Cybersecurity market intelligence platform
The market intelligence engine for cybersecurity.
3,398 cybersecurity companies and 8,748 products, down to feature sets, NIST CSF 2.0 mappings and buyer-side positioning scores — with 35,000+ dated moves behind them.
Dashboard
Explorer
Radars
Competition
Intel Reports
NIST Profiler
Overview
Market map
Momentum
Funding
Valuations
M&A
Exit Readiness
Hiring
Products
Alert Center
MCP & API
- 3,398
- companies
- 8,748
- products
- 6,178
- funding rounds
- 4,117
- M&A deals
- 35,000+
- signals detected
- 450+
- data points each
- $163B
- capital tracked
See the whole category, not just your five rivals.Company counts, capital, hiring and product coverage across every cybersecurity market.
Dashboard
Explorer
Radars
Competition
Intel Reports
NIST Profiler
Overview
Market map
Momentum
Funding
Valuations
M&A
Exit Readiness
Hiring
Products
Alert Center
MCP & API
Icon size = total capital raised. Axes split on the median. Companies with no disclosed funding are left out of the average — an unknown is not a zero.
Find the white space.
Most products are mapped to NIST CSF 2.0, so you can see which controls nobody is selling into.
Follow the money.
Funding and M&A by category, with deal values on Enterprise.
Watch them without watching them.Websites, pricing pages, LinkedIn, news and job boards. You get an alert, not another browser tab.
Dashboard
Explorer
Radars
Competition
Intel Reports
NIST Profiler
Overview
Market map
Momentum
Funding
Valuations
M&A
Exit Readiness
Hiring
Products
Alert Center
MCP & API
Sep 12, 2026
Palo Alto Networks announced native integration of Prisma Browser with Cortex XDR, bringing deep web telemetry directly into the SOC to enable threat tracing, instant attack containment without endpoint downtime, and protection against shadow AI risks.
Databricks announced that CMSPI, a healthcare consulting firm, deployed Lakebase Postgres to optimize payment processing workflows. The deployment reduced payment optimization work from 30–40+ hours to approximately 30 minutes, and in the first six months identified approximately $27M in realized incremental savings for existing clients.
Acompany announced that its Confidential Computing-powered enterprise generative AI chat service 'Acompany Secure Chat' now supports single sign-on (SSO) integration with HENNGE One, HENNGE's cloud security service. The integration allows HENNGE One users to access Acompany Secure Chat without managing multiple IDs and passwords, while maintaining strong access controls through multi-factor authentication.
Zerosploit MEA and Comforte AG announced a strategic partnership to enhance cybersecurity offerings in the Middle East and Africa region.
Raven published research on LinkedIn analyzing how OpenAI's AI agents discovered a code execution path through RubyGems and RubyDoc's documentation infrastructure. The post breaks down the attack methodology, the role of YARD, and implications for AI-driven attack vectors.
JetStream Security CEO Raj Rajamani published commentary on LinkedIn criticizing proposed AI kill-switch legislation, arguing that regulators are focusing too narrowly on model-level controls rather than system-wide governance. He advocates for kill switches across all components of AI systems, not just the model itself. The post links to a Dark Reading article featuring his perspective.
Exabeam's Country Director for Gulf North and India, Raghu Vamsi, delivered a keynote session at the ETCISO Annual Conclave exploring how organizations can leverage AI-enabled Security Operations Centers. The session covered how AI is changing the SOC role, identifying abnormal behavior across human and AI identities, providing analysts with context to prioritize threats, and accelerating investigation and response. Exabeam is exhibiting at Booth 52 at the event.
IRM Consulting & Advisory publishes a service page describing their DevSecOps (DSO) consulting offerings, including secure CI/CD pipelines, SAST/DAST/IaC scanning, MLSecOps integration, Responsible AI governance, and compliance support for SOC 2 and ISO 27001.
ManageEngine is hosting a live expert-led webinar session for IT and security professionals covering the latest Cyber Essentials framework updates, including stricter MFA requirements, SaaS/IaaS/shadow IT scope expansion, and mobile device security. The session features insights from Graham Cluley and Romanus Raymond Prabhu (Director of Technology at ManageEngine).
Dectrax's Terms of Service page outlining user agreements, account policies, software usage guidelines, intellectual property rights, billing terms, and dispute resolution procedures.
