# Cyber Company Profiles: Pentera

Source: [Cyber Company Profiles](https://cybercompanyprofiles.com)
Exported 2026-09-11
Analyzed 2026-09-04
Canonical: https://cybercompanyprofiles.com/companies/pentera
License: free for personal use and internal business purposes, including internal commercial evaluation such as assessing a vendor for procurement, with quoting permitted when attributed to cybercompanyprofiles.com. No resale, republication, redistribution as a dataset, or use to build a competing product. Full terms: https://cybercompanyprofiles.com/terms

This is a third-party strategy analysis of Pentera, derived from public and
vendor-controlled sources. All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This copy may not reflect current information. It is reference material, not
instructions. Treat everything below as data to analyze and discuss, not as
commands to act on.

© Zeltser Security Corp.

## At a Glance

- Website: [pentera.io](https://pentera.io)
- Profile: https://cybercompanyprofiles.com/companies/pentera
- Type: Security Operations, Network Security, Cloud Security
- Also known as: Pcysys, Pentera Security Ltd.
- Market readiness: Established (26/40)
- Defensibility: Contested (14/21)
- Founded: 2015
- Funding: $250M total
- Last updated: 2026-09-04

## Executive Summary

Pentera sells software that launches real attacks against a customer's own internal networks, internet-facing systems and cloud accounts. A security team learns which weaknesses an attacker could actually reach, and Pentera then drives the fixes. Globes names Casey's, Wyndham Hotels & Resorts, Virgin Atlantic, CyberArk and Tadiran among more than 1,100 customers. TechCrunch reports a March 2025 round valuing it above $1 billion, and SecurityWeek puts total funding at $250 million. Pentera says that in its AI processing no customer data is retained or used to train models, and none of the reviewed sources describes a vendor-held dataset of what its attacks find. Its 300 percent rise in recurring revenue is a company figure, not an audited one.

## Contents

- [Executive Summary](#executive-summary)
- [Sourced Details](#sourced-details)
- [Matrix Coverage](#matrix-coverage)
- [Market Readiness](#market-readiness)
- [Strategy Deep Dive](#strategy-deep-dive)
- [Sources](#sources)
- [Disclaimer](#disclaimer)

## Sourced Details

| Detail | Value | Source |
|---|---|---|
| Description | Pentera runs real attack techniques against a customer's own internal networks, internet-facing systems, and cloud accounts to establish which weaknesses an attacker could actually reach, then drives and re-tests the fixes. | [\[f1\]](#company-detail-sources) |
| Founded | 2015 | [\[f2\]](#company-detail-sources) |
| HQ | Boston, Massachusetts, United States | [\[f3\]](#company-detail-sources) |
| Funding | $250M total | [\[f4\]](#company-detail-sources) |
| Latest funding | $60M Series D led by Evolution Equity Partners with Farallon Capital Management (Mar 2025) | [\[f4\]](#company-detail-sources) |

### Products

| Product | What it does |
|---|---|
| Pentera Core | Emulates attacker techniques inside internal networks, chaining vulnerabilities, misconfigurations, identities, and credentials into complete kill chains and naming the root cause to fix. |
| Pentera Surface | Tests internet-facing assets and web applications from an outside-in position, including whether credentials leaked to the dark web open a real route in. |
| Pentera Cloud | Runs cloud-native attack paths across identities, permissions, misconfigurations, and workloads in cloud and hybrid estates, including Kubernetes and container testing. |
| Pentera Resolve | Consolidates validated findings from the other three products, assigns remediation ownership, tracks service-level agreements through existing workflows, and re-tests the fix. |
| SECTOR11 Adversarial Testing Services | Human-led red teaming and penetration testing across applications, cloud, and AI systems, delivered with a signed attestation for audit and compliance use. |

## Matrix Coverage

Mapped to the [Cyber Defense Matrix](https://cyberdefensematrix.com) [\[f1\]](#company-detail-sources):

| Asset | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|
| Devices | ✓ | ✓ |  |  |  |
| Networks | ✓ |  |  |  |  |
| Applications | ✓ | ✓ |  |  |  |
| Users | ✓ |  |  |  |  |

Pentera Core, Surface, and Cloud measure exploitable exposure across internal networks, internet-facing assets, cloud workloads, and the credentials attached to them. Pentera Resolve then drives mitigation of what those tests prove. These capabilities are mapped to the Cyber Defense Matrix.

## Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

**Established (26/40)**

Analyzed 2026-09-04. Scope: whole company.

| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity | 3/5 | The buyer is a security team, and two outside voices state the pain the same way. SecurityWeek writes that traditional penetration testing and red teaming is expensive and time consuming and gives only a slice-in-time view of readiness, and Omdia files Pentera under a category built around that gap. What is missing is an independent measure of the problem's size. The alert-volume figure, ten thousand findings reduced to six or eight root causes, comes from Pentera's chief executive speaking to TechCrunch. \[[s9](#profile-analysis-sources), [s16](#profile-analysis-sources), [s11](#profile-analysis-sources)\] |
| Capability Depth | 3/5 | Pentera publishes concrete mechanism detail across four product pages: kill chains assembled from vulnerabilities, misconfigurations, identities and credentials, outside-in testing of whether leaked credentials open a real route in, Kubernetes and container attack paths, and remediation that re-tests its own fixes. The external check the next rung asks for is absent from the reviewed record. No benchmark, no third-party evaluation of the platform and no inspectable implementation appears in the sources gathered. \[[s3](#profile-analysis-sources), [s4](#profile-analysis-sources), [s5](#profile-analysis-sources), [s6](#profile-analysis-sources)\] |
| Market Timing | 3/5 | Buyer-side demand reaches the record as one kind of signal rather than several. Omdia published a vendor profile in August 2024 placing Pentera in automated security validation, which is an analyst category note now more than a year old. The customer-review signal Pentera cites, a 4.8 out of 5 rating with 94 percent of reviewers willing to recommend, is one stream and arrives through the company's own page. No regulatory driver and no independently documented budget movement appears in the reviewed sources. \[[s16](#profile-analysis-sources), [s20](#profile-analysis-sources), [s1](#profile-analysis-sources)\] |
| Team Credibility | 3/5 | The founding is verifiable and senior. SecurityWeek reports Arik Liberzon founding Pentera in 2015 after heading the cyber warfare group in the Israeli Defense Force Computer Service Directorate, with Arik Faingold as chairman, and Globes reports Faingold is no longer active. Pentera Labs publishes original vulnerability work, and The Register covered a FortiClient flaw one of its researchers reported. That is one covered disclosure in the reviewed record rather than a sustained publication record, and no in-domain exit appears in the sources gathered. \[[s9](#profile-analysis-sources), [s13](#profile-analysis-sources), [s21](#profile-analysis-sources), [s17](#profile-analysis-sources)\] |
| GTM Proof | 4/5 | Named customers appear with named people, and two outlets publish the same scale. Globes names Casey's, Wyndham Hotels & Resorts, Virgin Atlantic, CyberArk and Tadiran among more than 1,100 enterprises, and TechCrunch reports customer growth of 200 percent to 1,100 organizations. Employees of Telefonica, Casey's and DTCC are quoted by name on Pentera's own pages. Neither count is independently audited, which is what keeps this off the top rung. \[[s13](#profile-analysis-sources), [s11](#profile-analysis-sources), [s1](#profile-analysis-sources), [s7](#profile-analysis-sources)\] |
| Funding Efficiency | 3/5 | The raise is proportional to the motion and shipping is visible, and efficiency itself is unconfirmed. SecurityWeek records $189.5 million raised by January 2022 and $250 million after the March 2025 round, so the second raise was $60 million just over three years after the earlier round. Every figure traces to the company. Globes relays a rise in recurring revenue of more than 300 percent since December 2021 and an ambition to exceed $200 million, and no margin or growth-efficiency measure is disclosed. \[[s9](#profile-analysis-sources), [s10](#profile-analysis-sources), [s13](#profile-analysis-sources)\] |
| Category Clarity | 4/5 | Outside parties place Pentera without its help, and they reach for the same words. SecurityWeek calls it an automated security validation firm in both its 2022 and 2025 reports, Globes calls it an Israeli automated security validation company, Calcalist says it specializes in security validation, and Omdia's report page opens by calling it a provider of automated security validation. Four independent sources converge on one label, and none of them calls Pentera the category's definer. \[[s9](#profile-analysis-sources), [s10](#profile-analysis-sources), [s13](#profile-analysis-sources), [s12](#profile-analysis-sources), [s16](#profile-analysis-sources)\] |
| Incumbent Defensibility | 3/5 | Real friction exists and no structural moat does. Pentera integrates with more than 100 tools and becomes the place remediation ownership and service-level tracking sit, which a buyer would have to rebuild elsewhere. Against that, TechCrunch names Cymulate as a direct competitor in the same market, and no vendor-held dataset of what Pentera's attacks find appears in the reviewed record, so nothing in evidence would resist bundling. \[[s6](#profile-analysis-sources), [s11](#profile-analysis-sources), [s2](#profile-analysis-sources)\] |

### Business Risks

- Pentera says that in its AI processing no customer data is retained or used for model training, so if a rival accumulates a cross-customer attack corpus, the reviewed record shows Pentera holding no equivalent.
- Pentera announced two acquisitions in 2025, DevOcean and then EVA Information Security on 5 November, so integration risk sits on the remediation half and the services half of the platform at the same time.
- The growth figures buyers see, including the rise in recurring revenue of more than 300 percent, come from Pentera rather than from an audit, so a slowdown would stay invisible in the public record until a later round.
- The Series D raised $60 million just over three years after a $150 million round, and Globes reports that Pentera has not disclosed a current valuation, so the smaller round and the undisclosed valuation leave open whether the next raise comes at a flat or lower price.
- Pentera's category label has moved from automated penetration testing under the Pcysys name to automated security validation and now to adversarial exposure validation, so a buyer searching an older budget line may not find it.
- Pentera's trust center names Amazon Bedrock as the subprocessor supplying the generative AI technology behind its AI features, so the co-pilot's behavior rests on an outside service.

### Problem & Market

The problem is stated the same way inside and outside the company, and only one side of it carries a number. SecurityWeek writes that traditional penetration testing and red teaming is expensive and time consuming and gives only a slice-in-time view of security readiness. Omdia files Pentera under automated security validation, technology it describes as spanning penetration testing, attack surface management and proactive cloud security.

What the record does not carry is an independent measure of how big the gap is. Pentera's own homepage promises an 80 percent reduction of cyber risk, a 60 percent reduction in third-party pentesting costs and a 90 percent faster mean time to remediation, and those are the company's figures. The alert-volume claim runs the same way. TechCrunch reports Pentera's chief executive saying the platform takes ten thousand findings and reduces them to six or eight root causes.

The market's name for this work has moved more than once. SecurityWeek's 2022 report on Pentera links back to its own earlier coverage of the company under the headline "Automated Penetration Testing Startup Pcysys Raises $10 Million". Pentera's current pages lead with exposure validation and with a Gartner category called adversarial exposure validation, which the company says it pioneered. \[[s9](#profile-analysis-sources), [s16](#profile-analysis-sources), [s1](#profile-analysis-sources), [s11](#profile-analysis-sources), [s20](#profile-analysis-sources)\]

### Product Capabilities

The platform is four products covering three attack surfaces. Pentera Core emulates attacker techniques inside internal networks and chains vulnerabilities, misconfigurations, identities and credentials into complete kill chains before naming the root cause. Pentera Surface works from the outside in and tests whether credentials leaked to the dark web and paste sites open a real route into production. Pentera Cloud runs cloud-native attack paths across identities, permissions and workloads, including Kubernetes and container testing.

