Startup Diligence
Diligence report cybersecurity Series C 2026-07-07

Safe Security

Agentic AI Cyber Risk Platform — CRQ, CTEM, and TPRM Converged

Safe Security is a credible category leader in enterprise cyber risk management with strong Forrester and analyst validation, but limited financial transparency keeps the $1B+ entry multiple at the borderline of fair-to-stretched without audited unit economics.

Cover facts

Last raised 01
$70M Series C [CO019]
Total raised 02
$170M+ [CO021]
Valuation 03
$1B+ [CO019]
Founded 04
2012 [CO001]
Fortune 500 customers 05
10% (~50) [CU006]
Headcount 06
51–200 [CO025]

Company profile

Safe Security (formerly Lucideus) is a Palo Alto, California-headquartered cybersecurity platform company founded in 2012 at IIT Bombay by Saket Modi, Rahul Tyagi, and Vidit Baxi. Originally a penetration-testing and cyber-hygiene services firm, the company pivoted to SaaS in the mid-2010s and rebranded as SAFE in 2021. The SAFE Platform now unifies Cyber Risk Quantification (CRQ), Continuous Threat Exposure Management (CTEM), Third-Party Risk Management (TPRM), and AI Security Posture Management (AI-SPM) under an agentic AI architecture. Strategic acquisitions of RiskLens (2022) and Balbix (2025) added FAIR-based CRQ automation and AI-native cyber asset intelligence. The company raised a $70 million Series C in July 2025 at an implied $1B+ unicorn valuation and reported triple-digit year-over-year revenue growth for three consecutive years. Forrester named SAFE a Leader in Cyber Risk Quantification Solutions in its Q2 2025 Wave, and Liminal rated it the #1 TPRM platform by product capability. Named customers include Google, T-Mobile, Fidelity, Chevron, and IHG.

Website
safe.security
Founded
2012-01-01
Founders
Saket Modi, Rahul Tyagi, Vidit Baxi
Founding location
Mumbai (IIT Bombay), India
Headquarters
Palo Alto, California, USA
Product
The SAFE Platform delivers four integrated modules: CRQ (SAFE CRQ Engine using FAIR methodology to quantify breach risk in financial terms), CTEM (the claimed world's first fully autonomous CTEM solution powered by 50+ AI agent nodes and 100+ workflow templates), TPRM (autonomous third-party risk assessment for vendor ecosystems), and AI-SPM (AI Security Posture Management for AI workload risk). Balbix's CAASM capabilities anchor the asset intelligence layer; RiskLens IP underpins the FAIR quantification engine.
Customers
Fortune 500 enterprises, with emphasis on financial services, telecom, energy, healthcare, and technology verticals. Primary buyers are CISOs, CROs, and cyber risk or TPRM program leaders.
Business model
SaaS subscription with enterprise licensing; pricing is not publicly disclosed but industry proxies indicate six-figure to seven-figure annual contract values for Fortune 500 accounts. Revenue model spans CRQ, TPRM, and CTEM module tiers, with cross-sell driving net expansion.
Stage
Series C
Funding status
$70M Series C closed July 31, 2025, led by Avataar Ventures with Susquehanna Asia Venture Capital, NextEquity Partners, Prosperity7 Ventures, Eight Roads (Fidelity), John Chambers, and Sorenson Capital. Total disclosed funding exceeds $170M across seed, Series A ($33M, British Telecom + John Chambers), Series B ($50M, Sorenson Capital + Eight Roads + Telstra + WTI), and Series C.
[CO001, CO002, CO004, CO006, CO007, CO008, CO009, CO019]

Executive summary

Top strengths

  • Forrester Wave Leader Q2 2025 in CRQ and Liminal #1 in TPRM — independent analyst validation of market leadership.
  • Unified CRQ + CTEM + TPRM + AI-SPM platform eliminates point-solution sprawl and creates cross-sell expansion leverage.
  • Strategic acquisitions of RiskLens (FAIR CRQ) and Balbix (AI-native CAASM) built defensible IP moat faster than organic R&D.
  • Fortune 500 customer base (claimed 10%) with named logos including Google, T-Mobile, Fidelity, and Chevron demonstrates enterprise credibility.
  • Triple-digit YoY revenue growth for three consecutive years, and 50%+ TPRM module adoption among existing CRQ customers.

Top risks

  • Financial opacity: ARR, gross margin, NRR, and burn rate remain undisclosed, making the $1B valuation impossible to benchmark rigorously.
  • Competitive displacement: CrowdStrike, Palo Alto Networks, and Tenable are adding CTEM and risk quantification capabilities to existing installed bases.
  • Key-person concentration: Saket Modi is the primary external face, investor relationship holder, and strategic narrator.
  • Acquisition integration risk: digesting both RiskLens and Balbix simultaneously introduces technical-debt and cultural complexity.
  • India-origin data governance exposure: customer security posture data handled across India operations creates data-sovereignty and regulatory compliance risk.

Open gaps

  • Audited ARR, gross margin, NRR, and CAC/LTV ratios — essential to validate the $1B+ valuation and growth sustainability.
  • Precise headcount and geographic breakdown — LinkedIn signals 51–200, inconsistent with Fortune 500 scale.
  • Cap table, secondary pricing, and preferred economics — necessary to assess effective dilution and downside protection.
  • Retention cohort data — TPRM 50% cross-sell is company-claimed; independent churn or NRR evidence is unavailable.
  • Balbix acquisition price and integration timeline — undisclosed; material to understanding capital efficiency.

Contents

Chapter 01

01Company Overview

1.1 Identity, headquarters, and business model

Safe Security is the current brand of Lucideus, a cybersecurity company founded in 2012 and now headquartered in Palo Alto, California. The company positions itself as an autonomous cyber risk management platform rather than a point security tool. Across its official pages, SAFE describes one unified platform that helps CISOs, TPRM leaders, and GRC teams continuously quantify, prioritize, and reduce cyber risk across enterprise, third-party, threat-exposure, and AI use cases. The product stack now spans Cyber Risk Quantification (CRQ), Third-Party Risk Management (TPRM), Continuous Threat Exposure Management (CTEM), and AI Security Posture Management (AI-SPM), with agentic workflows and a real-time risk graph as the connective tissue. Public location pages and the company LinkedIn profile anchor Palo Alto as headquarters and show additional operating presence in New York, Santa Clara, San Jose, New Delhi, Bengaluru, London, Dubai, and remote hiring markets. For later chapters, the safest canonical description is therefore: a privately held enterprise cyber-risk software vendor selling a platform subscription to large organizations, with product breadth expanding faster than its financial disclosure.[CO001, CO002, CO003, CO004, CO005, CO006]

Snapshot KPI Table
MetricValue/StatusDateConfidenceGap/Note
FoundingFounded in 2012 at IIT Bombay by Saket Modi, Rahul Tyagi, and Vidit Baxi2012highFounding story is corroborated by independent, investor, and founder-profile sources
HeadquartersPalo Alto, CaliforniacurrenthighOfficial contact page, LinkedIn profile, and Craft align on Palo Alto
Operating footprintPublic locations across Palo Alto, Santa Clara, San Jose, New York, New Delhi, Bengaluru, London, Dubai, and remote US/Australia hiring markets2026-07mediumPublic office lists are useful but may not be exhaustive of all sales or remote hubs
Business modelEnterprise cyber-risk software platform spanning CRQ, TPRM, CTEM, and AI-SPMcurrenthighProduct scope is clear; pricing and contract structure are not publicly disclosed
Latest disclosed round$70M Series C led by Avataar Ventures2025-07highUse of funds emphasized CyberAGI, CTEM, and growth investment
Total disclosed capital raisedOver $170M2025-07highCumulative figure is company-claimed but repeated across multiple news reports
Customer proofNamed logos include Google, Fidelity, T-Mobile, Chevron, and IHG2025-07highCustomer list is company-claimed, not third-party audited
Adoption proof10% of Fortune 500 trust SAFE; 50%+ of customers adopted TPRM after launch2025-2026mediumBoth are company-claimed adoption metrics
Growth signalTriple-digit revenue growth for three consecutive years; some sources frame this as 120%+ YoY since platform launch2025-07mediumNo absolute revenue run-rate or ARR disclosed
Headcount proxyLinkedIn lists 51-200 employees2026-07lowUseful directional proxy only; likely conservative versus global office footprint and acquisitions
ValuationNot supportably disclosed in retained official/news sourcescurrentmediumDo not treat unicorn status as verified without priced round evidence
Revenue / ARRNot publicly disclosedcurrenthighRequires management data room or lender/investor materials for verification

Snapshot rows separate disclosed facts from unsupported metrics. Where only company-claimed scale signals exist, the row says so explicitly instead of promoting them to audited facts.

[CO001, CO002, CO004, CO019, CO021, CO022]
FO002: SAFE Platform Business Model Logic

SAFE sells a unified cyber-risk software layer that ingests signals, applies agentic workflows and risk modeling, and turns them into remediation and executive decision support.

[CO003, CO004, CO005, CO020, CO029, CO033]
FO003: Snapshot KPIs

The most reusable chapter facts are stage, disclosed capital, customer proof, growth claims, and the explicit absence of a supportable public valuation.

[CO019, CO021, CO022, CO024, CO025, CO029]

1.2 Founders, leadership, and governance visibility

Founder identity is one of the better-corroborated parts of the SAFE story. Independent reporting, the CEO's own Forbes profile, and investor materials all point to Saket Modi, Rahul Tyagi, and Vidit Baxi as the founding trio, with Saket Modi still serving as the clearly dominant external face of the company as co-founder and CEO. Craft's company profile also identifies Vidit Baxi as co-founder and CISO, Rahul Tyagi as co-founder, and Saket Bajoria as Chief Product Officer. Leadership expansion has also come through acquisitions: after the 2023 RiskLens deal, former RiskLens CEO Nick Sanna joined SAFE as President and Jack Jones became Chief Research Scientist, and after the 2025 Balbix acquisition, founder Gaurav Banga joined as President of CTEM. The main governance caveat is disclosure depth. Public materials reviewed for this chapter identify investors, strategic backers, and operating executives, but they do not publish a complete board roster, committee structure, or explicit succession plan. That leaves meaningful key-person dependence around Saket Modi and incomplete visibility into board oversight, even though the company now has a late-stage investor set and multiple acquired business lines to integrate.[CO001, CO007, CO008, CO009, CO010, CO011]

Leadership and Founder Table
PersonRoleBackgroundFounder-Market FitKey-Person Dependency
Saket ModiCo-Founder & CEOFounded Lucideus in 2012 while at IIT Bombay; still the main external spokesman and strategic narratorStrong founder-market fit: created the company around cyber-risk quantification and remains tightly linked to product vision, fundraising, and category positioningHigh
Rahul TyagiCo-FounderPublicly identified as a founding executive across investor and company-history sourcesSupports continuity of the original founding team and early product/services evolution, but is less externally visible than Modi in recent yearsMedium
Vidit BaxiCo-Founder & CISOListed by Craft and investor materials as co-founder and security leaderAnchors practitioner credibility and security-domain continuity as the company scaled into enterprise risk workflowsMedium
Saket BajoriaChief Product OfficerNamed by Craft and quoted in the Cisco partnership announcement on product directionProvides current product-leadership coverage as SAFE expands from CRQ into AI and exposure-management categoriesMedium
Nick SannaPresident (post-RiskLens acquisition)Former RiskLens CEO who joined SAFE after the June 2023 acquisitionAdded deep FAIR/CRQ domain authority and helped integrate a category-defining acquired assetLow to medium
Gaurav BangaPresident of CTEM (post-Balbix acquisition)Founder and CEO of Balbix before joining SAFE in November 2025Critical to integrating CTEM/exposure-management capability and preserving Balbix talent and roadmap credibilityMedium

This table covers the named founders and publicly surfaced operating leaders or acquisition leaders found in retained sources. SAFE does not publish a full executive org chart or board roster in the materials reviewed.

[CO007, CO008, CO009, CO010, CO012, CO013]

1.3 Funding history, investors, and scale signals

SAFE's funding chronology is directionally clear even though the cap table and valuation are not. Lucideus disclosed angel funding in 2016 and a broader angel syndicate round in 2017 while describing itself as bootstrapped for its first four years and still primarily India-based. The modern institutional chronology comes from SAFE's own timeline and later financing announcements: the company says it secured a $33 million Series A led by British Telecom and John Chambers in 2021, then a $50 million Series B led by Sorenson Capital in April 2023 with Eight Roads, Telstra Ventures, and WTI, taking disclosed funding above $100 million. The biggest round came on July 31, 2025, when SAFE announced a $70 million Series C led by Avataar Ventures with Susquehanna Asia Venture Capital, NextEquity Partners, Prosperity7 Ventures, and existing investors including Eight Roads, John Chambers, and Sorenson Capital; both company and press-release coverage say total funding then exceeded $170 million. What is not supportable from retained official and independent reporting is a priced post-money valuation, debt stack, secondary volume, or precise ownership/control rights. For underwriting, total raised and investor quality are reusable facts; valuation and capitalization structure remain diligence requests, not chapter ground truth.[CO015, CO016, CO017, CO018, CO019, CO020]

Stakeholder or Investor Map
StakeholderRoleInvestment AmountStageDiligence Ask
Founders (Modi, Tyagi, Baxi)Operating founders and likely largest early equity holdersNot disclosedFounding onwardRequest current founder ownership, vesting status, and any super-voting or veto rights
John Chambers / JC2 networkLead Series A backer and recurring strategic supporterParticipated in 2021 Series A; later named among existing investors in 2025Series A through Series CConfirm board or observer rights, pro-rata participation, and any commercial influence
British TelecomNamed Series A lead with John Chambers on SAFE timelinePart of disclosed $33M Series ASeries A (2021)Clarify whether BT was purely financial, commercial-strategic, or both, and whether it still holds a stake
Sorenson CapitalSeries B lead and continuing investorLed disclosed $50M Series B; also listed among existing investors in 2025Series B onwardConfirm current ownership, governance rights, and whether it still leads institutional diligence
Eight Roads / Telstra Ventures / WTISeries B syndicate and continuing backersParticipated in disclosed $50M Series B; Eight Roads also listed in 2025 investor baseSeries B onwardBreak out check sizes, follow-on rights, and any regional distribution or commercial tie-ups
Avataar VenturesLead investor in the latest roundLed disclosed $70M Series CSeries C (2025)Confirm board seat, milestone expectations, and next-round or exit planning assumptions
Susquehanna Asia VC / NextEquity / Prosperity7 VenturesNew Series C co-investor cohortAmounts not broken out publiclySeries C (2025)Request exact allocations, rights, and any strategic-commercial overlays from the syndicate
RiskLens and Balbix acquired stakeholdersStrategic stakeholders added through acquisitions rather than financing roundsAcquisition terms undisclosedStrategic M&A (2023 and 2025)Confirm retention packages, earn-outs, integration KPIs, and any contingent liabilities from the acquisitions

The public record is good enough to identify the major funding counterparties but not exact ownership percentages, liquidation preferences, or board-rights allocation. Treat this as a stakeholder map, not a cap table.

[CO011, CO016, CO018, CO019, CO020, CO021]

1.4 Milestones, recognitions, partnerships, and adverse events

SAFE's trajectory shows a steady broadening from cyber-risk quantification into adjacent control planes. The company rebranded from Lucideus to SAFE in 2021, bought RiskLens in June 2023 to bring the FAIR methodology and leadership talent in-house, and then used 2024-2026 to widen platform scope from CRQ into TPRM, CTEM, and AI-SPM. Official 2025 materials claim more than half of customers adopted TPRM after its 2024 launch, while June 2025 SAFE materials cite Forrester naming the company a Leader in cyber risk quantification and April 2025 SAFE materials cite Liminal ranking it highest on TPRM product capability. July 2025 added both the Series C raise and a Cisco AI Defense partnership, and November 2025 added the Balbix acquisition, which brought exposure-management depth and placed Balbix founder Gaurav Banga into the operating team. The principal adverse item surfaced in late 2025, when SecurityScorecard sued SAFE over alleged unfair competition and trade-secret misuse; SAFE and SecurityScorecard then announced a resolution and research collaboration the next month. On balance, the milestone record is consistent with a company that is still scaling fast and adding categories, but that has not matched its product and financing pace with equally deep public disclosure on governance, valuation, or audited operating metrics.[CO006, CO013, CO014, CO018, CO019, CO020]

Milestone Table
DateEventTypeAmount/StatusParticipantsImplication
2012Lucideus is founded at IIT BombayfoundingCompany launchedSaket Modi, Rahul Tyagi, Vidit BaxiEstablishes the original founding identity later reused under the SAFE brand
2016-09Lucideus announces angel funding and expansion plansfinancingAmount undisclosedLucideus; Amit ChoudharyMarks the first clearly disclosed external capital and a shift toward larger operations
2017-05Lucideus closes a broader angel syndicate round and says it is preparing a cyber-risk platformfinancingAmount undisclosedLucideus; multiple angel investorsShows transition from services and assessments toward platform development
2021Lucideus rebrands to SAFE and company timeline says a $33M Series A led by British Telecom and John Chambers closesgovernance$33M Series A; brand resetSAFE; British Telecom; John ChambersCreates the modern brand and anchors the first large institutional round
2023-04SAFE raises Series Bfinancing$50M; total funding over $100MSorenson Capital; Eight Roads; Telstra Ventures; WTIProvides scale capital for the AI-driven cyber-risk platform
2023-06SAFE acquires RiskLensproductAcquisition announcedSAFE; RiskLensAdds FAIR-based CRQ credibility and brings Nick Sanna and Jack Jones into the organization
2024SAFE launches and cross-sells TPRM with specialized AI agentsproductModule launch and adoption rampSAFEExpands addressable workflow beyond CRQ into third-party cyber risk operations
2025-04 to 2025-06Liminal and Forrester recognize SAFE as a leader in TPRM and CRQscaleAnalyst recognitionSAFE; Liminal; ForresterSupports category-leadership narrative ahead of the next financing round
2025-07SAFE raises Series C, launches autonomous CTEM, and announces Cisco AI Defense integrationfinancing$70M; total funding over $170MAvataar Ventures; Susquehanna Asia VC; NextEquity; Prosperity7; CiscoExpands capital base and broadens the platform into exposure management and AI risk
2025-09 to 2025-10SecurityScorecard sues SAFE, then both companies publicly resolve the dispute and announce research collaborationadverseLawsuit filed, then resolvedSecurityScorecard; SAFEFlags commercial/legal friction but not an unresolved public case by run date
2025-11SAFE acquires BalbixproductAcquisition announcedSAFE; BalbixAdds CTEM depth and brings Balbix founder Gaurav Banga into the operating team
2026-05SAFE launches AI-SPMproductNew module launchedSAFEExtends the platform into AI-governance and AI-exposure management

This chronology is intentionally selective: it covers the milestones most reusable by later chapters and highlights where financing, platform breadth, analyst validation, partnerships, and adverse events changed underwriting context.

[CO001, CO006, CO015, CO016, CO018, CO019]
FO001: Company Milestone Timeline

SAFE moved from an IIT Bombay-founded services player into a multi-module cyber-risk platform through financing, acquisitions, analyst validation, and one disclosed legal dispute.

[CO001, CO006, CO013, CO014, CO015, CO016]

1.5 Exhibits

Chapter 02

02Market Analysis

2.1 Market Definition and Landscape

Safe Security's most defensible market is not “all cybersecurity,” but the narrower enterprise workflow where technical exposure is translated into business and governance action. SAFE's own 2025-2026 platform messaging now bundles CRQ, CTEM, TPRM, and AI-SPM into one operating layer, which means the chapter should treat market definition before market size. CRQ covers the financial expression of cyber risk for boards, finance, and insurance workflows. CTEM covers the continuous discovery, prioritization, validation, and mobilization of exposures across the attack surface. TPRM covers the lifecycle of onboarding, assessing, monitoring, and governing vendors and fourth parties. Those categories overlap with CAASM, exposure assessment platforms, GRC, IRM, and even EDR/XDR or traditional vulnerability management, but they are not interchangeable. The buying job is converging around continuous, evidence-backed cyber risk decisions, while the budget still sits across multiple adjacent line items.[CM001, CM002, CM003, CM004, CM005, CM006]

Market Definition Table
SegmentDefinitionSafe.security PositionAdjacent Markets
CRQFinancially expresses cyber risk for boards, finance, and insurer-facing workflows.Historical wedge and brand anchor through SAFE, RiskLens, and Forrester leadership messaging.IRM, cyber insurance analytics, board reporting
CTEMContinuously scopes, discovers, prioritizes, validates, and mobilizes against exposures.Post-Balbix expansion area positioned as agentic CTEM powered by business-impact context.CAASM, EASM, BAS, exposure assessment platforms
TPRMManages vendor lifecycle risk from onboarding and due diligence through monitoring and termination.Fast-growth adjacency where SAFE is pushing autonomous workflows and continuous monitoring.Vendor risk management, procurement risk, operational resilience
AI-SPMMonitors and governs AI activity, configuration, exposure, and policy evidence.Newest expansion wedge linking AI adoption to SAFE's existing risk platform.AI governance, AI security tooling, DSPM-like controls
GRC / IRM adjacencyGovernance, policy, audit, and enterprise-risk workflows that often own or consume cyber-risk outputs.Useful budget adjacency and system-of-record complement, but not SAFE's entire core market.GRC suites, audit platforms, ERM software
EDR/XDR and traditional VM substitutesDetection, response, or scanner-led programs that can crowd out management-layer budgets when buyers prioritize immediate operations.Important status-quo substitute and objection source rather than additive TAM.EDR, XDR, VM, patch management

Rows describe non-additive market layers and substitutes. The same buyer may use several of these categories simultaneously, so the table defines boundary rather than additive TAM.

[CM001, CM002, CM005, CM006, CM016, CM028]

2.2 Market Sizing: TAM, SAM, SOM

Public sizing evidence confirms that SAFE is selling into multi-billion categories, but it does not justify one simple additive TAM slide. Mordor's broader CRQ scoring-platform lens reaches USD 5.43 billion in 2026, while its narrower CRQ-governance lens is USD 2.04 billion in 2026 and SAFE's own older framing sits at USD 4 billion. CTEM is still an emerging market category, with a Grand View / GII lens at USD 2.70 billion in 2025 and roughly USD 3.04 billion on a 2026 forward estimate, while CAASM adjacency is already around USD 3.70 billion in 2026. TPRM software is the largest directly adjacent workflow at USD 8.5 billion in 2025 and roughly USD 9.78 billion on a 2026 forward estimate. Broader GRC and cybersecurity pools are far larger, at USD 23.32 billion and USD 264.43 billion respectively, but they materially overstate what SAFE can serve today. The right diligence takeaway is that TAM is real, SAM and SOM are not publicly isolatable, and overlap between categories is itself a core market fact.[CM009, CM010, CM011, CM012, CM013, CM014]

TAM / SAM / SOM Sizing Lens
SegmentEstimate ($B)SourceMethodYearConfidence
CRQ scoring platforms5.43Mordor IntelligencePublished 2026 market size for broader CRQ scoring-platform lens2026medium
CRQ governance platforms2.04Mordor IntelligencePublished 2026 market size for narrower CRQ-governance lens2026medium
SAFE-claimed CRQ market4SAFE / PR NewswireCompany-stated market framing attached to RiskLens acquisition2023 claim still referenced in 2026 positioningmedium
CTEM market2.7Grand View Research via GIIPublished 2025 market size for standalone CTEM lens2025medium
CAASM software3.7360iResearchPublished 2026 market size for CAASM adjacency2026medium
TPRM software8.5QY ResearchPublished 2025 market size for third-party risk-management software2025medium
Derived TPRM 2026 lens9.78Author estimate from QY Research CAGR2025 base grown one year at stated 15.0% CAGR2026Emedium
Broader GRC software adjacency23.32Mordor IntelligencePublished 2026 market size for GRC software2026medium
Broader cybersecurity adjacency264.43Mordor IntelligencePublished 2026 market size for total cybersecurity market2026medium

This is a bracketing table, not an additive TAM model. Public estimates use different category perimeters and time bases, so derived 2026 rows are shown only where the underlying source published a CAGR and current-year base.

[CM009, CM012, CM014, CM015, CM019, CM050]
FM001: Market Sizing Lens

Nested lens from broad cybersecurity spend down to the narrower categories most directly relevant to SAFE's current platform narrative.

The pyramid is not additive. It shows progressively narrower market lenses or adjacencies, and two values (TPRM 2026E and CTEM 2026E) are one-year forward estimates derived from the source CAGR and current-year base.

[CM019, CM020, CM048, CM050, CM051]
FM002: Market Estimate Range

Low/base/high ranges showing how public category definitions widen or narrow SAFE-relevant market lenses.

This figure mixes published current-year values with transparent forward estimates where the underlying source provides a CAGR and current base. It is meant to show category spread, not one audited consensus data set.

[CM014, CM015, CM050, CM051, CM052]

2.3 Buyer Profiles and Decision Criteria

SAFE's buyer map is attractive precisely because it is cross-functional, but that same breadth lengthens enterprise sales cycles. CRQ and CTEM purchases typically anchor with the CISO, CRO, enterprise-risk, or IT-risk organization because those teams own exposure prioritization, board reporting, and remediation governance. TPRM brings procurement, privacy, legal, and compliance teams into the motion because vendor onboarding, questionnaires, contracts, and ongoing monitoring all live across those functions. Finance and treasury influence the conversation when cyber insurance, capital allocation, or SEC disclosure quality become explicit use cases. Public TPRM frameworks from IBM and Moody's also show why automation matters: buyers want inventory, due diligence, workflow, scoring, contract controls, auditable records, and continuous monitoring, and they increasingly want security review to start earlier in procurement. That combination favors platforms that can unify data, but it also means SAFE must clear integration, workflow, and governance objections before a technical win becomes a booked enterprise contract.[CM018, CM021, CM022, CM023, CM024, CM025]

Segment / Buyer Map
Buyer TypeJob TitlePrimary NeedDecision CriteriaBudget Owner
Security leadershipCISO / VP SecurityPrioritize enterprise exposures, brief the board, and prove risk reductionBusiness-impact prioritization, integration breadth, remediation workflow, auditabilitySecurity or enterprise cyber budget
Enterprise riskCRO / Head of Enterprise Risk / IRM leadTranslate cyber into enterprise-risk, insurance, and capital-allocation languageDefensible quantification, alignment to governance frameworks, insurer/board credibilityCorporate risk or shared GRC budget
Third-party riskTPRM lead / Procurement risk / Vendor governance managerAssess vendors, collect evidence, monitor ongoing exposure, and enforce process disciplineWorkflow automation, questionnaires, monitoring, contract hooks, recordkeepingProcurement, IRM, compliance, or shared-services budget
Finance and insuranceCFO / Treasurer / Insurance managerSupport insurance buying, SEC disclosure coordination, and cyber capital allocationFinancial-loss framing, reporting discipline, insurer acceptance, cross-functional visibilityFinance, treasury, or insurance budget
Control ownersIT risk / GRC / remediation operationsTurn findings into tickets, ownership, exceptions, and recurring compliance evidenceTicketing integration, ownership routing, SLAs, exception management, low manual overheadShared GRC, IT, or security-operations budget

Large-enterprise buying is cross-functional. The same account often has a technical champion in security, an operational workflow owner in TPRM or GRC, and an economic influence path through finance, procurement, or the board.