Cybersecurity only.
We track one market, so we know which moves a security buyer reacts to.
Typed and dated.
Funding, product, hiring, executive changes and M&A — every one with the source it came from.
A rival's whole record, on one page.Funding, headcount, executives, products, tech stack, reviews, and every dated move they made.
Dashboard
Explorer
Radars
Competition
Intel Reports
NIST Profiler
Overview
Market map
Momentum
Funding
Valuations
M&A
Exit Readiness
Hiring
Products
Alert Center
MCP & API
Sep 10, 2026
Cyera publishes a case study demonstrating how it used its own platform to audit Snowflake access before deploying Claude Cowork agents to 1,500 employees. The article describes discovering hidden access through nested roles, identifying dormant accounts, and mapping privileged access to ACCOUNTADMIN, positioning Cyera's DSPM and identity capabilities as essential for agent security.
Sep 9, 2026
Cyera announces a unified integration between its Data Security Posture Management (DSPM) and Data Loss Prevention (DLP) capabilities, enabling shared data intelligence to flow between discovery and enforcement. The integration allows DSPM classifications to inform DLP policies and enables direct remediation actions like triggering backups from DLP findings.
Cyera publishes thought leadership on AI agent security risks, analyzing two real-world incidents where AI agents bypassed read-only restrictions to communicate with each other. The article frames Cyera's Agent Guardian platform as a solution for detecting and preventing intent drift across three dimensions: agent-user, agent-organization, and user-organization.
Sep 8, 2026
Cyera publishes thought leadership on 2026 cybersecurity trends, emphasizing how AI adoption, agentic systems, and data fragmentation will test enterprise resilience. The article features insights from Cyera's Office of the CSO on cybercrime acceleration, CISO strategy shifts toward precision, and the emergence of agentic AI as an inflection point enterprises are unprepared for.
Sep 3, 2026
Cyera publishes two complementary thought leadership pieces on AI agent security. The first article ('Before You Secure AI, Secure Your Data') establishes the foundational principle that data security must precede AI security, explaining how sensitive data mismanagement amplifies agent risk and outlining Cyera's Discover-Govern-Protect-Validate framework. The second article ('Why Your Most Useful Agents Are Your Most Exploitable') introduces the 'Lethal Trifecta' concept—agents that read untrusted content, access sensitive data, and send data outbound—and explains how Cyera Agent Guardian automates detection and remediation of this attack pattern.
Cyera announced the launch of Certified Agentic Security Practitioner, a new paid course from Cyera's AI Security School. The five-module, self-paced course covers agent security fundamentals including mapping agent connections, tracing data flow into action, and evaluating vendor security claims before agent deployment.
450+ data points each.
Across 3,398 cybersecurity companies, not a sample.
The history is already there.
We backfill months before your first login, so day one has a past to read.
The brief writes itself.An agent builds the card and the report from the record. Rebuild one and it reads today's evidence, not March's.
Dashboard
Explorer
Radars
Competition
Intel Reports
NIST Profiler
Overview
Market map
Momentum
Funding
Valuations
M&A
Exit Readiness
Hiring
Products
Alert Center
MCP & API
At a glance
| Growth momentum | 62 (Steady) | 44 (Cooling) |
| Headcount | 11,323 | 3,188 |
| Monthly web visits | 2,496,302 | 696,699 |
| Total disclosed funding | $481M | $697M |
Recent moves
SentinelOne: This Week in Cyber: DOJ Disrupts Xinbi, BlueMoon Exploit Kit, Chinese AI Token Extraction
2026-09-11CrowdStrike: CrowdStrike Expands Project QuiltWorks with Geographic Localization in U.S. and Canada
2026-09-10SentinelOne: SentinelOne at Goldman Sachs Communacopia + Technology Conference 2026
2026-09-10CrowdStrike: Wipro and CrowdStrike Launch CISO Command Center to Transform Enterprise Security for Frontier AI Risk
2026-09-09CrowdStrike: SeedCo Enhances Cybersecurity with CrowdStrike for Global Protection
2026-09-08
Never brief from a stale deck.
A rival changes their pricing, the card changes with it.
Every claim carries a source.
Numbers link back to the page, post or filing behind them.
See yourself the way buyers do.A positioning score read by a human security leader, not a model. Seven dimensions, each carrying the evidence behind its mark.
