Agent Configuration Profile supplies that flexibility and works across the company's apps, and continuous posture management re-checks the environment as assets, web apps, and cloud resources change.
Because Qualys runs the platform, the customer avoids operating the scanning backend. The trade is concentration: inventory, scanning, compliance, and risk scoring run on one vendor platform the customer depends on for the full loop.
Trust rests on an established public security vendor and on artifacts regulated buyers can audit. Qualys launched QualysGuard in 2000 as an early SaaS security company and has operated through multiple market cycles, a track record procurement teams recognize rather than a first-time entrant's.
Compliance is also the product the company sells. Policy Compliance maps mandate-based controls and collects audit-ready evidence, and TotalCloud proves compliance against frameworks such as PCI DSS 4.0, HIPAA, and NIST 800-53, so the posture buyers demand of Qualys is the capability Qualys delivers to them.
The strongest external trust signal is federal authorization. TotalCloud carries FedRAMP High Authorization on the Qualys cloud, which a commercial buyer reads as independent validation of the platform's security baseline.
The platform is positioned as integrated apps on one engine rather than separate tools, and the strategy is to make every security surface part of the same operating cadence. Findings flow into unified dashboards and a single TruRisk score across vulnerability, cloud, applications, and compliance, so each posture sits beside the others the customer already manages.
Outward, the lines cover multiple clouds and surfaces. TotalCloud spans AWS, Azure, and GCP, Web App Scanning covers web and API surfaces, and a TotalAI line covers AI workloads, so a multi-cloud enterprise can govern its estate centrally rather than accept one platform's native controls.
Inward, the breadth deepens reliance on Qualys. Standardizing discovery, scanning, compliance, and scoring on the platform concentrates the loop with one vendor, which is the consolidation Qualys sells and the single-vendor dependence a cautious buyer weighs against it.
The company is run by a long-tenured operator rather than an outside hire. President and chief executive Sumedh Thakar joined in 2003, shortly after the founding, and rose from engineer to chief executive, so the platform strategy is directed by leadership steeped in the core scanning business.
The financial discipline shows in the operating model. Qualys runs a 47 percent adjusted EBITDA margin and a 53 percent free-cash-flow margin while funding higher sales and marketing spend and a share-repurchase program, which reads as an operator that can grow from cash rather than fresh capital.
What the public record shows less of is a distinct, named research identity for the newer cloud and AI lines comparable to the company's long vulnerability-research history. The newer lines' credibility today is the parent's domain track record and detection catalog rather than a separately recognized team.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Qualys company about page | official | 2026-06-23 |
| f2 | Qualys Wikipedia entry | research | 2026-06-14 |
| f3 | Qualys company about page | official | 2026-06-14 |
| f4 | Dark Reading on the Qualys IPO pricing | press | 2026-06-14 |
| f5 | AI Defense Matrix Catalog entry | other | 2026-06-13 |
| f6 | AI Defense Matrix Catalog mapping | other | 2026-06-23 |
| f7 | Qualys VMDR product page | official | 2026-07-29 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Qualys homepage “Enterprise Cyber Risk and Security Platform” | official | 2026-06-23 |
| s2 | Qualys company about page “More than 10,000 subscription customers worldwide in more than 130 countries trust Qualys to underpin digital transformation for greater agility, better business outcomes, and substantial cost savings.” | official | 2026-06-23 |
| s3 | Qualys (QLYS) income statement “FY 2025 Revenue 669.13 ($669 million), FY 2024 Revenue 607.57 ($607 million), Operating Income 221.95 ($222 million), Revenue Growth (YoY) 10.13%.” | research | 2026-06-23 |
| s4 | Qualys VMDR product page “Measure Risk with 25+ sources of Real-Time Threat Intelligence (RTI) using TruRisk. Eliminate Risk 60% faster with built-in patching and remediation workflows.” | official | 2026-06-23 |
| s5 | Qualys TotalCloud CNAPP product page “TotalCloud, The Risk-minded CNAPP. Forrester Wave CNAPP Leader, KuppingerCole 2025 CNAPP Leader and GigaOm Radar Leader. FedRAMP High Authorization. Prove compliance with frameworks such as PCI DSS 4.0, HIPAA 2023, NIST 800-53/171, and GDPR.” | official | 2026-06-23 |
| s6 | Qualys Policy Compliance product page “Go beyond configuration assessments to simplify audits and reduce compliance risk with automated evidence collection, mandate-based controls, and seamless integration.” | official | 2026-06-23 |
| s7 | Qualys Web App Scanning product page “Discover, monitor & reduce your modern web app and API attack surface with advanced, AI-powered TruRisk platform ... vulnerabilities detected, including OWASP Top 10 ... Qualys TotalAppSec has continued to be a leader and outperformer in the GigaOm Radar Report in Application Security Testing.” | official | 2026-06-23 |
| s8 | Qualys leadership Sumedh Thakar “Sumedh Thakar, President and CEO ... He joined Qualys in 2003, shortly after the company's founding ... His contributions and leadership helped propel Qualys to its current success in cybersecurity.” | official | 2026-06-23 |
| s9 | Qualys Forbes Global penetration “Over 10,000 subscription customers worldwide trust Qualys. 74% Forbes Global 50, 57% Forbes Global 500, 35% Forbes Global 2000.” | official | 2026-06-23 |
