PlexTrac is a cybersecurity platform originally built around penetration testing reporting and workflow management that expanded to help organizations track remediation and verify that identified security issues have actually been resolved. Following its acquisition by Brinqa, the combined platform brings exposure prioritization, offensive security testing, remediation tracking, and verification into a more unified system. Pulse 2.0 interviewed PlexTrac Founder Dan DeCloss to learn more.
Dan DeCloss’ Background And PlexTrac’s Founding

When asked about his background and what spurred PlexTrac’s founding, DeCloss shared:
I started my security career in the Department of Defense, where I narrowed my focus to pentesting and application security. From there I moved into the private sector, hacking into networks, devices, websites, etc. to find vulnerabilities before attackers did.
I loved the puzzle of trying to break into software. It was almost like a chess game between me and the engineers who built it. What I loathed, though, was writing the pentest report afterward.
It consumed a lot of time, but the part that really irked me was coming back six months or a year later and rewriting substantially the same report for the same client. So, I used my computer science background to write software to solve my own problem.
It worked well, and peer feedback was that this was something they genuinely needed. At that point I felt there was a market for it, and PlexTrac was founded.

How Practitioner Experience Shaped The Product
When asked how his years as a cybersecurity practitioner influenced product decisions, DeCloss explained:
My background drove the user experience at the beginning. We would get comments all the time from prospects and customers that they could tell I had done their jobs before. The product made sense for the majority of workflows. This really helps with product decisions and features that drive to good outcomes for all.
It also allowed me to be opinionated about which feature requests we should prioritize. The most important balance in an early-stage product is building the product based on your vision for the long-term, versus the features that customers are paying money for right now. My background allowed us to thread that needle well.
Also, in this sector of cybersecurity, having the practitioner background helped with credibility. I can comfortably sit with a testing team and know within a few minutes if a workflow we designed is aligned to how they operate. This really helps to highlight how our solution fits their workflow and also which features will be more beneficial to them at the onset.
From Reporting To Verification
When asked how PlexTrac evolved from a pentesting reporting and workflow tool into a platform that can also confirm whether fixes worked, DeCloss said:
Having spent so much time in the industry, I knew that one of the most important steps is to actually get the work done in fixing the reported risks. The platform always had a status tracking capability from the beginning, to ensure every finding had a state that was visible throughout.
This filled an important gap around not just reporting issues, but being able to ensure they had ownership for remediation. It became a very popular feature ahead of its time regarding pentest findings specifically.
The industry caught up around the time it started describing security as a continuous cycle versus a project with an end date. This framed how we progressed to aid in the validation phase of the retest lifecycle.
(Or said another way, a ticket marked ‘closed’ is a claim someone made, but a retest is your evidence.)
We kept following customers toward that end goal of providing a great experience through the entire risk management lifecycle.

Screenshot
Why Verification Lagged Behind Discovery
When asked why cybersecurity verification has historically lagged behind finding vulnerabilities, DeCloss explained:
Finding things can be easier to sell, because you put a number on a dashboard the first week and there’s a warm feeling of productivity. It’s easy to identify potential issues via scanning and other techniques.
Verification requires a step to ensure the issue is valid, then another step to confirm it’s exploitable. That takes more effort and automation requires more advanced engineering. So the industry lagged for quite a while in the verification stage and hence why pentesting is such a crucial phase.
The team that finds an issue is rarely the one that fixes it, and it can be difficult to assign ownership to remediation.
The Brinqa Acquisition
When turning to the acquisition, DeCloss explained what Brinqa was acquiring and why the combination made sense:
Brinqa acquired the pentest reporting and management platform, our verification layer, and the practitioner community that comes with it.
Their roots were in exposure management, which is pulling together security weaknesses from across an environment and telling a customer what to fix first. The piece their customers kept asking for was proof that the fix worked, and building that credibly takes years and a roster of people who have done offensive security work for a living.
From our side, our customers were already within both worlds, where they were prioritizing in one system and verifying in another, then maintaining the connection between them by hand. Based on those use cases, this was a natural fit.
Both companies landed in the inaugural Gartner Magic Quadrant for Exposure Assessment Platforms, which told us that the category was homing in on full-featured solutions. Now we’re the only solution in that category to combine data and workflows across all sources of exposures.
A Single Exposure Management Platform
When asked what the combination means for customers that previously purchased prioritization and offensive testing separately, DeCloss said:
It helps with the consolidation story, for starters. You now have a single solution to service your entire exposure management program.
But the larger and most important change is having a single source of truth of what was found, tested, prioritized, fixed, and verified.
That history can otherwise live in pieces across systems that aren’t all that interoperable, which is cumbersome when you need immediate answers to questions around your risk posture. It’s also challenging reconstructing that story for external audits and compliance items.
With testing and prioritization in the same platform, those reports are generated at the click of a button.
Where AI Helps Security Teams
When asked where AI can provide the most value for security teams today and where expectations may be running ahead of the technology, DeCloss concluded:
It’s very good at the work around the work, like drafting a finding from technical notes and removing duplicates across overlapping tools. Those and other tasks take up practitioner time, but none require judgment about what an attacker would do next.
I think where the industry is ahead of itself is in any claim that AI is outright replacing security professionals. Figuring out a creative path into a system is still human work, and the modeling is only as useful as the data supporting it.
Most security data has never been verified by anyone, and there will always need to be a human in the loop regarding agentic pentesting and AI-generated attack paths.

