HUMAN Security
Internet-scale bot, fraud, and agentic trust platform
HUMAN Security appears strategically relevant and plausibly fairly valued on disclosed scale and cybersecurity-peer benchmarks, but public evidence is not strong enough on ARR quality, retention, margin, and debt status to support a conviction investment call.
Cover facts
Company profile
HUMAN Security was founded in 2012 as White Ops and rebranded in 2021 as it expanded from ad-fraud detection into a broader digital trust platform. The company now sells the Human Defense Platform across media security, application security, account protection, and agentic trust use cases, operating at internet scale with 20T+ verified weekly interactions and 500+ customer brands. Ownership and governance shifted materially after the 2020 Goldman Sachs/ClearSky/NightDragon acquisition, the 2022 PerimeterX merger, and the 2024 growth round. Despite strong strategic positioning and clear product-market relevance, the business remains financially opaque on revenue growth, retention, margins, and current valuation.
- Website
- www.humansecurity.com
- Founded
- 2012-01-01
- Founders
- Tamer Hassan, Michael Tiffany, Dan Kaminsky, Ash Kalb
- Founding location
- Brooklyn, New York, USA
- Headquarters
- New York City, New York, USA
- Product
- The Human Defense Platform combines bot mitigation, ad-fraud detection, application and account-abuse defense, threat intelligence, and newer agentic-AI governance products such as HUMAN Sightline and AgenticTrust. It uses large-scale telemetry, device intelligence, behavioral signals, and the Satori Threat Intelligence team to classify and disrupt malicious automation in real time.
- Customers
- Large digital businesses, adtech and media platforms, marketplaces, retailers, financial-services firms, and enterprise security teams that need to reduce fraud, invalid traffic, scraping, account takeover, and AI-agent abuse.
- Business model
- Enterprise cybersecurity software and managed intelligence platform sold through direct and partner channels across media security, application security, account protection, and trust-layer workflows.
- Stage
- Private growth stage
- Funding status
- Approximately $300M total equity raised. Latest financing: $50M+ growth round announced in October 2024 led by WestCap with Goldman Sachs Asset Management, ClearSky Security, NightDragon, and Vertex Ventures US. A $100M Blackstone Credit facility was also disclosed in 2022.
Executive summary
Top strengths
- Internet-scale telemetry and threat-intelligence network built on 20T+ weekly verified interactions.
- Strong institutional backing with repeat support from Goldman Sachs, WestCap, NightDragon, ClearSky, and Vertex.
- Product footprint spans media security, application protection, account abuse defense, and agentic-AI trust.
- Credible external recognition including Forrester leadership and strong customer-review surfaces in 2026.
Top risks
- Public financial opacity leaves ARR quality, retention, margin, and debt burden materially underwritten.
- Bundled competition from Cloudflare, Akamai, Google, and other platform vendors can compress standalone pricing power.
- Behavioral-data and fingerprinting models face evolving privacy and data-transfer regulation.
- AWS/cloud concentration and real-time detection requirements create meaningful operational outage risk.
- Adtech heritage may pull valuation multiples below pure-play cybersecurity peers in an exit process.
Open gaps
- Audited or management-confirmed ARR, growth, and product-segment revenue mix.
- Net revenue retention, gross retention, churn, and average contract duration by customer segment.
- Gross margin and cost-of-revenue split across threat intelligence, cloud infrastructure, and services.
- Current outstanding balance, maturity, and covenants of the 2022 Blackstone Credit facility.
- Updated post-2024 valuation, liquidation preferences, and cap-table ownership concentration.
Contents
01Company Overview
1.1 Identity, headquarters, and platform model
HUMAN Security, Inc. is a privately held cybersecurity company headquartered in New York City, with additional offices in Miami, Santa Clara, Tel Aviv (Israel), and the United Kingdom. The company was founded in 2012 in Brooklyn, New York under the name White Ops by Tamer Hassan, Michael Tiffany, Dan Kaminsky, and Ash Kalb. It rebranded to HUMAN Security in 2021 to reflect an expanded scope beyond advertising fraud into full-stack enterprise and consumer security. The company describes itself as the trust layer for media and agentic commerce platforms, verifying engagement, reducing fraud, and enabling authentic interactions across humans, bots, and AI agents. HUMAN's core commercial offering is the Human Defense Platform (HDP), which the company positions as a unified platform delivering protection across three principal pillars: Media Security (digital advertising fraud, invalid traffic detection, and ad integrity), Application and Enterprise Security (account takeover, credential stuffing, fake account creation, web scraping, and carding), and Account Protection (identity and authentication fraud). The platform's stated scale metrics are verifying more than 20 trillion digital interactions weekly across 3 billion unique devices, using 2,500+ signals per interaction, analyzed by 400+ adaptive machine learning models, to make binary bot-or-human decisions in milliseconds. The company serves 500+ global brands across media, finance, retail, government, education, and enterprise security verticals. As of mid-2026, HUMAN has expanded its platform into the agentic AI era, launching HUMAN Sightline Cyberfraud Defense, a unified trust and defense layer protecting digital businesses from bot attacks, human-led fraud, transaction abuse, and AI-driven risks across the full customer journey, and AgenticTrust, which allows customers to detect, classify, and govern AI agents operating on their platforms. HUMAN also operates the Satori Threat Intelligence and Research Team, which drives threat intel and orchestrates public-private disruptions of cybercriminal operations. The company characterizes its competitive position as the largest threat detection network globally by weekly interaction volume. Revenue model and pricing remain private. [CO001, CO003, CO004, CO005, CO006, CO007]
| metric | value/status | date | confidence | gap |
|---|---|---|---|---|
| Founded | 2012 (as White Ops) | 2012 | high | |
| Rebranded to HUMAN Security | 2021 | 2021 | high | |
| Headquarters | New York City, New York, US | high | ||
| Operating status | Private; Goldman Sachs Merchant Banking-anchored | high | ||
| Weekly digital interactions verified | >20 trillion | 2026-06 | high | Self-reported; no independent audit confirmed |
| Unique devices covered | 3 billion | 2026-06 | medium | Company-claimed; independent verification unavailable |
| Customers / brands served | 500+ | 2026-06 | medium | Company-claimed; no customer list published |
| Employees (headcount) | ~400 (as of Oct 2024); ~437 (estimated mid-2026) | 2024-10 | low | Exact current headcount not publicly confirmed |
| Total capital raised | ~$299-300M (equity); $100M Blackstone debt additional | 2024-10 | medium | Aggregator estimate; company has not confirmed exact total |
| Last disclosed valuation | ~$1.5B (January 2022 round) | 2022-01 | medium | No post-2022 valuation disclosed; figure is stale |
| Revenue / ARR | Not publicly disclosed | low | Private company; full diligence requires data room access | |
| Forrester Wave ranking | Leader (Q2 2026 Bot and Agent Trust Management) | 2026-06-15 | high |
All HUMAN-issued scale claims (20 trillion interactions, 3 billion devices, 500+ brands) are company-claimed and have not been independently audited. Employee and revenue figures are third-party estimates from data aggregators unless otherwise noted. The $1.5B valuation is from the January 2022 funding round and is now four-plus years old.
[CO001, CO004, CO005, CO007, CO008, CO038]HUMAN's scale and recognition metrics are strong; financial metrics are private and unavailable for public diligence without data room access.
[CO007, CO008, CO027, CO041, CO042, CO043]1.2 Founders, leadership, board, and key-person risk
HUMAN was founded by four individuals: Tamer Hassan (CEO through January 2024, now Executive Chairman), Michael Tiffany, Dan Kaminsky, and Ash Kalb. Hassan was the dominant public face of the company for its first twelve years, recognized by Fast Company in 2019 as its number one Most Creative Person in Business. He led the rebranding from White Ops, the merger with PerimeterX, the acquisition of clean.io, and the company's surpassing of $100M ARR. In January 2024, Hassan transitioned to the role of board member and Executive Chairman, remaining actively engaged in strategy, customer relationships, and public-policy advocacy. The co-founder network is therefore partially intact: Hassan retains a governance role, while the other three founding members are not publicly listed in active executive roles as of the June 2026 research date. In January 2024, Stu Solomon, formerly President of Recorded Future (the world's largest threat intelligence provider), was appointed CEO. Solomon brings executive and C-suite experience from Optiv (including as CTO), iSight Partners (acquired by FireEye), and Bank of America, as well as a more than 25-year military career in the Delaware Air National Guard and United States Air Force. HUMAN's current executive leadership also includes Isaac Itenberg (Chief Operating Officer and Chief Financial Officer), Gavin Reid (Chief Information Security Officer), and Christos Kalantzis (Chief Technology Officer). The board of directors as of the 2026 research date includes directors from Goldman Sachs (Anthony Arnold), NightDragon (Dave DeWalt), WestCap (Kevin Marcus), and ClearSky (Jay Leek), alongside Tamer Hassan (Executive Chairman) and Ido Safruti, who joined the board as part of the PerimeterX merger. A search of public records and company announcements found no evidence of Matt Cantor in HUMAN Security's current or recent leadership, executive team, or board. Key-person risk has improved somewhat with the CEO transition from Hassan to Solomon, which distributes strategic execution across a more experienced external management team. However, the board remains heavily investor-representative (Goldman Sachs, NightDragon, WestCap, ClearSky), and the company's threat-intelligence identity and customer relationships retain a degree of founder imprint through Hassan's Executive Chairman role. The board also lists eight observers (Ryan Benevides, Dan Burns, Itzhak Fisher, Steve Fredrick, Rhys Gordon, Hannah Huffman, Lance Matthews, Alexander Weiss), whose affiliations and control significance are not publicly disclosed in the current source set. Full board composition and governance terms remain a diligence gap. [CO002, CO011, CO012, CO013, CO014, CO015]
| person | role | background | founder-market fit / functional coverage | key-person dependency |
|---|---|---|---|---|
| Tamer Hassan | Co-Founder; Executive Chairman (since Jan 2024; CEO through Jan 2024) | Serial cybersecurity entrepreneur; Fast Company 2019 | Founding vision; market positioning; customer relationships; public policy; board governance | High: company identity, brand, and customer network remain closely associated with Hassan despite CEO transition |
| Stu Solomon | CEO (since Jan 2024) | President of Recorded Future (5 yrs); CTO at Optiv; iSight Partners exec; Bank of America; 25+ yr Delaware Air National Guard / USAF | Operational scaling; cybersecurity go-to-market; public-sector expansion; data science investment strategy | High: sole publicly facing CEO post-transition; all strategy and capital allocation decisions flow through Solomon |
| Michael Tiffany | Co-Founder | Co-founder of White Ops; background in bot detection and cybersecurity research | Founding technical vision; core bot-or-not detection methodology | Low to medium: not listed in current executive or board roles; role in current operations unclear |
| Dan Kaminsky | Co-Founder (deceased 2021) | Renowned security researcher; discovered critical DNS vulnerability; co-founder of White Ops | Founding threat intelligence philosophy; Satori team heritage | Historical: Kaminsky passed away in April 2021; his influence is embedded in platform DNA rather than active operations |
| Ash Kalb | Co-Founder | Co-founder; background in cybersecurity product development | Founding product and business development contribution | Low to medium: not listed in current executive or board roles; current role unclear |
| Isaac Itenberg | Chief Operating Officer and Chief Financial Officer | Senior operator and finance executive | Operational execution; financial management; company oversight | Medium: dual COO/CFO role centralizes operational and financial authority |
| Gavin Reid | Chief Information Security Officer | Experienced CISO with cybersecurity industry background | Internal security posture; product credibility with enterprise CISOs | Medium: CISO role matters for enterprise customer confidence |
| Christos Kalantzis | Chief Technology Officer | Senior technology executive | Platform technical architecture; AI/ML platform development; engineering roadmap | Medium: CTO continuity is important given the platform's machine learning core |
Enumerates the public-facing executive and founding team based on company announcements, press releases, and the Craft.co profile as of June 2026. Full board composition (including investor- designated directors and all 8 observer seats) and exact founder equity ownership are not publicly disclosed. Dan Kaminsky's entry is included for completeness; he passed away April 2021. Matt Cantor does not appear in any current or recent HUMAN Security leadership or board record.
[CO002, CO011, CO012, CO013, CO014, CO019]HUMAN's operating system connects PE-sponsored capital, a founder-turned-chairman governance layer, a threat-intelligence core (Satori), and a unified platform that serves three customer segments: media/adtech, enterprise application security, and agentic AI governance.
[CO007, CO015, CO016, CO017, CO018, CO043]1.3 Funding history, valuation, and investor map
HUMAN's capital history runs from venture-backed startup through a private equity buyout and into a growth-funded cybersecurity platform. The company completed its Series B in 2017 led by Canaan Partners and a $43M Series C in February 2019 led by Scale Venture Partners. In December 2020, Goldman Sachs Merchant Banking Division, ClearSky Security, and NightDragon jointly acquired White Ops from previous investors including Paladin Capital Group and Grotech Ventures. Terms were not disclosed. At the time of the acquisition, the company had 170 employees and was verifying 10 trillion interactions per week. Post-acquisition, HUMAN raised $57M in a Series D growth round in February 2021 with participation from Stereo Capital and others, and then completed a $100M growth round in January 2022 led by WestCap and NightDragon, which was reported to value the company at approximately $1.5 billion. In July 2022, concurrent with the PerimeterX merger, HUMAN secured a $100M debt facility from Blackstone Credit. The most recent external capital event is a $50M+ growth round announced October 9, 2024, led again by WestCap, with participation from Goldman Sachs, ClearSky, NightDragon, and Vertex Ventures US. CEO Stu Solomon stated that the $50M amount was deliberately constrained to enable targeted investments without over-capitalization. Total capital raised is reported as approximately $299-300M across all rounds, according to data aggregators. However, this figure may not include the $100M Blackstone debt facility, which was a debt instrument rather than equity. No current post-money valuation is publicly disclosed. The $1.5B valuation from January 2022 is the most recent publicly reported figure, but it predates both the 2022 PerimeterX merger and the October 2024 round. Exact equity ownership percentages, liquidation preferences, and cap-table composition remain private. HUMAN is a Goldman Sachs-anchored asset with recurring lead investor WestCap and strategic co-investors from the cybersecurity industry (NightDragon, ClearSky, Vertex Ventures US). [CO021, CO022, CO023, CO024, CO025, CO026]
| stakeholder | role | control / economic importance | diligence ask |
|---|---|---|---|
| Goldman Sachs Merchant Banking Division | Lead acquirer (Dec 2020); board representative (Anthony Arnold) | Acquired majority control in 2020 buyout; anchor institutional shareholder; retained through all subsequent rounds | Confirm current equity ownership percentage, board seat rights, exit horizon, and any secondary activity; Goldman Sachs's ownership makes this a PE-sponsored asset with implicit exit timeline |
| WestCap | Lead investor in January 2022 growth round and October 2024 growth round; board representative (Kevin Marcus) | Double lead investor with two consecutive growth rounds; co-COO-level operating expertise provided to management | Assess specific board governance rights, information rights, and any preference terms; WestCap's operator-at-heart model suggests active governance engagement |
| NightDragon | Co-investor in 2020 acquisition; co-investor in 2022 round; co-investor in 2024 round; board representative (Dave DeWalt, founder/CEO of NightDragon) | Recurring strategic investor; Vice Chairman of HUMAN board per 2020 acquisition announcement; cybersecurity ecosystem connector | Confirm current board seat and oversight rights; DeWalt's network spans enterprise cybersecurity buyers, making NightDragon a strategic rather than purely financial investor |
| ClearSky Security | Co-investor in 2020 acquisition; co-investor in 2024 round; board representative (Jay Leek) | Early acquisition partner; persistent board presence; specialized in cybersecurity and critical-infrastructure security | Clarify current equity stake and board rights; ClearSky's deep-security focus aligns with HUMAN's threat-intel differentiation |
| Vertex Ventures US | New investor in October 2024 round | First-round participation; new growth equity position; scale and governance rights unconfirmed | Request current equity ownership terms and any governance rights associated with the 2024 round |
| Scale Venture Partners | Led $43M Series C (Feb 2019); historical investor | Early institutional capital; pre-acquisition shareholder; current residual ownership unknown post-2020 buyout | Determine whether Scale Venture retained any equity post-Goldman Sachs acquisition; current ownership likely nominal |
| Canaan Partners | Led Series B (2017); historical investor | Early growth capital; pre-acquisition shareholder; current residual ownership unknown | As with Scale Venture, confirm post-acquisition stake; likely exited or marginally diluted |
| Blackstone Credit | $100M debt facility (July 2022, concurrent with PerimeterX merger) | Debt instrument; not equity; terms including covenants, maturity, and interest rate not publicly disclosed | Obtain full debt agreement terms; debt facility has implications for free cash flow, refinancing risk, and any security interest in HUMAN assets |
| Tamer Hassan (Executive Chairman) | Co-founder; board member; Executive Chairman since January 2024 | Residual founder equity stake; unclear size; strategic and governance influence | Confirm founder equity position, lock-up terms, and any secondary liquidity activity since the 2020 acquisition |
Ownership percentages are not publicly disclosed for any investor. Stakes listed are inferred from announced roles and round participation only. The 2020 Goldman Sachs acquisition was a majority buyout of prior shareholders; residual VC positions from Series B and C may have been partially or fully bought out. The $100M Blackstone credit facility is a debt instrument and is separate from the ~$299-300M equity capital raised figure cited by aggregators.
[CO021, CO022, CO024, CO025, CO026, CO027]1.4 Milestone chronology, competitive recognition, and adverse context
HUMAN's operating history is marked by a series of public-private threat disruptions that have established its identity and credibility in the cybersecurity market. In 2016, as White Ops, the company uncovered Methbot, one of the first large-scale dedicated ad fraud botnets. In 2018-2019, it participated with the FBI, Google, and Facebook in the takedown of 3ve, the largest ad fraud botnet to date. In 2021, the company led a collaborative PARETO disruption (a major Connected TV ad fraud operation) and rebranded from White Ops to HUMAN Security. The year 2022 was the most active on record: clean.io was acquired in March, the PerimeterX merger closed in July, and the VASTFLUX ad fraud scheme (affecting 11 million devices with 12 billion daily false bid requests) was disrupted and reported in January 2023. BADBOX, a pre-installed Android botnet affecting millions of devices globally, was disrupted in multiple phases in 2023, 2024, and 2025, with German authorities and a coalition including HUMAN, Google, and Shadowserver conducting the largest coordinated sinkholing operations. On the commercial and recognition side, HUMAN was named to TIME's Best Inventions of 2023, the TIME100 Most Influential Companies of 2023, and named a Leader in The Forrester Wave: Bot Management Software Q3 2024. In January 2024, the CEO transition from Tamer Hassan to Stu Solomon took effect. In October 2024, the $50M+ growth round closed. By June 2026, HUMAN was named a Leader in The Forrester Wave: Bot and Agent Trust Management Software Q2 2026, with the highest possible scores across nine criteria including Threat Research, the only vendor to receive a top score in that criterion. G2's Summer 2026 Grid for Bot Detection and Mitigation Software also named HUMAN the top overall Leader based entirely on customer feedback. The adverse record is limited. In October 2024, AdExchanger published a correction noting that CEO Stu Solomon had misspoken during an interview about building a proprietary deterministic ID for attribution; HUMAN's VP of Product clarified that no such product was planned. This represents a minor public messaging error with no regulatory or legal consequences. No material lawsuits, regulatory investigations, data breach disclosures, significant workforce reductions, or sanctions against HUMAN Security have been identified in public records as of the June 2026 research date. The absence of documented adverse events should be noted as an evidence gap for private proceedings that would not be publicly disclosed, and the company's private status means no public regulatory filing trail exists. [CO029, CO030, CO031, CO032, CO033, CO034]
| date | event | type | amount/valuation/status | participants | implication |
|---|---|---|---|---|---|
| 2012 | White Ops founded in Brooklyn, New York | founding | N/A | Tamer Hassan, Michael Tiffany, Dan Kaminsky, Ash Kalb | Origin of the "bot or not" detection company that became HUMAN Security |
| 2016 | Methbot ad fraud operation uncovered and disclosed | product | $3-5M/month criminal revenue disrupted | White Ops (Satori team) | First major public-private disruption; established White Ops as threat-intelligence leader in ad fraud |
| 2017 | Series B funding round closed | financing | Amount not disclosed | Canaan Partners (lead) | First institutional growth capital beyond seed; enabled platform scaling |
| 2019-02 | Series C funding round closed | financing | $43M | Scale Venture Partners (lead), Canaan | Accelerated growth into enterprise security use cases beyond advertising |
| 2018-2019 | 3ve botnet takedown completed; FBI indictments issued | product | Multi-billion impression fraud disrupted | White Ops, FBI, Google, Facebook, industry coalition | Largest private-sector collaborative cybersecurity disruption to date; defined White Ops' threat-intelligence identity |
| 2020-12 | Goldman Sachs Merchant Banking acquires White Ops; ClearSky and NightDragon co-invest | financing | Terms not disclosed; PE majority buyout | Goldman Sachs MBD, ClearSky, NightDragon | Transition from VC-backed startup to PE-owned growth asset; prior investors (Paladin Capital, Grotech Ventures) exited |
| 2021-Q1 | White Ops rebrands to HUMAN Security | governance | N/A | HUMAN Security management | Reflects expanded scope from ad fraud to full-stack digital identity protection |
| 2021 | PARETO (CTV ad fraud botnet) takedown; Dan Kaminsky passes away | product | Major CTV fraud operation disrupted | HUMAN, industry partners; Kaminsky (April 2021) | Notable takedown of Connected TV fraud; loss of founding team member |
| 2022-01 | $100M growth round closed; valuation approximately $1.5B (unicorn milestone) | financing | $100M raised; ~$1.5B post-money valuation | WestCap (lead), NightDragon | Unicorn designation; capital for PerimeterX merger and platform expansion |
| 2022-03 | HUMAN acquires clean.io (malvertising prevention) | product | Terms not disclosed | HUMAN (acquirer), clean.io | Adds malvertising prevention capability to the platform; cited by Hassan at CEO transition |
| 2022-07 | HUMAN merges with PerimeterX; Blackstone Credit $100M debt facility | product | $100M debt; combined entity has 450+ employees, $100M+ ARR | HUMAN, PerimeterX, Blackstone Credit | Largest strategic move in company history; unified ad-tech and enterprise security platform; Omri Iluz becomes president of Enterprise Security |
| 2023-01 | VASTFLUX ad fraud disruption disclosed (11M devices, 12B daily false bids peak) | product | 12B bid requests/day at peak; disrupted | HUMAN (Satori team) | Demonstrated HUMAN's ability to conduct large-scale coordinated private takedowns; reinforced threat-intel brand |
| 2023 | Named to TIME Best Inventions and TIME100 Most Influential Companies | scale | Industry recognition | TIME editorial, HUMAN | Mainstream credibility milestone; product reaching consumer-facing acknowledgment |
| 2023-2024 | BADBOX pre-installed Android botnet takedown (multiple phases; BADBOX 2.0 in 2024-2025) | product | 10M+ devices affected; disrupted | HUMAN, Google, German authorities, Shadowserver | Multi-year, multi-agency operation; positioned HUMAN as a persistent threat-disruption actor beyond one-time takedowns |
| 2024-01 | Stu Solomon appointed CEO; Tamer Hassan becomes Executive Chairman | governance | N/A | Stu Solomon (incoming CEO), Tamer Hassan (Executive Chairman) | First external CEO appointment; marks transition from founder-led to professional management |
| 2024-10 | $50M+ growth round closed | financing | $50M+ raised | WestCap (lead), Goldman Sachs, ClearSky, NightDragon, Vertex Ventures US | Second WestCap-led round; new investor Vertex Ventures US; CEO deliberately constrained size for targeted investment |
| 2026-06 | Named Leader in Forrester Wave Bot and Agent Trust Management Q2 2026; highest score in Threat Research | scale | Highest Forrester score in Threat Research criterion | Forrester Research | Validates platform expansion into agentic AI trust management; differentiating threat intelligence capability publicly recognized |
Milestone dates are drawn from press releases, news coverage, and company announcements. Exact acquisition and merger terms are not publicly disclosed. The PerimeterX merger closing date (July 2022) is from the BusinessWire announcement; regulatory approval was confirmed in that release. Dan Kaminsky's passing is included as an adverse milestone given his founding-team role. The $100M ARR figure at the time of the PerimeterX merger is from the BusinessWire announcement and represents combined ARR of the merged entities.
[CO001, CO004, CO021, CO022, CO023, CO024]HUMAN's operating history spans a founding-era threat-intelligence phase, a private equity consolidation phase (2020-2022), and a platform-expansion phase (2022-2026) now extending into agentic AI. Adverse events are limited to a minor public messaging correction and a founding member's death.
[CO001, CO004, CO029, CO030, CO031, CO037]1.5 Exhibits
02Market Analysis
2.1 Market Boundary, Included Spend, and Substitutes
HUMAN Security's revenue opportunity spans four distinct but overlapping product categories: (1) bot mitigation and behavioral analytics platforms protecting web applications, APIs, and mobile surfaces from automated abuse; (2) ad fraud and Sophisticated Invalid Traffic (SIVT) defense, covering pre-bid filtering, post-bid reporting, and MRC-accredited verification in programmatic advertising; (3) account-takeover (ATO) prevention targeting post-login credential abuse, session hijacking, and multi-stage attack chains; and (4) agentic AI trust management, a nascent category that emerged as AI-powered agents began transacting on behalf of users—growing 7,851% year-over-year in HUMAN's own network data. These four categories are increasingly unified under HUMAN Sightline Cyberfraud Defense and MediaGuard/Ad Integrity Suite within the Human Defense Platform. Included spend encompasses behavioral analytics SaaS subscriptions, MRC-accredited SIVT detection licensing, bot-score API fees, AgenticTrust policy enforcement, and managed threat intelligence services (Satori team). Excluded spend includes pure payment-fraud chargebacks and chargeback insurance, KYC/KYB identity proofing (document verification, biometric), AML compliance tooling, traditional CAPTCHA commodities without behavioral layers, DDoS mitigation (pure volumetric), and CDN infrastructure contracts where bot management is an untariffed add-on. Adjacent markets include web application firewalls, cloud access security brokers, identity and access management platforms, and API gateway security—all of which create partial substitutes for specific HUMAN use cases. Status-quo substitutes include: in-house fraud rule engines and data-science teams (common at large internet platforms such as Google, Meta, and major financial institutions), CDN-native bot management from Cloudflare (79% bot management install base by device share) and Akamai (6%), and point-solution SIVT vendors such as Integral Ad Science, DoubleVerify, and Pixalate. Cloudflare's bundling of bot management with CDN and WAF at flat-rate pricing starting around $350 annually for SMBs creates the most material displacement risk in the lower and mid-market. The competitive bundling threat constrains HUMAN's addressable market—particularly among organizations that already rely on Cloudflare for content delivery—and forces a differentiation argument based on signal depth (2,500+ behavioral signals per interaction), threat research (Satori team), and specialized ad fraud MRC accreditation that Cloudflare does not offer. [CM001, CM028, CM029, CM037, CM038, CM039]
| Segment / Category | Included Spend | Excluded Spend | Primary Buyer / Payer | Relevance to HUMAN |
|---|---|---|---|---|
| Bot Mitigation & Behavioral Analytics | Bot-score APIs, behavioral analytics SaaS, CAPTCHA-bypass detection, SDK-based session monitoring, managed bot services | CDN infrastructure, DDoS volumetric mitigation, network-layer firewall subscriptions | App security engineers, CISO / IT Security budget | Core — Bot Defender, Sightline Cyberfraud Defense |
| Ad Fraud / SIVT Defense | Pre-bid IVT filtering, post-bid reporting, MRC-accredited SIVT classification, TAG compliance tooling, Page Intelligence analytics | Viewability-only measurement (non-fraud), brand safety adjacency (non-IVT), ad serving infrastructure | Ad ops directors, CMO / Marketing P&L budget | Core — MediaGuard, Ad Integrity Suite, Page Intelligence |
| Account Takeover (ATO) Prevention | Post-login behavioral monitoring, credential-stuffing detection, session anomaly alerts, ATO threat intelligence | Full identity proofing (KYC/KYB), biometric authentication hardware, IAM platform subscriptions | Fraud operations teams, Head of Risk / CISO + CRO budget | Core and expanding — ATO monitoring within Sightline |
| Agentic AI Trust Management | AI agent identification and trust scoring, policy-based agent access controls, agentic commerce governance SaaS | Model alignment and AI safety (AI-company budgets), hardware-level secure enclave spend | Platform architects, trust & safety leads / Emerging shared security + engineering budget | New and growing — AgenticTrust module, AWS Bedrock integration |
| Adjacent Substitutes (Out-of-Scope Spend) | CDN-native bot management (Cloudflare, Akamai), WAF platform security bundles, in-house fraud rule engines and data-science teams, RASP, authentication overlay vendors (Arkose Labs, etc.) | — | Platform infrastructure teams, NOC/SOC / IT infrastructure budget | Displacement risk for portions of core market; not directly addressable |
Boundary definitions are HUMAN-product-anchored; adjacent substitute spend is excluded from SAM calculations but is presented here to document competitive displacement risk. Included spend categories are sourced from company documentation, MRC accreditation letter, and Forrester Wave evaluation criteria. Not all included spend is publicly quantified by independent analysts at the sub-category level.
[CM001, CM037, CM028, CM029, CM038, CM039]2.2 Market Sizing: TAM, SAM, and SOM Across Multiple Lenses
Market sizing for HUMAN's served market requires combining estimates across multiple analyst categories because no single published report matches its product boundary. The bot mitigation market is sized at $0.9 billion (2025) growing to $1.12 billion in 2026 at a 24.8% CAGR (Business Research Company), while Fortune Business Insights pegs the slightly broader "bot security" category at $1.05 billion (2025) and $1.27 billion (2026) at a 20.55% CAGR. Both estimates reach $2.4–$5.67 billion by 2030-2034. An outlier from MarkWide Research places a broader "bot mitigation" market at $3.8 billion in 2026 using a wider scope that may include adjacent WAF/CDN security spend. On the ad fraud side, Fraudlogix measured a 20.64% global IVT rate across 105.7 billion impressions in 2025, implying roughly $37 billion in US programmatic ad spend exposed to invalid traffic annually at the 23.69% US-specific rate. This is the potential fraud loss, not a vendor market size; vendor revenue for SIVT mitigation is a fraction of fraud exposure. Pixalate's Q1 2026 benchmarks confirmed a 24% US desktop IVT rate, 32% mobile app, and 24% CTV—rates that reinforce persistent demand for accredited SIVT vendors. For account takeover protection, Global Growth Insights estimates a standalone $7.46 billion market in 2026 at 18.89% CAGR. The eCommerce FDP broad market is projected at $88.77 billion in 2026 (BFSC) and the all-verticals fraud detection market at $40.4 billion (Grand View Research), but these include payment fraud, KYC/KYB, AML, and identity proofing that HUMAN does not directly serve—making them overstatements of the relevant TAM. An analyst-synthesized SAM for HUMAN is approximately $1.5–$2.0 billion in 2026, constructed as the sum of bot security ($1.27B) plus MRC-accredited SIVT vendor spend (estimated $500M–$800M, derived from advertiser spend on verification tools as a fraction of $836B global digital ad spend). This SAM is compressed by Cloudflare bundling for the SMB/mid-market segment. A SOM of $150–$300 million in 2026 is consistent with HUMAN's Forrester Wave leadership position, quadrillion-interaction network scale, and a realistic 10–20% penetration of the constrained SAM, but this estimate has no independent validation because HUMAN does not disclose revenue. [CM002, CM003, CM004, CM005, CM006, CM007]
| Publisher | Year | Geography | Market / Scope | Value (2026) | CAGR | Methodology | Confidence | Limitation for HUMAN Sizing |
|---|---|---|---|---|---|---|---|---|
| Business Research Company | 2026 | Global | Bot Mitigation | $1.12B | 24.8% | Demand-side; web, mobile, API bot mitigation tools and services | Medium | Narrower than HUMAN's full scope (excludes SIVT, ATO); may understate SAM |
| Fortune Business Insights | 2026 | Global | Bot Security | $1.27B | 20.55% (2025-34) | Demand-side; includes behavioral analytics, AI-driven detection platforms | Medium | Scope may include adjacent WAF/CDN security; North America = 38% share |
| MarkWide Research | 2026 | Global | Bot Mitigation (Broad) | $3.8B | ~18% | Supply+demand aggregation; broader boundary may include integrated WAF/CDN security | Low | Boundary inflation likely; compare with $1.12B from TBRC for same year—source-to-source gap of 3.4x |
| Fraudlogix | 2026 (data 2025) | United States | Programmatic Ad Spend Exposed to IVT (proxy for ad fraud scale) | $37B exposed | N/A | Impression-based; 23.69% IVT × $156B US programmatic spend (est.) | Medium | Measures fraud exposure, not vendor market; SIVT vendor revenue << $37B |
| Business Research Company | 2026 | Global | eCommerce Fraud Detection & Prevention | $88.77B | 20.8% | Broad e-commerce vertical; includes payment fraud, chargebacks, KYC | Low | Scope 70-80x wider than bot-only market; not directly comparable to HUMAN SAM |
| Grand View Research | 2026 | Global | Fraud Detection & Prevention (All Verticals) | $40.4B | 18.1% (2026-33) | All-vertical FDP including AML, KYC, payment fraud, identity proofing | Low | Includes non-addressable categories for HUMAN; use as ceiling, not floor |
| Global Growth Insights | 2026 | Global | Account Takeover Protection | $7.46B | 18.89% (2026-35) | Demand-side; ATO-specific platforms, credential protection, session security | Medium | ATO is one component of HUMAN's suite; full market >= HUMAN's ATO-related SAM |
| Analyst Synthesis (this report) | 2026 | Global | HUMAN SAM (Bot Security + SIVT Vendor Market) | $1.5–$2.0B (est.) | ~20% | Bottom-up: $1.27B bot security + est. $500M–$800M MRC-accredited SIVT vendor spend; pre-bundling haircut | Low | No independent source validates this exact boundary; subject to 20-40% downward revision for Cloudflare-covered market |
Analyst estimates reflect different market boundaries and must not be summed or compared directly. Values are in USD. CAGR figures are as reported by each publisher. The analyst synthesis row (bottom) is this report's estimate and does not represent a primary source; confidence is deliberately Low. MarkWide Research's $3.8B estimate diverges 3.4x from TBRC's $1.12B for the same year and geography, illustrating scope ambiguity.
[CM002, CM003, CM005, CM007, CM008, CM009]| Source | Estimate (2026) | Key Scope Inclusions Beyond HUMAN's Product | Implied Discount to HUMAN SAM | Diligence Implication |
|---|---|---|---|---|
| TBRC — Bot Mitigation | $1.12B | None significant; closely aligned with HUMAN's bot defense scope | ~0% (baseline) | Most conservative and scope-aligned estimate; use as floor for SAM |
| Fortune BI — Bot Security | $1.27B | Possibly includes some WAF/CDN-adjacent security; North America is 38% | ~0-5% | Slightly broader scope; most cited analyst estimate for this chapter's analysis |
| MarkWide Research — Bot Mitigation (Broad) | $3.8B | Likely includes integrated WAF/CDN security bundles; scope not clearly defined | ~50-70% discount to isolate pure bot defense | Outlier vs. TBRC/FortunBI for same period; treat as upper ceiling scenario only |
| Global Growth Insights — ATO Protection | $7.46B | ATO-specific platforms; includes identity proofing and biometric layers outside HUMAN's scope | ~40-60% discount to isolate HUMAN-relevant ATO spend | Use as reference for ATO sub-market adjacent to Sightline; do not add to bot market without boundary reconciliation |
| Grand View Research — Fraud Detection & Prevention | $40.4B | AML, KYC/KYB, payment fraud, chargebacks, identity verification, and compliance reporting | ~97% discount to reach bot-only market | Represents overall risk-management addressable market; HUMAN's share is small; illustrates category inflation risk in investor materials |
| BFSC — eCommerce Fraud Detection & Prevention | $88.77B | Payment fraud, chargeback management, refund abuse, account fraud, KYC for e-commerce onboarding | ~99% discount to reach bot-only market | Most inflated boundary; risk of benchmark misleading if cited without boundary disclaimer |
Discount estimates are qualitative analyst synthesis based on known scope differences; no primary source independently validates the split between HUMAN-relevant and non-relevant spend within each estimate. 'Implied Discount' is an approximation to illustrate scale of scope inflation, not a precise calculation. Preserve this table when presenting to investors to pre-empt over-reliance on the largest estimates.
[CM007, CM008, CM009, CM012, CM035, CM036]Three-layer market pyramid showing the range from broad fraud prevention TAM to HUMAN's estimated served market (SAM) and realistically achievable share (SOM) in 2026.
