Miju Labs

The security dossier

The autonomous pentest field

Ask one question of every company here — are they selling software that attacks, or human-generated data about attacking? Nine of nine sell the software, which is why nobody is currently selling the data.

high confidence9 minupdated 2026-08-30xbow · horizon3 · dreadnode · runsybil · competitor map

Every well-funded company adjacent to offensive-security data sells software that attacks. Not one sells human-generated data about attacking. That is the finding, and the cleanest way to hold it is to put a single question to each profile below.

Are they selling software that attacks, or human-generated data about attacking?

The answer determines whether a given company is a competitor for the same customer, a competitor for the same supply, or a customer. Those three are routinely confused, and confusing them is how a competitive map becomes useless.

CompanySellsHuman crowd or team?Human data as product?Relationship
XBOWAutonomous pentest softwareIn-house hacker teamNoSupply competitor, possible customer
Horizon3.aiNodeZero autonomous pentestNoNoDemand-side context
RunSybilAutonomous pentest agentNo — "no humans in the loop"NoNeither
Terra SecurityAgentic pentest + human-in-loopUnclear [UNVERIFIED]NoDepends on the answer
DreadnodeStrikes / Spyglass / CrucibleNoPlatform-generated onlyDepends on the answer
Strix (OmniSecure)Open-source + hosted agentNoNoPrice floor
ZeroPathAI SASTNoNoNeither
MindFortAutonomous pentest agentNoNoNeither

The scale player: Horizon3.ai

The clearest evidence of what autonomous attack software is worth, and the demand-side context for everything else on this page.

$250M Series E, 3 August 2026, led by NightDragon and NEA (both returning), at a $2B+ valuation, following $100M in June 2025 (TechCrunch; Business Wire). Revenue approached $100M ARR last year, growing 120% year on year — by far the best-verified revenue figure anywhere in this sector. Roughly 7,200–7,300 customers, from MSPs to the Fortune 10. Founders Snehal Antani and Anthony Pillitiere met at Joint Special Operations Command.

Its product, NodeZero, is explicitly positioned as a replacement for human pentesters; TechCrunch frames the market shift as away from firms that "hire human security firms to run annual tests."

So the $2B outcome in this category belongs to a company displacing human offensive labour. That is the environment in which anyone would be selling human offensive labour, and it should be stated rather than smoothed over.

The one that buys the supply: XBOW

The most client-relevant company on the page, for a reason that has nothing to do with its product.

$120M Series C, 18 March 2026, co-led by DFJ Growth and Northzone with Sofina, Alkeon, Altimeter, NFDG and Sequoia, at a valuation over $1B, $237M total raised (SecurityWeek), on top of a $75M Series B in June 2025 (Help Net Security). Founder Oege de Moor created GitHub Copilot and GitHub Advanced Security, having previously founded Semmle. XBOW's most-cited credential is that its AI reached the top of the HackerOne leaderboard.

The detail that matters: XBOW's CISO Nico Waisman, formerly Lyft's CISO, "assembled a team of professional hackers to train the system."

That is a payroll of expert humans producing training signal for an attack model — precisely the demand a specialist data company would serve, currently being met by in-housing. XBOW is a competitor for the same supply that is not a competitor for the same customer. It bids for the same scarce practitioners and sells to enterprises buying pentests, not to labs buying data. Whether it would buy that supply rather than employ it is the single highest-value commercial conversation available on this page.

The pattern worth naming

In-housing is what every buyer does before a market exists. XBOW hires hackers; Mechanize pays environment engineers $500K salaries; Anthropic is recruiting a Research Engineer for cyber RL at $300–405K. Each of those is a buyer proving demand by satisfying it the expensive way. See The labs as buyers.

The rest of the field

RunSybil. $40M, 18 March 2026, led by Khosla Ventures with S32, Anthropic's Anthology Fund, Menlo, Conviction, Elad Gil and angels from OpenAI, Palo Alto Networks, Stripe and Google (Fortune). Founders Ari Herbert-Voss — OpenAI's first security research hire, joined 2019 — and Vlad Ionescu, who led offensive security red teams at Meta. Their agent conducts continuous autonomous pentests "without humans in the loop," a phrase they use deliberately. Named customers: Cursor, Turbopuffer, Notion, Baseten, Thinking Machines Lab. Note the pedigree and the cap table: the talent and the capital in this category both run directly through the frontier labs.

