Company lists · Data refreshed September 2026

Top 22 Software vulnerability assessment companies based in San Francisco, United States

RevenueBase identified 51 software vulnerability assessment companies headquartered in San Francisco, United States as of September 2026 and tracks 10,864 professional contacts across them, including 1,040 with verified work emails. San Francisco is the largest hub.

This list covers software vulnerability assessment companies headquartered in San Francisco, United States, matched on what each company actually does as described in its own words. Ranked by team size, largest first. Every row shows the company's own description, its RevenueBase Smart Search rating, and when it was last checked. Data refreshed September 6, 2026.

Published by RevenueBase, a B2B data infrastructure company. This list was built with RevenueBase Smart Search, the natural-language company search RevenueBase customers use to build their own targeted lists and unlock verified emails and direct dials at the companies on them. How these lists are built and judged.

How to read this list HQ checked on every row RevenueBase Smart Search rating on every row Refreshed Sep 6, 2026 86% judged on-target in blind review
51Companies
10,864Contacts tracked
1,040Verified emails
Explore this list → Free signup · no credit card · 500 free credits

The 22 largest software vulnerability assessment companies based in San Francisco, United States

Ranked by team size
Top 22 of 51 software vulnerability assessment companies based in San Francisco, United States, ranked by team size, largest first. Data refreshed Sep 6, 2026. RevenueBase Smart Search rates how each company's information relates to software vulnerability assessment companies: strong evidence (its own description names it), partial (names part of it), indirect (matched on the rest of its profile rather than the description shown). Click a contact count to view that company's people.
#CompanyRevenueBase Smart SearchHeadquartersEmployeesContacts
1Indirect evidenceSan Francisco, CA, United StatesHQ checked Sep 6, 2026n/a6,058 contacts →

“HackerOne is a global leader in Continuous Threat Exposure Management (CTEM) and the only solution provider that pairs the simultaneous trust of the Fortune 500 and the world's…”

Source: company website · checked Sep 6, 2026
2Indirect evidenceSan Francisco, CA, United StatesHQ checked Sep 6, 2026n/a3,649 contacts →

“We are a crowdsourced security company that safeguards organizations' assets from sophisticated threat actors before they can strike-by uniting our customers with trusted hackers…”

Source: company website · checked Sep 6, 2026
3Indirect evidenceSan Francisco, CA, United StatesHQ checked Sep 6, 2026201-500350 contacts →

“Cobalt is the pioneer in pentesting as a service and a leader in offensive security services.”

Source: company website · checked Sep 6, 2026
4Partial evidenceSan Francisco, CA, United StatesHQ checked Sep 6, 202651-200208 contacts →

“TAC Security (NSE: TAC) TAC Security, a leading publicly listed global cybersecurity company specializing in vulnerability management, today serves clients across 100 countries…”

Source: company website · checked Sep 6, 2026
5Partial evidenceSan Francisco, CA, United StatesHQ checked Sep 6, 202651-200167 contacts →

“Fluid Attacks helps companies prevent, detect, manage and remediate vulnerabilities across their application attack surface.”

Source: company website · checked Sep 6, 2026
6Partial evidenceSan Francisco, CA, United StatesHQ checked Sep 6, 202651-20055 contacts →

“Mondoo's Agentic Managed Vulnerability Service, a combination of local expert security professionals and a proven AI-native platform, delivers the outcomes security professionals…”

Source: company website · checked Sep 6, 2026
7Indirect evidenceSan Francisco, CA, United StatesHQ checked Sep 6, 202611-5051 contacts →

“The APIsec security testing platform discovers business logic exploits.”

Source: company website · checked Sep 6, 2026
8Partial evidenceSan Francisco, CA, United StatesHQ checked Sep 6, 202611-5047 contacts →

Software ships daily.”

Source: company website · checked Sep 6, 2026
9Indirect evidenceSan Francisco, CA, United StatesHQ checked Sep 6, 202611-5043 contacts →

“Escape automates the full offensive security lifecycle, multiplying the impact of every security engineer tenfold.”

