Arcane Security
Acquired by SafeHill (March 2026) specifically to secure the rise of AI-generated software development, integrating Arcane's continuous automated pentesting into SafeHill's code-analysis and application-security offering; a logical, thematically-tight combination though both companies are early-stage.
+ Add to CompareInnovation Matrix Assessment
Autonomous agent-based penetration testing at scale, with human oversight retained, is a genuinely emerging offensive-security approach.
Targets a timely, concrete problem: security validation of rapidly-proliferating AI-generated application code.
March 2026 acquisition by SafeHill directly ties Arcane's technology into a code-security roadmap, though both firms are early-stage and the deal is small.
Continuous autonomous pentesting is a meaningful evolution beyond periodic manual penetration tests.
No independent benchmark comparing autonomous testing coverage/accuracy to manual pentesting has been published.
Security validation of AI-generated ("vibe coded") software is a fast-growing and durable need as AI coding tools proliferate.
Why CISOs Should Care
Arcane Security is an AI-focused offensive-security firm using autonomous agent frameworks to simulate real-world attackers at scale, with human ethical hackers retained as a final oversight layer, addressing concerns about AI-generated ("vibe coded") application vulnerabilities.
What Makes It Different
Its pairing of autonomous AI-driven penetration testing with mandatory human validation is a deliberate middle path between fully-automated scanning tools and traditional manual pentest firms.
The Matrix Verdict
42/100 — EMERGING / UNRANKED
Acquired by SafeHill (March 2026) specifically to secure the rise of AI-generated software development, integrating Arcane's continuous automated pentesting into SafeHill's code-analysis and application-security offering; a logical, thematically-tight combination though both companies are early-stage.
Editorial Note: Claims vs. Verified Findings
Claims about automated vulnerability validation accuracy and coverage are vendor-stated; no independent, third-party benchmark of Arcane's autonomous pentesting against manual testing has been published.
Sources
Alternatives to Arcane Security
CyCognito
Agentless attack surface management platform that maps organizations' entire external footprint, including subsidiaries and shadow assets, using graph-based…
Armis (a ServiceNow company)
Agentless asset intelligence platform discovering and assessing every connected IT, OT, IoT and medical device, now part of…
CybelAngel
External attack surface management and digital risk protection platform that scans the open, deep, and dark web for…
watchTowr
Singapore-based platform combining external attack surface management with continuous automated red teaming to validate whether exposures are actually…
Axonius
New York-based CAASM pioneer that aggregates data from hundreds of existing tools to build a unified, agentless asset…
Doppel
San Francisco AI-native digital risk protection platform that detects and automatically takes down phishing sites, impersonation accounts, and…