Bright Pixel (formerly Sonae IM)

Sonae IM is the corporate venturing arm of Sonae (retail and telco group), which is focused on investing in tech-based companies. The company invests in a broad range of companies related to Sonae's core, joining funding with a strategic profile. With a flexible investment style and approach, Sonae IM leverages on its technology expertise, brand capital, and access to a global network. The company supports companies to achieve success with an internal pool of experts, which supports portfolio management. Sonae has been developing different corporate venturing initiatives for long, namely revenue assurance leader WeDo (2001) and Mainroad spin-off (2003) and subsequent successful exit (2014). Moreover, after deciding that Cyber security was an interesting area, it invested in Spanish cyber security company s21sec (2014). Another critical space for retailers, location analytics, led to the investment in Movvo (2014). Since the official launch of Sonae IM in late 2015, the company invested in InovRetail (demand forecasting for retailers), StyleSage (fashion tech predictive analytics) and Sysvalue (cyber security add on for s21sec). Additionally, Sonae IM got involved in the acquisition of Novo Banco's stakes in 3 funds managed by ES Ventures and launched Bright Pixel (company builder studio). Sonae IM was officially founded in 2015, but corporate venturing initiatives within Sonae are in Sonae's DNA for longer and led to what Sonae IM is today. The company is based in Porto, Portugal.

Filipa Costa

Finance Director

João Moutinho

People Director

Cristina Novais

CFO

Eduardo Piedade

Managing Partner and CEO

Past deals in Penetration Testing

Picnic Corporation

Series A in 2023
Picnic operates as a cybersecurity firm that mitigates and prevents social engineering attacks. It protects those users in the chair more effectively than security awareness training and phishing simulations. The company is backed by institutional investors and a top-flight team of advisors and experts.

Hackuity

Series A in 2022
Hackuity is a cybersecurity firm that provides a platform designed to enhance the management of IT vulnerabilities within enterprises. The company specializes in risk-based vulnerability management software, which aggregates and normalizes vulnerability data from various assessment tools and audit results. By employing AI-driven predictive models, Hackuity enables security practitioners to develop risk-driven remediation plans that align with their current and future threat exposure. This approach facilitates faster resolution of vulnerabilities through tools orchestration, risk-based prioritization, and workflow automation, ultimately helping organizations reduce their exposure to cyber risks.

SafeBreach

Series D in 2021
SafeBreach Inc. is a cybersecurity company that specializes in breach and attack simulation, providing organizations with tools to enhance their security posture. Founded in 2014 and based in Sunnyvale, California, with an additional location in Tel Aviv, Israel, SafeBreach offers a comprehensive platform that simulates hacker techniques to identify vulnerabilities within a network. Its platform utilizes an extensive Hacker's Playbook, which includes real-world breach methods, to proactively predict potential attacks and validate existing security controls. By integrating with various security information and event management systems and other cybersecurity tools, SafeBreach enables continuous visibility into security issues, allowing businesses to detect and remediate potential breaches before they can be exploited by actual attackers. The company is supported by notable investors, including Sequoia Capital and Deutsche Telekom Capital.

Jscrambler

Series A in 2021
Jscrambler LDA is a web security company based in Porto, Portugal, founded in 2008, with additional locations in Lisbon and San Francisco. The company specializes in protecting web and mobile applications from various security threats. Its primary product, JScrambler, employs advanced JavaScript obfuscation techniques, providing robust security features, including code locks, self-defending capabilities, and threat monitoring. This platform helps prevent tampering, reverse-engineering, and counterfeit applications, while ensuring compliance with major technology frameworks such as HTML5 and Node.js. Jscrambler also offers a Webpage Integrity module, which delivers real-time visibility into client-side attacks, enabling businesses to respond swiftly to security incidents. The company's solutions cater to diverse sectors, including finance, healthcare, gaming, and online advertising, and are trusted by numerous organizations worldwide, including Fortune 500 companies.

Deepfence

Series A in 2020
Deepfence Inc, founded in 2016 and headquartered in Milpitas, California, specializes in security software tailored for cloud-native applications. The company focuses on enhancing application security by developing a workload protection platform that effectively prevents cyberattacks. This platform utilizes advanced techniques to identify subtle indicators of potential threats, offering real-time protection against complex multistage and multivector attacks. By creating a 'Security as Microservice' solution, Deepfence aims to provide comprehensive protection that aligns with modern application and infrastructure needs, ensuring businesses receive robust security against both known and unknown vulnerabilities.

IriusRisk

Series A in 2020
IriusRisk, developed by Continuum Security, SL, is a comprehensive tool designed to manage and assess software security risks throughout the software development lifecycle. Founded in 2008 and based in Huesca, Spain, the company focuses on providing solutions that integrate seamlessly into existing development workflows, ensuring that security processes support rather than hinder development speed. IriusRisk caters primarily to enterprises in the financial and technology sectors, enabling them to proactively address security challenges while promoting a culture of secure software development. In addition to IriusRisk, the company also offers BDD-Security, a security testing framework that further enhances its suite of security management tools.

Probely

Seed Round in 2020
Probely is a SaaS platform that specializes in web vulnerability scanning for agile teams, aimed at enhancing the security of web applications. The service offers continuous scanning capabilities, allowing businesses to efficiently manage the lifecycle of identified vulnerabilities through an intuitive web interface. Probely provides detailed remediation instructions, including code snippets, to assist users in addressing these vulnerabilities effectively. The platform incorporates advanced features such as machine learning and heuristic techniques to minimize false positives, while also supporting direct integration with continuous monitoring tools and development processes. This functionality enables businesses to automate security testing, thereby reducing the risk of cyber attacks and enhancing overall cybersecurity posture.

Arctic Wolf

Series D in 2020
Arctic Wolf Networks, Inc. specializes in providing security operations center-as-a-service to businesses, aiming to mitigate cyber risk. Founded in 2012 and headquartered in Eden Prairie, Minnesota, the company delivers a range of solutions including Managed Detection and Response, Managed Risk, and Managed Cloud Monitoring. These services are facilitated by a concierge security team that acts as an extension of a company's internal resources, offering tailored threat detection, response, and ongoing risk management. Arctic Wolf's platform incorporates cloud infrastructure monitoring, software application monitoring, dynamic asset identification, vulnerability assessments, and account takeover risk detection. Additionally, the company has developed the Arctic Wolf Agent, which collects actionable intelligence from IT environments. Arctic Wolf serves various industries, including financial services, healthcare, and legal sectors, with additional offices located in Provo, Utah, and Waterloo, Canada.

Fyde

Seed Round in 2019
Fyde helps companies with an increasingly distributed workforce to mitigate breach risk by enabling secure access to critical enterprise resources for their employees, partners, contractors, and outsourcers. Fyde’s flagship enterprise product provides granular access controls for your enterprise apps and workloads, continuously monitors access requests, improves the security posture of endpoints and protects user identities against phishing and account takeover attacks.

Excellium Services

Funding Round in 2018
Excellium Services S.A, founded in 2012 and based in Contern, Luxembourg, specializes in cybersecurity and management services. As a subsidiary of Grupo S21sec Gestión, S.A since January 2019, the company provides a range of services including security operations, incident response, and penetration testing. Utilizing a Software as a Service model and cloud capabilities, Excellium Services equips organizations to effectively respond to intrusions and assess their cybersecurity posture. The company employs advanced scanning technologies and ethical hacking techniques to help clients identify and mitigate vulnerabilities in their infrastructure. Through continuous monitoring and support, Excellium Services aims to enhance the security of clients' internet infrastructures, ensuring they can operate safely and efficiently in an increasingly complex digital landscape.

Probely

Seed Round in 2018
Probely is a SaaS platform that specializes in web vulnerability scanning for agile teams, aimed at enhancing the security of web applications. The service offers continuous scanning capabilities, allowing businesses to efficiently manage the lifecycle of identified vulnerabilities through an intuitive web interface. Probely provides detailed remediation instructions, including code snippets, to assist users in addressing these vulnerabilities effectively. The platform incorporates advanced features such as machine learning and heuristic techniques to minimize false positives, while also supporting direct integration with continuous monitoring tools and development processes. This functionality enables businesses to automate security testing, thereby reducing the risk of cyber attacks and enhancing overall cybersecurity posture.

Arctic Wolf

Series C in 2018
Arctic Wolf Networks, Inc. specializes in providing security operations center-as-a-service to businesses, aiming to mitigate cyber risk. Founded in 2012 and headquartered in Eden Prairie, Minnesota, the company delivers a range of solutions including Managed Detection and Response, Managed Risk, and Managed Cloud Monitoring. These services are facilitated by a concierge security team that acts as an extension of a company's internal resources, offering tailored threat detection, response, and ongoing risk management. Arctic Wolf's platform incorporates cloud infrastructure monitoring, software application monitoring, dynamic asset identification, vulnerability assessments, and account takeover risk detection. Additionally, the company has developed the Arctic Wolf Agent, which collects actionable intelligence from IT environments. Arctic Wolf serves various industries, including financial services, healthcare, and legal sectors, with additional offices located in Provo, Utah, and Waterloo, Canada.