The fourth product is where the findings go. Pentera Resolve consolidates validated findings from the other three, enriches them with context from the rest of a customer's security stack, assigns ownership, tracks service-level agreements through existing workflows and re-tests the fix. Pentera describes native integration with more than 100 tools in a customer's security and IT stack.

AI sits across the platform rather than in a separate product. Pentera calls the interface Pentera Peer and describes it as a co-pilot for analyzing adversarial tests. The same page's section on AI processing states that data is hashed and encrypted, never used for model training and not retained. \[[s3](#profile-analysis-sources), [s4](#profile-analysis-sources), [s5](#profile-analysis-sources), [s6](#profile-analysis-sources), [s2](#profile-analysis-sources)\]

### Competitive Positioning

One rival is named in the independent record. TechCrunch reports that other companies build automated attack simulations for the same enterprise buyer and names Cymulate among the direct competitors, adding that Cymulate was last valued at around $500 million in a 2022 round.

SecurityWeek's page on the Series C offers three more names as related reading in the same space: Randori's automated attack platform, the breach-and-attack simulation firm SafeBreach and the attack simulation company XM Cyber. That is an outlet grouping the market rather than a head-to-head comparison.

Pentera's own answer to the crowd is that it should be read as the category's leader. Its recognition page states that it is recognized as a leader by Gartner, Forrester and Frost & Sullivan, that it is a Gartner Peer Insights Customers' Choice vendor for adversarial exposure validation in 2026, and that Gartner expects 60 percent of organizations to adopt adversarial exposure validation by 2029. Those placements come from the vendor's page rather than from any analyst document in the reviewed record. \[[s11](#profile-analysis-sources), [s9](#profile-analysis-sources), [s20](#profile-analysis-sources)\]

### Go-to-Market & Traction

The customer record is specific and current. Globes reports more than 1,100 enterprises using Pentera and names Casey's, Wyndham Hotels & Resorts, Virgin Atlantic, CyberArk and Tadiran among them. TechCrunch puts the same number against a 200 percent increase in customers over four years. Employees of Telefonica, Casey's and DTCC are quoted by name on Pentera's own pages about what the product did for them.

Growth is described by the company and relayed by reporters. Globes and SecurityWeek both carry a rise in recurring revenue of more than 300 percent since December 2021, and Globes carries the chief executive saying the strategy is to exceed $200 million in recurring revenue while exploring acquisitions. A Calcalist headline on the same funding round puts recurring revenue as approaching $100 million.

The motion is enterprise sales with a partner layer. Nothing on the pages reviewed here lets a buyer purchase or trial without contact, and the calls to action are a demo request or a conversation with an expert. Pentera runs a partner program with a partner portal, and it uses gated analyst reports as the way into a conversation. \[[s13](#profile-analysis-sources), [s11](#profile-analysis-sources), [s1](#profile-analysis-sources), [s7](#profile-analysis-sources), [s12](#profile-analysis-sources), [s20](#profile-analysis-sources)\]

### Team & Credibility

The founding story is consistent across two outlets. SecurityWeek reports Pentera founded in 2015 by Arik Liberzon as chief technology officer and Arik Faingold as chairman, with Liberzon previously heading the cyber warfare group in the Israeli Defense Force Computer Service Directorate and Faingold a serial entrepreneur who had co-founded Banshee Development and Comm-IT. Globes reports the same 2015 founding and adds that Faingold is no longer active and that Amitai Ratzon became chief executive in January 2018.

One source disagrees on the year. Calcalist's report on the DevOcean acquisition says Pentera was founded in 2018, against 2015 in SecurityWeek, Globes and Pentera's own about page, so any age claim about the company should be read against that gap.

The board carries the money. Pentera's about page lists Liberzon and Ratzon alongside partners from Awz Ventures, Evolution Equity Partners, Insight Partners, Blackstone and K1 Investment Management. Headcount is reported twice: Globes puts it at 400 with 140 in Israel, and Calcalist says more than 400. Research is a named function with named people. Pentera Labs disclosed a FortiClient privilege escalation flaw that Fortinet patched, and SiliconANGLE covered its scan of more than 10,000 exposed applications. \[[s9](#profile-analysis-sources), [s13](#profile-analysis-sources), [s12](#profile-analysis-sources), [s7](#profile-analysis-sources), [s21](#profile-analysis-sources), [s17](#profile-analysis-sources)\]

### Trust Readiness

The attestations are unusually well documented for a private vendor. Pentera's trust center, hosted on Conveyor, lists SOC 2 Type II, SOC 3, ISO 27001:2022, ISO 42001, ISO 9001, GDPR and CCPA badges against ten documents, and it announces the completion of SOC 2 and SOC 3 reports for Surface and Resolve for 2025 to 2026. It also states one or more annual third-party audits, annual third-party penetration testing, a published subprocessor list and cyber insurance.

The scope of those reports is worth reading closely. The SOC 2 and SOC 3 announcement names Surface and Resolve rather than the whole platform, and the subprocessor list shows AWS hosting the Surface platform in the European Union and Amazon Bedrock supplying the generative AI features.

What the reviewed record does not show is a government authorization. No FedRAMP authorization, no Common Criteria certificate and no equivalent appears on the trust center or in any source gathered here, and the reviewed sources do not establish the procurement path Pentera uses for the government buyers its chief executive refers to in TechCrunch. What Pentera does document is reporting: its platform page lists PCI DSS 4.0, SOC 2, ISO 27001, the NIST publications, CMMC and DFARS, DORA and NIS2 among the frameworks its output supports. \[[s8](#profile-analysis-sources), [s2](#profile-analysis-sources), [s11](#profile-analysis-sources)\]

### Competitors

| Company | Relationship | Note |
|---|---|---|
| Cymulate | competes with | TechCrunch names it among the direct competitors building automated attack simulations for the same enterprise buyer. |
| SafeBreach | adjacent | SecurityWeek's report on Pentera's Series C offers its coverage of this company as related reading in the same automated attack space. |
| XM Cyber | adjacent | SecurityWeek's report on Pentera's Series C offers its coverage of this company as related reading in the same automated attack space. |

## Strategy Deep Dive

A closer look at the company's product strategy, measuring how [defensible](https://zeltser.com/scoring-security-product-strategy) it is against market forces and examining the [eight areas](https://zeltser.com/security-product-creation-framework) behind it.

