CrowdSec presents a compelling case for a 'Waze-like' approach to cybersecurity, moving away from static IP reputation lists toward a dynamic, crowd-sourced behavior assessment engine. The deck, dated June 2020, seeks a 300,000 Euro 'Smart Money' round to transition from an open-source tool to a monetized SaaS platform. The core value proposition relies on the network effect: as more users join the free open-source community, the precision of the security data increases, creating a proprietary database of aggressive traffic. While the deck is visually simple, it clearly articulates a 'Why Now…
Key takeaways
- The company is seeking approximately 300,000 Euros in a 'Smart Money' round to build community and strengthen their SaaS offering (Slide 29).
- CrowdSec positions itself as a 'Waze' for security, where increased user adoption directly correlates to higher data precision (Slide 9).
- The business model relies on an API-first approach to monetize the network effect by screening unknown IPs in real-time (Slide 17).
- A specific target conversion rate of 3.5% is identified, supported by a five-stage funnel from communication to retention (Slide 25).
- The technical solution is described as a 'decoupled detection & remediation' engine that uses behavior and reputation assessment (Slide 5).
- The 'Why Now' slide argues that previous attempts by companies like Symantec and Cisco failed because they were not crowd-based or open source (Slide 21).
- Adoption rate is cited as the 'sole KPI' during the current phase of the company's growth (Slide 29).
- The deck omits a dedicated team slide, though contact emails for the CEO and COO are provided on the final slide (Slide 33).
CrowdSec: A Collaborative Approach to Mass-Scale Hacking
The CrowdSec 'Smart Money Round' deck, dated June 18, 2020, represents a strategic pivot point for an open-source project moving toward a commercial SaaS model. With 33 slides in total (9 provided for this teardown), the deck focuses heavily on the power of the network effect and the technical superiority of a crowd-sourced security engine over traditional, siloed reputation lists.
Slide 1: Title and Vision
The cover slide introduces the company name, CrowdSec, alongside the tagline 'Safer Together.' It establishes four pillars for the brand: Open Source, Collaborative, Dynamic, and Security engine. The visual theme uses a mountain landscape, perhaps symbolizing the scale of the challenge or the 'peak' of security technology. The date indicates this deck was used during the early stages of the COVID-19 pandemic, a time of increased digital activity and cyber threats.
Slide 5: The Next Generation Solution
This slide breaks down the technical components of the CrowdSec offering. It highlights five key features: Real Time processing, Behavior assessment, Reputation assessment, Decoupled detection & remediation, and Crowd intel sharing. By 'decoupling' detection from remediation, the company suggests a modular architecture that can adapt to various environments without being tied to a specific firewall or blocking tool.
Slide 9: The Power of the Crowd
CrowdSec uses a 'Waze' analogy to explain their competitive advantage. The slide explicitly states that 'more users means better precision.' It argues that previous IP reputation systems failed because they were not crowd-based. The strategic choice to remain Open Source is framed here not just as a philosophy, but as a growth lever to 'enlarge our crowd' and improve the underlying data product.
Slide 13: One Stone, Ten Birds
This slide uses a flow diagram to show how the system qualifies traffic. An 'unknown' user (represented by a masked icon and a professional icon) passes through the CrowdSec brain. The system identifies various threats—symbolized by icons for bots, exploits, and phishing—and then qualifies, discards, and notifies the central database of aggressive traffic. This illustrates the data-loop that feeds their reputation engine.
Slide 17: API and Monetization
The business model is clarified here. The slide titled 'API: Monetizing the Network effect' shows a three-step process. 1) Unknown IPs make queries. 2) The first packet is screened by the CrowdSec API. 3) The API replies with a 'Pass' or 'Act' instruction. This indicates that while the tool may be free to use, the real-time access to the global 'crowd' intelligence is the primary value driver for monetization.
Slide 21: The 'Why Now' and Competitive Landscape
This is a critical slide for investors. It addresses why previous attempts by giants like Symantec and Cisco (Talos) missed the mark. CrowdSec identifies three factors: Size (accuracy comes from numbers), Versatility (API-first vs. email-focused), and Community (Open Source vs. self-financed). They position themselves as the successor to Fail2ban, aiming to reach a much broader audience than just mail administrators.
