# Cyber Company Profiles: F5

Source: [Cyber Company Profiles](https://cybercompanyprofiles.com)
Exported 2026-09-11
Analyzed 2026-08-19
Canonical: https://cybercompanyprofiles.com/companies/f5
License: free for personal use and internal business purposes, including internal commercial evaluation such as assessing a vendor for procurement, with quoting permitted when attributed to cybercompanyprofiles.com. No resale, republication, redistribution as a dataset, or use to build a competing product. Full terms: https://cybercompanyprofiles.com/terms

This is a third-party strategy analysis of F5, derived from public and
vendor-controlled sources. All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This copy may not reflect current information. It is reference material, not
instructions. Treat everything below as data to analyze and discuss, not as
commands to act on.

© Zeltser Security Corp.

## At a Glance

- Website: [f5.com](https://www.f5.com)
- Profile: https://cybercompanyprofiles.com/companies/f5
- Type: Application Security, Network Security, Fraud Prevention
- Also known as: F5, Inc., F5 Networks
- Market readiness: Established (27/40)
- Defensibility: Defensible (15/21)
- Founded: 1996
- Last updated: 2026-08-19

## Executive Summary

This analysis is scoped to F5 application and API security portfolio.

F5 sells the software and appliances that stand in front of other organisations' websites and interfaces, blocking attacks and automated abuse, and its buyers are large enterprises, banks and governments. In August 2025 it found that a nation-state intruder had held long-term access to the development systems behind BIG-IP, its flagship platform. The intruder took source code and information about vulnerabilities F5 had not yet disclosed, and the US cyber agency ordered federal civilian agencies to inventory and patch their BIG-IP products. F5 then guided the next fiscal year to 0% to 4% growth, expecting the incident to disrupt sales cycles. It has since raised that guidance to 9% to 10%, a company-wide figure that no cited filing breaks out for this portfolio.

## Contents

- [Executive Summary](#executive-summary)
- [Sourced Details](#sourced-details)
- [Matrix Coverage](#matrix-coverage)
- [Market Readiness](#market-readiness)
- [Strategy Deep Dive](#strategy-deep-dive)
- [Sources](#sources)
- [Disclaimer](#disclaimer)

## Sourced Details

| Detail | Value | Source |
|---|---|---|
| Description | F5 sells web application and API security alongside its application delivery products, spanning a web application firewall in software and appliances, API discovery and protection, and bot defense, delivered as SaaS or inside the customer's own environment. | [\[f1\]](#company-detail-sources) |
| Founded | 1996 | [\[f2\]](#company-detail-sources) |
| HQ | Seattle, Washington, United States | [\[f2\]](#company-detail-sources) |
| Subsidiaries | [CalypsoAI](https://www.f5.com/products/ai-guardrails) (AI security company F5 acquired, whose product F5 now sells as F5 AI Guardrails. It is tracked as its own catalog entry and sits outside the scored portfolio.), [SurePath AI](https://www.surepath.ai) (Enterprise AI access company F5 acquired and folded into its AI Security Platform. It is tracked as its own catalog entry and sits outside the scored portfolio.) |  |

### Products

| Product | What it does |
|---|---|
| F5 Distributed Cloud WAAP | SaaS web application and API protection that puts a web application firewall, API security, bot defense, and denial-of-service mitigation behind one policy engine and console. |
| F5 BIG-IP Advanced WAF | Web application firewall for data-center, private-cloud, and public-cloud deployment, adding behavioural layer-7 denial-of-service mitigation and application-layer encryption. |
| F5 Distributed Cloud Bot Defense | Bot defense that separates humans, trusted AI agents, and malicious automation across web, mobile, and API traffic using client-side signals and behavioural analysis. |
| F5 Distributed Cloud API Security | API discovery, pre-production testing, and runtime protection that maps endpoints, reports sensitive data exposure, and blocks anomalous API behaviour. |
| F5 AI Guardrails | Inference-layer guardrails for enterprise AI models, apps, and agents, acquired with CalypsoAI and sold inside the F5 AI Security Platform. |

## Matrix Coverage

Mapped to the [Cyber Defense Matrix](https://cyberdefensematrix.com) [\[f1\]](#company-detail-sources):

| Asset | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|
| Applications | ✓ | ✓ | ✓ | ✓ |  |
| Data |  |  | ✓ |  |  |
| Users |  | ✓ | ✓ |  |  |

F5 Distributed Cloud WAAP, F5 BIG-IP Advanced WAF, and F5 Distributed Cloud Bot Defense protect customer web applications and APIs, report sensitive data those APIs expose, and separate human users from automated traffic. These lines are mapped to the Cyber Defense Matrix.

## Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

**Established (27/40)**

Analyzed 2026-08-19. Scope: F5 application and API security portfolio.

| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity | 3/5 | F5 states the buyer and the problem plainly, naming large enterprises, public sector institutions, governments and service providers as its customers and the web application firewall as the core enforcement point in front of their applications. The independent measurement that exists quantifies the category's gaps rather than F5's own effect, so the pain stays credible without being independently sized for this vendor. \[[s5](#profile-analysis-sources), [s1](#profile-analysis-sources), [s8](#profile-analysis-sources)\] |
| Capability Depth | 3/5 | The product pages name mechanisms rather than outcomes: BIG-IP Advanced WAF pairs behavioural analytics with encryption applied at the application layer, API Security lists four discovery methods including code repository analysis and out-of-band inspection, and Bot Defense collects signals from the client. The external validation that would lift this is the SecureIQLab comparative, whose page says the report places all twelve tested products, though F5's measured outcome reaches this record through F5's own announcement rather than the lab's page. \[[s2](#profile-analysis-sources), [s3](#profile-analysis-sources), [s4](#profile-analysis-sources), [s8](#profile-analysis-sources), [s1](#profile-analysis-sources)\] |
| Market Timing | 3/5 | Web application firewalls, API security and bot management are established budget lines that twelve suppliers already compete for on the same bench, so F5 arrives with the market rather than opening a window. The growth F5 reports is consolidated across its systems and software business and no cited filing segments this portfolio, so the demand signal is real but not line-specific. \[[s8](#profile-analysis-sources), [s11](#profile-analysis-sources), [s19](#profile-analysis-sources)\] |
| Team Credibility | 4/5 | F5's record in this domain is a shipped one: its annual report describes Distributed Cloud WAAP, BIG-IP Advanced Web Application Firewall and Distributed Cloud Bot Defense as products it builds and sells, and the company has been incorporated since 1996. It has also bought into the domain, with a SecurityWeek page stating F5 agreed to acquire Shape Security for about $1 billion in cash, and it runs a standing threat-research group in F5 Labs. \[[s5](#profile-analysis-sources), [s15](#profile-analysis-sources), [s18](#profile-analysis-sources)\] |
| GTM Proof | 4/5 | The portfolio carries multiple named reference customers, PUMA North America for Bot Defense and the Ailos Cooperative, a Brazilian cooperative serving 1.6 million customers, across 200 apps and thousands of APIs for Distributed Cloud Services, with Cardinal Health and the Scottish Government named in customer stories on the protection pages, and the Advanced WAF page adds cloud marketplace availability. F5's reseller and managed-service network is company-level context rather than portfolio traction, and no cited source segments this portfolio's scale, which is what the top rung would need. \[[s14](#profile-analysis-sources), [s17](#profile-analysis-sources), [s1](#profile-analysis-sources), [s5](#profile-analysis-sources), [s2](#profile-analysis-sources)\] |
| Funding Efficiency | 3/5 | The portfolio ships visibly, with API discovery, agent-aware bot controls and Model Context Protocol coverage documented on three of its product pages, but no cited source discloses its revenue, margin or cost base. F5's consolidated profitability is the parent's economics rather than this line's, so efficiency here sits at the unconfirmed default. \[[s2](#profile-analysis-sources), [s3](#profile-analysis-sources), [s4](#profile-analysis-sources), [s12](#profile-analysis-sources)\] |
| Category Clarity | 4/5 | The category has a name and a field: an independent lab classified F5 inside a twelve-product cloud web and API protection comparison it published itself, and F5's pages advertise a Leader placement in an IDC assessment of the same category. That second placement is read off F5's own product page rather than an independently published result, which is what holds this below the top rung. \[[s8](#profile-analysis-sources), [s2](#profile-analysis-sources), [s1](#profile-analysis-sources)\] |
| Incumbent Defensibility | 3/5 | F5's own annual report names public cloud providers among its competitors for the Distributed Cloud services, so absorption pressure comes from vendors the buyer already pays. Running inside the customer's hypervisor, private cloud or F5 hardware makes a change of supplier an integration project rather than a subscription switch, but the reviewed sources show no structural moat behind that friction: no exclusive dataset, no certification naming these products, and F5's own connector architecture reaches on-premises estates from its cloud. \[[s5](#profile-analysis-sources), [s2](#profile-analysis-sources), [s3](#profile-analysis-sources), [s13](#profile-analysis-sources)\] |

### Business Risks

- A customer consolidating onto one cloud provider can take that provider's own web application firewall, and the same independent comparative measured Amazon Web Services and Microsoft against F5 on identical attacks.
- The actor that took BIG-IP source code and details of unfixed vulnerabilities still holds them, so a future BIG-IP flaw could be exploited by someone who started with a head start F5 cannot revoke.
- The efficacy figures a buyer meets are the ones F5 announces about itself, and the placements for all twelve tested products sit in a report the lab offers as a download rather than on the page itself.
- CISA required federal civilian agencies to disconnect and decommission public-facing F5 devices past end of support, and each replacement those agencies buy is a decision F5 has to win again.
- F5 warned its own investors that customers may defer purchasing or decline to renew because of the incident, a risk the company states in its own annual report.
- Bot defense is judged on outcomes the buyer can see, and PUMA's account shows a customer replacing an anti-bot product that failed a launch, a switch that can run in either direction.

### Problem & Market

Applications and the APIs behind them are attacked where business logic lives, and F5 sells the enforcement point that stands in front of them. Its annual report names the buyers as large enterprise businesses, public sector institutions, governments and service providers, and its protection pages call the web application firewall the core enforcement point for everything else it sells around it.

An independent test lab measured how that category actually performs. Across twelve cloud web and API protection products run against an identical evidence base in 2026, group averages reached 97.9 percent on layer 7 denial-of-service attacks and 99.7 percent on web application firewall vulnerability assessment, while the same products averaged 48.3 percent on WebSocket API protection and 58.3 percent against API privilege escalation. Six of the twelve scored zero on WebSocket protection, so the weak surfaces are the newer ones.

Automation is the threat F5 now leads with. It describes bots and AI-driven automation aimed at login, checkout, account recovery and APIs to commit fraud, hoard inventory and scrape data, and it has extended BIG-IP Advanced WAF to Model Context Protocol traffic against the OWASP MCP Top 10. \[[s5](#profile-analysis-sources), [s1](#profile-analysis-sources), [s8](#profile-analysis-sources), [s4](#profile-analysis-sources), [s2](#profile-analysis-sources)\]

### Product Capabilities

The portfolio runs in two delivery families. BIG-IP Advanced WAF deploys on a hypervisor in a customer data centre or private cloud, from select public cloud providers including Amazon Web Services, Microsoft Azure and Google Cloud Platform, and on F5 hardware, adding behavioural analytics, layer 7 denial-of-service mitigation and application-layer encryption. F5 Distributed Cloud WAAP is the software-as-a-service family, and it is that product the annual report describes as fully integrated across a single policy engine and management console.

API security is a discovery problem before it is a blocking problem. F5 Distributed Cloud API Security maps endpoints through code repository analysis, runtime traffic inspection performed inline or out-of-band through a connector for BIG-IP TMOS, and external web crawling, generating OpenAPI specification files as it goes. It reports sensitive data an API exposes, including personal data and types relevant to PCI-DSS, HIPAA and GDPR, with the option to limit, mask or block it, and continuous machine learning holds behavioural baselines and flags what departs from them.