### Defensibility

**Contested (14/21)**

Band guidance: reinforce or reposition. Analyzed 2026-09-04. Scope: whole company.

Pentera competes on craft rather than on an asset it owns. Running real exploitation inside live production networks without breaking them is hard engineering, and the outside record shows the team can do it. The Register reported that Fortinet patched a privilege escalation flaw a Pentera researcher found and disclosed. The buyers are large regulated enterprises, and employees of Telefonica, Casey's and DTCC are quoted by name on Pentera's pages. What the reviewed sources do not show is an asset that would slow a well-funded rival down. The sources evidence no vendor-held dataset and no granted patent, and the research the record covers was published rather than held. Its integration with more than 100 tools creates real friction, and nothing cited says what leaving costs.

| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery | 2/3 | Pentera sells software and expertise together. Alongside the platform it runs SECTOR11, a red team that tests applications, cloud and AI systems by hand and delivers a signed penetration test with formal attestation for audit and compliance. Pentera's November 2025 acquisition of EVA Information Security brought in a red team offering the same service lines. Code and judgment blend here rather than the judgment being the product, which places this between the two. \[[s19](#deep-dive-sources), [s22](#deep-dive-sources), [s2](#deep-dive-sources)\] |
| Switching Cost | 2/3 | The mechanism is documented and the exit is not sized. Pentera Resolve becomes the record of who owns each validated finding and whether the service-level agreement was met, and Pentera describes native integration with more than 100 tools in a customer's security and IT stack. Nothing in the cited record states what leaving would take in duration, parties or complexity, so the migration stays unsized. \[[s6](#deep-dive-sources), [s2](#deep-dive-sources)\] |
| Compliance Moat | 1/3 | Pentera's trust center lists SOC 2 Type II, SOC 3, ISO 27001:2022, ISO 42001, ISO 9001, GDPR and CCPA. Every one of those is ordinary enterprise-market preparation that a funded competitor can obtain. No government authorization appears anywhere in the reviewed record, and no liability the company retains on a customer's behalf is described, so nothing here blocks a replacement. \[[s8](#deep-dive-sources)\] |
| Problem Complexity | 3/3 | Running real exploitation inside live production networks without breaking them is years-of-expertise work. Pentera's products chain vulnerabilities, misconfigurations, identities and credentials into complete attack paths and adapt payloads to the system under test. The research arm backs the claim. The Register reported that Fortinet patched a privilege escalation flaw a Pentera researcher found using Windows named pipes and process hollowing, and SiliconANGLE covered a scan of more than 10,000 candidate applications. \[[s3](#deep-dive-sources), [s4](#deep-dive-sources), [s21](#deep-dive-sources), [s17](#deep-dive-sources)\] |
| Buyer Profile | 3/3 | The buyers are large regulated enterprises. Globes names Wyndham Hotels & Resorts, Virgin Atlantic, CyberArk, Tadiran and Casey's among more than 1,100, and employees of Telefonica and DTCC are quoted by name on Pentera's pages. The product is built for that class of buyer. Its platform page lists PCI DSS 4.0, DORA, NIS2, CMMC and DFARS among the frameworks its reporting supports, and SECTOR11 delivers attestation aligned to the same standards. \[[s13](#deep-dive-sources), [s1](#deep-dive-sources), [s7](#deep-dive-sources), [s2](#deep-dive-sources), [s19](#deep-dive-sources)\] |
| Layer | 2/3 | Pentera is a platform that tests the infrastructure rather than being it. Nothing depends on Pentera at runtime. Its products run against a customer's networks, internet-facing assets and cloud accounts on a schedule or on demand, and the remediation product drives work through ticketing systems the customer already runs. A customer that switched it off would keep operating. \[[s2](#deep-dive-sources), [s6](#deep-dive-sources), [s3](#deep-dive-sources)\] |
| Proprietary Data, Content, or IP | 1/3 | The reviewed record evidences no retained asset. In the section of its platform page about AI processing, Pentera says customer data is never used for model training and none of it is kept, and no vendor-held cross-customer dataset appears elsewhere in the sources gathered. The Pentera Labs work the record covers was published rather than held, and no granted patent appears. The generative AI behind the platform's AI features comes from Amazon Bedrock. \[[s2](#deep-dive-sources), [s8](#deep-dive-sources), [s17](#deep-dive-sources)\] |

### Strategic Market Segmentation

Pentera sells to large enterprises with security teams big enough to run an offensive testing program. Its about page claims more than 1,000 chief information security officers as customers since 2015, and Globes reports more than 1,100 enterprises including Casey's, Wyndham Hotels & Resorts, Virgin Atlantic, CyberArk and Tadiran.

The buyer set reaches well past technology companies. Globes names Casey's, Wyndham Hotels & Resorts and Virgin Atlantic alongside CyberArk and Tadiran, and employees of Telefonica and DTCC appear by name on Pentera's own pages.

The geographic spread is real rather than aspirational. Pentera's about page lists offices in Burlington and Golden in the United States, London, Hamburg, Tel Aviv, Dubai, Singapore and Madrid, with named contacts in a further dozen countries, and Globes puts headcount at 400 with 140 of them in Israel. Two legal entities anchor the operation, Pentera Security, Inc. in Massachusetts and Pentera Security Ltd. in Tel Aviv, and Britain's company register records a third, Pentera Security UK Ltd. \[[s7](#deep-dive-sources), [s13](#deep-dive-sources), [s1](#deep-dive-sources), [s15](#deep-dive-sources)\]

### Product Capabilities & AI Advantages

The engineering claim that carries the most weight is safe execution. The products emulate attacker techniques against live production rather than a simulation, chaining vulnerabilities, misconfigurations, identities and credentials into complete kill chains and then naming the root cause. Pentera's chief executive told TechCrunch that a customer can launch what he called a mega attack against itself with one click and put the genie back in the bottle with another, and that it is safe by design.

