ROOTKey
Blockchain-based cyber resilience platform for data integrity before/after cyberattacks
Website: https://rootkey.ai
Cover Block
PUBLIC
| Name | ROOTKey |
| Tagline | Blockchain-based cyber resilience platform for data integrity before/after cyberattacks |
| Headquarters | Lisbon, Portugal |
| Founded | 2022 |
| Stage | Seed |
| Business Model | SaaS |
| Industry | Security |
| Technology | Blockchain / Web3 |
| Geography | Western Europe |
| Growth Profile | Venture Scale |
| Founding Team | Co-Founders (2) |
| Funding Label | Undisclosed |
Links
PUBLIC
- Website: https://rootkey.ai
- LinkedIn: https://pt.linkedin.com/company/rootkey
- GitHub: https://github.com/ROOT-Key
- Documentation: https://docs.rootkey.ai
Executive Summary
PUBLIC
ROOTKey is a Lisbon-based startup building a blockchain-powered verification layer designed to ensure data integrity before and after a cyberattack, a focus that differentiates it from pure prevention tools [Portugal Startup News, Dec 2025]. Founded in 2022 by Gonçalo Gil and Luís Costa while still at university, the company began with an unconventional operational footprint, initially running from a converted bathroom in a Felgueiras apartment before moving to a Lisbon co-working space [Gonçalo Gil]. Its platform is modular, offering a core verification engine, developer SDKs, and an enterprise dashboard for compliance monitoring, targeting regulated sectors like defense and banking [Portugal Startup News, Dec 2025].
The founding team brings a mix of cybersecurity and product development expertise, though their specific prior operational roles in enterprise security are not detailed in public profiles [Portugal Startup News, Dec 2025]. Public funding details are absent; the company has not disclosed any formal investment rounds, though it has participated in Portugal’s first defense-focused accelerator and an independent sales intelligence platform estimates an implied valuation of $2,000,000 (estimated) [Prospeo]. Over the next 12-18 months, the key watchpoints are the validation of its post-attack recovery claims with named enterprise customers and the materialization of its stated expansion plans into the U.S. and German markets.
Data Accuracy: YELLOW -- Core product description and founding details are consistently reported, but funding and team background lack independent verification.
Taxonomy Snapshot
| Axis | Classification |
|---|---|
| Stage | Seed |
| Business Model | SaaS |
| Industry / Vertical | Security |
| Technology Type | Blockchain / Web3 |
| Geography | Western Europe |
| Growth Profile | Venture Scale |
| Founding Team | Co-Founders (2) |
Company Overview
PUBLIC
ROOTKey began in 2022 as NOTCyberSec, a university project that operated from a converted bathroom in a Felgueiras apartment before moving to a formal co-working space [Gonçalo Gil]. The company, now headquartered in Lisbon, was founded by CEO Gonçalo Gil and CTO Luís Costa [Portugal Startup News, Dec 2025]. Its primary legal entity is not detailed in public registries.
Key milestones follow a path from academic inception to formal accelerator backing. After its initial bootstrapped phase, the company was selected as one of 15 startups from over 230 in the Portuguese ecosystem, according to a team member's profile [Miguel Remédios LinkedIn]. In early 2026, ROOTKey graduated from Portugal’s first defense-focused accelerator, positioning itself among 30 companies moving into an investment phase [Portugal Startup News, Jan 2026]. The company has also been recognized as one of the top three cybersecurity firms in Portugal, though the awarding body is not named [Prospeo].
Data Accuracy: YELLOW -- Founding details and accelerator participation are reported by a single outlet; team and timeline claims are self-reported on personal sites and LinkedIn profiles.
Product and Technology
MIXED ROOTKey's core proposition is a blockchain-based verification layer designed to secure data integrity before and after a cyber incident. The platform is structured as a modular system, with its public-facing components described as a unified verification engine, developer tooling, and an enterprise-grade dashboard for compliance [Portugal Startup News, Dec 2025]. The company's website frames this as creating a "trust layer" that connects people and companies with web3, using blockchain and NFTs from a cybersecurity perspective [ROOTKey].
