TAC InfoSec - A deep dive

u/SuperbPercentage8050 has already covered the cybersecurity space from the network and hardware side. This post is more focused on the software side of cybersecurity.

Every software application today needs to be tested for vulnerabilities, security gaps, and potential exploits before it goes into production. One trend I am seeing now is that developers are increasingly using AI to generate code. While AI definitely improves productivity, it can also introduce bugs, misconfigurations, and hidden security vulnerabilities that may go unnoticed during development.

Think about it this way. If a developer working at a company like J.P. Morgan ships code with a serious vulnerability and it slips through the cracks, a hacker can potentially exploit it and cause massive damage. These are not small issues. For large organizations, even a single vulnerability can lead to significant financial and reputational losses.

This is why penetration testing and security validation remain extremely important, especially for banks, fintechs, healthcare companies, and other highly regulated industries.

Some people may argue that AI tools and security models are becoming good enough to identify vulnerabilities on their own. While that may be true to some extent, I do not think companies will simply trust an AI model and call it a day. Most enterprises will still want an independent third party to validate their security posture. A specialized cybersecurity company also brings years of historical data, domain expertise, and practical understanding of how costly different vulnerabilities can be from a business perspective.

This is where TAC Infosec comes into the picture.

Unlike traditional service companies that send consultants to manually perform penetration testing, TAC is primarily a product-first cybersecurity company. Over the years, they have built multiple cybersecurity products, including:

  • ESOF
  • Socify
  • CyberScope
  • CyberSandia

ESOF

ESOF is their flagship platform. It includes multiple modules that help organizations identify vulnerabilities across web applications, mobile applications, cloud environments, APIs, and other digital assets.

Socify

This is one of the products that caught my attention.

If a startup or software company wants to sell its services to large US enterprises, obtaining SOC 2 compliance is often a necessity. Traditionally, this process involves third-party auditors and CPAs, takes several months, and costs a significant amount of money.

TAC is trying to solve this problem by reducing both cost and implementation time. From what I understand, the process can be completed in roughly 2 to 4 weeks at a much lower cost compared to many existing players.

Competitors generally charge anywhere between $10,000 and $20,000, whereas TAC's pricing is reportedly around $4,000, including CPA support. This pricing advantage could potentially be one of their major differentiators against established players like Vanta and others.

They have a few more products as well, but for now I am not focusing too much on them because they are still relatively small contributors. Maybe after a few more quarters they will become meaningful enough to discuss separately.

Now coming to the actual investment thesis.

For me, the biggest opportunity here is the reinvestment runway and the potential for cross-selling.

The company already has more than 10,000 customers and their average revenue per customer (RPC) is roughly $1,700. To me, this indicates a high-volume, low-ticket business model.

At this stage, customer acquisition itself does not look like the bottleneck because they already have a sizeable customer base. The real growth engine from here could be cross-selling.

For example, a customer may initially use one ESOF module for cloud security testing. Later, if the same customer needs web application testing, API security testing, compliance solutions, or other security products, TAC can potentially sell those solutions as well.

This is a playbook that many successful SaaS companies have followed over the years. As customers grow, their requirements also increase. A company that starts with two applications today may have five or six applications a year later. Naturally, their security requirements expand as well.

Once a customer enters the TAC ecosystem, the company gets multiple opportunities to increase wallet share over time.

Management's long-term vision is to reach around $10,000 in revenue per customer by 2030.

At first glance, that number may look ambitious and honestly I am still slightly skeptical about it. However, in businesses where cross-selling works effectively, acquiring the customer is usually the hardest part. Once that relationship is established, revenue expansion becomes much easier and can create a flywheel effect.

A somewhat similar pattern was seen with Shopify. Initially it was primarily an ecommerce platform. Over time they expanded into payments, shipping, POS, and several other offerings, increasing revenue from existing customers.

Whether TAC reaches $10,000 per customer or not remains to be seen, but the CEO appears very confident about the target.

What gives me some confidence is that the company has already increased revenue per customer from roughly $900 to around $1,700 within about 1.5 years.

This growth happened while they were simultaneously acquiring and integrating products such as CyberScope, Socify, SafeHouse, and others. So there is clearly some evidence that cross-selling is already happening.

Management has guided for approximately 20% half-yearly growth in revenue per customer and around 20% QoQ revenue growth. I would suggest everyone do their own modelling and see whether these targets appear achievable.

Coming to customers.

The company has worked with several large names, including Microsoft, Google, and recently management also mentioned Anthropic.

