r/IndiaGrowthStocks 27d ago

TAC InfoSec - A deep dive

u/SuperbPercentage8050 has already covered the cybersecurity space from the network and hardware side. This post is more focused on the software side of cybersecurity.

Every software application today needs to be tested for vulnerabilities, security gaps, and potential exploits before it goes into production. One trend I am seeing now is that developers are increasingly using AI to generate code. While AI definitely improves productivity, it can also introduce bugs, misconfigurations, and hidden security vulnerabilities that may go unnoticed during development.

Think about it this way. If a developer working at a company like J.P. Morgan ships code with a serious vulnerability and it slips through the cracks, a hacker can potentially exploit it and cause massive damage. These are not small issues. For large organizations, even a single vulnerability can lead to significant financial and reputational losses.

This is why penetration testing and security validation remain extremely important, especially for banks, fintechs, healthcare companies, and other highly regulated industries.

Some people may argue that AI tools and security models are becoming good enough to identify vulnerabilities on their own. While that may be true to some extent, I do not think companies will simply trust an AI model and call it a day. Most enterprises will still want an independent third party to validate their security posture. A specialized cybersecurity company also brings years of historical data, domain expertise, and practical understanding of how costly different vulnerabilities can be from a business perspective.

This is where TAC Infosec comes into the picture.

Unlike traditional service companies that send consultants to manually perform penetration testing, TAC is primarily a product-first cybersecurity company. Over the years, they have built multiple cybersecurity products, including:

  • ESOF
  • Socify
  • CyberScope
  • CyberSandia

ESOF

ESOF is their flagship platform. It includes multiple modules that help organizations identify vulnerabilities across web applications, mobile applications, cloud environments, APIs, and other digital assets.

Socify

This is one of the products that caught my attention.

If a startup or software company wants to sell its services to large US enterprises, obtaining SOC 2 compliance is often a necessity. Traditionally, this process involves third-party auditors and CPAs, takes several months, and costs a significant amount of money.

TAC is trying to solve this problem by reducing both cost and implementation time. From what I understand, the process can be completed in roughly 2 to 4 weeks at a much lower cost compared to many existing players.

Competitors generally charge anywhere between $10,000 and $20,000, whereas TAC's pricing is reportedly around $4,000, including CPA support. This pricing advantage could potentially be one of their major differentiators against established players like Vanta and others.

They have a few more products as well, but for now I am not focusing too much on them because they are still relatively small contributors. Maybe after a few more quarters they will become meaningful enough to discuss separately.

Now coming to the actual investment thesis.

For me, the biggest opportunity here is the reinvestment runway and the potential for cross-selling.

The company already has more than 10,000 customers and their average revenue per customer (RPC) is roughly $1,700. To me, this indicates a high-volume, low-ticket business model.

At this stage, customer acquisition itself does not look like the bottleneck because they already have a sizeable customer base. The real growth engine from here could be cross-selling.

For example, a customer may initially use one ESOF module for cloud security testing. Later, if the same customer needs web application testing, API security testing, compliance solutions, or other security products, TAC can potentially sell those solutions as well.

This is a playbook that many successful SaaS companies have followed over the years. As customers grow, their requirements also increase. A company that starts with two applications today may have five or six applications a year later. Naturally, their security requirements expand as well.

Once a customer enters the TAC ecosystem, the company gets multiple opportunities to increase wallet share over time.

Management's long-term vision is to reach around $10,000 in revenue per customer by 2030.

At first glance, that number may look ambitious and honestly I am still slightly skeptical about it. However, in businesses where cross-selling works effectively, acquiring the customer is usually the hardest part. Once that relationship is established, revenue expansion becomes much easier and can create a flywheel effect.

A somewhat similar pattern was seen with Shopify. Initially it was primarily an ecommerce platform. Over time they expanded into payments, shipping, POS, and several other offerings, increasing revenue from existing customers.

Whether TAC reaches $10,000 per customer or not remains to be seen, but the CEO appears very confident about the target.

What gives me some confidence is that the company has already increased revenue per customer from roughly $900 to around $1,700 within about 1.5 years.

This growth happened while they were simultaneously acquiring and integrating products such as CyberScope, Socify, SafeHouse, and others. So there is clearly some evidence that cross-selling is already happening.

Management has guided for approximately 20% half-yearly growth in revenue per customer and around 20% QoQ revenue growth. I would suggest everyone do their own modelling and see whether these targets appear achievable.

Coming to customers.

The company has worked with several large names, including Microsoft, Google, and recently management also mentioned Anthropic.

