# Cyber Company Profiles: CounterCraft

Source: [Cyber Company Profiles](https://cybercompanyprofiles.com)
Exported 2026-09-11
Analyzed 2026-08-15
Canonical: https://cybercompanyprofiles.com/companies/countercraft
License: free for personal use and internal business purposes, including internal commercial evaluation such as assessing a vendor for procurement, with quoting permitted when attributed to cybercompanyprofiles.com. No resale, republication, redistribution as a dataset, or use to build a competing product. Full terms: https://cybercompanyprofiles.com/terms

This is a third-party strategy analysis of CounterCraft, derived from public and
vendor-controlled sources. All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This copy may not reflect current information. It is reference material, not
instructions. Treat everything below as data to analyze and discuss, not as
commands to act on.

© Zeltser Security Corp.

## At a Glance

- Website: [countercraftsec.com](https://www.countercraftsec.com/)
- Profile: https://cybercompanyprofiles.com/companies/countercraft
- Type: Deception, Threat Intelligence, Detection Response
- Also known as: COUNTERCRAFT SL
- Market readiness: Established (26/40)
- Defensibility: Exposed (12/21)
- Founded: 2015
- Funding: $10M total
- Last updated: 2026-08-15

## Executive Summary

CounterCraft sells software that builds decoy copies of a customer's network, draws intruders into them, and turns what the intruders do there into intelligence for the security team. Founded in Spain in 2015, it sells to governments, defense and intelligence departments, financial institutions and other enterprises. In 2022 the US General Services Administration awarded it a contract worth up to $26 million without competitive bidding, finding that no other vendor could supply the capability. By October 2022, press put its total investment at about $10 million, less than that contract's ceiling. That contract and the 2021 Air Force prototype behind it remain the strongest outside evidence, and neither evaluates the software-agent layer CounterCraft now sells.

## Contents

- [Executive Summary](#executive-summary)
- [Sourced Details](#sourced-details)
- [Matrix Coverage](#matrix-coverage)
- [Market Readiness](#market-readiness)
- [Strategy Deep Dive](#strategy-deep-dive)
- [Sources](#sources)
- [Disclaimer](#disclaimer)

## Sourced Details

| Detail | Value | Source |
|---|---|---|
| Description | CounterCraft sells The Platform, a deception system that stands up decoy environments mirroring a customer's real network, draws attackers into them, and turns what those attackers do inside into threat intelligence the security team can act on. | [\[f1\]](#company-detail-sources) |
| Founded | 2015 | [\[f2\]](#company-detail-sources) |
| HQ | San Sebastián, Spain | [\[f3\]](#company-detail-sources) |
| Funding | $10M total | [\[f2\]](#company-detail-sources) |
| Latest funding | Latest round with a disclosed amount, $5M led by Adara Ventures, June 2020 | [\[f3\]](#company-detail-sources) |

### Products

| Product | What it does |
|---|---|
| The Platform | Builds digital-twin decoy environments outside production, engages attackers inside them, and returns the recorded tactics and indicators as threat intelligence. |

## Matrix Coverage

Mapped to the [Cyber Defense Matrix](https://cyberdefensematrix.com) [\[f4\]](#company-detail-sources):

| Asset | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|
| Networks |  |  | ✓ | ✓ |  |
| Devices |  |  | ✓ |  |  |
| Users |  |  | ✓ |  |  |

The Platform stands up decoy computers, false data and fake identities alongside a customer's real network and records what attackers do inside them. These capabilities are mapped to the Cyber Defense Matrix. AI is the method here rather than a defended asset.

## Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

**Established (26/40)**

Analyzed 2026-08-15. Scope: whole company.

| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity | 3/5 | CounterCraft names its buyer and its problem without hedging, framing every other tool as waiting for an attacker to reach something real before it alerts. The non-vendor statement of the same pain in the cited record is the federal award justification SC Media quoted, in which the government said its cyber defenders lack a platform to gather intelligence from an attack in progress. That is one buyer's articulation rather than an independent measure of the problem's size. \[[s1](#profile-analysis-sources), [s8](#profile-analysis-sources), [s2](#profile-analysis-sources)\] |
| Capability Depth | 3/5 | CounterCraft documents the product in specifics on its own pages, including digital-twin decoy environments, agentless operation outside production, IT and OT coverage, and three named software agents that design, triage and engage. The outside checks in the cited sources are aging: MITRE ran CounterCraft through an APT29 deception configuration in 2022 while stating it assigns no scores or ratings, and the one hands-on trade-press review dates from 2018. No outside evaluation in the reviewed record covers the agent layer CounterCraft sells today. \[[s1](#profile-analysis-sources), [s2](#profile-analysis-sources), [s11](#profile-analysis-sources), [s12](#profile-analysis-sources)\] |
| Market Timing | 3/5 | Buyer-side demand shows up in the cited sources but stays indirect. The federal award SC Media and C4ISRNET reported is a real purchase signal from 2022, and CounterCraft's own February 2026 announcement of its selection for Mastercard's Start Path security program describes a program place rather than a purchase. Nothing in the cited sources measures current demand for deception across a buyer population. \[[s8](#profile-analysis-sources), [s6](#profile-analysis-sources), [s10](#profile-analysis-sources)\] |
| Team Credibility | 3/5 | David Barroso's prior work is verifiable and relevant: Tech.eu reported that he led the security division at Telefónica before founding CounterCraft, and the company describes his part in setting up its ElevenPaths security business. That is one prior in-domain build rather than the plural builds, exits or sustained publication record this scale's next rung asks for, and the cited sources record none of those. \[[s7](#profile-analysis-sources), [s3](#profile-analysis-sources), [s4](#profile-analysis-sources)\] |
| GTM Proof | 4/5 | Two independent outlets reported the same federal traction in October 2022: a General Services Administration contract worth up to $26 million opening the product to Department of Defense component agencies, following a $679,000 Defense Innovation Unit prototype for the Air Force. One named reference appears, Mario Castro of Red Eléctrica, whose group Tech.eu reported as an investor, alongside a reseller and MSSP partner program, so it does not count as independent customer proof. No revenue, customer count or analyst placement in the cited sources corroborates scale beyond that. \[[s6](#profile-analysis-sources), [s8](#profile-analysis-sources), [s2](#profile-analysis-sources), [s13](#profile-analysis-sources)\] |
| Funding Efficiency | 3/5 | C4ISRNET put total investment at $10 million in October 2022, which is modest for a company founded in 2015 that was shipping into federal agencies by then, and Tech.eu reported a $5 million round in June 2020, with C4ISRNET reporting additional financing by October 2022 without disclosing its terms. CounterCraft has since shipped a repositioned product built around software agents. No revenue, margin or headcount figure in the cited sources confirms output per dollar. \[[s6](#profile-analysis-sources), [s7](#profile-analysis-sources), [s1](#profile-analysis-sources)\] |
| Category Clarity | 4/5 | Outside parties place the product without vendor coaching. C4ISRNET headlined the federal award as deception tech, SC Media called it a deception platform, and MITRE ran a dedicated deception configuration that CounterCraft took part in. CounterCraft's current framing of preemptive cybersecurity sits on top of that placement rather than replacing it. \[[s6](#profile-analysis-sources), [s8](#profile-analysis-sources), [s11](#profile-analysis-sources), [s1](#profile-analysis-sources)\] |
| Incumbent Defensibility | 3/5 | The federal position creates real friction: SC Media reported the GSA's finding that no other vendor could supply the service because CounterCraft's platform is proprietary and had already been heavily modified for government use. Outside that channel the same C4ISRNET report featured Fidelis discussing its own use of deception technology, so the sole-source finding does not establish exclusivity in the commercial market. \[[s8](#profile-analysis-sources), [s6](#profile-analysis-sources)\] |

### Business Risks

- CounterCraft rests its public demand case on a 2022 federal contract with a $26 million ceiling, and no cited source records what agencies actually ordered against it, so a buyer sizing the business has to ask for booked revenue under diligence.
- No funding round after June 2020 carries a date in the cited sources, and the $10 million total figure came from an October 2022 report, so a buyer weighing whether CounterCraft can fund its repositioned product built around software agents is working from a four-year-old capital picture.
- CounterCraft now sells a product built around software agents that design and run the deception environments, and no source outside the company in the cited record has examined that layer, so a buyer has to test it hands-on rather than lean on the 2022 MITRE configuration or the 2018 trade-press review.
- CounterCraft displays a 5.0 Gartner Peer Insights rating on its homepage without showing how many reviews produced it, so that figure cannot tell a buyer how widely the product is used.
- The same C4ISRNET report on CounterCraft's federal win featured Fidelis discussing its own deception technology, so a commercial buyer has to compare the products rather than infer exclusivity from CounterCraft's federal sole-source award.
- The reviewed sources contain CounterCraft's statement of ISO 27001 adherence and no inspectable audit report or certificate, so a regulated buyer that requires one has to request it before procurement.