[CM018, CM021, CM022, CM023, CM024, CM039]
FM003: Buyer / Segment Map

Qualitative view of which buyer types feel the strongest need across SAFE's four main solution areas.

[CM021, CM022, CM025, CM027, CM045]

2.4 Growth Drivers and Market Constraints

The strongest growth drivers are visible and current. AI adoption is creating new machine identities, shadow-AI workflows, and configuration risk that push cyber governance beyond traditional security controls. SEC cyber disclosure rules force public companies to operationalize materiality, governance, and board oversight in a way that favors defensible quantification and reporting. Cyber insurance continues to grow, and carriers increasingly reward clients that can quantify exposure or at least produce better evidence. Supply-chain attacks remain frequent enough that third-party risk is no longer a niche compliance task. At the same time, the market has real brakes. Budget growth in 2026 is still positive, but buyers increasingly want measurable efficacy, fewer tools, and lower operating friction. CRQ also carries a trust problem when outputs look overly precise or are poorly aligned with the audience. Finally, privacy limits, fragmented telemetry, and long cross-functional implementations mean SAFE is selling into a category where technical urgency is high but conversion speed is not guaranteed.[CM028, CM029, CM030, CM031, CM032, CM033]

Growth Drivers and Constraints
FactorTypeImpactEvidence
AI-agent and AI-platform adoption expands attack surface and governance needsdriverhighGartner highlights AI-agent oversight as a top 2026 security trend; SAFE launched AI-SPM to address the gap.
SEC cyber disclosure rules force recurring governance and reporting disciplinedriverhighSEC and KPMG show four-business-day incident disclosure plus annual governance and strategy disclosure requirements.
Cyber insurance growth increases demand for quantification and better evidencedrivermediumMunich Re, Fitch, and Marsh-linked reporting connect insurance demand to better risk assessment and underwriting data.
Third-party and supply-chain attacks keep TPRM on the board agendadriverhighSecurityScorecard and Moody's show third-party breaches remain common and operationally material.
Budget growth remains positive in 2026drivermediumPicus and PwC-linked reporting show continuing budget expansion even amid scrutiny.
Tool consolidation and ROI proof pressure platform purchasesconstraintmediumPicus and Mordor both describe a shift away from disconnected tools toward efficacy and integration.
Implementation complexity and data fragmentation slow deploymentsconstrainthighIBM, Moody's, Mordor, and SAFE's own low-friction messaging imply inventory cleanup, integration work, and workflow redesign are still real barriers.
CRQ trust gaps can weaken board adoption when outputs look overly preciseconstraintmediumExtraHop and PwC-linked coverage show many firms still distrust or underuse financial quantification outputs.
Privacy and data-availability limits can weaken model qualityconstraintmediumMordor explicitly cites fragmented data pools and privacy rules as headwinds for CRQ model accuracy and cost.

Impact ratings reflect likely effect on adoption timing for large-enterprise SAFE buyers, not a macro forecast for the whole cybersecurity sector.

[CM028, CM030, CM032, CM034, CM035, CM036]
FM004: Enterprise Cyber Risk Management Adoption Flow

The practical buying path starts with exposure or disclosure pressure, expands into cross-functional workflow needs, and ends with a platform-consolidation decision.

[CM021, CM023, CM032, CM044, CM046]

2.5 Exhibits

Chapter 03

03Competitors

3.1 Competitive Landscape: SAFE Competes Across Direct CRQ, CTEM, TPRM, and Platform-Consolidation Sets

SAFE is not defending a single-category niche. The reviewed evidence shows a four-front landscape. First are direct CRQ and cyber-risk-management vendors: SAFE, Tenable, SecurityScorecard, BitSight, and adjacent CAASM player Axonius all claim to convert raw exposure or telemetry into business-prioritized risk insight. Second are CTEM and exposure-validation vendors such as Tenable, CrowdStrike, Rapid7, and Cymulate, which increasingly sell exploitability proof, attack-path context, and remediation automation. Third are dedicated TPRM specialists including Panorays, Prevalent, OneTrust, and ProcessUnity, plus Vanta from the trust-management side. Fourth are broad platform substitutes such as Palo Alto and CrowdStrike that can absorb the same budget through renewal-driven platform consolidation. Forrester's 2025 CRQ commentary is important because it explicitly says vendors have expanded into adjacent use cases like exposure management and third-party risk, meaning SAFE's real competition is broader than the legacy CRQ cohort alone. SAFE therefore wins or loses not only on quantification accuracy, but on whether buyers prefer a unified cross-domain risk platform versus a specialized ratings, TPRM, or exposure-management tool.[CP001, CP009, CP011, CP013, CP015, CP018]

Competitor Profile Table
CompetitorPrimary categoryScale / public signalTarget buyerKey product / moduleRelative strength vs SAFE
TenableExposure management / CTEMPublic; Tenable One spans 300+ integrationsEnterprise / public-sector security teamsTenable OneBroadest installed-base bundling threat and strongest cross-surface CTEM breadth
AxoniusCAASM / exposure adjacency$2.6B valuation; $200M Series EIT + security operationsAxonius CAASM / SaaS ManagementAsset visibility depth and many integrations, but weaker native CRQ narrative
SecurityScorecardThreat-informed TPRM / ratingsAI-led TPRM platform; A-F ratings benchmarkThird-party risk + board reporting teamsTITAN AI PlatformMassive outside-in telemetry and ratings credibility; weaker first-party quantification
BitSightCyber risk intelligence / ratingsMoody's-linked ICT covers 325M organizationsEnterprise risk, insurance, and supply-chain teamsBitSight cyber risk platformExternal intelligence scale and Moody's distribution; thinner workflow depth than SAFE
PanoraysTPRMQuote-based enterprise platform; ISO 42001-governed AITPRM leaders and procurement-aligned teamsPanorays TPCRMStrong nth-party mapping and contextual vendor rating workflow
PrevalentTPRMMitratech-owned; 800+ templates and managed servicesLarge vendor-risk programsPrevalent TPRMMature lifecycle coverage and services layer, but less CRQ-native positioning
OneTrustGRC / TPRM adjacencyBroad governance footprintLegal, privacy, compliance, and risk organizationsOneTrust Third-Party Risk ManagementNatural procurement path for governance buyers, but less differentiated CRQ depth
ProcessUnityTPRM18k attested assessments; 370k vendor profilesLarge enterprises with complex TPRM programsProcessUnity TPRM + Global Risk ExchangeDeep assessment exchange and AI evidence review capabilities
VantaTrust management / TPRM adjacency$2.45B valuation; >$100M ARR; 8k+ customersMid-market to enterprise compliance-led teamsVanta trust platform + vendor riskPackaged trust platform and fast growth, but CRQ depth is lighter
CrowdStrikeExposure management / platform substituteFalcon platform; AI exposure and prioritizationSecurity operations and platform-consolidation buyersFalcon Exposure ManagementReal-time exploitability and remediation embedded in a larger platform
Palo Alto NetworksAI SOC / platform substituteXSIAM-led platformization motionSOC modernization buyersCortex XSIAMCan absorb budget through broader SOC transformation rather than direct CRQ parity
Rapid7Exposure management / vulnerability managementInsightVM now powers Exposure CommandSecurity teams standardizing on VM + ASMExposure Command / InsightVMCan bundle attack-surface and vulnerability context into existing contracts
CymulateCTEM / exposure validationAgentic CTEM and exposure-validation workflowSecurity validation and detection-engineering teamsCymulate CTEM / Exposure ValidationStrong proof-of-exploitability workflow, but simulation-centric versus SAFE's board-facing quantification

Partial enumeration of the most visible direct, adjacent, and substitute vendors appearing in 2025-2026 public materials relevant to SAFE's CRQ, CTEM, and TPRM evaluation set; not a complete list of all cybersecurity or GRC alternatives.

[CP009, CP011, CP013, CP015, CP016, CP018]
FP001: Competitive Positioning Map

Ordinal positioning across breadth of platform and depth of risk quantification shows SAFE closest to the top-right corner, with Tenable strongest on breadth and ratings vendors stronger on external telemetry than on native CRQ depth.

Axes are ordinal analyst scores inferred from reviewed public positioning, not vendor-published benchmark values. The figure is directional and intended to compare strategic posture rather than quote exact performance metrics.

[CP001, CP009, CP013, CP015, CP016, CP024]

3.2 Capability Comparison: SAFE Leads on Unified Quantification, But Rivals Match It in AI Messaging and Parts of Workflow Depth

The strongest evidence-backed distinction is that SAFE unifies CRQ, CTEM, and TPRM in one storyline, while most competitors remain strongest in one of those layers. Tenable is the most dangerous broad-platform rival because Tenable One already combines exposure data, attack-path analysis, AI agents, and integrations at enterprise scale. SecurityScorecard and BitSight remain formidable where outside-in ratings, continuous vendor monitoring, and large external datasets matter most, but the reviewed materials do not show the same native first-party FAIR-based business-impact framing SAFE emphasizes. Panorays, Prevalent, OneTrust, and ProcessUnity show that specialized TPRM players are not standing still: they all automate assessments and monitoring, while Panorays and ProcessUnity now use explicit AI language. Vanta demonstrates a different commercial angle by embedding vendor risk inside a broader trust-management package with AI questionnaire quotas and vendor discovery. The net effect is that SAFE's AI story alone is no moat. Its advantage depends on whether buyers value a shared data model that ties exposure, vendors, and business impact together more than they value incumbent breadth, outside-in ratings scale, or deeply specialized TPRM operations.[CP008, CP010, CP012, CP014, CP016, CP017]

Feature / Capability Matrix
Capability dimensionSAFETenable OneSecurityScorecardBitSightAxoniusPanorays
Native CRQ / business-impact modelingFull — FAIR-based CRQ and board narrativePartial — quantifies exposure and prioritization, but not FAIR-native in reviewed materialsLimited — threat-informed ratings and TPRM, less first-party financial modelingLimited — cyber risk intelligence and ratings, not native FAIR-style CRQLimited — asset/risk control focus, no reviewed native CRQ narrativePartial — trusted vendor risk rating, but vendor-centric not enterprise-wide CRQ
CTEM / exploitability automationFull — Balbix expands CTEM linkage to business impactFull — attack paths, exposure signals, remediation workflowsLimited — continuous supplier monitoring more than CTEMLimited — external intelligence, less exploitability proofPartial — asset and posture context, not direct exploit validationPartial — external attack-surface monitoring and remediation
TPRM lifecycle coverageFull — discovery, tiering, questionnaires, monitoring, reportingLimited — can ingest third-party data, but not TPRM-firstStrong — threat-informed TPRM and questionnairesModerate — strong continuous monitoring, lighter workflow depthWeak — not a TPRM system of recordStrong — questionnaires, nth-party mapping, continuous monitoring
AI agents / workflow automationFull — 100+ AI agents and agentic workflowsStrong — Hexa AI and automation layerStrong — TITAN AI agentsLimited — analytics-first rather than agentic workflow emphasisModerate — automation and policy actionsStrong — agentic AI positioning and governed AI framework
Integration ecosystemStrong — positioned as cloud-of-clouds and cross-domain platformStrong — 300+ integrations and connectorsModerate — integrates threat and third-party dataModerate — APIs and ecosystem workflowsStrong — hundreds of data sourcesModerate — third-party ecosystem focus
Third-party discovery / nth-party contextStrong — shadow-vendor discovery and third-party automationLimited — not a TPRM-native workflowStrong — continuous supplier discovery and nth-party awarenessModerate — external monitoring of suppliersWeak — not a TPRM-native workflowStrong — nth-party mapping and dynamic ratings
Board / executive reportingStrong — CRQ-centric business impact narrativeModerate — exposure cards and dashboardsStrong — ratings and risk-reduction storytellingStrong — ratings and cyber risk intelligence outputsModerate — asset and posture reportingModerate — risk ratings and compliance reporting

Cells summarize evidence from official product pages plus limited vendor-authored comparison material; they describe reviewed public positioning, not the outcome of a hands-on lab validation or paid proof-of-concept.

[CP001, CP008, CP010, CP012, CP014, CP016]
Pricing / Packaging Comparison
VendorPublic packaging signalLikely charging unitPublic price visibilityMinimum / entry motionNotes
SAFEUsage-based / all-inclusive enterprise platform claims in TPRM materialsEnterprise platform / usage rather than per-vendor list priceCustom quoteSales-led demoSAFE emphasizes avoiding per-vendor charges, but realized ACV is not public
Tenable OnePlatform licensing with bundled exposure modulesPlatform / asset / surface coverageCustom quoteGuided demo / enterprise salesPackaging benefits from consolidation economics, not list-price transparency
SecurityScorecardThreat-informed TPRM platform sold with ratings and workflowsPortfolio / vendor ecosystem / service tierCustom quoteSales-ledPublic materials focus on outcomes and telemetry, not list pricing
PanoraysQuote-based TPCRM platformVendor portfolio / programRequest quoteSales-led quotePricing page confirms custom quoting and lifecycle scope
ProcessUnityTPRM platform plus exchange and AI modulesVendor / module / connector / service mixCustom quoteSales-led demoPublic sources emphasize modular workflow and exchange value, not public list prices
PrevalentSoftware + vendor intelligence + managed servicesProgram / vendor lifecycle / servicesCustom quoteSales-ledManaged-services component implies implementation-heavy enterprise packaging
VantaPackaged trust platform with included AI questionnaire quotas and vendor risk featuresEmployees, resources, devices, apps, questionnairesPersonalized pricingFree demo / tiered plansMost transparent packaging structure among reviewed vendors even though list prices are still private

Public web evidence supports packaging style more strongly than exact prices. Only Vanta exposes meaningful packaged feature tiers, while Panorays explicitly requests quotes and most enterprise peers stay fully sales-led.

[CP017, CP021, CP022, CP031, CP037]
FP002: Feature Breadth / Capability Map

Scored summary matrix highlights SAFE's strongest relative position in cross-domain integration and CRQ depth, while Tenable leads broad exposure breadth and SecurityScorecard/Panorays remain strongest in specialist TPRM lanes.

Scores are analytic abstractions of the detailed matrix in TP002 and are meant to make relative positioning legible. They are not vendor-published ratings and should not be interpreted as audited benchmarks.

[CP010, CP014, CP017, CP022, CP028, CP032]

3.3 Moat Analysis: RiskLens and Balbix Improve Durability, While Analyst Validation Reinforces SAFE's Positioning

SAFE's most durable moat elements come from methodology, integration, and customer proof rather than from a proprietary AI slogan. RiskLens matters because it brought FAIR-native cyber risk quantification and FAIR Institute credibility into SAFE's stack, directly supporting transparent business-impact modeling. Balbix matters because it gave SAFE an established CTEM and exposure-management asset at a time when buyers want exploitability context, not just dashboards. Those two acquisitions let SAFE tell a more complete story than a pure ratings vendor or a pure TPRM workflow tool. Analyst evidence helps, too: SAFE says Forrester named it a CRQ leader, while Liminal ranked it highly in TPRM product capability and practitioner satisfaction. Just as important, SAFE cites reference customers such as Google, Fidelity, T-Mobile, Chevron, and IHG, which helps explain why enterprise buyers may tolerate a newer platform if it appears to solve multiple risk workflows at once. The durability caveat is that none of these moats are exclusive forever. FAIR usage is spreading, AI automation is spreading, and exposure-management incumbents are bundling aggressively. SAFE's moat therefore looks strongest when the buyer explicitly wants quantified business-impact decisions across first-party and third-party risk, not when the buyer is simply shopping for one more monitoring tool.[CP002, CP003, CP004, CP005, CP006, CP007]

Moat Durability / Competitive Risk Register
Moat claimWhy it mattersDurabilityMain competitive riskLikely timeline
RiskLens + FAIR methodologySupports transparent, board-ready CRQ and standards alignmentHighFAIR becomes table stakes as more vendors adopt recognized models12-36 months for narrative narrowing; longer for community credibility
Balbix CTEM acquisitionAdds exploitability, exposure context, and CTEM data to SAFE's CRQ coreMedium-HighCTEM incumbents keep shipping automation faster than SAFE integrates modules12-24 months
Unified CRQ+CTEM+TPRM architectureLets one platform connect first-party, third-party, and exposure decisionsMediumBuyers accept best-of-breed tools plus integrations instead of one system of recordImmediate and ongoing
Named enterprise customers and analyst proofImproves referenceability in large-account bakeoffsMediumCompetitors with larger installed bases or stronger procurement paths neutralize referencesOngoing
Usage-based / all-inclusive TPRM storyCan reduce vendor-count pricing friction if real in practiceMedium-LowOpaque realized pricing prevents SAFE from proving durable price advantage publiclyImmediate
AI-agent workflow narrativeSupports efficiency and onboarding speed claimsLow-MediumAI automation is now common language across SecurityScorecard, Panorays, ProcessUnity, Vanta, and CTEM vendorsImmediate

Durability reflects public evidence only. The strongest moat elements are methodology and integrated workflow breadth; the weakest are AI branding and publicly provable pricing power.

[CP002, CP003, CP004, CP028, CP029, CP034]
FP003: Moat / Readiness KPIs

Compact moat dashboard shows why SAFE currently looks most credible when buyers want one quantified system across first-party, third-party, and exposure risk — but also why pricing proof and bundling resistance still need diligence.

KPI values are direct counts or qualitative summaries derived from public sources reviewed for this chapter; they are not internal operating metrics.

[CP001, CP002, CP003, CP004, CP005, CP006]

3.4 Competitive Risks: Bundling, Ratings-Scale Data, and Specialized TPRM Depth Are the Main Threats

The highest strategic risk is bundling by broader platforms. Tenable already looks closest to SAFE's unified narrative, and CrowdStrike or Palo Alto can win by wrapping exposure or AI operations into a larger renewal rather than by matching SAFE feature-for-feature. A second risk is that ratings-led vendors such as SecurityScorecard and BitSight can still win programs where outside-in monitoring, ecosystem benchmarking, or portfolio-scale external intelligence matter more than deep first-party quantification. A third risk is specialist workflow depth in TPRM. ProcessUnity, Panorays, OneTrust, and Prevalent all present mature vendor-lifecycle tooling, and ProcessUnity in particular markets a large risk-data exchange that SAFE does not publicly match with a comparable disclosed corpus. Finally, pricing transparency remains weak across the category. SAFE can tell an appealing usage-based or all-inclusive story, but public evidence does not disclose realized ACV or clean win-rate data, making it hard to prove durable pricing power. The chapter's adverse read, therefore, is that SAFE's moat is real but conditional: it is strongest when buyers want one quantified risk system of record, and weaker when buyers prioritize incumbent suite consolidation, outside-in ratings scale, or deeply specialized TPRM operating machinery.[CP028, CP031, CP032, CP033, CP034, CP035]

3.5 Exhibits

Chapter 04

04Financials

4.1 Revenue model and monetization

SAFE's public materials point to a platform-style enterprise SaaS model rather than a services-led security consultancy. The company consistently presents CRQ, TPRM, and CTEM as one unified cyber risk platform, which implies a land-and-expand motion: CRQ appears to be the historical wedge for board-, regulator-, and insurance-facing cyber risk decisions; TPRM is the first clearly disclosed expansion module; and CTEM is the newest attach product layered onto the same control plane. That sequence matters financially. SAFE launched TPRM in 2024 with 100+ customers live within a week, and by the July 2025 Series C announcement management said more than half of customers had already adopted the module. That makes TPRM the strongest public signal of wallet expansion, while CTEM looks more like a 2025-to-2026 upsell vector than an already mature revenue base. Public pricing is intentionally thin, but the clues that do exist are enterprise-like: SAFE advertised 50% contract buyouts from incumbent TPRM vendors, no vendor caps, AWS Marketplace private offers, and case-study references to flat pricing. Together those clues support a negotiated annual subscription model, likely sold by module and scope rather than simple per-seat pricing.[CI001, CI002, CI003, CI005, CI006, CI010]

Revenue streams table
Revenue streamPricing model / mechanismEstimated contributionEvidence source
CRQ core platformNegotiated enterprise subscription tied to risk quantification, board reporting, and ROI workflowsLargest current revenue base (estimated 40-55% of ARR)SAFE CRQ datasheet; About page; Series C press
TPRM moduleAdd-on or bundled enterprise subscription with flat-pricing references and no-vendor-cap positioningFastest visible growth contributor (estimated 25-35% of ARR)TPRM launch press; Instacart and Kyriba stories; AWS page
CTEM moduleNew attach module sold into existing enterprise accounts and new unified-platform dealsEarly but strategic contribution (estimated 10-20% of ARR)Series C launch; CTEM datasheet; Balbix acquisition materials
Implementation / premium supportOnboarding, integrations, reporting, and customer-success services around platform deploymentAncillary, likely <10% of revenueCustomer stories; T-Mobile deployment scope
Channel / marketplace procurementAWS Marketplace private offers plus partner-influenced enterprise procurementBooking accelerator more than a standalone revenue lineAWS Marketplace page; Sorenson and Avataar investor descriptions

Contribution ranges are low-confidence estimates based on module timing, customer stories, and attach-rate clues; SAFE does not disclose audited product-level revenue mix.

[CI001, CI002, CI003, CI011, CI012, CI013]
Pricing / monetization table
Product / motionPricing modelEstimated ACV / ARR signalNotes
CRQ enterprise coreCustom annual platform contract$300k-$700k ACV estimateBoard, regulator, and insurance-facing workflows suggest high-budget enterprise buyers; no list price is public.
TPRM flat-price deploymentsFlat subscription priced to assess the full vendor estate$150k-$400k ACV estimateInstacart and Kyriba both reference flat pricing and scaling without added headcount or per-vendor cost.
TPRM competitive buyout offerFirst-year subscription discount equal to 50% of incumbent contract valueDiscounted land motion, not steady-state pricingMay 2024 launch promotion implies aggressive replacement pricing against legacy TPRM vendors.
CTEM add-onModule attach to the broader platform$150k-$400k incremental ACV estimateNo public rate card; 2025 launch timing suggests attach revenue more than standalone volume pricing.
AWS Marketplace procurementPrivate offer / annual enterprise contractingDeal-size signal only; not a list priceMarketplace availability reduces procurement friction but still points to negotiated enterprise pricing.

These are monetization signals, not realized contract values. SAFE discloses procurement structure and discounting clues, but not list prices or average selling prices.

[CI011, CI012, CI017, CI018, CI028, CI037]
FI001: Revenue model bridge

SAFE appears to land via CRQ, expand through TPRM, and attach CTEM into the same enterprise account rather than monetizing each workflow as a separate low-price point tool.

This is a mechanism figure, not a reported revenue waterfall. The ordering is based on launch chronology, attach-rate clues, and customer stories.

[CI001, CI002, CI003, CI011, CI013, CI041]

4.2 Unit economics and benchmark proxies

SAFE does not publish ACV, CAC, payback, NRR, gross margin, or ARR, so the investor has to triangulate from deployment scale, customer outcomes, and public-company benchmarks. The customer stories are useful because they show SAFE landing in large, operationally important environments: T-Mobile used SAFE across more than one million digital assets, Instacart operationalized TPRM across 600+ third parties in three weeks, and Kyriba migrated 290+ vendors in under a week while moving from pay-per-vendor economics to flat pricing. Those signals support a blended enterprise ACV that is probably well above commodity security-tool pricing. A reasonable public estimate is roughly $250,000 to $800,000 per year for meaningful multi-module deployments, with TPRM-only or pilot deals likely below that range and broad CRQ+TPRM+CTEM platform deals above it. For margin and go-to-market benchmarks, public cyber SaaS comps are helpful but cautionary: Zscaler still posted ~77% GAAP gross margin at scale, but its 10-K shows that data-center expansion and added headcount can compress margins; CrowdStrike's filing shows a very high-subscription mix but also heavy sales and operating investment. That suggests SAFE could ultimately look like healthy enterprise SaaS on gross margin, yet still absorb significant CAC upfront through enterprise selling, partner enablement, and post-acquisition integration.[CI016, CI017, CI018, CI029, CI030, CI031]

Unit economics table
MetricEstimated valueBasisConfidence
Blended enterprise ACV$250k-$800kDerived from marquee enterprise logos, T-Mobile scale, and flat-pricing multi-vendor TPRM case studies.Low
Estimated current ARR$55M-$90MLow-confidence scenario based on 100+ early TPRM customers, >50% module adoption, and repeated triple-digit growth claims.Low
Long-run gross margin band70%-80%Anchored to public cyber SaaS comps, including Zscaler at ~77% GAAP gross margin in fiscal 2025.Low-medium
Sales & marketing / CAC proxyHigh-touch enterprise motion; comp S&M intensity roughly 25%-47% of revenueCrowdStrike and Zscaler filings both show significant sales-headcount and commission intensity even at scale.Medium
CAC payback proxy18-30 monthsEnterprise selling, partner motions, and large deployments imply slower payback than PLG software but still reasonable for security platforms.Low
NRR estimate110%-120%Cross-sell path from CRQ to TPRM to CTEM plus >50% TPRM adoption implies expansion potential, but no cohorts are public.Low
LTV / CAC estimate3x-5xUses the gross-margin and payback proxy ranges above; should be treated as a benchmark-driven scenario, not a disclosed fact.Low
Comparable revenue per employee$337k-$450kZscaler and CrowdStrike public filings imply that range at scaled cyber SaaS peers.Medium

All SAFE-specific unit economics in this table are estimated from public proxies; only the comparable-company anchor points are directly disclosed by their own public filings or market-data pages.

[CI029, CI030, CI031, CI032, CI034, CI036]
FI002: Unit economics bridge

The public unit-economics path runs from large-account deployments and flat-pricing scale to expansion and benchmark gross margin, but breaks at undisclosed CAC, retention, and cash conversion details.

Gross-margin and CAC nodes are benchmark-derived rather than company-disclosed. SAFE has not published the numeric bridge needed to convert these proxies into audited unit economics.

[CI016, CI017, CI018, CI029, CI030, CI031]

4.3 Capital history and adequacy

Capital adequacy looks acceptable in the near term but still opaque in the ways that matter for underwriting. SAFE's retained public sources support a financing arc from a $50 million Series B to a $70 million Series C and more than $170 million raised overall, with older SEC Form D records confirming that the company had been tapping private capital long before the current branding cycle. The July 2025 Series C narrative is expansionary rather than defensive: the proceeds were framed around engineering, go-to-market, R&D, and the CyberAGI roadmap, not around restructuring or balance-sheet repair. That is directionally positive. But the same file leaves key adequacy questions unanswered. SAFE does not disclose current cash on hand, monthly burn, or any debt schedule. It also does not disclose what RiskLens or Balbix cost, what integration spend has already been incurred, or how much additional product and GTM investment the Balbix combination requires to monetize CTEM at scale. On a low-confidence public estimate, a company of this profile could plausibly be burning roughly $25-$45 million per year, which would imply roughly 18-30 months of runway for the Series C proceeds before considering any remaining prior-round cash. That is enough to keep building, but not enough transparency to underwrite next-round timing precisely.[CI005, CI008, CI009, CI020, CI021, CI022]

Capital adequacy table
Round / capital eventAmountDateInvestors / counterpartiesImplied valuation / statusUse of proceeds
Series A$33M2018British Telecom; John ChambersPublic amount disclosed; valuation not retained hereInitial productization and CRQ platform buildout
Series B$50M2021Sorenson Capital; Eight Roads; Telstra Ventures; WTI; existing investorsPublic amount disclosed; valuation not publicly disclosed in retained evidenceContinue innovating the real-time AI-driven cyber risk platform and support rapid growth
SEC Form D disclosure$25.0M offered / $15.0M sold / $10.0M remaining2021SAFE Securities Inc. private offeringFiling-level private capital disclosure, not a priced public roundShows private capital still being placed during the SAFE rebrand period
Series C$70M2025-07-31Avataar Ventures; SIG Venture Capital; NextEquity Partners; Prosperity7 Ventures; existing investorsPublic amount disclosed; valuation not independently disclosed in retained sourcesEngineering, go-to-market, R&D, and CyberAGI roadmap acceleration
Acquisition considerationUndisclosed2022 and 2025RiskLens and BalbixMaterial open itemWould capture purchase price, retention packages, integration costs, and any earn-outs
Total publicly disclosed capital raised>$170MThrough 2025Aggregate of public company statementsCompany-claimed aggregate onlySufficient for near-term execution, but not enough to infer cash-on-hand or runway without management data

Company Overview owns the full round chronology. This table keeps only the funding facts needed for forward capital adequacy and highlights what is still missing for underwriting.

