Startup Diligence
Diligence report Cybersecurity / digital fraud prevention Private growth stage 2026-06-19

HUMAN Security

Internet-scale bot, fraud, and agentic trust platform

HUMAN Security appears strategically relevant and plausibly fairly valued on disclosed scale and cybersecurity-peer benchmarks, but public evidence is not strong enough on ARR quality, retention, margin, and debt status to support a conviction investment call.

Cover facts

Last disclosed valuation 01
$1.5B USD [CO026, CV003]
Latest funding round 03
$50M+ USD [CO025, CV004]
Weekly interactions verified 06
20T+ interactions [CO007, CI006]
Founded 07
2012 [CO001]
Headquarters 08
New York City [CO005]

Company profile

HUMAN Security was founded in 2012 as White Ops and rebranded in 2021 as it expanded from ad-fraud detection into a broader digital trust platform. The company now sells the Human Defense Platform across media security, application security, account protection, and agentic trust use cases, operating at internet scale with 20T+ verified weekly interactions and 500+ customer brands. Ownership and governance shifted materially after the 2020 Goldman Sachs/ClearSky/NightDragon acquisition, the 2022 PerimeterX merger, and the 2024 growth round. Despite strong strategic positioning and clear product-market relevance, the business remains financially opaque on revenue growth, retention, margins, and current valuation.

Website
www.humansecurity.com
Founded
2012-01-01
Founders
Tamer Hassan, Michael Tiffany, Dan Kaminsky, Ash Kalb
Founding location
Brooklyn, New York, USA
Headquarters
New York City, New York, USA
Product
The Human Defense Platform combines bot mitigation, ad-fraud detection, application and account-abuse defense, threat intelligence, and newer agentic-AI governance products such as HUMAN Sightline and AgenticTrust. It uses large-scale telemetry, device intelligence, behavioral signals, and the Satori Threat Intelligence team to classify and disrupt malicious automation in real time.
Customers
Large digital businesses, adtech and media platforms, marketplaces, retailers, financial-services firms, and enterprise security teams that need to reduce fraud, invalid traffic, scraping, account takeover, and AI-agent abuse.
Business model
Enterprise cybersecurity software and managed intelligence platform sold through direct and partner channels across media security, application security, account protection, and trust-layer workflows.
Stage
Private growth stage
Funding status
Approximately $300M total equity raised. Latest financing: $50M+ growth round announced in October 2024 led by WestCap with Goldman Sachs Asset Management, ClearSky Security, NightDragon, and Vertex Ventures US. A $100M Blackstone Credit facility was also disclosed in 2022.
[CO001, CO004, CO005, CO006, CO007, CO010, CO021, CO025]

Executive summary

Top strengths

  • Internet-scale telemetry and threat-intelligence network built on 20T+ weekly verified interactions.
  • Strong institutional backing with repeat support from Goldman Sachs, WestCap, NightDragon, ClearSky, and Vertex.
  • Product footprint spans media security, application protection, account abuse defense, and agentic-AI trust.
  • Credible external recognition including Forrester leadership and strong customer-review surfaces in 2026.

Top risks

  • Public financial opacity leaves ARR quality, retention, margin, and debt burden materially underwritten.
  • Bundled competition from Cloudflare, Akamai, Google, and other platform vendors can compress standalone pricing power.
  • Behavioral-data and fingerprinting models face evolving privacy and data-transfer regulation.
  • AWS/cloud concentration and real-time detection requirements create meaningful operational outage risk.
  • Adtech heritage may pull valuation multiples below pure-play cybersecurity peers in an exit process.

Open gaps

  • Audited or management-confirmed ARR, growth, and product-segment revenue mix.
  • Net revenue retention, gross retention, churn, and average contract duration by customer segment.
  • Gross margin and cost-of-revenue split across threat intelligence, cloud infrastructure, and services.
  • Current outstanding balance, maturity, and covenants of the 2022 Blackstone Credit facility.
  • Updated post-2024 valuation, liquidation preferences, and cap-table ownership concentration.

Contents

Chapter 01

01Company Overview

1.1 Identity, headquarters, and platform model

HUMAN Security, Inc. is a privately held cybersecurity company headquartered in New York City, with additional offices in Miami, Santa Clara, Tel Aviv (Israel), and the United Kingdom. The company was founded in 2012 in Brooklyn, New York under the name White Ops by Tamer Hassan, Michael Tiffany, Dan Kaminsky, and Ash Kalb. It rebranded to HUMAN Security in 2021 to reflect an expanded scope beyond advertising fraud into full-stack enterprise and consumer security. The company describes itself as the trust layer for media and agentic commerce platforms, verifying engagement, reducing fraud, and enabling authentic interactions across humans, bots, and AI agents. HUMAN's core commercial offering is the Human Defense Platform (HDP), which the company positions as a unified platform delivering protection across three principal pillars: Media Security (digital advertising fraud, invalid traffic detection, and ad integrity), Application and Enterprise Security (account takeover, credential stuffing, fake account creation, web scraping, and carding), and Account Protection (identity and authentication fraud). The platform's stated scale metrics are verifying more than 20 trillion digital interactions weekly across 3 billion unique devices, using 2,500+ signals per interaction, analyzed by 400+ adaptive machine learning models, to make binary bot-or-human decisions in milliseconds. The company serves 500+ global brands across media, finance, retail, government, education, and enterprise security verticals. As of mid-2026, HUMAN has expanded its platform into the agentic AI era, launching HUMAN Sightline Cyberfraud Defense, a unified trust and defense layer protecting digital businesses from bot attacks, human-led fraud, transaction abuse, and AI-driven risks across the full customer journey, and AgenticTrust, which allows customers to detect, classify, and govern AI agents operating on their platforms. HUMAN also operates the Satori Threat Intelligence and Research Team, which drives threat intel and orchestrates public-private disruptions of cybercriminal operations. The company characterizes its competitive position as the largest threat detection network globally by weekly interaction volume. Revenue model and pricing remain private. [CO001, CO003, CO004, CO005, CO006, CO007]

Snapshot KPI table
metricvalue/statusdateconfidencegap
Founded2012 (as White Ops)2012high
Rebranded to HUMAN Security20212021high
HeadquartersNew York City, New York, UShigh
Operating statusPrivate; Goldman Sachs Merchant Banking-anchoredhigh
Weekly digital interactions verified>20 trillion2026-06highSelf-reported; no independent audit confirmed
Unique devices covered3 billion2026-06mediumCompany-claimed; independent verification unavailable
Customers / brands served500+2026-06mediumCompany-claimed; no customer list published
Employees (headcount)~400 (as of Oct 2024); ~437 (estimated mid-2026)2024-10lowExact current headcount not publicly confirmed
Total capital raised~$299-300M (equity); $100M Blackstone debt additional2024-10mediumAggregator estimate; company has not confirmed exact total
Last disclosed valuation~$1.5B (January 2022 round)2022-01mediumNo post-2022 valuation disclosed; figure is stale
Revenue / ARRNot publicly disclosedlowPrivate company; full diligence requires data room access
Forrester Wave rankingLeader (Q2 2026 Bot and Agent Trust Management)2026-06-15high

All HUMAN-issued scale claims (20 trillion interactions, 3 billion devices, 500+ brands) are company-claimed and have not been independently audited. Employee and revenue figures are third-party estimates from data aggregators unless otherwise noted. The $1.5B valuation is from the January 2022 funding round and is now four-plus years old.

[CO001, CO004, CO005, CO007, CO008, CO038]
FO003: Snapshot KPIs

HUMAN's scale and recognition metrics are strong; financial metrics are private and unavailable for public diligence without data room access.

[CO007, CO008, CO027, CO041, CO042, CO043]

1.2 Founders, leadership, board, and key-person risk

HUMAN was founded by four individuals: Tamer Hassan (CEO through January 2024, now Executive Chairman), Michael Tiffany, Dan Kaminsky, and Ash Kalb. Hassan was the dominant public face of the company for its first twelve years, recognized by Fast Company in 2019 as its number one Most Creative Person in Business. He led the rebranding from White Ops, the merger with PerimeterX, the acquisition of clean.io, and the company's surpassing of $100M ARR. In January 2024, Hassan transitioned to the role of board member and Executive Chairman, remaining actively engaged in strategy, customer relationships, and public-policy advocacy. The co-founder network is therefore partially intact: Hassan retains a governance role, while the other three founding members are not publicly listed in active executive roles as of the June 2026 research date. In January 2024, Stu Solomon, formerly President of Recorded Future (the world's largest threat intelligence provider), was appointed CEO. Solomon brings executive and C-suite experience from Optiv (including as CTO), iSight Partners (acquired by FireEye), and Bank of America, as well as a more than 25-year military career in the Delaware Air National Guard and United States Air Force. HUMAN's current executive leadership also includes Isaac Itenberg (Chief Operating Officer and Chief Financial Officer), Gavin Reid (Chief Information Security Officer), and Christos Kalantzis (Chief Technology Officer). The board of directors as of the 2026 research date includes directors from Goldman Sachs (Anthony Arnold), NightDragon (Dave DeWalt), WestCap (Kevin Marcus), and ClearSky (Jay Leek), alongside Tamer Hassan (Executive Chairman) and Ido Safruti, who joined the board as part of the PerimeterX merger. A search of public records and company announcements found no evidence of Matt Cantor in HUMAN Security's current or recent leadership, executive team, or board. Key-person risk has improved somewhat with the CEO transition from Hassan to Solomon, which distributes strategic execution across a more experienced external management team. However, the board remains heavily investor-representative (Goldman Sachs, NightDragon, WestCap, ClearSky), and the company's threat-intelligence identity and customer relationships retain a degree of founder imprint through Hassan's Executive Chairman role. The board also lists eight observers (Ryan Benevides, Dan Burns, Itzhak Fisher, Steve Fredrick, Rhys Gordon, Hannah Huffman, Lance Matthews, Alexander Weiss), whose affiliations and control significance are not publicly disclosed in the current source set. Full board composition and governance terms remain a diligence gap. [CO002, CO011, CO012, CO013, CO014, CO015]

Leadership and founder table
personrolebackgroundfounder-market fit / functional coveragekey-person dependency
Tamer HassanCo-Founder; Executive Chairman (since Jan 2024; CEO through Jan 2024)Serial cybersecurity entrepreneur; Fast Company 2019Founding vision; market positioning; customer relationships; public policy; board governanceHigh: company identity, brand, and customer network remain closely associated with Hassan despite CEO transition
Stu SolomonCEO (since Jan 2024)President of Recorded Future (5 yrs); CTO at Optiv; iSight Partners exec; Bank of America; 25+ yr Delaware Air National Guard / USAFOperational scaling; cybersecurity go-to-market; public-sector expansion; data science investment strategyHigh: sole publicly facing CEO post-transition; all strategy and capital allocation decisions flow through Solomon
Michael TiffanyCo-FounderCo-founder of White Ops; background in bot detection and cybersecurity researchFounding technical vision; core bot-or-not detection methodologyLow to medium: not listed in current executive or board roles; role in current operations unclear
Dan KaminskyCo-Founder (deceased 2021)Renowned security researcher; discovered critical DNS vulnerability; co-founder of White OpsFounding threat intelligence philosophy; Satori team heritageHistorical: Kaminsky passed away in April 2021; his influence is embedded in platform DNA rather than active operations
Ash KalbCo-FounderCo-founder; background in cybersecurity product developmentFounding product and business development contributionLow to medium: not listed in current executive or board roles; current role unclear
Isaac ItenbergChief Operating Officer and Chief Financial OfficerSenior operator and finance executiveOperational execution; financial management; company oversightMedium: dual COO/CFO role centralizes operational and financial authority
Gavin ReidChief Information Security OfficerExperienced CISO with cybersecurity industry backgroundInternal security posture; product credibility with enterprise CISOsMedium: CISO role matters for enterprise customer confidence
Christos KalantzisChief Technology OfficerSenior technology executivePlatform technical architecture; AI/ML platform development; engineering roadmapMedium: CTO continuity is important given the platform's machine learning core

Enumerates the public-facing executive and founding team based on company announcements, press releases, and the Craft.co profile as of June 2026. Full board composition (including investor- designated directors and all 8 observer seats) and exact founder equity ownership are not publicly disclosed. Dan Kaminsky's entry is included for completeness; he passed away April 2021. Matt Cantor does not appear in any current or recent HUMAN Security leadership or board record.

[CO002, CO011, CO012, CO013, CO014, CO019]
FO002: Company snapshot logic

HUMAN's operating system connects PE-sponsored capital, a founder-turned-chairman governance layer, a threat-intelligence core (Satori), and a unified platform that serves three customer segments: media/adtech, enterprise application security, and agentic AI governance.

[CO007, CO015, CO016, CO017, CO018, CO043]

1.3 Funding history, valuation, and investor map

HUMAN's capital history runs from venture-backed startup through a private equity buyout and into a growth-funded cybersecurity platform. The company completed its Series B in 2017 led by Canaan Partners and a $43M Series C in February 2019 led by Scale Venture Partners. In December 2020, Goldman Sachs Merchant Banking Division, ClearSky Security, and NightDragon jointly acquired White Ops from previous investors including Paladin Capital Group and Grotech Ventures. Terms were not disclosed. At the time of the acquisition, the company had 170 employees and was verifying 10 trillion interactions per week. Post-acquisition, HUMAN raised $57M in a Series D growth round in February 2021 with participation from Stereo Capital and others, and then completed a $100M growth round in January 2022 led by WestCap and NightDragon, which was reported to value the company at approximately $1.5 billion. In July 2022, concurrent with the PerimeterX merger, HUMAN secured a $100M debt facility from Blackstone Credit. The most recent external capital event is a $50M+ growth round announced October 9, 2024, led again by WestCap, with participation from Goldman Sachs, ClearSky, NightDragon, and Vertex Ventures US. CEO Stu Solomon stated that the $50M amount was deliberately constrained to enable targeted investments without over-capitalization. Total capital raised is reported as approximately $299-300M across all rounds, according to data aggregators. However, this figure may not include the $100M Blackstone debt facility, which was a debt instrument rather than equity. No current post-money valuation is publicly disclosed. The $1.5B valuation from January 2022 is the most recent publicly reported figure, but it predates both the 2022 PerimeterX merger and the October 2024 round. Exact equity ownership percentages, liquidation preferences, and cap-table composition remain private. HUMAN is a Goldman Sachs-anchored asset with recurring lead investor WestCap and strategic co-investors from the cybersecurity industry (NightDragon, ClearSky, Vertex Ventures US). [CO021, CO022, CO023, CO024, CO025, CO026]

Stakeholder or investor map
stakeholderrolecontrol / economic importancediligence ask
Goldman Sachs Merchant Banking DivisionLead acquirer (Dec 2020); board representative (Anthony Arnold)Acquired majority control in 2020 buyout; anchor institutional shareholder; retained through all subsequent roundsConfirm current equity ownership percentage, board seat rights, exit horizon, and any secondary activity; Goldman Sachs's ownership makes this a PE-sponsored asset with implicit exit timeline
WestCapLead investor in January 2022 growth round and October 2024 growth round; board representative (Kevin Marcus)Double lead investor with two consecutive growth rounds; co-COO-level operating expertise provided to managementAssess specific board governance rights, information rights, and any preference terms; WestCap's operator-at-heart model suggests active governance engagement
NightDragonCo-investor in 2020 acquisition; co-investor in 2022 round; co-investor in 2024 round; board representative (Dave DeWalt, founder/CEO of NightDragon)Recurring strategic investor; Vice Chairman of HUMAN board per 2020 acquisition announcement; cybersecurity ecosystem connectorConfirm current board seat and oversight rights; DeWalt's network spans enterprise cybersecurity buyers, making NightDragon a strategic rather than purely financial investor
ClearSky SecurityCo-investor in 2020 acquisition; co-investor in 2024 round; board representative (Jay Leek)Early acquisition partner; persistent board presence; specialized in cybersecurity and critical-infrastructure securityClarify current equity stake and board rights; ClearSky's deep-security focus aligns with HUMAN's threat-intel differentiation
Vertex Ventures USNew investor in October 2024 roundFirst-round participation; new growth equity position; scale and governance rights unconfirmedRequest current equity ownership terms and any governance rights associated with the 2024 round
Scale Venture PartnersLed $43M Series C (Feb 2019); historical investorEarly institutional capital; pre-acquisition shareholder; current residual ownership unknown post-2020 buyoutDetermine whether Scale Venture retained any equity post-Goldman Sachs acquisition; current ownership likely nominal
Canaan PartnersLed Series B (2017); historical investorEarly growth capital; pre-acquisition shareholder; current residual ownership unknownAs with Scale Venture, confirm post-acquisition stake; likely exited or marginally diluted
Blackstone Credit$100M debt facility (July 2022, concurrent with PerimeterX merger)Debt instrument; not equity; terms including covenants, maturity, and interest rate not publicly disclosedObtain full debt agreement terms; debt facility has implications for free cash flow, refinancing risk, and any security interest in HUMAN assets
Tamer Hassan (Executive Chairman)Co-founder; board member; Executive Chairman since January 2024Residual founder equity stake; unclear size; strategic and governance influenceConfirm founder equity position, lock-up terms, and any secondary liquidity activity since the 2020 acquisition

Ownership percentages are not publicly disclosed for any investor. Stakes listed are inferred from announced roles and round participation only. The 2020 Goldman Sachs acquisition was a majority buyout of prior shareholders; residual VC positions from Series B and C may have been partially or fully bought out. The $100M Blackstone credit facility is a debt instrument and is separate from the ~$299-300M equity capital raised figure cited by aggregators.

[CO021, CO022, CO024, CO025, CO026, CO027]

1.4 Milestone chronology, competitive recognition, and adverse context

HUMAN's operating history is marked by a series of public-private threat disruptions that have established its identity and credibility in the cybersecurity market. In 2016, as White Ops, the company uncovered Methbot, one of the first large-scale dedicated ad fraud botnets. In 2018-2019, it participated with the FBI, Google, and Facebook in the takedown of 3ve, the largest ad fraud botnet to date. In 2021, the company led a collaborative PARETO disruption (a major Connected TV ad fraud operation) and rebranded from White Ops to HUMAN Security. The year 2022 was the most active on record: clean.io was acquired in March, the PerimeterX merger closed in July, and the VASTFLUX ad fraud scheme (affecting 11 million devices with 12 billion daily false bid requests) was disrupted and reported in January 2023. BADBOX, a pre-installed Android botnet affecting millions of devices globally, was disrupted in multiple phases in 2023, 2024, and 2025, with German authorities and a coalition including HUMAN, Google, and Shadowserver conducting the largest coordinated sinkholing operations. On the commercial and recognition side, HUMAN was named to TIME's Best Inventions of 2023, the TIME100 Most Influential Companies of 2023, and named a Leader in The Forrester Wave: Bot Management Software Q3 2024. In January 2024, the CEO transition from Tamer Hassan to Stu Solomon took effect. In October 2024, the $50M+ growth round closed. By June 2026, HUMAN was named a Leader in The Forrester Wave: Bot and Agent Trust Management Software Q2 2026, with the highest possible scores across nine criteria including Threat Research, the only vendor to receive a top score in that criterion. G2's Summer 2026 Grid for Bot Detection and Mitigation Software also named HUMAN the top overall Leader based entirely on customer feedback. The adverse record is limited. In October 2024, AdExchanger published a correction noting that CEO Stu Solomon had misspoken during an interview about building a proprietary deterministic ID for attribution; HUMAN's VP of Product clarified that no such product was planned. This represents a minor public messaging error with no regulatory or legal consequences. No material lawsuits, regulatory investigations, data breach disclosures, significant workforce reductions, or sanctions against HUMAN Security have been identified in public records as of the June 2026 research date. The absence of documented adverse events should be noted as an evidence gap for private proceedings that would not be publicly disclosed, and the company's private status means no public regulatory filing trail exists. [CO029, CO030, CO031, CO032, CO033, CO034]

Milestone table
dateeventtypeamount/valuation/statusparticipantsimplication
2012White Ops founded in Brooklyn, New YorkfoundingN/ATamer Hassan, Michael Tiffany, Dan Kaminsky, Ash KalbOrigin of the "bot or not" detection company that became HUMAN Security
2016Methbot ad fraud operation uncovered and disclosedproduct$3-5M/month criminal revenue disruptedWhite Ops (Satori team)First major public-private disruption; established White Ops as threat-intelligence leader in ad fraud
2017Series B funding round closedfinancingAmount not disclosedCanaan Partners (lead)First institutional growth capital beyond seed; enabled platform scaling
2019-02Series C funding round closedfinancing$43MScale Venture Partners (lead), CanaanAccelerated growth into enterprise security use cases beyond advertising
2018-20193ve botnet takedown completed; FBI indictments issuedproductMulti-billion impression fraud disruptedWhite Ops, FBI, Google, Facebook, industry coalitionLargest private-sector collaborative cybersecurity disruption to date; defined White Ops' threat-intelligence identity
2020-12Goldman Sachs Merchant Banking acquires White Ops; ClearSky and NightDragon co-investfinancingTerms not disclosed; PE majority buyoutGoldman Sachs MBD, ClearSky, NightDragonTransition from VC-backed startup to PE-owned growth asset; prior investors (Paladin Capital, Grotech Ventures) exited
2021-Q1White Ops rebrands to HUMAN SecuritygovernanceN/AHUMAN Security managementReflects expanded scope from ad fraud to full-stack digital identity protection
2021PARETO (CTV ad fraud botnet) takedown; Dan Kaminsky passes awayproductMajor CTV fraud operation disruptedHUMAN, industry partners; Kaminsky (April 2021)Notable takedown of Connected TV fraud; loss of founding team member
2022-01$100M growth round closed; valuation approximately $1.5B (unicorn milestone)financing$100M raised; ~$1.5B post-money valuationWestCap (lead), NightDragonUnicorn designation; capital for PerimeterX merger and platform expansion
2022-03HUMAN acquires clean.io (malvertising prevention)productTerms not disclosedHUMAN (acquirer), clean.ioAdds malvertising prevention capability to the platform; cited by Hassan at CEO transition
2022-07HUMAN merges with PerimeterX; Blackstone Credit $100M debt facilityproduct$100M debt; combined entity has 450+ employees, $100M+ ARRHUMAN, PerimeterX, Blackstone CreditLargest strategic move in company history; unified ad-tech and enterprise security platform; Omri Iluz becomes president of Enterprise Security
2023-01VASTFLUX ad fraud disruption disclosed (11M devices, 12B daily false bids peak)product12B bid requests/day at peak; disruptedHUMAN (Satori team)Demonstrated HUMAN's ability to conduct large-scale coordinated private takedowns; reinforced threat-intel brand
2023Named to TIME Best Inventions and TIME100 Most Influential CompaniesscaleIndustry recognitionTIME editorial, HUMANMainstream credibility milestone; product reaching consumer-facing acknowledgment
2023-2024BADBOX pre-installed Android botnet takedown (multiple phases; BADBOX 2.0 in 2024-2025)product10M+ devices affected; disruptedHUMAN, Google, German authorities, ShadowserverMulti-year, multi-agency operation; positioned HUMAN as a persistent threat-disruption actor beyond one-time takedowns
2024-01Stu Solomon appointed CEO; Tamer Hassan becomes Executive ChairmangovernanceN/AStu Solomon (incoming CEO), Tamer Hassan (Executive Chairman)First external CEO appointment; marks transition from founder-led to professional management
2024-10$50M+ growth round closedfinancing$50M+ raisedWestCap (lead), Goldman Sachs, ClearSky, NightDragon, Vertex Ventures USSecond WestCap-led round; new investor Vertex Ventures US; CEO deliberately constrained size for targeted investment
2026-06Named Leader in Forrester Wave Bot and Agent Trust Management Q2 2026; highest score in Threat ResearchscaleHighest Forrester score in Threat Research criterionForrester ResearchValidates platform expansion into agentic AI trust management; differentiating threat intelligence capability publicly recognized

Milestone dates are drawn from press releases, news coverage, and company announcements. Exact acquisition and merger terms are not publicly disclosed. The PerimeterX merger closing date (July 2022) is from the BusinessWire announcement; regulatory approval was confirmed in that release. Dan Kaminsky's passing is included as an adverse milestone given his founding-team role. The $100M ARR figure at the time of the PerimeterX merger is from the BusinessWire announcement and represents combined ARR of the merged entities.

[CO001, CO004, CO021, CO022, CO023, CO024]
FO001: Company milestone timeline

HUMAN's operating history spans a founding-era threat-intelligence phase, a private equity consolidation phase (2020-2022), and a platform-expansion phase (2022-2026) now extending into agentic AI. Adverse events are limited to a minor public messaging correction and a founding member's death.

[CO001, CO004, CO029, CO030, CO031, CO037]

1.5 Exhibits

Chapter 02

02Market Analysis

2.1 Market Boundary, Included Spend, and Substitutes

HUMAN Security's revenue opportunity spans four distinct but overlapping product categories: (1) bot mitigation and behavioral analytics platforms protecting web applications, APIs, and mobile surfaces from automated abuse; (2) ad fraud and Sophisticated Invalid Traffic (SIVT) defense, covering pre-bid filtering, post-bid reporting, and MRC-accredited verification in programmatic advertising; (3) account-takeover (ATO) prevention targeting post-login credential abuse, session hijacking, and multi-stage attack chains; and (4) agentic AI trust management, a nascent category that emerged as AI-powered agents began transacting on behalf of users—growing 7,851% year-over-year in HUMAN's own network data. These four categories are increasingly unified under HUMAN Sightline Cyberfraud Defense and MediaGuard/Ad Integrity Suite within the Human Defense Platform. Included spend encompasses behavioral analytics SaaS subscriptions, MRC-accredited SIVT detection licensing, bot-score API fees, AgenticTrust policy enforcement, and managed threat intelligence services (Satori team). Excluded spend includes pure payment-fraud chargebacks and chargeback insurance, KYC/KYB identity proofing (document verification, biometric), AML compliance tooling, traditional CAPTCHA commodities without behavioral layers, DDoS mitigation (pure volumetric), and CDN infrastructure contracts where bot management is an untariffed add-on. Adjacent markets include web application firewalls, cloud access security brokers, identity and access management platforms, and API gateway security—all of which create partial substitutes for specific HUMAN use cases. Status-quo substitutes include: in-house fraud rule engines and data-science teams (common at large internet platforms such as Google, Meta, and major financial institutions), CDN-native bot management from Cloudflare (79% bot management install base by device share) and Akamai (6%), and point-solution SIVT vendors such as Integral Ad Science, DoubleVerify, and Pixalate. Cloudflare's bundling of bot management with CDN and WAF at flat-rate pricing starting around $350 annually for SMBs creates the most material displacement risk in the lower and mid-market. The competitive bundling threat constrains HUMAN's addressable market—particularly among organizations that already rely on Cloudflare for content delivery—and forces a differentiation argument based on signal depth (2,500+ behavioral signals per interaction), threat research (Satori team), and specialized ad fraud MRC accreditation that Cloudflare does not offer. [CM001, CM028, CM029, CM037, CM038, CM039]

Market Definition: Included Spend, Excluded Spend, and Substitutes
Segment / CategoryIncluded SpendExcluded SpendPrimary Buyer / PayerRelevance to HUMAN
Bot Mitigation & Behavioral AnalyticsBot-score APIs, behavioral analytics SaaS, CAPTCHA-bypass detection, SDK-based session monitoring, managed bot servicesCDN infrastructure, DDoS volumetric mitigation, network-layer firewall subscriptionsApp security engineers, CISO / IT Security budgetCore — Bot Defender, Sightline Cyberfraud Defense
Ad Fraud / SIVT DefensePre-bid IVT filtering, post-bid reporting, MRC-accredited SIVT classification, TAG compliance tooling, Page Intelligence analyticsViewability-only measurement (non-fraud), brand safety adjacency (non-IVT), ad serving infrastructureAd ops directors, CMO / Marketing P&L budgetCore — MediaGuard, Ad Integrity Suite, Page Intelligence
Account Takeover (ATO) PreventionPost-login behavioral monitoring, credential-stuffing detection, session anomaly alerts, ATO threat intelligenceFull identity proofing (KYC/KYB), biometric authentication hardware, IAM platform subscriptionsFraud operations teams, Head of Risk / CISO + CRO budgetCore and expanding — ATO monitoring within Sightline
Agentic AI Trust ManagementAI agent identification and trust scoring, policy-based agent access controls, agentic commerce governance SaaSModel alignment and AI safety (AI-company budgets), hardware-level secure enclave spendPlatform architects, trust & safety leads / Emerging shared security + engineering budgetNew and growing — AgenticTrust module, AWS Bedrock integration
Adjacent Substitutes (Out-of-Scope Spend)CDN-native bot management (Cloudflare, Akamai), WAF platform security bundles, in-house fraud rule engines and data-science teams, RASP, authentication overlay vendors (Arkose Labs, etc.)Platform infrastructure teams, NOC/SOC / IT infrastructure budgetDisplacement risk for portions of core market; not directly addressable

Boundary definitions are HUMAN-product-anchored; adjacent substitute spend is excluded from SAM calculations but is presented here to document competitive displacement risk. Included spend categories are sourced from company documentation, MRC accreditation letter, and Forrester Wave evaluation criteria. Not all included spend is publicly quantified by independent analysts at the sub-category level.

[CM001, CM037, CM028, CM029, CM038, CM039]

2.2 Market Sizing: TAM, SAM, and SOM Across Multiple Lenses

Market sizing for HUMAN's served market requires combining estimates across multiple analyst categories because no single published report matches its product boundary. The bot mitigation market is sized at $0.9 billion (2025) growing to $1.12 billion in 2026 at a 24.8% CAGR (Business Research Company), while Fortune Business Insights pegs the slightly broader "bot security" category at $1.05 billion (2025) and $1.27 billion (2026) at a 20.55% CAGR. Both estimates reach $2.4–$5.67 billion by 2030-2034. An outlier from MarkWide Research places a broader "bot mitigation" market at $3.8 billion in 2026 using a wider scope that may include adjacent WAF/CDN security spend. On the ad fraud side, Fraudlogix measured a 20.64% global IVT rate across 105.7 billion impressions in 2025, implying roughly $37 billion in US programmatic ad spend exposed to invalid traffic annually at the 23.69% US-specific rate. This is the potential fraud loss, not a vendor market size; vendor revenue for SIVT mitigation is a fraction of fraud exposure. Pixalate's Q1 2026 benchmarks confirmed a 24% US desktop IVT rate, 32% mobile app, and 24% CTV—rates that reinforce persistent demand for accredited SIVT vendors. For account takeover protection, Global Growth Insights estimates a standalone $7.46 billion market in 2026 at 18.89% CAGR. The eCommerce FDP broad market is projected at $88.77 billion in 2026 (BFSC) and the all-verticals fraud detection market at $40.4 billion (Grand View Research), but these include payment fraud, KYC/KYB, AML, and identity proofing that HUMAN does not directly serve—making them overstatements of the relevant TAM. An analyst-synthesized SAM for HUMAN is approximately $1.5–$2.0 billion in 2026, constructed as the sum of bot security ($1.27B) plus MRC-accredited SIVT vendor spend (estimated $500M–$800M, derived from advertiser spend on verification tools as a fraction of $836B global digital ad spend). This SAM is compressed by Cloudflare bundling for the SMB/mid-market segment. A SOM of $150–$300 million in 2026 is consistent with HUMAN's Forrester Wave leadership position, quadrillion-interaction network scale, and a realistic 10–20% penetration of the constrained SAM, but this estimate has no independent validation because HUMAN does not disclose revenue. [CM002, CM003, CM004, CM005, CM006, CM007]

TAM/SAM/SOM Sizing Lens Table
PublisherYearGeographyMarket / ScopeValue (2026)CAGRMethodologyConfidenceLimitation for HUMAN Sizing
Business Research Company2026GlobalBot Mitigation$1.12B24.8%Demand-side; web, mobile, API bot mitigation tools and servicesMediumNarrower than HUMAN's full scope (excludes SIVT, ATO); may understate SAM
Fortune Business Insights2026GlobalBot Security$1.27B20.55% (2025-34)Demand-side; includes behavioral analytics, AI-driven detection platformsMediumScope may include adjacent WAF/CDN security; North America = 38% share
MarkWide Research2026GlobalBot Mitigation (Broad)$3.8B~18%Supply+demand aggregation; broader boundary may include integrated WAF/CDN securityLowBoundary inflation likely; compare with $1.12B from TBRC for same year—source-to-source gap of 3.4x
Fraudlogix2026 (data 2025)United StatesProgrammatic Ad Spend Exposed to IVT (proxy for ad fraud scale)$37B exposedN/AImpression-based; 23.69% IVT × $156B US programmatic spend (est.)MediumMeasures fraud exposure, not vendor market; SIVT vendor revenue << $37B
Business Research Company2026GlobaleCommerce Fraud Detection & Prevention$88.77B20.8%Broad e-commerce vertical; includes payment fraud, chargebacks, KYCLowScope 70-80x wider than bot-only market; not directly comparable to HUMAN SAM
Grand View Research2026GlobalFraud Detection & Prevention (All Verticals)$40.4B18.1% (2026-33)All-vertical FDP including AML, KYC, payment fraud, identity proofingLowIncludes non-addressable categories for HUMAN; use as ceiling, not floor
Global Growth Insights2026GlobalAccount Takeover Protection$7.46B18.89% (2026-35)Demand-side; ATO-specific platforms, credential protection, session securityMediumATO is one component of HUMAN's suite; full market >= HUMAN's ATO-related SAM
Analyst Synthesis (this report)2026GlobalHUMAN SAM (Bot Security + SIVT Vendor Market)$1.5–$2.0B (est.)~20%Bottom-up: $1.27B bot security + est. $500M–$800M MRC-accredited SIVT vendor spend; pre-bundling haircutLowNo independent source validates this exact boundary; subject to 20-40% downward revision for Cloudflare-covered market

Analyst estimates reflect different market boundaries and must not be summed or compared directly. Values are in USD. CAGR figures are as reported by each publisher. The analyst synthesis row (bottom) is this report's estimate and does not represent a primary source; confidence is deliberately Low. MarkWide Research's $3.8B estimate diverges 3.4x from TBRC's $1.12B for the same year and geography, illustrating scope ambiguity.

[CM002, CM003, CM005, CM007, CM008, CM009]
Contradictory Market Size Estimates: Boundary Analysis
SourceEstimate (2026)Key Scope Inclusions Beyond HUMAN's ProductImplied Discount to HUMAN SAMDiligence Implication
TBRC — Bot Mitigation$1.12BNone significant; closely aligned with HUMAN's bot defense scope~0% (baseline)Most conservative and scope-aligned estimate; use as floor for SAM
Fortune BI — Bot Security$1.27BPossibly includes some WAF/CDN-adjacent security; North America is 38%~0-5%Slightly broader scope; most cited analyst estimate for this chapter's analysis
MarkWide Research — Bot Mitigation (Broad)$3.8BLikely includes integrated WAF/CDN security bundles; scope not clearly defined~50-70% discount to isolate pure bot defenseOutlier vs. TBRC/FortunBI for same period; treat as upper ceiling scenario only
Global Growth Insights — ATO Protection$7.46BATO-specific platforms; includes identity proofing and biometric layers outside HUMAN's scope~40-60% discount to isolate HUMAN-relevant ATO spendUse as reference for ATO sub-market adjacent to Sightline; do not add to bot market without boundary reconciliation
Grand View Research — Fraud Detection & Prevention$40.4BAML, KYC/KYB, payment fraud, chargebacks, identity verification, and compliance reporting~97% discount to reach bot-only marketRepresents overall risk-management addressable market; HUMAN's share is small; illustrates category inflation risk in investor materials
BFSC — eCommerce Fraud Detection & Prevention$88.77BPayment fraud, chargeback management, refund abuse, account fraud, KYC for e-commerce onboarding~99% discount to reach bot-only marketMost inflated boundary; risk of benchmark misleading if cited without boundary disclaimer

Discount estimates are qualitative analyst synthesis based on known scope differences; no primary source independently validates the split between HUMAN-relevant and non-relevant spend within each estimate. 'Implied Discount' is an approximation to illustrate scale of scope inflation, not a precise calculation. Preserve this table when presenting to investors to pre-empt over-reliance on the largest estimates.

