Provides manual penetration testing and vulnerability disclosure programs tailored for startups, using methodologies like OWASP ASVS, NIST SP 800-53A, and OSSTMM to identify and remediate security flaws in web applications, APIs, and networks. Helps businesses meet compliance requirements for SOC2, ISO 27001, and HIPAA while offering on-demand reports, remediation guidance, and year-round CISO-like support via Slack.
Funding
$120K raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.


Founders
Product
Problem
Startups often lack the resources for comprehensive, continuous security assessments, leaving them vulnerable to attacks and making it difficult to meet compliance requirements like SOC2, ISO 27001, and HIPAA. Traditional penetration testing can be expensive and infrequent, failing to provide ongoing protection against evolving threats.
Solution
Federacy provides on-demand penetration testing and vulnerability disclosure programs tailored for startups, helping them identify and remediate security flaws in web applications, APIs, and network infrastructure. Their manual penetration testing simulates real-world attacks, uncovering vulnerabilities through rigorous evaluation methodologies incorporating OWASP ASVS, NIST SP 800-53A, and OSSTMM. Federacy also offers ongoing support via Slack, acting as a virtual CISO to assist with architectural decisions, dependency risk assessment, and vulnerability remediation. The platform provides on-demand reports and letters of attestation to satisfy auditor, partner, and customer security requests.
Target Audience
Federacy's primary customers are startups that need to satisfy SOC2, ISO 27001, HIPAA, and other compliance requirements, as well as meet vendor security assessment requests.
Features
- Manual penetration testing with over 100 hours of testing and 200 individual security checks
- Methodologies include OWASP ASVS, OWASP Testing Guide v5, NIST SP 800-53A, and OSSTMM
- Flexible team sizes and turnaround times as quick as 3 weeks
- Remediation advice and retesting included
- Issue tracking through the Federacy Inbox
- On-demand reports and letters of attestation
- Year-round CISO-like guidance via Slack for security-related questions