Skip to content

Equixly

Florence, Italy-based startup using autonomous AI agents to continuously penetration-test APIs for business-logic and authorization vulnerabilities.

Visit Website ↗ + Add to Compare
55/100Incremental Innovator

Overview

Equixly builds an AI agent-driven platform that continuously penetration-tests APIs, aiming to replace or supplement periodic manual API pentests with autonomous agents that probe for business-logic flaws, broken authorization, and other OWASP API Top 10-style vulnerabilities on an ongoing basis rather than a point-in-time snapshot. Founded in 2022 in Florence, Italy, by brothers Mattia and Alessio Dalla Piazza, the company frames its approach as agentic AI acting like a hacker embedded across the software development lifecycle rather than a static scanning tool.

API security is one of the fastest-growing attack surfaces because APIs proliferate faster than security teams can manually test them, and continuous, AI-driven testing is a real response to that scaling problem rather than a marketing repackaging of an old category. Equixly raised a €10 million Series A in December 2025, led by 33N Ventures with participation from Alpha Intelligence Capital, JME Ventures, and others, bringing total funding to roughly $13.3 million, and the company reports customers across European banking, energy, insurance, and retail sectors, though specific named enterprise logos beyond general sector descriptions were not found in independent coverage.

As a young, recently-funded startup, Equixly’s specific claims about autonomous agent effectiveness versus traditional manual pentesting or established API security scanners (such as those from Salt Security, Noname, or Traceable) have not yet been validated by independent third-party benchmarks; the Series A funding and founder pedigree (ex-IBM, UniCredit, Accenture) are the strongest independently verifiable signals at this stage.

Innovation Matrix Assessment

Innovation Velocity 7/10

Closed a €10M Series A in December 2025 explicitly earmarked for building proprietary AI models and accelerating global expansion, a fast funding cadence for a company founded in 2022.

Operational Value 4/10

A single-product agentic API testing platform used by customers across banking, energy, insurance, and retail per company statements, but with limited independently verifiable detail on scale of deployment or integration breadth.

Market Momentum 6/10

A €10M Series A round in December 2025 led by 33N Ventures with multiple co-investors, covered independently by SecurityWeek and Tech.eu, is a credible, verifiable momentum signal for a three-year-old startup.

Category Disruption 6/10

Continuous, autonomous AI-agent-driven API testing addresses a real scaling gap (APIs proliferating faster than manual pentest capacity can cover), a genuinely different operating model than periodic manual pentests or static API scanners.

Real-World Efficacy 3/10

No independent third-party benchmark comparing Equixly's autonomous agent detection rate against manual pentesting or established API security scanners was found; efficacy is scored conservatively due to lack of independent verification, not a negative finding about the technology.

Enduring Relevance 7/10

API security is a fast-growing, well-documented attack surface concern for enterprises, and continuous automated testing directly addresses the gap left by infrequent manual pentest cycles.

Why CISOs Should Care

Offers application security teams a way to test APIs continuously as they change, rather than relying solely on periodic manual pentests that quickly go stale as APIs are updated.

What Makes It Different

Positions its AI agents as autonomous testers acting like real attackers across the development lifecycle, rather than a traditional static or rules-based API vulnerability scanner.

The Matrix Verdict

55/100 — INCREMENTAL INNOVATOR

A well-funded, credibly-backed early-stage entrant into a genuinely important API security niche; strong funding and founder signals, but real-world detection efficacy versus competitors and manual testing remains independently unverified at this stage.

Editorial Note: Claims vs. Verified Findings

The Series A funding amount, investors, and founding details are independently confirmed via SecurityWeek, Tech.eu, and multiple other funding-news outlets. Claims about customer base composition and the specific effectiveness of the 'agentic AI hacker' approach versus alternatives are vendor-sourced and have not been independently benchmarked.

Sources