[CM007, CM008, CM009, CM012, CM035, CM036]
FM001: Market Sizing Pyramid: TAM, SAM, and SOM for HUMAN Security (2026)

Three-layer market pyramid showing the range from broad fraud prevention TAM to HUMAN's estimated served market (SAM) and realistically achievable share (SOM) in 2026.

TAM figure is the broadest commonly cited estimate and includes non-HUMAN segments; the bot-mitigation-only TAM of $1.12-1.27B is more defensible. SAM and SOM are analyst-synthesized estimates with no primary-source validation. SOM range is $150M-$300M; midpoint $220M used.

[CM002, CM003, CM008, CM009, CM010, CM011]
FM002: Market Estimate Range: Bot Security and HUMAN SAM Scenarios (2026)

Low/base/high estimates for the bot security market and HUMAN's SAM under different boundary assumptions, all expressed in $B for 2026, illustrating the scope-sensitivity of published estimates.

All values in USD billions. Cloudflare-adjusted SAM row is this report's construction and has no independent primary source. Broad/all-FDP row is indicative only; HUMAN does not compete in most of that market. Unit consistency: all rows use $B (2026 estimate).

[CM002, CM003, CM009, CM035, CM036]

2.3 Buyer, User, and Payer Segmentation

HUMAN's buyer landscape is segmented by product line and underlying job-to-be-done. For bot mitigation and ATO defense (Bot Defender + Sightline), the primary buyers are application security engineers and fraud operations teams at e-commerce, travel, and financial services companies. Budget typically sits within IT Security or Risk/Compliance and is owned by the CISO or CTO. Adoption triggers include a post-breach incident, detection of checkout fraud or scraping attacks, or a competitive intelligence threat from inventory scraping. HUMAN's own 2026 benchmark report found that retail and e-commerce topped all verticals for scraping (70% of all observed attacks), carding, and ATO attempts, with over 440,000 unique threat profiles targeting the sector—more than four times the next-highest vertical. For ad fraud/SIVT defense (MediaGuard/Ad Integrity Suite), the buyer profile shifts to ad operations directors, chief media officers, and programmatic trading teams at advertisers, agencies, DSPs, SSPs, and publishers. Budget ownership moves to the marketing P&L. Adoption is often compliance-driven: MRC accreditation mandates for impression counting, TAG certification requirements for supply chain participants, or agency holding-group standards mandating independent IVT measurement. HUMAN's 2026 MRC re-accreditation for both its pre-bid Ad Fraud Defense and post-serve Ad Fraud Sensor platforms across desktop, mobile, and CTV reinforces its standing as a certified vendor in this segment. A third and emerging segment is agentic AI trust management (AgenticTrust/Sightline), where buyers are platform architects, trust and safety leads, and "agentic commerce" product owners at companies deploying or receiving AI-agent traffic at scale. This buyer is newer, with budgets not yet fully allocated, and the category itself was renamed by Forrester only in 2025 ("Bot and Agent Trust Management Software") to reflect the shift. HUMAN's support for Amazon AWS Bedrock AgentCore browser verification signals a partnership-driven go-to-market for this segment. The payer here may be a combined security-and-platform engineering budget rather than the traditional CISO owner. EXTE's March 2026 integration of HUMAN's MediaGuard illustrates the partner/platform buyer: a programmatic advertising company integrating HUMAN's solution as a supply-quality layer—payer is the platform, user is the advertiser downstream. Global cybersecurity budgets are rising to $240 billion in 2026 (12.5% YoY per Gartner), with 40% of enterprise security budgets allocated to software and platforms where HUMAN competes. [CM015, CM016, CM017, CM018, CM019, CM020]

Buyer / User / Payer Segment Map
SegmentPrimary BuyerUserPayer / Budget OwnerWorkflow ServedKey Adoption Trigger
Programmatic Ad / Media / Ad-TechCMO, Ad Ops Director, Head of ProgrammaticProgrammatic traders, DSPs, SSPs, publishersCMO/CFO via marketing tech stack / media P&LPre-bid IVT filtering, post-bid reporting, TAG/MRC compliance, Page Intelligence analyticsMRC accreditation mandate, TAG certification requirement, agency holding-group standard, ad fraud complaint from advertiser
E-Commerce & RetailVP Engineering, Head of Fraud, Application Security LeadSecurity engineers, fraud analysts, product teamsCISO/CTO / IT Security or Risk budgetScraping defense, carding prevention, checkout ATO, inventory skewing mitigation, bot performance impactPost-breach response, checkout fraud spike, competitive scraping detected, bot-driven latency incident
Travel & HospitalityVP Product, Head of Trust & Safety, CISOPlatform engineers, customer experience teamsCTO/CRO / Platform engineering budgetInventory scraping, fake review injection, ATO on loyalty accounts, fraudulent booking chainsOTA scraping disruption, loyalty ATO spike, performance degradation from bot traffic (>50% on login pages per HUMAN case study)
Media & StreamingChief Compliance Officer, Ad Ops DirectorSecurity engineers, ad ops, content teamsCMO + CISO / Marketing + Security shared budgetAI scraper control, content protection, ad revenue fraud, AI-agent-driven traffic classificationAI scraper surge targeting content (41% of AI scraper targets), ad fraud complaint, viewability/IVT audit failure
Financial ServicesVP Information Security, Fraud Risk Officer, CISOSecurity engineering, fraud analytics, compliance teamsCISO + Chief Risk Officer / Compliance/Risk budgetATO detection, credential stuffing, account opening fraud, API abuse, synthetic identity signalsRegulatory requirement (PSD2, NIST, OCC), ATO incident, credential breach, PCI-DSS audit finding
Agentic AI / Platform OperatorsPlatform Architect, Head of Trust & Safety, Product Security LeadDevelopers, AI-product managers, trust teamsCTO / Engineering or emerging 'AI Governance' budgetAI agent identification, trust-scoring, policy-based access controls for agentic commerceAI-agent traffic surge on platform, AWS Bedrock or similar agentic platform adoption, agentic fraud incident

Buyer personas and workflow descriptions are synthesized from HUMAN Security case studies, Forrester Wave evaluation context, and HUMAN's 2026 State of AI Traffic report. Budget ownership varies by deal size and organizational maturity; dual-budget (CISO + CMO) deals occur in media companies with both ad fraud and security exposure. 'Payer' reflects the organizational unit holding the contract; 'Buyer' is the economic buyer with decision authority.

[CM015, CM016, CM017, CM018, CM019, CM020]
FM003: Buyer / Segment Map: Budget Ownership and Adoption Path

Matrix mapping HUMAN Security's five primary buyer segments to budget ownership, key adoption triggers, and competitive substitutes, illustrating the multi-buyer nature of the platform.

Substitute columns reflect dominant competitive alternatives observed in the market; specific deal-level win/loss data for HUMAN is not publicly available.

[CM016, CM018, CM019, CM024, CM040, CM042]
FM004: Enterprise Adoption Funnel: Bot and Agent Trust Management Software

Five-stage adoption funnel for an enterprise buyer evaluating HUMAN Security, from initial awareness through expansion upsell, illustrating conversion drop-off and switching friction at each stage.

Funnel values are estimated percentages relative to an indexed baseline of 100 and do not represent HUMAN's actual pipeline conversion rates, which are not publicly disclosed. Percentages are illustrative of the general enterprise security SaaS adoption pattern and are based on industry benchmarks and HUMAN's known go-to-market model.

[CM022, CM023, CM027, CM032, CM033, CM046]

2.4 Growth Drivers and Adoption Constraints

The single most potent growth driver is the explosion of automated and agentic traffic. HUMAN's own 2026 benchmark report found automated traffic growing 23.51% year-over-year while human traffic grew only 3.10%—a ratio of roughly 8:1. AI-driven traffic surged 187% in 2025, and agentic AI traffic from agents and browsers grew 7,851% YoY. The category that Forrester renamed "Bot and Agent Trust Management Software" in 2025 reflects a structural expansion of the addressable problem: it is no longer sufficient to classify traffic as human vs. bot; organizations must now govern whether an AI agent can be trusted to transact on a user's behalf. This expansion creates a new TAM layer above traditional bot mitigation where no established incumbent dominates, and HUMAN's AgenticTrust module was designed specifically for this gap. A second driver is regulatory and compliance pressure. TAG awarded 307 certification seals to 196 companies in 2026, with 74% independently audited—signaling that ad industry compliance is tightening beyond self-attestation. MRC accreditation for SIVT detection is increasingly a prerequisite for programmatic platform participation. Regulatory drivers such as PSD2 (financial services), NIST CIAM guidance, and emerging EU AI Act provisions on autonomous system accountability are creating non-discretionary budget lines for bot and agent trust management in regulated verticals. ATO attacks quadrupled in HUMAN's customer base between 2024 and 2025 (averaging 400,000+ post-login compromise attempts per customer per year), driving upsell and cross-sell opportunities within the existing base. Ad fraud losses exceeding $100 billion in 2026 with a 20%+ IVT rate sustain advertiser urgency for verified traffic. The primary constraint is competitive bundling: Cloudflare holds approximately 79% of bot management install share (vs. Akamai's 6%) by providing integrated CDN, WAF, and bot management at flat-rate pricing starting below $400 annually—a package that displaces dedicated bot defense vendors in the SMB and lower-mid market. DataDome's market share fell from 13.8% to 8.9% between 2025 and 2026, potentially reflecting this bundling pressure. A second constraint is ROI proof: bot mitigation savings appear as "fraud losses avoided" rather than revenue—invisible in P&L statements and requiring sophisticated measurement frameworks to justify budget to non-technical stakeholders. A third constraint is switching friction: enterprise bot management integrates deeply into login flows, checkout APIs, and analytics pipelines; migration risk deters switches from incumbents, slowing new logo acquisition. In-house build remains a viable alternative at large platforms with sufficient engineering capacity, further limiting HUMAN's net-addressable market. [CM023, CM024, CM025, CM026, CM027, CM028]

Growth Drivers and Adoption Constraints
FactorTypeDirectionTimingImplication for HUMANDiligence Ask
Agentic AI traffic growing 7,851% YoY (HUMAN data)DriverStrong positiveCurrent and accelerating (2025-2027)Expands TAM from bot-only to full agent trust management; new category where HUMAN has first-mover Forrester recognitionConfirm TAM for agent trust management is budgeted separately from bot management or is an upsell/add-on within existing contracts
Automated traffic growing 8x faster than human trafficDriverStrong positiveCurrent (ongoing)Increases urgency across all buyer segments; raises baseline need for behavioral detection beyond simple IP-rate-limitingQuantify what % of HUMAN's pipeline is driven by net-new bot-problem discovery vs. Cloudflare/Akamai displacement
AI-driven traffic up 187% in 2025 with AI scrapers up 597%DriverStrong positiveCurrentMedia and e-commerce buyers face immediate scraper threat; drives cross-sell from bot defense to AI-traffic governanceVerify signal applies to HUMAN's customer verticals, not only its own observed traffic
ATO attacks quadrupled in HUMAN customer base 2024-2025DriverStrong positiveCurrent and acceleratingUpsell opportunity within existing base; cross-sell ATO module to bot-only customers; expands contract valueConfirm ATO growth rate is broad market, not an artifact of improved HUMAN detection coverage
Global ad fraud losses >$100B, IVT rate 20%+ in 2026DriverModerate positivePersistentSustains advertiser demand for MRC-accredited SIVT vendors; supports MediaGuard/Ad Integrity Suite renewal ratesAssess what fraction of HUMAN's SIVT customers are mandated (TAG/MRC-required) vs. discretionary buyers
TAG 307 certifications in 2026 (74% independently audited); regulatory pressure (PSD2, NIST, EU AI Act)DriverModerate positiveBuilding (2024-2028)Non-discretionary budget lines for bot/agent trust management in regulated and ad-industry verticalsIdentify which specific regulations create contractual requirements for HUMAN's products vs. general security awareness
Cloudflare dominates bot management install base (~79% share)ConstraintStrong negative for SMB/mid-marketPresent and growingHUMAN effectively excluded from much of the SMB market; must sell on depth of signal (2,500+ signals/interaction) and specialized accreditation that Cloudflare lacksQuantify Cloudflare penetration in HUMAN's current customer segments; does HUMAN co-exist or displace?
ROI proof is 'invisible savings' (fraud losses avoided)ConstraintModerate negativePersistentLengthens enterprise sales cycles; requires trusted measurement methodology; budget approval requires non-technical stakeholder buy-inRequest HUMAN customer ROI case studies verified by third-party; what is average sales cycle length?
Deep API/login-flow integration creates high switching costs (both ways)ConstraintMixedPersistentProtects HUMAN's installed base (high NRR likely) but slows new logo acquisition from incumbent vendors; migration risk deters changesObtain NRR and logo retention metrics; what is HUMAN's average customer tenure?
In-house fraud teams as build-vs-buy alternative at large platformsConstraintModerate negative (selective)PresentLimits SAM at large internet companies (Google, Meta, Amazon) with sufficient ML engineering; HUMAN's SAM skews to mid-large enterprises without in-house capabilityIdentify win/loss record against in-house build decisions; what engineering headcount threshold correlates with in-house preference?

Directions are assessed relative to HUMAN's revenue opportunity. 'Timing' is qualitative. Driver/constraint categorization reflects the dominant expected effect; some factors (e.g., switching costs) have mixed implications depending on whether HUMAN is the incumbent or the challenger in a given account.

[CM021, CM025, CM026, CM027, CM028, CM030]

2.5 Sizing Gaps, Contradictory Estimates, and Diligence Asks

Three structural gaps prevent a definitive market size from being established. First, HUMAN Security does not disclose revenue, ARR, or customer count, making bottom-up SOM estimation entirely reliant on inferred metrics such as Forrester Wave ranking, G2 position, and network scale. Second, the analyst community has not yet independently sized the "agent trust management" sub-market—Forrester renamed the category only in 2025, and no consensus market forecast exists for this segment in 2026. Third, the $1.12B–$88.77B range of market estimates cited in analyst reports reflects boundary inconsistency, not genuine disagreement on fundamentals: the $88.77B eCommerce FDP estimate includes payment fraud, chargebacks, KYC/KYB, and identity proofing that HUMAN does not address, while the $1.27B bot security estimate excludes SIVT vendor revenue. Neither cleanly maps to HUMAN's actual product scope. Contradictory sizing evidence worth preserving: Grand View Research's $40.4B fraud detection market implies HUMAN's market is 30-40x larger than the bot-security-only figure—a discrepancy that reflects scope rather than error. Cloudflare's near-80% install share in bot management is presented by wmtips.com as evidence that HUMAN and other dedicated vendors compete in a niche carve-out within a Cloudflare-dominant market, which would compress the effective SAM well below $1.27B for markets already served by Cloudflare. This constraint does not appear in any of the market research reports sampled, representing a significant gap in published analysis. Any financial model should apply a 20–40% SAM haircut for Cloudflare-served customers as a conservative floor scenario. Diligence asks: (1) Request HUMAN's ARR, NRR, and customer cohort data to validate SOM assumptions. (2) Quantify Cloudflare penetration among HUMAN's target buyer segments to size the addressable residual. (3) Obtain independent sizing of the MRC-accredited SIVT vendor market. (4) Confirm whether the agentic trust management segment is tracking toward a distinct budget line or remains a feature expansion within existing bot-management contracts. [CM012, CM035, CM036, CM045, CM048, CM049]

2.6 Exhibits

Chapter 03

03Competitors

3.1 Competitive Landscape Overview

HUMAN Security sits at the intersection of two rapidly evolving markets. In bot and agent trust management, the vendor set spans purpose-built specialists (Kasada, Arkose Labs, DataDome, Netacea, Fingerprint), infrastructure-native players who bundle detection into broader platforms (Cloudflare, Akamai, Imperva/Thales), and the status quo of in-house rule engines and rate-limiting logic that many enterprises still rely on as a first-line filter. In digital ad verification, HUMAN's newly launched Ad Integrity Suite (June 2026) enters direct competition with publicly traded DoubleVerify ($748M FY2025 revenue, 14% YoY growth) and Integral Ad Science ($591M revenue), as well as the full-funnel GTM security platform CHEQ. The Forrester Wave: Bot and Agent Trust Management Software Q2 2026 evaluated eight vendors and renamed the category from "Bot Management" to "Bot and Agent Trust Management," signaling that the competitive frontier has shifted from detecting automated traffic to governing trust for legitimate AI agents. HUMAN and Kasada were both named Leaders; Netacea was a Strong Performer. Cloudflare and Akamai were not evaluated in the Wave, as their offerings remain adjuncts to edge/CDN platforms rather than purpose-built bot intelligence products. The most important structural dynamic shaping competition is the proliferation of agentic AI: HUMAN's 2026 benchmark data shows AI-driven traffic grew 187% in 2025 alone, with agentic browser traffic up 7,851% year-over-year, meaning the traditional "bot or not" binary is obsolete and purpose-built trust management platforms have a structural advantage over legacy WAF and CDN-based detection. [CP001, CP002, CP003, CP004, CP005, CP033]

3.2 Direct Peer Profiles (Bot and Agent Trust)

Kasada is HUMAN's most direct peer in the Forrester Wave, also named a Leader with the highest possible scores in nine criteria and strong Strategy scores. The February 2026 $20M EQT-led round brings Kasada's total to $64.2M—far below HUMAN's estimated $220M+ raised—but the company claims to protect more than $150 billion in eCommerce revenue, a formidable proof point for enterprise procurement. Notably, more than 85% of Kasada customers previously used another bot mitigation provider, implying high win-rate in competitive displacement. Kasada differentiates on server-side, CAPTCHA-free detection and a reported 250%+ ROI. Arkose Labs ($114M raised, Series C in 2021) occupies a distinct niche with challenge-response gamification that deliberately frustrates bot operators through interactive puzzles rather than passive behavioral analysis. Adobe is a named enterprise customer. Arkose holds 5.0% mindshare in the PeerSpot Bot Management category as of June 2026, up from 2.8% the prior year—a sign of growing enterprise recognition despite a smaller scale. DataDome ($82M raised, $36M ARR 2024) focuses on e-commerce and media with rapid edge-ML detection, serving 300+ enterprises including Rakuten, Reddit, and AngelList; its revenue almost doubled from $16.9M to $36M from 2023 to 2024. Fingerprint differentiates on device intelligence rather than full-stack bot management—its platform identified over 1 billion unique devices per month in 2026, achieved 65% ARR growth, serves 2,000 customers with 128% NRR, and added Booking.com as a customer. Netacea ($29.7M raised, $55.9M valuation) differentiates on a fully managed server-side service model where Netacea handles detection configuration and tuning on behalf of the customer, receiving a Strong Performer rating in the Q2 2026 Forrester Wave with top scores in web and LLM scraping management. In PeerSpot's June 2026 Bot Management category, Imperva leads mindshare at 15.7% and Akamai holds 9.7%, both above HUMAN's 8.1%, though the incumbent positions reflect install base more than pure-play bot intelligence capability. [CP008, CP009, CP010, CP011, CP012, CP013]

Competitor Profile Table
CompetitorCategoryFoundedTotal FundingKey Customers / ProofTarget SegmentKey DifferentiatorLimitation
HUMAN SecurityBot defense + ad verification2012~$220M est.Global brands, ad platforms, mediaEnterpriseQuadrillion-scale behavioral network; Satori threat takedowns; agentic trustHigher price point; humansecurity.com blocks crawlers, limiting public pricing evidence
KasadaBot defense + agentic AI trust2014$64.2MGlobal enterprises, retail, airlinesMid/large enterpriseServer-side detection; CAPTCHA-free; 250%+ claimed ROI; Forrester Wave Leader Q2 2026Smaller team and brand vs. HUMAN; limited public ARR disclosure
Arkose LabsBot defense + ATO2013$114MAdobe, banks, gaming platformsMid/large enterprise (gaming, fintech)Challenge-response gamification; dedicated ATO preventionChallenge creates friction; web-focused; last major raise was 2021 Series C
DataDomeBot protection2015$82MRakuten, Reddit, AngelListE-commerce, classifiedsReal-time edge ML; rapid deployment; $36M ARR 2024Smaller scale vs. HUMAN; primarily web/API, limited agent trust coverage
FingerprintDevice intelligence2012$77MBooking.com, Dropbox, checkout.comFintech, e-commerce, SaaS1B+ device IDs/month; 128% NRR; Authorized AI Agent Detection; 65% ARR growth FY2026Not full-stack bot management; complement to rather than substitute for HUMAN
Cloudflare Bot ManagementCDN + bot detection (bundled)2009Public (NYSE: NET)Any enterprise on CloudflareAll segments (bundled in edge contract)Edge-integrated; near-zero marginal cost for existing customers; ML bot scoringEnterprise-only add-on; less specialized analytics; no behavioral signal network
Imperva / ThalesWAF + bot protection2002 / acq. 2023Public (Thales parent)Banks, compliance-heavy enterpriseEnterprise compliance (PCI DSS 4.0)700+ behavioral dimensions; strongest mindshare in Bot Mgmt (15.7% PeerSpot Jun 2026)High setup cost; Thales acquisition adds integration risk; less agentic AI roadmap
Akamai Bot ManagerCDN + bot protection1998Public (NASDAQ: AKAM)Global enterprises, e-commerceLarge enterprise / DevOps-heavyEdge pre-origin filtering; CI/CD integration; second-highest mindshare (9.7% PeerSpot)Less specialized vs. pure-play vendors; customer setup complexity noted
DoubleVerify (DV)Ad verification2008Public (NYSE: DV)Top brands, agencies, publishersAd ecosystem (agencies, DSPs, SSPs)67% market share in ad fraud detection; $748M FY2025 revenue; 109% NRRNot a full bot management platform; limited application/API fraud coverage
Integral Ad Science (IAS)Ad verification2009Public (NASDAQ: IAS)Top brands, agenciesAd ecosystemBrand safety, programmatic measurement; $591M TTM revenue Q1 2026Lower market share vs. DV; 167 tracked customers vs. DV's 4,324
CHEQGTM security + ad fraud2016PrivateEnterprise + SMB performance marketersPerformance marketing / GTM teams6T signals/day; 0.009% false positive rate; SMB-accessible via ClickCease/EssentialsLess known for enterprise application security; lighter bot mitigation depth
NetaceaBot management (managed service)2015$29.7MGlobal retail, media, travelEnterprise (managed service preferred)Fully managed; highest Forrester scores in LLM scraping and transaction assurance Q2 2026Small funding base; limited global brand vs. HUMAN; managed model limits enterprise DIY

Funding figures from Tracxn, Crunchbase, and company press releases; represent total funding raised across all rounds. HUMAN Security total funding is an estimate based on publicly disclosed rounds; exact figure not confirmed. Mindshare percentages from PeerSpot June 2026. ARR figures from GetLatka and company disclosures (DataDome ARR as of Oct 2024).

[CP005, CP008, CP011, CP013, CP017, CP019]
FP001: Competitive Positioning Map — Bot and Agent Trust Vendors (Q2 2026)

Ordinal positioning of key bot management and agent trust vendors on two axes: Detection Depth (sophistication of behavioral signal network and threat intelligence, 1=low to 10=high) vs. Platform Breadth (scope of use cases covered beyond bot detection, 1=narrow to 10=broad). Scores are evidence-backed ordinal judgments derived from Forrester Wave Q2 2026 evaluations, PeerSpot mindshare data, and company product disclosures as of June 2026.

Ordinal scores are analyst judgments based on public evidence, not audited capability benchmarks. Cloudflare, Akamai, and Imperva scores reflect their bot management products only, not their full security platform breadth. DoubleVerify and IAS are included for orientation but compete primarily in ad verification rather than bot management.

[CP005, CP006, CP012, CP022, CP023, CP037]

3.3 Ad Verification and Fraud Measurement Peers

HUMAN's June 2026 launch of the Ad Integrity Suite—combining IVT intelligence, AI-powered brand safety and suitability, and viewability in a single framework—puts it in direct competition with the two dominant publicly traded ad verification platforms. DoubleVerify (NYSE: DV) reported $748.3M in FY2025 revenue, a 14% year-over-year increase, with net revenue retention of 109% and measurement of 9.5 trillion billable media transactions annually. It holds a 67% market share in ad fraud detection tools as tracked by 6sense, with 4,324 tracked customers versus IAS's 167. Integral Ad Science (NASDAQ: IAS) reported $590.67M revenue for the twelve months ending Q1 2026, competing primarily on brand safety and programmatic measurement. Both DV and IAS have deep agency holding company integrations and MRC-accredited measurement, which constitute strong switching-cost moats. HUMAN's differentiation is explicitly cybersecurity-grade fraud intelligence—replacing "black box" keyword signals with explainable, URL-level classifications backed by its behavioral network—and the convergence of security and ad verification into a unified platform that security, ad-ops, and marketing teams can share. AdRoll's Global Head of Supply Platforms praised the suite for transparency and reduced ambiguity, suggesting differentiated positioning even against the dominant DV/IAS pair. CHEQ occupies a complementary niche: it processes six trillion signals per day across one million monitored domains with a claimed 0.009% false positive rate, primarily serving performance marketers and SMBs seeking full-funnel GTM security rather than premium brand-safe inventory measurement. The ad verification space is the highest-strategic-risk competitive vector for HUMAN because DV and IAS have contractual leverage through DSP/SSP integrations that took years to build, and their revenue scale is ~10x–15x HUMAN's estimated ARR, giving them capital to match any HUMAN product innovation in the verification layer. [CP009, CP010, CP033, CP034, CP035, CP036]

3.4 Capability, Pricing, and GTM Comparison

Across the pure-play bot management vendors, all publish custom enterprise pricing with no public rate cards. Cloudflare is the only platform that provides published pricing tiers—its Bot Management is an Enterprise-only add-on bundled into contracts that range from approximately $5,000 to $80,000+ per month. For organizations already using Cloudflare for CDN and WAF, the marginal cost of adding bot management can be near zero, creating a structural disadvantage for pure-play vendors that must justify a separate license. However, Cloudflare's bot detection is less specialized: it provides ML-based bot scoring, JA3/JA4 fingerprinting, and detection IDs, but lacks the behavioral signal depth (one quadrillion interactions per year), adversarial threat intelligence, or agentic trust governance that purpose-built vendors provide. Imperva (Thales-owned) leads PeerSpot mindshare at 15.7% with strong positioning around PCI DSS 4.0 compliance and 700+ behavioral dimensions; Akamai (#2, 9.7%) differentiates on edge-first, pre-origin filtering and CI/CD integration. Both have higher initial setup complexity versus Kasada and HUMAN's SDK/API deployment. On GTM, HUMAN's strongest channel is its deep partnership ecosystem: Forrester specifically cited the breadth and awards of HUMAN's partnership program as a standout, aligned with emerging agentic trust and commerce use cases. Major AI operators including OpenAI and AWS have recognized HUMAN as a trusted solution to verify AI agent traffic, which creates an ecosystem-lock dynamic as agent trust becomes a procurement requirement. Fingerprint's 128% NRR is a strong signal that buyers expand usage after initial deployment, consistent with a land-and- expand motion that differs from Cloudflare's bundle-and-upsell approach. The in-house build alternative—custom WAF rules, rate limiting, device fingerprinting, and ML anomaly detection— remains viable for large tech-native enterprises but requires sustained investment in specialized talent and continuous adversarial evolution that most organizations cannot sustain at HUMAN's pace of threat intelligence updates. Desktop browser tampering techniques doubled year-over-year to 4.4% of identifications in 2025, illustrating the escalating detection complexity that favors vendors with cross-customer behavioral networks over single-enterprise in-house systems. [CP030, CP031, CP032, CP040, CP041, CP042]

Feature and Capability Coverage Matrix
CapabilityHUMAN SecurityKasadaArkose LabsDataDomeCloudflare BMImperva
Behavioral signal network (cross-customer)Yes — quadrillion interactions/yrYes — server-side telemetryPartial — challenge analyticsYes — edge ML per customerPartial — Cloudflare network signalsYes — 700+ behavioral dimensions
Agentic AI / LLM agent trust governanceYes — AgenticTrust, granular per-agent permissionsYes — AI Agent Trust product launched 2026Unknown — no public agentic AI productUnknown — no public agentic AI productPartial — AI crawler block onlyUnknown — no public agentic AI product
Device fingerprinting / device intelligenceYes — device + browser signalsYes — device telemetry signalsYes — challenge-bound fingerprintingYes — real-time edge fingerprintingYes — JA3/JA4 TLS fingerprintingYes — full device fingerprinting
Ad fraud / IVT detectionYes — Ad Integrity Suite, Jun 2026No — bot defense onlyNo — ATO/bot focusNo — bot/scraping focusNo — no ad fraud productNo — app security only
Threat intelligence and takedown operationsYes — Satori team; coordinated takedownsUnknown — no public threat research teamPartial — challenge analytics sharedUnknown — no public threat researchPartial — Cloudflare threat intel feedYes — threat intelligence feeds
Fully managed detection serviceNo — customer-configured with HUMAN supportNo — platform-driven, low configNo — self-serve with guidanceNo — self-serve SaaSNo — self-serve with Solutions EngineeringNo — customer-managed with Imperva support

Capability coverage based on public product documentation, Forrester Wave Q2 2026 evaluation criteria, and company website content as of June 2026. "Unknown" indicates the capability was not publicly confirmed at the time of research. Table reflects presence, not depth of implementation. Agentic AI coverage is evolving rapidly across all vendors.

[CP001, CP003, CP004, CP009, CP010, CP012]
Pricing and Packaging Comparison
VendorPricing ModelEntry Point (est.)Enterprise Range (est.)Pricing TransparencyKey Packaging Note
HUMAN SecurityCustom enterprise SaaSUnknown — no public pricingUnknown — no public pricingOpaque — no public rate cardSightline Cyberfraud Defense and Ad Integrity Suite sold separately; platform bundle pricing not disclosed
KasadaCustom enterpriseUnknown — no public pricingUnknown — no public pricingOpaque — no public rate cardClaims 250%+ ROI; pricing based on traffic volume and use case breadth
Arkose LabsCustom enterpriseUnknown — no public pricingUnknown — no public pricingOpaque — no public rate cardChallenge-response SaaS; pricing likely scales with challenge volume
DataDomeSaaS subscription$500–$1,000/mo est. for small sites$15,000+/mo for enterprisePartial — some public tier indicationsBot and fraud protection for web, mobile, API; SMB-accessible entry point
FingerprintUsage-based SaaSFree tier available$100–$10,000+/mo based on API callsPartial — public pricing page for SMB/developer tiersDevice intelligence API; pricing based on identification events per month
Cloudflare Bot ManagementEnterprise add-on to CDN contract$5,000/mo min (bundled Enterprise)$5,000–$80,000+/mo depending on footprintModerate — enterprise range publicly estimated from procurement dataBot Management is bundled into Enterprise plan; near-zero marginal cost for existing Cloudflare customers
Imperva (Thales)Custom enterpriseHigher upfront cost vs. Akamai (per reviews)Custom — higher long-term ROI cited by buyersOpaque — no public rate cardFull stack WAF + bot; pricing scales with protected traffic and feature depth
Akamai Bot ManagerCustom enterpriseLower setup cost vs. Imperva (per reviews)Custom — ongoing costs scale with advanced featuresOpaque — no public rate cardOften bundled with Akamai CDN/WAF; most cost-competitive for existing Akamai customers

All custom enterprise pricing is estimated from third-party procurement reports, buyer reviews on PeerSpot and Gartner, and publicly disclosed pricing analysis (Cloudflare). Vendor-published price cards do not exist for HUMAN, Kasada, Arkose, Imperva, or Akamai. DataDome and Fingerprint have partial public pricing based on the developer/SMB tier. Enterprise pricing at all vendors involves contract negotiation and is not auditable.

[CP031, CP032]
FP002: Capability Depth Map — Top Bot and Agent Trust Vendors

Qualitative depth assessment (Strong / Moderate / Weak / Unknown) of five strategic capabilities across the six most-evaluated vendors in the Q2 2026 Forrester Wave and adjacent markets. Distinct from the binary coverage table (TP002) by focusing on verified depth and market proof rather than feature presence.

Depth ratings are analyst judgments derived from Forrester Wave Q2 2026 scoring, PeerSpot peer review analysis, and publicly available product documentation. "Strong" requires independent corroboration (Forrester top score, named customer case study, or press release proof point). "Unknown" means no public corroboration of depth was found despite the feature being present.

[CP004, CP006, CP013, CP021, CP037, CP038]

3.5 Moat Durability and Displacement Risk

HUMAN Security's primary moat is its behavioral signal network—over one quadrillion interactions analyzed in 2025—which creates a data flywheel that is structurally difficult for any single- customer alternative to replicate. The Satori Threat Intelligence and Research team adds a second moat layer: Forrester noted that HUMAN's coordinated attack takedowns "create impact far beyond its customer base," meaning the team operates as a public-good defense function that reinforces HUMAN's trust brand in ways no single-customer deployment can match. The platform's deep integrations across WAF, CDN, IAM, and Adobe Experience Platform create switching costs that are operational rather than contractual, since unplugging HUMAN requires reconfiguring detection logic across the entire technology stack. However, three displacement risks are material. First, infrastructure bundling: Cloudflare's near-zero marginal cost for bot detection for existing customers will continue to capture cost-sensitive SMB and mid-market segments. Second, competitive intensity at the top: Kasada's 85%-of-customers-from-competitors win rate and the Forrester co-Leader position show that HUMAN's enterprise segment is actively contested rather than defensively dominant. Third, ad verification displacement: DV and IAS have agency-embedded measurement relationships that predate HUMAN's ad offering by over a decade, giving incumbents significant inertia even against a technically superior product. Positive durability signals include HUMAN's declining-but-present PeerSpot mindshare (8.1%, down from 11.6%), which reflects Cloudflare and Imperva gains rather than pure-play specialist displacement, and the Forrester renaming of the category to "Bot and Agent Trust Management" which aligns the market definition with HUMAN's platform investments in AgenticTrust. Post-login account compromise quadrupling year-over-year (402,000 attempts per organization on average) and 250% carding growth since 2022 create structural demand tailwinds that preserve the moat against commoditization, as attack sophistication directly amplifies the gap between behavioral-network specialists and edge-bundled alternatives. [CP001, CP006, CP007, CP041, CP044, CP045]

Moat Durability and Competitive Risk Register
Moat ClaimThreatSeverityMitigation / StatusDiligence Ask
Quadrillion-interaction behavioral data network creates detection advantageCloudflare, Akamai, and AWS amass their own aggregate traffic signals at comparable or greater scaleHighHUMAN's signals are enriched by cross-customer attack correlation; raw volume is necessary but not sufficientConfirm whether HUMAN's detection accuracy benchmarks are independently validated vs. Cloudflare BM on identical attack types
Satori Threat Intelligence team produces coordinated takedowns benefiting all customersCompetitors could grow threat research functions or acquire specialist firmsMediumForrester cited takedowns as uniquely differentiating; no peer has equivalent public track recordAssess team size, retention, and pipeline of active operations; verify customer NPS attribution to Satori specifically
Deep WAF/CDN/IAM/AEP integrations raise operational switching costsCustomers may consolidate onto Cloudflare or Akamai to reduce vendorsHighHUMAN's platform integrations are multi-layer; replacement requires reconfiguring detection across the entire stackObtain customer contract terms (typical length, auto-renew, data portability) and churn attribution by reason
Partner ecosystem (OpenAI, AWS, Adobe) creates agent trust network effectsCompeting agent trust frameworks from hyperscalers could preempt or absorb HUMAN's positionHighForrester cited HUMAN's partnership program as a standout; hyperscaler partnerships are live signals of early adoptionConfirm exclusivity or co-marketing terms in key AI operator partnerships; assess revenue contribution of partner channel
Established behavioral signal network is expensive to replicate from scratchWell-funded new entrant with hyperscaler backing could build comparable scale within 24–36 monthsMediumNo credible new entrant has yet emerged; category requires multi-year data accumulationTrack venture investment into agent trust and bot management startups for signs of well-capitalized new entrants
Ad Integrity Suite leverages existing behavioral network for superior IVT detection vs. legacy providersDoubleVerify and IAS have MRC accreditation, DSP/SSP integrations, and 10+ years of agency trust that HUMAN lacksHighHUMAN's differentiation is explainability and cybersecurity-grade signals; gaining MRC accreditation is a prerequisite for parityAssess MRC accreditation timeline and agency holding company adoption rate for HUMAN Ad Integrity Suite

Severity ratings are analyst judgments based on publicly available evidence as of June 2026. "High" indicates a threat that could materially affect HUMAN's competitive position within 12–24 months. "Medium" indicates a threat that is real but unlikely to materially erode the moat within the near term without significant competitor investment. All diligence asks require non-public company data to answer definitively.

