C

Casco

Spring 2025
casco.comB2BUnknown

Investor read

Evidence-bound summary — expand sections for movement, risks, and signals.

Memo snapshot · May 19, 2026, 7:58 PM

What they do

Casco - Autonomous Security Testing Casco performs autonomous security testing for web apps, APIs, infrastructure, and AI systems

Quick read

  • Casco - Autonomous Security Testing Casco performs autonomous security testing for web apps, APIs, infrastructure, and AI systems
  • Reported angle: What to Share When Clients Ask for a Pentest Report?
  • Indexed activity snapshot: 0 funding‑related row(s), 1 hiring‑related, 0 GitHub‑tagged, 20 product/news‑style — scoring reflects corpus coverage only.

Stage

Unknown

Evidence summary

Verified facts

  • Casco - Autonomous Security Testing Casco performs autonomous security testing for web apps, APIs, infrastructure, and AI systems
  • Reported angle: What to Share When Clients Ask for a Pentest Report?
  • Indexed activity snapshot: 0 funding‑related row(s), 1 hiring‑related, 0 GitHub‑tagged, 20 product/news‑style — scoring reflects corpus coverage only.
Nexus growth score
40.0Early / quiet
7D+0%
30D+0%
Medium Confidence

Source health

  • public_market_enrichmentok
    Last checked Mon, May 11, 09:04 AM
  • public_page:_pressnot_found
    Last checked Mon, May 11, 09:04 AM

    HTTP 404

  • public_page:_newsnot_found
    Last checked Mon, May 11, 09:04 AM

    HTTP 404

  • public_page:_jobsnot_found
    Last checked Mon, May 11, 09:04 AM

    HTTP 404

  • public_page:_companynot_found
    Last checked Mon, May 11, 09:04 AM

    HTTP 404

  • public_page:_careersok
    Last checked Mon, May 11, 09:04 AM
  • public_page:_blog_what-to-share-when-clients-ask-for-pentest-reportok
    Last checked Mon, May 11, 09:04 AM
  • public_page:_blog_what-to-pack-for-rsac-2026ok
    Last checked Mon, May 11, 09:04 AM
  • public_page:_blog_what-is-a-high-quality-penetration-testok
    Last checked Mon, May 11, 09:04 AM
  • public_page:_blog_we-hacked-ycombinator-agentsok
    Last checked Mon, May 11, 09:04 AM
  • public_page:_blog_vouch-insurance-and-casco-partnershipok
    Last checked Mon, May 11, 09:04 AM
  • public_page:_blog_the-myth-of-the-clean-pentest-reportok
    Last checked Mon, May 11, 09:04 AM
  • public_page:_blog_the-importance-of-rate-limitingok
    Last checked Mon, May 11, 09:04 AM
  • public_page:_blog_the-blueprint-of-a-north-korean-attack-on-open-sourceok
    Last checked Mon, May 11, 09:04 AM
  • public_page:_blog_owasp-top-10-2025-navigating-the-new-security-landscapeok
    Last checked Mon, May 11, 09:04 AM
  • public_page:_blog_owasp-ai-exchange-sponsorshipok
    Last checked Mon, May 11, 09:04 AM
  • public_page:_blog_no-more-clean-pentest-reportsok
    Last checked Mon, May 11, 09:04 AM
  • public_page:_blog_mcp-tool-poisoningok
    Last checked Mon, May 11, 09:04 AM
  • public_page:_blog_how-we-hireok
    Last checked Mon, May 11, 09:04 AM
  • public_page:_blog_how-to-hack-ford-for-130k-dollarsok
    Last checked Mon, May 11, 09:04 AM
  • public_page:_blog_electricsql-order-by-sql-injectionok
    Last checked Mon, May 11, 09:04 AM
  • public_page:_blog_dont-get-scammed-by-your-pentester-the-5-levels-of-pentestingok
    Last checked Mon, May 11, 09:04 AM
  • public_page:_blog_customer-crewaiok
    Last checked Mon, May 11, 09:04 AM
  • public_page:_blog_crest-penetration-testing-approvalok
    Last checked Mon, May 11, 09:04 AM
  • public_page:_blog_building-self-securing-softwareok
    Last checked Mon, May 11, 09:04 AM
  • public_page:_blogok
    Last checked Mon, May 11, 09:04 AM
  • public_page:_aboutnot_found
    Last checked Mon, May 11, 09:04 AM

    HTTP 404

  • public_page:_ok
    Last checked Mon, May 11, 09:04 AM
  • public_page:homeok
    Last checked Mon, May 11, 09:04 AM

Nexus score momentum

407D +030D +0
100500
2026-05-11: 40

More runs will build history.

