# NeuraLegion Financial Model

AI-driven application security platform (DAST/IAST/OSA/Pen-testing) integrated into CI/CD pipelines, spanning build to compliance.

- Canonical: https://finamodel.com/startups/neuralegion
- Excel download: https://finamodel.com/startup-models/neuralegion.xlsx
- Category: Dev Tools
- Model type: SaaS ARR / Valuation
- Funding round: Seed
- Funding: $4.7M
- Founded: 2020
- Geography: Israel (HQ), offices in Bosnia, London, San Francisco [DECK slide 8].
- Customer: B2B

## About the company

NeuraLegion’s NeXploit platform spans application security from code analysis and scanning to penetration testing and compliance. It supports API and multi-protocol testing, authenticated and single-page-app scanning, CI/CD integration, and machine-learning vulnerability detection, including business-logic vulnerabilities that conventional tools may miss.

The product is designed to embed security in developer workflows and claims to cover build-to-compliance in one system. Its commercial structure is not disclosed, but the research supports a SaaS model based on seats, scans, projects, or enterprise licences, sold through both developer-led and enterprise channels.

The company had 24 employees, including 14 security, machine-learning, and developer experts. No customer, ARR, price, or usage figures are available. The model should therefore use assumptions for developers, applications, scans, enterprise wins, integration cost, sales cycle, expansion, churn, and cloud margin.

## What's included

- 5-year monthly revenue build with stage-appropriate growth assumptions
- Full P&L, headcount plan, and operating-expense schedule
- Cash-flow statement, runway, and burn-rate tracking
- Valuation via exit multiple with a DCF cross-check
- Returns analysis with MOIC and IRR
- Unit economics including CAC, LTV, payback, and cohort retention

## Product & value proposition

- Product: NeXploit - an AppSec platform covering the full security lifecycle from code (OSA/SAST), to application scanning (DAST/IAST), to pen testing, to compliance.
- Core claim: Only solution that spans build-to-compliance AND detects Business Logic Vulnerabilities AND integrates with QAA workflows - no competitor does all three.
- Key technical differentiators: API & multi-protocol testing, authenticated site + SPA scanning, CI/CD native integration, ML/AI-driven vulnerability detection.
- Dev-first design: security embedded in the developer workflow, not bolted on post-release.

## Market

- TAM: >$20B combined (company's own framing).
  - Forrester: AppSec Market = $11B by 2024.
  - Markets & Markets: Developer-Driven AppSec Market = $9.5B.
  - Markets & Markets: App Pen Test Market = $5B.
- Market growth rate: Not explicitly stated; deck cites >50% of dev orgs adopting CI/CD by 2020 as an inflection point.
- Tailwinds cited: CI/CD adoption, security professional shortage, cost/complexity of manual pen-testing.

## Revenue model

- Given developer-first positioning and CI/CD integration, likely SaaS subscription (seat-based or usage-based per scan/project). Enterprise license deals probable for compliance-driven buyers.
- Go-to-market: direct sales (enterprise) + self-serve/PLG for developer adoption, given the dev-first branding.

## Traction & metrics

- Team size: 24 employees including 14 Security, ML & Dev Experts.

## Competition / moat

- Competitors mapped on two quadrant charts:
  - Build-to-compliance axis competitors: HCL (AppScan), Contrast Security, Micro Focus, Synopsys, WhiteHat Security.
  - Code/SAST/OSA competitors: Checkmarx, Veracode, Rapid7, Acunetix.
  - Modern dev practices competitors (partial): GitLab, various.
- Competitor gaps claimed:
  - Checkmarx, Rapid7, Acunetix, Veracode, Contrast: don't have IAST or have low-quality DAST, or don't have DAST.
  - Synopsys, WhiteHat, Micro Focus: span build-to-compliance but don't support modern dev practices.
  - None have Business Logic detection or QAA integration.
- Moat: proprietary ML/AI engine (Chief Scientist with neural network / ML background), full-stack coverage no competitor matches, CI/CD-native architecture.

## Team & funding ask / use of funds

- Shoham Cohen, CEO: Founder/COO Sogo; Head of Global Investments, Phoenix Group; Developer/Architect, Comverse; 20 years college professor (Hebrew Univ / COLMAN); 5 academic degrees.
- Gadi Bashvitz, President & CCO: CRO multiple companies up to $50M ARR; Founder/CEO OLSET (M&A); VP Product & Global Business, Merced (M&A >$300M); VP Product/PMK/Customer Success, Verint (IPO); MBA magna cum laude, NYU.
- Bar Hofesh, CTO: CISO & System Architect, Safe-T-Data; Security & DevSecOps advisor >10 companies; multiple publications in cybersecurity; CISO & MCITP certified.
- Art Linkov, Chief Scientist: PhD researcher, biology & stem cell regeneration; ML/AI/algorithm expert; researcher/publisher in neural networks; Bachelor/Masters/PhD, Technion.

---

## Recommended financial model

- **Archetype + why:** B2B SaaS ARR model. NeuraLegion sells recurring software subscriptions to enterprise security/dev teams. The natural metrics are ARR, net revenue retention, seat expansion, and CAC/LTV ratios. A 3-statement model is not warranted at this stage - ARR waterfall with a connected P&L is the right level.

- **Forecast horizon & granularity:** 3 years (Year 1–3), monthly in Year 1, quarterly in Years 2–3. Early stage with no disclosed revenue warrants a bottoms-up new-logo build in Year 1.

- **Key drivers & assumptions:**

| Driver | Value |
| -- | -- |
| Starting ARR | $0 (no traction disclosed) |
| Average Contract Value (ACV) | $30K–$80K - enterprise AppSec deals typically mid-market to enterprise range |
| New logos per quarter (Y1) | 2–5 - small team, early sales motion |
| Net Revenue Retention | 110–120% - land-and-expand via seat growth and module upsell |
| Gross margin | 70–80% - SaaS, cloud-hosted scanning; some COGS for compute |
| Sales cycle | 3–6 months - enterprise security buyer, compliance use case |
| Headcount (current) | 24 |
| R&D as % of OpEx | ~50% - 14 of 24 are technical |
| AppSec market TAM (2024) | $11B (Forrester) / $9.5B developer-driven (M&M) |
| CI/CD adoption inflection | >50% of dev orgs by 2020 |

- **Scenarios (Base / Bull / Bear - which variables flex):**
  - **Base:** 3–4 new logos/quarter at $40K ACV, 110% NRR, moderate hiring.
  - **Bull:** PLG motion accelerates deal velocity; 6–8 logos/quarter, ACV expansion to $60K+, NRR 120%+.
  - **Bear:** Long enterprise sales cycles + security budget freezes → 1–2 logos/quarter, high churn risk on pilot accounts.
  - Primary flex variables: new logo velocity, ACV, NRR, sales headcount ramp time.

- **Required sheets / outputs:**
  1. Assumptions (all drivers in one place, color-coded inputs).
  2. ARR Waterfall (new, expansion, churn, net new ARR by period).
  3. P&L (revenue → gross profit → S&M, R&D, G&A → EBITDA → net income).
  4. Headcount plan (by department, with salary assumptions).
  5. Cash & runway (cash burn, runway months at current/projected burn).
  6. KPI dashboard (ARR, logos, ACV, NRR, CAC, LTV, LTV/CAC, months to payback, gross margin).
  7. Scenario toggle (Base / Bull / Bear linked to assumptions sheet).

## Frequently asked questions

### Is the NeuraLegion financial model free?

Yes. The NeuraLegion model is a free Excel download with live formulas.

### Can I change the assumptions?

Yes. The workbook is editable and its live formulas recalculate when assumptions change.