[CP001, CP005, CP006, CP007, CP041, CP044]
FP003: Moat and Competitive Durability KPIs

Compact snapshot of HUMAN Security's competitive durability metrics as of Q2 2026, drawn from independently verifiable public sources. Items mix confirmed metrics, analyst estimates, and chapter-level synthesis; units and sources are explicit.

Mindshare figures from PeerSpot June 2026 (bot management category). Interaction volume from HUMAN's 2026 benchmark report (company-published). Threat profile count from HUMAN Threat Tracker via published benchmark. Kasada win rate from Kasada press release. Fingerprint NRR from BusinessWire press release (fiscal year 2026). DoubleVerify NRR from IR press release FY2025.

[CP001, CP015, CP027, CP028, CP033, CP044]

3.6 Exhibits

Chapter 04

04Financials

4.1 Revenue Architecture and Pricing Model

HUMAN Security operates a pure subscription SaaS model built around the Human Defense Platform, which integrates three commercial pillars: advertising protection, application security and bot mitigation, and account protection. Revenue is generated as annual enterprise contracts priced on the basis of traffic volume, number of protected assets (web, mobile, API endpoints), and the specific module mix selected by the customer. There is no publicly listed price card; all enterprise pricing is custom and negotiated. The platform monetises through four verifiable revenue streams: (1) advertising/media security (pre- and post-bid fraud, click fraud, malvertising defence via the clean.io acquisition), (2) application security and bot mitigation (the former BotGuard and PerimeterX stack), (3) account protection (credential stuffing, fake account creation), and (4) HUMAN Sightline with AgenticTrust (launched July 2025), which adds AI-agent trust and agentic commerce protection as an emerging fourth stream. The median enterprise annual spend benchmarked by Vendr is $104,906 per year, with a reported range from $46,601 to over $1.34 million for large, complex deployments. Official pricing is therefore a floor proxy for list price, not disclosed realised revenue. Revenue quality is expected to be high given the mission-critical nature of fraud prevention and the high switching costs inherent in deeply embedded platform integrations, but the exact ARR mix by segment is not publicly available. [CI001, CI002, CI003, CI004, CI005, CI009]

Revenue Streams
StreamMechanismUnitCurrent Status / ValueRevenue QualityDiligence Ask
Advertising / Media ProtectionAnnual SaaS subscription; ad-fraud and malvertising mitigation across programmatic, CTV, mobilePer traffic volume + module scopeActive; primary historical revenue stream; clean.io expanded malvertising coverage Nov 2022High — mission-critical for ad buyers and publishers; high switching costExact ARR contribution vs. application security; publisher vs. brand revenue split
Application Security / Bot MitigationAnnual SaaS subscription; bot defence, scraping, ATO, carding across web / mobile / APIPer protected endpoint and traffic volumeActive; significantly expanded via PerimeterX merger Jul 2022High — direct enterprise security spend; deeply embedded in customer infrastructurePost-merger ARR by legacy HUMAN vs. PerimeterX customers; churn from integration
Account ProtectionAnnual SaaS subscription add-on; credential stuffing, fake account, compromised account defencePer-platform, usage-tieredActive; growing segment as identity fraud escalatesMedium-high — upsell motion to existing platform customers; attach rate unknownAccount protection attach rate; incremental ACV per seat
HUMAN Sightline / AgenticTrustAnnual SaaS add-on; AI agent trust and agentic commerce visibility and governancePer platform, agent volumeLaunched July 2025; early commercial stage; ~200 customers on solution at launchMedium — novel product; strong differentiation but limited track recordEarly ARR; pricing model for agentic AI traffic; customer uptake rate
Public Sector (via Carahsoft)Government contracts through reseller network; NCPA, OMNIA Partners cooperative vehiclesPer-agency contract valueActive and growing; Carahsoft partnership since November 2022; VP Public Sector Sales hired 2024Medium — longer procurement cycles; potential multi-year contract durabilityGovernment contract win rates; public-sector revenue as percentage of total ARR
Channel / Partner RevenueIndirect via HUMAN Advantage Partner Program; co-sell and referralPartner margin share on new bookingsNascent; program launched August 2024; no direct or indirect partner-sourced metrics publicLow-medium — early-stage channel; pipeline generation not yet measurablePartner-sourced pipeline share; partner-attach rate to new ARR

Revenue mix and ARR contribution by stream are not publicly disclosed. Status and quality assessments are based on company press releases, product announcements, and partner programme documents, not audited financials. Clean.io acquisition terms were undisclosed.

[CI001, CI013, CI014, CI015, CI016, CI017]
Pricing and Monetization
Product / Customer TierContract TypePrice per Year (USD)List vs. RealizedSource
Base Bot Defense / Mid-marketAnnual SaaS~$46,601 (Vendr low end)Realized benchmark; list price not disclosedVendr procurement benchmark (2025)
Full Platform Suite / Median EnterpriseAnnual SaaS~$104,906 (Vendr median)Likely discounted off undisclosed list price; volume and module-mix drivenVendr procurement benchmark (2025)
Large / Complex EnterpriseAnnual SaaS; multi-year availableUp to $1,343,250+ (Vendr high)Custom negotiated; significant variation by traffic volume, coverage scope, SLAsVendr procurement benchmark (2025)
Public Sector (via Carahsoft)Government contract via NCPA / OMNIA cooperativeCustom; below standard list pricing per government procurement normsGovernment discount applies; no public rate cardCarahsoft partnership announcement (2022)
AgenticTrust / HUMAN Sightline Add-onAnnual SaaS; add-on to existing platform subscriptionNot publicly disclosed; new SKU as of July 2025Early pricing; unknown list or realized levelsHUMAN official press release (July 2025)

Pricing data from Vendr represents benchmark spend by Vendr's enterprise buyer network, not HUMAN's published price card. Actual realized pricing will vary by deal size, module selection, traffic volume, and negotiation leverage. AgenticTrust pricing is a newly launched product with no benchmark data available.

[CI009, CI010, CI011, CI012, CI019]
FI001: Revenue Model Bridge — Customer Interaction to Subscription Revenue

How customer digital activity converts to HUMAN revenue through platform detection layers and subscription invoicing.

Node descriptions are qualitative; the exact number of ML models, signal types, and module revenue mix are company-confidential. Relative revenue contribution per module is not publicly disclosed.

[CI006, CI013, CI027, CI028]

4.2 Go-to-Market Motion and Sales Efficiency

HUMAN Security has undergone a deliberate GTM transformation from a historically direct-sales-only organisation to a partner-first channel model. Prior to 2024, the company had no formal channel programme and long enterprise sales cycles of six to seven months were common for large accounts due to the need to negotiate legal, MSA, and pricing terms directly. In August 2024, HUMAN launched the HUMAN Advantage Partner Program, a tiered channel initiative with incentives based on annualized bookings, training completion, and customer retention. The program targets resellers, distributors, and advisory partners globally. Separately, HUMAN partnered with Carahsoft Technology in November 2022 as its Master Government Aggregator, enabling public sector access via NCPA, E&I, and OMNIA cooperative contracts. CEO Stu Solomon (appointed January 2024, formerly President of Recorded Future) and CRO Chris Scanlan (formerly President at ExtraHop) are executing the commercial and marketing pivot. The partner-led motion is designed to shorten sales cycles by leveraging embedded partner relationships and pre-existing MSAs, thereby reducing the average deal time and widening addressable pipeline. No partner-sourced pipeline share or quantified CAC/payback data is publicly available. The ecosystem-first approach also enables HUMAN to reach fragmented buyer personas (security, commerce, digital, marketing) without diluting direct sales bandwidth. [CI018, CI019, CI020, CI021, CI022, CI023]

4.3 Cost Structure and Margin Drivers

HUMAN's cost structure is dominated by three categories: (1) ML and data infrastructure for processing over 20 trillion digital interactions per week (over one quadrillion annually as of 2025), representing substantial cloud compute and storage spend; (2) the Satori Threat Intelligence and Research Team, a human-in-the-loop cost centre that conducts proactive threat research and executes takedowns (3ve, Methbot, PARETO, BADBOX 2.0), and which differentiates HUMAN's research-backed detection but adds material personnel cost; and (3) sales and marketing, expanding with the channel programme investment and headcount growth from approximately 197 employees in late 2023 to an estimated 469–519 employees by mid-2026. Gross margin is not publicly disclosed. SaaS cybersecurity benchmarks (Benchmarkit 2024/2025) indicate typical gross margins of 75–85% for pure SaaS models, with downward pressure where significant human-in-the-loop operations exist. HUMAN's Satori team and the scale of its signal collection infrastructure (running on hyperscaler compute at internet scale) may compress margins below median SaaS benchmarks. R&D is estimated at approximately 34% of revenue for private SaaS companies, while sales and marketing typically runs at 47% for VC-backed SaaS companies at HUMAN's growth stage. If HUMAN's ARR is at or near $100M, ARR per FTE of $200–$300K is the SaaS benchmark, suggesting moderate revenue efficiency. [CI006, CI007, CI024, CI025, CI026, CI027]

Unit Economics
MetricValue / StatusConfidenceWhy It MattersDiligence Ask
ARR (company-claimed)>$100M (company stated; post-PerimeterX merger, reaffirmed Jan 2024)Medium — company-claimed, not independently auditedPrimary indicator of recurring revenue scaleAudited ARR by product segment; definition of ARR (GAAP vs. bookings)
ARR (conflicting third-party)$15M (GetLatka, December 2023; likely reflects pre-merger or incomplete data)Low — third-party model inconsistent with headcount and merger evidenceMaterial discrepancy must be resolved before underwriting revenue qualityIndependent ARR audit; reconciliation of Latka figure to company books
Gross MarginNot disclosed; SaaS cybersecurity benchmark range 65–85%; Satori team and infra may compress below 75%Low — benchmark estimate onlyDetermines scalability of revenue growth and path to profitabilityAudited COGS vs. gross profit by product line in data room
Net Revenue Retention (NRR)Not disclosed; SaaS benchmark median 101% (Benchmarkit 2024)Low — benchmark proxy; no HUMAN-specific dataQuality of expansion ARR vs. churn; critical for platform business valuationRequest historical NRR and GRR by product module and cohort vintage
Enterprise Sales Cycle6–7 months for large enterprise (company-stated, pre-channel program)Medium — company-stated in channel interview; post-program not yet measuredEfficiency of new ARR generation; cash conversion cycleValidated average sales cycle post-HUMAN Advantage Partner Program (Aug 2024)
ARR per FTE$200–$300K (SaaS benchmark proxy at $100M ARR and ~500 employees)Low — benchmark estimate; actual HUMAN data unavailableRevenue efficiency relative to headcount investmentActual ARR per FTE for internal headcount planning and efficiency benchmarking

All unit economics values are either company-claimed, conflicting third-party estimates, or SaaS industry benchmarks; none are independently verified for HUMAN Security. Gross margin, NRR, and ARR per FTE are benchmark proxies only and may not reflect HUMAN's actual operating model given its hybrid security-intelligence delivery.

[CI003, CI004, CI024, CI025, CI026, CI027]
FI002: Unit Economics Bridge — Cost Drivers to Gross Profit (Qualitative)

Qualitative cost driver map from platform operations to estimated gross profit; all values are benchmark-based estimates since HUMAN does not disclose unit economics.

All cost nodes are estimates based on Benchmarkit 2024/2025 SaaS benchmarks applied to the company's claimed ARR and public headcount. HUMAN does not disclose gross margin, COGS breakdown, or operating income. Actual unit economics may differ materially.

[CI024, CI025, CI026, CI027, CI028]

4.4 Public Financial Traction and Private Metric Gaps

HUMAN Security discloses very limited financial data as a private company. The principal public traction signals are: (1) company-claimed ARR exceeding $100M, first confirmed when the combined HUMAN+PerimeterX entity announced over $100M ARR at the July 2022 merger, and reiterated in the January 2024 CEO transition announcement attributing the milestone to Tamer Hassan's tenure; (2) 500+ global brands served as of October 2024, corroborated across multiple press releases; and (3) platform scale of 20 trillion digital interactions verified per week, and over one quadrillion annually in 2025. A directly conflicting third-party data point exists: GetLatka reported HUMAN ARR at $15 million as of December 2023. This figure is inconsistent with the merged entity's scale, headcount (437+ employees by mid-2024), and the post-merger ARR disclosure. GrowJo's model-based estimate of $140.4M annual revenue is more consistent with the post-merger company. The Latka figure may reflect pre-merger White Ops standalone revenue or a miscalculation; it cannot be resolved without audited disclosure. Net revenue retention, gross revenue retention, customer concentration, and cohort-level ARR data are entirely absent from public sources. [CI002, CI003, CI004, CI005, CI006, CI007]

Public Financial Gaps
Missing Private MetricImpact on DiligenceExact Diligence Path
Exact ARR by product segment (advertising vs. application vs. account vs. agentic)Cannot assess revenue concentration risk, cross-sell efficiency, or segment marginRequest audited ARR breakdown by product line and historical growth rate per segment
Gross margin (GAAP)Cannot assess cost leverage, infrastructure scalability, or path to profitabilityRequest GAAP income statement with COGS detail separating cloud infra from professional services
Net Revenue Retention (NRR) and Gross Revenue Retention (GRR)Cannot assess expansion quality, churn risk, or durability of >$100M ARR baseRequest NRR and GRR by product module, contract vintage, and customer segment
Monthly cash burn and current cash positionCannot assess runway, next-round trigger, or distress riskRequest CFO cash flow bridge with 12-month forward projection and current bank balance
Blackstone Credit $100M debt facility statusCannot assess true capital structure, covenant risk, or leverage burdenConfirm via term sheet review in data room; request current balance, covenants, maturity date
Customer concentration (top 10 customers as % of ARR)Cannot assess single-customer revenue risk or enterprise contract durabilityRequest customer concentration analysis; top 10 by ARR, tenure, and renewal history

All items in this table reflect genuinely unavailable public evidence and represent hard diligence requirements before financial underwriting. The ARR discrepancy between company-claimed >$100M and GetLatka's $15M is an especially urgent first-order gap.

[CI003, CI004, CI031, CI037, CI038]
FI003: Financial Estimate Ranges — Key Metrics with Source-Backed Bounds

Source-backed low and high bounds for HUMAN Security's key financial metrics; wide ranges reflect the conflict between company-claimed and third-party figures.

All ranges are estimates. ARR range spans conflicting third-party and company-claimed figures. Burn rate, runway, and valuation are inferences. No value in this figure reflects audited financial data.

[CI003, CI004, CI005, CI033, CI034]

4.5 Capital Adequacy and Financing Dependency

HUMAN Security has raised approximately $300 million in total equity capital across eight rounds (Tracxn and SiliconAngle, October 2024), including a $100 million growth round in January 2022 (WestCap, NightDragon), and most recently a $50 million growth round in October 2024 (WestCap, Goldman Sachs, ClearSky, NightDragon, Vertex Ventures US). Additionally, in July 2022 HUMAN obtained a $100 million debt facility from Blackstone Credit in connection with the PerimeterX merger, bringing total capital resources to approximately $350 million or more. White Ops filed a Form D with the SEC in June 2014 for its Series A raise, confirming its Delaware incorporation and the earliest equity financing event. The October 2024 round is expressly allocated to: accelerating AI platform capabilities (AgenticTrust and advanced detection models), expanding into the public sector, and strengthening the channel partner programme. With a headcount of approximately 469–519 as of mid-2026 and assuming a fully-loaded cost per employee of $180–$220K per year (senior-heavy tech company), implied annual payroll is $84–$114M. Including cloud infrastructure and G&A, estimated monthly burn is $9–$13 million. Post-October 2024 round, inferred runway at this burn rate is approximately 18–36 months depending on gross margin and revenue growth—extending to late 2026 through 2027. Cash position, exact burn rate, and the current status of the Blackstone debt facility are not publicly disclosed. [CI029, CI031, CI032, CI033, CI034, CI035]

Capital Adequacy
ItemAmount / StatusDateNotes
Series A (Form D filed with SEC)$11.1M equity2014White Ops, Inc. CIK 0001611028; Delaware incorporation confirmed
Series B$20M equity2016Led by institutional investors; company scale-up phase
Goldman Sachs / ClearSky InvestmentUndisclosed; majority stake acquisition2020-12Merchant banking division of Goldman Sachs and ClearSky; strategic majority investment
Growth Round (WestCap / NightDragon)$100M equity2022-01Led by WestCap; additional investment from NightDragon and Goldman Sachs; fuelled PerimeterX merger
Blackstone Credit Debt Facility$100M debt2022-07Provided at time of PerimeterX merger; repayment status not publicly confirmed as of 2026
Growth Round (WestCap / Goldman / ClearSky / NightDragon / Vertex)$50M+ equity2024-10Led by WestCap; use of funds: AI platform, public sector, channel programme
Total Capital (equity + debt)~$350M estimatedThrough Oct 2024~$300M equity per company disclosure; $100M Blackstone debt additional; some round overlaps possible
Estimated Monthly Burn$9–$13M/month (inferred)2026Based on ~500 employees at $180–220K fully-loaded; cloud infra and G&A additional; private
Estimated Runway (post-Oct 2024 round)18–36 months (inferred to late 2026 – mid 2027)2026-06Dependent on revenue growth and gross margin; burn rate is private; requires diligence confirmation

Exact cash position, burn rate, and the repayment or extension status of the $100M Blackstone Credit facility are not publicly disclosed. Monthly burn and runway estimates are inferred from publicly available headcount data and industry compensation benchmarks; actual figures may differ materially. All inferred fields require data-room confirmation.

[CI029, CI031, CI032, CI033, CI034]
FI004: Capital History — Funding Events and Strategic Purpose

Cumulative capital raise history showing equity rounds, debt facility, and strategic purpose of each financing event from 2014 through 2024.

Goldman Sachs acquisition amount and clean.io acquisition price were not publicly disclosed. Blackstone debt facility repayment status is unknown. Total equity raised is approximately $300M per company statement; total capital including debt ~$350M+.

[CI029, CI031, CI032, CI033]

4.6 Financial Verdict

HUMAN Security presents a credible SaaS platform business with company-claimed ARR above $100M, a defensible high-switching-cost product footprint, and a Forrester Leader designation in both Bot Management Q3 2024 and the expanded Bot and Agent Trust Management Q2 2026. The October 2024 $50M+ round and total ~$300M in equity financing signal sustained investor conviction. However, the revenue quality, margin path, and capital efficiency story cannot be independently underwritten: gross margin, NRR, exact ARR by segment, burn rate, and cash position are all private. A material discrepancy between the company-claimed >$100M ARR and GetLatka's $15M figure demands independent resolution as a first-order diligence step. The Blackstone $100M debt facility (2022) introduces leverage risk that is not yet reconciled in any public filing. The partner-first GTM pivot is strategically sound but nascent, and its contribution to sales efficiency is not yet measurable from public data. Financial verdict: revenue quality appears strong given enterprise stickiness and platform scale, but margin path and capital intensity remain diligence blockers. [CI003, CI004, CI031, CI036, CI037, CI038]

4.7 Exhibits

Chapter 05

05Product & Technology

5.1 Human Defense Platform — Product Lines and Customer Workflow

The Human Defense Platform (HDP) is structured around a unified claim: that digital interactions should be verifiable as legitimate human activity, trusted AI-agent traffic, or confirmed automated threats before they reach the customer's revenue-generating workflows. Customers deploy HDP across three core workflow challenges. First, eliminating invalid traffic (IVT) and ad fraud from programmatic advertising supply chains, where DSPs and SSPs accept bids without validating the underlying traffic. Second, blocking automated abuse targeting web applications, mobile apps, and APIs, including credential stuffing, scraping, transaction abuse, and fake account creation. Third, securing user account journeys from initial registration through post-login financial activity. As of 2026, HDP comprises four named product lines available on the AWS Marketplace and through enterprise contracts: HUMAN Advertising Protection (formerly MediaGuard), safeguarding the programmatic advertising supply chain with pre-bid and post-bid IVT detection; HUMAN Application Protection (formerly Bot Defender), protecting web and mobile applications and APIs from sophisticated bot attacks including scraping, transaction abuse, and fake signups; HUMAN Account Protection (formerly Account Defender), covering the full account lifecycle with pre-login, at-login, and post-login defenses against credential stuffing and fake account fraud; and HUMAN Client-side Defense (formerly Code Defender), enabling control over third-party scripts running in user browsers and supporting PCI DSS 4 compliance obligations. An additional module, BotGuard for Growth Marketing, targets marketing funnel integrity by filtering bot-driven click fraud and fake lead generation. The Sightline Cyberfraud Defense platform, launched July 30, 2025, serves as the unified interface across all product lines, adding AgenticTrust for AI-agent classification and governance and Page Intelligence for AI-driven traffic analytics for marketing teams. The clean.io acquisition in 2022 added real-time client-side JavaScript behavioral analysis for malvertising defense, expanding HUMAN's detection coverage earlier in the attack cycle. HUMAN serves 500+ global brands across media, finance, retail, government, and education verticals.[CE001, CE008, CE009, CE010, CE011, CE012]

Human Defense Platform — Product Module and Asset Matrix
Module / Product LineFormer NameTarget UserMaturity / StatusKey DifferentiationEvidence / Diligence Gap
Advertising ProtectionMediaGuardDSPs, SSPs, publishers, brandsGA — 14+ years in marketPre-bid + post-bid IVT; FraudSensor; MRC-accredited viewability (April 2026); TAG certifiedRevenue or IVT-reduction metrics not publicly disclosed
Application ProtectionBot Defender / BotGuardE-commerce, fintech, SaaS, enterprise web/API teamsGA — mature, continuously updated2,500+ signals, 400+ ML models, sub-2ms verdict; covers scraping, ATO, transaction abuse, fake signupsIndependent TPR/FPR benchmarks not published; black-box detection logic
Account ProtectionAccount DefenderFinancial services, retail loyalty, gaming, educationGAPre-login, at-login, and post-login coverage; device and behavioral signal continuity across full lifecycleNRR, retention cohort, and account-fraud reduction metrics not public
Client-side DefenseCode DefenderE-commerce, regulated industries requiring PCI DSS 4GA — launched in current form 2022Browser-level script monitoring and enforcement; PCI DSS 4 client-side compliance supportIndependent security audit of the product not publicly available
AgenticTrust (within Sightline)New — no prior nameEnterprise digital teams; agentic commerce and AI-agent governanceGA — launched July 2025; AWS Bedrock AgentCore support added 2026Cryptographic HTTP Message Signature verification; per-agent permission controls; AWS-native integrationAdoption metrics, agent coverage breadth vs. competitors not disclosed
BotGuard for Growth MarketingBotGuard for Growth MarketingPerformance marketing, affiliate, lead generation teamsGAFilters fake leads, bot-driven click fraud, and affiliate-code abuse from marketing funnelsCoverage scope and false-positive rate in marketing attribution stacks not independently validated

Data sourced from AWS Marketplace official listing (June 2026) and SoftwareOne product catalog. Former names reflect the nomenclature restructuring applied when Sightline Cyberfraud Defense launched July 30, 2025. Maturity assessments are derived from public product availability and market tenure, not from internal product-readiness scores.

[CE001, CE008, CE009, CE010, CE011, CE012]
Customer Use Cases — Workflow, Solution, and Limitation
User Job / Threat ScenarioWorkflow Without HUMANHUMAN Solution ModuleMeasurable Benefit (Claimed)Known Limitation
Programmatic ad buying; eliminate bot-driven IVTDSPs accept bids including fraudulent invalid traffic; viewability metrics are inflated by bot impressionsAdvertising Protection + FraudSensor (pre-bid and post-bid IVT filtering); MRC-accredited viewabilityIVT-filtered impression counts; MRC-validated viewability; reduced wasted ad spendSub-2ms insertion adds latency on lowest-latency inventory paths; pre-bid coverage depends on DSP/SSP integration breadth
Web application protection; block credential stuffing and scrapingRate-limiting and CAPTCHA; sophisticated attackers rotate IPs and bypass CAPTCHAs at scaleApplication Protection; 2,500+ signals analyzed; Precheck auto-validates ~95% of users; Human Challenge for ambiguous sessions95% of legitimate users pass without friction; sophisticated bot campaigns blocked via behavioral and device profilingComplex rule management for multi-region or custom API configurations; documentation depth cited as improvement area
Full-lifecycle account security; prevent ATO and fake accountsAuthentication at login only; post-login anomaly detection is reactive and session-scopedAccount Protection; pre/at/post-login behavioral continuity; device and session history across the account lifecycleLifecycle coverage reduces fraud that bypasses single-point login controls; covers fake account creation and compromised account useNo published TPR/FPR benchmarks; outcome metrics (fraud reduction %, chargeback rates) not independently verified
Govern AI agents accessing digital propertiesNo standardized governance; organizations either block all bot-like traffic (blocking legitimate agents) or allow all automationAgenticTrust within Sightline; classifies agent type and trust level; enforces per-agent permissions; cryptographic verification for AWS Bedrock agentsEnables agentic commerce without opening attack surface; reduces impersonation and excessive agentic scrapingCryptographic verification limited to agents implementing HTTP Message Signatures; legacy agents without signature support default to behavioral heuristics

Benefit claims are company-stated or analyst-reported; independent outcome benchmarks are not publicly available. Limitation entries are derived from user reviews (TrustRadius, PeerSpot) and analyst commentary as of June 2026.

[CE006, CE019, CE020, CE033]
FE002: Customer Protection Workflow — From Interaction to Enforcement

End-to-end flow from an incoming digital interaction through sensor collection, decision-engine verdict, and differentiated enforcement for humans, bots, and AI agents.

[CE005, CE006, CE019, CE020, CE033]

5.2 Core Technical Architecture and Detection Methodology

HUMAN's detection architecture separates into two complementary deployment components: the Sensor and the Enforcer. The JavaScript Sensor (version 9.6.6+ required for AgenticTrust support) is injected into the customer's web property via the HTML head tag and collects device fingerprinting signals, behavioral biometrics, session history, and network characteristics. This client-side signal stream is transmitted to HUMAN's cloud-hosted Decision Engine for real-time analysis. The Decision Engine is the platform's core intelligence layer, processing 2,500+ signals per interaction using 400+ adaptive ML models to produce a verdict—human, bot, or AI agent—in under two milliseconds. Approximately 95% of traffic is auto-validated by the Precheck mechanism without user friction; the Human Challenge is deployed only for interactions whose signal profile is ambiguous. The ML stack includes Profile Deviation Models 2.0 for detecting anomalous post-login behavior, attack profiling for segmenting traffic into distinct behavioral threat profiles, and network attack event detection for assessing the scope and coordinated complexity of in-progress campaigns. HUMAN Threat Tracker surfaces these profiles as actionable intelligence dashboards for security teams. On the enforcement side, HUMAN's Enforcer is available in over 20 integration formats, spanning major CDN and cloud providers (AWS Lambda@Edge, Azure Front Door, Cloudflare, Fastly VCL, Akamai EdgeWorker, Edgio), server frameworks (Nginx, Apache, HAProxy, Envoy, Varnish), language runtimes (Go, Java, .NET Core, Node Express), API gateways (AWS API Gateway, Apigee, Kong), and enterprise platforms (Salesforce). Python, PHP, Ruby, and Akamai ESI are not supported for the AgenticTrust module. FraudSensor, HUMAN's post-bid ad detection component, validates ad impressions after serving to provide supply-path-level viewability rates filtered for bot traffic, forming the foundation of the MRC-accredited Ad Viewability Measurement product.[CE002, CE003, CE005, CE006, CE015, CE016]

Technology and Operating Architecture — Layers and Dependencies
Layer / ComponentRoleKey Technology / SpecificationDependenciesRisk
JavaScript Sensor (client-side)Collects device fingerprints, behavioral biometrics, session and network signals from user browsersJavaScript Sensor v9.6.6+ for AgenticTrust; injected via HTML <head> tagRequires HTML head-tag access; blocked or degraded by browser ad-blockers and privacy extensionsPrivacy-tool proliferation and server-side rendering reduce signal fidelity for a fraction of sessions
Enforcer (server-side / edge)Enforces bot verdicts inline at CDN, WAF, API gateway, or origin; blocks, redirects, or rate-limits confirmed threats20+ Enforcer integrations: AWS Lambda@Edge v4.8.0+, Cloudflare v6.12.0+, Fastly VCL v12.3.0+, Akamai EdgeWorker v4.4.0+, F5 BIG-IP v3.1.1+, Nginx, Kong, Azure Front Door v1.2.1+CDN/cloud provider availability; API-key management per integration; PHP, Python, Ruby runtimes unsupported for AgenticTrustSingle-provider CDN outage or integration-version mismatch can impair enforcement path; custom runtimes require manual SDK integration
Decision Engine (cloud-hosted)Central AI/ML verdict system; processes 2,500+ signals per interaction using 400+ adaptive ML models; delivers sub-2ms verdictsProprietary multi-region cloud stack; Precheck mechanism auto-validates ~95% of traffic; Profile Deviation Models 2.0 for post-login anomaliesHUMAN cloud infrastructure uptime; ML model refresh cadence; data partnership qualityPlatform-side incidents directly affect customer protection; model updates can transiently affect false-positive rates
Behavioral Signal Network (data foundation)Training and inference data corpus; provides cross-customer threat correlation; enriches ML models with new attack patterns20T+ weekly interactions across 3B devices; 14+ years of behavioral data; supplemented by Satori IOC pipelineData partnerships with major ad exchanges, CDNs, and platforms; continuous data-partner agreementsNetwork effects depend on platform scale; smaller or niche verticals receive proportionally less correlated signal
FraudSensor (post-bid ad detection)Validates ad impressions after serving; filters bot and IVT-generated impressions before viewability calculationPost-bid detection; supply-path-level signal analysis; MRC-accredited viewability outputIntegration with DSP/SSP data pipelines; MRC audit compliancePost-bid detection captures fraud after cost is incurred; does not prevent fraudulent bids, only validates outcomes

Architecture details derived from HUMAN technical documentation, AWS Marketplace listing, and SoftwareOne product catalog as of June 2026. Enforcer version minimums are from HUMAN's official AgenticTrust documentation. Risk assessments are analyst-inferred from public architecture disclosures; internal SLA and uptime data are not public.

[CE002, CE003, CE004, CE005, CE015, CE016]
FE001: Human Defense Platform — Architecture Stack

Five-layer architecture from behavioral signal foundation to unified product interface, showing how Sensor, Enforcer, Decision Engine, and Satori intelligence interlock.

Layer groupings are analyst-derived from public architecture disclosures; internal service boundaries and exact data-flow topology are not publicly disclosed.

[CE002, CE003, CE004, CE007, CE015, CE016]

5.3 Satori Threat Intelligence — Research and Disruption Operations

The Satori Threat Intelligence and Research Team is HUMAN's internal threat research unit, led operationally by Lindsay Kaye (Vice President of Threat Intelligence) and overseen by Gavin Reid (CISO). Satori's mandate extends beyond reactive detection: the team investigates, reverse-engineers, and orchestrates coordinated disruption operations targeting large-scale threat actor schemes. This proactive posture—publicly disclosed takedowns that remove criminal infrastructure rather than merely blocking traffic—is the primary differentiator cited in HUMAN's Forrester Wave Q2 2026 top score, where HUMAN was the sole vendor to receive a perfect 5/5 in the Threat Research criterion. Historical disruption operations include: 3ve (a large-scale CPC fraud scheme dismantled in cooperation with the FBI, Google, and Facebook), Methbot (culminating in a 10-year prison sentence for the operator), PARETO (the most sophisticated CTV botnet identified at the time, disrupted with Roku and Google), Scylla (targeting advertising SDKs on Google Play and the Apple App Store), BADBOX 2.0, SlopAds, and Pushpaganda. The most recent major operation is Trapdoor, disclosed on May 19, 2026: a multi-stage scheme fusing malvertising distribution with hidden ad-fraud monetization across 455 malicious Android apps and 183 threat-actor-owned HTML5 domains. At its peak, Trapdoor accounted for 480 million bid requests per day, with associated apps downloaded more than 24 million times before Google Play removed the identified apps. Intelligence from these operations enriches the Decision Engine's ML models and is shared through private-sector and public-sector partnerships, including law enforcement agencies, app store operators, and cloud providers. This feedback loop between field research and product protection represents a technical moat that pure detection vendors cannot easily replicate. Satori also provides real-time event coverage—during Super Bowl LX in February 2026, HUMAN tracked 74 million blocked retail scraping attacks, a 33% rise in invalid bid requests, and a 5% increase in AI agent activity.[CE027, CE028, CE029, CE030, CE031, CE037]

5.4 Deployment, Integration, and Product Roadmap

HUMAN's deployment model is cloud-native and integration-forward. Customers access HDP through direct cloud contracts, the AWS Marketplace, or through channel partners including Carahsoft (federal and public sector distribution). The platform integrates with CDNs, WAFs, CIAM platforms, and analytics infrastructure without requiring rearchitecting of the customer's stack. Deployments range from lightweight Sensor-only implementations (for organizations that need signal coverage without inline enforcement) to full Sensor-plus-Enforcer deployments at the CDN or origin layer. The AWS partnership deepened materially in 2026 when AgenticTrust extended cryptographic verification support to Amazon Bedrock AgentCore traffic. AI agents built on the Bedrock platform are now cryptographically signed and policy-verified through HUMAN's AgenticTrust module, enabling enterprises to enforce granular per-action controls on AI agents operating within AWS-hosted applications. Supported integration targets for AgenticTrust (minimum Sensor version 9.6.6) include AWS Lambda@Edge from v4.8.0, AWS API Gateway from v0.1.1, Cloudflare from v6.12.0, Fastly VCL from v12.3.0, F5 BIG-IP from v3.1.1, and Azure Front Door from v1.2.1. On the standards front, HUMAN open-sourced a reference implementation of the HUMAN Verified AI Agent in November 2025, demonstrating HTTP Message Signatures (RFC 9421) for cryptographic agent identity—implemented via Ed25519 key pairs and the OWASP Agent Name Service (ANS v1.0) naming standard. This positions HUMAN as both a commercial vendor and an ecosystem standards contributor. The April 2026 Agentic Visibility expansion extended Sightline's bot and agent classification data natively into Adobe Experience Platform, making HUMAN the only bot-management vendor with a native Adobe integration for marketing measurement teams.[CE015, CE016, CE018, CE032, CE033, CE035]

Product Roadmap and Key Milestones (2022–2026)
Date / StageFeature / MilestoneStatusImplicationSource
2022 H2Acquisition of clean.io (anti-malvertising); integration into HUMAN Advertising ProtectionCompletedAdded real-time client-side JS behavioral analysis for malvertising defense; clean.io covered 125B impressions/month pre-acquisitionaithority.com; darkreading.com
July 30, 2025Launch of HUMAN Sightline Cyberfraud Defense featuring AgenticTrust; actor-level visibility across humans, bots, AI agentsGAFirst unified human/bot/AI-agent trust layer from HUMAN; intent-based governance model replaces binary bot/human detectionknowledgenile.com
November 2025Open-source HUMAN Verified AI Agent reference implementation; HTTP Message Signatures (RFC 9421); OWASP ANS v1.0Released (GitHub)Positions HUMAN as standards contributor for cryptographic agent identity; demonstrates A2A protocol with Ed25519 keysgithub.com/humansecurity/human-verified-ai-agent
April 21, 2026Agentic Visibility expanded to marketing and commerce teams; native integration with Adobe Experience PlatformGAExtends Sightline's bot/agent classification data to marketing measurement workflows; Adobe partnership reduces adoption frictionppc.land; cmswire.com
April 27, 2026MRC accreditation for Ad Viewability Measurement (display + video; desktop, mobile web, mobile app)GrantedIndustry validation of HUMAN's IVT-filtered viewability methodology; first security-first viewability accreditation in MRC historyppc.land (MRC accreditation article)
2026 (ongoing)AgenticTrust cryptographic verification support for Amazon Bedrock AgentCore; policy-compliant AI agents on AWSGA (rolling support)Enterprises using AWS Bedrock for agentic workloads can cryptographically verify agent identity; enforces per-action governance policiesitdigest.com

Roadmap entries sourced from official announcements and third-party news coverage. Forward-looking items beyond June 2026 are not included; no public roadmap document was available from HUMAN as of the research date.