TAM figure is the broadest commonly cited estimate and includes non-HUMAN segments; the bot-mitigation-only TAM of $1.12-1.27B is more defensible. SAM and SOM are analyst-synthesized estimates with no primary-source validation. SOM range is $150M-$300M; midpoint $220M used.
[CM002, CM003, CM008, CM009, CM010, CM011]Low/base/high estimates for the bot security market and HUMAN's SAM under different boundary assumptions, all expressed in $B for 2026, illustrating the scope-sensitivity of published estimates.
All values in USD billions. Cloudflare-adjusted SAM row is this report's construction and has no independent primary source. Broad/all-FDP row is indicative only; HUMAN does not compete in most of that market. Unit consistency: all rows use $B (2026 estimate).
[CM002, CM003, CM009, CM035, CM036]2.3 Buyer, User, and Payer Segmentation
HUMAN's buyer landscape is segmented by product line and underlying job-to-be-done. For bot mitigation and ATO defense (Bot Defender + Sightline), the primary buyers are application security engineers and fraud operations teams at e-commerce, travel, and financial services companies. Budget typically sits within IT Security or Risk/Compliance and is owned by the CISO or CTO. Adoption triggers include a post-breach incident, detection of checkout fraud or scraping attacks, or a competitive intelligence threat from inventory scraping. HUMAN's own 2026 benchmark report found that retail and e-commerce topped all verticals for scraping (70% of all observed attacks), carding, and ATO attempts, with over 440,000 unique threat profiles targeting the sector—more than four times the next-highest vertical. For ad fraud/SIVT defense (MediaGuard/Ad Integrity Suite), the buyer profile shifts to ad operations directors, chief media officers, and programmatic trading teams at advertisers, agencies, DSPs, SSPs, and publishers. Budget ownership moves to the marketing P&L. Adoption is often compliance-driven: MRC accreditation mandates for impression counting, TAG certification requirements for supply chain participants, or agency holding-group standards mandating independent IVT measurement. HUMAN's 2026 MRC re-accreditation for both its pre-bid Ad Fraud Defense and post-serve Ad Fraud Sensor platforms across desktop, mobile, and CTV reinforces its standing as a certified vendor in this segment. A third and emerging segment is agentic AI trust management (AgenticTrust/Sightline), where buyers are platform architects, trust and safety leads, and "agentic commerce" product owners at companies deploying or receiving AI-agent traffic at scale. This buyer is newer, with budgets not yet fully allocated, and the category itself was renamed by Forrester only in 2025 ("Bot and Agent Trust Management Software") to reflect the shift. HUMAN's support for Amazon AWS Bedrock AgentCore browser verification signals a partnership-driven go-to-market for this segment. The payer here may be a combined security-and-platform engineering budget rather than the traditional CISO owner. EXTE's March 2026 integration of HUMAN's MediaGuard illustrates the partner/platform buyer: a programmatic advertising company integrating HUMAN's solution as a supply-quality layer—payer is the platform, user is the advertiser downstream. Global cybersecurity budgets are rising to $240 billion in 2026 (12.5% YoY per Gartner), with 40% of enterprise security budgets allocated to software and platforms where HUMAN competes. [CM015, CM016, CM017, CM018, CM019, CM020]
| Segment | Primary Buyer | User | Payer / Budget Owner | Workflow Served | Key Adoption Trigger |
|---|---|---|---|---|---|
| Programmatic Ad / Media / Ad-Tech | CMO, Ad Ops Director, Head of Programmatic | Programmatic traders, DSPs, SSPs, publishers | CMO/CFO via marketing tech stack / media P&L | Pre-bid IVT filtering, post-bid reporting, TAG/MRC compliance, Page Intelligence analytics | MRC accreditation mandate, TAG certification requirement, agency holding-group standard, ad fraud complaint from advertiser |
| E-Commerce & Retail | VP Engineering, Head of Fraud, Application Security Lead | Security engineers, fraud analysts, product teams | CISO/CTO / IT Security or Risk budget | Scraping defense, carding prevention, checkout ATO, inventory skewing mitigation, bot performance impact | Post-breach response, checkout fraud spike, competitive scraping detected, bot-driven latency incident |
| Travel & Hospitality | VP Product, Head of Trust & Safety, CISO | Platform engineers, customer experience teams | CTO/CRO / Platform engineering budget | Inventory scraping, fake review injection, ATO on loyalty accounts, fraudulent booking chains | OTA scraping disruption, loyalty ATO spike, performance degradation from bot traffic (>50% on login pages per HUMAN case study) |
| Media & Streaming | Chief Compliance Officer, Ad Ops Director | Security engineers, ad ops, content teams | CMO + CISO / Marketing + Security shared budget | AI scraper control, content protection, ad revenue fraud, AI-agent-driven traffic classification | AI scraper surge targeting content (41% of AI scraper targets), ad fraud complaint, viewability/IVT audit failure |
| Financial Services | VP Information Security, Fraud Risk Officer, CISO | Security engineering, fraud analytics, compliance teams | CISO + Chief Risk Officer / Compliance/Risk budget | ATO detection, credential stuffing, account opening fraud, API abuse, synthetic identity signals | Regulatory requirement (PSD2, NIST, OCC), ATO incident, credential breach, PCI-DSS audit finding |
| Agentic AI / Platform Operators | Platform Architect, Head of Trust & Safety, Product Security Lead | Developers, AI-product managers, trust teams | CTO / Engineering or emerging 'AI Governance' budget | AI agent identification, trust-scoring, policy-based access controls for agentic commerce | AI-agent traffic surge on platform, AWS Bedrock or similar agentic platform adoption, agentic fraud incident |
Buyer personas and workflow descriptions are synthesized from HUMAN Security case studies, Forrester Wave evaluation context, and HUMAN's 2026 State of AI Traffic report. Budget ownership varies by deal size and organizational maturity; dual-budget (CISO + CMO) deals occur in media companies with both ad fraud and security exposure. 'Payer' reflects the organizational unit holding the contract; 'Buyer' is the economic buyer with decision authority.
[CM015, CM016, CM017, CM018, CM019, CM020]Matrix mapping HUMAN Security's five primary buyer segments to budget ownership, key adoption triggers, and competitive substitutes, illustrating the multi-buyer nature of the platform.
Substitute columns reflect dominant competitive alternatives observed in the market; specific deal-level win/loss data for HUMAN is not publicly available.
[CM016, CM018, CM019, CM024, CM040, CM042]Five-stage adoption funnel for an enterprise buyer evaluating HUMAN Security, from initial awareness through expansion upsell, illustrating conversion drop-off and switching friction at each stage.
Funnel values are estimated percentages relative to an indexed baseline of 100 and do not represent HUMAN's actual pipeline conversion rates, which are not publicly disclosed. Percentages are illustrative of the general enterprise security SaaS adoption pattern and are based on industry benchmarks and HUMAN's known go-to-market model.
[CM022, CM023, CM027, CM032, CM033, CM046]2.4 Growth Drivers and Adoption Constraints
The single most potent growth driver is the explosion of automated and agentic traffic. HUMAN's own 2026 benchmark report found automated traffic growing 23.51% year-over-year while human traffic grew only 3.10%—a ratio of roughly 8:1. AI-driven traffic surged 187% in 2025, and agentic AI traffic from agents and browsers grew 7,851% YoY. The category that Forrester renamed "Bot and Agent Trust Management Software" in 2025 reflects a structural expansion of the addressable problem: it is no longer sufficient to classify traffic as human vs. bot; organizations must now govern whether an AI agent can be trusted to transact on a user's behalf. This expansion creates a new TAM layer above traditional bot mitigation where no established incumbent dominates, and HUMAN's AgenticTrust module was designed specifically for this gap. A second driver is regulatory and compliance pressure. TAG awarded 307 certification seals to 196 companies in 2026, with 74% independently audited—signaling that ad industry compliance is tightening beyond self-attestation. MRC accreditation for SIVT detection is increasingly a prerequisite for programmatic platform participation. Regulatory drivers such as PSD2 (financial services), NIST CIAM guidance, and emerging EU AI Act provisions on autonomous system accountability are creating non-discretionary budget lines for bot and agent trust management in regulated verticals. ATO attacks quadrupled in HUMAN's customer base between 2024 and 2025 (averaging 400,000+ post-login compromise attempts per customer per year), driving upsell and cross-sell opportunities within the existing base. Ad fraud losses exceeding $100 billion in 2026 with a 20%+ IVT rate sustain advertiser urgency for verified traffic. The primary constraint is competitive bundling: Cloudflare holds approximately 79% of bot management install share (vs. Akamai's 6%) by providing integrated CDN, WAF, and bot management at flat-rate pricing starting below $400 annually—a package that displaces dedicated bot defense vendors in the SMB and lower-mid market. DataDome's market share fell from 13.8% to 8.9% between 2025 and 2026, potentially reflecting this bundling pressure. A second constraint is ROI proof: bot mitigation savings appear as "fraud losses avoided" rather than revenue—invisible in P&L statements and requiring sophisticated measurement frameworks to justify budget to non-technical stakeholders. A third constraint is switching friction: enterprise bot management integrates deeply into login flows, checkout APIs, and analytics pipelines; migration risk deters switches from incumbents, slowing new logo acquisition. In-house build remains a viable alternative at large platforms with sufficient engineering capacity, further limiting HUMAN's net-addressable market. [CM023, CM024, CM025, CM026, CM027, CM028]
| Factor | Type | Direction | Timing | Implication for HUMAN | Diligence Ask |
|---|---|---|---|---|---|
| Agentic AI traffic growing 7,851% YoY (HUMAN data) | Driver | Strong positive | Current and accelerating (2025-2027) | Expands TAM from bot-only to full agent trust management; new category where HUMAN has first-mover Forrester recognition | Confirm TAM for agent trust management is budgeted separately from bot management or is an upsell/add-on within existing contracts |
| Automated traffic growing 8x faster than human traffic | Driver | Strong positive | Current (ongoing) | Increases urgency across all buyer segments; raises baseline need for behavioral detection beyond simple IP-rate-limiting | Quantify what % of HUMAN's pipeline is driven by net-new bot-problem discovery vs. Cloudflare/Akamai displacement |
| AI-driven traffic up 187% in 2025 with AI scrapers up 597% | Driver | Strong positive | Current | Media and e-commerce buyers face immediate scraper threat; drives cross-sell from bot defense to AI-traffic governance | Verify signal applies to HUMAN's customer verticals, not only its own observed traffic |
| ATO attacks quadrupled in HUMAN customer base 2024-2025 | Driver | Strong positive | Current and accelerating | Upsell opportunity within existing base; cross-sell ATO module to bot-only customers; expands contract value | Confirm ATO growth rate is broad market, not an artifact of improved HUMAN detection coverage |
| Global ad fraud losses >$100B, IVT rate 20%+ in 2026 | Driver | Moderate positive | Persistent | Sustains advertiser demand for MRC-accredited SIVT vendors; supports MediaGuard/Ad Integrity Suite renewal rates | Assess what fraction of HUMAN's SIVT customers are mandated (TAG/MRC-required) vs. discretionary buyers |
| TAG 307 certifications in 2026 (74% independently audited); regulatory pressure (PSD2, NIST, EU AI Act) | Driver | Moderate positive | Building (2024-2028) | Non-discretionary budget lines for bot/agent trust management in regulated and ad-industry verticals | Identify which specific regulations create contractual requirements for HUMAN's products vs. general security awareness |
| Cloudflare dominates bot management install base (~79% share) | Constraint | Strong negative for SMB/mid-market | Present and growing | HUMAN effectively excluded from much of the SMB market; must sell on depth of signal (2,500+ signals/interaction) and specialized accreditation that Cloudflare lacks | Quantify Cloudflare penetration in HUMAN's current customer segments; does HUMAN co-exist or displace? |
| ROI proof is 'invisible savings' (fraud losses avoided) | Constraint | Moderate negative | Persistent | Lengthens enterprise sales cycles; requires trusted measurement methodology; budget approval requires non-technical stakeholder buy-in | Request HUMAN customer ROI case studies verified by third-party; what is average sales cycle length? |
| Deep API/login-flow integration creates high switching costs (both ways) | Constraint | Mixed | Persistent | Protects HUMAN's installed base (high NRR likely) but slows new logo acquisition from incumbent vendors; migration risk deters changes | Obtain NRR and logo retention metrics; what is HUMAN's average customer tenure? |
| In-house fraud teams as build-vs-buy alternative at large platforms | Constraint | Moderate negative (selective) | Present | Limits SAM at large internet companies (Google, Meta, Amazon) with sufficient ML engineering; HUMAN's SAM skews to mid-large enterprises without in-house capability | Identify win/loss record against in-house build decisions; what engineering headcount threshold correlates with in-house preference? |
Directions are assessed relative to HUMAN's revenue opportunity. 'Timing' is qualitative. Driver/constraint categorization reflects the dominant expected effect; some factors (e.g., switching costs) have mixed implications depending on whether HUMAN is the incumbent or the challenger in a given account.
[CM021, CM025, CM026, CM027, CM028, CM030]2.5 Sizing Gaps, Contradictory Estimates, and Diligence Asks
Three structural gaps prevent a definitive market size from being established. First, HUMAN Security does not disclose revenue, ARR, or customer count, making bottom-up SOM estimation entirely reliant on inferred metrics such as Forrester Wave ranking, G2 position, and network scale. Second, the analyst community has not yet independently sized the "agent trust management" sub-market—Forrester renamed the category only in 2025, and no consensus market forecast exists for this segment in 2026. Third, the $1.12B–$88.77B range of market estimates cited in analyst reports reflects boundary inconsistency, not genuine disagreement on fundamentals: the $88.77B eCommerce FDP estimate includes payment fraud, chargebacks, KYC/KYB, and identity proofing that HUMAN does not address, while the $1.27B bot security estimate excludes SIVT vendor revenue. Neither cleanly maps to HUMAN's actual product scope. Contradictory sizing evidence worth preserving: Grand View Research's $40.4B fraud detection market implies HUMAN's market is 30-40x larger than the bot-security-only figure—a discrepancy that reflects scope rather than error. Cloudflare's near-80% install share in bot management is presented by wmtips.com as evidence that HUMAN and other dedicated vendors compete in a niche carve-out within a Cloudflare-dominant market, which would compress the effective SAM well below $1.27B for markets already served by Cloudflare. This constraint does not appear in any of the market research reports sampled, representing a significant gap in published analysis. Any financial model should apply a 20–40% SAM haircut for Cloudflare-served customers as a conservative floor scenario. Diligence asks: (1) Request HUMAN's ARR, NRR, and customer cohort data to validate SOM assumptions. (2) Quantify Cloudflare penetration among HUMAN's target buyer segments to size the addressable residual. (3) Obtain independent sizing of the MRC-accredited SIVT vendor market. (4) Confirm whether the agentic trust management segment is tracking toward a distinct budget line or remains a feature expansion within existing bot-management contracts. [CM012, CM035, CM036, CM045, CM048, CM049]
2.6 Exhibits
03Competitors
3.1 Competitive Landscape Overview
HUMAN Security sits at the intersection of two rapidly evolving markets. In bot and agent trust management, the vendor set spans purpose-built specialists (Kasada, Arkose Labs, DataDome, Netacea, Fingerprint), infrastructure-native players who bundle detection into broader platforms (Cloudflare, Akamai, Imperva/Thales), and the status quo of in-house rule engines and rate-limiting logic that many enterprises still rely on as a first-line filter. In digital ad verification, HUMAN's newly launched Ad Integrity Suite (June 2026) enters direct competition with publicly traded DoubleVerify ($748M FY2025 revenue, 14% YoY growth) and Integral Ad Science ($591M revenue), as well as the full-funnel GTM security platform CHEQ. The Forrester Wave: Bot and Agent Trust Management Software Q2 2026 evaluated eight vendors and renamed the category from "Bot Management" to "Bot and Agent Trust Management," signaling that the competitive frontier has shifted from detecting automated traffic to governing trust for legitimate AI agents. HUMAN and Kasada were both named Leaders; Netacea was a Strong Performer. Cloudflare and Akamai were not evaluated in the Wave, as their offerings remain adjuncts to edge/CDN platforms rather than purpose-built bot intelligence products. The most important structural dynamic shaping competition is the proliferation of agentic AI: HUMAN's 2026 benchmark data shows AI-driven traffic grew 187% in 2025 alone, with agentic browser traffic up 7,851% year-over-year, meaning the traditional "bot or not" binary is obsolete and purpose-built trust management platforms have a structural advantage over legacy WAF and CDN-based detection. [CP001, CP002, CP003, CP004, CP005, CP033]
3.2 Direct Peer Profiles (Bot and Agent Trust)
Kasada is HUMAN's most direct peer in the Forrester Wave, also named a Leader with the highest possible scores in nine criteria and strong Strategy scores. The February 2026 $20M EQT-led round brings Kasada's total to $64.2M—far below HUMAN's estimated $220M+ raised—but the company claims to protect more than $150 billion in eCommerce revenue, a formidable proof point for enterprise procurement. Notably, more than 85% of Kasada customers previously used another bot mitigation provider, implying high win-rate in competitive displacement. Kasada differentiates on server-side, CAPTCHA-free detection and a reported 250%+ ROI. Arkose Labs ($114M raised, Series C in 2021) occupies a distinct niche with challenge-response gamification that deliberately frustrates bot operators through interactive puzzles rather than passive behavioral analysis. Adobe is a named enterprise customer. Arkose holds 5.0% mindshare in the PeerSpot Bot Management category as of June 2026, up from 2.8% the prior year—a sign of growing enterprise recognition despite a smaller scale. DataDome ($82M raised, $36M ARR 2024) focuses on e-commerce and media with rapid edge-ML detection, serving 300+ enterprises including Rakuten, Reddit, and AngelList; its revenue almost doubled from $16.9M to $36M from 2023 to 2024. Fingerprint differentiates on device intelligence rather than full-stack bot management—its platform identified over 1 billion unique devices per month in 2026, achieved 65% ARR growth, serves 2,000 customers with 128% NRR, and added Booking.com as a customer. Netacea ($29.7M raised, $55.9M valuation) differentiates on a fully managed server-side service model where Netacea handles detection configuration and tuning on behalf of the customer, receiving a Strong Performer rating in the Q2 2026 Forrester Wave with top scores in web and LLM scraping management. In PeerSpot's June 2026 Bot Management category, Imperva leads mindshare at 15.7% and Akamai holds 9.7%, both above HUMAN's 8.1%, though the incumbent positions reflect install base more than pure-play bot intelligence capability. [CP008, CP009, CP010, CP011, CP012, CP013]
| Competitor | Category | Founded | Total Funding | Key Customers / Proof | Target Segment | Key Differentiator | Limitation |
|---|---|---|---|---|---|---|---|
| HUMAN Security | Bot defense + ad verification | 2012 | ~$220M est. | Global brands, ad platforms, media | Enterprise | Quadrillion-scale behavioral network; Satori threat takedowns; agentic trust | Higher price point; humansecurity.com blocks crawlers, limiting public pricing evidence |
| Kasada | Bot defense + agentic AI trust | 2014 | $64.2M | Global enterprises, retail, airlines | Mid/large enterprise | Server-side detection; CAPTCHA-free; 250%+ claimed ROI; Forrester Wave Leader Q2 2026 | Smaller team and brand vs. HUMAN; limited public ARR disclosure |
| Arkose Labs | Bot defense + ATO | 2013 | $114M | Adobe, banks, gaming platforms | Mid/large enterprise (gaming, fintech) | Challenge-response gamification; dedicated ATO prevention | Challenge creates friction; web-focused; last major raise was 2021 Series C |
| DataDome | Bot protection | 2015 | $82M | Rakuten, Reddit, AngelList | E-commerce, classifieds | Real-time edge ML; rapid deployment; $36M ARR 2024 | Smaller scale vs. HUMAN; primarily web/API, limited agent trust coverage |
| Fingerprint | Device intelligence | 2012 | $77M | Booking.com, Dropbox, checkout.com | Fintech, e-commerce, SaaS | 1B+ device IDs/month; 128% NRR; Authorized AI Agent Detection; 65% ARR growth FY2026 | Not full-stack bot management; complement to rather than substitute for HUMAN |
| Cloudflare Bot Management | CDN + bot detection (bundled) | 2009 | Public (NYSE: NET) | Any enterprise on Cloudflare | All segments (bundled in edge contract) | Edge-integrated; near-zero marginal cost for existing customers; ML bot scoring | Enterprise-only add-on; less specialized analytics; no behavioral signal network |
| Imperva / Thales | WAF + bot protection | 2002 / acq. 2023 | Public (Thales parent) | Banks, compliance-heavy enterprise | Enterprise compliance (PCI DSS 4.0) | 700+ behavioral dimensions; strongest mindshare in Bot Mgmt (15.7% PeerSpot Jun 2026) | High setup cost; Thales acquisition adds integration risk; less agentic AI roadmap |
| Akamai Bot Manager | CDN + bot protection | 1998 | Public (NASDAQ: AKAM) | Global enterprises, e-commerce | Large enterprise / DevOps-heavy | Edge pre-origin filtering; CI/CD integration; second-highest mindshare (9.7% PeerSpot) | Less specialized vs. pure-play vendors; customer setup complexity noted |
| DoubleVerify (DV) | Ad verification | 2008 | Public (NYSE: DV) | Top brands, agencies, publishers | Ad ecosystem (agencies, DSPs, SSPs) | 67% market share in ad fraud detection; $748M FY2025 revenue; 109% NRR | Not a full bot management platform; limited application/API fraud coverage |
| Integral Ad Science (IAS) | Ad verification | 2009 | Public (NASDAQ: IAS) | Top brands, agencies | Ad ecosystem | Brand safety, programmatic measurement; $591M TTM revenue Q1 2026 | Lower market share vs. DV; 167 tracked customers vs. DV's 4,324 |
| CHEQ | GTM security + ad fraud | 2016 | Private | Enterprise + SMB performance marketers | Performance marketing / GTM teams | 6T signals/day; 0.009% false positive rate; SMB-accessible via ClickCease/Essentials | Less known for enterprise application security; lighter bot mitigation depth |
| Netacea | Bot management (managed service) | 2015 | $29.7M | Global retail, media, travel | Enterprise (managed service preferred) | Fully managed; highest Forrester scores in LLM scraping and transaction assurance Q2 2026 | Small funding base; limited global brand vs. HUMAN; managed model limits enterprise DIY |
Funding figures from Tracxn, Crunchbase, and company press releases; represent total funding raised across all rounds. HUMAN Security total funding is an estimate based on publicly disclosed rounds; exact figure not confirmed. Mindshare percentages from PeerSpot June 2026. ARR figures from GetLatka and company disclosures (DataDome ARR as of Oct 2024).
[CP005, CP008, CP011, CP013, CP017, CP019]Ordinal positioning of key bot management and agent trust vendors on two axes: Detection Depth (sophistication of behavioral signal network and threat intelligence, 1=low to 10=high) vs. Platform Breadth (scope of use cases covered beyond bot detection, 1=narrow to 10=broad). Scores are evidence-backed ordinal judgments derived from Forrester Wave Q2 2026 evaluations, PeerSpot mindshare data, and company product disclosures as of June 2026.
Ordinal scores are analyst judgments based on public evidence, not audited capability benchmarks. Cloudflare, Akamai, and Imperva scores reflect their bot management products only, not their full security platform breadth. DoubleVerify and IAS are included for orientation but compete primarily in ad verification rather than bot management.
[CP005, CP006, CP012, CP022, CP023, CP037]3.3 Ad Verification and Fraud Measurement Peers
HUMAN's June 2026 launch of the Ad Integrity Suite—combining IVT intelligence, AI-powered brand safety and suitability, and viewability in a single framework—puts it in direct competition with the two dominant publicly traded ad verification platforms. DoubleVerify (NYSE: DV) reported $748.3M in FY2025 revenue, a 14% year-over-year increase, with net revenue retention of 109% and measurement of 9.5 trillion billable media transactions annually. It holds a 67% market share in ad fraud detection tools as tracked by 6sense, with 4,324 tracked customers versus IAS's 167. Integral Ad Science (NASDAQ: IAS) reported $590.67M revenue for the twelve months ending Q1 2026, competing primarily on brand safety and programmatic measurement. Both DV and IAS have deep agency holding company integrations and MRC-accredited measurement, which constitute strong switching-cost moats. HUMAN's differentiation is explicitly cybersecurity-grade fraud intelligence—replacing "black box" keyword signals with explainable, URL-level classifications backed by its behavioral network—and the convergence of security and ad verification into a unified platform that security, ad-ops, and marketing teams can share. AdRoll's Global Head of Supply Platforms praised the suite for transparency and reduced ambiguity, suggesting differentiated positioning even against the dominant DV/IAS pair. CHEQ occupies a complementary niche: it processes six trillion signals per day across one million monitored domains with a claimed 0.009% false positive rate, primarily serving performance marketers and SMBs seeking full-funnel GTM security rather than premium brand-safe inventory measurement. The ad verification space is the highest-strategic-risk competitive vector for HUMAN because DV and IAS have contractual leverage through DSP/SSP integrations that took years to build, and their revenue scale is ~10x–15x HUMAN's estimated ARR, giving them capital to match any HUMAN product innovation in the verification layer. [CP009, CP010, CP033, CP034, CP035, CP036]
3.4 Capability, Pricing, and GTM Comparison
Across the pure-play bot management vendors, all publish custom enterprise pricing with no public rate cards. Cloudflare is the only platform that provides published pricing tiers—its Bot Management is an Enterprise-only add-on bundled into contracts that range from approximately $5,000 to $80,000+ per month. For organizations already using Cloudflare for CDN and WAF, the marginal cost of adding bot management can be near zero, creating a structural disadvantage for pure-play vendors that must justify a separate license. However, Cloudflare's bot detection is less specialized: it provides ML-based bot scoring, JA3/JA4 fingerprinting, and detection IDs, but lacks the behavioral signal depth (one quadrillion interactions per year), adversarial threat intelligence, or agentic trust governance that purpose-built vendors provide. Imperva (Thales-owned) leads PeerSpot mindshare at 15.7% with strong positioning around PCI DSS 4.0 compliance and 700+ behavioral dimensions; Akamai (#2, 9.7%) differentiates on edge-first, pre-origin filtering and CI/CD integration. Both have higher initial setup complexity versus Kasada and HUMAN's SDK/API deployment. On GTM, HUMAN's strongest channel is its deep partnership ecosystem: Forrester specifically cited the breadth and awards of HUMAN's partnership program as a standout, aligned with emerging agentic trust and commerce use cases. Major AI operators including OpenAI and AWS have recognized HUMAN as a trusted solution to verify AI agent traffic, which creates an ecosystem-lock dynamic as agent trust becomes a procurement requirement. Fingerprint's 128% NRR is a strong signal that buyers expand usage after initial deployment, consistent with a land-and- expand motion that differs from Cloudflare's bundle-and-upsell approach. The in-house build alternative—custom WAF rules, rate limiting, device fingerprinting, and ML anomaly detection— remains viable for large tech-native enterprises but requires sustained investment in specialized talent and continuous adversarial evolution that most organizations cannot sustain at HUMAN's pace of threat intelligence updates. Desktop browser tampering techniques doubled year-over-year to 4.4% of identifications in 2025, illustrating the escalating detection complexity that favors vendors with cross-customer behavioral networks over single-enterprise in-house systems. [CP030, CP031, CP032, CP040, CP041, CP042]
| Capability | HUMAN Security | Kasada | Arkose Labs | DataDome | Cloudflare BM | Imperva |
|---|---|---|---|---|---|---|
| Behavioral signal network (cross-customer) | Yes — quadrillion interactions/yr | Yes — server-side telemetry | Partial — challenge analytics | Yes — edge ML per customer | Partial — Cloudflare network signals | Yes — 700+ behavioral dimensions |
| Agentic AI / LLM agent trust governance | Yes — AgenticTrust, granular per-agent permissions | Yes — AI Agent Trust product launched 2026 | Unknown — no public agentic AI product | Unknown — no public agentic AI product | Partial — AI crawler block only | Unknown — no public agentic AI product |
| Device fingerprinting / device intelligence | Yes — device + browser signals | Yes — device telemetry signals | Yes — challenge-bound fingerprinting | Yes — real-time edge fingerprinting | Yes — JA3/JA4 TLS fingerprinting | Yes — full device fingerprinting |
| Ad fraud / IVT detection | Yes — Ad Integrity Suite, Jun 2026 | No — bot defense only | No — ATO/bot focus | No — bot/scraping focus | No — no ad fraud product | No — app security only |
| Threat intelligence and takedown operations | Yes — Satori team; coordinated takedowns | Unknown — no public threat research team | Partial — challenge analytics shared | Unknown — no public threat research | Partial — Cloudflare threat intel feed | Yes — threat intelligence feeds |
| Fully managed detection service | No — customer-configured with HUMAN support | No — platform-driven, low config | No — self-serve with guidance | No — self-serve SaaS | No — self-serve with Solutions Engineering | No — customer-managed with Imperva support |
Capability coverage based on public product documentation, Forrester Wave Q2 2026 evaluation criteria, and company website content as of June 2026. "Unknown" indicates the capability was not publicly confirmed at the time of research. Table reflects presence, not depth of implementation. Agentic AI coverage is evolving rapidly across all vendors.
[CP001, CP003, CP004, CP009, CP010, CP012]| Vendor | Pricing Model | Entry Point (est.) | Enterprise Range (est.) | Pricing Transparency | Key Packaging Note |
|---|---|---|---|---|---|
| HUMAN Security | Custom enterprise SaaS | Unknown — no public pricing | Unknown — no public pricing | Opaque — no public rate card | Sightline Cyberfraud Defense and Ad Integrity Suite sold separately; platform bundle pricing not disclosed |
| Kasada | Custom enterprise | Unknown — no public pricing | Unknown — no public pricing | Opaque — no public rate card | Claims 250%+ ROI; pricing based on traffic volume and use case breadth |
| Arkose Labs | Custom enterprise | Unknown — no public pricing | Unknown — no public pricing | Opaque — no public rate card | Challenge-response SaaS; pricing likely scales with challenge volume |
| DataDome | SaaS subscription | $500–$1,000/mo est. for small sites | $15,000+/mo for enterprise | Partial — some public tier indications | Bot and fraud protection for web, mobile, API; SMB-accessible entry point |
| Fingerprint | Usage-based SaaS | Free tier available | $100–$10,000+/mo based on API calls | Partial — public pricing page for SMB/developer tiers | Device intelligence API; pricing based on identification events per month |
| Cloudflare Bot Management | Enterprise add-on to CDN contract | $5,000/mo min (bundled Enterprise) | $5,000–$80,000+/mo depending on footprint | Moderate — enterprise range publicly estimated from procurement data | Bot Management is bundled into Enterprise plan; near-zero marginal cost for existing Cloudflare customers |
| Imperva (Thales) | Custom enterprise | Higher upfront cost vs. Akamai (per reviews) | Custom — higher long-term ROI cited by buyers | Opaque — no public rate card | Full stack WAF + bot; pricing scales with protected traffic and feature depth |
| Akamai Bot Manager | Custom enterprise | Lower setup cost vs. Imperva (per reviews) | Custom — ongoing costs scale with advanced features | Opaque — no public rate card | Often bundled with Akamai CDN/WAF; most cost-competitive for existing Akamai customers |
All custom enterprise pricing is estimated from third-party procurement reports, buyer reviews on PeerSpot and Gartner, and publicly disclosed pricing analysis (Cloudflare). Vendor-published price cards do not exist for HUMAN, Kasada, Arkose, Imperva, or Akamai. DataDome and Fingerprint have partial public pricing based on the developer/SMB tier. Enterprise pricing at all vendors involves contract negotiation and is not auditable.
[CP031, CP032]Qualitative depth assessment (Strong / Moderate / Weak / Unknown) of five strategic capabilities across the six most-evaluated vendors in the Q2 2026 Forrester Wave and adjacent markets. Distinct from the binary coverage table (TP002) by focusing on verified depth and market proof rather than feature presence.
Depth ratings are analyst judgments derived from Forrester Wave Q2 2026 scoring, PeerSpot peer review analysis, and publicly available product documentation. "Strong" requires independent corroboration (Forrester top score, named customer case study, or press release proof point). "Unknown" means no public corroboration of depth was found despite the feature being present.
[CP004, CP006, CP013, CP021, CP037, CP038]3.5 Moat Durability and Displacement Risk
HUMAN Security's primary moat is its behavioral signal network—over one quadrillion interactions analyzed in 2025—which creates a data flywheel that is structurally difficult for any single- customer alternative to replicate. The Satori Threat Intelligence and Research team adds a second moat layer: Forrester noted that HUMAN's coordinated attack takedowns "create impact far beyond its customer base," meaning the team operates as a public-good defense function that reinforces HUMAN's trust brand in ways no single-customer deployment can match. The platform's deep integrations across WAF, CDN, IAM, and Adobe Experience Platform create switching costs that are operational rather than contractual, since unplugging HUMAN requires reconfiguring detection logic across the entire technology stack. However, three displacement risks are material. First, infrastructure bundling: Cloudflare's near-zero marginal cost for bot detection for existing customers will continue to capture cost-sensitive SMB and mid-market segments. Second, competitive intensity at the top: Kasada's 85%-of-customers-from-competitors win rate and the Forrester co-Leader position show that HUMAN's enterprise segment is actively contested rather than defensively dominant. Third, ad verification displacement: DV and IAS have agency-embedded measurement relationships that predate HUMAN's ad offering by over a decade, giving incumbents significant inertia even against a technically superior product. Positive durability signals include HUMAN's declining-but-present PeerSpot mindshare (8.1%, down from 11.6%), which reflects Cloudflare and Imperva gains rather than pure-play specialist displacement, and the Forrester renaming of the category to "Bot and Agent Trust Management" which aligns the market definition with HUMAN's platform investments in AgenticTrust. Post-login account compromise quadrupling year-over-year (402,000 attempts per organization on average) and 250% carding growth since 2022 create structural demand tailwinds that preserve the moat against commoditization, as attack sophistication directly amplifies the gap between behavioral-network specialists and edge-bundled alternatives. [CP001, CP006, CP007, CP041, CP044, CP045]
| Moat Claim | Threat | Severity | Mitigation / Status | Diligence Ask |
|---|---|---|---|---|
| Quadrillion-interaction behavioral data network creates detection advantage | Cloudflare, Akamai, and AWS amass their own aggregate traffic signals at comparable or greater scale | High | HUMAN's signals are enriched by cross-customer attack correlation; raw volume is necessary but not sufficient | Confirm whether HUMAN's detection accuracy benchmarks are independently validated vs. Cloudflare BM on identical attack types |
| Satori Threat Intelligence team produces coordinated takedowns benefiting all customers | Competitors could grow threat research functions or acquire specialist firms | Medium | Forrester cited takedowns as uniquely differentiating; no peer has equivalent public track record | Assess team size, retention, and pipeline of active operations; verify customer NPS attribution to Satori specifically |
| Deep WAF/CDN/IAM/AEP integrations raise operational switching costs | Customers may consolidate onto Cloudflare or Akamai to reduce vendors | High | HUMAN's platform integrations are multi-layer; replacement requires reconfiguring detection across the entire stack | Obtain customer contract terms (typical length, auto-renew, data portability) and churn attribution by reason |
| Partner ecosystem (OpenAI, AWS, Adobe) creates agent trust network effects | Competing agent trust frameworks from hyperscalers could preempt or absorb HUMAN's position | High | Forrester cited HUMAN's partnership program as a standout; hyperscaler partnerships are live signals of early adoption | Confirm exclusivity or co-marketing terms in key AI operator partnerships; assess revenue contribution of partner channel |
| Established behavioral signal network is expensive to replicate from scratch | Well-funded new entrant with hyperscaler backing could build comparable scale within 24–36 months | Medium | No credible new entrant has yet emerged; category requires multi-year data accumulation | Track venture investment into agent trust and bot management startups for signs of well-capitalized new entrants |
| Ad Integrity Suite leverages existing behavioral network for superior IVT detection vs. legacy providers | DoubleVerify and IAS have MRC accreditation, DSP/SSP integrations, and 10+ years of agency trust that HUMAN lacks | High | HUMAN's differentiation is explainability and cybersecurity-grade signals; gaining MRC accreditation is a prerequisite for parity | Assess MRC accreditation timeline and agency holding company adoption rate for HUMAN Ad Integrity Suite |
Severity ratings are analyst judgments based on publicly available evidence as of June 2026. "High" indicates a threat that could materially affect HUMAN's competitive position within 12–24 months. "Medium" indicates a threat that is real but unlikely to materially erode the moat within the near term without significant competitor investment. All diligence asks require non-public company data to answer definitively.
[CP001, CP005, CP006, CP007, CP041, CP044]Compact snapshot of HUMAN Security's competitive durability metrics as of Q2 2026, drawn from independently verifiable public sources. Items mix confirmed metrics, analyst estimates, and chapter-level synthesis; units and sources are explicit.