| s10 | Qualys Enterprise TruRisk Platform compliance “The Enterprise TruRisk Platform and its integrated apps help businesses simplify security operations and lower the cost of compliance by delivering critical security intelligence on demand and automating the full spectrum of auditing, compliance and protection for IT systems and web applications.” | official | 2026-06-23 |
| s11 | Qualys Wikipedia history “The company launched QualysGuard in 2000, making Qualys one of the first entrants in the vulnerability management market ... Qualys went public on the Nasdaq under the stock ticker QLYS on September 28, 2012.” | research | 2026-06-18 |
| s12 | Qualys Q1 2026 earnings transcript “Revenues grew 10% to $175.6 million. The channel continued to increase its contribution, making up 52% of total revenue ... adjusted EBITDA for the first quarter of 2026 was $83.3 million, representing a 47% margin ... free cash flow was $93.6 million, representing a 53% margin.” | press | 2026-06-23 |
| s13 | SEC EDGAR entity and filing record for Qualys, Inc. (CIK 0001107843), Nasdaq QLYS, incorporated in Delaware, latest 10-K filed 2026-02-20 “name QUALYS, INC., tickers QLYS, exchanges Nasdaq, stateOfIncorporation DE, latest 10-K filingDate 2026-02-20 reportDate 2025-12-31” | regulatory | 2026-06-30 |
| s14 | KuppingerCole Leadership Compass Cloud-Native Application Protection Platforms (CNAPP), published June 10, 2025, covering Qualys among Vendors to Watch “Leadership Compass: Cloud-Native Application Protection Platforms (CNAPP) ... published on June 10, 2025 ... Vendors to Watch ... Qualys” | other | 2026-06-30 |
| s15 | NVD CVE-2023-28142, Qualys Cloud Agent for Windows local privilege escalation, CVSS 3.1 base 7.0 HIGH (NVD NIST) and 6.7 MEDIUM (Qualys CNA) “A Race Condition exists in the Qualys Cloud Agent for Windows platform in versions from 3.1.3.34 and before 4.5.3.1. This allows attackers to escalate privileges ... Attackers may gain SYSTEM level privileges on that asset to run arbitrary commands.” | regulatory | 2026-06-30 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Qualys company about page “More than 10,000 subscription customers worldwide in more than 130 countries trust Qualys to underpin digital transformation for greater agility, better business outcomes, and substantial cost savings.” | official | 2026-06-23 |
| s2 | Qualys Enterprise TruRisk Platform “The Enterprise TruRisk Platform and its integrated apps help businesses simplify security operations and lower the cost of compliance by delivering critical security intelligence on demand and automating the full spectrum of auditing, compliance and protection for IT systems and web applications.” | official | 2026-06-23 |
| s3 | Qualys VMDR product page “Measure Risk with 25+ sources of Real-Time Threat Intelligence (RTI) using TruRisk. Eliminate Risk 60% faster with built-in patching and remediation workflows.” | official | 2026-06-23 |
| s4 | Qualys TotalCloud CNAPP product page “TotalCloud, The Risk-minded CNAPP. Forrester Wave CNAPP Leader, KuppingerCole 2025 CNAPP Leader and GigaOm Radar Leader and Outperformer. PeerSpot highest rated CNAPP vendor, FedRAMP High Authorization.” | official | 2026-06-23 |
| s5 | Qualys TotalCloud compliance and identity coverage “Meet and prove compliance with frameworks across deployed cloud resources and IaC templates such as PCI DSS 4.0, HIPAA 2023, NIST 800-53/171, and GDPR ... Deepen CIEM + DSPM to correlate identity, permission, and sensitive-data exposure.” | official | 2026-06-23 |
| s6 | Qualys Policy Compliance product page “Go beyond configuration assessments to simplify audits and reduce compliance risk with automated evidence collection, mandate-based controls, and seamless integration.” | official | 2026-06-23 |
| s7 | Qualys Web App Scanning product page “Discover, monitor & reduce your modern web app and API attack surface with advanced, AI-powered TruRisk platform ... vulnerabilities detected, including OWASP Top 10, with continuous monitoring.” | official | 2026-06-23 |
| s8 | Qualys Q1 2026 revenue and channel “Revenues grew 10% to $175.6 million. The channel continued to increase its contribution, making up 52% of total revenue compared to 49% a year ago.” | press | 2026-06-23 |
| s9 | Qualys Q1 2026 margins and cash flow “adjusted EBITDA for the first quarter of 2026 was $83.3 million, representing a 47% margin ... our free cash flow was $93.6 million, representing a 53% margin.” | press | 2026-06-23 |
| s10 | Qualys ETM system of record “our massive data context, LLM and SLM integration and trusted execution serve as the system of record for pre-beach cyber risk management.” | press | 2026-06-23 |
| s11 | Qualys leadership Sumedh Thakar “He joined Qualys in 2003, shortly after the company's founding ... His contributions and leadership helped propel Qualys to its current success in cybersecurity.” | official | 2026-06-23 |
| s12 | Qualys Forbes Global penetration “Over 10,000 subscription customers worldwide trust Qualys. 74% Forbes Global 50, 57% Forbes Global 500, 35% Forbes Global 2000.” | official | 2026-06-23 |
| s13 | Qualys Wikipedia history “The company launched QualysGuard in 2000, making Qualys one of the first entrants in the vulnerability management market.” | research | 2026-06-18 |
| s14 | Qualys Cloud Agent product page “A single agent for real-time, global visibility and response ... Over 110 million Cloud Agents actively deployed across the globe ... One agent. One platform. More Visibility.” | official | 2026-07-11 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.