Kratikal Tech Limited
1. Overview
Kratikal Tech Limited is an India-based AI-driven, Software-as-a-Service (SaaS) cybersecurity company providing proprietary security software platforms supported by cybersecurity and regulatory compliance services. Incorporated in November 2013 and headquartered in Noida, Uttar Pradesh, the Company has built a vertically integrated cybersecurity practice spanning the People–Process–Technology stack, enabling enterprises to achieve measurable cyber risk reduction.
The Company operates through 2 integrated business lines — (i) AI-Driven People Security Management (PSM) offered through its proprietary Threatcop product suite, and (ii) Technology & Process Security Services offered under the Kratikal brand, encompassing Vulnerability Assessment & Penetration Testing (VAPT), application & infrastructure security, red-team exercises, and Governance, Risk & Compliance (GRC) services — all delivered on its in-house AI-driven AutoSecT VMDR (Vulnerability Management, Detection & Response) platform.
As of FY2026, Kratikal serves 677 clients across sectors including BFSI, fintech, telecom, IT/ITES, healthcare, pharmaceuticals, e-commerce and manufacturing — both in India and internationally. The Company is a CERT-In Empanelled Security Auditor and is empanelled by NSE to perform system audits for trading members. Its workforce stood at 200 employees as of March 31, 2026.
Kratikal is led by Promoters and founder-Directors Mr. Pavan Kumar (Chairman, MD & CEO) and Mr. Paratosh Kumar (Whole-Time Director), both with 11 years of industry experience each.
2. Business Model and Revenue Streams
The Company operates two distinct but complementary monetization models corresponding to its two business lines:
A. People Security Management (Threatcop Product Suite) — Subscription SaaS
- Per-User, Per-Year Subscription: Customers are charged based on the number of end users onboarded; licences are typically contracted annually and billed in advance. User counts may be increased mid-term on a pro-rata basis; reductions take effect at renewal.
- Tiered Licensing: Multiple licence tiers vary by module coverage, analytics depth, integrations and support. Advanced features may be bundled in higher tiers or offered as paid add-ons.
- Channel + Direct Distribution: Contracted directly with customers or through channel partners and distributors. Invoiced annually in advance.
B. Technology & Process Security Services (Cybersecurity Services + AutoSecT Platform)
- Asset-Based Annual Pricing: Charged based on the number and type of assets covered — IP addresses, applications, servers, infrastructure components — on a per-asset, per-year basis.
- Managed Services Model: Continuous monitoring and recurring assessments under fixed/semi-variable recurring fees, invoiced periodically and governed by SLAs. Generally annual or multi-year.
- Project-Based & Hybrid Engagements: One-time VAPT, audits or gap assessments priced on deliverables; some customers opt for hybrid (assessment + recurring monitoring).
- AutoSecT (SaaS): Subscription-based, asset-linked and usage-based pricing, with editions ranging from Standard to Managed VMDR; additional revenue from incremental scans, expanded asset coverage and modular add-ons.
Revenue by Geography (Domestic vs Export — ₹ in Crore)
| Particulars | FY2026 | FY2025 | FY2024 |
|---|---|---|---|
| Domestic Revenue | 25.72 | 18.10 | 11.32 |
| Export Revenue | 10.99 | 2.75 | 1.70 |
| Domestic % of Revenue | 70.06% | 86.81% | 86.95% |
| Export % of Revenue | 29.94% | 13.19% | 13.05% |
A clear strategic pivot toward exports is visible — export share more than doubled from ~13% in FY24/FY25 to ~30% in FY26, anchored by growth in UAE (₹3.55 Cr; 9.67%), USA (₹3.00 Cr; 8.17%) and Saudi Arabia (₹2.05 Cr; 5.58%).
Geographic Concentration (Domestic — Top 6 States, FY2026)
| State | Amount (₹ Cr) | % of Total Revenue |
|---|---|---|
| Maharashtra | 6.42 | 17.49% |
| Karnataka | 5.81 | 15.82% |
| Haryana | 3.39 | 9.23% |
| Delhi | 3.04 | 8.29% |
| Uttar Pradesh | 2.91 | 7.93% |
| Tamil Nadu | 1.58 | 4.31% |
| Top 6 Total | 23.16 | 63.07% |
Client Concentration (Customer-Level Operating Metrics)
| Metric | FY2026 | FY2025 | FY2024 |
|---|---|---|---|
| Clients Served | 677 | 638 | 424 |
| Workforce Strength | 200 | 165 | 124 |
| Top 1 Customer (% of Revenue) | 8.93% | 5.11% | 3.80% |
| Top 3 Customers (% of Revenue) | 16.18% | 11.62% | 10.55% |
| Top 5 Customers (% of Revenue) | 21.22% | 15.90% | 15.72% |
| Top 10 Customers (% of Revenue) | 31.60% | 21.89% | 25.11% |
Customer concentration remains moderate — no single customer accounts for more than ~9% of revenue, while the top 10 collectively contribute ~31.6% — reflecting a broad and diversified customer base characteristic of a maturing SaaS-and-services hybrid.
3. Products and Service Portfolio
The Company's portfolio is structured into two clearly demarcated product/service families:
A. Threatcop — People Security Management Product Suite
A subscription SaaS platform built on the proprietary AAPE framework (Assess, Aware, Protect, Empower), addressing human-layer risks:
- TSAT (Threatcop Security Awareness Training): Simulation-led platform for phishing and social engineering exercises with targeted awareness content.