[CE013, CE014, CE032, CE033, CE034, CE035]
FE003: Critical Dependency Map — Platform, Partners, and Ecosystem

Directed graph of HUMAN's critical external dependencies spanning cloud infrastructure, enforcement partners, data partners, analytics integrations, and disruption-operation partners.

[CE015, CE016, CE031, CE032, CE033]

5.5 Trust, Compliance, Privacy, and Identified Limitations

HUMAN's formal compliance posture is anchored by two external validations in 2026: MRC accreditation for Ad Viewability Measurement (granted April 27, 2026) and active TAG (Trustworthy Accountability Group) certification. The MRC accreditation is notable because HUMAN's methodology integrates FraudSensor IVT filtering directly into viewability calculation—the system counts only human-validated impressions as viewable, a security-first architecture that most pure viewability vendors do not implement. The accreditation covers display and video impressions across desktop, mobile web, and mobile app. The Client-side Defense product explicitly supports PCI DSS 4 client-side requirements by monitoring and enforcing JavaScript behavior policies in consumer browsers. Material limitations exist in the public evidence record. HUMAN has not published independent false-positive or true-positive rate benchmarks under controlled conditions, making it difficult for prospects to compare detection accuracy against competitors on a vendor-neutral basis. The decision engine operates as a "black box" from the customer's perspective: customers receive threat verdicts and attack profiles but have limited visibility into the specific model logic or signal weights. Enterprise customers have reported integration complexity for organizations with bespoke API infrastructure, and documentation depth for custom rule management is cited as an area for improvement. Additionally, HUMAN's Bot Management mindshare on PeerSpot declined from 11.6% to 8.1% year-over-year as of June 2026, suggesting competitive pressure despite strong analyst recognition. Privacy controls rely on standard enterprise SaaS practices. HUMAN's signal network collects behavioral and device data at massive scale; no independent privacy audit or detailed data retention policy has been made publicly available. For customers in regulated industries (healthcare, financial services, EU GDPR scope), the absence of a published independent privacy audit is a diligence gap. SOC 2 Type II compliance is implied by enterprise procurement standards but is not publicly confirmed.[CE034, CE038, CE039, CE042, CE043, CE044]

Trust, Quality, and Compliance Controls
Control / CertificationStatus (June 2026)ScopeGap / Limitation
MRC Ad Viewability Measurement AccreditationGranted April 27, 2026Display and video impressions across desktop, mobile web, and mobile app; covers viewability + IVT filtering (FraudSensor)CTV viewability MRC extension not confirmed as of June 2026; accreditation covers measurement methodology, not the broader HDP security posture
TAG (Trustworthy Accountability Group) CertificationActive — renewed in 2026 recertification cycleDigital advertising supply chain anti-fraud standards; applies to ad ecosystem partnersScope limited to advertising vertical; does not cover application protection, account security, or AgenticTrust capabilities
PCI DSS 4 Client-Side Compliance SupportSupported by Client-side Defense (Code Defender)Browser-level enforcement of third-party script behavior policies required under PCI DSS 4 client-side controlsCompliance attestation is the customer's responsibility; no independent HUMAN-issued PCI audit report publicly available
GDPR / CCPA Data HandlingImplied by enterprise SaaS standard; no independent audit publicly disclosedSignal collection and behavioral data processing under EU and US privacy frameworks for enterprise customersPrecise data retention schedules, sub-processor lists, and DPA templates not publicly published; SOC 2 Type II certification not publicly confirmed

Compliance status derived from official HUMAN announcements and third-party news coverage. SOC 2 and ISO 27001 certifications are standard for enterprise cybersecurity SaaS vendors but have not been independently confirmed for HUMAN in publicly available sources. Gap entries reflect absence of public evidence, not confirmed non-compliance.

[CE034, CE038, CE039]
FE004: Product Maturity and Capability Assessment by Module

Analyst-assessed capability maturity across five dimensions for HUMAN's five principal product lines/modules as of June 2026.

Maturity ratings are analyst-derived assessments based on public disclosures, third-party reviews, and analyst reports as of June 2026. They do not reflect internal HUMAN capability scorecards.

[CE001, CE030, CE042, CE043, CE044]

5.6 Exhibits

Chapter 06

06Customers

6.1 Customer Base Segmentation

HUMAN Security's customer base spans five distinct buying segments aligned to its three-pillar product platform (advertising protection, application/bot defense, account protection). The largest segment by historical revenue is advertising technology: DSPs, SSPs, ad-verification vendors, agency holding companies, and brand advertisers who require MRC-accredited invalid traffic filtration for digital media budgets. LinkedIn (B2B professional network), Sovrn (publisher platform), Madhive (local-media CTV OS), and AdRoll (performance DSP) are named production customers in this vertical. The second segment is programmatic marketplaces and commerce platforms—e-commerce and retail brands requiring Bot Defender and Sightline to stop scraping, credential-stuffing, and ATO attacks. Gartner Peer Insights reviews from $500M–$1B and $10B+ retail accounts describe production deployments for high-heat sneaker releases and multi-brand e-commerce portfolios. The third segment is financial services, where agentic AI traffic doubled month-on-month in May 2026 (HUMAN's own benchmark), driving demand for account-protection and transactional fraud defense. The fourth segment is broader enterprise security teams—organizations protecting web applications, APIs, and mobile channels—who access HUMAN's platform through the channel program (Optiv, serving 73% of the Fortune 100, and Consortium Networks as a managed security concierge). Travel and hospitality is an emerging fifth segment; a Gartner reviewer from a $250M–$500M travel brand describes production use of managed bot defense. Geographic segmentation is predominantly North America and Western Europe, with Tel Aviv R&D and UK commercial presence supporting EMEA. No revenue breakdown by vertical or geography is publicly disclosed. [CU001, CU002, CU003, CU004, CU005, CU006]

Customer Segment Map
SegmentPrimary Buyer/UserKey Use CaseScale / Revenue SignalRepresentative Customers / PartnersEvidence Gap
Advertising & AdtechDSPs, SSPs, brand advertisers, agenciesPre-bid and post-bid IVT detection; MRC-accredited ad fraud defenseLargest historical segment; 500+ global brands claimMadhive, LinkedIn, Sovrn, AdRollNo revenue share or account count disclosed
E-commerce & RetailSecurity engineers, fraud ops, product managersBot Defender, ATO prevention, scraping defense, high-heat event protectionGartner reviews from $500M–$1B and $10B+ retailersNamed accounts in Gartner (anonymous), sneaker retailer exampleProduction customers not publicly named
Financial ServicesFraud teams, application security leadsAccount takeover, credential stuffing, transactional abuse defenseAgentic traffic doubled MoM in May 2026 in this vertical (HUMAN benchmark)Unnamed; no published case studiesWeakest named-proof segment
Enterprise Security (via Channel)CISOs, security architects, IT procurementFull-platform deployment via Optiv/Consortium Networks managed serviceOptiv serves 73% of Fortune 100; Consortium Networks as concierge MSSPOptiv, Consortium Networks (named channel partners)No end-customer names from channel disclosed
Travel & HospitalityApplication security engineersBot mitigation, managed bot defense, DDoS assistGartner review from $250M–$500M travel brand (2026)Anonymous Gartner reviewerOnly one identified customer in this segment

Segment revenue shares are not disclosed by HUMAN (private company). Scale signals are derived from Gartner Peer Insights reviewer industries, press releases, and MRC-accredited deployment announcements. Financial services entry based on HUMAN's own agentic traffic benchmark data, not named customers.

[CU001, CU002, CU003, CU004, CU005, CU006]

6.2 Adoption Trajectory and Scale

HUMAN's most credible adoption signal is the sheer scale of its collective defense network. The company's 2026 State of AI Traffic & Cyberthreat Benchmark Report (released March 26, 2026) reports analysis of over one quadrillion digital interactions in calendar year 2025, while the Gartner Peer Insights company profile (updated February 2026) states HUMAN verifies "more than 30 trillion digital interactions per week across advertising, marketing, e-commerce, government, education and enterprise security." This represents an increase from the 20 trillion per week figure cited at the October 2024 fundraise, suggesting genuine network growth. The company claims 500+ global brands and organizations as customers, a metric that has been consistent in press releases from 2022 through 2026. A meaningful adoption acceleration marker is the exponential growth of agentic AI traffic: HUMAN's platform identified a 7,851% year-over-year increase in AI agent traffic in 2025, and legitimate AI-driven traffic overall grew 187% over the same period, concentrating heavily in retail/e-commerce, streaming/media, and travel/hospitality—HUMAN's three leading customer verticals by volume. Named deployments confirmed through public sources include LinkedIn (integrated May 2024, protecting 1 billion+ member professional network), AdRoll (Oct 2025, first DSP to combine HUMAN pre-bid fraud defense with viewability), Sovrn (long-standing partner, cited in April 2026 MRC accreditation announcement), and Madhive (described by HUMAN CEO Stu Solomon as a "long-standing partner" in June 2025). No ARR growth trajectory, customer count CAGR, or deployment milestone cadence is publicly disclosed for this private company, creating material tracking gaps. [CU007, CU008, CU009, CU010, CU011, CU012]

Customer Growth and Adoption Trajectory
MetricValueDateSourceConfidenceImplicationMissing Denominator
Weekly digital interactions verified>30 trillion/week2026-02-17Gartner Peer Insights company profilemediumNetwork growth: from 20T (Oct 2024) to 30T+ (Feb 2026)No customer count denominator
Annual digital interactions analyzed>1 quadrillion in 20252026-03-26HUMAN 2026 State of AI Traffic benchmark (newsroom)mediumMeaningful platform scale; requires HUMAN's own network to be this largeNo breakdown by customer segment or product
Brands / organizations served500+ global brands2024-08-21HUMAN GlobeNewswire partner program releaselowRepeated in multiple releases but no method disclosed; likely logos not ARRUnique paying customers vs. logos vs. integrated platforms unclear
Monthly devices monitored3 billion devices/month2024-08-21HUMAN GlobeNewswire partner program releasemediumLarge device fingerprint; consistent across multiple press releasesNo breakdown by product or vertical
AI agent traffic growth YoY7851% YoY in 20252026-03-26HUMAN 2026 AI Traffic benchmarkmediumSignals greenfield demand for AgenticTrust module; early mover advantagePercentage based on HUMAN's own platform, not industry-wide
LinkedIn: IVT rate detected<1% of desktop impressions in first 30 days2024-06-20HUMAN/LinkedIn joint press release (Yahoo Finance)highMeasurable outcome validating production deployment qualitySingle 30-day window; no long-term track

Metrics are sourced from company-issued press releases and third-party coverage. Confidence ratings reflect source independence and corroboration level. The 500+ brands claim is consistent across releases but unaudited. LinkedIn <1% IVT is a high-confidence claim corroborated by joint press release with a named counterparty.

[CU007, CU008, CU009, CU010, CU011, CU012]
FU002: Adoption and Deployment Funnel

Discovery-to-expansion funnel illustrating the conversion path from brand awareness to multi-module production deployment.

Top stage (500+ brands) is company-claimed across multiple 2024 press releases; unaudited. Named production deployments (6) are the publicly verified entries in TU003. Quantified-outcome deployments (3) are those with a published metric (LinkedIn <1% IVT, AdRoll 12ms, Madhive Fraud Free Guarantee). Multi-module estimate (2) is inferred from Madhive and LinkedIn evidence of combined advertising + application surface use; HUMAN does not disclose module attach rates or pipeline counts.

[CU007, CU009, CU015, CU031]

6.3 Named Customer Proof

Six named customer or partner deployments are supportable from public evidence as of June 2026. Madhive, the leading local-media CTV operating system trusted by Fox, Scripps, and Hearst, is the strongest case study: in June 2025 Madhive announced a Fraud Free Guarantee powered by HUMAN's MRC-accredited pre-bid and post-bid fraud detection, covering all 30,000+ daily local campaigns averaging under $5,000 per budget. HUMAN CEO Stu Solomon called Madhive a "long-standing partner" in the public announcement, indicating a multi-year production relationship. LinkedIn integrated HUMAN in May 2024, with the deployment detecting less than 1% of desktop impressions as invalid traffic across LinkedIn's publisher network including CTV in the first 30 days—a quantified outcome with an named spokesperson (VP Abhishek Shrivastava of LinkedIn Marketing Solutions). Sovrn, a publisher/advertiser platform, is cited by name in HUMAN's April 2026 MRC viewability accreditation announcement, with MD Jeff Meglio providing a testimonial about "stronger campaign performance" and "more efficient budget utilization." AdRoll became the first DSP to combine HUMAN FraudSensor post-bid measurement with MediaGuard pre-bid technology in October 2025, enabling IVT detection within 12 milliseconds. Consortium Networks CEO Nate Ungerott provided a public testimonial at the August 2024 partner program launch, describing HUMAN as bringing "exceptional value to our customers" for sophisticated fraud defense. Optiv, which serves 73% of the Fortune 100, is named by HUMAN as an "integral ally" channel partner. The Forrester Wave Q2 2026 report additionally notes that "HUMAN's customers compliment the level of detail and attack insight that they receive from the Sightline feature," indicating reference-quality deployments beyond the named set, though without naming specific organizations. [CU015, CU016, CU017, CU018, CU019, CU020]

Named Customer Proof Table
Customer / PartnerSegmentDeployment / Use CaseStatusOutcomeEvidence FreshnessLimitation
MadhiveAdtech / CTV local media OSMRC-accredited pre-bid Ad Fraud Defense + post-bid Ad Fraud Sensor for 30,000+ daily local campaignsProduction (long-standing partner per CEO quote)Fraud Free Guarantee launched June 2025; credit mechanism for suspect traffic; SOC I/II/III + TAG certified by Madhive using HUMAN tech2025-06-04Only CEO-level quote as corroboration; no quantified fraud reduction rate disclosed
LinkedInAdtech / Professional networking platformPre-bid IVT filtering + post-bid detection for desktop and CTV publisher network (1B+ members)Production (since May 2024)<1% IVT rate on desktop impressions in first 30 days; VP Abhishek Shrivastava publicly endorsed2024-06-20Outcome is from launch window only; no update published in 2025 or 2026
SovrnAdtech / Publisher platformMRC-accredited HUMAN Ad Viewability Measurement with IVT-filtered viewable impressionsProduction (long-standing partner per BI article)MD Jeff Meglio: HUMAN viewability metrics provide confidence in performance measurement with detailed reporting2026-04-27Testimonial-level evidence; no campaign-outcome metric disclosed
AdRollAdtech / Performance DSPFirst DSP to combine HUMAN FraudSensor post-bid + MediaGuard pre-bid; 12ms IVT detection across desktop, mobile, in-app, CTVProduction (since Oct 2025)Speed and coverage outcome: 12ms detection; first integrated dual-layer DSP2025-10-28Named via PPC Land timeline; no joint press release with AdRoll confirmed
Consortium NetworksEnterprise security channel / MSSPFull-platform resale and managed delivery of HUMAN Defense Platform to enterprise clientsProduction (named at program launch)CEO Nate Ungerott: HUMAN Security will continue to bring exceptional value to our customers2024-08-21Channel partner testimonial; no end-customer outcomes named
OptivEnterprise security channel / SIStrategic resell of HUMAN platform to Fortune 100 accounts via Advantage Partner ProgramProduction (named at program launch)Named as "integral ally" by HUMAN head of worldwide partnerships Tuan Nguyen; Optiv serves 73% of Fortune 1002024-08-21No specific deployment or customer outcome cited

Table covers publicly confirmed named relationships only. Production status inferred from duration and CEO-level quotes characterizing relationships as "long-standing." Pilot vs. production distinction cannot be fully verified externally for all entries. Gartner reviewer accounts (retail, travel) are anonymous and excluded.

[CU015, CU016, CU017, CU018, CU019, CU020]
FU001: Customer Journey Map — HUMAN Security Digital Trust Lifecycle

Maps customer segments through discovery, procurement, deployment, and expansion touchpoints across HUMAN's three platform surfaces.

Journey stages synthesized from named deployment evidence and channel program disclosures; procurement cycle durations from financials chapter evidence.

[CU016, CU017, CU018, CU019, CU031, CU032]
FU003: Customer Proof Quality Matrix

Rates named customer deployments on two axes — evidence quality (corroboration depth) and deployment maturity (production breadth).

Matrix positions are inferred from public evidence quality and deployment scope descriptions. Financial services pilot placement reflects absence of any named customer in that vertical. Exact production scope for Optiv and Consortium Networks end-customers is unknown.

[CU015, CU017, CU018, CU019, CU020, CU021]

6.4 Retention and Durability Evidence

HUMAN Security does not disclose NRR, GRR, churn rates, average contract length, or cohort retention for any customer segment—standard for a private company at this stage. Proxy evidence for retention and durability is available from review platforms and partner testimonials. On Gartner Peer Insights (updated through April 2026), HUMAN Sightline Cyberfraud Defense holds a 4.7/5 overall rating with 4.8 on Service & Support and 4.7 on Product Capabilities. One reviewer from a travel and hospitality company ($250M–$500M) rates the managed service 5/5 noting "their managed service is very responsive" and ongoing multi-year collaboration. A reviewer from a 1B–10B USD retail company specifically states "We have a long relationship with Human"—indicating multi-year tenure. A 10B+ retail company reviewer describes HUMAN enabling "a very secure online presence" across "all of our brands"— suggesting enterprise-wide deployment breadth. G2 recognized HUMAN as Best Security Software Product of 2026 (#1 in Bot Detection & Mitigation), a crowd-sourced peer validation. The Forrester Wave Q2 2026 report notes positive customer feedback specifically on attack insight depth, implying reference-quality relationships. One adverse signal: a 3/5 Gartner review from a $500M–$1B retail company describes HUMAN as a "black box"—limited visibility into detection logic, no proactive change notifications, and minimal manual tuning capability. This represents a real procurement friction point and a churn risk for technically-demanding security buyers. Retention signals from the HUMAN Advantage Partner Program (launched August 2024) note the three-tier structure is built around retention as a core metric alongside bookings and training, suggesting management awareness of this dimension, but no retention data is published. Industry benchmark data indicates 35% of cybersecurity vendor churn is attributable to CX rather than product performance, and 42% of cybersecurity customers switched vendors in the past two years— a sector headwind HUMAN's managed-service approach and Gartner 4.8/5 support score is designed to counter. [CU023, CU024, CU025, CU026, CU027, CU028]

Retention and Repeat Usage Signals
Metric / SignalValue or EvidenceSegmentConfidenceDiligence Ask
Gartner Peer Insights overall rating4.7/5 (as of 2026)Cross-segment (retail, travel, enterprise)mediumRequest verified renewal rate from references; Gartner sample size not disclosed
Gartner Peer Insights service & support score4.8/5Cross-segmentmediumIndicator of managed service stickiness; ask for CS-team:account ratio
G2 Bot Detection & Mitigation rank#1 Best Security Software 2026; prior #1 G2 Summer 2024 GridEnterprise cross-segmentmediumG2 reviews are not verified tenure data; ask for median contract age
Long-term relationship signalGartner reviewer: 'We have a long relationship with Human' (1B–10B retail)RetaillowSingle anonymous review; not independently verifiable
Adverse retention signal3/5 Gartner review: product described as 'black box' with no change notifications or tuning visibilityRetail ($500M–$1B)mediumBlack-box perception is a documented churn precursor; ask if HUMAN has shipped detection transparency roadmap
Channel retention incentiveHUMAN Advantage Partner tier structure rewards customer retention alongside bookings and trainingChannel / enterpriselowRetention metric targets and actuals not disclosed; <2 years old
NRR / GRRnull — not disclosed (private company)All segmentslowHighest-priority diligence ask; request at or before term-sheet stage
Average contract lengthnull — not disclosedAll segmentslowRequest breakdown by SMB channel vs. direct enterprise vs. adtech platform

NRR and GRR are null because HUMAN Security is a private company that does not disclose these metrics. Gartner Peer Insights and G2 data provide directional satisfaction signals only, not retention proof. Adverse retention signal from Gartner 3-star review is a real procurement friction indicator.

[CU023, CU024, CU025, CU026, CU027, CU028]
FU004: Customer Review Platform Ratings — HUMAN vs. Category Benchmark

Comparison of HUMAN Security's G2 and Gartner Peer Insights ratings against bot-management category benchmarks and adverse feedback signals.

Gartner Peer Insights values from the product page updated February–April 2026 (4 reviews visible in the public snippet). Benchmark values are approximate category averages from Gartner's bot/agent trust management market category. G2 rank from February 2026 Best Security Software announcement. Adverse review share approximated from 1 critical review out of 4 visible reviews in the Gartner snippet — actual distribution may differ with full review corpus. This figure substitutes for the planned cohort figure because no time-series customer-retention percentage data is publicly available for this private company.

[CU023, CU024, CU025, CU026, CU027]

6.5 Expansion and Concentration Risk

HUMAN's primary land-and-expand motion operates through three vectors: (1) cross-sell from advertising protection into application/bot defense and account protection within the same enterprise account; (2) agentic AI trust (AgenticTrust module within Sightline) as a greenfield upsell driver given the 7,851% growth in AI agent traffic; and (3) the HUMAN Advantage Partner Program launched August 2024, which deploys Optiv and Consortium Networks as channel multipliers under a three-tier structure rewarding annualized bookings, training completion, and customer retention. Strategic technology partnerships that expand addressable accounts include AWS Bedrock AgentCore browser support (cryptographically signed AI agent verification) and the Riskified partnership (August 2026 per RivalSense) for ecommerce fraud prevention via AI Agent Approve and AI Agent Intelligence. Concentration risk is material on two dimensions. First, HUMAN's legacy revenue base is heavily concentrated in digital advertising and adtech—a vertical where DoubleVerify and IAS command much larger market shares and where budget cycles are tied to media spend decisions rather than security budgets, creating sensitivity to macro advertising downturns. The Gartner Peer Insights reviewer base skews toward retail and travel sectors for application defense, but the company's historical brand identity and most public case studies remain ad-tech-centric. Second, no customer count, top-10-customer revenue share, or revenue-by-segment data is available for a private company, making it impossible to quantify concentration from external evidence. The HUMAN Advantage Program's deal registration and incumbency protections are designed to reduce channel conflict and improve account durability, but the program is less than two years old and maturity signals are absent. Procurement friction—6–7 month enterprise sales cycles requiring legal, MSA, and pricing negotiation before direct-sales channel program—has been explicitly acknowledged in prior financial chapter evidence and is a retention-adjacent risk. The channel model launched specifically to reduce this friction via managed onboarding. [CU031, CU032, CU033, CU034, CU035, CU036]

Expansion Drivers and Concentration Risk
Driver / RiskTypeEvidenceImpactDiligence Path
AgenticTrust module upsellExpansion driver7,851% YoY AI agent traffic growth; AWS Bedrock AgentCore support; Forrester Wave highest-score criterionHigh — first-mover greenfield expansion within existing customer baseAsk what % of existing Sightline customers have enabled AgenticTrust by mid-2026
HUMAN Advantage Partner ProgramExpansion driver (channel)Launched Aug 2024; Optiv + Consortium Networks named; 3-tier structure; deal registration + incumbencyMedium — less than 2 years old; partner enablement track record unclearRequest partner-sourced bookings as % of total new ARR in FY2025 and H1 2026
MRC viewability accreditation (April 2026)Expansion driver (adtech)Sovrn early adopter; AdRoll DSP integration; IVT-filtered viewability is differentiated vs. DV and IASMedium — opens viewability budget alongside fraud budgets for same customersAsk if viewability is bundled or separately priced; attached revenue per account
Riskified partnership (ecommerce)Expansion driver (new vertical)RivalSense: HUMAN + Riskified partnership Aug 2026 for ecommerce AI Agent Approve and AI Agent IntelligenceMedium — extends reach into merchant/payment fraud buyers not in core adtech baseVerify partnership terms; ask for co-sell pipeline
Ad-tech segment concentrationConcentration riskMajority of public case studies and named deployments in adtech/programmatic; historical brand = 'ad fraud company'High — ad budgets are macro-correlated; DV and IAS are larger-scale alternatives in same verticalAsk for revenue breakdown by product line and vertical; flag if >50% from adtech
Private company, no customer-count disclosureConcentration risk (information gap)Zero public disclosure of top-customer share, revenue by segment, or customer count by cohortHigh — impossible to assess concentration without management data room accessRequest top-10 customers as % of ARR and vertical breakdown under NDA
Enterprise direct-sales cycle friction (6–7 months)Concentration risk / churn riskAcknowledged in prior chapter; channel program designed to address; MSA and pricing complexityMedium — long cycles reduce switching propensity but also create entry barriers for new accountsAsk if channel program has reduced median sales cycle; target <4 months for mid-market via partner

Expansion drivers are based on publicly announced partnerships and product launches. Concentration risk is structural (adtech-heavy brand and customer base) compounded by private company opacity. The Riskified partnership date is from RivalSense competitive intelligence and should be independently verified.

[CU031, CU032, CU033, CU034, CU035, CU036]

6.6 Exhibits

Chapter 07

07Risks

7.1 Regulatory and Legal Risk Landscape

HUMAN Security's core technical capability—collecting and analyzing behavioral fingerprinting signals across more than one quadrillion digital interactions annually—creates a material and growing data privacy surface. The company processes device fingerprints, mouse-movement telemetry, keystroke timing, browser attributes, IP addresses, and cross-property behavioral patterns to distinguish bots from humans. Under 20 U.S. states that now actively enforce comprehensive privacy laws (as of January 2026), plus GDPR in Europe, any misclassification of HUMAN's data as personal-data brokerage or its behavioral signals as regulated data could trigger enforcement. The FTC sent formal warning letters to 13 data brokers under the Protecting Americans' Data from Foreign Adversaries Act (PADFAA) in February 2026, signaling active regulatory surveillance of mass-scale behavioral data vendors. The Department of Justice's Data Security Program (DSP) imposes additional restrictions on bulk cross-border transfers of covered personal data to "countries of concern." HUMAN operates globally and processes data from devices in 222+ countries; any configuration that routes covered data through Israel (where HUMAN has offices and engineering staff) or partnerships with entities with covered-country links requires CISA-compliant security controls. Plaintiffs' attorneys have developed a novel strategy: citing DSP violations as predicates for federal Wiretap Act claims even without a private right of action under the DSP itself, opening adtech data flows to class action exposure. The volume of online privacy lawsuits escalated from approximately 200 cases in 2023 to approximately 4,000 in 2024; the same behavioral tracking technologies HUMAN deploys for fraud prevention are precisely those targeted by plaintiffs. On the positive side, HUMAN earned MRC accreditation for Ad Viewability Measurement in April 2026, demonstrating compliance rigor. The MRC Digital Advertising Auction Transparency Standards were also finalized in January 2026, tightening disclosure requirements for ad auction participants. Critics, including the Check My Ads Institute, argue these self-regulatory frameworks are structurally insufficient—calling for government regulation— suggesting ongoing sector-level regulatory risk even for compliant vendors. As of June 2026, no active regulatory enforcement or litigation directly targeting HUMAN Security is publicly known; the risk is latent but material given the behavioral data scale. [CR001, CR002, CR003, CR004, CR005, CR006]

Regulatory / legal risk register
Rule / Case / LicenseJurisdictionStatus / MaturityLikelihood (HUMAN)SeverityMitigationResidual ExposureDiligence Path
CCPA/CPRA behavioral data complianceCalifornia (20-state patchwork)Active enforcement; CPPA fining since 2026MediumHighPrivacy-by-design; DPA in place; consent managementLatent; opt-out bypass creates dark-pattern riskObtain DSAR procedure; audit consent-management tool chain
FTC PADFAA / DOJ DSP cross-border dataFederal (US)Active — FTC warned 13 data brokers Feb 2026Low–MediumHighData mapping; CISA security controls; covered-country vendor auditMedium; Israel office and global data routing require DSP controlsRequest cross-border data flow map and DSP compliance certification
Wiretap Act class action (DSP predicate theory)Federal & multi-stateNovel theory; cases filed 2025–2026; untested on adtech vendorsLowHighPrivacy policy disclosure accuracy; web activity pixel auditMedium; behavioral tracking at HUMAN's scale is a target-classReview pixel/SDK data sharing with any covered-country entities
MRC accreditation complianceUS (voluntary industry)Accredited April 2026 for Ad Viewability; ongoing audit cycleLowMediumMRC audit program; transparent measurement methodologyLow; recent accreditation reduces near-term riskConfirm MRC audit schedule and next renewal date
Adtech sector self-regulation gap / government interventionFederal & EULatent; Check My Ads Institute and Senate scrutiny of digital ad fraudLow–MediumMediumMRC accreditation; public disruption ops (BADBOX, PARETO)Medium; legislative risk for mandated independent audits or fee structuresMonitor FASB/FTC guidance on adtech measurement mandates

Coverage is partial: rows represent material publicly known regulatory risks as of June 2026 based on law firm analyses, regulatory retrospectives, and MRC documentation. Undisclosed litigation, sealed proceedings, and non-U.S. enforcement actions are excluded. Likelihood scores reflect HUMAN-specific exposure, not sector-wide base rates.

[CR001, CR002, CR003, CR004, CR005, CR006]

7.2 Operational, Technical, and ML Risks

HUMAN's operational risk profile is dominated by three interrelated dynamics: cloud infrastructure concentration, bot-detection false positives, and an accelerating ML-model arms race. The platform's requirement to process 20+ trillion digital interactions weekly demands massive cloud compute and storage infrastructure, with AWS serving as the dominant public cloud provider. AWS suffered two significant infrastructure failures in early 2026: a March 2026 kinetic attack on UAE data centers that disrupted 38+ and 46+ services in the ME-CENTRAL-1 and ME-SOUTH-1 regions respectively, and a May 2026 thermal event in US-EAST-1 that cascaded across 150+ dependent cloud services. Any equivalent outage affecting HUMAN's primary detection infrastructure would directly impair SLA delivery to 500+ enterprise customers, many of whom rely on HUMAN for real-time fraud prevention at checkout or login. HUMAN has not publicly disclosed multi-cloud or active-active failover architecture details, creating a diligence gap around resilience posture. The false-positive problem is a structural weakness with legal and commercial consequences. Anti-bot systems produce false positives when legitimate users deploy privacy tools—ad blockers, VPNs, Tor, non-mainstream browsers, and anti-fingerprinting extensions. Ad blockers often suppress anti-bot scripts entirely, causing detection systems to classify the session as a bot; VPNs route traffic through shared IPs historically flagged as bot sources. For HUMAN's enterprise customers, false positives drive legitimate user friction, reduce conversion rates, and can trigger chargeback or complaint cycles that damage customer retention. The problem is not unique to HUMAN but shapes competitive dynamics with vendors that offer lower friction-profile detection. The detection arms race is intensifying. Automated traffic grew 23.51% year-over-year in 2025 while AI-driven traffic grew 187% in the same period per HUMAN's own benchmark data. BADBOX 2.0 emerged as a direct evolution of BADBOX 1.0 after HUMAN's original exposure—demonstrating that threat actors iterate quickly when disrupted. DoubleVerify detected 140% more CTV fraud scheme variants in Q1 2026 versus Q1 2025, driven by AI-assisted fraudster tooling. The threat is not static: agentic AI traffic grew 7,851% year-over-year and binary bot/human classification increasingly fails to address beneficial versus malicious AI agent traffic. Fraud signature drift means HUMAN's 400+ ML models must be continuously retrained, and regulatory fragmentation under 20 state privacy laws is now actively constraining data pipeline completeness, degrading model inputs. [CR011, CR012, CR013, CR014, CR015, CR016]

Operational / quality / security risk register
Failure ModeLikelihoodSeverityMitigation MaturityResidual ExposureUnresolved Gap
AWS cloud outage (single-region concentration)MediumCriticalLow–MediumHighNo public multi-cloud or active-active failover documentation
Bot detection false positives (privacy-tool users)HighMediumMediumMediumNo disclosed FP-rate benchmark in commercial contracts
ML model drift from evolving bot evasion tacticsHighHighMediumMediumRetraining cycle frequency and cost not publicly disclosed
Agentic AI traffic misclassification (trust vs. not)HighHighLowHighBinary bot/human models not fully adapted to AI agent governance
Data pipeline fragmentation from privacy regulationMediumMediumLowMediumNo disclosed approach to model retraining under GDPR/CCPA data limits
Threat actor iteration (BADBOX 3.0, new supply-chain attack)HighHighMediumMediumOngoing disruptions require continuous FBI and partner coordination

Likelihood and severity reflect informed assessments based on publicly reported 2026 cloud outage data, security research, and HUMAN's own threat benchmark report. Mitigation maturity scores are inferred from public disclosures; proprietary resilience architecture, SLA guarantees, and internal DR test results are not publicly available.

[CR011, CR012, CR013, CR014, CR015, CR016]
FR001: Risk heatmap

Severity-likelihood-mitigation heatmap for HUMAN Security's five principal risk domains as of June 2026. Agentic AI misclassification and AWS cloud concentration combine high severity with low mitigation maturity, yielding the highest residual exposure.

Likelihood and impact ratings are analyst assessments based on industry benchmarks and public disclosures; internal risk scoring is not available.

