Seed Round — Basel, Switzerland — March 2026

We hold the only complete map of the Swiss digital attack surface.

Switzerland's new cybersecurity laws just made our product mandatory. 75,000 SMEs. No accessible solution. We are building it.

Request Investor Brief See the Platform →
🇨🇭 Basel-Stadt GmbH (Q2 2026) · CHF 300k Seed Round · rafael@extrapolo.com
2.5M+ .ch domains scanned
100% .ch namespace mapped
CHF 6M+ revenue at 10% penetration
85%+ gross margin at scale
ISG mandatory since Apr 2025
The Problem

Three laws. 600,000 SMEs. Zero accessible tools.

Switzerland's regulatory landscape has fundamentally shifted — and the mass market of SMEs has no compliant, affordable solution.

⚖️

ISG — Swiss Federal Law

Since April 2025, organisations must report cyberattacks to the NCSC within 24 hours. Fines up to CHF 100,000. Knowing your attack surface is the only defensible compliance strategy.

🏦

DORA — EU Resilience Act

Operative since January 2025. Swiss financial institutions and their suppliers must conduct annual attack surface assessments. Creates indirect obligations for thousands of Swiss SME suppliers.

🔗

NIS2 — Cascade Effect

European clients now audit their Swiss suppliers' cybersecurity posture as a condition of contract. A Swiss SME without evidence of surface monitoring risks losing enterprise customers.

🎯

The Gap Is Enormous

Existing solutions cost CHF 10,000–25,000/year, require internal IT access, and target enterprise clients. 70% of Swiss SMEs have no formal cybersecurity posture — and no tool built for them.

No competitor holds what we built.

Before company formation, we independently enumerated the entire Swiss .ch domain namespace — over 2.5 million domains. This proprietary dataset is the foundation for every product feature and cannot be easily replicated. No domestic or international player holds this asset.

The dataset enables national-level risk benchmarking against Swiss industry peers, identification of .ch look-alike domains used for phishing, and longitudinal tracking of the Swiss internet attack surface over time. These are capabilities no generic global platform can offer.

"We have performed a complete enumeration of the entire Swiss .ch domain namespace. This is the foundation for a scalable SaaS product — and a moat that grows with every scan."

The Platform

Automated. External. Zero internal access required. Constantly.

HELVETISCAN monitors everything an attacker can see from the outside — no agent installation, no IT access, no technical expertise needed by the client.

TLS & Certs

Certificate Intelligence

Expired or weak TLS certificates, missing CT logs, outdated protocol versions — including certificates expiring within 30 days.

DNS

DNS & DNSSEC Analysis

Missing CAA records, absence of DNSSEC signing, wildcard exposure, and full subdomain enumeration including forgotten legacy assets.

HTTP

Security Header Audit

HSTS, CSP, X-Frame-Options, Referrer-Policy, Permissions-Policy — scored and benchmarked against Swiss industry peers.

Ports

Exposed Services

Open database ports, RDP, legacy protocols visible on the public internet — ranked by exploitability and business impact.

Email

Email Spoofability

Full SPF/DKIM/DMARC policy validation — not just presence detection. Identifies whether a domain can be impersonated today.

AI

AI Risk Narrative

LLM-generated plain-language risk reports explaining findings in business terms — structured for ISG, DORA, and FINMA audit requirements.

Live Scan Data

What we found scanning every .ch domain.

These are not estimates. Every figure comes from production scans of the full Swiss namespace — the same engine that powers the platform.

HTTP / DNS

1 in 4 .ch domains is dead

76.4% of .ch domains return a live HTTP response. 450,916 domains fail DNS entirely — no active server behind them.

  • Apache: 38.3% · nginx: 34.0% · Cloudflare: 10.2%
  • WordPress powers 71.5% of identifiable CMS sites (~19% of all live .ch)
  • 43,473 active sites run end-of-life PHP versions
HTTPS & TLS

28.3% still on plain HTTP

71.7% of live .ch domains end on HTTPS — but over a quarter of Swiss sites transmit data unencrypted in 2025.

  • TLS 1.3 adoption: 92.9% of HTTPS sites
  • Let's Encrypt issues 83.1% of certificates
  • 60,171 certificates expire within 30 days
Email Security

43.3% of domains fully spoofable

Nearly half of scanned .ch domains can be impersonated in a phishing attack today — SPF absent or permissive, DMARC missing or on p=none.

  • DKIM adoption: only 6.8%
  • 24.7% of DMARC adopters use p=none (no enforcement)
  • Only 30.2% implement HSTS despite 71.7% serving HTTPS
Exposed Services

313,472 domains expose MySQL

Databases, file shares, and container APIs are directly reachable from the public internet on tens of thousands of Swiss domains.

