Vendor lineage
Qualys
Delivered security scanning as a service in 2000, before anybody had a word for that.
Qualys was founded in 1999 by Philippe Langlois and Gilles Samoun, incorporated in Delaware at the end of that December, with Langlois as chief technology officer and Samoun as chief executive. Philippe Courtot invested in 1999 and became chief executive and chairman in March 2001, and it is his tenure the company is usually remembered for. Some sources describe Courtot as a founder; the majority record him as the early investor who then ran it for twenty years, and that is the account used here.
QualysGuard launched in 2000, and the decision that made it distinctive was not what it scanned but how it arrived. Competitors sold software you installed. Qualys sold a subscription to a service, at a time when software as a service barely existed as a phrase - and the argument for it was specific rather than fashionable: vulnerability data ages badly. A scanner is only as good as its knowledge of what to look for, and installed software is exactly as current as its last update, which in most organisations is not very. A service updated centrally is current for everyone at once.
That is the same argument this timeline shows repeatedly, arriving for a fifth time. IronPort made it about email sender reputation in 2002, Zscaler about web traffic in 2007, Cloudflare about the web in 2009, CrowdStrike about endpoint behaviour in 2013. Qualys made it about vulnerability knowledge in 2000, which makes it the earliest instance on this page. The idea that a centrally operated platform beats locally installed software because it is never stale was worked out in this segment first.
And it completes a trio here on a different axis. Tenable, Rapid7 and Qualys compete in the same market and the other two entries contrast them on open source - one closed a project to fund itself, one bought a project and kept it open. Qualys differs on something else entirely: it never shipped software to be run by the customer at all. Three companies, three strategies, three answers to what a security vendor actually sells.
Philippe Courtot's career before Qualys is worth its own paragraph. In 1988 he founded cc:Mail, took it to roughly forty per cent of the email platform market, and sold it to Lotus in 1991. In 1993 he became chief executive of Verity, taking it public in 1995. He then led Signio through its acquisition by VeriSign. Qualys was his fifth chief executive role, and he ran it for two decades.
He also spent that time on work with no commercial return attached: helping found the Cloud Security Alliance in 2008, starting the Trustworthy Internet Movement and the CSO Interchange, and serving as a trustee of the Internet Society. He stepped down in March 2021 for health reasons and died on 5 June that year, aged 76.
The company went public in 2012 and reported revenue of $669M for 2025 with around 2,625 staff. The product argument has moved where every vendor in this segment moved, from finding everything to ranking what matters, because the constraint stopped being detection a long time ago and became the fact that nobody can patch it all.
Founding stories
Qualys
Incorporated at the end of December 1999 with Langlois as chief technology officer and Samoun as chief executive. QualysGuard followed in 2000, and the distinguishing decision was delivery rather than detection: the scanner was a service you subscribed to, at a time when security software arrived on a disc and lived in your rack.
The timeline
- Incorporated
In Delaware, in the last days of the year.
- QualysGuard
Vulnerability scanning delivered from the vendor's infrastructure - software as a service before the term was in general use, and years before anybody would buy security that way without argument.
- The Cloud Security Alliance
Philippe Courtot, chief executive from 2001, was among its founders - part of a pattern of work with no direct commercial return attached.
- NASDAQ listing
Listed as QLYS.
- Scale
Revenue of $669M with around 2,625 staff, and recognition as a leader in both Gartner's exposure assessment quadrant and IDC's exposure management assessment.
Flagship products and solutions
- VMDRVulnerability Management, Detection and Response: scanning, prioritisation and patch deployment in one platform behind a single agent - the consolidation argument made concrete.
- Qualys Cloud AgentA lightweight agent reporting continuously, which changes assessment from something scheduled into something ambient.
- TruRiskThe prioritisation layer, scoring findings by exploitability and asset importance rather than by severity alone.
- TotalCloudCloud posture and workload coverage, and the fastest-growing part of the portfolio by practitioner mindshare.
- Policy ComplianceThe deepest compliance reporting in the category by most accounts - PCI, HIPAA and the rest - which is why the platform is often bought by organisations whose driver is audit rather than risk.
Key innovations
- Security as a subscription, in 2000Persuading organisations to let scan data leave their premises took years of argument, and the argument is now so settled that the difficulty is hard to remember. Everything in the category is delivered this way today.
- Patching inside the scannerFinding a vulnerability and fixing it had historically been separate products bought by separate teams. Putting deployment in the same platform addresses the actual failure, which is not discovery but the gap between discovery and remediation.
- Aggregate visibility as a defensive assetOne vendor scanning many estates sees which vulnerabilities are being exploited in the field before any single customer would. The install base improves the product for everyone in it.
- Research published rather than heldThe Threat Research Unit's work has been recognised by the field's own awards, including for remote code execution research - the kind of output that has no direct revenue attached and builds the credibility that does.
Main markets
Enterprise and heavily regulated sectors, with compliance depth as a distinguishing reason to buy. Priced per asset, quoted around two hundred dollars per asset per year before negotiation.
It competes with Tenable and Rapid7, both here, and with cloud-native posture vendors on the TotalCloud front.
Analyst standing
- A 2025 Gartner Magic Quadrant Leader for exposure assessment platforms and a leader in IDC's exposure management assessment, with its cloud and vulnerability products separately recognised in industry awards.
- As with its two competitors, the reposition toward exposure management is incomplete across the whole category, and buyers still decide on scan coverage and risk scoring rather than on the platform layer above them.
- Wikipedia: Qualys - founders Philippe Langlois and Gilles Samoun, Courtot investing in 1999 and becoming CEO and chair in 2001, QualysGuard in 2000 as one of the first entrants in vulnerability management, and 2025 revenue
- Qualys announcement of Courtot's death - cc:Mail founded 1988 and sold to Lotus in 1991 at ~40% market share, Verity CEO from 1993 with a 1995 IPO, Signio through to the VeriSign acquisition, the Cloud Security Alliance in 2008, the Trustworthy Internet Movement, the CSO Interchange, Internet Society trusteeship, and his death on 5 June 2021 aged 76
- Wikipedia: Philippe Courtot - born 26 August 1944 in France, a five-time chief executive who led two companies to IPO
- Company history - Delaware incorporation on 30 December 1999, QualysGuard Vulnerability Management launched 2000, and the SaaS model as unusual for a security vendor at the time
- Ownership history - $28.4M raised across two rounds including a $20M Series B in April 2001 with Bessemer Venture Partners, and Courtot stepping down in March 2021 for health reasons