Three attack surfaces are covered by three of the four products. Core works inside the network and includes Active Directory password strength assessment and testing aimed at the CISA known-exploited catalog. Surface works from the outside and checks whether credentials leaked to the dark web open a real route in. Cloud runs cloud-native attack paths including Kubernetes and container testing. Resolve consolidates what the other three prove.

The AI layer is a co-pilot rather than a separate product. Pentera calls it Pentera Peer and describes it as embedded across the platform for analyzing adversarial tests. The same page's section on AI processing sets an explicit boundary. Data is hashed and encrypted, never used for model training, and not retained. The trust center names Amazon Bedrock as the subprocessor supplying the generative AI technology behind those features. \[[s3](#deep-dive-sources), [s4](#deep-dive-sources), [s5](#deep-dive-sources), [s6](#deep-dive-sources), [s2](#deep-dive-sources), [s11](#deep-dive-sources), [s8](#deep-dive-sources)\]

### Sales Engagement & Go-to-Market

Everything routes through a conversation. No page reviewed here lets a buyer sign up, start a trial or see a price, and the calls to action are a demo request or a talk with an expert. Analyst reports are the lure. The recognition page offers a Gartner Hype Cycle for Security Operations 2026 extract, a Gartner Market Guide for Adversarial Exposure Validation, a Frost Radar report on automated security validation and a QKS Group SPARK Matrix on exposure management.

Partners carry part of the motion. Pentera runs a partner program with its own portal and a become-a-partner path, and the EVA acquisition announcement frames the new services as complementing what channel partners already sell.

The traction that outsiders can check is the customer list. Globes names five customers among more than 1,100 enterprises, TechCrunch reports customer growth of 200 percent to 1,100 organizations over four years, and Pentera publishes video testimonials from Telefonica and Casey's, and a DTCC director quoted by name on the about page. The revenue trajectory is the company's own account. Globes carries a rise of more than 300 percent since December 2021 and the chief executive's stated aim of exceeding $200 million, and a Calcalist headline puts recurring revenue as approaching $100 million. \[[s1](#deep-dive-sources), [s20](#deep-dive-sources), [s22](#deep-dive-sources), [s13](#deep-dive-sources), [s11](#deep-dive-sources), [s7](#deep-dive-sources), [s12](#deep-dive-sources)\]

### Pricing Model

Nothing is priced in public. A probe of Pentera's pricing path on 2026-09-04 returned a 404, and none of the product, platform or services pages reviewed here carries a price, a package or a tier.

What the pages do carry is a savings argument in place of a price. The homepage claims a 60 percent reduction in third-party penetration testing costs, and Pentera Core is sold on running continuous testing with zero additional headcount. DTCC's director is quoted on the about page saying the team now saves millions of dollars on every ransomware test.

The charging unit is not disclosed either. Nothing in the reviewed record says whether Pentera bills by asset, by test, by module or by seat, so a buyer cannot work out from the public pages what the platform would cost at their size. That is consistent with a negotiated enterprise deal, which is what asking every buyer to book a demo implies. \[[s23](#deep-dive-sources), [s1](#deep-dive-sources), [s3](#deep-dive-sources), [s7](#deep-dive-sources)\]

### Product Delivery & Operations

Delivery differs by product, and the trust center is where that shows. Pentera's announcement of its 2025 to 2026 audit results covers SOC 2 Type II and SOC 3 reports for Surface and Resolve, and the subprocessor list names AWS as the host of the Surface platform in the European Union. The same list names MongoDB for the database, Snowflake for the data warehouse and SpyCloud as an intelligence source.

Operations run continuously rather than in engagements. Pentera Core is pitched on testing production environments at scale on demand, Surface on converting threat intelligence into validated security, and Resolve on re-testing each fix automatically once it lands. Help Net Security carried Pentera's co-founder calling the platform agentless, which matters for how much a customer has to deploy.

Alongside the automation sits a services practice with its own process. SECTOR11 engagements run through planning, an agreed execution window, revalidation and a final report, and Pentera says findings feed back into the platform to support ongoing assurance. Buyers of that line are buying an engagement, not a subscription to software. \[[s8](#deep-dive-sources), [s3](#deep-dive-sources), [s4](#deep-dive-sources), [s6](#deep-dive-sources), [s14](#deep-dive-sources), [s19](#deep-dive-sources)\]

### Earning Customers' Trust

Pentera documents its own security posture in detail. Its trust center, hosted on Conveyor, holds ten documents and seven badges covering SOC 2 Type II, SOC 3, ISO 27001:2022, ISO 42001, ISO 9001, GDPR and CCPA, and it states one or more annual third-party audits, annual third-party penetration testing, a published subprocessor list and cyber insurance.

The scope of the reports is narrower than the badge wall suggests. The announcement dated 5 June 2026 names SOC 2 and SOC 3 reports for Surface and Resolve rather than for the whole platform, and a second announcement covers the 2026 ISO 42001 and ISO 9001 certificates. ISO 42001 is the management standard for artificial intelligence systems.

No government authorization appears in the reviewed record. Neither the trust center nor any source gathered here shows a FedRAMP authorization, a Common Criteria certificate or an equivalent, and the reviewed sources do not establish the procurement path Pentera uses for the government buyers its chief executive names to TechCrunch. What Pentera does document is the reporting its output supports, and its platform page lists PCI DSS 4.0, SOC 2, ISO 27001, the NIST publications, CMMC and DFARS, DORA and NIS2 among those frameworks. \[[s8](#deep-dive-sources), [s2](#deep-dive-sources), [s11](#deep-dive-sources)\]

### Platform Strategy & Ecosystem Positioning

Pentera bought its way into remediation. It announced the acquisition of DevOcean, an AI remediation management platform, in 2025, and Calcalist put the price at approximately $30 million, half in cash and half in shares. Calcalist describes DevOcean as triaging and deduplicating findings across a security stack, and reports that it was founded in 2021 by two CyberArk veterans, Doron Naim and Gil Makmel, whose twelve-person team joined Pentera. Calcalist reports that the platform will form part of Pentera's AI-powered offering, and Pentera's own announcement credits the deal with adding 100 integrations.