[CR001, CR015, CR023, CR040, CR041]

7.3 Partner, Platform, and Market Dependency Risks

HUMAN operates within a web of critical partner dependencies that are both competitive and cooperative. The BADBOX 2.0 disruption illustrates the co-dependency structure: HUMAN's Satori team discovered the threat, but actual remediation required Google to update Play Protect and take legal action in federal court, Shadowserver Foundation to sinkhole command-and-control domains, and FBI coordination for public warnings. This public-private model is a competitive moat but also a dependency—HUMAN cannot sinkhole infrastructure independently, and Google's involvement is discretionary. Google is simultaneously a key distribution partner (through Google Play Protect certification), a customer, and a competitor with growing in-house ad fraud detection capability. In the Bot Management market, HUMAN is ranked fifth in mindshare at 8.1% versus Cloudflare at 9.2% (ranked third) per Gartner Peer Insights and PeerSpot. Cloudflare's platform approach bundles DDoS mitigation, WAF, bot management, and API security as a single integrated stack with global edge distribution, while HUMAN offers deeper signal fidelity at the application layer but narrower infrastructure breadth. The ad verification segment has consolidated to a near-duopoly of DoubleVerify and Integral Ad Science as public companies with scale advantages. Large platform vendors—Google, Meta, Amazon— provide in-house fraud detection for their walled-garden inventory, structurally reducing demand for third-party verification on the highest-value impression segments. HUMAN must continuously demonstrate incremental lift over bundled alternatives to justify per-traffic-unit pricing. MRC accreditation, while recently earned, creates a governance dependency: the MRC is a voluntary industry body that critics find structurally under-resourced for enforcement. Loss of MRC accreditation, however unlikely, would impair HUMAN's competitive positioning with media buyers and agency partners who treat accreditation as baseline. The ad exchange integration layer—DSP, SSP, and publisher tech partnerships— also creates concentration risk if a major exchange deprecates HUMAN's SDK in favor of a bundled or competing solution. [CR023, CR024, CR025, CR026, CR027, CR028]

Partner / dependency risk register
DependencyCounterpartyRoleConcentrationFailure ScenarioSeverityMitigationResidual Exposure
Cloud compute / ML inferenceAWS (primary)Processes 20T+ weekly interactionsHighUS-EAST-1 outage during peak traffic eventCriticalUndisclosed resilience architecture; region diversification unknownHigh
BADBOX botnet disruption (C2 sinkholing)Google / Shadowserver FoundationSinkhole C2 domains; Play Protect enforcementHighGoogle deprioritizes disruption or Shadowserver capacity insufficientMediumJoint research publication; FBI coordination; co-prosecutionMedium
Ad verification ecosystemDoubleVerify / IAS (competitors)Market standard-setting; MRC compliance benchmarksMediumDV/IAS capture HUMAN's media-security use cases in bundleHighDifferentiation on behavioral signal depth; MRC accreditationMedium
Bot management competitive positionCloudflare / Google Cloud Armor / AWS WAFBundled platform alternative for enterprise customersHighEnterprise migration to bundled stack reduces HUMAN ARRHighDeeper behavioral telemetry; Satori threat intel; MAP datasetMedium–High
MRC accreditation governanceMedia Rating CouncilAccreditation body for ad viewability and IVT measurementLowMRC audit failure or governance reform removes accreditationMediumTransparent methodology; April 2026 accreditation achievedLow

Concentration scores reflect HUMAN's estimated reliance on each counterparty based on publicly available partnership disclosures and product architecture inference. Actual contractual terms, SLAs, minimum commitments, and exit rights are not publicly disclosed. Failure scenarios are illustrative worst cases, not predictions.

[CR023, CR024, CR025, CR026, CR028, CR029]
FR003: Dependency map

HUMAN Security's critical external dependencies mapped by category: cloud infrastructure, threat intelligence partners, regulatory bodies, and competitive/platform counterparties.

[CR025, CR029, CR030, CR023, CR031]

7.4 Financial, Competitive, and Execution Risks

HUMAN's financial risk profile is characterized by deep opacity. The most recently disclosed post-money valuation is $1.5 billion from January 2022—over four years stale and predating the PerimeterX merger, the clean.io acquisition integration, and the October 2024 $50M+ growth round. Market data aggregators (PitchBook, Premier Alts) show no current valuation disclosure. ARR, gross margin, net revenue retention, burn rate, and cash runway are all private. The 2024 round was described by CEO Stu Solomon as "deliberately constrained"—but that framing is unverifiable without independent financial disclosure. Investor-reported ARR of $100M+ (from the January 2024 CEO transition announcement) carries no gross margin or churn qualification; a third-party estimate of $15M ARR (GetLatka 2023) is irreconcilable without audited disclosure. Competitive pricing pressure from bundled-platform vendors is a medium-term model risk. Cloudflare, Google Cloud Armor, and AWS WAF with Bot Control offer comprehensive security stacks at scale with bundled pricing that effectively prices out standalone bot-management spend for enterprises already committed to those platforms. The ad fraud verification market has six or more competing tools including CHEQ, DoubleVerify, IAS, DataDome, and Cloudflare Bot Management, all competing on overlapping use cases. HUMAN's differentiation through the MAP (Media-Acquired Protection) dataset and the Satori threat intel moat is real but not permanently defensible if a platform vendor acquires comparable signal density. Execution risk centers on the January 2024 CEO transition from co-founder Tamer Hassan to Stu Solomon. Solomon brings credible operational experience (Recorded Future, Optiv, iSight Partners) but inherited both the PerimeterX integration and the need to scale a partner-first channel program from a previously direct-sales-only motion. The board is heavily investor-representative with Goldman Sachs, NightDragon, WestCap, and ClearSky as anchor investors, creating governance concentration around investor return timelines. The company has no disclosed path to public markets, and investor holding periods from the 2020 Goldman acquisition and 2021-2022 growth rounds are now entering year five or six, elevating exit-pressure risk. Model drift from agentic AI traffic growth (7,851% YoY) means HUMAN's classification infrastructure must evolve beyond binary bot/human decisions toward trust-or-not judgments in a regime shift that may require material R&D investment. [CR033, CR034, CR035, CR036, CR037, CR038]

People / execution risk register
Role / FunctionGap or DependencyLikelihoodSeverityMitigationDiligence Path
CEO (Stu Solomon, since Jan 2024)No prior CEO tenure at public company; inherited PerimeterX integrationLowHighBoard continuity; experienced operational team (COO/CFO Itenberg)Reference checks; assess integration execution track record
Satori threat intelligence team (CISO Gavin Reid)Specialized research team with limited bench depthMediumHighCo-develops threat intel with Google, Shadowserver, FBIAssess key-person risk; team headcount and retention incentives
Channel / CRO (Chris Scanlan, since 2024)Partner program launched Aug 2024 from zero; unproven at scaleMediumHighHUMAN Advantage Partner Program with tiered incentivesRequest partner-sourced pipeline share; CAC/payback period data
Board governance (investor-dominated)Goldman Sachs, NightDragon, WestCap, ClearSky hold majority seatsLowMediumExecutive Chairman Hassan provides founder continuityRequest board charter; confirm independent director representation

People/execution assessments are based on publicly disclosed leadership bios and company announcements. Compensation structures, equity grants, retention agreements, and succession plans are not publicly available. Severity reflects impact if the gap materializes, not probability.

[CR033, CR035, CR036, CR037, CR039, CR042]
FR002: Risk transmission map

Directed acyclic graph showing how HUMAN Security's primary risk categories propagate through the business to affect revenue, customer retention, margin, financing, and valuation.

[CR005, CR015, CR023, CR033, CR034, CR037]

7.5 Mitigations, Thesis-Break Triggers, and Diligence Asks

HUMAN's primary mitigations are structural: the Satori threat intelligence moat from monitoring one quadrillion+ interactions per year creates genuine detection advantages that point-in-time competitors cannot replicate. MRC accreditation (earned April 2026) provides media-buyer trust anchoring. The public-private disruption model—FBI, Google, Shadowserver, Trend Micro co-operations on BADBOX 1.0 and 2.0—demonstrates that HUMAN is embedded in the threat-response ecosystem in ways that bundled vendors are not. The $50M 2024 growth round and investor continuity (Goldman, WestCap, NightDragon) reduce near-term liquidity risk. The HUMAN Advantage Partner Program launched August 2024 diversifies customer acquisition away from long direct-sales cycles. Thesis-break triggers are concentrated in three areas. The first is platform bundling absorption: if Cloudflare, Google, or AWS meaningfully close the behavioral signal gap through acquisition or model improvement, HUMAN's pricing premium collapses for the majority of its customer base that already runs on those platforms. The second is a material cloud outage during peak traffic: AWS US-EAST-1 remains HUMAN's most likely operational single point of failure; a multi-hour outage during high-value media events (Super Bowl, Prime Day) would create immediate contractual and reputational exposure. The third is a privacy enforcement action: if a state AG or FTC action reclassifies HUMAN's behavioral signal network under a data-broker framework, or if novel Wiretap Act class actions citing DSP predicates name HUMAN as a defendant, compliance costs and customer trust could be materially impaired. Priority diligence asks: independent ARR confirmation and NRR benchmarking; multi-cloud resilience architecture documentation; data flow mapping to confirm DSP compliance for cross-border transfers; top-10 customer revenue concentration; post-PerimeterX integration gross margin trend; and AWS contractual terms including any minimum commitments and exit options. Given the valuation opacity, a secondary-market cap-table analysis is necessary before any entry at or above the 2022 $1.5B reference. [CR003, CR007, CR009, CR015, CR022, CR025]

Mitigation and kill criteria table
RiskMonitorable TriggerThreshold / EventAction Implication
Platform bundling encroachmentCloudflare/Google bot management market share growth; HUMAN customer churn to bundled stacksHUMAN mindshare falls below 5% in Gartner/PeerSpot; two top-10 customers migrate in 12 monthsThesis break: accelerate thesis re-evaluation; scenario-plan acquirer exit
AWS infrastructure single point of failureAWS US-EAST-1 outage coinciding with HUMAN peak traffic windowAny >4-hour outage with documented SLA breach across ≥5 enterprise customersMaterial breach: audit DR architecture; require multi-cloud commitment as covenant
Privacy enforcement (data-broker reclassification)FTC or state AG action naming adtech behavioral signal vendorsAny named enforcement action against HUMAN or a direct peer with identical data modelThesis break: immediate legal diligence; assess consent-management remediation cost
ARR growth decelerationNet new ARR from independent audited disclosure or channel partner reportingARR growth below 15% in any two consecutive reporting periodsRe-price: reduce valuation multiple; require quarterly ARR reporting as board covenant
ML model quality degradationFalse positive rate disclosed in customer-facing benchmarks or third-party auditsCustomer-reported FP rate above 1% in any major vertical or contract churn attributed to FPOperational watch: require model performance SLA in investment term sheet

Thresholds are indicative and should be refined with portfolio monitoring covenants. Trigger data depends on access to HUMAN's internal metrics, which are not currently publicly disclosed. Monitoring relies on secondary signals (market share data, peer enforcement actions, customer testimonials) in the absence of direct reporting.

[CR001, CR015, CR023, CR033, CR034, CR040]

7.6 Exhibits

Chapter 08

08Valuation

8.1 Investment Thesis and Anti-Thesis

HUMAN Security's investment thesis rests on five interlocking pillars. First, market necessity: bot-driven fraud, invalid traffic, credential abuse, and agentic-AI threats are non-discretionary security problems that expand as the digital economy grows; Gartner forecasts global information security spending of $244.2 billion in 2026, up 13.3% year-over-year, with cloud security growing 28.8%. Second, platform scale moat: verifying 20 trillion digital interactions weekly across 3 billion unique devices creates a data network effect that smaller competitors (Arkose Labs at $46.9M ARR, DataDome, Netacea) cannot replicate without equivalent infrastructure and threat-intel investment. Third, agentic-AI positioning: the July 2025 launch of HUMAN Sightline and AgenticTrust places the company directly in the highest-multiple cybersecurity niche (AI security, $2B in financing deployed YTD 2026 per Momentum Cyber). Fourth, investor conviction: five institutional backers—Goldman Sachs Merchant Banking, WestCap, NightDragon, ClearSky, Vertex—have consistently re-invested across multiple rounds through 2024. Fifth, platformization tailwind: strategic buyers drove 92% of cybersecurity M&A by value in 2026, and HUMAN's cross-layer platform (media security, application security, account protection, agentic trust) fits the buyer consolidation thesis. The anti-thesis is equally substantive. First, financial opacity: HUMAN discloses no NRR, gross margin, or ARR growth rate. The single available third-party ARR estimate (GetLatka, $15M as of December 2023) is an order of magnitude below the company-claimed $100M+ and remains unresolved. Second, capital overhang: approximately $300M in equity plus a $100M Blackstone Credit facility creates a $400M total capital base against which a $1.3–1.5B EV implies only a 3.25–3.75x gross MOIC on invested capital before dilution and liquidation preferences. Third, sector discount risk: HUMAN's ad-verification revenue stream (historically its primary business) benchmarks to DV/IAS multiples of 1.9x revenue—a fraction of the 15x cybersecurity peers' multiple—and buyers may apply a blended discount. Fourth, existing-investor concentration: the October 2024 round drew no new institutional names, which could indicate a restricted pricing ceiling. Fifth, consolidation threat: Cloudflare, CrowdStrike, and Palo Alto are all investing heavily in bot management and fraud prevention capability that could erode HUMAN's standalone premium. [CV001, CV002, CV003, CV006, CV007, CV009]

Recommendation Summary
DimensionAssessmentEvidence Basis
RecommendationTrackARR, platform positioning, and market benchmarks are consistent with a hold; undisclosed NRR/margin prevent conviction

Assessment reflects public evidence available as of the June 2026 research date. Confidence, risk rating, and valuation stance reflect the author's analytical judgment based on the comparable set and disclosed information. Undisclosed metrics could shift recommendation to buy or avoid.

[CV009, CV016, CV045]
Thesis and Anti-Thesis by Pillar
PillarThesis ArgumentAnti-Thesis ArgumentView-Changing Evidence
MarketBot/fraud/AI-agent security is non-discretionary and growing (Gartner $244.2B 2026 +13.3% YoY)Platform consolidation by hyperscalers compresses standalone bot-management TAMMeasurable multi-year ARR CAGR and channel partner pipeline growth rates
ProductInternet-scale detection network (20T interactions/week) with 400+ adaptive ML models creates data moatCloudflare, Akamai, and AWS amass comparable traffic telemetry at zero marginal cost for existing customersIndependent benchmark comparing HUMAN vs. Cloudflare Bot Management false-positive rates on identical traffic
Customers500+ global brand customers; mission-critical deployment creates high switching costsNo disclosed NRR or gross revenue retention; customer concentration unknownAudited NRR >115% and top-10 customer <5% ARR concentration
FinancialsCompany-claimed ARR >$100M at <$350K ARR/FTE suggests moderate capital efficiencyGetLatka $15M ARR data point is unresolved; gross margin and burn rate undisclosedAudited ARR, gross margin, NRR, and Blackstone Credit facility status
CompetitionLargest pure-play bot management platform; Forrester Wave Q2 2026 Leader designationDV/IAS anchor ad-verification multiples at 1.9x revenue; CrowdStrike/Palo Alto encroachingSustained Forrester Leader position and documented displacement of DV/IAS customers
Exit / ValuationCybersecurity M&A at record pace; private cyber median 15.2x and M&A median 16.3xOctober 2024 existing-investor-only round; no new external capital at step-up valuationNew institutional investor participation in a growth round or confirmed strategic M&A process

Thesis/anti-thesis arguments derived from public sources; view-changing evidence represents specific disclosures or external validations that would warrant a full thesis revision. All multiples cited reflect the Q2 2026 research date benchmarks.

[CV009, CV010, CV013, CV016, CV017, CV018]

8.2 Financing Context and Valuation History

White Ops was acquired by Goldman Sachs Merchant Banking Division, ClearSky Security, and NightDragon in December 2020 for an undisclosed price. In January 2022, the resulting HUMAN Security entity raised a $100 million growth round led by WestCap and NightDragon, with Goldman Sachs Asset Management participating. In July 2022, the PerimeterX merger valued the combined entity at approximately $1.5 billion, at which point HUMAN also secured a $100 million debt facility from Blackstone Credit. The 2022 valuation was set during the elevated private-market multiple environment of 2021–2022, when private cybersecurity medians exceeded 15x ARR. In October 2024, HUMAN closed a $50 million-plus growth round led by WestCap with Goldman Sachs Asset Management, ClearSky Security, NightDragon, and Vertex Ventures US, bringing total equity raised to approximately $300 million. Critically, no new valuation was disclosed, and no new institutional investors joined the cap table—a pattern that may reflect deliberate access rationing by existing investors or an inability to attract external capital at a step-up price. Windsor Drake notes that companies raising at inflated 2021–2022 valuations often use "structured rounds" with preferred return features to maintain nominal face-value marks. The current status of the Blackstone Credit $100M debt facility (issued July 2022) has not been publicly confirmed as of June 2026. If the facility remains outstanding, it creates seniority ahead of equity, compressing equity returns in any scenario below $1.1B enterprise value. The total capital at risk ($300M equity + $100M debt = $400M) against a $1.5B EV implies 3.75x gross MOIC, adequate but not exceptional for a position held since 2020. Premier Alternatives lists HUMAN's current private valuation as "N/A" with no secondary market data available. [CV001, CV002, CV003, CV004, CV005, CV006]

8.3 Comparable Valuation Analysis

HUMAN's valuation benchmarks against three peer sets: public ad-verification platforms (DV, IAS), private cybersecurity application-security peers, and cross-sector M&A precedents. These three sets produce materially divergent implied valuations, reflecting HUMAN's hybrid positioning between the ad-verification and pure-play cybersecurity markets. Public ad-verification comps provide the pessimistic anchor. DoubleVerify (NYSE: DV) reported LTM revenue of $781 million, EBITDA of $261 million, and gross margin of 82%, yet trades at only 1.9x EV/Revenue—a $2 billion enterprise value—reflecting structural headwinds in programmatic advertising and slow revenue growth of approximately 10% NTM. Integral Ad Science posted approximately $530 million in LTM revenue at a similar compressed multiple. The broader AdTech SaaS sector median NTM EV/Revenue is just 0.9x per Multiples.vc's June 2026 analysis, the lowest across all SaaS segments. Applied to a $100 million ARR, this would imply an EV of only $90–190 million—clearly inapplicable for a company with HUMAN's cybersecurity positioning, but it sets the floor if buyers mark HUMAN's ad-verification revenue at sector-appropriate rates. The cybersecurity comps are far more favorable. Finro's Q2 2026 dataset of 265 companies across 9 niches places Application Security (HUMAN's closest peer niche) at a 15.4x average and 13.0x median EV/Revenue. Windsor Drake's November 2025 report puts the private cybersecurity median at 15.2x ARR and M&A exit median at 16.3x. The cloud security niche trades even higher at 22.7x average (Finro), anchored by the Google/Wiz $32 billion transaction at 32x ARR. Kroll's Spring 2026 analysis notes that median cybersecurity EV/NTM Revenue multiples fell 26% quarter-over-quarter in Q1 2026 due to AI-related equity market pressure, so even the cybersecurity premium is currently under pressure. Private-market SaaS comps at HUMAN's revenue scale ($100M+ ARR) imply a range of 5.5–7.2x ARR for non-AI SaaS per iMerge Q1 2026, or up to 12–15x for AI-native platforms with high NRR. The Acquiry 2026 dataset corroborates: AI-native SaaS at 20–50% growth commands 7–12x ARR; traditional SaaS at 15–30% growth, 3–5x ARR. Given HUMAN's AI-native positioning claims but undisclosed growth rate, the range is wide. [CV012, CV013, CV014, CV015, CV016, CV017]

Comparable Valuation Table
ComparableTypeMetricEV / Revenue MultipleRelevance to HUMANKey Limitation
DoubleVerify (DV, NYSE)Public comp — ad verification$781M LTM revenue; $2B EV1.9x LTM RevenueShares HUMAN's advertising-fraud-prevention revenue stream and media-brand customer basePure ad-verification; no bot management or application security; 10% revenue growth; sector structural headwinds
Integral Ad Science (IAS, NASDAQ)Public comp — ad verification~$530M LTM revenue~1.7–2.5x (estimated)Overlaps with HUMAN's media security vertical; competitor in programmatic fraud detectionAgency-embedded distribution HUMAN lacks; no application security or agentic AI product
Application Security niche median (Finro Q2 2026)Private/M&A benchmark — 52 companiesAvg 15.4x; median 13.0x EV/Revenue13.0–15.4xClosest niche match; includes bot management and web application protection vendorsAggregated benchmark; individual company range wide (seed 15.5x to Series C 12.7x)
Private cybersecurity median (Windsor Drake)Private M&A benchmark — broad cyberMedian 15.2x ARR; M&A exit median 16.3x15.2–16.3xSector-wide private benchmark; HUMAN competes in same enterprise security buyer universeDoes not isolate application security sub-niche; includes cloud, identity, endpoint
Arkose LabsPrivate comp — bot management$46.9M ARR (2024); $140.7M valuation (~3x ARR)~3.0x ARRClosest product competitor; also pure-play bot management with enterprise focusMuch smaller scale ($47M vs. $100M+ ARR); last raise Series C in 2021; valuation may be stale
Wiz / Google (M&A precedent)M&A precedent — cloud security$1B ARR; $32B acquisition price~32x ARRSets ceiling for AI-native category-defining cybersecurity assetsCloud-native CNAPP is structurally different from bot management; AI-first architecture premium

Multiples as of June 2026 research date where available; Arkose Labs valuation from GetLatka 2024 data which may be stale. IAS multiple is an estimate from analyst coverage; precise current figure requires financial data subscription. All EV/Revenue multiples are on LTM or ARR basis as disclosed. Finro and Windsor Drake benchmarks cover private and M&A transactions; exact source transactions not individually auditable without paid dataset access.

[CV012, CV013, CV014, CV015, CV016, CV017]

8.4 Bull, Base, and Bear Scenario Analysis

The bear case assumes HUMAN's true ARR is at the lower bound of defensible estimates ($80–100 million), NRR has drifted below 105%, and gross margin is compressed below 70% due to heavy Satori team and infrastructure costs. Under these assumptions, the company's SaaS quality may not sustain a pure cybersecurity multiple, and buyers apply a 8–10x blended discount reflecting ad-verification revenue exposure. The resulting implied EV is $640M–$1.0B, below the total capital invested. The primary bear-case catalyst is a down-round forced by the need to extend cash runway beyond 2027 without improved metrics disclosure. The base case assumes the $100M+ ARR claim is accurate, NRR is in the 105–115% range (below best-in-class cybersecurity but positive), gross margin is 70–78%, and the platform is growing at 10–20% annually. At the application-security median of 13.0x, implied EV is $1.3B; at the private-cybersecurity median of 15.2x, implied EV is $1.52B—roughly in-line with the 2022 mark. A strategic exit to a platform consolidator (CrowdStrike, Palo Alto, or Cloudflare) at 14–16x represents a $1.4–1.6B range, yielding a 3.5–4.0x gross MOIC for the 2022 equity investors. The likely exit window is 2027–2029 given Netskope's 2025 IPO precedent and the current partial reopening of the cybersecurity IPO market. The bull case assumes ARR has grown to $130–140M (consistent with GrowJo's $140.4M estimate), NRR exceeds 115%, the agentic AI product line has achieved measurable bookings contribution, and HUMAN is designated as a Leader in the Forrester Bot and Agent Trust Management Q2 2026 Wave. Under these conditions, a strategic acquirer applying a 18–20x top-quartile multiple implies an EV of $2.34–2.8B. At CyberArk/Palo Alto precedent multiples (18.6x), $130M ARR implies $2.42B EV. An IPO exit at 12–14x NTM would require $175–210M in NTM revenue to support a $2B+ public market cap, achievable in 2027–2028 if growth rate accelerates to 20%+ annually. [CV009, CV010, CV011, CV017, CV018, CV019]

Bull, Base, and Bear Scenario Analysis
ScenarioKey AssumptionsImplied ARREV MultipleImplied EV (USD M)Probability SignalDownside Trigger
BullARR $130–140M; NRR >115%; AI-native platform premium; Forrester Leader sustained; strategic M&A process opened$130–140M18–20x$2,340–2,800Low-medium (requires ARR growth confirmation and NRR disclosure)AI product fails to achieve measurable bookings contribution within 2 product cycles
BaseARR $100–115M confirmed; NRR 105–115%; gross margin 70–78%; app-security median multiple; exit via strategic M&A 2027–2029$100–115M13–15x$1,300–1,725Medium (consistent with disclosed milestones and comp set benchmarks)Blackstone debt overhang limits equity upside; down-round bridge needed before exit
BearARR $80–100M (lower-bound); NRR <105%; margin compressed by Satori + infra costs; blended cyber/adtech discount$80–100M8–10x$640–1,000Low (requires significantly worse-than-disclosed operating metrics)Forced down-round below $1B; top-5 customer churn; regulatory action on ad-verification workflows

EV ranges are illustrative scenario analyses anchored to comparable benchmarks, not DCF-based valuations. Implied ARR and multiples are based on Finro Q2 2026 Application Security niche data (13.0x median, 15.4x average) and Windsor Drake private cybersecurity benchmarks (15.2x median). Downside multiples reflect blended cybersecurity/ad-verification sector pricing. Probability signals are qualitative assessments based on evidence availability and internal consistency with publicly disclosed milestones. USD millions.

[CV009, CV011, CV017, CV018, CV019, CV031]
FV002: Valuation Sensitivity to ARR Multiple

Implied HUMAN Security enterprise value across six scenarios from the ad-verification floor (1.9x) to the AI-native cybersecurity ceiling (22x), all applied to $100M ARR baseline.

All values applied to $100M ARR baseline (company-claimed floor). Actual ARR may be higher (GrowJo $140.4M estimate) or lower (GetLatka $15M disputed figure). Multiples sourced from Multiples.vc (DV), Finro Q2 2026 (App Sec), Windsor Drake (private cyber, M&A median), and Acquiry/SaaS Mag (AI-native range). Values in USD millions.

[CV013, CV016, CV017, CV019, CV031, CV032]
FV003: Valuation Return Range by Scenario

Low, mid, and high enterprise-value estimates for bear, base, and bull scenarios with explicit assumption anchors.

Bear low of $640M reflects 8x on $80M ARR; bear high of $1.0B reflects 10x on $100M ARR. Base range anchored to Finro App Sec median (13x) and private cyber median (15.2x). Bull range applies CyberArk/Palo Alto M&A precedent multiple (18.6x) at $130M ARR for mid, stretched to 20x at $140M ARR for high. All figures in USD millions. Ranges do not account for liquidation preferences, debt seniority, or dilution from new financing rounds.

[CV017, CV018, CV019, CV025, CV032, CV033]

8.5 Recommendation, Exit Readiness, and Diligence Asks

Based on available public evidence, the recommendation is Track. HUMAN presents a credible cybersecurity platform story with internet-scale proof, strong institutional backing, and strategic positioning in high-growth threat categories (bot management, AI agent trust). The investment is neither obviously overpriced—the 2022 $1.5B valuation aligns with current application-security benchmarks at stated ARR—nor obviously attractive absent confirmation of core operating metrics. Confidence is medium because material diligence gaps (NRR, gross margin, ARR growth, debt status, cap table preferences) cannot be closed from public sources. Exit readiness is partial. HUMAN is not named in any confirmed 2026 cybersecurity IPO pipeline. The company would need to close the financial disclosure gap with audited metrics, demonstrate a clear Rule of 40 score, and position the agentic AI product line as a growth driver before an IPO narrative would hold in the current selective public market. Strategic M&A is the more likely near-term path. Acquirers with strategic fit include CrowdStrike (identity + bot management integration with Falcon), Palo Alto Networks (platformization of anti-fraud across SASE + XSIAM), and Cloudflare (extending from CDN/WAF into full-stack bot and AI agent governance). Google (post-Wiz) and ServiceNow (post-Armis) are less likely but financially capable. A financial sponsor take-private is possible if MOIC at current multiples clears a 3.5x threshold on a 2027–2030 hold. Thesis-break triggers are defined as observable events that would require a full thesis revision, not just scenario adjustment. These include: an audited ARR disclosure below $80 million; confirmation of NRR below 95%; a down-round valuation below $1.0B; loss of a top-5 customer accounting for >15% of ARR; or regulatory action targeting core ad-verification workflows. The final diligence priority list (TV006) identifies six asks that would materially change the conviction level of this assessment. [CV016, CV017, CV025, CV030, CV039, CV041]

Thesis-Break and Kill Triggers
TriggerThreshold or EventTransmission to ThesisAction Implication
ARR disclosure below floorAudited ARR <$80MInvalidates cybersecurity-premium multiple basis; implies valuation is 2–3x current bear-case EVImmediate exit or deep discount reassessment; thesis collapses
Net revenue retention below retention floorAudited NRR <95%Signals negative land-and-expand; customer cohort deteriorating; multiple compression to 6–8xReassess as services-adjacent rather than SaaS; require evidence of retention fix before next round
Down-round financing eventNew equity round at valuation <$1.0BConfirmed overhang from $400M+ invested; signals internal consensus on distressed valueReassess hold position; potential liquidation preference dislocation
Platform vendor product displacementConfirmed HUMAN customer loss >15% ARR to Cloudflare, CrowdStrike, or Palo Alto in a single fiscal yearStructural erosion of the independent bot-management market; strategic buyer pool shrinksDowngrade to avoid; market share data confirms commoditization risk
Regulatory or legal adverse actionEnforcement action, material litigation outcome, or GDPR/CCPA violation affecting core productRevenue at risk from affected geography; potential customer churn; legal overhang raises discount ratePlace thesis on hold pending legal outcome; evaluate geography-specific customer concentration

Kill triggers represent observable events requiring full thesis revision, not scenario adjustments. Thresholds are set at levels where the base-case valuation range becomes unsustainable. All triggers are testable against public disclosures or management communications in a future diligence cycle.

[CV009, CV034, CV036, CV045, CV047]
Final Diligence Asks
TopicMissing EvidenceWhy It MattersOwner or Diligence Path
Net Revenue RetentionAudited or management-confirmed NRR by cohort year (target: current + 2 prior years)NRR is the single most important SaaS quality metric; determines whether multiple expansion or compression applies; gap between 95% and 120% NRR implies 30–50% valuation differenceManagement disclosure in data room; cross-check against customer reference calls
Gross Margin by ProductGross margin by revenue pillar (media security, application security, account protection, agentic AI)Satori team and ML infrastructure costs may compress blended margin below 70%; determines whether HUMAN is valued as pure SaaS (8–15x) or tech-enabled services (3–5x)Audited financial statements; CFO interview; infrastructure cost benchmarking
ARR Growth Rate and BridgeYear-over-year ARR growth from January 2022 ($100M claimed) to present, segmented by product lineFour-year growth rate determines whether the platform is in acceleration or deceleration; breaks the $1.52B vs. $640M valuation divergenceCFO interview; management accounts; cross-check with headcount/spend growth proxy
Blackstone Credit Facility StatusCurrent balance, maturity, interest rate, and covenant structure of the $100M debt facilitySeniority ahead of equity affects equity upside in scenarios below $1.5B EV; covenant violations could force premature exitLegal and accounting data room review; publicly available debt registration filings if any
Cap Table and Preference StackFull capitalization table showing share classes, liquidation preferences, participation rights, and anti-dilution provisions$300M equity across 8 rounds at varying prices may have created participating preferred structures that materially reduce common equity value in sub-$2B exit scenariosLegal data room; investor rights agreements; capitalization summary certificate
Customer ConcentrationTop-10 customer revenue contribution as a percentage of ARR; names of top-3 or anonymized revenue bandsBot management revenue is often concentrated among digital-media and e-commerce leaders; single-customer risk >10% ARR is a material thesis modifierCFO interview; contract abstracts; cross-reference with disclosed 500+ brand claim

Priority order reflects financial-materiality weighting: NRR and gross margin are immediate valuation determinants; ARR growth and Blackstone facility status are near-term thesis validators; cap table and concentration are deal-structuring inputs. All six items are required to progress from Track to Buy in a subsequent diligence cycle.

[CV007, CV009, CV036, CV045]
FV001: Recommendation Logic Flow

Logical chain from HUMAN's platform scale and financial evidence through risk assessment to the Track recommendation and primary exit paths.

Flow nodes represent the logical evaluation chain, not a financial model. Exit path timing is indicative based on comparable cybersecurity company trajectories and current IPO market conditions.

[CV009, CV016, CV019, CV039, CV045]
FV004: Investment KPI Scorecard

IC-ready scoring across eight dimensions from 0–10; reflects evidence-constrained assessment as of June 2026.

Scores are the author's evidence-constrained ordinal judgments (0=no evidence/critical failure, 10=best-in-class with full disclosure). Financial Metrics scored 3/10 due to absence of NRR, gross margin, burn rate, and ARR growth disclosure. Evidence Quality scored 4/10 due to the GetLatka/company-claimed ARR conflict and no audited financials. All other scores derived from public evidence reviewed during this research run.

[CV009, CV019, CV041, CV042, CV044, CV045]

8.6 Exhibits

Disclaimer

This report is for informational purposes only and is based solely on public information available as of 2026-06-19. It is not investment advice, does not constitute an offer or solicitation, and may omit material non-public information. Independent diligence and qualified financial, legal, and technical review are required before any investment decision.