[CI005, CI008, CI009, CI021, CI022, CI025]
FI003: Financial estimate range

Where SAFE withholds operating metrics, the most defensible public ranges are on ACV, ARR, burn, and runway rather than on precise historical income-statement lines.

All ranges are estimated and should be replaced with management financials before underwriting. The figure is useful for framing diligence, not for setting a final valuation.

[CI034, CI037, CI039, CI043, CI049]
FI004: Capital intensity / cash-flow map

SAFE’s disclosed capital stack appears to fund growth and category expansion, but acquisitions and ongoing enterprise selling create cash demands that are not visible in public financial statements.

This figure maps likely uses of capital and hidden cash drains rather than a published cash-flow statement. Acquisition consideration and debt remain undisclosed in retained public sources.

[CI005, CI021, CI022, CI025, CI026, CI040]

4.4 Financial gaps and diligence blockers

The core underwriting problem is not whether SAFE has a plausible software business; it is that the public record never shows the operating math underneath the narrative. No retained source discloses ARR, GAAP revenue, deferred revenue, module mix, gross margin, net revenue retention, churn, customer concentration, cash balance, monthly burn, or acquisition consideration for RiskLens and Balbix. That means a sophisticated investor cannot tell whether SAFE is a high-quality recurring software engine with attractive expansion economics, or a capital-hungry platform story still carrying meaningful integration and services drag. The diligence path should therefore be exact and financial rather than thematic: request ARR and billings by module; realized pricing and discount ladders for CRQ, TPRM, and CTEM; deferred revenue and RPO; cohort retention and expansion by vintage; cloud-hosting and support cost drivers; sales and marketing efficiency by channel; acquisition integration scorecards; and a monthly cash runway model that includes any debt, earn-outs, or retention packages. Until that package is visible, the right financial conclusion is cautiously positive on revenue quality and product breadth, but still blocked on precision, margin path, and capital efficiency.[CI027, CI028, CI035, CI040, CI044, CI045]

Public financial gaps table
Missing metricStatusDisclosure levelDiligence path
Current ARR and revenue by moduleNot publicly disclosedPrivate onlyRequest monthly ARR, GAAP revenue, and billings by CRQ, TPRM, CTEM, services, and geography.
Gross margin bridgeNot publicly disclosedPrivate onlyRequest module-level gross margin plus hosting, support, data, and professional-services cost drivers.
Cash on hand, burn, and runwayNot publicly disclosedPrivate onlyRequest the latest board package or CFO cash-flow model with monthly actuals and base/upside/downside runway.
Net revenue retention and churnNot publicly disclosedPrivate onlyRequest cohort retention by vintage, segment, and module, including gross and net dollar retention.
Acquisition economics for RiskLens and BalbixPurchase price and integration spend undisclosedPrivate onlyRequest deal consideration, retention packages, synergy plan, and post-close integration scorecard.
Customer concentration and realized pricingNot publicly disclosedPrivate onlyRequest top-20 customer revenue mix, median ACV, discount ladders, term length, and renewal rates.

Null or missing metrics in this table are absence-of-disclosure findings, not zero values. Each diligence path is intended as a data-room or management-request list.

[CI027, CI028, CI035, CI040, CI044, CI045]
Chapter 05

05Product & Technology

5.1 Platform overview and modules

SAFE’s product story is no longer just cyber risk quantification. Public materials now present SAFE One as a unified operating layer across strategic, vendor, tactical, and AI exposure management. In practice, that means four commercial modules are doing different jobs inside one narrative. CRQ remains the board-facing financial engine: it converts telemetry, threat data, control evidence, and scenario logic into quantified loss exposure and investment decisions. CTEM is the tactical layer that normalizes asset and vulnerability data, prioritizes by exploitability and business impact, validates whether controls actually blunt attack paths, and then routes remediation. TPRM applies the same agentic logic to vendor onboarding, questionnaires, monitoring, and reassessments. AI-SPM extends the stack to AI vendors and AI usage, including shadow AI, contract risk, configuration drift, and outside-in exposure. SAFE also still positions SafeX as a reasoning layer that turns those module outputs into operational decisions. That breadth is strategically useful because it lets one budget owner buy a shared data and workflow plane rather than separate point tools, but it also means the investment case depends on whether the modules truly share one operating model rather than only a top-level brand umbrella.[CE001, CE002, CE003, CE005, CE008, CE012]

Product module / asset matrix
ModuleDescriptionMaturityKey differentiatorCompetitors
SAFE CRQFinancial cyber-risk decision engine that quantifies exposure in dollar terms using FAIR-based scenario modeling, control analytics, and board-ready reporting.Most mature commercial pillar; externally validated by Forrester in 2025Combines FAIR-based quantification, FAIR-CAM control analytics, and high integration breadth in one platformAxio, RiskLens legacy base, KPMG, CYE, ThreatConnect
SAFE CTEMExposure-management layer that unifies asset and vulnerability telemetry, prioritizes by exploitability and business impact, validates attack paths, and routes remediation.Newer than CRQ but strategically central after July 2025 launch and Balbix acquisitionConnects tactical exposures directly to quantified business impact rather than treating CTEM as a separate scoring siloBalbix legacy platform, Nucleus, Zafran, Tenable exposure products
SAFE TPRMAgentic workflow-driven third-party risk platform for onboarding, questionnaires, monitoring, reassessment, and fourth-party visibility.Rapidly scaling; SAFE says >50% customer adoption by July 2025 and $10M ARR in under one yearUses specialized AI agents to eliminate manual vendor chasing and turn TPRM into a risk-ranked operating workflowSecurityScorecard, BitSight, Black Kite, Whistic, ProcessUnity
SAFE AI-SPMAI security posture management for shadow AI discovery, AI-vendor visibility, contracts, configurations, questionnaires, and live activity monitoring.Newest module; launched publicly in 2026 and positioned as fast time-to-valueReal-Time AI Risk Graph plus the same workflow engine used elsewhere in SAFE, without requiring inline deploymentCranium, Obsidian, emerging AI-SPM / AI-governance vendors
SafeX and workflow fabricReasoning and workflow layer that turns telemetry into actions, reports, summaries, assignments, and remediation orchestration across modules.Strategic platform layer rather than a stand-alone SKUShared agentic-workflow model across CRQ, CTEM, TPRM, and AI-SPM reduces tool sprawl if modules are genuinely integratedTines, ServiceNow, bespoke internal orchestration
API and integrations layerREST APIs, GitHub integration, and connector marketplace that bring external tools, assets, findings, and documents into SAFE.Production-grade public surface with published auth and rate-limit detailsCombines admin-managed API access with broad no-code integration surface across security, ITSM, cloud, and productivity toolsPoint integrations from individual scanners, custom ETL, SOAR connectors

Maturity reflects public commercial evidence and external validation, not a full underwritten view of reliability or customer satisfaction for every module.

[CE001, CE002, CE005, CE008, CE012, CE016]

5.2 Technical architecture and agentic AI

The public architecture that can actually be verified is centered on connectors, a normalization layer, FAIR-based risk logic, and a workflow engine rather than on low-level infrastructure diagrams. SAFE’s CRQ surface says the platform ingests data from 200+ security and business systems and reviews roughly 600 threat events a day. The CTEM page shows how that expands into vulnerability scanners, CMDBs, cloud tools, pen-test outputs, and ticketing systems so exposures can be de-duplicated, prioritized, and mobilized. The integrations marketplace and API docs make that story more concrete: SAFE exposes Swagger-based REST APIs with versioned endpoints, admin-managed credentials, and a stated 1,200-request-per-minute cap, while integration guides such as GitHub show how findings and assets are pulled from source systems into SAFE. On top of that data plane sits the workflow fabric. Docs describe triggers, actions, flow controls, and AI tasks; product pages market 100+ workflows, 100+ AI agents, and 150+ connectors. The key architectural takeaway is that SAFE is trying to become an orchestration and reasoning layer above the customer’s existing security stack. The public gap is that SAFE has not published a detailed internal service map, queueing model, or fault-domain explanation, so the operational resilience of that orchestration layer still needs direct diligence.[CE004, CE006, CE010, CE017, CE018, CE019]

Workflow / use-case table
Use caseUserWorkflow stepsValue delivered
Board-level cyber-risk planningCISO, board liaison, finance partnerIngest telemetry and assessments -> run FAIR-based scenarios -> quantify loss exposure -> compare remediation or budget optionsTurns security posture into financial trade-offs that are easier to prioritize and defend
Exposure reduction in CTEMVulnerability team, platform security, IT operationsPull asset and finding data -> normalize and de-duplicate -> rank by exploitability and business criticality -> trigger ownership and ticket workflowsCuts noise and pushes teams toward the small set of exposures most likely to matter
Third-party onboarding and reassessmentTPRM analyst, procurement, business ownerAuto-tier vendor -> assign right questionnaire -> chase evidence and trust-center artifacts -> summarize and monitor continuouslyRemoves repetitive coordination work so analysts spend time on genuinely risky vendors
AI-vendor governance and shadow AI controlSecurity architecture, AI governance, privacyDiscover AI usage -> map contracts/configurations/live activity -> prioritize risky AI tools -> trigger governance or escalation workflowsProvides one operational view of AI adoption risk instead of scattered point reviews
Developer / integration enrichmentPlatform engineer, security engineeringAuthenticate to SAFE APIs or integrations -> sync findings and assets -> enrich external tools with SAFE context -> automate downstream actionsLets SAFE act as a shared context layer rather than a dashboard that traps data inside itself

Workflow steps summarize the public operating model; the exact internal state machine, exception paths, and SLA behavior are not publicly documented.

[CE004, CE005, CE008, CE010, CE012, CE013]
Technology / operating architecture table
ComponentTechnologyFunctionDependencies
Connector and ingestion layer150+ marketplace connectors, REST APIs, GitHub integration, marketplace listingsPulls telemetry, findings, documents, cloud signals, and vendor data into SAFECustomer source-system quality, API credentials, connector maintenance, and rate limits
Normalization and knowledge layerAsset/finding normalization, risk graphing, cross-tool de-duplicationCreates shared context across assets, exposures, controls, vendors, and AI usageConsistent identifiers across scanners, CMDBs, and cloud systems; Balbix integration depth
CRQ / FAIR engineFAIR scenarios, FAIR-MAM, FAIR-CAM, threat research, financial modelingTranslates telemetry into breach likelihood, loss magnitude, and prioritized decision optionsFAIR assumptions, industry data, control evidence quality, and regulator-facing explainability
Agentic workflow engineTriggers, actions, flow controls, AI tasks, templates, summaries, transformsAutomates onboarding, reassessments, remediation routing, policy escalation, and reportingLLM routing, template quality, change control, and human override / review design
Module applicationsCRQ, CTEM, TPRM, AI-SPM, SafeX user experiencesExpose differentiated user journeys for boards, analysts, TPRM teams, and AI-governance ownersShared data model, release coordination, and whether newer modules are truly one platform
Action / ecosystem layerTicketing tools, email, external monitoring, cloud and identity systemsPushes decisions into remediation, governance, procurement, and reporting processesITSM availability, vendor cooperation, third-party trust-center access, and cloud-provider signals

This is a public-evidence operating model; SAFE has not published a low-level service diagram with queues, data stores, or failure domains.

[CE004, CE005, CE006, CE017, CE018, CE019]
FE001: Product architecture map

SAFE’s public architecture reads as a connector-fed data plane that powers a common reasoning and workflow layer across four modules.

[CE001, CE003, CE015, CE016, CE017, CE018]
FE002: Customer workflow / operating flow

A typical SAFE operating flow starts with telemetry and vendor data, creates a shared risk view, and then triggers automated response or governance actions.

[CE004, CE005, CE008, CE012, CE018, CE040]

5.3 Acquisitions, IP, and differentiated technology

SAFE’s strongest product differentiation comes from combining two acquisitions with its original platform thesis. RiskLens brought the FAIR intellectual property and practitioner credibility that many CRQ competitors still lack; SAFE now uses that acquisition to frame itself as not merely FAIR-aligned but operationally FAIR-based through FAIR-CAM and automated control analytics. Balbix added a different kind of depth: AI-native asset discovery, exposure discovery, exploitability analysis, control-efficacy context, and remediation workflow hooks. Together, those acquisitions support SAFE’s claim that it can connect technical attack-surface evidence to business loss in one system. That is the core strategic argument behind CyberAGI and “risk singularity”: not just more dashboards, but a combined graph where assets, exposures, controls, vendors, AI use cases, and financial consequences are measured on one plane. Public evidence is good enough to support the thesis directionally, especially because outside coverage of Balbix confirms real CTEM capabilities. The unresolved diligence issue is integration maturity. Most public sources still describe what the combination should become, not which Balbix-origin services, schemas, or remediation loops are already merged into the production SAFE One experience.[CE020, CE021, CE022, CE023, CE024, CE025]

FE003: Critical dependency map

SAFE’s differentiators rely on outside intellectual property, cloud infrastructure, LLM providers, partner integrations, and successful Balbix/RiskLens integration.

[CE020, CE023, CE024, CE027, CE029, CE036]

5.4 Compliance, trust, and data handling

SAFE’s trust posture is stronger than its public infrastructure disclosure. The security page lists SOC 2 Type 2, ISO 27001:2013, ISO 9001:2015, and TX-RAMP, and it describes a multi-tenant AWS deployment model with customer-selectable regions, TLS 1.2 in transit, AES-256 at rest, AWS KMS-based key management, continuous SAST and DAST scanning, daily vulnerability assessment, and periodic access review. The AI policy adds the clearest trust language for the newer agentic surface. SAFE says prompts are tenant-scoped, customer data is not used to train shared or cross-tenant models, data is not shared across customers, and model routing can involve AWS Bedrock-hosted, Anthropic, and OpenAI models. It also discloses that AI interactions are logged, AI usage can be disabled by admins, and SAFE AI is not designed for PHI/HIPAA workloads. That is meaningful enterprise-grade disclosure. The remaining caveat is scope precision. The public trust pages do not provide audit report excerpts, certificate numbers, or renewal dates for most certifications, and they do not explain how AI-specific controls map to each certification boundary. Buyers in regulated environments should treat the published posture as credible but incomplete until trust-center artifacts are shared.[CE026, CE027, CE028, CE029, CE030, CE031]

Trust / quality / compliance table
Certification / controlStatusScopeRenewal date
SOC 2 Type 2Listed as activeSAFE SaaS platform; AI policy says AI runs within SOC 2 governed controlsNot publicly disclosed
ISO 27001:2013Listed as activeInformation-security management and AI controls inherit the same frameworkNot publicly disclosed
ISO 9001:2015Listed as activeQuality-management process for the company and platform operationsNot publicly disclosed
TX-RAMPListed as activePublic-sector cloud trust signal shown on the security pageNot publicly disclosed
Data security architectureOperational controlAWS hosting, regional tenancy, TLS 1.2, AES-256 at rest, AWS KMS / customer-managed keysOngoing operational control
AI governance policyUpdated and publicTenant isolation, no cross-tenant training, logged AI interactions, no HIPAA support for SAFE AIUpdated 2026-04-06

SAFE publishes meaningful trust controls, but buyers still need the underlying trust-center artifacts, audit scope, and certificate metadata to fully underwrite the posture.

[CE026, CE027, CE028, CE029, CE030, CE031]

5.5 Roadmap, maturity, and direction of travel

The roadmap is visible enough to understand direction even if not every milestone is independently underwritten. The sequence is coherent: RiskLens in 2023 gave SAFE defensible quantification IP; TPRM was launched in 2024 and then repositioned in 2025 as a fully autonomous, agentic workflow product; CTEM arrived in July 2025 as the next major module; Balbix followed in November 2025 to deepen exposure-management and asset-intelligence coverage; AI-SPM arrived by 2026 to extend the same platform into AI governance and AI-vendor exposure. In other words, SAFE is building outward from strategic quantification into operational risk reduction. External signals, however, are mixed. Forrester’s CRQ view is strongly positive and validates the FAIR-CAM differentiation, customer stories show production use, and AWS marketplace presence suggests enterprise buying intent. But BankInfoSecurity notes that users still want better asset and exposure tagging at scale, PeerSpot shows very limited grassroots review depth versus incumbents, and GARP’s CyberAGI coverage underscores how much of the autonomy story remains aspirational. SAFE looks commercially mature in CRQ, commercially accelerating in TPRM and CTEM, and earlier in AI-SPM; the common risk across all three newer surfaces is that the autonomy narrative currently has more public breadth than public engineering proof.[CE007, CE009, CE011, CE013, CE016, CE032]

Roadmap / release / development-stage table
Feature / milestoneStatusExpected dateStrategic importance
RiskLens acquisition and FAIR embeddingReleased2023Turned FAIR decision science into core platform IP and strengthened CRQ defensibility
Commercial launch of SAFE TPRMReleased2024Extended SAFE from strategic CRQ into vendor-risk workflows and created a land-and-expand path
Fully autonomous TPRM launchReleased2025-04-22Repositioned TPRM around specialized AI agents and workflow automation rather than questionnaire administration
Forrester CRQ leadership / FAIR-CAM validationAchievedQ2 2025Independent validation of SAFE’s CRQ differentiation and control-performance thesis
Fully autonomous CTEM plus Series C fundingReleased / funded2025-07-31Moved SAFE into tactical exposure reduction and funded the stated CyberAGI roadmap
Balbix acquisition and unified exposure-management thesisIntegration in progress2025-11-18 onwardShould deepen CAASM and CTEM intelligence and tighten the link between exposures and business impact
AI-SPM launch and AI risk graph expansionReleased2026Pushes SAFE into AI-vendor and AI-usage governance, broadening the platform beyond classic cyber telemetry

Later roadmap rows describe direction of travel and integration intent; public sources are clearer on launches and acquisitions than on post-launch completion milestones.

[CE020, CE023, CE026, CE032, CE033, CE034]
FE004: Product maturity / capability map

Public evidence points to high maturity in CRQ, fast-rising maturity in TPRM and CTEM, and earlier-stage evidence depth for AI-SPM and the broad autonomy narrative.

[CE016, CE033, CE034, CE035, CE036, CE039]

5.6 Exhibits

Chapter 06

06Customers

6.1 Customer Segmentation and Profile

SAFE’s public customer evidence points to a large-enterprise and upper-enterprise customer base rather than a broad SMB or self-serve motion. The homepage claims SAFE is used by 10% of the Fortune 500, while the customer library highlights telecom, financial services, healthcare, insurance, retail, utilities, consulting, and hospitality names. The buyer in these stories is usually a CISO, cyber-risk leader, GRC owner, or TPRM leader looking for board-grade risk communication, budget justification, or defensible prioritization. The day-to-day users are security, risk, and vendor-management teams; the payer is typically the enterprise security, compliance, or risk budget owner. Public use cases cluster around CRQ, executive reporting, and increasingly TPRM automation, with repeated emphasis on financial language and business impact rather than technical telemetry alone. That mix suggests higher implied ACVs and deeper workflow embedding, but it also implies longer enterprise sales cycles and more concentration risk if a relatively small number of very large customers account for a disproportionate share of revenue.[CU001, CU002, CU003, CU004, CU005, CU006]

Customer segmentation table
SegmentEstimated public count / proofBuyer / user / payerCore use caseImplied ACV rangeEvidence
Fortune 500 / global enterprise~50 Fortune 500 logos implied by SAFE’s 10% claim; exact count undisclosedBuyer: CISO / cyber-risk / board; User: security, risk, GRC; Payer: enterprise security budgetCRQ, CTEM, TPRM, executive risk reporting$150k-$500k+ inferred for multi-module enterprise motionHomepage claim plus July 2025 funding materials
Telecom and digital infrastructureT-Mobile case study plus Verizon and Delta logo mentions on the homepage/customers surfacesBuyer: cyber-risk or security leader; User: security operations / risk team; Payer: telecom security budgetQuantify risk across huge digital footprints and vendor ecosystems$150k-$400k+ inferredT-Mobile case study and homepage/customer-page logo proof
High-growth tech / marketplaces / retailInstacart, Carvana, Victoria’s Secret, and Glovo have public storiesBuyer: security / GRC / IT risk; User: security analysts and vendor-risk teams; Payer: enterprise tech or security budgetCRQ, TPRM automation, insurance optimization, budget justification$100k-$350k inferred2025-2026 customer stories
Financial software, insurance, and adjacent financial servicesKyriba, Fidelity, Shelter Insurance, and T-Mobile’s financial-risk framing provide public proofBuyer: TPRM leader, risk lead, or CISO; User: vendor-risk and compliance teams; Payer: risk/compliance budgetVendor-risk automation, board reporting, financial risk language$100k-$300k inferredKyriba, Shelter, and Fidelity scale evidence
Healthcare providers / clinical systemsOB Hospitalist Group, Max Healthcare, Kettering Health, and Main Line Health are in the story libraryBuyer: GRC / security leader; User: analyst or compliance team; Payer: provider security budgetTPRM visibility, clinical-confidence reporting, quantified cyber risk$100k-$300k inferredCustomer stories archive and OBHG case study
Energy, utilities, and critical infrastructureAboitiz Power, ISO New England, and Chevron provide visible sector fitBuyer: CISO / OT-risk lead; User: IT and OT risk teams; Payer: enterprise or infrastructure security budgetCRQ for critical infrastructure, budget allocation, phased control deployment$150k-$400k inferredAboitiz, ISO New England, Chevron scale and cybersecurity pages

Estimated counts and ACV ranges are inferred from public logo quality, workflow depth, and enterprise buying motion; SAFE does not publish a customer-by-segment census or price list.

[CU001, CU002, CU003, CU004, CU005, CU006]
FU001: Customer journey map

SAFE’s public journey usually starts with a CISO or TPRM leader trying to replace subjective cyber-risk workflows, then expands into board reporting and adjacent modules once the platform is embedded.

Journey stages are inferred from customer stories and review surfaces rather than a published SAFE sales-process diagram.

[CU003, CU004, CU009, CU011, CU036, CU037]

6.2 Named Customer Proof

SAFE’s named-customer proof is real, but it is not equally deep across the roster. T-Mobile is the strongest marquee proof in the reviewed corpus: SAFE’s story describes more than one million monitored digital assets, automated risk quantification, and a 75% reduction in reporting time. IHG also has meaningful use-case detail through SAFE’s community spotlight, which describes moving from qualitative risk scoring toward quantified high-value-asset risk communication and budget allocation. Instacart and Kyriba add high-quality TPRM proof, with quantified onboarding, automation, and ecosystem-coverage outcomes. By contrast, Google, Fidelity, and Chevron were retrieved only as named customers in SAFE’s July 2025 funding materials and a matching independent news recap; no module-specific deployment page, customer-authored story, or quantified outcome was retrieved for them in this run. The right diligence interpretation is that SAFE has believable marquee-logo breadth, but public proof depth is still concentrated in a smaller set of flagship stories.[CU009, CU010, CU011, CU012, CU015, CU016]

Named customer proof table
CustomerIndustryPublic deployment / use caseProof depthObservable valueLimitation
T-MobileTelecomCRQ-led cyber-risk management across 1M+ digital assets and vendor ecosystemHigh75% reporting-time reduction and automated risk prioritizationNo public renewal, contract size, or module attach-rate disclosure
IHGHospitalityQuantified high-value-asset risk communication, budgeting, and treatment selectionMediumMoves a global hotel operator from qualitative scoring to risk quantificationRetrieved via SAFE community spotlight rather than a live full case-study page
GoogleTechnology / internetNamed as a customer in 2025 funding materials; specific module not publicly disclosed in this runLowConfirms marquee hyperscale-logo presence if currentNo retrieved use-case page, customer quote, or quantified outcome
FidelityFinancial servicesNamed as a customer in 2025 funding materials; specific module not publicly disclosed in this runLowConfirms financial-services relevance if currentNo retrieved deployment detail, module, or business outcome
ChevronEnergyNamed as a customer in 2025 funding materials; specific module not publicly disclosed in this runLowConfirms critical-infrastructure relevance if currentNo retrieved case study, quote, or quantified outcome
InstacartMarketplace / grocery technologyExisting CRQ customer that became a design partner for autonomous TPRMHigh600+ third parties onboarded in three weeks; 100% assessed without extra headcountEvidence is company-hosted rather than customer-authored
KyribaTreasury / enterprise softwareAutonomous TPRM transformation at enterprise scaleHigh290+ vendors onboarded in under a week; 72% SOC 2 match; 100% ecosystem coverageEvidence is company-hosted rather than customer-authored

Rows distinguish deep public deployment proof from name-level logo proof; logos alone are not treated as evidence of retention or contract durability.

[CU009, CU010, CU011, CU012, CU015, CU016]
FU003: Customer proof matrix

SAFE’s named-customer file is strongest where use cases and outcomes are disclosed, but independent review surfaces still do not close the retention-visibility gap for the name-only references.

[CU009, CU011, CU015, CU025, CU026, CU027]

6.3 Adoption Trajectory

SAFE does not publish a precise active-customer count in the retrieved public materials, but it does disclose multiple adoption signals that together point to meaningful traction. The strongest are the claim that 10% of the Fortune 500 use SAFE, the April 2025 disclosure that SAFE reached $10 million of TPRM ARR in less than a year, and the July 2025 disclosure that more than half of customers adopted TPRM after launch. The company also says it is trusted by hundreds of global organizations and has delivered triple-digit growth for three consecutive years. The customer-story archive adds a useful freshness signal: 13 public stories are currently listed, and six were added between January and May 2026 alone. That cadence, combined with 100+ integrations and 3 billion daily signals processed, supports the view that SAFE is winning real production deployments and then expanding the visible reference set. What remains missing is the denominator: how many active accounts exist today, how many are paying versus pilot, and how many of the named stories represent net-new logos versus deeper wallet share inside existing customers.[CU006, CU008, CU028, CU029, CU030, CU031]

Customer growth / adoption trajectory table
Period / signalPublic metric or proofSourceConfidenceImplicationMissing denominator
Mid-2020 onwardSAFE says it has grown 100%+ y/y every year since going live with the platformVisionary customers blogmediumShows sustained commercial momentum rather than a one-year spikeNo starting customer count or ARR base disclosed
Apr 2025Trusted by hundreds of global organizationsAutonomous TPRM launch releasemediumSets a floor for customer breadth even though the exact count is undisclosedNo precise active-account count
Apr 2025$10M TPRM ARR in less than one yearAutonomous TPRM launch releasemediumShows fast module traction and meaningful expansion demandNo split between recurring software and associated services
Jul 202550%+ of customers adopted TPRM after the 2024 launchSeries C / CTEM releasemediumStrong land-and-expand signal inside the installed baseNo cohort breakout by logo age or vertical
Jul 2025Triple-digit growth for three consecutive years / 120%+ YoY since launchSeries C release and Indian Startup NewshighSupports a fast-scaling customer base and wallet-share storyNo disclosed revenue base, churn, or retention bridge
2026 homepage10% of Fortune 500 use SAFESAFE homepagemediumImplies meaningful penetration of the largest enterprise cohortNo list or exact count beyond the 10% claim
Jan-May 2026Six new public customer stories added in five monthsCustomer stories archivemediumFresh proof set suggests the reference base is still expandingStory cadence is not identical to net-new logo count
2026 homepage100+ integrations and 3 billion daily signals processedSAFE homepagemediumOperational scale is consistent with broad live deploymentsNot broken out by customer count or module

This trajectory table mixes customer-count proxies, module traction, and production-scale signals because SAFE does not publish a single audited customer series.