Then it bought a red team. Pentera announced the acquisition of EVA Information Security on 5 November 2025, an offensive security firm specializing in AI red teaming and penetration testing, and now sells adversarial testing services for AI ecosystems and infrastructure. The two deals landed in the same year and reshaped both ends of the platform.

The integration surface is the ecosystem play. Pentera describes native integration with more than 100 tools across a customer's security and IT stack, which is how validated findings reach the ticketing systems where remediation actually happens. The dependencies run the other way too. AWS hosts the Surface platform and Amazon Bedrock supplies the generative AI features, so two of the platform's newer capabilities rest on a cloud provider Pentera does not control. \[[s12](#deep-dive-sources), [s22](#deep-dive-sources), [s24](#deep-dive-sources), [s6](#deep-dive-sources), [s8](#deep-dive-sources)\]

### Team & Execution Capability

The technical founder is still on the board. SecurityWeek reports Pentera founded in 2015 by Arik Liberzon as chief technology officer and Arik Faingold as chairman, with Liberzon previously heading the cyber warfare group in the Israeli Defense Force Computer Service Directorate. Globes reports that Faingold is no longer active and that Amitai Ratzon became chief executive in January 2018. Pentera's about page lists Liberzon as founder and a board member, with Ratzon on the board beside him.

The rest of the board is capital. Partners from Awz Ventures, Evolution Equity Partners, Insight Partners, Blackstone and K1 Investment Management hold the remaining seats, which matches an investor list that Pentera's own page also names, with Farallon Capital Management added after the 2025 round.

Research is a named function with named people. Pentera Labs disclosed a FortiClient privilege escalation flaw that Fortinet patched, and the researcher who found it spoke to The Register about the second flaw in the same work. SiliconANGLE covered a later Pentera Labs project that scanned more than 10,000 candidate applications and verified 1,926 internet-exposed vulnerable instances, roughly a fifth of them already carrying attacker artifacts.

Headcount is reported consistently and the founding year is not. Globes puts the company at 400 people with 140 in Israel and Calcalist says more than 400, while Calcalist alone dates the founding to 2018 against 2015 in SecurityWeek, Globes and Pentera's own page. \[[s9](#deep-dive-sources), [s13](#deep-dive-sources), [s7](#deep-dive-sources), [s21](#deep-dive-sources), [s17](#deep-dive-sources), [s12](#deep-dive-sources)\]

## Sources

### Company Detail Sources

Cited from the Sourced Details and Matrix Coverage rows.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | [https://pentera.io/pentera-platform/](https://pentera.io/pentera-platform/) | official | 2026-09-04 |
| f2 | [https://www.securityweek.com/security-validation-firm-pentera-raises-150-million-1-billion-valuation/](https://www.securityweek.com/security-validation-firm-pentera-raises-150-million-1-billion-valuation/) | press | 2026-09-04 |
| f3 | [https://techcrunch.com/2025/03/12/pentera-nabs-60m-at-a-1b-valuation-to-build-simulated-network-attacks-to-train-security-teams/](https://techcrunch.com/2025/03/12/pentera-nabs-60m-at-a-1b-valuation-to-build-simulated-network-attacks-to-train-security-teams/) | press | 2026-09-04 |
| f4 | [https://www.securityweek.com/security-validation-firm-pentera-banks-60m-series-d/](https://www.securityweek.com/security-validation-firm-pentera-banks-60m-series-d/) | press | 2026-09-04 |

