Equixly
Florence, Italy-based startup using autonomous AI agents to continuously penetration-test APIs for business-logic and authorization vulnerabilities.
Visit Website ↗ + Add to CompareOverview
Equixly builds an AI agent-driven platform that continuously penetration-tests APIs, aiming to replace or supplement periodic manual API pentests with autonomous agents that probe for business-logic flaws, broken authorization, and other OWASP API Top 10-style vulnerabilities on an ongoing basis rather than a point-in-time snapshot. Founded in 2022 in Florence, Italy, by brothers Mattia and Alessio Dalla Piazza, the company frames its approach as agentic AI acting like a hacker embedded across the software development lifecycle rather than a static scanning tool.
API security is one of the fastest-growing attack surfaces because APIs proliferate faster than security teams can manually test them, and continuous, AI-driven testing is a real response to that scaling problem rather than a marketing repackaging of an old category. Equixly raised a €10 million Series A in December 2025, led by 33N Ventures with participation from Alpha Intelligence Capital, JME Ventures, and others, bringing total funding to roughly $13.3 million, and the company reports customers across European banking, energy, insurance, and retail sectors, though specific named enterprise logos beyond general sector descriptions were not found in independent coverage.
As a young, recently-funded startup, Equixly’s specific claims about autonomous agent effectiveness versus traditional manual pentesting or established API security scanners (such as those from Salt Security, Noname, or Traceable) have not yet been validated by independent third-party benchmarks; the Series A funding and founder pedigree (ex-IBM, UniCredit, Accenture) are the strongest independently verifiable signals at this stage.
Innovation Matrix Assessment
Closed a €10M Series A in December 2025 explicitly earmarked for building proprietary AI models and accelerating global expansion, a fast funding cadence for a company founded in 2022.
A single-product agentic API testing platform used by customers across banking, energy, insurance, and retail per company statements, but with limited independently verifiable detail on scale of deployment or integration breadth.
A €10M Series A round in December 2025 led by 33N Ventures with multiple co-investors, covered independently by SecurityWeek and Tech.eu, is a credible, verifiable momentum signal for a three-year-old startup.
Continuous, autonomous AI-agent-driven API testing addresses a real scaling gap (APIs proliferating faster than manual pentest capacity can cover), a genuinely different operating model than periodic manual pentests or static API scanners.
No independent third-party benchmark comparing Equixly's autonomous agent detection rate against manual pentesting or established API security scanners was found; efficacy is scored conservatively due to lack of independent verification, not a negative finding about the technology.
API security is a fast-growing, well-documented attack surface concern for enterprises, and continuous automated testing directly addresses the gap left by infrequent manual pentest cycles.
Why CISOs Should Care
Offers application security teams a way to test APIs continuously as they change, rather than relying solely on periodic manual pentests that quickly go stale as APIs are updated.
What Makes It Different
Positions its AI agents as autonomous testers acting like real attackers across the development lifecycle, rather than a traditional static or rules-based API vulnerability scanner.
The Matrix Verdict
55/100 — INCREMENTAL INNOVATOR
A well-funded, credibly-backed early-stage entrant into a genuinely important API security niche; strong funding and founder signals, but real-world detection efficacy versus competitors and manual testing remains independently unverified at this stage.
Editorial Note: Claims vs. Verified Findings
The Series A funding amount, investors, and founding details are independently confirmed via SecurityWeek, Tech.eu, and multiple other funding-news outlets. Claims about customer base composition and the specific effectiveness of the 'agentic AI hacker' approach versus alternatives are vendor-sourced and have not been independently benchmarked.
Sources
Alternatives to Equixly
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…