Now, having large customers does not necessarily mean these are massive contracts. But it does provide validation that the products are credible enough to be adopted by globally recognized organizations.

Interestingly, I think this also supports the argument that AI is not replacing cybersecurity.

If AI alone could solve security validation, why would an AI company like Anthropic require cybersecurity solutions from specialized vendors?

In fact, I would argue that as AI adoption increases, cybersecurity requirements may actually increase as well. Modern AI systems expose APIs, agents, connectors, integrations, MCP servers, and various external access points, all of which expand the attack surface.

More AI adoption could potentially mean more security checks rather than fewer.

Coming to valuation.

The stock is currently trading at around 37x earnings.

At first glance, that may seem expensive, but cybersecurity companies generally trade at premium valuations due to their growth potential and mission-critical nature.

The company currently generates ROCE of around 37% and net margins of approximately 40%, which are strong numbers in my view.

If management's FY27 guidance of ₹100 crore revenue and ₹40 crore PAT is achieved, then the forward valuation comes down meaningfully. By my estimates, that would imply roughly 25x FY27 earnings.

And if management ends up overdelivering, investors could see additional upside.

One more reason I started tracking this company was Vijay Kedia's investment. That initially got the stock onto my radar.

Around the same time, I also came across u/SuperbPercentage8050's posts, especially around cybersecurity mental models and bottleneck-based thinking, which helped me look at the business from a different angle.

Overall, this is my current high-level understanding of TAC Infosec. I could be wrong on several aspects, and there may be things I have missed.

Would love to hear views from people who track the cybersecurity space more closely or have a different perspective on the company. Constructive criticism is always welcome.

reddit.com
u/Plus-Bad-1857 — 8 days ago

JPMC SDE 2 Interview - Cleared 2 back-to-back initial rounds, moving to in-person Round 3 (Techno-Managerial). What to expect?

Hey guys,

I am currently in the loop for an SDE 2 role at JPMorgan Chase Bangalore location

I finished my initial 2 rounds back-to-back recently. Today the recruiter called back saying I’ve cleared them and moved on to the 3rd round, which they mentioned will be a Techno-Managerial round.

Since this is the final stage for an SDE 2 role, I wanted to get some insights from anyone who has given this round at JPMC before.

How technical does a JPMC techno-managerial round actually get? Will they grill heavily on high-level/low-level system design (HLD/LLD), or do they mostly stick to deep-diving into past projects and resume points? Also, if you guys have any tips on what kind of scenarios or behavioral questions they focus on at this stage, please let me know.

Any pointers or recent experiences would be a huge help. Thanks!

reddit.com
u/Plus-Bad-1857 — 1 month ago

JPMC SDE 2 Interview - Cleared 2 back-to-back initial rounds, moving to in-person Round 3 (Techno-Managerial). What to expect?

Hey guys,

I am currently in the loop for an SDE 2 role at JPMorgan Chase Bangalore location

I finished my initial 2 rounds back-to-back recently. Today the recruiter called back saying I’ve cleared them and moved on to the 3rd round, which they mentioned will be a Techno-Managerial round.

Since this is the final stage for an SDE 2 role, I wanted to get some insights from anyone who has given this round at JPMC before.

How technical does a JPMC techno-managerial round actually get? Will they grill heavily on high-level/low-level system design (HLD/LLD), or do they mostly stick to deep-diving into past projects and resume points? Also, if you guys have any tips on what kind of scenarios or behavioral questions they focus on at this stage, please let me know.

Any pointers or recent experiences would be a huge help. Thanks!

reddit.com
u/Plus-Bad-1857 — 1 month ago

JPMC SDE 2 Interview. Completed 2 round. What to expect in in-person round 3?

Hey guys

I am currently in the loop for an SDE 2 role at JPMorgan Chase

I finished my initial 2 rounds back-to-back recently. Today the recruiter called back saying I’ve cleared them and moved on to the 3rd round, which they mentioned will be a Techno-Managerial round.

Since this is the final stage for an SDE 2 role, I wanted to get some insights from anyone who has given this round at JPMC before.

How technical does a JPMC techno-managerial round actually get? Will they grill heavily on high-level/low-level system design (HLD/LLD), or do they mostly stick to deep-diving into past projects and resume points? Also, if you guys have any tips on what kind of scenarios or behavioral questions they focus on at this stage, please let me know.

Any pointers or recent experiences would be a huge help. Thanks!

reddit.com
u/Plus-Bad-1857 — 1 month ago