Fundraising Fox

Synack

Techstars '13

Redwood City, US · Founded 2013 · Delaware corporation · 24 known investors

synack.com

Synack provides penetration testing and security assessments for enterprise security teams, combining AI agents with human testers to evaluate complex attack surfaces and protect critical infrastructure.

AI & Machine LearningCybersecurityEnterprise Software

Founders & leadership

Synack was founded in 2013 by Mark Kuhr and Jay Kaplan.

MKMark Kuhr
Mark KuhrCTO and Co-Founder
JKJay Kaplan
Jay KaplanCEO and Co-Founder30 Under 30 2015
AH
Angela Heindl-SchoberChief Marketing Officer
SS
Steve SoperVice President of Legal
RC
Rob CrossVice President, East

Board

TS
Ted SchleinDirector (Kleiner Perkins Caufield & Byers, later Ballistic Ventures)
GSGlenn Solomon
Glenn Solomonin𝕏Board MemberInvestor at GGV Capital
DW
Derek W. SmithDirector; also individual seed investor and CEO of Shape Security
TM
Tom MawhinneyBoard directorGeneral Partner at Icon Ventures
T(
Thomas (Tom) MawhinneyBoard director
GS
Gary SteeleDirector (added by 2017 Series C filing)
RG
Rashmi GopinathDirector (added by 2017 Series C filing)

Investors · 24

Also in the syndicate · 7

Derek SmithDerek Smith (individual)Derek Smith / Shape SecurityGoogle Ventures (GV)Microsoft Ventures (M12)Singtel Innov8Wing Venture Partners

Reported raises · per SEC filings

Form D private placements

$105.2M disclosed across 4 of 7 rounds · 2013–2020

$51.6MraisedMay 2020 · 15 investors · Other
Rule 506(b)
Officers, directors & promoters on the filing
  • William KilmerDirector
  • Ted SchleinDirector
  • Tom MawhinneyDirector
  • Rashmi GopinathDirector
  • Glenn SolomonDirector
  • Derek SmithDirector
  • Mark KuhrDirector, Executive Officer
  • Tamara SteffensDirector
  • Gary SteeleDirector
  • Jay KaplanExecutive Officer, Director
Offering amount
$51.6M
Amount sold
$51.6M
First sale
Mar 2020
Incorporated
Corporation, Delaware
Federal exemptions
06b
Full filing on SEC EDGAR ↗
$21.2MraisedApr 2017 · 10 investors · Other
Rule 506(b)
Officers, directors & promoters on the filing
  • Glenn SolomonDirector
  • Ted SchleinDirector
  • Mark KuhrDirector, Executive Officer
  • Rashmi GopinathDirector
  • Derek SmithDirector
  • Gary SteeleDirector
  • Jay KaplanExecutive Officer, Director
  • Tom MawhinneyDirector
Offering amount
$21.2M
Amount sold
$21.2M
First sale
Mar 2017
Incorporated
Corporation, Delaware, 2013
Federal exemptions
06b
Full filing on SEC EDGAR ↗
$25MraisedFeb 2015 · 10 investors · Other
Rule 506(b)
Officers, directors & promoters on the filing
  • Ted SchleinDirector
  • Glenn SolomonDirector
  • Derek W. SmithDirector
  • Mark KuhrDirector
  • Jay KaplanExecutive Officer, Director
  • Tom MawhinneyDirector
Offering amount
$25M
Amount sold
$25M
First sale
Dec 2014
Incorporated
Corporation, Delaware, 2013
Federal exemptions
06b
Full filing on SEC EDGAR ↗
$7.3MraisedApr 2014 · 5 investors · Other
Rule 506(b)
Officers, directors & promoters on the filing
  • Derek W. SmithDirector
  • Jay KaplanExecutive Officer, Director
  • Mark KuhrExecutive Officer, Director
  • Ted SchleinDirector
Offering amount
$7.5M
Amount sold
$7.3M
First sale
Apr 2014
Incorporated
Corporation, Delaware, 2013
Federal exemptions
06b
Full filing on SEC EDGAR ↗

Source: SEC EDGAR Form D. Amounts as filed; amended filings shown once at their latest values.

Valuation · disclosed

Disclosed events
$500Mvaluation at Series DMay 2020
filing ↗

Source: SEC prospectus filings, and round valuations the company or its investors disclosed — follow each entry's link for the claim.

Company profile

researched Aug 2026

Synack was founded in January 2013 by Jay Kaplan and Mark Kuhr, two cybersecurity specialists who met while working at the U.S. National Security Agency (NSA), where Kaplan served as a Senior Cyber Analyst (2009–2013) supporting counterterrorism-related intelligence operations and Kuhr spent over nine years across the NSA and the Defense Information Systems Agency (DISA). Both had NSA/DoD-funded academic fellowships (Kaplan at George Washington University; Kuhr earned a Ph.D. at Auburn University under a DoD/NSA-sponsored fellowship, after starting at West Point). Drawing on their government offensive-security backgrounds, they set out to build a 'controlled crowdsourced' penetration-testing model — vetting a global community of independent security researchers and pairing them with proprietary scanning and orchestration technology — as an alternative to traditional, episodic consulting-firm pentests. The company announced $1.5M+ in seed funding on August 1, 2013 from Greylock Partners and Kleiner Perkins Caufield & Byers (partner Ted Schlein), along with Wing Venture Partners, Allegis Capital, and Shape Security CEO Derek Smith as an individual investor; Synack's own SEC Form D shows $1.71M sold in that initial offering.

