The pitch sounds almost too clean: give us fifteen minutes, and autonomous AI agents will hunt for vulnerabilities in your code, validate them with working exploits, and push fixes directly into GitHub—no human pentester required.
That's the promise MindFort AI is selling after closing a $3 million seed round on April 21, 2026. The San Francisco startup, a graduate of Y Combinator's Spring 2025 batch, joins a crowded field racing to automate one of cybersecurity's most stubborn problems: the manual, time-intensive process of finding and fixing holes before the bad guys do.
Soma Capital led the round, with participation from Y Combinator, 468 Capital, CRV, and Sandwith Ventures. The company had previously raised $500,000 in a pre-seed round last June.
Credentials That Matter
If the idea sounds familiar, the founders bring résumés that help explain why investors leaned in. Co-founder Brandon Veiseh led product at ProjectDiscovery, the company behind Nuclei enterprise, and later ran AI tooling for offensive security at NetSPI. His co-founder, Akul Gupta, holds a master's in computer science from the University of Illinois Urbana-Champaign and worked on red teaming and model safety at both OpenAI and Anthropic.
Gupta has published research on LLM-enabled cyberattacks, including a 2024 paper with a title that likely raised eyebrows in security circles: "LLM Agents can Autonomously Exploit One-day Vulnerabilities." In other words, he's been thinking about this problem—and its risks—for a while.
The small team is building what they call MF-1, a purpose-built model for offensive security. It's paired with something called HillClimb, a recursive learning system designed to build institutional knowledge across security engagements. Whether that architecture can deliver on the company's ambitions remains to be seen.
What the Money Will Buy
MindFort plans to deploy the capital in three directions: expanding infrastructure capacity, hiring an applied AI research team to train MF-1, and broadening platform coverage to include web applications, APIs, network infrastructure, and cloud environments. The company's funding announcement framed its goal with the kind of bold simplicity that either signals vision or invites skepticism: "The future of security is autonomous AI agents protecting every company on earth."
Since launching, MindFort has signed what it describes as enterprise customers and fast-growing startups, though it hasn't disclosed names. According to the company, setup takes less than 15 minutes, with initial results delivered within hours—a timeline that would represent a significant improvement over traditional penetration testing, which can take days or weeks.
How the Platform Actually Works
The system runs continuous security assessments that can be triggered manually, scheduled at intervals, or fired automatically on every code push. When the agents identify a vulnerability, they validate it with a proof-of-exploit, then generate pull requests directly into GitHub or file tickets in project management tools like Jira or Linear.

MindFort claims its platform outperforms legacy DAST (dynamic application security testing) and SAST (static application security testing) scanners, maintains a false-positive rate below 3%, and reduces mean time to remediation to minutes. Those are company-reported benchmarks. Independent validation would help, but the company hasn't yet published third-party audits.
Pricing starts at $199 per month for an Essential tier, scaling to $999 for Professional and custom pricing for Enterprise customers. Assessments run in three modes—Turbo takes roughly four hours and consumes 200 credits; Balanced runs about six hours at 400 credits; Deep scans take around eight hours and burn 800 credits. Higher tiers unlock automated patching pull requests, CI/CD integrations, and SAML/SSO authentication.
A Crowded, Well-Funded Race
The raise arrives at a moment when venture capital is flooding into what some are calling "agentic security." Horizon3.ai closed a $100 million Series D in June 2025 for its NodeZero platform. Synack launched Sara, its agentic pentesting solution, in August of that year. Hadrian introduced Nova just last month. Axios recently characterized the trend as cybersecurity's search for the "CrowdStrike or Wiz of AI security"—in other words, the category-defining winner.

Industry analysts are watching closely. Bessemer Venture Partners has noted that Gartner projects 40% of enterprise applications will embed task-specific agents by the end of this year. And a March survey from Synack and Omdia found that while 95% of enterprises say penetration testing is a priority, only 32% of their attack surfaces actually get tested. That gap—between intention and execution—is what MindFort and its competitors are betting they can close.
Whether autonomous agents can truly replace skilled human pentesters at scale is still an open question. The technology is improving, certainly, but so are the attacks. MindFort holds SOC 2 Type II certification and recently appeared at RSA Conference's Early Stage Expo—the kind of credibility markers that matter in an industry where trust is currency.
The capital flowing into the space suggests investors, at least, are willing to place bets before all the answers are in.
