Gecko Security
Gecko Security is a Y Combinator-backed AI security testing platform that uses LLMs and custom code indexing to find complex vulnerabilities traditional scanners miss, then helps verify and fix them, with the team already credited with discovering 30+ real CVEs in open-source projects.
Visit Website ↗ + Add to CompareOverview
Gecko Security describes its product as “the AI Security Engineer to Find and Fix Vulnerabilities,” using large language models combined with custom code-indexing techniques to identify complex, logic-level security flaws in applications that traditional pattern-matching scanners typically miss, then assist with verification and remediation.
Founded by Jeevan Jutla and Artemiy Malyshau, Gecko Security went through Y Combinator’s Fall 2024 batch and is based in London. The team has publicly credited its platform with finding more than 30 CVEs in widely used open-source projects including Ollama, Gradio, and Ragflow, and reports customers experience roughly 50% fewer false positives than with traditional scanners.
Innovation Matrix Assessment
Discovering and publicly disclosing 30+ real CVEs in significant open-source projects (Ollama, Gradio, Ragflow) within roughly a year of founding is a concrete, verifiable pace of technical output.
Finding logic-level vulnerabilities traditional scanners miss, combined with a reported reduction in false positives, would meaningfully reduce triage burden for security teams if the claims hold at scale.
As a two-founder, very early-stage company with no disclosed funding round or named enterprise customers, independently verifiable commercial momentum is currently limited beyond its technical CVE track record.
LLM-based reasoning over custom code indexes to find logic-level flaws, evidenced by real CVE discoveries in major open-source AI tooling, is a genuinely different and more capable approach than pattern-matching static analysis.
The 30+ publicly disclosed CVEs in named, widely used open-source projects is independently verifiable, credible evidence of real-world efficacy, even though the 50% false-positive reduction figure specifically is vendor-stated.
As AI-generated and AI-assisted code accelerates the volume of software shipped, tools capable of finding the complex logic-level flaws pattern-matching scanners miss are likely to grow in importance.
Why CISOs Should Care
Traditional static analysis tools routinely miss complex, logic-level vulnerabilities that require understanding application context; an LLM-based approach with a public track record of real CVE discoveries in major open-source AI tooling gives CISOs evidence-backed reason to evaluate it against harder-to-find vulnerability classes.
What Makes It Different
Gecko's use of custom code indexing alongside LLM-based reasoning to find logic-level vulnerabilities, combined with a public, verifiable CVE discovery track record, differentiates it from AI security tools that only claim capability without demonstrated findings.
The Matrix Verdict
53/100 — INCREMENTAL INNOVATOR
A young but demonstrably capable AI-driven vulnerability discovery vendor with real, publicly verifiable CVE credits in significant open-source projects; scores reflect genuine technical evidence tempered by very early commercial-stage maturity.
Editorial Note: Claims vs. Verified Findings
YC batch, founders, headquarters, and the 30+ CVE discovery claim in named open-source projects are independently confirmed via Gecko's Y Combinator company page; the 50% false-positive reduction figure is vendor-stated and not independently benchmarked.
Sources
Alternatives to Gecko Security
Adaptive Security
AI-driven platform that simulates deepfake, voice, and multichannel social-engineering attacks to train and test organizations against next-generation phishing.
Quilr
Early-stage agentic AI security startup building a 'Service-as-Software' platform to guard against human-related breaches and secure AI agent…
Zenity
Governance and security platform for AI agents and low-code/no-code development, securing agent identity, permissions and behavior across the…
Tenzai
An agentic AI penetration testing startup building autonomous 'AI hackers' to find and validate exploitable vulnerabilities at a…
Reco
Reco secures the "agentic ecosystem" — mapping what AI agents can access across SaaS and enterprise apps, detecting…
Charm Security
Agentic AI workforce that investigates and intervenes on scams and fraud in real time, reading manipulation and intent…