Hackuity raised €16M in a Series B round led by Forgepoint Capital to automate vulnerability triage as AI-driven discovery outpaces human security teams.
- Hackuity closed €16M ($19M) in a Series B led by Forgepoint Capital International, bringing total capital raised to €32M ($38M).
- The platform aggregates findings from 130+ security tools across 6,000+ users, protecting 2 million assets and managing 1 billion findings.
- Co-investors Bright Pixel, Bpifrance, and Seventure Partners all returned from prior rounds.
Lead
Hackuity, the Lyon-based vulnerability operations center (VOC) startup, closed a €16 million ($19 million) Series B on September 16, 2026, led by Forgepoint Capital International. The round brings total capital raised to €32 million ($38 million) and arrives as AI-powered scanning tools accelerate the pace at which new vulnerabilities are surfaced, creating a remediation backlog that enterprise security teams cannot keep up with.
What Does Hackuity Actually Do?
The platform pulls findings from more than 130 security tools - scanners, endpoint detection systems, cloud security posture managers - and applies risk-based prioritization to help teams decide which vulnerabilities demand immediate attention. The core pitch: stop overwhelming teams with alerts and direct effort toward actual business risk. Hackuity claims customers have reduced critical-vulnerability noise by 99.99%, cut mean time to remediate by a factor of three, and automated up to 70% of exposure-management activities.
The company covers more than 2 million assets and handles 1 billion findings across its user base. Clients include ENGIE, BPCE, and managed security provider Orange Cyberdefense. Founded in 2018, Hackuity positioned itself early in the emerging VOC category, which focuses on remediation workflow orchestration rather than raw vulnerability detection - a distinction from traditional vulnerability management tools that matters more as alert volumes grow.
Why Is AI Making the Vulnerability Problem Worse?
AI-based code analysis and fuzzing tools are surfacing software weaknesses at a rate that human analysts cannot match. AI-assisted development is also producing more code, faster, which introduces new defects at volume. The result is a widening gap between discovery and remediation, not a narrowing one.
For vendors in vulnerability management, this dynamic is simultaneously a market tailwind and a product challenge. Prioritization algorithms built for smaller data sets must now hold up against a far larger daily inflow of findings. Hackuity's response has been to train models on correlations between asset criticality, exploit availability, and business context - departing from CVSS severity scores, which security practitioners have long criticized as an unreliable proxy for actual risk.
Investor and Round Context
Forgepoint Capital International - the European vehicle of San Francisco-based Forgepoint Capital, a cybersecurity-focused firm - led the Series B. Its participation signals continued interest in the French security ecosystem, which has produced a cluster of startups supported by government programs and technical institutions in Paris, Lyon, and Grenoble.
Returning co-investors Bright Pixel (formerly Sonae IM), Bpifrance, and Seventure Partners all participated. Bright Pixel led Hackuity's 2022 Series A of approximately $13 million. Valuation was not disclosed for either round.
The round size invites scrutiny. At €16 million, the Series B is not dramatically larger than the Series A. That could signal deliberate capital efficiency in a market where high-burn cybersecurity startups have struggled since 2023. Alternatively, it reflects a bet on market timing rather than a repriced growth trajectory. Neither interpretation is flattering on its face, though discipline on burn is not an obviously bad outcome in the current funding environment.
What Comes Next for Hackuity?
The company plans to deploy capital across AI product development within the VOC platform and international expansion into European and Asian markets. The European push has natural momentum: large French enterprise clients with cross-border operations provide a reference base for neighboring markets.
The category remains fragmented. Legacy vulnerability management vendors are adding risk-scoring features. Detection-heavy platforms are building workflow automation. Hackuity sits at that intersection and will need to defend the position as larger players prioritize the same use cases on their roadmaps.
Outlook
With €32 million in total funding and a platform at meaningful enterprise scale, Hackuity enters its next phase at a point when the underlying pressure driving demand - AI-generated vulnerability volume - is unlikely to ease. The strategic risk is commoditization: risk-based prioritization is becoming a standard feature checkpoint rather than a differentiator. Converting a structural market tailwind into durable, defensible revenue before incumbents close the feature gap is the central task the Series B is meant to fund.



