初创公司尽调
尽调报告 Cybersecurity / digital fraud prevention Private growth stage 2026-06-19

HUMAN Security

面向互联网规模的机器人、欺诈与智能体信任平台

HUMAN Security 在战略上与市场需求高度相关,披露规模和网络安全同业基准显示估值或许合理;但 ARR 质量、留存、利润率和债务状态的公开证据还不够强,无法支撑高确信度投资结论。

封面要素

每周验证交互 06
20T+ interactions [CO007, CI006]
成立时间 07
2012 [CO001]
总部 08
New York City [CO005]

公司概况

HUMAN Security 2012 年以 White Ops 名义成立,2021 年更名;业务从广告欺诈检测扩展为更宽的数字信任平台。公司如今销售 Human Defense Platform,覆盖媒体安全、应用安全、账户保护和智能体信任等场景,以互联网规模运行,每周验证 20T+ 次交互,服务 500+ 个客户品牌。2020 年 Goldman Sachs/ClearSky/NightDragon 收购、2022 年 PerimeterX 合并、2024 年成长轮融资之后,所有权和治理结构明显变化。尽管战略位置强、产品市场相关性清晰,收入增长、留存、利润率和当前估值仍不透明。

官网
www.humansecurity.com
成立时间
2012-01-01
创始人
Tamer Hassan, Michael Tiffany, Dan Kaminsky, Ash Kalb
创立地点
Brooklyn, New York, USA
总部
New York City, New York, USA
产品
Human Defense Platform 把机器人缓解、广告欺诈检测、应用和账户滥用防御、威胁情报,以及 HUMAN Sightline、AgenticTrust 等较新的智能体 AI 治理产品整合在一起。平台借助大规模遥测、设备情报、行为信号和 Satori Threat Intelligence 团队,实时识别并打断恶意自动化。
客户
大型数字业务、广告技术和媒体平台、市场平台、零售商、金融服务公司,以及需要减少欺诈、无效流量、抓取、账户接管和 AI 智能体滥用的企业安全团队。
商业模式
企业网络安全软件和托管情报平台,通过直销和合作伙伴渠道销售,覆盖媒体安全、应用安全、账户保护和信任层工作流。
阶段
Private growth stage
融资情况
股权融资总额约 $300M。最新融资:2024 年 10 月宣布的 $50M+ 成长轮,由 WestCap 领投,Goldman Sachs Asset Management、ClearSky Security、NightDragon 和 Vertex Ventures US 参投。2022 年还披露了 Blackstone Credit 提供的 $100M 信贷额度。
[CO001, CO004, CO005, CO006, CO007, CO010, CO021, CO025]

执行摘要

主要优势

  • 基于每周 20T+ 次已验证交互,搭建了互联网级遥测和威胁情报网络。
  • Goldman Sachs、WestCap、NightDragon、ClearSky 和 Vertex 等机构投资人多轮支持,股东质量强。
  • 产品覆盖媒体安全、应用保护、账户滥用防护和智能体 AI 信任。
  • 2026 年获得 Forrester 领导者评级等可信外部认可,客户评价面也较强。

主要风险

  • 公开财务信息不透明,ARR 质量、留存、利润率和债务负担仍缺乏实质验证。
  • Cloudflare、Akamai、Google 等平台厂商打包竞争,可能挤压独立产品定价权。
  • 行为数据和指纹识别模型面临持续变化的隐私与数据跨境监管。
  • AWS/云集中度和实时检测要求带来显著运营中断风险。
  • 广告科技出身可能在退出时把估值倍数压到纯网络安全同业以下。

未决问题

  • 经审计或管理层确认的 ARR、增长和按产品分部划分的收入结构。
  • 按客户分层拆分的净收入留存、总留存、流失率和平均合同期限。
  • 威胁情报、云基础设施和服务之间的毛利率与收入成本拆分。
  • 2022 年 Blackstone Credit 信贷额度的当前未偿余额、到期日和契约条款。
  • 2024 年之后的最新估值、清算优先权和股权结构集中度。

目录

Chapter 01

01公司概览

1.1 身份、总部与平台模式

HUMAN Security, Inc. 是一家私人持有的网络安全公司,总部位于纽约市,另在 Miami、Santa Clara、Tel Aviv(Israel)和 United Kingdom 设有办公室。公司 2012 年由 Tamer Hassan、Michael Tiffany、Dan Kaminsky 和 Ash Kalb 在 New York 的 Brooklyn 以 White Ops 名义创立。2021 年,公司更名为 HUMAN Security,反映业务范围从广告欺诈扩展到全栈企业和消费者安全。公司把自己定位为媒体和智能体商务平台的信任层,负责验证互动、减少欺诈,并让人类、机器人和 AI 智能体之间的真实交互得以发生。 HUMAN 的核心商业产品是 Human Defense Platform(HDP)。公司将其定位为统一平台,覆盖三大支柱:Media Security(数字广告欺诈、无效流量检测和广告完整性)、Application and Enterprise Security(账户接管、撞库、虚假账户创建、网页抓取和盗刷测试),以及 Account Protection(身份和认证欺诈)。平台披露的规模指标是:每周在 30 亿台独立设备上验证超过 20 万亿次数字交互;每次交互使用 2,500+ 个信号,由 400+ 个自适应机器学习模型分析,在毫秒级做出机器人或人类的二元判断。公司服务媒体、金融、零售、政府、教育和企业安全等垂直领域的 500+ 个全球品牌。 截至 2026 年中,HUMAN 已把平台扩展到智能体 AI 时代,推出 HUMAN Sightline Cyberfraud Defense 和 AgenticTrust。前者是统一的信任与防御层,保护数字业务在完整客户旅程中免受机器人攻击、人为欺诈、交易滥用和 AI 驱动风险;后者让客户检测、分类并治理在其平台上运行的 AI 智能体。HUMAN 还运营 Satori Threat Intelligence and Research Team,负责威胁情报,并协调对网络犯罪行动的公私联合打击。公司称,按每周交互量计算,其竞争位置是全球最大的威胁检测网络。收入模式和定价仍未公开。 [CO001, CO003, CO004, CO005, CO006, CO007]

快照 KPI 表
指标数值 / 状态日期置信度缺口
成立2012(以 White Ops 名义)2012
更名为 HUMAN Security20212021
总部美国纽约州纽约市
运营状态私营;以 Goldman Sachs Merchant Banking 为锚
每周验证的数字交互>20 trillion2026-06公司自报;未确认独立审计
覆盖的独立设备3 billion2026-06公司声称;无法独立验证
服务的客户 / 品牌500+2026-06公司声称;未发布客户名单
员工(人数)~400(截至 2024 年 10 月);~437(2026 年中估算)2024-10当前准确人数未公开确认
累计融资~$299-300M(股权);另有 $100M Blackstone 债务2024-10聚合商估算;公司未确认准确总额
最近披露估值~$1.5B(2022 年 1 月轮次)2022-012022 年后未披露估值;数字已经过时
收入 / ARR未公开披露私营公司;完整尽调需要进入数据室
Forrester Wave 排名领导者(2026 年二季度 Bot and Agent Trust Management)2026-06-15

HUMAN 发布的所有规模主张(20 trillion 次交互、3 billion 台设备、500+ 个品牌)均为公司自报,未经过独立审计。除非另有说明,员工和收入数字均为数据聚合商的第三方估算。$1.5B 估值来自 2022 年 1 月融资轮,距今已超过四年。

[CO001, CO004, CO005, CO007, CO008, CO038]
FO003: 快照 KPI

HUMAN 的规模和认可度指标很强;财务指标为私有,若无数据室访问,公开尽调拿不到。

[CO007, CO008, CO027, CO041, CO042, CO043]

1.2 创始人、领导层、董事会与关键人风险

HUMAN 由四人创立:Tamer Hassan(CEO 任至 2024 年 1 月,现任执行董事长)、Michael Tiffany、Dan Kaminsky 和 Ash Kalb。Hassan 是公司前十二年最主要的公开面孔,2019 年被 Fast Company 评为商业领域最具创造力人物第一名。他主导了 White Ops 更名、与 PerimeterX 合并、收购 clean.io,以及公司 ARR 突破 $100M。2024 年 1 月,Hassan 转任董事会成员和执行董事长,仍积极参与战略、客户关系和公共政策倡导。因此,联合创始人网络仍部分保留:Hassan 保有治理角色,而截至 2026 年 6 月研究日,另外三位创始成员未在公开资料中列为现任高管。 2024 年 1 月,曾任 Recorded Future(全球最大的威胁情报提供商)总裁的 Stu Solomon 出任 CEO。Solomon 拥有 Optiv(包括 CTO 任职)、iSight Partners(后被 FireEye 收购)和 Bank of America 的高管及 C-suite 经验,还在 Delaware Air National Guard 和 United States Air Force 服役超过 25 年。HUMAN 当前高管团队还包括 Isaac Itenberg(首席运营官兼首席财务官)、Gavin Reid(首席信息安全官)和 Christos Kalantzis(首席技术官)。截至 2026 年研究日,董事会包括来自 Goldman Sachs(Anthony Arnold)、NightDragon(Dave DeWalt)、WestCap(Kevin Marcus)和 ClearSky(Jay Leek)的董事,以及 Tamer Hassan(执行董事长)和因 PerimeterX 合并加入董事会的 Ido Safruti。对公开记录和公司公告的检索未发现 Matt Cantor 出现在 HUMAN Security 当前或近期领导层、高管团队或董事会中。 Hassan 向 Solomon 交接 CEO 后,关键人风险有所改善,战略执行分散到一支外部经验更丰富的管理团队。但董事会仍以投资人代表为主(Goldman Sachs、NightDragon、WestCap、ClearSky),公司威胁情报身份和客户关系仍通过 Hassan 的执行董事长角色带有一定创始人印记。董事会还列出八名观察员(Ryan Benevides、Dan Burns、Itzhak Fisher、Steve Fredrick、Rhys Gordon、Hannah Huffman、Lance Matthews、Alexander Weiss),其所属机构和控制权意义未在当前来源集中公开披露。完整董事会构成和治理条款仍是尽调缺口。 [CO002, CO011, CO012, CO013, CO014, CO015]

领导层与创始人表
人员角色背景创始人-市场匹配 / 职能覆盖关键人依赖
Tamer Hassan联合创始人;执行董事长(自 2024 年 1 月起;CEO 任至 2024 年 1 月)连续网络安全创业者;Fast Company 2019创始愿景;市场定位;客户关系;公共政策;董事会治理高:尽管完成 CEO 交接,公司身份、品牌和客户网络仍与 Hassan 紧密绑定
Stu SolomonCEO(自 2024 年 1 月起)Recorded Future 总裁(5 年);Optiv CTO;iSight Partners 高管;Bank of America;Delaware Air National Guard / USAF 25+ 年运营扩张;网络安全市场进入;公共部门扩张;数据科学投资策略高:交接后唯一公开面对市场的 CEO;所有战略和资本配置决策都经由 Solomon
Michael Tiffany联合创始人White Ops 联合创始人;具备 bot detection 和网络安全研究背景创始技术愿景;核心 bot-or-not 检测方法低到中:未列入当前高管或董事会角色;当前运营角色不清楚
Dan Kaminsky联合创始人(2021 年去世)知名安全研究员;发现关键 DNS 漏洞;White Ops 联合创始人创始威胁情报理念;Satori 团队传承历史性:Kaminsky 于 2021 年 4 月去世;其影响嵌入平台 DNA,而非参与当前运营
Ash Kalb联合创始人联合创始人;具备网络安全产品开发背景创始产品与业务开发贡献低到中:未列入当前高管或董事会角色;当前角色不清楚
Isaac Itenberg首席运营官兼首席财务官资深运营与财务高管运营执行;财务管理;公司监督中:COO/CFO 双重角色集中运营和财务权力
Gavin Reid首席信息安全官有网络安全行业背景的资深 CISO内部安全态势;面向企业 CISO 的产品可信度中:CISO 角色影响企业客户信心
Christos Kalantzis首席技术官资深技术高管平台技术架构;AI/ML 平台开发;工程路线图中:考虑到平台的机器学习核心,CTO 连续性很重要

根据公司公告、新闻稿和 Craft.co 资料,列出截至 2026 年 6 月的公开高管和创始团队。完整董事会构成(包括投资人指定董事和全部 8 个观察员席位)以及准确创始人股权持有情况未公开披露。Dan Kaminsky 条目为完整性而纳入;他于 2021 年 4 月去世。Matt Cantor 未出现在任何当前或近期 HUMAN Security 领导层或董事会记录中。

[CO002, CO011, CO012, CO013, CO014, CO019]
FO002: 公司快照逻辑

HUMAN 的操作系统把 PE 支持的资本、创始人转任董事长的治理层、威胁情报核心(Satori)和统一平台连接起来。 平台服务三类客户:媒体 / adtech、企业应用安全和 agentic AI 治理。

[CO007, CO015, CO016, CO017, CO018, CO043]

1.3 融资历史、估值与投资人图谱

HUMAN 的资本历史从风险投资支持的初创公司,经过私募股权收购,演变为成长融资支持的网络安全平台。公司 2017 年完成由 Canaan Partners 领投的 Series B,2019 年 2 月完成由 Scale Venture Partners 领投的 $43M Series C。2020 年 12 月,Goldman Sachs Merchant Banking Division、ClearSky Security 和 NightDragon 从 Paladin Capital Group、Grotech Ventures 等此前投资人手中联合收购 White Ops。交易条款未披露。收购时,公司有 170 名员工,每周验证 10 万亿次交互。 收购后,HUMAN 2021 年 2 月完成 $57M Series D 成长轮,Stereo Capital 等参投;随后在 2022 年 1 月完成由 WestCap 和 NightDragon 领投的 $100M 成长轮,据报道该轮将公司估值定在约 $1.5 billion。2022 年 7 月,在与 PerimeterX 合并的同时,HUMAN 获得 Blackstone Credit 提供的 $100M 债务额度。最近一次外部资本事件是 2024 年 10 月 9 日宣布的 $50M+ 成长轮,再次由 WestCap 领投,Goldman Sachs、ClearSky、NightDragon 和 Vertex Ventures US 参投。CEO Stu Solomon 表示,$50M 金额是有意控制的,目的是支持定向投资而不过度资本化。 数据聚合方称,所有轮次合计融资约 $299-300M。但该数字可能不包括 Blackstone 的 $100M 债务额度,因为它是债务工具而非股权。当前 post-money 估值未公开披露。2022 年 1 月的 $1.5B 估值是最近公开报道的数字,但早于 2022 年 PerimeterX 合并和 2024 年 10 月融资。精确股权比例、清算优先权和股权结构仍为私有信息。HUMAN 是以 Goldman Sachs 为锚的资产,WestCap 反复担任领投方,另有来自网络安全行业的战略共同投资人(NightDragon、ClearSky、Vertex Ventures US)。 [CO021, CO022, CO023, CO024, CO025, CO026]

利益相关方或投资人图谱
利益相关方角色控制权 / 经济重要性尽调问题
Goldman Sachs 商业银行部主导收购方(2020 年 12 月);董事会代表(Anthony Arnold)2020 年买断中取得多数控制权;锚定机构股东;后续所有轮次均保留确认当前股权持有比例、董事席位权、退出期限以及任何二级交易活动;Goldman Sachs 的所有权使其成为带隐含退出时间表的 PE 支持资产
WestCap2022 年 1 月增长轮和 2024 年 10 月增长轮主导投资人;董事会代表(Kevin Marcus)连续两轮增长轮的双重主导投资人;向管理层提供 co-COO 级运营专业能力评估具体董事会治理权、信息权以及任何优先权条款;WestCap 以运营者为核心的模式暗示其会积极参与治理
NightDragon2020 年收购共同投资人;2022 年轮次共同投资人;2024 年轮次共同投资人;董事会代表(NightDragon 创始人 / CEO Dave DeWalt)持续参与的战略投资人;按 2020 年收购公告,担任 HUMAN 董事会 Vice Chairman;网络安全生态连接者确认当前董事席位和监督权;DeWalt 的网络覆盖企业网络安全买家,使 NightDragon 更像战略投资人,而非纯财务投资人
ClearSky Security2020 年收购共同投资人;2024 年轮次共同投资人;董事会代表(Jay Leek)早期收购伙伴;持续董事会席位;专注网络安全和关键基础设施安全澄清当前股权持有和董事会权利;ClearSky 的深安全专长与 HUMAN 的威胁情报差异化一致
Vertex Ventures US2024 年 10 月轮次新投资人首轮参与;新增长股权仓位;规模和治理权未确认要求提供当前股权所有权条款,以及与 2024 年轮次相关的任何治理权
Scale Venture Partners领投 $43M Series C(2019 年 2 月);历史投资人早期机构资本;收购前股东;2020 年买断后当前剩余所有权不明判断 Scale Venture 在 Goldman Sachs 收购后是否保留任何股权;当前所有权可能很小
Canaan Partners领投 Series B(2017);历史投资人早期增长资本;收购前股东;当前剩余所有权不明与 Scale Venture 一样,确认收购后持股;可能已退出或被边缘稀释
Blackstone Credit$100M 债务额度(2022 年 7 月,与 PerimeterX 合并同步)债务工具;不是股权;契约、到期日和利率等条款未公开披露获取完整债务协议条款;债务额度会影响自由现金流、再融资风险以及 HUMAN 资产上的任何担保权益
Tamer Hassan(执行董事长)联合创始人;董事会成员;自 2024 年 1 月起任执行董事长剩余创始人股权;规模不清楚;具备战略和治理影响力确认创始人股权仓位、锁定条款,以及 2020 年收购以来任何二级流动性活动

任何投资人的持股比例均未公开披露。所列持股仅根据已宣布角色和轮次参与推断。2020 年 Goldman Sachs 收购是对既有股东的多数买断;Series B 和 C 的剩余 VC 仓位可能已被部分或全部买断。$100M Blackstone 信贷额度是债务工具,独立于聚合商引用的约 $299-300M 股权融资金额。

[CO021, CO022, CO024, CO025, CO026, CO027]

1.4 里程碑时间线、竞争认可与负面背景

HUMAN 的运营历史由一系列公私联合威胁打击行动塑造,这些行动确立了其在网络安全市场的身份和可信度。2016 年,公司仍名为 White Ops 时,揭露了 Methbot,这是最早的大规模专用广告欺诈僵尸网络之一。2018-2019 年,公司与 FBI、Google 和 Facebook 参与打掉 3ve,这是截至当时最大的广告欺诈僵尸网络。2021 年,公司主导协作式 PARETO 打击行动(一个大型 Connected TV 广告欺诈行动),并从 White Ops 更名为 HUMAN Security。2022 年是公开记录中最活跃的一年:3 月收购 clean.io,7 月完成 PerimeterX 合并,影响 1,100 万台设备、每日产生 120 亿次虚假竞价请求的 VASTFLUX 广告欺诈方案被打断,并在 2023 年 1 月披露。BADBOX 是一个预装 Android 僵尸网络,影响全球数百万台设备,2023、2024 和 2025 年被分阶段打击;德国当局以及包括 HUMAN、Google 和 Shadowserver 在内的联盟执行了最大规模的协调 sinkholing 行动。 商业和行业认可方面,HUMAN 入选 TIME 的 Best Inventions of 2023、TIME100 Most Influential Companies of 2023,并在 The Forrester Wave: Bot Management Software Q3 2024 中被评为 Leader。2024 年 1 月,Tamer Hassan 向 Stu Solomon 的 CEO 交接生效。2024 年 10 月,$50M+ 成长轮完成。到 2026 年 6 月,HUMAN 在 The Forrester Wave: Bot and Agent Trust Management Software Q2 2026 中被评为 Leader,在包括 Threat Research 在内的九项标准上获得最高可能分数,并且是唯一在该标准获得最高分的供应商。G2 的 Summer 2026 Grid for Bot Detection and Mitigation Software 也完全基于客户反馈,将 HUMAN 评为总榜第一的 Leader。 负面记录有限。2024 年 10 月,AdExchanger 发布更正,称 CEO Stu Solomon 在采访中谈到为归因构建专有确定性 ID 时失言;HUMAN 产品副总裁澄清并无此类产品计划。这是一次轻微公开信息表述错误,没有监管或法律后果。截至 2026 年 6 月研究日,公开记录未发现针对 HUMAN Security 的重大诉讼、监管调查、数据泄露披露、重大裁员或制裁。没有记录在案的负面事件本身应作为证据缺口处理,因为私人程序可能不会公开披露;公司私人持有,也意味着不存在公开监管申报轨迹。 [CO029, CO030, CO031, CO032, CO033, CO034]

里程碑表
日期事件类型金额 / 估值 / 状态参与方含义
2012White Ops 在纽约布鲁克林成立创立N/A四位创始人:Tamer Hassan、Michael Tiffany、Dan Kaminsky、Ash Kalb这家后来成为 HUMAN Security、专做“是否为 bot”检测的公司由此起步
2016Methbot 广告欺诈行动被发现并披露产品扰乱每月 $3-5M 犯罪收入White Ops(Satori 团队)第一次大型公私协作处置;确立 White Ops 在广告欺诈威胁情报上的领先地位
2017Series B 融资完成融资金额未披露Canaan Partners(领投)种子轮之后的首笔机构增长资本;支持平台扩张
2019-02Series C 融资完成融资$43MScale Venture Partners(领投)、Canaan加速从广告走向企业安全用例
2018-2019完成 3ve botnet 下线;FBI 发出起诉产品扰乱数十亿次展示欺诈White Ops、FBI、Google、Facebook、行业联盟当时规模最大的私营部门协作式网络安全处置;定义了 White Ops 的威胁情报身份
2020-12Goldman Sachs Merchant Banking 收购 White Ops;ClearSky 和 NightDragon 共同投资融资条款未披露;PE 多数买断Goldman Sachs MBD、ClearSky 与 NightDragon 共同投资从 VC 支持的创业公司转为 PE 持有的增长资产;原投资人(Paladin Capital、Grotech Ventures)退出
2021-Q1White Ops 更名为 HUMAN Security治理N/AHUMAN Security 管理层反映范围从广告欺诈扩展到全栈数字身份保护
2021PARETO(CTV 广告欺诈 botnet)下线;Dan Kaminsky 去世产品重大 CTV 欺诈行动被处置HUMAN、行业伙伴;Kaminsky(2021 年 4 月)Connected TV 欺诈的标志性处置;创始团队成员离世
2022-01$100M 增长轮完成;估值约 $1.5B(独角兽里程碑)融资融资 $100M;投后估值约 $1.5BWestCap(领投)、NightDragon独角兽身份;为 PerimeterX 合并和平台扩张提供资本
2022-03HUMAN 收购 clean.io(恶意广告预防)产品条款未披露HUMAN(收购方)、clean.io为平台增加恶意广告预防能力;Hassan 在 CEO 交接时引用
2022-07HUMAN 与 PerimeterX 合并;Blackstone Credit 提供 $100M 债务额度产品$100M 债务;合并后实体有 450+ 名员工、$100M+ ARRHUMAN、PerimeterX、Blackstone Credit公司史上最大战略动作;统一广告技术与企业安全平台;Omri Iluz 出任 Enterprise Security 总裁
2023-01披露 VASTFLUX 广告欺诈处置(11M 台设备,峰值 12B 次每日虚假竞价)产品峰值 12B 次 bid requests/day;已处置HUMAN(Satori 团队)展示 HUMAN 组织大规模协同私营处置的能力;强化威胁情报品牌
2023入选 TIME Best Inventions 和 TIME100 Most Influential Companies规模行业认可TIME 编辑部、HUMAN主流可信度里程碑;产品获得面向消费者的认可
2023-2024BADBOX 预装 Android botnet 下线(多阶段;BADBOX 2.0 于 2024–2025 年)产品影响 10M+ 台设备;已处置HUMAN、Google、德国当局、Shadowserver多年、多机构行动;让 HUMAN 被定位为持续威胁处置参与者,而非一次性下线角色
2024-01Stu Solomon 被任命为 CEO;Tamer Hassan 转任执行董事长治理N/AStu Solomon(新任 CEO)、Tamer Hassan(执行董事长)首次任命外部 CEO;标志公司从创始人主导转向职业化管理
2024-10$50M+ 增长轮完成融资融资 $50M+WestCap(领投)、Goldman Sachs、ClearSky、NightDragon、Vertex Ventures US第二轮 WestCap 领投;新投资人 Vertex Ventures US;CEO 为定向投入而有意限制融资规模
2026-06获评 Forrester Wave Bot and Agent Trust Management Q2 2026 领导者;Threat Research 得分最高规模Threat Research 维度 Forrester 最高分Forrester Research验证平台扩张到 agentic AI trust management;差异化威胁情报能力获得公开认可

里程碑日期来自新闻稿、新闻报道和公司公告。准确收购和合并条款未公开披露。PerimeterX 合并交割日期(2022 年 7 月)来自 BusinessWire 公告;该公告确认了监管批准。鉴于 Dan Kaminsky 是创始团队成员,其去世被列为负面里程碑。PerimeterX 合并时的 $100M ARR 数字来自 BusinessWire 公告,代表合并实体的合并 ARR。

[CO001, CO004, CO021, CO022, CO023, CO024]
FO001: 公司里程碑时间线

HUMAN 的经营历史横跨创立期威胁情报阶段、私募股权整合阶段(2020–2022),以及平台扩张阶段(2022–2026), 现在延伸到 agentic AI。不利事件仅限一次轻微的公开表述更正,以及一名创始成员去世。

[CO001, CO004, CO029, CO030, CO031, CO037]

1.5 展示材料

Chapter 02

02市场分析

2.1 市场边界、纳入支出与替代品

HUMAN Security 的收入机会横跨四个不同但重叠的产品类别:(1)机器人缓解和行为分析平台,保护 Web 应用、API 和移动端免受自动化滥用;(2)广告欺诈和 Sophisticated Invalid Traffic(SIVT)防御,覆盖程序化广告中的竞价前过滤、竞价后报告和 MRC 认证验证;(3)账户接管(ATO)预防,针对登录后的凭据滥用、会话劫持和多阶段攻击链;(4)智能体 AI 信任管理,这是一个新兴类别,随着 AI 驱动智能体开始代表用户交易而出现——在 HUMAN 自身网络数据中同比增长 7,851%。这四类产品正越来越多地整合到 Human Defense Platform 内的 HUMAN Sightline Cyberfraud Defense 和 MediaGuard/Ad Integrity Suite 之下。 纳入支出包括行为分析 SaaS 订阅、MRC 认证 SIVT 检测许可、机器人评分 API 费用、AgenticTrust 政策执行,以及托管威胁情报服务(Satori 团队)。排除支出包括纯支付欺诈拒付和拒付保险、KYC/KYB 身份核验(证件验证、生物识别)、AML 合规工具、没有行为层的传统 CAPTCHA 商品化产品、DDoS 缓解(纯流量型),以及机器人管理只是未单独计费附加项的 CDN 基础设施合同。相邻市场包括 Web 应用防火墙、云访问安全代理、身份与访问管理平台和 API 网关安全——这些都会对 HUMAN 的特定用例形成部分替代。 现状替代品包括:自建欺诈规则引擎和数据科学团队(Google、Meta 和大型金融机构等大型互联网平台常见)、Cloudflare(按设备份额计占机器人管理安装基数 79%)和 Akamai(6%)提供的 CDN 原生机器人管理,以及 Integral Ad Science、DoubleVerify、Pixalate 等点状 SIVT 供应商。Cloudflare 把机器人管理与 CDN、WAF 捆绑,SMB 平价套餐年费约 $350 起,这在低端和中端市场形成最实质的替代风险。竞争性捆绑威胁压缩 HUMAN 的可服务市场——尤其是已依赖 Cloudflare 做内容分发的组织——并迫使 HUMAN 用信号深度(每次交互 2,500+ 个行为信号)、威胁研究(Satori 团队)和 Cloudflare 不提供的专门广告欺诈 MRC 认证来证明差异化。 [CM001, CM028, CM029, CM037, CM038, CM039]

市场定义:纳入支出、排除支出与替代品
细分 / 类别纳入支出排除支出主要买方 / 付款方与 HUMAN 的相关性
Bot 缓解与行为分析Bot-score APIs、行为分析 SaaS、CAPTCHA 绕过检测、基于 SDK 的会话监控、托管 bot 服务CDN 基础设施、DDoS 容量型缓解、网络层防火墙订阅App 安全工程师、CISO / IT Security 预算核心 — Bot Defender、Sightline Cyberfraud Defense
广告欺诈 / SIVT 防御出价前 IVT 过滤、出价后报告、MRC 认证 SIVT 分类、TAG 合规工具、Page Intelligence 分析仅可见性测量(非欺诈)、品牌安全邻近项(非 IVT)、广告投放基础设施广告运营负责人、CMO / Marketing P&L 预算核心 — MediaGuard、Ad Integrity Suite、Page Intelligence
账户接管(ATO)预防登录后行为监控、撞库检测、会话异常告警、ATO 威胁情报完整身份核验(KYC/KYB)、生物识别认证硬件、IAM 平台订阅欺诈运营团队、Head of Risk / CISO + CRO 预算核心并在扩张 — Sightline 内的 ATO 监控
Agentic AI 信任管理AI agent 识别与信任评分、基于策略的 agent 访问控制、agentic commerce 治理 SaaS模型对齐和 AI 安全(AI 公司预算)、硬件级安全 enclave 支出平台架构师、trust & safety 负责人 / 新兴共享安全 + 工程预算新兴且增长中 — AgenticTrust 模块、AWS Bedrock 集成
相邻替代品(范围外支出)CDN 原生 bot management(Cloudflare、Akamai)、WAF 平台安全打包、内部欺诈规则引擎和数据科学团队、RASP、认证叠加供应商(Arkose Labs 等)平台基础设施团队、NOC/SOC / IT 基础设施预算核心市场的一部分存在被替代风险;HUMAN 无法直接覆盖

边界定义锚定 HUMAN 产品;相邻替代支出不计入 SAM 测算,但在这里列出,用于说明竞争替代风险。纳入的支出类别来自公司文件、MRC 认证函和 Forrester Wave 评估标准。并非所有纳入支出都有独立分析机构在子类别层面公开量化。

[CM001, CM037, CM028, CM029, CM038, CM039]

2.2 市场规模:从多重视角看 TAM、SAM 与 SOM

HUMAN 所服务市场的规模测算需要合并多个分析师类别,因为没有单一公开报告与其产品边界完全匹配。Business Research Company 估算,机器人缓解市场 2025 年为 $0.9 billion,2026 年以 24.8% CAGR 增至 $1.12 billion;Fortune Business Insights 则把稍宽的“bot security”类别估为 2025 年 $1.05 billion、2026 年 $1.27 billion,CAGR 为 20.55%。两项估算到 2030-2034 年均达到 $2.4–$5.67 billion。MarkWide Research 的离群估算把更宽的“bot mitigation”市场定在 2026 年 $3.8 billion,范围更大,可能包含相邻 WAF/CDN 安全支出。 广告欺诈方面,Fraudlogix 在 2025 年 105.7 billion 次展示中测得全球 IVT 率为 20.64%;按美国特定的 23.69% 率计算,意味着美国程序化广告支出每年约 $37 billion 暴露于无效流量。这是潜在欺诈损失,不是供应商市场规模;SIVT 缓解供应商收入只是欺诈暴露额的一小部分。Pixalate 的 Q1 2026 基准确认,美国桌面 IVT 率为 24%、移动应用为 32%、CTV 为 24%——这些比例强化了市场对认证 SIVT 供应商的持续需求。 账户接管保护方面,Global Growth Insights 估算 2026 年独立市场规模为 $7.46 billion,CAGR 为 18.89%。eCommerce FDP 大市场预计 2026 年为 $88.77 billion(BFSC),全垂直欺诈检测市场为 $40.4 billion(Grand View Research),但这些都包括 HUMAN 不直接服务的支付欺诈、KYC/KYB、AML 和身份核验,因此高估了相关 TAM。 分析师综合后的 HUMAN SAM 约为 2026 年 $1.5–$2.0 billion,构成为机器人安全($1.27B)加 MRC 认证 SIVT 供应商支出(估计 $500M–$800M,按全球 $836B 数字广告支出中广告主用于验证工具的比例推导)。SMB/中端市场受到 Cloudflare 捆绑压缩。2026 年 SOM 估算为 $150–$300 million,与 HUMAN 的 Forrester Wave 领导者位置、万亿级交互网络规模和对受限 SAM 10–20% 的现实渗透率相符,但因为 HUMAN 不披露收入,该估算没有独立验证。 [CM002, CM003, CM004, CM005, CM006, CM007]

TAM/SAM/SOM 规模测算视角表
发布方年份地区市场 / 范围价值(2026)CAGR方法论置信度对 HUMAN 规模测算的限制
Business Research Company2026全球Bot 缓解$1.12B24.8%需求侧;Web、移动端、API bot 缓解工具和服务比 HUMAN 的完整范围更窄(不含 SIVT、ATO);可能低估 SAM
Fortune Business Insights2026全球Bot 安全$1.27B20.55% (2025-34)需求侧;包含行为分析、AI 驱动检测平台范围可能包含相邻的 WAF/CDN 安全;北美占 38%
MarkWide Research2026全球Bot 缓解(宽口径)$3.8B~18%供给 + 需求汇总;更宽边界可能包含集成式 WAF/CDN 安全边界可能膨胀;与 TBRC 同年 $1.12B 对照,来源之间相差 3.4x
Fraudlogix2026(数据 2025)美国暴露于 IVT 的程序化广告支出(广告欺诈规模代理指标)$37B 暴露N/A基于展示量;23.69% IVT × $156B 美国程序化支出(估算)衡量欺诈暴露额,不是厂商市场;SIVT 厂商收入 << $37B
Business Research Company2026全球电商欺诈检测与防护$88.77B20.8%宽口径电商垂直;包含支付欺诈、拒付、KYC范围比 bot-only 市场宽 70-80x;不能直接与 HUMAN SAM 比较
Grand View Research2026全球欺诈检测与防护(全垂直)$40.4B18.1% (2026-33)全垂直 FDP,包含 AML、KYC、支付欺诈、身份核验包含 HUMAN 无法覆盖的类别;只能作上限,不能作下限
Global Growth Insights(市场研究)2026全球账户接管防护$7.46B18.89% (2026-35)需求侧;ATO 专项平台、凭证保护、会话安全ATO 是 HUMAN 套件的一部分;完整市场 >= HUMAN 的 ATO 相关 SAM
分析师综合(本报告)2026全球HUMAN SAM(Bot 安全 + SIVT 厂商市场)$1.5–$2.0B(估算)~20%自下而上:$1.27B bot 安全 + 估算 $500M–$800M MRC 认证 SIVT 厂商支出;捆绑前折价没有独立来源验证这一精确边界;受 Cloudflare 覆盖市场影响,可能下修 20-40%

分析师估算采用不同市场边界,不能相加,也不能直接比较。数值均为美元。CAGR 按各发布方口径列示。最下方的分析师综合行是本报告估算,不代表一手来源;置信度有意设为低。MarkWide Research 的 $3.8B 估算与 TBRC 同年同地区的 $1.12B 相差 3.4x,说明范围边界并不清晰。

[CM002, CM003, CM005, CM007, CM008, CM009]
矛盾的市场规模估算:边界分析
来源估算(2026)超出 HUMAN 产品的关键纳入范围对 HUMAN SAM 的隐含折价尽调含义
TBRC — Bot 缓解$1.12B无显著项目;与 HUMAN 的 bot 防御范围高度一致~0%(基准)最保守且范围最一致的估算;作为 SAM 下限
Fortune BI — Bot 安全$1.27B可能包含部分 WAF/CDN 相邻安全;北美为 38%~0-5%范围略宽;本章分析引用最多的分析师估算
MarkWide Research — Bot 缓解(宽口径)$3.8B可能包含集成式 WAF/CDN 安全捆绑包;范围没有清晰定义~50-70% 折价,用于分离纯 bot 防御与同一时期的 TBRC/FortunBI 相比是离群值;只作为上限情景
Global Growth Insights — ATO 防护$7.46BATO 专项平台;包含 HUMAN 范围之外的身份核验和生物识别层~40-60% 折价,用于分离 HUMAN 相关 ATO 支出作为 Sightline 相邻 ATO 子市场参考;未调和边界前,不要加到 bot 市场
Grand View Research — 欺诈检测与防护$40.4BAML、KYC/KYB、支付欺诈、拒付、身份验证和合规报告~97% 折价,回到 bot-only 市场代表整体风险管理可服务市场;HUMAN 份额很小;说明投资者材料里的类别膨胀风险
BFSC — 电商欺诈检测与防护$88.77B支付欺诈、拒付管理、退款滥用、账户欺诈、电商入驻 KYC~99% 折价,回到 bot-only 市场边界最膨胀;若引用时不附边界免责声明,基准可能误导