Source: company website · checked Sep 6, 2026
10Indirect evidenceSan Francisco, CA, United StatesHQ checked Sep 6, 202611-5027 contacts →

“We specialize in Web Application and API penetration Testing, Cyber Threat Intelligence, and Detecting Account Takeovers (ATOs) from attackers.”

Source: company website · checked Sep 6, 2026
11Partial evidenceSan Francisco, CA, United StatesHQ checked Sep 6, 202611-5023 contacts →

“Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.”

Source: company website · checked Sep 6, 2026
12Partial evidenceSan Francisco, CA, United StatesHQ checked Sep 6, 202611-5012 contacts →

“RunSybil is an AI-native offensive security platform that autonomously discovers and exploits real-world vulnerabilities across modern applications.”

Source: company website · checked Sep 6, 2026
13Indirect evidenceSan Francisco, CA, United StatesHQ checked Sep 6, 202611-508 contacts →

“Web pentesting with Defensive Security and Offensive Security.”

Source: company website · checked Sep 6, 2026
14Indirect evidenceSan Francisco, CA, United StatesHQ checked Sep 6, 202611-506 contacts →

“Humanize is an innovative and data-conscious company that transforms cybersecurity weaknesses to human readable quantified risks for C-Suite.”

Source: company website · checked Sep 6, 2026
15Partial evidenceSan Francisco, United StatesHQ checked Sep 6, 20261-106 contacts →

“We believe that recent advancements in Large Language Models (LLMs) present a unique opportunity to automate or heavily augment the identification, assessment, and remediation of…”

Source: company website · checked Sep 6, 2026
16Partial evidenceSan Francisco, United StatesHQ checked Sep 6, 20261-105 contacts →

“We make it easy to catch critical vulnerabilities in your web app or API so you don't wake up to a bad breach.”

Source: company website · checked Sep 6, 2026
17Partial evidenceSan Francisco, CA, United StatesHQ checked Sep 6, 20261-104 contacts →

“Gecko finds and fixes security vulnerabilities in your codebase, just like having a security engineer making your code secure.”

Source: company website · checked Sep 6, 2026
18Indirect evidenceSan Francisco, CA, United StatesHQ checked Sep 6, 20261-103 contacts →

“SecureNexa is a global cybersecurity partner for small and mid-sized businesses.”

Source: company website · checked Sep 6, 2026
19Indirect evidenceSan Francisco, CA, United StatesHQ checked Sep 6, 20261-102 contacts →

“Defend against cyber criminals with engaging security awareness and social engineering prevention videos, training, talks and penetration testing.”

Source: company website · checked Sep 6, 2026
20Indirect evidenceSan Francisco, CA, United StatesHQ checked Sep 6, 202611-502 contacts →

“Lucent Sky designs tools to accelerate and scale application security processes.”

Source: company website · checked Sep 6, 2026
21Strong evidenceSan Francisco, CA, United StatesHQ checked Sep 6, 20261-102 contacts →

“Cobaltix Compliance provides risk assessments, creates policies and procedures, conducts vulnerability assessments and penetration testing, and performs vendor due diligence…”

Source: company website · checked Sep 6, 2026
22Indirect evidenceSan Francisco, CA, United StatesHQ checked Sep 6, 20261-101 contacts →

“Secure your website in 10 minutes.”

Source: company website · checked Sep 6, 2026

Showing 22 of 51 software vulnerability assessment companies based in San Francisco, United States

See the full list, filter by size, metro and specialty, and get verified emails and direct dials for all 1,040 reachable decision-makers.

Free signup · no credit card

View the full list →

Software vulnerability assessment companies based in San Francisco, United States at a glance

As of Sep 6, 2026
9.6%Verified-email coverage
213.0Average contacts per company
11-50Median size (employees)
100.0%Largest-city concentration · San Francisco
Sep 6, 2026Page data refreshed

Companies by employee count

1-10
23
11-50
17
51-200
8
201-500
3

Email recency for this list is measured across the whole United States list rather than this city, so it is reported there. Company counts and contact totals on this page are exact for San Francisco, over 51 companies.

