Escape
Escape Technologies SAS is a Paris-based AI-native offensive security platform that helps enterprise security and engineering teams continuously discover, test, and remediate application and API vulnerabilities through multi-agent AI pentesting, business-logic-aware DAST, and attack surface management, serving over 2,000 security teams globally.
- Company typePrivate
- Founded2020
- HeadquartersParis, France
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Escape does
Escape Technologies SAS, founded in 2020 and headquartered in Paris with operations in Biarritz, is an AI-native offensive security engineering platform serving security and development teams. Originally positioned as an API discovery and API security vendor using generative AI to identify exposed APIs, the company rebranded in March 2026 around a broader offensive security thesis: continuously discovering, testing, and remediating vulnerabilities inside engineering workflows. The platform is built on a proprietary Business Logic Security Testing algorithm (the MetaGraph model) combined with NLP-based sourcing inference, strong typing inference across more than 800 data types, and reinforcement learning for API exploration. A multi-agent architecture — including the Cascade pentesting engine and AI Pentesting Agents 2.0 — orchestrates specialized exploitation agents (XSS, SQLi, BOLA, business logic, regression testing) with proof-of-concept validation.
The company sells three core products — Attack Surface Management, Business-Logic-Aware DAST, and AI Pentesting — designed to function as a continuous loop from discovery to remediation. Native integrations span Wiz (risk unification), Azure DevOps (CI/CD gates), and AI-assisted IDEs (Cursor, Claude Code, Gemini) for automated code remediation, alongside the open-source GraphQL Armor middleware. Escape reports more than 2,000 security teams as customers globally, with named enterprise logos including Visma, Miro, Schibsted, HealthEquity, Cato Networks, and Applied. The GTM is enterprise demo-led, with the company claiming 15%+ month-on-month revenue growth and serving customers across France, the UK, and the United States. Backed by Balderton Capital (Series A lead), Uncorrelated Ventures, IRIS, and Y Combinator, Escape has raised approximately $23 million in total venture funding across seed and Series A rounds.
Escape firmographics
Firmographics- Name
- Escape
- Legal name
- Escape Technologies SAS
- Website
- https://escape.tech
- Company type
- Private
- Founded year
- 2020
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Escape Technologies SAS is a Paris-based AI-native offensive security platform that helps enterprise security and engineering teams continuously discover, test, and remediate application and API vulnerabilities through multi-agent AI pentesting, business-logic-aware DAST, and attack surface management, serving over 2,000 security teams globally.
- Ownership category
- akta.pro rank
Escape industry classification
Industry- Product category
- Application Security Testing
- NAICS
- Security Systems Services (56162), Investigation and Security Services (5616)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Application Security Engineering (DevSecOps, AppSec Remediation) (BPAEAFAI)
- akta.pro secondary industries
- Vulnerability Intelligence & Exploit Prediction (HDADAHAI), Security Analytics & Detection Engineering (HDADAGAE)
Keywords
Where Escape is headquartered
LocationHeadquarters
- HQ city
- Paris
- HQ country
- France
- HQ region
- Europe
Markets served
Escape business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Operations, Infrastructure
Escape product offering
Product offeringCore offering
Escape is an AI-native offensive security engineering platform that continuously discovers, tests, and remediates vulnerabilities across modern applications, APIs, and infrastructure. Its three core products—Attack Surface Management, Business-Logic-Aware DAST, and AI Pentesting—use a proprietary MetaGraph algorithm and multi-agent architecture to replace legacy scanners and manual pentesting with automated, business-logic-aware security testing integrated into engineering workflows.
Product overview
Escape is an AI-native offensive security engineering platform that offers three core products: Attack Surface Management, Business-logic-aware DAST, and AI Pentesting. These products work together in a continuous workflow: ASM discovers assets (APIs, SPAs, hosts, schemas) across code to cloud, DAST tests every release at the business logic level, and AI Pentesting proves exploitability at scale with automated remediation. Key differentiators include the proprietary Business Logic Security Testing algorithm using MetaGraph, sourcing inference, and reinforcement learning. Additional offerings include the Cascade multi-agent pentesting engine, Visage Surface Scanner, Escape Rules for custom security checks, and the open-source GraphQL Armor middleware.
Differentiator
Problem solved
Functional benefit
Products and services
- Attack Surface Management Discovers and validates exposure of modern applications, APIs, SPAs, and infrastructure from code to cloud for enterprise security teams; flows discovered assets into Wiz with risk context.
- Business-logic-aware DAST AI-powered Dynamic Application Security Testing that secures applications at the business logic level for AppSec teams; features ≤4% false positive rate, OAuth/SSO/multi-tenant support, and developer-friendly remediation context.
- AI Pentesting Agent-driven penetration testing that replaces manual pentests and bug bounty programs for security teams; uses agentic attack reasoning with proof-of-exploitability artifacts and regression testing of bug bounty findings.
- Cascade Multi-agent pentesting engine for continuous, compounding security assessments of modern web applications, using specialized agents (orchestrator, coverage, exploitation, reporter) that build contextual knowledge of the attack surface over time.
Companies that use Escape
Customer profileIdeal customer profiles2 records
Escape technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration5 records
AI capability9 records
Escape partnerships and signals
Strategic signalRecent moves6 records
Expansion highlights6 records
Escape competitors and assessment
Company assessmentDirect peers
- PortSwigger: Creator of Burp Suite, the dominant web application and API security testing platform used by penetration testers globally. Direct competitor in DAST and pentesting workflows, with significantly larger installed base among security professionals.
- Invicti: Provider of Invicti (formerly Netsparker) and Acunetix DAST platforms for web application and API security testing. Directly comparable in automated vulnerability discovery, proof-based scanning, and enterprise DAST positioning.
- Detectify: External Attack Surface Management and DAST platform focused on modern web applications and APIs. Closely overlaps with Escape's ASM and DAST products, targeting similar AppSec teams.
- StackHawk: API and application security testing platform purpose-built for developers and CI/CD pipelines. Direct competitor with similar developer-first DAST positioning and modern auth/multi-tenant support.
- Noname Security: API security platform offering API discovery, posture management, and runtime protection. Direct overlap with Escape's original API security focus and ASM capabilities.
Broad incumbents
- Snyk: Comprehensive developer security platform spanning SAST, SCA, container, IaC, and DAST. A broader incumbent in application security that competes with Escape on DAST/API testing while also serving adjacent categories.
- Veracode: Established enterprise application security platform covering SAST, DAST, and software composition analysis. Incumbent in the AppSec category with deep Fortune 500 penetration and full portfolio coverage.
Emerging players
- Hadrian: AI-native offensive security platform providing autonomous attack surface management and continuous penetration testing. Closest emerging competitor in the AI-driven offensive security category Escape is targeting post-rebrand.
- FireTail: API security platform offering API discovery, inventory, and runtime threat detection. Emerging player with significant overlap in API-centric security testing and ASM.
- Beagle Security: Automated web application and API penetration testing platform with AI-assisted vulnerability discovery. Comparable in automated pentest positioning and SMB/mid-market go-to-market.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
Escape social profiles
Digital presenceEscape compliance and trust
Trust signalCompliance6 records
Escape financial estimates
Financial estimateRevenue estimate
Valuation estimate
Escape leadership team
Management profileNumber of profiles
Profiles2 records
Escape funding detail
Funding detailFunding overview
Funding rounds4 records
Investors8 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Escape M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Escape
What does Escape do?
Escape is an AI-native offensive security engineering platform that continuously discovers, tests, and remediates vulnerabilities across modern applications, APIs, and infrastructure. Its three core products—Attack Surface Management, Business-Logic-Aware DAST, and AI Pentesting—use a proprietary MetaGraph algorithm and multi-agent architecture to replace legacy scanners and manual pentesting with automated, business-logic-aware security testing integrated into engineering workflows.
Is Escape a public or private company?
Escape is a private company. It is classified as venture growth investor backed and is currently operating.
When was Escape founded?
Escape was founded in 2020. It employs 1 to 10 people.
Where is Escape based?
Escape is headquartered in Paris, France, in the Europe region.
Who are Escape's main competitors?
Direct peers on record are PortSwigger, Invicti, Detectify, StackHawk and Noname Security. Broad incumbents are Snyk and Veracode. Emerging players are Hadrian, FireTail and Beagle Security.
Does Escape have an API?
Yes. Escape offers a fully programmable platform with Public API, CLI, and MCP Server. The API enables programmatic access to all platform capabilities including scan triggering, policy configuration, event-based workflows for triage/routing/escalation, and CI/CD security gates. The platform is event-based, allowing scripts to automate offensive security workflows. Developer documentation is at docs.escape.tech.
What industry is Escape in?
Escape's product category is Application Security Testing. Its primary akta.pro industry code is BPAEAFAI, Application Security Engineering (DevSecOps, AppSec Remediation), with a secondary code of HDADAHAI, Vulnerability Intelligence & Exploit Prediction. Its NAICS code is 56162 and its SIC code is 7373.