[CU006, CU008, CU028, CU029, CU030, CU031]
FU002: Adoption / deployment funnel

Public proof narrows from broad lower-bound scale claims to a much smaller set of deeply documented customer transformations.

The first two stages use conservative public proxies rather than audited customer counts; the funnel measures proof depth, not internal conversion rates.

[CU028, CU029, CU030, CU031, CU033]

6.4 Retention and Expansion

Public evidence supports expansion more clearly than it supports classic SaaS retention metrics. Instacart is the cleanest cross-sell example because it was already using SAFE for CRQ before partnering on TPRM. Kyriba shows another expansion pattern: SAFE’s autonomous TPRM module replaced a pay-per-vendor model with flat-price coverage of the whole vendor ecosystem, while still driving automation and prioritization gains. SAFE’s July 2025 funding announcement adds the strongest company-wide proxy by saying more than 50% of customers adopted TPRM after launch. Customer stories also repeat a durable value proposition around board reporting, budget allocation, cyber-insurance negotiations, and business-case framing—use cases that usually become sticky once embedded into governance routines. Independent review surfaces are directionally supportive, with Gartner showing 99 reviews and a 4.5 average rating and FeaturedCustomers showing a 4.8/5 reference score. The major caveat is that none of the reviewed sources disclose NRR, GRR, logo churn, renewal rates, or contract duration, so public evidence proves expansion and satisfaction proxies better than it proves renewal quality.[CU011, CU015, CU018, CU030, CU031, CU034]

Retention / repeat usage / satisfaction table
MetricPublic valueSegmentConfidenceImplicationDiligence ask
TPRM customer adoption share50%+ of customersCompany-widemediumCross-sell into the newer TPRM module is real at scaleRequest attach rates by customer cohort and by initial product landed
TPRM ARR>$10M in less than one yearCompany-widemediumModule traction is commercially meaningful, not merely experimentalRequest software-vs-services split and renewal profile for early TPRM cohorts
Instacart expansion proofCRQ customer became TPRM design partnerMarketplace / techmediumInstalled-base expansion is visible, not just new-logo salesRequest ARR uplift and contract expansion tied to TPRM adoption
Kyriba ecosystem coverage100% vendor ecosystem under flat pricingEnterprise software / finance-adjacentmediumSAFE can expand usage intensity after initial landRequest usage depth, reassessment frequency, and renewal economics
Independent review average4.5 average rating across 99 Gartner reviewsCompany-widemediumDirectionally positive satisfaction signal across multiple product marketsRequest product-level review recency and distribution by module
Independent reference score4.8/5 based on 1,263 FeaturedCustomers reference ratingsCompany-widemediumBroad testimonial surface supports referenceability but not cohort durabilityRequest customer references not curated by SAFE
NRR / GRR / logo churnCompany-widelowThe biggest public durability gap remains unsolvedRequest NRR, GRR, logo churn, and cancellation-reason dashboards
Contract length / renewal termEnterprise / Fortune 500lowLong or multi-year contracts would materially change durability confidenceRequest standard contract terms, auto-renew mechanics, and termination rights

Null values mark metrics not publicly disclosed in the reviewed corpus; positive review surfaces and expansion proxies do not substitute for true retention cohorts.

[CU030, CU031, CU034, CU035, CU036, CU037]
FU004: Retention / repeat cohort proxy

Proxy disclosure map showing that SAFE has strong short-horizon deployment and expansion proof, but essentially no public long-horizon renewal or churn disclosure.

These are not literal customer-retention percentages. A value reflects the percentage strength of retained public disclosure at that lifecycle horizon; 0 means no retained public renewal or churn evidence was found.

[CU029, CU031, CU038, CU041]

6.5 Concentration and Expansion Risk

The central customer risk is not a lack of logos; it is a lack of disclosed durability and concentration metrics. SAFE’s public reference set is heavy on very large enterprises and mission-critical operators—exactly the kind of accounts that can produce attractive ACVs and powerful references, but also create long sales cycles, bespoke implementation work, and meaningful top-customer exposure if the base is not broad enough underneath. Geography also looks mixed: there is clear international reach through IHG, Glovo, and Aboitiz, yet the public story still leans North America-heavy overall. Proof depth is similarly uneven. T-Mobile, Instacart, Kyriba, Carvana, Aboitiz, and OB Hospitalist Group provide quantified narratives, whereas Google, Fidelity, and Chevron remain name-level proof in the reviewed corpus. Finally, Gartner’s description of the TPRM category as a multi-function, multi-stakeholder market underscores procurement friction: these are complex enterprise sales, not lightweight tool purchases. Until SAFE discloses customer-count bridges, top-customer exposure, geo mix, and retention cohorts, concentration risk remains one of the biggest open diligence asks.[CU039, CU040, CU041, CU042, CU043, CU044]

Expansion and concentration risk table
Risk typeLevelEvidenceWhy it mattersMitigation / diligence path
Large-enterprise customer concentrationHigh10% Fortune 500 claim plus Google, Fidelity, T-Mobile, Chevron, and IHG name-level proofA few very large customers could dominate ARR even if logo count looks healthyRequest top-10 customer revenue share, customers above key ARR thresholds, and renewal calendar
Proof-depth concentrationMedium-highDeep quantified stories are concentrated in T-Mobile, Instacart, Kyriba, Carvana, Aboitiz, and OBHGFlagship references can overstate average deployment depth if the long tail is shallowerRun broader reference calls and ask for anonymized win-loss / deployment-depth distribution
North America skew in public referencesMediumMost deep stories are U.S.-centric, with IHG, Glovo, and Aboitiz as the main non-U.S. counterweightsRegional concentration can amplify macro or execution risk in one geographyRequest ARR and customer counts by region plus international pipeline conversion
Retention opacityHighNo public NRR, GRR, logo churn, or contract-length disclosure was foundWithout cohort durability, it is hard to underwrite customer qualityObtain cohort tables, churn reasons, and contract schedules under NDA
Procurement friction in TPRM and partner-led channelsMediumGartner describes TPRM as multi-function and SAFE’s AWS page emphasizes private offers and co-sell supportComplex, multi-stakeholder deals can lengthen cycle times and increase implementation workRequest median sales-cycle length, pilot-to-production conversion, and channel-vs-direct mix
New-module mix riskMediumTPRM ramp is fast, but the module only launched in 2024 and is being sold partly through expansionEarly hyper-growth can mask immature renewal behavior in the newest product lineRequest first-cohort TPRM renewals, upsell timing, and services content

This table mixes upside and risk because SAFE’s public customer file is strongest on why customers buy and weakest on how diversified and durable the base is over time.

[CU031, CU038, CU039, CU040, CU041, CU042]

6.6 Exhibits

Chapter 07

07Risks

7.1 Regulatory and legal risks

Safe’s regulatory and legal exposure is not a headline enforcement case today; it is a stack of obligations that become material precisely because Safe sits inside customer governance workflows. Public-company customers now face SEC Item 1.05 and Item 106 disclosure obligations, so any Safe output used in board reporting, cyber materiality assessment, or incident escalation can become part of a regulated decision chain. Safe’s own policies add cross-border complexity. The privacy policy explicitly distinguishes between Safe as a controller for its own-site data and a processor for customer data, while also listing processing jurisdictions that span the United States, Europe, Bahrain, India, Australia, and Singapore. That makes GDPR transfer mechanics, India DPDP breach obligations, and customer-contract DPA terms central diligence questions rather than back-office hygiene. The customer terms also surface export and sanctions obligations and sharply limit contractual remedies, while the recent SecurityScorecard dispute proves competitive or legal friction can reach the company even if the specific matter was resolved. The risk is therefore less about one visible case and more about whether Safe can support enterprise-grade contracting, disclosure, and incident response under scrutiny.[CR001, CR002, CR003, CR004, CR005, CR006]

Regulatory / legal risk register
Risk / issueJurisdiction / surfaceSeverityLikelihoodCurrent statusMitigationResidual exposureDiligence path
SEC-disclosure dependence on Safe outputsU.S. public-company customers / SECHighMedium-HighItem 1.05 and Item 106 are active, making cyber materiality and governance workflows disclosure-sensitiveExplainable workflows, audit trails, and customer-side review before external useHigh — a wrong or delayed risk signal can still become part of a regulated disclosure chainRequest customer use cases, model-governance controls for disclosure workflows, and any indemnity carve-outs for board or SEC-facing use
GDPR and SCC compliance for cross-border processingEU and UK customer data transfersHighMediumSafe discloses multi-country processing and EU SCCs remain the standard transfer mechanismRegion selection, processor posture, SCC annexes, and contractual controlsMedium-High — no public DPA or subprocessor list is available to verify the paper trailObtain the standard DPA, SCC modules, subprocessors, and regional data-flow map
India DPDP security and breach-notification exposureIndia operations and India-linked personal-data processingHighMediumDPDP Rules 2025 introduce material penalties and breach-notification duties for data fiduciariesLocal compliance ownership, security controls, and rapid breach-notification playbooksMedium-High — India engineering concentration raises execution relevance if Indian data or staff systems are affectedRequest India entity governance, DPDP compliance controls, and any significant-data-fiduciary assessment
Export-control and sanctions obligationsEAR / ITAR / OFAC contractual surfaceModerate-HighLow-MediumCustomer terms explicitly recognize export and sanctions restrictionsRestricted-market blocking, access controls, and legal review for global deploymentsMedium — public language acknowledges the risk, but operating procedures are not publicReview export-control policy, restricted-party screening, and developer access controls for regulated features
Contractual remedy asymmetry and legal-opacity riskCustomer contracts, incident remedies, and competitive disputesModerate-HighMediumWarranty and remedy language are narrow and only one resolved public dispute is visibleInsurance, negotiated enterprise paper, and bespoke security exhibitsHigh — private contract carve-outs, claims inventory, and insurance limits are not visibleRequest standard MSA redlines, current litigation schedule, insurance tower, and any unresolved legal notices

Rows rank the most supportable legal and regulatory exposures from public disclosures; private DPA, insurance, and claims schedules remain unavailable.

[CR001, CR002, CR003, CR005, CR007, CR008]
FR001: Risk heatmap

Residual Safe Security risks plotted by impact and likelihood using public evidence only.

Likelihood and impact are analyst estimates derived from the public record; private incident history, customer concentration, and model-error data were not available for calibration.

[CR055, CR056, CR059, CR060]

7.2 Operational and security risks

The hardest operational risk to underwrite is the sensitivity of the data Safe touches. A breach of Safe would not look like an ordinary SaaS incident, because the platform is designed to aggregate vulnerability, exposure, cloud, identity, AI, and third-party risk signals into one decision surface. Safe publicly discloses region choice, TLS 1.2, AES-256 with AWS KMS, and SOC 3 coverage, which are meaningful mitigants, but they do not erase the consequence of compromise. Independent sector evidence matters here: Tenable and Qualys still suffered customer-data exposure in the Salesloft Drift OAuth campaign, and the larger Salesforce supply-chain incident reached more than 700 organizations while exposing embedded credentials. Safe’s own AI policy also introduces a subtler risk surface. The company says prompts may be retained for operational reasons, model routing is dynamic, and customers cannot select individual providers. Those are manageable practices only if the supporting DPA, subprocessor, logging, and validation layers are as strong as the policy language implies. Public proof of those deeper layers remains thin, so the residual view on platform security and data-handling failure remains high.[CR013, CR014, CR015, CR016, CR017, CR018]

Operational / quality / security risk register
Failure modeCategorySeverityEvidenceMitigationResidual exposure
Breach of Safe platform or underlying support systems exposes customer security telemetry, vulnerability inventories, or embedded credentialsPlatform securityCriticalSafe aggregates high-sensitivity cyber data; cybersecurity vendors like Tenable and Qualys still leaked customer data via third-party OAuth compromiseAWS region choice, encryption, SOC 3, tenant isolation, and customer-owned keysHigh
Integration or connector failure produces stale, partial, or misleading risk signals across CRQ, CTEM, or TPRM workflowsSignal integrityHighSafe depends on AWS signals, external integrations, and cross-platform data normalization for its core product claimsWorkflow automation, monitoring, and human review layersHigh
SAFE AI workflow error or opaque score logic drives bad prioritization or board-level decisionsAI / model qualityHighSafe markets explainability but does not publish external calibration, false-positive, or back-testing evidenceSAFE AURA governance claims, human oversight, and customer reviewHigh
Balbix and RiskLens integrations consume engineering attention and slow unified-platform deliveryPost-acquisition integrationHighSafe is trying to fuse CTEM, CRQ, and TPRM while marketing CyberAGI and autonomous workflowsNamed integration leadership and one-platform narrativeHigh
AWS-region outage or control-plane issue disrupts customer visibility or onboardingInfrastructure dependencyModerate-HighSafe publicly anchors hosting, keys, and marketplace motion in AWSRegional selection, customer-owned keys, and cloud-native controlsMedium-High

Operational rows emphasize consequence rather than probability alone: the platform handles unusually sensitive security data, and public validation of model quality remains incomplete.

[CR013, CR014, CR015, CR017, CR018, CR019]

7.3 Technical and dependency risks

Safe’s technical upside and its technical risk now come from the same place: the attempt to collapse CRQ, CTEM, TPRM, AI-vendor governance, and autonomous remediation into one platform. The Balbix acquisition extends Safe from quantification into exposure validation, while RiskLens anchors the FAIR-based financialization layer. The promise is strategically strong, but the public record also makes the integration challenge explicit. Enterprise Security Tech says the company is trying to bridge historically siloed operational exposure data and business-level risk intelligence and is not yet at true cyber autonomy. Independent CTEM coverage reinforces the execution difficulty: CTEM is not plug-and-play, can be difficult to implement across mismatched tools, and can encourage business-driven deferral of urgent patches. Safe also depends on AWS telemetry, AWS Marketplace procurement, external LLM providers, and a large web of integrations and connectors to keep its outputs current. In other words, the company does not just have software complexity; it has dependency-chain complexity, and each new acquisition or AI workflow multiplies the number of places where stale data, broken integrations, or mismatched abstractions can distort risk decisions.[CR019, CR020, CR021, CR022, CR024, CR025]

Partner / dependency risk register
DependencyTypeImpact if impairedAlternativesMitigantResidual exposure
AWS hosting, KMS, and regional control planeCloud infrastructure and procurement channelService availability, key management, and deployment speed all degrade togetherMulti-cloud rebuild is theoretically possible but not publicly evidencedCustomer region choice, customer-owned KMS keys, AWS-native controlsHigh
AWS Marketplace and private-offer motionChannel and procurement dependencyEnterprise purchasing friction rises and cloud-budget leverage weakens if the channel underperformsDirect enterprise sales remain possible but slowerMarketplace listing, consolidated billing, and private offersMedium-High
Third-party LLM providers and dynamic routingModel-provider dependencyProvider outage, policy shift, or region gap can affect SAFE AI behavior and data pathingDifferent models can be swapped, but customers cannot choose providers directlyNo-training commitments and admin-gated searchHigh
RiskLens and FAIR methodology ecosystemMethodology and talent dependencyIf FAIR translation or key domain talent slips, Safe’s CRQ differentiation weakensIn-house scoring can continue, but credibility may fallRiskLens acquisition and retained FAIR-linked leadershipMedium-High
Balbix CTEM data model and integration fabricAcquired technology dependencyUnification delays or migrations can distort exposure data and customer trustOrganic build would take time and still leave migration riskNamed CTEM leadership and shared one-platform roadmapHigh

Dependency risk is not only technical; it also includes procurement, methodology, and external-model concentration that can reshape Safe’s product behavior or go-to-market leverage.

[CR019, CR021, CR022, CR024, CR025, CR026]
FR002: Risk transmission map

How Safe’s technical and governance risks can propagate into customers, growth, and valuation.

Edges are qualitative transmission paths rather than quantified probabilities because Safe does not publish customer concentration, churn, or model-error rates.

[CR028, CR029, CR032, CR034, CR055, CR058]
FR003: Dependency map

Critical infrastructure, model, and acquisition dependencies underlying the Safe platform.

The map reflects named dependencies in public materials; private reseller, customer concentration, and subcontractor relationships are not visible.

[CR019, CR021, CR022, CR030, CR031, CR048]

7.4 People and execution risks

People risk is unusually important for Safe because the company is simultaneously founder-led, acquisition-led, and AI-story-led. Saket Modi remains the public face of the company’s category claims, fundraising, and CyberAGI narrative, while Gaurav Banga now owns CTEM integration and RiskLens leadership remains tied to the FAIR layer. That concentration might be manageable if the labor market were loose and employee sentiment strong, but neither is true. TechStrong’s 2026 survey says AI engineers and cybersecurity engineers are the two hardest roles to fill, and Safe needs exactly that hybrid talent. Economic Times reports roughly half of the company’s headcount and most R&D sit in India, which adds coordination and retention complexity across U.S. enterprise selling, India engineering execution, and post-acquisition cultural integration. The most concrete adverse evidence comes from AmbitionBox, where Safe’s overall employee rating is 2.5 out of 5 and work-life balance and job security score worst. Those reviews are not dispositive, but they are directionally important because long hours, weak job security, and management friction are the exact conditions that can slow integration and weaken AI product quality.[CR041, CR042, CR043, CR044, CR045, CR046]

People / execution risk register
RiskKey person / teamSeverityEvidenceMitigationDiligence path
Founder and external-face concentrationSaket ModiHighFundraising, category framing, and CyberAGI narrative remain tightly associated with the co-founder and CEOExpanded executive bench and product leaders from acquisitionsReview succession planning, delegated operating cadence, and customer-facing leadership depth
Post-acquisition retention and execution driftGaurav Banga, RiskLens / Balbix leaders, FAIR-linked expertsHighBalbix and RiskLens both brought named leaders who anchor technical credibility and customer transitionFormal role continuity after acquisitionRequest retention packages, post-close org charts, and product-ownership boundaries
India-U.S. cross-border management complexityIndia R&D team and U.S. enterprise leadershipMedium-HighEconomic Times reports roughly 100 of 200 employees sit in India R&D while customers and HQ are U.S.-centeredDistributed-team operating rhythms and founder familiarity with India deliveryObtain geo headcount by function, management spans, and release-ownership map
Talent retention and culture strainAI and cybersecurity engineering talent baseHighThe labor market is tight and AmbitionBox shows weak scores on work-life balance and job securityMission appeal, growth narrative, and access to frontier AI workReview attrition, regretted-loss metrics, and time-to-fill for senior engineering and research roles
Growth-claim execution pressureProduct, go-to-market, and support teamsMedium-HighSafe pairs triple-digit growth claims with a much broader unified-platform promise after two acquisitionsNew capital, named customers, and category focusRequest quarterly product and customer-success dashboards for legacy vs. acquired cohorts

Execution risk is driven by concentration of narrative leadership and scarce hybrid talent, not by lack of ambition or market relevance.

[CR024, CR025, CR041, CR042, CR043, CR044]

7.5 Kill criteria and monitoring

Safe is not unmitigated. The company has real security disclosures, public assurance coverage, strong access to capital, and a credible strategic explanation for why Balbix and RiskLens matter. But a prudent investor should treat the current file as a proof-of-possibility case rather than a proof-of-control case. The immediate thesis-break triggers are observable. A meaningful security incident at Safe itself, evidence that major customers cannot rely on Safe outputs for disclosure-sensitive or board-sensitive use cases, visible churn or migration pain in Balbix and RiskLens cohorts, or senior departures across the founder and acquisition leadership bench would all materially change the underwriting case. The larger issue is what the public record still does not show: a public DPA or subprocessor list, benchmarked model-accuracy evidence, acquisition economics, and hard integration milestones. Those gaps are not cosmetic. They are the difference between believing the company has built a defensible control plane for cyber-risk decisions and merely believing it has marketed one. Until those gaps close, monitoring needs to be explicit and unforgiving.[CR053, CR054, CR055, CR056, CR057, CR058]

Mitigation and kill criteria table
RiskCurrent mitigationKill criterionMonitoring signal
Platform-data breach or material customer-data exposureEncryption, tenant isolation, SOC 3, and AWS-native controls are publicAny confirmed incident exposing vulnerability, exposure, or embedded-credential data at scaleIncident disclosures, customer notices, support-case spikes, or emergency region/key rotations
Model or score reliability failure in disclosure-sensitive workflowsSAFE AURA, human oversight, and no-training claimsEvidence that major customers cannot trust Safe outputs for board, disclosure, or prioritization use casesBenchmark requests, override rates, customer escalations, or withdrawn deployment claims
Balbix or RiskLens integration dragNamed leaders, one-platform narrative, and acquisition rationaleMissed migration milestones, customer confusion, or churn in acquired cohorts for more than two quartersRoadmap slips, SKU proliferation, support backlog, or downgrade language in customer references
Regulatory and contracting fragilityRegion choice, processor framing, SCC compatibility, and export clausesInability to provide DPA, subprocessor transparency, or breach-notification commitments acceptable to regulated buyersSecurity questionnaire slippage, legal redlines, or regional deal delays tied to privacy terms
Talent and leadership deteriorationFresh capital and mission-driven recruiting narrativeDeparture of Saket Modi, Gaurav Banga, or a cluster of AI / risk-engine leaders without clear successionExecutive turnover, extended senior-hiring gaps, or rising attrition and negative employee-review trend
Capital opacity or acquisition overhangRecent Series C and claimed triple-digit growthDown-round, distressed debt, or acquisition-write-down signals before Balbix integration value is evidentFundraising rumor cycle, unusual covenant requests, or delayed integration hires and product commitments

Kill criteria are intentionally concrete and monitorable because the main remaining gaps are in private evidence, not in awareness of the risk categories.

[CR041, CR044, CR045, CR046, CR047, CR055]
Chapter 08

08Valuation

8.1 Valuation thesis and framework

SAFE's valuation case starts with a real operating story, not a slide-deck fantasy. The company publicly disclosed a $70 million Series C, total funding above $170 million, triple-digit growth claims, and expanding module adoption after moving from CRQ into TPRM and CTEM. Forrester's Q2 2025 CRQ leadership call and SAFE's Liminal positioning help justify a premium versus slower, narrower cyber vendors. The problem is not whether SAFE has ambition or product breadth; the problem is that public evidence does not disclose audited ARR, gross margin, NRR, or the current cap-table and preference stack. That forces valuation to be inference-driven. In this chapter, a hypothetical $1 billion entry price is treated as an underwriting scenario rather than a confirmed public mark. On that basis, the key question becomes whether SAFE is already operating near $80 million to $100 million of ARR and whether the market should reward it with a 10x to 14x forward multiple. Without those answers, the correct lens is price discipline rather than simple admiration for category leadership.[CV001, CV002, CV003, CV004, CV005, CV006]

Recommendation summary table
DimensionFindingConfidenceEvidence
Overall recommendationTrackMediumReal category leadership is visible, but price support still depends on private metrics that are not publicly disclosed.
Risk ratingHighMediumValuation support is less mature than the product narrative because audited ARR, NRR, margin, and terms are missing.
Valuation stanceFair only with proof; otherwise stretchedMediumA hypothetical $1B entry fits a premium cyber band only if SAFE is already near the top of an $80M-$100M ARR underwrite.
Upside caseMeaningfulMediumBull upside to roughly $3B-$4.2B exists if SAFE becomes the dominant cross-module cyber-risk platform.
What changes the callAudited scale and clean termsMediumUpgrade requires a hard ARR bridge, retention and gross-margin proof, and cap-table transparency.

Recommendation is explicitly price-sensitive and evidence-sensitive. The table summarizes what public evidence supports today, not what management may be pitching privately.

[CV022, CV023, CV033, CV037, CV041, CV043]
Thesis / anti-thesis table
ThesisAnti-thesisWeightEvidence
SAFE has real CRQ category leadership and expanding platform scope.Leadership claims are mostly company-mediated and still need monetization proof outside marquee references.HighForrester leadership, Liminal recognition, and multi-module product breadth.
Triple-digit growth and 50%+ TPRM adoption can justify a premium multiple.Growth, retention, and gross-margin quality are not audited in the public record.HighSeries C disclosures and module-adoption claims, offset by disclosure gaps.
CRQ, TPRM, and CTEM together can create a strategic system-of-record position.Large security platforms can bundle adjacent capabilities and compress category pricing.MediumPlatform roadmap versus lower-multiple public cyber comps.
Public comps leave room for a premium above slower-growth names.Public cyber median multiples remain far below 2021-style exuberance and punish decelerating vendors quickly.HighTenable, Qualys, Rapid7, Windsor, Finro, Clipperton, and First Analysis.
A $1B entry could still work if SAFE is already near $100M ARR.Third-party private-market data points to a much lower mark and possibly additional undisclosed financing.HighPremier Alternatives versus implied-multiple math.

Weights reflect how strongly each argument should influence a new-money decision today. The anti-thesis is mostly about valuation opacity and market discipline, not about absence of product ambition.

[CV003, CV004, CV005, CV006, CV007, CV008]
FV001: Recommendation logic

Decision flow from category strength and product breadth through disclosure and price discipline to the current recommendation.

The chart reduces a complex underwriting process to the two gating questions that dominate this chapter: evidence quality and price discipline.

[CV035, CV037, CV041, CV043, CV044]

8.2 Comparable company analysis

The public comp set shows how sharply cybersecurity multiples separate by growth quality and maturity. Tenable is already near $1.1 billion of guided 2026 revenue, yet trades at only about 4.3x enterprise value to revenue; Rapid7 trades even lower near 1.2x EV to ARR because growth has stalled. Qualys is the more profitable and better-valued benchmark at about 6.8x EV to revenue, supported by 83% gross margin and disciplined execution. Sector studies from Windsor Drake, Finro, Clipperton, and First Analysis all point to the same conclusion: median public cyber pricing is far below the 2021 peak, while only genuine leaders with clean Rule-of-40 profiles keep double-digit multiples. Private and strategic comps are wider. Axonius' estimated 2024 revenue and $2.6 billion valuation imply a high-teens multiple, SecurityScorecard sits closer to the high-single digits, and BitSight's $2.4 billion Moody's-backed round shows how a strategic buyer can pay up for cyber-risk analytics. SAFE therefore deserves to be analyzed in a premium band above Tenable and Rapid7, but not in the same stratosphere as Wiz unless audited scale and scarcity become much clearer.[CV011, CV012, CV013, CV014, CV015, CV016]

Bull / base / bear scenario table
ScenarioARR assumptionMultipleImplied valuationKey drivers
Bear$60M-$70M ARR7x-10x$500M-$700MGrowth decelerates, platform vendors compress pricing, and the market treats SAFE like a lower-visibility late-stage cyber SaaS asset.
Base$175M-$200M ARR8x-10x$1.5B-$2.0BSAFE converts CRQ leadership into broader TPRM and CTEM adoption and matures into a durable cyber-risk platform.
Bull$300M-$350M ARR10x-12x$3.0B-$4.2BCyberAGI positioning converts into strategic scarcity, multi-module attach, and sustained premium growth.