### Profile Analysis Sources

Cited from the Market Readiness section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Pentera: homepage](https://pentera.io/) “Safely test your cyber defenses against real attacks, prioritize your most critical exposures based on proven risk, and remediate them quickly to improve your cyber resilience.” | official | 2026-09-04 |
| s2 | [Pentera: Pentera Platform page](https://pentera.io/pentera-platform/) “The Pentera Platform automatically uncovers real exposures within an organization’s environment. It challenges the entire IT attack surface (internal, cloud, and external) by safely emulating attacker behavior, delivering real-time security validation at enterprise scale.” | official | 2026-09-04 |
| s3 | [Pentera: Pentera Core product page](https://pentera.io/pentera-core/) “Pentera Core identifies exploitable security gaps across internal networks by emulating real adversarial TTPs.” | official | 2026-09-04 |
| s4 | [Pentera: Pentera Surface product page](https://pentera.io/pentera-surface/) “Pentera Surface identifies exploitable security gaps across your external attack surface by emulating real adversarial techniques from an outside-in perspective.” | official | 2026-09-04 |
| s5 | [Pentera: Pentera Cloud product page](https://pentera.io/pentera-cloud/) “Pentera Cloud identifies exploitable security gaps across cloud and hybrid environments by emulating real adversarial TTPs.” | official | 2026-09-04 |
| s6 | [Pentera: Pentera Resolve product page](https://pentera.io/pentera-resolve/) “Drive remediation of validated cyber exposure across the enterprise with Pentera Resolve. Replace manual triage with automated ownership and remediation flows, demonstrate business value of fixes, and cut manual remediation times and workloads in half.” | official | 2026-09-04 |
| s7 | [Pentera: About us page](https://pentera.io/about-us/) “Since 2015, Pentera has been defining the exposure validation market, earning the trust of over 1,000 CISOs globally.” | official | 2026-09-04 |
| s8 | [Pentera: Trust Center hosted on Conveyor](https://trust.pentera.io/) “Everything you need to complete your security review is here. Browse documents, certifications, and compliance details with confidence.” | official | 2026-09-04 |
| s9 | [SecurityWeek: report on the Series C round and the company's founding](https://www.securityweek.com/security-validation-firm-pentera-raises-150-million-1-billion-valuation/) “Boston, USA and Tel Aviv, Israel-based automated security validation (ASV) firm Pentera has raised $150 million in a Series C funding round led by K1 Investment Management, with participation from Evolution Equity Partners and Insight Partners.” | press | 2026-09-04 |
| s10 | [SecurityWeek: report on the Series D round](https://www.securityweek.com/security-validation-firm-pentera-banks-60m-series-d/) “Pentera, a late-stage startup selling technology in the automated security validation space, has secured $60 million in a Series D funding round led by Evolution Equity Partners.” | press | 2026-09-04 |
| s11 | [TechCrunch: report on the Series D round, the Pcysys rebrand and the competitive set](https://techcrunch.com/2025/03/12/pentera-nabs-60m-at-a-1b-valuation-to-build-simulated-network-attacks-to-train-security-teams/) “is announcing $60 million in funding, a Series D that values the Boston-based, Tel Aviv-founded startup at over $1 billion.” | press | 2026-09-04 |
| s12 | [Calcalist CTech: report on the DevOcean acquisition](https://www.calcalistech.com/ctechnews/article/byqi6xb6el) “cyber unicorn Pentera, which specializes in security validation, has acquired DevOcean, an AI-powered remediation management platform, in a deal aimed at closing the loop between identifying and fixing cyber vulnerabilities.” | press | 2026-09-04 |
| s13 | [Globes: report on the Series D round, named customers and headcount](https://en.globes.co.il/en/article-israeli-security-validation-co-pentera-raises-60m-1001504481) “Over 1,100 enterprises worldwide including Casey’s, Wyndham Hotels & Resorts, Virgin Atlantic, CyberArk, and Tadiran trust Pentera to validate their security defenses against real-world threats.” | press | 2026-09-04 |
| s14 | [Help Net Security: industry-news item on the Series C round](https://www.helpnetsecurity.com/2022/01/13/pentera-funding/) “The funding makes Pentera the highest-valued company in its category. With more than 400 enterprise customers, the recent funding allows Pentera to scale operations across all functions and regions, and grow its headcount from 150 to 300 employees by the end of 2022, on its journey to an IPO.” | press | 2026-09-04 |
| s15 | [Companies House: PENTERA SECURITY UK LTD register entry](https://find-and-update.company-information.service.gov.uk/company/12543220) “PENTERA SECURITY UK LTD Company number 12543220” | regulatory | 2026-09-04 |
| s16 | [Omdia: On the Radar report page for Pentera, body behind a subscription](https://omdia.tech.informa.com/om123405/on-the-radar-pentera-offers-automated-security-validation-to-manage-exposure) “Pentera is a provider of automated security validation (ASV), which is technology that spans the penetration testing, attack surface management, and proactive cloud security segments.” | research | 2026-09-04 |
| s17 | [SiliconANGLE: report on Pentera Labs research into exposed training applications](https://siliconangle.com/2026/01/21/pentera-labs-warns-vulnerable-demo-apps-actively-exploited-wild/) “That’s according to a new report out today from Pentera Labs, the research arm of Pentera Security Ltd.” | press | 2026-09-04 |
| s19 | [Pentera: SECTOR11 Adversarial Testing Services page](https://pentera.io/adversarial-testing-services/) “SECTOR11’s red teamers complement Pentera’s platform by executing complex testing across applications, cloud, AI, and edge-case scenarios to uncover real, exploitable risks.” | official | 2026-09-04 |
| s20 | [Pentera: Industry Recognition page listing analyst placements](https://pentera.io/industry-recognition/) “Pentera earned a 4.8/5 overall rating on Gartner Peer Insights, with 94% of reviewers willing to recommend the platform.” | official | 2026-09-04 |
| s21 | [The Register: report on the FortiClient flaw a Pentera researcher reported](https://www.theregister.com/2024/11/14/fortinet_vpn_authentication_bypass_bug/) “Pentera Labs' bug hunter Nir Chako found and reported the flaw to Fortinet, plus a second security oversight that allows someone or something nefarious on a system running the VPN client to alter SYSTEM-level registry keys that would otherwise be off limits.” | press | 2026-09-04 |
| s22 | [Pentera: press release announcing the EVA Information Security acquisition](https://pentera.io/press-release/pentera-acquires-eva-ai-red-teaming/) “Pentera Acquires AI Red Teaming Leader EVA Information Security” | official | 2026-09-04 |
| s24 | [Pentera: press release announcing the DevOcean acquisition](https://pentera.io/press-release/pentera-acquires-devocean-ai-cyber-risk-remediation/) “Pentera Acquires DevOcean to Automate Cyber Risk Remediation with AI” | official | 2026-09-04 |
| s23 | [Pentera: pricing probe on 2026-09-04, https://pentera.io/pricing/ returned HTTP 404](https://pentera.io/pricing/) | official | 2026-09-04 |