Evidence index

Claims
IDStatementConfidenceSources
CO001 HUMAN Security was founded in 2012 in Brooklyn, New York, originally under the name White Ops. High SO001, SO005
CO002 HUMAN Security's four co-founders are Tamer Hassan, Michael Tiffany, Dan Kaminsky, and Ash Kalb. High SO001, SO003
CO003 HUMAN Security, Inc. is a privately held cybersecurity company; it is not publicly traded. High SO001, SO015
CO004 White Ops rebranded to HUMAN Security in 2021 to reflect an expanded scope beyond digital advertising fraud. High SO004, SO005
CO005 HUMAN Security is headquartered in New York City, with additional offices in Miami, Santa Clara, Tel Aviv, and the United Kingdom. Medium SO015, SO006
CO006 HUMAN's commercial product is called the Human Defense Platform (HDP), positioned as a unified cybersecurity platform. High SO001, SO007
CO007 HUMAN verifies more than 20 trillion digital interactions weekly across 3 billion unique devices. High SO001, SO006, SO007
CO008 HUMAN's platform examines 2,500 or more signals per digital interaction to make bot-or-human determinations. Medium SO001, SO007
CO009 HUMAN uses 400 or more adaptive machine learning models to analyze interaction signals. Medium SO001, SO007
CO010 HUMAN's Human Defense Platform spans three pillars: Media Security (ad fraud, invalid traffic), Application and Enterprise Security (account takeover, scraping, carding), and Account Protection (credential stuffing, fake accounts). Medium SO001, SO009
CO011 Tamer Hassan co-founded HUMAN Security and served as CEO until January 2024, when he transitioned to the role of Executive Chairman of the board. High SO003, SO011
CO012 Stu Solomon, formerly President of Recorded Future, was appointed CEO of HUMAN Security in January 2024. High SO003, SO006, SO011
CO013 Stu Solomon's prior executive experience includes the presidency of Recorded Future, CTO role at Optiv, leadership at iSight Partners (acquired by FireEye), and five years at Bank of America, plus a 25-plus-year military career in the Delaware Air National Guard and USAF. High SO003, SO006
CO014 HUMAN Security's current executive team includes Isaac Itenberg (COO/CFO), Gavin Reid (CISO), and Christos Kalantzis (CTO). Medium SO015
CO015 Dave DeWalt, CEO and founder of NightDragon, joined the HUMAN Security board as part of the 2020 acquisition and was designated Vice Chairman of the company. High SO005, SO007
CO016 Jay Leek, Managing Partner of ClearSky, joined the HUMAN Security board as part of the 2020 acquisition. High SO005, SO007
CO017 Kevin Marcus, Partner and Co-COO at WestCap, is referenced in the 2024 growth round materials as a board-linked investor representative. Medium SO007, SO006
CO018 Anthony Arnold, Managing Director at Goldman Sachs, is referenced in HUMAN's funding announcements as the firm's representative investor and board contact. Medium SO005, SO007
CO019 Ido Safruti, co-founder and CTO of PerimeterX, joined HUMAN Security's board as part of the July 2022 PerimeterX merger. High SO004, SO020
CO020 No public record identifies Matt Cantor in any current or recent executive, board, or leadership role at HUMAN Security as of June 2026. Medium SO002, SO003
CO021 Goldman Sachs Merchant Banking Division, ClearSky Security, and NightDragon acquired White Ops in December 2020, buying out previous investors including Paladin Capital Group and Grotech Ventures; acquisition terms were not disclosed. High SO005, SO018
CO022 HUMAN Security raised a $100 million growth round in January 2022, led by WestCap with participation from NightDragon. High SO009, SO012, SO006
CO023 The January 2022 $100 million growth round was reported to value HUMAN Security at approximately $1.5 billion, representing a unicorn designation. Medium SO006, SO009
CO024 In connection with the July 2022 PerimeterX merger, HUMAN received a $100 million debt facility from Blackstone Credit; this is a debt instrument separate from equity capital raised. High SO004, SO019
CO025 HUMAN Security raised $50 million or more in a growth round announced October 9, 2024, led by WestCap. High SO006, SO007, SO008, SO009
CO026 The October 2024 growth round included Goldman Sachs, ClearSky, NightDragon, and Vertex Ventures US as additional investors beyond lead investor WestCap. High SO007, SO008, SO009, SO016
CO027 HUMAN Security's total capital raised is reported by data aggregators as approximately $299 to $300 million across all equity rounds; this figure may not include the $100 million Blackstone debt facility. Medium SO017, SO016
CO028 HUMAN's Series C of $43 million was led by Scale Venture Partners in February 2019, with Canaan Partners also participating. Medium SO017
CO029 White Ops, together with the FBI, Google, Facebook, and other industry partners, participated in the takedown of the 3ve botnet in 2018-2019, which was described as the largest private-sector collaborative cybersecurity disruption to date. High SO001, SO005, SO012
CO030 White Ops uncovered and disclosed the Methbot ad fraud botnet in 2016, which was generating an estimated $3 to $5 million per month in criminal revenue. Medium SO001, SO014
CO031 HUMAN Security and PerimeterX announced a market-changing merger on July 27, 2022, creating a combined entity with more than 450 employees, more than 500 customers, and more than $100 million in ARR. High SO004, SO019, SO020
CO032 HUMAN Security acquired malvertising prevention firm clean.io in approximately March 2022. Medium SO003, SO006
CO033 HUMAN Security disrupted and disclosed the VASTFLUX ad fraud scheme in January 2023; VASTFLUX had injected malicious JavaScript into ad creatives across more than 1,700 spoofed apps, affecting approximately 11 million devices at a peak of 12 billion daily false bid requests. High SO014, SO024, SO025
CO034 HUMAN Security (Human Defense Platform) was named to TIME's Best Inventions of 2023. High SO001, SO003
CO035 HUMAN Security was named among TIME100 Most Influential Companies of 2023. Medium SO003
CO036 HUMAN Security disrupted the BADBOX pre-installed Android botnet in multiple phases from 2023 through 2025, coordinating with Google, German authorities, and Shadowserver to sinkhole command-and-control infrastructure. Medium SO001, SO013
CO037 HUMAN Security was named a Leader in The Forrester Wave: Bot Management Software, Q3 2024. High SO001, SO006
CO038 HUMAN Security was named a Leader in The Forrester Wave: Bot and Agent Trust Management Software, Q2 2026, and was the only vendor to receive the highest possible score in the Threat Research criterion. High SO013, SO023
CO039 In October 2024, AdExchanger published a correction noting that HUMAN CEO Stu Solomon had misspoken during an interview; HUMAN clarified through its VP of Product that the company does not plan to build a proprietary deterministic ID or a measurement and attribution solution. Medium SO010
CO040 No material lawsuits, regulatory investigations, data breach disclosures, or formal sanctions against HUMAN Security have been identified in public records as of the June 2026 research date. Low SO001, SO002
CO041 HUMAN Security does not disclose its revenue, ARR, or current post-money valuation publicly; all financial metrics require data room engagement for diligence. High SO006, SO010
CO042 As of October 2024, HUMAN Security employs approximately 400 people, with plans to meaningfully expand the data science and engineering team, according to CEO Stu Solomon. Medium SO006, SO010
CO043 HUMAN Security serves 500 or more global brands across media, finance, retail, government, education, and enterprise security. Medium SO001, SO007
CO044 HUMAN's three product pillars are Media Security, Application and Enterprise Security, and Account Protection. Medium SO009, SO007
CO045 HUMAN's Satori Threat Intelligence and Research Team provides threat intelligence, feeds product enhancements, and orchestrates disruptions of cybercriminal operations, including major takedowns like VASTFLUX, BADBOX, and PARETO. Medium SO001, SO013
CO046 HUMAN launched HUMAN Sightline Cyberfraud Defense as a unified trust and defense layer protecting digital businesses from bot attacks, human-led fraud, transaction abuse, and AI-driven risks by mid-2026. Medium SO013
CO047 HUMAN launched AgenticTrust, a product enabling customers to detect, classify, and govern AI agents operating on their platforms, by mid-2026 as part of its agentic AI expansion. Medium SO013
CO048 G2's Summer 2026 Grid for Bot Detection and Mitigation Software named HUMAN the top overall Leader based entirely on customer feedback. Medium SO013
CM001 HUMAN Security's served market spans bot mitigation, ad fraud/SIVT defense, account takeover prevention, and agentic AI trust management, unified under the Human Defense Platform (Bot Defender, Sightline Cyberfraud Defense, MediaGuard/Ad Integrity Suite, and AgenticTrust module). Medium SM001, SM002
CM002 The global bot mitigation market is sized at $0.9 billion in 2025 and projected to reach $1.12 billion in 2026 at a CAGR of 24.8% (Business Research Company). Medium SM004
CM003 Fortune Business Insights values the global bot security market at $1.05 billion in 2025 and $1.27 billion in 2026, growing to $5.67 billion by 2034 at a CAGR of 20.55%, with North America accounting for 38% of global share. Medium SM005
CM004 Global digital advertising losses attributable to ad fraud exceeded $100 billion in 2026, driven by an approximately 20% invalid traffic rate globally across programmatic channels. Medium SM015, SM006
CM005 Fraudlogix's analysis of 105.7 billion impressions collected throughout 2025 showed a global IVT rate of 20.64%, with the US at 23.69% across 37.6 billion impressions, implying roughly $37 billion in US programmatic spend annually associated with invalid traffic. Medium SM006
CM006 The global account takeover protection market is estimated at $6.28 billion in 2025, projected to reach $7.46 billion in 2026 with an 18.89% CAGR through 2035 (Global Growth Insights). Medium SM019
CM007 The Business Research Company projects the eCommerce fraud detection and prevention market at $88.77 billion in 2026 at a CAGR of 20.8%, though this scope includes payment fraud, chargebacks, KYC, and identity proofing outside HUMAN's current product suite. Low SM012
CM008 Grand View Research estimates the all-verticals fraud detection and prevention market (including AML, KYC/KYB, payment fraud) at $40.4 billion in 2026 with an 18.1% CAGR through 2033—a scope roughly 30x wider than HUMAN's bot-security SAM. Low SM011
CM009 An analyst-synthesized SAM for HUMAN Security of approximately $1.5–$2.0 billion in 2026 is constructed from bot security ($1.27B per Fortune BI) plus an estimated $500M–$800M for MRC-accredited SIVT vendor spend; this is pre-bundling-haircut and has no independent primary-source validation. Low SM004, SM005, SM013
CM010 The bot mitigation market is projected to grow from $1.12 billion in 2026 to $2.4 billion in 2030 at a CAGR of 20.9% (Business Research Company). Medium SM004
CM011 Fortune Business Insights projects the bot security market at $5.67 billion by 2034 at a CAGR of 20.55%, with North America holding 38% of market share in 2026. Medium SM005
CM012 Published market estimates for the fraud prevention space range from $1.12 billion (bot mitigation only) to $88.77 billion (eCommerce FDP), a 79x spread driven by boundary definition rather than genuine disagreement, making cross-source TAM comparison unreliable without scope normalization. Medium SM004, SM012, SM005, SM011
CM013 At the US programmatic ad spend level, a 23.69% IVT rate applied to an estimated $156 billion US programmatic market implies approximately $37 billion in annual ad spend potentially exposed to invalid traffic (Fraudlogix, 2026). Medium SM006
CM014 North America represented the largest region in the bot mitigation market in 2025 and accounts for approximately 38% of the global bot security market per Fortune Business Insights. Medium SM005, SM004
CM015 HUMAN Security's Defense Platform analyzed more than one quadrillion digital interactions in 2025, providing a network effect advantage in behavioral signal training across bot, human, and agentic AI traffic. High SM001, SM003
CM016 More than 95% of AI-driven automation in 2025 was concentrated in three verticals: retail and e-commerce, streaming and media, and travel and hospitality—HUMAN's primary buyer segments. High SM001, SM010
CM017 HUMAN customers experienced on average more than 400,000 attempted post-login account compromise attacks in 2025, a figure quadruple that of 2024, reflecting the acceleration of ATO as a core enterprise security problem. Medium SM001
CM018 Retail and e-commerce topped all verticals for the highest volume of scraping, carding, and ATO attacks in HUMAN's 2025 data, with 70% of all observed scraping attacks targeting this segment. Medium SM001, SM010
CM019 More than 440,000 unique threat profiles targeted retail and e-commerce businesses in 2025 per HUMAN's Threat Tracker, more than four times the next-highest vertical total. Medium SM001
CM020 Traffic from AI agents and agentic browsers grew 7,851% year-over-year in 2025 per HUMAN's Defense Platform data, creating a new trust management challenge distinct from traditional bot detection. Medium SM001, SM010
CM021 Automated traffic across the internet grew 23.51% year-over-year in 2025 while human traffic increased only 3.10%, a ratio of approximately 8:1 (HUMAN Security 2026 benchmark report). Medium SM001, SM010
CM022 HUMAN Security was named a Leader in The Forrester Wave™: Bot and Agent Trust Management Software, Q2 2026, receiving the highest possible scores across nine evaluation criteria. High SM002, SM003
CM023 HUMAN was the only vendor in the Q2 2026 Forrester Wave evaluation to receive a 5/5 in the Threat Research criterion, underscoring differentiation via the Satori Threat Intelligence and Research team. High SM002, SM003
CM024 TAG awarded 307 certification seals to 196 companies in 2026 across four programs (Certified Against Fraud, Against Malvertising, Brand Safety Certified, Certified for Transparency), with 74% independently audited—acting as a market compliance driver for SIVT vendors. High SM008, SM009, SM018
CM025 Global cybersecurity spending is projected to reach $240 billion in 2026, a 12.5% year-over-year increase (Gartner), with approximately 40% of enterprise security budgets allocated to software and platforms. Medium SM025, SM026
CM026 Despite increased security budgets, 63% of organizations still experienced breaches in 2025, suggesting that budget growth alone is insufficient and creating demand for more effective behavioral and signal-based platforms. Medium SM025
CM027 AI-driven traffic surged 187% in 2025 from January to December (HUMAN data), fundamentally changing the nature of bot detection requirements from static rule-based systems to continuous behavioral validation across the session lifecycle. Medium SM001, SM010
CM028 Cloudflare holds approximately 79% of bot management install-base market share compared to Akamai's 6%, based on technology adoption data across major global markets in 2026. Medium SM014
CM029 Cloudflare's bundled CDN, WAF, and bot management offering starts at approximately $350 per year for SMBs with flat-rate predictable pricing, creating a price-point barrier that pure-play bot defense vendors cannot easily match at the lower market. Medium SM014
CM030 DataDome's market share in bot management fell from 13.8% to 8.9% between 2025 and 2026, potentially indicating headwinds for dedicated bot management vendors from Cloudflare's growing bundled security offer. Low SM017
CM031 Enterprise bot management solutions integrate deeply into login flows, checkout APIs, and analytics pipelines; migration to a new vendor requires thorough retesting of all affected flows, creating high switching costs that protect incumbents but slow new-logo acquisition. Medium SM017
CM032 HUMAN Security does not publish public pricing; enterprise contracts are custom-quoted following an environmental audit, creating sales friction compared to self-serve competitors such as Cloudflare and lengthening sales cycles. Medium SM021
CM033 Bot mitigation ROI primarily appears as fraud losses avoided rather than incremental revenue, making the benefit 'invisible' in P&L statements and requiring sophisticated measurement frameworks to justify budget approval from non-technical stakeholders. Medium SM017
CM034 In-house fraud rule engines and data-science teams represent a build-versus-buy alternative at large internet platforms with sufficient ML engineering capacity, limiting HUMAN's SAM to companies without that internal capability. Medium SM017
CM035 The $88.77 billion eCommerce FDP market estimate (Business Research Company) and the $1.27 billion bot security estimate (Fortune BI) are both 2026 figures but reflect incompatible scope boundaries: the eCommerce FDP estimate includes payment fraud, chargebacks, and identity proofing that HUMAN does not address. Medium SM012, SM005
CM036 Grand View Research's $40.4 billion fraud detection market estimate includes AML, KYC, payment fraud, and identity proofing, categories outside HUMAN's current scope; using this figure as HUMAN's TAM would overstate the relevant market by an estimated 30-40x. Medium SM011, SM005
CM037 Cloudflare and Akamai's bundling of bot management with CDN and WAF services may displace standalone bot defense vendors from a significant portion of the addressable market, particularly in the SMB and lower-mid market segments where flat-rate pricing is decisive. Medium SM014, SM017
CM038 Pixalate's Q1 2026 Ad Fraud Benchmark Report measured 24% IVT on US desktop and mobile web, 32% on mobile apps, and 24% on CTV, confirming persistent invalid traffic across all programmatic channels. Medium SM007
CM039 Europe maintained the lowest regional IVT rate at 7.80% while Asia-Pacific showed the highest at 27.85%, indicating that HUMAN's addressable market for SIVT defense is geographically uneven, with North America and APAC being the largest opportunities. Medium SM006
CM040 HUMAN's Ad Fraud Defense pre-bid platform and Ad Fraud Sensor post-serve platform hold MRC accreditation (renewed April 2025) for GIVT and SIVT detection across desktop, mobile web/app, and CTV environments. Medium SM013, SM016
CM041 AI training crawlers made up 67.5% of AI-driven traffic in 2025 but their share declined sharply as AI scraper traffic grew 597%, shifting the dominant automated threat from passive indexing to active data harvesting. Medium SM001
CM042 Forrester renamed the market category from 'Bot Management' to 'Bot and Agent Trust Management Software' in 2025, reflecting the structural shift from distinguishing human vs. bot traffic to governing whether an AI agent can be trusted to transact on a user's behalf. High SM002, SM003
CM043 HUMAN launched AgenticTrust in 2025, a module within Sightline Cyberfraud Defense that provides a unified approach for distinguishing among human, bot, and agentic AI traffic with granular agent permissions. Medium SM002, SM025
CM044 HUMAN announced support for Amazon Web Services' Bedrock AgentCore browser through AgenticTrust, verifying that AI-powered agents built on AWS infrastructure are cryptographically signed, policy-compliant, and secure. Medium SM002
CM045 HUMAN Security was named the top overall Leader in the G2 Summer 2026 Grid for Bot Detection and Mitigation Software, based entirely on verified customer feedback. Medium SM003
CM046 EXTE integrated HUMAN Security's MediaGuard (Ad Fraud Defence) in March 2026 as a supply-quality layer, making HUMAN the verification provider for EXTE's programmatic ad inventory. Medium SM016
CM047 The eCommerce-specific fraud prevention solutions market is separately valued at $8.31 billion in 2026 at a CAGR of 20.63% through 2032 (360i Research), providing an intermediate estimate between the bot-security-only figure and the broadest all-FDP estimate. Low SM012
CM048 41% of AI scraper traffic in 2025 targeted media and streaming websites, while 37% targeted e-commerce, confirming these as the two highest-volume verticals for AI-driven data harvesting attacks. Medium SM001
CM049 HUMAN Security raised $50 million in growth funding in October 2024 (led by Riverwood Capital) and $100 million in January 2022 (led by WestCap and NightDragon), providing capital to scale the Defense Platform across enterprise verticals. Medium SM020, SM026, SM022
CM050 AI-driven traffic in 2025 was generated predominantly by OpenAI (69% share), Meta (16%), and Anthropic (11%) across HUMAN's sensor network—indicating that the top AI platform operators drive the majority of agentic and scraper activity. Medium SM001
CP001 HUMAN Security's Human Defense Platform processed more than one quadrillion digital interactions across its global customer base in 2025. Medium SP006
CP002 Automated traffic grew 8x faster than human traffic year-over-year in 2025, as measured by HUMAN Security's platform data. Medium SP006
CP003 Monthly volumes of AI-driven traffic grew 187% from January to December 2025, nearly tripling over the calendar year. Medium SP006
CP004 AI agent and agentic browser traffic grew 7,851% year-over-year in 2025, per HUMAN Security's 2026 State of AI Traffic benchmark report. Medium SP006
CP005 HUMAN Security was named a Leader in The Forrester Wave—Bot and Agent Trust Management Software, Q2 2026. Medium SP003
CP006 HUMAN received the highest possible scores in nine criteria in the Forrester Wave Q2 2026, including Threat Research and AI Agent Trust Management. Medium SP003
CP007 Forrester wrote that HUMAN's partnership program is a standout, citing breadth and alignment with emerging agentic trust and agentic commerce use cases. Medium SP003
CP008 G2's Summer 2026 Grid named HUMAN Security Medium SP004
CP009 HUMAN Security launched the Ad Integrity Suite in June 2026, positioning it as a modern alternative to legacy ad verification providers like DoubleVerify and IAS. Medium SP005
CP010 HUMAN's Ad Integrity Suite combines IVT intelligence, AI-powered brand safety and suitability, and viewability in a single framework with URL-level explainability. Medium SP005
CP011 Kasada secured a $20 million funding round in February 2026, led by EQT with participation from Ten Eleven Ventures, Main Sequence Ventures, and other existing investors. Medium SP001
CP012 Kasada was named a Leader in The Forrester Wave—Bot and Agent Trust Management Software, Q2 2026. Medium SP002
CP013 Kasada received the highest possible scores in nine criteria in the Forrester Wave Q2 2026, including Account and Trust Protection, AI Agent Trust Management, and Transaction Assurance and Protection. Medium SP002
CP014 Kasada's platform protects more than $150 billion in eCommerce revenue for targeted enterprises, per company claims. Medium SP001
CP015 More than 85% of Kasada customers previously used another bot mitigation provider before switching to Kasada, per company disclosure. Medium SP001
CP016 Kasada claims an average customer ROI of over 250%, driven primarily by operational cost savings. Medium SP001
CP017 Kasada raised a total of $64.2 million across six funding rounds as of its December 2025 Series C closing. Medium SP023
CP018 Kasada differentiates by detecting attacks at the earliest point where automation begins, operating without CAPTCHAs or friction for legitimate users. Medium SP001
CP019 Arkose Labs raised $114 million in total funding from investors including PayPal, USVP, and SoftBank Vision Fund, with its last major round a Series C in 2021. Medium SP017
CP020 Arkose Labs claims a 95% reduction in automated attacks and prevention of over $50 million in annual fraud losses for customers. Medium SP016
CP021 Adobe uses Arkose Bot Manager to reduce fake account creation and bot abuse, citing measurable security improvements without compromising customer experience. Medium SP016
CP022 In PeerSpot's June 2026 Bot Management category data, Imperva holds the largest mindshare at 15.7%, followed by Akamai at 9.7%, and HUMAN at 8.1%. Medium SP024
CP023 Arkose Labs holds 5.0% mindshare in the PeerSpot Bot Management category as of June 2026, up from 2.8% the prior year. Medium SP007
CP024 DataDome raised $42.4 million in total funding, with a Series C of $42 million in March 2023 led by InfraVia Growth. High SP008, SP015
CP025 DataDome reported $36 million ARR in 2024, up from $16.9 million in 2023, representing 113% year-over-year ARR growth. Medium SP015
CP026 DataDome protects over 300 enterprises including Rakuten, Reddit, and AngelList from bot attacks. Medium SP008
CP027 Fingerprint reported 65% annual recurring revenue growth in fiscal year 2026, with a 36% growth in its customer base. High SP009, SP025
CP028 Fingerprint serves 2,000 customers in over 56 countries and achieved a net revenue retention rate of 128% in fiscal year 2026. Medium SP009
CP029 Fingerprint's device intelligence platform identifies over 1 billion unique devices per month, a 77% year-over-year increase. Medium SP009
CP030 In 2025, 4.4% of desktop browser identifications showed browser tampering techniques designed to confuse fingerprinting systems, nearly double the 2.6% rate from 2024. Medium SP010
CP031 Cloudflare's Bot Management is an Enterprise plan-only add-on that detects simple and sophisticated bots, headless browsers, and domain-specific anomalies using ML-based bot scoring with JA3/JA4 fingerprinting. Medium SP011
CP032 Cloudflare enterprise contracts range from approximately $5,000 to $80,000+ per month with no public rate card, and Bot Management is bundled, making it near-zero marginal cost for existing enterprise customers. Medium SP012
CP033 DoubleVerify reported full-year 2025 revenue of $748.3 million, a 14% year-over-year increase, with net revenue retention of 109%. High SP019, SP021
CP034 DoubleVerify holds a 67.08% market share in the ad fraud detection category with 4,324 tracked customers, versus Integral Ad Science's 2.59% market share and 167 customers. Medium SP013
CP035 Integral Ad Science reported revenue of $590.67 million for the twelve months ending Q1 2026. Medium SP021
CP036 CHEQ processes six trillion signals daily across one million monitored domains, claiming a 0.009% false positive rate. Medium SP020
CP037 Netacea was named a Strong Performer in the Forrester Wave—Bot and Agent Trust Management Software Q2 2026, with the highest possible scores in web and LLM scraping management and transaction assurance and protection criteria. Medium SP014
CP038 Netacea's internal data shows 18% of LLM scraping traffic is unannounced, meaning it mimics human click patterns to bypass client-side JavaScript and CAPTCHA tests. Medium SP014
CP039 Netacea differentiates on a fully managed service model where detection configuration and ongoing tuning is handled by the Netacea team rather than the customer. Medium SP014
CP040 In PeerSpot's June 2026 Bot Management category, Imperva ranks first with 15.7% mindshare, Akamai ranks second with 9.7%, both above HUMAN Security's 8.1%. Medium SP024, SP007
CP041 Forrester noted that HUMAN's threat research team conducts coordinated attack takedowns that create impact far beyond its own customer base, a capability cited as uniquely differentiating. Medium SP003
CP042 Over 95% of AI-driven traffic in 2025 was concentrated in three industries—retail and eCommerce, streaming and media, and travel and hospitality—which match HUMAN Security's core enterprise verticals. Medium SP006
CP043 OpenAI generated approximately 69% of all observed AI bot traffic in 2025, with Meta accounting for 16% and Anthropic 11%, per HUMAN Security's 2026 benchmark report. Medium SP006
CP044 Post-login account compromise attempts more than quadrupled year-over-year in 2025, with HUMAN Security's platform flagging an average of 402,000 attempts per organization. Medium SP006
CP045 Carding volume has surged 250% since 2022, per HUMAN Security's 2026 State of AI Traffic and Cyberthreat Benchmark Report. Medium SP006
CP046 Forrester renamed the Bot Management category to Bot and Agent Trust Management in 2026, reflecting the shift from detecting bots to governing trust for human, bot, and AI agent traffic. Medium SP014, SP003
CI001 HUMAN Security raised a $100 million growth round in January 2022 led by WestCap and NightDragon, with additional investment from Goldman Sachs Asset Management. High SI001, SI009
CI002 At the time of the July 2022 PerimeterX merger, the combined HUMAN+PerimeterX entity reported more than $100 million in ARR and 500+ customers. High SI002, SI009
CI003 HUMAN Security's January 2024 CEO transition announcement stated that Tamer Hassan led the company to surpass $100 million in ARR during his tenure. Medium SI009, SI025
CI004 GetLatka reported HUMAN Security revenue of $15 million ARR as of December 2023, directly conflicting with the company's stated $100M-plus ARR. Medium SI003
CI005 GrowJo's employee-count model estimates HUMAN Security annual revenue at $140.4 million, which is broadly consistent with the company's >$100M ARR claim and post-merger scale. Low SI022
CI006 HUMAN Security's Human Defense Platform verified over 20 trillion digital interactions per week as of October 2024. Medium SI007, SI008
CI007 In 2025, HUMAN's platform analyzed more than one quadrillion digital interactions over the full year per the company's 2026 State of AI Traffic Benchmark Report. Medium SI018
CI008 As of October 2024, HUMAN Security served more than 500 global brands across advertising, application, and account protection use cases. Medium SI007, SI008, SI014
CI009 Vendr's 2025 procurement benchmark reports the median enterprise annual spend on HUMAN Security products at $104,906 per year. Medium SI004
CI010 Vendr benchmarks show the enterprise pricing range for HUMAN Security from approximately $46,601 at the low end to over $1.34 million per year for large complex deployments. Medium SI004
CI011 HUMAN Security does not publish a standard price card; all enterprise pricing is custom-negotiated based on traffic volume, protected assets, and module mix. Medium SI005, SI004
CI012 HUMAN announced new packaging and pricing would be rolled out in 2024 as part of its channel programme launch, according to CRO Chris Scanlan at RSA 2024. Medium SI005
CI013 HUMAN Security's Human Defense Platform is structured around three commercial pillars: advertising and media protection, application security and bot mitigation, and account protection. Medium SI007, SI017
CI014 HUMAN acquired clean.io in November 2022 to add malvertising and e-commerce fraud protection capabilities to the platform; financial terms were not disclosed. Medium SI023, SI010
CI015 HUMAN merged with PerimeterX in July 2022, adding enterprise application security, account fraud, and carding protection to the Human Defense Platform. High SI002, SI009
CI016 HUMAN launched HUMAN Sightline Cyberfraud Defense featuring AgenticTrust in July 2025, providing visibility and governance across humans, bots, and AI agents. Medium SI013, SI017
CI017 AgenticTrust, launched as part of HUMAN Sightline in July 2025, extends the platform's coverage to classify and govern AI agent traffic separately from human and bot activity. Medium SI013, SI014
CI018 HUMAN launched the HUMAN Advantage Partner Program in August 2024, a tiered channel programme offering incentives based on annualized bookings, training completion, and customer retention. Medium SI014, SI016
CI019 In November 2022, HUMAN partnered with Carahsoft Technology as its Master Government Aggregator, enabling public sector procurement through NCPA, E&I, and OMNIA cooperative contracts. Medium SI019
CI020 Prior to 2024, HUMAN Security operated as a historically direct-minded sales organization with no formal channel programme and enterprise sales cycles of six to seven months for large accounts. Medium SI005
CI021 Chris Scanlan joined HUMAN as Chief Revenue Officer in 2024, previously President and CRO at ExtraHop, to lead the commercial and channel transformation. Medium SI005, SI016
CI022 HUMAN's ecosystem-first GTM strategy is designed to reach fragmented buyer personas including security, commerce, digital, and marketing teams through partner-embedded distribution rather than direct sales alone. Medium SI011, SI014
CI023 HUMAN's enterprise sales cycle for large customers was 6–7 months pre-channel programme, attributable to the need to negotiate legal agreements, MSAs, and pricing directly with enterprise procurement teams. Medium SI005
CI024 SaaS industry benchmark (Benchmarkit 2024/2025) shows sales and marketing expense at 47% of revenue for VC-backed private SaaS companies. Medium SI020
CI025 SaaS industry benchmark (Benchmarkit 2024/2025) shows R&D expense at 34% of revenue for private SaaS companies, versus 23% for public SaaS companies. Medium SI020
CI026 SaaS benchmark ARR per FTE is approximately $200,000 for companies at $50–100M ARR and rises to $300,000 per FTE for companies above $100M ARR. Medium SI020
CI027 HUMAN Security's signal collection and ML inference infrastructure for processing 20 trillion-plus digital interactions per week constitutes a material and scaling cloud compute cost centre. Medium SI007, SI018
CI028 HUMAN's Satori Threat Intelligence and Research Team, responsible for bot research, threat takedowns, and attack intelligence, represents a significant human-in-the-loop cost centre that increases operating expenses relative to pure SaaS peers. Medium SI017, SI014
CI029 White Ops, Inc. (HUMAN Security's predecessor entity, CIK 0001611028) filed a Form D with the SEC in June 2014 for a $11.1 million Series A exempt offering, confirming Delaware incorporation and early institutional fundraising. Medium SI024
CI030 HUMAN Security's headcount was estimated at approximately 469 employees as of 2026 per PitchBook, and 519 employees per Tracxn as of May 2026, up from 197 in late 2023. Medium SI015, SI016
CI031 In connection with the July 2022 PerimeterX merger, HUMAN received a $100 million debt facility from Blackstone Credit; the current repayment or extension status of this facility is not publicly confirmed as of June 2026. Medium SI002, SI023
CI032 In October 2024, HUMAN closed a $50 million-plus growth round led by WestCap, with additional investment from Goldman Sachs Asset Management, ClearSky Security, NightDragon, and Vertex Ventures US. High SI006, SI007, SI008
CI033 HUMAN Security's total equity raised is approximately $300 million as of October 2024 across eight funding rounds, per company statement and corroborating news sources. High SI007, SI006
CI034 Based on approximately 500 employees at an industry-average fully-loaded cost of $180,000–$220,000 per year, HUMAN's inferred annual payroll is $90–$110 million, implying a monthly burn rate of $9–$13 million including cloud infrastructure and G&A. Low SI015, SI020
CI035 HUMAN Security was named a Leader in The Forrester Wave for Bot Management Software Q3 2024, receiving the top strategy score and highest possible scores across nine criteria. Medium SI012, SI017
CI036 In June 2026, HUMAN Security was named a Leader in the Forrester Wave for Bot and Agent Trust Management Software Q2 2026, the only vendor to receive the top score in Threat Research, reflecting its expanded market position in the agentic AI era. Medium SI014, SI017
CI037 HUMAN Security's burn rate, gross margin, net revenue retention, and exact ARR breakdown by product segment are not publicly disclosed, creating material financial diligence blockers that cannot be resolved from public sources. Medium
CI038 HUMAN Security's capital structure includes a $100 million Blackstone Credit debt facility from 2022 whose repayment or extension status is unconfirmed, creating leverage uncertainty that cannot be assessed from public disclosures alone. Medium SI002
CE001 As of 2026, the Human Defense Platform comprises four named product lines: HUMAN Advertising Protection (formerly MediaGuard), HUMAN Application Protection (formerly Bot Defender), HUMAN Account Protection (formerly Account Defender), and HUMAN Client-side Defense (formerly Code Defender). High SE001, SE009
CE002 The Human Defense Platform decision engine analyzes over 2,500 signals per interaction to produce each bot/human/AI-agent verdict. High SE001, SE009, SE014
CE003 The decision engine uses 400 or more adaptive machine learning models to analyze the collected signals and detect automated threats. High SE001, SE009, SE014
CE004 HUMAN's behavioral signal network processes over 20 trillion digital interactions weekly across approximately 3 billion unique devices. High SE001, SE009, SE003
CE005 HUMAN's decision engine enforces protection decisions at the edge in under 2 milliseconds. High SE001, SE009
CE006 Approximately 95% of users are validated automatically by HUMAN's Precheck mechanism without any user-visible friction or challenge. High SE001, SE009
CE007 According to HUMAN's 2026 State of AI Report, automation (AI agent traffic) is growing eight times faster than human web traffic. Medium SE006, SE017, SE025
CE008 HUMAN Advertising Protection (formerly MediaGuard) safeguards digital advertising supply chains with pre-bid and post-bid IVT detection, malvertising defense, and the FraudSensor viewability product. High SE001, SE010
CE009 HUMAN Application Protection (formerly Bot Defender) protects web and mobile applications and APIs from scraping, credential stuffing, transaction abuse, fake signups, and client-side script attacks. High SE001, SE010
CE010 HUMAN Account Protection (formerly Account Defender) provides pre-login, at-login, and post-login security across the full account lifecycle to prevent ATO and fake account fraud. High SE001, SE010
CE011 HUMAN Client-side Defense (formerly Code Defender) monitors and enforces third-party JavaScript behavior in consumer browsers and explicitly supports PCI DSS 4 client-side compliance requirements. High SE001, SE010
CE012 BotGuard for Growth Marketing is a HUMAN module that protects marketing funnels and lead generation pipelines from bot-driven click fraud, fake leads, and affiliate-code abuse. Medium SE010, SE001
