Developer docs
API playgroundTry for free, no card

Search company profiles

Escape

Full company profile

uuid0000bot

Namestring
Escape
Legal namestring
Escape Technologies SAS
Websiteurl
escape.tech
Company typeenum
Private
Founded yearint
2020
Descriptiontext

Escape Technologies SAS, founded in 2020 and headquartered in Paris with operations in Biarritz, is an AI-native offensive security engineering platform serving security and development teams. Originally positioned as an API discovery and API security vendor using generative AI to identify exposed APIs, the company rebranded in March 2026 around a broader offensive security thesis: continuously discovering, testing, and remediating vulnerabilities inside engineering workflows. The platform is built on a proprietary Business Logic Security Testing algorithm (the MetaGraph model) combined with NLP-based sourcing inference, strong typing inference across more than 800 data types, and reinforcement learning for API exploration. A multi-agent architecture — including the Cascade pentesting engine and AI Pentesting Agents 2.0 — orchestrates specialized exploitation agents (XSS, SQLi, BOLA, business logic, regression testing) with proof-of-concept validation.

The company sells three core products — Attack Surface Management, Business-Logic-Aware DAST, and AI Pentesting — designed to function as a continuous loop from discovery to remediation. Native integrations span Wiz (risk unification), Azure DevOps (CI/CD gates), and AI-assisted IDEs (Cursor, Claude Code, Gemini) for automated code remediation, alongside the open-source GraphQL Armor middleware. Escape reports more than 2,000 security teams as customers globally, with named enterprise logos including Visma, Miro, Schibsted, HealthEquity, Cato Networks, and Applied. The GTM is enterprise demo-led, with the company claiming 15%+ month-on-month revenue growth and serving customers across France, the UK, and the United States. Backed by Balderton Capital (Series A lead), Uncorrelated Ventures, IRIS, and Y Combinator, Escape has raised approximately $23 million in total venture funding across seed and Series A rounds.

Short descriptiontext

Escape Technologies SAS is a Paris-based AI-native offensive security platform that helps enterprise security and engineering teams continuously discover, test, and remediate application and API vulnerabilities through multi-agent AI pentesting, business-logic-aware DAST, and attack surface management, serving over 2,000 security teams globally.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
1–10
akta.pro rankint
HeadquartersParis, France
HQ citystring
Paris
HQ countrystring
France
HQ regionstring
Europe
Markets served

Serves global market

Keyword5 values
application security testing, API security platform, attack surface management, AI penetration testing, offensive security platform
Industry3 codes
1Application Security Engineering (DevSecOps, AppSec Remediation)
CodeBPAEAFAIPrimaryYes
2Vulnerability Intelligence & Exploit Prediction
CodeHDADAHAIPrimaryNo
3Security Analytics & Detection Engineering
CodeHDADAGAEPrimaryNo
NAICS code2 codes
  • Security Systems Services56162
  • Investigation and Security Services5616
SIC code1 code
  • Services-Computer Integrated Systems Design7373
Product category
Application Security Testing
Cost components5 values
Technology or R&D, Personnel, Marketing or Sales, Operations, Infrastructure
GTM typeB2B
B2B
Offering typeSoftware
Software
Core offering1 text field

Escape is an AI-native offensive security engineering platform that continuously discovers, tests, and remediates vulnerabilities across modern applications, APIs, and infrastructure. Its three core products—Attack Surface Management, Business-Logic-Aware DAST, and AI Pentesting—use a proprietary MetaGraph algorithm and multi-agent architecture to replace legacy scanners and manual pentesting with automated, business-logic-aware security testing integrated into engineering workflows.

Differentiator
Functional benefit
Problem solved
Product overview1 text field

Escape is an AI-native offensive security engineering platform that offers three core products: Attack Surface Management, Business-logic-aware DAST, and AI Pentesting. These products work together in a continuous workflow: ASM discovers assets (APIs, SPAs, hosts, schemas) across code to cloud, DAST tests every release at the business logic level, and AI Pentesting proves exploitability at scale with automated remediation. Key differentiators include the proprietary Business Logic Security Testing algorithm using MetaGraph, sourcing inference, and reinforcement learning. Additional offerings include the Cascade multi-agent pentesting engine, Visage Surface Scanner, Escape Rules for custom security checks, and the open-source GraphQL Armor middleware.

