118 staff across Boston and Cambridge, application security posture management sold to enterprise AppSec teams
Company site + Massachusetts corporations registry
They are already in the databases. What is not in any database is whether their FedRAMP authorisation is live and at which impact level, which of their products carry a Common Criteria or FIPS 140-3 certificate, whether they assign their own CVEs, and when any of that last changed. Search on those, and Causo reads the FedRAMP Marketplace, the CVE Program list of Numbering Authorities, the Common Criteria certified products list and the IASME Cyber Essentials certificate search vendor by vendor, then shows you the evidence behind every match.
Run your first search$240B forecast worldwide end-user spending on information security in 2026

3 results for this search. Pick another above to see what it returns.
118 staff across Boston and Cambridge, application security posture management sold to enterprise AppSec teams
Company site + Massachusetts corporations registry
Cambridge developer tooling vendor, 74 staff, container build and SBOM tooling sold to platform engineering teams
Careers page + GitHub release history
61 staff in Quincy, secrets scanning for CI pipelines, publishes its own security advisories
Company site + state business registry
Illustrative example. The source types are the ones Causo genuinely reads for this market.
Every result is a starting point, not an endpoint. Ask a follow-up about any vendor on your list in plain English and the agents go back out and read for it, then answer with the sources they used.
Certified at Moderate impact level, sponsored by a single civilian agency. A second offering is listed as Ready rather than Authorised, so it cannot be bought yet.
Yes. They have been a CVE Numbering Authority since 2023, with a scope limited to their own products, and they publish advisories themselves rather than through a distributor.
One appliance is certified at EAL4+ and the certificate was issued two years ago. The software gateway is not certified at all, and the most recent entry against it is a maintenance report.
Contact databases are assembled from what companies publish about themselves: professional profiles, funding rounds, tech stacks, hiring pages. A security product company or a developer tools vendor produces all of that by default, so unlike a fabricator or a care home it is already in Apollo and ZoomInfo, with a headcount, a location and an industry label. The company is in the database. The thing you need to filter on is not. No contact database carries whether a vendor’s cloud offering is FedRAMP Authorised or merely In Process, which impact level it reached, which agency sponsored it, whether the vendor is a CVE Numbering Authority and what its CNA scope covers, which of its products hold a Common Criteria certificate and at what assurance level, whether a cryptographic module is FIPS 140-3 validated or still on a legacy 140-2 certificate, whether its Cyber Essentials Plus or ISO 27001 certificate is still in date, or which of its products a public body can actually buy through G-Cloud. Those facts live in the FedRAMP Marketplace, the CVE Program partner list, the Common Criteria portal, the NIST Cryptographic Module Validation Program, the IASME certificate search and the Digital Marketplace. None of those are where a profile-derived database looks, so the record you get back says "computer and network security, 90 employees, Boston" and stops exactly where a partner, distributor, auditor or investor starts qualifying.
Figures as of August 2026.
| Apollo / ZoomInfo | Buying a list | Causo | |
|---|---|---|---|
| Filtering on "FedRAMP Authorised at Moderate impact level" | No such field | No such field | Read from the FedRAMP Marketplace listing |
| Telling a security product vendor apart from a reseller or an MSSP | All three sit under "computer and network security" | Not distinguished | Read from product, pricing and documentation pages |
| Whether the vendor is its own CVE Numbering Authority | Not tracked | Not tracked | Read from the CVE Program partner list |
| Common Criteria assurance level, FIPS validation and certificate date | Not tracked | Date the list was compiled | Read from the certification register at search time |
| Reaching the product security, compliance or channel lead | Usually a shared sales address | Often bounced | Named role, verified address |
Because those are not fields in a contact database. Apollo and ZoomInfo cover cybersecurity and developer tools companies well, since the collection method is built on professional profiles, funding rounds, tech stacks and hiring pages, all of which a software vendor produces by default. What they hold is firmographic: headcount, location, industry label. FedRAMP status and impact level, CVE Numbering Authority status and scope, Common Criteria assurance level and certificate date are published elsewhere, in the FedRAMP Marketplace, the CVE Program partner list and the Common Criteria portal, and no filter can reach them.
Read the FedRAMP Marketplace rather than a contact database. It is the US federal government’s public catalogue of cloud service offerings, and for each one it publishes the certification status, the impact level, the service model and the agency that sponsored the authorisation. The distinction that matters when qualifying a vendor is between an offering that is fully authorised and one still listed as In Process or Ready, because only the first can be bought government wide. Causo reads that listing alongside the vendor’s own trust and compliance pages, so status and impact level become searchable criteria.
By reading what the firm sells rather than how it is labelled. All four sit under the same industry code in a contact database. The distinction shows up in whether there is a product with its own documentation and release notes, whether pricing is per seat or per engagement, whether the company publishes its own security advisories, whether it holds certifications in its own name rather than reselling someone else’s, and whether its engineering hiring is for product roles or for service delivery. Causo reads those pages, registers and job posts and reports which of the four a company actually is.
Start from the certification scheme, not the vendor. The Common Criteria Portal publishes every certified product with its assurance level, protection profile and certificate date, and national schemes such as BSI in Germany, ANSSI in France and NIAP in the United States publish their own certification reports underneath it. Separately, the NIST Cryptographic Module Validation Program, run jointly with the Canadian Centre for Cyber Security, publishes FIPS 140-2 and FIPS 140-3 validated modules by vendor with the validating laboratory and the validation date. Causo reads those registers, so assurance level and certificate age become filters rather than something you have to ask about on a call.
A CVE Numbering Authority, or CNA, is an organisation authorised by the CVE Program to assign CVE identifiers to vulnerabilities within an agreed scope, usually its own products. It matters when qualifying a vendor because becoming one requires a working disclosure process and a product security team, so CNA status is a strong signal that a company ships a real security product rather than reselling or wrapping someone else’s. The CVE Program publishes the full partner list, and CISA operates one of the roots, so the status is public and checkable.
The company, why it matched, the evidence behind that with its source, and the decision maker with a verified email address. For a security or developer tools vendor that typically means its FedRAMP status and impact level, whether it is a CVE Numbering Authority and what its scope covers, which products hold a Common Criteria or FIPS validation and when the certificate was issued, its UK certification position, and which legal entity holds each of those. You can then ask follow-up questions about any result and get answers with sources attached.
Yes. The Common Criteria Portal is international and covers schemes in more than twenty countries. The local layer differs: in the United States it is the FedRAMP Marketplace, SAM.gov, NIAP and the NIST Cryptographic Module Validation Program; in the United Kingdom it is the IASME Cyber Essentials certificate search, NCSC assured product listings, G-Cloud on the Digital Marketplace and Companies House; in Germany it is BSI certification reports and the Handelsregister, in France ANSSI and INPI, in Sweden Bolagsverket, and in Australia ASD and the Information Security Registered Assessors Programme. Causo reads whichever set applies to the country you are searching.
One token per researched company, per decision maker found, per question asked and per outreach sequence sent. Plans start at $10 a month, and the first 10 tokens are free with no card required.
10 free tokens. No card.