Hackuity
A Lyon-based vulnerability operations platform that aggregates data from 130+ security tools to prioritize and coordinate remediation of real exposure risk.
Visit Website ↗ + Add to Compare Claim This CompanyOverview
Hackuity builds a vulnerability operations center (VOC) platform that ingests findings from more than 130 scanners, cloud security tools, application security products, and threat intelligence feeds, then normalizes and de-duplicates them into a single risk view. Its proprietary scoring engine combines vulnerability severity, exploitability, asset criticality, and business context to rank which of the (often overwhelming) volume of raw findings actually matter, and the platform then routes remediation tasks to the security, IT, cloud, and engineering teams responsible for fixing them.
The company’s stated differentiator is vendor neutrality: rather than being tied to a single scanner or cloud provider, Hackuity positions itself as an aggregation and orchestration layer that sits above existing tools, competing with a small set of similar “vulnerability prioritization/exposure management” vendors (a category that also includes Vulcan Cyber, Nucleus Security, and Brinqa) rather than replacing scanners outright. Founded in 2018 in Lyon, France, the company says its platform is used by roughly 6,000 users protecting about 2 million assets, and cites named customers including ENGIE and BPCE.
On September 16, 2026, Hackuity announced a $19M (€16M) funding round led by Forgepoint Capital International, with participation from existing investors Bright Pixel, Bpifrance, and Seventure Partners, bringing total funding to $38M. The company frames the raise around an anticipated “AI-driven vulnerability explosion” as AI-assisted vulnerability discovery and AI-generated code increase the volume of findings enterprises must triage, and says the capital will fund product/AI development and expansion into Europe and Asia.
Innovation Matrix Assessment
Eight years from founding to a $38M cumulative raise with steady, incremental platform expansion (AI scoring, broader tool integrations) rather than rapid, headline-grabbing product cycles.
Aggregating 130+ tools into one prioritized, actionable queue and routing remediation across teams directly addresses a well-documented CISO pain point: alert fatigue and fragmented vulnerability data.
Real, sourced signals — $38M total funding, a Series B led by a known cybersecurity VC (Forgepoint), and named enterprise customers (ENGIE, BPCE) — but still a modestly sized company with a small stated user base (6,000 users) relative to established vulnerability management incumbents.
Vulnerability prioritization/exposure management is an established, moderately crowded category (Vulcan Cyber, Nucleus Security, Brinqa, Cisco/Kenna); Hackuity's vendor-neutral aggregation approach is a reasonable differentiator but not a category-redefining one.
Vendor-published metrics (e.g., cutting critical alerts to 0.01%, 3x faster remediation, up to $1M saved) are unverified marketing claims with no independent test or analyst validation found; named customers exist but no public case study detailing measured outcomes was located.
Vulnerability triage and prioritization will remain a core security operations need for years, and the anticipated growth in AI-assisted vulnerability discovery (cited by the company and echoed in press coverage) plausibly increases, not decreases, demand for this category.
Why CISOs Should Care
It reduces the practical burden of reconciling 130+ disparate vulnerability and asset feeds into one prioritized action list, which is the everyday operational problem most VM teams struggle with.
What Makes It Different
Hackuity positions itself as a vendor-agnostic aggregation and orchestration layer above existing scanners and cloud/AppSec tools rather than another single-source scanner, competing on breadth of integration and cross-team remediation routing.
The Matrix Verdict
57/100 — INCREMENTAL INNOVATOR
Hackuity lands as an Incremental Innovator: a credibly funded, real-customer vulnerability operations platform solving a genuine operational problem, but operating in a moderately crowded category with efficacy claims that remain vendor-asserted rather than independently verified.
Editorial Note: Claims vs. Verified Findings
Funding amount, lead investor, HQ, founding year, and named customers (ENGIE, BPCE) are corroborated across multiple independent outlets (SecurityWeek, TechFundingNews, EU-Startups); performance figures such as '0.01% critical alerts,' '3x faster remediation,' and '$1M saved' come only from company-sourced press materials and have not been independently verified.
Sources
- SecurityWeek — https://www.securityweek.com/hackuity-raises-19-million-for-ai-powered-vulnerability-management/
- TechFundingNews — https://techfundingnews.com/hackuity-raises-19m-series-b-forgepoint-capital-vulnerability-management/
- EU-Startups — https://www.eu-startups.com/2026/09/vulnerability-tsunami-prompts-frances-hackuity-to-land-e16-million-for-automated-cyber-remediation
- Morningstar/BusinessWire — https://www.morningstar.com/news/business-wire/20260916319331/hackuity-raises-19-million-to-help-enterprises-prepare-for-the-ai-driven-vulnerability-explosion
Alternatives to Hackuity
Unknown Cyber Inc.
CISO ReviewedMalware genomics platform using automated deep static analysis and code-lineage comparison to identify unseen malware, variants, and supply-chain…
Synack Inc
A penetration-testing-as-a-service platform pairing a vetted researcher community with AI-driven attack surface discovery for continuous security validation.
Horizon3.ai
Autonomous penetration testing company whose NodeZero platform self-attacks networks without persistent agents, aiming to replace annual manual pentests…
Cogent Security
Agentic AI platform that autonomously triages, investigates, and remediates vulnerabilities as a force multiplier for security teams.
Airlock Digital
Application allowlisting (deny-by-default) platform that blocks unapproved executables, scripts, and processes to prevent ransomware and malware execution.
ReversingLabs
Software supply chain security and binary analysis vendor that inspects compiled software and packages for malware and unauthorized…