Slide 25: Conversion Strategy
CrowdSec sets a specific target of a 3.5% conversion rate. The slide outlines a funnel inside a human head graphic: Communication (getting known), Easy deployment (onboarding), Ignite the need (premium incentives), Frictionless premium (easy payment/VAT handling), and Always offer more (retention). This shows a sophisticated understanding of SaaS growth mechanics beyond just the technical security aspect.
Slide 29: The Ask and Use of Funds
The company seeks approximately 300,000 Euros. The use of funds is split into three categories: Building the community (noting that adoption rate is the 'sole KPI' currently), Strengthening the SaaS (preparing for monetization), and Ramping up signal collection. The slide includes pie charts suggesting the allocation of resources, though specific percentages are not labeled. They explicitly state this round is to prepare for a 'Serie A.'
Slide 33: Conclusion and Contact
The final slide reiterates the core belief: 'Only the crowd can defeat mass scale hacking.' It provides contact information for the CEO (Philippe) and the COO (Laurent). Notably, this deck lacks a traditional 'Team' slide in the provided selection, which would usually detail the founders' backgrounds in cybersecurity to validate their ability to build such a complex engine.
What CrowdSec Does Well
The deck excels at explaining the Network Effect . By comparing themselves to Waze, they make a complex cybersecurity concept immediately understandable to a generalist investor. They also show a clear path to monetization through an API-first strategy, which is highly scalable. The inclusion of a specific conversion rate target (3.5%) on Slide 25 demonstrates that the founders are thinking about the business as a data-driven SaaS company, not just an open-source project.
What is Missing from the Deck
Team Background: While contact emails are provided, there is no slide detailing the founders' previous exits, technical expertise, or history in the security sector. · Unit Economics: The deck mentions a 3.5% conversion rate but does not provide projected Average Revenue Per User (ARPU) or Customer Acquisition Cost (CAC). · Detailed Financials: Beyond the 300,000 Euro ask, there are no projections for revenue growth or burn rate over the next 18-24 months. · Market Size (TAM/SAM/SOM): The deck assumes the investor understands the massive scale of the cybersecurity market but does not quantify the specific segment CrowdSec is targeting.
Founder Takeaways: What to Copy
Use Analogies for Complex Tech: If you are building a platform that relies on user data, the 'Waze for X' analogy is incredibly effective for explaining why your product gets better as it grows. Be Specific About KPIs: Stating that 'Adoption rate is our sole KPI' (Slide 29) shows focus. Investors prefer a team that knows exactly what metric matters most at their current stage. Visualize the Funnel: Slide 25 is a great example of how to visualize a go-to-market strategy. It moves beyond 'we will use social media' and looks at the actual friction points in a user's journey from free to paid.
Frequently asked questions
- What is the primary problem CrowdSec is solving?
- CrowdSec addresses the failure of traditional, centralized IP reputation systems. According to Slide 21, previous attempts by large firms like Symantec and Cisco were limited because they were self-financed, closed-source, and lacked the scale of a distributed community. CrowdSec solves this by using an open-source security engine that allows a global crowd to identify and share data on aggressive traffic in real-time.
- How does CrowdSec plan to make money?
- The monetization strategy is centered on an API-first SaaS model. Slide 17 illustrates a process where unknown IPs making queries are screened by the CrowdSec API. The API then provides a 'Pass' or 'Act' response based on the collective intelligence of the network. Slide 25 further details a 'frictionless premium' conversion path to move free open-source users into paying customers.
- What is the significance of the 'Smart Money' round?
- The round, totaling roughly 300,000 Euros, is intended to bridge the gap to a Series A. Slide 29 specifies that the funds will be used to build the community (their primary KPI), strengthen the SaaS infrastructure for monetization, and ramp up signal collection to increase the network effect value.
- What is the 'Waze' comparison mentioned in the deck?
- On Slide 9, the founders compare their security network to the navigation app Waze. The logic is that a security system's precision is dependent on the volume of its users. By being open source, CrowdSec aims to 'enlarge the crowd,' ensuring that the behavior and reputation data they collect is more accurate than closed, smaller networks.
- Who are the competitors identified by CrowdSec?
- Slide 21 lists several 'attempts' at IP reputation systems that the company views as predecessors or competitors, including Symantec, Talos (Cisco), Gossip, Repuscore, and IP group REP. They also credit Fail2ban for 'paving the way' but suggest it failed to reach a larger crowd beyond mail administrators.