Mindshare figures from PeerSpot June 2026 (bot management category). Interaction volume from HUMAN's 2026 benchmark report (company-published). Threat profile count from HUMAN Threat Tracker via published benchmark. Kasada win rate from Kasada press release. Fingerprint NRR from BusinessWire press release (fiscal year 2026). DoubleVerify NRR from IR press release FY2025.
[CP001, CP015, CP027, CP028, CP033, CP044]3.6 Exhibits
04Financials
4.1 Revenue Architecture and Pricing Model
HUMAN Security operates a pure subscription SaaS model built around the Human Defense Platform, which integrates three commercial pillars: advertising protection, application security and bot mitigation, and account protection. Revenue is generated as annual enterprise contracts priced on the basis of traffic volume, number of protected assets (web, mobile, API endpoints), and the specific module mix selected by the customer. There is no publicly listed price card; all enterprise pricing is custom and negotiated. The platform monetises through four verifiable revenue streams: (1) advertising/media security (pre- and post-bid fraud, click fraud, malvertising defence via the clean.io acquisition), (2) application security and bot mitigation (the former BotGuard and PerimeterX stack), (3) account protection (credential stuffing, fake account creation), and (4) HUMAN Sightline with AgenticTrust (launched July 2025), which adds AI-agent trust and agentic commerce protection as an emerging fourth stream. The median enterprise annual spend benchmarked by Vendr is $104,906 per year, with a reported range from $46,601 to over $1.34 million for large, complex deployments. Official pricing is therefore a floor proxy for list price, not disclosed realised revenue. Revenue quality is expected to be high given the mission-critical nature of fraud prevention and the high switching costs inherent in deeply embedded platform integrations, but the exact ARR mix by segment is not publicly available. [CI001, CI002, CI003, CI004, CI005, CI009]
| Stream | Mechanism | Unit | Current Status / Value | Revenue Quality | Diligence Ask |
|---|---|---|---|---|---|
| Advertising / Media Protection | Annual SaaS subscription; ad-fraud and malvertising mitigation across programmatic, CTV, mobile | Per traffic volume + module scope | Active; primary historical revenue stream; clean.io expanded malvertising coverage Nov 2022 | High — mission-critical for ad buyers and publishers; high switching cost | Exact ARR contribution vs. application security; publisher vs. brand revenue split |
| Application Security / Bot Mitigation | Annual SaaS subscription; bot defence, scraping, ATO, carding across web / mobile / API | Per protected endpoint and traffic volume | Active; significantly expanded via PerimeterX merger Jul 2022 | High — direct enterprise security spend; deeply embedded in customer infrastructure | Post-merger ARR by legacy HUMAN vs. PerimeterX customers; churn from integration |
| Account Protection | Annual SaaS subscription add-on; credential stuffing, fake account, compromised account defence | Per-platform, usage-tiered | Active; growing segment as identity fraud escalates | Medium-high — upsell motion to existing platform customers; attach rate unknown | Account protection attach rate; incremental ACV per seat |
| HUMAN Sightline / AgenticTrust | Annual SaaS add-on; AI agent trust and agentic commerce visibility and governance | Per platform, agent volume | Launched July 2025; early commercial stage; ~200 customers on solution at launch | Medium — novel product; strong differentiation but limited track record | Early ARR; pricing model for agentic AI traffic; customer uptake rate |
| Public Sector (via Carahsoft) | Government contracts through reseller network; NCPA, OMNIA Partners cooperative vehicles | Per-agency contract value | Active and growing; Carahsoft partnership since November 2022; VP Public Sector Sales hired 2024 | Medium — longer procurement cycles; potential multi-year contract durability | Government contract win rates; public-sector revenue as percentage of total ARR |
| Channel / Partner Revenue | Indirect via HUMAN Advantage Partner Program; co-sell and referral | Partner margin share on new bookings | Nascent; program launched August 2024; no direct or indirect partner-sourced metrics public | Low-medium — early-stage channel; pipeline generation not yet measurable | Partner-sourced pipeline share; partner-attach rate to new ARR |
Revenue mix and ARR contribution by stream are not publicly disclosed. Status and quality assessments are based on company press releases, product announcements, and partner programme documents, not audited financials. Clean.io acquisition terms were undisclosed.
[CI001, CI013, CI014, CI015, CI016, CI017]| Product / Customer Tier | Contract Type | Price per Year (USD) | List vs. Realized | Source |
|---|---|---|---|---|
| Base Bot Defense / Mid-market | Annual SaaS | ~$46,601 (Vendr low end) | Realized benchmark; list price not disclosed | Vendr procurement benchmark (2025) |
| Full Platform Suite / Median Enterprise | Annual SaaS | ~$104,906 (Vendr median) | Likely discounted off undisclosed list price; volume and module-mix driven | Vendr procurement benchmark (2025) |
| Large / Complex Enterprise | Annual SaaS; multi-year available | Up to $1,343,250+ (Vendr high) | Custom negotiated; significant variation by traffic volume, coverage scope, SLAs | Vendr procurement benchmark (2025) |
| Public Sector (via Carahsoft) | Government contract via NCPA / OMNIA cooperative | Custom; below standard list pricing per government procurement norms | Government discount applies; no public rate card | Carahsoft partnership announcement (2022) |
| AgenticTrust / HUMAN Sightline Add-on | Annual SaaS; add-on to existing platform subscription | Not publicly disclosed; new SKU as of July 2025 | Early pricing; unknown list or realized levels | HUMAN official press release (July 2025) |
Pricing data from Vendr represents benchmark spend by Vendr's enterprise buyer network, not HUMAN's published price card. Actual realized pricing will vary by deal size, module selection, traffic volume, and negotiation leverage. AgenticTrust pricing is a newly launched product with no benchmark data available.
[CI009, CI010, CI011, CI012, CI019]How customer digital activity converts to HUMAN revenue through platform detection layers and subscription invoicing.
Node descriptions are qualitative; the exact number of ML models, signal types, and module revenue mix are company-confidential. Relative revenue contribution per module is not publicly disclosed.
[CI006, CI013, CI027, CI028]4.2 Go-to-Market Motion and Sales Efficiency
HUMAN Security has undergone a deliberate GTM transformation from a historically direct-sales-only organisation to a partner-first channel model. Prior to 2024, the company had no formal channel programme and long enterprise sales cycles of six to seven months were common for large accounts due to the need to negotiate legal, MSA, and pricing terms directly. In August 2024, HUMAN launched the HUMAN Advantage Partner Program, a tiered channel initiative with incentives based on annualized bookings, training completion, and customer retention. The program targets resellers, distributors, and advisory partners globally. Separately, HUMAN partnered with Carahsoft Technology in November 2022 as its Master Government Aggregator, enabling public sector access via NCPA, E&I, and OMNIA cooperative contracts. CEO Stu Solomon (appointed January 2024, formerly President of Recorded Future) and CRO Chris Scanlan (formerly President at ExtraHop) are executing the commercial and marketing pivot. The partner-led motion is designed to shorten sales cycles by leveraging embedded partner relationships and pre-existing MSAs, thereby reducing the average deal time and widening addressable pipeline. No partner-sourced pipeline share or quantified CAC/payback data is publicly available. The ecosystem-first approach also enables HUMAN to reach fragmented buyer personas (security, commerce, digital, marketing) without diluting direct sales bandwidth. [CI018, CI019, CI020, CI021, CI022, CI023]
4.3 Cost Structure and Margin Drivers
HUMAN's cost structure is dominated by three categories: (1) ML and data infrastructure for processing over 20 trillion digital interactions per week (over one quadrillion annually as of 2025), representing substantial cloud compute and storage spend; (2) the Satori Threat Intelligence and Research Team, a human-in-the-loop cost centre that conducts proactive threat research and executes takedowns (3ve, Methbot, PARETO, BADBOX 2.0), and which differentiates HUMAN's research-backed detection but adds material personnel cost; and (3) sales and marketing, expanding with the channel programme investment and headcount growth from approximately 197 employees in late 2023 to an estimated 469–519 employees by mid-2026. Gross margin is not publicly disclosed. SaaS cybersecurity benchmarks (Benchmarkit 2024/2025) indicate typical gross margins of 75–85% for pure SaaS models, with downward pressure where significant human-in-the-loop operations exist. HUMAN's Satori team and the scale of its signal collection infrastructure (running on hyperscaler compute at internet scale) may compress margins below median SaaS benchmarks. R&D is estimated at approximately 34% of revenue for private SaaS companies, while sales and marketing typically runs at 47% for VC-backed SaaS companies at HUMAN's growth stage. If HUMAN's ARR is at or near $100M, ARR per FTE of $200–$300K is the SaaS benchmark, suggesting moderate revenue efficiency. [CI006, CI007, CI024, CI025, CI026, CI027]
| Metric | Value / Status | Confidence | Why It Matters | Diligence Ask |
|---|---|---|---|---|
| ARR (company-claimed) | >$100M (company stated; post-PerimeterX merger, reaffirmed Jan 2024) | Medium — company-claimed, not independently audited | Primary indicator of recurring revenue scale | Audited ARR by product segment; definition of ARR (GAAP vs. bookings) |
| ARR (conflicting third-party) | $15M (GetLatka, December 2023; likely reflects pre-merger or incomplete data) | Low — third-party model inconsistent with headcount and merger evidence | Material discrepancy must be resolved before underwriting revenue quality | Independent ARR audit; reconciliation of Latka figure to company books |
| Gross Margin | Not disclosed; SaaS cybersecurity benchmark range 65–85%; Satori team and infra may compress below 75% | Low — benchmark estimate only | Determines scalability of revenue growth and path to profitability | Audited COGS vs. gross profit by product line in data room |
| Net Revenue Retention (NRR) | Not disclosed; SaaS benchmark median 101% (Benchmarkit 2024) | Low — benchmark proxy; no HUMAN-specific data | Quality of expansion ARR vs. churn; critical for platform business valuation | Request historical NRR and GRR by product module and cohort vintage |
| Enterprise Sales Cycle | 6–7 months for large enterprise (company-stated, pre-channel program) | Medium — company-stated in channel interview; post-program not yet measured | Efficiency of new ARR generation; cash conversion cycle | Validated average sales cycle post-HUMAN Advantage Partner Program (Aug 2024) |
| ARR per FTE | $200–$300K (SaaS benchmark proxy at $100M ARR and ~500 employees) | Low — benchmark estimate; actual HUMAN data unavailable | Revenue efficiency relative to headcount investment | Actual ARR per FTE for internal headcount planning and efficiency benchmarking |
All unit economics values are either company-claimed, conflicting third-party estimates, or SaaS industry benchmarks; none are independently verified for HUMAN Security. Gross margin, NRR, and ARR per FTE are benchmark proxies only and may not reflect HUMAN's actual operating model given its hybrid security-intelligence delivery.
[CI003, CI004, CI024, CI025, CI026, CI027]Qualitative cost driver map from platform operations to estimated gross profit; all values are benchmark-based estimates since HUMAN does not disclose unit economics.
All cost nodes are estimates based on Benchmarkit 2024/2025 SaaS benchmarks applied to the company's claimed ARR and public headcount. HUMAN does not disclose gross margin, COGS breakdown, or operating income. Actual unit economics may differ materially.
[CI024, CI025, CI026, CI027, CI028]4.4 Public Financial Traction and Private Metric Gaps
HUMAN Security discloses very limited financial data as a private company. The principal public traction signals are: (1) company-claimed ARR exceeding $100M, first confirmed when the combined HUMAN+PerimeterX entity announced over $100M ARR at the July 2022 merger, and reiterated in the January 2024 CEO transition announcement attributing the milestone to Tamer Hassan's tenure; (2) 500+ global brands served as of October 2024, corroborated across multiple press releases; and (3) platform scale of 20 trillion digital interactions verified per week, and over one quadrillion annually in 2025. A directly conflicting third-party data point exists: GetLatka reported HUMAN ARR at $15 million as of December 2023. This figure is inconsistent with the merged entity's scale, headcount (437+ employees by mid-2024), and the post-merger ARR disclosure. GrowJo's model-based estimate of $140.4M annual revenue is more consistent with the post-merger company. The Latka figure may reflect pre-merger White Ops standalone revenue or a miscalculation; it cannot be resolved without audited disclosure. Net revenue retention, gross revenue retention, customer concentration, and cohort-level ARR data are entirely absent from public sources. [CI002, CI003, CI004, CI005, CI006, CI007]
| Missing Private Metric | Impact on Diligence | Exact Diligence Path |
|---|---|---|
| Exact ARR by product segment (advertising vs. application vs. account vs. agentic) | Cannot assess revenue concentration risk, cross-sell efficiency, or segment margin | Request audited ARR breakdown by product line and historical growth rate per segment |
| Gross margin (GAAP) | Cannot assess cost leverage, infrastructure scalability, or path to profitability | Request GAAP income statement with COGS detail separating cloud infra from professional services |
| Net Revenue Retention (NRR) and Gross Revenue Retention (GRR) | Cannot assess expansion quality, churn risk, or durability of >$100M ARR base | Request NRR and GRR by product module, contract vintage, and customer segment |
| Monthly cash burn and current cash position | Cannot assess runway, next-round trigger, or distress risk | Request CFO cash flow bridge with 12-month forward projection and current bank balance |
| Blackstone Credit $100M debt facility status | Cannot assess true capital structure, covenant risk, or leverage burden | Confirm via term sheet review in data room; request current balance, covenants, maturity date |
| Customer concentration (top 10 customers as % of ARR) | Cannot assess single-customer revenue risk or enterprise contract durability | Request customer concentration analysis; top 10 by ARR, tenure, and renewal history |
All items in this table reflect genuinely unavailable public evidence and represent hard diligence requirements before financial underwriting. The ARR discrepancy between company-claimed >$100M and GetLatka's $15M is an especially urgent first-order gap.
[CI003, CI004, CI031, CI037, CI038]Source-backed low and high bounds for HUMAN Security's key financial metrics; wide ranges reflect the conflict between company-claimed and third-party figures.
All ranges are estimates. ARR range spans conflicting third-party and company-claimed figures. Burn rate, runway, and valuation are inferences. No value in this figure reflects audited financial data.
[CI003, CI004, CI005, CI033, CI034]4.5 Capital Adequacy and Financing Dependency
HUMAN Security has raised approximately $300 million in total equity capital across eight rounds (Tracxn and SiliconAngle, October 2024), including a $100 million growth round in January 2022 (WestCap, NightDragon), and most recently a $50 million growth round in October 2024 (WestCap, Goldman Sachs, ClearSky, NightDragon, Vertex Ventures US). Additionally, in July 2022 HUMAN obtained a $100 million debt facility from Blackstone Credit in connection with the PerimeterX merger, bringing total capital resources to approximately $350 million or more. White Ops filed a Form D with the SEC in June 2014 for its Series A raise, confirming its Delaware incorporation and the earliest equity financing event. The October 2024 round is expressly allocated to: accelerating AI platform capabilities (AgenticTrust and advanced detection models), expanding into the public sector, and strengthening the channel partner programme. With a headcount of approximately 469–519 as of mid-2026 and assuming a fully-loaded cost per employee of $180–$220K per year (senior-heavy tech company), implied annual payroll is $84–$114M. Including cloud infrastructure and G&A, estimated monthly burn is $9–$13 million. Post-October 2024 round, inferred runway at this burn rate is approximately 18–36 months depending on gross margin and revenue growth—extending to late 2026 through 2027. Cash position, exact burn rate, and the current status of the Blackstone debt facility are not publicly disclosed. [CI029, CI031, CI032, CI033, CI034, CI035]
| Item | Amount / Status | Date | Notes |
|---|---|---|---|
| Series A (Form D filed with SEC) | $11.1M equity | 2014 | White Ops, Inc. CIK 0001611028; Delaware incorporation confirmed |
| Series B | $20M equity | 2016 | Led by institutional investors; company scale-up phase |
| Goldman Sachs / ClearSky Investment | Undisclosed; majority stake acquisition | 2020-12 | Merchant banking division of Goldman Sachs and ClearSky; strategic majority investment |
| Growth Round (WestCap / NightDragon) | $100M equity | 2022-01 | Led by WestCap; additional investment from NightDragon and Goldman Sachs; fuelled PerimeterX merger |
| Blackstone Credit Debt Facility | $100M debt | 2022-07 | Provided at time of PerimeterX merger; repayment status not publicly confirmed as of 2026 |
| Growth Round (WestCap / Goldman / ClearSky / NightDragon / Vertex) | $50M+ equity | 2024-10 | Led by WestCap; use of funds: AI platform, public sector, channel programme |
| Total Capital (equity + debt) | ~$350M estimated | Through Oct 2024 | ~$300M equity per company disclosure; $100M Blackstone debt additional; some round overlaps possible |
| Estimated Monthly Burn | $9–$13M/month (inferred) | 2026 | Based on ~500 employees at $180–220K fully-loaded; cloud infra and G&A additional; private |
| Estimated Runway (post-Oct 2024 round) | 18–36 months (inferred to late 2026 – mid 2027) | 2026-06 | Dependent on revenue growth and gross margin; burn rate is private; requires diligence confirmation |
Exact cash position, burn rate, and the repayment or extension status of the $100M Blackstone Credit facility are not publicly disclosed. Monthly burn and runway estimates are inferred from publicly available headcount data and industry compensation benchmarks; actual figures may differ materially. All inferred fields require data-room confirmation.
[CI029, CI031, CI032, CI033, CI034]Cumulative capital raise history showing equity rounds, debt facility, and strategic purpose of each financing event from 2014 through 2024.
Goldman Sachs acquisition amount and clean.io acquisition price were not publicly disclosed. Blackstone debt facility repayment status is unknown. Total equity raised is approximately $300M per company statement; total capital including debt ~$350M+.
[CI029, CI031, CI032, CI033]4.6 Financial Verdict
HUMAN Security presents a credible SaaS platform business with company-claimed ARR above $100M, a defensible high-switching-cost product footprint, and a Forrester Leader designation in both Bot Management Q3 2024 and the expanded Bot and Agent Trust Management Q2 2026. The October 2024 $50M+ round and total ~$300M in equity financing signal sustained investor conviction. However, the revenue quality, margin path, and capital efficiency story cannot be independently underwritten: gross margin, NRR, exact ARR by segment, burn rate, and cash position are all private. A material discrepancy between the company-claimed >$100M ARR and GetLatka's $15M figure demands independent resolution as a first-order diligence step. The Blackstone $100M debt facility (2022) introduces leverage risk that is not yet reconciled in any public filing. The partner-first GTM pivot is strategically sound but nascent, and its contribution to sales efficiency is not yet measurable from public data. Financial verdict: revenue quality appears strong given enterprise stickiness and platform scale, but margin path and capital intensity remain diligence blockers. [CI003, CI004, CI031, CI036, CI037, CI038]
4.7 Exhibits
05Product & Technology
5.1 Human Defense Platform — Product Lines and Customer Workflow
The Human Defense Platform (HDP) is structured around a unified claim: that digital interactions should be verifiable as legitimate human activity, trusted AI-agent traffic, or confirmed automated threats before they reach the customer's revenue-generating workflows. Customers deploy HDP across three core workflow challenges. First, eliminating invalid traffic (IVT) and ad fraud from programmatic advertising supply chains, where DSPs and SSPs accept bids without validating the underlying traffic. Second, blocking automated abuse targeting web applications, mobile apps, and APIs, including credential stuffing, scraping, transaction abuse, and fake account creation. Third, securing user account journeys from initial registration through post-login financial activity. As of 2026, HDP comprises four named product lines available on the AWS Marketplace and through enterprise contracts: HUMAN Advertising Protection (formerly MediaGuard), safeguarding the programmatic advertising supply chain with pre-bid and post-bid IVT detection; HUMAN Application Protection (formerly Bot Defender), protecting web and mobile applications and APIs from sophisticated bot attacks including scraping, transaction abuse, and fake signups; HUMAN Account Protection (formerly Account Defender), covering the full account lifecycle with pre-login, at-login, and post-login defenses against credential stuffing and fake account fraud; and HUMAN Client-side Defense (formerly Code Defender), enabling control over third-party scripts running in user browsers and supporting PCI DSS 4 compliance obligations. An additional module, BotGuard for Growth Marketing, targets marketing funnel integrity by filtering bot-driven click fraud and fake lead generation. The Sightline Cyberfraud Defense platform, launched July 30, 2025, serves as the unified interface across all product lines, adding AgenticTrust for AI-agent classification and governance and Page Intelligence for AI-driven traffic analytics for marketing teams. The clean.io acquisition in 2022 added real-time client-side JavaScript behavioral analysis for malvertising defense, expanding HUMAN's detection coverage earlier in the attack cycle. HUMAN serves 500+ global brands across media, finance, retail, government, and education verticals.[CE001, CE008, CE009, CE010, CE011, CE012]
| Module / Product Line | Former Name | Target User | Maturity / Status | Key Differentiation | Evidence / Diligence Gap |
|---|---|---|---|---|---|
| Advertising Protection | MediaGuard | DSPs, SSPs, publishers, brands | GA — 14+ years in market | Pre-bid + post-bid IVT; FraudSensor; MRC-accredited viewability (April 2026); TAG certified | Revenue or IVT-reduction metrics not publicly disclosed |
| Application Protection | Bot Defender / BotGuard | E-commerce, fintech, SaaS, enterprise web/API teams | GA — mature, continuously updated | 2,500+ signals, 400+ ML models, sub-2ms verdict; covers scraping, ATO, transaction abuse, fake signups | Independent TPR/FPR benchmarks not published; black-box detection logic |
| Account Protection | Account Defender | Financial services, retail loyalty, gaming, education | GA | Pre-login, at-login, and post-login coverage; device and behavioral signal continuity across full lifecycle | NRR, retention cohort, and account-fraud reduction metrics not public |
| Client-side Defense | Code Defender | E-commerce, regulated industries requiring PCI DSS 4 | GA — launched in current form 2022 | Browser-level script monitoring and enforcement; PCI DSS 4 client-side compliance support | Independent security audit of the product not publicly available |
| AgenticTrust (within Sightline) | New — no prior name | Enterprise digital teams; agentic commerce and AI-agent governance | GA — launched July 2025; AWS Bedrock AgentCore support added 2026 | Cryptographic HTTP Message Signature verification; per-agent permission controls; AWS-native integration | Adoption metrics, agent coverage breadth vs. competitors not disclosed |
| BotGuard for Growth Marketing | BotGuard for Growth Marketing | Performance marketing, affiliate, lead generation teams | GA | Filters fake leads, bot-driven click fraud, and affiliate-code abuse from marketing funnels | Coverage scope and false-positive rate in marketing attribution stacks not independently validated |
Data sourced from AWS Marketplace official listing (June 2026) and SoftwareOne product catalog. Former names reflect the nomenclature restructuring applied when Sightline Cyberfraud Defense launched July 30, 2025. Maturity assessments are derived from public product availability and market tenure, not from internal product-readiness scores.
[CE001, CE008, CE009, CE010, CE011, CE012]| User Job / Threat Scenario | Workflow Without HUMAN | HUMAN Solution Module | Measurable Benefit (Claimed) | Known Limitation |
|---|---|---|---|---|
| Programmatic ad buying; eliminate bot-driven IVT | DSPs accept bids including fraudulent invalid traffic; viewability metrics are inflated by bot impressions | Advertising Protection + FraudSensor (pre-bid and post-bid IVT filtering); MRC-accredited viewability | IVT-filtered impression counts; MRC-validated viewability; reduced wasted ad spend | Sub-2ms insertion adds latency on lowest-latency inventory paths; pre-bid coverage depends on DSP/SSP integration breadth |
| Web application protection; block credential stuffing and scraping | Rate-limiting and CAPTCHA; sophisticated attackers rotate IPs and bypass CAPTCHAs at scale | Application Protection; 2,500+ signals analyzed; Precheck auto-validates ~95% of users; Human Challenge for ambiguous sessions | 95% of legitimate users pass without friction; sophisticated bot campaigns blocked via behavioral and device profiling | Complex rule management for multi-region or custom API configurations; documentation depth cited as improvement area |
| Full-lifecycle account security; prevent ATO and fake accounts | Authentication at login only; post-login anomaly detection is reactive and session-scoped | Account Protection; pre/at/post-login behavioral continuity; device and session history across the account lifecycle | Lifecycle coverage reduces fraud that bypasses single-point login controls; covers fake account creation and compromised account use | No published TPR/FPR benchmarks; outcome metrics (fraud reduction %, chargeback rates) not independently verified |
| Govern AI agents accessing digital properties | No standardized governance; organizations either block all bot-like traffic (blocking legitimate agents) or allow all automation | AgenticTrust within Sightline; classifies agent type and trust level; enforces per-agent permissions; cryptographic verification for AWS Bedrock agents | Enables agentic commerce without opening attack surface; reduces impersonation and excessive agentic scraping | Cryptographic verification limited to agents implementing HTTP Message Signatures; legacy agents without signature support default to behavioral heuristics |
Benefit claims are company-stated or analyst-reported; independent outcome benchmarks are not publicly available. Limitation entries are derived from user reviews (TrustRadius, PeerSpot) and analyst commentary as of June 2026.
[CE006, CE019, CE020, CE033]End-to-end flow from an incoming digital interaction through sensor collection, decision-engine verdict, and differentiated enforcement for humans, bots, and AI agents.
[CE005, CE006, CE019, CE020, CE033]5.2 Core Technical Architecture and Detection Methodology
HUMAN's detection architecture separates into two complementary deployment components: the Sensor and the Enforcer. The JavaScript Sensor (version 9.6.6+ required for AgenticTrust support) is injected into the customer's web property via the HTML head tag and collects device fingerprinting signals, behavioral biometrics, session history, and network characteristics. This client-side signal stream is transmitted to HUMAN's cloud-hosted Decision Engine for real-time analysis. The Decision Engine is the platform's core intelligence layer, processing 2,500+ signals per interaction using 400+ adaptive ML models to produce a verdict—human, bot, or AI agent—in under two milliseconds. Approximately 95% of traffic is auto-validated by the Precheck mechanism without user friction; the Human Challenge is deployed only for interactions whose signal profile is ambiguous. The ML stack includes Profile Deviation Models 2.0 for detecting anomalous post-login behavior, attack profiling for segmenting traffic into distinct behavioral threat profiles, and network attack event detection for assessing the scope and coordinated complexity of in-progress campaigns. HUMAN Threat Tracker surfaces these profiles as actionable intelligence dashboards for security teams. On the enforcement side, HUMAN's Enforcer is available in over 20 integration formats, spanning major CDN and cloud providers (AWS Lambda@Edge, Azure Front Door, Cloudflare, Fastly VCL, Akamai EdgeWorker, Edgio), server frameworks (Nginx, Apache, HAProxy, Envoy, Varnish), language runtimes (Go, Java, .NET Core, Node Express), API gateways (AWS API Gateway, Apigee, Kong), and enterprise platforms (Salesforce). Python, PHP, Ruby, and Akamai ESI are not supported for the AgenticTrust module. FraudSensor, HUMAN's post-bid ad detection component, validates ad impressions after serving to provide supply-path-level viewability rates filtered for bot traffic, forming the foundation of the MRC-accredited Ad Viewability Measurement product.[CE002, CE003, CE005, CE006, CE015, CE016]
| Layer / Component | Role | Key Technology / Specification | Dependencies | Risk |
|---|---|---|---|---|
| JavaScript Sensor (client-side) | Collects device fingerprints, behavioral biometrics, session and network signals from user browsers | JavaScript Sensor v9.6.6+ for AgenticTrust; injected via HTML <head> tag | Requires HTML head-tag access; blocked or degraded by browser ad-blockers and privacy extensions | Privacy-tool proliferation and server-side rendering reduce signal fidelity for a fraction of sessions |
| Enforcer (server-side / edge) | Enforces bot verdicts inline at CDN, WAF, API gateway, or origin; blocks, redirects, or rate-limits confirmed threats | 20+ Enforcer integrations: AWS Lambda@Edge v4.8.0+, Cloudflare v6.12.0+, Fastly VCL v12.3.0+, Akamai EdgeWorker v4.4.0+, F5 BIG-IP v3.1.1+, Nginx, Kong, Azure Front Door v1.2.1+ | CDN/cloud provider availability; API-key management per integration; PHP, Python, Ruby runtimes unsupported for AgenticTrust | Single-provider CDN outage or integration-version mismatch can impair enforcement path; custom runtimes require manual SDK integration |
| Decision Engine (cloud-hosted) | Central AI/ML verdict system; processes 2,500+ signals per interaction using 400+ adaptive ML models; delivers sub-2ms verdicts | Proprietary multi-region cloud stack; Precheck mechanism auto-validates ~95% of traffic; Profile Deviation Models 2.0 for post-login anomalies | HUMAN cloud infrastructure uptime; ML model refresh cadence; data partnership quality | Platform-side incidents directly affect customer protection; model updates can transiently affect false-positive rates |
| Behavioral Signal Network (data foundation) | Training and inference data corpus; provides cross-customer threat correlation; enriches ML models with new attack patterns | 20T+ weekly interactions across 3B devices; 14+ years of behavioral data; supplemented by Satori IOC pipeline | Data partnerships with major ad exchanges, CDNs, and platforms; continuous data-partner agreements | Network effects depend on platform scale; smaller or niche verticals receive proportionally less correlated signal |
| FraudSensor (post-bid ad detection) | Validates ad impressions after serving; filters bot and IVT-generated impressions before viewability calculation | Post-bid detection; supply-path-level signal analysis; MRC-accredited viewability output | Integration with DSP/SSP data pipelines; MRC audit compliance | Post-bid detection captures fraud after cost is incurred; does not prevent fraudulent bids, only validates outcomes |
Architecture details derived from HUMAN technical documentation, AWS Marketplace listing, and SoftwareOne product catalog as of June 2026. Enforcer version minimums are from HUMAN's official AgenticTrust documentation. Risk assessments are analyst-inferred from public architecture disclosures; internal SLA and uptime data are not public.
[CE002, CE003, CE004, CE005, CE015, CE016]Five-layer architecture from behavioral signal foundation to unified product interface, showing how Sensor, Enforcer, Decision Engine, and Satori intelligence interlock.
Layer groupings are analyst-derived from public architecture disclosures; internal service boundaries and exact data-flow topology are not publicly disclosed.
[CE002, CE003, CE004, CE007, CE015, CE016]5.3 Satori Threat Intelligence — Research and Disruption Operations
The Satori Threat Intelligence and Research Team is HUMAN's internal threat research unit, led operationally by Lindsay Kaye (Vice President of Threat Intelligence) and overseen by Gavin Reid (CISO). Satori's mandate extends beyond reactive detection: the team investigates, reverse-engineers, and orchestrates coordinated disruption operations targeting large-scale threat actor schemes. This proactive posture—publicly disclosed takedowns that remove criminal infrastructure rather than merely blocking traffic—is the primary differentiator cited in HUMAN's Forrester Wave Q2 2026 top score, where HUMAN was the sole vendor to receive a perfect 5/5 in the Threat Research criterion. Historical disruption operations include: 3ve (a large-scale CPC fraud scheme dismantled in cooperation with the FBI, Google, and Facebook), Methbot (culminating in a 10-year prison sentence for the operator), PARETO (the most sophisticated CTV botnet identified at the time, disrupted with Roku and Google), Scylla (targeting advertising SDKs on Google Play and the Apple App Store), BADBOX 2.0, SlopAds, and Pushpaganda. The most recent major operation is Trapdoor, disclosed on May 19, 2026: a multi-stage scheme fusing malvertising distribution with hidden ad-fraud monetization across 455 malicious Android apps and 183 threat-actor-owned HTML5 domains. At its peak, Trapdoor accounted for 480 million bid requests per day, with associated apps downloaded more than 24 million times before Google Play removed the identified apps. Intelligence from these operations enriches the Decision Engine's ML models and is shared through private-sector and public-sector partnerships, including law enforcement agencies, app store operators, and cloud providers. This feedback loop between field research and product protection represents a technical moat that pure detection vendors cannot easily replicate. Satori also provides real-time event coverage—during Super Bowl LX in February 2026, HUMAN tracked 74 million blocked retail scraping attacks, a 33% rise in invalid bid requests, and a 5% increase in AI agent activity.[CE027, CE028, CE029, CE030, CE031, CE037]
5.4 Deployment, Integration, and Product Roadmap
HUMAN's deployment model is cloud-native and integration-forward. Customers access HDP through direct cloud contracts, the AWS Marketplace, or through channel partners including Carahsoft (federal and public sector distribution). The platform integrates with CDNs, WAFs, CIAM platforms, and analytics infrastructure without requiring rearchitecting of the customer's stack. Deployments range from lightweight Sensor-only implementations (for organizations that need signal coverage without inline enforcement) to full Sensor-plus-Enforcer deployments at the CDN or origin layer. The AWS partnership deepened materially in 2026 when AgenticTrust extended cryptographic verification support to Amazon Bedrock AgentCore traffic. AI agents built on the Bedrock platform are now cryptographically signed and policy-verified through HUMAN's AgenticTrust module, enabling enterprises to enforce granular per-action controls on AI agents operating within AWS-hosted applications. Supported integration targets for AgenticTrust (minimum Sensor version 9.6.6) include AWS Lambda@Edge from v4.8.0, AWS API Gateway from v0.1.1, Cloudflare from v6.12.0, Fastly VCL from v12.3.0, F5 BIG-IP from v3.1.1, and Azure Front Door from v1.2.1. On the standards front, HUMAN open-sourced a reference implementation of the HUMAN Verified AI Agent in November 2025, demonstrating HTTP Message Signatures (RFC 9421) for cryptographic agent identity—implemented via Ed25519 key pairs and the OWASP Agent Name Service (ANS v1.0) naming standard. This positions HUMAN as both a commercial vendor and an ecosystem standards contributor. The April 2026 Agentic Visibility expansion extended Sightline's bot and agent classification data natively into Adobe Experience Platform, making HUMAN the only bot-management vendor with a native Adobe integration for marketing measurement teams.[CE015, CE016, CE018, CE032, CE033, CE035]
| Date / Stage | Feature / Milestone | Status | Implication | Source |
|---|---|---|---|---|
| 2022 H2 | Acquisition of clean.io (anti-malvertising); integration into HUMAN Advertising Protection | Completed | Added real-time client-side JS behavioral analysis for malvertising defense; clean.io covered 125B impressions/month pre-acquisition | aithority.com; darkreading.com |
| July 30, 2025 | Launch of HUMAN Sightline Cyberfraud Defense featuring AgenticTrust; actor-level visibility across humans, bots, AI agents | GA | First unified human/bot/AI-agent trust layer from HUMAN; intent-based governance model replaces binary bot/human detection | knowledgenile.com |
| November 2025 | Open-source HUMAN Verified AI Agent reference implementation; HTTP Message Signatures (RFC 9421); OWASP ANS v1.0 | Released (GitHub) | Positions HUMAN as standards contributor for cryptographic agent identity; demonstrates A2A protocol with Ed25519 keys | github.com/humansecurity/human-verified-ai-agent |
| April 21, 2026 | Agentic Visibility expanded to marketing and commerce teams; native integration with Adobe Experience Platform | GA | Extends Sightline's bot/agent classification data to marketing measurement workflows; Adobe partnership reduces adoption friction | ppc.land; cmswire.com |
| April 27, 2026 | MRC accreditation for Ad Viewability Measurement (display + video; desktop, mobile web, mobile app) | Granted | Industry validation of HUMAN's IVT-filtered viewability methodology; first security-first viewability accreditation in MRC history | ppc.land (MRC accreditation article) |
| 2026 (ongoing) | AgenticTrust cryptographic verification support for Amazon Bedrock AgentCore; policy-compliant AI agents on AWS | GA (rolling support) | Enterprises using AWS Bedrock for agentic workloads can cryptographically verify agent identity; enforces per-action governance policies | itdigest.com |
Roadmap entries sourced from official announcements and third-party news coverage. Forward-looking items beyond June 2026 are not included; no public roadmap document was available from HUMAN as of the research date.
[CE013, CE014, CE032, CE033, CE034, CE035]Directed graph of HUMAN's critical external dependencies spanning cloud infrastructure, enforcement partners, data partners, analytics integrations, and disruption-operation partners.
