logo

PlexTrac Acquired by Brinqa: What the Acquisition Means for Pentest Reports

PlexTrac Acquired by Brinqa: What the Acquisition Means for Pentest Reports

PlexTrac was acquired by Brinqa on August 19, 2026. Financial terms of the PlexTrac acquisition were not disclosed. Brinqa, an Austin-based exposure management vendor, says the combined company now serves more than 3,000 customers across 57 countries, including over 25% of the Fortune 500 (announcement).

If PlexTrac is where your consultancy writes its reports, that headline is the story. The useful part is everything underneath it — what actually changes, when, and what you should do about it before your next renewal.

Disclosure: we build PentestPad, a PlexTrac competitor. That’s why every factual claim below links to a primary source — read us skeptically, and check the links.

What Was Announced in the PlexTrac Acquisition

The facts, straight from the press release and same-day coverage:

  • Brinqa acquired PlexTrac on August 19, 2026. Terms undisclosed (Brinqa newsroom).
  • The stated rationale is closing the CTEM loop — Brinqa identifies and prioritizes exposures, PlexTrac’s offensive-security workflow proves the fix actually held (Help Net Security).
  • Dan DeCloss, PlexTrac’s founder, joins Brinqa’s executive leadership team and board of directors (Help Net Security).
  • Brinqa says confirmed exploits and remediation results from PlexTrac will flow into Brinqa’s data layer and Cyber Risk Graph, feeding its AI agents and its Bring Your Own AI program (citybiz).
  • The combined entity positions itself as the largest standalone vendor in Unified Exposure Management.

Read that last bullet again, because it’s the whole story. PlexTrac is no longer a pentest reporting company. It is the validation layer inside an exposure management platform.

The Investor Detail Most Coverage Skipped

Insight Partners led PlexTrac’s $70M Series B in February 2022 (PRNewswire). Insight’s Thomas Krane also sits on Brinqa’s board and gave a supporting quote in the PlexTrac acquisition announcement (Help Net Security).

This is a sponsor-led consolidation inside one investor’s portfolio, not an outside strategic buyer paying up for a category leader. That’s not a scandal — it’s how enterprise software consolidation normally works. But it tells you something about the direction of travel. Portfolio roll-ups optimize for a single go-to-market motion and a single ideal customer profile. They rarely optimize for the smaller, noisier segment that happened to be the original one.

Why the PlexTrac Acquisition Hits Consultancies Harder Than Enterprises

PlexTrac started as a tool for pentesters. Consultancies and internal red teams used it to run engagements and ship client deliverables. That’s what made it the default name in the category.

Brinqa sells to CISOs running vulnerability and exposure programs. Its buyer has a CTEM budget, a Cyber Risk Graph, and a board deck to fill. That buyer does not care about whitelabeled client portals, per-client report branding, or whether your DOCX export preserves the cover page your designer built in 2019.

So the fork is roughly this:

If you’re an internal enterprise security team already running a CTEM program, the PlexTrac acquisition might genuinely help you. Pentest findings feeding directly into exposure prioritization, with retest evidence attached, is a real workflow improvement. You are now the primary customer.

If you’re a consultancy or MSSP, you just became a secondary segment inside someone else’s roadmap. Your requirements — client-facing delivery, multi-tenant separation, branding, per-engagement project structures, contract-driven scoping — are now line items competing with enterprise CTEM features for the same engineering hours.

Neither outcome is guaranteed. But you should find out which one you’re in before you sign a renewal.

What PlexTrac Customers Were Already Saying (Before the Acquisition)

Here’s the tell: the direction Brinqa is now formalizing was visible to PlexTrac’s own paying customers a year before the deal.

