Company lists · Data refreshed September 2026
Top 22 Software vulnerability assessment companies based in San Francisco, United States
RevenueBase identified 51 software vulnerability assessment companies headquartered in San Francisco, United States as of September 2026 and tracks 10,864 professional contacts across them, including 1,040 with verified work emails. San Francisco is the largest hub.
This list covers software vulnerability assessment companies headquartered in San Francisco, United States, matched on what each company actually does as described in its own words. Ranked by team size, largest first. Every row shows the company's own description, its RevenueBase Smart Search rating, and when it was last checked. Data refreshed September 6, 2026.
Published by RevenueBase, a B2B data infrastructure company. This list was built with RevenueBase Smart Search, the natural-language company search RevenueBase customers use to build their own targeted lists and unlock verified emails and direct dials at the companies on them. How these lists are built and judged.
The 22 largest software vulnerability assessment companies based in San Francisco, United States
Ranked by team size| # | Company | RevenueBase Smart Search | Contacts | ||
|---|---|---|---|---|---|
| 1 | Indirect evidence | 6,058 contacts → | |||
“HackerOne is a global leader in Continuous Threat Exposure Management (CTEM) and the only solution provider that pairs the simultaneous trust of the Fortune 500 and the world's…” Source: company website · checked Sep 6, 2026Thanks. The Data Team will review it. | |||||
| 2 | Indirect evidence | 3,649 contacts → | |||
“We are a crowdsourced security company that safeguards organizations' assets from sophisticated threat actors before they can strike-by uniting our customers with trusted hackers…” Source: company website · checked Sep 6, 2026Thanks. The Data Team will review it. | |||||
| 3 | Indirect evidence | 350 contacts → | |||
“Cobalt is the pioneer in pentesting as a service and a leader in offensive security services.” Source: company website · checked Sep 6, 2026Thanks. The Data Team will review it. | |||||
| 4 | Partial evidence | 208 contacts → | |||
“TAC Security (NSE: TAC) TAC Security, a leading publicly listed global cybersecurity company specializing in vulnerability management, today serves clients across 100 countries…” Source: company website · checked Sep 6, 2026Thanks. The Data Team will review it. | |||||
| 5 | Partial evidence | 167 contacts → | |||
“Fluid Attacks helps companies prevent, detect, manage and remediate vulnerabilities across their application attack surface.” Source: company website · checked Sep 6, 2026Thanks. The Data Team will review it. | |||||
| 6 | Partial evidence | 55 contacts → | |||
“Mondoo's Agentic Managed Vulnerability Service, a combination of local expert security professionals and a proven AI-native platform, delivers the outcomes security professionals…” Source: company website · checked Sep 6, 2026Thanks. The Data Team will review it. | |||||
| 7 | Indirect evidence | 51 contacts → | |||
“The APIsec security testing platform discovers business logic exploits.” Source: company website · checked Sep 6, 2026Thanks. The Data Team will review it. | |||||
| 8 | Partial evidence | 47 contacts → | |||
“Software ships daily.” Source: company website · checked Sep 6, 2026Thanks. The Data Team will review it. | |||||
| 9 | Indirect evidence | 43 contacts → | |||
“Escape automates the full offensive security lifecycle, multiplying the impact of every security engineer tenfold.” Source: company website · checked Sep 6, 2026Thanks. The Data Team will review it. | |||||
| 10 | Indirect evidence | 27 contacts → | |||
“We specialize in Web Application and API penetration Testing, Cyber Threat Intelligence, and Detecting Account Takeovers (ATOs) from attackers.” Source: company website · checked Sep 6, 2026Thanks. The Data Team will review it. | |||||
| 11 | Partial evidence | 23 contacts → | |||
“Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.” Source: company website · checked Sep 6, 2026Thanks. The Data Team will review it. | |||||
| 12 | Partial evidence | 12 contacts → | |||
“RunSybil is an AI-native offensive security platform that autonomously discovers and exploits real-world vulnerabilities across modern applications.” Source: company website · checked Sep 6, 2026Thanks. The Data Team will review it. | |||||
| 13 | Indirect evidence | 8 contacts → | |||
“Web pentesting with Defensive Security and Offensive Security.” Source: company website · checked Sep 6, 2026Thanks. The Data Team will review it. | |||||
| 14 | Indirect evidence | 6 contacts → | |||
“Humanize is an innovative and data-conscious company that transforms cybersecurity weaknesses to human readable quantified risks for C-Suite.” Source: company website · checked Sep 6, 2026Thanks. The Data Team will review it. | |||||
| 15 | Partial evidence | 6 contacts → | |||
“We believe that recent advancements in Large Language Models (LLMs) present a unique opportunity to automate or heavily augment the identification, assessment, and remediation of…” Source: company website · checked Sep 6, 2026Thanks. The Data Team will review it. | |||||
| 16 | Partial evidence | 5 contacts → | |||
“We make it easy to catch critical vulnerabilities in your web app or API so you don't wake up to a bad breach.” Source: company website · checked Sep 6, 2026Thanks. The Data Team will review it. | |||||
| 17 | Partial evidence | 4 contacts → | |||
“Gecko finds and fixes security vulnerabilities in your codebase, just like having a security engineer making your code secure.” Source: company website · checked Sep 6, 2026Thanks. The Data Team will review it. | |||||
| 18 | Indirect evidence | 3 contacts → | |||
“SecureNexa is a global cybersecurity partner for small and mid-sized businesses.” Source: company website · checked Sep 6, 2026Thanks. The Data Team will review it. | |||||
| 19 | Indirect evidence | 2 contacts → | |||
“Defend against cyber criminals with engaging security awareness and social engineering prevention videos, training, talks and penetration testing.” Source: company website · checked Sep 6, 2026Thanks. The Data Team will review it. | |||||
| 20 | Indirect evidence | 2 contacts → | |||
“Lucent Sky designs tools to accelerate and scale application security processes.” Source: company website · checked Sep 6, 2026Thanks. The Data Team will review it. | |||||
| 21 | Strong evidence | 2 contacts → | |||
“Cobaltix Compliance provides risk assessments, creates policies and procedures, conducts vulnerability assessments and penetration testing, and performs vendor due diligence…” Source: company website · checked Sep 6, 2026Thanks. The Data Team will review it. | |||||
| 22 | Indirect evidence | 1 contacts → | |||
“Secure your website in 10 minutes.” Source: company website · checked Sep 6, 2026Thanks. The Data Team will review it. | |||||
RevenueBase Smart Search
RevenueBase Smart Search assesses information from a company’s LinkedIn profile, information supplied directly by the company, its website, and other publicly available sources. It uses that information to rate how closely the company relates to this list’s category: software vulnerability assessment companies. Every row carries its rating and the description the rating was read from, so each one can be checked rather than taken on trust.
- Strong evidence
- The company's own public description of its business names software vulnerability assessment companies.
- Partial evidence
- Its own public description names part of software vulnerability assessment companies, so it works in or next to the category without describing itself that way.
- Indirect evidence
- The description shown does not name software vulnerability assessment companies. The match rests on the rest of the company's public profile rather than the one sentence quoted here, so this is the rating to check first.
RevenueBase Smart Search is how these lists are built: RevenueBase's data engine and AI assemble the companies that match a category defined in a user's own words, so a list can be about what companies actually do rather than about whichever industry code they were filed under.
Showing 22 of 51 software vulnerability assessment companies based in San Francisco, United States
See the full list, filter by size, metro and specialty, and get verified emails and direct dials for all 1,040 reachable decision-makers.
Free signup · no credit card
Software vulnerability assessment companies based in San Francisco, United States at a glance
As of Sep 6, 2026Companies by employee count
Email recency for this list is measured across the whole United States list rather than this city, so it is reported there. Company counts and contact totals on this page are exact for San Francisco, over 51 companies.
How this list was built
Company categories are rarely black and white. RevenueBase reads each company's own description of its business to decide whether it belongs among software vulnerability assessment companies, so some rows will be adjacent to the category rather than pure plays. The description and RevenueBase Smart Search rating on every row are there so you can check each match yourself.
- Source
- The RevenueBase company graph: 60 million companies and 398.9 million professional contacts resolved from primary sources, queried with RevenueBase Smart Search, the natural-language company search available to every RevenueBase user.
- What qualifies
- Companies headquartered in San Francisco, United States whose own description of what they do matches “software vulnerability assessment companies”. Matching reads each company's description, not its industry code or its name.
- RevenueBase Smart Search
- RevenueBase Smart Search is how this list is assembled and how each row is rated. RevenueBase's data engine and AI assess a company's LinkedIn profile, information supplied directly by the company, its website and other publicly available information, then relate it to a category defined in a user's own words. Each row is rated strong evidence (its own description names software vulnerability assessment companies), partial evidence (it names part of the category) or indirect evidence (the description shown names none of it and the match rests on the rest of the company's profile). The description supporting each rating is quoted on the row.
