About
Casco builds autonomous, always-on security testing for web applications, APIs, infrastructure, and AI systems. It sells to enterprises and fast-moving startups, differentiating through continuous testing, optional human supervision, and compliance-ready penetration-test reports.
Market
Casco competes in autonomous and continuous penetration testing, application security, cloud security, and AI red teaming. Its positioning is AI-native and agentic: it uses supervised AI agents and expert-like, multi-step attack simulation to provide year-round testing across applications, infrastructure, and AI systems, while retaining optional human oversight. This differentiates it from episodic traditional pentests and noisy automated scanners by emphasizing broader coverage, faster testing, and compliance-ready reporting.
Casco targets security teams and technical buyers at enterprises and fast-moving startups building web applications, APIs, cloud infrastructure, and AI agents or applications. It is especially relevant for organizations seeking year-round testing, remediation guidance, and penetration-test evidence for SOC 2 or ISO 27001 compliance.
At a Glance
Problem
Casco addresses the gap between periodic, point-in-time penetration testing and the need to continuously test a modern technology stack. Its target customers need security coverage across web applications, APIs, infrastructure, and AI systems, while traditional pentesting is the incumbent alternative they are seeking to move beyond. The central use case is always-on testing across a broad and changing attack surface, particularly for fast-moving companies that cannot rely solely on occasional manual assessments.
The economic case is the potential to obtain more continuous coverage and reduce dependence on recurring traditional pentester engagements, although the available research does not disclose pricing, quantified savings, or specific breach-cost data. Casco's positioning suggests that speed, breadth, and ongoing testing are the primary sources of value rather than a one-time compliance exercise.
Product / Service
Casco provides autonomous security testing as a software-led service. It tests web apps, APIs, infrastructure, and AI systems continuously, with human supervision available optionally. In practice, this gives customers an always-on testing layer that can operate across multiple parts of their environment without requiring every assessment to be performed manually.
The benefit is broader and more persistent security validation than a conventional periodic engagement, with the option to involve humans when additional oversight is useful. The company sells through a demo-led model and positions its service as an alternative selected by fast-moving companies over traditional pentesters.
Market
Casco competes in autonomous security testing and the broader application, infrastructure, API, and AI security-testing market. The clearest incumbent alternative identified in the research is the traditional penetration-testing provider; no specific direct competitors are named in the available evidence. Its scope across conventional software infrastructure and AI systems gives it a positioning at the intersection of automated pentesting, continuous security validation, and AI security.
Casco reports that it is trusted by more than 300 companies, ranging from enterprises to fast-moving startups, and displays customers or users including Gusto, CrewAI, Daytona, Whop, Spreedly, and others. Its LinkedIn profile identifies it as a privately held San Francisco data-security software company founded in 2025 with a small team; the available evidence does not provide revenue, funding, or profitability figures, so it should be treated as an early-stage company with meaningful customer traction rather than assigned a definitive revenue status.
Founders & Leadership
Funding History
Y Combinator, Rebel Fund, Batch Ventures, FundersClub, Pioneer Fund
Recent News
Casco introduced improved network observability, describing a unified system to receive security noise, recover context, run tests, and preserve evidence.
Casco announced an MCP server that connects its autonomous security-testing findings to AI assistants and coding agents such as Claude Code, Codex, and Cursor.
Casco announced a Series A led by Standard Capital, bringing its total capital raised to $17 million at a $100 million valuation.
Casco published a vulnerability disclosure concerning a database takeover in ElectricSQL.
Casco announced that it achieved CREST accreditation, meeting rigorous international standards for penetration-testing excellence.
Casco published guidance on building self-securing software using autonomous security testing and continuous security assessments.
Casco published an article addressing the OWASP Top 10 2025 and the implications of the updated security landscape.
Casco discussed why an apparently clean penetration-test report can be a warning sign rather than evidence that an application is secure.
Casco announced that it became a Gold Sponsor of the OWASP AI Exchange to help advance AI-security practices globally.
Active Roles
6Business Model
Casco monetizes a cloud-based B2B security-testing service through tiered, usage-based pricing. Its terms specify one-year subscriptions that renew annually, with monthly automatic payment based on the selected product tier and customer usage.