In an April 2025 r/Pentesting thread, a long-time PlexTrac customer summarized the drift directly:

“They did a huge freeze to pay off technical debt, then proceeded to ignore feature requests and push features that aren’t what their actual customer base wants. They’re trying so hard to expand their product into a complete remediation toolsuite at the cost of their primary customers, pentesters, that it’s leading to a shitty product.” — u/MAGArRacist

Other consultancy operators in the same thread reported the same pattern, months before Brinqa’s name was public:

  • Roadmap stalls on pentester-facing features. A two-year customer preparing to leave: “it’s been over 6 months and we’ll likely never see them implemented before we leave.”
  • B2B/client-portal fit as an afterthought. “We need a ‘client portal’ and while plextrac works well enough, it’s really obvious how it’s not really designed for that use case with how obtuse managing users is.”
  • Pricing vs. utilization mismatch. “It’s way too expensive, and we weren’t even using a quarter of the features we were paying for.”
  • Basics gated behind add-ons. PDF export template work reported as a paid service — “you are gonna have to pay extra money for them to make the template for you” — and the AI paraphrasing feature dismissed as “a joke.”
  • Adoption inertia making it worse, not better. “Honestly, it kind of sucks. And I see 80% of pentest shops using it right now. Scares the crap out of me.”

None of that is a rival vendor’s landing page. It’s public criticism from paying customers on a forum PlexTrac’s own team monitors — the official PlexTrac account replied in the thread offering to connect.

The Brinqa acquisition doesn’t create the shift toward enterprise exposure management. It ratifies a shift the customer base was already documenting.

What Acquisitions Typically Change, and When

Nothing breaks on day one. Acquisitions play out on a predictable clock, and knowing it tells you when to ask what.

Timeframe What typically shifts
0–3 months Nothing visible. Messaging changes, product doesn’t.
3–9 months Roadmap re-prioritization. Engineering resources follow the acquirer’s ICP.
6–12 months Support and CS reorganization. New account manager, merged ticket queues, revised SLAs.
9–18 months Packaging changes. Standalone product becomes a module or a tier.
12–24 months Infrastructure consolidation. Data location, sub-processors, and DPAs get revisited.
At renewal Pricing. Always at renewal, rarely mid-term.

These are patterns from vendor management generally, not predictions about this specific PlexTrac acquisition. Use them to time your questions, not to panic.

Seven Questions to Send Your PlexTrac Account Manager

Send these in writing, before your renewal conversation rather than during it. A written answer you can reference later is worth ten reassuring phone calls.

1. Will PlexTrac remain available as a standalone purchase, and for how long? “Standalone for now” is not an answer. “Standalone through at least [date]” is.

2. What are the specific roadmap commitments for consultancy and MSSP features over the next 24 months? Ask for named features with dates. Client portal, whitelabel, multi-tenant separation, report template engine. If the answer is a paragraph about continued commitment to the offensive security community, you have your answer.

3. What is the renewal pricing, and can you lock it? Enterprise platform pricing and pentest tooling pricing are different animals. If PlexTrac gets bundled into a Unified Exposure Management SKU, per-seat consultancy pricing may not survive the repackaging.

4. Where will our data live after infrastructure consolidation, and who becomes a sub-processor? If you’re an EU or UK firm, this is not a nice-to-have question. Your DPA, your data residency commitments, and your clients’ own contractual obligations all sit downstream of the answer. Ask for updated sub-processor lists and a commitment to notice periods before any change.

5. Will our findings data feed Brinqa’s data layer or train any AI models? The announcement is explicit that PlexTrac-generated exploit and remediation results flow into Brinqa’s Cyber Risk Graph and sharpen its AI agents. Get clarity, in writing, on what that means for client data from your engagements — especially under NDA-bound consulting agreements.

6. What exactly can we export, in what format, and will that remain true for the life of the contract? Findings, evidence, attachments, WriteupsDB entries, report templates, user and role configuration, API configurations. Ask whether the export is complete or lossy.

7. Who owns our account after integration, and what are the SLAs? Named contacts, response times, escalation path. Support consolidation is one of the earliest post-acquisition changes and one of the least announced.