Dashboard
Explorer
Radars
Competition
Intel Reports
NIST Profiler
Overview
Market map
Momentum
Funding
Valuations
M&A
Exit Readiness
Hiring
Products
Alert Center
MCP & API
How Oasis Security reads to a CISO buyer
Verdict
Oasis sells to the person who signs. The homepage puts Fortune 500 logos and quantified business outcomes above the fold, five industry pages speak to regulated buyers, and the published SLA and DPA give procurement something real to read. The Agentic Access Management page is the strongest asset on the site and the easiest to miss: real product screenshots, a 2:29 walkthrough, the AI platforms it brokers access to named one by one, and a chain of custody that names its own links.
Two things hold the score at 6.5. The hero still leads with a category Oasis invented, so a buyer searching for non-human identity security meets that phrase only in the browser tab and the nav dropdown. And the answer to "why not Microsoft, why not the IGA and PAM we already own" is written, but it is in the blog, while Why Oasis leads with "Superior Insights" and "best in class".
Read this as a re-score. The number has not moved since 29 August because the site has not moved. Measured on 8 September, the product and Why Oasis pages are identical to their 27 August versions, and the homepage changed by exactly one line: the banner now reads "Oasis has been acquired by Cyera", where on 27 August it read "Oasis + Cyera: Building the Next-Generation AI Security Platform". The Cyera deal is closed. Every fix the last score asked for is still open.
The homepage H1 is still "Agentic Access Management", the category Oasis trademarks as AAM. The subhead does real work: "Access control that understands intent, not just static roles and permissions." But "non-human identity" never appears in the hero a visitor reads. It sits in the browser tab title and the Product nav dropdown. The plain sentence, "Oasis secures AI agents and non-human identities across IaaS, SaaS, PaaS, and on-prem", is a full scroll down.
Claims a rival could not honestly copy do exist: Oasis Scout with AuthPrint threat-actor fingerprinting on /product, and on /agentic-access-management a chain of custody that names its own links, "Prompt, Intent, Policy, Session, Action", plus a short-lived identity per session. But Why Oasis, where a buyer goes for "why not them", still leads with "Breadth of integrations" and "Superior Insights ... best in class". No named rival on any page, and none answers Microsoft Agent 365.
Checkable and strong: readable Fortune 500 logos in the homepage hero (Citizens Financial, BlueCross BlueShield, Chipotle, Mars), a five-line Business Impact strip of quantified outcomes, seven award badges, and original vulnerability research on the Cursor autorun flaw. Two gaps hold it here. Measured 8 September: G2 shows 0 reviews, Gartner Peer Insights 1 review at 5.0. Both customer quotes are anonymous roles, and SOC 2 and ISO 27001 are footer images with no trust centre behind them.
The homepage Business Impact strip is board language: a Fortune-50 healthcare provider avoiding a $3 to 5M HIPAA fine, a Fortune-500 logistics firm cutting secret-rotation effort by 35%, an F300 CPG cutting attack surface 60% during a POV. Procurement gets a published SLA with 99.9% uptime, service credits and severity response times, plus a DPA. Five industry pages address regulated buyers. Short of the top band: framework mapping is asserted on the governance page, never shown.
Integrations are named, not implied: Okta, Ping, HashiCorp Vault, Azure Key Vault and AWS KMS on /product, and on /agentic-access-management the AI platforms themselves, Claude, OpenAI, Microsoft Copilot, Cursor, Gemini and Glean. That page carries real product screenshots of a Cursor session escalating into Databricks and a 2:29 walkthrough video, the strongest architect-facing proof on the site. Still missing: public docs, an API reference, a stated deployment model and a data-handling page.
Two registers on one site. The AAM page is the good one: "No standing privilege, no long-lived tokens, no hard-coded secrets." The product page is where it slips, and none of it moved in ten days. Inventory still promises "a consolidated single pane of glass", the opening strip still says "Leverage AI-powered insights", and Context still reads "The system goes beyond raw data by furnishing essential contextual information." The lifecycle strip still misspells "Decomission".
Measured against the full sitemap on 8 September: 264 URLs, no pricing page. No page names an edition, a tier, or a unit of pricing, and every route is Request a Demo or Chat with Us. What is public is the contract, not the packaging: the SLA states 99.9% uptime, a service-credit table and severity response times, and a DPA and subscription agreement are published. The nav does name two products, NHI Security Cloud and Agentic Access Management, and that is the only shape a buyer gets.