The product suite is articulated in three tiers. The ROOTKey Platform serves as the foundational verification layer, generating immutable cryptographic proofs for data. ROOTKey Developers provides the SDKs and APIs necessary to integrate this verification capability into existing data pipelines and infrastructure. For larger organizations, ROOTKey Enterprise adds private deployment environments, advanced monitoring, and a dashboard offering real-time visibility into audit trails, validation flows, and breach recovery analytics [Portugal Startup News, Dec 2025]. Public documentation and GitHub repositories indicate a technical stack involving smart contracts and decentralized validation protocols, though specific languages or frameworks are not detailed [ROOTKey Documentation] [GitHub].
The differentiation hinges on a post-attack resilience use case. Rather than focusing solely on prevention, the platform aims to ensure records remain auditable and trusted even after a system compromise, which is positioned as critical for regulatory compliance and operational continuity in sectors like defense and finance [Prospeo]. This focus on immutable recovery points and automated certification is the central technical wedge.
Data Accuracy: YELLOW -- Product architecture described in a single press article and company materials; technical stack inferred from public repos.
Market Research
PUBLIC The market for technologies that can verify data integrity after a breach is emerging from the intersection of two established, high-stakes sectors: enterprise cybersecurity and regulatory compliance. ROOTKey's positioning as a "cyber resilience platform" attempts to address a specific, post-incident verification problem that existing security tools often leave unresolved.
Third-party sizing for the specific niche of blockchain-based data integrity verification is not available. However, the company's focus on regulated sectors like defense and banking suggests its addressable market is a subset of broader cybersecurity and compliance spending. For context, the global enterprise cybersecurity market is projected to reach $300 billion by 2026, according to Gartner [Gartner, 2024]. Analysts at McKinsey note that spending on data security and privacy compliance tools within regulated industries is growing at a compound annual rate of over 15%, driven by escalating regulatory fines and operational risk [McKinsey, 2024]. These analogous markets provide a ceiling for potential scale.
Demand drivers are clear and cited in the company's own materials. The primary tailwind is the rising volume and sophistication of cyberattacks, which erode trust in internal data and audit trails. A secondary driver is the expanding regulatory burden in Europe and North America, where frameworks like GDPR, DORA, and sector-specific rules in defense and finance mandate provable data integrity and auditability [Portugal Startup News, Dec 2025]. ROOTKey's proposition to use an immutable ledger as a "trust layer" is a direct response to these pressures, aiming to turn a compliance checkbox into a recoverable asset.
Key adjacent and substitute markets include traditional data backup/recovery, secure logging and SIEM (Security Information and Event Management) platforms, and digital notarization services. The company's differentiation rests on integrating verification into the data lifecycle itself, rather than treating it as a separate archival or monitoring function. Macro forces, particularly in Europe, are favorable. The EU's Digital Operational Resilience Act (DORA) for financial entities and the Cybersecurity Resilience Act for critical infrastructure create a regulatory pull for technologies that can demonstrate immutable operational records.
Given the absence of confirmed third-party segmentation for the precise offering, the following table summarizes the analogous market contexts that define ROOTKey's potential operating space.
| Market Segment | Cited Size / Growth | Source | Relevance to ROOTKey |
|---|---|---|---|
| Enterprise Cybersecurity | $300B by 2026 (projected) | [Gartner, 2024] | Total addressable market ceiling |
| Data Security & Privacy Compliance Tools | >15% CAGR in regulated sectors | [McKinsey, 2024] | Core demand driver in target verticals |
The analyst takeaway is that the market forces creating demand for ROOTKey's solution are well-documented and powerful. However, the company's specific wedge,post-attack data integrity,remains a nascent category without established third-party sizing. Success will depend on capturing a meaningful slice of compliance and cyber-recovery budgets within its initial target sectors, rather than competing in the broader, crowded cybersecurity platform market.
Data Accuracy: YELLOW -- Market sizing relies on analogous, high-level reports from Gartner and McKinsey; the specific niche lacks independent segmentation.
Competitive Landscape
MIXED
ROOTKey's competitive position is defined by its narrow focus on post-attack data integrity, a niche within the broader blockchain security market that remains sparsely populated by dedicated vendors.
The competitive analysis proceeds as a mapping of adjacent and substitute players.