Product and service4 records
1Attack Surface Management
CategoryAttack Surface Management
Description

Discovers and validates exposure of modern applications, APIs, SPAs, and infrastructure from code to cloud for enterprise security teams; flows discovered assets into Wiz with risk context.

2Business-logic-aware DAST
CategoryDynamic Application Security Testing
Description

AI-powered Dynamic Application Security Testing that secures applications at the business logic level for AppSec teams; features ≤4% false positive rate, OAuth/SSO/multi-tenant support, and developer-friendly remediation context.

3AI Pentesting
CategoryAI Penetration Testing
Description

Agent-driven penetration testing that replaces manual pentests and bug bounty programs for security teams; uses agentic attack reasoning with proof-of-exploitability artifacts and regression testing of bug bounty findings.

4Cascade
CategoryAI Penetration Testing
Description

Multi-agent pentesting engine for continuous, compounding security assessments of modern web applications, using specialized agents (orchestrator, coverage, exploitation, reporter) that build contextual knowledge of the attack surface over time.

Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeDirect peer
Description

Creator of Burp Suite, the dominant web application and API security testing platform used by penetration testers globally. Direct competitor in DAST and pentesting workflows, with significantly larger installed base among security professionals.

TypeDirect peer
Description

Provider of Invicti (formerly Netsparker) and Acunetix DAST platforms for web application and API security testing. Directly comparable in automated vulnerability discovery, proof-based scanning, and enterprise DAST positioning.

TypeDirect peer
Description

External Attack Surface Management and DAST platform focused on modern web applications and APIs. Closely overlaps with Escape's ASM and DAST products, targeting similar AppSec teams.

TypeBroad incumbent
Description

Comprehensive developer security platform spanning SAST, SCA, container, IaC, and DAST. A broader incumbent in application security that competes with Escape on DAST/API testing while also serving adjacent categories.

TypeBroad incumbent
Description

Established enterprise application security platform covering SAST, DAST, and software composition analysis. Incumbent in the AppSec category with deep Fortune 500 penetration and full portfolio coverage.

TypeDirect peer
Description

API and application security testing platform purpose-built for developers and CI/CD pipelines. Direct competitor with similar developer-first DAST positioning and modern auth/multi-tenant support.

TypeDirect peer
Description

API security platform offering API discovery, posture management, and runtime protection. Direct overlap with Escape's original API security focus and ASM capabilities.

TypeEmerging player
Description

AI-native offensive security platform providing autonomous attack surface management and continuous penetration testing. Closest emerging competitor in the AI-driven offensive security category Escape is targeting post-rebrand.

TypeEmerging player
Description

API security platform offering API discovery, inventory, and runtime threat detection. Emerging player with significant overlap in API-centric security testing and ASM.

TypeEmerging player
Description

Automated web application and API penetration testing platform with AI-assisted vulnerability discovery. Comparable in automated pentest positioning and SMB/mid-market go-to-market.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat4 records

Each record includes

Type, Details

Key risks6 records

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Ideal customer profile2 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
Yes

Docs URL, Description

Integration5 records

Each record includes

Title, Type, Description, Source

AI capability9 records

Each record includes

Type, Description, Source

AI maturity
App detail

Has app

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles2 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
Compliance6 records

Each record includes

Name, Class, Description

Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds4 records

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors8 records

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Escape

Application Security Testingescape.tech

Escape Technologies SAS is a Paris-based AI-native offensive security platform that helps enterprise security and engineering teams continuously discover, test, and remediate application and API vulnerabilities through multi-agent AI pentesting, business-logic-aware DAST, and attack surface management, serving over 2,000 security teams globally.

What Escape does

Escape Technologies SAS, founded in 2020 and headquartered in Paris with operations in Biarritz, is an AI-native offensive security engineering platform serving security and development teams. Originally positioned as an API discovery and API security vendor using generative AI to identify exposed APIs, the company rebranded in March 2026 around a broader offensive security thesis: continuously discovering, testing, and remediating vulnerabilities inside engineering workflows. The platform is built on a proprietary Business Logic Security Testing algorithm (the MetaGraph model) combined with NLP-based sourcing inference, strong typing inference across more than 800 data types, and reinforcement learning for API exploration. A multi-agent architecture — including the Cascade pentesting engine and AI Pentesting Agents 2.0 — orchestrates specialized exploitation agents (XSS, SQLi, BOLA, business logic, regression testing) with proof-of-concept validation.