Synack raised a $7.3M Series A in April 2014, a $25M Series B in December 2014/February 2015 (with GGV Capital's Glenn Solomon joining the board around that time), a $21.25M Series C in April 2017 led by Microsoft Ventures with Hewlett Packard Enterprise and Singtel Innov8 (alongside prior investors GV/Google Ventures, GGV Capital and Kleiner Perkins), and a $51.6M (~$52M) Series D in May 2020 led by C5 Capital and B Capital Group. Across SEC filings, the five primary rounds total roughly $106.9M raised. Since 2020 there have been no further SEC Form D primary-round filings; Crunchbase records subsequent 'Secondary Market' transactions involving G Squared and LAPA Capital, indicating investor liquidity events rather than new primary capital.

Product-wise, Synack evolved from a pure crowdsourced bug-bounty/pentest marketplace into a broader 'Penetration Testing as a Service' (PTaaS) platform, adding attack surface management, vulnerability disclosure program management, and compliance-oriented continuous testing. The company built a public-sector practice early, offering free election-security testing to U.S. state election systems starting in 2018 (continuing through 2020 and 2024 election cycles) and working with agencies including the U.S. Department of Defense and Department of Health and Human Services. By 2025–2026, amid the AI boom, Synack pivoted its positioning toward 'Human + AI' continuous security validation: it launched an agentic AI pentesting capability in November 2025, published Synack/Omdia research in March 2026 finding that although 95% of enterprises prioritize pentesting, only 32% of attack surfaces are actually tested, launched a 'Glasswing' AI-readiness assessment in April 2026 to address AI/LLM security coverage gaps, and brought its AI agent 'Sara' (Synack Autonomous Red Agent) to general availability in May 2026 — claiming Sara can autonomously chain multiple vulnerabilities and, in early access, produced findings rated high/critical severity 70% of the time. The company reports its researcher network (the Synack Red Team) now spans 1,500+ vetted researchers across 80+ countries and has cumulatively delivered close to 10 million hours of expert security testing, and it was named a Leader and Fast Mover in GigaOm's 2025 PTaaS Radar.

Business model

B2B SaaS / managed security services; subscription and project-based Penetration-Testing-as-a-Service (PTaaS) sold to enterprises and government agencies, delivered via a marketplace of vetted freelance security researchers (the Synack Red Team) plus proprietary AI-assisted testing technology.

Subscription/flat-fee and engagement-based contracts for continuous penetration testing, attack surface management, vulnerability disclosure programs, and (from 2025/2026) AI-agent-assisted pentesting (Sara), also sold via AWS, Microsoft Azure and Google Cloud marketplaces.

Full profile — profile (continued), go-to-market, ownership

Profile (continued)

Jay Kaplan continues to serve as CEO and Mark Kuhr as CTO as of mid-2026, both also sitting on the board. Synack remains privately held, headquartered in Redwood City, California, with roughly 100–250 employees, competing chiefly against HackerOne and Bugcrowd (crowdsourced bug bounty/PTaaS), as well as Cobalt.io, NetSPI, Pentera, and various traditional pentest consultancies, in the broader offensive-security/attack-surface-validation market.

Go-to-market

Large enterprises and government agencies in financial services, public sector/federal government (incl. U.S. Department of Defense and civilian agencies), retail/e-commerce, healthcare, manufacturing, and technology; also state election administrators.

Ownership

private

Compiled by commissioned research from 22 cited public sources — announcements, filings, and press listed under research sources below.

Key figures

latest reported
Attack surface tested by enterprisesMar 202632%
Cumulative hours of expert security testing enabledMay 202610,000,000 hours
Employee countAug 2026175 employees
Researcher countriesJan 202580
Synack Red Team researchersMay 20261,500 researchers
Total primary funding raised (SEC Form D)May 2020$106.9M

Company-reported or press-reported figures, each dated to when it was claimed — not independently audited.

