General information and education, not investment advice. The author is not a SEBI-registered adviser or research analyst. No recommendation, no promised returns. Markets carry risk including loss of capital. Figures may not be current. Always consult a SEBI-registered adviser.
1 — At a Glance
Quarterly sales of ₹19.78 crore against ₹9.76 crore a year ago. That is 103% growth, which is the kind of number that usually comes with an asterisk, and here the asterisk is that the company is a ₹1,029 crore SME-platform cybersecurity firm doing roughly ₹57 crore of annual revenue. Operating margin for the quarter came in at 48.18%. Net profit was ₹7.79 crore.
Then the paperwork gets interesting. On 24 July 2026 the board granted in-principle approval to acquire 100% of Safehouse Technologies Limited, Israel, for an amount not exceeding ₹1 crore. On the same morning it approved incorporating a new subsidiary, TAC Safehouse Limited, with proposed investment up to ₹4 crore — four times the price of the company being acquired into it. It also allotted 1,040 ESOP shares, realising ₹5,200.
Separately, the NSE wrote in on 22 July asking why the Q1 results weren’t signed by an authorised signatory and where the segment details were. The company replied that the chairperson attended by video, delegated signing authority, and that TAC operates in a single segment so segment reporting doesn’t apply.
Debtor days moved from 356 in FY24 to 119 in FY25 to 145 in FY26. Borrowings are ₹0.93 crore. Cash is ₹33.23 crore.
Somewhere in here there is a company that describes 10,000 customers across 100 countries, and a subsidiary that has filed an F-1 with the US SEC. We’ll get to the F-1.
2 — Introduction
TAC Infosec Ltd was incorporated in 2016 and listed on the NSE Emerge platform on 5 April 2024, having raised ₹2,999.38 lakh through an IPO of 28.29 lakh shares. Of that, ₹18.65 crore was allocated to human resources and product development, ₹7.44 crore to general corporate purposes, and ₹3.90 crore to issue expenses. As of the June 2026 quarter filing, ₹12.77 crore of the first bucket has been utilised, with no deviation reported.
The last twenty-four months have been busy in a way that small companies rarely are. In March 2024 it acquired TAC Security INC in the US. In September 2024 it completed the acquisition of CyberSandia, an American cybersecurity firm holding an exclusive contract to provide IT services in New Mexico, and set up TAC Cyber Security Consultancy LLC in the UAE. In October 2024 it announced a partnership with Google as an authorised lab for Mobile Apps Security Assessment under the App Defence Alliance.
Then the corporate actions started stacking. October 2025: a 1:1 bonus allotment of 1,04,79,600 shares. December 2025: subsidiary CyberScope Web3 Security Inc. publicly filed a Form F-1 with the SEC, having filed confidentially in August, and reserved the Nasdaq ticker ‘CYSC’. March 2026: a ₹1 crore ESOF licence order from a confidential Government of India data centre, revenue recognised across March 2026 to March 2027 at a stated 40% margin.
March 2026 also produced two departures. On 11 March the Company Secretary and Compliance Officer resigned with immediate effect. On 12 March the board approved immediate termination of SCS & Co LLP, citing misconduct or malpractice. In May 2026, Sanjiv Swarup resigned as independent director effective 7 May and Hector Hugo Balderas was appointed for a three-year term.
And in February 2026, an NFAC order deleted a ₹5,03,31,263 disallowance under Section 80-IAC, extinguishing a ₹77,36,010 demand.
US
Now live
US Stocks terminal is live
13,000+ US tickers · EDGAR fundamentals · screener and filings feed — the same terminal, for American markets.
Explore →
3 — Business Model: WTF Do They Even Do?
TACIL sells risk-based vulnerability management and assessment, cybersecurity quantification, and penetration testing, delivered SaaS-style to organisations of any size, in India and abroad.
The flagship is ESOF — Enterprise Security in One Framework — launched in 2018, which is less a product than a shelf. On it sit ESOF Appsec, ESOF VMP, ESOF VACA, ESOF PCI ASV and ESOF CRQ, covering vulnerability management for web and application data, compliance assessment, and cyber risk quantification, plus asset tiering, business unit regrouping, and a cyber score. Five acronyms and a scoreboard. If you have ever wondered what happens when a security engineer is handed a brand naming exercise, this is the artefact.
The penetration testing side is ethical hacking with paperwork: find the holes, write them up, align to GDPR and ISO 27001. The company is CREST-certified, which in this industry functions roughly the way a food licence does in a restaurant — nobody praises you for having it, everybody notices when you don’t.
The client list is bank-heavy and regulator-adjacent: HDFC, Bandhan Bank, BSE, National Payments Corporation of India, DSP Investment Managers, Motilal Oswal Financial Services, NSDL e-Governance. In September 2024 the company added 200 new customers across 32 countries, naming Microsoft, Gen Digital, Brother Industries, Sedric, Yext, Freshworks and Lenovo.
FY24 revenue was roughly 98% cyber security service income and 2% other income, which is about as single-segment as a business gets — a point the company made to the exchange in writing in July 2026.
Management now proposes to widen the shelf considerably. At the July 2026 investor meet, the framing was that “it’s not anymore enterprise security, it’s everyone’s security in one framework now,” with Safe House as the entry vehicle into consumer security, cited as having more