The company sells three core products — Attack Surface Management, Business-Logic-Aware DAST, and AI Pentesting — designed to function as a continuous loop from discovery to remediation. Native integrations span Wiz (risk unification), Azure DevOps (CI/CD gates), and AI-assisted IDEs (Cursor, Claude Code, Gemini) for automated code remediation, alongside the open-source GraphQL Armor middleware. Escape reports more than 2,000 security teams as customers globally, with named enterprise logos including Visma, Miro, Schibsted, HealthEquity, Cato Networks, and Applied. The GTM is enterprise demo-led, with the company claiming 15%+ month-on-month revenue growth and serving customers across France, the UK, and the United States. Backed by Balderton Capital (Series A lead), Uncorrelated Ventures, IRIS, and Y Combinator, Escape has raised approximately $23 million in total venture funding across seed and Series A rounds.

Escape firmographics

Firmographics
Name
Escape
Legal name
Escape Technologies SAS
Website
https://escape.tech
Company type
Private
Founded year
2020
Operating status
Operating
Headcount range
1–10 employees
Short description
Escape Technologies SAS is a Paris-based AI-native offensive security platform that helps enterprise security and engineering teams continuously discover, test, and remediate application and API vulnerabilities through multi-agent AI pentesting, business-logic-aware DAST, and attack surface management, serving over 2,000 security teams globally.
Ownership category
akta.pro rank

Escape industry classification

Industry
Product category
Application Security Testing
NAICS
Security Systems Services (56162), Investigation and Security Services (5616)
SIC
Services-Computer Integrated Systems Design (7373)
akta.pro primary industry
Application Security Engineering (DevSecOps, AppSec Remediation) (BPAEAFAI)
akta.pro secondary industries
Vulnerability Intelligence & Exploit Prediction (HDADAHAI), Security Analytics & Detection Engineering (HDADAGAE)

Keywords

  • Application security testing
  • API security platform
  • Attack surface management
  • AI penetration testing
  • Offensive security platform

Where Escape is headquartered

Location

Headquarters

HQ city
Paris
HQ country
France
HQ region
Europe

Markets served

Escape business model

Business model
GTM type
B2B
Offering type
Software
Cost components
Technology or R&D, Personnel, Marketing or Sales, Operations, Infrastructure

Escape product offering

Product offering

Core offering

Escape is an AI-native offensive security engineering platform that continuously discovers, tests, and remediates vulnerabilities across modern applications, APIs, and infrastructure. Its three core products—Attack Surface Management, Business-Logic-Aware DAST, and AI Pentesting—use a proprietary MetaGraph algorithm and multi-agent architecture to replace legacy scanners and manual pentesting with automated, business-logic-aware security testing integrated into engineering workflows.

Product overview

Escape is an AI-native offensive security engineering platform that offers three core products: Attack Surface Management, Business-logic-aware DAST, and AI Pentesting. These products work together in a continuous workflow: ASM discovers assets (APIs, SPAs, hosts, schemas) across code to cloud, DAST tests every release at the business logic level, and AI Pentesting proves exploitability at scale with automated remediation. Key differentiators include the proprietary Business Logic Security Testing algorithm using MetaGraph, sourcing inference, and reinforcement learning. Additional offerings include the Cascade multi-agent pentesting engine, Visage Surface Scanner, Escape Rules for custom security checks, and the open-source GraphQL Armor middleware.

Differentiator

Problem solved

Functional benefit

Products and services

  • Attack Surface Management Discovers and validates exposure of modern applications, APIs, SPAs, and infrastructure from code to cloud for enterprise security teams; flows discovered assets into Wiz with risk context.
  • Business-logic-aware DAST AI-powered Dynamic Application Security Testing that secures applications at the business logic level for AppSec teams; features ≤4% false positive rate, OAuth/SSO/multi-tenant support, and developer-friendly remediation context.
  • AI Pentesting Agent-driven penetration testing that replaces manual pentests and bug bounty programs for security teams; uses agentic attack reasoning with proof-of-exploitability artifacts and regression testing of bug bounty findings.
  • Cascade Multi-agent pentesting engine for continuous, compounding security assessments of modern web applications, using specialized agents (orchestrator, coverage, exploitation, reporter) that build contextual knowledge of the attack surface over time.