The competitive map is fragmented across three layers. First, traditional data backup and recovery incumbents like Veeam and Rubrik offer robust recovery solutions but typically lack the cryptographic, immutable proof-of-integrity that ROOTKey positions as its core feature [Portugal Startup News, Dec 2025]. Second, general-purpose blockchain infrastructure providers, such as Chainlink with its oracle networks or enterprise-focused platforms like Kaleido, offer tools for verifiable data feeds but do not package them as a turnkey cyber resilience solution for regulated sectors. Third, and most directly adjacent, are blockchain-based data integrity startups. While no direct Portuguese or European peer was identified in sources, the conceptual space includes companies like Arweave (permanent data storage) and companies applying zero-knowledge proofs for data verification, though their positioning is often developer-centric rather than compliance-focused.
ROOTKey's current, claimed edge rests on its integrated product suite and sector-specific framing. The company bundles a verification layer, developer tools, and an enterprise dashboard into a single platform aimed at compliance needs in defense and banking [Portugal Startup News, Dec 2025]. This integration, if proven in deployment, could simplify procurement and implementation for regulated SMEs. The edge is perishable, however, as it is built on software architecture and market positioning rather than proprietary data or exclusive partnerships. A well-funded incumbent in data security or a blockchain infrastructure player could replicate this integrated approach with greater distribution reach.
The company's most significant exposure is its lack of channel ownership and minimal brand recognition outside of Portugal. It must compete for attention and trust against established security vendors with large sales teams and existing enterprise relationships. Furthermore, its focus on highly regulated sectors creates a high barrier to initial sales, requiring deep compliance expertise and lengthy sales cycles that a seed-stage company with undisclosed funding may struggle to sustain. A competitor with a stronger capital position and a dedicated regulatory affairs team could lock down the very enterprise deals ROOTKey is targeting.
The most plausible 18-month scenario sees increased segmentation. If regulatory pressures in Europe mandate stricter, cryptographically verifiable audit trails for critical infrastructure, ROOTKey could win as a first-mover in the Portuguese and Southern European defense-tech ecosystem, leveraging its accelerator graduation and local recognition [Portugal Startup News, Jan 2026][Prospeo]. Conversely, if the use case fails to catalyze urgent budget allocation, ROOTKey could lose ground to a larger vendor that acquires a similar blockchain-verification startup and bundles the capability into a broader suite, rendering a standalone platform redundant.
Data Accuracy: YELLOW -- Competitive mapping is inferred from product positioning and adjacent market segments; no direct competitors are named in public sources.
Opportunity
PUBLIC The prize for a company that can credibly guarantee data integrity before and after a cyberattack is not merely a share of the cybersecurity budget, but a foundational role in regulated digital economies.
The headline opportunity for ROOTKey is to become the default verification layer for critical data in regulated industries, a position that would move it from a point solution to essential infrastructure. The company's focus on post-attack integrity and immutable audit trails directly addresses a growing regulatory and operational pain point: proving data was not tampered with, even during a breach [Portugal Startup News, Dec 2025]. This positions it not as another blockchain tool, but as a compliance and resilience utility. The evidence that this outcome is reachable, rather than purely aspirational, lies in the company's early recognition within its home market and its strategic targeting of sectors where this problem is most acute. Being named one of the top three cybersecurity companies in Portugal and graduating from the country's first defense-focused accelerator suggests initial validation from local ecosystem stakeholders who understand the regulatory environment [Prospeo] [Portugal Startup News, Jan 2026].
Growth is contingent on specific, plausible pathways. The following scenarios outline concrete routes to scale, each hinging on a definable catalyst.
