EN
返回档案库

档案库 · 开发与企业工具 · 战略决策 · 2014–2025

这条还没译成中文,下面是英文原文。

Thinkst Canary bootstrapped a breach-detection honeypot to $20M ARR with no VC

A Cape Town cybersecurity shop bet a simple, deployable honeypot could outgrow funded rivals — no investors, no outbound sales, profitable since year one.

Thinkst

它在赌什么That a honeypot so easy to deploy it catches attackers by default would win on word of mouth — growth without venture capital, outbound sales, or press.在扩

做的是什么生意

Canary is a plug-in hardware honeypot (plus free Canarytokens) that alerts a company the moment an attacker touches it, cutting breach-detection time.

启动资金None raised; profitable since year one

起因

Haroon Meer's Cape Town-based Thinkst built Canary privately for about a year and launched it in mid-2015. The thesis: internally deployed honeypots would let customers discover breaches themselves instead of being told by third parties some 300 days later.

经过

By March 2021 Canary crossed $11M ARR with a 22-person team, profitable since year one, no capital raised, no price increases — with year-one customers still spending more. By 2023 it crossed $19M ARR; the company still had no outbound sales team and watched marketing spend carefully.

结果

In May 2025, on Canary's 10th anniversary, Thinkst was on track to make a healthy profit on $20M ARR — almost double 2021 — with ~40 employees, no outside funding, and 60% of first-year customers still customers. It remains independent and growing.

背景

Thinkst launched Canary in mid-2015 on a contrarian read of the security market: companies were spending millions on defense yet taking months or longer to realize they had been breached. The bet was a cheap, physical honeypot that would alert the moment an attacker touched it, so simple to deploy that it couldn't be set up wrong.

Canary started at $7,500 per appliance and grew without the usual startup machinery. There was no outbound sales team, no venture capital, and almost no launch press — one Ars Technica article was the extent of it. Instead, customers who caught attackers or pen-testers recommended the product, and year-one customers kept expanding their spend.

The numbers validate the model: profitable since year one, $11M ARR by 2021, $19M by 2023, and $20M ARR on track in 2025 with about 40 employees. Thinkst stayed in Cape Town, remote-first, and never raised prices.

The company still exists, still takes no outside money, and in 2025 acquired UK red-team firm DeceptIQ while continuing to add free detection tools like Canarytokens and OpenCanary.

这件事要成立,得有什么

  • Deployment simplicity was the wedge: honeypots had a decades-long history but were painful to install, and removing that pain became the product's North Star.
  • Funding wasn't needed because the go-to-market was organic — low-touch sales, conference booths staffed by engineers, and customers who doubled as the sales force.
  • Deliberate restraint (no outbound sales, no analyst-firm spending, no price hikes) kept the burn near zero, so the business was profitable from year one.
  • The product's promise — catch attackers early, don't drown users in alerts — was kept consistently, and customer retention and expansion did the marketing.

可借鉴之处

A product that keeps its promises becomes the sales motion: word of mouth compounds, and money isn't the gate to building a business.

后续进展

As of the TechCrunch anniversary report (May 2025), Thinkst was profitable on ~$20M ARR with roughly 40 employees, no outside funding, and no outbound sales team, with 60% of first-year customers still customers. Through late 2025 and 2026 it kept shipping: an MCP-server canary token, a package-proxy tool, Google SecOps SOAR integration, and the acquisition of UK-based DeceptIQ. Founders said $20M was not the ceiling, and the company remains independent and scaling on its own cash.

资料来源

发现哪里写错了?告诉我们。

轮到你了

你刚读完一家。说说你在做什么,看看谁在赌同一件事。

免费账号 · 3 次免费提问 · 不用绑卡