Skip to content

Gecko Security

Gecko Security is a Y Combinator-backed AI security testing platform that uses LLMs and custom code indexing to find complex vulnerabilities traditional scanners miss, then helps verify and fix them, with the team already credited with discovering 30+ real CVEs in open-source projects.

Visit Website ↗ + Add to Compare
53/100Incremental Innovator

Overview

Gecko Security describes its product as “the AI Security Engineer to Find and Fix Vulnerabilities,” using large language models combined with custom code-indexing techniques to identify complex, logic-level security flaws in applications that traditional pattern-matching scanners typically miss, then assist with verification and remediation.

Founded by Jeevan Jutla and Artemiy Malyshau, Gecko Security went through Y Combinator’s Fall 2024 batch and is based in London. The team has publicly credited its platform with finding more than 30 CVEs in widely used open-source projects including Ollama, Gradio, and Ragflow, and reports customers experience roughly 50% fewer false positives than with traditional scanners.

Innovation Matrix Assessment

Innovation Velocity 7/10

Discovering and publicly disclosing 30+ real CVEs in significant open-source projects (Ollama, Gradio, Ragflow) within roughly a year of founding is a concrete, verifiable pace of technical output.

Operational Value 5/10

Finding logic-level vulnerabilities traditional scanners miss, combined with a reported reduction in false positives, would meaningfully reduce triage burden for security teams if the claims hold at scale.

Market Momentum 3/10

As a two-founder, very early-stage company with no disclosed funding round or named enterprise customers, independently verifiable commercial momentum is currently limited beyond its technical CVE track record.

Category Disruption 6/10

LLM-based reasoning over custom code indexes to find logic-level flaws, evidenced by real CVE discoveries in major open-source AI tooling, is a genuinely different and more capable approach than pattern-matching static analysis.

Real-World Efficacy 5/10

The 30+ publicly disclosed CVEs in named, widely used open-source projects is independently verifiable, credible evidence of real-world efficacy, even though the 50% false-positive reduction figure specifically is vendor-stated.

Enduring Relevance 6/10

As AI-generated and AI-assisted code accelerates the volume of software shipped, tools capable of finding the complex logic-level flaws pattern-matching scanners miss are likely to grow in importance.

Why CISOs Should Care

Traditional static analysis tools routinely miss complex, logic-level vulnerabilities that require understanding application context; an LLM-based approach with a public track record of real CVE discoveries in major open-source AI tooling gives CISOs evidence-backed reason to evaluate it against harder-to-find vulnerability classes.

What Makes It Different

Gecko's use of custom code indexing alongside LLM-based reasoning to find logic-level vulnerabilities, combined with a public, verifiable CVE discovery track record, differentiates it from AI security tools that only claim capability without demonstrated findings.

The Matrix Verdict

53/100 — INCREMENTAL INNOVATOR

A young but demonstrably capable AI-driven vulnerability discovery vendor with real, publicly verifiable CVE credits in significant open-source projects; scores reflect genuine technical evidence tempered by very early commercial-stage maturity.

Editorial Note: Claims vs. Verified Findings

YC batch, founders, headquarters, and the 30+ CVE discovery claim in named open-source projects are independently confirmed via Gecko's Y Combinator company page; the 50% false-positive reduction figure is vendor-stated and not independently benchmarked.

Sources