Dreadnode. The company closest to the data question and the one with the most unresolved answer. $14M Series A, 25 February 2025, led by Decibel with Next Frontier Capital, In-Q-Tel, Sands Capital, Indie VC, Aviso Ventures and Jon Oringer (Dreadnode). Founders Will Pearce (CEO) and Nick Landers (CTO), both former AI red-team leads. Three products: Strikes (cyber evaluation and capability testing), Spyglass (AI red-team toolkit) and Crucible (an AI hacking sandbox for practitioner training). Dreadnode describes Strikes as generating "valuable training data for models and agents," and the In-Q-Tel investment signals US intelligence-community interest.

Strix (OmniSecure, Inc.). An open-source AI pentest agent under Apache-2.0 with 50,000+ GitHub stars and 5,000+ forks (Strix), launched publicly around November 2025 (Help Net Security). Free tier plus enterprise plans, hosted LLMs or local models via Ollama and vLLM. Its claimed user logos — AWS, PayPal, Uber, Cisco, ByteDance, Ford, Pfizer and others — are marketing and should be treated as such.

Strix matters as the price floor: a capable attack agent is now free and open source. Any pitch that assumes offensive capability is scarce has to answer for that.

Terra Security. $38M total — $8M seed April 2025, then a $30M Series A on 15 September 2025 led by Felicis with Dell Technology Capital and SVCI (SecurityWeek). Founder/CEO Shahar Peled; former Google CISO Gerhard Eschelbach on the board. The product is "a swarm of AI agents" running continuous tailored tests — with a human-in-the-loop mechanism delivering context-aware testing. The clearest hybrid in the category: agents at volume, humans for judgment.

ZeroPath. AI-native SAST — code analysis, not live attack. No human crowd, no trajectory data, the least relevant company here.

MindFort. $3M+ seed, 21 April 2026, led by Soma Capital with Y Combinator, 468 Capital, CRV, Sandwith and Blast (MindFort). Founders Brandon Veiseh and Akul Gupta, YC X25. Fully agentic pentests on schedule or on every CI/CD push, producing exploit proofs and fix PRs into GitHub, Linear and Jira. Setup in under fifteen minutes, no human crowd.

Also in the 2025–26 cohort, all software: AIM Intelligence ($7M Series A, April 2026, Samsung Venture and Mirae Asset), White Circle ($11M seed, May 2026, angels from OpenAI, Anthropic and Mistral), Trent AI ($13M seed, April 2026, LocalGlobe and Cambridge Innovation Capital) and WitnessAI ($58M Series B, January 2026) (New Market Pitch). The compiler of that deal list reaches the same conclusion independently: the dataset "contains no dedicated 'crowd data' or data-labeling companies for offensive security."

Four unresolved items, each of which flips a classification

These are not tidy-up items. Each one determines whether a company belongs in the competitor column or the customer column, and none is resolvable from public sources.

ZeroPath's funding is irreconcilable. SignalBase reports a $20M seed; a LinkedIn post from Raphael Karger announces $7M. These may be separate rounds or one may be wrong. Nothing reconciles them, and the founders are described only as "security engineers from Tesla and Google" by an aggregator that does not name them.

Strix/OmniSecure's founders and funding are undisclosed. Neither the site nor any coverage gives either. A company with 50,000 GitHub stars and an enterprise tier is not a hobby project, and knowing who capitalised it would say a great deal about whether the free agent is a loss leader for something else.

Terra Security's "human-in-the-loop" is undefined. Employees, contractors or a managed crowd — the coverage does not say. If it is a crowd, Terra is a direct competitor. If they are employees, Terra is a customer. No other single unknown on this page moves a company that far.

Whether Dreadnode productises human trajectory data from Crucible is unknown. Crucible is a practitioner training sandbox, which by construction generates human trajectory data. Nothing establishes whether that is productised. If it is, Dreadnode is the closest competitor in the sector; if it is not, an In-Q-Tel-backed platform sitting on unmonetised human trajectories is the most interesting partnership conversation available.

The column that matters is empty. Nine companies, none selling human offensive data as a product. That is either a market gap or a market verdict, and The bounty platforms is where the evidence for the second reading lives. Compare Gray Swan, in full, which acquires the data and sells the software, and Irregular, in full, which sells the judgment and never ships the data at all. See Offensive security for the vertical read, The defensive vendors for the same exercise on the blue-team side, and The generalists in cyber for who is already paying these people by the hour.