Hex Security | Y Combinator
Winter 2026 batch; continuous AI penetration testing.
Weak funding evidence: mention does not include a parsed raise amount/round and may refer to non-funding context.
Loading startup
Market data is refreshed once per day from public sources. Information may be incomplete or outdated — verify independently before making decisions. This is not investment advice.
Evidence-bound summary — expand sections for movement, risks, and signals.
Memo snapshot · May 20, 2026, 5:37 PM
What would change this read
DealFlow OS uses public web data and automated enrichment. Research may be incomplete, outdated, or incorrect. Verify important information before making investment or outreach decisions.
TL;DR
Seed (YC)Hex Security | AI-Powered Autonomous Penetration Testing Continuous offensive security agents for startups and enterprises.
Latest: Pre-seed (Jan 2026). Investors: Y Combinator. (High).
Funding
Latest: Pre-seed (Jan 2026). Investors: Y Combinator. (High).
Product / news
3 product/news‑styled row(s); headline risk without filings (High).
Traffic / social
3 social/traffic‑styled row(s) (Medium).
Verified facts
+1 more in Recent movement below
Winter 2026 batch; continuous AI penetration testing.
Weak funding evidence: mention does not include a parsed raise amount/round and may refer to non-funding context.
No open roles indexed yet.
The index price and activity score are algorithmic estimates based on observed public company-level signals. They may be incomplete, stale, or inaccurate and are not investment, legal, tax, or business advice.
Hex Security:reddit_credentials_not_configured
Source types found
Strongest / recent news-style rows
Wed, May 20, 05:37 PM · confidence 88%high quality
wikipedia · Mon, Jun 29, 05:41 PM · confidence 50%medium quality
wikipedia · Mon, Jun 29, 05:41 PM · confidence 50%medium quality
Newest first · 19 event(s)
Source: Blog
Hex Security's AI agents find critical vulnerabilities in your systems continuously—not just once a year. Trusted by YC companies. Start your free pentest.
Source: Homepage
Hex Security's AI agents find critical vulnerabilities in your systems continuously—not just once a year. Trusted by YC companies. Start your free pentest.
Source: official_site
Hex Security | AI-Powered Autonomous Penetration Testing Demo D Blogs Hex Security Is Now Free for Open Source Projects May 25, 2025 Open source maintainers can now get continuous AI pentesting at no cost. Hex Security covers IDORs, broken access control, XSS…
Source: Blog / news
Open source maintainers can now get continuous AI pentesting at no cost. Hex Security covers IDORs, broken access control, XSS, and infra misconfigs across every deploy.
Winter 2026 batch; continuous AI penetration testing.
Source: npm_registry
The best regular expression (regex) for matching hex color values from string.
Source: npm_registry
A simple method to check if a string is hex prefixed.
Source: npm_registry
A function to parse floating point hexadecimal strings as defined by the WebAssembly specification
Source: npm_registry
Use 4 & 8 character hex color notation in CSS
Source: hackernews
Source: wikipedia
Launch post on continuous pentesting agents.
Source: hackernews
Source: hackernews
Source: hackernews
Source: hackernews
2 row(s)
The company's own site — the authoritative description of what they sell and to whom. Marketing-controlled, so treat claims as positioning rather than verified traction.
Hex Security's AI agents find critical vulnerabilities in your systems continuously—not just once a year. Trusted by YC companies. Start your free pentest.
Why it matters: Primary source — the company's own positioning; best read for what they sell and to whom, not for traction claims.
Open source ↗Hex Security | AI-Powered Autonomous Penetration Testing Demo D Blogs Hex Security Is Now Free for Open Source Projects May 25, 2025 Open source maintainers can now get continuous AI pentesting at no cost. Hex Security covers IDORs, broken access control, XSS…
Why it matters: Primary source — the company's own positioning; best read for what they sell and to whom, not for traction claims.
Open source ↗3 row(s)
Third-party press coverage. Independent reporting corroborates company claims; repeated coverage across outlets is a momentum signal.
Why it matters: Independent coverage — third-party corroboration of company claims; recurring coverage indicates rising visibility.
Open source ↗Why it matters: Independent coverage — third-party corroboration of company claims; recurring coverage indicates rising visibility.
Open source ↗Launch post on continuous pentesting agents.
Why it matters: Independent coverage — third-party corroboration of company claims; recurring coverage indicates rising visibility.
Open source ↗1 row(s)
Funding announcements and investor-database records. The strongest public signal of capitalization: round, amount, and syndicate quality when disclosed.
Winter 2026 batch; continuous AI penetration testing.
Why it matters: Funding signal — Pre-Seed per this source; verify against the linked original before relying on it.
Open source ↗8 row(s)
Public engineering activity. Sustained commits, releases, and stars indicate real product development and, for dev tools, developer adoption.
The best regular expression (regex) for matching hex color values from string.
Why it matters: Engineering signal — public repo activity evidences active development and possible developer adoption.
Open source ↗Generate a hex color from the given text
Why it matters: Engineering signal — public repo activity evidences active development and possible developer adoption.
Open source ↗A simple method to check if a string is hex prefixed.
Why it matters: Engineering signal — public repo activity evidences active development and possible developer adoption.
Open source ↗A function to parse floating point hexadecimal strings as defined by the WebAssembly specification
Why it matters: Engineering signal — public repo activity evidences active development and possible developer adoption.
Open source ↗Use 4 & 8 character hex color notation in CSS
Why it matters: Engineering signal — public repo activity evidences active development and possible developer adoption.
Open source ↗Why it matters: Engineering signal — public repo activity evidences active development and possible developer adoption.
Open source ↗Why it matters: Engineering signal — public repo activity evidences active development and possible developer adoption.
Open source ↗Why it matters: Engineering signal — public repo activity evidences active development and possible developer adoption.
Open source ↗3 row(s)
Social presence and mentions. A soft signal — useful for gauging attention and launch reception, not a substitute for verified traction.
Why it matters: Attention signal — social mention or presence; soft signal of market interest.
Open source ↗Why it matters: Attention signal — social mention or presence; soft signal of market interest.
Open source ↗Why it matters: Attention signal — social mention or presence; soft signal of market interest.
Open source ↗2 row(s)
Company blog and newsletters. Shipping cadence and technical depth of posts hint at product velocity and team quality.
Hex Security's AI agents find critical vulnerabilities in your systems continuously—not just once a year. Trusted by YC companies. Start your free pentest.
Why it matters: Company publishing — post cadence and depth hint at product velocity.
Open source ↗Open source maintainers can now get continuous AI pentesting at no cost. Hex Security covers IDORs, broken access control, XSS, and infra misconfigs across every deploy.
Why it matters: Company publishing — post cadence and depth hint at product velocity.
Open source ↗Sign in as an active team member to view private notes, watchlist controls, transcript evidence, and interaction history.