Companies

Corgea

corgea.com

Corgea uses AI to find application vulnerabilities and deliver developer-ready fixes across code, infrastructure, and containers.

HQSan Francisco, California, United States
Employees1-50
7 active roles
Jobs checked 11h ago
CybersecurityAI Agent / AutomationB2B SaaS

About

Corgea builds an autonomous, AI-native application-security platform that finds and validates vulnerabilities across code, packages, infrastructure, and containers, then generates fixes developers can apply in their existing workflows. It sells to development and security teams, differentiating through detection of business-logic and authentication flaws that traditional scanners often miss, while reducing false positives and remediation effort.

Market

Corgea competes in application security and DevSecOps, spanning static code analysis, dependency/package security, infrastructure and container scanning, automated remediation, and AI-driven penetration testing. It positions itself as an AI-native, developer-first alternative to traditional scanners by validating which findings are real, reducing false positives, and delivering safe, developer- and agent-ready fixes rather than merely reporting vulnerabilities.

Target Customers

Corgea primarily targets software companies with active engineering and security/AppSec teams—especially organizations that need to reduce vulnerability-triage and remediation effort without adding headcount. Its buyers and users are likely security leaders and developers, with engineering teams approving the generated fixes; named production customers include Zapier and Yageo.

At a Glance

Problem

Corgea addresses the gap between finding application vulnerabilities and actually fixing them. Traditional SAST and related security tools can generate noisy findings while missing business-logic flaws, broken authentication, and authorization gaps hidden in real application flows. As software teams adopt AI coding assistants and ship faster, the volume and risk of insecure code increase, leaving security teams with costly triage, developer coordination, and remediation work that can slow releases or require additional headcount.

The killer use case is turning a validated security finding into a reviewable fix inside the developer’s existing workflow. Corgea says its workflow can eliminate roughly 80% of the work involved in remediation, while customer evidence cites more true positives, fewer false positives, and faster patching without adding headcount. Its AI pentesting product extends the same value to compliance and enterprise sales by producing validated findings and auditor-ready evidence in hours rather than waiting weeks for a traditional test.

Product / Service

Corgea is an AI-native application-security platform that detects, prioritizes, validates, and fixes insecure code, packages, infrastructure, and containers. It can connect to existing SAST and SCA tools such as Snyk and Semgrep, use their findings as input, generate contextual code changes and explanations, and open pull requests for developers to review. The platform also integrates with GitHub, GitLab, Azure DevOps, Bitbucket, Harness, and common IDEs, allowing security work to occur where engineers already build and ship software.

Its newer AI Pentest offering uses a multi-agent architecture: specialized agents investigate authentication, APIs, injection, access control, and other attack paths, adapt their testing to the application, validate exploitability, and generate evidence-backed reports. The service is delivered through one-time or continuous pentests, with published Standard and Comprehensive plans priced at $4,000 and $8,000 per pentest and enterprise plans for recurring, multi-application programs. The intended benefit is a closed loop from discovery to remediation and retesting, reducing false positives and shortening the time from security finding to verified fix.

Market

Corgea competes in application security and the emerging DevSecOps automated-remediation category, spanning AI-assisted SAST, vulnerability management, software-supply-chain security, and autonomous penetration testing. Its named comparison set includes Snyk, Checkmarx, Semgrep, Aikido, and GitHub, while traditional human penetration testing is an adjacent alternative. Corgea positions itself against incumbent scanners by emphasizing business-logic and authorization coverage, exploitability validation, developer-native remediation, and a single workflow across code and cloud.

The company appears commercial rather than pre-revenue: Y Combinator identifies production customers including Zapier and YAGEO, Corgea publishes an epilot case study, and its site claims thousands of developers and more than 71,000 scans per month. It raised a $2.6 million seed round led by Shorooq Partners in November 2024, with Y Combinator and other investors participating, and was recognized by IDC as an Innovator for DevSecOps Automated Remediation. Corgea does not disclose revenue in the available materials, so the evidence supports early customer traction and paid product offerings, not a quantified revenue scale.

