About ThreatCanary

Built by people who have attacked systems, secured public platforms and scaled enterprise technology.

ThreatCanary exists because attackers do not work from disconnected scanner queues. They follow relationships across exposed assets, APIs, identities and trust boundaries. We built one governed system that can do the same—and prove every conclusion with evidence.

What this covers

Security products should earn trust with evidence—not adjectives.

ThreatCanary was shaped by three disciplines that rarely meet in one product team: offensive research, high-assurance security engineering and enterprise technology delivery.

01

The problem we refused to accept

  • Conventional scanners are valuable for hygiene, but a known check and a severity score do not explain whether an attacker can reach what matters.
  • Point-in-time penetration tests provide depth, then begin ageing the moment the engagement ends.
  • Attackers combine small weaknesses across systems. Defenders deserve a platform that reasons across the same connected environment.
02

Research that becomes capability

  • ThreatCanary follows emerging techniques across languages, ecosystems and practitioner communities instead of waiting for them to become commodity signatures.
  • Candidate methods are interpreted and reproduced under controlled conditions before they are trusted.
  • Validated research becomes governed, reusable capability with provenance, scope and operating constraints attached.
03

Autonomy with hard boundaries

  • AI can decide what to investigate next inside authorised scope; it cannot turn an unproven hypothesis into a customer finding.
  • Scope, approvals, evidence capture and reproducibility are product architecture—not policy text added afterwards.
  • The result is a smaller set of defensible findings with clear impact, ownership and remediation priority.
04

Built for real operating environments

  • The team has led security work across government, financial services, cloud-native platforms, assurance and enterprise technology delivery.
  • Findings must make sense to the analyst reproducing them, the engineer fixing them and the executive accountable for the risk.
  • Every layer is designed to move from discovery to validated action without losing context or control.
Leadership

Three disciplines behind one operating model.

ThreatCanary combines original offensive research, security leadership in high-consequence environments and the experience required to deliver technology at enterprise scale.

Matt Flannery, Chief Executive Officer of ThreatCanary
Chief Executive Officer · Security engineering and assurance

Matt Flannery

Matt is a hands-on security leader who has built offensive security, threat intelligence, application-security and DevSecOps functions across NSW Government and Big Four consulting. Before ThreatCanary, he founded and exited a DevSecOps consultancy, led EY’s Oceania DevSecOps practice and served as an elected technical lead in CNCF TAG Security. He turns attacker reality into security systems that engineers can operate and executives can defend.

  • Built Service NSW’s Red Team and Threat Intelligence function, leading offensive security, adversary simulation, vulnerability management and exposure-management programs.
  • Established EY’s Oceania DevSecOps practice and delivered security architecture, secure-software and cloud programs across government, banking and critical infrastructure.
  • Founded and exited Ayenem, founded Kubernetes Community Days Australia and was elected Technical Lead of CNCF TAG Security.
Andrew Horton, Chief Technology Officer of ThreatCanary
Chief Technology Officer · Offensive research and product engineering

Andrew Horton

Andrew is a security researcher and engineering leader with nearly two decades of experience turning attacker techniques into useful tools. He leads ThreatCanary’s offensive methodology, research automation and technical product direction.

  • Created open-source security tools including WhatWeb and URLCrazy, distributed through Kali Linux and used by practitioners globally.
  • Led security and engineering work across banking, cryptocurrency payments and large-scale internet platforms.
  • Co-authors ThreatCanary research into prompt injection, AI sandbox security and novel attack techniques.
Marco Delgado, Chairman of ThreatCanary
Chairman · Enterprise technology and industry leadership

Marco Delgado

Marco is ThreatCanary’s Chairman and an enterprise technology founder whose work spans networking, cyber security, managed services, IoT, digital twins and agentic AI. He brings the governance, customer, delivery and commercialisation perspective required to turn ambitious security technology into an enterprise platform.

  • Founded and scaled Outcomex and 365mesh across enterprise technology, security, IoT and AI.
  • Led teams recognised repeatedly for Cisco ANZ security and innovation outcomes.
  • Brings experience connecting product strategy, channel delivery and measurable customer outcomes.