All three scenarios are analytical estimates rather than disclosed company guidance. They are intended to show what must be true operationally for different valuation bands to clear.

[CV033, CV034, CV035, CV038, CV039, CV040]
Comparable valuation table
CompanyStatusValuationARR/revenue estimateMultipleNotes
TenablePublic$4.61B EV$1.068B-$1.078B FY2026 revenue guide~4.3x EV/revenueLarge exposure-management platform with slower growth than SAFE.
QualysPublic$4.89B EV$721M-$727M FY2026 revenue guide~6.8x EV/revenueMore profitable benchmark with 83% GAAP gross margin and disciplined execution.
Rapid7Public$996.7M EV$832M ARR / $836M-$842M FY2026 revenue guide~1.2x EV/ARR / ~1.2x EV/revenueLow-end floor comp showing how harsh the market gets when growth stalls.
AxoniusPrivate$2.6B valuation$151.5M 2024 revenue estimate~17.2x valuation/revenuePremium private cyber-platform multiple at materially larger verified scale than SAFE discloses.
SecurityScorecardPrivate$980M valuation$144.3M 2024 revenue estimate~6.8x valuation/revenueRisk-analytics peer showing that private cyber leadership does not automatically command a premium-teens multiple.
BitSightPrivate / strategic$2.4B valuationARR not publicly disclosedn/dStrategic Moody's investment shows cyber-risk analytics can clear multibillion marks when a data buyer sees scarcity.
WizM&A exit$32B acquisition$500M-$700M ARR at signing per Acquiry~45x-65x ARROutlier cloud-security ceiling; useful as a ceiling, not a base case for SAFE.

Selected comparables mix public trading anchors, late-stage private references, and strategic exits. The set is intentionally partial rather than exhaustive because the goal is range-setting, not false precision.

[CV011, CV012, CV013, CV014, CV015, CV016]
FV002: Valuation sensitivity

Sensitivity of enterprise value to ARR and multiple assumptions around the current underwriting range.

Values are USD millions. The bars are analytical sensitivity points, not management guidance, and assume no adjustment for net cash, debt, or preference structure because those inputs are not public.

[CV017, CV018, CV019, CV020, CV033, CV034]
FV004: Investment KPIs

IC-style scorecard (0-10) across the dimensions that matter most for a new-money valuation decision.

Scores are analyst judgments based on the current public evidence set. Lower scores on transparency and valuation support reflect missing audited ARR, NRR, margin, and cap-table terms.

[CV005, CV007, CV008, CV021, CV041, CV043]

8.3 Scenario analysis

Scenario analysis is the only honest way to value SAFE with today's disclosure set. The bear case assumes the platform story outruns the underlying economics: growth slows, larger cyber suites commoditize risk-management packaging, and the market prices SAFE more like a lower-visibility late-stage SaaS asset than a scarce leader. Under that outcome, $60 million to $70 million of ARR at 7x to 10x yields only $500 million to $700 million of value. The base case assumes SAFE keeps converting CRQ leadership into broader TPRM and CTEM wallet share, matures into roughly $175 million to $200 million of ARR, and clears an 8x to 10x multiple, supporting about $1.5 billion to $2.0 billion. The bull case requires much more: CyberAGI positioning must translate into real platform leadership, ARR must scale toward $300 million to $350 million, and investors must still be willing to pay 10x to 12x for a strategic category winner. That yields roughly $3.0 billion to $4.2 billion. Those upside numbers are achievable, but only if execution closes the evidence gap rather than merely widening the narrative.[CV017, CV018, CV019, CV020, CV021, CV033]

Thesis-break and kill triggers table
TriggerThresholdMonitoring signalAction
Down round or structured financingAny primary round below a $1B reference point or with punitive downside protectionNew financing announcement, cap-table update, or rights summaryMove from Track toward Avoid until common-equity economics are re-underwritten.
Growth credibility fadesCurrent ARR bridge implies materially below ~$80M ARR or forward growth below category-premium levelsAudited ARR bridge, board pack, or investor presentationRe-rate toward public-comp bands rather than premium private bands.
Module adoption stallsNo evidence that CTEM and TPRM are adding durable paid wallet shareModule attach, expansion cohorts, and renewal dataCollapse the platform premium in scenario modeling.
Public comp resetPremium cyber multiples compress toward low-single digits againPublic comp tape for Qualys, Tenable, Rapid7, and broader cyber basketTighten entry price and lower base-case valuation.
Strategic narrative weakensSAFE stops looking like a system of record and looks more like a feature setWin-loss data versus large platforms and packaging/pricing changesTreat bull case as broken and focus on base-to-bear only.

These are monitorable triggers rather than abstract worries. The table is designed to force fast action if the bull thesis loses its economic foundation.

[CV020, CV021, CV032, CV037, CV041, CV042]
FV003: Valuation / return range

Bear, base, and bull valuation bands for SAFE under explicitly different ARR and multiple assumptions.

Values are USD millions. The figure presents valuation bands rather than investor IRR because public sources do not disclose SAFE's current share count or preferred-stack mechanics.

[CV038, CV039, CV040, CV043]

8.4 Investment recommendation

The final recommendation is Track, not Buy and not Avoid. SAFE has enough product proof, category leadership, and strategic ambition to stay on the diligence list, and a hypothetical $1 billion price is not obviously absurd if the business is already near the upper end of an $80 million to $100 million ARR band. However, the public record is still too opaque for a clean affirmative buy: third-party private-market data points to a much lower mark, public sources do not show audited ARR or current margin structure, and no disclosed preferred terms let investors translate narrative upside into common-equity outcomes. The chapter therefore sets a high evidence threshold for upgrade. Management must show a credible ARR bridge, strong retention, healthy gross margin, and proof that multi-module adoption is monetizing across CRQ, TPRM, and CTEM. The bull case fails if SAFE prints a flat or down round, if module attach stalls, or if larger platforms make cyber-risk management look like a feature rather than a scarce system of record. Until those issues are resolved, the right posture is disciplined monitoring rather than forcing conviction.[CV022, CV023, CV031, CV032, CV033, CV037]

Final diligence asks table
AskPriorityWhy it mattersTarget source
Current ARR bridge from FY2024 through the latest quarterCriticalDetermines whether a hypothetical $1B entry is 10x ARR, 14x ARR, or worse.Audited management financial package or board-approved KPI deck
Net revenue retention, gross margin, and burn / FCF profileCriticalSeparates premium-quality SaaS growth from narrative-only growth.Audited financials and operating metrics schedule
Current cap table, liquidation preferences, anti-dilution, and any post-Series-C debt termsCriticalDetermines whether valuation upside translates into common-equity returns.Cap table export, term sheets, and counsel summary
Module-level adoption and expansion for CRQ, TPRM, and CTEMHighTests whether platform breadth is monetizing or merely expanding product marketing.Cohort analysis and product attach dashboard
Win-loss and pricing data versus large security suitesHighShows whether SAFE has strategic scarcity or is vulnerable to bundling pressure.Sales analytics, battlecards, and closed-lost review
Evidence behind the current market mark, including any 2025 or 2026 secondary or debt financingHighResolves the gap between company narrative and adverse third-party valuation signals.Investor update, financing memo, or independent 409A / valuation work

These asks are decision-critical because they close the specific holes that block a buy recommendation, rather than collecting generic diligence trivia.

[CV022, CV023, CV037, CV041, CV042, CV043]

8.5 Exhibits

Disclaimer

This report is a public-evidence diligence snapshot, not investment advice. Important financial, legal, technical, and contractual facts remain non-public and should be verified directly with management and primary documents before any investment decision.