Signal breakdown

Latest momentum signal per category. Expand a card to inspect raw payloads.

Score snapshots

Public source summary

Total evidence rows
22
Latest evidence
Mon, May 11, 09:04 AM

Source types found

blogcareers_pageofficial_site

Public signal timeline

Newest first · 22 event(s)

1
Mon, May 11, 09:04 AM · careers_page · 90% · publichigh quality

Careers at Casco - Join Our Mission

Source: Careers

Join Casco and help build the future of security. We are looking for talented individuals passionate about keeping systems safe and secure.

Source ↗
2
Mon, May 11, 09:04 AM · blog · 90% · publichigh quality

What to Share When Clients Ask for a Pentest Report?

Source: Blog / news

Even though clients intuitively ask for a pentest report, they are often not getting the right one. You are actually supposed to share the remediation report instead. This blog post explains why and what to share instead.

Source ↗
3
Mon, May 11, 09:04 AM · blog · 90% · publichigh quality

What to Pack for RSAC 2026

Source: Blog / news

Most security professionals pack for RSA like they're heading to Vegas in February. Wrong coast, wrong weather, wrong strategy. Here's everything you need to know.

Source ↗
4
Mon, May 11, 09:04 AM · blog · 90% · publichigh quality

Artifacts You Should Expect From a High-Quality Pentest

Source: Blog / news

High-quality penetration test don't just stop with an initial report, they should include retesting, remediation reports, and actively discourage the practice of ingenuine "clean" reports.

Source ↗
5
Mon, May 11, 09:04 AM · blog · 90% · publichigh quality

We hacked Y Combinator's AI agents and what you can learn from it

Source: Blog / news

How we hacked Y Combinator spring batch's AI agents and what you can learn from it for your AI agent's security.

Source ↗
6
Mon, May 11, 09:04 AM · blog · 90% · publichigh quality

Better together: Vouch Insurance and Casco

Source: Blog / news

Get 20% off your annual pentest and 5% off your insurance with Vouch Insurance and Casco.

Source ↗
7
Mon, May 11, 09:04 AM · blog · 90% · publichigh quality

Why "Clean" Pentest Reports are a Red Flag

Source: Blog / news

Why a "clean" pentest report is a red flag and how to spot the good penetration tests from the bad ones.

Source ↗
8
Mon, May 11, 09:04 AM · blog · 90% · publichigh quality

Why You Need Account-Based Rate Limits

Source: Blog / news

The Importance of Rate Limiting.

Source ↗
9
Mon, May 11, 09:04 AM · blog · 90% · publichigh quality

The Blueprint of a North Korean Attack on Open-Source

Source: Blog / news

Just in the last 7 days, we've seen LiteLLM and axios impacted by supply chain attacks. Recently, I was chatting with Bereket Engida, the creator of the popular JS auth library. He observed repeated attempts by a contributor to add malicious code directly via a pull request.

Source ↗
10
Mon, May 11, 09:04 AM · blog · 90% · publichigh quality

OWASP Top 10 2025: Navigating the New Security Landscape

Source: Blog / news

The release of the OWASP Top 10 2025 marks a pivotal moment for application security. While some classic vulnerabilities remain, the list reflects a world where software is increasingly complex and interconnected. For security teams, this means the goalposts have moved from finding simple bugs to securing entire ecosystems.

Source ↗
11
Mon, May 11, 09:04 AM · blog · 90% · publichigh quality

Casco Becomes Gold Sponsor of OWASP AI Exchange to Advance AI Security

Source: Blog / news

Casco is proud to announce that we have become a Gold Sponsor of the OWASP AI Exchange to advance AI security practices globally.

Source ↗
12
Mon, May 11, 09:04 AM · blog · 90% · publichigh quality

Our Policy on "Clean" Pentest Reports

Source: Blog / news

Effective April 12, 2026, Casco no longer issues "clean pentest reports". Here's what that means and how to verify report authenticity.

