Home
Loading

aVenture is in Alpha: During this preview period, you should expect the research data to be limited and may not yet meet our exacting standards. We've made the decision to provide early access to our data to showcase the product as we build, but you should not yet rely upon it alone for your investment decisions.

aVenture is in Alpha: During this preview period, you should expect the research data to be limited and may not yet meet our exacting standards. We've made the decision to provide early access to our data to showcase the product as we build, but you should not yet rely upon it alone for your investment decisions.

Get in touch

  • Contact

  • Request a demo

  • Request data updates

  • Add a company

Research

  • Companies

  • Investors

  • People

aVenture

  • Sitemap

  • Feature requests

Member

Backed by

© aVenture Investment Company, 2026. All rights reserved.

San Francisco, CA, USA

Privacy Policy

aVenture Investment Company ("aVenture") is an independent research platform providing detailed analysis and data on startups, venture capital investments, and key industry individuals. It is not a registered investment adviser, broker-dealer, or investment advisor and does not provide investment advice or recommendations. The data provided by aVenture does not constitute recommendations or advice, whether by methodology, analysis, AI-generated content, or a statement written by a staff member of aVenture.

aVenture is not affiliated with any of the people, companies, organizations, government agencies, regulatory bodies, or investment funds we provide coverage for on this site unless explicitly stated otherwise. Users assume full responsibility for decisions made based on information obtained from this platform. Links to external websites do not imply endorsement or affiliation with aVenture. Any links that provide the ability to invest in a primary or secondary transaction in a company are for convenience only and do not constitute solicitations or offers to buy or sell an investment. Investors should exercise heightened precaution and due diligence when investing in private companies, especially those not independently audited.

While we strive to provide valuable insights with objectivity and professional diligence, we cannot guarantee the accuracy of the information provided on our platform. Before making any investment decisions, you should verify the accuracy of all pertinent details for your decision. To the fullest extent permitted by law, aVenture shall not be liable for any direct, indirect, incidental, consequential, or financial damages arising from use of this site, whether by consumers of its contents directly or by persons or organizations covered by our research, even if we are advised of the possibility. Our best-efforts processes and correction request forms do not create a warranty or duty of care.

Profiles on this platform may include content generated in part by large language models (LLMs, artificial intelligence) that aggregate publicly available sources (e.g., SEC EDGAR, public filings, press releases). Source attribution is provided where known; always verify statements and claims here against original sources before relying on any data. Content on our site may contain inaccuracies, omissions, or what are commonly called 'hallucinations' if generated in part or in full by AI / LLMs. The risk can also exist even when content is written by a human, as internal and third-party sources may also have inaccuracies for the same or different reasons. While we randomly audit a proportion of content, this is not exhaustive.

We recommend that an independent auditor be hired to verify the accuracy of the information before relying on it for any sensitive decisions. By accessing this platform, you agree not to rely solely on any information generated by AI, aggregated, or sourced or written otherwise on this site, for investment, financial, or other decisions. aVenture assumes no responsibility for inaccuracies, omissions, or hallucinations. You must independently verify all data from primary sources. Use of this platform constitutes your waiver of claims for reliance-based damages, including negligent misrepresentation. To report an error, request a correction, or dispute information about a company or individual, contact us via our request data updates form.

Loading
Loading
Home
News
Escape dynamically scans APIs to find security flaws

From TechCrunch

By Romain Dillet

June 6, 2023

Escape dynamically scans APIs to find security flaws

French startup Escape has raised a $3.9 million (€3.6 million) funding round shortly after ending Y Combinator’s winter 2023 cohort. The company provides a cybersecurity product focused on securing APIs before they are rolled out publicly.

French VC firm Iris is leading the round with Frst also participating. Existing investors Irregular Expressions, Tiny Supercomputers and Kima Ventures are participating in the round. Some of the company’s angel investors include Philippe Langlois, Mehdi Medjaoui and Roxanne Varza.

“We decided to create a custom algorithm powered by artificial intelligence that can simulate cyber attacks. Once it has found security flaws, it will give you remediations,” co-founder and CEO Tristan Kalos told me. He founded the startup with Antoine Carossio and there are now 10 people working for Escape.

In more technical terms, Escape is an agentless solution as it integrates directly in your development pipeline. Every time the dev team commits some new lines of code in the code repository, it will trigger Escape using an integration in the continuous integration/continuous delivery flow (CI/CD).

For instance, Escape can identify an issue with rate limiting. That means that a bad actor could leverage this flaw to extract large volumes of data. Escape can also see if invalid actions are properly blocked to prevent data manipulation. It integrates with Snyk so that Escape issues appear in your Snyk’s code issues.

“These are dynamic tests. We don’t test the source code itself, but rather the application as it runs. What’s complicated with an API is the business logic — how to interact and how to attack the API. We use reinforcement learning, a mix of deep learning and heuristics,” Kalos said.

Escape first decided to focus on GraphQL APIs as the startup identified that it would be the best go-to-market strategy. But the company is currently rolling out support for REST APIs, which are more widespread than GraphQL-based APIs.

The company has already convinced around 20 clients, such as Sorare, Shine and Neo4J. As you can see, Escape wants to focus on bigger clients working in sensitive industries, including banks and financial services companies. Each contract could potentially be worth tens of thousands of euros per year.

Before using Escape, making sure that your company’s APIs are secured was mostly a manual process. Every now and then, big companies work with security analysts to conduct a penetration test (or pentest, for short).

“Once or twice a year, they come in, look at everything that’s going on and hand you a security report. Companies review the findings internally and list the issues: we’ve got to resolve this, we’ve got to resolve that,” Kalos told me.

But then, companies have to find the developers who are in charge of this specific part of the product or that API in particular. In other words, it’s a reactive and imperfect process.