Evidence index

Claims
IDStatementConfidenceSources
CO001 Safe Security was founded in 2012 at IIT Bombay by Saket Modi, Rahul Tyagi, and Vidit Baxi. High SO010, SO026, SO027
CO002 Safe Security is headquartered in Palo Alto, California. High SO003, SO025, SO028
CO003 Public company materials list additional operating locations in Santa Clara, San Jose, New York, New Delhi, Bengaluru, London, and Dubai, with remote hiring footprints in the United States and Australia. High SO003, SO004, SO028
CO004 SAFE sells a unified cyber-risk platform that spans CRQ, TPRM, CTEM, and AI-SPM. High SO002, SO007, SO008, SO021
CO005 The platform is aimed primarily at enterprise CISOs, TPRM leaders, and GRC teams that need continuous cyber-risk prioritization and reporting. High SO005, SO006, SO021, SO028
CO006 SAFE public history materials say Lucideus rebranded as SAFE in 2021. Medium SO002
CO007 Saket Modi is Safe Security's co-founder and CEO. High SO025, SO026
CO008 Vidit Baxi is publicly identified as co-founder and CISO. Medium SO025, SO027
CO009 Rahul Tyagi is publicly identified as a co-founder of Safe Security. Medium SO025, SO027
CO010 Saket Bajoria is publicly identified as Chief Product Officer. Medium SO022, SO025
CO011 John Chambers is presented by SAFE as its lead Series A investor and remains a visible strategic backer in later company materials. High SO002, SO021, SO026
CO012 Retained public materials identify investors, advisors, and executives but do not publish a formal board roster or committee structure for SAFE. Medium SO002, SO025, SO027, SO028
CO013 After SAFE acquired RiskLens in June 2023, former RiskLens CEO Nick Sanna joined SAFE as President and Jack Jones joined as Chief Research Scientist while continuing his FAIR Institute role. Medium SO015
CO014 After SAFE acquired Balbix in November 2025, Balbix founder and CEO Gaurav Banga joined SAFE as President of CTEM. High SO013, SO014
CO015 Lucideus disclosed angel funding in September 2016 after describing itself as bootstrapped for its first four years. Medium SO018
CO016 Lucideus disclosed a broader angel syndicate round in May 2017 and said the capital would help develop a cyber-risk management platform. Medium SO017
CO017 SAFE's retained timeline says the company secured a $33 million Series A led by British Telecom and John Chambers in 2021. Medium SO002
CO018 SAFE announced a $50 million Series B in April 2023 led by Sorenson Capital with participation from Eight Roads, Telstra Ventures, WTI, and existing investors, bringing total funding above $100 million. High SO016, SO002
CO019 SAFE announced a $70 million Series C on July 31, 2025 led by Avataar Ventures with participation from Susquehanna Asia Venture Capital, NextEquity Partners, Prosperity7 Ventures, and existing investors including Eight Roads, John Chambers, and Sorenson Capital. High SO008, SO009, SO010, SO011, SO012
CO020 SAFE said the Series C proceeds would accelerate CyberAGI development and its autonomous CTEM roadmap. High SO008, SO009
CO021 Retained Series C sources state that SAFE's cumulative funding exceeded $170 million after the July 2025 round. High SO008, SO009, SO010, SO011, SO021
CO022 SAFE publicly claims triple-digit revenue growth for three consecutive years, and some investor or press materials frame that pace as at least 120% year-over-year since the platform launch. Medium SO008, SO010, SO019, SO027, SO028
CO023 SAFE says more than half of its customers adopted the TPRM module after the 2024 launch. Medium SO008, SO009
CO024 SAFE said in May 2026 that 10% of Fortune 500 companies trust the platform, naming Apple, AT&T, and Delta Airlines in the AI-SPM launch release. Medium SO021
CO025 SAFE's official LinkedIn profile listed company size as 51-200 employees as of the July 2026 access date. Low SO028
CO026 SAFE's location pages and third-party profiles show a distributed footprint with multiple US offices plus India, UK, and UAE presence. High SO003, SO004, SO025, SO028
CO027 The RiskLens acquisition added the FAIR methodology and brought a recognized cyber-risk quantification franchise into SAFE. Medium SO015
CO028 The Balbix acquisition combined exposure-management capabilities with SAFE's cyber-risk quantification platform to create a broader unified cyber-risk system. High SO013, SO014
CO029 SAFE launched AI Security Posture Management in May 2026 to monitor AI activity, configuration, outside-in exposure, contracts, and questionnaires in one workflow. High SO007, SO021
CO030 SAFE announced a Cisco AI Defense integration in July 2025 to connect AI telemetry, controls assessment, and quantified risk outputs. Medium SO022
CO031 SAFE said in June 2025 that Forrester named it a Leader in cyber risk quantification and gave it the highest possible scores in 21 criteria. Medium SO019
CO032 SAFE said in April 2025 that Liminal ranked it highest on TPRM product capability and named it a leader in the category. Medium SO020
CO033 SAFE's mission language centers on building cybersecurity superintelligence through agentic AI. High SO001, SO002
CO034 Retained public sources provide growth-rate claims but do not disclose SAFE's exact revenue run-rate or ARR. High SO008, SO010, SO019, SO028
CO035 Retained official and independent financing sources disclose round sizes and cumulative capital raised but do not disclose a priced post-money valuation for SAFE. High SO008, SO009, SO010, SO011
CO036 The investor set that is publicly visible across rounds consists of John Chambers, British Telecom, Sorenson Capital, Eight Roads, Telstra Ventures, WTI, Avataar Ventures, Susquehanna Asia Venture Capital, NextEquity Partners, and Prosperity7 Ventures. High SO002, SO008, SO016
CO037 Cybernoz reported that SecurityScorecard sued SAFE in 2025 alleging unfair competition, trade-secret misuse, and misuse of competitor data. Medium SO024
CO038 SAFE announced in October 2025 that it and SecurityScorecard had resolved their legal dispute and would collaborate on research. Medium SO023
CO039 SAFE is a privately held late-stage cybersecurity company whose latest disclosed financing milestone is the July 2025 Series C. High SO008, SO019, SO028
CM001 SAFE publicly positions its platform as a unified offering spanning Cyber Risk Quantification, Continuous Threat Exposure Management, Third-Party Risk Management, and AI Security Posture Management. High SM028, SM029, SM013
CM002 SAFE's 2025-2026 messaging expands from standalone CRQ into a broader autonomous cyber risk management platform through the Balbix acquisition and AI-SPM launch. Medium SM025, SM027, SM028
CM003 SAFE's 2023 RiskLens acquisition was explicitly framed as creating leadership in a $4 billion CRQ market and deepening ties to the FAIR ecosystem. Medium SM001, SM002, SM004
CM004 Public Forrester-related materials in 2025 describe SAFE as a leader in cyber risk quantification. Medium SM005, SM006
CM005 CTEM is a five-stage program that continuously scopes, discovers, prioritizes, validates, and mobilizes against exposures rather than a one-time tool purchase. Medium SM009, SM010
CM006 CTEM extends beyond traditional CVE-driven vulnerability management into misconfigurations, identity risks, excessive permissions, attack paths, and remediation orchestration. Medium SM009, SM029
CM007 Gartner's 2026 cybersecurity trend set centers on AI expansion, regulatory volatility, geopolitical tension, and the need for more adaptive risk and governance models. High SM007, SM008
CM008 Gartner says AI agents create new attack surfaces and require stronger governance, risk-based IAM, and board expectation resets. High SM007, SM008
CM009 Mordor Intelligence estimates the cyber risk quantification and scoring platforms market at USD 5.43 billion in 2026 after USD 4.84 billion in 2025. Medium SM003
CM010 Large enterprises accounted for 60.38% of the CRQ scoring-platform market in 2025, indicating that the category is enterprise-led rather than SMB-led. Medium SM003
CM011 Mordor Intelligence says cyber-insurance underwriting support is the fastest-growing CRQ application, at a 19.28% CAGR over the 2026-2031 forecast window. Medium SM003
CM012 Grand View Research's CTEM market lens, via GII, sizes the category at USD 2.70 billion in 2025 and USD 7.00 billion by 2033, implying a 12.7% CAGR. Medium SM032
CM013 Public CTEM market narratives tie category growth to continuous asset discovery, prioritization, validation, and remediation across complex hybrid environments. Medium SM032, SM009
CM014 360iResearch sizes cyber asset attack surface management software at USD 3.70 billion in 2026 after USD 3.24 billion in 2025. Medium SM033
CM015 QY Research values the global third-party risk management software market at USD 8.5 billion in 2025 and projects USD 22.205 billion by 2032 at a 15.0% CAGR. Medium SM031
CM016 TPRM is a lifecycle discipline that spans planning, onboarding, due diligence, contracting, ongoing monitoring, and termination rather than a point-in-time questionnaire exercise. High SM036, SM037
CM017 SecurityScorecard reports that 35.5% of breaches in 2024 were third-party related and that 41.4% of ransomware attacks now start through third parties. Medium SM012
CM018 IBM and Moody's both describe TPRM as a cross-functional program spanning procurement, risk, compliance, legal, and technology teams. High SM036, SM037
CM019 The broader adjacency pools are much larger than SAFE's core wedge: Mordor sizes global cybersecurity at USD 264.43 billion in 2026 and GRC software at USD 23.32 billion in 2026. Medium SM034, SM021
CM020 Public CRQ, CTEM, CAASM, TPRM, GRC, and cybersecurity estimates overlap materially, so they bracket opportunity but do not support one clean additive TAM. Medium SM003, SM032, SM031, SM033, SM021
CM021 Buyer ownership is split: CISO, CRO, and enterprise-risk teams anchor CRQ and CTEM decisions, while procurement, privacy, legal, and compliance teams join TPRM decisions. Medium SM036, SM037, SM007
CM022 IBM explicitly lists the CISO, Chief Procurement Officer, CIO, and Chief Privacy Officer among common TPRM owners. Medium SM036
CM023 IBM says vendor security assessments increasingly start during vendor selection and procurement rather than only at contract execution. Medium SM036
CM024 Public TPRM definitions consistently include vendor inventory, questionnaires, scoring, workflow, contract controls, and continuous monitoring as core product capabilities. Medium SM031, SM036, SM037
CM025 SAFE claims its TPRM platform automates assessment, onboarding, and monitoring workflows and crossed USD 10 million of TPRM ARR in less than one year. High SM014, SM013
CM026 SAFE CTEM claims more than 200 integrations and prioritization based on exploitability and business impact rather than CVSS alone. Medium SM029
CM027 SAFE's Balbix acquisition adds exposure-management capability and explicitly links it to SAFE's business-impact quantification layer. High SM025, SM026, SM027
CM028 SAFE AI-SPM says enterprises need continuous visibility into live AI activity, configuration risk, outside-in exposure, compliance evidence, and contracts. Medium SM028
CM029 Munich Re says nearly nine out of ten C-level respondents do not feel their company is adequately protected against cyber attacks, underscoring a continuing insurance protection gap. Medium SM018
CM030 Insurance Business, citing Swiss Re and Munich Re, says global cyber premiums should reach roughly USD 16.4 billion in 2026 and could more than double from 2025 to 2030. Medium SM020, SM018
CM031 Fitch says U.S. cyber insurance direct written premiums grew nearly 11% in 2025 even as pricing softened and underwriting complexity rose. Medium SM019
CM032 SEC cyber disclosure rules require material incident disclosure on Form 8-K within four business days after materiality is determined and annual disclosure of cyber risk management, strategy, and governance. High SM015, SM016, SM017
CM033 Those SEC rules put board oversight and management roles in cyber risk into recurring disclosure, which increases the value of defensible reporting and quantification. High SM015, SM016
CM034 Picus says global cybersecurity spending is expected to reach about USD 240 billion in 2026. Medium SM022
CM035 Picus argues that 2026 budgets are shifting toward optimization, measurable efficacy, complexity reduction, and platform consolidation instead of unchecked tool accumulation. Medium SM022
CM036 A PwC summary reported by The Global Treasurer says only 15% of organizations measure cyber risk financial impact to a significant extent and only 21% usually allocate cyber budget to top risks. Medium SM023
CM037 The same PwC summary says 77% of executives expected their cyber budget to increase the next year, showing that budget growth and quantification immaturity coexist. Medium SM023
CM038 ExtraHop argues that CRQ expressed in precise dollar terms can backfire when boards do not trust the output or when the organization does not discuss other risks in the same way. Medium SM024
CM039 ExtraHop says CISOs need tighter CFO and general-counsel relationships as cyber risk becomes more visible in SEC-related disclosure work. Medium SM024
CM040 Gartner says rapid incident-reporting requirements and data-sovereignty pressures force cybersecurity leaders to collaborate more closely with legal, business, and procurement teams. High SM007, SM008
CM041 Vectra describes CTEM demand as a response to too many vulnerabilities, too few analyst hours, and the need to prove that programs are getting safer over time. Medium SM009
CM042 Vectra says 75% of exposures are dead ends and only 2% reach critical systems, making prioritization and validation central to CTEM ROI. Medium SM009
CM043 Vectra says 61% of vulnerabilities exploited in 2025 were weaponized within 48 hours, which supports continuous rather than periodic exposure programs. Medium SM009
CM044 Moody's says TPRM is moving from static checklist-based approaches to integrated, intelligence-led, continuous monitoring models. Medium SM037
CM045 SAFE's CTEM and AI-SPM messaging both stress rapid deployment and lower manual overhead, which implies that implementation complexity is already a recognized category objection. Medium SM029, SM028
CM046 Mordor says cybersecurity buyers are abandoning isolated tools for converged suites, and the category is consolidating around integrated platforms. Medium SM034
CM047 Mordor says privacy laws and fragmented data pools lower CRQ model granularity and add complexity and cost, tempering market growth. Medium SM003
CM048 Large enterprises dominate the most relevant categories, controlling 60.38% of CRQ in 2025 and 67.55% of cybersecurity market revenue in 2025. Medium SM003, SM034
CM049 Public CTEM materials describe a vendor ecosystem spanning exposure assessment platforms, CAASM, EASM, and BAS rather than one turnkey monolithic product category. Medium SM009, SM030
CM050 Applying QY Research's 15.0% CAGR to its 2025 TPRM software base implies an estimated 2026 market lens of about USD 9.78 billion. Medium SM031
CM051 Applying the 12.7% CTEM CAGR to the 2025 USD 2.70 billion base implies an estimated 2026 CTEM lens of about USD 3.04 billion. Medium SM032
CM052 Public CRQ lenses span from USD 2.04 billion for narrower CRQ-governance platforms to USD 5.43 billion for broader CRQ-scoring platforms, with SAFE's own USD 4 billion claim sitting between them. Medium SM035, SM003, SM001
CP001 SAFE now markets a unified cyber risk platform spanning CRQ, CTEM, TPRM, and AI-SPM with agentic workflow automation. High SP002, SP035, SP036
CP002 SAFE's 2022 acquisition of RiskLens brought FAIR-based cyber risk quantification and FAIR Institute leadership into SAFE's product and positioning. High SP001, SP034
CP003 SAFE's 2025 acquisition of Balbix added AI-native CTEM and exposure-management capabilities to SAFE's CRQ foundation. High SP002, SP037
CP004 SAFE says Forrester named it a Leader in The Forrester Wave: Cyber Risk Quantification Solutions, Q2 2025 and called SAFE One the most comprehensive CRQ-native solution in the market. High SP003, SP031
CP005 SAFE says Liminal's 2025 TPRM Link Index ranked SAFE highest in product capability and above leader medians in practitioner satisfaction. High SP032, SP033
CP006 SAFE cites Google, Fidelity, T-Mobile, Chevron, and IHG among customers, indicating referenceability with large enterprises. High SP002, SP003
CP007 SAFE says the Balbix combination links exposure, control failures, and vulnerabilities to business impact on one agentic platform. High SP002, SP037
CP008 SAFE's TPRM product page says 100+ AI agents automate vendor tiering, questionnaires, monitoring, and lifecycle workflows. Medium SP004, SP032
CP009 Tenable One is an AI-powered exposure management platform spanning IT, OT, IoT, cloud, identity, web applications, AI exposure, and external attack surface data with 300+ integrations. Medium SP010
CP010 Tenable pairs attack-path analysis, exposure scoring, and agentic AI workflows, making it the broadest CTEM-style incumbent in this competitive set. Medium SP010
CP011 Axonius closed a $200 million Series E at a $2.6 billion valuation and says it integrates hundreds of data sources to serve CAASM and SaaS-management use cases. Medium SP028
CP012 Public Axonius evidence reviewed showed strong asset and SaaS-management positioning but did not show native FAIR-based financial quantification or end-to-end TPRM depth. Medium SP028
CP013 SecurityScorecard markets TITAN AI as a threat-informed continuous TPRM platform with AI agents, outside-in discovery, and integrated detection and response. Medium SP011, SP012
CP014 SecurityScorecard continues to differentiate on externally observed ratings and real-time telemetry rather than on native first-party FAIR-style business-impact quantification. Medium SP011, SP012
CP015 BitSight remains centered on cyber risk intelligence for enterprises and supply chains, and its Moody's-linked ICT claims coverage of more than 325 million organizations. Medium SP013, SP029
CP016 Panorays combines questionnaires, external attack-surface assessment, nth-party mapping, dynamic risk ratings, and ISO/IEC 42001-governed AI in one third-party risk workflow. Medium SP014, SP015
CP017 Panorays' public pricing surface is still request-a-quote, indicating custom enterprise packaging rather than transparent self-serve pricing. Medium SP016
CP018 Prevalent combines standardized assessments, continuous monitoring, remediation management, vendor intelligence, managed services, and 800+ templates across the third-party lifecycle. Medium SP017
CP019 OneTrust covers onboarding, assessment, inventory, reporting, and continuous monitoring inside a broader governance workflow. Medium SP018
CP020 ProcessUnity says its platform adds inherent-risk tiering, external ratings connectors, and a Global Risk Exchange containing more than 18,000 attested assessments and 370,000 vendor profiles. Medium SP019
CP021 ProcessUnity AI says it uses a proprietary TPRM-tuned LLM, 40 million question pairs, evidence evaluation, and assessment autofill to reduce manual review cycles. Medium SP020
CP022 Vanta packages vendor-risk functionality inside a broader trust-management suite with AI questionnaire quotas, automatic vendor discovery, and continuous vendor monitoring. Medium SP021, SP022
CP023 Vanta reported a $150 million Series C at a $2.45 billion valuation, more than $100 million in ARR, and over 8,000 customers, making it a fast-scaling adjacent competitor. Medium SP022
CP024 CrowdStrike Falcon Exposure Management focuses on exploitability, continuous monitoring, AI exposure, and remediation workflows across endpoints, cloud, network, OT, and shadow AI. Medium SP023
CP025 Palo Alto Cortex XSIAM positions as an AI-driven SOC platform that unifies exposure data with detection and response, making it an indirect substitute through platform consolidation rather than a direct CRQ peer. Medium SP024
CP026 Rapid7 says InsightVM now powers Exposure Command, whose Essentials bundle combines vulnerability management with attack-surface management and whose Ultimate tier adds cloud and application context. Medium SP025
CP027 Cymulate CTEM automates validation, prioritization, and mobilization, while Cymulate Exposure Validation uses Vero AI and attack simulation to prove exploitability and adapt controls. Medium SP026, SP027
CP028 Forrester says more vendors have entered CRQ and expanded into adjacent use cases such as exposure management, TPRM, and control monitoring, broadening SAFE's competitive set. Medium SP030
CP029 Forrester says buyers favor transparent, standards-aligned CRQ methods and that seven of the ten assessed vendors base CRQ on recognized standards, most commonly FAIR. Medium SP030
CP030 SAFE's comparison pages argue it combines outside-in, questionnaire, and inside-out assessments plus FAIR-based quantification, whereas Prevalent and ProcessUnity rely more on questionnaires, connectors, or proprietary scoring. Low SP006, SP007
CP031 SAFE's pricing story is packaging-led rather than list-price-led: SAFE promotes usage-based or all-inclusive economics while Panorays, Vanta, and most enterprise peers require demos or quote requests. Medium SP016, SP021, SP032, SP033
CP032 SecurityScorecard, Panorays, OneTrust, ProcessUnity, and Vanta all emphasize AI or automation in TPRM, so SAFE's AI-agent message is differentiated mainly by cross-domain integration rather than AI alone. Medium SP011, SP014, SP018, SP020, SP021
CP033 BitSight and SecurityScorecard appear strongest where outside-in ratings and large-scale vendor monitoring matter most, but the reviewed sources do not show the same native first-party CRQ and FAIR framing SAFE emphasizes. Medium SP011, SP013, SP029, SP036
CP034 Tenable is the most credible direct bundling threat because its platform already joins exposure data, risk insight, attack-path analysis, AI agents, and broad integrations in one exposure-management license. Medium SP010
CP035 CrowdStrike and Palo Alto threaten SAFE less on pure CRQ depth than on budget capture, because each sells exposure or AI operations as one module inside a broader platform renewal. Medium SP023, SP024
CP036 SAFE's moat is strongest in methodology and integration: RiskLens strengthened FAIR-native quantification, Balbix strengthened CTEM, and the current SAFE narrative unifies both with TPRM. High SP001, SP002, SP036
CP037 Public sources reviewed do not disclose SAFE's realized ACV, systematic win rates against Tenable or SecurityScorecard, or apples-to-apples list prices for enterprise CRQ and CTEM deals. Medium SP010, SP011, SP016, SP021
CP038 SAFE's named-customer and analyst proof points are meaningful, but competitor momentum is also real: Tenable and CrowdStrike are embedding AI agents, SecurityScorecard markets TITAN AI, and Panorays markets agentic AI plus ISO 42001 governance. Medium SP010, SP011, SP014, SP023
CI001 SAFE publicly presents one unified platform spanning CRQ, TPRM, and CTEM rather than three disconnected products. High SI001, SI002, SI005
CI002 SAFE said more than half of its customers had adopted TPRM by July 2025, making TPRM the clearest publicly disclosed expansion module. High SI001, SI002, SI003, SI004
CI003 SAFE launched CTEM with the Series C announcement and framed it as the next major module on the Cyber Risk Singularity platform. High SI001, SI002, SI003, SI004, SI013
CI004 The Series C announcement and related coverage describe SAFE as sustaining roughly 120%+ year-over-year growth since the 2020 platform launch. Medium SI001, SI002, SI029
CI005 SAFE publicly claims triple-digit revenue growth for three consecutive years and total funding above $170 million. High SI001, SI002, SI003, SI004, SI009
CI006 SAFE cites Google, Fidelity, T-Mobile, Chevron, and IHG as customers, pointing to a large-enterprise buyer base rather than SMB volume. High SI001, SI002, SI003, SI004, SI009
CI007 SAFE’s customer page says the company works with hundreds of visionaries, but it does not publish a precise customer count or revenue concentration split. Medium SI005, SI011
CI008 SAFE’s own timeline places CRQ first, RiskLens in 2022, TPRM in 2024, and both CTEM and Balbix in 2025, which is the clearest public chronology for how revenue mix likely evolved. Medium SI005
CI009 The 2021 Series B press release said SAFE had already raised over $100 million and was growing over 200% year over year for three consecutive years at that point. Medium SI006, SI019
CI010 SAFE launched TPRM in May 2024 with over 100 customers live on the module within one week. Medium SI019
CI011 SAFE’s public TPRM offer looks like an enterprise subscription model because the launch materials emphasize first-year contract buyouts and no vendor caps instead of transaction pricing. Medium SI012, SI015, SI019
CI012 SAFE’s AWS page says TPRM can be sold through AWS Marketplace using private offers and consolidated billing, which implies negotiated annual enterprise procurement rather than transparent list pricing. Medium SI015
CI013 The TPRM datasheet describes SAFE automating onboarding, assessments, monitoring, reporting, and offboarding, supporting platform-style pricing around full program coverage. Medium SI012, SI015
CI014 The CTEM datasheet says SAFE focuses users on the 1-5% of exposures that actually increase attack risk and powers the workflow with 40+ AI agents, which supports premium-module positioning. Medium SI013
CI015 The CRQ datasheet centers SAFE’s value around budget justification, ROI, board reporting, and regulator-ready defensibility, which is consistent with CRQ being the original enterprise land motion. Medium SI005, SI014
CI016 T-Mobile used SAFE across more than 1 million digital assets and cut reporting time by 75% in one week. Medium SI016
CI017 Instacart operationalized SAFE TPRM in three weeks across 600+ third parties, saved 1,800+ analyst minutes per assessment cycle, and scaled under a flat pricing model. Medium SI017
CI018 Kyriba onboarded 290+ vendors in under a week, matched 72% of vendors to existing SOC 2 reports autonomously, and moved from pay-per-vendor economics to SAFE’s flat pricing. Medium SI018
CI019 RiskLens added FAIR methodology and a 14,000-practitioner community linked to 50% of Fortune 500 companies, deepening SAFE’s CRQ position rather than creating a new unrelated revenue stream. Medium SI007, SI008
CI020 Balbix added exposure-management depth and a dedicated CTEM leader, which likely increases both CTEM product breadth and post-merger integration spend. Medium SI009, SI010
CI021 Lucideus appears in SEC EDGAR with multiple Form D filings across 2017, 2018, 2020, and 2021, confirming a long-running private-capital funding history. Medium SI020
CI022 SAFE Securities Inc.’s 2021 Form D disclosed a $25,000,004 offering with $14,999,988 sold and $10,000,016 remaining. High SI021, SI022
CI023 Sorenson Capital still describes SAFE as a platform serving enterprises, boards, regulators, and cyber insurers, reinforcing enterprise-budget positioning rather than narrow departmental pricing. Medium SI006, SI027
CI024 Avataar describes SAFE as having evolved from a service-focused provider into a product-led company trusted by Fortune 500 clients. Medium SI005, SI026
CI025 The 2025 Series C proceeds were publicly framed around engineering, go-to-market, R&D, and the CyberAGI roadmap rather than balance-sheet repair. High SI001, SI003
CI026 The retained public sources do not disclose the purchase price for either RiskLens or Balbix. Medium SI007, SI008, SI009, SI010
CI027 The retained public file contains no disclosed ARR, GAAP revenue, deferred revenue, cash balance, monthly burn, or debt schedule for SAFE. High SI001, SI006, SI011, SI020, SI021, SI022
CI028 SAFE’s public materials do not disclose realized pricing, discount ladders, contract minimums, or customer concentration by revenue. Medium SI011, SI012, SI015, SI019
CI029 Zscaler reported $2.673 billion of revenue in fiscal 2025 and had 7,923 employees as of July 31, 2025, implying roughly $337,000 of revenue per employee. Medium SI023, SI028
CI030 Zscaler’s 2025 Form 10-K said gross margin decreased from 78% to 77% as data-center costs and headcount expanded. Medium SI023
CI031 CrowdStrike reported $4.812 billion of revenue and 10,698 full-time employees for fiscal 2026, implying roughly $450,000 of revenue per employee. Medium SI024
CI032 CrowdStrike said 95% of fiscal 2026 revenue was subscription revenue and total revenue grew 22% year over year. Medium SI024
CI033 CrowdStrike disclosed that cost of revenue and sales and marketing growth were both partly driven by double-digit average headcount increases, highlighting the cash demands of scaling enterprise cyber SaaS. Medium SI024
CI034 The public-comp productivity band for scaled cyber SaaS appears to cluster around roughly $337,000-$450,000 of revenue per employee. Medium SI023, SI024, SI028
CI035 SAFE’s total headcount is not disclosed in retained sources; The Org exposes only partial team slices and named leaders, so any SAFE-specific ARR-per-employee estimate remains low-confidence. Medium SI003, SI025
CI036 A practical CAC proxy for SAFE is likely high by SMB standards because comparable security vendors continue to invest heavily in sales headcount, commissions, partner enablement, and marketing to win large accounts. Low SI023, SI024, SI027
CI037 A defensible public ACV estimate for SAFE is roughly $250,000-$800,000 per year for meaningful enterprise deployments. Low SI006, SI016, SI017, SI018, SI019
CI038 A reasonable public NRR estimate for SAFE is roughly 110%-120% because the company has visible cross-sell paths from CRQ into TPRM and CTEM, but no public cohort data confirms the exact figure. Low SI002, SI003, SI017, SI018
CI039 Using a rough 70%-80% gross-margin band and an 18-30 month payback proxy produces an estimated LTV/CAC band of about 3x-5x for SAFE. Low SI023, SI024, SI028
CI040 RiskLens and Balbix likely increased SAFE’s product, sales, and customer-success integration burden even as they improved platform breadth. Medium SI007, SI009, SI010, SI019
CI041 Because TPRM reached 100+ customers quickly and more than half of customers had adopted it by mid-2025, TPRM appears to be the clearest incremental revenue contributor after CRQ. Medium SI001, SI017, SI018, SI019
CI042 Because CTEM only launched with the Series C in 2025, it likely contributes pipeline and attach value before it contributes a CRQ-scale installed ARR base. Medium SI001, SI013, SI009
CI043 A low-confidence public operating model suggests SAFE could be burning roughly $25-$45 million per year, implying about 18-30 months of runway for the $70 million Series C proceeds before considering any undisclosed opening cash. Low SI001, SI003, SI024, SI025
CI044 The biggest underwriting blockers are undisclosed ARR, module mix, gross margin, cash balance, burn, NRR, customer concentration, acquisition consideration, and any debt or covenant package. Medium SI001, SI011, SI020, SI025
CI045 SEC-level diligence should request ARR by module, billings and deferred revenue, gross-margin bridges, sales and marketing efficiency, cohort retention, acquisition integration scorecards, and a monthly cash-runway model. Medium SI020, SI023, SI024, SI025
CI046 The safest public conclusion is that SAFE has credible near-term capital to keep investing in CRQ, TPRM, and CTEM, but not enough disclosure to underwrite margin durability or next-round timing with high confidence. Medium SI001, SI005, SI020, SI023, SI024
CI047 A conservative revenue-mix estimate is CRQ as the largest revenue base, TPRM as the fastest-growing expansion module, CTEM as an early attach module, and services/support as a small ancillary line. Low SI002, SI005, SI012, SI015, SI017, SI018, SI019
CI048 SAFE’s flat-pricing references in the Instacart and Kyriba case studies imply monetization is leaning toward enterprise platform subscriptions rather than purely per-vendor usage pricing. Medium SI017, SI018
CI049 A cautious public ARR estimate of roughly $55-$90 million is consistent with SAFE’s multi-module enterprise positioning, 100+ early TPRM customers, >50% TPRM attach, marquee enterprise logos, and repeated triple-digit growth claims. Low SI002, SI003, SI010, SI017, SI018, SI019
CI050 Series C proceeds appear aimed at innovation and go-to-market expansion rather than refinancing because retained sources discuss engineering, R&D, GTM, and CyberAGI but no restructuring or debt cleanup. Medium SI001, SI003
CE001 SAFE One is publicly positioned as a unified platform spanning CRQ, CTEM, TPRM, AI-SPM, and the SafeX reasoning layer. Medium SE001
CE002 SAFE CRQ measures cyber risk in financial terms and is purpose-built on open FAIR standards. High SE002, SE021
CE003 SAFE’s CRQ surface explicitly highlights FAIR-CAM for control performance and FAIR-MAM for loss magnitude and annualized loss exposure. High SE002, SE021
CE004 SAFE says its CRQ engine integrates with 200+ security and business systems and continuously analyzes roughly 600 threat events per day. Medium SE002
CE005 SAFE CTEM builds a unified exposure inventory by aggregating and de-duplicating asset and vulnerability data from existing tools. Medium SE003
CE006 SAFE CTEM prioritizes exposures using exploitability, business context, attack-path style validation, and control-efficacy checks before mobilizing remediation. Medium SE003
CE007 SAFE announced the “world’s first fully autonomous” CTEM solution in July 2025 and said it was powered by dozens of autonomous AI agents. Medium SE013
CE008 SAFE TPRM is marketed as an end-to-end vendor-risk workflow covering onboarding, questionnaires, monitoring, compliance, and offboarding. Medium SE004, SE014
CE009 SAFE’s April 2025 launch press release described TPRM as the industry’s first fully autonomous TPRM platform and said the business had reached $10M TPRM ARR in under one year. Medium SE014
CE010 The public TPRM page says SAFE can “let 100+ AI Agents take over” manual TPRM work and references hundreds of agentic workflows. Medium SE004
CE011 Instacart’s published case study says SAFE TPRM operationalized 600+ third parties in three weeks, parsed 1,000+ documents, and used 25+ AI agents. Medium SE017
CE012 SAFE AI-SPM says it continuously discovers shadow AI usage, AI-related exposures, AI data flows, identity risks, and associated business impact. Medium SE005, SE026
CE013 SAFE AI-SPM’s Real-Time AI Risk Graph is described as correlating live activity, configurations, contracts, questionnaires or compliance evidence, and outside-in exposure. Medium SE005, SE026
CE014 SAFE’s AI-SPM materials explicitly mention monitoring risk across major AI vendors such as ChatGPT, Claude, Copilot, and Gemini. Medium SE005, SE026
CE015 SAFE publicly frames its platform around strategic risk (CRQ), tactical risk (CTEM), vendor risk (TPRM), enterprise or AI risk, and a SafeX reasoning layer. Medium SE001, SE029