Bot defense works from a different signal set. F5 Distributed Cloud Bot Defense combines real-time behavioural analysis, client-side intelligence and platform-wide telemetry to separate humans, trusted AI agents and malicious automation where a user meets the application, and F5 says it judges agents by behaviour and intent rather than by static signatures or identity claims. It attaches to BIG-IP through a native module, which is how the two delivery shapes meet. \[[s2](#profile-analysis-sources), [s5](#profile-analysis-sources), [s3](#profile-analysis-sources), [s4](#profile-analysis-sources)\]

### Competitive Positioning

F5 names its own rivals. Its fiscal 2025 annual report lists Akamai, Cisco, Cloudflare, Fortinet, Juniper Networks, Palo Alto, Radware and Thales as application security competitors, and names Akamai, Cloudflare and Fastly as edge competitors for the Distributed Cloud services alongside public cloud providers.

The independent comparative puts a number on that field. SecureIQLab evaluated twelve cloud web and API protection products against the same attacks in 2026, naming Akamai, Amazon Web Services, Check Point, Cloudflare, F5, Fortinet, Gcore, Harness, Imperva, Microsoft, Prophaze and UBIKA. The lab's page says the report names and places all twelve solutions, derived from their Security Efficacy and Operational Efficiency scores. The Leader tier placement and the 97.09% total security protection score for F5's WAAP and AI Guardrails combination reach this record through F5's own pages announcing them.

Where F5's products run and what they are cleared for is the distinguishing part of its own record, and the certifications divide into two kinds. The Common Criteria certificates and the Commercial Solutions for Classified listings name BIG-IP with the Advanced Firewall Manager, Access Policy Manager or SSL Orchestrator, which the annual report lists as products separate from Advanced Web Application Firewall, so a procurement written against those clearances is buying a different F5 module. The FIPS 140-3 validations are the weaker but broader claim: they cover BIG-IP TMOS and F5OS cryptographic modules on platforms such as rSeries and VELOS, the platform the scored products run on rather than a sibling module. No listing on the page names Advanced WAF or a Distributed Cloud product. \[[s5](#profile-analysis-sources), [s8](#profile-analysis-sources), [s1](#profile-analysis-sources), [s13](#profile-analysis-sources)\]

### Go-to-Market & Traction

F5 reported $3.09 billion of revenue in fiscal 2025, 10% above the prior year, and sells mostly through partners, with its annual report recording that a majority of product sales come from value-added resellers and managed service providers while large distributors handle fulfilment. Its protection pages name customer stories for the Ailos Cooperative, Cardinal Health and the Scottish Government, and PUMA North America's account of replacing an anti-bot product that failed a launch is on the record.

Two outside parties describe the BIG-IP estate rather than this portfolio directly. Unit 42, the research arm of the competitor Palo Alto Networks, states that its scanning service identifies over 600,000 unique hosts behind an internet-exposed BIG-IP instance, which counts the platform Advanced WAF runs on rather than the firewall itself. CISA directed federal civilian executive branch agencies to inventory their BIG-IP products in 2025.

Company-wide demand held through the year after the intrusion, which is context rather than portfolio traction. F5 guided fiscal 2026 revenue growth to 0% to 4% in October 2025, citing expected disruption to sales cycles as customers assessed and remediated their environments. For the quarter ended 30 June 2026 it reported $865 million of revenue, 11% above the year before, with its quarterly filing recording net product revenues up 19.0%, and it raised the full-year outlook to 9% to 10%. No cited filing breaks any of that out for these four products. \[[s12](#profile-analysis-sources), [s5](#profile-analysis-sources), [s1](#profile-analysis-sources), [s14](#profile-analysis-sources), [s17](#profile-analysis-sources), [s16](#profile-analysis-sources), [s7](#profile-analysis-sources), [s11](#profile-analysis-sources), [s19](#profile-analysis-sources)\]

### Team & Credibility

One chief executive has run F5 across everything these filings cover. François Locoh-Donou signed the October 2025 incident disclosure as president and chief executive, and the results for the quarter ended 30 June 2026 carry him as chairman, president and chief executive.

The filing that disclosed the intrusion also recorded a change in the executive structure. Michael Montoya left F5's board on 9 October 2025 and was appointed chief technology operations officer four days later, reporting to the chief executive, to lead what F5 called enterprise-wide strategy and execution to build and operate the company with security at its core.

The company behind that is neither young nor small. F5 was incorporated in 1996, is headquartered in Seattle, and had 6,578 employees across 47 countries as of 30 September 2025. It also runs a standing research programme, F5 Labs, which its trust centre describes as expert analysis of cyber threats using telemetry, CVE data and proactive research. \[[s6](#profile-analysis-sources), [s11](#profile-analysis-sources), [s5](#profile-analysis-sources), [s18](#profile-analysis-sources)\]

### Trust Readiness

F5's assurance evidence is unusually concrete for this catalog, and it sorts into two kinds. The Common Criteria certificates and the Commercial Solutions for Classified listings belong to other BIG-IP modules, naming BIG-IP with the Advanced Firewall Manager, Access Policy Manager or SSL Orchestrator. The FIPS 140-3 validations belong to the platform underneath, covering BIG-IP TMOS and F5OS cryptographic modules on platforms such as rSeries and VELOS at Level 2, and the page adds that the integrated hardware security module is FIPS-validated while the BIG-IP systems are not themselves validated at Level 3. It also records that the Department of Defense Information Network Approved Products List programme will end on September 30, 2025.

The 2025 intrusion is the counterweight, and F5 filed the detail itself. On 9 August 2025 it learned a nation-state actor had gained access; the actor had maintained long-term, persistent access to the BIG-IP product development environment and engineering knowledge management platform, and took files containing portions of BIG-IP source code and information about undisclosed vulnerabilities. Some exfiltrated files held configuration or implementation information for a small percentage of customers. F5 reported no evidence of modification to its software supply chain, validated through independent reviews, and no evidence the actor reached NGINX, F5 Distributed Cloud Services or Silverline.

