Qualys
A U.S. cybersecurity company providing cloud-based vulnerability management, compliance, asset inventory, and risk operations software.
Last updated August 26, 2026
Overview
Qualys is a US publicly traded company that provides cloud-based cybersecurity and compliance solutions. Its platform covers vulnerability management, asset discovery, compliance, cloud and container security, web application security, endpoint capabilities, network visibility, and enterprise cyber risk operations. The company was founded in 1999 and went public on NASDAQ in 2012, with headquarters in the United States.
History
Qualys emerged during the growth of hosted security services in the late 1990s. Philippe Courtot invested in the company in 1999 and became its chief executive and board chair in 2001. At a time when many organizations relied on manually operated security appliances and periodic consulting assessments, Qualys pursued a software-as-a-service model intended to make vulnerability discovery more automated and repeatable. The company's first major offering was QualysGuard, launched in 2000. It could examine corporate local-area networks for vulnerabilities and help customers identify patches or other corrective measures. This initial vulnerability-management focus established the company's core operating model: collect technical data from an organization's environment, compare that information with known security and compliance requirements, and present findings through a hosted service. Qualys later broadened the platform with compliance assessment, malware detection, web-application scanning, and related security functions. During the 2000s, Qualys also developed scanning appliances and additional service components for enterprise environments. Its products were used by organizations that needed recurring security audits, vulnerability prioritization, and evidence for regulatory or internal compliance programs. The company built relationships with telecommunications providers, managed-security firms, technology companies, and consulting organizations, giving partners the ability to incorporate Qualys capabilities into broader services. Qualys completed its initial public offering on Nasdaq on September 28, 2012, trading under QLYS. The offering generated reported net proceeds of $87.5 million. Becoming a public company gave Qualys additional visibility in the expanding cloud-security market while preserving its focus on subscription software and recurring enterprise use cases. A significant product and architectural transition took place in 2015. Qualys launched its cloud platform together with a lightweight Cloud Agent. The platform was intended to provide more continuous visibility into infrastructure and applications, while the agent collected information from systems without requiring a full traditional scanning cycle for every assessment. This approach helped Qualys extend from point-in-time vulnerability scans toward ongoing asset inventory, configuration assessment, endpoint monitoring, and compliance management. Qualys subsequently expanded its coverage across cloud workloads, containers, web applications, endpoints, and networks. Its Network Passive Sensor added a network-observation layer that could identify devices and services from traffic metadata and transmit the resulting asset information to the Qualys Cloud Platform. This complemented active scanning and agents by helping security teams find assets that might not be fully registered or directly accessible. The company continued to develop partnerships and platform integrations. In 2021, Qualys and Red Hat worked to bring Cloud Agent capabilities to Red Hat Enterprise Linux CoreOS and Red Hat OpenShift, with container-security functionality intended to cover the OpenShift stack. In the same year, Courtot resigned as CEO for health reasons after leading Qualys for about twenty years. Sumedh Thakar, a long-serving company executive, became president and CEO. Under Thakar, Qualys increasingly emphasized risk prioritization and consolidation. Enterprise TruRisk Management, released in 2023, was designed to aggregate risk indicators from Qualys and other security tools, producing a more unified view of exposure. The strategy was to connect technical findings with the business importance of affected assets so that customers could focus remediation on the weaknesses most likely to affect critical operations. In 2024, Qualys announced trial access intended to help organizations evaluate this approach and introduced a Risk Operations Center associated with the platform. Qualys also expanded its channel infrastructure in 2024 through a managed-security-services partner portal. The portal provided partners with operational visibility over customer accounts, licenses, and user roles. In 2025, the Qualys Threat Research Unit received additional industry recognition for its vulnerability research. In 2026, the company announced Agent Val, an agentic-AI capability for exploit validation and autonomous remediation. These developments illustrate the brand's continuing movement from traditional vulnerability scanning toward continuous exposure management, automated prioritization, and machine-assisted remediation. Today, Qualys is an active public cybersecurity company serving enterprises, government organizations, service providers, and other institutions internationally. Its business spans vulnerability management, asset discovery, compliance, cloud and container security, web-application security, endpoint capabilities, network visibility, and enterprise cyber-risk operations.
- 2026Agent Val announced
Qualys announced an agentic-AI tool for exploit validation and autonomous remediation.