CE016 SAFE’s public product positioning includes 100+ agentic workflows, 100+ long-horizon AI agents, and 150+ connectors across the broader platform narrative. Medium SE001, SE007
CE017 SAFE’s integrations marketplace says the platform supports 150+ cybersecurity tools and 100+ out-of-the-box integrations across cloud, EDR, SIEM, ITSM, identity, and developer systems. Medium SE007, SE015
CE018 SAFE publishes a Swagger-based REST API surface with versioned endpoints and a documented authentication flow through POST /api/v3/auth. Medium SE019, SE030
CE019 SAFE’s API credentials are admin-managed, shown once at creation, support read/write access, and have a documented cap of 1,200 requests per minute. Medium SE019
CE020 The RiskLens acquisition combined FAIR-based risk quantification IP with SAFE’s automation platform and SAFE said it would embed FAIR into a platform processing over 3 billion signals per day. High SE010, SE024
CE021 The FAIR Institute said the RiskLens-SAFE combination effectively creates “automated FAIR” while keeping the FAIR Institute as a separate non-profit with SAFE as technical advisor. Medium SE024
CE022 SAFE’s FAIRCON25 write-up says the company now has more than 200 integrations, roughly 150 generally available, and exposes “triple-click” explainability from top-line risk outputs into underlying drivers. Medium SE025
CE023 SAFE says the Balbix acquisition unifies CTEM, CRQ, and TPRM on one living source of truth that traces every exposure or misconfiguration to quantified business impact. High SE011, SE012, SE022
CE024 Independent coverage of Balbix describes the acquired platform as AI-native exposure management with asset discovery, vulnerability and misconfiguration detection, control-efficacy context, and remediation workflow integrations. Medium SE011, SE022
CE025 SAFE is shifting CRQ language toward “decision intelligence,” arguing that continuous telemetry and explainability matter more than static scores alone. Medium SE025
CE026 SAFE’s security page lists SOC 2 Type 2, ISO 27001:2013, ISO 9001:2015, and TX-RAMP as public trust signals. Medium SE008
CE027 SAFE describes itself as a cloud SaaS platform hosted on AWS with regional tenancy, TLS 1.2 in transit, AES-256 at rest, and AWS KMS-based key management with optional customer-managed keys. Medium SE008
CE028 SAFE says it performs continuous SAST and DAST, daily vulnerability assessment, continuous log monitoring, periodic patch management, and pre-release business-logic testing. Medium SE008
CE029 SAFE’s AI policy says customer data is processed in a tenant-isolated manner, not shared across customers, and not used to train shared or cross-tenant models. Medium SE009
CE030 SAFE’s AI policy says its AI features can route across AWS Bedrock-hosted models, Anthropic Claude Sonnet / Nova, and OpenAI GPT models without customer-side provider selection. Medium SE009
CE031 SAFE’s AI policy says AI interactions are logged in a tamper-evident format and developed under SOC 2 / ISO 27001 governed controls, but SAFE AI is not designed for HIPAA workloads. Medium SE009
CE032 SAFE’s T-Mobile case study says the platform monitored more than 1 million digital assets and cut reporting time by 75%. Medium SE016
CE033 Independent and vendor-cited Forrester materials say SAFE was a Q2 2025 CRQ Leader, called the most comprehensive CRQ-native solution in the market, and the only vendor to implement FAIR-CAM. High SE018, SE021, SE023
CE034 BankInfoSecurity reported that Forrester praised SAFE’s automation, telemetry breadth, and agentic AI, but also said customers wanted better asset and exposure tagging at scale and stronger export formatting after custom queries. Medium SE023
CE035 PeerSpot shows SAFE One ranked #32 in IT Vendor Risk Management with 0.9% mindshare and zero listed reviews as of July 2026, far below SecurityScorecard’s 5.6% mindshare. Medium SE028
CE036 GARP’s CyberAGI coverage argues that explainability, human confirmation, and clean telemetry remain prerequisites for any credible move toward autonomous cyber-risk management. Medium SE027
CE037 AWS Marketplace describes SAFE One as a unified, FAIR-powered platform for first-party and third-party cyber risks with built-in scenarios and real-time telemetry ingestion. Medium SE029
CE038 API Tracker’s developer profile lists Safe Security with 6 APIs, REST style, OpenAPI/Swagger support, and 31 integrations. Medium SE030
CE039 FeaturedCustomers aggregates 18 testimonials, 16 case studies, and 1,263 reference ratings for Safe Security, indicating a non-trivial public reference base even if most proof remains marketing-led. Medium SE031
CE040 SAFE’s public AI agents page names at least 15 specialized agents, including VenderX, TierMaster, BreachWatch, TrustMiner, ShadowScan, ContractFX, and NetProphet. Medium SE006
CU001 SAFE’s public customer file is enterprise-led, with proof centered on Fortune 500 and other large, complex organizations rather than SMB self-serve buyers. Low SU001, SU004, SU017
CU002 Public customer proof spans telecom, retail and marketplaces, financial software and services, energy and utilities, healthcare, insurance, consulting, and hospitality. Medium SU004, SU005, SU006, SU007, SU009, SU010, SU021
CU003 SAFE’s visible buyer is usually a CISO, cyber-risk, GRC, or TPRM leader who needs board-grade reporting, defensible prioritization, and budget justification. Medium SU005, SU006, SU007, SU009, SU010, SU013, SU021
CU004 The day-to-day users in SAFE’s public stories are security, risk, and vendor-management teams, while the payer appears to be the enterprise security, risk, or compliance budget owner. Medium SU005, SU006, SU007, SU010, SU021
CU005 SAFE’s public customer evidence shows very little true mid-market or self-serve proof, implying that the current commercial motion is still weighted toward large-enterprise accounts. Low SU001, SU004, SU017
CU006 SAFE publicly claims that 10% of Fortune 500 companies use the platform. Medium SU001
CU007 SAFE’s customers page explicitly organizes proof around financial services, healthcare, telecom, and insurance verticals. Medium SU002
CU008 SAFE’s homepage says the platform connects to 100+ integrations and processes 3 billion signals every day, which is a production-scale usage signal rather than a pilot-scale one. Medium SU001
CU009 T-Mobile uses SAFE to quantify cyber risk in financial terms, automate assessments, monitor more than 1 million digital assets, and tighten loss-event controls. Medium SU005
CU010 T-Mobile’s SAFE case study says the team updated NIST control documentation and prioritized remediation in one week, reducing reporting time by 75 percent. Medium SU005
CU011 Instacart was already working with SAFE on CRQ before it became a design partner for SAFE’s autonomous TPRM product. Medium SU006
CU012 Instacart operationalized SAFE TPRM in three weeks and onboarded and assessed 600+ third parties. Medium SU006
CU013 Instacart says SAFE saved 1,800+ analyst minutes per assessment cycle. Medium SU006
CU014 Instacart says 100 percent of vendors were assessed without adding headcount or hours. Medium SU006
CU015 Kyriba chose SAFE’s autonomous TPRM platform to migrate all third parties and documentation into one unified system. Medium SU007
CU016 Kyriba says SAFE TPRM onboarded 290+ vendors in under a week. Medium SU007
CU017 Kyriba says 72 percent of vendors were autonomously matched to existing SOC 2 reports. Medium SU007
CU018 Kyriba says SAFE’s flat pricing let it assess 100 percent of its third-party ecosystem without adding budget. Medium SU007
CU019 Carvana says SAFE helped reduce breach likelihood by 40 percent within nine months. Medium SU008
CU020 Carvana says SAFE helped cut its cyber-insurance premium by 25 percent while doubling coverage. Medium SU008
CU021 Aboitiz Power says SAFE improved cybersecurity program effectiveness by 370 percent and unlocked more than $1.6 million in savings from right-sizing controls. Medium SU009
CU022 OB Hospitalist Group says SAFE reduced vendor-assessment cycle time by 70 percent, saved 10+ hours per week, and delivered 100 percent visibility into tier-one vendor risk. Medium SU010
CU023 Victoria’s Secret & Co. became a design partner for FAIR-CAM and expanded its analysis from limited scenario-specific controls to 68 controls assessed across many scenarios at once. Medium SU011
CU024 Booz Allen says SAFEOne reduced time-to-value by 50 percent across its service lines. Medium SU015, SU019
CU025 IHG used SAFE to move from qualitative IT risk scoring to quantified risk communication across high-value assets, budget allocation, and risk-treatment selection. Medium SU021
CU026 SAFE’s July 2025 funding announcement and Indian Startup News both name Google, Fidelity, T-Mobile, Chevron, and IHG as customers. Medium SU017, SU025
CU027 Within the retrieved public corpus, Google, Fidelity, and Chevron appear as named customers but do not have module-specific live case studies comparable to T-Mobile or IHG. Low SU004, SU017, SU025
CU028 SAFE’s public customer-story archive currently lists 13 customer stories. Medium SU004
CU029 Six of SAFE’s currently listed public customer stories were posted between January and May 2026. Medium SU004
CU030 SAFE says it crossed $10 million of TPRM ARR in less than one year from launching the module. Medium SU018
CU031 SAFE's reported TPRM cross-sell rate of more than 50% of its CRQ installed base within roughly 12 months of the 2024 module launch implies a strong platform land-and-expand motion and positions TPRM as the primary near-term expansion revenue vector for the company. Medium SU017
CU032 SAFE’s official and third-party funding materials claim triple-digit growth for three consecutive years, including 120%+ year-over-year growth since launch. High SU017, SU018, SU025
CU033 SAFE’s autonomous TPRM launch release says the company is trusted by hundreds of global organizations. Medium SU018
CU034 FeaturedCustomers shows 18 testimonials, 16 case studies, and a 4.8/5 score based on 1,263 reference ratings for Safe Security. Medium SU024
CU035 Gartner’s vendor page says Safe Security has 99 reviews, a 4.5 overall average rating, and products spread across five markets. Medium SU022
CU036 Instacart and Kyriba provide direct cross-sell proof because both public stories focus on SAFE TPRM after either earlier CRQ use or broader risk-program maturity. Medium SU006, SU007, SU017
CU037 Across T-Mobile, Aboitiz Power, IHG, OB Hospitalist Group, Shelter Insurance, and TrustRadius, SAFE’s repeated customer value proposition is board-ready financial communication of cyber risk. Medium SU005, SU009, SU010, SU013, SU021, SU023
CU038 The retrieved public corpus does not disclose net revenue retention, gross retention, logo churn, or standard customer contract length. Low SU004, SU017, SU018, SU022, SU023, SU024
CU039 SAFE’s public proof set is concentrated in large enterprises and mission-critical operators, which likely means higher ACVs but also raises top-customer concentration risk. Low SU001, SU017, SU026, SU027, SU029, SU031
CU040 SAFE’s public proof is international, but the named stories still skew North America-heavy, with Glovo, IHG, and Aboitiz as the main visible non-U.S. counterweights. Low SU004, SU009, SU012, SU021, SU027
CU041 The public proof-quality gradient is uneven: T-Mobile, Instacart, Kyriba, Carvana, Aboitiz, and OB Hospitalist Group have quantified narratives, while Google, Fidelity, and Chevron remain name-level references. Medium SU005, SU006, SU007, SU008, SU009, SU010, SU017, SU025
CU042 SAFE’s AWS page and Booz Allen partnership materials suggest procurement can be accelerated through private offers, co-sell motions, and partner-assisted delivery. Medium SU019, SU020
CU043 Gartner describes TPRM as a complex market spanning legal, compliance, procurement, supply chain, IT, cybersecurity, and other oversight teams, implying multi-stakeholder buying friction for SAFE’s expansion. Medium SU022
CU044 Fidelity employs over 80,000 associates across 11 countries, confirming that a current SAFE relationship would sit inside a very large financial-services organization. Medium SU031
CU045 IHG says it has more than one million rooms globally, confirming that SAFE’s hospitality proof sits at global-enterprise scale. Medium SU027
CU046 Chevron publicly says it experiences cyber incidents and operates a large industrial environment, supporting its fit as a critical-infrastructure-style named customer if the SAFE relationship is current. Medium SU029, SU030
CU047 Google’s corporate about page confirms global operating scale, which is directionally consistent with SAFE’s claim to serve hyperscale technology leaders. Low SU033
CR001 SEC rules require registrants to file Item 1.05 Form 8-K within four business days after determining that a cybersecurity incident is material. High SR018, SR019
CR002 SEC Item 106 requires annual disclosure of cybersecurity risk management processes and board and management oversight in Form 10-K. High SR018, SR019
CR003 Safe says it acts as data controller for its own-site personal data and as data processor when processing personal data on behalf of customers. Medium SR001
CR004 Safe says customer-related personal data may be processed in the United States, Germany, United Kingdom, Bahrain, India, Australia, and Singapore as determined by the customer. Medium SR001
CR005 EU standard contractual clauses are an approved GDPR transfer mechanism for controllers or processors in the EU/EEA sending data to parties outside the EU/EEA. High SR020, SR021
CR006 Safe’s privacy policy says it is a global business and may transfer personal data to countries with different data-protection rules. Medium SR001
CR007 India’s DPDP Rules 2025 define data fiduciary and data processor roles and impose penalties up to ₹250 crore for failure to maintain reasonable security safeguards. Medium SR022
CR008 India’s DPDP Rules 2025 require data fiduciaries to inform affected individuals without delay after a personal-data breach. Medium SR022
CR009 Safe’s customer terms say its products, technology, software, technical data, and services may be subject to EAR, ITAR, and OFAC sanctions programs. Medium SR002
CR010 Safe said it resolved a recent legal dispute with SecurityScorecard on 2025-10-17 and moved into a mutual research collaboration. Medium SR013
CR011 Safe’s terms disclaim that service operation or output will be uninterrupted, error-free, secure, accurate, reliable, or complete. Medium SR002
CR012 Safe’s limited warranty remedy is correction or workaround of errors or a refund of the most recent renewed term fee. Medium SR002
CR013 Safe says product and customer data are hosted on AWS and that customers can choose among supported AWS regions. Medium SR004
CR014 Safe says customer data is encrypted in transit with TLS 1.2 and at rest with AES 256-bit AWS KMS keys, with customer-provided keys supported. Medium SR004
CR015 Safe’s AI policy says all customer data is stored within AWS infrastructure with encryption at rest and in transit. Medium SR003
CR016 Safe’s privacy policy says it shares personal information with service providers such as hosting, cloud, IT, CRM, support, and analytics providers. Medium SR001
CR017 Safe’s AI policy says no customer data is used to train shared or cross-tenant models. High SR003, SR006
CR018 Safe’s AI policy says prompts may be stored for user history, troubleshooting, recurring-issue analysis, abuse prevention, or latency reduction. Medium SR003
CR019 Safe says it uses open-source models, AWS Bedrock-hosted models, Anthropic Claude, Nova, and OpenAI GPT through dynamic routing. Medium SR003
CR020 Safe AURA scores AI trust across dimensions including accuracy, explainability, safety, reliability, human oversight, latency, and business impact. Medium SR006
CR021 Safe’s product overview markets unified visibility across AI vendors including OpenAI, Claude, Copilot, and Gemini. Medium SR005
CR022 Safe’s AWS marketplace TPRM page says AWS alerts and posture changes can trigger agentic workflows across evidence review, remediation, and monitoring. Medium SR015
CR023 Safe’s public SOC 3 covers security, availability, processing integrity, confidentiality, and privacy for the period from 2025-01-01 through 2025-11-30. Medium SR008
CR024 Safe announced its Balbix acquisition on 2025-11-18. High SR009, SR039
CR025 Gaurav Banga joined Safe as President of CTEM after the Balbix acquisition. High SR009, SR039, SR040
CR026 SiliconANGLE reported that the Balbix acquisition price was undisclosed. Medium SR039
CR027 Safe says the Balbix combination is intended to unify CRQ, CTEM, and TPRM in one platform. Medium SR009, SR010
CR028 Enterprise Security Tech wrote that Safe and Balbix are trying to fuse historically siloed operational exposure data and business-level risk intelligence. Medium SR040
CR029 Enterprise Security Tech cautioned that the combined system is not yet true cyber autonomy. Medium SR040
CR030 Safe announced the RiskLens acquisition in July 2023 to combine FAIR-based cyber risk quantification with its AI platform. Medium SR011
CR031 Nick Sanna joined Safe as President and Jack Jones as Chief Research Scientist in the RiskLens transaction while continuing FAIR Institute roles. Medium SR011
CR032 The Hacker News said Gartner’s “three times less likely to be breached by 2026” CTEM prediction only holds if CTEM is operationalized. Medium SR029
CR033 The Hacker News said CTEM is not plug-and-play and requires frequent validation of internal and external assets. Medium SR029
CR034 SC Media said CTEM is a holistic process rather than an off-the-shelf platform and can be difficult to set up across tools that do not work well together. Medium SR032
CR035 SC Media said detractors argue CTEM can defer urgent patches that do not fit business goals or appear too costly to fix. Medium SR032
CR036 The QBER paper says current CRQ approaches still need better integration of economic viewpoints to provide decision-useful analysis. Medium SR030
CR037 Tenable and Qualys both reported limited Salesforce-data exposure after OAuth token theft tied to the Salesloft Drift campaign. Medium SR033
CR038 The Salesloft and Salesforce OAuth campaign affected 700+ organizations and exposed embedded credentials such as AWS keys and Snowflake tokens. Medium SR034
CR039 The American Bar Association said Oracle-related 2025 cloud breaches prompted CISA guidance and multiple lawsuits. Medium SR027
CR040 Infosecurity Magazine reported 43 U.S. data-breach class actions and 73 settlements between August 2024 and February 2025 totaling $155 million. Medium SR028
CR041 Safe raised a $70 million Series C on 2025-07-31, taking total funding above $170 million. High SR012, SR038
CR042 The Economic Times reported that Safe had about 200 employees in 2025, including an R&D team of about 100 in India. Medium SR038
CR043 The Economic Times reported that Safe was founded in 2012 by Saket Modi, Viditkumar Baxi, and Rahul Tyagi. Medium SR038
CR044 TechStrong reported that 39% of organizations cite AI engineers as the hardest role to fill and 38% cite cybersecurity engineers, while 70% prioritize senior hires. Medium SR037
CR045 AmbitionBox shows Safe Security at 2.5 out of 5 overall from 29 employee reviews updated on 2026-02-09. Medium SR043
CR046 AmbitionBox rates work-life balance at 1.7 out of 5 and job security at 1.8 out of 5, the lowest listed category scores on the page. Medium SR043
CR047 AmbitionBox review excerpts describe 14+ hour days, 7-day weeks, heavy scolding, and poor intern support at Safe Security. Medium SR043
CR048 Safe’s AWS marketplace page says customers can buy through AWS with streamlined contracting, consolidated billing, and private offers. Medium SR015
CR049 Safe’s AWS partnership page frames AWS Marketplace as a strategic distribution and deployment channel for Safe One. Medium SR014
CR050 Safe’s 2025 Series C press release says the company achieved triple-digit revenue growth for three consecutive years after launching its platform in 2020. Medium SR012
CR051 Safe’s Balbix press release says the company had raised over $170 million and markets one platform spanning CRQ, CTEM, and TPRM. Medium SR009, SR012
CR052 Safe’s AI policy says model-provider selection is dynamic and customers cannot choose individual LLM providers. Medium SR003
CR053 Safe’s AI policy says Internet Search is disabled by default and can only be enabled by an administrator. Medium SR003
CR054 Safe’s AI policy says SAFE AI is not HIPAA compliant and customers should avoid submitting PHI. Medium SR003
CR055 The current public record supports five top residual risks for Safe: a platform-data breach, model or score reliability failure, Balbix and RiskLens integration drag, AWS and LLM dependency, and leadership or talent execution strain. Medium SR003, SR004, SR009, SR011, SR033, SR034, SR043
CR056 The most material regulatory and legal risks in public evidence are SEC-sensitive customer use cases, GDPR and India cross-border handling obligations, export and sanctions clauses, and asymmetrical contract remedies. Medium SR001, SR002, SR018, SR019, SR020, SR022
CR057 Safe’s public disclosures show real control mitigants, but they do not publish a public DPA, public subprocessor list, public incident history, or quantified model-accuracy benchmarks. Medium SR001, SR003, SR004, SR006, SR008
CR058 The Balbix and RiskLens deals raise execution risk because Safe is trying to unify CTEM, CRQ, and TPRM while also marketing CyberAGI and autonomous workflows. Medium SR009, SR010, SR011, SR012, SR040
CR059 Safe’s funding and growth announcements prove access to capital but do not disclose valuation, burn, debt, runway, or acquisition consideration, limiting public underwriting of financial resilience. Medium SR012, SR038, SR039
CR060 People risk is elevated because Safe remains founder-led, runs a large India-based R&D footprint, and surfaces below-average employee sentiment on work-life balance and job security. Medium SR037, SR038, SR043
CV001 SAFE announced a $70 million Series C on July 31, 2025 led by Avataar Ventures. High SV001, SV002, SV003
CV002 SAFE said total funding exceeded $170 million after the Series C. High SV001, SV002, SV003
CV003 SAFE and its investors claim the company has sustained triple-digit or 120%+ year-over-year growth for three consecutive years. Medium SV001, SV002, SV005
CV004 SAFE said more than 50% of customers adopted TPRM after its 2024 launch. Medium SV001, SV002
CV005 SAFE was named a Leader in The Forrester Wave for Cyber Risk Quantification Solutions in Q2 2025. Medium SV004, SV005
CV006 SAFE's Forrester materials say the company earned the highest possible score in 21 criteria and ranked #1 in strategy. Medium SV004, SV005
CV007 SAFE's Liminal landing page says the company ranked #1 in product capability and outperformed other leaders in practitioner satisfaction by 8%. Medium SV006
CV008 SAFE markets CRQ, TPRM, CTEM, AI-SPM, and SafeX as a unified autonomous cyber-risk platform. Medium SV007, SV008
CV009 SAFE's CRQ page cites a 73% reduction in assessment and reporting time in a T-Mobile example. Medium SV008
CV010 SAFE's CRQ page cites 20% cyber-insurance savings in the same example. Medium SV008
CV011 Tenable guided FY2026 revenue to $1.068 billion to $1.078 billion after reporting $999.4 million of 2025 revenue. High SV009, SV032
CV012 Stock Analysis listed Tenable at $4.61 billion of enterprise value on July 6, 2026. Medium SV010
CV013 Qualys guided FY2026 revenue to $721 million to $727 million and reported 83% GAAP gross margin in Q1 2026. Medium SV011
CV014 Stock Analysis listed Qualys at $4.89 billion of enterprise value on July 6, 2026. Medium SV012
CV015 Rapid7 reported $832 million of ARR in Q1 2026 after $840 million of ARR and $860 million of revenue in FY2025. High SV013, SV033
CV016 Stock Analysis listed Rapid7 at roughly $996.65 million of enterprise value and 1.16x EV/Sales on July 6, 2026. Medium SV014
CV017 Windsor Drake says the broader public cybersecurity market traded at about 7.8x revenue in late 2025. Medium SV020
CV018 Windsor Drake says high-growth cloud and identity segments can reach roughly 13x to 15x public revenue multiples and strategic M&A can exceed 20x. Medium SV020
CV019 Finro says public cybersecurity companies averaged 7.8x revenue versus 15.2x in private transactions and 16.3x in M&A. Medium SV022
CV020 Clipperton says 2025 high-performing cybersecurity leaders traded at a median 18.5x EV/Revenue while low performers traded at 4.5x. Medium SV023
CV021 First Analysis says cybersecurity revenue grew 16.8% in 2025 even as the median cyber stock fell 18%. Medium SV024
CV022 Premier Alternatives estimated Safe Security at $368.3 million as of December 31, 2025. Low SV025
CV023 Premier Alternatives also listed $386.2 million of total funding and a December 2025 funding event for Safe Security. Low SV025
CV024 Latka estimated Axonius at $151.5 million of 2024 revenue and a $2.6 billion valuation. Medium SV015
CV025 Latka estimated SecurityScorecard at $144.3 million of 2024 revenue and a $980 million valuation. Medium SV016
CV026 Moody's invested $250 million in BitSight in 2021 at a $2.4 billion valuation and became its largest shareholder. High SV017, SV018, SV019
CV027 Google closed its Wiz acquisition in March 2026 and said Wiz would remain available across all major clouds. Medium SV026
CV028 Acquiry characterized Google's $32 billion Wiz purchase as roughly 45x to 65x ARR depending on revenue assumptions. Medium SV027
CV029 SailPoint priced 60 million IPO shares at $23 in February 2025. Medium SV028
CV030 SailPoint's S-1 showed $813 million of ARR, 30% ARR growth, 114% dollar-based net retention, and a Rule of 44 as of October 31, 2024. Medium SV029
CV031 CNBC reported Netskope's September 2025 IPO at a $7.3 billion valuation with $707 million of ARR growing 33%. Medium SV030
CV032 NY Venture Hub, citing PitchBook, said flat and down rounds reached 27.4% of VC deals in Q1 2024, the highest share in ten years. Medium SV031
CV033 At a hypothetical $1 billion entry, SAFE would need roughly $71 million to $83 million of ARR to clear a 12x to 14x premium cyber multiple and roughly $100 million of ARR to clear 10x. Medium SV017, SV018, SV019, SV020, SV022
CV034 Using the 7.8x public-cyber multiple, $70 million to $100 million of ARR implies about $546 million to $780 million of enterprise value. Medium SV020, SV022
CV035 Using a 13x to 15x premium-growth multiple, $70 million to $100 million of ARR implies about $910 million to $1.5 billion of enterprise value. Medium SV018, SV020, SV022
CV036 SAFE's leadership signals and platform breadth support paying above Tenable and Rapid7 multiples if growth proves durable. Medium SV004, SV005, SV006, SV007, SV011, SV015
CV037 The spread between Premier's $368.3 million estimate and a hypothetical $1 billion entry is too wide for a clean buy without harder proof of current ARR and terms. Medium SV025, SV031
CV038 A reasonable bear case is $500 million to $700 million if growth slows, investors demand 7x to 10x on $60 million to $70 million of ARR, and competition compresses the narrative premium. Medium SV020, SV021, SV022, SV023
CV039 A reasonable base case is $1.5 billion to $2.0 billion if SAFE grows into $175 million to $200 million of ARR at 8x to 10x as a credible CRQ, TPRM, and CTEM platform. Medium SV019, SV020, SV022, SV026
CV040 A reasonable bull case is $3.0 billion to $4.2 billion if SAFE reaches $300 million to $350 million of ARR and keeps a 10x to 12x strategic premium. Medium SV018, SV020, SV026, SV027
CV041 The strongest adverse case is price opacity because the public SAFE record does not disclose audited ARR, gross margin, NRR, or current preferred terms. Medium SV001, SV002, SV007, SV008, SV025
CV042 The current disclosure gap makes liquidation preferences, anti-dilution terms, and any post-Series-C debt or structure impossible to underwrite from public evidence. Medium SV023, SV025, SV031
CV043 The call can move from Track to Buy if management proves roughly $80 million or more of ARR, more than 110% NRR, around 75% or better gross margin, and sustained multi-module adoption at a price no worse than about 10x forward ARR. Medium SV004, SV006, SV020, SV021, SV029
CV044 The bull thesis breaks if SAFE discloses a flat or down round, if module adoption stalls, or if larger platforms commoditize cyber-risk-management pricing. Medium SV004, SV006, SV025, SV031
CV045 The most decision-critical diligence asks are the ARR bridge, retention and gross-margin metrics, cap-table terms, and proof that CTEM and TPRM expansion is monetizing. Medium SV001, SV002, SV004, SV006, SV007, SV025
CV046 Tenable's implied EV-to-revenue multiple is about 4.3x on the midpoint of FY2026 guidance. Medium SV009, SV010
CV047 Qualys's implied EV-to-revenue multiple is about 6.8x on the midpoint of FY2026 guidance. Medium SV011, SV012
CV048 Rapid7's implied EV-to-ARR multiple is about 1.2x based on Q1 2026 ARR and July 2026 enterprise value. Medium SV013, SV014
CV049 Axonius's implied valuation-to-revenue multiple is about 17.2x. Medium SV015
CV050 SecurityScorecard's implied valuation-to-revenue multiple is about 6.8x. Medium SV016
CV051 BitSight's $2.4 billion Moody's-backed valuation shows cyber-risk analytics can support multibillion outcomes when a strategic buyer sees data scarcity. Medium SV017, SV018, SV019
CV052 SailPoint and Netskope show that the 2025 IPO window rewarded companies with disclosed ARR, retention, and public-market readiness rather than narrative alone. Medium SV028, SV029, SV030
Sources
IDPublisherTitleQuote
SO001 SAFE Autonomous Cyber Risk Management | SAFE
SO002 SAFE About Us Secured $33M Series A funding, led by British Telecom and John Chambers.
SO003 SAFE Contact Us
SO004 Safe Security Jobs Explore Work Locations | Safe Security Jobs
SO005 SAFE Cyber Risk Quantification (CRQ) | SAFE
SO006 SAFE Autonomous Third-Party Risk Management | SAFE
SO007 SAFE AI Security Posture Management
SO008 SAFE SAFE Raises $70 Million Series C to Build CyberAGI; Unveils World’s First Fully Autonomous CTEM Solution SAFE counts Google, Fidelity, T-Mobile, Chevron, and IHG among its customers. With this round, total funding exceeds $170 million.
SO009 PR Newswire SAFE Raises $70 Million Series C to Build CyberAGI; Unveils World’s First Fully Autonomous CTEM Solution
SO010 Entrackr Safe Security raises $70 Mn in Series C led by Avataar Ventures Founded in 2012 at IIT-Bombay by Saket Modi, Viditkumar Baxi, and Rahul Tyagi, Safe Security spent its early years bootstrapped, later relocating headquarters to Palo Alto.
SO011 FinTech Global Cyber risk leader SAFE secures $70m in Series C round
SO012 Silicon Valley Journals SAFE Raises $70 Million Series C to Build CyberAGI; Unveils World’s First Fully Autonomous CTEM Solution
SO013 SAFE SAFE Acquires Balbix, Creating the Ultimate AI-native Platform for Unified Cyber Risk & Exposure Management (Press Release) Balbix founder and CEO Gaurav Banga ... is joining SAFE as the President of CTEM.
SO014 SiliconANGLE SAFE acquires Balbix to unify AI-native exposure management and cyber risk quantification
SO015 SAFE SAFE Acquires RiskLens to become the Undisputed Leader in the $4B Cyber Risk Quantification and Management (CRQM) Market Nick Sanna, formerly CEO of RiskLens, ... will join SAFE as the President and will continue to lead the FAIR Institute.
SO016 SAFE SAFE Raises $50 Million Series B Round for AI-Driven Platform to Manage and Mitigate Cyber Risk This round brings the company’s total funding to over $100 million.
SO017 SAFE Lucideus Raises Strategic Investment, Strengthens Market Leadership
SO018 SAFE Lucideus Receives Funding, Plans to Expand Team and Business We have been bootstrapped for 4 years now and have seen significant growth year on year.
SO019 SAFE Independent Research Firm Names SAFE a Leader in Cyber Risk Quantification (CRQ) Trusted by global enterprises such as Google, Fidelity, T-Mobile, Chevron, and Peloton, SAFE has achieved over 100% year-over-year revenue growth for three consecutive years.
SO020 SAFE Liminal Names SAFE Third-Party Risk Management Leader The report ranked SAFE highest among all vendors for Product Capability.
SO021 SAFE SAFE Launches AI Security Posture Management (AI-SPM) to Enable Enterprises to Deploy AI at Scale with Confidence Trusted by 10% of Fortune 500 companies including Apple, AT&T, and Delta Airlines. SAFE has raised $170 million.
SO022 SAFE SAFE and Cisco Partner to Deliver Unified AI Risk Management with Business Impact Visibility
SO023 SAFE SAFE and SecurityScorecard Resolve Legal Dispute and Announce Research Collaboration
SO024 Cybernoz SecurityScorecard Files Suit Against Safe Security SecurityScorecard has filed a lawsuit against ... Safe Security for alleged involvement in unfair competition and misappropriating trade secrets.
SO025 Craft.co Safe Security Company Profile - Office Locations, Competitors, Revenue, Financials, Employees, Key People, Subsidiaries | Craft.co
SO026 Forbes Technology Council Saket Modi | Co-Founder and CEO - Safe Security | Forbes Technology Council He founded Lucideus in 2012 while in his final year of engineering. Incubated from IIT Bombay, headquartered in Palo Alto and backed by Cisco's former Chairman and CEO John Chambers.
SO027 Avataar Ventures Safe Security | Avataar VC Portfolio Company Founded in 2012, Safe Security began as a service-focused cybersecurity provider ... With annual revenue growth consistently exceeding 120% and total funding of $170 million.
SO028 LinkedIn Safe Security | LinkedIn Company size 51-200 employees; Headquarters Palo Alto, California; Founded 2012.
SM001 PR Newswire SAFE Security acquires RiskLens to become undisputed leader in the $4B cyber risk quantification and management market
SM002 AiThority Safe Security acquires RiskLens to become undisputed leader in the $4 billion cyber risk quantification and management market
SM003 Mordor Intelligence Cyber Risk Quantification and Scoring Platforms Market Size, Share & 2031 Growth Trends Report
SM004 FAIR Institute RiskLens, technical advisor to the FAIR Institute, joins SAFE Security
SM005 SAFE Security SAFE Named a Leader in the 2025 CRQ Wave by an Independent Research Firm
SM006 PR Newswire Independent research firm names SAFE a leader in cyber risk quantification solutions
SM007 Gartner Top cybersecurity trends CISOs must act on in 2026
SM008 Gartner Gartner identifies the top cybersecurity trends for 2026
SM009 Vectra AI CTEM explained: Gartner's 5 stages and 2026 prediction
SM010 Security Boulevard Gartner Report: Implement a Continuous Threat Exposure Management (CTEM) Program
SM011 Black Kite 2026 Third-Party Breach Report
SM012 SecurityScorecard SecurityScorecard 2025 Global Third-Party Breach Report reveals surge in vendor-driven attacks