  • SMB (file sharing) exposed: 87,292 domains
  • Docker API exposed: 1,742 domains
  • FTP open: 688k domains — 42% of all scanned
Hosting

40.6% hosted outside Switzerland

Data sovereignty is a live compliance issue. A large share of Swiss domains are physically hosted abroad — often under foreign jurisdiction.

  • Germany: 17.3% · United States: 11.6%
  • Single Hostpoint IP hosts 133,425 domains (6.9% of live .ch)
  • Top 10 IPs collectively serve ~21% of the namespace
Security Headers

49.1% send zero security headers

Basic browser-enforced protections are absent on nearly half of Swiss domains — HSTS, CSP, X-Frame-Options are the norm in every other developed market.

  • 40.6% of sites expose server version strings
  • Domains in high-risk jurisdictions: 501 in RU/BY/IR/CN/SY
  • Wix: 77k · Register.it: 35k · Shopify: 15k Swiss domains
Explore Data Visualisation Full Findings Report View on GitHub
Competitive Landscape

An uncontested segment.

Every existing player has built upmarket. None of them have incentive to build a CHF 800/year automated tool for the SME mass market.

Criteria Swiss Post Cyber Exeon Analytics ImmuniWeb HELVETISCAN
Target Market Enterprise (250+) Mid-Market Enterprise SME (primary)
Annual Price CHF 200k+ CHF 50k+ CHF 15k+ CHF 800
Internal Access Required ✘ Yes ✘ Yes ⚠ Partial ✔ No
Swiss .ch Proprietary Dataset ✘ No ✘ No ✘ No ✔ 100% namespace
AI Risk Narrative ✘ No ⚠ Partial ⚠ Partial ✔ Yes
DORA-Ready Reports ✔ Yes ✔ Yes ⚠ Partial ✔ Yes
Self-Serve / No Sales Required ✘ No ✘ No ✘ No ✔ Yes
Market Opportunity

75,000 addressable clients. Zero direct competitors at this price.

Three high-priority verticals for go-to-market — each with a direct regulatory trigger.

🧬

Basel Pharma & Life Sciences

Roche, Novartis, and 3,000+ Swiss suppliers under GDPR, NIS2, and FDA cybersecurity requirements.

🏦

Swiss Financial Services

300+ fintechs, 200+ banks, thousands of insurance and asset management firms subject to FINMA and DORA.

⚖️

Professional Services

Law firms, audit firms, HR tech — increasingly required by enterprise clients to demonstrate cyber hygiene.

🤝

Treuhand Network

80% of Swiss SMEs work with fiduciaries. 10 partnerships unlock access to their entire client base.

600k

Total Swiss SMEs

75k

Serviceable addressable market

CHF 800

Entry price per year

85%+

Gross margin at 1,000 subscribers

300–400

Subscribers to break-even

Financial Projections

Profitable at Year 3. High margin from Year 2.

Infrastructure costs do not scale linearly with subscribers — enabling rapid margin expansion as the base grows.

Year 1
CHF 40–120k
50–150 subscribers
Year 2
CHF 240–480k
300–600 subscribers · Break-even
Year 3
CHF 800k–1.6M
1,000–2,000 subscribers
Year 4–5
CHF 4–6M
5,000–7,500 subscribers

Unit economics: CAC CHF 150–400 via LinkedIn outbound + content. LTV CHF 2,400 at 3-year retention. LTV:CAC ratio 6:1–16:1. Marginal cost of new subscriber near zero.

Traction & Milestones

Production-ready before the seed round.

Built by a technical founder. Every core module is operational.

Q1 2026 ✓

Complete .ch namespace enumeration (2.5M+ domains). Scan engine in Rust — HTTP, DNS, TLS, ports, WHOIS, subdomains. Risk scoring model v1. Swiss Innovation Challenge application submitted.

Q2 2026

GmbH incorporation (Basel-Stadt). Compliance report generator. REST API & web dashboard. First 10 paying pilot clients.

Q3 2026

Seed round close (CHF 300k). 50 subscribers. First Treuhandpartner partnership signed.

Q4 2026

100 subscribers. ISACA Switzerland community launch. First pharma enterprise pilot.

Q2 2027

200 subscribers. Break-even approaching. Series A preparation.

Investor Contact

Ready to back Switzerland's first SME cybersecurity intelligence platform?

Confidential — not for distribution
Message received — we'll reply within 48 hours.