There's a particular kind of exhaustion among software security teams these days. It stems from staring at endless lists of potential vulnerabilities, most of which turn out to be false alarms. ZeroPath, a San Francisco startup barely a year old, thinks it has found a way through the noise—and investors are betting $7 million that it's right.
The company announced the seed round in November 2025, led by HOF Capital and SurgePoint Capital. Y Combinator and its co-founder Paul Graham joined as well, a notable endorsement for founders who previously worked at Tesla and Google but are now tackling what might be called the remediation problem: not just finding bugs, but actually fixing them.
ZeroPath's pitch is deceptively straightforward. Take the findings from tools like Snyk, Semgrep, or Checkmarx—systems that organizations already use—then validate those findings, cut the false positives by roughly 75%, and generate patches developers can apply with one click. The platform leans on large language models, not just to spot the usual suspects (SQL injection, cross-site scripting) but to catch trickier business logic flaws: broken authorization, race conditions, the sort of issues that require understanding what code is supposed to do, not just what it does.
"It's like having an entire security team," said Jake Anderson of BRX.AI, in a testimonial the company shared. Perhaps hyperbole, perhaps not—but 750 companies have signed on since the platform launched, processing over 125,000 code scans each month.
Auto-Remediation Gets Crowded
ZeroPath isn't alone in this space, which is both a validation and a challenge. GitHub rolled out Copilot Autofix in March 2024, claiming developers tripled their fix speed during beta tests. Semgrep pulled in a hefty $100 million Series D last year specifically to build AI remediation features. Mend.io markets similar workflows. The money pouring into this corner of security suggests the problem is real—and lucrative.
What ZeroPath emphasizes, though, is its focus on AI-era vulnerabilities: prompt injection, insecure output handling, model denial-of-service attacks. Traditional static analysis tools, built for a different generation of software, often miss these entirely. The company also goes further than simple patching—it generates unit tests to verify fixes work, validates them in CI pipelines, and lets developers tweak patches using natural language directly in pull requests. It's an attempt to meet engineers where they already are, rather than asking them to learn another tool.
The team behind it has credentials. CEO Dean Valentine co-founded MEVlink, which bloXroute Labs acquired in May 2023. CTO Raphael Karger spent years in Google's security trenches. CIO Nathan Hrncirik earned more than $100,000 hunting bugs on Tesla's Red Team, the kind of résumé line that carries weight in security circles. COO Etienne Lunetta also came from the MEVlink founding team, giving ZeroPath a core group that's worked together before—always a plus when investors evaluate early-stage startups.
The company says it has tripled annual recurring revenue in the past three months, though it declined to share actual figures. (A common move at this stage; traction matters more than the dollar amount when you're still pre-Series A.)
Distribution Through Developers

ZeroPath is taking a developer-first approach to growth, offering a GitHub App, a command-line interface, and an MCP server that integrates with Claude and Cursor workflows. This kind of bottoms-up distribution has become standard in the DevOps world—let individual engineers discover and adopt the tool, then expand to teams and eventually entire organizations.
The company went through Y Combinator's Summer 2024 batch and closed a pre-seed round announced in September of that year. An earlier seed announcement in January 2025, also led by SurgePoint with participation from YC and Graham, didn't disclose the amount at the time—this November round appears to clarify and consolidate those earlier efforts.
Looking ahead, ZeroPath is preparing for RSA Conference 2026, where it claims a spot among the Top 10 finalists in the Innovation Sandbox competition, a showcase for emerging security companies. It's a stage that's launched companies like CrowdStrike and Okta in past years, though of course plenty of other finalists faded into obscurity. For now, though, ZeroPath has momentum—and capital—to find out which category it falls into.
The question, as with any security tool promising to automate what humans struggle with, is whether the fixes it generates are trustworthy enough to deploy without a second thought. Or whether, in solving alert fatigue, it introduces a new kind of risk: trusting the machine just a little too much.