Founders & Leadership

Ahmad SadeddinFounder
CEO and Founder
Adam BronteFounder
Co-founder
Tamara AbualhsanFounder
Co-founder
Yutaka HosoaiFounder
Co-founder

Funding History

2023-01
Accelerator / Incubator$500K

Y Combinator

2023-09
Pre-seedNot disclosed

Not publicly disclosed

2024-11
Seed$2.6M

Shorooq Partners, Y Combinator, Decacorn, Unbound Ventures, Propeller Ventures

Recent News

2026-07-30partnership
Changelog - July 30, 2026

Corgea announced Linear ticketing directly from vulnerability and dependency findings, along with branded PDF scan reports and simpler self-service SSO group mapping. The release also added self-hosted GitLab support and other workflow and reliability improvements.

2026-07-23product
Changelog - July 23, 2026

Corgea highlighted improved SAST and SCA scan-coverage visibility, malicious-dependency blocking, and broader vulnerability search and export workflows. The release also added Harness source-control integration provisioning through the API.

2026-07-23
CVE-2026-44891, 55831, and 55833: Netty 4.1.136 / 4.2.16 patch STOMP and SPDY DoS primitives

Corgea published research on newly disclosed Netty vulnerabilities affecting STOMP and SPDY components. The advisory explains that attacker-sized STOMP header sets could accumulate in memory and identifies affected Maven coordinates and denial-of-service risks.

2026-06-24product
Corgea: Agentic Pentesting

Corgea launched an autonomous penetration-testing engine that uses AI agents to plan, execute, validate, and report security tests. Corgea says a recent test found 25 findings versus six for a human pentester and was delivered in 4–8 hours instead of two weeks.

2025-12-26
The 9 top cybersecurity startups from Disrupt Startup Battlefield

TechCrunch featured Corgea among the top cybersecurity startups from Disrupt Startup Battlefield. The coverage describes Corgea as an AI-driven enterprise security product that scans code for flaws and detects broken security-related code.

2025-08-27
The 2025 Startup Battlefield 200 is here — see who made the cut

TechCrunch announced its 2025 Startup Battlefield 200 selection and listed Corgea among the selected companies. The selection provided press exposure ahead of TechCrunch Disrupt 2025.

Active Roles

7
San Francisco, CA, US / San Mateo, CA, US / Remote (CA, US)/Engineering/35d ago
JO / Remote (JO)/Engineering/35d ago
JO / Remote (JO)/Engineering/35d ago
San Francisco, CA, US / San Mateo, CA, US / Remote (CA, US)/Engineering/35d ago
San Francisco, CA, US / San Mateo, CA, US / Remote (US)/Engineering/35d ago
San Francisco, CA, US / Remote (US; CA, US)/Engineering/35d ago
JO / Remote (JO)/Engineering/35d ago

Business Model

Corgea operates as a SaaS application-security platform with a free tier, paid per-developer plans, and custom Enterprise pricing. Public paid plans include Growth at $39 per developer per month and Scale at $49 per developer per month, while Enterprise adds governance, deployment, SLA, and support capabilities.

Products

Autonomous AI-native application security platform for finding, validating, prioritizing, and fixing vulnerabilitiesCode and package security with automated remediationInfrastructure and container security scanningCorgea AI Pentest, an autonomous AI-agent penetration-testing engine

Customers

ZapierYageoEpilotSpeechLabChippFirst ResonanceSonaerepacketDandyLevers

Tech Stack

AI and autonomous AI agentsAI-native static application security testing (SAST)Vulnerability detection and validationReachability-aware vulnerability prioritizationAutomated source-code remediation and pull requestsCode, package, infrastructure, and container scanning

Competitors

Snyk
Semgrep
SonarQube
Checkmarx
Veracode
GitHub Advanced Security (CodeQL)