[CE015, CE016, CE031, CE032, CE033]5.5 Trust, Compliance, Privacy, and Identified Limitations
HUMAN's formal compliance posture is anchored by two external validations in 2026: MRC accreditation for Ad Viewability Measurement (granted April 27, 2026) and active TAG (Trustworthy Accountability Group) certification. The MRC accreditation is notable because HUMAN's methodology integrates FraudSensor IVT filtering directly into viewability calculation—the system counts only human-validated impressions as viewable, a security-first architecture that most pure viewability vendors do not implement. The accreditation covers display and video impressions across desktop, mobile web, and mobile app. The Client-side Defense product explicitly supports PCI DSS 4 client-side requirements by monitoring and enforcing JavaScript behavior policies in consumer browsers. Material limitations exist in the public evidence record. HUMAN has not published independent false-positive or true-positive rate benchmarks under controlled conditions, making it difficult for prospects to compare detection accuracy against competitors on a vendor-neutral basis. The decision engine operates as a "black box" from the customer's perspective: customers receive threat verdicts and attack profiles but have limited visibility into the specific model logic or signal weights. Enterprise customers have reported integration complexity for organizations with bespoke API infrastructure, and documentation depth for custom rule management is cited as an area for improvement. Additionally, HUMAN's Bot Management mindshare on PeerSpot declined from 11.6% to 8.1% year-over-year as of June 2026, suggesting competitive pressure despite strong analyst recognition. Privacy controls rely on standard enterprise SaaS practices. HUMAN's signal network collects behavioral and device data at massive scale; no independent privacy audit or detailed data retention policy has been made publicly available. For customers in regulated industries (healthcare, financial services, EU GDPR scope), the absence of a published independent privacy audit is a diligence gap. SOC 2 Type II compliance is implied by enterprise procurement standards but is not publicly confirmed.[CE034, CE038, CE039, CE042, CE043, CE044]
| Control / Certification | Status (June 2026) | Scope | Gap / Limitation |
|---|---|---|---|
| MRC Ad Viewability Measurement Accreditation | Granted April 27, 2026 | Display and video impressions across desktop, mobile web, and mobile app; covers viewability + IVT filtering (FraudSensor) | CTV viewability MRC extension not confirmed as of June 2026; accreditation covers measurement methodology, not the broader HDP security posture |
| TAG (Trustworthy Accountability Group) Certification | Active — renewed in 2026 recertification cycle | Digital advertising supply chain anti-fraud standards; applies to ad ecosystem partners | Scope limited to advertising vertical; does not cover application protection, account security, or AgenticTrust capabilities |
| PCI DSS 4 Client-Side Compliance Support | Supported by Client-side Defense (Code Defender) | Browser-level enforcement of third-party script behavior policies required under PCI DSS 4 client-side controls | Compliance attestation is the customer's responsibility; no independent HUMAN-issued PCI audit report publicly available |
| GDPR / CCPA Data Handling | Implied by enterprise SaaS standard; no independent audit publicly disclosed | Signal collection and behavioral data processing under EU and US privacy frameworks for enterprise customers | Precise data retention schedules, sub-processor lists, and DPA templates not publicly published; SOC 2 Type II certification not publicly confirmed |
Compliance status derived from official HUMAN announcements and third-party news coverage. SOC 2 and ISO 27001 certifications are standard for enterprise cybersecurity SaaS vendors but have not been independently confirmed for HUMAN in publicly available sources. Gap entries reflect absence of public evidence, not confirmed non-compliance.
[CE034, CE038, CE039]Analyst-assessed capability maturity across five dimensions for HUMAN's five principal product lines/modules as of June 2026.
Maturity ratings are analyst-derived assessments based on public disclosures, third-party reviews, and analyst reports as of June 2026. They do not reflect internal HUMAN capability scorecards.
[CE001, CE030, CE042, CE043, CE044]5.6 Exhibits
06Customers
6.1 Customer Base Segmentation
HUMAN Security's customer base spans five distinct buying segments aligned to its three-pillar product platform (advertising protection, application/bot defense, account protection). The largest segment by historical revenue is advertising technology: DSPs, SSPs, ad-verification vendors, agency holding companies, and brand advertisers who require MRC-accredited invalid traffic filtration for digital media budgets. LinkedIn (B2B professional network), Sovrn (publisher platform), Madhive (local-media CTV OS), and AdRoll (performance DSP) are named production customers in this vertical. The second segment is programmatic marketplaces and commerce platforms—e-commerce and retail brands requiring Bot Defender and Sightline to stop scraping, credential-stuffing, and ATO attacks. Gartner Peer Insights reviews from $500M–$1B and $10B+ retail accounts describe production deployments for high-heat sneaker releases and multi-brand e-commerce portfolios. The third segment is financial services, where agentic AI traffic doubled month-on-month in May 2026 (HUMAN's own benchmark), driving demand for account-protection and transactional fraud defense. The fourth segment is broader enterprise security teams—organizations protecting web applications, APIs, and mobile channels—who access HUMAN's platform through the channel program (Optiv, serving 73% of the Fortune 100, and Consortium Networks as a managed security concierge). Travel and hospitality is an emerging fifth segment; a Gartner reviewer from a $250M–$500M travel brand describes production use of managed bot defense. Geographic segmentation is predominantly North America and Western Europe, with Tel Aviv R&D and UK commercial presence supporting EMEA. No revenue breakdown by vertical or geography is publicly disclosed. [CU001, CU002, CU003, CU004, CU005, CU006]
| Segment | Primary Buyer/User | Key Use Case | Scale / Revenue Signal | Representative Customers / Partners | Evidence Gap |
|---|---|---|---|---|---|
| Advertising & Adtech | DSPs, SSPs, brand advertisers, agencies | Pre-bid and post-bid IVT detection; MRC-accredited ad fraud defense | Largest historical segment; 500+ global brands claim | Madhive, LinkedIn, Sovrn, AdRoll | No revenue share or account count disclosed |
| E-commerce & Retail | Security engineers, fraud ops, product managers | Bot Defender, ATO prevention, scraping defense, high-heat event protection | Gartner reviews from $500M–$1B and $10B+ retailers | Named accounts in Gartner (anonymous), sneaker retailer example | Production customers not publicly named |
| Financial Services | Fraud teams, application security leads | Account takeover, credential stuffing, transactional abuse defense | Agentic traffic doubled MoM in May 2026 in this vertical (HUMAN benchmark) | Unnamed; no published case studies | Weakest named-proof segment |
| Enterprise Security (via Channel) | CISOs, security architects, IT procurement | Full-platform deployment via Optiv/Consortium Networks managed service | Optiv serves 73% of Fortune 100; Consortium Networks as concierge MSSP | Optiv, Consortium Networks (named channel partners) | No end-customer names from channel disclosed |
| Travel & Hospitality | Application security engineers | Bot mitigation, managed bot defense, DDoS assist | Gartner review from $250M–$500M travel brand (2026) | Anonymous Gartner reviewer | Only one identified customer in this segment |
Segment revenue shares are not disclosed by HUMAN (private company). Scale signals are derived from Gartner Peer Insights reviewer industries, press releases, and MRC-accredited deployment announcements. Financial services entry based on HUMAN's own agentic traffic benchmark data, not named customers.
[CU001, CU002, CU003, CU004, CU005, CU006]6.2 Adoption Trajectory and Scale
HUMAN's most credible adoption signal is the sheer scale of its collective defense network. The company's 2026 State of AI Traffic & Cyberthreat Benchmark Report (released March 26, 2026) reports analysis of over one quadrillion digital interactions in calendar year 2025, while the Gartner Peer Insights company profile (updated February 2026) states HUMAN verifies "more than 30 trillion digital interactions per week across advertising, marketing, e-commerce, government, education and enterprise security." This represents an increase from the 20 trillion per week figure cited at the October 2024 fundraise, suggesting genuine network growth. The company claims 500+ global brands and organizations as customers, a metric that has been consistent in press releases from 2022 through 2026. A meaningful adoption acceleration marker is the exponential growth of agentic AI traffic: HUMAN's platform identified a 7,851% year-over-year increase in AI agent traffic in 2025, and legitimate AI-driven traffic overall grew 187% over the same period, concentrating heavily in retail/e-commerce, streaming/media, and travel/hospitality—HUMAN's three leading customer verticals by volume. Named deployments confirmed through public sources include LinkedIn (integrated May 2024, protecting 1 billion+ member professional network), AdRoll (Oct 2025, first DSP to combine HUMAN pre-bid fraud defense with viewability), Sovrn (long-standing partner, cited in April 2026 MRC accreditation announcement), and Madhive (described by HUMAN CEO Stu Solomon as a "long-standing partner" in June 2025). No ARR growth trajectory, customer count CAGR, or deployment milestone cadence is publicly disclosed for this private company, creating material tracking gaps. [CU007, CU008, CU009, CU010, CU011, CU012]
| Metric | Value | Date | Source | Confidence | Implication | Missing Denominator |
|---|---|---|---|---|---|---|
| Weekly digital interactions verified | >30 trillion/week | 2026-02-17 | Gartner Peer Insights company profile | medium | Network growth: from 20T (Oct 2024) to 30T+ (Feb 2026) | No customer count denominator |
| Annual digital interactions analyzed | >1 quadrillion in 2025 | 2026-03-26 | HUMAN 2026 State of AI Traffic benchmark (newsroom) | medium | Meaningful platform scale; requires HUMAN's own network to be this large | No breakdown by customer segment or product |
| Brands / organizations served | 500+ global brands | 2024-08-21 | HUMAN GlobeNewswire partner program release | low | Repeated in multiple releases but no method disclosed; likely logos not ARR | Unique paying customers vs. logos vs. integrated platforms unclear |
| Monthly devices monitored | 3 billion devices/month | 2024-08-21 | HUMAN GlobeNewswire partner program release | medium | Large device fingerprint; consistent across multiple press releases | No breakdown by product or vertical |
| AI agent traffic growth YoY | 7851% YoY in 2025 | 2026-03-26 | HUMAN 2026 AI Traffic benchmark | medium | Signals greenfield demand for AgenticTrust module; early mover advantage | Percentage based on HUMAN's own platform, not industry-wide |
| LinkedIn: IVT rate detected | <1% of desktop impressions in first 30 days | 2024-06-20 | HUMAN/LinkedIn joint press release (Yahoo Finance) | high | Measurable outcome validating production deployment quality | Single 30-day window; no long-term track |
Metrics are sourced from company-issued press releases and third-party coverage. Confidence ratings reflect source independence and corroboration level. The 500+ brands claim is consistent across releases but unaudited. LinkedIn <1% IVT is a high-confidence claim corroborated by joint press release with a named counterparty.
[CU007, CU008, CU009, CU010, CU011, CU012]Discovery-to-expansion funnel illustrating the conversion path from brand awareness to multi-module production deployment.
Top stage (500+ brands) is company-claimed across multiple 2024 press releases; unaudited. Named production deployments (6) are the publicly verified entries in TU003. Quantified-outcome deployments (3) are those with a published metric (LinkedIn <1% IVT, AdRoll 12ms, Madhive Fraud Free Guarantee). Multi-module estimate (2) is inferred from Madhive and LinkedIn evidence of combined advertising + application surface use; HUMAN does not disclose module attach rates or pipeline counts.
[CU007, CU009, CU015, CU031]6.3 Named Customer Proof
Six named customer or partner deployments are supportable from public evidence as of June 2026. Madhive, the leading local-media CTV operating system trusted by Fox, Scripps, and Hearst, is the strongest case study: in June 2025 Madhive announced a Fraud Free Guarantee powered by HUMAN's MRC-accredited pre-bid and post-bid fraud detection, covering all 30,000+ daily local campaigns averaging under $5,000 per budget. HUMAN CEO Stu Solomon called Madhive a "long-standing partner" in the public announcement, indicating a multi-year production relationship. LinkedIn integrated HUMAN in May 2024, with the deployment detecting less than 1% of desktop impressions as invalid traffic across LinkedIn's publisher network including CTV in the first 30 days—a quantified outcome with an named spokesperson (VP Abhishek Shrivastava of LinkedIn Marketing Solutions). Sovrn, a publisher/advertiser platform, is cited by name in HUMAN's April 2026 MRC viewability accreditation announcement, with MD Jeff Meglio providing a testimonial about "stronger campaign performance" and "more efficient budget utilization." AdRoll became the first DSP to combine HUMAN FraudSensor post-bid measurement with MediaGuard pre-bid technology in October 2025, enabling IVT detection within 12 milliseconds. Consortium Networks CEO Nate Ungerott provided a public testimonial at the August 2024 partner program launch, describing HUMAN as bringing "exceptional value to our customers" for sophisticated fraud defense. Optiv, which serves 73% of the Fortune 100, is named by HUMAN as an "integral ally" channel partner. The Forrester Wave Q2 2026 report additionally notes that "HUMAN's customers compliment the level of detail and attack insight that they receive from the Sightline feature," indicating reference-quality deployments beyond the named set, though without naming specific organizations. [CU015, CU016, CU017, CU018, CU019, CU020]
| Customer / Partner | Segment | Deployment / Use Case | Status | Outcome | Evidence Freshness | Limitation |
|---|---|---|---|---|---|---|
| Madhive | Adtech / CTV local media OS | MRC-accredited pre-bid Ad Fraud Defense + post-bid Ad Fraud Sensor for 30,000+ daily local campaigns | Production (long-standing partner per CEO quote) | Fraud Free Guarantee launched June 2025; credit mechanism for suspect traffic; SOC I/II/III + TAG certified by Madhive using HUMAN tech | 2025-06-04 | Only CEO-level quote as corroboration; no quantified fraud reduction rate disclosed |
| Adtech / Professional networking platform | Pre-bid IVT filtering + post-bid detection for desktop and CTV publisher network (1B+ members) | Production (since May 2024) | <1% IVT rate on desktop impressions in first 30 days; VP Abhishek Shrivastava publicly endorsed | 2024-06-20 | Outcome is from launch window only; no update published in 2025 or 2026 | |
| Sovrn | Adtech / Publisher platform | MRC-accredited HUMAN Ad Viewability Measurement with IVT-filtered viewable impressions | Production (long-standing partner per BI article) | MD Jeff Meglio: HUMAN viewability metrics provide confidence in performance measurement with detailed reporting | 2026-04-27 | Testimonial-level evidence; no campaign-outcome metric disclosed |
| AdRoll | Adtech / Performance DSP | First DSP to combine HUMAN FraudSensor post-bid + MediaGuard pre-bid; 12ms IVT detection across desktop, mobile, in-app, CTV | Production (since Oct 2025) | Speed and coverage outcome: 12ms detection; first integrated dual-layer DSP | 2025-10-28 | Named via PPC Land timeline; no joint press release with AdRoll confirmed |
| Consortium Networks | Enterprise security channel / MSSP | Full-platform resale and managed delivery of HUMAN Defense Platform to enterprise clients | Production (named at program launch) | CEO Nate Ungerott: HUMAN Security will continue to bring exceptional value to our customers | 2024-08-21 | Channel partner testimonial; no end-customer outcomes named |
| Optiv | Enterprise security channel / SI | Strategic resell of HUMAN platform to Fortune 100 accounts via Advantage Partner Program | Production (named at program launch) | Named as "integral ally" by HUMAN head of worldwide partnerships Tuan Nguyen; Optiv serves 73% of Fortune 100 | 2024-08-21 | No specific deployment or customer outcome cited |
Table covers publicly confirmed named relationships only. Production status inferred from duration and CEO-level quotes characterizing relationships as "long-standing." Pilot vs. production distinction cannot be fully verified externally for all entries. Gartner reviewer accounts (retail, travel) are anonymous and excluded.
[CU015, CU016, CU017, CU018, CU019, CU020]Maps customer segments through discovery, procurement, deployment, and expansion touchpoints across HUMAN's three platform surfaces.
Journey stages synthesized from named deployment evidence and channel program disclosures; procurement cycle durations from financials chapter evidence.
[CU016, CU017, CU018, CU019, CU031, CU032]Rates named customer deployments on two axes — evidence quality (corroboration depth) and deployment maturity (production breadth).
Matrix positions are inferred from public evidence quality and deployment scope descriptions. Financial services pilot placement reflects absence of any named customer in that vertical. Exact production scope for Optiv and Consortium Networks end-customers is unknown.
[CU015, CU017, CU018, CU019, CU020, CU021]6.4 Retention and Durability Evidence
HUMAN Security does not disclose NRR, GRR, churn rates, average contract length, or cohort retention for any customer segment—standard for a private company at this stage. Proxy evidence for retention and durability is available from review platforms and partner testimonials. On Gartner Peer Insights (updated through April 2026), HUMAN Sightline Cyberfraud Defense holds a 4.7/5 overall rating with 4.8 on Service & Support and 4.7 on Product Capabilities. One reviewer from a travel and hospitality company ($250M–$500M) rates the managed service 5/5 noting "their managed service is very responsive" and ongoing multi-year collaboration. A reviewer from a 1B–10B USD retail company specifically states "We have a long relationship with Human"—indicating multi-year tenure. A 10B+ retail company reviewer describes HUMAN enabling "a very secure online presence" across "all of our brands"— suggesting enterprise-wide deployment breadth. G2 recognized HUMAN as Best Security Software Product of 2026 (#1 in Bot Detection & Mitigation), a crowd-sourced peer validation. The Forrester Wave Q2 2026 report notes positive customer feedback specifically on attack insight depth, implying reference-quality relationships. One adverse signal: a 3/5 Gartner review from a $500M–$1B retail company describes HUMAN as a "black box"—limited visibility into detection logic, no proactive change notifications, and minimal manual tuning capability. This represents a real procurement friction point and a churn risk for technically-demanding security buyers. Retention signals from the HUMAN Advantage Partner Program (launched August 2024) note the three-tier structure is built around retention as a core metric alongside bookings and training, suggesting management awareness of this dimension, but no retention data is published. Industry benchmark data indicates 35% of cybersecurity vendor churn is attributable to CX rather than product performance, and 42% of cybersecurity customers switched vendors in the past two years— a sector headwind HUMAN's managed-service approach and Gartner 4.8/5 support score is designed to counter. [CU023, CU024, CU025, CU026, CU027, CU028]
| Metric / Signal | Value or Evidence | Segment | Confidence | Diligence Ask |
|---|---|---|---|---|
| Gartner Peer Insights overall rating | 4.7/5 (as of 2026) | Cross-segment (retail, travel, enterprise) | medium | Request verified renewal rate from references; Gartner sample size not disclosed |
| Gartner Peer Insights service & support score | 4.8/5 | Cross-segment | medium | Indicator of managed service stickiness; ask for CS-team:account ratio |
| G2 Bot Detection & Mitigation rank | #1 Best Security Software 2026; prior #1 G2 Summer 2024 Grid | Enterprise cross-segment | medium | G2 reviews are not verified tenure data; ask for median contract age |
| Long-term relationship signal | Gartner reviewer: 'We have a long relationship with Human' (1B–10B retail) | Retail | low | Single anonymous review; not independently verifiable |
| Adverse retention signal | 3/5 Gartner review: product described as 'black box' with no change notifications or tuning visibility | Retail ($500M–$1B) | medium | Black-box perception is a documented churn precursor; ask if HUMAN has shipped detection transparency roadmap |
| Channel retention incentive | HUMAN Advantage Partner tier structure rewards customer retention alongside bookings and training | Channel / enterprise | low | Retention metric targets and actuals not disclosed; <2 years old |
| NRR / GRR | null — not disclosed (private company) | All segments | low | Highest-priority diligence ask; request at or before term-sheet stage |
| Average contract length | null — not disclosed | All segments | low | Request breakdown by SMB channel vs. direct enterprise vs. adtech platform |
NRR and GRR are null because HUMAN Security is a private company that does not disclose these metrics. Gartner Peer Insights and G2 data provide directional satisfaction signals only, not retention proof. Adverse retention signal from Gartner 3-star review is a real procurement friction indicator.
[CU023, CU024, CU025, CU026, CU027, CU028]Comparison of HUMAN Security's G2 and Gartner Peer Insights ratings against bot-management category benchmarks and adverse feedback signals.
Gartner Peer Insights values from the product page updated February–April 2026 (4 reviews visible in the public snippet). Benchmark values are approximate category averages from Gartner's bot/agent trust management market category. G2 rank from February 2026 Best Security Software announcement. Adverse review share approximated from 1 critical review out of 4 visible reviews in the Gartner snippet — actual distribution may differ with full review corpus. This figure substitutes for the planned cohort figure because no time-series customer-retention percentage data is publicly available for this private company.
[CU023, CU024, CU025, CU026, CU027]6.5 Expansion and Concentration Risk
HUMAN's primary land-and-expand motion operates through three vectors: (1) cross-sell from advertising protection into application/bot defense and account protection within the same enterprise account; (2) agentic AI trust (AgenticTrust module within Sightline) as a greenfield upsell driver given the 7,851% growth in AI agent traffic; and (3) the HUMAN Advantage Partner Program launched August 2024, which deploys Optiv and Consortium Networks as channel multipliers under a three-tier structure rewarding annualized bookings, training completion, and customer retention. Strategic technology partnerships that expand addressable accounts include AWS Bedrock AgentCore browser support (cryptographically signed AI agent verification) and the Riskified partnership (August 2026 per RivalSense) for ecommerce fraud prevention via AI Agent Approve and AI Agent Intelligence. Concentration risk is material on two dimensions. First, HUMAN's legacy revenue base is heavily concentrated in digital advertising and adtech—a vertical where DoubleVerify and IAS command much larger market shares and where budget cycles are tied to media spend decisions rather than security budgets, creating sensitivity to macro advertising downturns. The Gartner Peer Insights reviewer base skews toward retail and travel sectors for application defense, but the company's historical brand identity and most public case studies remain ad-tech-centric. Second, no customer count, top-10-customer revenue share, or revenue-by-segment data is available for a private company, making it impossible to quantify concentration from external evidence. The HUMAN Advantage Program's deal registration and incumbency protections are designed to reduce channel conflict and improve account durability, but the program is less than two years old and maturity signals are absent. Procurement friction—6–7 month enterprise sales cycles requiring legal, MSA, and pricing negotiation before direct-sales channel program—has been explicitly acknowledged in prior financial chapter evidence and is a retention-adjacent risk. The channel model launched specifically to reduce this friction via managed onboarding. [CU031, CU032, CU033, CU034, CU035, CU036]
| Driver / Risk | Type | Evidence | Impact | Diligence Path |
|---|---|---|---|---|
| AgenticTrust module upsell | Expansion driver | 7,851% YoY AI agent traffic growth; AWS Bedrock AgentCore support; Forrester Wave highest-score criterion | High — first-mover greenfield expansion within existing customer base | Ask what % of existing Sightline customers have enabled AgenticTrust by mid-2026 |
| HUMAN Advantage Partner Program | Expansion driver (channel) | Launched Aug 2024; Optiv + Consortium Networks named; 3-tier structure; deal registration + incumbency | Medium — less than 2 years old; partner enablement track record unclear | Request partner-sourced bookings as % of total new ARR in FY2025 and H1 2026 |
| MRC viewability accreditation (April 2026) | Expansion driver (adtech) | Sovrn early adopter; AdRoll DSP integration; IVT-filtered viewability is differentiated vs. DV and IAS | Medium — opens viewability budget alongside fraud budgets for same customers | Ask if viewability is bundled or separately priced; attached revenue per account |
| Riskified partnership (ecommerce) | Expansion driver (new vertical) | RivalSense: HUMAN + Riskified partnership Aug 2026 for ecommerce AI Agent Approve and AI Agent Intelligence | Medium — extends reach into merchant/payment fraud buyers not in core adtech base | Verify partnership terms; ask for co-sell pipeline |
| Ad-tech segment concentration | Concentration risk | Majority of public case studies and named deployments in adtech/programmatic; historical brand = 'ad fraud company' | High — ad budgets are macro-correlated; DV and IAS are larger-scale alternatives in same vertical | Ask for revenue breakdown by product line and vertical; flag if >50% from adtech |
| Private company, no customer-count disclosure | Concentration risk (information gap) | Zero public disclosure of top-customer share, revenue by segment, or customer count by cohort | High — impossible to assess concentration without management data room access | Request top-10 customers as % of ARR and vertical breakdown under NDA |
| Enterprise direct-sales cycle friction (6–7 months) | Concentration risk / churn risk | Acknowledged in prior chapter; channel program designed to address; MSA and pricing complexity | Medium — long cycles reduce switching propensity but also create entry barriers for new accounts | Ask if channel program has reduced median sales cycle; target <4 months for mid-market via partner |
Expansion drivers are based on publicly announced partnerships and product launches. Concentration risk is structural (adtech-heavy brand and customer base) compounded by private company opacity. The Riskified partnership date is from RivalSense competitive intelligence and should be independently verified.
[CU031, CU032, CU033, CU034, CU035, CU036]6.6 Exhibits
07Risks
7.1 Regulatory and Legal Risk Landscape
HUMAN Security's core technical capability—collecting and analyzing behavioral fingerprinting signals across more than one quadrillion digital interactions annually—creates a material and growing data privacy surface. The company processes device fingerprints, mouse-movement telemetry, keystroke timing, browser attributes, IP addresses, and cross-property behavioral patterns to distinguish bots from humans. Under 20 U.S. states that now actively enforce comprehensive privacy laws (as of January 2026), plus GDPR in Europe, any misclassification of HUMAN's data as personal-data brokerage or its behavioral signals as regulated data could trigger enforcement. The FTC sent formal warning letters to 13 data brokers under the Protecting Americans' Data from Foreign Adversaries Act (PADFAA) in February 2026, signaling active regulatory surveillance of mass-scale behavioral data vendors. The Department of Justice's Data Security Program (DSP) imposes additional restrictions on bulk cross-border transfers of covered personal data to "countries of concern." HUMAN operates globally and processes data from devices in 222+ countries; any configuration that routes covered data through Israel (where HUMAN has offices and engineering staff) or partnerships with entities with covered-country links requires CISA-compliant security controls. Plaintiffs' attorneys have developed a novel strategy: citing DSP violations as predicates for federal Wiretap Act claims even without a private right of action under the DSP itself, opening adtech data flows to class action exposure. The volume of online privacy lawsuits escalated from approximately 200 cases in 2023 to approximately 4,000 in 2024; the same behavioral tracking technologies HUMAN deploys for fraud prevention are precisely those targeted by plaintiffs. On the positive side, HUMAN earned MRC accreditation for Ad Viewability Measurement in April 2026, demonstrating compliance rigor. The MRC Digital Advertising Auction Transparency Standards were also finalized in January 2026, tightening disclosure requirements for ad auction participants. Critics, including the Check My Ads Institute, argue these self-regulatory frameworks are structurally insufficient—calling for government regulation— suggesting ongoing sector-level regulatory risk even for compliant vendors. As of June 2026, no active regulatory enforcement or litigation directly targeting HUMAN Security is publicly known; the risk is latent but material given the behavioral data scale. [CR001, CR002, CR003, CR004, CR005, CR006]
| Rule / Case / License | Jurisdiction | Status / Maturity | Likelihood (HUMAN) | Severity | Mitigation | Residual Exposure | Diligence Path |
|---|---|---|---|---|---|---|---|
| CCPA/CPRA behavioral data compliance | California (20-state patchwork) | Active enforcement; CPPA fining since 2026 | Medium | High | Privacy-by-design; DPA in place; consent management | Latent; opt-out bypass creates dark-pattern risk | Obtain DSAR procedure; audit consent-management tool chain |
| FTC PADFAA / DOJ DSP cross-border data | Federal (US) | Active — FTC warned 13 data brokers Feb 2026 | Low–Medium | High | Data mapping; CISA security controls; covered-country vendor audit | Medium; Israel office and global data routing require DSP controls | Request cross-border data flow map and DSP compliance certification |
| Wiretap Act class action (DSP predicate theory) | Federal & multi-state | Novel theory; cases filed 2025–2026; untested on adtech vendors | Low | High | Privacy policy disclosure accuracy; web activity pixel audit | Medium; behavioral tracking at HUMAN's scale is a target-class | Review pixel/SDK data sharing with any covered-country entities |
| MRC accreditation compliance | US (voluntary industry) | Accredited April 2026 for Ad Viewability; ongoing audit cycle | Low | Medium | MRC audit program; transparent measurement methodology | Low; recent accreditation reduces near-term risk | Confirm MRC audit schedule and next renewal date |
| Adtech sector self-regulation gap / government intervention | Federal & EU | Latent; Check My Ads Institute and Senate scrutiny of digital ad fraud | Low–Medium | Medium | MRC accreditation; public disruption ops (BADBOX, PARETO) | Medium; legislative risk for mandated independent audits or fee structures | Monitor FASB/FTC guidance on adtech measurement mandates |
Coverage is partial: rows represent material publicly known regulatory risks as of June 2026 based on law firm analyses, regulatory retrospectives, and MRC documentation. Undisclosed litigation, sealed proceedings, and non-U.S. enforcement actions are excluded. Likelihood scores reflect HUMAN-specific exposure, not sector-wide base rates.
[CR001, CR002, CR003, CR004, CR005, CR006]7.2 Operational, Technical, and ML Risks
HUMAN's operational risk profile is dominated by three interrelated dynamics: cloud infrastructure concentration, bot-detection false positives, and an accelerating ML-model arms race. The platform's requirement to process 20+ trillion digital interactions weekly demands massive cloud compute and storage infrastructure, with AWS serving as the dominant public cloud provider. AWS suffered two significant infrastructure failures in early 2026: a March 2026 kinetic attack on UAE data centers that disrupted 38+ and 46+ services in the ME-CENTRAL-1 and ME-SOUTH-1 regions respectively, and a May 2026 thermal event in US-EAST-1 that cascaded across 150+ dependent cloud services. Any equivalent outage affecting HUMAN's primary detection infrastructure would directly impair SLA delivery to 500+ enterprise customers, many of whom rely on HUMAN for real-time fraud prevention at checkout or login. HUMAN has not publicly disclosed multi-cloud or active-active failover architecture details, creating a diligence gap around resilience posture. The false-positive problem is a structural weakness with legal and commercial consequences. Anti-bot systems produce false positives when legitimate users deploy privacy tools—ad blockers, VPNs, Tor, non-mainstream browsers, and anti-fingerprinting extensions. Ad blockers often suppress anti-bot scripts entirely, causing detection systems to classify the session as a bot; VPNs route traffic through shared IPs historically flagged as bot sources. For HUMAN's enterprise customers, false positives drive legitimate user friction, reduce conversion rates, and can trigger chargeback or complaint cycles that damage customer retention. The problem is not unique to HUMAN but shapes competitive dynamics with vendors that offer lower friction-profile detection. The detection arms race is intensifying. Automated traffic grew 23.51% year-over-year in 2025 while AI-driven traffic grew 187% in the same period per HUMAN's own benchmark data. BADBOX 2.0 emerged as a direct evolution of BADBOX 1.0 after HUMAN's original exposure—demonstrating that threat actors iterate quickly when disrupted. DoubleVerify detected 140% more CTV fraud scheme variants in Q1 2026 versus Q1 2025, driven by AI-assisted fraudster tooling. The threat is not static: agentic AI traffic grew 7,851% year-over-year and binary bot/human classification increasingly fails to address beneficial versus malicious AI agent traffic. Fraud signature drift means HUMAN's 400+ ML models must be continuously retrained, and regulatory fragmentation under 20 state privacy laws is now actively constraining data pipeline completeness, degrading model inputs. [CR011, CR012, CR013, CR014, CR015, CR016]
| Failure Mode | Likelihood | Severity | Mitigation Maturity | Residual Exposure | Unresolved Gap |
|---|---|---|---|---|---|
| AWS cloud outage (single-region concentration) | Medium | Critical | Low–Medium | High | No public multi-cloud or active-active failover documentation |
| Bot detection false positives (privacy-tool users) | High | Medium | Medium | Medium | No disclosed FP-rate benchmark in commercial contracts |
| ML model drift from evolving bot evasion tactics | High | High | Medium | Medium | Retraining cycle frequency and cost not publicly disclosed |
| Agentic AI traffic misclassification (trust vs. not) | High | High | Low | High | Binary bot/human models not fully adapted to AI agent governance |
| Data pipeline fragmentation from privacy regulation | Medium | Medium | Low | Medium | No disclosed approach to model retraining under GDPR/CCPA data limits |
| Threat actor iteration (BADBOX 3.0, new supply-chain attack) | High | High | Medium | Medium | Ongoing disruptions require continuous FBI and partner coordination |
Likelihood and severity reflect informed assessments based on publicly reported 2026 cloud outage data, security research, and HUMAN's own threat benchmark report. Mitigation maturity scores are inferred from public disclosures; proprietary resilience architecture, SLA guarantees, and internal DR test results are not publicly available.
[CR011, CR012, CR013, CR014, CR015, CR016]Severity-likelihood-mitigation heatmap for HUMAN Security's five principal risk domains as of June 2026. Agentic AI misclassification and AWS cloud concentration combine high severity with low mitigation maturity, yielding the highest residual exposure.
Likelihood and impact ratings are analyst assessments based on industry benchmarks and public disclosures; internal risk scoring is not available.
[CR001, CR015, CR023, CR040, CR041]7.3 Partner, Platform, and Market Dependency Risks
HUMAN operates within a web of critical partner dependencies that are both competitive and cooperative. The BADBOX 2.0 disruption illustrates the co-dependency structure: HUMAN's Satori team discovered the threat, but actual remediation required Google to update Play Protect and take legal action in federal court, Shadowserver Foundation to sinkhole command-and-control domains, and FBI coordination for public warnings. This public-private model is a competitive moat but also a dependency—HUMAN cannot sinkhole infrastructure independently, and Google's involvement is discretionary. Google is simultaneously a key distribution partner (through Google Play Protect certification), a customer, and a competitor with growing in-house ad fraud detection capability. In the Bot Management market, HUMAN is ranked fifth in mindshare at 8.1% versus Cloudflare at 9.2% (ranked third) per Gartner Peer Insights and PeerSpot. Cloudflare's platform approach bundles DDoS mitigation, WAF, bot management, and API security as a single integrated stack with global edge distribution, while HUMAN offers deeper signal fidelity at the application layer but narrower infrastructure breadth. The ad verification segment has consolidated to a near-duopoly of DoubleVerify and Integral Ad Science as public companies with scale advantages. Large platform vendors—Google, Meta, Amazon— provide in-house fraud detection for their walled-garden inventory, structurally reducing demand for third-party verification on the highest-value impression segments. HUMAN must continuously demonstrate incremental lift over bundled alternatives to justify per-traffic-unit pricing. MRC accreditation, while recently earned, creates a governance dependency: the MRC is a voluntary industry body that critics find structurally under-resourced for enforcement. Loss of MRC accreditation, however unlikely, would impair HUMAN's competitive positioning with media buyers and agency partners who treat accreditation as baseline. The ad exchange integration layer—DSP, SSP, and publisher tech partnerships— also creates concentration risk if a major exchange deprecates HUMAN's SDK in favor of a bundled or competing solution. [CR023, CR024, CR025, CR026, CR027, CR028]
| Dependency | Counterparty | Role | Concentration | Failure Scenario | Severity | Mitigation | Residual Exposure |
|---|---|---|---|---|---|---|---|
| Cloud compute / ML inference | AWS (primary) | Processes 20T+ weekly interactions | High | US-EAST-1 outage during peak traffic event | Critical | Undisclosed resilience architecture; region diversification unknown | High |
| BADBOX botnet disruption (C2 sinkholing) | Google / Shadowserver Foundation | Sinkhole C2 domains; Play Protect enforcement | High | Google deprioritizes disruption or Shadowserver capacity insufficient | Medium | Joint research publication; FBI coordination; co-prosecution | Medium |
| Ad verification ecosystem | DoubleVerify / IAS (competitors) | Market standard-setting; MRC compliance benchmarks | Medium | DV/IAS capture HUMAN's media-security use cases in bundle | High | Differentiation on behavioral signal depth; MRC accreditation | Medium |
| Bot management competitive position | Cloudflare / Google Cloud Armor / AWS WAF | Bundled platform alternative for enterprise customers | High | Enterprise migration to bundled stack reduces HUMAN ARR | High | Deeper behavioral telemetry; Satori threat intel; MAP dataset | Medium–High |
| MRC accreditation governance | Media Rating Council | Accreditation body for ad viewability and IVT measurement | Low | MRC audit failure or governance reform removes accreditation | Medium | Transparent methodology; April 2026 accreditation achieved | Low |
Concentration scores reflect HUMAN's estimated reliance on each counterparty based on publicly available partnership disclosures and product architecture inference. Actual contractual terms, SLAs, minimum commitments, and exit rights are not publicly disclosed. Failure scenarios are illustrative worst cases, not predictions.
[CR023, CR024, CR025, CR026, CR028, CR029]HUMAN Security's critical external dependencies mapped by category: cloud infrastructure, threat intelligence partners, regulatory bodies, and competitive/platform counterparties.
