Today we announced $19 million in new funding, bringing Hackuity's total funding to $38 million. The round was led by Forgepoint Capital International, alongside our existing investors Bright Pixel, Bpifrance and Seventure Partners.
Here is what they are backing: a platform that manages more than one billion findings across over 2 million assets, used by more than 6,000 security, IT and engineering practitioners, connected to 130+ security tools.
Enterprises including ENGIE and Groupe BPCE run their vulnerability operations on it, and partners such as Orange Cyberdefense deliver it to their own clients.
We’re proud of that. What matters now is what this funding enables our customers to do next.
Why now? The last assumption AI broke
In the AI era, code is generated faster than it can be reviewed. Infrastructure is spun up faster than it can be inventoried. Scanners themselves produce more findings than any team can read. And now, AI-powered detection adds a fourth accelerant: surfacing more vulnerabilities, faster than any human process can absorb.
No security team grows at that rate. None ever will. Findings and headcount stopped tracking each other years ago, and those two curves are never meeting again.
Rather than a story about attackers getting smarter, this is a story about arithmetic.
When we founded Hackuity in 2020, we bet the company on a single conviction: “detecting vulnerabilities is no longer the challenge, managing their volume is”.
Six years later, it has become the defining operational problem of every large security organization we talk to.
The regulatory environment has closed the last exit: NIS2 requires demonstrable vulnerability handling processes across essential and important entities, and DORA holds financial institutions accountable for the resilience of their entire ICT estate, including third parties. "We had too many findings to triage" has stopped being an explanation and become a finding of its own.
Our thesis: don’t think of detection as the limiting factor
Companies have invested heavily in knowing where they are exposed. Most large organizations now run several detection tools across cloud, endpoints, applications, identities or infrastructure.
For many large organizations, the biggest operational gap lies between a finding appearing and a fix being deployed.
Someone must decide whether the finding is an actual threat and whether it matters here, in this environment, on this asset. Someone must identify who owns the system. Another one must convince that owner to change their sprint. Then security, IT and engineering must agree on sequencing and track the work to completion. When that information lives in six disconnected tools, each of those steps is done manually… and done again next month.
Rather than being measured in dashboards, the cost is being measured in engineering capacity.
"Before Hackuity, we wasted 40% of our security engineering capacity simply cleaning and arguing over our scanner outputs. Now, we run a unified remediation queue mapped directly to internal owners." - CISO, Fortune 500 customer (anonymous)
40% of a scarce, expensive, hard-to-hire team spent preparing to reduce risk rather than reducing it: That is the problem we exist to remove.
The solution: what changes when the work is connected
- Across our enterprise deployments, the pattern is consistent:
- As little as 0.01% of raw findings have surfaced as genuinely critical, by scoring exploitability, asset criticality and business impact rather than severity alone;
- Mean time to remediate has been cut to a third of the pre-deployment baseline;
- Up to 70% of exposure-management activities is has been automated, from enrichment and de-duplication to ticket creation and closure verification;
- Documented savings ranged from $100,000 to more than $1 million per year, depending on estate size and team structure.
What these numbers describe is not a better dashboard: it is capacity returned to people who were doing work a machine should have done and who can finally do what they were hired for, which is applying real security expertise to what the business depends on.
Hackuity: One operational layer across the vulnerability stack
This is the thinking behind Hackuity's AI-powered Vulnerability Operations Center (VOC): we bring findings and asset data from 130+ security tools into a single operational view.
Our customers keep the tools they already own and the investment they already made: IoT, endpoint, cloud, applications, identities... they can keep choosing the best-in-class detection tools for each environment, and we remove the work of stitching the outputs together.
We then apply business and threat context, exploitability, asset criticality, exposure, and business ownership through our True Risk Score, so that a team of fifteen can act on the twenty things that matter this week instead of manually triaging forty thousand things that do not.
Those priorities drive coordinated remediation across security, IT and engineering, with ownership assigned, progress tracked and closure verified.
The connection between those steps is the whole product. A priority without an owner is a wish. An owner without context is an argument. A remediation task without verification is an assumption.
Where the $19 million goes
Our direction is to build on the automation already in place and make the full chain increasingly autonomous, while keeping teams in control.
It starts with an assistant that does the triage work a human should no longer be doing: reading every finding, correlating it against real exposure, and discarding the noise before a person ever has to look at it.
Then orchestration: the layer that decides, of what's left, what gets fixed first, by whom, and in what order. Sequencing is a decision teams have been making manually, finding by finding, for years. We're making it a system's job.
Then closed-loop remediation, the part most vendors stop short of. Opening a ticket is not fixing a vulnerability. We close the loop: verifying the fix actually landed, re-testing the exposure, and only then marking it resolved.
None of this is about putting AI on top of a dashboard. It is about measuring not how much we found, but how much actually got fixed. We want to make that outcome measurable across the entire remediation process.
The $19 million goes into extending and strengthening that chain from end to end.
Why Forgepoint
On paper, all money looks the same. It is not.
Forgepoint Capital International has been backing cybersecurity companies exclusively since 2015, with an advisory council of more than 100 industry operators and a footprint running from the Bay Area to London. For a Lyon-based company selling to global enterprises, that network matters considerably more than the wire transfer.
We will be candid about what decided it. Of all the funds we met, Forgepoint was the one that spent more time on our roadmap than on our multiples. That tells you something about the next three years.
And four years after backing a thesis that did not yet have a name, Bright Pixel, Bpifrance and Seventure Partners are doubling down. That speaks for itself.
Visions of the future: what we are building toward
We want Hackuity to be the operational foundation enterprises rely on to manage vulnerability risk: the layer that connects their existing security tools, maps their assets, gives every team the same priorities, and drives action across the business without adding manual work at every step.
The measure of success is not a feature list. It is less time spent deciding what matters, fewer delays finding the right owner, and faster action on the vulnerabilities that genuinely threaten the business.
To our customers and partners: thank you for the trust, and for the unvarnished feedback that shaped this platform.
To our investors: thank you for backing a conviction before it was obvious.
And to everyone at Hackuity: you spent years making a brutally hard problem look simple. That is the actual job. Thank you.
Our ambition is clear: help teams turn growing volumes of findings into faster, verified fixes.
Is your team spending more time sorting findings than fixing them?
We would like to hear what is getting in the way.
VR-1 | Property |
|---|---|
Model type | Post-trained cyber reasoning model |
Primary specialization | Multi-domain enterprise attack-chain discovery |
Starting condition | A scoped foothold and a concrete objective |
Operating surfaces | Cloud, identity, runtime, code, CI/CD, SaaS, and organizational context |
Success signal | Execution-verified completion of the objective |
Primary evaluation | IntrusionBench |
Preliminary result (preview) | More than 2× black-box pass@3 over the strongest evaluated frontier baseline |
Trajectory budget | Two-hour wall-clock limit per trajectory, or 250 agent turns (whichever comes first) |









