What the business is
DeepSurface built software that assesses potential risk and lays out a 'hacker roadmap' to help prioritize the most dangerous vulnerabilities.
Starting capital
$1M seed (September 2020) led by Cascade Seed Fund
How it started
Founded in 2017 by CEO James Dirksen, who had previously sold RuleSpace to Symantec and was an executive at Formaltech, and CTO Tim Morgan, a longtime security consultant.
What happened
The mission held from day one: 'empower security teams with smarter, more contextualized risk analysis — helping organizations focus on what truly matters' (Morgan).
How it ended up
Acquired by AttackIQ of Santa Clara in February 2025, terms undisclosed; the product is being embedded into AttackIQ's security control validation and breach-and-attack simulation business.
What has to be true
The pairing is technically coherent: attack simulation tells you what an attacker could do; DeepSurface's roadmap tells you what they would do first — exposure validation needs both.
For a seed-stage company of its vintage, an exit to a category leader is a respectable outcome for a crowded vulnerability-management market.
The founders' exits were soft landings into the acquirer's product story rather than acqui-hires, with the product explicitly being embedded.
Dirksen's second successful security-company sale (after RuleSpace to Symantec) shows repeat-founder pattern-matching on what platform buyers need.
What can be applied
A point product finds its exit when a platform buyer needs exactly your context to complete its own story.
Aftermath
As of the February 2025 announcement, DeepSurface's product was being folded into AttackIQ's AEV suite; terms were not disclosed.
FOLLOW THE EVIDENCE