CE013 HUMAN Sightline Cyberfraud Defense was launched on July 30, 2025, as a unified trust and defense layer providing actor-level visibility across humans, bots, and AI agents across the full digital customer journey. High SE018, SE009, SE004
CE014 AgenticTrust, a module within HUMAN Sightline, was launched in 2025 to classify AI agent activity, prevent spoofing, and apply granular per-agent governance controls on digital properties. High SE018, SE004
CE015 HUMAN's deployment architecture uses a JavaScript Sensor (client-side signal collection) paired with an Enforcer (server-side or edge-layer enforcement), with the minimum Sensor version for AgenticTrust support being v9.6.6. High SE002, SE009, SE001
CE016 HUMAN offers over 20 Enforcer integration targets, including AWS Lambda@Edge (v4.8.0+), AWS API Gateway (v0.1.1+), Cloudflare (v6.12.0+), Fastly VCL (v12.3.0+), Akamai EdgeWorker (v4.4.0+), Azure Front Door (v1.2.1+), F5 BIG-IP (v3.1.1+), Nginx, Apache, Kong, Go, Java, Node Express, and Salesforce. High SE002, SE001
CE017 PHP, Python 2, Python 3, Ruby, Akamai ESI, and ASP.NET runtimes are explicitly listed as unsupported for HUMAN's AgenticTrust module as of the June 2026 documentation. Medium SE002
CE018 HUMAN Sightline integrates with WAF, CDN, CIAM, and analytics infrastructure including Adobe Experience Platform and Salesforce, enabling deployment across existing customer security stacks. Medium SE018, SE004
CE019 The platform enforces bot verdicts in under 2 milliseconds at the CDN or origin edge, with the Precheck mechanism validating approximately 95% of traffic automatically. High SE009, SE001
CE020 HUMAN uses a Precheck mechanism to auto-validate the majority of sessions and a Human Challenge for ambiguous interactions, minimizing friction for legitimate users while maintaining protection. High SE009, SE001
CE021 HUMAN's decision engine has been enhanced with over 400 ML algorithms for superior threat detection, improved mitigation tracking, and advanced reporting providing analytics on malicious activities. Medium SE014, SE001
CE022 HUMAN introduced Profile Deviation ML Models 2.0, which enhance detection precision for post-login malicious activity by tracking behavioral deviations from established user profiles. Medium SE014
CE023 HUMAN's attack profiling capability segments traffic into distinct behavioral profiles for deeper analysis of in-progress attack campaigns. Medium SE014, SE004
CE024 HUMAN Threat Tracker delivers attack analytics intelligence to security teams, providing visibility into attacker behavior patterns and enabling proactive identification of attack trends. Medium SE014, SE004
CE025 HUMAN's FraudSensor is a post-bid detection system that validates ad impressions after serving, filters IVT before calculating viewability rates, and analyzes supply-path-level signals to identify the specific supply paths driving quality problems. High SE003, SE001
CE026 Page Intelligence, a component of Sightline, provides real-time page-level insights into invalid traffic to help marketing teams understand which campaigns and channels drive genuine engagement. Medium SE004, SE016
CE027 HUMAN's Satori Threat Intelligence and Research Team is led by Lindsay Kaye (Vice President of Threat Intelligence) and Gavin Reid (CISO, formerly VP of Threat Intelligence). Medium SE007, SE005
CE028 In May 2026, HUMAN's Satori team disrupted the Trapdoor operation, a multi-stage ad fraud and malvertising scheme involving 455 malicious Android apps and 183 threat-actor-owned HTML5 domains; Google removed all identified apps from Google Play. Medium SE007
CE029 At its peak, the Trapdoor scheme accounted for 480 million bid requests per day, with associated malicious apps downloaded more than 24 million times before disruption. Medium SE007
CE030 HUMAN was the only vendor in the Forrester Wave Bot and Agent Trust Management Software Q2 2026 evaluation to receive a perfect 5 out of 5 score in the Threat Research criterion. High SE004, SE005
CE031 HUMAN's historical threat disruption operations include 3ve (FBI collaboration), Methbot (led to 10-year prison sentence), PARETO (CTV botnet with Roku and Google), Scylla (Google Play and Apple App Store SDK attack), BADBOX 2.0, SlopAds, and Pushpaganda. High SE013, SE020, SE007, SE004
CE032 On April 21, 2026, HUMAN announced the expansion of Agentic Visibility within Sightline to marketing and commerce teams, with native integration into Adobe Experience Platform as an official Adobe technology partner. High SE016, SE017, SE006
CE033 HUMAN's AgenticTrust extended support to cryptographic verification of Amazon Bedrock AgentCore traffic in 2026, enabling enterprises to authenticate AI agents built on AWS infrastructure via policy-compliant cryptographic signing. High SE008, SE002, SE001
CE034 HUMAN Security received MRC accreditation for its Ad Viewability Measurement product on April 27, 2026, covering display and video impressions across desktop, mobile web, and mobile app environments. High SE003, SE004
CE035 In November 2025, HUMAN open-sourced the HUMAN Verified AI Agent, a reference implementation using HTTP Message Signatures (RFC 9421) and the Google A2A protocol for cryptographic agent-to-service authentication with Ed25519 key pairs. Medium SE019
CE036 Automation (AI agent traffic) is growing 8 times faster than human traffic according to HUMAN's 2026 State of AI Report, making AI-agent governance a critical emerging capability. Medium SE006, SE016
CE037 During Super Bowl LX in February 2026, HUMAN tracked 74 million blocked retail scraping attacks, a 33% rise in invalid bid requests, and a 5% increase in AI agent activity within the broadcast window. Medium SE006, SE003
CE038 HUMAN Client-side Defense explicitly supports PCI DSS 4 client-side script compliance by detecting suspicious activity, enforcing automated policies, and mitigating malicious behavior without interrupting website operations. High SE001, SE010
CE039 HUMAN's MRC Ad Viewability accreditation covers display and video impressions across desktop, mobile web, and mobile app, with IVT filtering via FraudSensor embedded in the viewability measurement product—distinguishing it from conventional viewability-only vendors. High SE003, SE004
CE040 The 2022 acquisition of clean.io added real-time client-side JavaScript behavioral analysis for malvertising detection and cleanCart cart-protection technology to HUMAN's product suite. High SE012, SE013, SE020
CE041 At the time of HUMAN's clean.io acquisition in 2022, clean.io's technology protected more than 125 billion advertising impressions monthly across millions of websites and mobile applications. High SE013, SE020, SE012
CE042 HUMAN was named the number-one ranked vendor on G2's Summer 2026 Grid for Bot Detection and Mitigation Software, based entirely on verified customer reviews. High SE005, SE004
CE043 In the Forrester Wave Q2 2026 Bot and Agent Trust Management Software evaluation, HUMAN received the highest possible scores across nine criteria, including Threat Research, AI Agent Trust Management, Marketing Analytics Assurance, Intent Visibility, Attack and User Analytics, Customizable Reports and Dashboards, Security Operations Integrations, Vision, and Partner Ecosystem. High SE005, SE004
CE044 HUMAN's Bot Management mindshare on PeerSpot declined from 11.6% to 8.1% year-over-year as of June 2026, suggesting increased competitive pressure from emerging bot-management vendors. Medium SE011
CE045 Enterprise customers and analyst reviewers have identified HUMAN's decision engine as operating as a "black box," with limited visibility into model logic, signal weights, or detection thresholds, making independent auditability of false-positive rates difficult. Medium SE010, SE011
CE046 User reviews and analyst comparisons as of 2026 cite HUMAN's complex integration setup for bespoke API infrastructure and limited documentation depth for custom rule management as recurring areas for improvement. Medium SE015, SE010
CU001 HUMAN Security's customer base spans five segments — advertising/adtech platforms, e-commerce and retail, financial services, enterprise security (via channel), and travel/hospitality. Medium SU014, SU020, SU006
CU002 Adtech and programmatic advertising is HUMAN Security's largest historical customer segment, comprising DSPs, SSPs, ad networks, brand advertisers, and agency holding companies. Medium SU002, SU010, SU011, SU001
CU003 E-commerce and retail customers use HUMAN's Bot Defender and Sightline for scraping defense, ATO prevention, and high-heat release protection, with verified deployments at $500M–$1B and $10B+ revenue accounts per Gartner Peer Insights. Medium SU014
CU004 Financial services is an early-adoption segment with no publicly named customers, but HUMAN's May 2026 benchmark shows agentic AI traffic in the vertical doubled month-over-month, indicating growing deployment interest. Low SU020, SU025
CU005 Optiv, which serves 73% of the Fortune 100, and Consortium Networks are named channel partners delivering HUMAN's platform to enterprise security buyers as of August 2024. Medium SU004, SU005, SU006, SU008, SU018
CU006 A travel and hospitality company with $250M–$500M revenue described a production deployment of HUMAN's managed bot defense in a 5-star Gartner Peer Insights review dated March 2026. Medium SU014
CU007 HUMAN Security's company description on Gartner Peer Insights (updated February 2026) states the platform verifies "more than 30 trillion digital interactions per week," an increase from the 20 trillion per week figure cited at the October 2024 fundraise. Medium SU014, SU006
CU008 HUMAN Security claims 500+ global brands and organizations as customers, a figure that has appeared consistently in press releases and fundraise announcements from 2022 through August 2024. Low SU006, SU021
CU009 In calendar year 2025, HUMAN's Defense Platform analyzed over one quadrillion digital interactions, as disclosed in the March 2026 State of AI Traffic benchmark report. Medium SU020
CU010 HUMAN Security verifies more than 3 billion unique devices per month, per the August 2024 partner program launch announcement. Medium SU006, SU005
CU011 AI-driven traffic rates on HUMAN's platform grew 187% from January to December 2025, with the majority concentrated in retail/e-commerce, streaming/media, and travel/hospitality. Medium SU020
CU012 Traffic from AI agents and agentic browsers grew 7,851% year-over-year in 2025 per HUMAN's 2026 benchmark, representing a new category of automated traffic distinct from legacy bots. Medium SU020
CU013 AdRoll integrated HUMAN Security's dual-layer fraud detection (FraudSensor post-bid + MediaGuard pre-bid) in October 2025, becoming the first DSP to combine both solutions with IVT detection in 12 milliseconds. Medium SU001
CU014 Automated traffic across the internet grew 23.51% year-over-year in 2025 while human traffic grew only 3.10%, according to HUMAN's 2026 benchmark, creating strong structural demand for bot management. Medium SU020
CU015 HUMAN Security's Ad Fraud Defense (pre-bid) and Ad Fraud Sensor (post-bid) platforms hold MRC accreditation for GIVT and SIVT detection across Desktop, Mobile Web, Mobile In-App, and CTV environments, as confirmed by the MRC Board of Directors letter dated April 4, 2025. High SU013, SU012
CU016 HUMAN Security's Ad Viewability Measurement product received MRC accreditation for viewability across display and video impressions on desktop, mobile web, and mobile app environments, announced April 27, 2026. High SU012, SU001
CU017 Madhive, described by HUMAN CEO Stu Solomon as a "long-standing partner," launched a Fraud Free Guarantee in June 2025 powered by HUMAN's MRC-accredited pre-bid and post-bid fraud detection, covering 30,000+ daily local campaigns. Medium SU002, SU003
CU018 LinkedIn integrated HUMAN Security in May 2024 for pre-bid IVT filtering and post-bid detection across its desktop ad network and publisher network including CTV, with the integration protecting a 1 billion+ member professional community. High SU010, SU011
CU019 HUMAN detected less than 1% of desktop impressions as invalid traffic on LinkedIn's ad network in the first 30 days after the May 2024 integration, as disclosed in HUMAN and LinkedIn's joint announcement. High SU010, SU011
CU020 Sovrn, a publisher/advertiser platform, is cited by name in HUMAN's April 2026 MRC viewability accreditation announcement as an early adopter with MD Jeff Meglio providing a named endorsement of improved campaign performance. Medium SU012, SU001
CU021 Consortium Networks CEO Nate Ungerott provided a public testimonial at HUMAN's August 2024 channel program launch, describing HUMAN as bringing "exceptional value to our customers" for defending against sophisticated fraud. Medium SU004, SU006, SU018
CU022 Optiv is named by HUMAN as an "integral ally" channel partner with access to the full HUMAN Defense Platform, and serves 73% of the Fortune 100 as a cybersecurity integrator. Medium SU006, SU005
CU023 HUMAN Sightline Cyberfraud Defense holds a 4.7/5 overall rating on Gartner Peer Insights with a 4.8/5 for Service & Support and 4.7/5 for Product Capabilities, based on reviews updated through April 2026. Medium SU014
CU024 G2 recognized HUMAN Security as Best Security Software Product of 2026 ranking Medium SU007, SU022
CU025 A Gartner Peer Insights reviewer from a 1B–10B USD retail company states "We have a long relationship with Human," indicating a multi-year production deployment of HUMAN's bot defense solution. Low SU014
CU026 A Gartner Peer Insights reviewer from a $500M–$1B retail company gave HUMAN Sightline a 3/5 rating in April 2026, describing the product as a "black box" with limited visibility into detection logic and no proactive change notifications. Medium SU014
CU027 Gartner Peer Insights reviewers identify specific dislikes: sluggish dashboard performance, data access limited to the past two weeks, limited manual tuning capability, and opaque detector logic with no proactive notification of changes. Medium SU014
CU028 HUMAN's Forrester Wave Q2 2026 report states "HUMAN's customers compliment the level of detail and attack insight that they receive from the Sightline feature," indicating reference-quality satisfaction among evaluated accounts. Medium SU019
CU029 Industry-wide, 42% of cybersecurity customers switched vendors in the past two years due to poor customer experience, and 35% of cybersecurity churn is attributable to CX issues rather than product performance (ZipDo, Feb 2026). Low SU009
CU030 HUMAN Security does not disclose NRR, GRR, average contract length, or customer churn rate, as it is a private company; these are the highest-priority retention metrics for diligence. Medium SU021
CU031 The HUMAN Advantage Partner Program, launched August 21, 2024, structures partner compensation as a three-tier system rewarding annualized bookings, training completion, and customer retention. Medium SU004, SU005, SU006
CU032 The HUMAN Advantage Partner Program offers deal registration and incumbency protections to channel partners, designed to reduce channel conflict and improve account durability for enterprise customers. Medium SU005, SU006
CU033 HUMAN launched AgenticTrust, a module within Sightline Cyberfraud Defense, in 2025 to distinguish among human, bot, and agentic AI traffic; it received the highest possible Forrester score in the AI Agent Trust Management criterion in Q2 2026. Medium SU019, SU007
CU034 HUMAN announced support for Amazon Web Services' Bedrock AgentCore browser in AgenticTrust, enabling cryptographically signed, policy-compliant verification of AI agents built on AWS infrastructure. Medium SU019
CU035 HUMAN Security's public case studies and named customer deployments are predominantly in adtech and programmatic advertising (LinkedIn, Sovrn, Madhive, AdRoll), creating identifiable sector concentration in the advertising vertical. Medium SU002, SU010, SU011, SU012, SU001
CU036 No top-customer revenue share, customer count by segment, or ARR breakdown is publicly disclosed by HUMAN Security, making it impossible to quantify concentration risk from external evidence alone. Medium SU021
CU037 HUMAN's Riskified partnership (announced August 2026 per RivalSense competitive intelligence) targets ecommerce fraud prevention via AI Agent Approve and AI Agent Intelligence, extending reach beyond core adtech buyers. Low SU017
CU038 Enterprise direct-sales cycles of 6–7 months for large accounts were a documented pre-2024 friction point; the channel program launched specifically to reduce this barrier via partner-led onboarding and managed service. Medium SU004, SU005
CU039 HUMAN Security launched Page Intelligence in October 2025, extending fraud detection to the landing page (the gap between click and user interaction), giving brands and publishers real-time IVT visibility via a lightweight asynchronous tag using 400+ algorithms. Medium SU015, SU016
CU040 A 10B+ USD retail company Gartner reviewer (March 2026) states HUMAN enabled "a very secure online presence" and helped become "one of the very few sneaker retailers without a waiting room," indicating multi-brand platform-wide production deployment. Medium SU014
CU041 HUMAN Security's product innovation in 2025–2026 (AgenticTrust, Page Intelligence, MRC viewability, AWS Bedrock support) represents significant expansion surface into marketing analytics buyers beyond traditional security teams. Medium SU019, SU015, SU012
CR001 The FTC sent formal warning letters to 13 data brokers under PADFAA on February 9, 2026, signaling active regulatory scrutiny of mass-scale behavioral data vendors. High SR006, SR012
CR002 HUMAN Security processes more than one quadrillion digital interactions per year, creating a large-scale behavioral data collection and analytics surface. Medium SR001, SR002
CR003 HUMAN's Ad Viewability Measurement solution earned MRC accreditation in April 2026 for display and video impressions across desktop, mobile web, and mobile app. High SR002, SR027
CR004 As of January 2026, 20 U.S. states are actively enforcing comprehensive consumer privacy laws, creating a multi-jurisdictional compliance patchwork for data vendors. High SR012, SR020
CR005 The DOJ Data Security Program restricts bulk cross-border data transfers involving "countries of concern," requiring CISA-compliant security controls for covered data flows. High SR006, SR020
CR006 Plaintiff attorneys have developed a novel theory using DSP violations as predicates for federal Wiretap Act class action claims against adtech behavioral data flows. Medium SR006
CR007 No active regulatory enforcement or litigation specifically targeting HUMAN Security is publicly known as of June 2026. Medium SR005, SR012
CR008 The Check My Ads Institute argues that MRC self-regulation is structurally insufficient for adtech accountability and calls for mandatory government regulation. Medium SR007
CR009 The MRC finalized Digital Advertising Auction Transparency Standards in January 2026, mandating disclosure of auction mechanics, pricing, and reporting by accredited vendors. Medium SR026, SR007
CR010 Online privacy lawsuit filings surged from approximately 200 in 2023 to approximately 4,000 in 2024 and continued rising through 2025, targeting behavioral tracking technologies. Medium SR020
CR011 Bot detection systems produce false positives for privacy-tool users including VPN subscribers, ad blocker users, and non-mainstream browser operators. Medium SR003, SR004
CR012 HUMAN's Defense Platform processes more than 20 trillion digital interactions weekly and over one quadrillion annually, requiring substantial cloud compute infrastructure. High SR001, SR002
CR013 Automated internet traffic grew 23.51% year-over-year in 2025, while AI-driven traffic grew 187% from January to December per HUMAN's 2026 benchmark report. Medium SR001
CR014 HUMAN customers averaged over 400,000 attempted post-login account takeover attacks in 2025, more than quadruple the 2024 baseline, per HUMAN's own benchmark data. Medium SR001
CR015 An AWS thermal event in US-EAST-1 on May 7–8, 2026 cascaded across more than 150 downstream cloud services, including security vendors reliant on that availability zone. Medium SR008, SR029
CR016 An AWS data center in the UAE (ME-CENTRAL-1) was struck by a kinetic attack on March 1–2, 2026, causing fires, power loss, and service disruption across 38+ AWS services in the UAE and 46+ in Bahrain. Medium SR029
CR017 BADBOX 2.0 evolved from BADBOX 1.0 using new backdoor mechanisms in direct response to HUMAN Security's original exposure, demonstrating rapid threat-actor adaptation. Medium SR009, SR023
CR018 DoubleVerify detected 140% more CTV fraud schemes and variants in Q1 2026 versus Q1 2025, fueled by AI-assisted fraudster tooling that automates scheme creation. Medium SR014
CR019 AI is automating high-velocity attacker operations in 2026, enabling low-skill threat actors to conduct high-impact attacks including deepfakes and automated exploit development. Medium SR017
CR020 The window between vulnerability disclosure and active exploitation collapsed from weeks to days in the second half of 2025 per Google Cloud threat research. Medium SR018
CR021 Ad blockers suppress anti-bot detection scripts, causing detection systems to classify privacy-conscious users as bots due to apparent JavaScript execution absence. Medium SR003, SR004
CR022 Fraud detection model performance degrades when data pipelines are fragmented by GDPR and CCPA data residency and processing restrictions. Medium SR030
CR023 Cloudflare is ranked #3 in Bot Management with 9.2% mindshare versus HUMAN at #5 with 8.1% per Gartner Peer Insights and PeerSpot comparisons as of 2026. Medium SR015, SR016
CR024 Cloudflare One achieves higher long-term ROI than HUMAN Defense Platform per independent user reviews due to its integrated multi-layer security suite. Medium SR016
CR025 HUMAN depends on Google to update Play Protect and execute C2 sinkholing for BADBOX-class botnet disruptions; HUMAN cannot sinkhole infrastructure unilaterally. Medium SR009, SR010
CR026 The ad verification market has consolidated to a near-duopoly of DoubleVerify and Integral Ad Science as listed public companies with scale cost advantages. Medium SR011, SR021
CR027 More than 95% of AI-driven automation traffic is concentrated in retail/ecommerce, streaming/media, and travel/hospitality verticals per HUMAN's 2026 benchmark. Medium SR001
CR028 MRC accreditation is voluntary, and critics argue the MRC lacks sufficient governance independence from the entities it accredits to enforce meaningful standards. Medium SR007, SR026
CR029 The Shadowserver Foundation sinkholed BADBOX 2.0 command-and-control domains, diverting over one million infected devices from criminal servers as part of the 2025 disruption. Medium SR022, SR025
CR030 HUMAN's ML inference at 20T+ weekly interaction scale requires substantial public cloud compute; AWS is inferred as the primary provider given HUMAN's infrastructure profile. Medium SR001, SR029
CR031 Google, Meta, and Amazon provide in-house fraud detection for walled-garden inventory, reducing the addressable market for third-party verification on premium impressions. Medium SR011
CR032 Google filed a lawsuit against 25 alleged BADBOX 2.0 operators in New York federal court, supported by evidence contributed by HUMAN Security and Trend Micro. Medium SR023, SR025
CR033 HUMAN Security's most recently disclosed valuation is $1.5 billion from January 2022, predating both the PerimeterX merger and the October 2024 growth round. Medium SR019
CR034 HUMAN remains a private company with no publicly disclosed ARR, gross margin, burn rate, or net revenue retention as of June 2026. Medium SR019
CR035 HUMAN's Bot Management market mindshare of 8.1% places it fifth in the competitive stack behind Cloudflare, Akamai, Imperva, and Radware per available review data. Medium SR015, SR016
CR036 The AI ad fraud and bot detection market includes six or more competing tools: HUMAN Security, CHEQ, DoubleVerify, IAS, Cloudflare Bot Management, and DataDome. Medium SR021
CR037 Bundled security platform solutions from Google, Meta, and Amazon eliminate marginal cost for enterprise customers already committed to those platforms, reducing HUMAN's pricing power. Medium SR011, SR031
CR038 Global digital advertising fraud is estimated at $80–$100 billion annually; HUMAN operates in a permanent escalating arms race with fraudsters. Medium SR011, SR028
CR039 HUMAN announced a $50M+ growth round in October 2024, described by CEO Stu Solomon as deliberately constrained to enable targeted investment without over-capitalization. Medium SR019
CR040 Fraud signature drift causes ML rule engines to expire before teams can update them, requiring continuous retraining cycles that increase COGS for detection platforms. Medium SR030, SR017
CR041 Agentic AI traffic grew 7,851% year-over-year in 2025, representing a new threat surface that existing binary bot/human classification systems do not fully address. Medium SR001
CR042 HUMAN's board is dominated by investor representatives from Goldman Sachs, NightDragon, WestCap, and ClearSky, creating governance concentration around investor return timelines. Medium SR019
CV001 White Ops was acquired by Goldman Sachs Merchant Banking Division, ClearSky Security, and NightDragon in December 2020 for an undisclosed purchase price. High SV015, SV014
CV002 HUMAN Security raised a $100 million growth round in January 2022 led by WestCap and NightDragon with participation from Goldman Sachs Asset Management. High SV014, SV017
CV003 In connection with the July 2022 PerimeterX merger, HUMAN Security's combined entity was valued at approximately $1.5 billion according to reporting from multiple independent sources. Medium SV015, SV022
CV004 In October 2024, HUMAN Security closed a $50 million-plus growth round led by WestCap, with additional investment from Goldman Sachs Asset Management, ClearSky Security, NightDragon, and Vertex Ventures US. High SV016, SV017, SV030
CV005 The October 2024 $50M+ growth round did not disclose a new company valuation; no post-money valuation figure was reported by any independent news source covering the round. Medium SV016, SV017
CV006 HUMAN Security's total equity raised is approximately $300 million as of October 2024 across approximately eight funding rounds, per company statement and corroborating sources. High SV017, SV022
CV007 HUMAN Security received a $100 million debt facility from Blackstone Credit in connection with the July 2022 PerimeterX merger; the repayment status, maturity date, and current outstanding balance of this facility have not been publicly confirmed as of June 2026. Medium SV015
CV008 The proceeds of the October 2024 $50M+ round were explicitly allocated to accelerating AI platform capabilities and strengthening the channel partner programme. Medium SV016, SV017
CV009 HUMAN Security's January 2024 CEO transition announcement stated that Tamer Hassan led the company to surpass $100 million in ARR during his tenure, representing the only company-confirmed ARR milestone publicly available as of June 2026. High SV018, SV017
CV010 GetLatka reported HUMAN Security ARR at $15 million as of December 2023, directly contradicting the company-claimed $100M+ ARR; this figure cannot be reconciled with post-merger headcount and platform scale and may reflect pre-merger standalone White Ops revenue or a data error. Low SV019
CV011 GrowJo's employee-count-model estimates HUMAN Security annual revenue at $140.4 million, consistent with the company's post-merger >$100M ARR claim and 469+ employee headcount. Low SV025
CV012 DoubleVerify (NYSE: DV) reported last-twelve-months revenue of $781 million and EBITDA of $261 million as of June 2026, with a gross margin of 82% in its most recently completed fiscal year per its FY2025 10-K filed February 26, 2026. High SV001, SV013
CV013 DoubleVerify's current enterprise value is approximately $2 billion as of June 2026, implying an EV/LTM Revenue multiple of approximately 1.9x, the ad-verification sector floor comp for HUMAN's valuation. High SV001, SV013
CV014 DoubleVerify's gross margin was 82% and EBITDA margin 33% in its most recently completed fiscal year, confirming pure-SaaS-tier margins despite trading at a compressed 1.9x revenue multiple due to advertising-sector structural headwinds. High SV001, SV013
CV015 Integral Ad Science (NASDAQ: IAS) reported approximately $530 million to $591 million in LTM revenue as of recent quarters, competing with HUMAN in programmatic fraud detection but not in application security or bot management. Medium SV002, SV001
CV016 The broader public cybersecurity market trades at a median EV/NTM Revenue multiple of approximately 7.8x as of late 2025 and Q1 2026, representing the median comp anchor for HUMAN's exit analysis per Windsor Drake's Cybersecurity Valuation Report. Medium SV005, SV008
CV017 The private cybersecurity market's median EV/ARR multiple stands at approximately 15.2x in 2025–2026, significantly above the public market median of 7.8x, reflecting the growth premium investors pay for earlier-stage companies per Windsor Drake. Medium SV005, SV008
CV018 Cybersecurity M&A exit multiples mediated at 16.3x revenue in 2025, with cloud-security transactions averaging 22.7x and strategic outliers reaching 35.5x per Windsor Drake and SaaS Mag reporting. Medium SV005, SV008
CV019 Finro's Q2 2026 cybersecurity multiples dataset (265 companies, 9 niches) places the Application Security niche — HUMAN's closest comparable niche — at an average EV/Revenue multiple of 15.4x and median of 13.0x, across 52 companies. Medium SV004
CV020 Threat Intelligence, an adjacent niche to HUMAN's Satori team, shows an average EV/Revenue of 14.9x and median 10.1x across 50 companies in the Finro Q2 2026 dataset; public threat intelligence comps average only 1.2x, highlighting the public-to-private valuation gap. Medium SV004
CV021 Cybersecurity M&A activity totaled $47 billion in Q1 2026 alone, following a record $96 billion across 400 transactions in full-year 2025, a 270% increase over 2024; strategic buyers including Palo Alto, CrowdStrike, and Check Point accounted for approximately $1.1 billion in Q1 aggregate value per Kroll and CloudStack Networks. Medium SV009, SV003
CV022 Disclosed cybersecurity M&A had already crossed $65 billion in aggregate deal value before mid-2026, anchored by Google's $32 billion Wiz acquisition (closed March 2026) and Palo Alto's $25 billion CyberArk acquisition (closed February 2026). Medium SV008, SV009
CV023 The median public SaaS EV/NTM Revenue multiple stands at approximately 8.5x as of mid-2026, up approximately 90% from the Q1 2023 trough of 4.5x, but still 47% below the 2021 peak of approximately 16x per Value Add VC. Medium SV011
CV024 Private SaaS companies at the $10–$50M ARR scale transacted at 5.5–7.2x ARR at the lower middle market in Q1 2026 per iMerge Advisors, with top-quartile (NRR >110%, Rule of 40 >40%) reaching 8.0x+. Medium SV006
CV025 Google acquired Wiz for $32 billion at approximately 32x ARR (approximately $1 billion ARR); Palo Alto Networks acquired CyberArk for $25 billion at approximately 18.6x ARR ($1.34B ARR); these represent ceiling-setting strategic M&A precedents in the cybersecurity sector. Medium SV005, SV008
CV026 Arkose Labs, HUMAN's closest pure-play bot management competitor, had ARR of $46.9 million and a valuation of $140.7 million (approximately 3x ARR) as of 2024 per GetLatka; at this scale and multiple HUMAN's stated $100M+ ARR would imply a notably higher per-ARR-dollar premium than Arkose Labs commands. Low SV027
CV027 Netacea, a bot management competitor, has raised only $22.47 million total across all rounds as of December 2024, with the most recent round being a $5.11 million Series A-III in December 2024; it represents a sub-scale comparator not useful for HUMAN's valuation benchmarking. Low SV026
CV028 DataDome closed a $42 million Series C in March 2023; current valuation is not publicly disclosed per PitchBook 2026 profile; DataDome is detected on over 1,450 enterprise websites. Medium SV028
CV029 The cybersecurity sector's premium over the broader SaaS market is at its widest level in at least five years as of 2026: public cybersecurity trades at 7.8x versus 5.5x for public B2B SaaS broadly, and private cybersecurity startups average 15.2x per SaaS Mag analysis. Medium SV008
CV030 Strategic buyers drove approximately 92% of cybersecurity M&A by value in 2026 as platform consolidation overtook private equity as the primary transaction driver, narrowing to platform-fit targets rather than broad portfolio expansion. Medium SV008, SV009
CV031 Sustaining the $1.5 billion 2022 valuation at the current application-security niche median of 13.0x requires HUMAN's ARR to be at or above approximately $115 million; at 15.2x private cybersecurity median it requires $99 million ARR, broadly consistent with the $100M+ claim. Medium SV004, SV005
CV032 At the private cybersecurity median of 15.2x applied to the company-claimed $100M+ ARR, HUMAN's implied enterprise value is approximately $1.52 billion, roughly in-line with the 2022 $1.5B mark and representing the base-case central estimate. Medium SV005, SV018
CV033 At the application-security niche median of 13.0x (Finro Q2 2026) applied to $100M ARR, HUMAN's implied enterprise value is approximately $1.3 billion, approximately 13% below the 2022 mark and representing the base-case low end. Medium SV004, SV018
CV034 In the bear scenario, applying an 8–10x blended cybersecurity/ad-verification multiple to $80–100M ARR implies an enterprise value of $640M–$1.0B, below the $400M total capital invested and potentially triggering liquidation preferences. Low SV004, SV006, SV019
CV035 In the bull scenario, applying a top-quartile cybersecurity multiple of 18–20x to ARR of $130–140M (consistent with GrowJo's $140.4M estimate) implies an enterprise value range of $2.34–2.8 billion, approximately 1.6–1.9x the 2022 mark. Low SV005, SV025, SV008
CV036 The approximately $400 million total capital invested ($300M equity plus $100M Blackstone debt) means a $1.5B base-case EV represents a 3.75x gross MOIC before dilution and liquidation preferences; achieving a 3x net return on the 2020 Goldman Sachs acquisition entry price likely requires a $1.5B+ exit EV. Medium SV006, SV015, SV017
CV037 No secondary market transactions or post-2022 valuation marks for HUMAN Security are publicly available on any alternative data platform (Premier Alternatives, secondary-market databases) as of June 2026. Medium SV010
CV038 Premier Alternatives lists HUMAN Security's current 2026 valuation as "N/A" with no funding history imported, confirming the absence of publicly available secondary-market pricing data. Medium SV010
CV039 HUMAN Security is not named in any confirmed 2026 cybersecurity IPO pipeline tracked by ipos.fyi, PitchBook's cybersecurity IPO list, or any confirmed strategic M&A announcement as of the June 2026 research date. Medium SV012, SV009
CV040 Kroll's Spring 2026 Cybersecurity M&A Industry Insights report notes that median EV/NTM Revenue multiples in its cybersecurity index fell 26% quarter-over-quarter in Q1 2026, driven by AI-related concerns weighing on cybersecurity equities. Medium SV003, SV008
CV041 HUMAN's platform breadth across bot management, ad verification, application security, account protection, and agentic AI trust differentiates it from single-point competitors such as Arkose Labs, DataDome, and Netacea, which address only one or two of these layers. Medium SV023, SV029, SV026
CV042 HUMAN's stated detection scale of 20 trillion digital interactions per week across 3 billion unique devices represents material competitive differentiation; no competitor has publicly claimed equivalent weekly interaction volume as of June 2026. Medium SV023, SV029
CV043 HUMAN's October 2024 growth round was participated in exclusively by five existing investors (WestCap, Goldman Sachs, ClearSky, NightDragon, Vertex); no new institutional investor joined the cap table, which may reflect investor-access rationing or an inability to attract step-up capital from arms-length external LPs. Medium SV016, SV017
CV044 HUMAN's July 2025 launch of Sightline Cyberfraud Defense and AgenticTrust positions the company in the AI Security niche, where Momentum Cyber recorded $2 billion in financing YTD 2026 and M&A deals are on pace for 400%+ growth in 2026, commanding the highest multiple premium in cybersecurity. Medium SV021, SV023
CV045 HUMAN Security has not publicly disclosed NRR, gross margin, burn rate, ARR growth rate, or any other operating metric from audited financial statements as of June 2026; these absences constitute the primary diligence blockers preventing a conviction recommendation. Medium SV010, SV019
CV046 The broader AdTech public SaaS sector median NTM EV/Revenue multiple is only 0.9x as of June 2026 per Multiples.vc, the lowest across all major SaaS subsectors; this represents the structural floor if HUMAN's ad-verification revenue is valued at AdTech sector rates rather than cybersecurity rates. Medium SV002
CV047 Windsor Drake notes that cybersecurity companies that raised at inflated 2021–2022 peak valuations are frequently executing structured rounds with guaranteed returns or participation rights to maintain nominal face-value marks while providing investor downside protection. Medium SV005
CV048 Momentum Cyber's May 2026 market review recorded 31 cybersecurity M&A transactions and 46 financing transactions during the month, with $823 million in total disclosed M&A deal value and $365 million in financing capital deployed, including 4 AI Security M&A deals. Medium SV021, SV009
CV049 Gartner forecasts global information security spending of $244.2 billion in 2026, up 13.3% in current dollars year-over-year, with cloud security growing 28.8% as the fastest subsegment, supporting the market-necessity argument in the investment thesis. Medium SV008