[CR025, CR029, CR030, CR023, CR031]7.4 Financial, Competitive, and Execution Risks
HUMAN's financial risk profile is characterized by deep opacity. The most recently disclosed post-money valuation is $1.5 billion from January 2022—over four years stale and predating the PerimeterX merger, the clean.io acquisition integration, and the October 2024 $50M+ growth round. Market data aggregators (PitchBook, Premier Alts) show no current valuation disclosure. ARR, gross margin, net revenue retention, burn rate, and cash runway are all private. The 2024 round was described by CEO Stu Solomon as "deliberately constrained"—but that framing is unverifiable without independent financial disclosure. Investor-reported ARR of $100M+ (from the January 2024 CEO transition announcement) carries no gross margin or churn qualification; a third-party estimate of $15M ARR (GetLatka 2023) is irreconcilable without audited disclosure. Competitive pricing pressure from bundled-platform vendors is a medium-term model risk. Cloudflare, Google Cloud Armor, and AWS WAF with Bot Control offer comprehensive security stacks at scale with bundled pricing that effectively prices out standalone bot-management spend for enterprises already committed to those platforms. The ad fraud verification market has six or more competing tools including CHEQ, DoubleVerify, IAS, DataDome, and Cloudflare Bot Management, all competing on overlapping use cases. HUMAN's differentiation through the MAP (Media-Acquired Protection) dataset and the Satori threat intel moat is real but not permanently defensible if a platform vendor acquires comparable signal density. Execution risk centers on the January 2024 CEO transition from co-founder Tamer Hassan to Stu Solomon. Solomon brings credible operational experience (Recorded Future, Optiv, iSight Partners) but inherited both the PerimeterX integration and the need to scale a partner-first channel program from a previously direct-sales-only motion. The board is heavily investor-representative with Goldman Sachs, NightDragon, WestCap, and ClearSky as anchor investors, creating governance concentration around investor return timelines. The company has no disclosed path to public markets, and investor holding periods from the 2020 Goldman acquisition and 2021-2022 growth rounds are now entering year five or six, elevating exit-pressure risk. Model drift from agentic AI traffic growth (7,851% YoY) means HUMAN's classification infrastructure must evolve beyond binary bot/human decisions toward trust-or-not judgments in a regime shift that may require material R&D investment. [CR033, CR034, CR035, CR036, CR037, CR038]
| Role / Function | Gap or Dependency | Likelihood | Severity | Mitigation | Diligence Path |
|---|---|---|---|---|---|
| CEO (Stu Solomon, since Jan 2024) | No prior CEO tenure at public company; inherited PerimeterX integration | Low | High | Board continuity; experienced operational team (COO/CFO Itenberg) | Reference checks; assess integration execution track record |
| Satori threat intelligence team (CISO Gavin Reid) | Specialized research team with limited bench depth | Medium | High | Co-develops threat intel with Google, Shadowserver, FBI | Assess key-person risk; team headcount and retention incentives |
| Channel / CRO (Chris Scanlan, since 2024) | Partner program launched Aug 2024 from zero; unproven at scale | Medium | High | HUMAN Advantage Partner Program with tiered incentives | Request partner-sourced pipeline share; CAC/payback period data |
| Board governance (investor-dominated) | Goldman Sachs, NightDragon, WestCap, ClearSky hold majority seats | Low | Medium | Executive Chairman Hassan provides founder continuity | Request board charter; confirm independent director representation |
People/execution assessments are based on publicly disclosed leadership bios and company announcements. Compensation structures, equity grants, retention agreements, and succession plans are not publicly available. Severity reflects impact if the gap materializes, not probability.
[CR033, CR035, CR036, CR037, CR039, CR042]Directed acyclic graph showing how HUMAN Security's primary risk categories propagate through the business to affect revenue, customer retention, margin, financing, and valuation.
[CR005, CR015, CR023, CR033, CR034, CR037]7.5 Mitigations, Thesis-Break Triggers, and Diligence Asks
HUMAN's primary mitigations are structural: the Satori threat intelligence moat from monitoring one quadrillion+ interactions per year creates genuine detection advantages that point-in-time competitors cannot replicate. MRC accreditation (earned April 2026) provides media-buyer trust anchoring. The public-private disruption model—FBI, Google, Shadowserver, Trend Micro co-operations on BADBOX 1.0 and 2.0—demonstrates that HUMAN is embedded in the threat-response ecosystem in ways that bundled vendors are not. The $50M 2024 growth round and investor continuity (Goldman, WestCap, NightDragon) reduce near-term liquidity risk. The HUMAN Advantage Partner Program launched August 2024 diversifies customer acquisition away from long direct-sales cycles. Thesis-break triggers are concentrated in three areas. The first is platform bundling absorption: if Cloudflare, Google, or AWS meaningfully close the behavioral signal gap through acquisition or model improvement, HUMAN's pricing premium collapses for the majority of its customer base that already runs on those platforms. The second is a material cloud outage during peak traffic: AWS US-EAST-1 remains HUMAN's most likely operational single point of failure; a multi-hour outage during high-value media events (Super Bowl, Prime Day) would create immediate contractual and reputational exposure. The third is a privacy enforcement action: if a state AG or FTC action reclassifies HUMAN's behavioral signal network under a data-broker framework, or if novel Wiretap Act class actions citing DSP predicates name HUMAN as a defendant, compliance costs and customer trust could be materially impaired. Priority diligence asks: independent ARR confirmation and NRR benchmarking; multi-cloud resilience architecture documentation; data flow mapping to confirm DSP compliance for cross-border transfers; top-10 customer revenue concentration; post-PerimeterX integration gross margin trend; and AWS contractual terms including any minimum commitments and exit options. Given the valuation opacity, a secondary-market cap-table analysis is necessary before any entry at or above the 2022 $1.5B reference. [CR003, CR007, CR009, CR015, CR022, CR025]
| Risk | Monitorable Trigger | Threshold / Event | Action Implication |
|---|---|---|---|
| Platform bundling encroachment | Cloudflare/Google bot management market share growth; HUMAN customer churn to bundled stacks | HUMAN mindshare falls below 5% in Gartner/PeerSpot; two top-10 customers migrate in 12 months | Thesis break: accelerate thesis re-evaluation; scenario-plan acquirer exit |
| AWS infrastructure single point of failure | AWS US-EAST-1 outage coinciding with HUMAN peak traffic window | Any >4-hour outage with documented SLA breach across ≥5 enterprise customers | Material breach: audit DR architecture; require multi-cloud commitment as covenant |
| Privacy enforcement (data-broker reclassification) | FTC or state AG action naming adtech behavioral signal vendors | Any named enforcement action against HUMAN or a direct peer with identical data model | Thesis break: immediate legal diligence; assess consent-management remediation cost |
| ARR growth deceleration | Net new ARR from independent audited disclosure or channel partner reporting | ARR growth below 15% in any two consecutive reporting periods | Re-price: reduce valuation multiple; require quarterly ARR reporting as board covenant |
| ML model quality degradation | False positive rate disclosed in customer-facing benchmarks or third-party audits | Customer-reported FP rate above 1% in any major vertical or contract churn attributed to FP | Operational watch: require model performance SLA in investment term sheet |
Thresholds are indicative and should be refined with portfolio monitoring covenants. Trigger data depends on access to HUMAN's internal metrics, which are not currently publicly disclosed. Monitoring relies on secondary signals (market share data, peer enforcement actions, customer testimonials) in the absence of direct reporting.
[CR001, CR015, CR023, CR033, CR034, CR040]7.6 Exhibits
08Valuation
8.1 Investment Thesis and Anti-Thesis
HUMAN Security's investment thesis rests on five interlocking pillars. First, market necessity: bot-driven fraud, invalid traffic, credential abuse, and agentic-AI threats are non-discretionary security problems that expand as the digital economy grows; Gartner forecasts global information security spending of $244.2 billion in 2026, up 13.3% year-over-year, with cloud security growing 28.8%. Second, platform scale moat: verifying 20 trillion digital interactions weekly across 3 billion unique devices creates a data network effect that smaller competitors (Arkose Labs at $46.9M ARR, DataDome, Netacea) cannot replicate without equivalent infrastructure and threat-intel investment. Third, agentic-AI positioning: the July 2025 launch of HUMAN Sightline and AgenticTrust places the company directly in the highest-multiple cybersecurity niche (AI security, $2B in financing deployed YTD 2026 per Momentum Cyber). Fourth, investor conviction: five institutional backers—Goldman Sachs Merchant Banking, WestCap, NightDragon, ClearSky, Vertex—have consistently re-invested across multiple rounds through 2024. Fifth, platformization tailwind: strategic buyers drove 92% of cybersecurity M&A by value in 2026, and HUMAN's cross-layer platform (media security, application security, account protection, agentic trust) fits the buyer consolidation thesis. The anti-thesis is equally substantive. First, financial opacity: HUMAN discloses no NRR, gross margin, or ARR growth rate. The single available third-party ARR estimate (GetLatka, $15M as of December 2023) is an order of magnitude below the company-claimed $100M+ and remains unresolved. Second, capital overhang: approximately $300M in equity plus a $100M Blackstone Credit facility creates a $400M total capital base against which a $1.3–1.5B EV implies only a 3.25–3.75x gross MOIC on invested capital before dilution and liquidation preferences. Third, sector discount risk: HUMAN's ad-verification revenue stream (historically its primary business) benchmarks to DV/IAS multiples of 1.9x revenue—a fraction of the 15x cybersecurity peers' multiple—and buyers may apply a blended discount. Fourth, existing-investor concentration: the October 2024 round drew no new institutional names, which could indicate a restricted pricing ceiling. Fifth, consolidation threat: Cloudflare, CrowdStrike, and Palo Alto are all investing heavily in bot management and fraud prevention capability that could erode HUMAN's standalone premium. [CV001, CV002, CV003, CV006, CV007, CV009]
| Dimension | Assessment | Evidence Basis |
|---|---|---|
| Recommendation | Track | ARR, platform positioning, and market benchmarks are consistent with a hold; undisclosed NRR/margin prevent conviction |
Assessment reflects public evidence available as of the June 2026 research date. Confidence, risk rating, and valuation stance reflect the author's analytical judgment based on the comparable set and disclosed information. Undisclosed metrics could shift recommendation to buy or avoid.
[CV009, CV016, CV045]| Pillar | Thesis Argument | Anti-Thesis Argument | View-Changing Evidence |
|---|---|---|---|
| Market | Bot/fraud/AI-agent security is non-discretionary and growing (Gartner $244.2B 2026 +13.3% YoY) | Platform consolidation by hyperscalers compresses standalone bot-management TAM | Measurable multi-year ARR CAGR and channel partner pipeline growth rates |
| Product | Internet-scale detection network (20T interactions/week) with 400+ adaptive ML models creates data moat | Cloudflare, Akamai, and AWS amass comparable traffic telemetry at zero marginal cost for existing customers | Independent benchmark comparing HUMAN vs. Cloudflare Bot Management false-positive rates on identical traffic |
| Customers | 500+ global brand customers; mission-critical deployment creates high switching costs | No disclosed NRR or gross revenue retention; customer concentration unknown | Audited NRR >115% and top-10 customer <5% ARR concentration |
| Financials | Company-claimed ARR >$100M at <$350K ARR/FTE suggests moderate capital efficiency | GetLatka $15M ARR data point is unresolved; gross margin and burn rate undisclosed | Audited ARR, gross margin, NRR, and Blackstone Credit facility status |
| Competition | Largest pure-play bot management platform; Forrester Wave Q2 2026 Leader designation | DV/IAS anchor ad-verification multiples at 1.9x revenue; CrowdStrike/Palo Alto encroaching | Sustained Forrester Leader position and documented displacement of DV/IAS customers |
| Exit / Valuation | Cybersecurity M&A at record pace; private cyber median 15.2x and M&A median 16.3x | October 2024 existing-investor-only round; no new external capital at step-up valuation | New institutional investor participation in a growth round or confirmed strategic M&A process |
Thesis/anti-thesis arguments derived from public sources; view-changing evidence represents specific disclosures or external validations that would warrant a full thesis revision. All multiples cited reflect the Q2 2026 research date benchmarks.
[CV009, CV010, CV013, CV016, CV017, CV018]8.2 Financing Context and Valuation History
White Ops was acquired by Goldman Sachs Merchant Banking Division, ClearSky Security, and NightDragon in December 2020 for an undisclosed price. In January 2022, the resulting HUMAN Security entity raised a $100 million growth round led by WestCap and NightDragon, with Goldman Sachs Asset Management participating. In July 2022, the PerimeterX merger valued the combined entity at approximately $1.5 billion, at which point HUMAN also secured a $100 million debt facility from Blackstone Credit. The 2022 valuation was set during the elevated private-market multiple environment of 2021–2022, when private cybersecurity medians exceeded 15x ARR. In October 2024, HUMAN closed a $50 million-plus growth round led by WestCap with Goldman Sachs Asset Management, ClearSky Security, NightDragon, and Vertex Ventures US, bringing total equity raised to approximately $300 million. Critically, no new valuation was disclosed, and no new institutional investors joined the cap table—a pattern that may reflect deliberate access rationing by existing investors or an inability to attract external capital at a step-up price. Windsor Drake notes that companies raising at inflated 2021–2022 valuations often use "structured rounds" with preferred return features to maintain nominal face-value marks. The current status of the Blackstone Credit $100M debt facility (issued July 2022) has not been publicly confirmed as of June 2026. If the facility remains outstanding, it creates seniority ahead of equity, compressing equity returns in any scenario below $1.1B enterprise value. The total capital at risk ($300M equity + $100M debt = $400M) against a $1.5B EV implies 3.75x gross MOIC, adequate but not exceptional for a position held since 2020. Premier Alternatives lists HUMAN's current private valuation as "N/A" with no secondary market data available. [CV001, CV002, CV003, CV004, CV005, CV006]
8.3 Comparable Valuation Analysis
HUMAN's valuation benchmarks against three peer sets: public ad-verification platforms (DV, IAS), private cybersecurity application-security peers, and cross-sector M&A precedents. These three sets produce materially divergent implied valuations, reflecting HUMAN's hybrid positioning between the ad-verification and pure-play cybersecurity markets. Public ad-verification comps provide the pessimistic anchor. DoubleVerify (NYSE: DV) reported LTM revenue of $781 million, EBITDA of $261 million, and gross margin of 82%, yet trades at only 1.9x EV/Revenue—a $2 billion enterprise value—reflecting structural headwinds in programmatic advertising and slow revenue growth of approximately 10% NTM. Integral Ad Science posted approximately $530 million in LTM revenue at a similar compressed multiple. The broader AdTech SaaS sector median NTM EV/Revenue is just 0.9x per Multiples.vc's June 2026 analysis, the lowest across all SaaS segments. Applied to a $100 million ARR, this would imply an EV of only $90–190 million—clearly inapplicable for a company with HUMAN's cybersecurity positioning, but it sets the floor if buyers mark HUMAN's ad-verification revenue at sector-appropriate rates. The cybersecurity comps are far more favorable. Finro's Q2 2026 dataset of 265 companies across 9 niches places Application Security (HUMAN's closest peer niche) at a 15.4x average and 13.0x median EV/Revenue. Windsor Drake's November 2025 report puts the private cybersecurity median at 15.2x ARR and M&A exit median at 16.3x. The cloud security niche trades even higher at 22.7x average (Finro), anchored by the Google/Wiz $32 billion transaction at 32x ARR. Kroll's Spring 2026 analysis notes that median cybersecurity EV/NTM Revenue multiples fell 26% quarter-over-quarter in Q1 2026 due to AI-related equity market pressure, so even the cybersecurity premium is currently under pressure. Private-market SaaS comps at HUMAN's revenue scale ($100M+ ARR) imply a range of 5.5–7.2x ARR for non-AI SaaS per iMerge Q1 2026, or up to 12–15x for AI-native platforms with high NRR. The Acquiry 2026 dataset corroborates: AI-native SaaS at 20–50% growth commands 7–12x ARR; traditional SaaS at 15–30% growth, 3–5x ARR. Given HUMAN's AI-native positioning claims but undisclosed growth rate, the range is wide. [CV012, CV013, CV014, CV015, CV016, CV017]
| Comparable | Type | Metric | EV / Revenue Multiple | Relevance to HUMAN | Key Limitation |
|---|---|---|---|---|---|
| DoubleVerify (DV, NYSE) | Public comp — ad verification | $781M LTM revenue; $2B EV | 1.9x LTM Revenue | Shares HUMAN's advertising-fraud-prevention revenue stream and media-brand customer base | Pure ad-verification; no bot management or application security; 10% revenue growth; sector structural headwinds |
| Integral Ad Science (IAS, NASDAQ) | Public comp — ad verification | ~$530M LTM revenue | ~1.7–2.5x (estimated) | Overlaps with HUMAN's media security vertical; competitor in programmatic fraud detection | Agency-embedded distribution HUMAN lacks; no application security or agentic AI product |
| Application Security niche median (Finro Q2 2026) | Private/M&A benchmark — 52 companies | Avg 15.4x; median 13.0x EV/Revenue | 13.0–15.4x | Closest niche match; includes bot management and web application protection vendors | Aggregated benchmark; individual company range wide (seed 15.5x to Series C 12.7x) |
| Private cybersecurity median (Windsor Drake) | Private M&A benchmark — broad cyber | Median 15.2x ARR; M&A exit median 16.3x | 15.2–16.3x | Sector-wide private benchmark; HUMAN competes in same enterprise security buyer universe | Does not isolate application security sub-niche; includes cloud, identity, endpoint |
| Arkose Labs | Private comp — bot management | $46.9M ARR (2024); $140.7M valuation (~3x ARR) | ~3.0x ARR | Closest product competitor; also pure-play bot management with enterprise focus | Much smaller scale ($47M vs. $100M+ ARR); last raise Series C in 2021; valuation may be stale |
| Wiz / Google (M&A precedent) | M&A precedent — cloud security | $1B ARR; $32B acquisition price | ~32x ARR | Sets ceiling for AI-native category-defining cybersecurity assets | Cloud-native CNAPP is structurally different from bot management; AI-first architecture premium |
Multiples as of June 2026 research date where available; Arkose Labs valuation from GetLatka 2024 data which may be stale. IAS multiple is an estimate from analyst coverage; precise current figure requires financial data subscription. All EV/Revenue multiples are on LTM or ARR basis as disclosed. Finro and Windsor Drake benchmarks cover private and M&A transactions; exact source transactions not individually auditable without paid dataset access.
[CV012, CV013, CV014, CV015, CV016, CV017]8.4 Bull, Base, and Bear Scenario Analysis
The bear case assumes HUMAN's true ARR is at the lower bound of defensible estimates ($80–100 million), NRR has drifted below 105%, and gross margin is compressed below 70% due to heavy Satori team and infrastructure costs. Under these assumptions, the company's SaaS quality may not sustain a pure cybersecurity multiple, and buyers apply a 8–10x blended discount reflecting ad-verification revenue exposure. The resulting implied EV is $640M–$1.0B, below the total capital invested. The primary bear-case catalyst is a down-round forced by the need to extend cash runway beyond 2027 without improved metrics disclosure. The base case assumes the $100M+ ARR claim is accurate, NRR is in the 105–115% range (below best-in-class cybersecurity but positive), gross margin is 70–78%, and the platform is growing at 10–20% annually. At the application-security median of 13.0x, implied EV is $1.3B; at the private-cybersecurity median of 15.2x, implied EV is $1.52B—roughly in-line with the 2022 mark. A strategic exit to a platform consolidator (CrowdStrike, Palo Alto, or Cloudflare) at 14–16x represents a $1.4–1.6B range, yielding a 3.5–4.0x gross MOIC for the 2022 equity investors. The likely exit window is 2027–2029 given Netskope's 2025 IPO precedent and the current partial reopening of the cybersecurity IPO market. The bull case assumes ARR has grown to $130–140M (consistent with GrowJo's $140.4M estimate), NRR exceeds 115%, the agentic AI product line has achieved measurable bookings contribution, and HUMAN is designated as a Leader in the Forrester Bot and Agent Trust Management Q2 2026 Wave. Under these conditions, a strategic acquirer applying a 18–20x top-quartile multiple implies an EV of $2.34–2.8B. At CyberArk/Palo Alto precedent multiples (18.6x), $130M ARR implies $2.42B EV. An IPO exit at 12–14x NTM would require $175–210M in NTM revenue to support a $2B+ public market cap, achievable in 2027–2028 if growth rate accelerates to 20%+ annually. [CV009, CV010, CV011, CV017, CV018, CV019]
| Scenario | Key Assumptions | Implied ARR | EV Multiple | Implied EV (USD M) | Probability Signal | Downside Trigger |
|---|---|---|---|---|---|---|
| Bull | ARR $130–140M; NRR >115%; AI-native platform premium; Forrester Leader sustained; strategic M&A process opened | $130–140M | 18–20x | $2,340–2,800 | Low-medium (requires ARR growth confirmation and NRR disclosure) | AI product fails to achieve measurable bookings contribution within 2 product cycles |
| Base | ARR $100–115M confirmed; NRR 105–115%; gross margin 70–78%; app-security median multiple; exit via strategic M&A 2027–2029 | $100–115M | 13–15x | $1,300–1,725 | Medium (consistent with disclosed milestones and comp set benchmarks) | Blackstone debt overhang limits equity upside; down-round bridge needed before exit |
| Bear | ARR $80–100M (lower-bound); NRR <105%; margin compressed by Satori + infra costs; blended cyber/adtech discount | $80–100M | 8–10x | $640–1,000 | Low (requires significantly worse-than-disclosed operating metrics) | Forced down-round below $1B; top-5 customer churn; regulatory action on ad-verification workflows |
EV ranges are illustrative scenario analyses anchored to comparable benchmarks, not DCF-based valuations. Implied ARR and multiples are based on Finro Q2 2026 Application Security niche data (13.0x median, 15.4x average) and Windsor Drake private cybersecurity benchmarks (15.2x median). Downside multiples reflect blended cybersecurity/ad-verification sector pricing. Probability signals are qualitative assessments based on evidence availability and internal consistency with publicly disclosed milestones. USD millions.
[CV009, CV011, CV017, CV018, CV019, CV031]Implied HUMAN Security enterprise value across six scenarios from the ad-verification floor (1.9x) to the AI-native cybersecurity ceiling (22x), all applied to $100M ARR baseline.
All values applied to $100M ARR baseline (company-claimed floor). Actual ARR may be higher (GrowJo $140.4M estimate) or lower (GetLatka $15M disputed figure). Multiples sourced from Multiples.vc (DV), Finro Q2 2026 (App Sec), Windsor Drake (private cyber, M&A median), and Acquiry/SaaS Mag (AI-native range). Values in USD millions.
[CV013, CV016, CV017, CV019, CV031, CV032]Low, mid, and high enterprise-value estimates for bear, base, and bull scenarios with explicit assumption anchors.
Bear low of $640M reflects 8x on $80M ARR; bear high of $1.0B reflects 10x on $100M ARR. Base range anchored to Finro App Sec median (13x) and private cyber median (15.2x). Bull range applies CyberArk/Palo Alto M&A precedent multiple (18.6x) at $130M ARR for mid, stretched to 20x at $140M ARR for high. All figures in USD millions. Ranges do not account for liquidation preferences, debt seniority, or dilution from new financing rounds.
[CV017, CV018, CV019, CV025, CV032, CV033]8.5 Recommendation, Exit Readiness, and Diligence Asks
Based on available public evidence, the recommendation is Track. HUMAN presents a credible cybersecurity platform story with internet-scale proof, strong institutional backing, and strategic positioning in high-growth threat categories (bot management, AI agent trust). The investment is neither obviously overpriced—the 2022 $1.5B valuation aligns with current application-security benchmarks at stated ARR—nor obviously attractive absent confirmation of core operating metrics. Confidence is medium because material diligence gaps (NRR, gross margin, ARR growth, debt status, cap table preferences) cannot be closed from public sources. Exit readiness is partial. HUMAN is not named in any confirmed 2026 cybersecurity IPO pipeline. The company would need to close the financial disclosure gap with audited metrics, demonstrate a clear Rule of 40 score, and position the agentic AI product line as a growth driver before an IPO narrative would hold in the current selective public market. Strategic M&A is the more likely near-term path. Acquirers with strategic fit include CrowdStrike (identity + bot management integration with Falcon), Palo Alto Networks (platformization of anti-fraud across SASE + XSIAM), and Cloudflare (extending from CDN/WAF into full-stack bot and AI agent governance). Google (post-Wiz) and ServiceNow (post-Armis) are less likely but financially capable. A financial sponsor take-private is possible if MOIC at current multiples clears a 3.5x threshold on a 2027–2030 hold. Thesis-break triggers are defined as observable events that would require a full thesis revision, not just scenario adjustment. These include: an audited ARR disclosure below $80 million; confirmation of NRR below 95%; a down-round valuation below $1.0B; loss of a top-5 customer accounting for >15% of ARR; or regulatory action targeting core ad-verification workflows. The final diligence priority list (TV006) identifies six asks that would materially change the conviction level of this assessment. [CV016, CV017, CV025, CV030, CV039, CV041]
| Trigger | Threshold or Event | Transmission to Thesis | Action Implication |
|---|---|---|---|
| ARR disclosure below floor | Audited ARR <$80M | Invalidates cybersecurity-premium multiple basis; implies valuation is 2–3x current bear-case EV | Immediate exit or deep discount reassessment; thesis collapses |
| Net revenue retention below retention floor | Audited NRR <95% | Signals negative land-and-expand; customer cohort deteriorating; multiple compression to 6–8x | Reassess as services-adjacent rather than SaaS; require evidence of retention fix before next round |
| Down-round financing event | New equity round at valuation <$1.0B | Confirmed overhang from $400M+ invested; signals internal consensus on distressed value | Reassess hold position; potential liquidation preference dislocation |
| Platform vendor product displacement | Confirmed HUMAN customer loss >15% ARR to Cloudflare, CrowdStrike, or Palo Alto in a single fiscal year | Structural erosion of the independent bot-management market; strategic buyer pool shrinks | Downgrade to avoid; market share data confirms commoditization risk |
| Regulatory or legal adverse action | Enforcement action, material litigation outcome, or GDPR/CCPA violation affecting core product | Revenue at risk from affected geography; potential customer churn; legal overhang raises discount rate | Place thesis on hold pending legal outcome; evaluate geography-specific customer concentration |
Kill triggers represent observable events requiring full thesis revision, not scenario adjustments. Thresholds are set at levels where the base-case valuation range becomes unsustainable. All triggers are testable against public disclosures or management communications in a future diligence cycle.
[CV009, CV034, CV036, CV045, CV047]| Topic | Missing Evidence | Why It Matters | Owner or Diligence Path |
|---|---|---|---|
| Net Revenue Retention | Audited or management-confirmed NRR by cohort year (target: current + 2 prior years) | NRR is the single most important SaaS quality metric; determines whether multiple expansion or compression applies; gap between 95% and 120% NRR implies 30–50% valuation difference | Management disclosure in data room; cross-check against customer reference calls |
| Gross Margin by Product | Gross margin by revenue pillar (media security, application security, account protection, agentic AI) | Satori team and ML infrastructure costs may compress blended margin below 70%; determines whether HUMAN is valued as pure SaaS (8–15x) or tech-enabled services (3–5x) | Audited financial statements; CFO interview; infrastructure cost benchmarking |
| ARR Growth Rate and Bridge | Year-over-year ARR growth from January 2022 ($100M claimed) to present, segmented by product line | Four-year growth rate determines whether the platform is in acceleration or deceleration; breaks the $1.52B vs. $640M valuation divergence | CFO interview; management accounts; cross-check with headcount/spend growth proxy |
| Blackstone Credit Facility Status | Current balance, maturity, interest rate, and covenant structure of the $100M debt facility | Seniority ahead of equity affects equity upside in scenarios below $1.5B EV; covenant violations could force premature exit | Legal and accounting data room review; publicly available debt registration filings if any |
| Cap Table and Preference Stack | Full capitalization table showing share classes, liquidation preferences, participation rights, and anti-dilution provisions | $300M equity across 8 rounds at varying prices may have created participating preferred structures that materially reduce common equity value in sub-$2B exit scenarios | Legal data room; investor rights agreements; capitalization summary certificate |
| Customer Concentration | Top-10 customer revenue contribution as a percentage of ARR; names of top-3 or anonymized revenue bands | Bot management revenue is often concentrated among digital-media and e-commerce leaders; single-customer risk >10% ARR is a material thesis modifier | CFO interview; contract abstracts; cross-reference with disclosed 500+ brand claim |
Priority order reflects financial-materiality weighting: NRR and gross margin are immediate valuation determinants; ARR growth and Blackstone facility status are near-term thesis validators; cap table and concentration are deal-structuring inputs. All six items are required to progress from Track to Buy in a subsequent diligence cycle.
[CV007, CV009, CV036, CV045]Logical chain from HUMAN's platform scale and financial evidence through risk assessment to the Track recommendation and primary exit paths.
Flow nodes represent the logical evaluation chain, not a financial model. Exit path timing is indicative based on comparable cybersecurity company trajectories and current IPO market conditions.
[CV009, CV016, CV019, CV039, CV045]IC-ready scoring across eight dimensions from 0–10; reflects evidence-constrained assessment as of June 2026.
Scores are the author's evidence-constrained ordinal judgments (0=no evidence/critical failure, 10=best-in-class with full disclosure). Financial Metrics scored 3/10 due to absence of NRR, gross margin, burn rate, and ARR growth disclosure. Evidence Quality scored 4/10 due to the GetLatka/company-claimed ARR conflict and no audited financials. All other scores derived from public evidence reviewed during this research run.
[CV009, CV019, CV041, CV042, CV044, CV045]8.6 Exhibits
Disclaimer
This report is for informational purposes only and is based solely on public information available as of 2026-06-19. It is not investment advice, does not constitute an offer or solicitation, and may omit material non-public information. Independent diligence and qualified financial, legal, and technical review are required before any investment decision.