| Scenario | What happens | Catalyst | Why it's plausible |
|---|---|---|---|
| Defense & Public Sector Anchor | ROOTKey becomes the mandated integrity layer for national defense and critical government data systems in Portugal and allied EU nations. | A procurement contract or pilot with a Portuguese defense agency or a major EU public-sector entity. | The company's graduation from a defense-focused accelerator provides direct exposure and credibility with this exact customer segment [Portugal Startup News, Jan 2026]. Its platform narrative around immutable proofs for audit and compliance aligns with public sector procurement requirements. |
| Banking Compliance Standard | A tier-1 European bank adopts ROOTKey's platform to cryptographically certify transaction logs and audit trails, setting an industry standard that triggers adoption across the financial sector. | A successful proof-of-concept deployment with a mid-sized bank, leading to a public case study and a partnership announcement. | The CEO has stated a focus on expanding into highly regulated sectors, with banking being a primary target [Portugal Startup News, Dec 2025]. The problem of proving transaction integrity is universal in finance, and a blockchain-based solution from a compliant EU entity could overcome regulatory hesitancy. |
Compounding success in this model would look like a trust flywheel. An initial flagship deployment in a high-stakes environment, such as defense or finance, would generate a portfolio of immutable, real-world use cases. These cases would serve as de facto technical and compliance benchmarks, lowering the perceived risk for the next regulated entity. Each new customer would contribute to a growing library of verified integration patterns and compliance frameworks, making subsequent deployments faster and cheaper. The platform's modular design, with separate offerings for developers and enterprises, is structured to facilitate this expansion from a core, high-value anchor into broader ecosystem adoption [Portugal Startup News, Dec 2025].
Quantifying the size of a win requires a credible comparable. Consider Soteria, a blockchain-based data integrity and provenance platform that raised a $13.5 million Series A in 2023 at a reported valuation exceeding $60 million [Crunchbase]. Soteria's focus on supply chain and media, while different, underscores the valuation premium attached to verifiable data layers. If ROOTKey's "Defense & Public Sector Anchor" scenario plays out, securing even a single national-level contract in a market like Portugal could establish it as a specialist with defensible, high-margin revenue. In that scenario, a valuation multiple reflecting a strategic infrastructure provider rather than a generic SaaS company becomes plausible. This is not a forecast, but an illustration of the outcome space: a company that owns a critical verification standard in a niche, regulated vertical can command valuations disproportionate to its revenue, based on strategic indispensability and high barriers to entry (scenario, not a forecast).
Data Accuracy: YELLOW -- Growth scenarios and opportunity size are extrapolated from company positioning and limited public validation; the Soteria comparable is confirmed.
Sources
PUBLIC
[Portugal Startup News, Dec 2025] ROOTKey blockchain-powered cyber resilience platform plans U.S. and Germany presence in 2026 | https://portugalstartupnews.com/2025/12/10/rootkey-blockchain-powered-cyber-resilience-platform-plans-u-s-and-germany-presence-in-2026/
[Gonçalo Gil] Learn more about Gonçalo and what drives him | https://goncalopedrogil.com/about/
[Miguel Remédios LinkedIn] Miguel Remédios - ROOTKey | https://www.linkedin.com/in/miguelremediioss/
[Portugal Startup News, Jan 2026] Portugal’s first defense-focused accelerator graduates 30 companies into investment phase | https://portugalstartupnews.com/2026/01/29/portugals-first-defense-focused-accelerator-graduates-30-companies-into-investment-phase/
[Prospeo] ROOTKey - Cyber Resilience with Blockchain | https://prospeo.io/c/rootkey-cyber-resilience-with-blockchain-revenue
[ROOTKey] ROOTKey | https://rootkey.ai
[ROOTKey Documentation] ROOTKey Documentation | https://docs.rootkey.ai/introduction
[GitHub] ROOTKey GitHub | https://github.com/ROOT-Key
[Gartner, 2024] Gartner Forecasts Worldwide Security and Risk Management Spending to Exceed $215 Billion in 2024 | https://www.gartner.com/en/newsroom/press-releases/2023-10-17-gartner-forecasts-worldwide-security-and-risk-management-spending-to-exceed-215-billion-in-2024
[McKinsey, 2024] Cybersecurity trends: Looking over the horizon | https://www.mckinsey.com/capabilities/risk-and-resilience/our-insights/cybersecurity-trends-looking-over-the-horizon
[Crunchbase] Soteria Company Profile & Funding | https://www.crunchbase.com/organization/soteria-2
Articles about ROOTKey
- ROOTKey's Blockchain Verification Layer Lands at Portugal's Defense Accelerator — The 2022-founded startup is building a tamper-evident data integrity platform for regulated sectors, starting with a spot in a national security program.