Developer docs
API playgroundTry for free, no card

Search company profiles

Staris

Full company profile

uuid00025q2

Namestring
Staris
Legal namestring
Staris AI, Inc.
Websiteurl
staris.tech
Company typeenum
Private
Founded yearint
2023
Descriptiontext

Staris is a Seattle-based application security company, founded in 2023, that operates a continuous security validation platform positioned as an "immune system" for software applications. