When nearly 190 companies took the stage at Y Combinator's Winter 2026 Demo Day on March 24, most were bracing for the usual question: how do you stand out? Hex Security, a San Francisco startup barely old enough to have office coffee traditions, had an answer ready. Eight weeks in, the company says it's already crossed $1 million in annualized revenue selling something that sounds almost too obvious in hindsight—AI agents that hack your systems before someone else does.
The idea caught on. TechCrunch included Hex in an article featuring top startups at Demo Day, a distinction that matters when you're competing in a room packed with security and AI pitches.
Hex's proposition is simple, almost blunt: Why pay for penetration tests once a year when autonomous agents can probe your web applications and infrastructure continuously? The company calls it "security at the speed of development," a nod to the mismatch between how fast modern teams ship code and how slowly they tend to audit it. A critical vulnerability discovered halfway through an annual testing cycle means six months of exposure. For startups deploying daily, that math gets uncomfortable fast.
Always-On Offensive Security
According to the company's Y Combinator profile, Hex positions itself around "agentic offensive security at scale." The AI agents don't just scan—they attempt exploits, validate findings, and generate proof-of-concept evidence for each vulnerability they uncover. In a launch post, the team noted with some pride that "in the past few weeks, our agents found critical vulnerabilities in dozens of YC companies."
Whether those companies appreciated being used as test subjects wasn't specified.
It's fundamentally an automation play in a discipline that has long resisted it. Traditional security audits involve skilled humans poking at systems with purpose and creativity—traits that, until recently, seemed difficult to replicate at scale. Hex is betting that AI has crossed a threshold. The company's website hammers home the shift: "Autonomous AI agents... continuously, not once a year."
Like every company in its batch, Hex took Y Combinator's standard investment: $500,000 total, structured as a $125,000 post-money SAFE for 7% equity and a $375,000 uncapped most-favored-nation SAFE. Gustaf Alströmmer is their YC partner, though what that relationship looks like day-to-day remains the sort of detail founders don't often publicize.
Who's Building It

Three people are behind Hex, each bringing a different slice of technical background. Huzaifa Ahmad previously worked at PlayAI, AWS, and Capital One, and claims to have built consumer apps downloaded millions of times. According to his public profile, he reverse-engineered applicant tracking systems during college—perhaps more useful preparation for startup life than he realized at the time.
Ahmad Khan studied mathematics at the University of Waterloo and researched blockchain-based skill-sharing for robots, which sounds either visionary or wildly impractical depending on when you ask. He also holds what might be the most specific credential in Silicon Valley: he was reportedly "first in history to ring the NASDAQ bell" with a robot. His research touched on world models, the AI systems attempting to predict how environments evolve.
Prama Yudhistira rounds out the trio. He built asynchronous coding agents at Codegen and developed firmware testing infrastructure at AMD. He's also a competitive pianist, the kind of detail that adds color to a founding team story even if it has little to do with penetration testing.
The Competition Is Getting Thick

Hex is hardly alone. If anything, the space is becoming uncomfortably crowded with startups convinced that AI can automate offensive security.
Even within the YC ecosystem, the theme repeats. Escape, from the Winter 2023 batch, has raised an $18 million Series A and counts Zoom, Air France-KLM, Vanta, and Miro as customers for its AI-powered automated pentesting. Casco, from the more recent Prior 2025 batch, describes itself in nearly identical terms: "autonomous security testing for web apps, APIs, cloud, and AI systems."
Then there are the newer players. Veria Labs posted on Launch YC around September 2025—roughly six months before Hex's Demo Day appearance—pitching "AI agents that pentest your code continuously," though with a code-first angle. MindFort.ai emerged around May 2025 with "fully autonomous security agents" that promise to "find, validate, and patch vulnerabilities 24/7." Gecko Security, which launched more than a year ago, positions itself as an AI-powered static analysis tool that validates and exploits what it finds.
Within Hex's own Winter 2026 cohort, security and AI were inescapable themes. BeeSafe AI tackled fraud prevention for trust-based scams, led by three PhDs in AI and security. Crosslayer Labs appeared in TechCrunch's roundup of the batch's most interesting startups as a spoof-detection company.
The convergence suggests something has shifted—infrastructure and models have caught up to what founders have been promising for years. AI can now attempt exploits, validate findings, and generate reports with diminishing human oversight. Whether that transforms into durable competitive advantage or simply becomes the baseline everyone must meet is the question investors are now asking themselves, often late at night.
What Comes Next

If Hex's company-claimed $1 million-plus run-rate—reported by TechCrunch but not independently verified—is sustainable eight weeks into existence, it would justify at least some of the attention the company received. The startup hasn't disclosed any funding beyond Y Combinator's check, though TechCrunch reported that some W26 companies were raising at seed valuations around $30 million. A couple reportedly pushed past $100 million post-money, though which ones and under what terms remains speculation.
For now, Hex is focused on what its agents can uncover. The race, really, is to prove that continuous autonomous testing catches what annual audits miss, and to do so at a price point that works for the mid-market companies most exposed to attacks. The founders appear to understand that technical capability is only part of the equation.
The harder sell may be trust. Customers have to believe that AI agents can poke holes in their systems without supervision—and that those agents can keep pace with attackers who are almost certainly using similar tools. In security, the offense-defense balance has always been uneasy. Adding AI to both sides of that equation doesn't simplify the math. It just makes it faster.