折价估算是基于已知范围差异的定性分析师综合;没有一手来源独立验证每项估算中 HUMAN 相关与非相关支出的拆分。「隐含折价」只是用于说明范围膨胀幅度的近似值,不是精确计算。向投资者展示时应保留本表,避免过度依赖最大估算。

[CM007, CM008, CM009, CM012, CM035, CM036]
FM001: 市场规模金字塔:HUMAN Security 的 TAM、SAM 与 SOM(2026)

三层市场金字塔展示从广义欺诈防护 TAM,到 HUMAN 估算可服务市场(SAM)和 2026 年现实可达份额(SOM)的范围。

TAM 数字是最常被引用的最广义估算,包含非 HUMAN 细分;仅 bot 缓解的 TAM 为 $1.12-1.27B,更站得住。 SAM 和 SOM 是分析师综合估算,没有一手来源验证。SOM 区间为 $150M-$300M;采用中点 $220M。

[CM002, CM003, CM008, CM009, CM010, CM011]
FM002: 市场估算区间:Bot Security 与 HUMAN SAM 场景(2026)

Bot 安全市场和 HUMAN 的 SAM 在不同边界假设下的低 / 基准 / 高估算,均以 2026 年 $B 表示,展示公开估算对范围边界的敏感性。

所有数值单位为十亿美元。Cloudflare 调整后 SAM 行是本报告构建,没有独立一手来源。广义 / 全 FDP 行仅作指示; HUMAN 并不参与该市场的大多数部分。单位一致性:所有行均使用 $B(2026 年估算)。

[CM002, CM003, CM009, CM035, CM036]

2.3 买方、用户与付款方分层

HUMAN 的买方版图按产品线和底层待完成任务分层。机器人缓解和 ATO 防御(Bot Defender + Sightline)的主要买方,是电商、旅游和金融服务公司的应用安全工程师与欺诈运营团队。预算通常落在 IT Security 或 Risk/Compliance,由 CISO 或 CTO 拥有。采用触发点包括遭遇入侵事件、发现结账欺诈或抓取攻击,或者库存抓取带来的竞争情报威胁。HUMAN 自己的 2026 年基准报告发现,零售和电商在抓取(占所有观测攻击 70%)、盗刷测试和 ATO 尝试方面均居各垂直行业之首,有超过 440,000 个独特威胁画像瞄准该行业——是第二高垂直行业的四倍以上。 广告欺诈/SIVT 防御(MediaGuard/Ad Integrity Suite)的买方画像转向广告主、代理商、DSP、SSP 和出版商中的广告运营负责人、首席媒体官和程序化交易团队。预算所有权转到营销 P&L。采用往往由合规驱动:展示计数需要 MRC 认证、供应链参与者需要 TAG 认证,或代理控股集团标准要求独立 IVT 测量。HUMAN 2026 年对竞价前 Ad Fraud Defense 和投放后 Ad Fraud Sensor 平台在桌面、移动和 CTV 范围内再次获得 MRC 认证,强化了其在该细分市场作为认证供应商的地位。 第三个新兴细分是智能体 AI 信任管理(AgenticTrust/Sightline)。买方是在大规模部署或接收 AI 智能体流量的公司中的平台架构师、信任与安全负责人,以及“agentic commerce”产品负责人。这个买方更新,预算尚未完全分配;类别本身也直到 2025 年才被 Forrester 更名为“Bot and Agent Trust Management Software”以反映这一转变。HUMAN 支持 Amazon AWS Bedrock AgentCore 浏览器验证,显示该细分市场采用合作伙伴驱动的 GTM。这里的付款方可能是安全与平台工程的合并预算,而非传统 CISO 所有者。 EXTE 2026 年 3 月集成 HUMAN 的 MediaGuard,说明了合作伙伴/平台买方模式:一家程序化广告公司把 HUMAN 方案整合为供应质量层——付款方是平台,用户是下游广告主。Gartner 称,全球网络安全预算 2026 年将升至 $240 billion(同比 +12.5%),其中 40% 的企业安全预算投向 HUMAN 所竞争的软件和平台。 [CM015, CM016, CM017, CM018, CM019, CM020]

买方 / 用户 / 付款方分群图
分群主要买方用户付款方 / 预算负责人服务的工作流关键采用触发因素
程序化广告 / 媒体 / Ad-TechCMO、广告运营总监、程序化负责人程序化交易员、DSP、SSP、发布商CMO/CFO,通过营销技术栈 / 媒体 P&L竞价前 IVT 过滤、竞价后报告、TAG/MRC 合规、Page Intelligence 分析MRC 认证要求、TAG 认证要求、代理控股集团标准、广告主提出广告欺诈投诉
电商与零售工程副总裁、欺诈负责人、应用安全负责人安全工程师、欺诈分析师、产品团队CISO/CTO / IT 安全或风险预算抓取防御、盗刷防护、结账 ATO、库存扰动缓解、bot 性能影响事后响应、结账欺诈激增、发现竞争性抓取、bot 导致的延迟事件
旅游与酒店产品副总裁、信任与安全负责人、CISO平台工程师、客户体验团队CTO/CRO / 平台工程预算库存抓取、虚假评论注入、忠诚度账户 ATO、欺诈性预订链OTA 抓取扰动、忠诚度 ATO 激增、bot 流量导致性能下降(HUMAN 案例研究称登录页超过 50%)
媒体与流媒体首席合规官、广告运营总监安全工程师、广告运营、内容团队CMO + CISO / 营销 + 安全共享预算AI 抓取器控制、内容保护、广告收入欺诈、AI agent 驱动流量分类AI 抓取器集中攻击内容(AI 抓取器目标中 41% 为内容)、广告欺诈投诉、可见性 / IVT 审计失败
金融服务信息安全副总裁、欺诈风险官、CISO安全工程、欺诈分析、合规团队CISO + 首席风险官 / 合规与风险预算ATO 检测、撞库、开户欺诈、API 滥用、合成身份信号监管要求(PSD2、NIST、OCC)、ATO 事件、凭证泄露、PCI-DSS 审计发现
Agentic AI / 平台运营方平台架构师、信任与安全负责人、产品安全负责人开发者、AI 产品经理、信任团队CTO / 工程或新兴「AI 治理」预算AI agent 识别、信任评分、面向 agentic commerce 的基于策略访问控制平台 AI-agent 流量激增、采用 AWS Bedrock 或类似 agentic 平台、agentic 欺诈事件

买方画像和工作流描述综合自 HUMAN Security 案例研究、Forrester Wave 评估语境,以及 HUMAN 的 2026 State of AI Traffic 报告。预算归属会随交易规模和组织成熟度变化;同时暴露于广告欺诈和安全风险的媒体公司会出现双预算(CISO + CMO)交易。「付款方」指持有合同的组织单元;「买方」指拥有决策权的经济买方。

[CM015, CM016, CM017, CM018, CM019, CM020]
FM003: 买方 / 细分地图:预算归属与采用路径

矩阵把 HUMAN Security 的五个主要买方细分映射到预算归属、关键采用触发因素和竞争替代方案,展示平台的多买方属性。

替代方案列反映市场中观察到的主导竞争选择;HUMAN 的具体交易级赢单 / 输单数据未公开。

[CM016, CM018, CM019, CM024, CM040, CM042]
FM004: 企业采用漏斗:Bot 与 Agent 信任管理软件

企业买方评估 HUMAN Security 的五阶段采用漏斗,从初始认知到扩张增购,展示每一阶段的转化流失和切换摩擦。

漏斗数值是相对于 100 指数基准的估算百分比,不代表 HUMAN 实际管线转化率,后者未公开披露。 百分比用于说明企业安全 SaaS 的一般采用模式,基于行业基准和 HUMAN 已知 go-to-market 模型。

[CM022, CM023, CM027, CM032, CM033, CM046]

2.4 增长驱动因素与采用约束

最强的单一增长驱动,是自动化和智能体流量爆发。HUMAN 自己的 2026 年基准报告发现,自动化流量同比增长 23.51%,而人类流量仅增长 3.10%——比例约为 8:1。AI 驱动流量 2025 年激增 187%,来自智能体和浏览器的智能体 AI 流量同比增长 7,851%。Forrester 2025 年更名为“Bot and Agent Trust Management Software”的类别,反映可服务问题的结构性扩张:仅把流量分为人类或机器人已不够,组织还必须治理 AI 智能体能否可信地代表用户交易。这个扩张在传统机器人缓解之上创造了新的 TAM 层,目前没有既有主导者;HUMAN 的 AgenticTrust 模块正是为这一缺口设计。 第二个驱动是监管和合规压力。TAG 2026 年向 196 家公司授予 307 个认证印章,其中 74% 经独立审计——说明广告行业合规正在从自我声明继续收紧。MRC 对 SIVT 检测的认证,越来越成为参与程序化平台的前提。PSD2(金融服务)、NIST CIAM 指引,以及新兴 EU AI Act 中有关自主系统问责的条款,正在受监管垂直行业中为机器人和智能体信任管理创造非可选预算线。 HUMAN 客户群中的 ATO 攻击在 2024 至 2025 年间增长四倍(每客户每年平均 400,000+ 次登录后攻陷尝试),推动现有客户内的增购和交叉销售机会。2026 年广告欺诈损失超过 $100 billion,IVT 率超过 20%,让广告主持续急于获得经验证的流量。 主要约束是竞争性捆绑:Cloudflare 通过集成 CDN、WAF 和机器人管理,以年费低于 $400 起的平价套餐,掌握约 79% 的机器人管理安装份额(Akamai 为 6%)。这套组合在 SMB 和低端中端市场替代专用机器人防御供应商。DataDome 的市场份额 2025 至 2026 年从 13.8% 降至 8.9%,可能反映了这种捆绑压力。第二个约束是 ROI 证明:机器人缓解节省体现为“避免的欺诈损失”而非收入——在 P&L 中不可见,需要复杂测量框架才能向非技术利益相关方证明预算合理。第三个约束是切换摩擦:企业机器人管理深度嵌入登录流程、结账 API 和分析管线;迁移风险抑制从现有供应商切换,放慢新客户获取。大型平台只要工程能力充足,自建仍是可行替代,这进一步限制 HUMAN 的净可服务市场。 [CM023, CM024, CM025, CM026, CM027, CM028]

增长驱动因素与采用约束
因素类型方向时间对 HUMAN 的含义尽调追问
Agentic AI 流量同比增长 7,851%(HUMAN 数据)驱动因素强正向当前且在加速(2025-2027)TAM 从单纯 bot 扩到完整 agent 信任管理;HUMAN 在这个新类别里率先获得 Forrester 认可确认 agent 信任管理的 TAM 是独立于 bot 管理编列预算,还是现有合同中的 upsell / add-on
自动化流量增速是人类流量的 8x驱动因素强正向当前(持续)所有买方分群的紧迫性都会提高;简单 IP 频率限制之外,行为检测的基线需求上升量化 HUMAN 管线中有多少比例来自新发现 bot 问题,多少来自替换 Cloudflare/Akamai
2025 年 AI 驱动流量增长 187%,AI 抓取器增长 597%驱动因素强正向当前媒体和电商买方面临即时抓取威胁;推动从 bot 防御交叉销售到 AI 流量治理确认该信号适用于 HUMAN 的客户垂直,而不只是其自身观测到的流量
HUMAN 客户群内 ATO 攻击在 2024-2025 年翻了两番驱动因素强正向当前且在加速在现有客户群内形成 upsell 机会;向 bot-only 客户交叉销售 ATO 模块;扩大合同金额确认 ATO 增速来自广泛市场,而不是 HUMAN 检测覆盖提升造成的假象
全球广告欺诈损失 >$100B,2026 年 IVT 率 20%+驱动因素中等正向持续广告主对 MRC 认证 SIVT 厂商的需求得以维持;支撑 MediaGuard/Ad Integrity Suite 续约率评估 HUMAN 的 SIVT 客户中,强制要求(TAG/MRC-required)与自主采购买方各占多少
2026 年 TAG 认证 307 项(74% 经独立审计);监管压力(PSD2、NIST、EU AI Act)驱动因素中等正向形成中(2024-2028)受监管和广告行业垂直会为 bot/agent 信任管理配置非可自由裁量预算线识别哪些具体法规会为 HUMAN 产品创造合同要求,而不只是提升一般安全意识
Cloudflare 主导 bot 管理安装基数(约 79% 份额)约束对 SMB / 中端市场强负向当前且在增长HUMAN 实际上被排除在很大一部分 SMB 市场之外;必须靠信号深度(每次交互 2,500+ 信号)和 Cloudflare 不具备的专项认证来销售量化 Cloudflare 在 HUMAN 当前客户分群中的渗透率;HUMAN 是共存还是替换?
ROI 证明是「看不见的节省」(避免欺诈损失)约束中等负向持续拉长企业销售周期;需要可信的衡量方法;预算批准需要非技术利益相关方买入要求 HUMAN 提供经第三方验证的客户 ROI 案例研究;平均销售周期多长?
深度 API / 登录流程集成带来高切换成本(双向)约束混合持续保护 HUMAN 现有安装基数(NRR 可能较高),但放慢从既有厂商手中拿新 logo 的速度;迁移风险会阻止变更获取 NRR 和 logo 留存指标;HUMAN 平均客户年限多长?
大型平台的内部欺诈团队构成自建替代约束中等负向(选择性)当前在具备足够 ML 工程能力的大型互联网公司(Google、Meta、Amazon),SAM 受限;HUMAN 的 SAM 更偏向没有内部能力的中大型企业识别与内部自建决策竞争时的赢 / 输记录;多大工程人员规模会与自建偏好相关?

方向均相对于 HUMAN 的收入机会评估。「时间」为定性判断。驱动因素 / 约束的分类反映主导预期效果;部分因素(例如切换成本)会因 HUMAN 在具体账户中是既有厂商还是挑战者而影响不同。

[CM021, CM025, CM026, CM027, CM028, CM030]

2.5 规模缺口、矛盾估算与尽调问题

三个结构性缺口阻止市场规模被明确建立。第一,HUMAN Security 不披露收入、ARR 或客户数,自下而上的 SOM 估算完全依赖 Forrester Wave 排名、G2 位置和网络规模等推断指标。第二,分析师群体尚未独立测算“agent trust management”子市场——Forrester 直到 2025 年才更名该类别,2026 年该细分还没有共识市场预测。第三,分析师报告引用的 $1.12B–$88.77B 市场估算区间,反映的是边界不一致,而非基本面真正分歧:$88.77B eCommerce FDP 估算包括 HUMAN 不覆盖的支付欺诈、拒付、KYC/KYB 和身份核验,而 $1.27B bot security 估算排除了 SIVT 供应商收入。两者都不能干净映射到 HUMAN 的实际产品范围。 值得保留的矛盾规模证据:Grand View Research 的 $40.4B 欺诈检测市场暗示 HUMAN 的市场比仅机器人安全口径大 30-40 倍——这一差异源于范围而非错误。wmtips.com 把 Cloudflare 在机器人管理中接近 80% 的安装份额作为证据,说明 HUMAN 和其他专用供应商是在 Cloudflare 主导市场中的利基切块内竞争;在已由 Cloudflare 覆盖的市场中,这会把有效 SAM 压到远低于 $1.27B。抽样的市场研究报告均未体现这一约束,是公开分析中的重大缺口。任何财务模型都应在保守底线情景中,对 Cloudflare 已服务客户给 SAM 打 20–40% 折扣。 尽调问题:(1)要求 HUMAN 提供 ARR、NRR 和客户 cohort 数据,以验证 SOM 假设。(2)量化 HUMAN 目标买方细分中的 Cloudflare 渗透率,以测算剩余可服务空间。(3)获取 MRC 认证 SIVT 供应商市场的独立规模测算。(4)确认智能体信任管理细分是否正走向独立预算线,还是仍只是现有机器人管理合同中的功能扩展。 [CM012, CM035, CM036, CM045, CM048, CM049]

2.6 展示材料

Chapter 03

03竞争对手

3.1 竞争格局概览

HUMAN Security 位于两个快速演进市场的交汇处。在机器人和智能体信任管理领域,供应商集合包括专门构建的专业厂商(Kasada、Arkose Labs、DataDome、Netacea、Fingerprint)、把检测捆绑进更宽平台的基础设施原生玩家(Cloudflare、Akamai、Imperva/Thales),以及许多企业仍作为第一道过滤依赖的自建规则引擎和限速逻辑。在数字广告验证领域,HUMAN 2026 年 6 月新推出的 Ad Integrity Suite,直接进入与上市公司 DoubleVerify(FY2025 收入 $748M,同比增长 14%)和 Integral Ad Science(收入 $591M)的竞争,也面对全漏斗 GTM 安全平台 CHEQ。The Forrester Wave: Bot and Agent Trust Management Software Q2 2026 评估了八家供应商,并把类别从“Bot Management”更名为“Bot and Agent Trust Management”,说明竞争前沿已从检测自动化流量转向为合法 AI 智能体治理信任。HUMAN 和 Kasada 均被评为 Leader;Netacea 为 Strong Performer。Cloudflare 和 Akamai 未进入该 Wave,因为其产品仍是边缘/CDN 平台的附属功能,而非专门构建的机器人情报产品。塑造竞争的最重要结构性动态,是智能体 AI 的扩散:HUMAN 2026 年基准数据显示,AI 驱动流量仅在 2025 年就增长 187%,智能体浏览器流量同比增长 7,851%,意味着传统“是不是机器人”的二元判断已经过时,专门构建的信任管理平台相对传统 WAF 和 CDN 型检测具备结构性优势。 [CP001, CP002, CP003, CP004, CP005, CP033]

3.2 直接同业画像(机器人与智能体信任)

Kasada 是 HUMAN 在 Forrester Wave 中最直接的同业,也被评为 Leader,在九项标准上获得最高可能分数,Strategy 得分强。2026 年 2 月由 EQT 领投的 $20M 融资使 Kasada 总融资达到 $64.2M——远低于 HUMAN 估计的 $220M+——但公司声称保护超过 $150 billion 的 eCommerce 收入,这是企业采购中的有力证明点。值得注意的是,Kasada 超过 85% 的客户此前使用过另一家机器人缓解供应商,暗示其在竞争性替换中胜率高。Kasada 以服务器端、无 CAPTCHA 检测和据称 250%+ ROI 做差异化。Arkose Labs(融资 $114M,2021 年 Series C)占据不同利基,用 challenge-response 游戏化方式通过互动谜题刻意挫败机器人操作者,而非被动行为分析。Adobe 是其企业客户之一。截至 2026 年 6 月,Arkose 在 PeerSpot Bot Management 类别中的 mindshare 为 5.0%,高于上一年的 2.8%,说明尽管规模较小,企业认知度正在上升。DataDome(融资 $82M,2024 年 ARR $36M)聚焦电商和媒体,依靠快速边缘 ML 检测,服务 Rakuten、Reddit、AngelList 等 300+ 家企业;其收入 2023 至 2024 年从 $16.9M 几乎翻倍至 $36M。Fingerprint 以设备情报而非全栈机器人管理做差异化——其平台 2026 年每月识别超过 10 亿台独立设备,实现 65% ARR 增长,服务 2,000 家客户,NRR 为 128%,并新增 Booking.com 为客户。Netacea(融资 $29.7M,估值 $55.9M)以完全托管的服务器端服务模式差异化,由 Netacea 代表客户处理检测配置和调优;其在 Q2 2026 Forrester Wave 中获 Strong Performer 评级,并在 Web 和 LLM 抓取管理上得分最高。PeerSpot 2026 年 6 月 Bot Management 类别中,Imperva 以 15.7% mindshare 领先,Akamai 为 9.7%,两者均高于 HUMAN 的 8.1%;但这些既有位置更多反映安装基数,而非纯机器人情报能力。 [CP008, CP009, CP010, CP011, CP012, CP013]

竞争对手画像表
竞争对手类别成立时间总融资关键客户 / 证明目标分群关键差异点局限
HUMAN SecurityBot 防御 + 广告验证2012约 $220M(估算)全球品牌、广告平台、媒体企业四万亿级行为网络;Satori 威胁清剿;agentic 信任价格更高;humansecurity.com 屏蔽爬虫,限制公开定价证据
KasadaBot 防御 + agentic AI 信任2014$64.2M全球企业、零售、航空公司中大型企业服务端检测;无需 CAPTCHA;宣称 ROI 250%+;Forrester Wave 2026 Q2 领导者相比 HUMAN 团队和品牌更小;公开 ARR 披露有限
Arkose LabsBot 防御 + ATO2013$114MAdobe、银行、游戏平台中大型企业(游戏、金融科技)挑战-响应游戏化;专门 ATO 防护挑战会制造摩擦;偏 Web;最近一次大额融资是 2021 年 Series C
DataDomeBot 防护2015$82MRakuten、Reddit、AngelList电商、分类信息实时边缘 ML;快速部署;2024 年 ARR $36M相比 HUMAN 规模更小;主要覆盖 Web/API,agent 信任覆盖有限
Fingerprint设备智能2012$77MBooking.com、Dropbox、checkout.com 等客户金融科技、电商、SaaS每月 1B+ 设备 ID;128% NRR;Authorized AI Agent Detection;FY2026 ARR 增长 65%不是全栈 bot 管理;更像 HUMAN 的补充,而非替代
Cloudflare Bot ManagementCDN + bot 检测(捆绑)2009上市公司(NYSE: NET)所有使用 Cloudflare 的企业全分群(捆绑在边缘合同中)边缘集成;现有客户的边际成本近乎为零;ML bot 评分仅企业版 add-on;专项分析较弱;没有行为信号网络
Imperva / ThalesWAF + bot 防护2002 / 2023 年被收购上市公司(Thales 母公司)银行、合规要求重的企业企业合规(PCI DSS 4.0)700+ 行为维度;Bot Mgmt 心智份额最高(PeerSpot 2026 年 6 月 15.7%)设置成本高;Thales 收购带来整合风险;agentic AI 路线图较弱
Akamai Bot ManagerCDN + bot 防护1998上市公司(NASDAQ: AKAM)全球企业、电商大型企业 / DevOps 重度团队边缘源站前过滤;CI/CD 集成;心智份额第二高(PeerSpot 9.7%)相比 pure-play 厂商专项能力较弱;客户设置复杂度被提及
DoubleVerify (DV)广告验证2008上市公司(NYSE: DV)头部品牌、代理商、发布商广告生态(代理商、DSP、SSP)广告欺诈检测 67% 市场份额;FY2025 收入 $748M;109% NRR不是完整 bot 管理平台;应用 / API 欺诈覆盖有限
Integral Ad Science (IAS)广告验证2009上市公司(NASDAQ: IAS)头部品牌、代理商广告生态品牌安全、程序化衡量;2026 Q1 TTM 收入 $591M市场份额低于 DV;跟踪客户 167 家,DV 为 4,324 家
CHEQGTM 安全 + 广告欺诈2016私有公司企业 + SMB 效果营销团队效果营销 / GTM 团队每日 6T 信号;0.009% 误报率;可通过 ClickCease/Essentials 覆盖 SMB企业应用安全认知较弱;bot 缓解深度较轻
NetaceaBot 管理(托管服务)2015$29.7M全球零售、媒体、旅游企业(偏好托管服务)全托管;2026 Q2 Forrester 在 LLM 抓取和交易保障上得分最高融资基数小;全球品牌弱于 HUMAN;托管模式限制企业 DIY

融资数字来自 Tracxn、Crunchbase 和公司新闻稿;代表所有轮次累计融资。HUMAN Security 总融资为估算,基于公开披露轮次;准确数字未确认。心智份额百分比来自 PeerSpot 2026 年 6 月。ARR 数字来自 GetLatka 和公司披露(DataDome ARR 截至 2024 年 10 月)。

[CP005, CP008, CP011, CP013, CP017, CP019]
FP001: 竞争定位图 — Bot 与 Agent 信任厂商(2026 年 Q2)

关键 bot 管理和 agent 信任厂商在两条轴上的序数定位:检测深度(行为信号网络和威胁情报的复杂度,1=低至 10=高) vs. 平台广度(bot 检测之外覆盖的用例范围,1=窄至 10=广)。分数是有证据支撑的序数判断,来自 Forrester Wave 2026 年 Q2 评估、PeerSpot 心智份额数据,以及截至 2026 年 6 月的公司产品披露。

序数分数是基于公开证据的分析师判断,不是经审计的能力基准。Cloudflare、Akamai 和 Imperva 的分数仅反映其 bot 管理产品,不反映完整安全平台广度。DoubleVerify 和 IAS 纳入是为了定位参照,但它们主要在广告验证而非 bot 管理领域竞争。

[CP005, CP006, CP012, CP022, CP023, CP037]

3.3 广告验证与欺诈测量同业

HUMAN 2026 年 6 月推出 Ad Integrity Suite,将 IVT 情报、AI 驱动的品牌安全与适配性、可视性整合到单一框架中,使其直接与两家主导性上市广告验证平台竞争。DoubleVerify(NYSE: DV)报告 FY2025 收入 $748.3M,同比增长 14%,净收入留存 109%,每年测量 9.5 万亿笔可计费媒体交易。按 6sense 跟踪,DV 在广告欺诈检测工具中占 67% 市场份额,跟踪客户 4,324 家,而 IAS 为 167 家。Integral Ad Science(NASDAQ: IAS)截至 Q1 2026 的过去十二个月收入为 $590.67M,主要在品牌安全和程序化测量上竞争。DV 和 IAS 都与代理控股公司深度集成,并拥有 MRC 认证测量,这构成很强的切换成本护城河。HUMAN 的差异化明确是网络安全级欺诈情报——用可解释的 URL 级分类替代“黑箱”关键词信号,并由其行为网络支撑——以及把安全和广告验证收敛到一个安全、广告运营和营销团队可共享的统一平台。AdRoll 的 Global Head of Supply Platforms 称赞该套件透明、减少歧义,说明即便面对占主导的 DV/IAS 组合,HUMAN 仍有差异化定位。CHEQ 占据互补利基:其每天处理六万亿个信号,覆盖一百万个受监测域名,声称误报率为 0.009%,主要服务追求全漏斗 GTM 安全而非高端品牌安全库存测量的绩效营销人员和 SMB。广告验证领域是 HUMAN 战略风险最高的竞争向量,因为 DV 和 IAS 通过多年建立的 DSP/SSP 集成拥有合同杠杆,收入规模约为 HUMAN 估计 ARR 的 10x–15x,具备资本能力在验证层追平 HUMAN 的任何产品创新。 [CP009, CP010, CP033, CP034, CP035, CP036]

3.4 能力、定价与 GTM 对比

在纯机器人管理供应商中,各家都发布定制企业定价,没有公开价目表。Cloudflare 是唯一提供公开价格层级的平台——其 Bot Management 是 Enterprise-only 附加项,捆绑进月费约 $5,000 到 $80,000+ 的合同。对已使用 Cloudflare CDN 和 WAF 的组织来说,增加机器人管理的边际成本可能接近零,这让必须证明单独许可合理性的纯供应商处于结构性劣势。但 Cloudflare 的机器人检测专业化程度较低:它提供基于 ML 的机器人评分、JA3/JA4 指纹和检测 ID,但缺少专门供应商提供的行为信号深度(每年一千万亿次交互)、对抗性威胁情报或智能体信任治理。Imperva(Thales 旗下)以 15.7% 的 PeerSpot mindshare 领先,围绕 PCI DSS 4.0 合规和 700+ 个行为维度定位强;Akamai(第 2,9.7%)以 edge-first、源站前过滤和 CI/CD 集成差异化。与 Kasada 和 HUMAN 的 SDK/API 部署相比,两者初始设置复杂度更高。GTM 方面,HUMAN 最强的渠道是深度合作伙伴生态:Forrester 特别指出 HUMAN 合作伙伴项目的广度和获奖情况突出,并与新兴智能体信任和商务用例相匹配。OpenAI 和 AWS 等主要 AI 运营方已认可 HUMAN 是验证 AI 智能体流量的可信方案;随着智能体信任成为采购要求,这会形成生态锁定动态。Fingerprint 的 128% NRR 是强信号,说明买方在初始部署后会扩大使用,符合 land-and-expand 动作,与 Cloudflare 的 bundle-and-upsell 路径不同。自建替代——定制 WAF 规则、限速、设备指纹和 ML 异常检测——对大型技术原生企业仍可行,但需要持续投入专业人才,并持续跟上对抗性演进;大多数组织无法以 HUMAN 更新威胁情报的速度维持。2025 年桌面浏览器篡改技术在识别中的占比同比翻倍至 4.4%,说明检测复杂度不断升级;这更有利于拥有跨客户行为网络的供应商,而非单一企业自建系统。 [CP030, CP031, CP032, CP040, CP041, CP042]

功能与能力覆盖矩阵
能力HUMAN SecurityKasadaArkose LabsDataDomeCloudflare BMImperva
行为信号网络(跨客户)是 — 每年数千万亿次交互是 — 服务端遥测部分 — 挑战分析是 — 按客户运行边缘 ML部分 — Cloudflare 网络信号是 — 700+ 个行为维度
Agentic AI / LLM 代理信任治理是 — AgenticTrust,按代理细分权限是 — AI Agent Trust 产品 2026 年推出未知 — 无公开 agentic AI 产品未知 — 无公开 agentic AI 产品部分 — 仅拦截 AI 爬虫未知 — 无公开 agentic AI 产品
设备指纹 / 设备智能是 — 设备 + 浏览器信号是 — 设备遥测信号是 — 绑定挑战的指纹识别是 — 实时边缘指纹识别是 — JA3/JA4 TLS 指纹识别是 — 完整设备指纹识别
广告欺诈 / IVT 检测是 — Ad Integrity Suite,2026 年 6 月否 — 仅机器人防护否 — 聚焦 ATO / 机器人否 — 聚焦机器人 / 抓取否 — 无广告欺诈产品否 — 仅应用安全
威胁情报与下架行动是 — Satori 团队;协同下架未知 — 无公开威胁研究团队部分 — 共享挑战分析未知 — 无公开威胁研究部分 — Cloudflare 威胁情报源是 — 威胁情报源
全托管检测服务否 — 客户配置,HUMAN 提供支持否 — 平台驱动,低配置否 — 自助使用,提供指导否 — 自助 SaaS否 — 自助使用,解决方案工程团队支持否 — 客户管理,Imperva 提供支持

能力覆盖基于公开产品文档、Forrester Wave 2026 年 Q2 评估标准,以及截至 2026 年 6 月的公司网站内容。「未知」表示研究时无法从公开信息确认该能力。本表反映是否具备能力,而非落地深度。所有厂商的 agentic AI 覆盖都在快速演进。

[CP001, CP003, CP004, CP009, CP010, CP012]
定价与打包对比
厂商定价模型起步门槛(估计)企业级区间(估计)定价透明度关键打包说明
HUMAN Security定制企业级 SaaS未知 — 无公开定价未知 — 无公开定价不透明 — 无公开价目表Sightline Cyberfraud Defense 与 Ad Integrity Suite 分开销售;平台捆绑定价未披露
Kasada定制企业级未知 — 无公开定价未知 — 无公开定价不透明 — 无公开价目表声称 250%+ ROI;定价取决于流量规模和用例广度
Arkose Labs定制企业级未知 — 无公开定价未知 — 无公开定价不透明 — 无公开价目表挑战-响应 SaaS;定价可能随挑战量扩展
DataDomeSaaS 订阅$500–$1,000/月,小型网站估算$15,000+/月,企业级部分 — 有一些公开档位线索面向 Web、移动端、API 的机器人与欺诈防护;SMB 可进入的起步档位
Fingerprint按用量计费 SaaS有免费档$100–$10,000+/月,按 API 调用量部分 — SMB / 开发者档位有公开定价页设备智能 API;按每月识别事件数定价
Cloudflare Bot ManagementCDN 合同的企业级附加项$5,000/月最低(捆绑 Enterprise)$5,000–$80,000+/月,取决于部署范围中等 — 企业级区间可从采购数据公开估算Bot Management 捆绑进 Enterprise 方案;现有 Cloudflare 客户的边际成本接近零
Imperva (Thales)定制企业级前期成本高于 Akamai(据评论)定制 — 买方称长期 ROI 更高不透明 — 无公开价目表全栈 WAF + 机器人;定价随受保护流量和功能深度扩展
Akamai Bot Manager定制企业级设置成本低于 Imperva(据评论)定制 — 持续成本随高级功能扩展不透明 — 无公开价目表通常与 Akamai CDN/WAF 捆绑;对现有 Akamai 客户最具成本竞争力

所有定制企业级定价都来自第三方采购报告、PeerSpot 与 Gartner 买方评论,以及公开披露的定价分析(Cloudflare)估算。HUMAN、Kasada、Arkose、Imperva、Akamai 均没有厂商发布的价目表。DataDome 与 Fingerprint 基于开发者 / SMB 档位,具备部分公开定价。所有厂商的企业级定价都需要合同谈判,无法审计。

[CP031, CP032]
FP002: 能力深度图 — 头部 Bot 与 Agent 信任厂商

对 2026 年 Q2 Forrester Wave 及相邻市场中六家最常被评估厂商,按五项战略能力给出定性深度评估(强 / 中等 / 弱 / 未知)。 不同于二元覆盖表(TP002),这里关注已验证深度和市场证明,而非功能是否存在。

深度评级是基于 Forrester Wave 2026 年 Q2 评分、PeerSpot 同行评审分析和公开产品文档得出的分析师判断。 “强”需要独立佐证(Forrester 最高分、具名客户案例研究或新闻稿证明点)。“未知”表示尽管功能存在,但未找到公开深度佐证。

[CP004, CP006, CP013, CP021, CP037, CP038]

3.5 护城河耐久性与替代风险

HUMAN Security 的主要护城河是其行为信号网络——2025 年分析超过一千万亿次交互——形成数据飞轮,任何单客户替代方案都很难从结构上复制。Satori Threat Intelligence and Research team 增加第二层护城河:Forrester 指出,HUMAN 协调的攻击打击行动“产生的影响远超其客户群”,意味着该团队承担类似公共品的防御职能,以单客户部署无法比拟的方式强化 HUMAN 的信任品牌。平台与 WAF、CDN、IAM 和 Adobe Experience Platform 的深度集成创造的是运营层面而非合同层面的切换成本,因为拔掉 HUMAN 需要重配整个技术栈中的检测逻辑。但三类替代风险很实质。第一,基础设施捆绑:对现有客户而言,Cloudflare 的机器人检测边际成本近乎为零,将继续吸走成本敏感的 SMB 和中端市场。第二,高端竞争激烈:Kasada 85% 客户来自竞争对手的胜率,以及 Forrester 共同 Leader 位置,说明 HUMAN 的企业细分正被积极争夺,而非防御性主导。第三,广告验证替代:DV 和 IAS 的代理嵌入式测量关系比 HUMAN 的广告产品早十多年,即使 HUMAN 技术更优,既有者仍有显著惯性。正面的耐久性信号包括 HUMAN 下降但仍存在的 PeerSpot mindshare(8.1%,低于此前 11.6%),这反映 Cloudflare 和 Imperva 增长,而非纯专业厂商替代;以及 Forrester 将类别更名为“Bot and Agent Trust Management”,使市场定义与 HUMAN 在 AgenticTrust 上的平台投资对齐。登录后账户攻陷同比增长四倍(每组织平均 402,000 次尝试)和自 2022 年以来盗刷测试增长 250%,创造了结构性需求顺风,帮助护城河抵御商品化;攻击复杂度越高,行为网络专家与边缘捆绑替代方案之间的差距就越大。 [CP001, CP006, CP007, CP041, CP044, CP045]