SM013 SAFE Security Autonomous Third-Party Risk Management
SM014 PR Newswire SAFE launches industry's first fully autonomous TPRM platform, reaches $10M TPRM ARR in less than one year
SM015 U.S. Securities and Exchange Commission SEC adopts rules on cybersecurity risk management, strategy, governance, and incident disclosure An Item 1.05 Form 8-K will generally be due four business days after a registrant determines that a cybersecurity incident is material.
SM016 KPMG SEC finalizes cybersecurity rules
SM017 KPMG SEC issues rules - Enhancing cybersecurity disclosures
SM018 Munich Re Cyber insurance: Risks and trends 2026
SM019 Fitch Ratings U.S. cyber insurance growth raises underwriting risk
SM020 Insurance Business America Cyber risk investments to shape 2026 insurance market - Marsh
SM021 Mordor Intelligence GRC Software Market Size, Share & 2031 Growth Trends Report
SM022 Picus Security How to optimize cybersecurity budget in 2026
SM023 The Global Treasurer Lack of cyber risk quantification leaves companies financially exposed, PwC report finds
SM024 ExtraHop The dangers of cyber risk quantification If you go into a board meeting and say there's a $20 million risk associated with your organization being the victim of a ransomware attack, half the directors will think that's a very high estimate and half will think it's a low estimate. But all of them will think you're wrong.
SM025 PR Newswire SAFE acquires Balbix, creating the ultimate AI-native platform for unified cyber risk and exposure management
SM026 SAFE Security SAFE acquires Balbix - fact sheet
SM027 SiliconANGLE SAFE acquires Balbix to unify AI-native exposure management and cyber risk quantification
SM028 PR Newswire SAFE launches AI security posture management (AI-SPM) to enable enterprises to deploy AI at scale with confidence
SM029 SAFE Security Continuous Threat Exposure Management (CTEM)
SM030 Gartner Peer Insights Best cyber asset attack surface management reviews 2026
SM031 QY Research Global Third-Party Risk Management Software Market Research Report 2026
SM032 Global Information / Grand View Research Continuous Threat Exposure Management Market Size, Share & Trends Analysis Report
SM033 360iResearch Cyber Asset Attack Surface Management Software Market - Global Forecast 2026-2032
SM034 Mordor Intelligence Cybersecurity Market Size & Growth Trends Report 2031
SM035 Mordor Intelligence Cyber Risk Quantification and Governance Platforms Market Size, Share & 2031 Growth Trends Report
SM036 IBM What is Third-Party Risk Management (TPRM)?
SM037 Moody's TPRM 101: What is third-party risk management and why does it matter?
SP001 Safe Security SAFE Acquires RiskLens to become the Undisputed Leader in the $4B Cyber Risk Quantification and Management (CRQM) Market SAFE, the AI-Driven Cyber Risk Management company, has acquired RiskLens, the pioneer of the Cyber Risk Quantification standard – FAIR.
SP002 Safe Security SAFE Acquires Balbix, Creating the Ultimate AI-native Platform for Unified Cyber Risk & Exposure Management (Press Release) SAFE, the leader in Autonomous Cyber Risk Quantification and Management, today announced its acquisition of Balbix, a recognized Leader in Continuous Threat Exposure Management (CTEM).
SP003 Safe Security Independent Research Firm Names SAFE a Leader in Cyber Risk Quantification (CRQ) The SAFE One Platform 'the most comprehensive CRQ-native risk management solution in the market'.
SP004 Safe Security Autonomous Third-Party Risk Management | SAFE Let SAFE's 100+ AI Agents take over the boring parts of your TPRM Program.
SP005 Safe Security Benchmarking Based on FAIR, MITRE ATT&CK and other respected standards.
SP006 Safe Security SAFE vs Prevalent SAFE provides a predictable and scalable flat-rate pricing model that cuts third-party management expenses.
SP007 Safe Security SAFE vs ProcessUnity Predictable, all-inclusive pricing that reduces costs by covering unlimited vendors without additional fees.
SP008 Safe Security Safe vs Bitsight Bitsight focuses primarily on cybersecurity ratings and outside-in.
SP009 Safe Security Inside the Conversations: What Security Leaders Are Prioritizing in 2026 The conversations confirmed that security leaders are entering a new phase of cyber risk management — one where AI governance, AI security, and third-party risk are becoming deeply interconnected.
SP010 Tenable Tenable One exposure management platform Take action on cyber exposure with Tenable One, the world’s leading AI-powered exposure management platform for the AI era.
SP011 SecurityScorecard SecurityScorecard | Supply Chain & Third-Party Risk Platform A swarm of agents. An army of risk engineers. One threat-informed TPRM platform to stop risk before it spreads across your supply chain.
SP012 SecurityScorecard Supply Chain Cybersecurity Platform | SecurityScorecard Titan AI The world’s first AI-powered platform for threat-informed, continuous third-party risk management with integrated detection and response.
SP013 BitSight Cyber Risk Intelligence Platform A dynamic map of assets and vulnerabilities, prioritized by real-time threat intelligence, across your enterprise and supply chain.
SP014 Panorays Homepage Panorays AI uncovers hidden third-, fourth-, and nth-party relationships, giving you a single, consolidated view of risk.
SP015 Panorays External Attack Surface Management Continuously monitor your external attack surface and detect vulnerabilities across your digital ecosystem.
SP016 Panorays Pricing Request your quote.
SP017 Mitratech / Prevalent Prevalent The Mitratech Third-Party Risk Management solution combines automated, standardized risk assessments with continuous risk monitoring and remediation management across the entire third-party lifecycle.
SP018 OneTrust Third-Party Risk Management | Products Streamline every stage of your third-party lifecycle – from onboarding and assessment to reporting and monitoring.
SP019 ProcessUnity Third-Party Risk Management Extend the power of the ProcessUnity TPRM Platform with a subscription to the Global Risk Exchange, the world’s largest database of third-party risk assessments and curated risk profiles.
SP020 ProcessUnity ProcessUnity AI ProcessUnity AI is built on a proprietary large language model tailored for TPRM.
SP021 Vanta Plans and Pricing Request a free demo today to discuss your business needs and get personalized pricing.
SP022 Business Wire Vanta Raises $150 Million Series C Funding to Fuel Enterprise Expansion and AI Innovation Vanta, the leading trust management platform, announced today that it has raised a $150 million Series C funding round at a valuation of $2.45 billion.
SP023 CrowdStrike Outpacing Threats | CrowdStrike Falcon® Exposure Management Falcon Exposure Management gives teams real-time visibility across external assets, endpoints, cloud, network, OT/IoT, and shadow AI.
SP024 Palo Alto Networks Explore Cortex XSIAM Security Analytics The first AI-driven SOC platform that unifies proactive and reactive security to see every asset, threat and exposure with up to 99% less noise.
SP025 Rapid7 InsightVM Vulnerability Management | Rapid7 Exposure Command InsightVM is the vulnerability management technology that powers Exposure Command.
SP026 Cymulate CTEM Platform Cymulate CTEM automates exposure validation to prove exploitability, prioritizes with context of what’s already mitigated and mobilizes action.
SP027 Cymulate Exposure Validation Cymulate Exposure Validation includes Vero AI to design, build and execute offensive testing specific to your environment and threats.
SP028 Business Wire Axonius Closes $200 Million Series E at $2.6 Billion Valuation Axonius ... closed $200 million in Series E funding ... with a valuation of $2.6 billion.
SP029 PR Newswire Bitsight and Moody's Launch New Cyber Risk Solution Covering More Than 325 Million Organizations Bitsight, a global leader in cyber risk management, and Moody's ... announced the launch of the Implied Cyber Threat (ICT) ... for more than 325 million organizations worldwide.
SP030 Forrester Announcing The Forrester Wave™: Cyber Risk Quantification Solutions, Q2 2025 Several vendors have expanded into adjacent markets and now offer CRQ-powered capability for vulnerability and exposure management, threat intelligence, third-party risk, cyber insurance, application security, control monitoring, and compliance assessments.
SP031 Safe Security Forrester Wave™: Cyber Risk Quantification Solutions Report The only vendor with FAIR-CAM.
SP032 Safe Security Liminal Names SAFE Third-Party Risk Management Leader SAFE was highlighted for delivering autonomous, end-to-end third-party risk management powered by Agentic AI.
SP033 Safe Security SAFE Named a Leader by Liminal for Third-Party Risk Management SAFE was rated #1 in Product Capability among top vendors and outperformed other leaders in practitioner satisfaction by 8%.
SP034 Safe Security RiskLens, a SAFE Company, Named a Leader in a Cyber Risk Quantification Report by an Independent Research Firm RiskLens, a SAFE Company, Named a Leader in a Cyber Risk Quantification Report by an Independent Research Firm
SP035 Safe Security Autonomous Cyber Risk Management | SAFE Put AI to Work with SAFE's Agentic Workflow Engine
SP036 Safe Security Cyber Risk Quantification (CRQ) | SAFE Cyber Risk Quantification (CRQ) | SAFE
SP037 PR Newswire SAFE Acquires Balbix, Creating the Ultimate AI-native Platform for Unified Cyber Risk & Exposure Management SAFE acquires Balbix, creating the ultimate AI-native platform for unified cyber risk & exposure management.
SI001 Safe Security SAFE Raises $70 Million Series C to Build CyberAGI; Unveils World’s First Fully Autonomous CTEM Solution Since launching TPRM in 2024, over 50% of SAFE’s customers have adopted the module.
SI002 PR Newswire SAFE Raises $70 Million Series C to Build CyberAGI; Unveils World's First Fully Autonomous CTEM Solution SAFE counts Google, Fidelity, T-Mobile, Chevron, and IHG among its customers. With this round, total funding exceeds $170 million.
SI003 Entrackr Safe Security raises $70 Mn in Series C led by Avataar Ventures The fresh capital will be used to accelerate Safe's ‘CyberAGI’ vision, growing its engineering, go-to-market, and R&D.
SI004 FinTech Global Cyber risk leader SAFE secures $70m in Series C round SAFE’s client roster includes Google, Fidelity, T-Mobile, Chevron and IHG. It has now raised over $170m in total.
SI005 Safe Security About Us SAFE unifies Cyber Risk Management (CRQ), Continuous Threat Exposure Management (CTEM), and Third-Party Risk Management (TPRM) into a single platform.
SI006 Safe Security SAFE Raises $50 Million Series B Round for AI-Driven Platform to Manage and Mitigate Cyber Risk Despite economic headwinds, SAFE has been growing over 200% for three consecutive years.
SI007 Safe Security SAFE Acquires RiskLens to become the Undisputed Leader in the $4B Cyber Risk Quantification and Management (CRQM) Market Having raised over $100M, SAFE is growing over 200% year over year, consecutively for the last three years.
SI008 Safe Security The SAFE x RiskLens Acquisition Will Transform Cyber Risk Management Integrating FAIR’s rigorous decade-long research and SAFE’s automated processing capability of over 3 billion signals daily will provide organizations with unmatched confidence.
SI009 Safe Security SAFE Acquires Balbix, Creating the Ultimate AI-native Platform for Unified Cyber Risk & Exposure Management (Press Release) Trusted by industry leaders including Google, Fidelity, T-Mobile, Chevron, and IHG, SAFE has achieved triple-digit revenue growth every year since the launch of its platform in 2020.
SI010 Safe Security SAFE Acquires Balbix For the first time, cybersecurity programs can be framed by ROI at planning – and monitored every day as risk is burned down.
SI011 Safe Security Customers At SAFE, we have had the privilege of standing shoulder to shoulder with hundreds of visionaries and change-makers.
SI012 Safe Security SAFE TPRM | Datasheet SAFE is available via AWS Marketplace.
SI013 Safe Security SAFE CTEM Datasheet, 2026 SAFE isolates the 1–5% of exposures that actually increase attack risk.
SI014 Safe Security SAFE CRQ | Datasheet | 2025 SAFE enables precise project prioritization, budget justification, and tech stack rationalization by mapping every security initiative against its expected reduction in financial exposure.
SI015 Safe Security Autonomous TPRM at Enterprise Scale with SAFE and AWS Access custom pricing and terms through AWS Private Offers to accelerate procurement cycles.
SI016 Safe Security T-Mobile: Cutting the Cord on Subjective Risk Scores T-Mobile further automated its processes, implemented new integrations to monitor more than 1 million digital assets, and tightened its loss event controls.
SI017 Safe Security Instacart: Designing TPRM and Delivering Risk Singularity SAFE’s autonomous TPRM platform was the perfect fit for Instacart… with a flat pricing model that allows the team to scale without adding time, headcount, or cost.
SI018 Safe Security Kyriba: Scaling with Efficiency & Transparency Moved from a pay-per-vendor model to assessing 100% of their third-party ecosystem with SAFE’s flat pricing.
SI019 Safe Security SAFE to Replace SecurityScorecard and Bitsight with the Industry's First Risk-Based Third-Party Management Platform that Radically Reduces Cost and Time Receive SAFE TPRM at half the cost for the first year… Bonus = no limit to vendors.
SI020 U.S. Securities and Exchange Commission EDGAR Search Results The browse page lists Form D filings for 2017, 2018, 2020, and 2021.
SI021 U.S. Securities and Exchange Commission EDGAR Filing Documents for 0001700214-21-000002 Form D - Notice of Exempt Offering of Securities: SEC Accession No. 0001700214-21-000002.
SI022 U.S. Securities and Exchange Commission SAFE Securities Inc. Form D primary XML disclosure The filing shows a $25,000,004 offering with $14,999,988 sold and $10,000,016 remaining.
SI023 U.S. Securities and Exchange Commission Zscaler Annual Report on Form 10-K Gross margin decreased from 78% to 77% for fiscal 2025 as compared to fiscal 2024.
SI024 U.S. Securities and Exchange Commission CrowdStrike Annual Report on Form 10-K Subscription revenue accounted for 95% of total revenue for each of fiscal 2026 and fiscal 2025.
SI025 The Org Safe Security | The Org The Org page shows named executives and only small visible team slices, not a total company headcount.
SI026 Avataar VC Avataar VC Portfolio – Showcasing Our Investment Success Stories Safe Security… has evolved into a product-led company trusted by Fortune 500 clients like Google, Netflix, and British Telecom.
SI027 Sorenson Capital Safe Security - Sorenson Capital Safe Security is a cyber risk management platform that empowers enterprises, boards, regulators, and cyber insurance carriers to understand cyber risk in an aggregated and granular manner.
SI028 Macrotrends via Internet Archive Zscaler Gross Margin 2016-2025 | ZS As of 2025-07-31 the page lists $2.67B of TTM revenue, $2.05B of TTM gross profit, and 76.84% gross margin for Zscaler.
SI029 Silicon Valley Journals SAFE Raises $70 Million Series C to Build CyberAGI; Unveils World’s First Fully Autonomous CTEM Solution Nishant Rao said most cybersecurity sub-sectors are either overcrowded or limited to tactical, widget-like solutions.
SE001 Safe Security SAFE One: One Platform. All Exposures.
SE002 Safe Security Cyber Risk Quantification (CRQ) | SAFE
SE003 Safe Security Continuous Threat Exposure Management (CTEM) | SAFE
SE004 Safe Security Autonomous Third-Party Risk Management | SAFE
SE005 Safe Security AI Security Posture Management
SE006 Safe Security AI Agents
SE007 Safe Security Integrations
SE008 Safe Security Security SAFE encrypts the customers’ data at rest using the AES 256-bit AWS KMS key.
SE009 Safe Security AI Policy No customer data is used to train shared or cross-tenant models; data is processed in a tenant-isolated manner.
SE010 Safe Security SAFE Acquires RiskLens to become the Undisputed Leader in the $4B Cyber Risk Quantification and Management (CRQM) Market
SE011 Safe Security SAFE Acquires Balbix, Creating the Ultimate AI-native Platform for Unified Cyber Risk & Exposure Management (Press Release) For the first time, organizations can run on a single, living source of truth, enabling remediation, reporting, and resource allocation to be driven by a unified, real-time understanding of cyber risk.
SE012 Safe Security SAFE Acquires Balbix - Fact Sheet
SE013 Safe Security SAFE Raises $70 Million Series C to Build CyberAGI; Unveils World’s First Fully Autonomous CTEM Solution Alongside the funding, SAFE unveiled the most transformative upgrade to its Cyber Risk Singularity platform yet: the world’s first fully autonomous Continuous Threat Exposure Management (CTEM) solution, powered by Agentic AI.
SE014 Safe Security SAFE Launches Industry's First Fully Autonomous TPRM Platform, Reaches $10M TPRM ARR in Less than One Year Today, the company launched the industry’s first fully autonomous TPRM platform—built on a system of specialized AI agents that automate the entire vendor risk lifecycle.
SE015 Safe Security SAFE Expands to 50 Technology Integrations to Make Cyber Risk Quantification and Management More Trustworthy and Accessible to All
SE016 Safe Security T-Mobile: Cutting the Cord on Subjective Risk Scores
SE017 Safe Security Instacart: Designing TPRM and Delivering Risk Singularity
SE018 Safe Security Docs Workflows Overview
SE019 Safe Security Docs Accessing SAFE APIs
SE020 Safe Security Docs GitHub Integration
SE021 PR Newswire Independent Research Firm Names SAFE a Leader in Cyber Risk Quantification (CRQ) Solutions The SAFE One Platform is “the most comprehensive CRQ-native risk management solution in the market” and SAFE is “the only vendor to have implemented FAIR-CAM.”
SE022 SiliconANGLE SAFE acquires Balbix to unify AI-native exposure management and cyber risk quantification
SE023 BankInfoSecurity KPMG Climbs, ThreatConnect Falls in Latest Cyber Risk Quantification Forrester Wave
SE024 FAIR Institute RiskLens Technical Advisor FAIR Institute Safe Security Think “automated FAIR.”
SE025 FAIR Institute From cyber risk quantification to decision intelligence
SE026 PR Newswire SAFE Launches AI Security Posture Management (AI-SPM) to Enable Enterprises to Deploy AI at Scale with Confidence
SE027 GARP Superintelligence May Exacerbate Cybersecurity Weaknesses. Is CyberAGI the Solution? AI systems are only as good as their training data. Many organizations have fragmented, inconsistent security telemetry.
SE028 PeerSpot SAFE One vs SecurityScorecard comparison As of July 2026, in the IT Vendor Risk Management category, the mindshare of SAFE One is 0.9% ... Number of Reviews: 0.
SE029 AWS Marketplace SAFE One on AWS Marketplace
SE030 API Tracker Safe Security API - Developer docs, APIs, SDKs, and auth.
SE031 FeaturedCustomers 34 Safe Security Customer Reviews & References
SU001 SAFE Autonomous Cyber Risk Management | SAFE 10% of Fortune 500 put AI to work with SAFE.
SU002 SAFE Customers: Cybersecurity Risk Quantification & Management (CRQM) - Safe Security How T-Mobile Scaled Cyber Risk Management Across Over 1 Million Digital Assets.
SU003 SAFE About Us
SU004 SAFE Customer Stories Archives Customer Stories — May 14, 2026: Aboitiz Power; OB Hospitalist Group; Feb 23, 2026: Carvana; Feb 16, 2026: T-Mobile; Feb 02, 2026: Kyriba; Jan 26, 2026: Instacart.
SU005 SAFE T-Mobile: Cutting the Cord on Subjective Risk Scores Using SAFE One’s integrations that provided continuous data, the team was able to rapidly assess controls and prioritize remediation in just a week — a 75% reduction in reporting time.
SU006 SAFE Instacart: Designing TPRM and Delivering Risk Singularity In just three weeks, Instacart operationalized SAFE TPRM, onboarding and assessing 600+ third parties.
SU007 SAFE Kyriba: Scaling with Efficiency & Transparency After adopting SAFE TPRM, Kyriba onboarded 290+ vendors in under a week.
SU008 SAFE Carvana: Driving Cyber Resilience Up, Insurance Down The company experienced a 40% reduction in breach likelihood within 9 months.
SU009 SAFE Aboitiz Power: Powering Data-Driven Decisions 370% program effectiveness; $1.6M+ savings from right-sizing security controls.
SU010 SAFE OB Hospitalist Group: Quantifying Cyber Risk to Drive Clinical Confidence 70% Reduction in vendor assessment cycle time; 10+ Hours Saved per week.
SU011 SAFE Victoria's Secret: Pioneering the Future of Cyber Risk Management Victoria’s Secret & Co. became a key design partner in the development of the FAIR Control Analytics Model (CAM).
SU012 SAFE Glovo Customer Spotlight SAFE One allows them to quantify the decrease in likelihood associated with maturing such controls as well as compare reduction in ALE against the cost of the control.
SU013 SAFE Shelter Insurance Customer Spotlight SAFE is the tool we use to share our risk story and security concerns in non-technical terms.
SU014 SAFE ISO New England Customer Spotlight These data and insights support communication among board members, PMO team, developers and security analysts alike.
SU015 SAFE Booz Allen Hamilton Customer Spotlight 50% reduction in Time-to-Value across all Service Lines.
SU016 SAFE Celebrating the Visionaries … the Changemakers That is what has enabled us to continuously grow over 100% y/y every year since going live with our platform in mid-2020.
SU017 SAFE SAFE Raises $70 Million Series C to Build CyberAGI; Unveils World’s First Fully Autonomous CTEM Solution Since launching TPRM in 2024, over 50% of SAFE’s customers have adopted the module.
SU018 SAFE SAFE Launches Industry's First Fully Autonomous TPRM Platform, Reaches $10M TPRM ARR in Less than One Year The company has also crossed $10M in TPRM ARR in less than one year from launching its TPRM offering.
SU019 SAFE SAFE and Booz Allen Hamilton Launch a Next-Generation Integrated Risk Management-as-a-Service (IRMaaS) Offering SAFE and Booz Allen Hamilton Launch a Next-Generation Integrated Risk Management-as-a-Service (IRMaaS) Offering.
SU020 SAFE Autonomous TPRM at Enterprise Scale with SAFE and AWS Access custom pricing and terms through AWS Private Offers to accelerate procurement cycles.
SU021 SAFE Community IHG Hotels Customer Spotlight | Community SAFE has added a new capability that has aided IHG in achieving its desired business outcomes, including the ability to understand and communicate top risks across IHG’s HVAs.
SU022 Gartner Safe Security Enterprise Software and Services Reviews Safe Security is present in 5 markets with 6 products. Safe Security has 99 reviews with an overall average rating of 4.5.
SU023 TrustRadius Safe Security Reviews & Ratings 2026 | TrustRadius The SAFE platform establishes a common language to talk with the C-Suite and the Board.
SU024 FeaturedCustomers 34 Safe Security Customer Reviews & References Customer Rating Review Score based on 1263 reference ratings: 4.8/5.0.
SU025 Indian Startup News Saket Modi's SAFE Security raises $70 million in funding to build CyberAGI SAFE counts Google, Fidelity, T-Mobile, Chevron, and IHG among its customers.
SU026 T-Mobile Online Safety Resources | T-Mobile Privacy Center At T-Mobile, we work hard to keep your information safe with state-of-the-art cybersecurity technology, rigorous monitoring and response operations, and strict compliance to global industry standards.
SU027 IHG Hotels & Resorts Home We are one of the world’s leading hotel companies.
SU028 IHG Hotels & Resorts Policies and Position Statements IHG requires new corporate suppliers to confirm their acceptance of the Supplier Code of Conduct at the onboarding stage.
SU029 Chevron Chevron Corporation - Human Energy Chevron is expanding into the power-for-AI business to deliver dedicated, on-site electricity to a next-generation Microsoft data center.
SU030 Chevron Cybersecurity Although we experience cyber incidents in our business, including breaches, we have taken actions to mitigate the impact of these incidents through our cybersecurity safeguards.
SU031 Fidelity Investments About Fidelity Investments - Financial Services Headquartered in Boston, Massachusetts, we employ over 80,000 associates across 11 countries, 14 global regional sites, and 215 Investor Centers.
SU032 Fidelity Investments Account Data Security at Fidelity Our goal is to strengthen and secure the financial wellbeing of our customers.
SU033 Google About Google: Our products, technology and company information Google around the globe.
SR001 Safe Security Privacy Policy SAFE Securities is the data processor for the processing of your personal information when it is processing such information on behalf of a customer.
SR002 Safe Security Terms of Service Neither company nor end user warrants that the operation or output of the services will be uninterrupted, error-free, secure, accurate, reliable, or complete.
SR003 Safe Security AI Policy No customer data is used to train shared or cross-tenant models.
SR004 Safe Security Security SAFE encrypts the customers’ data at rest using the AES 256-bit AWS KMS key.
SR005 Safe Security SAFE One: One Platform. All Exposures. Unified visibility across AI vendors including OpenAI, Claude, Copilot, Gemini and any key AI vendors.
SR006 Safe Security SAFE AURA: Trustable Intelligence for Cyber Risk Decisions SAFE AURA evaluates AI systems across seven key dimensions of trust, including accuracy, explainability, safety, reliability, latency, human oversight, and business impact.
SR008 Safe Security Safe Security SOC 3 Report 2026 Throughout the period January 01, 2025 to November 30, 2025.
SR009 Safe Security SAFE Acquires Balbix, Creating the Ultimate AI-native Platform for Unified Cyber Risk & Exposure Management Gaurav Banga, Founder and CEO of Balbix, is joining SAFE as the President of CTEM.
SR010 Safe Security SAFE Acquires Balbix - Fact Sheet No product has been able to link technical vulnerabilities to strategic business risk. We unify CTEM, CRQ and TPRM in one holistic cyber risk management platform, connected with AI.
SR011 Safe Security SAFE Acquires RiskLens to become the Undisputed Leader in the $4B Cyber Risk Quantification and Management (CRQM) Market Nick Sanna, formerly CEO of RiskLens, will join SAFE as the President and will continue to lead the FAIR Institute.
SR012 Safe Security SAFE Raises $70 Million Series C to Build CyberAGI; Unveils World’s First Fully Autonomous CTEM Solution With this round, total funding exceeds $170 million.
SR013 Safe Security SAFE and SecurityScorecard Resolve Legal Dispute and Announce Research Collaboration SAFE and SecurityScorecard today announced that they have resolved their recent legal dispute and are moving forward with a collaborative research partnership.
SR014 Safe Security SAFE Joins Forces with AWS: Empowering Cloud Security through Strategic AWS Marketplace Offerings By listing on the AWS Marketplace, SAFE not only simplifies procurement and deployment of its solutions but also ensures that organizations can leverage their AWS investments to gain enhanced visibility into cyber risks.
SR015 Safe Security Autonomous TPRM at Enterprise Scale with SAFE and AWS Purchase SAFE TPRM directly through your AWS account with streamlined contracting and consolidated billing.
SR017 PR Newswire Safe Security Raises $50 Million Series B Round for AI-Driven Platform to Manage and Mitigate Cyber Risk Safe Security Raises $50 Million Series B Round for AI-Driven Platform to Manage and Mitigate Cyber Risk.
SR018 U.S. Securities and Exchange Commission SEC Adopts Rules on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure by Public Companies An Item 1.05 Form 8-K will generally be due four business days after a registrant determines that a cybersecurity incident is material.
SR019 U.S. Securities and Exchange Commission Final Rule: Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure An Item 1.05 Form 8-K must be filed within four business days of determining an incident was material.
SR020 European Commission Standard Contractual Clauses (SCC) On 4 June 2021, the Commission issued modernised standard contractual clauses under the GDPR for data transfers from controllers or processors in the EU/EEA to controllers or processors established outside the EU/EEA.
SR021 EUR-Lex Implementing decision - 2021/914 - EN Implementing decision - 2021/914 - EN.
SR022 Press Information Bureau, Government of India Digital Personal Data Protection (DPDP) Rules, 2025 The highest penalty up to ₹250 crore applies to failure of a Data Fiduciary to maintain reasonable security safeguards.
SR023 Information Technology and Innovation Foundation India’s Cross-Border Data Transfer Regulation India’s negative-list approach preserves government discretion over future transfer restrictions.
SR026 Harvard Law School Forum on Corporate Governance SolarWinds Dismissed: What the SEC’s U-turn Signals for Cyber Enforcement The SEC’s cyber disclosure regime still leaves issuers and their vendors exposed to materiality and process questions.
SR027 American Bar Association Oracle Cloud Breaches Lead to CISA Guidance and Lawsuits The Oracle breaches have led to multiple lawsuits as well.
SR028 Infosecurity Magazine US Data Breach Lawsuits Total $155M Amid Cybersecurity Failures US companies paid out a total of $155m in class action lawsuits related to data breaches over the last six months.
SR029 The Hacker News Between Buzz and Reality: The CTEM Conversation We All Need CTEM isn’t plug-and-play.
SR030 arXiv QBER: Quantifying Cyber Risks for Strategic Decisions Current approaches still need to work on blending economic viewpoints to provide insightful analysis.
SR032 SC Media The state of continuous threat exposure management A CTEM program may be difficult to set up, as it involves implementing and coordinating different tools that are perhaps not well suited to working with each other.
SR033 Infosecurity Magazine Qualys, Tenable Latest Victims of Salesloft Drift Hack Cybersecurity providers Tenable and Qualys are the latest in a growing list of companies affected by a significant supply chain attack targeting Salesforce customer data.
SR034 Help Net Security A Full Recap of Salesforce Supply-Chain Nightmare: How One Breach Impacted 700+ Organizations The blast radius? 700+ organizations, including major tech and cybersecurity firms.
SR037 TechStrong AI AI, Cybersecurity Roles Top 2026 Hiring Priorities: Survey While 91% of organizations are prioritizing AI-skilled hires this year, 39% identify AI engineers as the hardest role to fill, narrowly edging out cybersecurity engineers (38%).
SR038 The Economic Times Cybersecurity startup Safe Security raises $70 million from Avataar Ventures, others Safe Security currently has around 200 employees, with its research and development team of 100 based in India.
SR039 SiliconANGLE SAFE acquires Balbix to unify AI-native exposure management and cyber risk quantification SAFE Securities Inc. today announced that it has acquired cybersecurity posture firm Balbix Inc. for an undisclosed sum.
SR040 Enterprise Security Tech SAFE’s Balbix Acquisition Signals the First Real Shot at Autonomous Cyber Risk Management Is this true cyber autonomy? Not yet.
SR043 AmbitionBox Safe Security Reviews by 20+ Employees | Rated 2.5/5 With an overall rating of 2.5 out of 5 from over 29 employee reviews, it is clear that most employees have a below average experience working at Safe Security.
SV001 PR Newswire SAFE raises $70 million Series C to build CyberAGI, unveils world's first fully autonomous CTEM solution SAFE has achieved triple-digit revenue growth for three consecutive years and raised over $170 million to date.
SV002 Safe Security SAFE Series C and CTEM launch press release SAFE today announced a $70 million Series C funding round.
SV003 Entrackr Safe Security raises $70 Mn in Series C led by Avataar Ventures
SV004 Safe Security SAFE named leader in 2025 Forrester CRQ Wave SAFE earned the highest possible scores in 21 criteria.
SV005 PR Newswire Independent research firm names SAFE a leader in cyber risk quantification solutions SAFE has achieved over 100% year-over-year revenue growth for three consecutive years.
SV006 Safe Security SAFE named as leader in Liminal's Cybersecurity Third-Party Risk Management Link Index report Rated #1 in product capability among top vendors.
SV007 Safe Security SAFE One platform product overview
SV008 Safe Security Cyber risk quantification product page 73% Reduction in Assessment & Reporting Time.
SV009 Tenable Investor Relations Tenable announces first quarter 2026 financial results
SV010 Stock Analysis Tenable Holdings market cap
SV011 Qualys Investor Relations Qualys announces first quarter 2026 financial results
SV012 Stock Analysis Qualys market cap
SV013 Rapid7 Investor Relations Rapid7 announces first quarter 2026 financial results
SV014 Stock Analysis Rapid7 statistics and valuation
SV015 Latka Axonius company profile
SV016 Latka SecurityScorecard company profile
SV017 SecurityWeek BitSight raises $250 million at $2.4 billion valuation
SV018 TechCrunch BitSight raises $250M from Moody's and acquires VisibleRisk
SV019 Moody's Investor Relations Moody's and BitSight partner to create integrated cybersecurity risk platform The transaction values BitSight at $2.4 billion.
SV020 Windsor Drake Cybersecurity valuation report The broader public cybersecurity market trades at about 7.8x revenue right now.
SV021 Windsor Drake SaaS valuation multiples
SV022 Finro CA Cybersecurity valuation multiples mid-2025 Public cybersecurity companies trade at a significantly lower average of 7.8x revenue, compared to 15.2x in private transactions and 16.3x in M&A.
SV023 Clipperton Cybersecurity Market Monitor 2025 Low performers traded at a median 4.5x EV/Revenue.
SV024 First Analysis Cybersecurity March 2026 sector analysis The median stock declined 18% over the past year.
SV025 Premier Alternatives SAFE Security valuation SAFE Security is currently valued at $368.3M as of December 31, 2025.
SV026 Google Google closes acquisition of Wiz
SV027 Acquiry Google-Wiz acquisition analysis Paying 45-65x ARR for a company that is not yet profitable is a bet on future growth, not current value.
SV028 SailPoint Investor Relations SailPoint announces pricing of upsized initial public offering
SV029 U.S. Securities and Exchange Commission SailPoint S-1 registration statement
SV030 CNBC Netskope prices IPO at $19, valuing company at $7.3 billion
SV031 NY Venture Hub Navigating the downside: the rise of down rounds in 2024 VC deals Flat and down rounds reached 27.4% of all VC deals in Q1 2024, the highest level in ten years.
SV032 Tenable Investor Relations Tenable announces fourth quarter and full year 2025 financial results
SV033 Rapid7 Investor Relations Rapid7 announces fourth quarter and full-year 2025 financial results