- 2024Risk Operations Center introduced
Qualys introduced a real-time Risk Operations Center connected with Enterprise TruRisk Management.
- 2023Enterprise TruRisk Management launches
Qualys released a platform for consolidating cyber-risk signals and prioritizing remediation according to business impact.
- 2021Leadership transition
Sumedh Thakar became president and CEO after Philippe Courtot stepped down for health reasons.
- 2015Cloud Platform and Cloud Agent introduced
Qualys introduced a cloud platform and lightweight agent to support continuous monitoring of systems, applications, and compliance conditions.
- 2012Qualys goes public on Nasdaq
Qualys began trading on Nasdaq under QLYS on September 28, 2012, with reported net IPO proceeds of $87.5 million.
- 2001Philippe Courtot becomes CEO and board chair
Courtot assumed the company's chief executive and board-chair roles.
- 2000QualysGuard launches
Qualys launched QualysGuard, an early cloud-delivered vulnerability-management service capable of scanning networks and identifying remediation options.
- 1999Philippe Courtot invests in Qualys
Philippe Courtot invested in the company, preceding his appointment as chief executive and board chair.
Products and positioning
Enterprise-focused cloud cybersecurity and compliance platform emphasizing continuous asset visibility, automated vulnerability assessment, and risk-based remediation.
Qualys Cloud PlatformCloud cybersecurity platform2015
The Qualys Cloud Platform is the company's central hosted environment for collecting, analyzing, and presenting security and compliance data. It brings together information from scanners, agents, passive sensors, and integrations across endpoints, servers, cloud workloads, containers, networks, and applications. The platform supports asset inventory, vulnerability assessment, configuration analysis, compliance reporting, and risk prioritization. Its cloud architecture is intended to provide a common data layer across multiple security functions rather than requiring customers to operate separate appliances for each use case.
Qualys Vulnerability ManagementVulnerability management2000
Qualys vulnerability-management capabilities identify weaknesses in systems, applications, and network-connected assets. The product family evolved from QualysGuard and supports scanning, vulnerability assessment, prioritization, remediation tracking, and reporting. It is intended for security teams that need recurring or continuous visibility into exposure across enterprise environments. Findings can be connected with asset context and compliance information so that organizations can distinguish urgent weaknesses on important systems from lower-priority issues.
Qualys Cloud AgentEndpoint and workload agent2015
The lightweight Cloud Agent collects security, configuration, inventory, and compliance information from endpoints and workloads and sends it to the Qualys Cloud Platform. It was introduced to complement active scanning and provide more continuous visibility. The agent is used across supported operating systems and environments, including infrastructure associated with cloud and container platforms. Its role is to reduce blind spots and shorten the time between a system change and the availability of updated security information.
Enterprise TruRisk ManagementCyber-risk management2023
Enterprise TruRisk Management aggregates cyber-risk signals and helps organizations score, rank, and manage exposure. Qualys positioned the product as a way to combine information from multiple security tools, including sources outside the Qualys portfolio, into a more unified view. Its purpose is to connect technical vulnerabilities and configuration issues with asset importance and business impact, allowing security and information-technology teams to concentrate remediation on the risks that matter most.
Qualys Network Passive SensorNetwork discovery and monitoring
The Network Passive Sensor observes network traffic and extracts metadata about devices, services, and other elements present in an environment. It sends the resulting information to the Qualys Cloud Platform for analysis and asset visibility. Passive monitoring complements active scanners and installed agents by helping identify systems that may be unmanaged, difficult to scan, or absent from official inventories. The capability is particularly relevant to organizations seeking a broader view of unknown or changing network assets.
Qualys Web Application ScanningWeb application security
Web Application Scanning extends Qualys's assessment model to websites and web applications. It is designed to identify application-layer security issues and provide findings for investigation and remediation. The offering sits alongside network and host assessment capabilities, allowing customers to address vulnerabilities in externally accessible applications as well as the infrastructure that supports them.
Agent ValAI-assisted security operations2026
Agent Val was announced as an agentic-AI capability for exploit validation and autonomous remediation. The stated use case is to help determine whether identified weaknesses can be exploited and to support automated corrective action. Detailed product scope, availability, and commercial terms were not specified in the supplied reference material.