护城河耐久性与竞争风险清单
护城河主张威胁严重性缓解 / 状态尽调问题
数千万亿次交互的行为数据网络带来检测优势Cloudflare、Akamai、AWS 也在积累自己的聚合流量信号,规模相当或更大HUMAN 的信号经过跨客户攻击相关性增强;原始规模必要,但不充分确认 HUMAN 的检测准确率基准是否在相同攻击类型上,独立验证过优于 Cloudflare BM
Satori Threat Intelligence 团队发起协同下架,所有客户受益竞争对手可能扩大威胁研究职能,或收购专业公司Forrester 将下架能力列为独特差异点;同业没有等价的公开战绩评估团队规模、留存和活跃行动管线;验证客户 NPS 是否具体归因于 Satori
深度 WAF/CDN/IAM/AEP 集成抬高运营切换成本客户可能整合到 Cloudflare 或 Akamai,以减少供应商数量HUMAN 的平台集成跨多层;替换它需要在整个技术栈重新配置检测获取客户合同条款(典型期限、自动续约、数据可携带性)及按原因拆分的流失归因
合作伙伴生态(OpenAI、AWS、Adobe)带来代理信任网络效应超大云厂商的竞争性代理信任框架可能抢先占位,或吸收 HUMAN 的位置Forrester 将 HUMAN 的合作伙伴计划列为突出项;超大云厂商合作是早期采用的现实信号确认关键 AI 运营方合作中的独家性或联合营销条款;评估合作伙伴渠道的收入贡献
既有行为信号网络从零复制成本高有超大云厂商背书、资金充足的新进入者,可能在 24–36 个月内建出相近规模可信新进入者尚未出现;该品类需要多年数据积累跟踪代理信任与机器人管理初创公司的风险投资,寻找资本充足的新进入者迹象
Ad Integrity Suite 借助既有行为网络,相比传统厂商提供更强 IVT 检测DoubleVerify 与 IAS 具备 MRC 认证、DSP/SSP 集成,以及 HUMAN 欠缺的 10+ 年代理商信任HUMAN 的差异点在可解释性和网络安全级信号;取得 MRC 认证是达到同等地位的前提评估 MRC 认证时间表,以及广告代理控股集团对 HUMAN Ad Integrity Suite 的采用率

严重性评级是分析师基于截至 2026 年 6 月公开证据作出的判断。「高」表示该威胁可能在 12–24 个月内实质影响 HUMAN 的竞争位置。「中」表示威胁真实存在,但若竞争对手不大举投入,短期内不太可能实质侵蚀护城河。所有尽调问题都需要非公开公司数据才能给出确定答案。

[CP001, CP005, CP006, CP007, CP041, CP044]
FP003: 护城河与竞争耐久性 KPI

截至 2026 年第二季度,HUMAN Security 竞争耐久性指标的压缩快照,取自可独立核验的公开来源。条目混合了已确认指标、分析师估计和章节级综合判断;单位和来源均已明确。

心智份额数据来自 PeerSpot 2026 年 6 月(bot 管理类别)。互动量来自 HUMAN 的 2026 年基准报告(公司发布)。威胁画像数量来自 HUMAN Threat Tracker,经已发布基准报告披露。Kasada 胜率来自 Kasada 新闻稿。Fingerprint NRR 来自 BusinessWire 新闻稿(2026 财年)。DoubleVerify NRR 来自 FY2025 IR 新闻稿。

[CP001, CP015, CP027, CP028, CP033, CP044]

3.6 展示材料

Chapter 04

04财务

4.1 收入架构与定价模型

HUMAN Security 围绕 Human Defense Platform 运营纯订阅 SaaS 模式,平台把三条商业支柱合在一起:广告保护、应用安全与 bot 缓解、账户保护。收入来自年度企业合同,定价看流量规模、受保护资产数量(web、移动端、API 端点)以及客户选择的具体模块组合。公司没有公开价目表;所有企业定价均为定制谈判。平台有四条可验证收入流:(1)广告 / 媒体安全(竞价前后欺诈、点击欺诈,以及通过 clean.io 收购获得的恶意广告防御);(2)应用安全与 bot 缓解(原 BotGuard 和 PerimeterX 技术栈);(3)账户保护(撞库、虚假账户创建);(4)2025 年 7 月推出、带 AgenticTrust 的 HUMAN Sightline,把 AI agent 信任和 agentic commerce 保护作为新兴第四条收入流。Vendr 给出的企业年支出中位数为每年 $104,906,披露区间从 $46,601 到大型复杂部署超过 $1.34 million。因此,官方定价只能作为标价下限代理,不能代表已披露的实际收入。欺诈防护具备任务关键属性,平台集成又很深、切换成本高,收入质量预期较高;但各细分领域的具体 ARR 组合没有公开。 [CI001, CI002, CI003, CI004, CI005, CI009]

收入来源
收入流机制单位当前状态 / 价值收入质量尽调问题
广告 / 媒体保护年度 SaaS 订阅;覆盖程序化广告、CTV、移动端的广告欺诈与恶意广告缓解按流量规模 + 模块范围活跃;主要历史收入流;clean.io 在 2022 年 11 月扩大了恶意广告覆盖高 — 对广告买方和发布商是关键任务;切换成本高相比应用安全的确切 ARR 贡献;发布商与品牌收入拆分
应用安全 / 机器人缓解年度 SaaS 订阅;覆盖 Web / 移动端 / API 的机器人防御、抓取、ATO、盗刷按受保护端点和流量规模活跃;2022 年 7 月通过 PerimeterX 合并显著扩展高 — 直接企业安全支出;深度嵌入客户基础设施合并后按原 HUMAN 与 PerimeterX 客户拆分的 ARR;来自整合的流失
账户保护年度 SaaS 订阅附加项;撞库、虚假账户、被盗账户防御按平台,分用量档活跃;身份欺诈升级带动该板块增长中高 — 面向既有平台客户的追加销售;挂载率未知账户保护挂载率;每席位增量 ACV
HUMAN Sightline / AgenticTrust年度 SaaS 附加项;AI 代理信任,以及代理式商业的可见性与治理按平台、代理量2025 年 7 月推出;商业化早期;上线时约 200 个客户使用该方案中 — 新产品;差异化强,但战绩有限早期 ARR;agentic AI 流量定价模型;客户采用率
公共部门(经 Carahsoft)通过经销商网络拿政府合同;NCPA、OMNIA Partners 合作采购工具按机构合同金额活跃且在增长;2022 年 11 月起与 Carahsoft 合作;2024 年聘任公共部门销售 VP中 — 采购周期更长;可能具备多年合同耐久性政府合同中标率;公共部门收入占总 ARR 的比例
渠道 / 合作伙伴收入通过 HUMAN Advantage Partner Program 间接产生;联合销售与转介绍新预订中的合作伙伴利润分成初期;计划 2024 年 8 月推出;未公开直接或间接来自合作伙伴的指标低中 — 早期渠道;管线生成尚无法衡量合作伙伴来源管线占比;合作伙伴对新 ARR 的挂载率

按收入流拆分的收入结构和 ARR 贡献未公开。状态和质量评估基于公司新闻稿、产品公告和合作伙伴计划文件,而非经审计财务。Clean.io 收购条款未披露。

[CI001, CI013, CI014, CI015, CI016, CI017]
定价与货币化
产品 / 客户层级合同类型年价格(USD)标价 vs. 实收来源
基础 Bot Defense / 中端市场年度 SaaS~$46,601(Vendr 低端)实收基准;标价未披露Vendr 采购基准(2025)
全平台套件 / 企业级中位数年度 SaaS~$104,906(Vendr 中位数)可能相对未披露标价打折;由规模和模块组合驱动Vendr 采购基准(2025)
大型 / 复杂企业年度 SaaS;可签多年最高 $1,343,250+(Vendr 高端)定制谈判;因流量规模、覆盖范围、SLA 差异显著Vendr 采购基准(2025)
公共部门(经 Carahsoft)通过 NCPA / OMNIA 合作采购的政府合同定制;按政府采购惯例低于标准标价适用政府折扣;无公开价目表Carahsoft 合作公告(2022)
AgenticTrust / HUMAN Sightline 附加项年度 SaaS;既有平台订阅的附加项未公开披露;截至 2025 年 7 月的新 SKU早期定价;标价或实收水平未知HUMAN 官方新闻稿(2025 年 7 月)

Vendr 定价数据代表 Vendr 企业买方网络的基准支出,不是 HUMAN 发布的价目表。实际实收价格会随交易规模、模块选择、流量规模和谈判筹码变化。AgenticTrust 是新推出产品,尚无可用基准数据。

[CI009, CI010, CI011, CI012, CI019]
FI001: 收入模型桥接 — 从客户互动到订阅收入

客户数字活动如何经过平台检测层和订阅开票,转化为 HUMAN 收入。

节点描述为定性信息;ML 模型、信号类型和模块收入组合的确切数量属于公司机密。各模块相对收入贡献未公开披露。

[CI006, CI013, CI027, CI028]

4.2 商业化动作与销售效率

HUMAN Security 有意识地改造 GTM:从历史上的纯直销组织,转向伙伴优先渠道模式。2024 年前,公司没有正式渠道计划,大客户需要直接谈法律、MSA 和定价条款,企业销售周期常见六到七个月。2024 年 8 月,HUMAN 推出 HUMAN Advantage Partner Program,这是一套分层渠道计划,激励依据年度化订单额、培训完成度和客户留存。计划面向全球经销商、分销商和咨询伙伴。另一路上,HUMAN 2022 年 11 月与 Carahsoft Technology 合作,由后者担任 Master Government Aggregator,让公共部门可通过 NCPA、E&I 和 OMNIA 合作合同采购。CEO Stu Solomon(2024 年 1 月任命,曾任 Recorded Future 总裁)和 CRO Chris Scanlan(曾任 ExtraHop 总裁)在执行商业和营销转向。伙伴驱动打法借既有伙伴关系和预存 MSA 缩短销售周期,压低平均成交时间,并扩大可触达管线。公开资料没有披露伙伴来源管线占比,也没有量化 CAC / 回本数据。生态优先打法还让 HUMAN 能触达分散的购买人群(安全、商业、数字、营销),同时不稀释直销带宽。 [CI018, CI019, CI020, CI021, CI022, CI023]

4.3 成本结构与利润率驱动因素

HUMAN 的成本结构主要由三类支出主导:(1)用于每周处理超过 20 万亿次数字交互(截至 2025 年年化超过 1 千万亿次)的 ML 和数据基础设施,带来大量云计算与存储支出;(2)Satori Threat Intelligence and Research Team,这是有人参与的成本中心,负责主动威胁研究并执行打击行动(3ve、Methbot、PARETO、BADBOX 2.0),让 HUMAN 的检测有研究背书,但也增加可观人力成本;(3)销售与营销,随着渠道计划投入增加、员工数从 2023 年末约 197 人增至 2026 年中估计 469–519 人而扩张。公司没有公开毛利率。SaaS 网络安全基准(Benchmarkit 2024/2025)显示,纯 SaaS 模式典型毛利率为 75–85%;若存在大量 human-in-the-loop 运营,毛利率会承压。HUMAN 的 Satori 团队,以及按互联网规模运行在 hyperscaler compute 上的信号采集基础设施,可能把利润率压到 SaaS 中位数基准以下。私营 SaaS 公司 R&D 估计约占收入 34%,而 HUMAN 这一增长阶段的 VC 支持 SaaS 公司销售与营销通常占 47%。若 HUMAN ARR 接近或达到 $100M,SaaS 基准是每 FTE 贡献 $200–$300K ARR,意味着收入效率中等。 [CI006, CI007, CI024, CI025, CI026, CI027]

单位经济
指标数值 / 状态置信度为什么重要尽调问题
ARR(公司声称)>$100M(公司披露;PerimeterX 合并后,2024 年 1 月重申)中 — 公司声称,未经独立审计经常性收入规模的主要指标按产品分部审计 ARR;ARR 定义(GAAP vs. bookings)
ARR(冲突的第三方数据)$15M(GetLatka,2023 年 12 月;可能反映合并前或不完整数据)低 — 第三方模型与员工数和并购证据不一致承销收入质量前,必须解决这一重大差异独立 ARR 审计;将 Latka 数字与公司账簿对账
毛利率未披露;SaaS 网络安全基准区间 65–85%;Satori 团队和基础设施可能把毛利率压到 75% 以下低 — 仅为基准估算决定收入增长可扩展性和盈利路径数据室中按产品线拆分的经审计 COGS vs. 毛利润
净收入留存(NRR)未披露;SaaS 基准中位数 101%(Benchmarkit 2024)低 — 基准代理;无 HUMAN 特定数据扩张 ARR 相比流失的质量;平台业务估值关键索取按产品模块和队列年份拆分的历史 NRR 与 GRR
企业销售周期大型企业 6–7 个月(公司披露,渠道计划前)中 — 公司在渠道访谈中披露;计划后尚未测量新 ARR 生成效率;现金转换周期验证 HUMAN Advantage Partner Program(2024 年 8 月)推出后的平均销售周期
每 FTE ARR$200–$300K(基于 $100M ARR 和约 500 名员工的 SaaS 基准代理)低 — 基准估算;HUMAN 实际数据不可得相对员工投入的收入效率用于内部人力规划和效率基准的实际每 FTE ARR

所有单位经济数值要么来自公司声称、相互冲突的第三方估算,要么来自 SaaS 行业基准;没有一项针对 HUMAN Security 得到独立验证。毛利率、NRR 和每 FTE ARR 仅为基准代理,考虑到其混合安全情报交付模式,可能无法反映 HUMAN 的实际运营模型。

[CI003, CI004, CI024, CI025, CI026, CI027]
FI002: 单位经济桥接 — 从成本驱动到毛利润(定性)

从平台运营到估计毛利润的定性成本驱动图;HUMAN 未披露单位经济,所有数值均基于基准估计。

所有成本节点均为估计,基于 Benchmarkit 2024/2025 SaaS 基准,并套用公司的 ARR 主张和公开员工数。HUMAN 未披露毛利率、COGS 构成或营业收入。实际单位经济可能存在重大差异。

[CI024, CI025, CI026, CI027, CI028]

4.4 公开财务牵引与私有指标缺口

HUMAN Security 是私营公司,披露的财务数据很少。主要公开牵引信号包括:(1)公司声称 ARR 超过 $100M,这一点最早在 2022 年 7 月 HUMAN+PerimeterX 合并实体宣布 ARR 超过 $100M 时得到确认,并在 2024 年 1 月 CEO 交接公告中再次提及,公告将该里程碑归功于 Tamer Hassan 任内;(2)截至 2024 年 10 月服务 500+ 全球品牌,多份新闻稿可相互印证;(3)平台规模达到每周验证 20 万亿次数字交互,2025 年年化超过 1 千万亿次。有一个直接冲突的第三方数据点:GetLatka 报告 HUMAN 截至 2023 年 12 月 ARR 为 $15 million。该数字与合并实体规模、员工数(2024 年中 437+ 人)以及合并后的 ARR 披露不一致。GrowJo 基于模型估算的年收入 $140.4M,更贴近合并后公司的状态。Latka 数字可能反映合并前 White Ops 独立收入,也可能是误算;没有审计披露前无法解决。公开来源完全缺失净收入留存、总收入留存、客户集中度和 cohort 级 ARR 数据。 [CI002, CI003, CI004, CI005, CI006, CI007]

公开财务缺口
缺失的私有指标对尽调的影响确切尽调路径
按产品分部拆分的确切 ARR(广告 vs. 应用 vs. 账户 vs. agentic)无法评估收入集中度风险、交叉销售效率或分部利润率索取按产品线拆分的经审计 ARR,以及各分部历史增长率
毛利率(GAAP)无法评估成本杠杆、基础设施可扩展性或盈利路径索取 GAAP 利润表,并要求 COGS 明细区分云基础设施和专业服务
净收入留存(NRR)和总收入留存(GRR)无法评估扩张质量、流失风险或 >$100M ARR 基础的耐久性按产品模块、合同批次和客户细分索取 NRR 与 GRR
月度现金消耗和当前现金头寸无法评估跑道、下一轮触发条件或困境风险索取 CFO 现金流桥表,包含未来 12 个月预测和当前银行余额
Blackstone Credit $100M 债务融资状态无法评估真实资本结构、契约风险或杠杆负担通过资料室条款清单核验;索取当前余额、契约和到期日
客户集中度(前 10 大客户占 ARR 比例)无法评估单一客户收入风险或企业合同韧性索取客户集中度分析;按 ARR、合作年限和续约历史列出前 10 大客户

本表所有项目都对应公开证据真正缺失的部分,是财务承销前的硬性尽调要求。公司声称 ARR 超过 $100M,而 GetLatka 给出的数字为 $15M,这一差异尤其是一级紧急缺口。

[CI003, CI004, CI031, CI037, CI038]
FI003: 财务估计区间 — 有来源支撑的关键指标上下界

HUMAN Security 关键财务指标的有来源支撑上下界;区间较宽,反映公司主张与第三方数据之间的冲突。

所有区间均为估计。ARR 区间横跨相互冲突的第三方数据与公司主张。烧钱率、跑道和估值均为推断。图中没有任何数值来自经审计财务数据。

[CI003, CI004, CI005, CI033, CI034]

4.5 资本充足性与融资依赖

HUMAN Security 已通过八轮融资累计募集约 $300 million 股权资本(Tracxn 和 SiliconAngle,2024 年 10 月),包括 2022 年 1 月 $100 million 成长期融资(WestCap、NightDragon),以及最近 2024 年 10 月 $50 million 成长期融资(WestCap、Goldman Sachs、ClearSky、NightDragon、Vertex Ventures US)。另在 2022 年 7 月,HUMAN 因 PerimeterX 合并从 Blackstone Credit 获得 $100 million 债务额度,使总资本资源达到约 $350 million 或更高。White Ops 2014 年 6 月就 Series A 向 SEC 提交 Form D,确认其 Delaware 注册地和最早股权融资事件。2024 年 10 月融资明确投向:加速 AI 平台能力(AgenticTrust 和高级检测模型)、拓展公共部门、强化渠道伙伴计划。以 2026 年中约 469–519 名员工、每名员工全成本 $180–$220K / 年(资深员工占比较高的科技公司)计算,隐含年度薪酬支出为 $84–$114M。加上云基础设施和 G&A,估计月度烧钱为 $9–$13 million。2024 年 10 月融资后,在该烧钱速度下推算现金续航期约 18–36 个月,取决于毛利率和收入增长,可延续到 2026 年末至 2027 年。现金头寸、准确烧钱速度和 Blackstone 债务额度当前状态均未公开。 [CI029, CI031, CI032, CI033, CI034, CI035]

资本充足性
项目金额 / 状态日期备注
Series A(向 SEC 提交 Form D)$11.1M 股权2014White Ops, Inc. CIK 0001611028;已确认在 Delaware 注册
Series B$20M 股权2016由机构投资者领投;公司规模化阶段
Goldman Sachs / ClearSky 投资未披露;收购多数股权2020-12Goldman Sachs 商业银行部门与 ClearSky;战略性多数股权投资
增长轮(WestCap / NightDragon)$100M 股权2022-01WestCap 领投;NightDragon 与 Goldman Sachs 追加投资;推动 PerimeterX 合并
Blackstone Credit 债务融资$100M 债务2022-07PerimeterX 合并时提供;截至 2026 年,偿还或展期状态未公开确认
增长轮(WestCap / Goldman / ClearSky / NightDragon / Vertex)$50M+ 股权2024-10WestCap 领投;资金用途:AI 平台、公共部门、渠道计划
总资本(股权 + 债务)~$350M 估计截至 2024 年 10 月公司披露约 $300M 股权;另有 $100M Blackstone 债务;部分轮次可能重叠
估计月度烧钱$9–$13M/月(推导)2026基于约 500 名员工、每人 $180–220K 全成本;另有云基础设施和 G&A;私有数据
估计续航期(2024 年 10 月轮次后)18–36 个月(推导至 2026 年底 – 2027 年中)2026-06取决于收入增长和毛利率;烧钱率为私有数据;需要尽调确认

确切现金位置、烧钱率,以及 $100M Blackstone Credit 融资的偿还或展期状态均未公开披露。月度烧钱和续航期估算由公开员工数和行业薪酬基准推导,实际数字可能存在重大差异。所有推导字段都需要数据室确认。

[CI029, CI031, CI032, CI033, CI034]
FI004: 资本历史 — 融资事件与战略目的

累计融资历史,展示 2014 至 2024 年的股权轮、债务授信及每次融资事件的战略目的。

Goldman Sachs 收购金额和 clean.io 收购价格未公开披露。Blackstone 债务授信的偿还状态未知。公司声明总股权融资约 $300M;包含债务的总资本约 $350M+。

[CI029, CI031, CI032, CI033]

4.6 财务结论

HUMAN Security 呈现出一个可信的 SaaS 平台业务:公司声称 ARR 超过 $100M,产品足迹具备高切换成本且可防守,并在 Forrester Bot Management Q3 2024 以及扩展后的 Bot and Agent Trust Management Q2 2026 中均获 Leader 评级。2024 年 10 月 $50M+ 融资和累计约 $300M 股权融资,显示投资人信心仍在。但收入质量、利润率路径和资本效率无法独立承销:毛利率、NRR、各细分 ARR、烧钱速度和现金头寸都未公开。公司声称的 >$100M ARR 与 GetLatka 的 $15M 数字存在重大差异,必须作为一级尽调事项独立解决。2022 年 Blackstone $100M 债务额度带来杠杆风险,尚未在任何公开文件中被对账。伙伴优先 GTM 转向战略上合理,但仍处早期;其对销售效率的贡献还无法从公开数据衡量。财务结论:考虑企业粘性和平台规模,收入质量看起来强,但利润率路径和资本强度仍是尽调阻塞项。 [CI003, CI004, CI031, CI036, CI037, CI038]

4.7 展示材料

Chapter 05

05产品与技术

5.1 Human Defense Platform — 产品线与客户工作流

Human Defense Platform(HDP)围绕一个统一主张搭建:数字交互进入客户创收工作流之前,应先被验证为合法人类活动、可信 AI-agent 流量,或已确认的自动化威胁。客户部署 HDP,主要应对三类核心工作流挑战。第一,在程序化广告供应链中剔除无效流量(IVT)和广告欺诈;DSP 与 SSP 接受出价时,往往不会验证底层流量。第二,阻断针对 web 应用、移动 app 和 API 的自动化滥用,包括撞库、抓取、交易滥用和虚假账户创建。第三,从初始注册到登录后金融活动,保护用户账户旅程。 截至 2026 年,HDP 包含四条有命名的产品线,可通过 AWS Marketplace 和企业合同采购:HUMAN Advertising Protection(原 MediaGuard)用竞价前和竞价后 IVT 检测保护程序化广告供应链;HUMAN Application Protection(原 Bot Defender)保护 web 与移动应用、API,抵御抓取、交易滥用、虚假注册等复杂 bot 攻击;HUMAN Account Protection(原 Account Defender)覆盖账户全生命周期,在登录前、登录时、登录后防御撞库和虚假账户欺诈;HUMAN Client-side Defense(原 Code Defender)让客户控制用户浏览器中运行的第三方脚本,并支持 PCI DSS 4 合规义务。另一个模块 BotGuard for Growth Marketing 面向营销漏斗完整性,通过过滤 bot 驱动的点击欺诈和虚假线索生成来发挥作用。 2025 年 7 月 30 日推出的 Sightline Cyberfraud Defense 平台,是所有产品线的统一界面;它加入 AgenticTrust,用于 AI-agent 分类与治理,也加入 Page Intelligence,为营销团队分析 AI 驱动流量。2022 年收购 clean.io 后,HUMAN 获得实时客户端 JavaScript 行为分析能力,用于恶意广告防御,把检测覆盖提前到攻击周期更早阶段。HUMAN 服务 500+ 全球品牌,覆盖媒体、金融、零售、政府和教育等垂直领域。[CE001, CE008, CE009, CE010, CE011, CE012]

Human Defense Platform——产品模块与资产矩阵
模块 / 产品线原名称目标用户成熟度 / 状态关键差异化证据 / 尽调缺口
Advertising ProtectionMediaGuardDSP、SSP、发布商、品牌GA——已上市 14 年以上竞价前 + 竞价后 IVT;FraudSensor;MRC 认证可见性(2026 年 4 月);TAG 认证收入或 IVT 降低指标未公开披露
Application ProtectionBot Defender / BotGuard电商、金融科技、SaaS、企业 Web/API 团队GA——成熟,持续更新2,500+ 信号、400+ ML 模型、低于 2ms 的判定;覆盖抓取、ATO、交易滥用、虚假注册未发布独立 TPR/FPR 基准;检测逻辑为黑盒
Account ProtectionAccount Defender金融服务、零售会员、游戏、教育GA覆盖登录前、登录时和登录后;设备与行为信号贯穿全生命周期NRR、留存 cohort 和账户欺诈降低指标未公开
Client-side DefenseCode Defender电商、需要 PCI DSS 4 的受监管行业GA——当前形态于 2022 年推出浏览器层脚本监控与执行;支持 PCI DSS 4 客户端合规产品独立安全审计未公开
AgenticTrust(Sightline 内)新产品——无原名称企业数字团队;代理式商务和 AI agent 治理GA——2025 年 7 月推出;2026 年加入 AWS Bedrock AgentCore 支持加密式 HTTP Message Signature 验证;按 agent 设置权限控制;AWS 原生集成采用指标、agent 覆盖广度相对竞品未披露
BotGuard for Growth Marketing 增长营销防护BotGuard for Growth Marketing 原名称效果营销、联盟营销、线索生成团队GA从营销漏斗中过滤虚假线索、机器人驱动的点击欺诈和联盟代码滥用营销归因栈中的覆盖范围和误报率未获独立验证

数据来自 AWS Marketplace 官方列表(2026 年 6 月)和 SoftwareOne 产品目录。原名称反映 Sightline Cyberfraud Defense 于 2025 年 7 月 30 日推出时应用的命名重组。成熟度评估来自公开产品可用性和上市年限, 不是内部产品就绪度评分。

[CE001, CE008, CE009, CE010, CE011, CE012]
客户用例——工作流、解决方案与限制
用户任务 / 威胁场景不使用 HUMAN 时的工作流HUMAN 解决方案模块可衡量收益(公司声称)已知限制
程序化广告购买;消除机器人驱动的 IVTDSP 接受的出价包含欺诈性无效流量;可见性指标被机器人展示抬高Advertising Protection + FraudSensor(竞价前和竞价后 IVT 过滤);MRC 认证可见性过滤 IVT 后的展示量;MRC 验证的可见性;减少浪费的广告支出在最低延迟库存路径上,低于 2ms 的插入仍会增加延迟;竞价前覆盖取决于 DSP/SSP 集成广度
Web 应用防护;阻断撞库和抓取限速和 CAPTCHA;成熟攻击者大规模轮换 IP 并绕过 CAPTCHAApplication Protection;分析 2,500+ 信号;Precheck 自动验证约 95% 的用户;Human Challenge 处理模糊会话95% 合法用户无摩擦通过;靠行为和设备画像阻断复杂机器人活动多区域或自定义 API 配置需要复杂规则管理;文档深度被提及为改进点
全生命周期账户安全;防止 ATO 和虚假账户只在登录时认证;登录后异常检测偏被动,且局限于会话Account Protection;登录前 / 登录时 / 登录后行为连续性;覆盖账户生命周期的设备和会话历史生命周期覆盖减少绕过单点登录控制的欺诈;覆盖虚假账户创建和被攻陷账户使用未发布 TPR/FPR 基准;结果指标(欺诈降低比例、拒付率)未获独立验证
治理访问数字资产的 AI agents没有标准化治理;组织要么阻断所有类似机器人的流量(误拦合法 agents),要么放行所有自动化Sightline 内的 AgenticTrust;分类 agent 类型和信任等级;执行按 agent 设置的权限;为 AWS Bedrock agents 做加密验证支持代理式商务,同时不打开攻击面;减少冒充和过度代理式抓取加密验证仅限实现 HTTP Message Signatures 的 agents;不支持签名的旧式 agents 默认走行为启发式判断

收益主张来自公司表述或分析师报道;独立结果基准未公开。限制项来自截至 2026 年 6 月的用户评论(TrustRadius、PeerSpot) 和分析师评论。

[CE006, CE019, CE020, CE033]
FE002: 客户保护工作流 — 从互动到执行

端到端流程:传入数字互动后,经过 Sensor 采集、Decision Engine 判定,并对人类、bot 和 AI agent 做差异化执行。

[CE005, CE006, CE019, CE020, CE033]

5.2 核心技术架构与检测方法

HUMAN 的检测架构拆成两个互补部署组件:Sensor 和 Enforcer。JavaScript Sensor(AgenticTrust 支持要求 9.6.6+ 版本)通过 HTML head 标签注入客户 web 资产,采集设备指纹信号、行为生物特征、会话历史和网络特征。这条客户端信号流会传到 HUMAN 云端托管的 Decision Engine,做实时分析。 Decision Engine 是平台核心智能层,每次交互处理 2,500+ 个信号,调用 400+ 个自适应 ML 模型,在两毫秒内给出判定——人类、bot 或 AI agent。约 95% 流量通过 Precheck 机制自动验证,不增加用户摩擦;只有信号画像模糊的交互才会触发 Human Challenge。ML 技术栈包括 Profile Deviation Models 2.0,用于检测登录后异常行为;攻击画像,用于把流量切分成不同的行为威胁画像;以及网络攻击事件检测,用于评估进行中攻击活动的范围和协同复杂度。HUMAN Threat Tracker 把这些画像呈现为安全团队可行动的情报仪表盘。 执行侧,HUMAN 的 Enforcer 支持 20 多种集成形态,覆盖主要 CDN 和云服务商(AWS Lambda@Edge、Azure Front Door、Cloudflare、Fastly VCL、Akamai EdgeWorker、Edgio)、服务器框架(Nginx、Apache、HAProxy、Envoy、Varnish)、语言运行时(Go、Java、.NET Core、Node Express)、API 网关(AWS API Gateway、Apigee、Kong)和企业平台(Salesforce)。AgenticTrust 模块不支持 Python、PHP、Ruby 和 Akamai ESI。FraudSensor 是 HUMAN 的竞价后广告检测组件,在广告投放后验证曝光,提供按供应路径切分、已过滤 bot 流量的可见率,构成 MRC 认证 Ad Viewability Measurement 产品的基础。[CE002, CE003, CE005, CE006, CE015, CE016]

技术与运营架构——层级和依赖
层级 / 组件角色关键技术 / 规格依赖风险
JavaScript Sensor(客户端)从用户浏览器收集设备指纹、行为生物识别、会话和网络信号用于 AgenticTrust 的 JavaScript Sensor v9.6.6+;通过 HTML <head> 标签注入需要访问 HTML head 标签;会被浏览器广告拦截器和隐私扩展阻断或削弱隐私工具普及和服务端渲染会降低部分会话的信号保真度
Enforcer(服务端 / 边缘)在 CDN、WAF、API gateway 或源站内联执行机器人判定;对确认威胁进行阻断、重定向或限速20+ 个 Enforcer 集成:AWS Lambda@Edge v4.8.0+、Cloudflare v6.12.0+、Fastly VCL v12.3.0+、Akamai EdgeWorker v4.4.0+、F5 BIG-IP v3.1.1+、Nginx、Kong、Azure Front Door v1.2.1+CDN/云服务商可用性;各集成的 API key 管理;AgenticTrust 不支持 PHP、Python、Ruby 运行时单一 CDN 提供商宕机或集成版本不匹配会削弱执行路径;自定义运行时需要手工 SDK 集成
Decision Engine(云托管)中央 AI/ML 判定系统;每次交互处理 2,500+ 信号,使用 400+ 自适应 ML 模型;给出低于 2ms 的判定专有多区域云栈;Precheck 机制自动验证约 95% 流量;用于登录后异常的 Profile Deviation Models 2.0HUMAN 云基础设施正常运行时间;ML 模型刷新节奏;数据合作质量平台侧事件会直接影响客户防护;模型更新可能短暂影响误报率
Behavioral Signal Network(数据基础)训练和推理数据语料;提供跨客户威胁关联;用新攻击模式丰富 ML 模型每周 20T+ 次交互,覆盖 3B 台设备;14+ 年行为数据;由 Satori IOC 管线补充与主要广告交易所、CDN 和平台的数据合作;持续的数据合作伙伴协议网络效应取决于平台规模;较小或垂直细分场景获得的关联信号相对更少
FraudSensor(竞价后广告检测)广告投放后验证展示;在可见性计算前过滤机器人和 IVT 生成的展示竞价后检测;供应路径级信号分析;MRC 认证可见性输出与 DSP/SSP 数据管线集成;MRC 审计合规竞价后检测在成本已经发生后捕捉欺诈;它不阻止欺诈性出价,只验证结果

架构细节来自截至 2026 年 6 月的 HUMAN 技术文档、AWS Marketplace 列表和 SoftwareOne 产品目录。Enforcer 最低版本来自 HUMAN 官方 AgenticTrust 文档。风险评估由分析师根据公开架构披露推断;内部 SLA 和正常运行时间数据未公开。

[CE002, CE003, CE004, CE005, CE015, CE016]
FE001: Human Defense Platform — 架构栈

从行为信号基础到统一产品界面的五层架构,展示 Sensor、Enforcer、Decision Engine 与 Satori 情报如何咬合。

分层由分析师根据公开架构披露归纳;内部服务边界和确切数据流拓扑未公开披露。

[CE002, CE003, CE004, CE007, CE015, CE016]

5.3 Satori Threat Intelligence — 研究与打击行动

Satori Threat Intelligence and Research Team 是 HUMAN 的内部威胁研究单元,运营上由 Lindsay Kaye(Vice President of Threat Intelligence)领导,并由 Gavin Reid(CISO)监督。Satori 的职责不止于被动检测:团队调查、逆向,并组织针对大规模威胁行为者计划的协同打击行动。这种主动姿态——公开披露打击行动,拆除犯罪基础设施,而不只是阻断流量——是 HUMAN 在 Forrester Wave Q2 2026 获得高分时被提到的主要差异化;HUMAN 是 Threat Research 标准中唯一拿到满分 5/5 的厂商。 历史打击行动包括:3ve(与 FBI、Google、Facebook 合作拆解的大规模 CPC 欺诈计划)、Methbot(最终使运营者获刑 10 年)、PARETO(当时识别出的最复杂 CTV botnet,与 Roku 和 Google 合作打击)、Scylla(瞄准 Google Play 和 Apple App Store 上的广告 SDK)、BADBOX 2.0、SlopAds 和 Pushpaganda。最近一次重大行动是 2026 年 5 月 19 日披露的 Trapdoor:一个多阶段计划,在 455 个恶意 Android app 和 183 个威胁行为者自有 HTML5 域名中,把恶意广告分发与隐藏广告欺诈变现融合起来。高峰期 Trapdoor 每天产生 4.8 亿次 bid requests;Google Play 移除已识别 app 前,相关 app 下载量超过 2,400 万次。 这些行动沉淀出的情报会增强 Decision Engine 的 ML 模型,并通过私营部门和公共部门合作共享,包括执法机构、应用商店运营方和云服务商。现场研究与产品防护之间的反馈回路,构成纯检测厂商难以复制的技术护城河。Satori 还提供实时事件覆盖——2026 年 2 月 Super Bowl LX 期间,HUMAN 追踪到 7,400 万次被阻断的零售抓取攻击、无效 bid requests 上升 33%,以及 AI agent 活动增加 5%。[CE027, CE028, CE029, CE030, CE031, CE037]

