SecurityPal Scales to $110M Valuation from Queens Basement to Salesforce Tower
SecurityPal founder and CEO Pukar Hamal has turned a $21 million seed raise into a $110 million cloud‑based security SaaS, now headquartered on the 37th floor of San Francisco’s Salesforce Tower and serving 1,000 global enterprises. The company’s Kathmandu Security Operations Command Center employs over 210 Nepali engineers, underscoring a new model for vertical SaaS scaling.
Why It Matters
SecurityPal’s story illustrates how vertical SaaS founders can combine product‑led growth with a strategically placed services arm to accelerate ARR and improve net retention. By locating a high‑skill security ops center in Kathmandu, Hamal demonstrates a scalable model for leveraging cost‑effective talent without sacrificing service quality—a playbook that other security‑focused SaaS firms may emulate. The company’s rapid ascent to a $110 million valuation also signals strong investor appetite for niche compliance platforms that solve enterprise‑level friction points, especially as large organizations tighten security governance.
The Kathmandu SOCC further underscores the growing importance of hybrid delivery models in SaaS. As cloud providers and enterprise buyers demand faster, more reliable security assessments, firms that can blend automated questionnaire tooling with human‑driven threat analysis gain a competitive moat. Hamal’s approach could catalyze a wave of similar offshore‑centric security operations, reshaping the geography of SaaS talent and expanding the definition of what constitutes a “global” SaaS company.
Key Points
- SecurityPal valued at $110 million after $21 million VC raise
- Founded by Nepal‑born CEO Pukar Hamal, now headquartered in Salesforce Tower
- Serves 1,000 enterprise clients, including Fortune 500 firms
- Operates a 210‑person Security Operations Command Center in Kathmandu
- Net retention above 120 % and gross margins in the high‑70s
Analysis
SecurityPal’s ascent is a textbook case of a vertical SaaS firm turning a painful sales loss into a defensible product category. The platform’s focus on automating security questionnaires addresses a clear pain point for enterprise buyers, creating a sticky revenue stream that drives expansion revenue—a hallmark of mature SaaS businesses. By coupling this product with a near‑shore security ops center, Hamal has effectively built a hybrid model that mitigates the classic SaaS talent bottleneck while preserving high‑margin service delivery.
Historically, security compliance tools have been fragmented, with large incumbents offering point solutions that lack integration. SecurityPal’s end‑to‑end approach—spanning questionnaire automation, continuous compliance monitoring, and human‑driven threat analysis—creates a network effect: as more enterprises adopt the platform, the data pool improves AI‑driven risk scoring, further enhancing the product’s value proposition. This virtuous cycle can drive higher net retention and lower churn, positioning the company for a potential IPO or strategic acquisition.
From a market dynamics perspective, the Kathmandu SOCC signals a shift in how SaaS firms think about global delivery. Rather than treating offshore teams as pure cost centers, Hamal frames the operation as a technology entrepreneurship hub, which could attract top talent and foster innovation in regions traditionally seen as labor pools. If other SaaS verticals replicate this model, we may see a rebalancing of SaaS talent geography, with emerging markets playing a larger role in product development and service delivery, ultimately expanding the global SaaS talent pipeline.