Companies that use Escape

Customer profile

Ideal customer profiles2 records

Escape technology and API

Technology

Technology focussed Yes

API detail

Has API
Yes
API docs
API detail

Core technology

AI maturity

App detail

Integration5 records

AI capability9 records

Escape partnerships and signals

Strategic signal

Recent moves6 records

Expansion highlights6 records

Escape competitors and assessment

Company assessment

Direct peers

  • PortSwigger: Creator of Burp Suite, the dominant web application and API security testing platform used by penetration testers globally. Direct competitor in DAST and pentesting workflows, with significantly larger installed base among security professionals.
  • Invicti: Provider of Invicti (formerly Netsparker) and Acunetix DAST platforms for web application and API security testing. Directly comparable in automated vulnerability discovery, proof-based scanning, and enterprise DAST positioning.
  • Detectify: External Attack Surface Management and DAST platform focused on modern web applications and APIs. Closely overlaps with Escape's ASM and DAST products, targeting similar AppSec teams.
  • StackHawk: API and application security testing platform purpose-built for developers and CI/CD pipelines. Direct competitor with similar developer-first DAST positioning and modern auth/multi-tenant support.
  • Noname Security: API security platform offering API discovery, posture management, and runtime protection. Direct overlap with Escape's original API security focus and ASM capabilities.

Broad incumbents

  • Snyk: Comprehensive developer security platform spanning SAST, SCA, container, IaC, and DAST. A broader incumbent in application security that competes with Escape on DAST/API testing while also serving adjacent categories.
  • Veracode: Established enterprise application security platform covering SAST, DAST, and software composition analysis. Incumbent in the AppSec category with deep Fortune 500 penetration and full portfolio coverage.

Emerging players

  • Hadrian: AI-native offensive security platform providing autonomous attack surface management and continuous penetration testing. Closest emerging competitor in the AI-driven offensive security category Escape is targeting post-rebrand.
  • FireTail: API security platform offering API discovery, inventory, and runtime threat detection. Emerging player with significant overlap in API-centric security testing and ASM.
  • Beagle Security: Automated web application and API penetration testing platform with AI-assisted vulnerability discovery. Comparable in automated pentest positioning and SMB/mid-market go-to-market.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat4 records

Key risks6 records

Key highlights7 records

Customer concentration

Escape social profiles

Digital presence

Escape compliance and trust

Trust signal

Compliance6 records

Escape financial estimates

Financial estimate

Revenue estimate

Valuation estimate

Escape leadership team

Management profile

Number of profiles

Profiles2 records

Escape funding detail

Funding detail

Funding overview

Funding rounds4 records

Investors8 records

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

Escape M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about Escape

What does Escape do?

Escape is an AI-native offensive security engineering platform that continuously discovers, tests, and remediates vulnerabilities across modern applications, APIs, and infrastructure. Its three core products—Attack Surface Management, Business-Logic-Aware DAST, and AI Pentesting—use a proprietary MetaGraph algorithm and multi-agent architecture to replace legacy scanners and manual pentesting with automated, business-logic-aware security testing integrated into engineering workflows.

Is Escape a public or private company?

Escape is a private company. It is classified as venture growth investor backed and is currently operating.

When was Escape founded?

Escape was founded in 2020. It employs 1 to 10 people.

Where is Escape based?

Escape is headquartered in Paris, France, in the Europe region.

Who are Escape's main competitors?

Direct peers on record are PortSwigger, Invicti, Detectify, StackHawk and Noname Security. Broad incumbents are Snyk and Veracode. Emerging players are Hadrian, FireTail and Beagle Security.

Does Escape have an API?

Yes. Escape offers a fully programmable platform with Public API, CLI, and MCP Server. The API enables programmatic access to all platform capabilities including scan triggering, policy configuration, event-based workflows for triage/routing/escalation, and CI/CD security gates. The platform is event-based, allowing scripts to automate offensive security workflows. Developer documentation is at docs.escape.tech.

What industry is Escape in?