5.4 部署、集成与产品路线图

HUMAN 的部署模式是 cloud-native 且 integration-forward。客户可通过直接云合同、AWS Marketplace,或 Carahsoft(联邦与公共部门分销)等渠道伙伴访问 HDP。平台可接入 CDN、WAF、CIAM 平台和分析基础设施,不要求客户重构技术栈。部署形态从轻量级纯 Sensor 实施(适合需要信号覆盖但不需要 inline enforcement 的组织),到 CDN 或源站层的完整 Sensor-plus-Enforcer 部署。 2026 年,AgenticTrust 把加密验证支持扩展到 Amazon Bedrock AgentCore 流量,AWS 合作显著加深。基于 Bedrock 平台构建的 AI agents 现在可通过 HUMAN 的 AgenticTrust 模块完成加密签名和策略验证,让企业能对运行在 AWS 托管应用中的 AI agents 执行细粒度、逐动作控制。AgenticTrust(最低 Sensor 版本 9.6.6)支持的集成目标包括 AWS Lambda@Edge v4.8.0 起、AWS API Gateway v0.1.1 起、Cloudflare v6.12.0 起、Fastly VCL v12.3.0 起、F5 BIG-IP v3.1.1 起,以及 Azure Front Door v1.2.1 起。 标准层面,HUMAN 2025 年 11 月开源 HUMAN Verified AI Agent 的参考实现,演示用 HTTP Message Signatures(RFC 9421)做加密 agent 身份,具体通过 Ed25519 密钥对和 OWASP Agent Name Service(ANS v1.0)命名标准实现。这让 HUMAN 同时成为商业厂商和生态标准贡献者。2026 年 4 月 Agentic Visibility 扩展把 Sightline 的 bot 与 agent 分类数据原生延伸进 Adobe Experience Platform,使 HUMAN 成为唯一为营销测量团队提供原生 Adobe 集成的 bot-management 厂商。[CE015, CE016, CE018, CE032, CE033, CE035]

产品路线图与关键里程碑(2022–2026)
日期 / 阶段功能 / 里程碑状态影响来源
2022 H2收购 clean.io(反恶意广告);整合进 HUMAN Advertising Protection已完成为恶意广告防护加入实时客户端 JS 行为分析;clean.io 收购前覆盖每月 125B 次展示aithority.com;darkreading.com 报道
2025 年 7 月 30 日推出 HUMAN Sightline Cyberfraud Defense,包含 AgenticTrust;在 human、bot、AI agent 层面提供主体级可见性GAHUMAN 首个统一 human/bot/AI-agent 信任层;基于意图的治理模型取代二元 bot/human 检测knowledgenile.com
2025 年 11 月开源 HUMAN Verified AI Agent 参考实现;HTTP Message Signatures(RFC 9421);OWASP ANS v1.0已发布(GitHub)将 HUMAN 放在加密 agent 身份标准贡献者的位置;用 Ed25519 keys 演示 A2A 协议github.com/humansecurity/human-verified-ai-agent 代码库
2026 年 4 月 21 日Agentic Visibility 扩展到营销和商务团队;原生集成 Adobe Experience PlatformGA将 Sightline 的 bot/agent 分类数据延伸到营销测量工作流;Adobe 合作降低采用摩擦ppc.land;cmswire.com 报道
2026 年 4 月 27 日Ad Viewability Measurement 的 MRC 认证(展示 + 视频;桌面、移动 Web、移动应用)已授予行业验证 HUMAN 的 IVT 过滤可见性方法;MRC 历史上首个 security-first 可见性认证ppc.land(MRC 认证文章)
2026(持续)AgenticTrust 为 Amazon Bedrock AgentCore 提供加密验证支持;AWS 上符合策略的 AI agentsGA(滚动支持)使用 AWS Bedrock 承载代理式工作负载的企业可加密验证 agent 身份;执行按操作设置的治理策略itdigest.com

路线图条目来自官方公告和第三方新闻报道。不包含 2026 年 6 月之后的前瞻性项目;截至研究日期,HUMAN 没有可公开获取的路线图文件。

[CE013, CE014, CE032, CE033, CE034, CE035]
FE003: 关键依赖地图 — 平台、伙伴与生态

HUMAN 关键外部依赖的有向图,覆盖云基础设施、执行伙伴、数据伙伴、分析集成和打击行动伙伴。

[CE015, CE016, CE031, CE032, CE033]

5.5 信任、合规、隐私与已识别限制

HUMAN 的正式合规姿态由 2026 年两项外部验证支撑:Ad Viewability Measurement 的 MRC 认证(2026 年 4 月 27 日授予),以及有效的 TAG(Trustworthy Accountability Group)认证。MRC 认证值得注意,因为 HUMAN 的方法把 FraudSensor IVT 过滤直接纳入可见性计算——系统只把经人类验证的曝光计为可见,这是一种 security-first 架构,多数纯可见性厂商并未采用。认证覆盖桌面端、移动 web 和移动 app 的展示与视频曝光。Client-side Defense 产品通过监控并执行消费者浏览器中的 JavaScript 行为策略,明确支持 PCI DSS 4 客户端要求。 公开证据中存在实质限制。HUMAN 没有发布受控条件下的独立误报率或真阳性率基准,潜在客户很难在厂商中立基础上比较其检测准确性与竞品。站在客户视角,Decision Engine 像一个「黑箱」:客户拿到威胁判定和攻击画像,但对具体模型逻辑或信号权重能见度有限。企业客户报告称,拥有定制 API 基础设施的组织会遇到集成复杂性;自定义规则管理的文档深度也被点名为改进空间。另外,截至 2026 年 6 月,HUMAN 在 PeerSpot 上的 Bot Management mindshare 同比从 11.6% 降至 8.1%,说明即便分析师认可度强,竞争压力仍在。 隐私控制依赖标准企业 SaaS 做法。HUMAN 的信号网络以大规模采集行为和设备数据;公司没有公开独立隐私审计或详细数据保留政策。监管行业客户(医疗、金融服务、EU GDPR 范围)会把未发布独立隐私审计视为尽调缺口。企业采购标准暗示需要 SOC 2 Type II 合规,但公开资料未确认。[CE034, CE038, CE039, CE042, CE043, CE044]

信任、质量与合规控制
控制 / 认证状态(2026 年 6 月)范围缺口 / 限制
MRC 广告可见性测量认证2026 年 4 月 27 日授予覆盖桌面、移动 Web 和移动应用的展示与视频展示;涵盖可见性 + IVT 过滤(FraudSensor)截至 2026 年 6 月,CTV 可见性 MRC 扩展未确认;认证覆盖测量方法,不覆盖更广泛的 HDP 安全态势
TAG(Trustworthy Accountability Group)认证有效——在 2026 年再认证周期续期数字广告供应链反欺诈标准;适用于广告生态合作伙伴范围限于广告垂直;不覆盖应用防护、账户安全或 AgenticTrust 能力
PCI DSS 4 客户端合规支持由 Client-side Defense(Code Defender)支持在浏览器层执行第三方脚本行为策略,这是 PCI DSS 4 客户端控制要求合规证明由客户负责;HUMAN 出具的独立 PCI 审计报告未公开
GDPR / CCPA 数据处理企业 SaaS 标准隐含要求;未公开披露独立审计为企业客户在欧盟和美国隐私框架下收集信号、处理行为数据精确数据留存周期、子处理方清单和 DPA 模板未公开发布;SOC 2 Type II 认证未公开确认

合规状态来自 HUMAN 官方公告和第三方新闻报道。SOC 2 和 ISO 27001 认证是企业网络安全 SaaS 供应商的标准配置, 但公开来源尚未独立确认 HUMAN 具备这些认证。缺口项反映公开证据缺失,不代表已确认的不合规。

[CE034, CE038, CE039]
FE004: 按模块评估产品成熟度与能力

截至 2026 年 6 月,分析师从五个维度评估 HUMAN 五条主要产品线 / 模块的能力成熟度。

成熟度评分是分析师基于公开披露、第三方评论和截至 2026 年 6 月的分析师报告作出的评估。它们不反映 HUMAN 内部能力评分卡。

[CE001, CE030, CE042, CE043, CE044]

5.6 展示材料

Chapter 06

06客户

6.1 客户群分层

HUMAN Security 的客户群横跨五个不同购买细分,与其三支柱产品平台(广告保护、应用 / bot 防御、账户保护)相匹配。按历史收入看,最大细分是广告技术:DSP、SSP、广告验证厂商、代理控股公司和品牌广告主,它们需要 MRC 认证的无效流量过滤来保护数字媒体预算。LinkedIn(B2B 职业网络)、Sovrn(出版商平台)、Madhive(本地媒体 CTV OS)和 AdRoll(效果 DSP)是该垂直中的具名生产客户。第二个细分是程序化市场和商业平台——电商与零售品牌需要 Bot Defender 和 Sightline 阻断抓取、撞库和 ATO 攻击。Gartner Peer Insights 上来自 $500M–$1B 与 $10B+ 零售账户的评论,描述了高热度球鞋发售和多品牌电商组合中的生产部署。第三个细分是金融服务;2026 年 5 月 agentic AI 流量环比翻倍(HUMAN 自有基准),带动账户保护和交易欺诈防御需求。第四个细分是更广义的企业安全团队——保护 web 应用、API 和移动渠道的组织——它们通过渠道计划访问 HUMAN 平台(Optiv 服务 73% 的 Fortune 100,Consortium Networks 则提供托管安全礼宾服务)。旅游与酒店是正在出现的第五个细分;一位来自 $250M–$500M 旅游品牌的 Gartner 评论者描述了托管 bot 防御的生产使用。地域分层以北美和西欧为主,Tel Aviv R&D 和英国商业团队支持 EMEA。公司未公开按垂直或地域划分的收入拆分。 [CU001, CU002, CU003, CU004, CU005, CU006]

客户细分地图
细分主要买方 / 用户核心用例规模 / 收入信号代表客户 / 合作伙伴证据缺口
广告与广告技术DSP、SSP、品牌广告主、代理商竞价前和竞价后 IVT 检测;MRC 认证广告欺诈防护历史最大细分;声称覆盖 500+ 全球品牌Madhive、LinkedIn、Sovrn、AdRoll未披露收入占比或账户数量
电商与零售安全工程师、欺诈运营、产品经理Bot Defender、ATO 防范、抓取防护、高热度活动保护来自 $500M–$1B 和 $10B+ 零售商的 Gartner 评论Gartner 中的具名账户(匿名)、运动鞋零售商案例未公开点名生产客户
金融服务欺诈团队、应用安全负责人账户接管、撞库、交易滥用防护2026 年 5 月该垂直的 agentic 流量环比翻倍(HUMAN 基准)未具名;无公开案例研究具名证明最弱的细分
企业安全(通过渠道)CISO、安全架构师、IT 采购通过 Optiv/Consortium Networks 托管服务部署全平台Optiv 服务 73% 的 Fortune 100;Consortium Networks 作为 concierge MSSPOptiv、Consortium Networks(具名渠道伙伴)未披露来自渠道的终端客户名称
旅游与酒店应用安全工程师机器人缓解、托管机器人防御、DDoS 辅助来自 $250M–$500M 旅游品牌的 Gartner 评论(2026)匿名 Gartner 评论者该细分仅识别出一个客户

HUMAN(私营公司)未披露各细分收入占比。规模信号来自 Gartner Peer Insights 评论者行业、新闻稿和 MRC 认证部署公告。 金融服务条目基于 HUMAN 自身 agentic 流量基准数据,不是具名客户。

[CU001, CU002, CU003, CU004, CU005, CU006]

6.2 采用轨迹与规模

HUMAN 最可信的采用信号,是其集体防御网络的绝对规模。公司 2026 State of AI Traffic & Cyberthreat Benchmark Report(2026 年 3 月 26 日发布)称,2025 日历年分析了超过 1 千万亿次数字交互;Gartner Peer Insights 公司简介(2026 年 2 月更新)则称 HUMAN「每周在广告、营销、电商、政府、教育和企业安全领域验证超过 30 万亿次数字交互」。这高于 2024 年 10 月融资时引用的每周 20 万亿次,说明网络确有增长。公司声称拥有 500+ 全球品牌和组织客户,这一指标在 2022 至 2026 年新闻稿中保持一致。一个有意义的采用加速标志,是 agentic AI 流量的指数级增长:HUMAN 平台识别出 2025 年 AI agent 流量同比增长 7,851%,合法 AI 驱动流量同期整体增长 187%,高度集中在零售 / 电商、流媒体 / 媒体、旅游 / 酒店——这三类也是 HUMAN 按流量计的领先客户垂直。公开来源确认的具名部署包括 LinkedIn(2024 年 5 月集成,保护 10 亿+ 成员职业网络)、AdRoll(2025 年 10 月,首个把 HUMAN 竞价前欺诈防御与可见性结合的 DSP)、Sovrn(长期伙伴,在 2026 年 4 月 MRC 认证公告中被引用)和 Madhive(HUMAN CEO Stu Solomon 2025 年 6 月称其为「长期合作伙伴」)。这家私营公司没有公开 ARR 增长轨迹、客户数 CAGR 或部署里程碑节奏,留下重大跟踪缺口。 [CU007, CU008, CU009, CU010, CU011, CU012]

客户增长与采用轨迹
指标数值日期来源置信度影响缺失分母
每周验证的数字交互>30 trillion/week2026-02-17Gartner Peer Insights 公司资料网络增长:从 20T(2024 年 10 月)到 30T+(2026 年 2 月)无客户数量分母
年度分析的数字交互2025 年 >1 quadrillion2026-03-26HUMAN 2026 State of AI Traffic 基准(newsroom)平台规模可观;前提是 HUMAN 自身网络达到这一量级无按客户细分或产品拆分
服务的品牌 / 组织500+ 全球品牌2024-08-21HUMAN GlobeNewswire 合作伙伴计划新闻稿多份新闻稿重复这一说法,但未披露方法;可能是 logo 而非 ARR独立付费客户、logo 与集成平台之间边界不清
每月监测设备每月 3 billion 台设备2024-08-21HUMAN GlobeNewswire 合作伙伴计划新闻稿大规模设备指纹;多份新闻稿说法一致无按产品或垂直拆分
AI agent 流量同比增长7851% YoY in 20252026-03-26HUMAN 2026 AI Traffic 基准指向 AgenticTrust 模块的绿地需求;先发优势百分比基于 HUMAN 自身平台,不代表全行业
LinkedIn:检测到的 IVT 率前 30 天桌面展示 <1%2024-06-20HUMAN/LinkedIn 联合新闻稿(Yahoo Finance)有可衡量结果验证生产部署质量单一 30 天窗口;没有长期跟踪

指标来自公司发布的新闻稿和第三方报道。置信度评级反映来源独立性和交叉验证程度。500+ 品牌说法在多份新闻稿中一致, 但未经审计。LinkedIn <1% IVT 是高置信度主张,由具名交易对手的联合新闻稿佐证。

[CU007, CU008, CU009, CU010, CU011, CU012]
FU002: 采用与部署漏斗

从发现到扩展的漏斗,展示从品牌认知到多模块生产部署的转化路径。

顶部阶段(500+ 个品牌)是公司在多份 2024 年新闻稿中的主张;未经审计。具名生产部署(6)是 TU003 中公开验证的条目。有量化结果的部署(3)指发布过指标的案例(LinkedIn <1% IVT、AdRoll 12ms、Madhive Fraud Free Guarantee)。多模块估计(2)由 Madhive 和 LinkedIn 在广告 + 应用表面联合使用的证据推断;HUMAN 未披露模块挂载率或 pipeline 数量。

[CU007, CU009, CU015, CU031]

6.3 具名客户证明

截至 2026 年 6 月,公开证据可支持六个具名客户或伙伴部署。Madhive 是最强案例:它是 Fox、Scripps 和 Hearst 信任的领先本地媒体 CTV 操作系统。2025 年 6 月,Madhive 宣布由 HUMAN 的 MRC 认证竞价前后欺诈检测驱动的 Fraud Free Guarantee,覆盖每天 30,000+ 个本地广告活动,单个预算平均低于 $5,000。HUMAN CEO Stu Solomon 在公开公告中称 Madhive 为「长期合作伙伴」,说明双方有多年生产关系。LinkedIn 2024 年 5 月集成 HUMAN,前 30 天内,该部署在 LinkedIn 包括 CTV 的出版商网络中检测出低于 1% 的桌面曝光为无效流量——这是带具名发言人(LinkedIn Marketing Solutions VP Abhishek Shrivastava)的量化结果。Sovrn 是出版商 / 广告主平台,在 HUMAN 2026 年 4 月 MRC 可见性认证公告中被具名引用,MD Jeff Meglio 也提供了关于「更强广告活动表现」和「更高效预算利用」的证言。AdRoll 2025 年 10 月成为首个把 HUMAN FraudSensor 竞价后测量与 MediaGuard 竞价前技术结合的 DSP,可在 12 毫秒内检测 IVT。Consortium Networks CEO Nate Ungerott 在 2024 年 8 月伙伴计划发布时提供公开证言,称 HUMAN 为复杂欺诈防御给「客户带来卓越价值」。HUMAN 将服务 73% Fortune 100 的 Optiv 称为「不可或缺的盟友」渠道伙伴。Forrester Wave Q2 2026 报告还指出,「HUMAN 客户称赞他们从 Sightline 功能获得的细节层级和攻击洞察」,说明具名集合之外也存在可作参考的部署,但未披露具体组织名称。 [CU015, CU016, CU017, CU018, CU019, CU020]

具名客户证明表
客户 / 合作伙伴细分部署 / 用例状态结果证据新鲜度限制
Madhive广告技术 / CTV 本地媒体 OS面向 30,000+ 个每日本地 campaign 的 MRC 认证竞价前 Ad Fraud Defense + 竞价后 Ad Fraud Sensor生产(CEO 引述称为长期合作伙伴)Fraud Free Guarantee 于 2025 年 6 月推出;针对可疑流量的抵扣机制;Madhive 使用 HUMAN 技术获得 SOC I/II/III + TAG 认证2025-06-04只有 CEO 层面引述佐证;未披露量化欺诈降低率
LinkedIn广告技术 / 职业社交平台面向桌面和 CTV 发布商网络的竞价前 IVT 过滤 + 竞价后检测(1B+ 会员)生产(自 2024 年 5 月起)上线前 30 天桌面展示 IVT 率 <1%;VP Abhishek Shrivastava 公开背书2024-06-20结果仅来自上线窗口;2025 或 2026 年未发布更新
Sovrn广告技术 / 发布商平台MRC 认证 HUMAN Ad Viewability Measurement,提供 IVT 过滤后的可见展示生产(BI 文章称为长期合作伙伴)MD Jeff Meglio:HUMAN 可见性指标通过详细报告,让绩效测量更可信2026-04-27证据停留在推荐语层面;未披露 campaign 结果指标
AdRoll广告技术 / 效果 DSP首个结合 HUMAN FraudSensor 竞价后 + MediaGuard 竞价前的 DSP;在桌面、移动、应用内、CTV 上 12ms 检测 IVT生产(自 2025 年 10 月起)速度和覆盖结果:12ms 检测;首个集成双层 DSP2025-10-28由 PPC Land 时间线具名;未确认与 AdRoll 的联合新闻稿
Consortium Networks企业安全渠道 / MSSP向企业客户转售并托管交付 HUMAN Defense Platform 全平台生产(项目推出时具名)CEO Nate Ungerott:HUMAN Security 将继续为我们的客户带来卓越价值2024-08-21渠道伙伴推荐语;未具名终端客户结果
Optiv企业安全渠道 / SI通过 Advantage Partner Program 向 Fortune 100 账户战略转售 HUMAN 平台生产(项目推出时具名)HUMAN 全球合作伙伴负责人 Tuan Nguyen 称其为“重要盟友”;Optiv 服务 73% 的 Fortune 1002024-08-21未引用具体部署或客户结果

本表只覆盖公开确认且点名的合作关系。生产状态根据合作时长以及 CEO 层面将关系描述为“长期”的引述推断。所有条目都无法从外部完全核验试点与生产的区分。Gartner 评论者案例(零售、旅行)为匿名,已排除。

[CU015, CU016, CU017, CU018, CU019, CU020]
FU001: 客户旅程地图 — HUMAN Security 数字信任生命周期

将客户细分映射到发现、采购、部署和扩展触点,覆盖 HUMAN 三个平台表面。

旅程阶段由具名部署证据和渠道项目披露综合而来;采购周期时长来自财务章节证据。

[CU016, CU017, CU018, CU019, CU031, CU032]
FU003: 客户证据质量矩阵

从两个轴评估具名客户部署:证据质量(佐证深度)和部署成熟度(生产广度)。

矩阵位置由公开证据质量和部署范围描述推断。金融服务试点位置反映该垂直领域缺少任何具名客户。Optiv 和 Consortium Networks 终端客户的确切生产范围未知。

[CU015, CU017, CU018, CU019, CU020, CU021]

6.4 留存与耐久性证据

HUMAN Security 不披露任何客户细分的 NRR、GRR、流失率、平均合同长度或 cohort 留存——这符合该阶段私营公司的常态。留存和耐久性的代理证据来自评论平台与伙伴证言。Gartner Peer Insights(更新至 2026 年 4 月)上,HUMAN Sightline Cyberfraud Defense 总评分 4.7/5,Service & Support 为 4.8,Product Capabilities 为 4.7。一位来自旅游与酒店公司($250M–$500M)的评论者给托管服务 5/5,提到「他们的托管服务响应非常快」以及持续多年的合作。一位来自 1B–10B USD 零售公司的评论者明确表示「我们与 Human 合作已久」——说明合作已跨多年。一位 10B+ 零售公司评论者称 HUMAN 让「我们所有品牌」拥有「非常安全的线上存在」——暗示企业级部署覆盖面。G2 将 HUMAN 评为 Best Security Software Product of 2026(Bot Detection & Mitigation 第 1 名),这是众包同行验证。Forrester Wave Q2 2026 报告提到客户尤其肯定攻击洞察深度,暗示存在可作参考的关系。一个负面信号是:来自 $500M–$1B 零售公司的 3/5 Gartner 评论把 HUMAN 描述为「黑箱」——检测逻辑能见度有限、没有主动变更通知、手动调优能力很少。这是技术要求高的安全买家面临的真实采购摩擦点,也带来流失风险。HUMAN Advantage Partner Program(2024 年 8 月推出)的留存信号显示,三层结构把留存与订单额、培训并列作为核心指标,说明管理层意识到这一维度,但没有发布留存数据。行业基准显示,35% 网络安全厂商流失归因于 CX 而非产品表现,42% 网络安全客户在过去两年更换过厂商——HUMAN 的托管服务方法和 Gartner 4.8/5 支持评分,正是用来对冲这一行业逆风。 [CU023, CU024, CU025, CU026, CU027, CU028]

留存与重复使用信号
指标 / 信号数值或证据细分市场置信度尽调问题
Gartner Peer Insights 总体评分4.7/5(截至 2026 年)跨细分市场(零售、旅行、企业)向客户证明人索取已核验续约率;Gartner 样本量未披露
Gartner Peer Insights 服务与支持评分4.8/5跨细分市场托管服务粘性的指标;追问客户成功团队与账户数量之比
G2 Bot Detection & Mitigation 排名#1 2026 年最佳安全软件;此前为 G2 2024 夏季 Grid #1企业跨细分市场G2 评论不是已核验的客户年限数据;追问合同年龄中位数
长期合作关系信号Gartner 评论者:“我们与 Human 合作很久了”(1B–10B 零售)零售单条匿名评论;无法独立核验
负面留存信号Gartner 3/5 评论:产品被描述为“黑盒”,没有变更通知或调优可见性零售($500M–$1B)黑盒感是有记录的流失前兆;追问 HUMAN 是否已推出检测透明度路线图
渠道留存激励HUMAN Advantage Partner 分级结构在预订额和培训之外,也奖励客户留存渠道 / 企业留存指标目标和实际值未披露;项目上线不到 2 年
NRR / GRR未披露(私营公司)全部细分市场最高优先级尽调问题;在投资条款清单阶段或之前索取
平均合同期限未披露全部细分市场要求拆分 SMB 渠道、直销企业客户和广告技术平台

NRR 和 GRR 为空值,因为 HUMAN Security 是私营公司,不披露这些指标。Gartner Peer Insights 和 G2 数据只能提供方向性的满意度信号,不能证明留存。Gartner 3 星评论给出的负面留存信号,是采购摩擦的真实指标。

[CU023, CU024, CU025, CU026, CU027, CU028]
FU004: 客户评论平台评分 — HUMAN vs. 类别基准

将 HUMAN Security 的 G2 和 Gartner Peer Insights 评分,与 bot-management 类别基准和负面反馈信号对比。

Gartner Peer Insights 数值来自 2026 年 2–4 月更新的产品页(公开片段可见 4 条评论)。基准值是 Gartner bot/agent trust management 市场类别的近似类别平均值。G2 排名来自 2026 年 2 月 Best Security Software 公告。负面评论占比由 Gartner 片段中 4 条可见评论里 1 条批评性评论近似得出 — 完整评论语料下的实际分布可能不同。该图替代原计划的队列图,因为这家私营公司没有公开可用的时间序列客户留存百分比数据。

[CU023, CU024, CU025, CU026, CU027]

6.5 扩张与集中度风险

HUMAN 的主要 land-and-expand 动作通过三条向量展开:(1)在同一企业账户内,从广告保护交叉销售到应用 / bot 防御和账户保护;(2)鉴于 AI agent 流量增长 7,851%,把 agentic AI trust(Sightline 内的 AgenticTrust 模块)作为绿地 upsell 驱动;(3)2024 年 8 月推出 HUMAN Advantage Partner Program,在奖励年度化订单额、培训完成度和客户留存的三层结构下,用 Optiv 和 Consortium Networks 放大渠道。扩大可触达账户的战略技术伙伴关系包括 AWS Bedrock AgentCore 浏览器支持(加密签名 AI agent 验证),以及 Riskified 合作(RivalSense 称为 2026 年 8 月),后者通过 AI Agent Approve 和 AI Agent Intelligence 做电商欺诈预防。集中度风险在两个维度上都很重要。第一,HUMAN 的遗留收入基础高度集中于数字广告和 adtech;在这一垂直中,DoubleVerify 和 IAS 市场份额大得多,预算周期又绑定媒体支出决策而非安全预算,因此对宏观广告下行敏感。Gartner Peer Insights 评论者群体在应用防御上偏向零售和旅游行业,但公司历史品牌身份和多数公开案例仍以 ad-tech 为中心。第二,作为私营公司,HUMAN 没有可用的客户数、前十大客户收入占比或分细分收入数据,外部证据无法量化集中度。HUMAN Advantage Program 的交易登记和在位保护旨在降低渠道冲突、提升账户耐久性,但计划推出不到两年,成熟信号缺失。采购摩擦——直销渠道计划前,企业销售周期 6–7 个月,需谈法律、MSA 和定价——已在前述财务章节证据中被明确承认,也是与留存相邻的风险。渠道模式推出的目的,正是通过托管式 onboarding 降低这种摩擦。 [CU031, CU032, CU033, CU034, CU035, CU036]

扩张驱动因素与集中度风险
驱动因素 / 风险类型证据影响尽调路径
AgenticTrust 模块追加销售扩张驱动因素AI agent 流量同比增长 7,851%;支持 AWS Bedrock AgentCore;Forrester Wave 最高评分标准高——在既有客户群中率先开拓绿地扩张追问到 2026 年中,现有 Sightline 客户中有多少 % 已启用 AgenticTrust
HUMAN Advantage Partner Program扩张驱动因素(渠道)2024 年 8 月推出;点名 Optiv + Consortium Networks;三层结构;交易注册 + 既有客户保护中——上线不到 2 年;伙伴赋能记录尚不清楚要求披露伙伴贡献预订额占 FY2025 和 2026 年 H1 新增 ARR 总额的比例
MRC 可视性认证(2026 年 4 月)扩张驱动因素(广告技术)Sovrn 早期采用;AdRoll DSP 集成;IVT 过滤后的可视性相较 DV 和 IAS 具备差异化中——在欺诈预算之外,为同一批客户打开可视性预算追问可视性是打包销售还是单独定价;每账户附带收入
Riskified 合作(电商)扩张驱动因素(新垂直)RivalSense:HUMAN + Riskified 于 2026 年 8 月就电商 AI Agent Approve 和 AI Agent Intelligence 建立合作中——触达核心广告技术客户之外的商户 / 支付欺诈买家核验合作条款;追问联合销售管线
广告技术细分市场集中集中度风险公开案例研究和点名部署大多集中在广告技术 / 程序化领域;历史品牌 = “广告欺诈公司”高——广告预算与宏观周期相关;DV 和 IAS 是同一垂直中规模更大的替代方案要求按产品线和垂直拆分收入;若广告技术占比 >50%,标记风险
私营公司,未披露客户数量集中度风险(信息缺口)未公开披露头部客户占比、按细分市场收入或按客群客户数量高——没有管理层数据室数据,无法评估集中度在 NDA 下索取前 10 大客户占 ARR 比例和垂直拆分
企业直销周期摩擦(6–7 个月)集中度风险 / 流失风险前一章已确认;渠道计划旨在解决;MSA 和定价复杂中——长周期降低切换意愿,但也为新账户设置进入门槛追问渠道计划是否已压低销售周期中位数;通过伙伴覆盖中端市场,目标 <4 个月

扩张驱动因素来自公开宣布的合作关系和产品发布。集中度风险是结构性的:品牌和客户基础偏广告技术,私营公司不透明又放大了这一点。Riskified 合作日期来自 RivalSense 竞争情报,应独立核验。

[CU031, CU032, CU033, CU034, CU035, CU036]

6.6 展示材料

Chapter 07

07风险

7.1 监管与法律风险图景

HUMAN Security 的核心技术能力,是每年在超过 1 千万亿次数字交互中采集并分析行为指纹信号;这带来重大且不断扩大的数据隐私暴露面。公司处理设备指纹、鼠标移动遥测、击键时序、浏览器属性、IP 地址和跨资产行为模式,以区分 bot 与人类。截至 2026 年 1 月,美国已有 20 个州在积极执行综合隐私法,欧洲还有 GDPR;若 HUMAN 的数据被错误归类为个人数据经纪,或其行为信号被归类为受监管数据,都可能触发执法。FTC 2026 年 2 月根据 Protecting Americans' Data from Foreign Adversaries Act(PADFAA)向 13 家数据经纪商发送正式警告信,表明监管机构正主动盯防大规模行为数据厂商。 Department of Justice 的 Data Security Program(DSP)对向「受关注国家」批量跨境传输受覆盖个人数据施加额外限制。HUMAN 全球运营,并处理来自 222+ 国家设备的数据;任何把受覆盖数据路由经过 Israel(HUMAN 在当地有办公室和工程人员)的配置,或与存在受覆盖国家关联的实体合作,都需要符合 CISA 要求的安全控制。原告律师已经发展出一种新策略:即使 DSP 本身没有私人诉权,也把 DSP 违规作为联邦 Wiretap Act 诉讼的前提,从而让 adtech 数据流暴露于集体诉讼。在线隐私诉讼数量从 2023 年约 200 起激增至 2024 年约 4,000 起;HUMAN 用于欺诈预防的行为追踪技术,正是原告瞄准的技术。 正面看,HUMAN 2026 年 4 月获得 Ad Viewability Measurement 的 MRC 认证,体现合规严谨度。MRC Digital Advertising Auction Transparency Standards 也在 2026 年 1 月最终确定,收紧了广告拍卖参与者的披露要求。包括 Check My Ads Institute 在内的批评者认为,这些自律框架结构性不足,并呼吁政府监管;这意味着即使合规厂商,也会面对持续的行业级监管风险。截至 2026 年 6 月,公开资料未显示有直接针对 HUMAN Security 的现行监管执法或诉讼;但考虑其行为数据规模,该风险虽为潜在风险,却很重大。 [CR001, CR002, CR003, CR004, CR005, CR006]

监管 / 法律风险登记表
规则 / 案件 / 许可管辖区状态 / 成熟度可能性(HUMAN)严重性缓释措施剩余暴露尽调路径
CCPA/CPRA 行为数据合规加州(20 州拼图)执法活跃;CPPA 自 2026 年起开罚隐私内建;DPA 到位;同意管理潜在;绕过 opt-out 会带来暗黑模式风险获取 DSAR 流程;审计同意管理工具链
FTC PADFAA / DOJ DSP 跨境数据联邦(美国)活跃——FTC 于 2026 年 2 月警告 13 家数据经纪商低–中数据映射;CISA 安全控制;受管国家供应商审计中;以色列办公室和全球数据路由需要 DSP 控制要求跨境数据流图和 DSP 合规认证
Wiretap Act 集体诉讼(DSP 前提理论)联邦及多州新理论;案件于 2025–2026 年提交;尚未在广告技术供应商身上检验隐私政策披露准确性;网页活动像素审计中;HUMAN 这种规模的行为追踪属于目标类别审查与任何受管国家实体共享的 pixel/SDK 数据
MRC 认证合规美国(自愿行业)2026 年 4 月获得广告可视性认证;审计周期持续MRC 审计计划;透明测量方法低;近期认证降低短期风险确认 MRC 审计时间表和下一次续期日期
广告技术行业自律缺口 / 政府干预联邦及欧盟潜在;Check My Ads Institute 和参议院审视数字广告欺诈低–中MRC 认证;公开打击行动(BADBOX、PARETO)中;强制独立审计或收费结构存在立法风险跟踪 FASB/FTC 关于广告技术测量强制要求的指引

覆盖并不完整:各行代表截至 2026 年 6 月,基于律所分析、监管回顾和 MRC 文档可见的重大公开监管风险。未披露诉讼、密封程序和美国以外执法不在范围内。可能性评分反映 HUMAN 自身暴露,不是行业整体基准率。

[CR001, CR002, CR003, CR004, CR005, CR006]

7.2 运营、技术与 ML 风险

HUMAN 的运营风险画像由三组相互关联的动态主导:云基础设施集中、bot 检测误报,以及加速中的 ML 模型军备竞赛。平台每周需要处理 20+ 万亿次数字交互,要求海量云计算和存储基础设施,AWS 是主导公共云供应商。AWS 在 2026 年初遭遇两次重大基础设施故障:2026 年 3 月,UAE 数据中心遭 kinetic attack,分别扰乱 ME-CENTRAL-1 和 ME-SOUTH-1 区域 38+ 与 46+ 项服务;2026 年 5 月,US-EAST-1 发生热事件,级联影响 150+ 个依赖云服务。任何影响 HUMAN 主要检测基础设施的同等故障,都会直接削弱其向 500+ 企业客户交付 SLA 的能力;其中许多客户依赖 HUMAN 在结账或登录时做实时欺诈预防。HUMAN 没有公开多云或 active-active 故障转移架构细节,形成韧性姿态尽调缺口。 误报问题是带有法律和商业后果的结构性弱点。合法用户使用隐私工具——广告拦截器、VPN、Tor、非主流浏览器和反指纹扩展——时,anti-bot 系统会产生误报。广告拦截器常常完全压制 anti-bot 脚本,导致检测系统把会话归类为 bot;VPN 会把流量路由到共享 IP,而这些 IP 历史上可能被标为 bot 来源。对 HUMAN 的企业客户而言,误报会增加合法用户摩擦、降低转化率,并可能触发退款或投诉循环,损害客户留存。该问题并非 HUMAN 独有,但会塑造其与低摩擦画像检测厂商的竞争动态。 检测军备竞赛正在加剧。按 HUMAN 自有基准数据,2025 年自动化流量同比增长 23.51%,同期 AI 驱动流量增长 187%。HUMAN 最初曝光 BADBOX 1.0 后,BADBOX 2.0 作为直接演进版本出现——说明威胁行为者在被打断后会快速迭代。DoubleVerify 在 2026 年 Q1 检测到的 CTV 欺诈计划变体比 2025 年 Q1 多 140%,背后由 AI-assisted fraudster tooling 推动。威胁不是静态的:agentic AI 流量同比增长 7,851%,二元 bot / human 分类越来越难处理有益与恶意 AI agent 流量的差异。欺诈签名漂移意味着 HUMAN 的 400+ ML 模型必须持续再训练;20 个州隐私法下的监管碎片化,已经在主动约束数据管线完整性,削弱模型输入。 [CR011, CR012, CR013, CR014, CR015, CR016]

