CrowdSec’s pitch deck centers on the transition from a local security engine to a global 'Internet Trust Broker.' By utilizing an open-source model, the company aims to achieve massive adoption, which in turn fuels a data-driven reputation system. The deck outlines a clear four-step path to adoption, starting with becoming a de-facto Intrusion Detection and Prevention System (IDPS) and culminating in business-grade SaaS services. A standout feature is the concept of a 'Massively Multiplayer Firewall,' where users contribute sightings of malicious IPs to a collective blocklist. While the deck…
Key takeaways
- The company defines its core identity as an 'Internet Trust Broker' built on open-source behavior and reputation analysis (Slide 1).
- CrowdSec follows a four-stage adoption roadmap: becoming a de-facto IDPS, reaching thousands of users, providing SaaS, and achieving 'Internet Trust Broker' status (Slide 4).
- The product is described as a 'Massively Multiplayer Firewall' that connects to various data sources like Syslog, Cloudtrails, and Kafka (Slide 7).
- The technical workflow involves four steps: connecting data, detecting aggressions via behavior scenarios, applying remedies, and sharing sightings back to the community (Slide 7).
- A data-driven philosophy is emphasized through automated content marketing, community sonar, and daily/weekly KPI tracking (Slide 10).
- The funding roadmap shows a progression from a 200K€ Founders Round to a 700K€ SMR Round, leading to the current 4M€ Seeding Round (Slide 16).
- Monetization is specifically tied to API calls, where the network effect is leveraged to screen new IPs and provide 'Pass' or 'Act' replies (Slide 19).
- The deck explicitly mentions a future target of a 15M€ Series A following the successful execution of the seed round (Slide 16).
The Vision: Becoming the Internet's Trust Broker
CrowdSec enters the cybersecurity market with a distinctively community-centric pitch. Rather than positioning themselves as a traditional vendor of proprietary software, they lead with the 'Safer Together' mantra. The first slide establishes their four pillars: Open Source, Behavior, Reputation, and Security Engine. By labeling themselves an 'Internet Trust Broker,' they signal an ambition that goes beyond simple firewalling; they want to be the central authority on which IP addresses can be trusted across the global web.
Slide 1: Title and Identity
The cover slide is heavy on branding, featuring their llama mascots and a cityscape background overlaid with a network of icons (5G, AI, search, etc.). The core value proposition is summarized in four white pills: Open Source, Behavior, & Reputation, and Security Engine. The subtitle 'Internet Trust Broker' is the most important element here, as it defines their long-term market category.
Slide 4: The Path to Adoption
This slide outlines a linear four-step growth strategy. Step 1 is to 'become the de-facto IDPS' (Intrusion Detection and Prevention System). Step 2 focuses on user acquisition, aiming for 'thousands of users.' Step 3 introduces the business model: 'provide business grade SaaS services.' Finally, Step 4 represents the endgame: 'Grow to the de-facto status of Internet Trust Broker.' This roadmap is useful for investors because it separates the community-building phase from the monetization phase, showing a clear logical progression.
Slide 7: The Massively Multiplayer Firewall
Slide 7 is the technical heart of the deck. It breaks down the 'real innovation' into a four-step process. First, 'Connect the data source you want,' listing Syslog, journald, Cloudtrails, SIEM, ELK, and Kafka as examples. Second, 'Behavior scenarios detect aggressions,' distinguishing between 'yours' (local), 'ours' (CrowdSec provided), and 'community' scenarios. Third, 'Remedy where and how you want,' showing icons for blocking, 2FA, and other mitigations. Fourth, 'Share your own sightings,' which feeds 'Bad IP' data back into the CrowdSec Blocklists. This creates a virtuous cycle where the product improves as the user base grows.
Slide 10: Data-Driven Philosophy
This slide illustrates the company's internal operational loop. It shows a flow starting with 'Content marketing' leading to a 'Reactive user’s community sonar.' This data then feeds into 'Daily / weekly KPIs' and 'Budget / Tech adjustments,' which in turn informs further content marketing. The slide emphasizes that this process is 'FULLY AUTOMATED,' suggesting a highly efficient, low-touch growth engine driven by community engagement and data analysis rather than a massive sales force.
Slide 13: Practical Results
Slide 13 serves as a transition marker. It simply states 'Practical results FROM THE PAST THREE MONTHS.' While the specific data slides following this were not included in the provided set, the presence of this divider indicates that the deck relies on recent traction and real-world performance metrics to validate the 'Massively Multiplayer' concept. In a seed round, showing that the engine actually works in the wild is critical.
