Skip to content

Fleuret AI

Paris startup using two AI agents to run continuous, affordable penetration tests in place of one-off manual engagements.

Visit Website ↗ + Add to Compare Claim This Company
50/100Incremental Innovator

Overview

Fleuret AI automates penetration testing with agentic AI, aiming to make offensive security testing continuous and affordable rather than a once-a-year manual engagement. The platform uses two AI agents, named Emile and Champollion, to map systems, applications, APIs, and infrastructure, identify vulnerabilities, and test whether they can actually be exploited. Emile conducts the attack end to end, including reconnaissance, exploitation, a reproducible proof of concept, and an audit report.

Founded in 2026 by Yanis Grigy (CEO) and Augustin Ponsin (CTO), both Télécom Paris and EPITA graduates who had previously built a penetration-testing company together, Fleuret AI is based in Paris and hosts its findings through the European cloud provider Scaleway.

The company closed a €4 million pre-seed round in October 2026 led by RAISE Ventures, with participation from Auriga Cyber Ventures, Wind Capital, Better Angle, and several cybersecurity-industry angel investors, including the CEOs of Stoïk and GitGuardian.

Innovation Matrix Assessment

Innovation Velocity 6/10

Founders had prior pentesting-company experience and shipped a working agentic engine (Emile/Champollion) at launch.

Operational Value 6/10

Continuous, lower-cost pentesting addresses a real pain point for mid-market teams priced out of frequent manual engagements.

Market Momentum 3/10

Just a €4M pre-seed round announced October 2026; no disclosed customers or revenue yet.

Category Disruption 5/10

Agentic, continuous pentesting is a real trend, but it competes with several funded AI-pentesting entrants already active in the market.

Real-World Efficacy 4/10

Too early for independent efficacy evidence beyond the vendor's own product description.

Enduring Relevance 6/10

Demand for faster, cheaper, more frequent security testing (partly driven by EU rules like DORA and NIS2) should persist for years.

Why CISOs Should Care

Lets security teams run meaningful penetration tests far more often than an annual manual engagement allows, at a fraction of the cost.

What Makes It Different

Splits the work across two cooperating AI agents that both map the attack surface and execute exploitation end to end, rather than just flagging potential weaknesses.

The Matrix Verdict

50/100 — INCREMENTAL INNOVATOR

An Incremental Innovator at the very earliest stage: strong founder background and a real product, but no independent proof of efficacy or market traction yet.

Editorial Note: Claims vs. Verified Findings

All performance and capability claims currently come from the company and its launch coverage; no independent red-team validation or customer case studies were found.

Sources