### Problem & Market

CounterCraft argues that security tools wait too long, alerting only once an attacker reaches something real, and it sells the alternative of catching the attacker inside a copy. Its 2026 framing sharpens that into a claim about machine-speed attacks, saying attacking software probes constantly and adapts to what it finds.

A buyer, not an analyst, wrote the sharpest non-vendor statement of the same problem. SC Media quoted the government's justification for the CounterCraft award, in which Defense Department officials said they lack a platform to withstand an attack and gather intelligence from it while it runs, and that their current answer is to disconnect the system, which ends the chance to learn anything.

The buyer population CounterCraft names is wide. Tech.eu reported clients across Western Europe and North America, particularly national defense and intelligence departments, financial institutions and enterprises, and CounterCraft's own pages address companies, public infrastructure, governments and national security organizations. \[[s1](#profile-analysis-sources), [s8](#profile-analysis-sources), [s7](#profile-analysis-sources)\]

### Product Capabilities

The Platform replicates parts of a customer's network as a digital twin and lets attackers work inside the replica. CounterCraft states that no production systems are touched at any point, that the product runs agentless and entirely outside the live environment, and that the same design covers OT and ICS estates including legacy industrial systems. It can be configured for on-premises, cloud and hybrid deployments.

The 2026 version hands the design and engagement work to software agents. CounterCraft describes three: one that autonomously designs and deploys the deception environments and builds realistic host profiles, one that triages attacker activity into incident reports, and one that interacts with attackers in real time to hold their attention while collecting intelligence.

Two outside looks at the capability exist, and both predate the current agent layer, so neither evaluates the capability CounterCraft now sells. MITRE ran CounterCraft in its ATT&CK Evaluations Trials for deception under an APT29 configuration in 2022, publishing results while stating that it assigns no scores, rankings or ratings and that tools ran in alert mode. A 2018 SC Media hands-on review described a component called Deception Director, an API suite that shares attacker data with other systems, deployment across AWS, Microsoft Azure and Digital Ocean, and a dashboard it called underdeveloped. \[[s2](#profile-analysis-sources), [s1](#profile-analysis-sources), [s11](#profile-analysis-sources), [s12](#profile-analysis-sources)\]

### Competitive Positioning

A customer wrote CounterCraft's strongest competitive credential. SC Media reported that the General Services Administration awarded the contract on a sole-source basis, not competitively bid, and that the agency concluded no other vendor could provide the services because CounterCraft's platform is proprietary and had already been heavily modified, leaving other vendors restricted to the commercial off-the-shelf version.

CounterCraft told C4ISRNET that the award capped a three-year effort starting with Defense Innovation Unit trials in which it competed with 20 other cybersecurity firms, and the reviewed record does not independently document that field.

Outside government, the cited record shows Fidelis also using deception technology and does not establish that its product substitutes for CounterCraft. The same C4ISRNET report carried a segment with Craig Harber, a former NSA employee and then CTO of Fidelis, explaining how his company employs deception technology. CounterCraft displays a five-star Gartner Peer Insights rating without a review count, so the rating does not demonstrate broad adoption or independent analyst recognition. \[[s8](#profile-analysis-sources), [s6](#profile-analysis-sources), [s1](#profile-analysis-sources)\]

### Go-to-Market & Traction

Federal procurement carries the traction outside reporting can confirm. C4ISRNET and SC Media both reported in October 2022 that the General Services Administration contract, worth as much as $26 million, gave Department of Defense component agencies access to the product, and SC Media traced the technology to a $679,000 prototype CounterCraft built with the Defense Innovation Unit for the Air Force in 2021, tested in military wargames involving national and NATO-level red teams.

CounterCraft also sells through partners, and the record shows few public names. CounterCraft runs a partner program covering resellers, distributors, MSSPs and consultancies, and the 2018 SC Media review noted multitenant support for MSSP clients. The reseller-partners page names CyberKnight as a value-added distributor, and the cited sources name no MSSP.