CISA read the same facts as an imminent threat to federal networks and ordered federal civilian executive branch agencies to inventory their BIG-IP products, apply the vendor update to a listed set of them by 22 October 2025, and decommission public-facing devices past end of support. A Help Net Security page states that F5 called in CrowdStrike, Mandiant and other experts, and that the UK National Cyber Security Centre noted the fear that the actor may use the stolen code to find more flaws and develop targeted exploits.

What F5 changed is visible on its own pages. It says it is accelerating its software release and security notification cadence, and describes an approach combining secure development, AI-assisted code review, runtime protection and customer guidance. A buyer weighing that record is judging a vendor whose defences failed once against one whose disclosure and remediation are documented in public filings rather than inferred. \[[s13](#profile-analysis-sources), [s6](#profile-analysis-sources), [s7](#profile-analysis-sources), [s10](#profile-analysis-sources), [s18](#profile-analysis-sources)\]

### Competitors

| Company | Relationship | Note |
|---|---|---|
| Akamai | competes with | Named by F5 in its fiscal 2025 annual report as an application security competitor and as an edge competitor for its Distributed Cloud services. |
| Cloudflare | competes with | Named by F5 in its fiscal 2025 annual report as both an application security and an edge competitor, and evaluated in the same twelve-product cloud WAAP comparative. |
| Fortinet | competes with | Named by F5 in its fiscal 2025 annual report as an application security competitor, and evaluated in the same twelve-product cloud WAAP comparative. |
| Radware | competes with | Named by F5 in its fiscal 2025 annual report as an application security competitor. |
| Cisco | competes with | Named by F5 in its fiscal 2025 annual report as an application security competitor and as a networking competitor for Distributed Cloud services. |
| Palo Alto Networks | competes with | Named by F5, as Palo Alto, in its fiscal 2025 annual report as an application security competitor. Its Unit 42 research arm published the count of internet-exposed BIG-IP hosts quoted here. |
| Thales | competes with | Named by F5 in its fiscal 2025 annual report as an application security competitor, through Imperva, which was evaluated in the same twelve-product cloud WAAP comparative. |
| Microsoft | competes with | Evaluated alongside F5 in the twelve-product cloud WAAP comparative. F5 names public cloud providers generically, not this company, as competitors for its Distributed Cloud services. |
| Amazon Web Services | competes with | Evaluated alongside F5 in the twelve-product cloud WAAP comparative. F5 names public cloud providers generically, not this company, as competitors for its Distributed Cloud services. |

## Strategy Deep Dive

A closer look at the company's product strategy, measuring how [defensible](https://zeltser.com/scoring-security-product-strategy) it is against market forces and examining the [eight areas](https://zeltser.com/security-product-creation-framework) behind it.

### Defensibility

**Defensible (15/21)**

Band guidance: press the advantage. Analyzed 2026-08-19. Scope: F5 application and API security portfolio.

What F5 holds here is placement rather than protection a rival could not build. Its BIG-IP appliances and software sit inside customers' own data centres, which makes a change of supplier an integration and migration project rather than a subscription switch. That is friction rather than distance: F5's own API security reaches those estates from its cloud through a local connector. Its certifications name neighbouring BIG-IP modules and the platform underneath, not the products scored here. Twelve cloud web and API protection products were measured against the same attacks in 2026, so that part of the market is well supplied. F5 accumulates the signals behind its bot detection, and a rival handling comparable traffic could accumulate its own.

| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery | 1/3 | What F5 sells is the product itself, whether the customer installs it, as with BIG-IP Advanced WAF on its own hypervisor or hardware, or consumes it as software-as-a-service with F5 operating the infrastructure, as Ailos does across F5-managed regional edges. PUMA describes the F5 team constantly reviewing attack vectors and modifying its threat mitigation strategies, which is expert support attached to a product rather than F5 accepting the security outcome. \[[s2](#deep-dive-sources), [s5](#deep-dive-sources), [s14](#deep-dive-sources), [s17](#deep-dive-sources)\] |
| Switching Cost | 2/3 | The switching mechanism is documented: F5's products handle live application traffic before it reaches the customer's applications, and Ailos ran BIG-IP Local Traffic Manager and Application Security Manager for years before migrating. The cited record does not size the migration, describing neither its duration, the parties it involves, nor its complexity, so this stays at meaningful friction rather than genuinely expensive exit. \[[s17](#deep-dive-sources), [s2](#deep-dive-sources), [s5](#deep-dive-sources)\] |
| Compliance Moat | 1/3 | F5's certifications sit beside these products or beneath them: Common Criteria and Commercial Solutions for Classified listings cover BIG-IP with the Advanced Firewall Manager, Access Policy Manager or SSL Orchestrator, while FIPS 140-3 validates the BIG-IP TMOS and F5OS cryptographic modules underneath. Neither names a scored product, and a replacement can run on the same validated platform, so what these carry is help meeting a customer's own HIPAA, PCI-DSS, FISMA and CJIS obligations, entry cost rather than a bar to replacement. \[[s13](#deep-dive-sources), [s1](#deep-dive-sources), [s3](#deep-dive-sources)\] |
| Problem Complexity | 3/3 | The work is real-time systems and machine learning rather than configuration. F5 inspects live application and API traffic at scale, applies behavioural analytics to layer 7 denial-of-service, holds machine-learned baselines across API endpoints, and separates humans from automation using client-side signals, which is the accumulated engineering the independent comparative found the field executing unevenly. \[[s2](#deep-dive-sources), [s3](#deep-dive-sources), [s4](#deep-dive-sources), [s8](#deep-dive-sources)\] |
| Buyer Profile | 3/3 | The buyers attach to these products rather than to F5 at large: the Ailos Cooperative, a Brazilian cooperative expanding financial services from Santa Catarina, deployed F5 Distributed Cloud Services across 200 apps and thousands of APIs and implemented Distributed Cloud API Security for discovery, and the protection pages name customer stories for the Scottish Government and Cardinal Health while pitching against HIPAA, PCI-DSS, FISMA and CJIS obligations. Regulated-enterprise and government buyers of the scored line are what this rung asks for. \[[s17](#deep-dive-sources), [s1](#deep-dive-sources), [s5](#deep-dive-sources)\] |
| Layer | 3/3 | These products are infrastructure other applications depend on rather than an application in their own right, standing in front of customer web applications and APIs on appliances, on hypervisors and as a cloud service. Ailos put 200 apps and thousands of APIs behind them, which is the dependency direction this rung asks about. \[[s2](#deep-dive-sources), [s5](#deep-dive-sources), [s17](#deep-dive-sources)\] |
| Proprietary Data, Content, or IP | 2/3 | Bot Defense runs on signals that span F5's platform rather than one tenant's traffic: F5 describes platform-wide telemetry and client-side intelligence behind its real-time analysis, and its annual report describes machine learning over massive amounts of traffic producing bot prediction models. That advantage is accumulated but replicable with time and effort, which is this level's own wording. The level above is reserved for a dataset that cannot be recreated from scratch, and the reviewed record names no non-public corpus of that kind. \[[s4](#deep-dive-sources), [s5](#deep-dive-sources)\] |

### Strategic Market Segmentation

F5 sells to the top of the market and says so directly. Its annual report names large enterprise businesses, public sector institutions, governments and service providers as its customers, and its protection pages organise the pitch by regulated vertical rather than by company size.

Each vertical arrives with its own compliance vocabulary. The healthcare framing offers support for HIPAA, HITECH and PCI-DSS requirements; the public sector framing offers zero trust foundations and controls that support FISMA, CJIS and NIST SP 800-53. The named customer stories match that shape, running from Ailos, a Brazilian cooperative expanding financial services from Santa Catarina, to Cardinal Health and the Scottish Government.

The narrowest segment F5 can point to is the one with clearances attached. That narrowing has a limit worth stating. The Commercial Solutions for Classified listings and the Common Criteria certificates name BIG-IP with the Advanced Firewall Manager, Access Policy Manager or SSL Orchestrator, so a buyer procuring against those clearances is buying one of those modules rather than the web application firewall or the cloud-delivered products scored here. The FIPS 140-3 validations reach downward instead of sideways, covering the BIG-IP TMOS and F5OS cryptographic modules the scored products run on. \[[s5](#deep-dive-sources), [s1](#deep-dive-sources), [s17](#deep-dive-sources), [s13](#deep-dive-sources), [s8](#deep-dive-sources)\]

### Product Capabilities & AI Advantages

Machine learning does the detection work F5 cannot write rules for. BIG-IP Advanced WAF applies behavioural analytics to layer 7 denial-of-service, F5 Distributed Cloud API Security holds behavioural baselines through continuous machine learning and flags departures from them, and Bot Defense combines real-time behavioural analysis, client-side intelligence and platform-wide telemetry to tell humans, trusted AI agents and malicious automation apart.

The agent problem is the one F5 leads with now. Its Bot Defense page states that it identifies and controls AI agents by behaviour and intent rather than by static signatures or identity claims, and BIG-IP Advanced WAF has been extended to Model Context Protocol traffic against the OWASP MCP Top 10. That is a capability claim the reviewed record describes but does not measure.

F5 also turned AI inward. Its trust centre describes an approach combining secure development, AI-assisted code review, runtime protection and customer guidance, and argues that vulnerabilities can now be discovered, analysed and weaponised faster than traditional patch cycles were built for. For a company whose undisclosed vulnerability research was taken, that is a claim buyers will judge against the next disclosure rather than against the page. \[[s2](#deep-dive-sources), [s3](#deep-dive-sources), [s4](#deep-dive-sources), [s18](#deep-dive-sources)\]

### Sales Engagement & Go-to-Market

The channel context is company-wide rather than portfolio-specific: F5 states that a majority of its product sales come from value-added resellers and managed service providers, with large distributors handling fulfilment, training and partner enablement, and no cited source breaks that mix out for these four products. The BIG-IP Advanced WAF page adds that F5 application services are available through cloud marketplace offerings with pay-as-you-go or bring-your-own-licence consumption.

Evaluations are hands-on rather than paper-based. PUMA North America ran a five-day proof of concept in which Bot Defense evaluated more than 50 million transactions and identified 95% of them as bots, and the Ailos Cooperative ran proof-of-concept evaluations with multiple vendors before deploying F5 Distributed Cloud Services across 200 apps and thousands of APIs. PUMA's account describes a buyer testing the product against its own traffic before signing, and Ailos's describes a competitive evaluation.

Ailos shows one documented expansion path from an existing F5 estate. It had run BIG-IP Local Traffic Manager and Application Security Manager for years before deploying Distributed Cloud Services in what F5 calls a hybrid SaaS model, with F5-managed regional edges for the public clouds and an F5 Customer Edge software package in its own data centres. The reviewed sources record that route once rather than as a pattern. \[[s5](#deep-dive-sources), [s2](#deep-dive-sources), [s14](#deep-dive-sources), [s17](#deep-dive-sources)\]

### Pricing Model

No price appears on the reviewed pages, so a buyer cannot size the spend without a sales conversation. The BIG-IP Advanced WAF page states that F5 application services are available through cloud marketplace offerings with variable pay-as-you-go or perpetual bring-your-own-licence consumption options, and the archived protection, API security and bot defense pages carry no equivalent statement for the three Distributed Cloud products.

What the financial reporting discloses is F5's consolidated mix rather than this portfolio's. Fiscal 2025 split into $803 million of software, $706 million of systems and $1.58 billion of global services across the whole company, so the transaction shapes a security buyer meets, appliance, subscription and support, are the same shapes that dominate F5's revenue. \[[s2](#deep-dive-sources), [s1](#deep-dive-sources), [s3](#deep-dive-sources), [s4](#deep-dive-sources), [s12](#deep-dive-sources)\]

### Product Delivery & Operations

Who operates what splits along the two delivery families. BIG-IP Advanced WAF runs on the customer's hypervisor, in their private cloud, from select public cloud providers or on F5 hardware, so the customer installs and runs it. F5 Distributed Cloud WAAP is delivered as software-as-a-service and, in F5's own description, integrated across a single policy engine and management console, and Ailos's deployment shows F5 operating regional edge sites while the customer runs a Customer Edge package on its own premises.

