The application security problem has grown almost comically complex. Modern development teams juggle sprawling codebases, cloud configurations, third-party dependencies, and an ever-expanding attack surface—all while trying to ship features fast enough to satisfy impatient customers and hungrier investors.
Enter Nullify, a San Francisco startup that thinks it has an answer: what it's calling "AI employees" for security work. Not assistants. Not copilots. Employees.
On February 5, the company closed a $12.5 million seed round led by SYN Ventures, with Black Nova Venture Capital returning to double down on its earlier bet. The fresh capital brings Nullify's total raise to $16.9 million—a war chest the founders say they'll use to scale a product that's already handling vulnerability triage and generating code fixes across dozens of enterprise customers.
Whether that pitch holds up under scrutiny is another question. But for now, at least, investors are buying in.
The Money and the Players
Glenn Chisholm doesn't make bets lightly. As operating partner at SYN Ventures and former CTO of Cylance—the endpoint security firm that BlackBerry acquired for $1.4 billion—Chisholm has seen more than his share of security hype cycles. He's joining Nullify's board as part of the deal.
SYN runs a dedicated cybersecurity seed fund, the kind of vehicle that's become increasingly common as investors hunt for the next Wiz or CrowdStrike. The firm's roster includes former CISOs, CTOs, and CEOs who've actually built security companies, not just funded them. It's the sort of investor that can sniff out vaporware from across a conference room.
Black Nova Venture Capital, which backed Nullify in previous rounds, increased its stake this time around. The vote of confidence matters—repeat investors are often the most discriminating. Nullify first raised $3.41 million in March 2024, co-led by Two Sigma Ventures and Root Ventures, following a $1.1 million pre-seed from OIF Ventures in 2023.
For a two-year-old company operating out of offices in San Francisco and Sydney, that's a fairly aggressive fundraising trajectory.
What They Actually Built

Strip away the marketing language and Nullify's pitch is straightforward: application security teams are drowning in alerts, and most of those alerts require tedious manual work to validate, prioritize, and fix. The company's platform attempts to automate that entire workflow.
Rather than layering on another dashboard that security engineers have to monitor, Nullify built what it describes as autonomous agents—software that detects vulnerabilities, triages them, validates whether they're exploitable, and then generates merge-ready code to fix them. The system plugs into GitHub, Jira, and Slack, the tools engineers already live in.
One feature, called Vault, functions as organizational memory. It ingests code repositories, cloud configurations, internal documentation—essentially the institutional knowledge that normally lives in a senior engineer's head—and uses that context to inform security decisions. Another component, Campaigns, bundles validated vulnerabilities, assigns them to the appropriate developers, opens pull requests automatically, and nags teams via Slack if SLAs start slipping.
According to Nullify's own metrics, the platform has saved more than 48,000 hours of manual security work, auto-resolved over 450 vulnerabilities, and achieved roughly a 90 percent acceptance rate on fix pull requests. The company lists Foxtel Group, InfoTrack, and nib Health Funds as customers. It covers the usual suspects—business logic flaws, exposed secrets, dependency vulnerabilities, API misconfigurations, container issues—and starts at $6,000 per month for smaller teams.
Those numbers sound impressive. Whether they hold up at scale, across different types of organizations and codebases, remains to be seen.
The Founders and the Plan

CEO Shan Kulkarni and CTO Tim Thacker co-founded Nullify in 2022. The duo went through CyRise, a cybersecurity-focused accelerator, in 2023, and also participated in Conviction's Embed AI program in San Francisco the same year. After closing its March 2024 seed, the company made its U.S. debut at New York Tech Week that June.
Now, with fresh capital in hand, Nullify says it plans to expand its go-to-market operations—sales and marketing, in plain English—while growing engineering and research teams. The company targets mid-sized enterprises and high-growth SaaS companies, the kind of organizations that have enough code complexity to feel the pain but not necessarily the budget to hire an army of security engineers.
Nullify currently employs somewhere between 11 and 50 people, depending on who's counting. That's typical startup opacity.
The Broader Context
Nullify's raise arrives amid a sustained wave of investor enthusiasm for AI-driven security automation. 7AI pulled in a staggering $130 million Series A in December 2025. Root Evidence secured $12.5 million in seed funding last July. Nebulock raised $8.5 million for AI-powered threat hunting around the same time.
The pattern is hard to miss. Venture capitalists, sensing both opportunity and necessity, are flooding the category with capital. The cybersecurity workforce shortage—which industry group ISC2 has been documenting for years—shows no signs of abating. Throughout 2024 and 2025, the organization highlighted accelerating adoption of AI and automation in security workflows, a trend driven as much by desperation as innovation.
Security teams simply can't hire fast enough to keep pace with the volume of vulnerabilities modern software stacks generate. If AI can genuinely handle the grunt work, the labor economics start to make sense.
But that's a big if. Autonomous security agents sound appealing in a pitch deck. Making them reliable, accurate, and trustworthy enough to deploy at scale? That's the hard part. Nullify has a few dozen customers and $16.9 million to prove it's possible.
The market will be watching.