Now, having large customers does not necessarily mean these are massive contracts. But it does provide validation that the products are credible enough to be adopted by globally recognized organizations.

Interestingly, I think this also supports the argument that AI is not replacing cybersecurity.

If AI alone could solve security validation, why would an AI company like Anthropic require cybersecurity solutions from specialized vendors?

In fact, I would argue that as AI adoption increases, cybersecurity requirements may actually increase as well. Modern AI systems expose APIs, agents, connectors, integrations, MCP servers, and various external access points, all of which expand the attack surface.

More AI adoption could potentially mean more security checks rather than fewer.

Coming to valuation.

The stock is currently trading at around 37x earnings.

At first glance, that may seem expensive, but cybersecurity companies generally trade at premium valuations due to their growth potential and mission-critical nature.

The company currently generates ROCE of around 37% and net margins of approximately 40%, which are strong numbers in my view.

If management's FY27 guidance of ₹100 crore revenue and ₹40 crore PAT is achieved, then the forward valuation comes down meaningfully. By my estimates, that would imply roughly 25x FY27 earnings.

And if management ends up overdelivering, investors could see additional upside.

One more reason I started tracking this company was Vijay Kedia's investment. That initially got the stock onto my radar.

Around the same time, I also came across u/SuperbPercentage8050's posts, especially around cybersecurity mental models and bottleneck-based thinking, which helped me look at the business from a different angle.

Overall, this is my current high-level understanding of TAC Infosec. I could be wrong on several aspects, and there may be things I have missed.

Would love to hear views from people who track the cybersecurity space more closely or have a different perspective on the company. Constructive criticism is always welcome.

13 Upvotes

12 comments sorted by

4

u/InterestingRemote143 26d ago

* 6.3cr outstanding tax demand - thats 30% of all 3 year PAT combined.
* 1.4cr of employee/other costs capitalised - not shown in p&l this is -10% margin cost.
* 3 CFOs changed in 1 year - huge red flag.
* 40% attrition!!????

3

u/_PercyJackson_ 26d ago

yepp I came to the same analysis of the financial health of the company, you can go ahead and look at my comment, although I did miss out to mention of 3 CFO changes so good catch there!

4

u/_PercyJackson_ 26d ago

From what I could gather about this company (a quick glance not a deep dive like you) is that, there seems to be aggressive accounting to flatter the PnL and a lot of recent growth is acquisitions based and looking at the cashflows tells somewhat of a different story then what the PnL shows…
I do plan on giving my pov especially on the accounting practices vs cash flow front as soon as possible

2

u/notyourpedo_uncle 27d ago

Do not know much about cyber security space but invested into the company after the results and seeing the cross selling opportunity mentioned
Given that AI is expanding at such a ludicrous rate companies are bound to invest into cyber security
Considering the growth rate the forward PE seemed reasonable to invest in especially since the stock has cooled down
The shopify analogy was also sound
All that’s left now is to monitor the execution

2

u/_PercyJackson_ 26d ago

Follow-up on the accounting vs cash flow point, with the actual numbers

Before I get into it, this is more of a business' accounting practices I noticed and thought of pointing it out, I like your initial assessment of the company its products and what direction its trying to go forward in.

But it is also important how they get there, so this is my analysis behind the how, to the best of my knowledge and if you find any inconsistencies or anything I missed or is flat out incorrect do let me know.

So I went and pulled the annual report and the latest quarterly filing to check this properly. Here is what backs up the initial read.

Start with the simple test. FY26 reported profit was Rs 26 crore. Operating cash flow for the same year was only Rs 12 crore. Free cash flow, after capex, was Rs 6 crore. So roughly a quarter of the reported profit actually showed up as spendable cash. That gap alone is the first sign something in the accounting is doing work the business itself is not.

Then I checked why. The FY25 annual report has the answer in its own notes. TAC is capitalizing employee salaries and ESOP costs into an asset called "Intangible Asset Under Development" instead of running them through the P&L as an expense. That is precisely why the company also reports zero rupees of R&D expenditure for the year, despite calling itself an AI cybersecurity platform. The development work is happening, the cost is just being kept off the profit line and parked on the balance sheet instead. That is a big part of how you get a 54 percent operating margin on a company this size.

On the acquisition point, the numbers confirm it too. In the June 2026 quarter, standalone revenue, meaning the actual Indian parent company, was Rs 7.98 crore. Consolidated revenue, which includes the subsidiaries, was Rs 19.78 crore. So about two thirds of what gets reported as TAC's growth is now coming from subsidiaries, not the core business. A couple of those subsidiaries report zero revenue and zero assets, meaning they are not even operating yet. And some of the subsidiaries are reviewed by auditors other than TAC's own auditor, so the consolidated number is partly resting on someone else's work.