Export Your PlexTrac Data This Month, Regardless

This is standard vendor hygiene after any acquisition, and it costs you an afternoon.

Pull a full export and store it somewhere your team controls — not on the platform you’re evaluating risk against. At minimum:

  • All project data: findings, evidence, screenshots, attachments
  • Your reusable finding library (WriteupsDB content)
  • Report templates and executive summary templates
  • Methodology and checklist content
  • User, team, and role configuration
  • Documentation of any custom API integrations, even where they can’t be exported as files

Do this even if you’re renewing. Especially if you’re renewing. An archive you never use costs nothing; an archive you needed and didn’t take costs a quarter.

Evaluating PlexTrac Alternatives: What Switching Actually Costs

Here’s where most competitor blog posts get dishonest, so let’s not.

Migrating a reporting platform is real work. Template rebuilds, finding library reconstruction, integration rewiring, retraining a team that has muscle memory in the old UI. Most vendors will tell you to budget two to four weeks of part-time effort for a team of five to ten. That’s an honest number for most of the market.

It’s also the part we deliberately took off your plate. With PentestPad, you send us your existing DOCX report template and our team rebuilds it inside the platform for you, at no cost. Your first report out of the new system looks like your reports always have — same cover, same typography, same section structure, same client-facing polish. Template engineering is a service we run, not homework we assign.

The rest of the practical differences, briefly and checkably:

  • Public, per-seat pricing. Our pricing page has numbers on it. No “contact sales” gate, no annual lock required to see a figure.
  • EU-hosted, GDPR, ISO 27001 certified — with US cloud hosting too. We’re a European company subject to European privacy law, with actual certification rather than a trust-centre page about intentions. If your clients need data to sit stateside, we also have a US presence and can host in US cloud.
  • Cloud or fully self-hosted — including self-hosted AI. Run the AI assistant against a model inside your own network so client data never crosses your perimeter. That matters more now than it did a week ago.
  • Built for client delivery. Whitelabeled client portal, custom domain, remediation tracking, retest requests. Your brand, not ours.
  • DOCX, PDF and XLSX in and out. Import from 20+ tools. Round-trip without reformatting marathons.

If you want the wider landscape rather than our pitch, we wrote an honest comparison of the 2026 pentest reporting tools that covers PlexTrac, Dradis, Cyver Core, GhostWriter, Pwndoc and others, including where each one struggles.

The Fair Question: What If PentestPad Gets Acquired?

You should ask us this. Any vendor telling you their corporate future is guaranteed is selling something.

What we can give you is structure rather than promises:

  • You can self-host. Deploy PentestPad on your own infrastructure, including air-gapped. A vendor’s corporate event does not reach into your data centre.
  • Your data comes out whole. DOCX, PDF, XLSX, and API export. We designed migration in, which means we also designed migration out. A platform that makes it easy to arrive is a platform that can’t hold you hostage to stay.
  • We’re an EU entity under EU law. Whatever changes, GDPR obligations and your DPA don’t evaporate.

That’s an architectural answer, not a contractual one — and architectural answers are the only kind that survive a change of ownership.

What to Do This Week

  1. Run a full export from PlexTrac and store it on infrastructure you control.
  2. Send the seven questions to your account manager, in writing, before renewal season.
  3. Check your renewal date. Your leverage exists in the 60 days before it and nowhere else.
  4. Get four things in writing if you renew: pricing lock, roadmap commitments for consultancy features, export availability at current terms, and SLA continuity.
  5. If you’re evaluating alternatives, book a demo and send us your current report template. We’ll rebuild it live and you can judge the output rather than the sales deck.

Frequently Asked Questions

Who acquired PlexTrac?

Brinqa, an Austin, Texas-based exposure management company, acquired PlexTrac. The PlexTrac acquisition was announced on August 19, 2026, and financial terms were not disclosed.

When was PlexTrac acquired?

