runsonwhat

OffSec's tech stack

What does OffSec use?

OffSec (offensive-security.com) uses at least 28 tools we can see from public records, including Google Workspace for email and documents, HubSpot for sales, Zendesk for customer support and Google Tag Manager for analytics. Last checked .

Founded
2005
LinkedIn
Company page
Tools found
28
Categories
13
Layers
5 of 5
Last checked
Oct 2026

OffSec's stack, layer by layer

Each tool links to the other companies we've found using it. The label says what kind of public trace gave it away.

Edge & Hosting

2 tools, where the bytes are served from

Application

3 tools, what the product is built with

Data & Observability

1 tool, what they measure and store

OffSec tech stack FAQ

What tools does OffSec use?

We've found 28 tools at OffSec (offensive-security.com). Edge & Hosting: Cloudflare and Gandi. Application: Anthropic, Tailwind CSS and Astro. Data & Observability: Google Tag Manager. Go-to-market: WordPress, HubSpot and Yoast SEO. Company Ops: Google Workspace, SendGrid and Apple Business. Last checked October 3, 2026.

What CRM does OffSec use?

OffSec uses HubSpot, Salesforce and ZoomInfo for sales and CRM, among 4 tools in this category. We found HubSpot through email records and website code.

What email provider does OffSec use?

OffSec uses Google Workspace and Apple Business for email and documents. We found Google Workspace through email records.

What does OffSec use for customer support?

OffSec uses Zendesk and Discord for customer support. We found Zendesk through email records.

What analytics tools does OffSec use?

OffSec uses Google Tag Manager for analytics. We found Google Tag Manager through website code.

What CMS does OffSec use?

OffSec uses WordPress and Yoast SEO for its website. We found WordPress through website code.

Does OffSec use Cloudflare?

Yes. We found Cloudflare at OffSec through custom domain. Cloudflare is used by 147,753 companies we track.

How does runsonwhat know what OffSec uses?

We read public traces only: OffSec's DNS and email records, certificate logs, the code its website loads, and published subprocessor lists. A tool is listed only when a direct record backs it up. DNS is rechecked weekly and the website monthly.

We read public traces only: DNS and email records, certificate logs, website code and published subprocessor lists. A tool is listed when a direct record backs it up, and dropped when a recheck no longer finds it. Is this your company? See how to opt out.