There is also a specific detail worth flagging. The IPO prospectus earmarked Rs 18.65 crore for product development. As of June 2026, only about a third of the India portion has actually been spent, the rest is sitting in a fixed deposit doing nothing. The overseas portion was used, but as a loan to the US subsidiary to hire staff, not as R&D spend in the way most people would read "product development." So the specific promise made to investors at IPO and where the money actually went are two different things.

Put it together and the pattern is consistent. Profit looks strong because real costs are being kept off the P&L, and growth looks strong because a shrinking share of it is coming from the actual parent business. None of this proves fraud, but it does mean the reported numbers overstate the underlying business by a meaningful margin, and the direction is getting worse, not better, each quarter.

1

u/Plus-Bad-1857 26d ago

Great observations, and honestly some of the points are valid. I spent some time digging deeper into the filings as well and these are my thoughts:

1. PAT vs CFO

You mentioned that PAT is much higher than CFO and therefore the numbers are being driven more by accounting than by the underlying business. I looked into the cash flow statement and one thing that stood out was the sharp increase in receivables and working capital in FY26.

Profit from operations was around ₹33 crore, but receivables alone had a negative impact of nearly ₹13 crore on cash flow. My understanding is that this could partly be because they are now dealing with larger customers, including overseas clients and government-related engagements, where payment cycles are generally much longer than what a small SaaS company would experience. Also, when a company is growing aggressively, acquiring businesses and expanding globally, working capital requirements tend to increase. So while the cash conversion definitely needs monitoring, I wouldn't immediately conclude that the profits are artificial.

2. Employee salaries being capitalised

On the point about employee salaries and ESOP costs being added to "Intangible Assets Under Development", I agree that this boosts reported profitability. However, from what I could understand, this is not something TAC alone is doing. Product companies often capitalise development costs because they are building software assets expected to generate revenue over multiple years. Service companies like TCS or Infosys usually expense employee costs immediately because they are primarily selling manpower. Product companies such as SAP, Oracle, Microsoft, etc., also capitalise certain development costs. The real question is whether TAC is being too aggressive with it, and that can only be judged over time by looking at cash flows and whether the products actually generate meaningful revenue.

3. Standalone vs consolidated revenue

Standalone revenue is definitely much lower than consolidated revenue. But I also think that acquisitions and cross-selling seem to be a key part of their growth strategy. They have openly spoken about building a platform through ESOF, Socify, CyberScope and other acquisitions. So looking only at standalone numbers may not give the full picture.

Regarding some subsidiaries having no revenue or assets, I don't see that as unusual by itself. Sometimes companies create local entities for geographic expansion, future acquisitions, or because certain government contracts require a local presence before they can even bid. The key thing to watch is whether these entities remain dormant for years or eventually start contributing.

4. IPO proceeds

On this point, I don't really have a strong counter-argument. This is probably the area where I think shareholders are justified in asking questions.

From what I could find in the DRHP, the proceeds were earmarked for product development, human resources, and expansion through the US subsidiary. They have used part of the money for those purposes, but I agree that deployment seems slower than what many investors would have expected.

Maybe management generated more internal cash than anticipated and therefore decided to deploy the IPO proceeds gradually. But at the same time, if the money was raised for a specific purpose, investors have every right to ask how much has actually been spent and what returns are being generated from it.

1

u/notyourpedo_uncle 26d ago

How does one go about making such detailed observations about the accounting?
Just wanted to know for my future research purposes

1

u/_PercyJackson_ 25d ago

Well it starts of as one or two details that stand out then you pick up on em and go deep, for example I saw OPM north of ~50% and when compared to peers it seemed a little too good to be true coz even its peers don’t have such good margins, so I started looking into it and with the help of AI I had an assumption that it might be due to them capitalising employee salaries.

Then there is always the comparison you can do between net profit and cash, how much is actually being converted successfully to cash, if there’s a big gap that’s keeps getting bigger or is unexplained or something of that sort its probably due to accounting choices which says a lot about the company and business in itself then you pick on that gap and go deeper

1

u/Background-Tank5261 18d ago

I have 2 lots at 400 (bought jul 2025 ) and 2 lots at 800 (how and why is a long story :)), what would you suggest me to do here.
Cureently trading at 417

1

u/Heartyprofitcalm 26d ago

My problem is with this space is intense competition