运营 / 质量 / 安全风险登记表
失效模式可能性严重性缓释成熟度剩余暴露未解决缺口
AWS 云宕机(单一区域集中)关键低–中未公开多云或 active-active 故障切换文档
Bot 检测误报(隐私工具用户)商业合同未披露 FP 率基准
Bot 规避策略演进导致 ML 模型漂移再训练周期频率和成本未公开披露
Agentic AI 流量误分类(可信 vs. 不可信)二元 bot/human 模型尚未完全适配 AI agent 治理
隐私监管导致数据管线碎片化未披露在 GDPR/CCPA 数据限制下如何再训练模型
威胁行为者迭代(BADBOX 3.0、新供应链攻击)持续打击需要 FBI 和伙伴连续协调

可能性和严重性是基于公开报道的 2026 年云宕机数据、安全研究和 HUMAN 自身威胁基准报告得出的知情判断。缓释成熟度评分根据公开披露推断;专有韧性架构、SLA 保证和内部 DR 测试结果均未公开。

[CR011, CR012, CR013, CR014, CR015, CR016]
FR001: 风险热力图

截至 2026 年 6 月,HUMAN Security 五个主要风险域的严重性-可能性-缓释热力图。Agentic AI 误分类与 AWS 云集中度叠加,高严重性遇上低缓释成熟度,形成最高剩余敞口。

可能性和影响评级是分析师基于行业基准和公开披露作出的判断;内部风险评分不可得。

[CR001, CR015, CR023, CR040, CR041]

7.3 伙伴、平台与市场依赖风险

HUMAN 处在一张关键伙伴依赖网里,既竞争也协作。BADBOX 2.0 的处置说明了这种共生结构:HUMAN 的 Satori 团队发现威胁,但真正完成修复,需要 Google 更新 Play Protect 并在联邦法院采取法律行动,需要 Shadowserver Foundation 接管命令与控制域名,还需要 FBI 协调公开预警。这种公私协作模式既是竞争护城河,也是依赖——HUMAN 不能独立接管基础设施,Google 是否介入也有裁量空间。Google 同时是关键分发伙伴(通过 Google Play Protect 认证)、客户,也是一个自有广告欺诈检测能力不断增强的竞争者。 在 Bot Management 市场,按 Gartner Peer Insights 和 PeerSpot 的心智份额口径,HUMAN 以 8.1% 排第五,Cloudflare 以 9.2% 排第三。Cloudflare 走平台路线,把 DDoS 缓解、WAF、Bot Management 和 API 安全打包成一套全球边缘分发的一体化堆栈;HUMAN 在应用层信号保真度更深,但基础设施覆盖更窄。广告验证板块已经集中到接近 DoubleVerify 和 Integral Ad Science 双寡头,两家公司都有上市公司规模优势。Google、Meta、Amazon 等大型平台厂商为自己的围墙花园库存提供自有欺诈检测,结构性压低了最高价值展示段对第三方验证的需求。HUMAN 必须持续证明自己相对打包替代品有增量提升,才能支撑按流量单位收费。 MRC 认证虽然刚刚取得,却也形成治理依赖:MRC 是自愿性行业机构,批评者认为其执法资源结构性不足。即便可能性很低,一旦失去 MRC 认证,HUMAN 在媒体买家和代理机构伙伴中的竞争位置会受损,因为这些客户把认证视为基线。广告交易所集成层——DSP、SSP 和发布商技术伙伴——也带来集中度风险:如果一家主要交易所弃用 HUMAN 的 SDK,转向打包方案或竞品方案,风险就会暴露。 [CR023, CR024, CR025, CR026, CR027, CR028]

伙伴 / 依赖风险登记表
依赖交易对手角色集中度失效场景严重性缓释措施剩余暴露
云计算 / ML 推理AWS(主要)每周处理 20T+ 次交互峰值流量期间 US-EAST-1 宕机关键韧性架构未披露;区域多元化未知
BADBOX 僵尸网络打击(C2 sinkhole)Google / Shadowserver Foundation接管 C2 域名流量;Play Protect 执法Google 降低打击优先级,或 Shadowserver 容量不足联合研究发表;FBI 协调;共同起诉
广告验证生态DoubleVerify / IAS(竞争对手)市场标准制定;MRC 合规基准DV/IAS 在打包方案中拿走 HUMAN 的媒体安全用例以行为信号深度做差异化;MRC 认证
Bot 管理竞争位置Cloudflare / Google Cloud Armor / AWS WAF 打包平台面向企业客户的打包平台替代方案企业迁移到打包技术栈,压低 HUMAN ARR更深的行为遥测;Satori 威胁情报;MAP 数据集中–高
MRC 认证治理Media Rating Council广告可视性和 IVT 测量认证机构MRC 审计失败或治理改革取消认证方法透明;已取得 2026 年 4 月认证

集中度评分反映基于公开合作披露和产品架构推断得出的 HUMAN 对各交易对手的估计依赖。实际合同条款、SLA、最低承诺和退出权均未公开披露。失效场景是说明性的最坏情况,不是预测。

[CR023, CR024, CR025, CR026, CR028, CR029]
FR003: 依赖图

按类别梳理 HUMAN Security 的关键外部依赖:云基础设施、威胁情报伙伴、监管机构,以及竞争 / 平台交易对手。

[CR025, CR029, CR030, CR023, CR031]

7.4 财务、竞争与执行风险

HUMAN 的财务风险画像高度不透明。最近一次披露的投后估值是 2022 年 1 月的 $1.5 billion,已经过时四年以上,且发生在 PerimeterX 合并、clean.io 收购整合以及 2024 年 10 月 $50M+ 增长轮之前。市场数据聚合商(PitchBook、Premier Alts)没有显示当前估值披露。ARR、毛利率、净收入留存率、烧钱速度和现金跑道全都未公开。CEO Stu Solomon 把 2024 年融资称为“deliberately constrained”,但没有独立财务披露就无法验证这种说法。投资人披露的 $100M+ ARR(来自 2024 年 1 月 CEO 交接公告)没有毛利率或流失率限定;第三方估算的 $15M ARR(GetLatka 2023)若没有经审计披露,无法与之调和。 来自打包平台厂商的定价压力,是中期商业模式风险。Cloudflare、Google Cloud Armor 以及带 Bot Control 的 AWS WAF,都以规模化打包定价提供完整安全堆栈;对已经押注这些平台的企业来说,这种定价会有效挤出单独的 bot-management 预算。广告欺诈验证市场至少有六类竞争工具,包括 CHEQ、DoubleVerify、IAS、DataDome 和 Cloudflare Bot Management,用例彼此重叠。HUMAN 靠 MAP(Media-Acquired Protection)数据集和 Satori 威胁情报护城河做出的差异化是真实的,但如果平台厂商收购到相近的信号密度,这种差异并非永久可守。 执行风险集中在 2024 年 1 月 CEO 从联合创始人 Tamer Hassan 交给 Stu Solomon。Solomon 的运营履历可信(Recorded Future、Optiv、iSight Partners),但他接手时同时背着 PerimeterX 整合,以及把原本只靠直销的打法扩成伙伴优先渠道项目的任务。董事会高度由投资人代表组成,Goldman Sachs、NightDragon、WestCap 和 ClearSky 是锚定投资人,治理重心集中在投资回报时间表上。公司没有披露通往公开市场的路径;从 2020 年 Goldman 收购和 2021–2022 年增长轮算起,投资人持有期已进入第五或第六年,退出压力风险上升。Agentic AI 流量增长带来的模型漂移(同比 7,851%)意味着 HUMAN 的分类基础设施必须从二元 bot/human 判断,演进到信任 / 不信任判断;这种范式切换可能需要大量 R&D 投入。 [CR033, CR034, CR035, CR036, CR037, CR038]

人员 / 执行风险登记表
角色 / 职能缺口或依赖可能性严重性缓释措施尽调路径
CEO(Stu Solomon,2024 年 1 月起)此前未在上市公司担任 CEO;接手 PerimeterX 整合董事会延续性;经验丰富的运营团队(COO/CFO Itenberg)做证明人访谈;评估整合执行记录
Satori 威胁情报团队(CISO Gavin Reid)专业研究团队,梯队深度有限与 Google、Shadowserver、FBI 联合开发威胁情报评估关键人风险;团队人数和留任激励
渠道 / CRO(Chris Scanlan,2024 年起)伙伴计划于 2024 年 8 月从零推出;规模化尚未验证HUMAN Advantage Partner Program 采用分级激励要求披露伙伴贡献管线占比;CAC/回本周期数据
董事会治理(投资方主导)Goldman Sachs、NightDragon、WestCap、ClearSky 持有多数席位执行主席 Hassan 提供创始人延续性索取董事会章程;确认独立董事代表性

人员 / 执行评估基于公开披露的领导层履历和公司公告。薪酬结构、股权授予、留任协议和继任计划均未公开。严重性反映缺口一旦兑现后的影响,不是概率。

[CR033, CR035, CR036, CR037, CR039, CR042]
FR002: 风险传导图

有向无环图展示 HUMAN Security 的主要风险类别如何在业务中传导,并影响收入、客户留存、利润率、融资和估值。

[CR005, CR015, CR023, CR033, CR034, CR037]

7.5 缓释因素、论点失效触发项与尽调问题

HUMAN 的主要缓释因素是结构性的:Satori 威胁情报护城河来自每年监测一千万亿次以上交互,形成了真实的检测优势,点状竞争者无法复制。MRC 认证(2026 年 4 月取得)为媒体买家信任提供锚点。公私协作处置模式——FBI、Google、Shadowserver、Trend Micro 在 BADBOX 1.0 和 2.0 上协作——说明 HUMAN 以打包厂商没有的方式嵌在威胁响应生态里。2024 年 $50M 增长轮以及 Goldman、WestCap、NightDragon 等投资人的延续,降低了近期流动性风险。2024 年 8 月推出的 HUMAN Advantage Partner Program,让客户获取不再只依赖漫长直销周期。 论点失效触发项集中在三处。第一是平台打包吸收:如果 Cloudflare、Google 或 AWS 通过收购或模型改进,实质性缩小行为信号差距,HUMAN 对大多数已经跑在这些平台上的客户就会失去定价溢价。第二是高峰流量期出现重大云宕机:AWS US-EAST-1 仍是 HUMAN 最可能的运营单点故障;如果 Super Bowl、Prime Day 等高价值媒体事件期间发生数小时宕机,会立即带来合同和声誉风险。第三是隐私执法行动:如果州总检察长或 FTC 行动把 HUMAN 的行为信号网络重新归入数据经纪框架,或者引用 DSP 前提的新型 Wiretap Act 集体诉讼将 HUMAN 列为被告,合规成本和客户信任都可能受到实质损害。 优先尽调问题:独立确认 ARR 并对标 NRR;获取多云韧性架构文件;绘制数据流以确认跨境传输的 DSP 合规;前 10 大客户收入集中度;PerimeterX 整合后的毛利率趋势;以及 AWS 合同条款,包括任何最低承诺和退出选项。鉴于估值不透明,任何以 2022 年 $1.5B 参考估值或更高价格入场之前,都必须做二级市场 cap table 分析。 [CR003, CR007, CR009, CR015, CR022, CR025]

缓释与否决标准表
风险可监控触发器阈值 / 事件行动含义
平台打包侵蚀Cloudflare/Google bot 管理市场份额增长;HUMAN 客户流失到打包技术栈HUMAN 在 Gartner/PeerSpot 的心智份额降至 5% 以下;12 个月内两名前 10 大客户迁移投资逻辑破裂:加快重评投资逻辑;为被收购退出做情景规划
AWS 基础设施单点故障AWS US-EAST-1 宕机与 HUMAN 峰值流量窗口重合任何 >4 小时宕机,并在 ≥5 家企业客户中出现有记录的 SLA 违约重大违约:审计 DR 架构;将多云承诺列为契约条款
隐私执法(重新归类为数据经纪商)FTC 或州检察长行动点名广告技术行为信号供应商任何针对 HUMAN 或数据模型相同直接同行的点名执法行动投资逻辑破裂:立即做法律尽调;评估同意管理补救成本
ARR 增速放缓独立审计披露或渠道伙伴报告中的净新增 ARR任意连续两个报告期 ARR 增长低于 15%重新定价:下调估值倍数;要求按季度报告 ARR,作为董事会契约条款
ML 模型质量退化面向客户的基准或第三方审计披露误报率任何主要垂直中客户报告 FP 率超过 1%,或合同流失归因于 FP运营观察:要求在投资条款清单中加入模型性能 SLA

阈值是指示性的,应结合投后监控契约条款细化。触发数据取决于能否访问 HUMAN 内部指标,而这些指标目前未公开披露。在缺乏直接报告时,监控依赖二级信号(市场份额数据、同行执法行动、客户证言)。

[CR001, CR015, CR023, CR033, CR034, CR040]

7.6 附录

Chapter 08

08估值

8.1 投资论点与反论点

HUMAN Security 的投资论点建立在五个相互咬合的支柱上。第一,市场刚需:bot 驱动的欺诈、无效流量、凭证滥用和 agentic-AI 威胁都是非可选的安全问题,并会随数字经济扩张而扩大;Gartner 预测 2026 年全球信息安全支出为 $244.2 billion,同比增长 13.3%,其中云安全增长 28.8%。第二,平台规模护城河:每周验证 20 trillion 次数字交互、覆盖 3 billion 台独立设备,形成数据网络效应;较小竞争者(Arkose Labs ARR 为 $46.9M、DataDome、Netacea)没有同等基础设施和威胁情报投入,无法复制。第三,agentic-AI 站位:2025 年 7 月推出 HUMAN Sightline 和 AgenticTrust,把公司直接放进倍数最高的网络安全细分(AI security;据 Momentum Cyber,2026 年 YTD 已部署 $2B 融资)。第四,投资人信念:五家机构支持者——Goldman Sachs Merchant Banking、WestCap、NightDragon、ClearSky、Vertex——到 2024 年持续多轮复投。第五,平台化顺风:2026 年战略买家贡献了网络安全 M&A 价值的 92%,而 HUMAN 的跨层平台(媒体安全、应用安全、账户保护、agentic trust)契合买方整合逻辑。 反论点同样扎实。第一,财务不透明:HUMAN 没有披露 NRR、毛利率或 ARR 增速。唯一可用的第三方 ARR 估算(GetLatka,2023 年 12 月为 $15M)比公司声称的 $100M+ 低一个数量级,差异尚未解决。第二,资本包袱:约 $300M 股权加 $100M Blackstone Credit 贷款,形成 $400M 总资本基数;若按 $1.3–1.5B EV 计算,扣除稀释和清算优先权前,对投入资本只有 3.25–3.75x 总 MOIC。第三,板块折价风险:HUMAN 的广告验证收入流(历史主业)可对标 DV/IAS 的 1.9x 收入倍数,只有网络安全同行 15x 倍数的一小部分,买家可能套用混合折价。第四,现有投资人集中:2024 年 10 月融资没有新机构名称,可能说明定价上限受限。第五,整合威胁:Cloudflare、CrowdStrike 和 Palo Alto 都在大举投入 bot management 和欺诈预防能力,可能侵蚀 HUMAN 的独立溢价。 [CV001, CV002, CV003, CV006, CV007, CV009]

建议摘要
维度评估证据基础
建议跟踪ARR、平台定位和市场基准支持继续持有;未披露的 NRR / 利润率限制了确信度

评估反映截至 2026 年 6 月研究日期可获得的公开证据。置信度、风险评级和估值立场体现作者基于可比公司集合和披露信息形成的分析判断。未披露指标可能把建议推向买入或回避。

[CV009, CV016, CV045]
按支柱划分的投资逻辑与反向逻辑
支柱正方论点反方论点可改变判断的证据
市场Bot / 欺诈 / AI agent 安全已成刚需且仍在增长(Gartner 预计 2026 年 $244.2B,同比 +13.3%)超大云厂商推进平台整合,压缩独立 bot 管理的 TAM可量化的多年 ARR CAGR,以及渠道伙伴管线增速
产品互联网级检测网络(每周 20T 次交互)叠加 400+ 个自适应 ML 模型,形成数据护城河Cloudflare、Akamai 和 AWS 面向现有客户以零边际成本积累可比流量遥测在相同流量上独立基准测试 HUMAN 与 Cloudflare Bot Management 的误报率
客户500+ 家全球品牌客户;关键任务部署带来高切换成本未披露 NRR 或总收入留存率;客户集中度未知经审计 NRR >115%,且前 10 大客户占 ARR <5%
财务公司称 ARR >$100M,且 ARR/FTE <$350K,显示资本效率中等GetLatka 的 $15M ARR 数据点仍未解决;毛利率和烧钱率未披露经审计的 ARR、毛利率、NRR,以及 Blackstone Credit 融资状态
竞争最大的纯 bot 管理平台;Forrester Wave 2026 年 Q2 评为 LeaderDV / IAS 的广告验证估值锚定在 1.9x 收入;CrowdStrike / Palo Alto 正在切入持续保持 Forrester Leader 位置,并有记录显示替换 DV / IAS 客户
退出 / 估值网络安全 M&A 节奏创纪录;私营网络安全中位数 15.2x,M&A 中位数 16.3x2024 年 10 月为仅现有投资者参与的轮次;没有新的外部资本以更高估值进入新机构投资者参与增长轮,或已确认的战略 M&A 流程

正方 / 反方论点来自公开来源;可改变判断的证据指足以触发完整论点修订的具体披露或外部验证。 所有倍数均反映 2026 年 Q2 研究日期的基准。

[CV009, CV010, CV013, CV016, CV017, CV018]

8.2 融资背景与估值历史

White Ops 于 2020 年 12 月被 Goldman Sachs Merchant Banking Division、ClearSky Security 和 NightDragon 收购,价格未披露。2022 年 1 月,由此形成的 HUMAN Security 获得 WestCap 和 NightDragon 领投的 $100 million 增长轮,Goldman Sachs Asset Management 参投。2022 年 7 月,PerimeterX 合并把合并后实体估值定在约 $1.5 billion;同时,HUMAN 还从 Blackstone Credit 获得 $100 million 债务额度。2022 年估值是在 2021–2022 年私募市场倍数高位环境中确定的,当时私营网络安全公司中位数超过 15x ARR。 2024 年 10 月,HUMAN 完成 WestCap 领投的 $50 million-plus 增长轮,Goldman Sachs Asset Management、ClearSky Security、NightDragon 和 Vertex Ventures US 参投,使累计股权融资约为 $300 million。关键在于,公司没有披露新估值,也没有新机构投资人进入 cap table——这种模式可能反映现有投资人有意限制准入,也可能说明公司无法以更高价格吸引外部资本。Windsor Drake 指出,在 2021–2022 年高估值融资的公司,常用带优先回报特征的“structured rounds”维持名义面值标记。 截至 2026 年 6 月,Blackstone Credit $100M 债务额度(2022 年 7 月发放)的当前状态尚未公开确认。如果该额度仍未清偿,它会排在股权之前,在任何低于 $1.1B 企业价值的场景中压缩股权回报。总风险资本($300M 股权 + $100M 债务 = $400M)对应 $1.5B EV,意味着 3.75x 总 MOIC;对一笔自 2020 年持有的仓位来说尚可,但并不突出。Premier Alternatives 将 HUMAN 当前私募估值列为“N/A”,且没有可用二级市场数据。 [CV001, CV002, CV003, CV004, CV005, CV006]

8.3 可比估值分析

HUMAN 的估值要对标三组同行:上市广告验证平台(DV、IAS)、私营网络安全应用安全同行,以及跨行业 M&A 先例。这三组给出的隐含估值差异很大,反映出 HUMAN 夹在广告验证市场和纯网络安全市场之间的混合定位。 上市广告验证可比公司给出悲观锚点。DoubleVerify(NYSE: DV)报告 LTM 收入 $781 million、EBITDA $261 million、毛利率 82%,但交易倍数只有 1.9x EV/Revenue——企业价值 $2 billion——反映程序化广告的结构性逆风以及约 10% NTM 的缓慢收入增长。Integral Ad Science 的 LTM 收入约 $530 million,倍数同样被压缩。按 Multiples.vc 2026 年 6 月分析,更广义 AdTech SaaS 板块的 NTM EV/Revenue 中位数仅 0.9x,是所有 SaaS 细分中最低。套到 $100 million ARR 上,只意味着 $90–190 million EV——对具备 HUMAN 网络安全定位的公司显然不适用,但如果买家按板块合理倍数标记 HUMAN 的广告验证收入,这就是底部。 网络安全可比公司有利得多。Finro 2026 年二季度覆盖 9 个细分、265 家公司的数据集显示,Application Security(HUMAN 最接近的同行细分)平均 EV/Revenue 为 15.4x,中位数为 13.0x。Windsor Drake 2025 年 11 月报告给出的私营网络安全中位数为 15.2x ARR,M&A 退出中位数为 16.3x。云安全细分交易倍数更高,Finro 平均为 22.7x,并由 Google/Wiz $32 billion 交易的 32x ARR 锚定。Kroll 2026 年春季分析指出,由于 AI 相关股票市场压力,2026 年一季度网络安全 EV/NTM Revenue 中位数环比下降 26%,所以即便网络安全溢价目前也承压。 按 HUMAN 的收入规模($100M+ ARR)看,私募市场 SaaS 可比公司暗示非 AI SaaS 的区间为 5.5–7.2x ARR(iMerge 2026 年一季度),高 NRR 的 AI-native 平台最高可达 12–15x。Acquiry 2026 数据集相互印证:增长 20–50% 的 AI-native SaaS 可拿到 7–12x ARR;增长 15–30% 的传统 SaaS 为 3–5x ARR。考虑到 HUMAN 声称自己具备 AI-native 定位,但未披露增长率,估值区间会很宽。 [CV012, CV013, CV014, CV015, CV016, CV017]

可比估值表
可比对象类型指标EV / 收入倍数与 HUMAN 的相关性关键限制
DoubleVerify (DV, NYSE)公开可比公司 — 广告验证$781M LTM 收入;$2B EV1.9x LTM 收入与 HUMAN 共享广告欺诈防护收入流和媒体品牌客户基础纯广告验证;没有 bot 管理或应用安全;收入增长 10%;板块存在结构性逆风
Integral Ad Science(IAS,NASDAQ 上市)公开可比公司 — 广告验证~$530M LTM 收入~1.7–2.5x(估算)与 HUMAN 的媒体安全垂直重叠;在程序化欺诈检测中构成竞争拥有 HUMAN 缺少的嵌入式代理分销;没有应用安全或 agentic AI 产品
应用安全细分中位数(Finro 2026 年 Q2)私营 / M&A 基准 — 52 家公司平均 15.4x;中位 13.0x EV/Revenue13.0–15.4x最接近的细分匹配;包括 bot 管理和 Web 应用防护厂商聚合基准;单家公司区间很宽(种子轮 15.5x 到 Series C 12.7x)
私营网络安全中位数(Windsor Drake)私营 M&A 基准 — 广义网络安全中位 15.2x ARR;M&A 退出中位数 16.3x15.2–16.3x全行业私营基准;HUMAN 面向同一企业安全买方群体竞争未隔离应用安全子细分;包括云、身份、端点
Arkose Labs私营可比公司 — bot 管理$46.9M ARR(2024);$140.7M 估值(约 3x ARR)~3.0x ARR最接近的产品竞争对手;同样是专注企业的纯 bot 管理公司规模小得多($47M vs. $100M+ ARR);上一轮为 2021 年 Series C;估值可能已过时
Wiz / Google(M&A 先例)M&A 先例 — 云安全$1B ARR;$32B 收购价~32x ARR为 AI-native、品类定义型网络安全资产设定上限Cloud-native CNAPP 与 bot 管理结构不同;AI-first 架构享有溢价

如可得,倍数截至 2026 年 6 月研究日期;Arkose Labs 估值来自 GetLatka 2024 年数据,可能已过时。 IAS 倍数来自分析师覆盖的估算;精确当前数字需要金融数据订阅。所有 EV/Revenue 倍数均基于已披露的 LTM 或 ARR。Finro 和 Windsor Drake 基准覆盖私营与 M&A 交易;若无付费数据集访问,无法逐笔审计具体源交易。

[CV012, CV013, CV014, CV015, CV016, CV017]

8.4 乐观、基准与悲观情景分析

悲观情景假设 HUMAN 的真实 ARR 位于可辩护估算的下限($80–100 million),NRR 已降至 105% 以下,且由于 Satori 团队和基础设施成本较重,毛利率被压到 70% 以下。在这些假设下,公司的 SaaS 质量可能撑不起纯网络安全倍数,买家会给出 8–10x 混合折价,以反映广告验证收入暴露。由此得到的隐含 EV 为 $640M–$1.0B,低于总投入资本。悲观情景的主要催化剂,是公司需要把现金跑道延到 2027 年以后却无法改善指标披露,因而被迫下调估值融资。 基准情景假设 $100M+ ARR 说法准确,NRR 在 105–115% 区间(低于一流网络安全公司但仍为正),毛利率为 70–78%,平台年增长 10–20%。按应用安全 13.0x 中位数,隐含 EV 为 $1.3B;按私营网络安全 15.2x 中位数,隐含 EV 为 $1.52B——大致与 2022 年标记相符。如果战略退出给平台整合方(CrowdStrike、Palo Alto 或 Cloudflare),14–16x 倍数对应 $1.4–1.6B 区间,为 2022 年股权投资人带来 3.5–4.0x 总 MOIC。鉴于 Netskope 2025 年 IPO 先例以及当前网络安全 IPO 市场部分重开,可能退出窗口是 2027–2029 年。 乐观情景假设 ARR 已增至 $130–140M(与 GrowJo $140.4M 估算一致),NRR 超过 115%,agentic AI 产品线已贡献可量化签约额,且 HUMAN 在 Forrester Bot and Agent Trust Management Q2 2026 Wave 中被评为领导者。在这些条件下,战略收购方若套用 18–20x 的前四分位倍数,隐含 EV 为 $2.34–2.8B。按 CyberArk/Palo Alto 先例倍数(18.6x),$130M ARR 对应 $2.42B EV。若走 IPO,以 12–14x NTM 支撑 $2B+ 公开市值,需要 $175–210M NTM 收入;如果年增长率加速到 20%+,2027–2028 年可以实现。 [CV009, CV010, CV011, CV017, CV018, CV019]

牛市、基准与熊市场景分析
场景关键假设隐含 ARREV 倍数隐含 EV(USD M)概率信号下行触发因素
牛市ARR $130–140M;NRR >115%;AI-native 平台溢价;Forrester Leader 地位延续;战略 M&A 流程启动$130–140M18–20x$2,340–2,800低到中(需要确认 ARR 增长并披露 NRR)AI 产品在 2 个产品周期内未能带来可量化的预订贡献
基准ARR $100–115M 获确认;NRR 105–115%;毛利率 70–78%;应用安全中位倍数;2027–2029 年通过战略 M&A 退出$100–115M13–15x$1,300–1,725中(与已披露里程碑和可比公司基准一致)Blackstone 债务压力限制股权上行;退出前需要下轮估值下调的过桥融资
熊市ARR $80–100M(下限);NRR <105%;Satori + 基础设施成本压缩利润率;网络安全 / adtech 混合折价$80–100M8–10x$640–1,000低(需要经营指标显著差于已披露水平)被迫以低于 $1B 估值下轮融资;前 5 大客户流失;广告验证流程遭监管行动

EV 区间是锚定可比基准的示例性场景分析,并非基于 DCF 的估值。隐含 ARR 和倍数基于 Finro 2026 年 Q2 应用安全细分数据(中位数 13.0x,平均 15.4x)以及 Windsor Drake 私营网络安全基准(中位数 15.2x)。 下行倍数反映网络安全 / 广告验证板块的混合定价。概率信号是基于证据可得性以及与公开里程碑内部一致性的定性判断。 单位为百万美元。

[CV009, CV011, CV017, CV018, CV019, CV031]
FV002: ARR 倍数估值敏感性

在六种情景下测算 HUMAN Security 隐含企业价值,从广告验证底部(1.9x)到 AI-native 网络安全上限(22x),均套用 $100M ARR 基准。

所有数值均套用 $100M ARR 基准(公司声称的底线)。实际 ARR 可能更高(GrowJo 估计 $140.4M),也可能更低(GetLatka 有争议的 $15M 数字)。倍数来源于 Multiples.vc(DV)、Finro Q2 2026(App Sec)、Windsor Drake(私营网络安全、M&A 中位数)以及 Acquiry/SaaS Mag(AI-native 区间)。数值单位为百万美元。

[CV013, CV016, CV017, CV019, CV031, CV032]
FV003: 按情景划分的估值回报区间

悲观、基准、乐观三种情景下的低、中、高企业价值估计,并列明假设锚点。

悲观低端 $640M 反映 $80M ARR 上 8x;悲观高端 $1.0B 反映 $100M ARR 上 10x。基准区间锚定 Finro App Sec 中位数(13x)和私营网络安全中位数(15.2x)。乐观区间将 CyberArk/Palo Alto M&A 先例倍数(18.6x)套用于 $130M ARR 得出中位,并在高位拉伸至 $140M ARR 上 20x。所有数字单位为百万美元。区间未计入清算优先权、债务优先级,或新融资轮带来的稀释。

[CV017, CV018, CV019, CV025, CV032, CV033]

8.5 建议、退出准备度与尽调问题

基于可获得的公开证据,建议为跟踪。HUMAN 讲得出可信的网络安全平台故事:有互联网规模验证、强机构背书,并站在高增长威胁类别(bot management、AI agent trust)上。该投资既非明显定价过高——2022 年 $1.5B 估值按所称 ARR 与当前应用安全基准相符——也不能在缺少核心运营指标确认的情况下算明显有吸引力。置信度为中等,因为重大尽调缺口(NRR、毛利率、ARR 增速、债务状态、股权结构中的优先权)无法从公开来源补齐。 退出准备度不完整。HUMAN 没有出现在任何已确认的 2026 年网络安全 IPO 管线中。公司需要用经审计指标补上财务披露缺口,证明明确的 Rule of 40 分数,并把 agentic AI 产品线讲成增长驱动,IPO 叙事才可能在当前挑剔的公开市场成立。战略 M&A 是近期更可能的路径。具备战略契合的收购方包括 CrowdStrike(身份 + bot management 与 Falcon 集成)、Palo Alto Networks(把反欺诈跨 SASE + XSIAM 平台化)和 Cloudflare(从 CDN/WAF 延伸到全栈 bot 与 AI agent 治理)。Google(Wiz 之后)和 ServiceNow(Armis 之后)可能性较低,但财力足够。如果按当前倍数计算,2027–2030 年持有期的 MOIC 能跨过 3.5x 门槛,财务赞助方私有化也可能发生。 论点失效触发项被定义为可观察事件,一旦出现就需要完整修订投资论点,而不只是调整情景。这些事件包括:经审计 ARR 披露低于 $80 million;确认 NRR 低于 95%;下调估值融资低于 $1.0B;失去一个贡献 >15% ARR 的前 5 大客户;或监管行动瞄准核心广告验证流程。最终优先尽调清单(TV006)列出六项问题,若得到答案,会实质改变本评估的确信水平。 [CV016, CV017, CV025, CV030, CV039, CV041]

论点破裂与否决触发因素
触发因素阈值或事件对论点的传导行动含义
ARR 披露低于底线经审计 ARR <$80M推翻网络安全溢价倍数基础;意味着估值只有当前熊市 EV 的 2–3x立即退出或按深度折价重新评估;论点坍塌
净收入留存低于留存底线经审计 NRR <95%显示 land-and-expand 为负;客户 cohort 恶化;倍数压缩至 6–8x重新按类服务业务而非 SaaS 评估;下一轮前要求看到留存修复证据
下轮估值下调融资事件新股权轮估值 <$1.0B确认 $400M+ 已投资本形成压力;显示内部对困境价值达成共识重新评估持有仓位;可能出现清算优先权错位
平台厂商产品替代单一财年内确认 HUMAN 客户向 Cloudflare、CrowdStrike 或 Palo Alto 流失 >15% ARR独立 bot 管理市场结构性侵蚀;战略买方池收缩下调至规避;市场份额数据确认商品化风险
监管或法律不利行动执法行动、重大诉讼结果,或影响核心产品的 GDPR / CCPA 违规受影响地区收入承压;客户可能流失;法律悬而未决推高折现率暂停论点,等待法律结果;评估具体地区客户集中度

否决触发因素是需要完整修订论点的可观察事件,不是场景调整。阈值设在基准估值区间无法维持的水平。 所有触发因素都可在未来尽调周期中用公开披露或管理层沟通检验。

[CV009, CV034, CV036, CV045, CV047]
最终尽调问题清单
主题缺失证据重要性负责人或尽调路径
净收入留存按 cohort 年份划分的经审计或管理层确认 NRR(目标:当前年份 + 前 2 年)NRR 是最重要的 SaaS 质量指标;决定适用倍数扩张还是压缩;95% 与 120% NRR 之间意味着 30–50% 的估值差异数据室中的管理层披露;与客户访谈交叉核验
按产品划分毛利率按收入支柱划分的毛利率(媒体安全、应用安全、账户保护、agentic AI)Satori 团队和 ML 基础设施成本可能把混合毛利率压到 70% 以下;决定 HUMAN 按纯 SaaS(8–15x) 还是技术赋能服务(3–5x)估值经审计财务报表;CFO 访谈;基础设施成本基准
ARR 增长率与桥接从 2022 年 1 月(公司称 $100M)到当前的同比 ARR 增长,按产品线拆分四年增长率决定平台是在加速还是减速;打破 $1.52B 与 $640M 的估值分歧CFO 访谈;管理账;与员工数 / 支出增长代理指标交叉核验
Blackstone Credit Facility 状态$100M 债务融资的当前余额、到期日、利率和 covenant 结构在低于 $1.5B EV 的场景中,优先于股权的偿付顺位会影响股权上行;违反 covenant 可能迫使提前退出法务和会计数据室审阅;如有,查阅公开债务登记文件
股本表与优先权堆栈完整资本化表,列明股份类别、清算优先权、参与权和反稀释条款8 轮、不同价格的 $300M 股权融资可能形成参与型优先股结构,在低于 $2B 的退出场景中显著削减普通股价值法务数据室;投资者权利协议;资本化摘要证书
客户集中度前 10 大客户收入占 ARR 比例;前 3 大客户名称或匿名化收入区间Bot 管理收入往往集中在数字媒体和电商龙头;单一客户风险 >10% ARR 是重大论点修正因素CFO 访谈;合同摘要;与已披露的 500+ 品牌说法交叉引用

优先级按财务重要性排序:NRR 和毛利率是即时估值决定因素;ARR 增长和 Blackstone 融资状态是近期论点验证项; 股本表和集中度是交易结构输入。六项全部拿到后,后续尽调周期才可从 Track 推进到 Buy。

[CV007, CV009, CV036, CV045]
FV001: 建议逻辑流

从 HUMAN 的平台规模和财务证据出发,经过风险评估,推导出「跟踪」建议和主要退出路径的逻辑链。

流程节点代表逻辑评估链,不是财务模型。退出路径时间是指示性判断,依据可比网络安全公司的发展轨迹和当前 IPO 市场环境。

[CV009, CV016, CV019, CV039, CV045]
FV004: 投资 KPI 评分卡

面向 IC 的八维 0–10 分评分;反映截至 2026 年 6 月的证据约束评估。

分数是作者在证据受限下作出的顺序判断(0=无证据 / 关键失败,10=同类最佳且完整披露)。由于缺少 NRR、毛利率、烧钱速度和 ARR 增长披露,财务指标得 3/10。由于 GetLatka 与公司声称 ARR 冲突,且没有审计财务,证据质量得 4/10。其他所有分数均来自本次研究审阅的公开证据。

[CV009, CV019, CV041, CV042, CV044, CV045]

