Staris
AI-driven continuous penetration-testing platform using 'virtual security engineers' to find, prove, and patch exploitable application vulnerabilities.
Visit Website ↗ + Add to Compare Claim This CompanyOverview
Staris, based in Seattle, was founded in 2023 by Adam Cecchetti and Austin Fath, former Carnegie Mellon classmates. Cecchetti previously founded Deja Vu Security, a Seattle application-security firm acquired by Accenture in 2019, giving the founding team direct prior exit experience in the same market. Staris describes its product as building “virtual security engineers” that continuously review and harden application code, positioning itself less as a PR-review bot and more as an automated, continuous alternative to traditional manual penetration testing. Its “Total Context Security” platform is built around three claims: findings come with working, exploit-proven proof (not just pattern matches), engineers get PR-ready patches they can ship same day, and the company issues signed monthly “Receipts” that can be shown to boards, auditors, or customers as assurance evidence.
The company raised a $5.7M seed round (reported by GeekWire in 2025) led by Freestyle VC, and had six employees at the time of that raise. Its site names three customers with executive testimonials: OpsHelm (CEO Bill Gambarella) and AMI Asset Track (CEO Tom Watson), plus Atlas Networks. Staris markets claims of “zero false positives,” a “40:1 efficiency” gain over traditional pentesting, and cutting noise by 99% before findings reach a security team — all vendor-stated figures without independent benchmarking found in available sources.
For a CISO evaluating application security spend, Staris’s pitch is replacing or supplementing episodic, expensive manual pentests with continuous, exploit-validated findings at a fraction of the cost (plans start at $4,900/year, scaling to $4,500+/month for validated tiers). The founders’ track record (a prior successful AppSec company exit) is a real positive signal, but the company remains very small (single-digit employees as of its most recent public funding news) with only a few named customers, so its claims of efficiency and accuracy gains have not yet been independently tested at scale.
Innovation Matrix Assessment
Founders bring a prior successful AppSec exit (Deja Vu Security to Accenture) and have shipped a differentiated product concept (exploit-proof continuous pentesting) within about two years of founding.
Targets a genuine CISO pain point — the cost and cadence limits of manual penetration testing — with continuous, exploit-validated findings and board-ready reporting ('Receipts'), which if accurate as described would materially change AppSec operating cadence.
A $5.7M seed round, six employees at time of last public funding news, and only three named customers (OpsHelm, AMI Asset Track, Atlas Networks) indicate very early-stage, unproven market traction.
Automating exploit-proof penetration testing is a distinct angle from PR-review-centric competitors (DryRun Security, Dam Secure), but the continuous/automated pentesting space itself already has established players, limiting first-mover disruption claims.
Headline claims ('zero false positives,' '40:1 efficiency,' '99% noise reduction') are vendor-published with no independent audit, named-incident validation, or third-party test found in available sources.
Continuous, automated validation of exploitability addresses a durable AppSec need, especially as release cadences accelerate under AI-assisted development, likely to remain relevant over a 3-5 year horizon.
Why CISOs Should Care
Offers continuous, exploit-validated vulnerability findings with auditor/board-ready reporting as a lower-cost, higher-cadence alternative to periodic manual penetration tests.
What Makes It Different
Findings are demonstrated as actually exploitable (not just pattern-flagged) and paired with same-day-shippable patches, plus recurring signed 'Receipts' for external stakeholders.
The Matrix Verdict
47/100 — EMERGING / UNRANKED
A founder-credible, differentiated early-stage entrant in automated penetration testing, but still too small and thinly deployed for its efficacy claims to be independently confirmed.
Editorial Note: Claims vs. Verified Findings
Performance claims ('zero false positives', '40:1 efficiency gains', '99% noise reduction') are vendor marketing statements; no independent test or third-party validation was found and none should be inferred.
Sources
Alternatives to Staris
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…