Flagship businesses
- Qualys Cloud Platform
- Qualys Cloud Agent
- Enterprise TruRisk Management
- Qualys Vulnerability Management
- Qualys Network Passive Sensor
- Qualys Web Application Scanning
Marketing campaigns
- 2024Enterprise TruRisk Management free 30-day access
United Kingdom · International
Qualys offered free 30-day access to Enterprise TruRisk Management to help organizations evaluate risk prioritization and support vulnerability-patching practices associated with guidance from the U.K. National Cyber Security Centre.
Outcome. Promoted trial adoption of the company's risk-management platform; broader commercial results were not specified.
Brand decisions
- 2024Investment in partner operationsStrategy
Managed-security-service providers require centralized visibility into customer accounts, licenses, and permissions.
What changed. Qualys launched an MSSP portal within its global partner program.
Aftermath. The portal was intended to improve partner efficiency and strengthen distribution through managed-security providers.
- 2023Enterprise TruRisk Management launchProduct launch
Enterprise security teams increasingly needed to aggregate findings from multiple products and prioritize them according to business impact.
What changed. Qualys released Enterprise TruRisk Management as a risk-scoring and prioritization framework capable of incorporating signals from different security tools.
Aftermath. The product reinforced Qualys's strategy of positioning its platform around enterprise risk operations rather than isolated vulnerability findings.
- 2021Expansion into Red Hat cloud-native environmentsStrategy
Customers operating OpenShift and RHEL CoreOS required security visibility across cloud-native infrastructure and container stacks.
What changed. Qualys partnered with Red Hat to support Cloud Agent and container-security capabilities in RHEL CoreOS and OpenShift environments.
Aftermath. The partnership extended Qualys coverage into Red Hat's cloud-native ecosystem.
- 2015Shift toward continuous cloud-based monitoringStrategy
Periodic vulnerability scanning was being supplemented by demand for continuous visibility across endpoints, applications, and cloud infrastructure.
What changed. Qualys launched its cloud platform and lightweight Cloud Agent to collect and analyze security data continuously.
Aftermath. The move broadened Qualys from a vulnerability-scanning provider into a wider cloud-delivered security and compliance platform.
Leadership
| Name | Title | Tenure |
|---|---|---|
| Sumedh Thakar | President and Chief Executive Officer | 2021– |
| Philippe Courtot | Former Chief Executive Officer and Board Chairformer | 2001–2021 |
Recent events
- 2026Qualys debuts Agent Val for exploit validation and remediation
Qualys announced Agent Val, described as an agentic-AI tool for validating exploitability and supporting autonomous remediation.
Product launch - 2025Qualys Threat Research Unit receives two additional Pwnie Awards
The research unit was recognized in the Epic Achievement and Best Remote Code Execution categories.
Other - 2024Qualys announces free trial access to Enterprise TruRisk Management
The company announced a free 30-day access program intended to help organizations evaluate risk-management capabilities and support vulnerability-patching practices aligned with U.K. guidance.
CampaignProduct launch - 2024Qualys introduces its Risk Operations Center
Qualys presented a real-time Risk Operations Center connected with Enterprise TruRisk Management at its annual conference in San Diego.
Product launch - 2024Qualys launches a managed-security-services partner portal
The portal was designed to give managed-service partners improved visibility into customer accounts, licenses, and user permissions while streamlining partner operations.
Product launch - 2023Qualys releases Enterprise TruRisk Management
Qualys introduced Enterprise TruRisk Management to combine cyber-risk signals and provide organizations with a framework for scoring and prioritizing technology risk.
Product launch - 2021Philippe Courtot steps down as CEO and Sumedh Thakar succeeds him
Philippe Courtot resigned as chief executive for health reasons after approximately two decades in the role. Sumedh Thakar became president and CEO.
Leadership change - 2021Qualys partners with Red Hat for OpenShift and RHEL CoreOS security
The partnership extended Qualys Cloud Agent and container-security capabilities to Red Hat Enterprise Linux CoreOS and Red Hat OpenShift environments.
OtherProduct launch - 2021Qualys Threat Research Unit receives two Pwnie Awards
Qualys's research team received awards recognizing work on a privilege-escalation vulnerability and security research considered insufficiently recognized by the industry.
Other - 2015Qualys launches its cloud platform and lightweight Cloud Agent
Qualys introduced a cloud-based platform and lightweight agent intended to support continuous monitoring of infrastructure, endpoints, applications, and compliance posture.
Product launch
Sources
Cite this profile: Cite the canonical profile. /brand-wiki/qualys · Editorial policy · How profiles are compiled