Evidence index
| ID | Statement | Confidence | Sources |
|---|---|---|---|
| CO001 | HUMAN Security was founded in 2012 in Brooklyn, New York, originally under the name White Ops. | High | SO001, SO005 |
| CO002 | HUMAN Security's four co-founders are Tamer Hassan, Michael Tiffany, Dan Kaminsky, and Ash Kalb. | High | SO001, SO003 |
| CO003 | HUMAN Security, Inc. is a privately held cybersecurity company; it is not publicly traded. | High | SO001, SO015 |
| CO004 | White Ops rebranded to HUMAN Security in 2021 to reflect an expanded scope beyond digital advertising fraud. | High | SO004, SO005 |
| CO005 | HUMAN Security is headquartered in New York City, with additional offices in Miami, Santa Clara, Tel Aviv, and the United Kingdom. | Medium | SO015, SO006 |
| CO006 | HUMAN's commercial product is called the Human Defense Platform (HDP), positioned as a unified cybersecurity platform. | High | SO001, SO007 |
| CO007 | HUMAN verifies more than 20 trillion digital interactions weekly across 3 billion unique devices. | High | SO001, SO006, SO007 |
| CO008 | HUMAN's platform examines 2,500 or more signals per digital interaction to make bot-or-human determinations. | Medium | SO001, SO007 |
| CO009 | HUMAN uses 400 or more adaptive machine learning models to analyze interaction signals. | Medium | SO001, SO007 |
| CO010 | HUMAN's Human Defense Platform spans three pillars: Media Security (ad fraud, invalid traffic), Application and Enterprise Security (account takeover, scraping, carding), and Account Protection (credential stuffing, fake accounts). | Medium | SO001, SO009 |
| CO011 | Tamer Hassan co-founded HUMAN Security and served as CEO until January 2024, when he transitioned to the role of Executive Chairman of the board. | High | SO003, SO011 |
| CO012 | Stu Solomon, formerly President of Recorded Future, was appointed CEO of HUMAN Security in January 2024. | High | SO003, SO006, SO011 |
| CO013 | Stu Solomon's prior executive experience includes the presidency of Recorded Future, CTO role at Optiv, leadership at iSight Partners (acquired by FireEye), and five years at Bank of America, plus a 25-plus-year military career in the Delaware Air National Guard and USAF. | High | SO003, SO006 |
| CO014 | HUMAN Security's current executive team includes Isaac Itenberg (COO/CFO), Gavin Reid (CISO), and Christos Kalantzis (CTO). | Medium | SO015 |
| CO015 | Dave DeWalt, CEO and founder of NightDragon, joined the HUMAN Security board as part of the 2020 acquisition and was designated Vice Chairman of the company. | High | SO005, SO007 |
| CO016 | Jay Leek, Managing Partner of ClearSky, joined the HUMAN Security board as part of the 2020 acquisition. | High | SO005, SO007 |
| CO017 | Kevin Marcus, Partner and Co-COO at WestCap, is referenced in the 2024 growth round materials as a board-linked investor representative. | Medium | SO007, SO006 |
| CO018 | Anthony Arnold, Managing Director at Goldman Sachs, is referenced in HUMAN's funding announcements as the firm's representative investor and board contact. | Medium | SO005, SO007 |
| CO019 | Ido Safruti, co-founder and CTO of PerimeterX, joined HUMAN Security's board as part of the July 2022 PerimeterX merger. | High | SO004, SO020 |
| CO020 | No public record identifies Matt Cantor in any current or recent executive, board, or leadership role at HUMAN Security as of June 2026. | Medium | SO002, SO003 |
| CO021 | Goldman Sachs Merchant Banking Division, ClearSky Security, and NightDragon acquired White Ops in December 2020, buying out previous investors including Paladin Capital Group and Grotech Ventures; acquisition terms were not disclosed. | High | SO005, SO018 |
| CO022 | HUMAN Security raised a $100 million growth round in January 2022, led by WestCap with participation from NightDragon. | High | SO009, SO012, SO006 |
| CO023 | The January 2022 $100 million growth round was reported to value HUMAN Security at approximately $1.5 billion, representing a unicorn designation. | Medium | SO006, SO009 |
| CO024 | In connection with the July 2022 PerimeterX merger, HUMAN received a $100 million debt facility from Blackstone Credit; this is a debt instrument separate from equity capital raised. | High | SO004, SO019 |
| CO025 | HUMAN Security raised $50 million or more in a growth round announced October 9, 2024, led by WestCap. | High | SO006, SO007, SO008, SO009 |
| CO026 | The October 2024 growth round included Goldman Sachs, ClearSky, NightDragon, and Vertex Ventures US as additional investors beyond lead investor WestCap. | High | SO007, SO008, SO009, SO016 |
| CO027 | HUMAN Security's total capital raised is reported by data aggregators as approximately $299 to $300 million across all equity rounds; this figure may not include the $100 million Blackstone debt facility. | Medium | SO017, SO016 |
| CO028 | HUMAN's Series C of $43 million was led by Scale Venture Partners in February 2019, with Canaan Partners also participating. | Medium | SO017 |
| CO029 | White Ops, together with the FBI, Google, Facebook, and other industry partners, participated in the takedown of the 3ve botnet in 2018-2019, which was described as the largest private-sector collaborative cybersecurity disruption to date. | High | SO001, SO005, SO012 |
| CO030 | White Ops uncovered and disclosed the Methbot ad fraud botnet in 2016, which was generating an estimated $3 to $5 million per month in criminal revenue. | Medium | SO001, SO014 |
| CO031 | HUMAN Security and PerimeterX announced a market-changing merger on July 27, 2022, creating a combined entity with more than 450 employees, more than 500 customers, and more than $100 million in ARR. | High | SO004, SO019, SO020 |
| CO032 | HUMAN Security acquired malvertising prevention firm clean.io in approximately March 2022. | Medium | SO003, SO006 |
| CO033 | HUMAN Security disrupted and disclosed the VASTFLUX ad fraud scheme in January 2023; VASTFLUX had injected malicious JavaScript into ad creatives across more than 1,700 spoofed apps, affecting approximately 11 million devices at a peak of 12 billion daily false bid requests. | High | SO014, SO024, SO025 |
| CO034 | HUMAN Security (Human Defense Platform) was named to TIME's Best Inventions of 2023. | High | SO001, SO003 |
| CO035 | HUMAN Security was named among TIME100 Most Influential Companies of 2023. | Medium | SO003 |
| CO036 | HUMAN Security disrupted the BADBOX pre-installed Android botnet in multiple phases from 2023 through 2025, coordinating with Google, German authorities, and Shadowserver to sinkhole command-and-control infrastructure. | Medium | SO001, SO013 |
| CO037 | HUMAN Security was named a Leader in The Forrester Wave: Bot Management Software, Q3 2024. | High | SO001, SO006 |
| CO038 | HUMAN Security was named a Leader in The Forrester Wave: Bot and Agent Trust Management Software, Q2 2026, and was the only vendor to receive the highest possible score in the Threat Research criterion. | High | SO013, SO023 |
| CO039 | In October 2024, AdExchanger published a correction noting that HUMAN CEO Stu Solomon had misspoken during an interview; HUMAN clarified through its VP of Product that the company does not plan to build a proprietary deterministic ID or a measurement and attribution solution. | Medium | SO010 |
| CO040 | No material lawsuits, regulatory investigations, data breach disclosures, or formal sanctions against HUMAN Security have been identified in public records as of the June 2026 research date. | Low | SO001, SO002 |
| CO041 | HUMAN Security does not disclose its revenue, ARR, or current post-money valuation publicly; all financial metrics require data room engagement for diligence. | High | SO006, SO010 |
| CO042 | As of October 2024, HUMAN Security employs approximately 400 people, with plans to meaningfully expand the data science and engineering team, according to CEO Stu Solomon. | Medium | SO006, SO010 |
| CO043 | HUMAN Security serves 500 or more global brands across media, finance, retail, government, education, and enterprise security. | Medium | SO001, SO007 |
| CO044 | HUMAN's three product pillars are Media Security, Application and Enterprise Security, and Account Protection. | Medium | SO009, SO007 |
| CO045 | HUMAN's Satori Threat Intelligence and Research Team provides threat intelligence, feeds product enhancements, and orchestrates disruptions of cybercriminal operations, including major takedowns like VASTFLUX, BADBOX, and PARETO. | Medium | SO001, SO013 |
| CO046 | HUMAN launched HUMAN Sightline Cyberfraud Defense as a unified trust and defense layer protecting digital businesses from bot attacks, human-led fraud, transaction abuse, and AI-driven risks by mid-2026. | Medium | SO013 |
| CO047 | HUMAN launched AgenticTrust, a product enabling customers to detect, classify, and govern AI agents operating on their platforms, by mid-2026 as part of its agentic AI expansion. | Medium | SO013 |
| CO048 | G2's Summer 2026 Grid for Bot Detection and Mitigation Software named HUMAN the top overall Leader based entirely on customer feedback. | Medium | SO013 |
| CM001 | HUMAN Security's served market spans bot mitigation, ad fraud/SIVT defense, account takeover prevention, and agentic AI trust management, unified under the Human Defense Platform (Bot Defender, Sightline Cyberfraud Defense, MediaGuard/Ad Integrity Suite, and AgenticTrust module). | Medium | SM001, SM002 |
| CM002 | The global bot mitigation market is sized at $0.9 billion in 2025 and projected to reach $1.12 billion in 2026 at a CAGR of 24.8% (Business Research Company). | Medium | SM004 |
| CM003 | Fortune Business Insights values the global bot security market at $1.05 billion in 2025 and $1.27 billion in 2026, growing to $5.67 billion by 2034 at a CAGR of 20.55%, with North America accounting for 38% of global share. | Medium | SM005 |
| CM004 | Global digital advertising losses attributable to ad fraud exceeded $100 billion in 2026, driven by an approximately 20% invalid traffic rate globally across programmatic channels. | Medium | SM015, SM006 |
| CM005 | Fraudlogix's analysis of 105.7 billion impressions collected throughout 2025 showed a global IVT rate of 20.64%, with the US at 23.69% across 37.6 billion impressions, implying roughly $37 billion in US programmatic spend annually associated with invalid traffic. | Medium | SM006 |
| CM006 | The global account takeover protection market is estimated at $6.28 billion in 2025, projected to reach $7.46 billion in 2026 with an 18.89% CAGR through 2035 (Global Growth Insights). | Medium | SM019 |
| CM007 | The Business Research Company projects the eCommerce fraud detection and prevention market at $88.77 billion in 2026 at a CAGR of 20.8%, though this scope includes payment fraud, chargebacks, KYC, and identity proofing outside HUMAN's current product suite. | Low | SM012 |
| CM008 | Grand View Research estimates the all-verticals fraud detection and prevention market (including AML, KYC/KYB, payment fraud) at $40.4 billion in 2026 with an 18.1% CAGR through 2033—a scope roughly 30x wider than HUMAN's bot-security SAM. | Low | SM011 |
| CM009 | An analyst-synthesized SAM for HUMAN Security of approximately $1.5–$2.0 billion in 2026 is constructed from bot security ($1.27B per Fortune BI) plus an estimated $500M–$800M for MRC-accredited SIVT vendor spend; this is pre-bundling-haircut and has no independent primary-source validation. | Low | SM004, SM005, SM013 |
| CM010 | The bot mitigation market is projected to grow from $1.12 billion in 2026 to $2.4 billion in 2030 at a CAGR of 20.9% (Business Research Company). | Medium | SM004 |
| CM011 | Fortune Business Insights projects the bot security market at $5.67 billion by 2034 at a CAGR of 20.55%, with North America holding 38% of market share in 2026. | Medium | SM005 |
| CM012 | Published market estimates for the fraud prevention space range from $1.12 billion (bot mitigation only) to $88.77 billion (eCommerce FDP), a 79x spread driven by boundary definition rather than genuine disagreement, making cross-source TAM comparison unreliable without scope normalization. | Medium | SM004, SM012, SM005, SM011 |
| CM013 | At the US programmatic ad spend level, a 23.69% IVT rate applied to an estimated $156 billion US programmatic market implies approximately $37 billion in annual ad spend potentially exposed to invalid traffic (Fraudlogix, 2026). | Medium | SM006 |
| CM014 | North America represented the largest region in the bot mitigation market in 2025 and accounts for approximately 38% of the global bot security market per Fortune Business Insights. | Medium | SM005, SM004 |
| CM015 | HUMAN Security's Defense Platform analyzed more than one quadrillion digital interactions in 2025, providing a network effect advantage in behavioral signal training across bot, human, and agentic AI traffic. | High | SM001, SM003 |
| CM016 | More than 95% of AI-driven automation in 2025 was concentrated in three verticals: retail and e-commerce, streaming and media, and travel and hospitality—HUMAN's primary buyer segments. | High | SM001, SM010 |
| CM017 | HUMAN customers experienced on average more than 400,000 attempted post-login account compromise attacks in 2025, a figure quadruple that of 2024, reflecting the acceleration of ATO as a core enterprise security problem. | Medium | SM001 |
| CM018 | Retail and e-commerce topped all verticals for the highest volume of scraping, carding, and ATO attacks in HUMAN's 2025 data, with 70% of all observed scraping attacks targeting this segment. | Medium | SM001, SM010 |
| CM019 | More than 440,000 unique threat profiles targeted retail and e-commerce businesses in 2025 per HUMAN's Threat Tracker, more than four times the next-highest vertical total. | Medium | SM001 |
| CM020 | Traffic from AI agents and agentic browsers grew 7,851% year-over-year in 2025 per HUMAN's Defense Platform data, creating a new trust management challenge distinct from traditional bot detection. | Medium | SM001, SM010 |
| CM021 | Automated traffic across the internet grew 23.51% year-over-year in 2025 while human traffic increased only 3.10%, a ratio of approximately 8:1 (HUMAN Security 2026 benchmark report). | Medium | SM001, SM010 |
| CM022 | HUMAN Security was named a Leader in The Forrester Wave™: Bot and Agent Trust Management Software, Q2 2026, receiving the highest possible scores across nine evaluation criteria. | High | SM002, SM003 |
| CM023 | HUMAN was the only vendor in the Q2 2026 Forrester Wave evaluation to receive a 5/5 in the Threat Research criterion, underscoring differentiation via the Satori Threat Intelligence and Research team. | High | SM002, SM003 |
| CM024 | TAG awarded 307 certification seals to 196 companies in 2026 across four programs (Certified Against Fraud, Against Malvertising, Brand Safety Certified, Certified for Transparency), with 74% independently audited—acting as a market compliance driver for SIVT vendors. | High | SM008, SM009, SM018 |
| CM025 | Global cybersecurity spending is projected to reach $240 billion in 2026, a 12.5% year-over-year increase (Gartner), with approximately 40% of enterprise security budgets allocated to software and platforms. | Medium | SM025, SM026 |
| CM026 | Despite increased security budgets, 63% of organizations still experienced breaches in 2025, suggesting that budget growth alone is insufficient and creating demand for more effective behavioral and signal-based platforms. | Medium | SM025 |
| CM027 | AI-driven traffic surged 187% in 2025 from January to December (HUMAN data), fundamentally changing the nature of bot detection requirements from static rule-based systems to continuous behavioral validation across the session lifecycle. | Medium | SM001, SM010 |
| CM028 | Cloudflare holds approximately 79% of bot management install-base market share compared to Akamai's 6%, based on technology adoption data across major global markets in 2026. | Medium | SM014 |
| CM029 | Cloudflare's bundled CDN, WAF, and bot management offering starts at approximately $350 per year for SMBs with flat-rate predictable pricing, creating a price-point barrier that pure-play bot defense vendors cannot easily match at the lower market. | Medium | SM014 |
| CM030 | DataDome's market share in bot management fell from 13.8% to 8.9% between 2025 and 2026, potentially indicating headwinds for dedicated bot management vendors from Cloudflare's growing bundled security offer. | Low | SM017 |
| CM031 | Enterprise bot management solutions integrate deeply into login flows, checkout APIs, and analytics pipelines; migration to a new vendor requires thorough retesting of all affected flows, creating high switching costs that protect incumbents but slow new-logo acquisition. | Medium | SM017 |
| CM032 | HUMAN Security does not publish public pricing; enterprise contracts are custom-quoted following an environmental audit, creating sales friction compared to self-serve competitors such as Cloudflare and lengthening sales cycles. | Medium | SM021 |
| CM033 | Bot mitigation ROI primarily appears as fraud losses avoided rather than incremental revenue, making the benefit 'invisible' in P&L statements and requiring sophisticated measurement frameworks to justify budget approval from non-technical stakeholders. | Medium | SM017 |
| CM034 | In-house fraud rule engines and data-science teams represent a build-versus-buy alternative at large internet platforms with sufficient ML engineering capacity, limiting HUMAN's SAM to companies without that internal capability. | Medium | SM017 |
| CM035 | The $88.77 billion eCommerce FDP market estimate (Business Research Company) and the $1.27 billion bot security estimate (Fortune BI) are both 2026 figures but reflect incompatible scope boundaries: the eCommerce FDP estimate includes payment fraud, chargebacks, and identity proofing that HUMAN does not address. | Medium | SM012, SM005 |
| CM036 | Grand View Research's $40.4 billion fraud detection market estimate includes AML, KYC, payment fraud, and identity proofing, categories outside HUMAN's current scope; using this figure as HUMAN's TAM would overstate the relevant market by an estimated 30-40x. | Medium | SM011, SM005 |
| CM037 | Cloudflare and Akamai's bundling of bot management with CDN and WAF services may displace standalone bot defense vendors from a significant portion of the addressable market, particularly in the SMB and lower-mid market segments where flat-rate pricing is decisive. | Medium | SM014, SM017 |
| CM038 | Pixalate's Q1 2026 Ad Fraud Benchmark Report measured 24% IVT on US desktop and mobile web, 32% on mobile apps, and 24% on CTV, confirming persistent invalid traffic across all programmatic channels. | Medium | SM007 |
| CM039 | Europe maintained the lowest regional IVT rate at 7.80% while Asia-Pacific showed the highest at 27.85%, indicating that HUMAN's addressable market for SIVT defense is geographically uneven, with North America and APAC being the largest opportunities. | Medium | SM006 |
| CM040 | HUMAN's Ad Fraud Defense pre-bid platform and Ad Fraud Sensor post-serve platform hold MRC accreditation (renewed April 2025) for GIVT and SIVT detection across desktop, mobile web/app, and CTV environments. | Medium | SM013, SM016 |
| CM041 | AI training crawlers made up 67.5% of AI-driven traffic in 2025 but their share declined sharply as AI scraper traffic grew 597%, shifting the dominant automated threat from passive indexing to active data harvesting. | Medium | SM001 |
| CM042 | Forrester renamed the market category from 'Bot Management' to 'Bot and Agent Trust Management Software' in 2025, reflecting the structural shift from distinguishing human vs. bot traffic to governing whether an AI agent can be trusted to transact on a user's behalf. | High | SM002, SM003 |
| CM043 | HUMAN launched AgenticTrust in 2025, a module within Sightline Cyberfraud Defense that provides a unified approach for distinguishing among human, bot, and agentic AI traffic with granular agent permissions. | Medium | SM002, SM025 |
| CM044 | HUMAN announced support for Amazon Web Services' Bedrock AgentCore browser through AgenticTrust, verifying that AI-powered agents built on AWS infrastructure are cryptographically signed, policy-compliant, and secure. | Medium | SM002 |
| CM045 | HUMAN Security was named the top overall Leader in the G2 Summer 2026 Grid for Bot Detection and Mitigation Software, based entirely on verified customer feedback. | Medium | SM003 |
| CM046 | EXTE integrated HUMAN Security's MediaGuard (Ad Fraud Defence) in March 2026 as a supply-quality layer, making HUMAN the verification provider for EXTE's programmatic ad inventory. | Medium | SM016 |
| CM047 | The eCommerce-specific fraud prevention solutions market is separately valued at $8.31 billion in 2026 at a CAGR of 20.63% through 2032 (360i Research), providing an intermediate estimate between the bot-security-only figure and the broadest all-FDP estimate. | Low | SM012 |
| CM048 | 41% of AI scraper traffic in 2025 targeted media and streaming websites, while 37% targeted e-commerce, confirming these as the two highest-volume verticals for AI-driven data harvesting attacks. | Medium | SM001 |
| CM049 | HUMAN Security raised $50 million in growth funding in October 2024 (led by Riverwood Capital) and $100 million in January 2022 (led by WestCap and NightDragon), providing capital to scale the Defense Platform across enterprise verticals. | Medium | SM020, SM026, SM022 |
| CM050 | AI-driven traffic in 2025 was generated predominantly by OpenAI (69% share), Meta (16%), and Anthropic (11%) across HUMAN's sensor network—indicating that the top AI platform operators drive the majority of agentic and scraper activity. | Medium | SM001 |
| CP001 | HUMAN Security's Human Defense Platform processed more than one quadrillion digital interactions across its global customer base in 2025. | Medium | SP006 |
| CP002 | Automated traffic grew 8x faster than human traffic year-over-year in 2025, as measured by HUMAN Security's platform data. | Medium | SP006 |
| CP003 | Monthly volumes of AI-driven traffic grew 187% from January to December 2025, nearly tripling over the calendar year. | Medium | SP006 |
| CP004 | AI agent and agentic browser traffic grew 7,851% year-over-year in 2025, per HUMAN Security's 2026 State of AI Traffic benchmark report. | Medium | SP006 |
| CP005 | HUMAN Security was named a Leader in The Forrester Wave—Bot and Agent Trust Management Software, Q2 2026. | Medium | SP003 |
| CP006 | HUMAN received the highest possible scores in nine criteria in the Forrester Wave Q2 2026, including Threat Research and AI Agent Trust Management. | Medium | SP003 |
| CP007 | Forrester wrote that HUMAN's partnership program is a standout, citing breadth and alignment with emerging agentic trust and agentic commerce use cases. | Medium | SP003 |
| CP008 | G2's Summer 2026 Grid named HUMAN Security | Medium | SP004 |
| CP009 | HUMAN Security launched the Ad Integrity Suite in June 2026, positioning it as a modern alternative to legacy ad verification providers like DoubleVerify and IAS. | Medium | SP005 |
| CP010 | HUMAN's Ad Integrity Suite combines IVT intelligence, AI-powered brand safety and suitability, and viewability in a single framework with URL-level explainability. | Medium | SP005 |
| CP011 | Kasada secured a $20 million funding round in February 2026, led by EQT with participation from Ten Eleven Ventures, Main Sequence Ventures, and other existing investors. | Medium | SP001 |
| CP012 | Kasada was named a Leader in The Forrester Wave—Bot and Agent Trust Management Software, Q2 2026. | Medium | SP002 |
| CP013 | Kasada received the highest possible scores in nine criteria in the Forrester Wave Q2 2026, including Account and Trust Protection, AI Agent Trust Management, and Transaction Assurance and Protection. | Medium | SP002 |
| CP014 | Kasada's platform protects more than $150 billion in eCommerce revenue for targeted enterprises, per company claims. | Medium | SP001 |
| CP015 | More than 85% of Kasada customers previously used another bot mitigation provider before switching to Kasada, per company disclosure. | Medium | SP001 |
| CP016 | Kasada claims an average customer ROI of over 250%, driven primarily by operational cost savings. | Medium | SP001 |
| CP017 | Kasada raised a total of $64.2 million across six funding rounds as of its December 2025 Series C closing. | Medium | SP023 |
| CP018 | Kasada differentiates by detecting attacks at the earliest point where automation begins, operating without CAPTCHAs or friction for legitimate users. | Medium | SP001 |
| CP019 | Arkose Labs raised $114 million in total funding from investors including PayPal, USVP, and SoftBank Vision Fund, with its last major round a Series C in 2021. | Medium | SP017 |
| CP020 | Arkose Labs claims a 95% reduction in automated attacks and prevention of over $50 million in annual fraud losses for customers. | Medium | SP016 |
| CP021 | Adobe uses Arkose Bot Manager to reduce fake account creation and bot abuse, citing measurable security improvements without compromising customer experience. | Medium | SP016 |
| CP022 | In PeerSpot's June 2026 Bot Management category data, Imperva holds the largest mindshare at 15.7%, followed by Akamai at 9.7%, and HUMAN at 8.1%. | Medium | SP024 |
| CP023 | Arkose Labs holds 5.0% mindshare in the PeerSpot Bot Management category as of June 2026, up from 2.8% the prior year. | Medium | SP007 |
| CP024 | DataDome raised $42.4 million in total funding, with a Series C of $42 million in March 2023 led by InfraVia Growth. | High | SP008, SP015 |
| CP025 | DataDome reported $36 million ARR in 2024, up from $16.9 million in 2023, representing 113% year-over-year ARR growth. | Medium | SP015 |
| CP026 | DataDome protects over 300 enterprises including Rakuten, Reddit, and AngelList from bot attacks. | Medium | SP008 |
| CP027 | Fingerprint reported 65% annual recurring revenue growth in fiscal year 2026, with a 36% growth in its customer base. | High | SP009, SP025 |
| CP028 | Fingerprint serves 2,000 customers in over 56 countries and achieved a net revenue retention rate of 128% in fiscal year 2026. | Medium | SP009 |
| CP029 | Fingerprint's device intelligence platform identifies over 1 billion unique devices per month, a 77% year-over-year increase. | Medium | SP009 |
| CP030 | In 2025, 4.4% of desktop browser identifications showed browser tampering techniques designed to confuse fingerprinting systems, nearly double the 2.6% rate from 2024. | Medium | SP010 |
| CP031 | Cloudflare's Bot Management is an Enterprise plan-only add-on that detects simple and sophisticated bots, headless browsers, and domain-specific anomalies using ML-based bot scoring with JA3/JA4 fingerprinting. | Medium | SP011 |
| CP032 | Cloudflare enterprise contracts range from approximately $5,000 to $80,000+ per month with no public rate card, and Bot Management is bundled, making it near-zero marginal cost for existing enterprise customers. | Medium | SP012 |
| CP033 | DoubleVerify reported full-year 2025 revenue of $748.3 million, a 14% year-over-year increase, with net revenue retention of 109%. | High | SP019, SP021 |
| CP034 | DoubleVerify holds a 67.08% market share in the ad fraud detection category with 4,324 tracked customers, versus Integral Ad Science's 2.59% market share and 167 customers. | Medium | SP013 |
| CP035 | Integral Ad Science reported revenue of $590.67 million for the twelve months ending Q1 2026. | Medium | SP021 |
| CP036 | CHEQ processes six trillion signals daily across one million monitored domains, claiming a 0.009% false positive rate. | Medium | SP020 |
| CP037 | Netacea was named a Strong Performer in the Forrester Wave—Bot and Agent Trust Management Software Q2 2026, with the highest possible scores in web and LLM scraping management and transaction assurance and protection criteria. | Medium | SP014 |
| CP038 | Netacea's internal data shows 18% of LLM scraping traffic is unannounced, meaning it mimics human click patterns to bypass client-side JavaScript and CAPTCHA tests. | Medium | SP014 |
| CP039 | Netacea differentiates on a fully managed service model where detection configuration and ongoing tuning is handled by the Netacea team rather than the customer. | Medium | SP014 |
| CP040 | In PeerSpot's June 2026 Bot Management category, Imperva ranks first with 15.7% mindshare, Akamai ranks second with 9.7%, both above HUMAN Security's 8.1%. | Medium | SP024, SP007 |
| CP041 | Forrester noted that HUMAN's threat research team conducts coordinated attack takedowns that create impact far beyond its own customer base, a capability cited as uniquely differentiating. | Medium | SP003 |
| CP042 | Over 95% of AI-driven traffic in 2025 was concentrated in three industries—retail and eCommerce, streaming and media, and travel and hospitality—which match HUMAN Security's core enterprise verticals. | Medium | SP006 |
| CP043 | OpenAI generated approximately 69% of all observed AI bot traffic in 2025, with Meta accounting for 16% and Anthropic 11%, per HUMAN Security's 2026 benchmark report. | Medium | SP006 |
| CP044 | Post-login account compromise attempts more than quadrupled year-over-year in 2025, with HUMAN Security's platform flagging an average of 402,000 attempts per organization. | Medium | SP006 |
| CP045 | Carding volume has surged 250% since 2022, per HUMAN Security's 2026 State of AI Traffic and Cyberthreat Benchmark Report. | Medium | SP006 |
| CP046 | Forrester renamed the Bot Management category to Bot and Agent Trust Management in 2026, reflecting the shift from detecting bots to governing trust for human, bot, and AI agent traffic. | Medium | SP014, SP003 |
| CI001 | HUMAN Security raised a $100 million growth round in January 2022 led by WestCap and NightDragon, with additional investment from Goldman Sachs Asset Management. | High | SI001, SI009 |
| CI002 | At the time of the July 2022 PerimeterX merger, the combined HUMAN+PerimeterX entity reported more than $100 million in ARR and 500+ customers. | High | SI002, SI009 |
| CI003 | HUMAN Security's January 2024 CEO transition announcement stated that Tamer Hassan led the company to surpass $100 million in ARR during his tenure. | Medium | SI009, SI025 |
| CI004 | GetLatka reported HUMAN Security revenue of $15 million ARR as of December 2023, directly conflicting with the company's stated $100M-plus ARR. | Medium | SI003 |
| CI005 | GrowJo's employee-count model estimates HUMAN Security annual revenue at $140.4 million, which is broadly consistent with the company's >$100M ARR claim and post-merger scale. | Low | SI022 |
| CI006 | HUMAN Security's Human Defense Platform verified over 20 trillion digital interactions per week as of October 2024. | Medium | SI007, SI008 |
| CI007 | In 2025, HUMAN's platform analyzed more than one quadrillion digital interactions over the full year per the company's 2026 State of AI Traffic Benchmark Report. | Medium | SI018 |
| CI008 | As of October 2024, HUMAN Security served more than 500 global brands across advertising, application, and account protection use cases. | Medium | SI007, SI008, SI014 |
| CI009 | Vendr's 2025 procurement benchmark reports the median enterprise annual spend on HUMAN Security products at $104,906 per year. | Medium | SI004 |
| CI010 | Vendr benchmarks show the enterprise pricing range for HUMAN Security from approximately $46,601 at the low end to over $1.34 million per year for large complex deployments. | Medium | SI004 |
| CI011 | HUMAN Security does not publish a standard price card; all enterprise pricing is custom-negotiated based on traffic volume, protected assets, and module mix. | Medium | SI005, SI004 |
| CI012 | HUMAN announced new packaging and pricing would be rolled out in 2024 as part of its channel programme launch, according to CRO Chris Scanlan at RSA 2024. | Medium | SI005 |
| CI013 | HUMAN Security's Human Defense Platform is structured around three commercial pillars: advertising and media protection, application security and bot mitigation, and account protection. | Medium | SI007, SI017 |
| CI014 | HUMAN acquired clean.io in November 2022 to add malvertising and e-commerce fraud protection capabilities to the platform; financial terms were not disclosed. | Medium | SI023, SI010 |
| CI015 | HUMAN merged with PerimeterX in July 2022, adding enterprise application security, account fraud, and carding protection to the Human Defense Platform. | High | SI002, SI009 |
| CI016 | HUMAN launched HUMAN Sightline Cyberfraud Defense featuring AgenticTrust in July 2025, providing visibility and governance across humans, bots, and AI agents. | Medium | SI013, SI017 |
| CI017 | AgenticTrust, launched as part of HUMAN Sightline in July 2025, extends the platform's coverage to classify and govern AI agent traffic separately from human and bot activity. | Medium | SI013, SI014 |
| CI018 | HUMAN launched the HUMAN Advantage Partner Program in August 2024, a tiered channel programme offering incentives based on annualized bookings, training completion, and customer retention. | Medium | SI014, SI016 |
| CI019 | In November 2022, HUMAN partnered with Carahsoft Technology as its Master Government Aggregator, enabling public sector procurement through NCPA, E&I, and OMNIA cooperative contracts. | Medium | SI019 |
| CI020 | Prior to 2024, HUMAN Security operated as a historically direct-minded sales organization with no formal channel programme and enterprise sales cycles of six to seven months for large accounts. | Medium | SI005 |
| CI021 | Chris Scanlan joined HUMAN as Chief Revenue Officer in 2024, previously President and CRO at ExtraHop, to lead the commercial and channel transformation. | Medium | SI005, SI016 |
| CI022 | HUMAN's ecosystem-first GTM strategy is designed to reach fragmented buyer personas including security, commerce, digital, and marketing teams through partner-embedded distribution rather than direct sales alone. | Medium | SI011, SI014 |
| CI023 | HUMAN's enterprise sales cycle for large customers was 6–7 months pre-channel programme, attributable to the need to negotiate legal agreements, MSAs, and pricing directly with enterprise procurement teams. | Medium | SI005 |
| CI024 | SaaS industry benchmark (Benchmarkit 2024/2025) shows sales and marketing expense at 47% of revenue for VC-backed private SaaS companies. | Medium | SI020 |
| CI025 | SaaS industry benchmark (Benchmarkit 2024/2025) shows R&D expense at 34% of revenue for private SaaS companies, versus 23% for public SaaS companies. | Medium | SI020 |
| CI026 | SaaS benchmark ARR per FTE is approximately $200,000 for companies at $50–100M ARR and rises to $300,000 per FTE for companies above $100M ARR. | Medium | SI020 |
| CI027 | HUMAN Security's signal collection and ML inference infrastructure for processing 20 trillion-plus digital interactions per week constitutes a material and scaling cloud compute cost centre. | Medium | SI007, SI018 |
| CI028 | HUMAN's Satori Threat Intelligence and Research Team, responsible for bot research, threat takedowns, and attack intelligence, represents a significant human-in-the-loop cost centre that increases operating expenses relative to pure SaaS peers. | Medium | SI017, SI014 |
| CI029 | White Ops, Inc. (HUMAN Security's predecessor entity, CIK 0001611028) filed a Form D with the SEC in June 2014 for a $11.1 million Series A exempt offering, confirming Delaware incorporation and early institutional fundraising. | Medium | SI024 |
| CI030 | HUMAN Security's headcount was estimated at approximately 469 employees as of 2026 per PitchBook, and 519 employees per Tracxn as of May 2026, up from 197 in late 2023. | Medium | SI015, SI016 |
| CI031 | In connection with the July 2022 PerimeterX merger, HUMAN received a $100 million debt facility from Blackstone Credit; the current repayment or extension status of this facility is not publicly confirmed as of June 2026. | Medium | SI002, SI023 |
| CI032 | In October 2024, HUMAN closed a $50 million-plus growth round led by WestCap, with additional investment from Goldman Sachs Asset Management, ClearSky Security, NightDragon, and Vertex Ventures US. | High | SI006, SI007, SI008 |
| CI033 | HUMAN Security's total equity raised is approximately $300 million as of October 2024 across eight funding rounds, per company statement and corroborating news sources. | High | SI007, SI006 |
| CI034 | Based on approximately 500 employees at an industry-average fully-loaded cost of $180,000–$220,000 per year, HUMAN's inferred annual payroll is $90–$110 million, implying a monthly burn rate of $9–$13 million including cloud infrastructure and G&A. | Low | SI015, SI020 |
| CI035 | HUMAN Security was named a Leader in The Forrester Wave for Bot Management Software Q3 2024, receiving the top strategy score and highest possible scores across nine criteria. | Medium | SI012, SI017 |
| CI036 | In June 2026, HUMAN Security was named a Leader in the Forrester Wave for Bot and Agent Trust Management Software Q2 2026, the only vendor to receive the top score in Threat Research, reflecting its expanded market position in the agentic AI era. | Medium | SI014, SI017 |
| CI037 | HUMAN Security's burn rate, gross margin, net revenue retention, and exact ARR breakdown by product segment are not publicly disclosed, creating material financial diligence blockers that cannot be resolved from public sources. | Medium | |
| CI038 | HUMAN Security's capital structure includes a $100 million Blackstone Credit debt facility from 2022 whose repayment or extension status is unconfirmed, creating leverage uncertainty that cannot be assessed from public disclosures alone. | Medium | SI002 |
| CE001 | As of 2026, the Human Defense Platform comprises four named product lines: HUMAN Advertising Protection (formerly MediaGuard), HUMAN Application Protection (formerly Bot Defender), HUMAN Account Protection (formerly Account Defender), and HUMAN Client-side Defense (formerly Code Defender). | High | SE001, SE009 |
| CE002 | The Human Defense Platform decision engine analyzes over 2,500 signals per interaction to produce each bot/human/AI-agent verdict. | High | SE001, SE009, SE014 |
| CE003 | The decision engine uses 400 or more adaptive machine learning models to analyze the collected signals and detect automated threats. | High | SE001, SE009, SE014 |
| CE004 | HUMAN's behavioral signal network processes over 20 trillion digital interactions weekly across approximately 3 billion unique devices. | High | SE001, SE009, SE003 |
| CE005 | HUMAN's decision engine enforces protection decisions at the edge in under 2 milliseconds. | High | SE001, SE009 |
| CE006 | Approximately 95% of users are validated automatically by HUMAN's Precheck mechanism without any user-visible friction or challenge. | High | SE001, SE009 |
| CE007 | According to HUMAN's 2026 State of AI Report, automation (AI agent traffic) is growing eight times faster than human web traffic. | Medium | SE006, SE017, SE025 |
| CE008 | HUMAN Advertising Protection (formerly MediaGuard) safeguards digital advertising supply chains with pre-bid and post-bid IVT detection, malvertising defense, and the FraudSensor viewability product. | High | SE001, SE010 |
| CE009 | HUMAN Application Protection (formerly Bot Defender) protects web and mobile applications and APIs from scraping, credential stuffing, transaction abuse, fake signups, and client-side script attacks. | High | SE001, SE010 |
| CE010 | HUMAN Account Protection (formerly Account Defender) provides pre-login, at-login, and post-login security across the full account lifecycle to prevent ATO and fake account fraud. | High | SE001, SE010 |
| CE011 | HUMAN Client-side Defense (formerly Code Defender) monitors and enforces third-party JavaScript behavior in consumer browsers and explicitly supports PCI DSS 4 client-side compliance requirements. | High | SE001, SE010 |
| CE012 | BotGuard for Growth Marketing is a HUMAN module that protects marketing funnels and lead generation pipelines from bot-driven click fraud, fake leads, and affiliate-code abuse. | Medium | SE010, SE001 |