Reblaze

Series A in 2018
Reblaze Technologies Ltd. specializes in providing comprehensive web security solutions designed to protect websites, web applications, and APIs from various internet threats. Based in St. Louis, Missouri, with additional offices in Sunnyvale, California, and Manchester, United Kingdom, the company offers a cloud-based platform that includes a web application firewall, DDoS protection, bot mitigation, and content delivery network services. Reblaze's unique approach leverages machine learning for adaptive threat detection and employs dedicated Virtual Private Clouds to ensure maximum privacy and security for its clients. The platform also features an intuitive management console for real-time traffic control and fine-grained access controls for precise regulation of incoming traffic. By blocking hostile traffic in the cloud before it reaches the protected network, Reblaze enables organizations to effectively safeguard their data and web assets against damaging attacks.

Jscrambler

Series A in 2018
Jscrambler LDA is a web security company based in Porto, Portugal, founded in 2008, with additional locations in Lisbon and San Francisco. The company specializes in protecting web and mobile applications from various security threats. Its primary product, JScrambler, employs advanced JavaScript obfuscation techniques, providing robust security features, including code locks, self-defending capabilities, and threat monitoring. This platform helps prevent tampering, reverse-engineering, and counterfeit applications, while ensuring compliance with major technology frameworks such as HTML5 and Node.js. Jscrambler also offers a Webpage Integrity module, which delivers real-time visibility into client-side attacks, enabling businesses to respond swiftly to security incidents. The company's solutions cater to diverse sectors, including finance, healthcare, gaming, and online advertising, and are trusted by numerous organizations worldwide, including Fortune 500 companies.

Arctic Wolf

Series B in 2018
Arctic Wolf Networks, Inc. specializes in providing security operations center-as-a-service to businesses, aiming to mitigate cyber risk. Founded in 2012 and headquartered in Eden Prairie, Minnesota, the company delivers a range of solutions including Managed Detection and Response, Managed Risk, and Managed Cloud Monitoring. These services are facilitated by a concierge security team that acts as an extension of a company's internal resources, offering tailored threat detection, response, and ongoing risk management. Arctic Wolf's platform incorporates cloud infrastructure monitoring, software application monitoring, dynamic asset identification, vulnerability assessments, and account takeover risk detection. Additionally, the company has developed the Arctic Wolf Agent, which collects actionable intelligence from IT environments. Arctic Wolf serves various industries, including financial services, healthcare, and legal sectors, with additional offices located in Provo, Utah, and Waterloo, Canada.

IriusRisk

Venture Round in 2017
IriusRisk, developed by Continuum Security, SL, is a comprehensive tool designed to manage and assess software security risks throughout the software development lifecycle. Founded in 2008 and based in Huesca, Spain, the company focuses on providing solutions that integrate seamlessly into existing development workflows, ensuring that security processes support rather than hinder development speed. IriusRisk caters primarily to enterprises in the financial and technology sectors, enabling them to proactively address security challenges while promoting a culture of secure software development. In addition to IriusRisk, the company also offers BDD-Security, a security testing framework that further enhances its suite of security management tools.

Probely

Seed Round in 2017
Probely is a SaaS platform that specializes in web vulnerability scanning for agile teams, aimed at enhancing the security of web applications. The service offers continuous scanning capabilities, allowing businesses to efficiently manage the lifecycle of identified vulnerabilities through an intuitive web interface. Probely provides detailed remediation instructions, including code snippets, to assist users in addressing these vulnerabilities effectively. The platform incorporates advanced features such as machine learning and heuristic techniques to minimize false positives, while also supporting direct integration with continuous monitoring tools and development processes. This functionality enables businesses to automate security testing, thereby reducing the risk of cyber attacks and enhancing overall cybersecurity posture.

S21sec

Private Equity Round in 2014
S21sec is a cybersecurity company. S21sec offers various security-related services (e.g. protection of critical infrastructures and personal data protection) and software (e.g. information security management systems) S21sec is focused on providing security for governs, energy and critical infrastructures, finance institutions and telco industries. S21sec has a CERT section, a 24-hour security intelligence center, and a CyberCrime one, where it collaborates with governs and governmental institutions like Europool[1] and the FBI.[2] More than 20% of the Dow Jones Eurostoxx 50 companies are clients of S21sec.

S21sec

Acquisition in 2014
S21sec is a cybersecurity company. S21sec offers various security-related services (e.g. protection of critical infrastructures and personal data protection) and software (e.g. information security management systems) S21sec is focused on providing security for governs, energy and critical infrastructures, finance institutions and telco industries. S21sec has a CERT section, a 24-hour security intelligence center, and a CyberCrime one, where it collaborates with governs and governmental institutions like Europool[1] and the FBI.[2] More than 20% of the Dow Jones Eurostoxx 50 companies are clients of S21sec.
Spot something off? Help us improve by flagging any incorrect or outdated information. Just email us at support@teaserclub.com. Your feedback is most welcome.