PlexTrac was acquired on August 19, 2026. Brinqa and PlexTrac announced the deal jointly from Austin, Texas and Boise, Idaho.

How much did Brinqa pay for PlexTrac?

The financial terms of the PlexTrac acquisition were not disclosed. PlexTrac had previously raised approximately $82M in venture funding, including a $70M Series B led by Insight Partners in February 2022.

Why did Brinqa acquire PlexTrac?

Brinqa’s stated reason is to close the CTEM (Continuous Threat Exposure Management) loop. Brinqa’s platform identifies and prioritizes exposures; PlexTrac adds offensive security validation, so customers can verify that a vulnerability was genuinely exploitable before remediation and genuinely fixed after it, rather than trusting a closed ticket.

Does the PlexTrac acquisition change the product immediately?

No. Acquisitions rarely change products quickly. The typical pattern is roadmap re-prioritization within 3 to 9 months, support reorganization within 6 to 12 months, packaging and product-line changes across 12 to 24 months, and pricing changes at renewal. The immediate change is organizational: who sets the roadmap, and which customer that roadmap serves.

What does the PlexTrac acquisition mean for consultancies and MSSPs?

Consultancies should expect to become a secondary segment. Brinqa sells to enterprise CISOs running exposure management programs, not to firms delivering client-facing pentest reports. Features like whitelabeling, multi-tenant client separation, and custom report templates now compete for engineering resources against enterprise CTEM priorities. Ask your account manager for written roadmap commitments on those specific features before renewing.

Will my data move now that PlexTrac has been acquired?

Ask, and get the answer in writing. Infrastructure consolidation typically happens 12 to 24 months after an acquisition, and it’s the point at which data location, sub-processors, and DPA terms get revisited. EU and UK firms with data residency commitments to their own clients should request updated sub-processor lists and a change-notice commitment now rather than at renewal.

Can I export my data from PlexTrac?

Yes. Check PlexTrac’s current export documentation for supported formats and completeness. At minimum, archive project data, evidence and attachments, your reusable finding library, report templates, methodology content, and user and role configuration. Store the archive on infrastructure you control.

What are the best PlexTrac alternatives in 2026?

For consultancies and MSSPs, PentestPad is the closest replacement for what PlexTrac originally was: client-facing pentest delivery with a whitelabeled portal, flexible DOCX templates, AI-assisted finding writing, public per-seat pricing, EU hosting, GDPR compliance and ISO 27001 certification, in cloud or fully self-hosted deployments. Dradis and Cyver Core are also credible commercial options, and GhostWriter and Pwndoc are the strongest open-source choices if you have the engineering capacity to run them. Our 2026 comparison covers all of them, including where each falls short.

Is it worth switching pentest reporting platforms because of the PlexTrac acquisition?

Not on its own, and not mid-contract. The realistic decision point is renewal. Use the time before it to get written answers on roadmap, pricing, data handling and support — then decide with information rather than reflex. If the answers are vague, that’s information too.


Thinking about what comes next? Start a free trial or book a demo and send us your existing report template — we’ll rebuild it inside PentestPad and show you what your first report would look like before you commit to anything.

Date

24. August, 2026

Tags

PlexTrac acquisition, PlexTrac acquired, PlexTrac Brinqa, PlexTrac alternative, pentest reporting tool, pentest reporting software, vendor risk, CTEM, pentest platform

Audit-Ready Cybersecurity: The Tools You Need to Prove It
Insights

23. June, 2025

Audit-Ready Cybersecurity: The Tools You Need to Prove It

Best Pentest Reporting Tools & Software in 2026: An Honest Comparison
Insights

14. April, 2026

Best Pentest Reporting Tools & Software in 2026: An Honest Comparison

Penetration Test Report Template + Free Download
Insights

5. June, 2025

Penetration Test Report Template + Free Download

Let's get you started

Create your account with PentestPad now, a tool developed by pentesters for pentesters.

logo-cta