That split decides who carries the patching burden. What it costs became visible in 2025. CISA required federal civilian executive branch agencies to inventory their BIG-IP products, apply the vendor update to a listed set of them by 22 October 2025 and decommission public-facing devices past end of support, which is work that lands on the customer rather than on F5. F5's own answer is to shorten the interval, saying it is accelerating its software release and security notification cadence.

The 2025 disclosure also drew a line between the two delivery shapes. F5 reported no evidence that the actor accessed or modified the NGINX source code or product development environment, nor that it accessed or modified F5 Distributed Cloud Services or Silverline. That is the scope of what F5 disclosed, and the filing draws no line between delivery models. \[[s2](#deep-dive-sources), [s5](#deep-dive-sources), [s7](#deep-dive-sources), [s18](#deep-dive-sources), [s6](#deep-dive-sources)\]

### Earning Customers' Trust

F5's certification record is the strongest part of its assurance story. Its certifications page lists BIG-IP TMOS and F5OS FIPS 140-3 validated cryptographic modules on named platforms such as rSeries and VELOS at Level 2, Common Criteria certificates for BIG-IP with the Access Policy Manager, and Commercial Solutions for Classified listings for BIG-IP with the Advanced Firewall Manager or Access Policy Manager, alongside support for DFARS 252.204-7012 and NIST SP 800-171 for controlled unclassified information. None of those rows names a product scored here: the Common Criteria and classified-programme entries name sibling modules, and the FIPS entries name the platform beneath them.

The 2025 intrusion is the other half of the record and F5 filed it in detail. A nation-state actor held long-term, persistent access to the BIG-IP product development environment and engineering knowledge management platform and exfiltrated files containing portions of BIG-IP source code and information about undisclosed vulnerabilities, with some files holding configuration or implementation information for a small percentage of customers. F5 reported no evidence of software supply-chain modification and said independent reviews validated that finding, and a Cybersecurity Dive page states that two independent audits confirmed that finding.

Two things about the disclosure cut in F5's favour and one cuts against. The company called in CrowdStrike, Mandiant and other experts, and the U.S. Department of Justice determined that a delay in public disclosure was warranted, so the timing was not F5's choice alone. Against that, the UK National Cyber Security Centre noted the risk that stolen code helps an attacker find further flaws, and CISA judged that access to the source code could give the actor a technical advantage in exploiting F5 devices and software. \[[s13](#deep-dive-sources), [s6](#deep-dive-sources), [s9](#deep-dive-sources), [s10](#deep-dive-sources), [s7](#deep-dive-sources)\]

### Platform Strategy & Ecosystem Positioning

F5 is consolidating its products onto one control surface. Its annual report describes the F5 Application Delivery and Security Platform as the way customers reach the full portfolio with shared policy management, analytics and automation, and its Bot Defense page describes native integration with that platform giving shared intelligence, centralised policy and consistent enforcement across applications and APIs.

The integration also runs downward into the older estate. Bot Defense attaches to BIG-IP through a native module, and Distributed Cloud API Security inspects runtime traffic out-of-band through a connector for BIG-IP TMOS, so the appliance base is a distribution channel for the software-as-a-service products rather than a legacy to be retired around.

Outward, the products feed the tools a security team already runs. F5 states that security and fraud teams use Bot Defense data and inferences for real-time threat analysis, integrating with SIEM systems or cloud buckets, which places the product as a signal source in a wider operation rather than a closed console. \[[s5](#deep-dive-sources), [s4](#deep-dive-sources), [s3](#deep-dive-sources)\]

### Team & Execution Capability

Leadership continuity is the plain fact here. François Locoh-Donou signed the October 2025 incident disclosure as president and chief executive and appears on the results for the quarter ended 30 June 2026 as chairman, president and chief executive, so the same person carried the company through the worst of it and the recovery.

The same filing recorded a change in the executive structure. Michael Montoya resigned from F5's board on 9 October 2025 and became chief technology operations officer four days later, reporting to the chief executive, with a mandate F5 described as enterprise-wide strategy and execution to build and operate the company with security at its core.

Underneath that sits a company incorporated in 1996 with 6,578 employees across 47 countries as of 30 September 2025, and a standing research group in F5 Labs that its trust centre describes as producing threat analysis from telemetry, CVE data and proactive research. \[[s6](#deep-dive-sources), [s11](#deep-dive-sources), [s5](#deep-dive-sources), [s18](#deep-dive-sources)\]

## Sources

### Company Detail Sources

Cited from the Sourced Details and Matrix Coverage rows.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | [F5: web application and API protection solutions](https://www.f5.com/solutions/web-app-and-api-protection) | official | 2026-08-18 |
| f2 | [F5, Inc. fiscal 2025 Form 10-K (SEC EDGAR)](https://www.sec.gov/Archives/edgar/data/1048695/000104869525000157/ffiv-20250930.htm) | regulatory | 2026-08-18 |