8.6 附录

免责声明

本报告仅供参考,完全基于截至 2026-06-19 可获得的公开信息。报告不构成投资建议,也不构成要约或招揽,并且可能遗漏重大非公开信息。作出任何投资决定前,必须开展独立尽调,并由合格的财务、法律和技术专业人士审阅。

证据索引

结论
编号陈述可信度来源
CO001 HUMAN Security was founded in 2012 in Brooklyn, New York, originally under the name White Ops. SO001, SO005
CO002 HUMAN Security's four co-founders are Tamer Hassan, Michael Tiffany, Dan Kaminsky, and Ash Kalb. SO001, SO003
CO003 HUMAN Security, Inc. is a privately held cybersecurity company; it is not publicly traded. SO001, SO015
CO004 White Ops rebranded to HUMAN Security in 2021 to reflect an expanded scope beyond digital advertising fraud. SO004, SO005
CO005 HUMAN Security is headquartered in New York City, with additional offices in Miami, Santa Clara, Tel Aviv, and the United Kingdom. SO015, SO006
CO006 HUMAN's commercial product is called the Human Defense Platform (HDP), positioned as a unified cybersecurity platform. SO001, SO007
CO007 HUMAN verifies more than 20 trillion digital interactions weekly across 3 billion unique devices. SO001, SO006, SO007
CO008 HUMAN's platform examines 2,500 or more signals per digital interaction to make bot-or-human determinations. SO001, SO007
CO009 HUMAN uses 400 or more adaptive machine learning models to analyze interaction signals. SO001, SO007
CO010 HUMAN's Human Defense Platform spans three pillars: Media Security (ad fraud, invalid traffic), Application and Enterprise Security (account takeover, scraping, carding), and Account Protection (credential stuffing, fake accounts). SO001, SO009
CO011 Tamer Hassan co-founded HUMAN Security and served as CEO until January 2024, when he transitioned to the role of Executive Chairman of the board. SO003, SO011
CO012 Stu Solomon, formerly President of Recorded Future, was appointed CEO of HUMAN Security in January 2024. SO003, SO006, SO011
CO013 Stu Solomon's prior executive experience includes the presidency of Recorded Future, CTO role at Optiv, leadership at iSight Partners (acquired by FireEye), and five years at Bank of America, plus a 25-plus-year military career in the Delaware Air National Guard and USAF. SO003, SO006
CO014 HUMAN Security's current executive team includes Isaac Itenberg (COO/CFO), Gavin Reid (CISO), and Christos Kalantzis (CTO). SO015
CO015 Dave DeWalt, CEO and founder of NightDragon, joined the HUMAN Security board as part of the 2020 acquisition and was designated Vice Chairman of the company. SO005, SO007
CO016 Jay Leek, Managing Partner of ClearSky, joined the HUMAN Security board as part of the 2020 acquisition. SO005, SO007
CO017 Kevin Marcus, Partner and Co-COO at WestCap, is referenced in the 2024 growth round materials as a board-linked investor representative. SO007, SO006
CO018 Anthony Arnold, Managing Director at Goldman Sachs, is referenced in HUMAN's funding announcements as the firm's representative investor and board contact. SO005, SO007
CO019 Ido Safruti, co-founder and CTO of PerimeterX, joined HUMAN Security's board as part of the July 2022 PerimeterX merger. SO004, SO020
CO020 No public record identifies Matt Cantor in any current or recent executive, board, or leadership role at HUMAN Security as of June 2026. SO002, SO003
CO021 Goldman Sachs Merchant Banking Division, ClearSky Security, and NightDragon acquired White Ops in December 2020, buying out previous investors including Paladin Capital Group and Grotech Ventures; acquisition terms were not disclosed. SO005, SO018
CO022 HUMAN Security raised a $100 million growth round in January 2022, led by WestCap with participation from NightDragon. SO009, SO012, SO006
CO023 The January 2022 $100 million growth round was reported to value HUMAN Security at approximately $1.5 billion, representing a unicorn designation. SO006, SO009
CO024 In connection with the July 2022 PerimeterX merger, HUMAN received a $100 million debt facility from Blackstone Credit; this is a debt instrument separate from equity capital raised. SO004, SO019
CO025 HUMAN Security raised $50 million or more in a growth round announced October 9, 2024, led by WestCap. SO006, SO007, SO008, SO009
CO026 The October 2024 growth round included Goldman Sachs, ClearSky, NightDragon, and Vertex Ventures US as additional investors beyond lead investor WestCap. SO007, SO008, SO009, SO016
CO027 HUMAN Security's total capital raised is reported by data aggregators as approximately $299 to $300 million across all equity rounds; this figure may not include the $100 million Blackstone debt facility. SO017, SO016
CO028 HUMAN's Series C of $43 million was led by Scale Venture Partners in February 2019, with Canaan Partners also participating. SO017
CO029 White Ops, together with the FBI, Google, Facebook, and other industry partners, participated in the takedown of the 3ve botnet in 2018-2019, which was described as the largest private-sector collaborative cybersecurity disruption to date. SO001, SO005, SO012
CO030 White Ops uncovered and disclosed the Methbot ad fraud botnet in 2016, which was generating an estimated $3 to $5 million per month in criminal revenue. SO001, SO014
CO031 HUMAN Security and PerimeterX announced a market-changing merger on July 27, 2022, creating a combined entity with more than 450 employees, more than 500 customers, and more than $100 million in ARR. SO004, SO019, SO020
CO032 HUMAN Security acquired malvertising prevention firm clean.io in approximately March 2022. SO003, SO006
CO033 HUMAN Security disrupted and disclosed the VASTFLUX ad fraud scheme in January 2023; VASTFLUX had injected malicious JavaScript into ad creatives across more than 1,700 spoofed apps, affecting approximately 11 million devices at a peak of 12 billion daily false bid requests. SO014, SO024, SO025
CO034 HUMAN Security (Human Defense Platform) was named to TIME's Best Inventions of 2023. SO001, SO003
CO035 HUMAN Security was named among TIME100 Most Influential Companies of 2023. SO003
CO036 HUMAN Security disrupted the BADBOX pre-installed Android botnet in multiple phases from 2023 through 2025, coordinating with Google, German authorities, and Shadowserver to sinkhole command-and-control infrastructure. SO001, SO013
CO037 HUMAN Security was named a Leader in The Forrester Wave: Bot Management Software, Q3 2024. SO001, SO006
CO038 HUMAN Security was named a Leader in The Forrester Wave: Bot and Agent Trust Management Software, Q2 2026, and was the only vendor to receive the highest possible score in the Threat Research criterion. SO013, SO023
CO039 In October 2024, AdExchanger published a correction noting that HUMAN CEO Stu Solomon had misspoken during an interview; HUMAN clarified through its VP of Product that the company does not plan to build a proprietary deterministic ID or a measurement and attribution solution. SO010
CO040 No material lawsuits, regulatory investigations, data breach disclosures, or formal sanctions against HUMAN Security have been identified in public records as of the June 2026 research date. SO001, SO002
CO041 HUMAN Security does not disclose its revenue, ARR, or current post-money valuation publicly; all financial metrics require data room engagement for diligence. SO006, SO010
CO042 As of October 2024, HUMAN Security employs approximately 400 people, with plans to meaningfully expand the data science and engineering team, according to CEO Stu Solomon. SO006, SO010
CO043 HUMAN Security serves 500 or more global brands across media, finance, retail, government, education, and enterprise security. SO001, SO007
CO044 HUMAN's three product pillars are Media Security, Application and Enterprise Security, and Account Protection. SO009, SO007
CO045 HUMAN's Satori Threat Intelligence and Research Team provides threat intelligence, feeds product enhancements, and orchestrates disruptions of cybercriminal operations, including major takedowns like VASTFLUX, BADBOX, and PARETO. SO001, SO013
CO046 HUMAN launched HUMAN Sightline Cyberfraud Defense as a unified trust and defense layer protecting digital businesses from bot attacks, human-led fraud, transaction abuse, and AI-driven risks by mid-2026. SO013
CO047 HUMAN launched AgenticTrust, a product enabling customers to detect, classify, and govern AI agents operating on their platforms, by mid-2026 as part of its agentic AI expansion. SO013
CO048 G2's Summer 2026 Grid for Bot Detection and Mitigation Software named HUMAN the top overall Leader based entirely on customer feedback. SO013
CM001 HUMAN Security's served market spans bot mitigation, ad fraud/SIVT defense, account takeover prevention, and agentic AI trust management, unified under the Human Defense Platform (Bot Defender, Sightline Cyberfraud Defense, MediaGuard/Ad Integrity Suite, and AgenticTrust module). SM001, SM002
CM002 The global bot mitigation market is sized at $0.9 billion in 2025 and projected to reach $1.12 billion in 2026 at a CAGR of 24.8% (Business Research Company). SM004
CM003 Fortune Business Insights values the global bot security market at $1.05 billion in 2025 and $1.27 billion in 2026, growing to $5.67 billion by 2034 at a CAGR of 20.55%, with North America accounting for 38% of global share. SM005
CM004 Global digital advertising losses attributable to ad fraud exceeded $100 billion in 2026, driven by an approximately 20% invalid traffic rate globally across programmatic channels. SM015, SM006
CM005 Fraudlogix's analysis of 105.7 billion impressions collected throughout 2025 showed a global IVT rate of 20.64%, with the US at 23.69% across 37.6 billion impressions, implying roughly $37 billion in US programmatic spend annually associated with invalid traffic. SM006
CM006 The global account takeover protection market is estimated at $6.28 billion in 2025, projected to reach $7.46 billion in 2026 with an 18.89% CAGR through 2035 (Global Growth Insights). SM019
CM007 The Business Research Company projects the eCommerce fraud detection and prevention market at $88.77 billion in 2026 at a CAGR of 20.8%, though this scope includes payment fraud, chargebacks, KYC, and identity proofing outside HUMAN's current product suite. SM012
CM008 Grand View Research estimates the all-verticals fraud detection and prevention market (including AML, KYC/KYB, payment fraud) at $40.4 billion in 2026 with an 18.1% CAGR through 2033—a scope roughly 30x wider than HUMAN's bot-security SAM. SM011
CM009 An analyst-synthesized SAM for HUMAN Security of approximately $1.5–$2.0 billion in 2026 is constructed from bot security ($1.27B per Fortune BI) plus an estimated $500M–$800M for MRC-accredited SIVT vendor spend; this is pre-bundling-haircut and has no independent primary-source validation. SM004, SM005, SM013
CM010 The bot mitigation market is projected to grow from $1.12 billion in 2026 to $2.4 billion in 2030 at a CAGR of 20.9% (Business Research Company). SM004
CM011 Fortune Business Insights projects the bot security market at $5.67 billion by 2034 at a CAGR of 20.55%, with North America holding 38% of market share in 2026. SM005
CM012 Published market estimates for the fraud prevention space range from $1.12 billion (bot mitigation only) to $88.77 billion (eCommerce FDP), a 79x spread driven by boundary definition rather than genuine disagreement, making cross-source TAM comparison unreliable without scope normalization. SM004, SM012, SM005, SM011
CM013 At the US programmatic ad spend level, a 23.69% IVT rate applied to an estimated $156 billion US programmatic market implies approximately $37 billion in annual ad spend potentially exposed to invalid traffic (Fraudlogix, 2026). SM006
CM014 North America represented the largest region in the bot mitigation market in 2025 and accounts for approximately 38% of the global bot security market per Fortune Business Insights. SM005, SM004
CM015 HUMAN Security's Defense Platform analyzed more than one quadrillion digital interactions in 2025, providing a network effect advantage in behavioral signal training across bot, human, and agentic AI traffic. SM001, SM003
CM016 More than 95% of AI-driven automation in 2025 was concentrated in three verticals: retail and e-commerce, streaming and media, and travel and hospitality—HUMAN's primary buyer segments. SM001, SM010
CM017 HUMAN customers experienced on average more than 400,000 attempted post-login account compromise attacks in 2025, a figure quadruple that of 2024, reflecting the acceleration of ATO as a core enterprise security problem. SM001
CM018 Retail and e-commerce topped all verticals for the highest volume of scraping, carding, and ATO attacks in HUMAN's 2025 data, with 70% of all observed scraping attacks targeting this segment. SM001, SM010
CM019 More than 440,000 unique threat profiles targeted retail and e-commerce businesses in 2025 per HUMAN's Threat Tracker, more than four times the next-highest vertical total. SM001
CM020 Traffic from AI agents and agentic browsers grew 7,851% year-over-year in 2025 per HUMAN's Defense Platform data, creating a new trust management challenge distinct from traditional bot detection. SM001, SM010
CM021 Automated traffic across the internet grew 23.51% year-over-year in 2025 while human traffic increased only 3.10%, a ratio of approximately 8:1 (HUMAN Security 2026 benchmark report). SM001, SM010
CM022 HUMAN Security was named a Leader in The Forrester Wave™: Bot and Agent Trust Management Software, Q2 2026, receiving the highest possible scores across nine evaluation criteria. SM002, SM003
CM023 HUMAN was the only vendor in the Q2 2026 Forrester Wave evaluation to receive a 5/5 in the Threat Research criterion, underscoring differentiation via the Satori Threat Intelligence and Research team. SM002, SM003
CM024 TAG awarded 307 certification seals to 196 companies in 2026 across four programs (Certified Against Fraud, Against Malvertising, Brand Safety Certified, Certified for Transparency), with 74% independently audited—acting as a market compliance driver for SIVT vendors. SM008, SM009, SM018
CM025 Global cybersecurity spending is projected to reach $240 billion in 2026, a 12.5% year-over-year increase (Gartner), with approximately 40% of enterprise security budgets allocated to software and platforms. SM025, SM026
CM026 Despite increased security budgets, 63% of organizations still experienced breaches in 2025, suggesting that budget growth alone is insufficient and creating demand for more effective behavioral and signal-based platforms. SM025
CM027 AI-driven traffic surged 187% in 2025 from January to December (HUMAN data), fundamentally changing the nature of bot detection requirements from static rule-based systems to continuous behavioral validation across the session lifecycle. SM001, SM010
CM028 Cloudflare holds approximately 79% of bot management install-base market share compared to Akamai's 6%, based on technology adoption data across major global markets in 2026. SM014
CM029 Cloudflare's bundled CDN, WAF, and bot management offering starts at approximately $350 per year for SMBs with flat-rate predictable pricing, creating a price-point barrier that pure-play bot defense vendors cannot easily match at the lower market. SM014
CM030 DataDome's market share in bot management fell from 13.8% to 8.9% between 2025 and 2026, potentially indicating headwinds for dedicated bot management vendors from Cloudflare's growing bundled security offer. SM017
CM031 Enterprise bot management solutions integrate deeply into login flows, checkout APIs, and analytics pipelines; migration to a new vendor requires thorough retesting of all affected flows, creating high switching costs that protect incumbents but slow new-logo acquisition. SM017
CM032 HUMAN Security does not publish public pricing; enterprise contracts are custom-quoted following an environmental audit, creating sales friction compared to self-serve competitors such as Cloudflare and lengthening sales cycles. SM021
CM033 Bot mitigation ROI primarily appears as fraud losses avoided rather than incremental revenue, making the benefit 'invisible' in P&L statements and requiring sophisticated measurement frameworks to justify budget approval from non-technical stakeholders. SM017
CM034 In-house fraud rule engines and data-science teams represent a build-versus-buy alternative at large internet platforms with sufficient ML engineering capacity, limiting HUMAN's SAM to companies without that internal capability. SM017
CM035 The $88.77 billion eCommerce FDP market estimate (Business Research Company) and the $1.27 billion bot security estimate (Fortune BI) are both 2026 figures but reflect incompatible scope boundaries: the eCommerce FDP estimate includes payment fraud, chargebacks, and identity proofing that HUMAN does not address. SM012, SM005
CM036 Grand View Research's $40.4 billion fraud detection market estimate includes AML, KYC, payment fraud, and identity proofing, categories outside HUMAN's current scope; using this figure as HUMAN's TAM would overstate the relevant market by an estimated 30-40x. SM011, SM005
CM037 Cloudflare and Akamai's bundling of bot management with CDN and WAF services may displace standalone bot defense vendors from a significant portion of the addressable market, particularly in the SMB and lower-mid market segments where flat-rate pricing is decisive. SM014, SM017
CM038 Pixalate's Q1 2026 Ad Fraud Benchmark Report measured 24% IVT on US desktop and mobile web, 32% on mobile apps, and 24% on CTV, confirming persistent invalid traffic across all programmatic channels. SM007
CM039 Europe maintained the lowest regional IVT rate at 7.80% while Asia-Pacific showed the highest at 27.85%, indicating that HUMAN's addressable market for SIVT defense is geographically uneven, with North America and APAC being the largest opportunities. SM006
CM040 HUMAN's Ad Fraud Defense pre-bid platform and Ad Fraud Sensor post-serve platform hold MRC accreditation (renewed April 2025) for GIVT and SIVT detection across desktop, mobile web/app, and CTV environments. SM013, SM016
CM041 AI training crawlers made up 67.5% of AI-driven traffic in 2025 but their share declined sharply as AI scraper traffic grew 597%, shifting the dominant automated threat from passive indexing to active data harvesting. SM001
CM042 Forrester renamed the market category from 'Bot Management' to 'Bot and Agent Trust Management Software' in 2025, reflecting the structural shift from distinguishing human vs. bot traffic to governing whether an AI agent can be trusted to transact on a user's behalf. SM002, SM003
CM043 HUMAN launched AgenticTrust in 2025, a module within Sightline Cyberfraud Defense that provides a unified approach for distinguishing among human, bot, and agentic AI traffic with granular agent permissions. SM002, SM025
CM044 HUMAN announced support for Amazon Web Services' Bedrock AgentCore browser through AgenticTrust, verifying that AI-powered agents built on AWS infrastructure are cryptographically signed, policy-compliant, and secure. SM002
CM045 HUMAN Security was named the top overall Leader in the G2 Summer 2026 Grid for Bot Detection and Mitigation Software, based entirely on verified customer feedback. SM003
CM046 EXTE integrated HUMAN Security's MediaGuard (Ad Fraud Defence) in March 2026 as a supply-quality layer, making HUMAN the verification provider for EXTE's programmatic ad inventory. SM016
CM047 The eCommerce-specific fraud prevention solutions market is separately valued at $8.31 billion in 2026 at a CAGR of 20.63% through 2032 (360i Research), providing an intermediate estimate between the bot-security-only figure and the broadest all-FDP estimate. SM012
CM048 41% of AI scraper traffic in 2025 targeted media and streaming websites, while 37% targeted e-commerce, confirming these as the two highest-volume verticals for AI-driven data harvesting attacks. SM001
CM049 HUMAN Security raised $50 million in growth funding in October 2024 (led by Riverwood Capital) and $100 million in January 2022 (led by WestCap and NightDragon), providing capital to scale the Defense Platform across enterprise verticals. SM020, SM026, SM022
CM050 AI-driven traffic in 2025 was generated predominantly by OpenAI (69% share), Meta (16%), and Anthropic (11%) across HUMAN's sensor network—indicating that the top AI platform operators drive the majority of agentic and scraper activity. SM001
CP001 HUMAN Security's Human Defense Platform processed more than one quadrillion digital interactions across its global customer base in 2025. SP006
CP002 Automated traffic grew 8x faster than human traffic year-over-year in 2025, as measured by HUMAN Security's platform data. SP006
CP003 Monthly volumes of AI-driven traffic grew 187% from January to December 2025, nearly tripling over the calendar year. SP006
CP004 AI agent and agentic browser traffic grew 7,851% year-over-year in 2025, per HUMAN Security's 2026 State of AI Traffic benchmark report. SP006
CP005 HUMAN Security was named a Leader in The Forrester Wave—Bot and Agent Trust Management Software, Q2 2026. SP003
CP006 HUMAN received the highest possible scores in nine criteria in the Forrester Wave Q2 2026, including Threat Research and AI Agent Trust Management. SP003
CP007 Forrester wrote that HUMAN's partnership program is a standout, citing breadth and alignment with emerging agentic trust and agentic commerce use cases. SP003
CP008 G2's Summer 2026 Grid named HUMAN Security SP004
CP009 HUMAN Security launched the Ad Integrity Suite in June 2026, positioning it as a modern alternative to legacy ad verification providers like DoubleVerify and IAS. SP005
CP010 HUMAN's Ad Integrity Suite combines IVT intelligence, AI-powered brand safety and suitability, and viewability in a single framework with URL-level explainability. SP005
CP011 Kasada secured a $20 million funding round in February 2026, led by EQT with participation from Ten Eleven Ventures, Main Sequence Ventures, and other existing investors. SP001
CP012 Kasada was named a Leader in The Forrester Wave—Bot and Agent Trust Management Software, Q2 2026. SP002
CP013 Kasada received the highest possible scores in nine criteria in the Forrester Wave Q2 2026, including Account and Trust Protection, AI Agent Trust Management, and Transaction Assurance and Protection. SP002
CP014 Kasada's platform protects more than $150 billion in eCommerce revenue for targeted enterprises, per company claims. SP001
CP015 More than 85% of Kasada customers previously used another bot mitigation provider before switching to Kasada, per company disclosure. SP001
CP016 Kasada claims an average customer ROI of over 250%, driven primarily by operational cost savings. SP001
CP017 Kasada raised a total of $64.2 million across six funding rounds as of its December 2025 Series C closing. SP023
CP018 Kasada differentiates by detecting attacks at the earliest point where automation begins, operating without CAPTCHAs or friction for legitimate users. SP001
CP019 Arkose Labs raised $114 million in total funding from investors including PayPal, USVP, and SoftBank Vision Fund, with its last major round a Series C in 2021. SP017
CP020 Arkose Labs claims a 95% reduction in automated attacks and prevention of over $50 million in annual fraud losses for customers. SP016
CP021 Adobe uses Arkose Bot Manager to reduce fake account creation and bot abuse, citing measurable security improvements without compromising customer experience. SP016
CP022 In PeerSpot's June 2026 Bot Management category data, Imperva holds the largest mindshare at 15.7%, followed by Akamai at 9.7%, and HUMAN at 8.1%. SP024
CP023 Arkose Labs holds 5.0% mindshare in the PeerSpot Bot Management category as of June 2026, up from 2.8% the prior year. SP007
CP024 DataDome raised $42.4 million in total funding, with a Series C of $42 million in March 2023 led by InfraVia Growth. SP008, SP015
CP025 DataDome reported $36 million ARR in 2024, up from $16.9 million in 2023, representing 113% year-over-year ARR growth. SP015
CP026 DataDome protects over 300 enterprises including Rakuten, Reddit, and AngelList from bot attacks. SP008
CP027 Fingerprint reported 65% annual recurring revenue growth in fiscal year 2026, with a 36% growth in its customer base. SP009, SP025
CP028 Fingerprint serves 2,000 customers in over 56 countries and achieved a net revenue retention rate of 128% in fiscal year 2026. SP009
CP029 Fingerprint's device intelligence platform identifies over 1 billion unique devices per month, a 77% year-over-year increase. SP009
CP030 In 2025, 4.4% of desktop browser identifications showed browser tampering techniques designed to confuse fingerprinting systems, nearly double the 2.6% rate from 2024. SP010
CP031 Cloudflare's Bot Management is an Enterprise plan-only add-on that detects simple and sophisticated bots, headless browsers, and domain-specific anomalies using ML-based bot scoring with JA3/JA4 fingerprinting. SP011
CP032 Cloudflare enterprise contracts range from approximately $5,000 to $80,000+ per month with no public rate card, and Bot Management is bundled, making it near-zero marginal cost for existing enterprise customers. SP012
CP033 DoubleVerify reported full-year 2025 revenue of $748.3 million, a 14% year-over-year increase, with net revenue retention of 109%. SP019, SP021
CP034 DoubleVerify holds a 67.08% market share in the ad fraud detection category with 4,324 tracked customers, versus Integral Ad Science's 2.59% market share and 167 customers. SP013
CP035 Integral Ad Science reported revenue of $590.67 million for the twelve months ending Q1 2026. SP021
CP036 CHEQ processes six trillion signals daily across one million monitored domains, claiming a 0.009% false positive rate. SP020
CP037 Netacea was named a Strong Performer in the Forrester Wave—Bot and Agent Trust Management Software Q2 2026, with the highest possible scores in web and LLM scraping management and transaction assurance and protection criteria. SP014
CP038 Netacea's internal data shows 18% of LLM scraping traffic is unannounced, meaning it mimics human click patterns to bypass client-side JavaScript and CAPTCHA tests. SP014
CP039 Netacea differentiates on a fully managed service model where detection configuration and ongoing tuning is handled by the Netacea team rather than the customer. SP014
CP040 In PeerSpot's June 2026 Bot Management category, Imperva ranks first with 15.7% mindshare, Akamai ranks second with 9.7%, both above HUMAN Security's 8.1%. SP024, SP007
CP041 Forrester noted that HUMAN's threat research team conducts coordinated attack takedowns that create impact far beyond its own customer base, a capability cited as uniquely differentiating. SP003
CP042 Over 95% of AI-driven traffic in 2025 was concentrated in three industries—retail and eCommerce, streaming and media, and travel and hospitality—which match HUMAN Security's core enterprise verticals. SP006
CP043 OpenAI generated approximately 69% of all observed AI bot traffic in 2025, with Meta accounting for 16% and Anthropic 11%, per HUMAN Security's 2026 benchmark report. SP006
CP044 Post-login account compromise attempts more than quadrupled year-over-year in 2025, with HUMAN Security's platform flagging an average of 402,000 attempts per organization. SP006
CP045 Carding volume has surged 250% since 2022, per HUMAN Security's 2026 State of AI Traffic and Cyberthreat Benchmark Report. SP006
CP046 Forrester renamed the Bot Management category to Bot and Agent Trust Management in 2026, reflecting the shift from detecting bots to governing trust for human, bot, and AI agent traffic. SP014, SP003
CI001 HUMAN Security raised a $100 million growth round in January 2022 led by WestCap and NightDragon, with additional investment from Goldman Sachs Asset Management. SI001, SI009
CI002 At the time of the July 2022 PerimeterX merger, the combined HUMAN+PerimeterX entity reported more than $100 million in ARR and 500+ customers. SI002, SI009
CI003 HUMAN Security's January 2024 CEO transition announcement stated that Tamer Hassan led the company to surpass $100 million in ARR during his tenure. SI009, SI025
CI004 GetLatka reported HUMAN Security revenue of $15 million ARR as of December 2023, directly conflicting with the company's stated $100M-plus ARR. SI003
CI005 GrowJo's employee-count model estimates HUMAN Security annual revenue at $140.4 million, which is broadly consistent with the company's >$100M ARR claim and post-merger scale. SI022
CI006 HUMAN Security's Human Defense Platform verified over 20 trillion digital interactions per week as of October 2024. SI007, SI008
CI007 In 2025, HUMAN's platform analyzed more than one quadrillion digital interactions over the full year per the company's 2026 State of AI Traffic Benchmark Report. SI018
CI008 As of October 2024, HUMAN Security served more than 500 global brands across advertising, application, and account protection use cases. SI007, SI008, SI014
CI009 Vendr's 2025 procurement benchmark reports the median enterprise annual spend on HUMAN Security products at $104,906 per year. SI004
CI010 Vendr benchmarks show the enterprise pricing range for HUMAN Security from approximately $46,601 at the low end to over $1.34 million per year for large complex deployments. SI004
CI011 HUMAN Security does not publish a standard price card; all enterprise pricing is custom-negotiated based on traffic volume, protected assets, and module mix. SI005, SI004
CI012 HUMAN announced new packaging and pricing would be rolled out in 2024 as part of its channel programme launch, according to CRO Chris Scanlan at RSA 2024. SI005
CI013 HUMAN Security's Human Defense Platform is structured around three commercial pillars: advertising and media protection, application security and bot mitigation, and account protection. SI007, SI017
CI014 HUMAN acquired clean.io in November 2022 to add malvertising and e-commerce fraud protection capabilities to the platform; financial terms were not disclosed. SI023, SI010
CI015 HUMAN merged with PerimeterX in July 2022, adding enterprise application security, account fraud, and carding protection to the Human Defense Platform. SI002, SI009
CI016 HUMAN launched HUMAN Sightline Cyberfraud Defense featuring AgenticTrust in July 2025, providing visibility and governance across humans, bots, and AI agents. SI013, SI017
CI017 AgenticTrust, launched as part of HUMAN Sightline in July 2025, extends the platform's coverage to classify and govern AI agent traffic separately from human and bot activity. SI013, SI014
CI018 HUMAN launched the HUMAN Advantage Partner Program in August 2024, a tiered channel programme offering incentives based on annualized bookings, training completion, and customer retention. SI014, SI016
CI019 In November 2022, HUMAN partnered with Carahsoft Technology as its Master Government Aggregator, enabling public sector procurement through NCPA, E&I, and OMNIA cooperative contracts. SI019
CI020 Prior to 2024, HUMAN Security operated as a historically direct-minded sales organization with no formal channel programme and enterprise sales cycles of six to seven months for large accounts. SI005
CI021 Chris Scanlan joined HUMAN as Chief Revenue Officer in 2024, previously President and CRO at ExtraHop, to lead the commercial and channel transformation. SI005, SI016
CI022 HUMAN's ecosystem-first GTM strategy is designed to reach fragmented buyer personas including security, commerce, digital, and marketing teams through partner-embedded distribution rather than direct sales alone. SI011, SI014
CI023 HUMAN's enterprise sales cycle for large customers was 6–7 months pre-channel programme, attributable to the need to negotiate legal agreements, MSAs, and pricing directly with enterprise procurement teams. SI005
CI024 SaaS industry benchmark (Benchmarkit 2024/2025) shows sales and marketing expense at 47% of revenue for VC-backed private SaaS companies. SI020
CI025 SaaS industry benchmark (Benchmarkit 2024/2025) shows R&D expense at 34% of revenue for private SaaS companies, versus 23% for public SaaS companies. SI020
CI026 SaaS benchmark ARR per FTE is approximately $200,000 for companies at $50–100M ARR and rises to $300,000 per FTE for companies above $100M ARR. SI020
CI027 HUMAN Security's signal collection and ML inference infrastructure for processing 20 trillion-plus digital interactions per week constitutes a material and scaling cloud compute cost centre. SI007, SI018
CI028 HUMAN's Satori Threat Intelligence and Research Team, responsible for bot research, threat takedowns, and attack intelligence, represents a significant human-in-the-loop cost centre that increases operating expenses relative to pure SaaS peers. SI017, SI014
CI029 White Ops, Inc. (HUMAN Security's predecessor entity, CIK 0001611028) filed a Form D with the SEC in June 2014 for a $11.1 million Series A exempt offering, confirming Delaware incorporation and early institutional fundraising. SI024
CI030 HUMAN Security's headcount was estimated at approximately 469 employees as of 2026 per PitchBook, and 519 employees per Tracxn as of May 2026, up from 197 in late 2023. SI015, SI016
CI031 In connection with the July 2022 PerimeterX merger, HUMAN received a $100 million debt facility from Blackstone Credit; the current repayment or extension status of this facility is not publicly confirmed as of June 2026. SI002, SI023
CI032 In October 2024, HUMAN closed a $50 million-plus growth round led by WestCap, with additional investment from Goldman Sachs Asset Management, ClearSky Security, NightDragon, and Vertex Ventures US. SI006, SI007, SI008
CI033 HUMAN Security's total equity raised is approximately $300 million as of October 2024 across eight funding rounds, per company statement and corroborating news sources. SI007, SI006
CI034 Based on approximately 500 employees at an industry-average fully-loaded cost of $180,000–$220,000 per year, HUMAN's inferred annual payroll is $90–$110 million, implying a monthly burn rate of $9–$13 million including cloud infrastructure and G&A. SI015, SI020
CI035 HUMAN Security was named a Leader in The Forrester Wave for Bot Management Software Q3 2024, receiving the top strategy score and highest possible scores across nine criteria. SI012, SI017
CI036 In June 2026, HUMAN Security was named a Leader in the Forrester Wave for Bot and Agent Trust Management Software Q2 2026, the only vendor to receive the top score in Threat Research, reflecting its expanded market position in the agentic AI era. SI014, SI017
CI037 HUMAN Security's burn rate, gross margin, net revenue retention, and exact ARR breakdown by product segment are not publicly disclosed, creating material financial diligence blockers that cannot be resolved from public sources.
CI038 HUMAN Security's capital structure includes a $100 million Blackstone Credit debt facility from 2022 whose repayment or extension status is unconfirmed, creating leverage uncertainty that cannot be assessed from public disclosures alone. SI002
CE001 As of 2026, the Human Defense Platform comprises four named product lines: HUMAN Advertising Protection (formerly MediaGuard), HUMAN Application Protection (formerly Bot Defender), HUMAN Account Protection (formerly Account Defender), and HUMAN Client-side Defense (formerly Code Defender). SE001, SE009
CE002 The Human Defense Platform decision engine analyzes over 2,500 signals per interaction to produce each bot/human/AI-agent verdict. SE001, SE009, SE014
CE003 The decision engine uses 400 or more adaptive machine learning models to analyze the collected signals and detect automated threats. SE001, SE009, SE014
CE004 HUMAN's behavioral signal network processes over 20 trillion digital interactions weekly across approximately 3 billion unique devices. SE001, SE009, SE003
CE005 HUMAN's decision engine enforces protection decisions at the edge in under 2 milliseconds. SE001, SE009
CE006 Approximately 95% of users are validated automatically by HUMAN's Precheck mechanism without any user-visible friction or challenge. SE001, SE009
CE007 According to HUMAN's 2026 State of AI Report, automation (AI agent traffic) is growing eight times faster than human web traffic. SE006, SE017, SE025
CE008 HUMAN Advertising Protection (formerly MediaGuard) safeguards digital advertising supply chains with pre-bid and post-bid IVT detection, malvertising defense, and the FraudSensor viewability product. SE001, SE010
CE009 HUMAN Application Protection (formerly Bot Defender) protects web and mobile applications and APIs from scraping, credential stuffing, transaction abuse, fake signups, and client-side script attacks. SE001, SE010
CE010 HUMAN Account Protection (formerly Account Defender) provides pre-login, at-login, and post-login security across the full account lifecycle to prevent ATO and fake account fraud. SE001, SE010
CE011 HUMAN Client-side Defense (formerly Code Defender) monitors and enforces third-party JavaScript behavior in consumer browsers and explicitly supports PCI DSS 4 client-side compliance requirements. SE001, SE010
CE012 BotGuard for Growth Marketing is a HUMAN module that protects marketing funnels and lead generation pipelines from bot-driven click fraud, fake leads, and affiliate-code abuse. SE010, SE001
CE013 HUMAN Sightline Cyberfraud Defense was launched on July 30, 2025, as a unified trust and defense layer providing actor-level visibility across humans, bots, and AI agents across the full digital customer journey. SE018, SE009, SE004
CE014 AgenticTrust, a module within HUMAN Sightline, was launched in 2025 to classify AI agent activity, prevent spoofing, and apply granular per-agent governance controls on digital properties. SE018, SE004