- TLMS (Threatcop Learning Management System): Centralized cybersecurity awareness and behavior-improvement platform with role-based learning journeys.
- TDMARC: Real-time DMARC enforcement with continuous SPF/DKIM monitoring and Sender ID visibility — a key differentiator highlighting actual sending identity behind each message to detect look-alike senders and unauthorized third-party senders.
- TPIR (Threatcop Phishing Incident Response): Standardized employee phishing-reporting workflow with rapid escalation to security teams.
B. Kratikal Brand — Cybersecurity Services
- VAPT (Vulnerability Assessment & Penetration Testing): Across networks, cloud, web/mobile applications and APIs; based on OWASP, SANS Top 25, NIST and CIS Benchmarks.
- Compliance & Audit Services: SOC 2 Type I & II, NIST CSF 2.0, RBI Compliance Audits, IRDAI Compliance Audits, SEBI CSCRF Audits, CERT-In Security Audits, SAR Compliance Audits, DPDP Act 2023 readiness, IT General Controls (ITGC/GCC), and DLA (Digital Lending Application) Audits.
- Virtual CISO (vCISO) and Cyber Governance Advisory: Outsourced, on-demand security leadership including multi-year security strategy formulation, incident response readiness and continuous governance.
- Red-Team Exercises and Application/Infrastructure Security.
C. AutoSecT — AI-Driven VMDR & Pentest Platform
The Company's flagship in-house technology platform delivering:
- Automated, continuous and scalable security assessments across networks, cloud, web, mobile, APIs and externally exposed digital assets;
- Integrated asset discovery, vulnerability scanning, AI-based risk prioritisation, exploit validation and remediation guidance;
- Centralized CISO dashboard and analytics dashboards;
- AI-led capabilities: AI Vishing Simulations, AI Awareness Manager, AI Studio (video localization), AI Templates (phishing template generation).
4. Key Business Strengths
- Integrated People + Tech Security Platform: The Company is among the few players offering a unified People–Process–Technology cybersecurity stack through proprietary Threatcop + AutoSecT platforms — enabling cross-sell, deeper account penetration and competitive differentiation versus single-service vendors.
- Real-Time DMARC with Sender ID Visibility: TDMARC's Sender ID visibility — surfacing actual sending identities behind email messages — is a distinctive technical differentiator in the BEC/email-spoofing protection segment, helping enterprises triage incidents faster and detect unauthorized third-party senders.
- AI-Driven Technology Foundation (AutoSecT): In-house AI-led VMDR + pentest platform delivers automated, continuous, scalable assessments — reducing manual effort, minimizing false positives via intelligent validation, and enabling repeatable, high-quality service delivery at scale with strong intellectual property embedded in service execution.
- CERT-In Empanelment and Regulatory Authority: Empanelment with CERT-In and NSE provides regulatory credibility, particularly valuable for engagements with government bodies, PSUs, BFSI, NBFCs and large enterprises in compliance-driven assessments — a high-barrier qualification criterion that smaller competitors typically lack.
- Broad Multi-Sector Diversified Client Base: 677 clients across BFSI, fintech, telecom, IT/ITES, healthcare, pharmaceuticals, e-commerce and manufacturing — no single client contributing more than 9% of revenue — providing revenue resilience and limited concentration risk.
- Experienced Founder-Led Management: Founder-Promoters Mr. Pavan Kumar and Mr. Paratosh Kumar bring 11 years of focused cybersecurity industry experience, providing continuity, technical depth and strategic clarity — both have led the Company since incorporation in 2013.
- Debt-Free Balance Sheet with Strong Profitability: Zero debt with RoE of ~35% in FY26 and debt-free funding of growth via internal accruals — reflecting healthy capital efficiency and providing significant flexibility for inorganic or organic expansion.
5. Future Growth Strategy
- International Expansion (Threatcop FZ LLC, UAE and Threatcop AI Inc, USA): The Company is deploying ₹23.08 Cr (largest object of the issue) in its UAE and USA subsidiaries for sales, marketing and workforce development — directly supporting the export thesis (export share up from 13% to ~30% in FY26).
- Product Development & Platform Deepening: ₹9.23 Cr allocated to product development — funding AI capability expansion across the AutoSecT VMDR roadmap (AI Vishing Simulations, AI Awareness Manager, AI Studio, AI Templates) and Threatcop product enhancements.
- Cross-Sell and Upsell Across the Integrated Stack: Leveraging the People + Tech integrated portfolio to deepen existing customer relationships — bundling Threatcop subscriptions with AutoSecT-led services and vCISO engagements to drive higher account-level revenue and retention.
- Channel-Led GTM via MSPs/MSSPs and Cybersecurity Integrators: Expansion through Managed Security Service Providers and integrator partnerships for AutoSecT — enabling capital-light reach into mid-market and regulated customer segments globally.
- Regulatory & Compliance Tailwind: Positioning to capture demand from DPDP Act 2023, SEBI CSCRF, RBI ITGC and CERT-In mandates — regulatory requirements that systematically expand the addressable market for cybersecurity audit and advisory services in India.
- Brand Building and Demand Generation: Sustained investment in PR, thought-leadership content, cybersecurity events, account-based marketing and the annual "People Security Review" publication — strengthening top-of-funnel demand generation across direct and channel motions.
Delete Comment?
Are you sure you want to delete this comment? This action cannot be undone.
Discussion
Join the discussion!
Log In to CommentNo comments yet. Be the first to share your thoughts!