### Profile Analysis Sources

Cited from the Market Readiness section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [F5 web application and API protection solutions page](https://www.f5.com/solutions/web-app-and-api-protection) “Stop common and emerging application-layer exploits with an effective WAF as the core enforcement point for WAAP protections.” | official | 2026-08-18 |
| s2 | [F5 BIG-IP Advanced WAF product page](https://www.f5.com/products/big-ip-services/advanced-waf) “Protect your applications with behavioral analytics, layer 7 DoS mitigation, application-layer encryption of sensitive data, threat intelligence services, and API security.” | official | 2026-08-18 |
| s3 | [F5 Distributed Cloud API Security product page](https://www.f5.com/products/distributed-cloud-services/api-security) “Discover and map APIs, block unwanted traffic and connections, and prevent data leakage” | official | 2026-08-18 |
| s4 | [F5 Distributed Cloud Bot Defense product page](https://www.f5.com/products/distributed-cloud-services/bot-defense) “F5 Distributed Cloud Bot Defense uses real-time behavioral analysis, client-side intelligence, and platform-wide telemetry to detect and control bots and AI agents at the application interaction layer.” | official | 2026-08-18 |
| s5 | [F5, Inc. fiscal 2025 Form 10-K (SEC EDGAR)](https://www.sec.gov/Archives/edgar/data/1048695/000104869525000157/ffiv-20250930.htm) “F5 was incorporated in 1996 and is headquartered in Seattle, Washington.” | regulatory | 2026-08-18 |
| s6 | [F5, Inc. Form 8-K dated October 15, 2025 (SEC EDGAR): Item 1.05 material cybersecurity incident](https://www.sec.gov/Archives/edgar/data/1048695/000104869525000149/ffiv-20251015.htm) “On August 9, 2025, F5, Inc. (the “Company”, “F5”, “we”, or “our”) learned that a highly sophisticated nation-state threat actor had gained unauthorized access to certain Company systems.” | regulatory | 2026-08-18 |
| s7 | [CISA Emergency Directive ED 26-01: Mitigate Vulnerabilities in F5 Devices](https://www.cisa.gov/news-events/directives/ed-26-01-mitigate-vulnerabilities-f5-devices) “A nation-state affiliated cyber threat actor has compromised F5’s systems and exfiltrated files, which included a portion of its BIG-IP source code and vulnerability information.” | regulatory | 2026-08-18 |
| s8 | [SecureIQLab: 2026 WAAP CyberRisk Validation v5.0 Comparative Report page](https://secureiqlab.com/waap-v5-report/) “The public comparative evaluated 12 leading cloud WAAP solutions, listed alphabetically: Akamai, AWS, Check Point, Cloudflare, F5, Fortinet, Gcore, Harness (formerly Traceable), Imperva, Microsoft, Prophaze, and UBIKA. Every product faced an identical evidence base and scoring rubric.” | research | 2026-08-18 |
| s9 | [Cybersecurity Dive: Nation-state hackers breached sensitive F5 systems, stole customer data](https://www.cybersecuritydive.com/news/f5-supply-chain-breach-nation-state-cisa/802887/) “Government-backed hackers breached enterprise technology vendor F5, accessing its production environment and its engineering resource portal, the company said on Wednesday.” | press | 2026-08-18 |
| s10 | [Help Net Security: F5 data breach, nation-state attackers stole BIG-IP source code and vulnerability information](https://www.helpnetsecurity.com/2025/10/15/f5-big-ip-data-breach/) “F5 called in CrowdStrike, Mandiant, and other cybersecurity experts to help with the investigation” | press | 2026-08-18 |
| s11 | [F5 press release: third quarter fiscal year 2026 results](https://www.f5.com/company/news/press-releases/earnings-q3-fy26) “Third quarter fiscal year 2026 revenue totaled $865 million, representing 11% growth compared with $780 million in the third quarter of fiscal year 2025.” | official | 2026-08-18 |
| s12 | [F5 press release: fourth quarter and fiscal year 2025 results](https://www.f5.com/company/news/press-releases/earnings-fy25-q4) “Fiscal year 2025 revenue totaled $3.09 billion, representing 10% growth compared with $2.82 billion in fiscal year 2024.” | official | 2026-08-18 |
| s13 | [F5 product certifications page: FIPS, Common Criteria, DoDIN APL and CSfC listings](https://www.f5.com/company/certifications) “BIG IP - TMOS Common Criteria Certified Modules” | official | 2026-08-18 |
| s14 | [F5 customer story: PUMA North America and Distributed Cloud Bot Defense](https://www.f5.com/case-studies/puma-north-america-dunks-on-bots-with-an-assist-from-f5) “Sneaker bots disrupted the launches of hot new product launches from PUMA North America, disappointing customers and taking the site down for hours at a time until help from F5 Distributed Cloud Bot Defense brought victory over the attackers and a better experience for PUMA’s loyal fans.” | official | 2026-08-18 |
| s15 | [SecurityWeek: F5 to acquire Shape Security for $1 billion in cash](https://www.securityweek.com/f5-acquire-shape-security-1-billion-cash/) “F5 Networks announced on Thursday that it has agreed to acquire privately held Shape Security for approximately $1 billion in cash.” | press | 2026-08-18 |
| s16 | [Palo Alto Networks Unit 42 threat brief on the F5 source code theft](https://unit42.paloaltonetworks.com/nation-state-threat-actor-steals-f5-source-code/) “Cortex Xpanse currently identifies over 600,000 unique hosts behind a Big-IP instance exposed to the internet.” | research | 2026-08-18 |
| s17 | [F5 customer story: Ailos Cooperative and Distributed Cloud Services](https://www.f5.com/case-studies/ailos-cooperative-fortifies-app-and-api-security-with-f5) “After conducting several proof-of-concept (POC) evaluations with multiple vendors, Ailos leaders opted to deploy F5 Distributed Cloud Services to safeguard 200 apps and thousands of APIs.” | official | 2026-08-18 |
| s18 | [F5 Trust Center: certification programme, release cadence and F5 Labs research](https://www.f5.com/company/trust-center) “F5 maintains an active product certification and evaluation program to maintain secure IT environments. Key certifications include FIPS, NIST, ISO, JIST PKE, and more.” | official | 2026-08-18 |
| s19 | [F5, Inc. Form 10-Q for the quarter ended June 30, 2026 (SEC EDGAR)](https://www.sec.gov/Archives/edgar/data/1048695/000104869526000067/ffiv-20260630.htm) “Net product revenues increased 19.0% and 17.3% for the three and nine months ended June 30, 2026, respectively, from the comparable periods in the prior year.” | regulatory | 2026-08-19 |

### Deep-Dive Sources

Cited from the Strategy Deep Dive section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [F5 web application and API protection solutions page](https://www.f5.com/solutions/web-app-and-api-protection) “Stop common and emerging application-layer exploits with an effective WAF as the core enforcement point for WAAP protections.” | official | 2026-08-18 |
| s2 | [F5 BIG-IP Advanced WAF product page](https://www.f5.com/products/big-ip-services/advanced-waf) “Protect your applications with behavioral analytics, layer 7 DoS mitigation, application-layer encryption of sensitive data, threat intelligence services, and API security.” | official | 2026-08-18 |
| s3 | [F5 Distributed Cloud API Security product page](https://www.f5.com/products/distributed-cloud-services/api-security) “Discover and map APIs, block unwanted traffic and connections, and prevent data leakage” | official | 2026-08-18 |
| s4 | [F5 Distributed Cloud Bot Defense product page](https://www.f5.com/products/distributed-cloud-services/bot-defense) “F5 Distributed Cloud Bot Defense uses real-time behavioral analysis, client-side intelligence, and platform-wide telemetry to detect and control bots and AI agents at the application interaction layer.” | official | 2026-08-18 |
| s5 | [F5, Inc. fiscal 2025 Form 10-K (SEC EDGAR)](https://www.sec.gov/Archives/edgar/data/1048695/000104869525000157/ffiv-20250930.htm) “F5 was incorporated in 1996 and is headquartered in Seattle, Washington.” | regulatory | 2026-08-18 |
| s6 | [F5, Inc. Form 8-K dated October 15, 2025 (SEC EDGAR): Item 1.05 material cybersecurity incident](https://www.sec.gov/Archives/edgar/data/1048695/000104869525000149/ffiv-20251015.htm) “On August 9, 2025, F5, Inc. (the “Company”, “F5”, “we”, or “our”) learned that a highly sophisticated nation-state threat actor had gained unauthorized access to certain Company systems.” | regulatory | 2026-08-18 |
| s7 | [CISA Emergency Directive ED 26-01: Mitigate Vulnerabilities in F5 Devices](https://www.cisa.gov/news-events/directives/ed-26-01-mitigate-vulnerabilities-f5-devices) “A nation-state affiliated cyber threat actor has compromised F5’s systems and exfiltrated files, which included a portion of its BIG-IP source code and vulnerability information.” | regulatory | 2026-08-18 |
| s8 | [SecureIQLab: 2026 WAAP CyberRisk Validation v5.0 Comparative Report page](https://secureiqlab.com/waap-v5-report/) “The public comparative evaluated 12 leading cloud WAAP solutions, listed alphabetically: Akamai, AWS, Check Point, Cloudflare, F5, Fortinet, Gcore, Harness (formerly Traceable), Imperva, Microsoft, Prophaze, and UBIKA. Every product faced an identical evidence base and scoring rubric.” | research | 2026-08-18 |
| s9 | [Cybersecurity Dive: Nation-state hackers breached sensitive F5 systems, stole customer data](https://www.cybersecuritydive.com/news/f5-supply-chain-breach-nation-state-cisa/802887/) “Government-backed hackers breached enterprise technology vendor F5, accessing its production environment and its engineering resource portal, the company said on Wednesday.” | press | 2026-08-18 |
| s10 | [Help Net Security: F5 data breach, nation-state attackers stole BIG-IP source code and vulnerability information](https://www.helpnetsecurity.com/2025/10/15/f5-big-ip-data-breach/) “F5 called in CrowdStrike, Mandiant, and other cybersecurity experts to help with the investigation” | press | 2026-08-18 |
| s11 | [F5 press release: third quarter fiscal year 2026 results](https://www.f5.com/company/news/press-releases/earnings-q3-fy26) “Third quarter fiscal year 2026 revenue totaled $865 million, representing 11% growth compared with $780 million in the third quarter of fiscal year 2025.” | official | 2026-08-18 |
| s12 | [F5 press release: fourth quarter and fiscal year 2025 results](https://www.f5.com/company/news/press-releases/earnings-fy25-q4) “Fiscal year 2025 revenue totaled $3.09 billion, representing 10% growth compared with $2.82 billion in fiscal year 2024.” | official | 2026-08-18 |
| s13 | [F5 product certifications page: FIPS, Common Criteria, DoDIN APL and CSfC listings](https://www.f5.com/company/certifications) “BIG IP - TMOS Common Criteria Certified Modules” | official | 2026-08-18 |
| s14 | [F5 customer story: PUMA North America and Distributed Cloud Bot Defense](https://www.f5.com/case-studies/puma-north-america-dunks-on-bots-with-an-assist-from-f5) “Sneaker bots disrupted the launches of hot new product launches from PUMA North America, disappointing customers and taking the site down for hours at a time until help from F5 Distributed Cloud Bot Defense brought victory over the attackers and a better experience for PUMA’s loyal fans.” | official | 2026-08-18 |
| s15 | [SecurityWeek: F5 to acquire Shape Security for $1 billion in cash](https://www.securityweek.com/f5-acquire-shape-security-1-billion-cash/) “F5 Networks announced on Thursday that it has agreed to acquire privately held Shape Security for approximately $1 billion in cash.” | press | 2026-08-18 |
| s16 | [Palo Alto Networks Unit 42 threat brief on the F5 source code theft](https://unit42.paloaltonetworks.com/nation-state-threat-actor-steals-f5-source-code/) “Cortex Xpanse currently identifies over 600,000 unique hosts behind a Big-IP instance exposed to the internet.” | research | 2026-08-18 |
| s17 | [F5 customer story: Ailos Cooperative and Distributed Cloud Services](https://www.f5.com/case-studies/ailos-cooperative-fortifies-app-and-api-security-with-f5) “After conducting several proof-of-concept (POC) evaluations with multiple vendors, Ailos leaders opted to deploy F5 Distributed Cloud Services to safeguard 200 apps and thousands of APIs.” | official | 2026-08-18 |
| s18 | [F5 Trust Center: certification programme, release cadence and F5 Labs research](https://www.f5.com/company/trust-center) “F5 maintains an active product certification and evaluation program to maintain secure IT environments. Key certifications include FIPS, NIST, ISO, JIST PKE, and more.” | official | 2026-08-18 |
| s19 | [F5, Inc. Form 10-Q for the quarter ended June 30, 2026 (SEC EDGAR)](https://www.sec.gov/Archives/edgar/data/1048695/000104869526000067/ffiv-20260630.htm) “Net product revenues increased 19.0% and 17.3% for the three and nine months ended June 30, 2026, respectively, from the comparable periods in the prior year.” | regulatory | 2026-08-19 |

## Disclaimer

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.
