Companies

Escape

escape.tech

Escape provides AI-powered offensive security, continuously pentesting APIs and applications for engineering teams.

HQSan Francisco, California, United States
Employees1-50
3 active roles
Jobs checked 22h ago
CybersecurityAI-EnhancedB2B SaaS

About

Escape builds an AI-powered offensive security platform for security and engineering teams at enterprise organizations. Its agents continuously discover, test, and remediate application and API vulnerabilities, differentiating the platform through business-logic-aware testing, IDOR scanning, multi-tenant capabilities, and automation that scales beyond manual pentests.

Market

Escape competes in API security, application security, DAST, attack-surface management, and automated offensive-security markets. It differentiates from general-purpose DAST and manual penetration testing through AI agents, agentless discovery of internal and external APIs and SPAs, API-native testing, business-logic testing, GraphQL coverage, and CI/CD integration.

Target Customers

Escape primarily targets Application Security and Engineering teams at API-centric organizations that build and operate SPAs, APIs, microservices, and other distributed applications. The principal buyers and users are AppSec leaders, security engineers, and developers seeking to automate API discovery, testing, and remediation; a specific company-size profile is not explicitly stated.

At a Glance

Problem

Security teams are increasingly outnumbered by the scale and complexity of modern applications, APIs, cloud infrastructure, and rapid release cycles. Escape targets the gaps left by legacy scanners and manual offensive-security processes: conventional DAST often misses business-logic flaws, authorization failures, multi-step workflows, and multi-tenant issues such as IDORs. The resulting pain is both operational and financial—security engineers spend substantial time triaging noisy findings and coordinating manual tests, while important vulnerabilities can remain undiscovered.

The clearest use case is continuously testing modern APIs and applications at the level of real business workflows, then proving whether complex attack paths are exploitable. Escape cites customer outcomes including a manual pentest process reduced from five days to five hours, 12 hours saved per security engineer per month, and a 50% reduction in application risk within the first weeks; these are company-reported customer claims rather than independently verified benchmarks.

Product / Service

Escape positions itself as an offensive-security engineering platform that automates the lifecycle from discovery through remediation and compliance. Its Attack Surface Management product discovers APIs, single-page applications, and other assets in real time; its business-logic-aware DAST tests workflows, access control, authentication, and multi-step processes; and its AI Pentesting agents use graph context to reason through attack chains and provide screenshots, execution logs, and proof of exploitability. The platform is designed to work with modern OAuth, SSO, and multi-tenant environments rather than relying only on conventional payload scanning.

The delivery model is an integrated, programmable platform with APIs, a CLI, an MCP server, event-based workflows, CI/CD security gates, and integrations into security and developer tooling. It also offers AI-assisted remediation with code suggestions tailored to the customer’s technology stack, allowing findings to flow to the responsible engineering teams with context. The intended benefit is to replace point-in-time manual pentests, bug-bounty dependence, and disconnected scanners with continuous, scalable testing and remediation.

Market

Escape competes in application security and offensive-security software, spanning attack-surface management, API security, business-logic-aware DAST, automated and AI-assisted penetration testing, remediation, and compliance automation. Its own competitive landscape names Noname Security, Salt Security, Qualys, StackHawk, Bright Security, Rapid7, Invicti, and other automated pentesting solutions. The company’s differentiation is its emphasis on API and business-logic coverage, exploit validation, IDOR and multi-tenant testing, and agentic reasoning across multi-step attack paths.

The available evidence indicates commercial traction rather than a pre-revenue-only posture: Escape says it is trusted by more than 2,000 security teams worldwide and reports customer examples involving application-risk reduction, ROI, coverage improvement, and replacement of manual pentesting. The corpus does not provide revenue, ARR, customer-count methodology, or pricing, so Escape’s financial scale and whether it is technically profitable or pre-revenue cannot be determined from the available material.

Founders & Leadership

Tristan KalosFounder
CEO
Antoine CarossioFounder
CTO

Funding History

2023-04
Pre-Seed (YC W23)$500K

Y Combinator

2023-06
Seed$3.9M

IRIS

2026-03
Series A$18M

Balderton Capital

Recent News

2026-07-07partnership
Introducing Escape's Partner Program

Escape announced a partner program officially opened on June 1, 2026, designed to help resellers, MSSPs, and consulting partners bring its offensive security platform to customers. Benefits include sales and technical training, sandbox access, deal registration, dedicated representatives, and marketing support.

2026-05-08product
How one of the leading FinTech platforms used Escape to automate business logic security testing at scale

Escape described how a European FinTech platform became a design partner for its AI pentesting product and helped shape capabilities such as attack-path visualization, multi-user attack graphs, and AI agents for business-logic testing.

2026-03-10funding
Escape raises $18M Series A to replace legacy scanners with AI agent-driven discovery, pentesting, and remediation

Escape raised an $18 million Series A led by Balderton Capital, with participation from Uncorrelated Ventures, IRIS, and Y Combinator. The company said the funding would accelerate full-lifecycle offensive security and AI-agent capabilities, alongside a new brand identity.

2026-01-26partnership
DoubleVerify case study: Escape x Wiz integration

Escape highlighted how its integration with Wiz helped DoubleVerify achieve full API visibility and accelerate targeted remediation. The integration combines Wiz cloud findings with Escape's application and API security testing.

2025-11-06product
[Webinar] Automating Offensive Security with AI: A Guide to Scaling Pentesting with Escape

Escape announced a webinar focused on practical automation of offensive security, including how AI-driven pentesting differs from legacy DAST and manual testing. The session also covered tenant-isolation testing, attack-path discovery, and the Wiz integration.

2025-10-30
Feedback From Escape Customers: Securing AI-Driven Applications with DAST

Escape published customer feedback on using DAST to secure AI-driven applications, reflecting its broader focus on application security testing as AI becomes more embedded in software development workflows.

Active Roles

3
NYC Office/Technical Account Manager/9d ago
NYC Office/Sales/33d ago

Business Model

Escape sells recurring B2B software subscriptions for automated API and application security. Plans are structured around usage, including the number of scanned applications, APIs, or developers; the company also sells through AWS Marketplace and negotiates enterprise pricing.

Products

Escape DASTAttack Surface ManagementAPI Discovery and API InventoryDynamic GraphQL Security TestingAI-powered offensive security and continuous penetration testing

Customers

BetterHelpPandaDocCyberCubeArkose LabsShine (Société Générale)SorareNeo4jBridgetech GroupApplied SystemsDoubleVerifyFrench Football FederationSungage FinancialLightspeedThinkific

Tech Stack

AI agents for automated API discovery, security testing, and remediationAgentless API scanning and inventoryAPI-native DAST for REST and GraphQL APIsCI/CD, repository, cloud-provider, and ticketing integrationsCLI, public API, and MCP Server tooling

Competitors

Rapid7
XBOW
StackHawk