| CE013 | HUMAN Sightline Cyberfraud Defense was launched on July 30, 2025, as a unified trust and defense layer providing actor-level visibility across humans, bots, and AI agents across the full digital customer journey. | High | SE018, SE009, SE004 |
| CE014 | AgenticTrust, a module within HUMAN Sightline, was launched in 2025 to classify AI agent activity, prevent spoofing, and apply granular per-agent governance controls on digital properties. | High | SE018, SE004 |
| CE015 | HUMAN's deployment architecture uses a JavaScript Sensor (client-side signal collection) paired with an Enforcer (server-side or edge-layer enforcement), with the minimum Sensor version for AgenticTrust support being v9.6.6. | High | SE002, SE009, SE001 |
| CE016 | HUMAN offers over 20 Enforcer integration targets, including AWS Lambda@Edge (v4.8.0+), AWS API Gateway (v0.1.1+), Cloudflare (v6.12.0+), Fastly VCL (v12.3.0+), Akamai EdgeWorker (v4.4.0+), Azure Front Door (v1.2.1+), F5 BIG-IP (v3.1.1+), Nginx, Apache, Kong, Go, Java, Node Express, and Salesforce. | High | SE002, SE001 |
| CE017 | PHP, Python 2, Python 3, Ruby, Akamai ESI, and ASP.NET runtimes are explicitly listed as unsupported for HUMAN's AgenticTrust module as of the June 2026 documentation. | Medium | SE002 |
| CE018 | HUMAN Sightline integrates with WAF, CDN, CIAM, and analytics infrastructure including Adobe Experience Platform and Salesforce, enabling deployment across existing customer security stacks. | Medium | SE018, SE004 |
| CE019 | The platform enforces bot verdicts in under 2 milliseconds at the CDN or origin edge, with the Precheck mechanism validating approximately 95% of traffic automatically. | High | SE009, SE001 |
| CE020 | HUMAN uses a Precheck mechanism to auto-validate the majority of sessions and a Human Challenge for ambiguous interactions, minimizing friction for legitimate users while maintaining protection. | High | SE009, SE001 |
| CE021 | HUMAN's decision engine has been enhanced with over 400 ML algorithms for superior threat detection, improved mitigation tracking, and advanced reporting providing analytics on malicious activities. | Medium | SE014, SE001 |
| CE022 | HUMAN introduced Profile Deviation ML Models 2.0, which enhance detection precision for post-login malicious activity by tracking behavioral deviations from established user profiles. | Medium | SE014 |
| CE023 | HUMAN's attack profiling capability segments traffic into distinct behavioral profiles for deeper analysis of in-progress attack campaigns. | Medium | SE014, SE004 |
| CE024 | HUMAN Threat Tracker delivers attack analytics intelligence to security teams, providing visibility into attacker behavior patterns and enabling proactive identification of attack trends. | Medium | SE014, SE004 |
| CE025 | HUMAN's FraudSensor is a post-bid detection system that validates ad impressions after serving, filters IVT before calculating viewability rates, and analyzes supply-path-level signals to identify the specific supply paths driving quality problems. | High | SE003, SE001 |
| CE026 | Page Intelligence, a component of Sightline, provides real-time page-level insights into invalid traffic to help marketing teams understand which campaigns and channels drive genuine engagement. | Medium | SE004, SE016 |
| CE027 | HUMAN's Satori Threat Intelligence and Research Team is led by Lindsay Kaye (Vice President of Threat Intelligence) and Gavin Reid (CISO, formerly VP of Threat Intelligence). | Medium | SE007, SE005 |
| CE028 | In May 2026, HUMAN's Satori team disrupted the Trapdoor operation, a multi-stage ad fraud and malvertising scheme involving 455 malicious Android apps and 183 threat-actor-owned HTML5 domains; Google removed all identified apps from Google Play. | Medium | SE007 |
| CE029 | At its peak, the Trapdoor scheme accounted for 480 million bid requests per day, with associated malicious apps downloaded more than 24 million times before disruption. | Medium | SE007 |
| CE030 | HUMAN was the only vendor in the Forrester Wave Bot and Agent Trust Management Software Q2 2026 evaluation to receive a perfect 5 out of 5 score in the Threat Research criterion. | High | SE004, SE005 |
| CE031 | HUMAN's historical threat disruption operations include 3ve (FBI collaboration), Methbot (led to 10-year prison sentence), PARETO (CTV botnet with Roku and Google), Scylla (Google Play and Apple App Store SDK attack), BADBOX 2.0, SlopAds, and Pushpaganda. | High | SE013, SE020, SE007, SE004 |
| CE032 | On April 21, 2026, HUMAN announced the expansion of Agentic Visibility within Sightline to marketing and commerce teams, with native integration into Adobe Experience Platform as an official Adobe technology partner. | High | SE016, SE017, SE006 |
| CE033 | HUMAN's AgenticTrust extended support to cryptographic verification of Amazon Bedrock AgentCore traffic in 2026, enabling enterprises to authenticate AI agents built on AWS infrastructure via policy-compliant cryptographic signing. | High | SE008, SE002, SE001 |
| CE034 | HUMAN Security received MRC accreditation for its Ad Viewability Measurement product on April 27, 2026, covering display and video impressions across desktop, mobile web, and mobile app environments. | High | SE003, SE004 |
| CE035 | In November 2025, HUMAN open-sourced the HUMAN Verified AI Agent, a reference implementation using HTTP Message Signatures (RFC 9421) and the Google A2A protocol for cryptographic agent-to-service authentication with Ed25519 key pairs. | Medium | SE019 |
| CE036 | Automation (AI agent traffic) is growing 8 times faster than human traffic according to HUMAN's 2026 State of AI Report, making AI-agent governance a critical emerging capability. | Medium | SE006, SE016 |
| CE037 | During Super Bowl LX in February 2026, HUMAN tracked 74 million blocked retail scraping attacks, a 33% rise in invalid bid requests, and a 5% increase in AI agent activity within the broadcast window. | Medium | SE006, SE003 |
| CE038 | HUMAN Client-side Defense explicitly supports PCI DSS 4 client-side script compliance by detecting suspicious activity, enforcing automated policies, and mitigating malicious behavior without interrupting website operations. | High | SE001, SE010 |
| CE039 | HUMAN's MRC Ad Viewability accreditation covers display and video impressions across desktop, mobile web, and mobile app, with IVT filtering via FraudSensor embedded in the viewability measurement product—distinguishing it from conventional viewability-only vendors. | High | SE003, SE004 |
| CE040 | The 2022 acquisition of clean.io added real-time client-side JavaScript behavioral analysis for malvertising detection and cleanCart cart-protection technology to HUMAN's product suite. | High | SE012, SE013, SE020 |
| CE041 | At the time of HUMAN's clean.io acquisition in 2022, clean.io's technology protected more than 125 billion advertising impressions monthly across millions of websites and mobile applications. | High | SE013, SE020, SE012 |
| CE042 | HUMAN was named the number-one ranked vendor on G2's Summer 2026 Grid for Bot Detection and Mitigation Software, based entirely on verified customer reviews. | High | SE005, SE004 |
| CE043 | In the Forrester Wave Q2 2026 Bot and Agent Trust Management Software evaluation, HUMAN received the highest possible scores across nine criteria, including Threat Research, AI Agent Trust Management, Marketing Analytics Assurance, Intent Visibility, Attack and User Analytics, Customizable Reports and Dashboards, Security Operations Integrations, Vision, and Partner Ecosystem. | High | SE005, SE004 |
| CE044 | HUMAN's Bot Management mindshare on PeerSpot declined from 11.6% to 8.1% year-over-year as of June 2026, suggesting increased competitive pressure from emerging bot-management vendors. | Medium | SE011 |
| CE045 | Enterprise customers and analyst reviewers have identified HUMAN's decision engine as operating as a "black box," with limited visibility into model logic, signal weights, or detection thresholds, making independent auditability of false-positive rates difficult. | Medium | SE010, SE011 |
| CE046 | User reviews and analyst comparisons as of 2026 cite HUMAN's complex integration setup for bespoke API infrastructure and limited documentation depth for custom rule management as recurring areas for improvement. | Medium | SE015, SE010 |
| CU001 | HUMAN Security's customer base spans five segments — advertising/adtech platforms, e-commerce and retail, financial services, enterprise security (via channel), and travel/hospitality. | Medium | SU014, SU020, SU006 |
| CU002 | Adtech and programmatic advertising is HUMAN Security's largest historical customer segment, comprising DSPs, SSPs, ad networks, brand advertisers, and agency holding companies. | Medium | SU002, SU010, SU011, SU001 |
| CU003 | E-commerce and retail customers use HUMAN's Bot Defender and Sightline for scraping defense, ATO prevention, and high-heat release protection, with verified deployments at $500M–$1B and $10B+ revenue accounts per Gartner Peer Insights. | Medium | SU014 |
| CU004 | Financial services is an early-adoption segment with no publicly named customers, but HUMAN's May 2026 benchmark shows agentic AI traffic in the vertical doubled month-over-month, indicating growing deployment interest. | Low | SU020, SU025 |
| CU005 | Optiv, which serves 73% of the Fortune 100, and Consortium Networks are named channel partners delivering HUMAN's platform to enterprise security buyers as of August 2024. | Medium | SU004, SU005, SU006, SU008, SU018 |
| CU006 | A travel and hospitality company with $250M–$500M revenue described a production deployment of HUMAN's managed bot defense in a 5-star Gartner Peer Insights review dated March 2026. | Medium | SU014 |
| CU007 | HUMAN Security's company description on Gartner Peer Insights (updated February 2026) states the platform verifies "more than 30 trillion digital interactions per week," an increase from the 20 trillion per week figure cited at the October 2024 fundraise. | Medium | SU014, SU006 |
| CU008 | HUMAN Security claims 500+ global brands and organizations as customers, a figure that has appeared consistently in press releases and fundraise announcements from 2022 through August 2024. | Low | SU006, SU021 |
| CU009 | In calendar year 2025, HUMAN's Defense Platform analyzed over one quadrillion digital interactions, as disclosed in the March 2026 State of AI Traffic benchmark report. | Medium | SU020 |
| CU010 | HUMAN Security verifies more than 3 billion unique devices per month, per the August 2024 partner program launch announcement. | Medium | SU006, SU005 |
| CU011 | AI-driven traffic rates on HUMAN's platform grew 187% from January to December 2025, with the majority concentrated in retail/e-commerce, streaming/media, and travel/hospitality. | Medium | SU020 |
| CU012 | Traffic from AI agents and agentic browsers grew 7,851% year-over-year in 2025 per HUMAN's 2026 benchmark, representing a new category of automated traffic distinct from legacy bots. | Medium | SU020 |
| CU013 | AdRoll integrated HUMAN Security's dual-layer fraud detection (FraudSensor post-bid + MediaGuard pre-bid) in October 2025, becoming the first DSP to combine both solutions with IVT detection in 12 milliseconds. | Medium | SU001 |
| CU014 | Automated traffic across the internet grew 23.51% year-over-year in 2025 while human traffic grew only 3.10%, according to HUMAN's 2026 benchmark, creating strong structural demand for bot management. | Medium | SU020 |
| CU015 | HUMAN Security's Ad Fraud Defense (pre-bid) and Ad Fraud Sensor (post-bid) platforms hold MRC accreditation for GIVT and SIVT detection across Desktop, Mobile Web, Mobile In-App, and CTV environments, as confirmed by the MRC Board of Directors letter dated April 4, 2025. | High | SU013, SU012 |
| CU016 | HUMAN Security's Ad Viewability Measurement product received MRC accreditation for viewability across display and video impressions on desktop, mobile web, and mobile app environments, announced April 27, 2026. | High | SU012, SU001 |
| CU017 | Madhive, described by HUMAN CEO Stu Solomon as a "long-standing partner," launched a Fraud Free Guarantee in June 2025 powered by HUMAN's MRC-accredited pre-bid and post-bid fraud detection, covering 30,000+ daily local campaigns. | Medium | SU002, SU003 |
| CU018 | LinkedIn integrated HUMAN Security in May 2024 for pre-bid IVT filtering and post-bid detection across its desktop ad network and publisher network including CTV, with the integration protecting a 1 billion+ member professional community. | High | SU010, SU011 |
| CU019 | HUMAN detected less than 1% of desktop impressions as invalid traffic on LinkedIn's ad network in the first 30 days after the May 2024 integration, as disclosed in HUMAN and LinkedIn's joint announcement. | High | SU010, SU011 |
| CU020 | Sovrn, a publisher/advertiser platform, is cited by name in HUMAN's April 2026 MRC viewability accreditation announcement as an early adopter with MD Jeff Meglio providing a named endorsement of improved campaign performance. | Medium | SU012, SU001 |
| CU021 | Consortium Networks CEO Nate Ungerott provided a public testimonial at HUMAN's August 2024 channel program launch, describing HUMAN as bringing "exceptional value to our customers" for defending against sophisticated fraud. | Medium | SU004, SU006, SU018 |
| CU022 | Optiv is named by HUMAN as an "integral ally" channel partner with access to the full HUMAN Defense Platform, and serves 73% of the Fortune 100 as a cybersecurity integrator. | Medium | SU006, SU005 |
| CU023 | HUMAN Sightline Cyberfraud Defense holds a 4.7/5 overall rating on Gartner Peer Insights with a 4.8/5 for Service & Support and 4.7/5 for Product Capabilities, based on reviews updated through April 2026. | Medium | SU014 |
| CU024 | G2 recognized HUMAN Security as Best Security Software Product of 2026 ranking | Medium | SU007, SU022 |
| CU025 | A Gartner Peer Insights reviewer from a 1B–10B USD retail company states "We have a long relationship with Human," indicating a multi-year production deployment of HUMAN's bot defense solution. | Low | SU014 |
| CU026 | A Gartner Peer Insights reviewer from a $500M–$1B retail company gave HUMAN Sightline a 3/5 rating in April 2026, describing the product as a "black box" with limited visibility into detection logic and no proactive change notifications. | Medium | SU014 |
| CU027 | Gartner Peer Insights reviewers identify specific dislikes: sluggish dashboard performance, data access limited to the past two weeks, limited manual tuning capability, and opaque detector logic with no proactive notification of changes. | Medium | SU014 |
| CU028 | HUMAN's Forrester Wave Q2 2026 report states "HUMAN's customers compliment the level of detail and attack insight that they receive from the Sightline feature," indicating reference-quality satisfaction among evaluated accounts. | Medium | SU019 |
| CU029 | Industry-wide, 42% of cybersecurity customers switched vendors in the past two years due to poor customer experience, and 35% of cybersecurity churn is attributable to CX issues rather than product performance (ZipDo, Feb 2026). | Low | SU009 |
| CU030 | HUMAN Security does not disclose NRR, GRR, average contract length, or customer churn rate, as it is a private company; these are the highest-priority retention metrics for diligence. | Medium | SU021 |
| CU031 | The HUMAN Advantage Partner Program, launched August 21, 2024, structures partner compensation as a three-tier system rewarding annualized bookings, training completion, and customer retention. | Medium | SU004, SU005, SU006 |
| CU032 | The HUMAN Advantage Partner Program offers deal registration and incumbency protections to channel partners, designed to reduce channel conflict and improve account durability for enterprise customers. | Medium | SU005, SU006 |
| CU033 | HUMAN launched AgenticTrust, a module within Sightline Cyberfraud Defense, in 2025 to distinguish among human, bot, and agentic AI traffic; it received the highest possible Forrester score in the AI Agent Trust Management criterion in Q2 2026. | Medium | SU019, SU007 |
| CU034 | HUMAN announced support for Amazon Web Services' Bedrock AgentCore browser in AgenticTrust, enabling cryptographically signed, policy-compliant verification of AI agents built on AWS infrastructure. | Medium | SU019 |
| CU035 | HUMAN Security's public case studies and named customer deployments are predominantly in adtech and programmatic advertising (LinkedIn, Sovrn, Madhive, AdRoll), creating identifiable sector concentration in the advertising vertical. | Medium | SU002, SU010, SU011, SU012, SU001 |
| CU036 | No top-customer revenue share, customer count by segment, or ARR breakdown is publicly disclosed by HUMAN Security, making it impossible to quantify concentration risk from external evidence alone. | Medium | SU021 |
| CU037 | HUMAN's Riskified partnership (announced August 2026 per RivalSense competitive intelligence) targets ecommerce fraud prevention via AI Agent Approve and AI Agent Intelligence, extending reach beyond core adtech buyers. | Low | SU017 |
| CU038 | Enterprise direct-sales cycles of 6–7 months for large accounts were a documented pre-2024 friction point; the channel program launched specifically to reduce this barrier via partner-led onboarding and managed service. | Medium | SU004, SU005 |
| CU039 | HUMAN Security launched Page Intelligence in October 2025, extending fraud detection to the landing page (the gap between click and user interaction), giving brands and publishers real-time IVT visibility via a lightweight asynchronous tag using 400+ algorithms. | Medium | SU015, SU016 |
| CU040 | A 10B+ USD retail company Gartner reviewer (March 2026) states HUMAN enabled "a very secure online presence" and helped become "one of the very few sneaker retailers without a waiting room," indicating multi-brand platform-wide production deployment. | Medium | SU014 |
| CU041 | HUMAN Security's product innovation in 2025–2026 (AgenticTrust, Page Intelligence, MRC viewability, AWS Bedrock support) represents significant expansion surface into marketing analytics buyers beyond traditional security teams. | Medium | SU019, SU015, SU012 |
| CR001 | The FTC sent formal warning letters to 13 data brokers under PADFAA on February 9, 2026, signaling active regulatory scrutiny of mass-scale behavioral data vendors. | High | SR006, SR012 |
| CR002 | HUMAN Security processes more than one quadrillion digital interactions per year, creating a large-scale behavioral data collection and analytics surface. | Medium | SR001, SR002 |
| CR003 | HUMAN's Ad Viewability Measurement solution earned MRC accreditation in April 2026 for display and video impressions across desktop, mobile web, and mobile app. | High | SR002, SR027 |
| CR004 | As of January 2026, 20 U.S. states are actively enforcing comprehensive consumer privacy laws, creating a multi-jurisdictional compliance patchwork for data vendors. | High | SR012, SR020 |
| CR005 | The DOJ Data Security Program restricts bulk cross-border data transfers involving "countries of concern," requiring CISA-compliant security controls for covered data flows. | High | SR006, SR020 |
| CR006 | Plaintiff attorneys have developed a novel theory using DSP violations as predicates for federal Wiretap Act class action claims against adtech behavioral data flows. | Medium | SR006 |
| CR007 | No active regulatory enforcement or litigation specifically targeting HUMAN Security is publicly known as of June 2026. | Medium | SR005, SR012 |
| CR008 | The Check My Ads Institute argues that MRC self-regulation is structurally insufficient for adtech accountability and calls for mandatory government regulation. | Medium | SR007 |
| CR009 | The MRC finalized Digital Advertising Auction Transparency Standards in January 2026, mandating disclosure of auction mechanics, pricing, and reporting by accredited vendors. | Medium | SR026, SR007 |
| CR010 | Online privacy lawsuit filings surged from approximately 200 in 2023 to approximately 4,000 in 2024 and continued rising through 2025, targeting behavioral tracking technologies. | Medium | SR020 |
| CR011 | Bot detection systems produce false positives for privacy-tool users including VPN subscribers, ad blocker users, and non-mainstream browser operators. | Medium | SR003, SR004 |
| CR012 | HUMAN's Defense Platform processes more than 20 trillion digital interactions weekly and over one quadrillion annually, requiring substantial cloud compute infrastructure. | High | SR001, SR002 |
| CR013 | Automated internet traffic grew 23.51% year-over-year in 2025, while AI-driven traffic grew 187% from January to December per HUMAN's 2026 benchmark report. | Medium | SR001 |
| CR014 | HUMAN customers averaged over 400,000 attempted post-login account takeover attacks in 2025, more than quadruple the 2024 baseline, per HUMAN's own benchmark data. | Medium | SR001 |
| CR015 | An AWS thermal event in US-EAST-1 on May 7–8, 2026 cascaded across more than 150 downstream cloud services, including security vendors reliant on that availability zone. | Medium | SR008, SR029 |
| CR016 | An AWS data center in the UAE (ME-CENTRAL-1) was struck by a kinetic attack on March 1–2, 2026, causing fires, power loss, and service disruption across 38+ AWS services in the UAE and 46+ in Bahrain. | Medium | SR029 |
| CR017 | BADBOX 2.0 evolved from BADBOX 1.0 using new backdoor mechanisms in direct response to HUMAN Security's original exposure, demonstrating rapid threat-actor adaptation. | Medium | SR009, SR023 |
| CR018 | DoubleVerify detected 140% more CTV fraud schemes and variants in Q1 2026 versus Q1 2025, fueled by AI-assisted fraudster tooling that automates scheme creation. | Medium | SR014 |
| CR019 | AI is automating high-velocity attacker operations in 2026, enabling low-skill threat actors to conduct high-impact attacks including deepfakes and automated exploit development. | Medium | SR017 |
| CR020 | The window between vulnerability disclosure and active exploitation collapsed from weeks to days in the second half of 2025 per Google Cloud threat research. | Medium | SR018 |
| CR021 | Ad blockers suppress anti-bot detection scripts, causing detection systems to classify privacy-conscious users as bots due to apparent JavaScript execution absence. | Medium | SR003, SR004 |
| CR022 | Fraud detection model performance degrades when data pipelines are fragmented by GDPR and CCPA data residency and processing restrictions. | Medium | SR030 |
| CR023 | Cloudflare is ranked #3 in Bot Management with 9.2% mindshare versus HUMAN at #5 with 8.1% per Gartner Peer Insights and PeerSpot comparisons as of 2026. | Medium | SR015, SR016 |
| CR024 | Cloudflare One achieves higher long-term ROI than HUMAN Defense Platform per independent user reviews due to its integrated multi-layer security suite. | Medium | SR016 |
| CR025 | HUMAN depends on Google to update Play Protect and execute C2 sinkholing for BADBOX-class botnet disruptions; HUMAN cannot sinkhole infrastructure unilaterally. | Medium | SR009, SR010 |
| CR026 | The ad verification market has consolidated to a near-duopoly of DoubleVerify and Integral Ad Science as listed public companies with scale cost advantages. | Medium | SR011, SR021 |
| CR027 | More than 95% of AI-driven automation traffic is concentrated in retail/ecommerce, streaming/media, and travel/hospitality verticals per HUMAN's 2026 benchmark. | Medium | SR001 |
| CR028 | MRC accreditation is voluntary, and critics argue the MRC lacks sufficient governance independence from the entities it accredits to enforce meaningful standards. | Medium | SR007, SR026 |
| CR029 | The Shadowserver Foundation sinkholed BADBOX 2.0 command-and-control domains, diverting over one million infected devices from criminal servers as part of the 2025 disruption. | Medium | SR022, SR025 |
| CR030 | HUMAN's ML inference at 20T+ weekly interaction scale requires substantial public cloud compute; AWS is inferred as the primary provider given HUMAN's infrastructure profile. | Medium | SR001, SR029 |
| CR031 | Google, Meta, and Amazon provide in-house fraud detection for walled-garden inventory, reducing the addressable market for third-party verification on premium impressions. | Medium | SR011 |
| CR032 | Google filed a lawsuit against 25 alleged BADBOX 2.0 operators in New York federal court, supported by evidence contributed by HUMAN Security and Trend Micro. | Medium | SR023, SR025 |
| CR033 | HUMAN Security's most recently disclosed valuation is $1.5 billion from January 2022, predating both the PerimeterX merger and the October 2024 growth round. | Medium | SR019 |
| CR034 | HUMAN remains a private company with no publicly disclosed ARR, gross margin, burn rate, or net revenue retention as of June 2026. | Medium | SR019 |
| CR035 | HUMAN's Bot Management market mindshare of 8.1% places it fifth in the competitive stack behind Cloudflare, Akamai, Imperva, and Radware per available review data. | Medium | SR015, SR016 |
| CR036 | The AI ad fraud and bot detection market includes six or more competing tools: HUMAN Security, CHEQ, DoubleVerify, IAS, Cloudflare Bot Management, and DataDome. | Medium | SR021 |
| CR037 | Bundled security platform solutions from Google, Meta, and Amazon eliminate marginal cost for enterprise customers already committed to those platforms, reducing HUMAN's pricing power. | Medium | SR011, SR031 |
| CR038 | Global digital advertising fraud is estimated at $80–$100 billion annually; HUMAN operates in a permanent escalating arms race with fraudsters. | Medium | SR011, SR028 |
| CR039 | HUMAN announced a $50M+ growth round in October 2024, described by CEO Stu Solomon as deliberately constrained to enable targeted investment without over-capitalization. | Medium | SR019 |
| CR040 | Fraud signature drift causes ML rule engines to expire before teams can update them, requiring continuous retraining cycles that increase COGS for detection platforms. | Medium | SR030, SR017 |
| CR041 | Agentic AI traffic grew 7,851% year-over-year in 2025, representing a new threat surface that existing binary bot/human classification systems do not fully address. | Medium | SR001 |
| CR042 | HUMAN's board is dominated by investor representatives from Goldman Sachs, NightDragon, WestCap, and ClearSky, creating governance concentration around investor return timelines. | Medium | SR019 |
| CV001 | White Ops was acquired by Goldman Sachs Merchant Banking Division, ClearSky Security, and NightDragon in December 2020 for an undisclosed purchase price. | High | SV015, SV014 |
| CV002 | HUMAN Security raised a $100 million growth round in January 2022 led by WestCap and NightDragon with participation from Goldman Sachs Asset Management. | High | SV014, SV017 |
| CV003 | In connection with the July 2022 PerimeterX merger, HUMAN Security's combined entity was valued at approximately $1.5 billion according to reporting from multiple independent sources. | Medium | SV015, SV022 |
| CV004 | In October 2024, HUMAN Security closed a $50 million-plus growth round led by WestCap, with additional investment from Goldman Sachs Asset Management, ClearSky Security, NightDragon, and Vertex Ventures US. | High | SV016, SV017, SV030 |
| CV005 | The October 2024 $50M+ growth round did not disclose a new company valuation; no post-money valuation figure was reported by any independent news source covering the round. | Medium | SV016, SV017 |
| CV006 | HUMAN Security's total equity raised is approximately $300 million as of October 2024 across approximately eight funding rounds, per company statement and corroborating sources. | High | SV017, SV022 |
| CV007 | HUMAN Security received a $100 million debt facility from Blackstone Credit in connection with the July 2022 PerimeterX merger; the repayment status, maturity date, and current outstanding balance of this facility have not been publicly confirmed as of June 2026. | Medium | SV015 |
| CV008 | The proceeds of the October 2024 $50M+ round were explicitly allocated to accelerating AI platform capabilities and strengthening the channel partner programme. | Medium | SV016, SV017 |
| CV009 | HUMAN Security's January 2024 CEO transition announcement stated that Tamer Hassan led the company to surpass $100 million in ARR during his tenure, representing the only company-confirmed ARR milestone publicly available as of June 2026. | High | SV018, SV017 |
| CV010 | GetLatka reported HUMAN Security ARR at $15 million as of December 2023, directly contradicting the company-claimed $100M+ ARR; this figure cannot be reconciled with post-merger headcount and platform scale and may reflect pre-merger standalone White Ops revenue or a data error. | Low | SV019 |
| CV011 | GrowJo's employee-count-model estimates HUMAN Security annual revenue at $140.4 million, consistent with the company's post-merger >$100M ARR claim and 469+ employee headcount. | Low | SV025 |
| CV012 | DoubleVerify (NYSE: DV) reported last-twelve-months revenue of $781 million and EBITDA of $261 million as of June 2026, with a gross margin of 82% in its most recently completed fiscal year per its FY2025 10-K filed February 26, 2026. | High | SV001, SV013 |
| CV013 | DoubleVerify's current enterprise value is approximately $2 billion as of June 2026, implying an EV/LTM Revenue multiple of approximately 1.9x, the ad-verification sector floor comp for HUMAN's valuation. | High | SV001, SV013 |
| CV014 | DoubleVerify's gross margin was 82% and EBITDA margin 33% in its most recently completed fiscal year, confirming pure-SaaS-tier margins despite trading at a compressed 1.9x revenue multiple due to advertising-sector structural headwinds. | High | SV001, SV013 |
| CV015 | Integral Ad Science (NASDAQ: IAS) reported approximately $530 million to $591 million in LTM revenue as of recent quarters, competing with HUMAN in programmatic fraud detection but not in application security or bot management. | Medium | SV002, SV001 |
| CV016 | The broader public cybersecurity market trades at a median EV/NTM Revenue multiple of approximately 7.8x as of late 2025 and Q1 2026, representing the median comp anchor for HUMAN's exit analysis per Windsor Drake's Cybersecurity Valuation Report. | Medium | SV005, SV008 |
| CV017 | The private cybersecurity market's median EV/ARR multiple stands at approximately 15.2x in 2025–2026, significantly above the public market median of 7.8x, reflecting the growth premium investors pay for earlier-stage companies per Windsor Drake. | Medium | SV005, SV008 |
| CV018 | Cybersecurity M&A exit multiples mediated at 16.3x revenue in 2025, with cloud-security transactions averaging 22.7x and strategic outliers reaching 35.5x per Windsor Drake and SaaS Mag reporting. | Medium | SV005, SV008 |
| CV019 | Finro's Q2 2026 cybersecurity multiples dataset (265 companies, 9 niches) places the Application Security niche — HUMAN's closest comparable niche — at an average EV/Revenue multiple of 15.4x and median of 13.0x, across 52 companies. | Medium | SV004 |
| CV020 | Threat Intelligence, an adjacent niche to HUMAN's Satori team, shows an average EV/Revenue of 14.9x and median 10.1x across 50 companies in the Finro Q2 2026 dataset; public threat intelligence comps average only 1.2x, highlighting the public-to-private valuation gap. | Medium | SV004 |
| CV021 | Cybersecurity M&A activity totaled $47 billion in Q1 2026 alone, following a record $96 billion across 400 transactions in full-year 2025, a 270% increase over 2024; strategic buyers including Palo Alto, CrowdStrike, and Check Point accounted for approximately $1.1 billion in Q1 aggregate value per Kroll and CloudStack Networks. | Medium | SV009, SV003 |
| CV022 | Disclosed cybersecurity M&A had already crossed $65 billion in aggregate deal value before mid-2026, anchored by Google's $32 billion Wiz acquisition (closed March 2026) and Palo Alto's $25 billion CyberArk acquisition (closed February 2026). | Medium | SV008, SV009 |
| CV023 | The median public SaaS EV/NTM Revenue multiple stands at approximately 8.5x as of mid-2026, up approximately 90% from the Q1 2023 trough of 4.5x, but still 47% below the 2021 peak of approximately 16x per Value Add VC. | Medium | SV011 |
| CV024 | Private SaaS companies at the $10–$50M ARR scale transacted at 5.5–7.2x ARR at the lower middle market in Q1 2026 per iMerge Advisors, with top-quartile (NRR >110%, Rule of 40 >40%) reaching 8.0x+. | Medium | SV006 |
| CV025 | Google acquired Wiz for $32 billion at approximately 32x ARR (approximately $1 billion ARR); Palo Alto Networks acquired CyberArk for $25 billion at approximately 18.6x ARR ($1.34B ARR); these represent ceiling-setting strategic M&A precedents in the cybersecurity sector. | Medium | SV005, SV008 |
| CV026 | Arkose Labs, HUMAN's closest pure-play bot management competitor, had ARR of $46.9 million and a valuation of $140.7 million (approximately 3x ARR) as of 2024 per GetLatka; at this scale and multiple HUMAN's stated $100M+ ARR would imply a notably higher per-ARR-dollar premium than Arkose Labs commands. | Low | SV027 |
| CV027 | Netacea, a bot management competitor, has raised only $22.47 million total across all rounds as of December 2024, with the most recent round being a $5.11 million Series A-III in December 2024; it represents a sub-scale comparator not useful for HUMAN's valuation benchmarking. | Low | SV026 |
| CV028 | DataDome closed a $42 million Series C in March 2023; current valuation is not publicly disclosed per PitchBook 2026 profile; DataDome is detected on over 1,450 enterprise websites. | Medium | SV028 |
| CV029 | The cybersecurity sector's premium over the broader SaaS market is at its widest level in at least five years as of 2026: public cybersecurity trades at 7.8x versus 5.5x for public B2B SaaS broadly, and private cybersecurity startups average 15.2x per SaaS Mag analysis. | Medium | SV008 |
| CV030 | Strategic buyers drove approximately 92% of cybersecurity M&A by value in 2026 as platform consolidation overtook private equity as the primary transaction driver, narrowing to platform-fit targets rather than broad portfolio expansion. | Medium | SV008, SV009 |
| CV031 | Sustaining the $1.5 billion 2022 valuation at the current application-security niche median of 13.0x requires HUMAN's ARR to be at or above approximately $115 million; at 15.2x private cybersecurity median it requires $99 million ARR, broadly consistent with the $100M+ claim. | Medium | SV004, SV005 |
| CV032 | At the private cybersecurity median of 15.2x applied to the company-claimed $100M+ ARR, HUMAN's implied enterprise value is approximately $1.52 billion, roughly in-line with the 2022 $1.5B mark and representing the base-case central estimate. | Medium | SV005, SV018 |
| CV033 | At the application-security niche median of 13.0x (Finro Q2 2026) applied to $100M ARR, HUMAN's implied enterprise value is approximately $1.3 billion, approximately 13% below the 2022 mark and representing the base-case low end. | Medium | SV004, SV018 |
| CV034 | In the bear scenario, applying an 8–10x blended cybersecurity/ad-verification multiple to $80–100M ARR implies an enterprise value of $640M–$1.0B, below the $400M total capital invested and potentially triggering liquidation preferences. | Low | SV004, SV006, SV019 |
| CV035 | In the bull scenario, applying a top-quartile cybersecurity multiple of 18–20x to ARR of $130–140M (consistent with GrowJo's $140.4M estimate) implies an enterprise value range of $2.34–2.8 billion, approximately 1.6–1.9x the 2022 mark. | Low | SV005, SV025, SV008 |
| CV036 | The approximately $400 million total capital invested ($300M equity plus $100M Blackstone debt) means a $1.5B base-case EV represents a 3.75x gross MOIC before dilution and liquidation preferences; achieving a 3x net return on the 2020 Goldman Sachs acquisition entry price likely requires a $1.5B+ exit EV. | Medium | SV006, SV015, SV017 |
| CV037 | No secondary market transactions or post-2022 valuation marks for HUMAN Security are publicly available on any alternative data platform (Premier Alternatives, secondary-market databases) as of June 2026. | Medium | SV010 |
| CV038 | Premier Alternatives lists HUMAN Security's current 2026 valuation as "N/A" with no funding history imported, confirming the absence of publicly available secondary-market pricing data. | Medium | SV010 |
| CV039 | HUMAN Security is not named in any confirmed 2026 cybersecurity IPO pipeline tracked by ipos.fyi, PitchBook's cybersecurity IPO list, or any confirmed strategic M&A announcement as of the June 2026 research date. | Medium | SV012, SV009 |
| CV040 | Kroll's Spring 2026 Cybersecurity M&A Industry Insights report notes that median EV/NTM Revenue multiples in its cybersecurity index fell 26% quarter-over-quarter in Q1 2026, driven by AI-related concerns weighing on cybersecurity equities. | Medium | SV003, SV008 |
| CV041 | HUMAN's platform breadth across bot management, ad verification, application security, account protection, and agentic AI trust differentiates it from single-point competitors such as Arkose Labs, DataDome, and Netacea, which address only one or two of these layers. | Medium | SV023, SV029, SV026 |
| CV042 | HUMAN's stated detection scale of 20 trillion digital interactions per week across 3 billion unique devices represents material competitive differentiation; no competitor has publicly claimed equivalent weekly interaction volume as of June 2026. | Medium | SV023, SV029 |
| CV043 | HUMAN's October 2024 growth round was participated in exclusively by five existing investors (WestCap, Goldman Sachs, ClearSky, NightDragon, Vertex); no new institutional investor joined the cap table, which may reflect investor-access rationing or an inability to attract step-up capital from arms-length external LPs. | Medium | SV016, SV017 |
| CV044 | HUMAN's July 2025 launch of Sightline Cyberfraud Defense and AgenticTrust positions the company in the AI Security niche, where Momentum Cyber recorded $2 billion in financing YTD 2026 and M&A deals are on pace for 400%+ growth in 2026, commanding the highest multiple premium in cybersecurity. | Medium | SV021, SV023 |
| CV045 | HUMAN Security has not publicly disclosed NRR, gross margin, burn rate, ARR growth rate, or any other operating metric from audited financial statements as of June 2026; these absences constitute the primary diligence blockers preventing a conviction recommendation. | Medium | SV010, SV019 |
| CV046 | The broader AdTech public SaaS sector median NTM EV/Revenue multiple is only 0.9x as of June 2026 per Multiples.vc, the lowest across all major SaaS subsectors; this represents the structural floor if HUMAN's ad-verification revenue is valued at AdTech sector rates rather than cybersecurity rates. | Medium | SV002 |
| CV047 | Windsor Drake notes that cybersecurity companies that raised at inflated 2021–2022 peak valuations are frequently executing structured rounds with guaranteed returns or participation rights to maintain nominal face-value marks while providing investor downside protection. | Medium | SV005 |
| CV048 | Momentum Cyber's May 2026 market review recorded 31 cybersecurity M&A transactions and 46 financing transactions during the month, with $823 million in total disclosed M&A deal value and $365 million in financing capital deployed, including 4 AI Security M&A deals. | Medium | SV021, SV009 |
| CV049 | Gartner forecasts global information security spending of $244.2 billion in 2026, up 13.3% in current dollars year-over-year, with cloud security growing 28.8% as the fastest subsegment, supporting the market-necessity argument in the investment thesis. | Medium | SV008 |
| CV050 | The 2026 cybersecurity IPO window has reopened following Netskope's September 2025 IPO, but the market remains selective; investors require clean financials, AI innovation, and Rule of 40 performance before awarding premium multiples to cybersecurity IPO candidates. | Medium | SV005, SV012 |
