LeoTrace, a London security startup incorporated in September 2025, thinks it has found a market in a problem most developers didn't know existed yet: the vulnerabilities that AI coding assistants introduce when they write code on our behalf.
The company announced Wednesday it raised €1.7 million (roughly $2 million) in a pre-seed round with participation from Golden Egg Check, a €15 million fund focused on frontier AI companies. The pitch is straightforward. LeoTrace's LeoPrevent tool intercepts code as it flows from AI agents like Cursor, GitHub Copilot or Claude Code back to human developers, scans it for common security holes, then bounces flawed work back to the agent for a second try. All of this happens in under two seconds, according to Thomas Mensink, CEO of Golden Egg Check.
Whether the approach gains traction hinges on a bet that companies will trust a machine to catch what another machine got wrong, then trust a third machine to fix it—without a person in the loop.
Scanning Before the Handoff
LeoPrevent sits at a chokepoint: the moment an AI agent believes its work is finished. Before a developer sees the code, LeoTrace runs checks for server-side request forgery, cross-site scripting, insecure direct object references, path traversal flaws, OS command injection and open redirects. The system then surfaces a before-and-after diff in a dashboard, complete with an audit trail.
LeoTrace claimed in a LinkedIn post last month that internal testing shows the tool removes about half the vulnerabilities that would otherwise ship, though no independent validation has been made public. Golden Egg Check's announcement cited independent testing indicating a one-third reduction on certain tasks, though those reports have not been released publicly. The startup says it already has production deployments at unnamed tier-one financial institutions in the UK and US, though it has not disclosed client names.
That vagueness is typical for an early-stage security company trying to build credibility without spooking enterprise clients wary of public disclosures.

A Hacker and a Sales Veteran
Florian Walter, a German ethical hacker, and Patrick Rycroft, who spent eight years selling enterprise security tools, incorporated LeoTrace in England on September 25, 2025. Rycroft wrote on LinkedIn earlier this year that "detection got really good" in application security over the past decade, but "prevention barely moved." The implication: catching bugs after they're written is table stakes now. Stopping them beforehand is the unlock.
The company recently brought on Boy Baukema, a 19-year application security veteran who logged nine years at Veracode, as head of security research. His LinkedIn and Dealroom profiles confirm the hire, though LeoTrace has kept staffing details close. A LinkedIn snapshot from last month showed two employees, a figure that likely excludes contractors and may already be outdated.
Timing the Market
LeoTrace closed its round in August 2026—share allotments dated August 13 and August 24 appear in UK Companies House filings submitted August 27—and went public with the news September 10. The timing may not be coincidental.
OpenAI published a postmortem two weeks ago on a July incident tied to Hugging Face repositories, and Axios reported in early September that agent-to-agent attacks and misaligned agent behavior have resurfaced as concerns inside the AI safety community. Both Anthropic and GitHub have responded. Anthropic added automated security reviews to Claude Code in March; GitHub rolled out a /security-review command for Copilot in July, according to public documentation from both companies.
That Microsoft and Anthropic are building guardrails directly into their tools suggests the problem LeoTrace is addressing is real. It also means the startup will eventually compete with the platforms it integrates with today.
A Crowded Neighborhood
LeoTrace is hardly alone. Beacon Security raised $13 million in August for an AI agent cyber-defense data layer. Ossprey closed a pre-seed round in July to scan open-source packages for malicious code. LeoTrace's website lists Snyk, Ox Security and Aikido Security as "complementary" scanners, a diplomatic way of acknowledging overlap without picking fights.

The company declined to share how it plans to spend the €1.7 million or whether it intends to hire aggressively. Rycroft wrote months ago that more than 1,200 people had joined the waitlist, though converting free-tier interest into paying enterprise contracts is a different challenge entirely.
For now, LeoTrace is making a calculated wager: that as AI agents write more code, the cost of letting them ship vulnerabilities will outweigh the friction of adding another layer of automated review. Whether enterprises agree remains to be seen.