Competitors · 10

by search overlap
Crowdstrike244 shared keywordsCrowdStrike provides an AI-native cybersecurity platform that unifies endpoint, identity, cloud, SaaS, and AI protection to detect and stop breaches for enterprise organizations. It combines automated response with human-led security operations including managed detection and response, threat hunting, and security services.
Cobalt213 shared keywordsCobalt provides penetration testing as a service (PTaaS) and offensive security testing for enterprises, offering both on-demand pentests and continuous testing programs enhanced with AI-powered vulnerability detection.
Hackerone212 shared keywordsHackerOne operates a platform for coordinating cybersecurity vulnerability disclosures and bug bounty programs. The company connects security researchers with organizations to identify and remediate security vulnerabilities.
Netezza207 shared keywordsIBM is a global technology company whose business spans enterprise software (including Red Hat, HashiCorp, and Confluent), IT infrastructure such as mainframes, servers, and storage, and IT consulting services. The company is also investing heavily in quantum computing and AI-based enterprise offerings, including its Lightwell open-source software security clearinghouse and the Anderon quantum wafer foundry.
ASTRA by Czar Securities206 shared keywordsAstra builds a continuous offensive pentest platform that helps businesses identify and remediate security vulnerabilities. The platform serves thousands of businesses seeking to improve their security posture.
Sentinel One197 shared keywordsSentinelOne provides an AI-powered cybersecurity platform for enterprises that integrates endpoint protection, threat detection, and incident response capabilities. The company serves large enterprises, including many Fortune 500 organizations, to protect against cyber threats at scale.
Check Point Software187 shared keywordsCheck Point Software Technologies is a cybersecurity company providing security products and solutions. This page is its investor relations section, containing annual reports, SEC filings, financial results, and corporate governance information.
Bugcrowd174 shared keywordsBugcrowd operates a platform that connects security researchers and hackers with organizations to identify and report vulnerabilities in their attack surface. The platform enables companies to proactively discover security weaknesses through crowdsourced penetration testing and bug bounty programs.
Splunk174 shared keywordsSplunk offers a unified platform for security and observability that ingests and analyzes large-scale data across hybrid cloud environments. Its tools support security operations centers with analytics and automated response, and help teams monitor application and infrastructure performance.
CyCognito173 shared keywordsCyCognito provides an external attack surface management (ASM) platform that continuously discovers, tests, and prioritizes exposures across an organization's internet-facing assets, subsidiaries, and third-party connections. It serves enterprise security teams with automated asset discovery, autonomous security testing (including DAST and vulnerability scanning), risk prioritization, and remediation workflows.

Companies competing with Synack for the same Google search keywords, organic and paid, via search-intersection analysis.

Customers & partners

Named customers · 3

U.S. Department of DefenseU.S. Department of Health and Human ServicesU.S. state election systems / election administrators

Relationships the company or its partners disclosed publicly — case studies, joint announcements, press.

Timeline · 9

launches, deals, and filings
May 2026
Sara AI Pentesting reaches general availability

Synack announces general availability of Sara (Synack Autonomous Red Agent), an AI pentesting agent for continuous security validation, available via the Synack platform and AWS/Microsoft/Google Cloud marketplaces.

source ↗

Apr 2026
Glasswing AI-Readiness Assessment launched

Synack launches the 'Glasswing' AI-Readiness Assessment to help close the security coverage gap for enterprise AI/LLM deployments.

source ↗

Mar 2026
Synack/Omdia research on attack surface testing gaps

Synack and Omdia publish joint research finding 95% of enterprises prioritize pentesting, yet only 32% of attack surfaces are actually tested.

source ↗

Nov 2025
Agentic AI pentesting solution introduced

Synack introduces a new agentic AI pentesting capability, an early step toward its later 'Sara' AI Pentesting product.

source ↗

May 2020
Series D funding ($51.6M) at ~$500M valuation

Synack raises a $51.6M Series D co-led by C5 Capital and B Capital Group, reportedly valuing the company at approximately $500M.

source ↗

Jun 2018
Free election security testing for states

Synack becomes one of the first cybersecurity companies to offer free crowdsourced security testing services to U.S. state election systems ahead of the midterms.

source ↗

Apr 2017
Series C funding ($21.25M)

Synack raises $21.25M led by Microsoft Ventures with Hewlett Packard Enterprise and Singtel Innov8, bringing total funding to date to roughly $55M; reports ~100 enterprise customers and revenue doubling annually.

source ↗

Aug 2013
Seed funding announced

Synack announces ~$1.5M seed funding from Greylock Partners and Kleiner Perkins Caufield & Byers, with Wing Venture Partners, Allegis Capital, and Shape Security CEO Derek Smith also participating.

source ↗

Jan 2013
Company founded

Jay Kaplan and Mark Kuhr, former NSA cybersecurity specialists, found Synack to build a crowdsourced, 'controlled' penetration testing platform.

source ↗

Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.

Legal entities · 1

corporate structure
SynackDelaware

In the news

Research sources · 22

primary sources listed

22 public sources were cited for this profile; the first-party ones are listed here.

Frequently asked questions

What does Synack do?
AI Finds More. Humans Prove What Matters.
Who founded Synack?
Synack was founded by Mark Kuhr, Jay Kaplan in 2013.
Who are Synack's investors?
Synack's investors include ALLEGIS CAPITAL, AllegisCyber Capital, B Capital Group, B4 Capital, C5 Capital, G Squared, GV (Google Ventures), Icon Ventures and 9 more.
How much funding has Synack raised?
Synack has disclosed $105.2M raised across 4 of its 7 known rounds.
Where is Synack headquartered?
Synack is headquartered in Redwood City, US.