Raxis logo

Raxis

Claimed

US penetration testing firm founded in 2011, running 600+ engagements a year with a fully remote, US-based team. Manual, expert-led testing across web, network, cloud, mobile, wireless, OT/ICS, and AI/LLM. Gartner Sample Vendor for PTaaS.

Featured in: Penetration Testing for Energy & Utilities

Visit Raxis
Founded
2011
Team Size
11-50
Geography
National
Pricing
Mid-Range
Model
Per Project, Retainer
Last verified: Jul 2026

Key facts

  • Founded in Atlanta in 2011 by Mark Puckett, formerly head of the global Red Team at Home Depot.
  • Runs over 600 penetration tests a year with a fully remote, US-based team.
  • Every engineer is a senior-level practitioner based in the United States; testing is never offshored.
  • Named a Sample Vendor for PTaaS in Gartner's 2024 Hype Cycle reports for Security Operations and Application Security.
  • Team members have discovered and published CVEs, including CVE-2022-25245 and CVE-2022-35739.
  • Delivers testing through the Raxis One portal, with real-time findings and Jira integration.
  • The Raxis Transporter appliance enables remote internal network testing without travel or a VPN.
  • Tests critical infrastructure across energy, water and wastewater utilities, transportation, government, and education.
  • Headquartered in Atlanta, Georgia, United States.
  • Team of 11-50 security professionals.
  • Holds OSCP Employer accreditation.
  • Delivers 16 penetration testing services.
  • Serves clients in North America.
  • Specialises in Adversary Simulation, Cloud-Native Security, and OT/ICS Security.
  • Compliance expertise across PCI DSS, SOC 2, HIPAA, GLBA, and ISO 27001.

About

Raxis is a US penetration testing firm founded in Atlanta in 2011 by Mark Puckett, who previously led the global Red Team at Home Depot. Penetration testing is the only thing the company does. It runs over 600 penetration tests a year with a fully remote, US-based team serving clients nationwide.

Testing is manual and expert-led. Raxis tests web applications, networks, cloud environments (AWS, Azure, GCP), mobile applications, wireless, SCADA/ICS, and AI/LLM systems, delivered through the Raxis One platform. Red team services cover physical intrusion, social engineering, and assumed-breach scenarios, alongside purple teaming and secure code review.

Team members hold OSCP, OSWE, OSCE, OSEP, CRTO, GPEN, PNPT, CISSP, CISM, and CISA certifications. Reports are built to satisfy PCI DSS, SOC 2, HIPAA, GLBA, and ISO 27001 requirements, including GLBA testing under the FTC Safeguards Rule. Raxis was named a Sample Vendor for Penetration Testing as a Service in Gartner's 2024 Hype Cycle reports for Security Operations and Application Security.

Raxis in Depth

Enhanced

Overview

Raxis is a US penetration testing firm founded in Atlanta in 2011 by Mark Puckett, who previously led the global Red Team at Home Depot. Penetration testing is the only thing the company does. It runs more than 600 engagements a year with a fully remote, US-based team, and its client roster spans regional banks, defense contractors, Fortune 500 enterprises, and critical infrastructure operators.

The team publishes original security research, including CVEs discovered by named Raxis testers and disclosed through the company's blog.

Approach

Testing is manual and expert-led. Automation and AI are used where they help coverage, but findings are validated and exploited by hand by senior US-based engineers, and testing is never offshored. Engagements are delivered through Raxis One, the company's PTaaS portal, with findings reported in real time and integration into Jira and DevSecOps workflows. For internal testing, the Raxis Transporter appliance ships overnight and connects in minutes, so internal networks can be tested remotely without travel or a VPN.

What They Test

Web applications and APIs
Manual testing of web applications and APIs, with findings validated by hand and reported in real time through Raxis One.
Networks
External and internal network testing, with internal engagements delivered remotely via the Raxis Transporter appliance.
Cloud
AWS, Azure, and GCP environment testing.
Mobile and wireless
iOS and Android application testing and wireless assessments.
SCADA/ICS and OT
Critical infrastructure testing across energy, water and wastewater utilities, and transportation, including IT/OT boundary work.
AI and LLM systems
Testing of AI and LLM-backed applications.
Red team and social engineering
Red teaming including physical intrusion, social engineering, and assumed-breach scenarios, plus purple teaming and secure code review.

Working with Raxis

Is Raxis's testing manual or automated?
Manual and expert-led. Automation and AI assist with coverage, but every finding is validated and exploited by hand by a senior engineer. Raxis positions itself explicitly against scanner-driven, report-only testing.
Where are Raxis's testers located?
All engineers are senior-level practitioners based in the United States. Raxis states that testing is never offshored.
How does Raxis test internal networks remotely?
Through the Raxis Transporter, a network appliance shipped to the client that connects in minutes without a VPN. It supports internal testing for requirements such as CMMC, NIST 800-171, PCI DSS, and HIPAA without an on-site visit.
What compliance requirements do Raxis reports support?
Reports are built to satisfy PCI DSS, SOC 2, HIPAA, GLBA, and ISO 27001 requirements, including GLBA testing under the FTC Safeguards Rule.

Methodologies

OWASPNISTPTES

Team Certifications

OSCP
1 certified
OSWE
1 certified
OSCE
1 certified
OSEP
1 certified
CRTO
1 certified
GPEN
1 certified
PNPT
1 certified
CISSP
1 certified
CISM
1 certified
CISA
1 certified
Visit Raxis