- What we exclude
- Companies whose own description does not clearly place them among software vulnerability assessment companies, and records with no verified work email. Companies headquartered outside San Francisco are excluded even when they keep an office there.
- Match quality
- In blind human judging of this matching method, 86% of matched companies were on target. Expect roughly 1 in 7 rows to be adjacent to the category rather than a pure play. Every row shows the company's own description and its RevenueBase Smart Search rating so you can judge each match yourself. Read the full methodology: how the lists are built, how the judging worked, and what the figure means.
- Ranking
- Team size, largest first: companies are ordered by the number of professionals RevenueBase tracks at each one. Employee ranges shown are reported bands, for context.
- Verification
- Every listed company carries at least one verified work email, 1,040 across the full list. Contacts re-verify on a rolling cadence, and each contact's own verification date is shown inside RevenueBase.
- Refresh
- This page's figures were pulled from the company graph on September 6, 2026. Lists refresh periodically as the graph is re-checked.
- Corrections
- Wrong category, wrong headquarters, or a company that has closed? Use “Report an issue” on any row. Reports go to the RevenueBase Data Team and feed back into the company graph.
Software vulnerability assessment companies by metro in the United States
- Software vulnerability assessment companies in San Francisco51
- Software vulnerability assessment companies in New York47
- Software vulnerability assessment companies in Austin30
Frequently asked
What is RevenueBase Smart Search?
RevenueBase Smart Search is how RevenueBase decides which companies belong on this list and how strongly each one fits. Its data engine and AI assess a company's LinkedIn profile, information supplied directly by the company, its website and other publicly available information, then relate it to the category the list is about. Each row is rated strong evidence when the company's own description names software vulnerability assessment companies, partial evidence when it names part of the category, and indirect evidence when the description shown names none of it and the match rests on the rest of the company's profile.
How many software vulnerability assessment companies are there based in San Francisco, United States?
RevenueBase identified 51 software vulnerability assessment companies headquartered in San Francisco, United States as of September 2026, matched on each company's own description of what it does rather than its industry code.
What is the largest company on this list?
Hackerone, headquartered in San Francisco, tops this list with the largest team on record.
Which city has the most software vulnerability assessment companies?
San Francisco leads with 51 headquartered companies, followed by New York (47) and Austin (30).
How do I get contact information for these companies?
A free RevenueBase account lets you run this exact search and work the top results, verified emails and direct dials included. Upgrading unlocks all 1,040 verified decision-maker contacts tracked across these 51 companies.
How current is this list?
The list refreshes periodically as the company graph is re-checked. This page's figures were pulled on September 6, 2026.
Ready to reach these companies? Verified emails and direct dials for all 51 software vulnerability assessment companies based in San Francisco, United States. Start with a free account, no credit card.
Download this list →Related lists
Software vulnerability assessment companies by geography
- Software vulnerability assessment companies based in the United States
- Software vulnerability assessment companies based in the United Kingdom
- Software vulnerability assessment companies based in Canada
- Software vulnerability assessment companies based in Australia
- Software vulnerability assessment companies based in France
- Software vulnerability assessment companies based in Germany
- Software vulnerability assessment companies based in Brazil
- Software vulnerability assessment companies based in the Netherlands
- Software vulnerability assessment companies based in Israel
- Software vulnerability assessment companies based in Spain
- Software vulnerability assessment companies based in Italy
- Software vulnerability assessment companies based in Switzerland
Browse the directory
Browse: Companies home · Software vulnerability assessment companies in United States · All United States lists · All Software vulnerability assessment companies lists · New lists
About this data
RevenueBase is a B2B data infrastructure company. Its company graph covers 60 million companies and 398.9 million professional contacts, with emails verified on a rolling cadence rather than scraped once and left to decay. These company lists are generated directly from that graph with RevenueBase Smart Search, the same natural-language company search every RevenueBase user has: describe a market in plain words, get the companies that match, and add verified emails and direct dials for the people at them. It is the same data that powers RevenueBase's B2B data products, and a free account includes 500 credits to start. How these lists are built and judged.
More company lists
- All company lists
- Lists by location
- Lists A-Z
- New lists
- Software vulnerability assessment companies based in the United States
- Software vulnerability assessment companies based in the United Kingdom
- Software vulnerability assessment companies based in Canada
- Software vulnerability assessment companies based in Australia
- Software vulnerability assessment companies based in France
- Software vulnerability assessment companies based in Germany