Skip to content

Product1 publisher3 min readPublished

Brinqa buys PlexTrac because a ranked exposure list never proved anything got fixed

The deal folds penetration test validation into an exposure management platform, and it puts standalone offensive-security reporting vendors in an awkward spot.

The Product Desk · Product desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • Brinqa Inc. announced on Aug. 19, 2026 that it had acquired offensive security validation and reporting platform company PlexTrac Inc. for an undisclosed sum.
  • Brinqa collects findings from scanners, cloud accounts and application security tools, then ranks the exposures an organization should deal with first.
  • Verifying that a remediation worked has been someone else's job for Brinqa; PlexTrac sells the software penetration testers use to run that check and write it up.
  • Brinqa said it can now cover continuous threat exposure management from discovery through confirmed remediation.
  • Validation now sits at both ends of the remediation cycle: testers can establish that an exposure is genuinely exploitable before an engineer is assigned to it, and a retest afterward shows whether the problem is actually gone.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

Brinqa said on Aug. 19, 2026 that it had acquired PlexTrac, the offensive security validation and reporting platform, for an undisclosed sum [1]. The reason to care is structural rather than financial: Brinqa's product collected findings from scanners, cloud accounts and application security tools and ranked which exposures to fix first, while confirming that a fix actually worked was someone else's job [2][3].

PlexTrac sells the software penetration testers use to run that check and write it up, and Brinqa now says it can cover continuous threat exposure management from discovery through confirmed remediation [3][4]. The company's framing is that validation sits at both ends of the cycle: a tester can establish that an exposure is genuinely exploitable before an engineer is assigned to it, and a retest afterward shows whether the problem is gone [5]. Every confirmed exploit and remediation feeds Brinqa's Cyber Risk Graph, the data layer its AI agents draw on [6]. Chief Executive Dan Pagel said PlexTrac "brings real offensive security depth, from practitioners who have spent years proving exactly how attackers get in," and that pairing it with the assessment platform gives customers evidence they can put in front of a board, an auditor or an AI system acting on the data [7].

Strip the language back and the acquisition is an admission about what prioritisation alone is worth. A list of ranked exposures is a claim; a retest is a receipt. That distinction matters more once agents are the things reading the data, and Brinqa has spent the period shipping Model Context Protocol interfaces and agents that handle attribution and deduplication of findings [8]. Feeding those agents unverified scanner output produces confident output about work nobody confirmed.

The competitive squeeze is the other half of it. Gartner named both companies in its inaugural Magic Quadrant for Exposure Assessment Platforms last year, so the two were already being measured on the same page before one bought the other [9]. Brinqa says the combined companies serve more than 3,000 customers in 57 countries, including more than 25% of the Fortune 500, which it claims makes it the largest standalone vendor in unified exposure management [10][11]. Brinqa reported 164% year-over-year growth in new bookings for 2025 and said new logo bookings have more than doubled year-over-year in 2026 [12]. Anyone else selling pentest reporting as a product now has to explain why validation should be bought separately from the system that decides what gets validated.

There was no arm's length here. Insight Partners led Brinqa's $110 million growth round in June 2021 and also did PlexTrac's $70 million Series B announced in February 2022, roughly $180 million of shared backing across the two [13][14][1]. Founder Dan DeCloss, who started PlexTrac in Boise in 2018, joins Brinqa's executive leadership team and board and will run the combined offensive security practice, about eight years after founding the company [15][16][2].

Two things to watch. PlexTrac's products will keep selling standalone, with the option to extend into Brinqa's platform later [17]; the test is whether consultancies that use PlexTrac, including customers such as Deloitte and Expedia, stay comfortable buying tooling from a vendor that now runs its own offensive security practice [17][18]. The second is pricing: if retest evidence becomes a bundled feature rather than a line item, standalone reporting vendors lose the argument that they are a separate purchase.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories