Skip to content

Escape

A Paris-based API and application security testing platform, founded by Tristan Kalos and Antoine Carossio, using AI agents to automate discovery and offensive security testing across the software lifecycle, backed by an $18M Series A.

Visit Website ↗ + Add to Compare
53/100Incremental Innovator

Overview

Escape (Escape Technologies), founded in 2020 by CEO Tristan Kalos and CTO Antoine Carossio, builds an agentless Dynamic Application Security Testing (DAST) and API security platform aimed at automating API discovery, inventory, and vulnerability testing for application security teams. In March 2026 the company raised an $18M Series A to expand its use of AI agents toward automating a larger share of the offensive security testing lifecycle.

Escape’s agentless approach — testing applications and APIs from the outside without requiring code instrumentation or agents installed in the target environment — reduces deployment friction for AppSec teams, while its 2026 funding round signals a push toward broader AI-agent-driven automation of tasks traditionally requiring manual penetration testers.

Innovation Matrix Assessment

Innovation Velocity 6/10

A 2026 Series A explicitly funding expansion of AI-agent-driven automation across the offensive security testing lifecycle indicates an actively accelerating roadmap.

Operational Value 6/10

Agentless API discovery and continuous testing reduce deployment friction and keep pace with fast-changing API inventories better than periodic manual testing.

Market Momentum 6/10

An $18M Series A in 2026 following earlier seed funding indicates sustained, growing investor confidence in a young company.

Category Disruption 5/10

Applying AI agents to automate tasks traditionally requiring manual penetration testers is a meaningful, if still-maturing, shift in offensive security testing delivery.

Real-World Efficacy 3/10

Founded in 2020 with continued early-stage growth; no independent efficacy or exploit-detection-accuracy data was found.

Enduring Relevance 6/10

API security testing is an increasingly critical, durable need as API surfaces grow faster than manual testing capacity can cover.

Why CISOs Should Care

CISOs whose AppSec teams struggle to keep pace with rapidly-changing API inventories get automated, agentless discovery and continuous testing rather than depending on manual API documentation and periodic pentest engagements.

What Makes It Different

Escape's agentless testing approach avoids the deployment overhead of instrumentation-based tools, and its 2026 Series A is explicitly funding AI-agent automation of tasks (like exploit chaining) traditionally requiring skilled human pentesters.

The Matrix Verdict

53/100 — INCREMENTAL INNOVATOR

A well-funded, fast-moving French API security startup with a credible agentless-testing differentiator and a clear AI-automation roadmap; still early-stage in scale, moderating efficacy confidence relative to established DAST/API-security incumbents.

Editorial Note: Claims vs. Verified Findings

Founding year, funding rounds, and Y Combinator/founder details are corroborated across SecurityWeek, Y Combinator's company page, and iris.vc; specific AI-agent testing-coverage claims are vendor-stated and were not independently benchmarked.

Sources