Founderland Logofounderland
the ★ top ★ 100 ★ marketers ★
SavedSearch
FoundersFounders
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Product Launches
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Investment News
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Research & Innovation
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
FoundersFounders
Return

Recommended Articles

SaaS iconSaaSOctober 4, 2026

Subvocal launches under-chin wearable for silent computer control

Subvocal launches under-chin wearable for silent computer control
YcBrain Computer Interface+3
SaaS iconSaaSOctober 4, 2026

DoD Solution raises $2M for AI drone navigation in war zones

DoD Solution raises $2M for AI drone navigation in war zones
Defense TechDrone Tech+3
Climate / Social Tech iconClimate / Social TechFebruary 18, 2026

RoboDock Tackles Robotaxi Charging Bottleneck With Depot Automation

RoboDock Tackles Robotaxi Charging Bottleneck With Depot Automation
YcRobotics+3
SaaS iconSaaSFebruary 18, 2026

RamAIn Launches AI Agents That Automate Legacy Systems 10x Faster

RamAIn Launches AI Agents That Automate Legacy Systems 10x Faster
YcAi Agents+3

Founders Mentioned

Huzaifa Ahmad

Hex Security

saas icon
SaaS

Ahmad Khan

Hex Security

saas icon
SaaS

Prama Yudhistira

Hex Security

saas icon
SaaS

Huzaifa Ahmad

Hex Security

saas icon
SaaS

Ahmad Khan

Hex Security

saas icon
SaaS

Prama Yudhistira

Hex Security

saas icon
SaaS
SaaS iconSaaS
February 18, 2026
YcAi AgentsCyber SecurityAutomationB2b Saas

YC Startup's AI Agents Automate Continuous Penetration Tests

Hex Security launches autonomous AI agents that replace annual security audits with 24/7 testing, claiming $3B+ in prevented damages across dozens of YC companies.

YC Startup's AI Agents Automate Continuous Penetration Tests

The ritual is familiar to anyone who has run corporate security: schedule the annual penetration test, wait weeks for the report, patch what you can, file it for compliance. Then cross your fingers until next year.

Hex Security thinks that model is finished. The San Francisco startup, barely out of Y Combinator's Winter 2026 batch, is pitching something closer to science fiction than security theater—autonomous AI agents that probe your applications and infrastructure continuously, hunting for vulnerabilities the way a skilled researcher would, only without sleep or coffee breaks.

The company claims its agents have already discovered critical flaws across dozens of YC portfolio companies during development. SQL injections exposing billions of records. A proof-of-concept worm. Access to hundreds of codebases. Hex estimates it prevented over $3 billion in potential damages, a figure derived from IBM's breach cost benchmarks that sounds audacious given the company raised just $500,000 in a convertible note from Y Combinator and Pioneer Fund, according to CB Insights.

But timing, in startups as in security, is everything. The market for automated security validation is heating up fast—perhaps faster than most realize.

What Happens When the Agents Start Probing

Hex Security's platform runs autonomous agents designed to mimic how security researchers think. They test web applications, APIs, infrastructure. All day, every day.

The workflow is deliberately stripped down: connect the agent to your systems without lengthy scoping exercises. Let it probe continuously for vulnerabilities in authentication flows and business logic. Receive validated findings with working proof-of-concept exploits and remediation steps.

Every finding, the company insists, comes with a working PoC. No false positives. That's a bold claim in a field where alert fatigue from scanners has become something of a chronic condition. Hex says its agents don't just flag known CVEs—they chain exploits together and target the kinds of business logic flaws that traditional scanners regularly miss.

During the YC batch, the platform got tested at "dozens" of companies in the accelerator's portfolio. The findings were severe enough to raise eyebrows. The startup also earned more than $250,000 in bug bounties during development, an interesting data point that suggests its agents can find the kinds of issues that bug bounty programs actually reward, not just theoretical vulnerabilities.

The Crowded Race Toward Autonomous Pentesting

Hex is far from alone. The autonomous pentesting space is getting crowded, and quickly.

Horizon3's NodeZero platform has offered scheduled autonomous testing for some time now, marketing "safe by default" exploitation even in production environments. Synack recently launched Sara Pentest, an AI-led offering priced at roughly $5,000 per test in beta, alongside a $16,000 standard platform subscription. Terra Security raised approximately $8 million in April 2025 for a similar agentic approach to web application testing. HackerOne previewed "Agentic PtaaS" for continuous proof of exploitability. FireCompass unveiled what it called the industry's first Agent AI for autonomous pentesting back in July 2024.