Escape doesn’t want to replace pentests altogether. Pentests don’t just focus on APIs either, they are much larger than that. Escape just wants to surface security flaws at the API level so that they are fixed when they first appear. This way, most issues are already fixed when a security firm conducts a pentest. It’s a more proactive and dynamic security model, and that could be a nice selling point.

Escape dynamically scans APIs to find security flaws by Romain Dillet originally published on TechCrunch

Most Recent

Arcee, a US open source AI lab, says Chinese models are not inherently dangerous

Arcee, a US open source AI lab, says Chinese models are not inherently dangerous

As Chinese AI models grow in capability and popularity among US companies, the arguing over what should be done about them has reached a fever pitch.

Jul 22, 2026

Cascade raises $3.5M to help construction firms find and win projects

Cascade raises $3.5M to help construction firms find and win projects

a16z Speedrun, Ada Ventures, and Snowball VC have invested in Cascade's $3.5 million seed round.

Jul 22, 2026

The browser wars aren’t about search anymore — here are the best alternatives to Chrome and Safari

The browser wars aren’t about search anymore — here are the best alternatives to Chrome and Safari

We’ve compiled an overview of some of the top alternative browsers available today aiming to challenge Chrome and Safari.

Jul 22, 2026

Glow emerges from stealth at $1.2B valuation to challenge endpoint security in the AI era

Glow emerges from stealth at $1.2B valuation to challenge endpoint security in the AI era

Glow is targeting a new class of endpoint risks created by the rapid adoption of AI agents and developer tools inside enterprises.

Jul 22, 2026

Similar Posts

Astrix Security, which uses ML to secure app integrations, raises $25M

Astrix Security, which uses ML to secure app integrations, raises $25M

Astrix Security, a platform that helps companies manage and secure third-party app integrations, today announced that it closed a $25 million Series A funding round led by CRV with participation from Bessemer Venture Partners and F2 Venture Capital. Co-founder and CEO Alon Jackson says that the round, which brings Astrix’s total raised to $40 million, […]

Jun 28, 2023

Fig Security emerges from stealth with $38M to help security teams deal with change

Fig Security emerges from stealth with $38M to help security teams deal with change

Fig traces data flows in the security stack and then alerts security teams when changes at any point affect detection or response capabilities.

Mar 3, 2026

Oneleet raises $33M to shake up the world of security compliance

Oneleet raises $33M to shake up the world of security compliance

Founder Bryan Onel says too many companies are doing the bare minimum to meet their security compliance obligations, and raised $33 million to help his customers get both compliant and secure.

Oct 2, 2025

Socket lands a fresh $40M to scan software for security flaws

Socket lands a fresh $40M to scan software for security flaws

The software supply chain, which comprises the components and processes used to develop software, has become precarious. According to one recent survey, 88% of companies believe poor software supply chain security presents an “enterprise-wide risk” to their organizations. Open source supply chain components are especially fraught, thanks to the logistical hurdles in keeping each component well-maintained. Security firm Synopsys found in its 2023 report that 89% of businesses’ codebases containe

Oct 22, 2024

Most Recent

Arcee, a US open source AI lab, says Chinese models are not inherently dangerous

Arcee, a US open source AI lab, says Chinese models are not inherently dangerous

As Chinese AI models grow in capability and popularity among US companies, the arguing over what should be done about them has reached a fever pitch.

Jul 22, 2026

Cascade raises $3.5M to help construction firms find and win projects

Cascade raises $3.5M to help construction firms find and win projects

a16z Speedrun, Ada Ventures, and Snowball VC have invested in Cascade's $3.5 million seed round.

Jul 22, 2026

The browser wars aren’t about search anymore — here are the best alternatives to Chrome and Safari

The browser wars aren’t about search anymore — here are the best alternatives to Chrome and Safari

We’ve compiled an overview of some of the top alternative browsers available today aiming to challenge Chrome and Safari.

Jul 22, 2026

Glow emerges from stealth at $1.2B valuation to challenge endpoint security in the AI era

Glow emerges from stealth at $1.2B valuation to challenge endpoint security in the AI era

Glow is targeting a new class of endpoint risks created by the rapid adoption of AI agents and developer tools inside enterprises.

Jul 22, 2026

Similar Posts

Astrix Security, which uses ML to secure app integrations, raises $25M

Astrix Security, which uses ML to secure app integrations, raises $25M

Astrix Security, a platform that helps companies manage and secure third-party app integrations, today announced that it closed a $25 million Series A funding round led by CRV with participation from Bessemer Venture Partners and F2 Venture Capital. Co-founder and CEO Alon Jackson says that the round, which brings Astrix’s total raised to $40 million, […]

Jun 28, 2023

Fig Security emerges from stealth with $38M to help security teams deal with change

Fig Security emerges from stealth with $38M to help security teams deal with change

Fig traces data flows in the security stack and then alerts security teams when changes at any point affect detection or response capabilities.

Mar 3, 2026

Oneleet raises $33M to shake up the world of security compliance

Oneleet raises $33M to shake up the world of security compliance

Founder Bryan Onel says too many companies are doing the bare minimum to meet their security compliance obligations, and raised $33 million to help his customers get both compliant and secure.

Oct 2, 2025

Socket lands a fresh $40M to scan software for security flaws

Socket lands a fresh $40M to scan software for security flaws

The software supply chain, which comprises the components and processes used to develop software, has become precarious. According to one recent survey, 88% of companies believe poor software supply chain security presents an “enterprise-wide risk” to their organizations. Open source supply chain components are especially fraught, thanks to the logistical hurdles in keeping each component well-maintained. Security firm Synopsys found in its 2023 report that 89% of businesses’ codebases containe

Oct 22, 2024