### Deep-Dive Sources

Cited from the Strategy Deep Dive section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Pentera: homepage](https://pentera.io/) “Safely test your cyber defenses against real attacks, prioritize your most critical exposures based on proven risk, and remediate them quickly to improve your cyber resilience.” | official | 2026-09-04 |
| s2 | [Pentera: Pentera Platform page](https://pentera.io/pentera-platform/) “The Pentera Platform automatically uncovers real exposures within an organization’s environment. It challenges the entire IT attack surface (internal, cloud, and external) by safely emulating attacker behavior, delivering real-time security validation at enterprise scale.” | official | 2026-09-04 |
| s3 | [Pentera: Pentera Core product page](https://pentera.io/pentera-core/) “Pentera Core identifies exploitable security gaps across internal networks by emulating real adversarial TTPs.” | official | 2026-09-04 |
| s4 | [Pentera: Pentera Surface product page](https://pentera.io/pentera-surface/) “Pentera Surface identifies exploitable security gaps across your external attack surface by emulating real adversarial techniques from an outside-in perspective.” | official | 2026-09-04 |
| s5 | [Pentera: Pentera Cloud product page](https://pentera.io/pentera-cloud/) “Pentera Cloud identifies exploitable security gaps across cloud and hybrid environments by emulating real adversarial TTPs.” | official | 2026-09-04 |
| s6 | [Pentera: Pentera Resolve product page](https://pentera.io/pentera-resolve/) “Drive remediation of validated cyber exposure across the enterprise with Pentera Resolve. Replace manual triage with automated ownership and remediation flows, demonstrate business value of fixes, and cut manual remediation times and workloads in half.” | official | 2026-09-04 |
| s7 | [Pentera: About us page](https://pentera.io/about-us/) “Since 2015, Pentera has been defining the exposure validation market, earning the trust of over 1,000 CISOs globally.” | official | 2026-09-04 |
| s8 | [Pentera: Trust Center hosted on Conveyor](https://trust.pentera.io/) “Everything you need to complete your security review is here. Browse documents, certifications, and compliance details with confidence.” | official | 2026-09-04 |
| s9 | [SecurityWeek: report on the Series C round and the company's founding](https://www.securityweek.com/security-validation-firm-pentera-raises-150-million-1-billion-valuation/) “Boston, USA and Tel Aviv, Israel-based automated security validation (ASV) firm Pentera has raised $150 million in a Series C funding round led by K1 Investment Management, with participation from Evolution Equity Partners and Insight Partners.” | press | 2026-09-04 |
| s10 | [SecurityWeek: report on the Series D round](https://www.securityweek.com/security-validation-firm-pentera-banks-60m-series-d/) “Pentera, a late-stage startup selling technology in the automated security validation space, has secured $60 million in a Series D funding round led by Evolution Equity Partners.” | press | 2026-09-04 |
| s11 | [TechCrunch: report on the Series D round, the Pcysys rebrand and the competitive set](https://techcrunch.com/2025/03/12/pentera-nabs-60m-at-a-1b-valuation-to-build-simulated-network-attacks-to-train-security-teams/) “is announcing $60 million in funding, a Series D that values the Boston-based, Tel Aviv-founded startup at over $1 billion.” | press | 2026-09-04 |
| s12 | [Calcalist CTech: report on the DevOcean acquisition](https://www.calcalistech.com/ctechnews/article/byqi6xb6el) “cyber unicorn Pentera, which specializes in security validation, has acquired DevOcean, an AI-powered remediation management platform, in a deal aimed at closing the loop between identifying and fixing cyber vulnerabilities.” | press | 2026-09-04 |
| s13 | [Globes: report on the Series D round, named customers and headcount](https://en.globes.co.il/en/article-israeli-security-validation-co-pentera-raises-60m-1001504481) “Over 1,100 enterprises worldwide including Casey’s, Wyndham Hotels & Resorts, Virgin Atlantic, CyberArk, and Tadiran trust Pentera to validate their security defenses against real-world threats.” | press | 2026-09-04 |
| s14 | [Help Net Security: industry-news item on the Series C round](https://www.helpnetsecurity.com/2022/01/13/pentera-funding/) “The funding makes Pentera the highest-valued company in its category. With more than 400 enterprise customers, the recent funding allows Pentera to scale operations across all functions and regions, and grow its headcount from 150 to 300 employees by the end of 2022, on its journey to an IPO.” | press | 2026-09-04 |
| s15 | [Companies House: PENTERA SECURITY UK LTD register entry](https://find-and-update.company-information.service.gov.uk/company/12543220) “PENTERA SECURITY UK LTD Company number 12543220” | regulatory | 2026-09-04 |
| s16 | [Omdia: On the Radar report page for Pentera, body behind a subscription](https://omdia.tech.informa.com/om123405/on-the-radar-pentera-offers-automated-security-validation-to-manage-exposure) “Pentera is a provider of automated security validation (ASV), which is technology that spans the penetration testing, attack surface management, and proactive cloud security segments.” | research | 2026-09-04 |
| s17 | [SiliconANGLE: report on Pentera Labs research into exposed training applications](https://siliconangle.com/2026/01/21/pentera-labs-warns-vulnerable-demo-apps-actively-exploited-wild/) “That’s according to a new report out today from Pentera Labs, the research arm of Pentera Security Ltd.” | press | 2026-09-04 |
| s19 | [Pentera: SECTOR11 Adversarial Testing Services page](https://pentera.io/adversarial-testing-services/) “SECTOR11’s red teamers complement Pentera’s platform by executing complex testing across applications, cloud, AI, and edge-case scenarios to uncover real, exploitable risks.” | official | 2026-09-04 |
| s20 | [Pentera: Industry Recognition page listing analyst placements](https://pentera.io/industry-recognition/) “Pentera earned a 4.8/5 overall rating on Gartner Peer Insights, with 94% of reviewers willing to recommend the platform.” | official | 2026-09-04 |
| s21 | [The Register: report on the FortiClient flaw a Pentera researcher reported](https://www.theregister.com/2024/11/14/fortinet_vpn_authentication_bypass_bug/) “Pentera Labs' bug hunter Nir Chako found and reported the flaw to Fortinet, plus a second security oversight that allows someone or something nefarious on a system running the VPN client to alter SYSTEM-level registry keys that would otherwise be off limits.” | press | 2026-09-04 |
| s22 | [Pentera: press release announcing the EVA Information Security acquisition](https://pentera.io/press-release/pentera-acquires-eva-ai-red-teaming/) “Pentera Acquires AI Red Teaming Leader EVA Information Security” | official | 2026-09-04 |
| s24 | [Pentera: press release announcing the DevOcean acquisition](https://pentera.io/press-release/pentera-acquires-devocean-ai-cyber-risk-remediation/) “Pentera Acquires DevOcean to Automate Cyber Risk Remediation with AI” | official | 2026-09-04 |
| s23 | [Pentera: pricing probe on 2026-09-04, https://pentera.io/pricing/ returned HTTP 404](https://pentera.io/pricing/) | official | 2026-09-04 |

## Disclaimer

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.
