Trident, a Y Combinator-backed security startup, has launched a platform that automates penetration testing across applications, APIs, and cloud infrastructure on a continuous basis. The San Francisco company becomes at least the eighth vendor to introduce such a product since January, as the cybersecurity industry scrambles to address what many see as an accelerating arms race between AI-generated code and AI-assisted attacks.
The timing reflects mounting anxiety among security professionals. A research note from the Cloud Security Alliance in May documented the first known AI-assisted zero-day exploit discovered in live systems and warned that agentic frameworks now enable "continuous, largely autonomous attack operations." Whether the threat is as dire as vendors suggest, or whether the industry is seizing on AI hype to sell upgraded tooling, remains an open question.
Trident's pitch is straightforward: traditional pentests often happen once a year, leaving companies vulnerable the other 360 days. The startup's platform runs on every code deploy and pull request, testing web applications and APIs while mapping attack paths across AWS, Azure, and Google Cloud. It scans identity systems such as Okta and AWS IAM, and data stores including Snowflake, BigQuery, and PostgreSQL.
Findings arrive as pull requests. Trident claims its system writes the patch, opens the PR, and reruns the exploit to confirm the vulnerability is closed. Each finding includes the exploit code that reproduces it—a level of specificity intended to eliminate false positives. "Model output on its own is never treated as proof of a vulnerability," the company notes in its FAQ, a nod to skepticism around AI-generated security findings.
Founded in 2025 by Dekai Li and Junaid Mahmood, Trident operates under the legal entity Esprit Labs Inc. Harshita Arora is listed as the primary Y Combinator partner. The company has not disclosed customer names, pricing, or additional funding details beyond its Y Combinator backing.
A Sudden Rush
The competitive landscape has shifted rapidly. HackerOne announced its Agentic PTaaS offering on January 26. OX Security followed with an "Agentic Pentester" in March. NetSPI, Prescient Security, CyCognito, Sprocket Security, and Cobalt all launched similar products between May and August, each promising to replace episodic testing with continuous monitoring.
CyCognito CEO Rob Gurzeev captured the industry's framing in a June blog post: "AI now writes a quarter of production code, with twice as many vulnerabilities." OX Security CEO Neatsun Ziv made a similar argument in March, saying AI writes code faster than security teams can review it, and attackers exploit that gap "at machine speed."
The claims are hard to verify independently. Most vendors cite internal research or customer anecdotes rather than peer-reviewed data. Still, the consensus among CISOs appears real: development velocity has increased, and traditional security workflows lag behind.
Trident has added a layer aimed at securing AI agents themselves. The platform offers observability and tracing for prompts and tool calls, red-teaming with over 200 automated attack scenarios targeting the OWASP Agentic Top-10, and a runtime firewall that converts confirmed findings into blocking rules within five minutes. The company provides TypeScript and Python SDKs, plus a CLI tool called tridentctl, for developers who want to integrate security checks into their existing workflows.
The platform exposes a Model Context Protocol server, allowing coding assistants such as Claude, Cursor, and GitHub Copilot to pull findings directly into their editing context with the affected file, line range, and exploit attached. It's a design choice that assumes developers trust AI enough to let it suggest fixes, which may prove optimistic.
What Trident hasn't disclosed is traction. The company's website offers no case studies, no named customers, and no pricing. For a product that requires deep access to cloud environments and identity systems, adoption will likely hinge on trust—a commodity that takes longer to earn than a few months on the market.
The broader question is whether continuous pentesting represents a genuine shift or simply repackages existing vulnerability scanning with better marketing. Annual pentests have long been criticized as compliance theater, but automating them doesn't necessarily solve the underlying problem: organizations still need people to prioritize findings, apply patches, and manage risk. Tools can find vulnerabilities faster. Whether companies can fix them faster is another matter entirely.