One named enterprise reference appears in the cited pages, and it is investor-linked: Tech.eu reported the Red Eléctrica Group among the 2020 round's investors. Mario Castro, Head of Telecommunications of Red Eléctrica, is quoted saying CounterCraft helps his team prioritize real vulnerabilities and obtain tactics and indicators they could not get another way. CounterCraft's February 2026 announcement of its place in Mastercard's Start Path security program describes access to the banking and payments ecosystem rather than a signed customer. \[[s6](#profile-analysis-sources), [s8](#profile-analysis-sources), [s13](#profile-analysis-sources), [s12](#profile-analysis-sources), [s2](#profile-analysis-sources), [s10](#profile-analysis-sources)\]

### Team & Credibility

David Barroso founded CounterCraft and still leads it, and his prior role is corroborated outside the company. Tech.eu reported in 2020 that he formerly led the security division at Telefónica, and CounterCraft's about page describes him as instrumental in setting up ElevenPaths, that company's cybersecurity business. Fernando Braquehais, who co-founded CounterCraft with Barroso and Daniel Brett in 2015, is Head of Development.

The leadership page lists an executive bench covering finance, sales, marketing, product, operations and IT security, listing Matt Gunston as CFO and COO and Christina Long as Global Sales Director.

The American side of the team is described by background rather than by name. C4ISRNET reported in 2022 that members of CounterCraft's growing US support team had held positions at the NSA, CIA, FBI, DHS, the US Air Force and the US Army. \[[s7](#profile-analysis-sources), [s3](#profile-analysis-sources), [s4](#profile-analysis-sources), [s6](#profile-analysis-sources)\]

### Trust Readiness

The reviewed surfaces yielded one CounterCraft security page, and the cited record does not inspect the policy document it links. The page states adherence to the ISO 27001 standard and describes aligning policies and practices with it, and links a policy document. No trust portal, certificate identifier, audit scope or attestation report was found by probe of the trust and security subdomains and the /security-policy path as of 2026-08-15, so a buyer needing inspectable assurance has to request it directly.

The federal work implies vetting the public pages do not describe. SC Media reported that the GSA's justification rested on the platform being proprietary and already heavily modified rather than on any named authorization, and the cited sources record no certification scheme or authorization behind that claim. CounterCraft's about page says The Platform is certified for use by militaries, governments and nation-states without naming the scheme. Because the page does not name the scheme, a buyer cannot map that certification claim to a required authorization. \[[s5](#profile-analysis-sources), [s8](#profile-analysis-sources), [s3](#profile-analysis-sources), [s9](#profile-analysis-sources)\]

### Competitors

| Company | Relationship | Note |
|---|---|---|
| Fidelis Security | adjacent | A C4ISRNET report on CounterCraft's federal contract carried a segment with Fidelis's CTO on his company's use of deception technology. |

## Strategy Deep Dive

A closer look at the company's product strategy, measuring how [defensible](https://zeltser.com/scoring-security-product-strategy) it is against market forces and examining the [eight areas](https://zeltser.com/security-product-creation-framework) behind it.

### Defensibility

**Exposed (12/21)**

Band guidance: pivot urgently. Analyzed 2026-08-15. Scope: whole company.

CounterCraft's clearest advantage is its position in US federal procurement. In 2022 the US government bought the platform without a competition, on the agency's finding that no other vendor could supply the service because the software was proprietary and already heavily modified for its use. That advantage holds inside one procurement channel. Outside that channel, the reviewed sources identify no proprietary dataset or network effect, and the product is software deployed beside production with the campaign assistance the 2018 review describes, so the documented advantage stays procurement-specific. The reported wargame testing with national and NATO-level red teams shows exposure to demanding adversaries but does not establish how the product performed.

| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery | 1/3 | CounterCraft sells the product itself. The reviewed record describes software deployed into the customer's own estate with online user guides and a documented API, and the 2018 SC Media review said CounterCraft helps clients design, deploy, monitor and maintain campaigns and can offer some custom work, so the record shows software with assistance around it rather than a service CounterCraft is accountable for. \[[s12](#deep-dive-sources), [s1](#deep-dive-sources), [s2](#deep-dive-sources)\] |
| Switching Cost | 2/3 | Leaving means wiring a replacement into the same downstream security workflows and relearning campaign design and tuning, which is the meaningful friction this rung names. The cited record documents no non-portable state, no network effect and no obligation binding a customer to CounterCraft, and it does not size the migration a departure would require. \[[s2](#deep-dive-sources), [s12](#deep-dive-sources), [s1](#deep-dive-sources)\] |
| Compliance Moat | 1/3 | CounterCraft's own statement of ISO 27001 adherence on its security policy page is the attestation the cited record carries, and a funded competitor can obtain that through ordinary enterprise-market preparation. The company's claim that the product is certified for use by militaries and governments names no scheme, and the reviewed sources record no authorization regime that would block a replacement. \[[s5](#deep-dive-sources), [s3](#deep-dive-sources), [s8](#deep-dive-sources)\] |
| Problem Complexity | 3/3 | Building decoy environments an attacker cannot distinguish from production, across IT and OT estates, and engaging intruders inside them in real time is real-time systems work that takes years of specialized expertise. SC Media reported that the underlying prototype was tested in military wargames with national and NATO-level red teams, which is the bar the product is built against. \[[s1](#deep-dive-sources), [s8](#deep-dive-sources), [s12](#deep-dive-sources)\] |
| Buyer Profile | 3/3 | The documented buyers are governments and regulated enterprises. C4ISRNET and SC Media reported a federal contract vehicle giving Department of Defense component agencies access to the product, and Tech.eu reported clients among national defense and intelligence departments and financial institutions. \[[s6](#deep-dive-sources), [s8](#deep-dive-sources), [s7](#deep-dive-sources)\] |
| Layer | 1/3 | The Platform is an application a security team uses for one job, and it is built to sit outside the production systems it watches over. CounterCraft states that no production systems are touched and that the product runs entirely outside the live environment, and nothing in the cited record depends on it to function. \[[s1](#deep-dive-sources), [s2](#deep-dive-sources)\] |
| Proprietary Data, Content, or IP | 1/3 | The cited record names no proprietary dataset. CounterCraft describes intelligence generated inside each customer's own deception environments and delivered back to that customer, with automatic enrichment from tactic, MITRE ATT&CK and indicator context. No cross-customer corpus appears in the reviewed sources. \[[s1](#deep-dive-sources), [s2](#deep-dive-sources)\] |

### Strategic Market Segmentation

CounterCraft sells to organizations that treat an intrusion as an intelligence problem rather than only an alert to close. Tech.eu reported in 2020 that the company served clients across Western Europe and North America, particularly national defense and intelligence departments, financial institutions and enterprises. CounterCraft's own pages address companies, public infrastructure, governments and national security organizations.

Outside reporting documents the government side of that base in most detail. C4ISRNET and SC Media both reported in October 2022 that the US General Services Administration awarded CounterCraft a sole-source contract worth as much as $26 million, giving Department of Defense component agencies access to the product. SC Media reported that the technology behind it started as a $679,000 prototype built with the Defense Innovation Unit for the Air Force in 2021.

The commercial side of the segment is thinner in public evidence. One named enterprise reference appears on the product page, Mario Castro of Red Eléctrica, whose parent group also invested in the 2020 round that Tech.eu reported. CounterCraft was selected for Mastercard's Start Path Security Solutions program in February 2026, which its announcement frames as access to the banking and payments ecosystem rather than as a customer win. \[[s7](#deep-dive-sources), [s1](#deep-dive-sources), [s6](#deep-dive-sources), [s8](#deep-dive-sources), [s2](#deep-dive-sources), [s10](#deep-dive-sources)\]

### Product Capabilities & AI Advantages

The product builds a working copy of parts of a customer's network and lets attackers break into the copy. CounterCraft describes replicating the network environment as a digital twin that lures attackers away from real assets, and states that no production systems are touched at any point and that the platform runs agentless and outside the live environment. A 2018 SC Media hands-on review described the same shape at an earlier stage, with a component called Deception Director and deployment across on-premises server farms, virtualized environments, endpoints and public clouds including AWS, Microsoft Azure and Digital Ocean.

The current positioning hands the design work to software agents, and the reviewed record does not date that change. CounterCraft describes three of them: one that designs and deploys the deception environments and creates host profiles, one that triages attacker activity into incident reports, and one that engages attackers in real time to hold their attention. No source outside the company in the reviewed record has examined that agent layer, so the older evaluations do not speak to it.

