Curious about today's AI digest?ai-tldr.dev

Daily Digest

Pomegra Startups

Fleuret AI Raises €4M to Automate Pentesting in 2026

Fleuret AI (France) raised a €4M pre-seed led by RAISE Ventures for an AI-agent platform that automates penetration testing.

FundingAICybersecurityNOTABLE4 min read
Fleuret AI Raises €4M to Automate Pentesting in 2026

Paris-based Fleuret AI closed a €4M pre-seed led by RAISE Ventures to build AI agents that run penetration tests continuously instead of once a year.

Key Takeaways

  • Fleuret AI raised a €4M pre-seed round led by RAISE Ventures; valuation was not disclosed.
  • Auriga Cyber Ventures, Wind, Better Angle and cybersecurity angels also took part.
  • The platform's agents run on Scaleway cloud infrastructure in Paris, and a one-off web app pentest is priced at €4,000.

Lead

Fleuret AI, a Paris-based cybersecurity startup, announced on October 5, 2026 that it had raised €4M in pre-seed funding to automate penetration testing with AI agents. RAISE Ventures led the round. The company, founded by CEO Yanis Grigy and CTO Augustin Ponsin, plans to spend the money hiring specialists in AI, software development and offensive security, and to speed up work on its platform.

The company did not disclose a valuation or the equity stake sold. A €4M pre-seed is large for a company founded this year, which suggests investors are paying for a team and a thesis rather than for revenue history.

Who Backed the Round?

RAISE Ventures led, with Auriga Cyber Ventures, Wind and Better Angle participating. A group of cybersecurity operators also invested personally. They include Jules Veyrat, co-founder and CEO of Stoïk, and Alexandre Andreini, the insurer's Chief Risk Officer. Eric Fourrier, CEO of GitGuardian, Georges Lotigier, co-founder of Vade, and Olivier Pantaleo and Jean-François Aliotti, co-founders of Almond, also joined.

That angel list matters more than the fund names. Stoïk, a cyber insurer, appears both as an investor and as a listed customer, alongside Brevo and Yogosha. Customer-investors can speed early sales, but they also make early traction harder to read as independent demand.

RAISE Ventures co-head Thibaut Schlaeppi framed the bet around durability: "Fleuret built its platform to evolve continuously and stay a step ahead of attackers, with a team that puts AI to work for deep offensive expertise."

What Does Fleuret AI Actually Sell?

Fleuret AI sells an agentic pentesting platform that treats security testing as a continuous process rather than a one-off audit. It is organized around five tasks: mapping exposed systems, identifying vulnerabilities, demonstrating whether they can be exploited, supporting remediation, and verifying that fixes hold.

Two agents do the work, named Émile and Champollion. They map a company's environment, probe applications, APIs and infrastructure, and attempt exploitation, then document proof of compromise. The company's site says Émile chains discovered flaws into multi-step attack scenarios and produces reproducible proof-of-concept code for each finding. Targeted flaws include IDOR, SSRF, JWT confusion, race conditions and SQL injection.

Pricing is public. A single web application pentest costs €4,000 with re-testing included, against the €15,000 to €30,000 the company says traditional consultancies charge. Enterprise plans are quoted individually, and a free tier covers code scanning only.

Why Does Sovereignty Feature in the Pitch?

Fleuret AI hosts its agents on Scaleway, a French cloud provider, and markets itself as "sovereign by design." The reports it generates are mapped to the DORA and NIS2 regulatory frameworks, which impose security testing and resilience duties on financial entities and a broad set of essential and important companies in the EU.

The regulatory angle gives European buyers a procurement reason to choose a local vendor. It also narrows the audience: companies outside the EU have less reason to care where the agents run.

How Crowded Is the Field?

The category is busy. Fleuret AI's own comparison pages position it against French rival Patrowl and API-focused Escape, and Israeli vendor Pentera runs automated security validation at larger scale. Automated attack simulation is an established product category, so the pitch rests on whether LLM-driven agents find and exploit business-logic flaws that scanners miss.

Grigy put the ambition this way: "We don't just want to automate pentesting as it exists today...to stay secure all year round." The company targets firms that cannot afford regular manual testing, which is a sensible wedge but also a segment with small budgets.

What Comes Next?

The immediate test is hiring and delivery. Fleuret AI needs to show that agent-generated findings hold up against the judgment of human testers, and that false positives do not swamp the teams reading the reports. Customers acting on autonomous exploitation will also ask what guardrails stop an agent from damaging production systems.

A seed round in 2027 would be the next signal. Revenue figures, customer counts and retention, none of which the company has disclosed, will determine whether the €4M reads as a conviction bet or an early premium.

Outlook

Fleuret AI enters the market with €4M, a French and European hosting pitch, public pricing at €4,000 per web app, and a cybersecurity angel roster with close ties to its first customers. Valuation, revenue and team size remain undisclosed. The next 12 months will show whether continuous AI pentesting can win budget from firms that have so far bought it once a year, or not at all.

More Startup News