Slide 16: The Funding Roadmap
This slide provides a transparent look at the company's capital history and future needs. It labels the current opportunity as an 'UNSOLICITED FUNDING ROUND.' The timeline shows: 01 Founders Round at 200K€, 02 SMR Round at 700K€, 03 Seeding Round at 4M€ (the current focus), and 04 (Serie-A) at a projected 15M€. This clear laddering of rounds helps investors understand the valuation trajectory and the scale of ambition the founders have for the company.
Slide 19: Monetizing the Network Effect
The final slide in the set focuses on the 'API calls' revenue model. It uses a triangular diagram to explain the flow: 1) Unknown IPs make queries, 2) The first packet sent by a new IP is screened by the CrowdSec API (online or offline), and 3) The API replies with 'Pass' or 'Act.' This slide explicitly connects the community data collection (the network effect) to a tangible unit of value (the API call), providing a clear answer to how an open-source tool generates venture-scale returns.
What Works in This Deck
Clear Categorization: The term 'Internet Trust Broker' is a strong piece of positioning. It moves the conversation away from being 'just another firewall' and toward being a foundational layer of internet infrastructure. Visualizing the Loop: Slide 7 does an excellent job of explaining a complex technical process in a way that highlights the unique value of the community. It makes the 'massively multiplayer' aspect feel like a tangible technical advantage rather than just a marketing slogan. Honest Roadmap: The funding slide (Slide 16) is refreshing in its clarity. It doesn't hide previous rounds and sets a clear expectation for what the next milestone (Series A) looks like.
What is Omitted
Team Background: None of the provided slides detail the founders' backgrounds or technical expertise. In a seed-stage cybersecurity play, the 'why us' is just as important as the 'what.' Competitive Landscape: The deck focuses heavily on CrowdSec's internal logic but doesn't explicitly map out how they displace incumbents like Cloudflare or traditional hardware firewall vendors. Unit Economics: While the API monetization model is explained, there are no figures on Cost Per Acquisition (CPA), Lifetime Value (LTV), or specific pricing tiers for the 'business grade SaaS services' mentioned on Slide 4. Churn and Retention: For an open-source project, community health metrics (GitHub stars, active contributors, installation persistence) are vital, but they are not present in this selection of slides.
Founder's Playbook: Lessons to Copy
The 'Path to Adoption' Slide: Founders building open-source or bottom-up SaaS should emulate Slide 4. It manages investor expectations by showing that monetization (Step 3) follows adoption (Step 2). It justifies why the company might be focusing on 'thousands of users' before 'millions in revenue.' The Virtuous Cycle: If your product has a network effect, you must visualize it as clearly as Slide 7 does. Showing how a single user's contribution (a 'sighting') benefits the entire network is the best way to prove defensibility. Naming the Innovation: 'Massively Multiplayer Firewall' is a sticky, memorable phrase. It uses a familiar concept (gaming) to explain a technical shift (distributed threat intelligence). Founders should look for similar metaphors to make their technical 'moats' understandable to non-technical investors.
Frequently asked questions
- What is CrowdSec's primary product offering?
- CrowdSec offers an open-source security engine that acts as a modern, community-driven version of a firewall or IDPS. According to slide 7, it connects to diverse data sources (like Syslog and SIEM), uses behavior scenarios to detect threats, and allows users to share 'sightings' of malicious IPs to build a collective blocklist.
- How does CrowdSec plan to make money?
- The deck highlights a SaaS-based monetization strategy focused on API calls. Slide 19 explains that they 'monetize the network effect' by charging for API queries that screen new IPs. When a new IP attempts to connect, the API provides a reputation-based response, advising the user to either 'Pass' or 'Act' based on community data.
- What is the 'Massively Multiplayer Firewall' mentioned in the deck?
- This is a metaphor for their crowdsourced security model. As shown on slide 7, it means that instead of every server defending itself in isolation, every instance of CrowdSec shares threat intelligence. When one user detects an attack, the 'sightings' are shared, protecting the entire community from that specific 'Bad IP'.
- What are the historical funding stages for CrowdSec?
- Slide 16 outlines a clear financial history: a Founders Round of 200K€, followed by an 'SMR Round' of 700K€. The current deck is for a 4M€ 'Seeding Round,' with a projected 15M€ Series A as the next major milestone in their growth trajectory.
- What data sources does the CrowdSec engine support?
- Slide 7 lists several compatible data sources for the engine, including Syslog, journald, Cloudtrails, SIEM, ELK, and Kafka. This versatility allows the engine to integrate into various existing tech stacks to monitor for aggressive behaviors and malicious activity.