Escape's product category is Application Security Testing. Its primary akta.pro industry code is BPAEAFAI, Application Security Engineering (DevSecOps, AppSec Remediation), with a secondary code of HDADAHAI, Vulnerability Intelligence & Exploit Prediction. Its NAICS code is 56162 and its SIC code is 7373.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
Security BoulevardDriving efficiency in pentesting: new features live in EscapeEscape launched four new pentesting features on October 7: Issue Retest, Secrets vault integration, OSCP certification, and GitHub whitebox integration. These remove manual steps like full re-runs, credential management, and separate sign-offs. The features are live by default for customers.Security BoulevardEscape AI Pentesting Cascade v2: wider coverage, deeper exploits, less noiseEscape released Cascade v2, an AI pentesting product with wider coverage and deeper exploits. White-box mode now examines 100% of files, black-box API coverage rose from 60% to 90%, and false positives dropped threefold. The next iteration will focus on chaining exploits to find complex vulnerabilities.Security BoulevardHow Amp got its SOC 2 type II pentest evidence in hoursAmp, an AI hiring platform, used Escape's agent-based pentesting to generate SOC 2 Type II evidence in hours, compressing a manual engagement that takes weeks. The test produced two reports, and findings were remediated and confirmed on retest. Amp now considers more frequent pentests than the annual cadence.Security BoulevardHow Amp got its SOC 2 type II pentest evidence in hoursAmp, an AI hiring platform, used Escape's agent-based pentesting to obtain SOC 2 Type II evidence in hours, compressing a manual engagement that takes weeks. The test produced two reports, and findings were remediated quickly, with ISO 27001 planned for next year.Security BoulevardHorizon3.ai alternatives in 2026: Escape vs NodeZero and 4 more toolsHorizon3.ai launched NodeZero WebApp Pentesting and closed a $250 million funding round on July 29, 2026. The article evaluates this expansion against competitors like Escape, Pentera, and Cobalt, highlighting ongoing debates regarding autonomous AI penetration testing capabilities in enterprise environments.Security BoulevardEscape joins Anthropic’s Cyber Verification Program to advance AI-powered offensive securityEscape, an offensive security company, announced it has become a verified member of Anthropic's Cyber Verification Program, gaining access to frontier AI models for legitimate vulnerability research and security tooling development. The access will support Escape's AI-powered pentesting product Cascade, which uses multiple frontier and open-weight models to discover application vulnerabilities and provide working exploits with remediation code. The company argues this enables small security teams to keep pace with attackers who increasingly use AI to find and chain vulnerabilities faster than human teams can review them.Security BoulevardEscape joins OpenAI’s Trusted Access for Cyber (TAC) to advance AI-powered offensive securityEscape has been approved for OpenAI's Trusted Access for Cyber (TAC) preview program, giving their security and engineering teams verified access to frontier AI models for offensive security research. The access is intended to accelerate their Cascade AI pentesting agent and reduce the time between vulnerability discovery and proof-of-exploit plus remediation from months to hours. The company argues this levels the playing field against attackers who are already using AI for vulnerability discovery and exploitation, and positions verified AI access as an emerging component of vendor due diligence alongside SOC 2 and data residency.Security BoulevardWhitebox pentesting is now available in Escape’s AI Pentesting – CascadeEscape has announced the availability of whitebox pentesting mode in its AI pentesting engine Cascade, allowing users to attach source code repositories at the start of a pentest so the AI can begin with pre-existing knowledge of the codebase rather than discovering it blind. The feature automatically analyzes attached code to generate a tech fingerprint, auth model mapping, and source code map with flagged unguarded handlers and dangerous sinks. Benchmark results show the whitebox mode delivered a 32% improvement in vulnerability detection on average, with Cascade finding 28 validated findings on Photoview versus 12 in blackbox-only mode, both at 0% false-positive rate.Security BoulevardHow Escape DAST helped Sigma Computing achieve complete GraphQL API endpoint coverageSigma Computing, a cloud-native analytics platform, implemented Escape's GraphQL-native DAST security scanning tool, achieving 100% endpoint coverage across their API infrastructure after one year of deployment. The tool's in-cluster scanning model and exploitability evidence capabilities enabled the detection of previously undetected vulnerabilities including alias batching attacks and exposed MySQL instances with default credentials, significantly reducing triage time compared to their previous SAST-only approach. Sigma Computing is now exploring Escape's AI pentesting solution to further extend their security operations based on the context gathered from continuous DAST scanning.Security BoulevardHow Escape DAST Bypassed Immich’s Locked Folder By Finding a Missing DefaultEscape's DAST security testing tool discovered a broken access control vulnerability in Immich v3.0.2, a self-hosted media management application, where the locked folder PIN protection could be bypassed by omitting the visibility field in a POST /search/random request, allowing unauthorized access to private photos from sessions that never entered the PIN. The vulnerability stems from a missing default value in one of five sibling search handlers that correctly implement the protection, and also exposes a partner's locked assets due to an additional scope bypass. The issue was privately reported on July 13, 2026 and patched the same day, with Escape noting the fix simply requires applying the same visibility default that the other four search methods already use.