Source ↗
13
Mon, May 11, 09:04 AM · blog · 90% · publichigh quality

Understanding MCP Security: Tool Poisoning

Source: Blog / news

Why unverified MCPs can be a major vulnerability

Source ↗
14
Mon, May 11, 09:04 AM · blog · 90% · publichigh quality

How We Hire

Source: Blog / news

How we hire at Casco. Our mission is to make all software effortlessly secure. We hire with a simple 3-step process.

Source ↗
15
Mon, May 11, 09:04 AM · blog · 90% · publichigh quality

How to Hack Ford.com for $130,000

Source: Blog / news

How we hacked Ford.com for $130,000. This is a story about a forgotten subdomain and a $130,000 domain purchase that could have led to a massive breach.

Source ↗
16
Mon, May 11, 09:04 AM · blog · 90% · publichigh quality

Vulnerability Disclosure: Database Takeover in ElectricSQL

Source: Blog / news

A SQL injection vulnerability in ElectricSQL's ORDER BY parameter gave attackers full database access. The ElectricSQL team fixed and deployed it in 2 hours.

Source ↗
17
Mon, May 11, 09:04 AM · blog · 90% · publichigh quality

The 5 Levels of Penetration Testing

Source: Blog / news

Why many penetration test are not getting approved by clients and how to spot the good penetration tests from the bad ones.

Source ↗
18
Mon, May 11, 09:04 AM · blog · 90% · publichigh quality

CrewAI + Casco

Source: Blog / news

Announcing CrewAI as a customer of Casco.

Source ↗
19
Mon, May 11, 09:04 AM · blog · 90% · publichigh quality

Casco Achieves CREST Accreditation for Penetration Testing

Source: Blog / news

Casco is proud to announce that we have achieved CREST accreditation, meeting rigorous international standards for penetration testing excellence.

Source ↗
20
Mon, May 11, 09:04 AM · blog · 90% · publichigh quality

Building Self-Securing Software

Source: Blog / news

How to build self-securing software with autonomous security testing.

Source ↗
21
Mon, May 11, 09:04 AM · blog · 90% · publichigh quality

Security Blog - Insights on Autonomous Security Testing with Agentic AI | Casco

Source: Blog / news

Expert insights on security testing, autonomous security testing, and agentic AI security. Learn from our security engineers about the latest in cybersecurity.

Source ↗
22
Mon, May 11, 09:04 AM · official_site · 90% · publichigh quality

Casco - Autonomous Security Testing

Source: Homepage

Casco performs autonomous security testing for web apps, APIs, infrastructure, and AI systems. Get year-round protection with expert human supervision.

Source ↗

Official / company site

1 row(s)

official_site·Mon, May 11, 09:04 AM·Confidence 90%high qualitypublic

Casco - Autonomous Security Testing

Source name: Homepage

Casco performs autonomous security testing for web apps, APIs, infrastructure, and AI systems. Get year-round protection with expert human supervision.

https://casco.com/

Hiring

1 row(s)

careers_page·Mon, May 11, 09:04 AM·Confidence 90%high qualitypublic

Careers at Casco - Join Our Mission

Source name: Careers

Join Casco and help build the future of security. We are looking for talented individuals passionate about keeping systems safe and secure.

https://casco.com/careers

Blog

20 row(s)

blog·Mon, May 11, 09:04 AM·Confidence 90%high qualitypublic

What to Share When Clients Ask for a Pentest Report?

Source name: Blog / news

Even though clients intuitively ask for a pentest report, they are often not getting the right one. You are actually supposed to share the remediation report instead. This blog post explains why and what to share instead.

https://casco.com/blog/what-to-share-when-clients-ask-for-pentest-report
blog·Mon, May 11, 09:04 AM·Confidence 90%high qualitypublic

What to Pack for RSAC 2026

Source name: Blog / news

Most security professionals pack for RSA like they're heading to Vegas in February. Wrong coast, wrong weather, wrong strategy. Here's everything you need to know.

https://casco.com/blog/what-to-pack-for-rsac-2026
blog·Mon, May 11, 09:04 AM·Confidence 90%high qualitypublic

Artifacts You Should Expect From a High-Quality Pentest

Source name: Blog / news

High-quality penetration test don't just stop with an initial report, they should include retesting, remediation reports, and actively discourage the practice of ingenuine "clean" reports.

https://casco.com/blog/what-is-a-high-quality-penetration-test
blog·Mon, May 11, 09:04 AM·Confidence 90%high qualitypublic

We hacked Y Combinator's AI agents and what you can learn from it

Source name: Blog / news

How we hacked Y Combinator spring batch's AI agents and what you can learn from it for your AI agent's security.

https://casco.com/blog/we-hacked-ycombinator-agents
blog·Mon, May 11, 09:04 AM·Confidence 90%high qualitypublic

The Blueprint of a North Korean Attack on Open-Source

Source name: Blog / news

Just in the last 7 days, we've seen LiteLLM and axios impacted by supply chain attacks. Recently, I was chatting with Bereket Engida, the creator of the popular JS auth library. He observed repeated attempts by a contributor to add malicious code directly via a pull request.

https://casco.com/blog/the-blueprint-of-a-north-korean-attack-on-open-source
blog·Mon, May 11, 09:04 AM·Confidence 90%high qualitypublic

OWASP Top 10 2025: Navigating the New Security Landscape

Source name: Blog / news

The release of the OWASP Top 10 2025 marks a pivotal moment for application security. While some classic vulnerabilities remain, the list reflects a world where software is increasingly complex and interconnected. For security teams, this means the goalposts have moved from finding simple bugs to securing entire ecosystems.

https://casco.com/blog/owasp-top-10-2025-navigating-the-new-security-landscape
blog·Mon, May 11, 09:04 AM·Confidence 90%high qualitypublic

Casco Becomes Gold Sponsor of OWASP AI Exchange to Advance AI Security

Source name: Blog / news

Casco is proud to announce that we have become a Gold Sponsor of the OWASP AI Exchange to advance AI security practices globally.

https://casco.com/blog/owasp-ai-exchange-sponsorship
blog·Mon, May 11, 09:04 AM·Confidence 90%high qualitypublic

Our Policy on "Clean" Pentest Reports

Source name: Blog / news

Effective April 12, 2026, Casco no longer issues "clean pentest reports". Here's what that means and how to verify report authenticity.

https://casco.com/blog/no-more-clean-pentest-reports
blog·Mon, May 11, 09:04 AM·Confidence 90%high qualitypublic

Understanding MCP Security: Tool Poisoning

Source name: Blog / news

Why unverified MCPs can be a major vulnerability

https://casco.com/blog/mcp-tool-poisoning
blog·Mon, May 11, 09:04 AM·Confidence 90%high qualitypublic

How We Hire

Source name: Blog / news

How we hire at Casco. Our mission is to make all software effortlessly secure. We hire with a simple 3-step process.

https://casco.com/blog/how-we-hire
blog·Mon, May 11, 09:04 AM·Confidence 90%high qualitypublic

How to Hack Ford.com for $130,000

Source name: Blog / news

How we hacked Ford.com for $130,000. This is a story about a forgotten subdomain and a $130,000 domain purchase that could have led to a massive breach.

https://casco.com/blog/how-to-hack-ford-for-130k-dollars
blog·Mon, May 11, 09:04 AM·Confidence 90%high qualitypublic

Vulnerability Disclosure: Database Takeover in ElectricSQL

Source name: Blog / news

A SQL injection vulnerability in ElectricSQL's ORDER BY parameter gave attackers full database access. The ElectricSQL team fixed and deployed it in 2 hours.

https://casco.com/blog/electricsql-order-by-sql-injection
blog·Mon, May 11, 09:04 AM·Confidence 90%high qualitypublic

Casco Achieves CREST Accreditation for Penetration Testing

Source name: Blog / news

Casco is proud to announce that we have achieved CREST accreditation, meeting rigorous international standards for penetration testing excellence.

https://casco.com/blog/crest-penetration-testing-approval
blog·Mon, May 11, 09:04 AM·Confidence 90%high qualitypublic

Security Blog - Insights on Autonomous Security Testing with Agentic AI | Casco

Source name: Blog / news

Expert insights on security testing, autonomous security testing, and agentic AI security. Learn from our security engineers about the latest in cybersecurity.

https://casco.com/blog

Private workspace

Sign in as an active team member to view private notes, watchlist controls, transcript evidence, and interaction history.