In summary
- ThreatCanary has launched in Sydney, combining EASM, API security and autonomous offensive security into a single platform.
- The platform's threat intelligence is grounded in Australian-based knowledge, regulatory context and local operating environments.
- The founding team includes chief executive Matt Flannery, chief technology officer Andrew Horton, and Marco Delgado, who has joined as co-founder and chairman.
ThreatCanary, an Australian offensive security platform, has launched in Sydney, combining external attack surface management (EASM), API security and autonomous offensive security into a single platform aimed at helping organisations identify real-world attack paths before they are exploited.
It continuously discovers exposure, maps attack paths and validates exploitability rather than producing disconnected lists of findings.
The company is positioning itself as a 'sovereign' alternative to offshore platforms, saying its threat intelligence is grounded in Australian-based knowledge, regulatory context and local operating environments.
ThreatCanary's three core pillars are EASM - which maps the external attack surface from an attacker's perspective - API security, which identifies how APIs expose logic, data, identity and trust boundaries, and autonomous offensive security, which combines automated and agentic penetration testing, vulnerability research and red teaming into one platform.
Supporting modules cover vulnerability and threat intelligence, dark web monitoring and asset management.
The company's threat intelligence capability is designed to operate, according to ThreatCanary, more like an autonomous security research team than a conventional CVE feed.
It said research agents can monitor advisories, exploit repositories and technical disclosures published across multiple languages and regions, including Chinese and Russian-language research that English-speaking security teams have traditionally found difficult to follow at scale.
The founding team comprises Matt Flannery as chief executive, Andrew Horton as chief technology officer, and Marco Delgado - chief executive of Outcomex, 365mesh, Lucendus and Farmdeck - who has joined as co-founder and chairman.
"Security teams do not need another thousand findings," said Flannery.
"They need to know which weaknesses can actually be chained into compromise, what attackers would do next, and what to fix first. ThreatCanary is built to give organisations the attacker view continuously."
Horton said the platform's focus on API security reflects the risk posed by custom-developed APIs that never receive security updates and have been the source of major data breaches affecting Australians.
"“Through Australian ingenuity, ThreatCanary now delivers the continuous offensive security layer that is now needed for modern organisations: one platform that discovers what is exposed, understands how systems connect, creates the tests needed to prove risk, and continuously validates how attackers could move," he said.
Delgado said ThreatCanary is entering the market at the right time due to AI changing both the speed of attack and the expectations placed on teams.
"We believe Australia has the talent to build globally relevant cyber security companies, and ThreatCanary has the technical depth, product ambition and execution focus to compete on that stage. Australia should not simply consume the next generation of AI. We should build it, own it, and control it," he said.