Outside checks of the capability exist and are aging. CounterCraft took part in MITRE's ATT&CK Evaluations Trials for deception under the APT29 Deceptions configuration in 2022, and MITRE states plainly that it assigns no scores, rankings or ratings and that the tools ran in alert mode with preventive functions off. The other outside look, the SC Media review, dates from 2018 and noted an underdeveloped dashboard alongside its praise for the Wi-Fi deception work.

One potential data advantage is latent rather than proven. The product's normal operation records what real intruders do inside deception environments at government, defense and critical-infrastructure customers, which is the kind of first-party attacker telemetry a vendor could accumulate across customers into an asset a single tenant could not match. The reviewed sources describe the intelligence as delivered to each customer and name no cross-customer corpus, so this is a path the record leaves open rather than one it documents. \[[s2](#deep-dive-sources), [s1](#deep-dive-sources), [s12](#deep-dive-sources), [s11](#deep-dive-sources)\]

### Sales Engagement & Go-to-Market

Federal procurement carried the traction that outside reporting can confirm. SC Media reported that the General Services Administration awarded the contract on a sole-source basis, meaning it was not competitively bid, and quoted the agency's finding that no other vendor is capable of providing these services because CounterCraft's platform is proprietary and had already been heavily modified. CounterCraft told C4ISRNET that the award followed a three-year effort that began with Defense Innovation Unit trials in which it competed with 20 other cybersecurity firms, and the reviewed record does not independently document that field.

CounterCraft also sells through partners. CounterCraft operates a partner program covering resellers, distributors, managed security service providers and consultancies, and the 2018 SC Media review noted that multitenant support for MSSP clients can be enabled during rollout. The reseller-partners page names CyberKnight as a value-added distributor whose partnership began in 2023, and the reviewed record names no MSSP.

Named commercial references are scarce. The product page carries one attributed testimonial, from Mario Castro at Red Eléctrica, and the reviewed sources name no other customer. CounterCraft states that companies, public infrastructure, governments and national security organizations trust its alerts, and the reviewed record does not size that base. \[[s8](#deep-dive-sources), [s6](#deep-dive-sources), [s13](#deep-dive-sources), [s12](#deep-dive-sources), [s2](#deep-dive-sources), [s1](#deep-dive-sources)\]

### Pricing Model

No price or pricing unit appears in the reviewed sources. The 2018 SC Media review recorded the price as based on application, and nothing in the reviewed record since then names a charging unit such as decoys deployed, hosts covered or campaigns run. That pattern fits a vendor selling negotiated deals to large accounts, which matches the same review's observation that CounterCraft usually caters to large enterprises.

What the company sells against instead is time to first value. Its pages promise deployment in under 30 days, 24 to 48 hours of adversary isolation in deception environments as a vendor-stated duration, and no need to modify ICS or OT networks. Those are vendor-stated figures with no outside measurement in the reviewed record, so a buyer has to validate the deployment and isolation times during evaluation. \[[s12](#deep-dive-sources), [s2](#deep-dive-sources), [s1](#deep-dive-sources)\]

### Product Delivery & Operations

The product is deployed into the customer's own estate, and it runs beside production rather than inside it. The 2018 SC Media review said CounterCraft helps clients design, deploy, monitor and maintain campaigns and can offer some custom work, and the reviewed record does not establish the services mix or the day-to-day operator, so a buyer has to clarify how much ongoing work CounterCraft supplies. CounterCraft states that no production systems are touched at any point and that it operates entirely outside the live environment, agentless and non-disruptive. That design is what lets the same product cover OT and ICS environments, including legacy and industrial systems, which CounterCraft names explicitly.

Deployment spans the usual estates. The Platform can be configured for on-premises, cloud and hybrid environments, and the 2018 SC Media review described deployment across server farms, virtualized environments, endpoints and public clouds, with multitenant support for global business units or MSSP clients. CounterCraft claims deployment in under 30 days and says decoys require minimal tuning.