CE015 HUMAN's deployment architecture uses a JavaScript Sensor (client-side signal collection) paired with an Enforcer (server-side or edge-layer enforcement), with the minimum Sensor version for AgenticTrust support being v9.6.6. SE002, SE009, SE001
CE016 HUMAN offers over 20 Enforcer integration targets, including AWS Lambda@Edge (v4.8.0+), AWS API Gateway (v0.1.1+), Cloudflare (v6.12.0+), Fastly VCL (v12.3.0+), Akamai EdgeWorker (v4.4.0+), Azure Front Door (v1.2.1+), F5 BIG-IP (v3.1.1+), Nginx, Apache, Kong, Go, Java, Node Express, and Salesforce. SE002, SE001
CE017 PHP, Python 2, Python 3, Ruby, Akamai ESI, and ASP.NET runtimes are explicitly listed as unsupported for HUMAN's AgenticTrust module as of the June 2026 documentation. SE002
CE018 HUMAN Sightline integrates with WAF, CDN, CIAM, and analytics infrastructure including Adobe Experience Platform and Salesforce, enabling deployment across existing customer security stacks. SE018, SE004
CE019 The platform enforces bot verdicts in under 2 milliseconds at the CDN or origin edge, with the Precheck mechanism validating approximately 95% of traffic automatically. SE009, SE001
CE020 HUMAN uses a Precheck mechanism to auto-validate the majority of sessions and a Human Challenge for ambiguous interactions, minimizing friction for legitimate users while maintaining protection. SE009, SE001
CE021 HUMAN's decision engine has been enhanced with over 400 ML algorithms for superior threat detection, improved mitigation tracking, and advanced reporting providing analytics on malicious activities. SE014, SE001
CE022 HUMAN introduced Profile Deviation ML Models 2.0, which enhance detection precision for post-login malicious activity by tracking behavioral deviations from established user profiles. SE014
CE023 HUMAN's attack profiling capability segments traffic into distinct behavioral profiles for deeper analysis of in-progress attack campaigns. SE014, SE004
CE024 HUMAN Threat Tracker delivers attack analytics intelligence to security teams, providing visibility into attacker behavior patterns and enabling proactive identification of attack trends. SE014, SE004
CE025 HUMAN's FraudSensor is a post-bid detection system that validates ad impressions after serving, filters IVT before calculating viewability rates, and analyzes supply-path-level signals to identify the specific supply paths driving quality problems. SE003, SE001
CE026 Page Intelligence, a component of Sightline, provides real-time page-level insights into invalid traffic to help marketing teams understand which campaigns and channels drive genuine engagement. SE004, SE016
CE027 HUMAN's Satori Threat Intelligence and Research Team is led by Lindsay Kaye (Vice President of Threat Intelligence) and Gavin Reid (CISO, formerly VP of Threat Intelligence). SE007, SE005
CE028 In May 2026, HUMAN's Satori team disrupted the Trapdoor operation, a multi-stage ad fraud and malvertising scheme involving 455 malicious Android apps and 183 threat-actor-owned HTML5 domains; Google removed all identified apps from Google Play. SE007
CE029 At its peak, the Trapdoor scheme accounted for 480 million bid requests per day, with associated malicious apps downloaded more than 24 million times before disruption. SE007
CE030 HUMAN was the only vendor in the Forrester Wave Bot and Agent Trust Management Software Q2 2026 evaluation to receive a perfect 5 out of 5 score in the Threat Research criterion. SE004, SE005
CE031 HUMAN's historical threat disruption operations include 3ve (FBI collaboration), Methbot (led to 10-year prison sentence), PARETO (CTV botnet with Roku and Google), Scylla (Google Play and Apple App Store SDK attack), BADBOX 2.0, SlopAds, and Pushpaganda. SE013, SE020, SE007, SE004
CE032 On April 21, 2026, HUMAN announced the expansion of Agentic Visibility within Sightline to marketing and commerce teams, with native integration into Adobe Experience Platform as an official Adobe technology partner. SE016, SE017, SE006
CE033 HUMAN's AgenticTrust extended support to cryptographic verification of Amazon Bedrock AgentCore traffic in 2026, enabling enterprises to authenticate AI agents built on AWS infrastructure via policy-compliant cryptographic signing. SE008, SE002, SE001
CE034 HUMAN Security received MRC accreditation for its Ad Viewability Measurement product on April 27, 2026, covering display and video impressions across desktop, mobile web, and mobile app environments. SE003, SE004
CE035 In November 2025, HUMAN open-sourced the HUMAN Verified AI Agent, a reference implementation using HTTP Message Signatures (RFC 9421) and the Google A2A protocol for cryptographic agent-to-service authentication with Ed25519 key pairs. SE019
CE036 Automation (AI agent traffic) is growing 8 times faster than human traffic according to HUMAN's 2026 State of AI Report, making AI-agent governance a critical emerging capability. SE006, SE016
CE037 During Super Bowl LX in February 2026, HUMAN tracked 74 million blocked retail scraping attacks, a 33% rise in invalid bid requests, and a 5% increase in AI agent activity within the broadcast window. SE006, SE003
CE038 HUMAN Client-side Defense explicitly supports PCI DSS 4 client-side script compliance by detecting suspicious activity, enforcing automated policies, and mitigating malicious behavior without interrupting website operations. SE001, SE010
CE039 HUMAN's MRC Ad Viewability accreditation covers display and video impressions across desktop, mobile web, and mobile app, with IVT filtering via FraudSensor embedded in the viewability measurement product—distinguishing it from conventional viewability-only vendors. SE003, SE004
CE040 The 2022 acquisition of clean.io added real-time client-side JavaScript behavioral analysis for malvertising detection and cleanCart cart-protection technology to HUMAN's product suite. SE012, SE013, SE020
CE041 At the time of HUMAN's clean.io acquisition in 2022, clean.io's technology protected more than 125 billion advertising impressions monthly across millions of websites and mobile applications. SE013, SE020, SE012
CE042 HUMAN was named the number-one ranked vendor on G2's Summer 2026 Grid for Bot Detection and Mitigation Software, based entirely on verified customer reviews. SE005, SE004
CE043 In the Forrester Wave Q2 2026 Bot and Agent Trust Management Software evaluation, HUMAN received the highest possible scores across nine criteria, including Threat Research, AI Agent Trust Management, Marketing Analytics Assurance, Intent Visibility, Attack and User Analytics, Customizable Reports and Dashboards, Security Operations Integrations, Vision, and Partner Ecosystem. SE005, SE004
CE044 HUMAN's Bot Management mindshare on PeerSpot declined from 11.6% to 8.1% year-over-year as of June 2026, suggesting increased competitive pressure from emerging bot-management vendors. SE011
CE045 Enterprise customers and analyst reviewers have identified HUMAN's decision engine as operating as a "black box," with limited visibility into model logic, signal weights, or detection thresholds, making independent auditability of false-positive rates difficult. SE010, SE011
CE046 User reviews and analyst comparisons as of 2026 cite HUMAN's complex integration setup for bespoke API infrastructure and limited documentation depth for custom rule management as recurring areas for improvement. SE015, SE010
CU001 HUMAN Security's customer base spans five segments — advertising/adtech platforms, e-commerce and retail, financial services, enterprise security (via channel), and travel/hospitality. SU014, SU020, SU006
CU002 Adtech and programmatic advertising is HUMAN Security's largest historical customer segment, comprising DSPs, SSPs, ad networks, brand advertisers, and agency holding companies. SU002, SU010, SU011, SU001
CU003 E-commerce and retail customers use HUMAN's Bot Defender and Sightline for scraping defense, ATO prevention, and high-heat release protection, with verified deployments at $500M–$1B and $10B+ revenue accounts per Gartner Peer Insights. SU014
CU004 Financial services is an early-adoption segment with no publicly named customers, but HUMAN's May 2026 benchmark shows agentic AI traffic in the vertical doubled month-over-month, indicating growing deployment interest. SU020, SU025
CU005 Optiv, which serves 73% of the Fortune 100, and Consortium Networks are named channel partners delivering HUMAN's platform to enterprise security buyers as of August 2024. SU004, SU005, SU006, SU008, SU018
CU006 A travel and hospitality company with $250M–$500M revenue described a production deployment of HUMAN's managed bot defense in a 5-star Gartner Peer Insights review dated March 2026. SU014
CU007 HUMAN Security's company description on Gartner Peer Insights (updated February 2026) states the platform verifies "more than 30 trillion digital interactions per week," an increase from the 20 trillion per week figure cited at the October 2024 fundraise. SU014, SU006
CU008 HUMAN Security claims 500+ global brands and organizations as customers, a figure that has appeared consistently in press releases and fundraise announcements from 2022 through August 2024. SU006, SU021
CU009 In calendar year 2025, HUMAN's Defense Platform analyzed over one quadrillion digital interactions, as disclosed in the March 2026 State of AI Traffic benchmark report. SU020
CU010 HUMAN Security verifies more than 3 billion unique devices per month, per the August 2024 partner program launch announcement. SU006, SU005
CU011 AI-driven traffic rates on HUMAN's platform grew 187% from January to December 2025, with the majority concentrated in retail/e-commerce, streaming/media, and travel/hospitality. SU020
CU012 Traffic from AI agents and agentic browsers grew 7,851% year-over-year in 2025 per HUMAN's 2026 benchmark, representing a new category of automated traffic distinct from legacy bots. SU020
CU013 AdRoll integrated HUMAN Security's dual-layer fraud detection (FraudSensor post-bid + MediaGuard pre-bid) in October 2025, becoming the first DSP to combine both solutions with IVT detection in 12 milliseconds. SU001
CU014 Automated traffic across the internet grew 23.51% year-over-year in 2025 while human traffic grew only 3.10%, according to HUMAN's 2026 benchmark, creating strong structural demand for bot management. SU020
CU015 HUMAN Security's Ad Fraud Defense (pre-bid) and Ad Fraud Sensor (post-bid) platforms hold MRC accreditation for GIVT and SIVT detection across Desktop, Mobile Web, Mobile In-App, and CTV environments, as confirmed by the MRC Board of Directors letter dated April 4, 2025. SU013, SU012
CU016 HUMAN Security's Ad Viewability Measurement product received MRC accreditation for viewability across display and video impressions on desktop, mobile web, and mobile app environments, announced April 27, 2026. SU012, SU001
CU017 Madhive, described by HUMAN CEO Stu Solomon as a "long-standing partner," launched a Fraud Free Guarantee in June 2025 powered by HUMAN's MRC-accredited pre-bid and post-bid fraud detection, covering 30,000+ daily local campaigns. SU002, SU003
CU018 LinkedIn integrated HUMAN Security in May 2024 for pre-bid IVT filtering and post-bid detection across its desktop ad network and publisher network including CTV, with the integration protecting a 1 billion+ member professional community. SU010, SU011
CU019 HUMAN detected less than 1% of desktop impressions as invalid traffic on LinkedIn's ad network in the first 30 days after the May 2024 integration, as disclosed in HUMAN and LinkedIn's joint announcement. SU010, SU011
CU020 Sovrn, a publisher/advertiser platform, is cited by name in HUMAN's April 2026 MRC viewability accreditation announcement as an early adopter with MD Jeff Meglio providing a named endorsement of improved campaign performance. SU012, SU001
CU021 Consortium Networks CEO Nate Ungerott provided a public testimonial at HUMAN's August 2024 channel program launch, describing HUMAN as bringing "exceptional value to our customers" for defending against sophisticated fraud. SU004, SU006, SU018
CU022 Optiv is named by HUMAN as an "integral ally" channel partner with access to the full HUMAN Defense Platform, and serves 73% of the Fortune 100 as a cybersecurity integrator. SU006, SU005
CU023 HUMAN Sightline Cyberfraud Defense holds a 4.7/5 overall rating on Gartner Peer Insights with a 4.8/5 for Service & Support and 4.7/5 for Product Capabilities, based on reviews updated through April 2026. SU014
CU024 G2 recognized HUMAN Security as Best Security Software Product of 2026 ranking SU007, SU022
CU025 A Gartner Peer Insights reviewer from a 1B–10B USD retail company states "We have a long relationship with Human," indicating a multi-year production deployment of HUMAN's bot defense solution. SU014
CU026 A Gartner Peer Insights reviewer from a $500M–$1B retail company gave HUMAN Sightline a 3/5 rating in April 2026, describing the product as a "black box" with limited visibility into detection logic and no proactive change notifications. SU014
CU027 Gartner Peer Insights reviewers identify specific dislikes: sluggish dashboard performance, data access limited to the past two weeks, limited manual tuning capability, and opaque detector logic with no proactive notification of changes. SU014
CU028 HUMAN's Forrester Wave Q2 2026 report states "HUMAN's customers compliment the level of detail and attack insight that they receive from the Sightline feature," indicating reference-quality satisfaction among evaluated accounts. SU019
CU029 Industry-wide, 42% of cybersecurity customers switched vendors in the past two years due to poor customer experience, and 35% of cybersecurity churn is attributable to CX issues rather than product performance (ZipDo, Feb 2026). SU009
CU030 HUMAN Security does not disclose NRR, GRR, average contract length, or customer churn rate, as it is a private company; these are the highest-priority retention metrics for diligence. SU021
CU031 The HUMAN Advantage Partner Program, launched August 21, 2024, structures partner compensation as a three-tier system rewarding annualized bookings, training completion, and customer retention. SU004, SU005, SU006
CU032 The HUMAN Advantage Partner Program offers deal registration and incumbency protections to channel partners, designed to reduce channel conflict and improve account durability for enterprise customers. SU005, SU006
CU033 HUMAN launched AgenticTrust, a module within Sightline Cyberfraud Defense, in 2025 to distinguish among human, bot, and agentic AI traffic; it received the highest possible Forrester score in the AI Agent Trust Management criterion in Q2 2026. SU019, SU007
CU034 HUMAN announced support for Amazon Web Services' Bedrock AgentCore browser in AgenticTrust, enabling cryptographically signed, policy-compliant verification of AI agents built on AWS infrastructure. SU019
CU035 HUMAN Security's public case studies and named customer deployments are predominantly in adtech and programmatic advertising (LinkedIn, Sovrn, Madhive, AdRoll), creating identifiable sector concentration in the advertising vertical. SU002, SU010, SU011, SU012, SU001
CU036 No top-customer revenue share, customer count by segment, or ARR breakdown is publicly disclosed by HUMAN Security, making it impossible to quantify concentration risk from external evidence alone. SU021
CU037 HUMAN's Riskified partnership (announced August 2026 per RivalSense competitive intelligence) targets ecommerce fraud prevention via AI Agent Approve and AI Agent Intelligence, extending reach beyond core adtech buyers. SU017
CU038 Enterprise direct-sales cycles of 6–7 months for large accounts were a documented pre-2024 friction point; the channel program launched specifically to reduce this barrier via partner-led onboarding and managed service. SU004, SU005
CU039 HUMAN Security launched Page Intelligence in October 2025, extending fraud detection to the landing page (the gap between click and user interaction), giving brands and publishers real-time IVT visibility via a lightweight asynchronous tag using 400+ algorithms. SU015, SU016
CU040 A 10B+ USD retail company Gartner reviewer (March 2026) states HUMAN enabled "a very secure online presence" and helped become "one of the very few sneaker retailers without a waiting room," indicating multi-brand platform-wide production deployment. SU014
CU041 HUMAN Security's product innovation in 2025–2026 (AgenticTrust, Page Intelligence, MRC viewability, AWS Bedrock support) represents significant expansion surface into marketing analytics buyers beyond traditional security teams. SU019, SU015, SU012
CR001 The FTC sent formal warning letters to 13 data brokers under PADFAA on February 9, 2026, signaling active regulatory scrutiny of mass-scale behavioral data vendors. SR006, SR012
CR002 HUMAN Security processes more than one quadrillion digital interactions per year, creating a large-scale behavioral data collection and analytics surface. SR001, SR002
CR003 HUMAN's Ad Viewability Measurement solution earned MRC accreditation in April 2026 for display and video impressions across desktop, mobile web, and mobile app. SR002, SR027
CR004 As of January 2026, 20 U.S. states are actively enforcing comprehensive consumer privacy laws, creating a multi-jurisdictional compliance patchwork for data vendors. SR012, SR020
CR005 The DOJ Data Security Program restricts bulk cross-border data transfers involving "countries of concern," requiring CISA-compliant security controls for covered data flows. SR006, SR020
CR006 Plaintiff attorneys have developed a novel theory using DSP violations as predicates for federal Wiretap Act class action claims against adtech behavioral data flows. SR006
CR007 No active regulatory enforcement or litigation specifically targeting HUMAN Security is publicly known as of June 2026. SR005, SR012
CR008 The Check My Ads Institute argues that MRC self-regulation is structurally insufficient for adtech accountability and calls for mandatory government regulation. SR007
CR009 The MRC finalized Digital Advertising Auction Transparency Standards in January 2026, mandating disclosure of auction mechanics, pricing, and reporting by accredited vendors. SR026, SR007
CR010 Online privacy lawsuit filings surged from approximately 200 in 2023 to approximately 4,000 in 2024 and continued rising through 2025, targeting behavioral tracking technologies. SR020
CR011 Bot detection systems produce false positives for privacy-tool users including VPN subscribers, ad blocker users, and non-mainstream browser operators. SR003, SR004
CR012 HUMAN's Defense Platform processes more than 20 trillion digital interactions weekly and over one quadrillion annually, requiring substantial cloud compute infrastructure. SR001, SR002
CR013 Automated internet traffic grew 23.51% year-over-year in 2025, while AI-driven traffic grew 187% from January to December per HUMAN's 2026 benchmark report. SR001
CR014 HUMAN customers averaged over 400,000 attempted post-login account takeover attacks in 2025, more than quadruple the 2024 baseline, per HUMAN's own benchmark data. SR001
CR015 An AWS thermal event in US-EAST-1 on May 7–8, 2026 cascaded across more than 150 downstream cloud services, including security vendors reliant on that availability zone. SR008, SR029
CR016 An AWS data center in the UAE (ME-CENTRAL-1) was struck by a kinetic attack on March 1–2, 2026, causing fires, power loss, and service disruption across 38+ AWS services in the UAE and 46+ in Bahrain. SR029
CR017 BADBOX 2.0 evolved from BADBOX 1.0 using new backdoor mechanisms in direct response to HUMAN Security's original exposure, demonstrating rapid threat-actor adaptation. SR009, SR023
CR018 DoubleVerify detected 140% more CTV fraud schemes and variants in Q1 2026 versus Q1 2025, fueled by AI-assisted fraudster tooling that automates scheme creation. SR014
CR019 AI is automating high-velocity attacker operations in 2026, enabling low-skill threat actors to conduct high-impact attacks including deepfakes and automated exploit development. SR017
CR020 The window between vulnerability disclosure and active exploitation collapsed from weeks to days in the second half of 2025 per Google Cloud threat research. SR018
CR021 Ad blockers suppress anti-bot detection scripts, causing detection systems to classify privacy-conscious users as bots due to apparent JavaScript execution absence. SR003, SR004
CR022 Fraud detection model performance degrades when data pipelines are fragmented by GDPR and CCPA data residency and processing restrictions. SR030
CR023 Cloudflare is ranked #3 in Bot Management with 9.2% mindshare versus HUMAN at #5 with 8.1% per Gartner Peer Insights and PeerSpot comparisons as of 2026. SR015, SR016
CR024 Cloudflare One achieves higher long-term ROI than HUMAN Defense Platform per independent user reviews due to its integrated multi-layer security suite. SR016
CR025 HUMAN depends on Google to update Play Protect and execute C2 sinkholing for BADBOX-class botnet disruptions; HUMAN cannot sinkhole infrastructure unilaterally. SR009, SR010
CR026 The ad verification market has consolidated to a near-duopoly of DoubleVerify and Integral Ad Science as listed public companies with scale cost advantages. SR011, SR021
CR027 More than 95% of AI-driven automation traffic is concentrated in retail/ecommerce, streaming/media, and travel/hospitality verticals per HUMAN's 2026 benchmark. SR001
CR028 MRC accreditation is voluntary, and critics argue the MRC lacks sufficient governance independence from the entities it accredits to enforce meaningful standards. SR007, SR026
CR029 The Shadowserver Foundation sinkholed BADBOX 2.0 command-and-control domains, diverting over one million infected devices from criminal servers as part of the 2025 disruption. SR022, SR025
CR030 HUMAN's ML inference at 20T+ weekly interaction scale requires substantial public cloud compute; AWS is inferred as the primary provider given HUMAN's infrastructure profile. SR001, SR029
CR031 Google, Meta, and Amazon provide in-house fraud detection for walled-garden inventory, reducing the addressable market for third-party verification on premium impressions. SR011
CR032 Google filed a lawsuit against 25 alleged BADBOX 2.0 operators in New York federal court, supported by evidence contributed by HUMAN Security and Trend Micro. SR023, SR025
CR033 HUMAN Security's most recently disclosed valuation is $1.5 billion from January 2022, predating both the PerimeterX merger and the October 2024 growth round. SR019
CR034 HUMAN remains a private company with no publicly disclosed ARR, gross margin, burn rate, or net revenue retention as of June 2026. SR019
CR035 HUMAN's Bot Management market mindshare of 8.1% places it fifth in the competitive stack behind Cloudflare, Akamai, Imperva, and Radware per available review data. SR015, SR016
CR036 The AI ad fraud and bot detection market includes six or more competing tools: HUMAN Security, CHEQ, DoubleVerify, IAS, Cloudflare Bot Management, and DataDome. SR021
CR037 Bundled security platform solutions from Google, Meta, and Amazon eliminate marginal cost for enterprise customers already committed to those platforms, reducing HUMAN's pricing power. SR011, SR031
CR038 Global digital advertising fraud is estimated at $80–$100 billion annually; HUMAN operates in a permanent escalating arms race with fraudsters. SR011, SR028
CR039 HUMAN announced a $50M+ growth round in October 2024, described by CEO Stu Solomon as deliberately constrained to enable targeted investment without over-capitalization. SR019
CR040 Fraud signature drift causes ML rule engines to expire before teams can update them, requiring continuous retraining cycles that increase COGS for detection platforms. SR030, SR017
CR041 Agentic AI traffic grew 7,851% year-over-year in 2025, representing a new threat surface that existing binary bot/human classification systems do not fully address. SR001
CR042 HUMAN's board is dominated by investor representatives from Goldman Sachs, NightDragon, WestCap, and ClearSky, creating governance concentration around investor return timelines. SR019
CV001 White Ops was acquired by Goldman Sachs Merchant Banking Division, ClearSky Security, and NightDragon in December 2020 for an undisclosed purchase price. SV015, SV014
CV002 HUMAN Security raised a $100 million growth round in January 2022 led by WestCap and NightDragon with participation from Goldman Sachs Asset Management. SV014, SV017
CV003 In connection with the July 2022 PerimeterX merger, HUMAN Security's combined entity was valued at approximately $1.5 billion according to reporting from multiple independent sources. SV015, SV022
CV004 In October 2024, HUMAN Security closed a $50 million-plus growth round led by WestCap, with additional investment from Goldman Sachs Asset Management, ClearSky Security, NightDragon, and Vertex Ventures US. SV016, SV017, SV030
CV005 The October 2024 $50M+ growth round did not disclose a new company valuation; no post-money valuation figure was reported by any independent news source covering the round. SV016, SV017
CV006 HUMAN Security's total equity raised is approximately $300 million as of October 2024 across approximately eight funding rounds, per company statement and corroborating sources. SV017, SV022
CV007 HUMAN Security received a $100 million debt facility from Blackstone Credit in connection with the July 2022 PerimeterX merger; the repayment status, maturity date, and current outstanding balance of this facility have not been publicly confirmed as of June 2026. SV015
CV008 The proceeds of the October 2024 $50M+ round were explicitly allocated to accelerating AI platform capabilities and strengthening the channel partner programme. SV016, SV017
CV009 HUMAN Security's January 2024 CEO transition announcement stated that Tamer Hassan led the company to surpass $100 million in ARR during his tenure, representing the only company-confirmed ARR milestone publicly available as of June 2026. SV018, SV017
CV010 GetLatka reported HUMAN Security ARR at $15 million as of December 2023, directly contradicting the company-claimed $100M+ ARR; this figure cannot be reconciled with post-merger headcount and platform scale and may reflect pre-merger standalone White Ops revenue or a data error. SV019
CV011 GrowJo's employee-count-model estimates HUMAN Security annual revenue at $140.4 million, consistent with the company's post-merger >$100M ARR claim and 469+ employee headcount. SV025
CV012 DoubleVerify (NYSE: DV) reported last-twelve-months revenue of $781 million and EBITDA of $261 million as of June 2026, with a gross margin of 82% in its most recently completed fiscal year per its FY2025 10-K filed February 26, 2026. SV001, SV013
CV013 DoubleVerify's current enterprise value is approximately $2 billion as of June 2026, implying an EV/LTM Revenue multiple of approximately 1.9x, the ad-verification sector floor comp for HUMAN's valuation. SV001, SV013
CV014 DoubleVerify's gross margin was 82% and EBITDA margin 33% in its most recently completed fiscal year, confirming pure-SaaS-tier margins despite trading at a compressed 1.9x revenue multiple due to advertising-sector structural headwinds. SV001, SV013
CV015 Integral Ad Science (NASDAQ: IAS) reported approximately $530 million to $591 million in LTM revenue as of recent quarters, competing with HUMAN in programmatic fraud detection but not in application security or bot management. SV002, SV001
CV016 The broader public cybersecurity market trades at a median EV/NTM Revenue multiple of approximately 7.8x as of late 2025 and Q1 2026, representing the median comp anchor for HUMAN's exit analysis per Windsor Drake's Cybersecurity Valuation Report. SV005, SV008
CV017 The private cybersecurity market's median EV/ARR multiple stands at approximately 15.2x in 2025–2026, significantly above the public market median of 7.8x, reflecting the growth premium investors pay for earlier-stage companies per Windsor Drake. SV005, SV008
CV018 Cybersecurity M&A exit multiples mediated at 16.3x revenue in 2025, with cloud-security transactions averaging 22.7x and strategic outliers reaching 35.5x per Windsor Drake and SaaS Mag reporting. SV005, SV008
CV019 Finro's Q2 2026 cybersecurity multiples dataset (265 companies, 9 niches) places the Application Security niche — HUMAN's closest comparable niche — at an average EV/Revenue multiple of 15.4x and median of 13.0x, across 52 companies. SV004
CV020 Threat Intelligence, an adjacent niche to HUMAN's Satori team, shows an average EV/Revenue of 14.9x and median 10.1x across 50 companies in the Finro Q2 2026 dataset; public threat intelligence comps average only 1.2x, highlighting the public-to-private valuation gap. SV004
CV021 Cybersecurity M&A activity totaled $47 billion in Q1 2026 alone, following a record $96 billion across 400 transactions in full-year 2025, a 270% increase over 2024; strategic buyers including Palo Alto, CrowdStrike, and Check Point accounted for approximately $1.1 billion in Q1 aggregate value per Kroll and CloudStack Networks. SV009, SV003
CV022 Disclosed cybersecurity M&A had already crossed $65 billion in aggregate deal value before mid-2026, anchored by Google's $32 billion Wiz acquisition (closed March 2026) and Palo Alto's $25 billion CyberArk acquisition (closed February 2026). SV008, SV009
CV023 The median public SaaS EV/NTM Revenue multiple stands at approximately 8.5x as of mid-2026, up approximately 90% from the Q1 2023 trough of 4.5x, but still 47% below the 2021 peak of approximately 16x per Value Add VC. SV011
CV024 Private SaaS companies at the $10–$50M ARR scale transacted at 5.5–7.2x ARR at the lower middle market in Q1 2026 per iMerge Advisors, with top-quartile (NRR >110%, Rule of 40 >40%) reaching 8.0x+. SV006
CV025 Google acquired Wiz for $32 billion at approximately 32x ARR (approximately $1 billion ARR); Palo Alto Networks acquired CyberArk for $25 billion at approximately 18.6x ARR ($1.34B ARR); these represent ceiling-setting strategic M&A precedents in the cybersecurity sector. SV005, SV008
CV026 Arkose Labs, HUMAN's closest pure-play bot management competitor, had ARR of $46.9 million and a valuation of $140.7 million (approximately 3x ARR) as of 2024 per GetLatka; at this scale and multiple HUMAN's stated $100M+ ARR would imply a notably higher per-ARR-dollar premium than Arkose Labs commands. SV027
CV027 Netacea, a bot management competitor, has raised only $22.47 million total across all rounds as of December 2024, with the most recent round being a $5.11 million Series A-III in December 2024; it represents a sub-scale comparator not useful for HUMAN's valuation benchmarking. SV026
CV028 DataDome closed a $42 million Series C in March 2023; current valuation is not publicly disclosed per PitchBook 2026 profile; DataDome is detected on over 1,450 enterprise websites. SV028
CV029 The cybersecurity sector's premium over the broader SaaS market is at its widest level in at least five years as of 2026: public cybersecurity trades at 7.8x versus 5.5x for public B2B SaaS broadly, and private cybersecurity startups average 15.2x per SaaS Mag analysis. SV008
CV030 Strategic buyers drove approximately 92% of cybersecurity M&A by value in 2026 as platform consolidation overtook private equity as the primary transaction driver, narrowing to platform-fit targets rather than broad portfolio expansion. SV008, SV009
CV031 Sustaining the $1.5 billion 2022 valuation at the current application-security niche median of 13.0x requires HUMAN's ARR to be at or above approximately $115 million; at 15.2x private cybersecurity median it requires $99 million ARR, broadly consistent with the $100M+ claim. SV004, SV005
CV032 At the private cybersecurity median of 15.2x applied to the company-claimed $100M+ ARR, HUMAN's implied enterprise value is approximately $1.52 billion, roughly in-line with the 2022 $1.5B mark and representing the base-case central estimate. SV005, SV018
CV033 At the application-security niche median of 13.0x (Finro Q2 2026) applied to $100M ARR, HUMAN's implied enterprise value is approximately $1.3 billion, approximately 13% below the 2022 mark and representing the base-case low end. SV004, SV018
CV034 In the bear scenario, applying an 8–10x blended cybersecurity/ad-verification multiple to $80–100M ARR implies an enterprise value of $640M–$1.0B, below the $400M total capital invested and potentially triggering liquidation preferences. SV004, SV006, SV019
CV035 In the bull scenario, applying a top-quartile cybersecurity multiple of 18–20x to ARR of $130–140M (consistent with GrowJo's $140.4M estimate) implies an enterprise value range of $2.34–2.8 billion, approximately 1.6–1.9x the 2022 mark. SV005, SV025, SV008
CV036 The approximately $400 million total capital invested ($300M equity plus $100M Blackstone debt) means a $1.5B base-case EV represents a 3.75x gross MOIC before dilution and liquidation preferences; achieving a 3x net return on the 2020 Goldman Sachs acquisition entry price likely requires a $1.5B+ exit EV. SV006, SV015, SV017
CV037 No secondary market transactions or post-2022 valuation marks for HUMAN Security are publicly available on any alternative data platform (Premier Alternatives, secondary-market databases) as of June 2026. SV010
CV038 Premier Alternatives lists HUMAN Security's current 2026 valuation as "N/A" with no funding history imported, confirming the absence of publicly available secondary-market pricing data. SV010
CV039 HUMAN Security is not named in any confirmed 2026 cybersecurity IPO pipeline tracked by ipos.fyi, PitchBook's cybersecurity IPO list, or any confirmed strategic M&A announcement as of the June 2026 research date. SV012, SV009
CV040 Kroll's Spring 2026 Cybersecurity M&A Industry Insights report notes that median EV/NTM Revenue multiples in its cybersecurity index fell 26% quarter-over-quarter in Q1 2026, driven by AI-related concerns weighing on cybersecurity equities. SV003, SV008
CV041 HUMAN's platform breadth across bot management, ad verification, application security, account protection, and agentic AI trust differentiates it from single-point competitors such as Arkose Labs, DataDome, and Netacea, which address only one or two of these layers. SV023, SV029, SV026
CV042 HUMAN's stated detection scale of 20 trillion digital interactions per week across 3 billion unique devices represents material competitive differentiation; no competitor has publicly claimed equivalent weekly interaction volume as of June 2026. SV023, SV029
CV043 HUMAN's October 2024 growth round was participated in exclusively by five existing investors (WestCap, Goldman Sachs, ClearSky, NightDragon, Vertex); no new institutional investor joined the cap table, which may reflect investor-access rationing or an inability to attract step-up capital from arms-length external LPs. SV016, SV017
CV044 HUMAN's July 2025 launch of Sightline Cyberfraud Defense and AgenticTrust positions the company in the AI Security niche, where Momentum Cyber recorded $2 billion in financing YTD 2026 and M&A deals are on pace for 400%+ growth in 2026, commanding the highest multiple premium in cybersecurity. SV021, SV023
CV045 HUMAN Security has not publicly disclosed NRR, gross margin, burn rate, ARR growth rate, or any other operating metric from audited financial statements as of June 2026; these absences constitute the primary diligence blockers preventing a conviction recommendation. SV010, SV019
CV046 The broader AdTech public SaaS sector median NTM EV/Revenue multiple is only 0.9x as of June 2026 per Multiples.vc, the lowest across all major SaaS subsectors; this represents the structural floor if HUMAN's ad-verification revenue is valued at AdTech sector rates rather than cybersecurity rates. SV002
CV047 Windsor Drake notes that cybersecurity companies that raised at inflated 2021–2022 peak valuations are frequently executing structured rounds with guaranteed returns or participation rights to maintain nominal face-value marks while providing investor downside protection. SV005
CV048 Momentum Cyber's May 2026 market review recorded 31 cybersecurity M&A transactions and 46 financing transactions during the month, with $823 million in total disclosed M&A deal value and $365 million in financing capital deployed, including 4 AI Security M&A deals. SV021, SV009
CV049 Gartner forecasts global information security spending of $244.2 billion in 2026, up 13.3% in current dollars year-over-year, with cloud security growing 28.8% as the fastest subsegment, supporting the market-necessity argument in the investment thesis. SV008
CV050 The 2026 cybersecurity IPO window has reopened following Netskope's September 2025 IPO, but the market remains selective; investors require clean financials, AI innovation, and Rule of 40 performance before awarding premium multiples to cybersecurity IPO candidates. SV005, SV012
CV051 HUMAN Security's estimated headcount of approximately 469–519 employees as of mid-2026, applied to the company-claimed >$100M ARR, implies an ARR-per-FTE of $200–$300K, broadly consistent with SaaS cybersecurity industry benchmarks, indicating moderate revenue efficiency. SV024, SV018
CV052 HUMAN was recognized as a Leader in the Forrester Wave: Bot and Agent Trust Management Q2 2026 evaluation, alongside Kasada, providing third-party validation of the platform's competitive positioning in the bot and agent governance market. SV029
来源
编号出版方标题引文