| CV051 | HUMAN Security's estimated headcount of approximately 469–519 employees as of mid-2026, applied to the company-claimed >$100M ARR, implies an ARR-per-FTE of $200–$300K, broadly consistent with SaaS cybersecurity industry benchmarks, indicating moderate revenue efficiency. | Low | SV024, SV018 |
| CV052 | HUMAN was recognized as a Leader in the Forrester Wave: Bot and Agent Trust Management Q2 2026 evaluation, alongside Kasada, providing third-party validation of the platform's competitive positioning in the bot and agent governance market. | Medium | SV029 |
| ID | Publisher | Title | Quote |
|---|---|---|---|
| SO001 | HUMAN Security | About | HUMAN Security | "Our founders—Tamer Hassan, Michael Tiffany, Dan Kaminsky, and Ash Kalb—set the foundation for a 'bot or not' company... protecting the internet today by safeguarding the entire customer journey and upholding the integrity of 20 trillion digital interactions a week." |
| SO002 | HUMAN Security | Board of Directors | HUMAN Security | Board Observers: Ryan Benevides, Dan Burns, Itzhak Fisher, Steve Fredrick, Rhys Gordon, Hannah Huffman, Lance Matthews, Alexander Weiss. |
| SO003 | PR Newswire | HUMAN Security Announces Strategic Leadership Transition: Tamer Hassan to Become Executive Chairman, Stu Solomon Appointed to CEO | "Tamer Hassan, co-founder and CEO who has led the company's transformation into a renowned platform for disrupting bot attacks, online fraud, and abuse, is transitioning to the role of board member and Executive Chairman of the company." |
| SO004 | BusinessWire | HUMAN and PerimeterX Unite in Market-Changing Merger to Safeguard Customers From Sophisticated Bot Attacks, Fraud and Account Abuse | "The combined companies will comprise more than 450 employees under the HUMAN company name, 500+ customers and have more than $100 million in ARR... HUMAN has received a $100 million debt facility from Blackstone Credit." |
| SO005 | BusinessWire | White Ops Announces Acquisition by Goldman Sachs Merchant Banking, ClearSky Security, and NightDragon | "Goldman Sachs Merchant Banking Division, in partnership with ClearSky Security and NightDragon (together, the 'Sponsors')... acquiring the business from previous investors Paladin Capital Group, Grotech Ventures, and other shareholders." |
| SO006 | BankInfoSecurity | Human Security Raises $50M+ to Take On Click Fraud Defense | "Human Security said the growth capital will help the New York-based company enhance its data science and engineering capabilities... Human employs 400 people today." |
| SO007 | Pulse2 | HUMAN: Cybersecurity Company Raises $50+ Million (Growth Capital) | "HUMAN has invested heavily in developing a unified Human Defense Platform that verifies over 20 trillion digital interactions weekly, enabling 500+ global brands with unparalleled telemetry." |
| SO008 | SiliconAngle | Human Security raises $50M+ to expand digital protection platform | |
| SO009 | SecurityWeek | Human Security Banks Another $50M in Growth Funding | "The latest raise follows a hefty $100 million funding round in January 2022 that included a push by Human Security into new product categories." |
| SO010 | AdExchanger | HUMAN Raises $50 Million | "Update 10/10/24: After publication, HUMAN said that the CEO misspoke about the company's product development plans, and that HUMAN does not plan to build a proprietary ID of any kind." |
| SO011 | Security Journal Americas | HUMAN Security announces new Executive Chairman and CEO | "HUMAN Security, an organization focused on digital fraud prevention, has announced that Tamer Hassan, Co-Founder and CEO, is transitioning to the role of board member and Executive Chairman." |
| SO012 | Fintech Global | Goldman Sachs-owned Human Security rakes in $100m | "Anti-bot and fraud detection company Human Security has concluded a $100m funding round led by WestCap. The funding round was also supported by NightDragon." |
| SO013 | GlobeNewswire via ITNewsOnline | HUMAN Recognized as a Leader by a Top Research Firm; Empowering Organizations to Transform Threat Intelligence into Action in the Agentic Internet | "HUMAN received the highest possible scores across nine criteria, including Threat Research (the only vendor to score 5/5), AI Agent Trust Management, Marketing Analytics Assurance, Intent Visibility, Attack and User Analytics, Customizable Reports and Dashboards, Security Operations Integrations, Vision, and Partner Ecosystem." |
| SO014 | The Hacker News | Massive Ad Fraud Scheme Targeted Over 11 Million Devices with 1,700 Spoofed Apps | "VASTFLUX was a malvertising attack that injected malicious JavaScript code into digital ad creatives... generating over 12 billion bid requests per day at its peak." |
| SO015 | Craft.co | HUMAN Security Company Profile | Total Funding $159 M |
| SO016 | TechFundingNews | Cybersecurity startup HUMAN Security raises $50M to protect against bots, fraud and threat | |
| SO017 | Tracxn | HUMAN — 2026 Funding Rounds & List of Investors | HUMAN has raised a total of $299M over 8 funding rounds. |
| SO018 | AlleyWatch | White Ops Acquired by Goldman Sachs Merchant Banking Division, ClearSky, and NightDragon | |
| SO019 | Globes (English) | Bot protection co PerimeterX merges with HUMAN Security | |
| SO020 | Security Systems News | HUMAN Security, PerimeterX announce merger to take on bots, identity fraud | |
| SO021 | citybiz | HUMAN Security Appoints Stu Solomon CEO | |
| SO022 | citybiz | HUMAN Raises $50+ Million in Growth Funding | |
| SO023 | TechIntelPro | HUMAN Named Leader in Forrester Wave for Bot and Agent Trust Management | |
| SO024 | PR Newswire Asia | HUMAN Orchestrates Unprecedented Private Takedown, VASTFLUX | |
| SO025 | Techerati | VastFlux ad-fraud scheme affecting millions taken down by HUMAN | |
| SM001 | HUMAN Security, Inc. | HUMAN Security's 2026 State of AI Traffic & Cyberthreat Benchmark Report Signals a New Internet Era: Automation Growth Now Outpaces Humans | "In 2025, HUMAN's Defense Platform analyzed more than one quadrillion digital interactions… automated traffic is growing eight times faster than human traffic." |
| SM002 | HUMAN Security, Inc. | HUMAN recognized as a Leader in The Forrester Wave™ for Bot and Agent Trust Management Software | |
| SM003 | Business Insider / GlobeNewswire | HUMAN Recognized as a Leader by a Top Research Firm; Empowering Organizations to Transform Threat Intelligence into Action in the Agentic Internet | "HUMAN Security, Inc., the trust layer for media and agentic commerce platforms, verifying engagement, reducing fraud, and enabling authentic interactions across humans, bots, and AI agents." |
| SM004 | The Business Research Company | Bot Mitigation Market Report 2026 | |
| SM005 | Fortune Business Insights | Bot Security Market Size, Share & Growth Rate [2026-2034] | "The global bot security market size was valued at USD 1.05 billion in 2025 and is projected to grow from USD 1.27 billion in 2026 to USD 5.67 billion by 2034, exhibiting a CAGR of 20.55%." |
| SM006 | Fraudlogix | Ad Fraud Statistics 2026: 20.64% IVT Rate | "Of the 105.7 billion impressions in our dataset, 21.81 billion (20.64%) showed risk signals indicating invalid traffic. Applied to U.S. programmatic ad spend, this IVT rate suggests approximately $37 billion in advertiser dollars may be associated with invalid traffic annually." |
| SM007 | Pixalate | Q1 2026 Ad Fraud Benchmarks Report for North America | "The IVT rate on Connected TV (CTV) apps was 24% in the US… desktop and mobile web: 24%, mobile app: 32%." |
| SM008 | TAG (Trustworthy Accountability Group) | TAG Recognizes Leading Companies Across Ad Industry Worldwide for Achieving 2026 Certifications | |
| SM009 | PR Newswire | TAG Recognizes Leading Companies Across Ad Industry Worldwide for Achieving 2026 Certifications | |
| SM010 | IT Business Net (GlobeNewswire) | HUMAN Security's 2026 State of AI Traffic & Cyberthreat Benchmark Report Signals a New Internet Era | |
| SM011 | Grand View Research | Fraud Detection and Prevention Market (2026-2033) | |
| SM012 | The Business Research Company | eCommerce Fraud Detection and Prevention Market Report 2026 | |
| SM013 | Media Rating Council (MRC) | MRC Accreditation Letter — HUMAN Ad Fraud Defense Pre-Bid and Ad Fraud Sensor Post-Serve Platforms | "The MRC Board of Directors has voted in favor of continuing accreditation for HUMAN's Ad Fraud Defense pre-bid platform ('the Service', formerly known as the MediaGuard platform) and Ad Fraud Sensor post-serve platform." |
| SM014 | wmtips.com | Akamai Bot Manager vs. Cloudflare Bot Management: 2026 Market Share & Usage Comparison | "Cloudflare leads in market share among bot mitigation technologies, holding roughly 79% compared to Akamai's 6%—this advantage holds in all major markets." |
| SM015 | Improvado | Ad Fraud in 2026: Detection, Prevention, and Protection Strategies | "Digital advertising fraud will exceed $100 billion globally in 2026, up from $84 billion in 2023. Invalid traffic (IVT) rates reached 20.64 percent globally in 2025." |
| SM016 | ExchangeWire | EXTE Joins Forces with HUMAN Security to Protect Ad Inventory Quality & Integrity | |
| SM017 | PeerSpot | Top Rated Bot Management Vendors 2026 | |
| SM018 | ppc.land | TAG hands out 307 seals to 196 companies in 2026 recertification | |
| SM019 | Global Growth Insights | Account Takeover Protection Market Analysis Report 2035 | "The Global Account Takeover Protection Market size is estimated at USD 6.28 billion in 2025 and is expected to reach USD 7.46 billion in 2026… registering a CAGR of 18.89%." |
| SM020 | SiliconAngle | Human Security raises $50M to expand digital protection platform | |
| SM021 | Vendr | HUMAN Security on Vendr Marketplace | |
| SM022 | Yahoo Finance | HUMAN raises $50 million in growth funding | |
| SM023 | Tracxn | HUMAN Security Company Profile | |
| SM024 | ChannelVision Magazine | HUMAN Security Beefs Up Exec Leadership, Go-to-Market Strategy | |
| SM025 | HUMAN Security, Inc. | Platform Expansion: Fueling the Future of HUMAN | |
| SM026 | Business Wire | HUMAN Raises $100 Million In Growth Funding Round Led By WestCap and NightDragon | |
| SM027 | Economic Times (CIOSEA) | Cybersecurity firm HUMAN Security raises $50 mn in growth funding | |
| SP001 | Kasada | Kasada Secures $20 Million Round to Accelerate Global Expansion and Broaden Platform Offerings | our average return on investment is over 250% driven largely by cost savings |
| SP002 | Kasada | Kasada Named a Leader in The Forrester Wave™: Bot and Agent Trust Management Software, Q2 2026 | |
| SP003 | Manila Times (GlobeNewswire) | HUMAN Recognized as a Leader by a Top Research Firm; Empowering Organizations to Transform Threat Intelligence into Action in the Agentic Internet | HUMAN stands out for its attack profiles, which offer rich attack analytics context and detail, and for a threat research team whose takedowns create impact far beyond its customer base. |
| SP004 | Secure IT World (GlobeNewswire) | HUMAN Security Tops G2's 2026 Best Security List | |
| SP005 | Markets Insider (GlobeNewswire) | HUMAN Launches AI-Powered Ad Verification for Advertisers and Agencies Seeking a Modern Alternative | While legacy providers have left brands and agencies stuck with outdated, opaque 'black box' signals, HUMAN provides a direct path to authenticity. |
| SP006 | HUMAN Security | The 2026 State of AI Traffic & Cyberthreat Benchmark Report | automated traffic—all non-human internet traffic—is growing eight times faster than human traffic, AI-driven traffic is the fastest-growing category of internet traffic |
| SP007 | PeerSpot | Compare Arkose vs Human Defense Platform (June 2026) | The mindshare of Human Defense Platform is 8.1%, down from 11.6% compared to the previous year. |
| SP008 | DataDome | DataDome Closes $42 Million in Series C Funding to Advance the Fight Against Bot-Driven Cyberattacks and Fraud | |
| SP009 | Business Wire | Fingerprint Reports 65% ARR Growth, Surpasses 1 Billion Device Identifications Per Month as Enterprises Adopt Device Intelligence to Combat AI-Driven Fraud | The company now serves 2,000 customers in over 56 countries, achieving 36% customer growth and an industry-leading net revenue retention rate of 128% |
| SP010 | Fingerprint | We Analyzed 23 Billion Device Identification Events. Here's What We Found. | |
| SP011 | Cloudflare | Plans — Bot Management for Enterprise · Cloudflare bot solutions docs | |
| SP012 | Blazing CDN | Cloudflare Enterprise Plan 2026: Pricing, Features Is It Worth It | Cloudflare publishes pricing for Free, Pro ($25/month), and Business ($250/month per zone). Enterprise has never appeared on a public rate card. |
| SP013 | 6sense | DoubleVerify vs Integral Ad Science: Ad Fraud Detection Comparison | |
| SP014 | PR Newswire | Netacea Positioned among Top Vendors in Bot and Agent Trust Management | 18% of LLM scraping traffic is unannounced, meaning it mimics human click patterns to slip through client-side protocols of JavaScript and CAPTCHA tests |
| SP015 | GetLatka | DataDome Revenue 2024: $36M ARR, $42.4M Raised | |
| SP016 | Arkose Labs | Customers | Arkose Labs | 95% Reduction in automated attacks; $50M+ Annual fraud loss prevented |
| SP017 | Tracxn | Arkose Labs — 2026 Company Profile | |
| SP018 | HUMAN Security | The Human Defense Platform | HUMAN Security | |
| SP019 | DoubleVerify Investor Relations | DoubleVerify Reports Fourth Quarter and Full Year 2025 Financial Results | We grew revenue 14% year-over-year to $748 million, exceeding our initial 10% growth outlook for the year |
| SP020 | CHEQ | The Global Leader in Go-to-Market Security | CHEQ | |
| SP021 | CSIMarket | DoubleVerify Holdings Inc Market share relative to its competitors, as of Q1 2026 | |
| SP022 | Akamai | Bot Manager | Bot Detection, Protection, and Management | Akamai | |
| SP023 | Tracxn | Kasada — 2026 Company Profile | |
| SP024 | PeerSpot | Compare Akamai Bot Manager vs Imperva Application Security Platform (Updated Mar 2026) | Imperva is ranked #1 with an average rating of 8.5; Akamai holds a 9.7% mindshare in BM, compared to Imperva's 15.7% mindshare |
| SP025 | Fingerprint | Fingerprint | Identify Every Web Visitor & Mobile Device | |
| SI001 | Business Wire | HUMAN Raises $100 Million In Growth Funding Round Led By WestCap and NightDragon | In 2021, the company experienced accelerated adoption of its specialized bot mitigation platform on a global basis and saw its revenue growth rate double year over year. |
| SI002 | Business Wire | HUMAN and PerimeterX Unite in Market-Changing Merger to Safeguard Customers From Sophisticated Bot Attacks, Fraud and Account Abuse | The combined companies will comprise more than 450 employees under the HUMAN company name, 500+ customers and have more than $100 million in ARR. |
| SI003 | GetLatka | HUMAN Revenue 2023: $15M ARR, $142.1M Raised | In 2023, HUMAN's revenue reached $15M. Since its launch in 2012, HUMAN has shown consistent revenue growth. |
| SI004 | Vendr | Human Software Pricing & Plans 2025: See Your Cost | Median buyer pays $104,906 per year |
| SI005 | ChannelVision Magazine | HUMAN Security Beefs Up Exec Leadership, Go-To-Market Strategy | Because HUMAN has historically been a direct-minded organization, Scanlan said, there will be no existing channel conflict. |
| SI006 | SiliconAngle | Human Security raises $50M+ to expand digital protection platform | Including the new funding, the company has raised around $300 million to date. |
| SI007 | Yahoo Finance / Globe Newswire | HUMAN Raises $50+ Million in Growth Funding to Protect the Digital Customer Journey | HUMAN has invested heavily in developing a unified Human Defense Platform that verifies over 20 trillion digital interactions weekly, empowering 500+ global brands. |
| SI008 | Economic Times CIO SEA | Cybersecurity firm Human Security raises $50+ Mn in growth funding | HUMAN has invested heavily in developing a unified Human Defense Platform that verifies over 20 trillion digital interactions weekly, empowering 500+ global brands. |
| SI009 | PR Newswire | HUMAN Security Announces Strategic Leadership Transition: Tamer Hassan to Become Executive Chairman, Stu Solomon Appointed to CEO | Hassan led HUMAN to remarkable heights, including surpassing $100M in ARR, merging with PerimeterX, acquiring anti-malvertising leader clean.io. |
| SI010 | Mobile Marketing Reads | Ad fraud detection and prevention firm HUMAN raises over $50 million | At the end of 2022, HUMAN acquired clean.io, a protection provider against e-commerce fraud and malicious advertising. |
| SI011 | Frontlines.io | HUMAN Security: The Category Expansion Playbook for When AI Disrupts Your Core Business | We've heard directly from them, hey, you need to get this data to my CMO, they need to use it today because we're all having this conversation. |
| SI012 | Yahoo Finance / Globe Newswire | Multimedia Update – HUMAN Continues to Be a Leader in Bot Management Software Industry | HUMAN Named a Leader in The Forrester Wave: Bot Management Software, Q3 2024. |
| SI013 | HUMAN Security | HUMAN Introduces the First Adaptive Trust Layer for the Agentic AI Era | This reimagined approach enables trusted interactions and transactions across the full spectrum of online actors: humans, bots and AI agents. |
| SI014 | IT News Online / Globe Newswire | HUMAN Recognized as a Leader by a Top Research Firm; Empowering Organizations to Transform Threat Intelligence into Action in the Agentic Internet | HUMAN received the highest possible scores across nine criteria, including Threat Research, AI Agent Trust Management. |
| SI015 | Tracxn | HUMAN – 2026 Company Profile and Team | HUMAN has raised a total funding of $299M over 8 rounds. Its latest funding round was a Series D round on Sep 26, 2024. |
| SI016 | RivalSense | HUMAN | Competitive Intelligence Profile | |
| SI017 | HUMAN Security | HUMAN recognized as a Leader in The Forrester Wave for Bot and Agent Trust Management Software | HUMAN's notable vision emphasizes trust governance, is rooted in data, and maps future market progression. |
| SI018 | HUMAN Security | HUMAN Security's 2026 State of AI Traffic and Cyberthreat Benchmark Report | In 2025, HUMAN's Defense Platform analyzed more than one quadrillion digital interactions. |
| SI019 | Carahsoft Technology Corp. | HUMAN Security and Carahsoft Partner to Provide Cybersecurity Solutions to the Public Sector | Carahsoft will serve as HUMAN's Master Government Aggregator, making the company's industry-leading bot, fraud, and account abuse protection services available to the Public Sector. |
| SI020 | Benchmarkit | 2025 SaaS Performance Metrics Benchmarks | Sales and Marketing as % of Revenue is 47% for VC-backed vs 33% for PE-backed companies. R&D is at 34% of revenue for private SaaS companies. |
| SI021 | Momentum Cyber | Goldman Sachs ClearSky Invest in White Ops | Goldman Sachs and ClearSky are ideal partners to support our growth across multiple markets. |
| SI022 | GrowJo | White Ops: Revenue, Competitors, Alternatives | White Ops's estimated annual revenue is currently $140.4M per year. |
| SI023 | AIThority | HUMAN Acquires Anti-Malvertising Leader, clean.io, to Enhance Protection Across the Media Ecosystem | Terms of the acquisition were not disclosed. |
| SI024 | U.S. Securities and Exchange Commission | White Ops, Inc. — Form D Notice of Exempt Offering of Securities (CIK 0001611028) | White Ops, Inc. — Delaware incorporation; executive officers: Michael Tiffany, Tamer Hassan, Daniel Kaminsky, Ashur Kalb, Philip Eliot, Steven Fredrick. |
| SI025 | CityBiz | HUMAN Security Appoints Stu Solomon CEO | Hassan led HUMAN to remarkable heights, including surpassing $100M in ARR, merging with PerimeterX, acquiring anti-malvertising leader clean.io. |
| SE001 | Amazon Web Services | Human Defense Platform by HUMAN Security — AWS Marketplace | "HUMAN is the only solution that combines fraud telemetry throughout every moment of the digital journey of your customers, from online advertising to site scraping, account creation, account takeover, and account fraud to detect, disrupt, and eliminate fraud." |
| SE002 | HUMAN Security (Documentation) | Getting started with AgenticTrust | HUMAN Documentation | "Sensor: 9.6.6 ... AWS API Gateway: From v0.1.1 ... AWS Lambda@Edge: From v4.8.0 ... Cloudflare: From v6.12.0 ... PHP: Unsupported ... Python3: Unsupported" |
| SE003 | PPC Land | HUMAN Security's viewability measurement earns MRC accreditation | "What makes HUMAN's accreditation different from most viewability certifications is the integration of invalid traffic (IVT) filtering directly into the measurement product." |
| SE004 | HUMAN Security | HUMAN recognized as a Leader in The Forrester Wave™ for Bot and Agent Trust Management Software | "HUMAN received the highest scores possible across nine core evaluation criteria, including Threat Research, AI Agent Trust Management, Marketing Analytics Assurance, Intent Visibility, Attack and User Analytics, Customizable Reports and Dashboards, Security Operations Integrations, Vision, and Partner Ecosystem." |
| SE005 | Manila Times (GlobeNewswire) | HUMAN Recognized as a Leader by a Top Research Firm; Empowering Organizations to Transform Threat Intelligence into Action in the Agentic Internet | "'We're incredibly proud to be recognized as a Leader in this category, and especially proud to be the only vendor to receive the top score in Threat Research,' said Stu Solomon, CEO." |
| SE006 | PPC Land | AI agent traffic is up 8x — HUMAN Security now tells marketers why | |
| SE007 | TMCnet (GlobeNewswire) | HUMAN's Satori Researchers Identify and Disrupt Multi-Layered Ad Fraud and Malvertising Scheme Named Trapdoor | "Trapdoor accounted for 480 million bid requests a day, with associated apps downloaded more than 24 million times." |
| SE008 | IT Digest | HUMAN and AWS Forge a New Trust Standard for AI Agents with Cryptographic Verification of Amazon Bedrock AgentCore | |
| SE009 | SoftwareOne | Defense Platform by HUMAN | SoftwareOne Marketplace | "Low Latency Enforcement: Decisions are enforced at the edge in under 2 milliseconds, with 95% of users validated swiftly." |
| SE010 | TrustRadius | HUMAN Bot Defender Details 2026 | TrustRadius | |
| SE011 | PeerSpot | Compare Arkose vs Human Defense Platform — Bot Management Mindshare (June 2026) | "The mindshare of Human Defense Platform is 8.1%, down from 11.6% compared to the previous year." |
| SE012 | Dark Reading | Human Security Tackles Malvertising With Clean.io Buy | |
| SE013 | AIThority | HUMAN Acquires Anti-Malvertising Leader, clean.io, to Enhance Protection Across the Media Ecosystem | |
| SE014 | TechEdge AI | HUMAN Security Enhances AI Capabilities for Advanced Cybersecurity Protection | |
| SE015 | SecuritySenses | The Best Platforms for Bot Management and Account Takeover Prevention in 2026 | "HUMAN is ranked #2 [in bot management] ... CHEQ leads this [ATO] category ... HUMAN Security focuses heavily on bot mitigation and fraud prevention, with strong ATO detection capabilities built into its platform." |
| SE016 | HUMAN Security | HUMAN Security Gives Marketing and Commerce Teams a Window Into the AI-Driven Internet through Expanded Capabilities and Adobe Integration | |
| SE017 | CMSWire | HUMAN Security Gives Marketing and Commerce Teams a Window Into the AI-Driven Internet through Expanded Capabilities and Adobe Integration | |
| SE018 | KnowledgeNile | Human Security Defends Digital Journeys With Intent-Based Trust (Sightline + AgenticTrust launch) | "HUMAN Sightline, featuring AgenticTrust, secures the customer journey and unlocks safe, scalable growth with actor-level visibility and intent-based control across humans, bots and AI agents." |
| SE019 | HUMAN Security (GitHub) | HumanSecurity/human-verified-ai-agent — Open-source A2A AI agent with HTTP Message Signatures | "This repository is an open-source showcase of A2A-based AI agents that implement HTTP Message Signatures for authenticating their requests ... The system is built on this RFC standard, with additional architectural considerations from the Web Bot Authentication Architecture draft." |
| SE020 | MarTech Series | HUMAN Acquires Anti-Malvertising Leader, clean.io | |
| SE021 | HUMAN Security | HUMAN Security Platform — Product Overview | |
| SE022 | HUMAN Security | Bot Detection and Mitigation Solutions | |
| SE023 | HUMAN Security | Satori Threat Intelligence and Research Team | |
| SE024 | HUMAN Security | HUMAN Sightline Cyberfraud Defense — First Adaptive Trust Layer for the Agentic AI Era | |
| SE025 | HUMAN Security | 2026 State of AI Traffic & Cyberthreat Benchmark Report | |
| SU001 | PPC Land | HUMAN Security's viewability measurement earns MRC accreditation | "According to Jeff Meglio, Managing Director of Sovrn, the partnership with HUMAN has produced more meaningful outcomes across the market, with viewability metrics providing confidence in performance measurement through detailed reporting that supports day-to-day operational decisions." |
| SU002 | Madhive | Madhive Announces Fraud Free Guarantee to Protect Local Advertisers | "This announcement underscores Madhive's unwavering commitment to transparency and quality," said Stu Solomon, CEO of HUMAN Security. "As a long-standing partner, Madhive has prioritized building a scalable, secure solution that stands out in the market." |
| SU003 | TheDesk.net | Madhive announces Fraud Free Guarantee for local ad buyers | "Madhive forges 'trusted partnerships' with leading, MRC-accredited, quality supply firms, including HUMAN Security." |
| SU004 | Security On Screen | HUMAN Security launches partner-first channel program | "As our customers face new and unprecedented threats on their applications and accounts, we must work with a partner who has the comprehensive coverage and unmatched human support to stop these attacks," said Nate Ungerott, CEO, Consortium Networks. |
| SU005 | ChannelVision Magazine | HUMAN Security Launches Advantage Partner-First Channel Program | |
| SU006 | GlobeNewswire (via Sina HK) | HUMAN Security Launches Partner-First Channel Program To Maximize Business Growth | "At HUMAN, we view our partners, like Optiv and Consortium Networks, as integral allies, giving them access to our platform and expertise to drive predictable growth." |
| SU007 | Yahoo Finance (GlobeNewswire) | G2 Honors HUMAN Security as a Best Security Software Product of the Year Amid Accelerated Product Innovation | "Major AI developers, including OpenAI and AWS, recognize HUMAN as a trusted solution to verify AI agent traffic." |
| SU008 | Consortium Networks | Consortium | Your Cybersecurity Concierge | |
| SU009 | ZipDo | Customer Experience In The Cyber Security Industry Statistics | "42% of cybersecurity customers have switched vendors in the past two years due to poor CX. The average Net Promoter Score (NPS) for cybersecurity vendors is 21, 15 points lower than the average for all industries. 35% of cybersecurity churn is due to CX issues, not product performance." |
| SU010 | PPC Land | IVT: LinkedIn Ads integrates HUMAN | "Since integrating with LinkedIn in May, over the past 30 days, HUMAN has identified less than 1% of impressions as invalid traffic for desktop ads on LinkedIn and across its network of publishers, including CTV." |
| SU011 | Yahoo Finance (GlobeNewswire) | HUMAN Security Solutions to Enhance Protections for Ad Traffic Quality on LinkedIn | "Our work with HUMAN furthers our goal to continue providing advertisers with a safe and trusted ecosystem to run their campaigns." — Abhishek Shrivastava, VP of LinkedIn Marketing Solutions |
| SU012 | Business Insider Markets (GlobeNewswire) | HUMAN Ad Viewability Measurement Earns MRC Accreditation, Redefining Transparency, Explainability, and Trust in Ad Measurement | "Sovrn has always focused on delivering clear, actionable insights that support performance. Our long-standing partnership with HUMAN reflects a shared commitment to transparency and precision across the media ecosystem." |
| SU013 | Media Rating Council | GI040425_HUMAN Accreditation Letter | "The MRC Board of Directors has voted in favor of continuing accreditation for HUMAN's Ad Fraud Defense pre-bid platform and Ad Fraud Sensor post-serve platform for measurement and reporting of GIVT and SIVT detection across Desktop, Mobile Web, Mobile In-App and CTV." |
| SU014 | Gartner Peer Insights (via Jina reader) | HUMAN Sightline Cyberfraud Defense Reviews & Ratings 2026 | "Platform Offers Valuable Support but Lacks Clarity on Detection Mechanisms" — 3/5 review from IT Security & Risk Management Associate, $500M–$1B Retail (Apr 14, 2026): "the product can feel like a 'black box' at times. While new detectors are being added, we have limited visibility into their specific functions or logic." |
| SU015 | Harro.com (MarTech original) | Invalid traffic detection gets smarter with HUMAN's Page Intelligence | |
| SU016 | Digitrendz Blog | HUMAN's Page Intelligence: Smarter Invalid Traffic Detection | |
| SU017 | RivalSense | HUMAN | Competitive Intelligence Profile | |
| SU018 | AGF | HUMAN Security Launches New Partner Program to Boost Growth | |
| SU019 | HUMAN Security (blog via Jina cache) | HUMAN recognized as a Leader in The Forrester Wave™ for Bot and Agent Trust Management Software | "HUMAN's customers compliment the level of detail and attack insight that they receive from the Sightline feature." |
| SU020 | HUMAN Security (newsroom via Jina) | HUMAN Security's 2026 State of AI Traffic & Cyberthreat Benchmark Report | "Automated traffic across the internet grew 23.51% year over year, while human traffic increased 3.10% over the same period. Monthly AI-driven traffic rates grew 187%." |
| SU021 | SiliconAngle | Human Security raises $50M+ to expand digital protection platform | |
| SU022 | Secure IT World | HUMAN Security Tops G2's 2026 Best Security List | |
| SU023 | Markets Business Insider (Forrester via HUMAN) | HUMAN Recognized as a Leader in The Forrester Wave™: Bot Management Software Q3 2024 | |
| SU024 | Markets Business Insider (HUMAN ad verification launch) | HUMAN launches AI-powered ad verification for advertisers | |
| SU025 | ITBusinessNet (HUMAN AI traffic benchmark) | HUMAN Security's 2026 State of AI Traffic & Cyberthreat Benchmark Report signals new internet era | |
| SR001 | HUMAN Security, Inc. | HUMAN Security's 2026 State of AI Traffic & Cyberthreat Benchmark Report | "Automated traffic across the internet grew 23.51% year over year, while human traffic increased 3.10% over the same period. Monthly AI-driven traffic rates grew 187%." |
| SR002 | HUMAN Security, Inc. | HUMAN Ad Viewability Measurement Earns MRC Accreditation | |
| SR003 | Security Boulevard | How bot detection misfires on non-mainstream browsers and privacy tools | "Privacy-related traits often correlate with bots, leading systems to flag legitimate users based on flawed assumptions." |
| SR004 | Notte.cc | The Hidden Cost of Bot Detection: Bot Detection False Positives | |
| SR005 | SecureWorld | Navigating the 2026 Cyber and AI Litigation Surge | "By midyear, 56% report increased exposure at the federal level, and 53% report the same at the state level." |
| SR006 | Mayer Brown LLP | Cross-Border Transfers of American Personal Information Carry Heightened Regulatory, Litigation Risks | "On February 9, 2026, the FTC sent formal warning letters to 13 companies identified by the Commission as 'data brokers,' emphasizing their obligation to comply with PADFAA's prohibitions on transfers of sensitive data to foreign adversaries." |
| SR007 | Check My Ads Institute | Comments on MRC Digital Advertising Auction Transparency Standards | "Time and time again, we have seen that self-regulation is insufficient to resolve these challenges in the complex and concentrated digital advertising market." |
| SR008 | StatusGator | AWS outage takes down more than 150 cloud services | |
| SR009 | HUMAN Security, Inc. | BADBOX 2.0: The sequel no one wanted | |
| SR010 | Google LLC | We're taking legal action against the BadBox 2.0 botnet | |
| SR011 | NewChannel | The State of Ad Fraud Detection in 2026 | |
| SR012 | Future of Privacy Forum | U.S. Privacy Enforcement in 2025 — Retrospective | |
| SR013 | Clarip | 2026 Data Privacy Enforcement Trends: What Regulators Are Actually Fining Companies For | |
| SR014 | DoubleVerify Holdings, Inc. | Global Study: Fueled by AI, CTV Fraud Schemes Surge 140% Globally | "DV detected 140% more CTV fraud schemes and variants in Q1 2026 compared with Q1 2025, underscoring how fraudsters are using advanced tools to scale and create more complex operations." |
| SR015 | Gartner | Cloudflare vs HUMAN Security 2026 | Gartner Peer Insights | |
| SR016 | PeerSpot | Compare Cloudflare One vs Human Defense Platform (2026) | "Cloudflare One appears to have the upper hand due to its comprehensive features and long-term value despite the appealing pricing of Human Defense Platform." |
| SR017 | Cloudflare, Inc. | Introducing the 2026 Cloudflare Threat Report | |
| SR018 | Google Cloud | Cloud Threat Horizons Report H1 2026 | |
| SR019 | Premier Alts | Human Security Valuation: N/A (2026) | |
| SR020 | Stinson LLP | A New Era of Comprehensive Privacy Laws and the Surge in Data Privacy Litigation: Important Updates for 2026 | "Nearly 4,000 cases [were] filed in 2024—up from just over 200 cases filed in 2023—alongside countless additional claims asserted through demand letters and arbitration." |
| SR021 | AI Pedias | AI Ad Fraud & Bot Detection Complete Guide 2026: HUMAN vs CHEQ vs DoubleVerify | |
| SR022 | HUMAN Security, Inc. | HUMAN, FBI, and Partners Take Action Against BADBOX 2.0 | |
| SR023 | The Register | Google sues 25 alleged BadBox 2.0 botnet operators | |
| SR024 | Forbes | FBI Warning To 10 Million Android Users — Disconnect Your Devices Now | |
| SR025 | CyberInsider | Google Sues Operators of BadBox 2.0 Botnet Behind Massive Global Malware Scheme | |
| SR026 | MediaPost | Going, Going, Gone: MRC Finalizes Ad Auction Standards | |
| SR027 | Yahoo Finance | HUMAN Ad Viewability Measurement Earns MRC Accreditation, Redefining Transparency, Explainability, and Trust | |
| SR028 | Specificity Inc. | Human Verified Traffic: Busting the Myths of Modern Ad Fraud in 2026 | |
| SR029 | Cybelesoft | AWS Outage March 2026: How the Global Cloud Failure Exposed VDI Vulnerabilities | "AWS data center facilities in the United Arab Emirates (ME-CENTRAL-1 region) triggered structural fires and forced emergency power shutdowns across multiple Availability Zones." |
| SR030 | Protegrity | AI Fraud Detection in 2026: What Security and Risk Leaders Must Know | |
| SR031 | Cyber Defense Magazine | Innovator Spotlight: HUMAN | |
| SV001 | Multiples.vc | DoubleVerify — Multiples.vc — Public Comps and Valuation Multiples | DoubleVerify reported last 12-month revenue of $781M and EBITDA of $261M. Current revenue multiple of DoubleVerify is 1.9x. DoubleVerify's current market cap is $2B. |
| SV002 | Multiples.vc | Public Software Valuation Multiples — June 2026 | AdTech and video streaming trade at even steeper discounts. Cybersecurity listed separately under infrastructure SaaS. Data as of June 19, 2026. |
| SV003 | Kroll | Cybersecurity M&A Industry Insights — Spring 2026 | AI related concerns weighed on cybersecurity equities in Q1, driving a decline in valuation multiples across Kroll's cybersecurity index. Median EV to next twelve months revenue multiples fell 26% quarter over quarter. |
| SV004 | Finro Financial Consulting | Cybersecurity Valuation Multiples Q2 2026 — 265 Companies, 9 Niches | Application Security: 52 companies, avg EV/Rev 15.4x, median 13.0x. Cloud Security: 16 companies, avg 22.7x, median 18.1x. Private companies only — medians decline from Seed (15.5x) through Series C (12.7x) before a modest recovery at Series D+. |
| SV005 | Windsor Drake | Cybersecurity Valuation Report 2026 | Private market transactions, particularly M&A exits, are happening at much higher multiples. Private M&A Multiples: High-growth private targets in hot sectors like Cloud Security are seeing M&A exit multiples average 16.3x, with outliers reaching as high as 22.7x. The median revenue multiple for private cybersecurity companies in 2025 stands at 15.2x. |
| SV006 | iMerge Advisors | Q1 2026 Private SaaS Valuation Report Insights | Scale ($10M–$50M ARR): Median ARR Multiple 5.5–7.2x, Top Quartile 8.0x+. Q1 2026 Valuation Matrix. Executive Summary: Private SaaS valuations have stabilized at 4.0x–5.5x ARR. |
| SV007 | Acquiry | SaaS Valuation Multiples in 2026: What the Data Actually Shows | AI-native SaaS (20–50% ARR growth): 7x to 12x ARR. Traditional SaaS (>30% ARR growth): 5x to 8x ARR. Net Revenue Retention is the single most important metric in SaaS valuation. |
| SV008 | SaaS Mag | Cybersecurity SaaS Premium: Highest Multiples in 2026 | Public cyber companies trade at a 7.8x revenue median, private cyber startups command 15.2x, and the M&A median runs 16.3x with cloud-security transactions reaching all the way up to 35.5x. Disclosed cybersecurity M&A hit $96 billion across 400 transactions in 2025. 2026 has already crossed $65 billion in disclosed deal value before the halfway mark. |
| SV009 | CloudStack Networks | Cybersecurity M&A Hits $47 Billion in Q1 2026 as Palo Alto, CrowdStrike Drive Platform Consolidation | The cybersecurity industry recorded $47 billion in M&A activity in Q1 2026 alone, following a record $96 billion in 2025. |
| SV010 | Premier Alternatives | Human Security Valuation: N/A (2026) | Current Valuation: N/A. Last Round: PE Growth/Expansion. Amount undisclosed. No funding history available. Funding data has not been imported for this company yet. |
| SV011 | Value Add VC | SaaS Valuation Multiples 2026: Median EV/Revenue 8.5x, Up 90% From the Trough | The median public SaaS multiple sits at ~8.5x NTM revenue in mid-2026 — up ~90% from the ~4.5x Q1 2023 trough. >50% YoY growth: Median EV/Revenue 12–18x. |
| SV012 | ipos.fyi | Cybersecurity IPOs — Companies Going Public (2026) | |
| SV013 | SEC EDGAR — DoubleVerify Holdings Inc. | DoubleVerify Holdings, Inc. Annual Report on Form 10-K for Fiscal Year Ended December 31, 2025 | |
| SV014 | Business Wire | HUMAN Raises $100 Million In Growth Funding Round Led By WestCap and NightDragon | |
| SV015 | Business Wire | HUMAN and PerimeterX Unite in Market-Changing Merger to Safeguard Customers From Sophisticated Bot Attacks, Fraud and Account Abuse | |
| SV016 | SiliconAngle | Human Security raises $50M+ to expand digital protection platform | |
| SV017 | Yahoo Finance / Globe Newswire | HUMAN Raises $50+ Million in Growth Funding to Protect the Digital Customer Journey | |
| SV018 | PR Newswire | HUMAN Security Announces Strategic Leadership Transition: Tamer Hassan to Become Executive Chairman, Stu Solomon Appointed to CEO | |
| SV019 | GetLatka | HUMAN Security Revenue 2023 | GetLatka reported HUMAN Security ARR at $15 million as of December 2023, directly conflicting with the company's stated $100M-plus ARR. |
| SV020 | SEC EDGAR — White Ops Inc. | White Ops Inc. Form D — Series A Exempt Offering, June 2014 (CIK 0001611028) | |
| SV021 | Momentum Cyber | Cybersecurity Market Review May 2026 | May 2026: 31 M&A transactions and 46 financing transactions. $823M in disclosed M&A value. AI Security M&A is on pace to increase 400%+ in 2026. |
| SV022 | Tracxn | HUMAN Security — Company Profile and Funding History | |
| SV023 | HUMAN Security | HUMAN Security — AgenticTrust and Sightline Platform | |
| SV024 | Benchmarkit | 2024/2025 SaaS Gross Margin Benchmarks | |
| SV025 | GrowJo | HUMAN Security Revenue Estimate | |
| SV026 | Kasada | Kasada Secures $20 Million Round to Accelerate Global Expansion | |
| SV027 | GetLatka | Arkose Labs Revenue 2024: $46.9M ARR, $140.7M Valuation | |
| SV028 | DataDome | DataDome Closes $42 Million Series C Funding | |
| SV029 | Manila Times / GlobeNewswire | HUMAN Recognized as a Leader by a Top Research Firm in the Forrester Wave: Bot and Agent Trust Management, Q2 2026 | |
| SV030 | SiliconAngle (October 2024 funding coverage) | Human Security raises $50M+ — investor and allocation details |