How this list was built

Company categories are rarely black and white. RevenueBase reads each company's own description of its business to decide whether it belongs among software vulnerability assessment companies, so some rows will be adjacent to the category rather than pure plays. The description and RevenueBase Smart Search rating on every row are there so you can check each match yourself.

Source
The RevenueBase company graph: 60 million companies and 398.9 million professional contacts resolved from primary sources, queried with RevenueBase Smart Search, the natural-language company search available to every RevenueBase user.
What qualifies
Companies headquartered in San Francisco, United States whose own description of what they do matches “software vulnerability assessment companies”. Matching reads each company's description, not its industry code or its name.
RevenueBase Smart Search
RevenueBase Smart Search is how this list is assembled and how each row is rated. RevenueBase's data engine and AI assess a company's LinkedIn profile, information supplied directly by the company, its website and other publicly available information, then relate it to a category defined in a user's own words. Each row is rated strong evidence (its own description names software vulnerability assessment companies), partial evidence (it names part of the category) or indirect evidence (the description shown names none of it and the match rests on the rest of the company's profile). The description supporting each rating is quoted on the row.
What we exclude
Companies whose own description does not clearly place them among software vulnerability assessment companies, and records with no verified work email. Companies headquartered outside San Francisco are excluded even when they keep an office there.
Match quality
In blind human judging of this matching method, 86% of matched companies were on target. Expect roughly 1 in 7 rows to be adjacent to the category rather than a pure play. Every row shows the company's own description and its RevenueBase Smart Search rating so you can judge each match yourself. Read the full methodology: how the lists are built, how the judging worked, and what the figure means.
Ranking
Team size, largest first: companies are ordered by the number of professionals RevenueBase tracks at each one. Employee ranges shown are reported bands, for context.
Verification
Every listed company carries at least one verified work email, 1,040 across the full list. Contacts re-verify on a rolling cadence, and each contact's own verification date is shown inside RevenueBase.
Refresh
This page's figures were pulled from the company graph on September 6, 2026. Lists refresh periodically as the graph is re-checked.
Corrections
Wrong category, wrong headquarters, or a company that has closed? Use “Report an issue” on any row. Reports go to the RevenueBase Data Team and feed back into the company graph.

Software vulnerability assessment companies by metro in the United States

Frequently asked

What is RevenueBase Smart Search?

RevenueBase Smart Search is how RevenueBase decides which companies belong on this list and how strongly each one fits. Its data engine and AI assess a company's LinkedIn profile, information supplied directly by the company, its website and other publicly available information, then relate it to the category the list is about. Each row is rated strong evidence when the company's own description names software vulnerability assessment companies, partial evidence when it names part of the category, and indirect evidence when the description shown names none of it and the match rests on the rest of the company's profile.

How many software vulnerability assessment companies are there based in San Francisco, United States?

RevenueBase identified 51 software vulnerability assessment companies headquartered in San Francisco, United States as of September 2026, matched on each company's own description of what it does rather than its industry code.

What is the largest company on this list?

Hackerone, headquartered in San Francisco, tops this list with the largest team on record.

Which city has the most software vulnerability assessment companies?

San Francisco leads with 51 headquartered companies, followed by New York (47) and Austin (30).

How do I get contact information for these companies?

A free RevenueBase account lets you run this exact search and work the top results, verified emails and direct dials included. Upgrading unlocks all 1,040 verified decision-maker contacts tracked across these 51 companies.

How current is this list?

The list refreshes periodically as the company graph is re-checked. This page's figures were pulled on September 6, 2026.

Ready to reach these companies? Verified emails and direct dials for all 51 software vulnerability assessment companies based in San Francisco, United States. Start with a free account, no credit card.

Download this list →

Related lists

About this data

RevenueBase is a B2B data infrastructure company. Its company graph covers 60 million companies and 398.9 million professional contacts, with emails verified on a rolling cadence rather than scraped once and left to decay. These company lists are generated directly from that graph with RevenueBase Smart Search, the same natural-language company search every RevenueBase user has: describe a market in plain words, get the companies that match, and add verified emails and direct dials for the people at them. It is the same data that powers RevenueBase's B2B data products, and a free account includes 500 credits to start. How these lists are built and judged.