The list goes on: Simbian, Penti.ai, ModernPentest. Others are staking claims in a market that blends AI capabilities with the growing demand for continuous security validation. Academic research is proliferating too, with preprints on frameworks like RapidPen, xOffense, and PenForge appearing with increasing regularity.

Hex differentiates itself with language about agents that "reason like elite researchers" and an emphasis on business logic testing rather than just infrastructure scanning. Whether that's a meaningful technical distinction or effective positioning remains to be seen—perhaps both. The company hasn't disclosed pricing. Prospective customers must book a discovery call. So it's unclear how Hex will stack up against competitors offering tiered subscriptions or per-test pricing.

When Attackers Have AI Too

Digital illustration for article section "When Attackers Have AI Too" in "YC Startup's AI Agents Automate Continuous Penetration Tests" - A high-fidelity 3D conceptual illustration depicting the automation of cyberattacks, rendered in a s...

The push toward agentic security tools comes as AI itself becomes a vector, not just a defense mechanism.

In November 2025, Anthropic reported that Chinese state-backed actors had used Claude to automate 80 to 90 percent of a cyberattack campaign. That incident, widely covered in tech media, underscored a reality that security professionals are still adjusting to: if attackers can automate reconnaissance and exploitation, defenders need continuous, automated validation to keep pace. The alternative is falling perpetually behind.

IBM's 2024 Cost of a Data Breach report found the global average breach cost rising to roughly $4.88 million, up from $4.45 million the prior period. Hex references those figures to support its "$3B+ prevented" claim, calculating potential damages from the volume of exposed records its agents discovered. It's a back-of-the-envelope estimate, but not an unreasonable one given the scale.

Three Founders, One Hybrid Model

Hex Security was founded by Huzaifa Ahmad, Ahmad Khan, and Prama Yudhistira. Khan previously worked in robotics and "world models" and holds a math degree from the University of Waterloo; he claims involvement with the "first robot to ring the NASDAQ bell," a detail that feels very Silicon Valley. Yudhistira's background includes stints at Codegen, which was acquired, and AMD. The company's corporate entity is listed as Anytool, Inc., though the relationship between the Hex Security brand and Anytool isn't formally explained on the website—a minor mystery for anyone digging through incorporation records.

The team of three is currently hiring penetration testers to work "alongside our AI agents," according to a LinkedIn job posting. That's a signal worth noting: the company sees a hybrid model rather than full automation, at least for now.

The Hard Part Comes Next

Digital illustration for article section "The Hard Part Comes Next" in "YC Startup's AI Agents Automate Continuous Penetration Tests" - A high-quality 3D rendered composition illustrating the concept of a high-stakes startup launch, fea...

Hex Security is in classic YC launch mode. The product is live, early adopters are being courted, and the company is funneling interest through discovery calls rather than self-service signup. The platform markets itself with a "no false positives" guarantee and the promise of actionable findings. But it doesn't publicly detail safety controls for production testing—rate limits, data handling protocols, impact thresholds—beyond the "validated PoC" language.

Whether Hex can turn YC batch momentum into broader traction will depend on execution, pricing strategy, and how well its agents actually perform compared to the growing field of autonomous pentesting platforms. The technology may be impressive. The competition is fierce. The market, though, seems ready.

For now, it's another entrant in a crowded race to make security testing less episodic and more like the threats companies face: relentless, continuous, and distressingly creative. The annual penetration test, that compliance staple, may not survive much longer. Which is probably as it should be.

More stories

  • Subvocal launches under-chin wearable for silent computer control
  • DoD Solution raises $2M for AI drone navigation in war zones
  • RoboDock Tackles Robotaxi Charging Bottleneck With Depot Automation
  • RamAIn Launches AI Agents That Automate Legacy Systems 10x Faster
  • How Edge AI Is Transforming Critical Infrastructure Control
  • Inside the Chip That Could Slash AI's Energy Crisis by 10-100x
fintech icon
climate-social-tech icon
saas icon
healthtech-biotech icon
ecommerce icon
media-entertainment icon
Loading...

About

Dreamwell AIContact UsOur Story

Articles

Product LaunchesInvestment NewsResearch & Innovation

founderland

We Use Cookies

We baked up some cookies – the digital kind. They help Draper run like a well-oiled mid-century machine. Some are essential to the experience, others help us tailor things to your taste. We promise, no crumbs on your blazer. Take a moment to choose what works for you.