Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →PortSwigger, the UK company behind Burp Suite, announced a $112 million external investment from Brighton Park Capital on June 27, 2024. It was announced as a growth investment—not a publicly disclosed acquisition. PortSwigger said the financing would fund product development, research, community initiatives, hiring and international expansion while founder Dafydd Stuttard remained CEO.
What the $112 million transaction actually was
Brighton Park Capital was the sole disclosed investor. The announcement described the transaction as PortSwigger’s first-ever external investment after roughly 16 years of bootstrapped operation. It did not disclose a valuation, ownership percentage, board rights, liquidation preferences, debt components or whether any existing shareholders sold shares.
Accordingly, the available evidence does not support saying that Brighton Park bought PortSwigger, acquired a controlling stake or paid $112 million for the company. The amount refers to financing, not revenue, profit or valuation. The primary announcement is available from Brighton Park Capital and PortSwigger.
The company behind Burp Suite
PortSwigger was founded in 2008 by Dafydd Stuttard, known in the security community as “Daf.” The company is based in Knutsford, England, and grew from tools Stuttard developed while working as a web-security consultant. He is also associated with The Web Application Hacker’s Handbook, a widely used application-security reference.
#1 Best Overall
That history matters because this was not a conventional venture-backed startup raising rescue capital. TechCrunch reported that PortSwigger was profitable and cash-flow positive; Stuttard said the objective was to add expertise and accelerate the business as application security became larger and more complex. Those profitability claims were reported by TechCrunch, rather than independently audited in the available coverage.
What Burp Suite does
Burp Suite is broader than a conventional vulnerability scanner. It lets security professionals intercept and modify HTTP and HTTPS traffic, replay requests, manipulate parameters, test authentication and authorization, validate vulnerabilities and automate selected portions of web-application testing.
| Offering | Primary role | Typical users |
|---|---|---|
| Burp Suite Professional | Human-led testing of web applications and APIs, including interception, manual exploitation and repeatable testing workflows | Penetration testers, consultants, bug-bounty researchers and security teams |
| Burp Suite Enterprise | Automated dynamic application-security testing for web applications and APIs, with recurring enterprise workflows | Organizations operating larger application portfolios and centralized security programs |
| Burp Suite Community Edition | Learning and more limited manual testing | Students, new practitioners and people beginning application-security work |
| Web Security Academy | Free educational material and hands-on web-security labs | Students, aspiring testers and teams building application-security skills |
Professional and Enterprise therefore address different workflows: expert-guided assessment on one side and repeatable automated testing on the other. Current feature limits, licensing and packaging can change, so buyers should check PortSwigger’s live product pages.
How large was PortSwigger when it took the investment?
PortSwigger and contemporary reports described a substantial international user base. These are announcement-era company figures, not independently audited totals, and the populations should not be added together.
Recommended Free Tools
- More than 20,000 organizations using PortSwigger products.
- Customers in approximately 170 countries.
- About 80,000 individuals using the paid enterprise edition, according to figures reported by TechCrunch.
- More than 1,000 enterprises and organizations using Burp Suite Enterprise.
- More than 1 million users of Web Security Academy.
Reported customers included Microsoft, Amazon, FedEx and Salesforce. SecurityWeek also reported approximately 20,000 customers but did not independently verify the figures; its coverage is at SecurityWeek.
Why accept outside capital after years of bootstrapping?
A profitable company can raise institutional money to move faster, not because it is running out of cash. PortSwigger said the investment would support:
- Product and engineering development, including enterprise capabilities.
- Security research and vulnerability knowledge.
- Free education and community initiatives.
- Hiring in product, engineering, customer success, sales and marketing.
- International expansion and a stronger presence in the United States.
Stuttard’s explanation, as reported by TechCrunch, was that PortSwigger wanted additional expertise while the application-security market expanded and became more complicated. The deal thus appears designed to accelerate an established business while preserving its founder-led identity, rather than to finance a turnaround.
Why Brighton Park Capital was interested
Brighton Park’s disclosed thesis centers on application-security software and PortSwigger’s two principal commercial products, Burp Suite Professional and Enterprise. Several features make the company attractive to a growth investor:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
- A strong reputation among practitioners who influence enterprise tooling decisions.
- A large installed base spanning individual testers and organizations.
- Increasing demand for testing as companies deploy more web applications and APIs.
- A path from practitioner adoption to centrally managed, automated enterprise programs.
- A combination of software, research, training and community reach.
- A long operating history and reported profitability under founder leadership.
In practical terms, a security professional may begin with hands-on Burp Suite work, while a larger employer can add recurring automated testing. That progression gives PortSwigger a route from individual product loyalty to broader organizational adoption.
Rank #4
What it could mean for Burp Suite customers
No price increase, licensing withdrawal, layoff or immediate product change was established in the 2024 announcement. Customers should nevertheless watch several areas where new capital could have an effect:
- Potential benefits: faster releases, stronger enterprise administration and integrations, more automation, expanded research, better support coverage and additional training resources.
- Possible trade-offs: greater emphasis on enterprise sales, pressure to increase monetization, changes to free programs or a stronger push toward automated scanning.
Those are scenarios, not announced outcomes. The investment itself does not prove that Burp Suite will become more effective, more expensive or less useful than competing tools.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why the deal matters to application security
The financing highlights the commercial value of tooling that connects manual penetration testing with DevSecOps and automated dynamic testing. Burp Suite Professional is built around skilled human testers who inspect and manipulate requests; Burp Suite Enterprise addresses repeatable scanning of applications and APIs. Treating both as the same kind of “scanner” misses the distinction.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
It also shows how free education and community adoption can support a commercial security platform. Web Security Academy can introduce practitioners to PortSwigger’s methods and tools, while enterprise products address organizations that need governance, recurring coverage and centralized workflows.
What remains unknown
The public announcement does not establish:
- PortSwigger’s valuation before or after the financing.
- Brighton Park’s ownership percentage.
- Whether the investment was entirely new capital, included secondary share sales, or used another structure.
- Board representation, voting rights or other governance terms.
- Whether Dafydd Stuttard retained majority voting control.
A later government market-analysis document appears to identify a different investor, “Five Arrows,” but that conflicts with the contemporaneous announcement and reporting. The primary announcement and June 2024 coverage identify Brighton Park Capital.
How to interpret the headline
The phrase “swallows $112 million” can imply that PortSwigger paid out $112 million or that an investor consumed the company. The more accurate reading is that PortSwigger secured $112 million of external financing from Brighton Park Capital. It was a major capital event for a mature, founder-led security-software company, but not a publicly announced full sale.
Bottom line
PortSwigger’s first disclosed outside investment marked institutional backing for a profitable business that had spent about 16 years bootstrapping Burp Suite. The money was earmarked for product development, research, community work, hiring and international growth. Until valuation, ownership and governance terms are disclosed, the transaction should be understood as growth financing—not proof that Brighton Park acquired PortSwigger or that customer pricing and licensing have changed.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