CV050 The 2026 cybersecurity IPO window has reopened following Netskope's September 2025 IPO, but the market remains selective; investors require clean financials, AI innovation, and Rule of 40 performance before awarding premium multiples to cybersecurity IPO candidates. Medium SV005, SV012
CV051 HUMAN Security's estimated headcount of approximately 469–519 employees as of mid-2026, applied to the company-claimed >$100M ARR, implies an ARR-per-FTE of $200–$300K, broadly consistent with SaaS cybersecurity industry benchmarks, indicating moderate revenue efficiency. Low SV024, SV018
CV052 HUMAN was recognized as a Leader in the Forrester Wave: Bot and Agent Trust Management Q2 2026 evaluation, alongside Kasada, providing third-party validation of the platform's competitive positioning in the bot and agent governance market. Medium SV029
Sources
IDPublisherTitleQuote
SO001 HUMAN Security About | HUMAN Security "Our founders—Tamer Hassan, Michael Tiffany, Dan Kaminsky, and Ash Kalb—set the foundation for a 'bot or not' company... protecting the internet today by safeguarding the entire customer journey and upholding the integrity of 20 trillion digital interactions a week."
SO002 HUMAN Security Board of Directors | HUMAN Security Board Observers: Ryan Benevides, Dan Burns, Itzhak Fisher, Steve Fredrick, Rhys Gordon, Hannah Huffman, Lance Matthews, Alexander Weiss.
SO003 PR Newswire HUMAN Security Announces Strategic Leadership Transition: Tamer Hassan to Become Executive Chairman, Stu Solomon Appointed to CEO "Tamer Hassan, co-founder and CEO who has led the company's transformation into a renowned platform for disrupting bot attacks, online fraud, and abuse, is transitioning to the role of board member and Executive Chairman of the company."
SO004 BusinessWire HUMAN and PerimeterX Unite in Market-Changing Merger to Safeguard Customers From Sophisticated Bot Attacks, Fraud and Account Abuse "The combined companies will comprise more than 450 employees under the HUMAN company name, 500+ customers and have more than $100 million in ARR... HUMAN has received a $100 million debt facility from Blackstone Credit."
SO005 BusinessWire White Ops Announces Acquisition by Goldman Sachs Merchant Banking, ClearSky Security, and NightDragon "Goldman Sachs Merchant Banking Division, in partnership with ClearSky Security and NightDragon (together, the 'Sponsors')... acquiring the business from previous investors Paladin Capital Group, Grotech Ventures, and other shareholders."
SO006 BankInfoSecurity Human Security Raises $50M+ to Take On Click Fraud Defense "Human Security said the growth capital will help the New York-based company enhance its data science and engineering capabilities... Human employs 400 people today."
SO007 Pulse2 HUMAN: Cybersecurity Company Raises $50+ Million (Growth Capital) "HUMAN has invested heavily in developing a unified Human Defense Platform that verifies over 20 trillion digital interactions weekly, enabling 500+ global brands with unparalleled telemetry."
SO008 SiliconAngle Human Security raises $50M+ to expand digital protection platform
SO009 SecurityWeek Human Security Banks Another $50M in Growth Funding "The latest raise follows a hefty $100 million funding round in January 2022 that included a push by Human Security into new product categories."
SO010 AdExchanger HUMAN Raises $50 Million "Update 10/10/24: After publication, HUMAN said that the CEO misspoke about the company's product development plans, and that HUMAN does not plan to build a proprietary ID of any kind."
SO011 Security Journal Americas HUMAN Security announces new Executive Chairman and CEO "HUMAN Security, an organization focused on digital fraud prevention, has announced that Tamer Hassan, Co-Founder and CEO, is transitioning to the role of board member and Executive Chairman."
SO012 Fintech Global Goldman Sachs-owned Human Security rakes in $100m "Anti-bot and fraud detection company Human Security has concluded a $100m funding round led by WestCap. The funding round was also supported by NightDragon."
SO013 GlobeNewswire via ITNewsOnline HUMAN Recognized as a Leader by a Top Research Firm; Empowering Organizations to Transform Threat Intelligence into Action in the Agentic Internet "HUMAN received the highest possible scores across nine criteria, including Threat Research (the only vendor to score 5/5), AI Agent Trust Management, Marketing Analytics Assurance, Intent Visibility, Attack and User Analytics, Customizable Reports and Dashboards, Security Operations Integrations, Vision, and Partner Ecosystem."
SO014 The Hacker News Massive Ad Fraud Scheme Targeted Over 11 Million Devices with 1,700 Spoofed Apps "VASTFLUX was a malvertising attack that injected malicious JavaScript code into digital ad creatives... generating over 12 billion bid requests per day at its peak."
SO015 Craft.co HUMAN Security Company Profile Total Funding $159 M
SO016 TechFundingNews Cybersecurity startup HUMAN Security raises $50M to protect against bots, fraud and threat
SO017 Tracxn HUMAN — 2026 Funding Rounds & List of Investors HUMAN has raised a total of $299M over 8 funding rounds.
SO018 AlleyWatch White Ops Acquired by Goldman Sachs Merchant Banking Division, ClearSky, and NightDragon
SO019 Globes (English) Bot protection co PerimeterX merges with HUMAN Security
SO020 Security Systems News HUMAN Security, PerimeterX announce merger to take on bots, identity fraud
SO021 citybiz HUMAN Security Appoints Stu Solomon CEO
SO022 citybiz HUMAN Raises $50+ Million in Growth Funding
SO023 TechIntelPro HUMAN Named Leader in Forrester Wave for Bot and Agent Trust Management
SO024 PR Newswire Asia HUMAN Orchestrates Unprecedented Private Takedown, VASTFLUX
SO025 Techerati VastFlux ad-fraud scheme affecting millions taken down by HUMAN
SM001 HUMAN Security, Inc. HUMAN Security's 2026 State of AI Traffic & Cyberthreat Benchmark Report Signals a New Internet Era: Automation Growth Now Outpaces Humans "In 2025, HUMAN's Defense Platform analyzed more than one quadrillion digital interactions… automated traffic is growing eight times faster than human traffic."
SM002 HUMAN Security, Inc. HUMAN recognized as a Leader in The Forrester Wave™ for Bot and Agent Trust Management Software
SM003 Business Insider / GlobeNewswire HUMAN Recognized as a Leader by a Top Research Firm; Empowering Organizations to Transform Threat Intelligence into Action in the Agentic Internet "HUMAN Security, Inc., the trust layer for media and agentic commerce platforms, verifying engagement, reducing fraud, and enabling authentic interactions across humans, bots, and AI agents."
SM004 The Business Research Company Bot Mitigation Market Report 2026
SM005 Fortune Business Insights Bot Security Market Size, Share & Growth Rate [2026-2034] "The global bot security market size was valued at USD 1.05 billion in 2025 and is projected to grow from USD 1.27 billion in 2026 to USD 5.67 billion by 2034, exhibiting a CAGR of 20.55%."
SM006 Fraudlogix Ad Fraud Statistics 2026: 20.64% IVT Rate "Of the 105.7 billion impressions in our dataset, 21.81 billion (20.64%) showed risk signals indicating invalid traffic. Applied to U.S. programmatic ad spend, this IVT rate suggests approximately $37 billion in advertiser dollars may be associated with invalid traffic annually."
SM007 Pixalate Q1 2026 Ad Fraud Benchmarks Report for North America "The IVT rate on Connected TV (CTV) apps was 24% in the US… desktop and mobile web: 24%, mobile app: 32%."
SM008 TAG (Trustworthy Accountability Group) TAG Recognizes Leading Companies Across Ad Industry Worldwide for Achieving 2026 Certifications
SM009 PR Newswire TAG Recognizes Leading Companies Across Ad Industry Worldwide for Achieving 2026 Certifications
SM010 IT Business Net (GlobeNewswire) HUMAN Security's 2026 State of AI Traffic & Cyberthreat Benchmark Report Signals a New Internet Era
SM011 Grand View Research Fraud Detection and Prevention Market (2026-2033)
SM012 The Business Research Company eCommerce Fraud Detection and Prevention Market Report 2026
SM013 Media Rating Council (MRC) MRC Accreditation Letter — HUMAN Ad Fraud Defense Pre-Bid and Ad Fraud Sensor Post-Serve Platforms "The MRC Board of Directors has voted in favor of continuing accreditation for HUMAN's Ad Fraud Defense pre-bid platform ('the Service', formerly known as the MediaGuard platform) and Ad Fraud Sensor post-serve platform."
SM014 wmtips.com Akamai Bot Manager vs. Cloudflare Bot Management: 2026 Market Share & Usage Comparison "Cloudflare leads in market share among bot mitigation technologies, holding roughly 79% compared to Akamai's 6%—this advantage holds in all major markets."
SM015 Improvado Ad Fraud in 2026: Detection, Prevention, and Protection Strategies "Digital advertising fraud will exceed $100 billion globally in 2026, up from $84 billion in 2023. Invalid traffic (IVT) rates reached 20.64 percent globally in 2025."
SM016 ExchangeWire EXTE Joins Forces with HUMAN Security to Protect Ad Inventory Quality & Integrity
SM017 PeerSpot Top Rated Bot Management Vendors 2026
SM018 ppc.land TAG hands out 307 seals to 196 companies in 2026 recertification
SM019 Global Growth Insights Account Takeover Protection Market Analysis Report 2035 "The Global Account Takeover Protection Market size is estimated at USD 6.28 billion in 2025 and is expected to reach USD 7.46 billion in 2026… registering a CAGR of 18.89%."
SM020 SiliconAngle Human Security raises $50M to expand digital protection platform
SM021 Vendr HUMAN Security on Vendr Marketplace
SM022 Yahoo Finance HUMAN raises $50 million in growth funding
SM023 Tracxn HUMAN Security Company Profile
SM024 ChannelVision Magazine HUMAN Security Beefs Up Exec Leadership, Go-to-Market Strategy
SM025 HUMAN Security, Inc. Platform Expansion: Fueling the Future of HUMAN
SM026 Business Wire HUMAN Raises $100 Million In Growth Funding Round Led By WestCap and NightDragon
SM027 Economic Times (CIOSEA) Cybersecurity firm HUMAN Security raises $50 mn in growth funding
SP001 Kasada Kasada Secures $20 Million Round to Accelerate Global Expansion and Broaden Platform Offerings our average return on investment is over 250% driven largely by cost savings
SP002 Kasada Kasada Named a Leader in The Forrester Wave™: Bot and Agent Trust Management Software, Q2 2026
SP003 Manila Times (GlobeNewswire) HUMAN Recognized as a Leader by a Top Research Firm; Empowering Organizations to Transform Threat Intelligence into Action in the Agentic Internet HUMAN stands out for its attack profiles, which offer rich attack analytics context and detail, and for a threat research team whose takedowns create impact far beyond its customer base.
SP004 Secure IT World (GlobeNewswire) HUMAN Security Tops G2's 2026 Best Security List
SP005 Markets Insider (GlobeNewswire) HUMAN Launches AI-Powered Ad Verification for Advertisers and Agencies Seeking a Modern Alternative While legacy providers have left brands and agencies stuck with outdated, opaque 'black box' signals, HUMAN provides a direct path to authenticity.
SP006 HUMAN Security The 2026 State of AI Traffic & Cyberthreat Benchmark Report automated traffic—all non-human internet traffic—is growing eight times faster than human traffic, AI-driven traffic is the fastest-growing category of internet traffic
SP007 PeerSpot Compare Arkose vs Human Defense Platform (June 2026) The mindshare of Human Defense Platform is 8.1%, down from 11.6% compared to the previous year.
SP008 DataDome DataDome Closes $42 Million in Series C Funding to Advance the Fight Against Bot-Driven Cyberattacks and Fraud
SP009 Business Wire Fingerprint Reports 65% ARR Growth, Surpasses 1 Billion Device Identifications Per Month as Enterprises Adopt Device Intelligence to Combat AI-Driven Fraud The company now serves 2,000 customers in over 56 countries, achieving 36% customer growth and an industry-leading net revenue retention rate of 128%
SP010 Fingerprint We Analyzed 23 Billion Device Identification Events. Here's What We Found.
SP011 Cloudflare Plans — Bot Management for Enterprise · Cloudflare bot solutions docs
SP012 Blazing CDN Cloudflare Enterprise Plan 2026: Pricing, Features Is It Worth It Cloudflare publishes pricing for Free, Pro ($25/month), and Business ($250/month per zone). Enterprise has never appeared on a public rate card.
SP013 6sense DoubleVerify vs Integral Ad Science: Ad Fraud Detection Comparison
SP014 PR Newswire Netacea Positioned among Top Vendors in Bot and Agent Trust Management 18% of LLM scraping traffic is unannounced, meaning it mimics human click patterns to slip through client-side protocols of JavaScript and CAPTCHA tests
SP015 GetLatka DataDome Revenue 2024: $36M ARR, $42.4M Raised
SP016 Arkose Labs Customers | Arkose Labs 95% Reduction in automated attacks; $50M+ Annual fraud loss prevented
SP017 Tracxn Arkose Labs — 2026 Company Profile
SP018 HUMAN Security The Human Defense Platform | HUMAN Security
SP019 DoubleVerify Investor Relations DoubleVerify Reports Fourth Quarter and Full Year 2025 Financial Results We grew revenue 14% year-over-year to $748 million, exceeding our initial 10% growth outlook for the year
SP020 CHEQ The Global Leader in Go-to-Market Security | CHEQ
SP021 CSIMarket DoubleVerify Holdings Inc Market share relative to its competitors, as of Q1 2026
SP022 Akamai Bot Manager | Bot Detection, Protection, and Management | Akamai
SP023 Tracxn Kasada — 2026 Company Profile
SP024 PeerSpot Compare Akamai Bot Manager vs Imperva Application Security Platform (Updated Mar 2026) Imperva is ranked #1 with an average rating of 8.5; Akamai holds a 9.7% mindshare in BM, compared to Imperva's 15.7% mindshare
SP025 Fingerprint Fingerprint | Identify Every Web Visitor & Mobile Device
SI001 Business Wire HUMAN Raises $100 Million In Growth Funding Round Led By WestCap and NightDragon In 2021, the company experienced accelerated adoption of its specialized bot mitigation platform on a global basis and saw its revenue growth rate double year over year.
SI002 Business Wire HUMAN and PerimeterX Unite in Market-Changing Merger to Safeguard Customers From Sophisticated Bot Attacks, Fraud and Account Abuse The combined companies will comprise more than 450 employees under the HUMAN company name, 500+ customers and have more than $100 million in ARR.
SI003 GetLatka HUMAN Revenue 2023: $15M ARR, $142.1M Raised In 2023, HUMAN's revenue reached $15M. Since its launch in 2012, HUMAN has shown consistent revenue growth.
SI004 Vendr Human Software Pricing & Plans 2025: See Your Cost Median buyer pays $104,906 per year
SI005 ChannelVision Magazine HUMAN Security Beefs Up Exec Leadership, Go-To-Market Strategy Because HUMAN has historically been a direct-minded organization, Scanlan said, there will be no existing channel conflict.
SI006 SiliconAngle Human Security raises $50M+ to expand digital protection platform Including the new funding, the company has raised around $300 million to date.
SI007 Yahoo Finance / Globe Newswire HUMAN Raises $50+ Million in Growth Funding to Protect the Digital Customer Journey HUMAN has invested heavily in developing a unified Human Defense Platform that verifies over 20 trillion digital interactions weekly, empowering 500+ global brands.
SI008 Economic Times CIO SEA Cybersecurity firm Human Security raises $50+ Mn in growth funding HUMAN has invested heavily in developing a unified Human Defense Platform that verifies over 20 trillion digital interactions weekly, empowering 500+ global brands.
SI009 PR Newswire HUMAN Security Announces Strategic Leadership Transition: Tamer Hassan to Become Executive Chairman, Stu Solomon Appointed to CEO Hassan led HUMAN to remarkable heights, including surpassing $100M in ARR, merging with PerimeterX, acquiring anti-malvertising leader clean.io.
SI010 Mobile Marketing Reads Ad fraud detection and prevention firm HUMAN raises over $50 million At the end of 2022, HUMAN acquired clean.io, a protection provider against e-commerce fraud and malicious advertising.
SI011 Frontlines.io HUMAN Security: The Category Expansion Playbook for When AI Disrupts Your Core Business We've heard directly from them, hey, you need to get this data to my CMO, they need to use it today because we're all having this conversation.
SI012 Yahoo Finance / Globe Newswire Multimedia Update – HUMAN Continues to Be a Leader in Bot Management Software Industry HUMAN Named a Leader in The Forrester Wave: Bot Management Software, Q3 2024.
SI013 HUMAN Security HUMAN Introduces the First Adaptive Trust Layer for the Agentic AI Era This reimagined approach enables trusted interactions and transactions across the full spectrum of online actors: humans, bots and AI agents.
SI014 IT News Online / Globe Newswire HUMAN Recognized as a Leader by a Top Research Firm; Empowering Organizations to Transform Threat Intelligence into Action in the Agentic Internet HUMAN received the highest possible scores across nine criteria, including Threat Research, AI Agent Trust Management.
SI015 Tracxn HUMAN – 2026 Company Profile and Team HUMAN has raised a total funding of $299M over 8 rounds. Its latest funding round was a Series D round on Sep 26, 2024.
SI016 RivalSense HUMAN | Competitive Intelligence Profile
SI017 HUMAN Security HUMAN recognized as a Leader in The Forrester Wave for Bot and Agent Trust Management Software HUMAN's notable vision emphasizes trust governance, is rooted in data, and maps future market progression.
SI018 HUMAN Security HUMAN Security's 2026 State of AI Traffic and Cyberthreat Benchmark Report In 2025, HUMAN's Defense Platform analyzed more than one quadrillion digital interactions.
SI019 Carahsoft Technology Corp. HUMAN Security and Carahsoft Partner to Provide Cybersecurity Solutions to the Public Sector Carahsoft will serve as HUMAN's Master Government Aggregator, making the company's industry-leading bot, fraud, and account abuse protection services available to the Public Sector.
SI020 Benchmarkit 2025 SaaS Performance Metrics Benchmarks Sales and Marketing as % of Revenue is 47% for VC-backed vs 33% for PE-backed companies. R&D is at 34% of revenue for private SaaS companies.
SI021 Momentum Cyber Goldman Sachs ClearSky Invest in White Ops Goldman Sachs and ClearSky are ideal partners to support our growth across multiple markets.
SI022 GrowJo White Ops: Revenue, Competitors, Alternatives White Ops's estimated annual revenue is currently $140.4M per year.
SI023 AIThority HUMAN Acquires Anti-Malvertising Leader, clean.io, to Enhance Protection Across the Media Ecosystem Terms of the acquisition were not disclosed.
SI024 U.S. Securities and Exchange Commission White Ops, Inc. — Form D Notice of Exempt Offering of Securities (CIK 0001611028) White Ops, Inc. — Delaware incorporation; executive officers: Michael Tiffany, Tamer Hassan, Daniel Kaminsky, Ashur Kalb, Philip Eliot, Steven Fredrick.
SI025 CityBiz HUMAN Security Appoints Stu Solomon CEO Hassan led HUMAN to remarkable heights, including surpassing $100M in ARR, merging with PerimeterX, acquiring anti-malvertising leader clean.io.
SE001 Amazon Web Services Human Defense Platform by HUMAN Security — AWS Marketplace "HUMAN is the only solution that combines fraud telemetry throughout every moment of the digital journey of your customers, from online advertising to site scraping, account creation, account takeover, and account fraud to detect, disrupt, and eliminate fraud."
SE002 HUMAN Security (Documentation) Getting started with AgenticTrust | HUMAN Documentation "Sensor: 9.6.6 ... AWS API Gateway: From v0.1.1 ... AWS Lambda@Edge: From v4.8.0 ... Cloudflare: From v6.12.0 ... PHP: Unsupported ... Python3: Unsupported"
SE003 PPC Land HUMAN Security's viewability measurement earns MRC accreditation "What makes HUMAN's accreditation different from most viewability certifications is the integration of invalid traffic (IVT) filtering directly into the measurement product."
SE004 HUMAN Security HUMAN recognized as a Leader in The Forrester Wave™ for Bot and Agent Trust Management Software "HUMAN received the highest scores possible across nine core evaluation criteria, including Threat Research, AI Agent Trust Management, Marketing Analytics Assurance, Intent Visibility, Attack and User Analytics, Customizable Reports and Dashboards, Security Operations Integrations, Vision, and Partner Ecosystem."
SE005 Manila Times (GlobeNewswire) HUMAN Recognized as a Leader by a Top Research Firm; Empowering Organizations to Transform Threat Intelligence into Action in the Agentic Internet "'We're incredibly proud to be recognized as a Leader in this category, and especially proud to be the only vendor to receive the top score in Threat Research,' said Stu Solomon, CEO."
SE006 PPC Land AI agent traffic is up 8x — HUMAN Security now tells marketers why
SE007 TMCnet (GlobeNewswire) HUMAN's Satori Researchers Identify and Disrupt Multi-Layered Ad Fraud and Malvertising Scheme Named Trapdoor "Trapdoor accounted for 480 million bid requests a day, with associated apps downloaded more than 24 million times."
SE008 IT Digest HUMAN and AWS Forge a New Trust Standard for AI Agents with Cryptographic Verification of Amazon Bedrock AgentCore
SE009 SoftwareOne Defense Platform by HUMAN | SoftwareOne Marketplace "Low Latency Enforcement: Decisions are enforced at the edge in under 2 milliseconds, with 95% of users validated swiftly."
SE010 TrustRadius HUMAN Bot Defender Details 2026 | TrustRadius
SE011 PeerSpot Compare Arkose vs Human Defense Platform — Bot Management Mindshare (June 2026) "The mindshare of Human Defense Platform is 8.1%, down from 11.6% compared to the previous year."
SE012 Dark Reading Human Security Tackles Malvertising With Clean.io Buy
SE013 AIThority HUMAN Acquires Anti-Malvertising Leader, clean.io, to Enhance Protection Across the Media Ecosystem
SE014 TechEdge AI HUMAN Security Enhances AI Capabilities for Advanced Cybersecurity Protection
SE015 SecuritySenses The Best Platforms for Bot Management and Account Takeover Prevention in 2026 "HUMAN is ranked #2 [in bot management] ... CHEQ leads this [ATO] category ... HUMAN Security focuses heavily on bot mitigation and fraud prevention, with strong ATO detection capabilities built into its platform."
SE016 HUMAN Security HUMAN Security Gives Marketing and Commerce Teams a Window Into the AI-Driven Internet through Expanded Capabilities and Adobe Integration
SE017 CMSWire HUMAN Security Gives Marketing and Commerce Teams a Window Into the AI-Driven Internet through Expanded Capabilities and Adobe Integration
SE018 KnowledgeNile Human Security Defends Digital Journeys With Intent-Based Trust (Sightline + AgenticTrust launch) "HUMAN Sightline, featuring AgenticTrust, secures the customer journey and unlocks safe, scalable growth with actor-level visibility and intent-based control across humans, bots and AI agents."
SE019 HUMAN Security (GitHub) HumanSecurity/human-verified-ai-agent — Open-source A2A AI agent with HTTP Message Signatures "This repository is an open-source showcase of A2A-based AI agents that implement HTTP Message Signatures for authenticating their requests ... The system is built on this RFC standard, with additional architectural considerations from the Web Bot Authentication Architecture draft."
SE020 MarTech Series HUMAN Acquires Anti-Malvertising Leader, clean.io
SE021 HUMAN Security HUMAN Security Platform — Product Overview
SE022 HUMAN Security Bot Detection and Mitigation Solutions
SE023 HUMAN Security Satori Threat Intelligence and Research Team
SE024 HUMAN Security HUMAN Sightline Cyberfraud Defense — First Adaptive Trust Layer for the Agentic AI Era
SE025 HUMAN Security 2026 State of AI Traffic & Cyberthreat Benchmark Report
SU001 PPC Land HUMAN Security's viewability measurement earns MRC accreditation "According to Jeff Meglio, Managing Director of Sovrn, the partnership with HUMAN has produced more meaningful outcomes across the market, with viewability metrics providing confidence in performance measurement through detailed reporting that supports day-to-day operational decisions."
SU002 Madhive Madhive Announces Fraud Free Guarantee to Protect Local Advertisers "This announcement underscores Madhive's unwavering commitment to transparency and quality," said Stu Solomon, CEO of HUMAN Security. "As a long-standing partner, Madhive has prioritized building a scalable, secure solution that stands out in the market."
SU003 TheDesk.net Madhive announces Fraud Free Guarantee for local ad buyers "Madhive forges 'trusted partnerships' with leading, MRC-accredited, quality supply firms, including HUMAN Security."
SU004 Security On Screen HUMAN Security launches partner-first channel program "As our customers face new and unprecedented threats on their applications and accounts, we must work with a partner who has the comprehensive coverage and unmatched human support to stop these attacks," said Nate Ungerott, CEO, Consortium Networks.
SU005 ChannelVision Magazine HUMAN Security Launches Advantage Partner-First Channel Program
SU006 GlobeNewswire (via Sina HK) HUMAN Security Launches Partner-First Channel Program To Maximize Business Growth "At HUMAN, we view our partners, like Optiv and Consortium Networks, as integral allies, giving them access to our platform and expertise to drive predictable growth."
SU007 Yahoo Finance (GlobeNewswire) G2 Honors HUMAN Security as a Best Security Software Product of the Year Amid Accelerated Product Innovation "Major AI developers, including OpenAI and AWS, recognize HUMAN as a trusted solution to verify AI agent traffic."
SU008 Consortium Networks Consortium | Your Cybersecurity Concierge
SU009 ZipDo Customer Experience In The Cyber Security Industry Statistics "42% of cybersecurity customers have switched vendors in the past two years due to poor CX. The average Net Promoter Score (NPS) for cybersecurity vendors is 21, 15 points lower than the average for all industries. 35% of cybersecurity churn is due to CX issues, not product performance."
SU010 PPC Land IVT: LinkedIn Ads integrates HUMAN "Since integrating with LinkedIn in May, over the past 30 days, HUMAN has identified less than 1% of impressions as invalid traffic for desktop ads on LinkedIn and across its network of publishers, including CTV."
SU011 Yahoo Finance (GlobeNewswire) HUMAN Security Solutions to Enhance Protections for Ad Traffic Quality on LinkedIn "Our work with HUMAN furthers our goal to continue providing advertisers with a safe and trusted ecosystem to run their campaigns." — Abhishek Shrivastava, VP of LinkedIn Marketing Solutions
SU012 Business Insider Markets (GlobeNewswire) HUMAN Ad Viewability Measurement Earns MRC Accreditation, Redefining Transparency, Explainability, and Trust in Ad Measurement "Sovrn has always focused on delivering clear, actionable insights that support performance. Our long-standing partnership with HUMAN reflects a shared commitment to transparency and precision across the media ecosystem."
SU013 Media Rating Council GI040425_HUMAN Accreditation Letter "The MRC Board of Directors has voted in favor of continuing accreditation for HUMAN's Ad Fraud Defense pre-bid platform and Ad Fraud Sensor post-serve platform for measurement and reporting of GIVT and SIVT detection across Desktop, Mobile Web, Mobile In-App and CTV."
SU014 Gartner Peer Insights (via Jina reader) HUMAN Sightline Cyberfraud Defense Reviews & Ratings 2026 "Platform Offers Valuable Support but Lacks Clarity on Detection Mechanisms" — 3/5 review from IT Security & Risk Management Associate, $500M–$1B Retail (Apr 14, 2026): "the product can feel like a 'black box' at times. While new detectors are being added, we have limited visibility into their specific functions or logic."
SU015 Harro.com (MarTech original) Invalid traffic detection gets smarter with HUMAN's Page Intelligence
SU016 Digitrendz Blog HUMAN's Page Intelligence: Smarter Invalid Traffic Detection
SU017 RivalSense HUMAN | Competitive Intelligence Profile
SU018 AGF HUMAN Security Launches New Partner Program to Boost Growth
SU019 HUMAN Security (blog via Jina cache) HUMAN recognized as a Leader in The Forrester Wave™ for Bot and Agent Trust Management Software "HUMAN's customers compliment the level of detail and attack insight that they receive from the Sightline feature."
SU020 HUMAN Security (newsroom via Jina) HUMAN Security's 2026 State of AI Traffic & Cyberthreat Benchmark Report "Automated traffic across the internet grew 23.51% year over year, while human traffic increased 3.10% over the same period. Monthly AI-driven traffic rates grew 187%."
SU021 SiliconAngle Human Security raises $50M+ to expand digital protection platform
SU022 Secure IT World HUMAN Security Tops G2's 2026 Best Security List
SU023 Markets Business Insider (Forrester via HUMAN) HUMAN Recognized as a Leader in The Forrester Wave™: Bot Management Software Q3 2024
SU024 Markets Business Insider (HUMAN ad verification launch) HUMAN launches AI-powered ad verification for advertisers
SU025 ITBusinessNet (HUMAN AI traffic benchmark) HUMAN Security's 2026 State of AI Traffic & Cyberthreat Benchmark Report signals new internet era
SR001 HUMAN Security, Inc. HUMAN Security's 2026 State of AI Traffic & Cyberthreat Benchmark Report "Automated traffic across the internet grew 23.51% year over year, while human traffic increased 3.10% over the same period. Monthly AI-driven traffic rates grew 187%."
SR002 HUMAN Security, Inc. HUMAN Ad Viewability Measurement Earns MRC Accreditation
SR003 Security Boulevard How bot detection misfires on non-mainstream browsers and privacy tools "Privacy-related traits often correlate with bots, leading systems to flag legitimate users based on flawed assumptions."
SR004 Notte.cc The Hidden Cost of Bot Detection: Bot Detection False Positives
SR005 SecureWorld Navigating the 2026 Cyber and AI Litigation Surge "By midyear, 56% report increased exposure at the federal level, and 53% report the same at the state level."
SR006 Mayer Brown LLP Cross-Border Transfers of American Personal Information Carry Heightened Regulatory, Litigation Risks "On February 9, 2026, the FTC sent formal warning letters to 13 companies identified by the Commission as 'data brokers,' emphasizing their obligation to comply with PADFAA's prohibitions on transfers of sensitive data to foreign adversaries."
SR007 Check My Ads Institute Comments on MRC Digital Advertising Auction Transparency Standards "Time and time again, we have seen that self-regulation is insufficient to resolve these challenges in the complex and concentrated digital advertising market."
SR008 StatusGator AWS outage takes down more than 150 cloud services
SR009 HUMAN Security, Inc. BADBOX 2.0: The sequel no one wanted
SR010 Google LLC We're taking legal action against the BadBox 2.0 botnet
SR011 NewChannel The State of Ad Fraud Detection in 2026
SR012 Future of Privacy Forum U.S. Privacy Enforcement in 2025 — Retrospective
SR013 Clarip 2026 Data Privacy Enforcement Trends: What Regulators Are Actually Fining Companies For
SR014 DoubleVerify Holdings, Inc. Global Study: Fueled by AI, CTV Fraud Schemes Surge 140% Globally "DV detected 140% more CTV fraud schemes and variants in Q1 2026 compared with Q1 2025, underscoring how fraudsters are using advanced tools to scale and create more complex operations."
SR015 Gartner Cloudflare vs HUMAN Security 2026 | Gartner Peer Insights
SR016 PeerSpot Compare Cloudflare One vs Human Defense Platform (2026) "Cloudflare One appears to have the upper hand due to its comprehensive features and long-term value despite the appealing pricing of Human Defense Platform."
SR017 Cloudflare, Inc. Introducing the 2026 Cloudflare Threat Report
SR018 Google Cloud Cloud Threat Horizons Report H1 2026
SR019 Premier Alts Human Security Valuation: N/A (2026)
SR020 Stinson LLP A New Era of Comprehensive Privacy Laws and the Surge in Data Privacy Litigation: Important Updates for 2026 "Nearly 4,000 cases [were] filed in 2024—up from just over 200 cases filed in 2023—alongside countless additional claims asserted through demand letters and arbitration."
SR021 AI Pedias AI Ad Fraud & Bot Detection Complete Guide 2026: HUMAN vs CHEQ vs DoubleVerify
SR022 HUMAN Security, Inc. HUMAN, FBI, and Partners Take Action Against BADBOX 2.0
SR023 The Register Google sues 25 alleged BadBox 2.0 botnet operators
SR024 Forbes FBI Warning To 10 Million Android Users — Disconnect Your Devices Now
SR025 CyberInsider Google Sues Operators of BadBox 2.0 Botnet Behind Massive Global Malware Scheme
SR026 MediaPost Going, Going, Gone: MRC Finalizes Ad Auction Standards
SR027 Yahoo Finance HUMAN Ad Viewability Measurement Earns MRC Accreditation, Redefining Transparency, Explainability, and Trust
SR028 Specificity Inc. Human Verified Traffic: Busting the Myths of Modern Ad Fraud in 2026
SR029 Cybelesoft AWS Outage March 2026: How the Global Cloud Failure Exposed VDI Vulnerabilities "AWS data center facilities in the United Arab Emirates (ME-CENTRAL-1 region) triggered structural fires and forced emergency power shutdowns across multiple Availability Zones."
SR030 Protegrity AI Fraud Detection in 2026: What Security and Risk Leaders Must Know
SR031 Cyber Defense Magazine Innovator Spotlight: HUMAN
SV001 Multiples.vc DoubleVerify — Multiples.vc — Public Comps and Valuation Multiples DoubleVerify reported last 12-month revenue of $781M and EBITDA of $261M. Current revenue multiple of DoubleVerify is 1.9x. DoubleVerify's current market cap is $2B.
SV002 Multiples.vc Public Software Valuation Multiples — June 2026 AdTech and video streaming trade at even steeper discounts. Cybersecurity listed separately under infrastructure SaaS. Data as of June 19, 2026.
SV003 Kroll Cybersecurity M&A Industry Insights — Spring 2026 AI related concerns weighed on cybersecurity equities in Q1, driving a decline in valuation multiples across Kroll's cybersecurity index. Median EV to next twelve months revenue multiples fell 26% quarter over quarter.
SV004 Finro Financial Consulting Cybersecurity Valuation Multiples Q2 2026 — 265 Companies, 9 Niches Application Security: 52 companies, avg EV/Rev 15.4x, median 13.0x. Cloud Security: 16 companies, avg 22.7x, median 18.1x. Private companies only — medians decline from Seed (15.5x) through Series C (12.7x) before a modest recovery at Series D+.
SV005 Windsor Drake Cybersecurity Valuation Report 2026 Private market transactions, particularly M&A exits, are happening at much higher multiples. Private M&A Multiples: High-growth private targets in hot sectors like Cloud Security are seeing M&A exit multiples average 16.3x, with outliers reaching as high as 22.7x. The median revenue multiple for private cybersecurity companies in 2025 stands at 15.2x.
SV006 iMerge Advisors Q1 2026 Private SaaS Valuation Report Insights Scale ($10M–$50M ARR): Median ARR Multiple 5.5–7.2x, Top Quartile 8.0x+. Q1 2026 Valuation Matrix. Executive Summary: Private SaaS valuations have stabilized at 4.0x–5.5x ARR.
SV007 Acquiry SaaS Valuation Multiples in 2026: What the Data Actually Shows AI-native SaaS (20–50% ARR growth): 7x to 12x ARR. Traditional SaaS (>30% ARR growth): 5x to 8x ARR. Net Revenue Retention is the single most important metric in SaaS valuation.
SV008 SaaS Mag Cybersecurity SaaS Premium: Highest Multiples in 2026 Public cyber companies trade at a 7.8x revenue median, private cyber startups command 15.2x, and the M&A median runs 16.3x with cloud-security transactions reaching all the way up to 35.5x. Disclosed cybersecurity M&A hit $96 billion across 400 transactions in 2025. 2026 has already crossed $65 billion in disclosed deal value before the halfway mark.
SV009 CloudStack Networks Cybersecurity M&A Hits $47 Billion in Q1 2026 as Palo Alto, CrowdStrike Drive Platform Consolidation The cybersecurity industry recorded $47 billion in M&A activity in Q1 2026 alone, following a record $96 billion in 2025.
SV010 Premier Alternatives Human Security Valuation: N/A (2026) Current Valuation: N/A. Last Round: PE Growth/Expansion. Amount undisclosed. No funding history available. Funding data has not been imported for this company yet.
SV011 Value Add VC SaaS Valuation Multiples 2026: Median EV/Revenue 8.5x, Up 90% From the Trough The median public SaaS multiple sits at ~8.5x NTM revenue in mid-2026 — up ~90% from the ~4.5x Q1 2023 trough. >50% YoY growth: Median EV/Revenue 12–18x.
SV012 ipos.fyi Cybersecurity IPOs — Companies Going Public (2026)
SV013 SEC EDGAR — DoubleVerify Holdings Inc. DoubleVerify Holdings, Inc. Annual Report on Form 10-K for Fiscal Year Ended December 31, 2025
SV014 Business Wire HUMAN Raises $100 Million In Growth Funding Round Led By WestCap and NightDragon
SV015 Business Wire HUMAN and PerimeterX Unite in Market-Changing Merger to Safeguard Customers From Sophisticated Bot Attacks, Fraud and Account Abuse
SV016 SiliconAngle Human Security raises $50M+ to expand digital protection platform
SV017 Yahoo Finance / Globe Newswire HUMAN Raises $50+ Million in Growth Funding to Protect the Digital Customer Journey
SV018 PR Newswire HUMAN Security Announces Strategic Leadership Transition: Tamer Hassan to Become Executive Chairman, Stu Solomon Appointed to CEO
SV019 GetLatka HUMAN Security Revenue 2023 GetLatka reported HUMAN Security ARR at $15 million as of December 2023, directly conflicting with the company's stated $100M-plus ARR.
SV020 SEC EDGAR — White Ops Inc. White Ops Inc. Form D — Series A Exempt Offering, June 2014 (CIK 0001611028)
SV021 Momentum Cyber Cybersecurity Market Review May 2026 May 2026: 31 M&A transactions and 46 financing transactions. $823M in disclosed M&A value. AI Security M&A is on pace to increase 400%+ in 2026.
SV022 Tracxn HUMAN Security — Company Profile and Funding History
SV023 HUMAN Security HUMAN Security — AgenticTrust and Sightline Platform
SV024 Benchmarkit 2024/2025 SaaS Gross Margin Benchmarks
SV025 GrowJo HUMAN Security Revenue Estimate
SV026 Kasada Kasada Secures $20 Million Round to Accelerate Global Expansion
SV027 GetLatka Arkose Labs Revenue 2024: $46.9M ARR, $140.7M Valuation
SV028 DataDome DataDome Closes $42 Million Series C Funding
SV029 Manila Times / GlobeNewswire HUMAN Recognized as a Leader by a Top Research Firm in the Forrester Wave: Bot and Agent Trust Management, Q2 2026
SV030 SiliconAngle (October 2024 funding coverage) Human Security raises $50M+ — investor and allocation details