SO001 HUMAN Security About | HUMAN Security "Our founders—Tamer Hassan, Michael Tiffany, Dan Kaminsky, and Ash Kalb—set the foundation for a 'bot or not' company... protecting the internet today by safeguarding the entire customer journey and upholding the integrity of 20 trillion digital interactions a week."
SO002 HUMAN Security Board of Directors | HUMAN Security Board Observers: Ryan Benevides, Dan Burns, Itzhak Fisher, Steve Fredrick, Rhys Gordon, Hannah Huffman, Lance Matthews, Alexander Weiss.
SO003 PR Newswire HUMAN Security Announces Strategic Leadership Transition: Tamer Hassan to Become Executive Chairman, Stu Solomon Appointed to CEO "Tamer Hassan, co-founder and CEO who has led the company's transformation into a renowned platform for disrupting bot attacks, online fraud, and abuse, is transitioning to the role of board member and Executive Chairman of the company."
SO004 BusinessWire HUMAN and PerimeterX Unite in Market-Changing Merger to Safeguard Customers From Sophisticated Bot Attacks, Fraud and Account Abuse "The combined companies will comprise more than 450 employees under the HUMAN company name, 500+ customers and have more than $100 million in ARR... HUMAN has received a $100 million debt facility from Blackstone Credit."
SO005 BusinessWire White Ops Announces Acquisition by Goldman Sachs Merchant Banking, ClearSky Security, and NightDragon "Goldman Sachs Merchant Banking Division, in partnership with ClearSky Security and NightDragon (together, the 'Sponsors')... acquiring the business from previous investors Paladin Capital Group, Grotech Ventures, and other shareholders."
SO006 BankInfoSecurity Human Security Raises $50M+ to Take On Click Fraud Defense "Human Security said the growth capital will help the New York-based company enhance its data science and engineering capabilities... Human employs 400 people today."
SO007 Pulse2 HUMAN: Cybersecurity Company Raises $50+ Million (Growth Capital) "HUMAN has invested heavily in developing a unified Human Defense Platform that verifies over 20 trillion digital interactions weekly, enabling 500+ global brands with unparalleled telemetry."
SO008 SiliconAngle Human Security raises $50M+ to expand digital protection platform
SO009 SecurityWeek Human Security Banks Another $50M in Growth Funding "The latest raise follows a hefty $100 million funding round in January 2022 that included a push by Human Security into new product categories."
SO010 AdExchanger HUMAN Raises $50 Million "Update 10/10/24: After publication, HUMAN said that the CEO misspoke about the company's product development plans, and that HUMAN does not plan to build a proprietary ID of any kind."
SO011 Security Journal Americas HUMAN Security announces new Executive Chairman and CEO "HUMAN Security, an organization focused on digital fraud prevention, has announced that Tamer Hassan, Co-Founder and CEO, is transitioning to the role of board member and Executive Chairman."
SO012 Fintech Global Goldman Sachs-owned Human Security rakes in $100m "Anti-bot and fraud detection company Human Security has concluded a $100m funding round led by WestCap. The funding round was also supported by NightDragon."
SO013 GlobeNewswire via ITNewsOnline HUMAN Recognized as a Leader by a Top Research Firm; Empowering Organizations to Transform Threat Intelligence into Action in the Agentic Internet "HUMAN received the highest possible scores across nine criteria, including Threat Research (the only vendor to score 5/5), AI Agent Trust Management, Marketing Analytics Assurance, Intent Visibility, Attack and User Analytics, Customizable Reports and Dashboards, Security Operations Integrations, Vision, and Partner Ecosystem."
SO014 The Hacker News Massive Ad Fraud Scheme Targeted Over 11 Million Devices with 1,700 Spoofed Apps "VASTFLUX was a malvertising attack that injected malicious JavaScript code into digital ad creatives... generating over 12 billion bid requests per day at its peak."
SO015 Craft.co HUMAN Security Company Profile Total Funding $159 M
SO016 TechFundingNews Cybersecurity startup HUMAN Security raises $50M to protect against bots, fraud and threat
SO017 Tracxn HUMAN — 2026 Funding Rounds & List of Investors HUMAN has raised a total of $299M over 8 funding rounds.
SO018 AlleyWatch White Ops Acquired by Goldman Sachs Merchant Banking Division, ClearSky, and NightDragon
SO019 Globes (English) Bot protection co PerimeterX merges with HUMAN Security
SO020 Security Systems News HUMAN Security, PerimeterX announce merger to take on bots, identity fraud
SO021 citybiz HUMAN Security Appoints Stu Solomon CEO
SO022 citybiz HUMAN Raises $50+ Million in Growth Funding
SO023 TechIntelPro HUMAN Named Leader in Forrester Wave for Bot and Agent Trust Management
SO024 PR Newswire Asia HUMAN Orchestrates Unprecedented Private Takedown, VASTFLUX
SO025 Techerati VastFlux ad-fraud scheme affecting millions taken down by HUMAN
SM001 HUMAN Security, Inc. HUMAN Security's 2026 State of AI Traffic & Cyberthreat Benchmark Report Signals a New Internet Era: Automation Growth Now Outpaces Humans "In 2025, HUMAN's Defense Platform analyzed more than one quadrillion digital interactions… automated traffic is growing eight times faster than human traffic."
SM002 HUMAN Security, Inc. HUMAN recognized as a Leader in The Forrester Wave™ for Bot and Agent Trust Management Software
SM003 Business Insider / GlobeNewswire HUMAN Recognized as a Leader by a Top Research Firm; Empowering Organizations to Transform Threat Intelligence into Action in the Agentic Internet "HUMAN Security, Inc., the trust layer for media and agentic commerce platforms, verifying engagement, reducing fraud, and enabling authentic interactions across humans, bots, and AI agents."
SM004 The Business Research Company Bot Mitigation Market Report 2026
SM005 Fortune Business Insights Bot Security Market Size, Share & Growth Rate [2026-2034] "The global bot security market size was valued at USD 1.05 billion in 2025 and is projected to grow from USD 1.27 billion in 2026 to USD 5.67 billion by 2034, exhibiting a CAGR of 20.55%."
SM006 Fraudlogix Ad Fraud Statistics 2026: 20.64% IVT Rate "Of the 105.7 billion impressions in our dataset, 21.81 billion (20.64%) showed risk signals indicating invalid traffic. Applied to U.S. programmatic ad spend, this IVT rate suggests approximately $37 billion in advertiser dollars may be associated with invalid traffic annually."
SM007 Pixalate Q1 2026 Ad Fraud Benchmarks Report for North America "The IVT rate on Connected TV (CTV) apps was 24% in the US… desktop and mobile web: 24%, mobile app: 32%."
SM008 TAG (Trustworthy Accountability Group) TAG Recognizes Leading Companies Across Ad Industry Worldwide for Achieving 2026 Certifications
SM009 PR Newswire TAG Recognizes Leading Companies Across Ad Industry Worldwide for Achieving 2026 Certifications
SM010 IT Business Net (GlobeNewswire) HUMAN Security's 2026 State of AI Traffic & Cyberthreat Benchmark Report Signals a New Internet Era
SM011 Grand View Research Fraud Detection and Prevention Market (2026-2033)
SM012 The Business Research Company eCommerce Fraud Detection and Prevention Market Report 2026
SM013 Media Rating Council (MRC) MRC Accreditation Letter — HUMAN Ad Fraud Defense Pre-Bid and Ad Fraud Sensor Post-Serve Platforms "The MRC Board of Directors has voted in favor of continuing accreditation for HUMAN's Ad Fraud Defense pre-bid platform ('the Service', formerly known as the MediaGuard platform) and Ad Fraud Sensor post-serve platform."
SM014 wmtips.com Akamai Bot Manager vs. Cloudflare Bot Management: 2026 Market Share & Usage Comparison "Cloudflare leads in market share among bot mitigation technologies, holding roughly 79% compared to Akamai's 6%—this advantage holds in all major markets."
SM015 Improvado Ad Fraud in 2026: Detection, Prevention, and Protection Strategies "Digital advertising fraud will exceed $100 billion globally in 2026, up from $84 billion in 2023. Invalid traffic (IVT) rates reached 20.64 percent globally in 2025."
SM016 ExchangeWire EXTE Joins Forces with HUMAN Security to Protect Ad Inventory Quality & Integrity
SM017 PeerSpot Top Rated Bot Management Vendors 2026
SM018 ppc.land TAG hands out 307 seals to 196 companies in 2026 recertification
SM019 Global Growth Insights Account Takeover Protection Market Analysis Report 2035 "The Global Account Takeover Protection Market size is estimated at USD 6.28 billion in 2025 and is expected to reach USD 7.46 billion in 2026… registering a CAGR of 18.89%."
SM020 SiliconAngle Human Security raises $50M to expand digital protection platform
SM021 Vendr HUMAN Security on Vendr Marketplace
SM022 Yahoo Finance HUMAN raises $50 million in growth funding
SM023 Tracxn HUMAN Security Company Profile
SM024 ChannelVision Magazine HUMAN Security Beefs Up Exec Leadership, Go-to-Market Strategy
SM025 HUMAN Security, Inc. Platform Expansion: Fueling the Future of HUMAN
SM026 Business Wire HUMAN Raises $100 Million In Growth Funding Round Led By WestCap and NightDragon
SM027 Economic Times (CIOSEA) Cybersecurity firm HUMAN Security raises $50 mn in growth funding
SP001 Kasada Kasada Secures $20 Million Round to Accelerate Global Expansion and Broaden Platform Offerings our average return on investment is over 250% driven largely by cost savings
SP002 Kasada Kasada Named a Leader in The Forrester Wave™: Bot and Agent Trust Management Software, Q2 2026
SP003 Manila Times (GlobeNewswire) HUMAN Recognized as a Leader by a Top Research Firm; Empowering Organizations to Transform Threat Intelligence into Action in the Agentic Internet HUMAN stands out for its attack profiles, which offer rich attack analytics context and detail, and for a threat research team whose takedowns create impact far beyond its customer base.
SP004 Secure IT World (GlobeNewswire) HUMAN Security Tops G2's 2026 Best Security List
SP005 Markets Insider (GlobeNewswire) HUMAN Launches AI-Powered Ad Verification for Advertisers and Agencies Seeking a Modern Alternative While legacy providers have left brands and agencies stuck with outdated, opaque 'black box' signals, HUMAN provides a direct path to authenticity.
SP006 HUMAN Security The 2026 State of AI Traffic & Cyberthreat Benchmark Report automated traffic—all non-human internet traffic—is growing eight times faster than human traffic, AI-driven traffic is the fastest-growing category of internet traffic
SP007 PeerSpot Compare Arkose vs Human Defense Platform (June 2026) The mindshare of Human Defense Platform is 8.1%, down from 11.6% compared to the previous year.
SP008 DataDome DataDome Closes $42 Million in Series C Funding to Advance the Fight Against Bot-Driven Cyberattacks and Fraud
SP009 Business Wire Fingerprint Reports 65% ARR Growth, Surpasses 1 Billion Device Identifications Per Month as Enterprises Adopt Device Intelligence to Combat AI-Driven Fraud The company now serves 2,000 customers in over 56 countries, achieving 36% customer growth and an industry-leading net revenue retention rate of 128%
SP010 Fingerprint We Analyzed 23 Billion Device Identification Events. Here's What We Found.
SP011 Cloudflare Plans — Bot Management for Enterprise · Cloudflare bot solutions docs
SP012 Blazing CDN Cloudflare Enterprise Plan 2026: Pricing, Features Is It Worth It Cloudflare publishes pricing for Free, Pro ($25/month), and Business ($250/month per zone). Enterprise has never appeared on a public rate card.
SP013 6sense DoubleVerify vs Integral Ad Science: Ad Fraud Detection Comparison
SP014 PR Newswire Netacea Positioned among Top Vendors in Bot and Agent Trust Management 18% of LLM scraping traffic is unannounced, meaning it mimics human click patterns to slip through client-side protocols of JavaScript and CAPTCHA tests
SP015 GetLatka DataDome Revenue 2024: $36M ARR, $42.4M Raised
SP016 Arkose Labs Customers | Arkose Labs 95% Reduction in automated attacks; $50M+ Annual fraud loss prevented
SP017 Tracxn Arkose Labs — 2026 Company Profile
SP018 HUMAN Security The Human Defense Platform | HUMAN Security
SP019 DoubleVerify Investor Relations DoubleVerify Reports Fourth Quarter and Full Year 2025 Financial Results We grew revenue 14% year-over-year to $748 million, exceeding our initial 10% growth outlook for the year
SP020 CHEQ The Global Leader in Go-to-Market Security | CHEQ
SP021 CSIMarket DoubleVerify Holdings Inc Market share relative to its competitors, as of Q1 2026
SP022 Akamai Bot Manager | Bot Detection, Protection, and Management | Akamai
SP023 Tracxn Kasada — 2026 Company Profile
SP024 PeerSpot Compare Akamai Bot Manager vs Imperva Application Security Platform (Updated Mar 2026) Imperva is ranked #1 with an average rating of 8.5; Akamai holds a 9.7% mindshare in BM, compared to Imperva's 15.7% mindshare
SP025 Fingerprint Fingerprint | Identify Every Web Visitor & Mobile Device
SI001 Business Wire HUMAN Raises $100 Million In Growth Funding Round Led By WestCap and NightDragon In 2021, the company experienced accelerated adoption of its specialized bot mitigation platform on a global basis and saw its revenue growth rate double year over year.
SI002 Business Wire HUMAN and PerimeterX Unite in Market-Changing Merger to Safeguard Customers From Sophisticated Bot Attacks, Fraud and Account Abuse The combined companies will comprise more than 450 employees under the HUMAN company name, 500+ customers and have more than $100 million in ARR.
SI003 GetLatka HUMAN Revenue 2023: $15M ARR, $142.1M Raised In 2023, HUMAN's revenue reached $15M. Since its launch in 2012, HUMAN has shown consistent revenue growth.
SI004 Vendr Human Software Pricing & Plans 2025: See Your Cost Median buyer pays $104,906 per year
SI005 ChannelVision Magazine HUMAN Security Beefs Up Exec Leadership, Go-To-Market Strategy Because HUMAN has historically been a direct-minded organization, Scanlan said, there will be no existing channel conflict.
SI006 SiliconAngle Human Security raises $50M+ to expand digital protection platform Including the new funding, the company has raised around $300 million to date.
SI007 Yahoo Finance / Globe Newswire HUMAN Raises $50+ Million in Growth Funding to Protect the Digital Customer Journey HUMAN has invested heavily in developing a unified Human Defense Platform that verifies over 20 trillion digital interactions weekly, empowering 500+ global brands.
SI008 Economic Times CIO SEA Cybersecurity firm Human Security raises $50+ Mn in growth funding HUMAN has invested heavily in developing a unified Human Defense Platform that verifies over 20 trillion digital interactions weekly, empowering 500+ global brands.
SI009 PR Newswire HUMAN Security Announces Strategic Leadership Transition: Tamer Hassan to Become Executive Chairman, Stu Solomon Appointed to CEO Hassan led HUMAN to remarkable heights, including surpassing $100M in ARR, merging with PerimeterX, acquiring anti-malvertising leader clean.io.
SI010 Mobile Marketing Reads Ad fraud detection and prevention firm HUMAN raises over $50 million At the end of 2022, HUMAN acquired clean.io, a protection provider against e-commerce fraud and malicious advertising.
SI011 Frontlines.io HUMAN Security: The Category Expansion Playbook for When AI Disrupts Your Core Business We've heard directly from them, hey, you need to get this data to my CMO, they need to use it today because we're all having this conversation.
SI012 Yahoo Finance / Globe Newswire Multimedia Update – HUMAN Continues to Be a Leader in Bot Management Software Industry HUMAN Named a Leader in The Forrester Wave: Bot Management Software, Q3 2024.
SI013 HUMAN Security HUMAN Introduces the First Adaptive Trust Layer for the Agentic AI Era This reimagined approach enables trusted interactions and transactions across the full spectrum of online actors: humans, bots and AI agents.
SI014 IT News Online / Globe Newswire HUMAN Recognized as a Leader by a Top Research Firm; Empowering Organizations to Transform Threat Intelligence into Action in the Agentic Internet HUMAN received the highest possible scores across nine criteria, including Threat Research, AI Agent Trust Management.
SI015 Tracxn HUMAN – 2026 Company Profile and Team HUMAN has raised a total funding of $299M over 8 rounds. Its latest funding round was a Series D round on Sep 26, 2024.
SI016 RivalSense HUMAN | Competitive Intelligence Profile
SI017 HUMAN Security HUMAN recognized as a Leader in The Forrester Wave for Bot and Agent Trust Management Software HUMAN's notable vision emphasizes trust governance, is rooted in data, and maps future market progression.
SI018 HUMAN Security HUMAN Security's 2026 State of AI Traffic and Cyberthreat Benchmark Report In 2025, HUMAN's Defense Platform analyzed more than one quadrillion digital interactions.
SI019 Carahsoft Technology Corp. HUMAN Security and Carahsoft Partner to Provide Cybersecurity Solutions to the Public Sector Carahsoft will serve as HUMAN's Master Government Aggregator, making the company's industry-leading bot, fraud, and account abuse protection services available to the Public Sector.
SI020 Benchmarkit 2025 SaaS Performance Metrics Benchmarks Sales and Marketing as % of Revenue is 47% for VC-backed vs 33% for PE-backed companies. R&D is at 34% of revenue for private SaaS companies.
SI021 Momentum Cyber Goldman Sachs ClearSky Invest in White Ops Goldman Sachs and ClearSky are ideal partners to support our growth across multiple markets.
SI022 GrowJo White Ops: Revenue, Competitors, Alternatives White Ops's estimated annual revenue is currently $140.4M per year.
SI023 AIThority HUMAN Acquires Anti-Malvertising Leader, clean.io, to Enhance Protection Across the Media Ecosystem Terms of the acquisition were not disclosed.
SI024 U.S. Securities and Exchange Commission White Ops, Inc. — Form D Notice of Exempt Offering of Securities (CIK 0001611028) White Ops, Inc. — Delaware incorporation; executive officers: Michael Tiffany, Tamer Hassan, Daniel Kaminsky, Ashur Kalb, Philip Eliot, Steven Fredrick.
SI025 CityBiz HUMAN Security Appoints Stu Solomon CEO Hassan led HUMAN to remarkable heights, including surpassing $100M in ARR, merging with PerimeterX, acquiring anti-malvertising leader clean.io.
SE001 Amazon Web Services Human Defense Platform by HUMAN Security — AWS Marketplace "HUMAN is the only solution that combines fraud telemetry throughout every moment of the digital journey of your customers, from online advertising to site scraping, account creation, account takeover, and account fraud to detect, disrupt, and eliminate fraud."
SE002 HUMAN Security (Documentation) Getting started with AgenticTrust | HUMAN Documentation "Sensor: 9.6.6 ... AWS API Gateway: From v0.1.1 ... AWS Lambda@Edge: From v4.8.0 ... Cloudflare: From v6.12.0 ... PHP: Unsupported ... Python3: Unsupported"
SE003 PPC Land HUMAN Security's viewability measurement earns MRC accreditation "What makes HUMAN's accreditation different from most viewability certifications is the integration of invalid traffic (IVT) filtering directly into the measurement product."
SE004 HUMAN Security HUMAN recognized as a Leader in The Forrester Wave™ for Bot and Agent Trust Management Software "HUMAN received the highest scores possible across nine core evaluation criteria, including Threat Research, AI Agent Trust Management, Marketing Analytics Assurance, Intent Visibility, Attack and User Analytics, Customizable Reports and Dashboards, Security Operations Integrations, Vision, and Partner Ecosystem."
SE005 Manila Times (GlobeNewswire) HUMAN Recognized as a Leader by a Top Research Firm; Empowering Organizations to Transform Threat Intelligence into Action in the Agentic Internet "'We're incredibly proud to be recognized as a Leader in this category, and especially proud to be the only vendor to receive the top score in Threat Research,' said Stu Solomon, CEO."
SE006 PPC Land AI agent traffic is up 8x — HUMAN Security now tells marketers why
SE007 TMCnet (GlobeNewswire) HUMAN's Satori Researchers Identify and Disrupt Multi-Layered Ad Fraud and Malvertising Scheme Named Trapdoor "Trapdoor accounted for 480 million bid requests a day, with associated apps downloaded more than 24 million times."
SE008 IT Digest HUMAN and AWS Forge a New Trust Standard for AI Agents with Cryptographic Verification of Amazon Bedrock AgentCore
SE009 SoftwareOne Defense Platform by HUMAN | SoftwareOne Marketplace "Low Latency Enforcement: Decisions are enforced at the edge in under 2 milliseconds, with 95% of users validated swiftly."
SE010 TrustRadius HUMAN Bot Defender Details 2026 | TrustRadius
SE011 PeerSpot Compare Arkose vs Human Defense Platform — Bot Management Mindshare (June 2026) "The mindshare of Human Defense Platform is 8.1%, down from 11.6% compared to the previous year."
SE012 Dark Reading Human Security Tackles Malvertising With Clean.io Buy
SE013 AIThority HUMAN Acquires Anti-Malvertising Leader, clean.io, to Enhance Protection Across the Media Ecosystem
SE014 TechEdge AI HUMAN Security Enhances AI Capabilities for Advanced Cybersecurity Protection
SE015 SecuritySenses The Best Platforms for Bot Management and Account Takeover Prevention in 2026 "HUMAN is ranked #2 [in bot management] ... CHEQ leads this [ATO] category ... HUMAN Security focuses heavily on bot mitigation and fraud prevention, with strong ATO detection capabilities built into its platform."
SE016 HUMAN Security HUMAN Security Gives Marketing and Commerce Teams a Window Into the AI-Driven Internet through Expanded Capabilities and Adobe Integration
SE017 CMSWire HUMAN Security Gives Marketing and Commerce Teams a Window Into the AI-Driven Internet through Expanded Capabilities and Adobe Integration
SE018 KnowledgeNile Human Security Defends Digital Journeys With Intent-Based Trust (Sightline + AgenticTrust launch) "HUMAN Sightline, featuring AgenticTrust, secures the customer journey and unlocks safe, scalable growth with actor-level visibility and intent-based control across humans, bots and AI agents."
SE019 HUMAN Security (GitHub) HumanSecurity/human-verified-ai-agent — Open-source A2A AI agent with HTTP Message Signatures "This repository is an open-source showcase of A2A-based AI agents that implement HTTP Message Signatures for authenticating their requests ... The system is built on this RFC standard, with additional architectural considerations from the Web Bot Authentication Architecture draft."
SE020 MarTech Series HUMAN Acquires Anti-Malvertising Leader, clean.io
SE021 HUMAN Security HUMAN Security Platform — Product Overview
SE022 HUMAN Security Bot Detection and Mitigation Solutions
SE023 HUMAN Security Satori Threat Intelligence and Research Team
SE024 HUMAN Security HUMAN Sightline Cyberfraud Defense — First Adaptive Trust Layer for the Agentic AI Era
SE025 HUMAN Security 2026 State of AI Traffic & Cyberthreat Benchmark Report
SU001 PPC Land HUMAN Security's viewability measurement earns MRC accreditation "According to Jeff Meglio, Managing Director of Sovrn, the partnership with HUMAN has produced more meaningful outcomes across the market, with viewability metrics providing confidence in performance measurement through detailed reporting that supports day-to-day operational decisions."
SU002 Madhive Madhive Announces Fraud Free Guarantee to Protect Local Advertisers "This announcement underscores Madhive's unwavering commitment to transparency and quality," said Stu Solomon, CEO of HUMAN Security. "As a long-standing partner, Madhive has prioritized building a scalable, secure solution that stands out in the market."
SU003 TheDesk.net Madhive announces Fraud Free Guarantee for local ad buyers "Madhive forges 'trusted partnerships' with leading, MRC-accredited, quality supply firms, including HUMAN Security."
SU004 Security On Screen HUMAN Security launches partner-first channel program "As our customers face new and unprecedented threats on their applications and accounts, we must work with a partner who has the comprehensive coverage and unmatched human support to stop these attacks," said Nate Ungerott, CEO, Consortium Networks.
SU005 ChannelVision Magazine HUMAN Security Launches Advantage Partner-First Channel Program
SU006 GlobeNewswire (via Sina HK) HUMAN Security Launches Partner-First Channel Program To Maximize Business Growth "At HUMAN, we view our partners, like Optiv and Consortium Networks, as integral allies, giving them access to our platform and expertise to drive predictable growth."
SU007 Yahoo Finance (GlobeNewswire) G2 Honors HUMAN Security as a Best Security Software Product of the Year Amid Accelerated Product Innovation "Major AI developers, including OpenAI and AWS, recognize HUMAN as a trusted solution to verify AI agent traffic."
SU008 Consortium Networks Consortium | Your Cybersecurity Concierge
SU009 ZipDo Customer Experience In The Cyber Security Industry Statistics "42% of cybersecurity customers have switched vendors in the past two years due to poor CX. The average Net Promoter Score (NPS) for cybersecurity vendors is 21, 15 points lower than the average for all industries. 35% of cybersecurity churn is due to CX issues, not product performance."
SU010 PPC Land IVT: LinkedIn Ads integrates HUMAN "Since integrating with LinkedIn in May, over the past 30 days, HUMAN has identified less than 1% of impressions as invalid traffic for desktop ads on LinkedIn and across its network of publishers, including CTV."
SU011 Yahoo Finance (GlobeNewswire) HUMAN Security Solutions to Enhance Protections for Ad Traffic Quality on LinkedIn "Our work with HUMAN furthers our goal to continue providing advertisers with a safe and trusted ecosystem to run their campaigns." — Abhishek Shrivastava, VP of LinkedIn Marketing Solutions
SU012 Business Insider Markets (GlobeNewswire) HUMAN Ad Viewability Measurement Earns MRC Accreditation, Redefining Transparency, Explainability, and Trust in Ad Measurement "Sovrn has always focused on delivering clear, actionable insights that support performance. Our long-standing partnership with HUMAN reflects a shared commitment to transparency and precision across the media ecosystem."
SU013 Media Rating Council GI040425_HUMAN Accreditation Letter "The MRC Board of Directors has voted in favor of continuing accreditation for HUMAN's Ad Fraud Defense pre-bid platform and Ad Fraud Sensor post-serve platform for measurement and reporting of GIVT and SIVT detection across Desktop, Mobile Web, Mobile In-App and CTV."
SU014 Gartner Peer Insights (via Jina reader) HUMAN Sightline Cyberfraud Defense Reviews & Ratings 2026 "Platform Offers Valuable Support but Lacks Clarity on Detection Mechanisms" — 3/5 review from IT Security & Risk Management Associate, $500M–$1B Retail (Apr 14, 2026): "the product can feel like a 'black box' at times. While new detectors are being added, we have limited visibility into their specific functions or logic."
SU015 Harro.com (MarTech original) Invalid traffic detection gets smarter with HUMAN's Page Intelligence
SU016 Digitrendz Blog HUMAN's Page Intelligence: Smarter Invalid Traffic Detection
SU017 RivalSense HUMAN | Competitive Intelligence Profile
SU018 AGF HUMAN Security Launches New Partner Program to Boost Growth
SU019 HUMAN Security (blog via Jina cache) HUMAN recognized as a Leader in The Forrester Wave™ for Bot and Agent Trust Management Software "HUMAN's customers compliment the level of detail and attack insight that they receive from the Sightline feature."
SU020 HUMAN Security (newsroom via Jina) HUMAN Security's 2026 State of AI Traffic & Cyberthreat Benchmark Report "Automated traffic across the internet grew 23.51% year over year, while human traffic increased 3.10% over the same period. Monthly AI-driven traffic rates grew 187%."
SU021 SiliconAngle Human Security raises $50M+ to expand digital protection platform
SU022 Secure IT World HUMAN Security Tops G2's 2026 Best Security List
SU023 Markets Business Insider (Forrester via HUMAN) HUMAN Recognized as a Leader in The Forrester Wave™: Bot Management Software Q3 2024
SU024 Markets Business Insider (HUMAN ad verification launch) HUMAN launches AI-powered ad verification for advertisers
SU025 ITBusinessNet (HUMAN AI traffic benchmark) HUMAN Security's 2026 State of AI Traffic & Cyberthreat Benchmark Report signals new internet era
SR001 HUMAN Security, Inc. HUMAN Security's 2026 State of AI Traffic & Cyberthreat Benchmark Report "Automated traffic across the internet grew 23.51% year over year, while human traffic increased 3.10% over the same period. Monthly AI-driven traffic rates grew 187%."
SR002 HUMAN Security, Inc. HUMAN Ad Viewability Measurement Earns MRC Accreditation
SR003 Security Boulevard How bot detection misfires on non-mainstream browsers and privacy tools "Privacy-related traits often correlate with bots, leading systems to flag legitimate users based on flawed assumptions."
SR004 Notte.cc The Hidden Cost of Bot Detection: Bot Detection False Positives
SR005 SecureWorld Navigating the 2026 Cyber and AI Litigation Surge "By midyear, 56% report increased exposure at the federal level, and 53% report the same at the state level."
SR006 Mayer Brown LLP Cross-Border Transfers of American Personal Information Carry Heightened Regulatory, Litigation Risks "On February 9, 2026, the FTC sent formal warning letters to 13 companies identified by the Commission as 'data brokers,' emphasizing their obligation to comply with PADFAA's prohibitions on transfers of sensitive data to foreign adversaries."
SR007 Check My Ads Institute Comments on MRC Digital Advertising Auction Transparency Standards "Time and time again, we have seen that self-regulation is insufficient to resolve these challenges in the complex and concentrated digital advertising market."
SR008 StatusGator AWS outage takes down more than 150 cloud services
SR009 HUMAN Security, Inc. BADBOX 2.0: The sequel no one wanted
SR010 Google LLC We're taking legal action against the BadBox 2.0 botnet
SR011 NewChannel The State of Ad Fraud Detection in 2026
SR012 Future of Privacy Forum U.S. Privacy Enforcement in 2025 — Retrospective
SR013 Clarip 2026 Data Privacy Enforcement Trends: What Regulators Are Actually Fining Companies For
SR014 DoubleVerify Holdings, Inc. Global Study: Fueled by AI, CTV Fraud Schemes Surge 140% Globally "DV detected 140% more CTV fraud schemes and variants in Q1 2026 compared with Q1 2025, underscoring how fraudsters are using advanced tools to scale and create more complex operations."
SR015 Gartner Cloudflare vs HUMAN Security 2026 | Gartner Peer Insights
SR016 PeerSpot Compare Cloudflare One vs Human Defense Platform (2026) "Cloudflare One appears to have the upper hand due to its comprehensive features and long-term value despite the appealing pricing of Human Defense Platform."
SR017 Cloudflare, Inc. Introducing the 2026 Cloudflare Threat Report
SR018 Google Cloud Cloud Threat Horizons Report H1 2026
SR019 Premier Alts Human Security Valuation: N/A (2026)
SR020 Stinson LLP A New Era of Comprehensive Privacy Laws and the Surge in Data Privacy Litigation: Important Updates for 2026 "Nearly 4,000 cases [were] filed in 2024—up from just over 200 cases filed in 2023—alongside countless additional claims asserted through demand letters and arbitration."
SR021 AI Pedias AI Ad Fraud & Bot Detection Complete Guide 2026: HUMAN vs CHEQ vs DoubleVerify
SR022 HUMAN Security, Inc. HUMAN, FBI, and Partners Take Action Against BADBOX 2.0
SR023 The Register Google sues 25 alleged BadBox 2.0 botnet operators
SR024 Forbes FBI Warning To 10 Million Android Users — Disconnect Your Devices Now
SR025 CyberInsider Google Sues Operators of BadBox 2.0 Botnet Behind Massive Global Malware Scheme
SR026 MediaPost Going, Going, Gone: MRC Finalizes Ad Auction Standards
SR027 Yahoo Finance HUMAN Ad Viewability Measurement Earns MRC Accreditation, Redefining Transparency, Explainability, and Trust
SR028 Specificity Inc. Human Verified Traffic: Busting the Myths of Modern Ad Fraud in 2026
SR029 Cybelesoft AWS Outage March 2026: How the Global Cloud Failure Exposed VDI Vulnerabilities "AWS data center facilities in the United Arab Emirates (ME-CENTRAL-1 region) triggered structural fires and forced emergency power shutdowns across multiple Availability Zones."
SR030 Protegrity AI Fraud Detection in 2026: What Security and Risk Leaders Must Know
SR031 Cyber Defense Magazine Innovator Spotlight: HUMAN
SV001 Multiples.vc DoubleVerify — Multiples.vc — Public Comps and Valuation Multiples DoubleVerify reported last 12-month revenue of $781M and EBITDA of $261M. Current revenue multiple of DoubleVerify is 1.9x. DoubleVerify's current market cap is $2B.
SV002 Multiples.vc Public Software Valuation Multiples — June 2026 AdTech and video streaming trade at even steeper discounts. Cybersecurity listed separately under infrastructure SaaS. Data as of June 19, 2026.
SV003 Kroll Cybersecurity M&A Industry Insights — Spring 2026 AI related concerns weighed on cybersecurity equities in Q1, driving a decline in valuation multiples across Kroll's cybersecurity index. Median EV to next twelve months revenue multiples fell 26% quarter over quarter.
SV004 Finro Financial Consulting Cybersecurity Valuation Multiples Q2 2026 — 265 Companies, 9 Niches Application Security: 52 companies, avg EV/Rev 15.4x, median 13.0x. Cloud Security: 16 companies, avg 22.7x, median 18.1x. Private companies only — medians decline from Seed (15.5x) through Series C (12.7x) before a modest recovery at Series D+.
SV005 Windsor Drake Cybersecurity Valuation Report 2026 Private market transactions, particularly M&A exits, are happening at much higher multiples. Private M&A Multiples: High-growth private targets in hot sectors like Cloud Security are seeing M&A exit multiples average 16.3x, with outliers reaching as high as 22.7x. The median revenue multiple for private cybersecurity companies in 2025 stands at 15.2x.
SV006 iMerge Advisors Q1 2026 Private SaaS Valuation Report Insights Scale ($10M–$50M ARR): Median ARR Multiple 5.5–7.2x, Top Quartile 8.0x+. Q1 2026 Valuation Matrix. Executive Summary: Private SaaS valuations have stabilized at 4.0x–5.5x ARR.
SV007 Acquiry SaaS Valuation Multiples in 2026: What the Data Actually Shows AI-native SaaS (20–50% ARR growth): 7x to 12x ARR. Traditional SaaS (>30% ARR growth): 5x to 8x ARR. Net Revenue Retention is the single most important metric in SaaS valuation.
SV008 SaaS Mag Cybersecurity SaaS Premium: Highest Multiples in 2026 Public cyber companies trade at a 7.8x revenue median, private cyber startups command 15.2x, and the M&A median runs 16.3x with cloud-security transactions reaching all the way up to 35.5x. Disclosed cybersecurity M&A hit $96 billion across 400 transactions in 2025. 2026 has already crossed $65 billion in disclosed deal value before the halfway mark.
SV009 CloudStack Networks Cybersecurity M&A Hits $47 Billion in Q1 2026 as Palo Alto, CrowdStrike Drive Platform Consolidation The cybersecurity industry recorded $47 billion in M&A activity in Q1 2026 alone, following a record $96 billion in 2025.
SV010 Premier Alternatives Human Security Valuation: N/A (2026) Current Valuation: N/A. Last Round: PE Growth/Expansion. Amount undisclosed. No funding history available. Funding data has not been imported for this company yet.
SV011 Value Add VC SaaS Valuation Multiples 2026: Median EV/Revenue 8.5x, Up 90% From the Trough The median public SaaS multiple sits at ~8.5x NTM revenue in mid-2026 — up ~90% from the ~4.5x Q1 2023 trough. >50% YoY growth: Median EV/Revenue 12–18x.
SV012 ipos.fyi Cybersecurity IPOs — Companies Going Public (2026)
SV013 SEC EDGAR — DoubleVerify Holdings Inc. DoubleVerify Holdings, Inc. Annual Report on Form 10-K for Fiscal Year Ended December 31, 2025
SV014 Business Wire HUMAN Raises $100 Million In Growth Funding Round Led By WestCap and NightDragon
SV015 Business Wire HUMAN and PerimeterX Unite in Market-Changing Merger to Safeguard Customers From Sophisticated Bot Attacks, Fraud and Account Abuse
SV016 SiliconAngle Human Security raises $50M+ to expand digital protection platform
SV017 Yahoo Finance / Globe Newswire HUMAN Raises $50+ Million in Growth Funding to Protect the Digital Customer Journey
SV018 PR Newswire HUMAN Security Announces Strategic Leadership Transition: Tamer Hassan to Become Executive Chairman, Stu Solomon Appointed to CEO
SV019 GetLatka HUMAN Security Revenue 2023 GetLatka reported HUMAN Security ARR at $15 million as of December 2023, directly conflicting with the company's stated $100M-plus ARR.
SV020 SEC EDGAR — White Ops Inc. White Ops Inc. Form D — Series A Exempt Offering, June 2014 (CIK 0001611028)
SV021 Momentum Cyber Cybersecurity Market Review May 2026 May 2026: 31 M&A transactions and 46 financing transactions. $823M in disclosed M&A value. AI Security M&A is on pace to increase 400%+ in 2026.
SV022 Tracxn HUMAN Security — Company Profile and Funding History
SV023 HUMAN Security HUMAN Security — AgenticTrust and Sightline Platform
SV024 Benchmarkit 2024/2025 SaaS Gross Margin Benchmarks
SV025 GrowJo HUMAN Security Revenue Estimate
SV026 Kasada Kasada Secures $20 Million Round to Accelerate Global Expansion
SV027 GetLatka Arkose Labs Revenue 2024: $46.9M ARR, $140.7M Valuation
SV028 DataDome DataDome Closes $42 Million Series C Funding
SV029 Manila Times / GlobeNewswire HUMAN Recognized as a Leader by a Top Research Firm in the Forrester Wave: Bot and Agent Trust Management, Q2 2026
SV030 SiliconAngle (October 2024 funding coverage) Human Security raises $50M+ — investor and allocation details