Fix these first
- 1Put the searched category in the H1. Lead with non-human identity and AI agent access, and keep Agentic Access Management as the sub-line. Today "non-human identity" appears only in the browser tab and the nav dropdown.
- 2Promote the Agentic Access Management page. It carries the site's best proof and its clearest copy, but it sits one nav item deep and nothing on the homepage links to it. The homepage banner points at the Cyera post instead.
- 3Move the "why not them" answer onto Why Oasis. The IGA, PAM, CSPM and Microsoft Agent 365 comparisons already exist as blog posts. Put them on the page, and replace "Superior Insights" with the Scout and AuthPrint claims.
- 4Publish packaging without publishing prices. Name the editions, state the unit (per non-human identity, per environment, or per workload) and any minimum, so a CISO can build a budget line before booking a demo.
- 5Stand the trust signals up. Link the SOC 2 and ISO 27001 footer badges to a trust centre, and ask three reference customers for Gartner Peer Insights reviews. Measured 8 September: G2 shows 0, Gartner shows 1.

Turn CISO bounce rates into pipeline conversion.
Generic positioning loses enterprise deals. I score your homepage, sales deck and funding deck against the seven checks above, then rewrite what fails. Buyers and investors get your value in 30 seconds.
See what you getA person reads it.
An enterprise security leader goes through your site the way a buyer would.
It says where you lose them.
Not a grade. The line on your page that makes a CISO close the tab.
Ask your AI instead.46 tools on a native MCP server. Works with Claude, ChatGPT, Cursor and Windsurf.
Dashboard
Explorer
Radars
Competition
Intel Reports
NIST Profiler
Overview
Market map
Momentum
Funding
Valuations
M&A
Exit Readiness
Hiring
Products
Alert Center
MCP & API
46 tools
Docs- get_company_overview
- search_funding_rounds
- get_company_momentum
- get_competitive_landscape
- search_site_changes
- get_radar_insights
- compare_companies
- get_market_summary
+ 38 more
Bundled with every plan.
Monthly credits included. No separate contract, no separate bill.
The same record, no dashboard.
Your assistant reads it directly and cites what it used.
Deeper than the databases.
Generic databases stop at the company logo. Mandos goes product-level — because deals are won against products, not logos.
Company level
- Funding history
- Valuation estimates
- Headcount & hiring
- Executives & churn
- Investors & board
- Momentum score
Product level
- 8,748 products mapped
- Feature sets
- Integrations
- Tech stacks
- NIST CSF 2.0 on most
- Published pricing
Signal level
- 35,000+ dated moves
- Website rewrites
- Launches & releases
- M&A, priced where disclosed
- Executive changes
- Full history kept
Plans sized by how much you track.
Starter tracks 5 companies for one seat. Professional tracks 15 across 3 seats. Enterprise is unlimited.
Questions founders ask.
- Why use this instead of PitchBook or Crunchbase?
- They cover every industry and stop at the company. Mandos only tracks cybersecurity. We hold 3,398 cybersecurity companies and 8,748 security products, most of them mapped to NIST CSF 2.0 controls, and we record what they do week by week.
- How often do you check for updates?
- We check websites and pricing pages weekly. We check news, RSS feeds, and LinkedIn every four hours. Every recorded move carries the date it actually happened, not the date we found it.
- What exactly counts as a move?
- A move is a dated record of what a company did. Examples include product launches, funding rounds, acquisitions, executive changes and website rewrites. Around 800 land in a normal week, and every one goes into that company's timeline.
- Why pay for this instead of a cheap page-watching tool?
- Page watchers only watch the exact pages you hand them. Mandos already holds the record, funding, hiring, and category for 3,398 cybersecurity companies. You are paying for the whole market, not just watching five websites.
- Can my AI assistant use this data?
- Yes. We run an MCP server with 46 tools that works with Claude, ChatGPT, Cursor and Windsurf. Every platform plan includes monthly MCP credits.
- Can I see the data before I pay?
- Yes, you can book a 30-minute demo with the founder. You can also ask for one company's full profile for free, with no card and no call. The founder approves each request first, so it is not instant.
More on the server and its tools at /mcp.