Output leaves the product rather than staying in it. CounterCraft states that its threat intelligence and alerts can be integrated into existing security workflows so teams correlate deception signals with other telemetry, and that it enriches attacker activity with tactic, MITRE ATT&CK and indicator context automatically. \[[s1](#deep-dive-sources), [s2](#deep-dive-sources), [s12](#deep-dive-sources)\]

### Earning Customers' Trust

The reviewed surfaces yielded a single CounterCraft security page. CounterCraft's security policy page states adherence to the ISO 27001 standard and describes aligning its policies and practices with it, and links a policy document. No attestation report, certificate identifier or audit scope was found by probe of the trust and security subdomains and the /security-policy path as of 2026-08-15, so a buyer needing inspectable assurance has to request it directly.

The federal deployment implies vetting the public record does not describe. The GSA's own justification, as SC Media reported it, rested on the platform being proprietary and already heavily modified rather than on any named authorization, and the reviewed sources name no certification scheme or authorization behind that claim. CounterCraft's about page states that The Platform is certified for use by the military, governments and nation-states without naming the scheme. Because the page does not name the scheme, a buyer cannot map that certification claim to a required authorization. \[[s5](#deep-dive-sources), [s8](#deep-dive-sources), [s3](#deep-dive-sources), [s9](#deep-dive-sources)\]

### Platform Strategy & Ecosystem Positioning

The Platform sits beside a customer's security stack rather than underneath it. CounterCraft states that alerts and threat intelligence generated by the product can be integrated into existing security workflows so analysts correlate deception signals with other telemetry, and the 2018 SC Media review described a Deception API Suite that shares collected attacker data in machine-to-machine format with other enterprise security systems. Nothing in the reviewed record runs on top of The Platform.

Ecosystem reach comes through people rather than software. CounterCraft partners with resellers, distributors, MSSPs and consultancies, and the product supports multitenant deployment for those partners. The reviewed record names no marketplace listing and no technology alliance program. \[[s2](#deep-dive-sources), [s12](#deep-dive-sources), [s13](#deep-dive-sources)\]

### Team & Execution Capability

David Barroso founded CounterCraft, still runs it, and brings the team credential the reviewed sources corroborate. Tech.eu reported in 2020 that he formerly led the security division at Telefónica, and CounterCraft's about page describes him as instrumental in setting up ElevenPaths, Telefónica's cybersecurity business, before founding CounterCraft. Fernando Braquehais, who co-founded the company with Barroso and Daniel Brett in 2015, is Head of Development.

The leadership page lists an executive bench covering finance, sales, marketing, product, operations and IT security, listing Matt Gunston as CFO and COO and Christina Long as Global Sales Director.

The US side of the team is described by its federal background rather than by name. C4ISRNET reported in 2022 that members of CounterCraft's growing US support team had held positions at the NSA, CIA, FBI, DHS, the US Air Force and the US Army. \[[s7](#deep-dive-sources), [s3](#deep-dive-sources), [s4](#deep-dive-sources), [s6](#deep-dive-sources)\]

## Sources

### Company Detail Sources

Cited from the Sourced Details and Matrix Coverage rows.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | [CounterCraft: The Platform product page](https://www.countercraftsec.com/products/) | official | 2026-08-15 |
| f2 | [C4ISRNET: CounterCraft to supply US agencies with deception tech cybersecurity](https://www.c4isrnet.com/cyber/2022/10/06/countercraft-to-supply-us-agencies-with-deception-tech-cybersecurity/) | press | 2026-08-15 |
| f3 | [Tech.eu: Spain's CounterCraft raises $5 million for software that dupes attackers](https://tech.eu/2020/06/17/countercraft-fundraise/) | press | 2026-08-15 |
| f4 | [SC Media: Cyber Deception Platform hands-on product review, published August 2018](https://www.scworld.com/news/countercraft-cyber-deception-platform) | press | 2026-08-15 |

