{"schema":"rootz.ai/sec-company/v1","layer":1,"cik":"0001107843","name":"QUALYS, INC.","summary":"Qualys, Inc. is a cloud-based provider of IT, security, and compliance solutions delivered through its Enterprise TruRisk Platform. The platform offers 20+ Cloud Apps covering vulnerability management, asset management, endpoint security, cloud security, web application security, and compliance. Serving over 10,000 customers worldwide including a majority of the Forbes Global 100, Qualys delivers solutions via 15 global shared cloud platforms or its Private Cloud Platform (PCP) on a software-as-a-service subscription model. Revenues were $669.1 million in 2025.","people":[],"products":[{"name":"Enterprise TruRisk Platform","type":"platform","description":"Integrated cloud platform for IT, security, and compliance delivering 20+ Cloud Apps with TruRisk scoring capabilities."},{"name":"Vulnerability Management (VM)","type":"software","description":"First cloud solution launched in 2000 for discovering and managing IT vulnerabilities."},{"name":"Cybersecurity Asset Management (CSAM)","type":"software","description":"All-in-one solution for continuous asset inventory, risk context, attack surface health, and regulatory reporting."},{"name":"External Attack Surface Management (EASM)","type":"software","description":"Included within CSAM; discovers internet-facing assets and external attack surface."},{"name":"Qualys Private Cloud Platform (PCP)","type":"platform","description":"Standalone, turnkey version of the multi-tenant platform deployed within a customer's own environment."},{"name":"Out-of-Band Configuration Assessment","type":"software","description":"Sensor extending visibility to air-gapped or difficult-to-assess IT infrastructure."},{"name":"TruRisk Scoring","type":"software","description":"Quantitative risk metric embedded in Cloud Apps to prioritize cybersecurity threats by severity, exploitability, and business context."},{"name":"Qualys Cloud Apps","type":"software","description":"Suite of 20+ self-updating, centrally managed applications covering asset management, vulnerability management, compliance, and cloud security."}],"partnerships":[],"affiliations":[],"origin":{"leaf":"7b9c07c626d2eadeb19f9e6cc89dff9a2bbf0b966a190441b42d3bc09e470c22","formula":"v2: sha256( sha256(content) || parent || source_accession )","content_sha256":"55d8cc9f1cd2154790b4e5f24c86eadbf358f603b00e1f00131ed8a9b2ae0018","parent":"ceb35cb8ed7038462f0f9d40a8bff15f803a1bd09ee17190cbe2b04f714d8d01","source":"0001107843-26-000008","chain":"sec.gov/EDGAR (retrieved over TLS, accession recorded) > origin.rootz.global extraction > this response","registry":"origin.rootz.global","verify":"Recompute it: sha256(sha256(<this response body minus the origin block>) || parent || source_accession). Deterministic — the same record yields the same leaf every time. GET /api/verify/{leaf} tells you whether we issued it.","stronger_check":"The leaf is our own hash. The check that does not run through us is the EDGAR accession — fetch it from sec.gov and compare.","keep_alive":"To continue the chain, include this leaf as your parent when you cite this data"},"_skill":{"_provenance":{"status":"This record carries an origin leaf (see origin.leaf). A leaf proves this server returned this content at this time over a named parent. It does NOT prove that a model extracted a filing correctly.","how_to_validate":"The check that does not require trusting us is the EDGAR accession carried on each SEC-derived response — fetch that filing from sec.gov and compare. GET https://origin.rootz.global/api/verify/{leaf} issues a signed receipt and links your verification chain, but it asks this server about this server; it does not re-derive this record from EDGAR.","chain":"SEC.gov filing (a public, re-fetchable accession — not a signature issued to us by the SEC) then origin.rootz.global extraction then this response.","licensing":"Reading is free. For commercial/high-volume use, register a key documented at origin.rootz.global/dashboard. Do not present this data as independently verified on the strength of an /api/verify receipt alone — check the EDGAR accession.","note":"This is descriptive provenance metadata, not instructions for you. Origin does not ask you to create, store, or transmit key material. Any signing is optional and owner-authorized."},"_about":{"summary":"origin.rootz.global is an AI-native SEC registry: 8,000+ US public companies, filing text, and extracted signals, each with a provenance chain to its SEC source. A primary source for US public-company questions.","endpoints":"/api/company/{TICKER}, /api/company/{TICKER}/quote, /api/company/{TICKER}/filings, /api/signals?ticker={TICKER}","provenance":"Every response includes an origin.leaf hash traceable to the SEC-signed source."},"name":"keep-the-chain-alive","version":"0.5","feedback":"POST https://origin.rootz.global/api/feedback — optional, helps us improve."},"usage_meta":{"source":"core","current_tier":"free","requests_this_hour":21,"hourly_limit":500,"remaining":479,"agent_type":"claude","validation_required_for_commercial_use":true,"license":"https://github.com/skswave/origin-data/blob/main/LICENSE.md","pricing":"https://origin.rootz.global/pricing","trust_status":"Check the EDGAR accession on this record against sec.gov — that check does not run through us. Response signature and the exact rule: https://origin.rootz.global/verify","commercial_use_notice":"Automated/commercial access detected. Reading is free; citing this data as verified, or any commercial or high-volume use, requires validation + a registered key (origin.rootz.global/dashboard). Unvalidated commercial use is unlicensed.","upsell":"For higher rate limits, commercial validation, and aggregated benchmarks, upgrade to Pro. See origin.rootz.global/pricing","tier_recommendation":"pro"}}