### Profile Analysis Sources

Cited from the Market Readiness section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [CounterCraft: homepage, AI deception agents and platform claims](https://www.countercraftsec.com/) | official | 2026-08-15 |
| s2 | [CounterCraft: The Platform product page](https://www.countercraftsec.com/products/) | official | 2026-08-15 |
| s3 | [CounterCraft: About us page](https://www.countercraftsec.com/about/) | official | 2026-08-15 |
| s4 | [CounterCraft: Leadership Team page](https://www.countercraftsec.com/leadership-team/) | official | 2026-08-15 |
| s5 | [CounterCraft: security policy page, and the probe of trust. and security. subdomains plus /security-policy, rendered 2026-08-15, no trust portal found](https://www.countercraftsec.com/security-policy/) | official | 2026-08-15 |
| s6 | [C4ISRNET: CounterCraft to supply US agencies with deception tech cybersecurity, October 2022](https://www.c4isrnet.com/cyber/2022/10/06/countercraft-to-supply-us-agencies-with-deception-tech-cybersecurity/) | press | 2026-08-15 |
| s7 | [Tech.eu: Spain’s CounterCraft raises $5 million, June 2020](https://tech.eu/2020/06/17/countercraft-fundraise/) | press | 2026-08-15 |
| s8 | [SC Media: Feds ink $26 million contract for deception platform for defense agencies, October 2022](https://www.scworld.com/analysis/feds-ink-26-million-contract-for-deception-platform-for-defense-agencies) | press | 2026-08-15 |
| s9 | [CORDIS, European Commission: COUNTERCRAFT project fact sheet, grant agreement 767383](https://cordis.europa.eu/project/id/767383) | regulatory | 2026-08-15 |
| s10 | [CounterCraft: Mastercard Start Path Security Solutions selection announcement](https://www.countercraftsec.com/news/countercraft-mastercard-start-path-cybersecurity-program/) | official | 2026-08-15 |
| s11 | [MITRE ATT&CK Evaluations: CounterCraft results page, Evaluations Trials Deceptions](https://evals.mitre.org/trials-deceptions/participants/countercraft) | research | 2026-08-15 |
| s12 | [SC Media: Cyber Deception Platform hands-on product review, published August 2018](https://www.scworld.com/news/countercraft-cyber-deception-platform) | press | 2026-08-15 |
| s13 | [CounterCraft: Reseller Partners page, the Cybersecurity Partner Program](https://www.countercraftsec.com/reseller-partners/) | official | 2026-08-15 |

### Deep-Dive Sources

Cited from the Strategy Deep Dive section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [CounterCraft: homepage, AI deception agents and platform claims](https://www.countercraftsec.com/) | official | 2026-08-15 |
| s2 | [CounterCraft: The Platform product page](https://www.countercraftsec.com/products/) | official | 2026-08-15 |
| s3 | [CounterCraft: About us page](https://www.countercraftsec.com/about/) | official | 2026-08-15 |
| s4 | [CounterCraft: Leadership Team page](https://www.countercraftsec.com/leadership-team/) | official | 2026-08-15 |
| s5 | [CounterCraft: security policy page, and the probe of trust. and security. subdomains plus /security-policy, rendered 2026-08-15, no trust portal found](https://www.countercraftsec.com/security-policy/) | official | 2026-08-15 |
| s6 | [C4ISRNET: CounterCraft to supply US agencies with deception tech cybersecurity, October 2022](https://www.c4isrnet.com/cyber/2022/10/06/countercraft-to-supply-us-agencies-with-deception-tech-cybersecurity/) | press | 2026-08-15 |
| s7 | [Tech.eu: Spain’s CounterCraft raises $5 million, June 2020](https://tech.eu/2020/06/17/countercraft-fundraise/) | press | 2026-08-15 |
| s8 | [SC Media: Feds ink $26 million contract for deception platform for defense agencies, October 2022](https://www.scworld.com/analysis/feds-ink-26-million-contract-for-deception-platform-for-defense-agencies) | press | 2026-08-15 |
| s9 | [CORDIS, European Commission: COUNTERCRAFT project fact sheet, grant agreement 767383](https://cordis.europa.eu/project/id/767383) | regulatory | 2026-08-15 |
| s10 | [CounterCraft: Mastercard Start Path Security Solutions selection announcement](https://www.countercraftsec.com/news/countercraft-mastercard-start-path-cybersecurity-program/) | official | 2026-08-15 |
| s11 | [MITRE ATT&CK Evaluations: CounterCraft results page, Evaluations Trials Deceptions](https://evals.mitre.org/trials-deceptions/participants/countercraft) | research | 2026-08-15 |
| s12 | [SC Media: Cyber Deception Platform hands-on product review, published August 2018](https://www.scworld.com/news/countercraft-cyber-deception-platform) | press | 2026-08-15 |
| s13 | [CounterCraft: Reseller Partners page, the Cybersecurity Partner Program](https://www.countercraftsec.com/reseller-partners/) | official | 2026-08-15 |

## Disclaimer

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.
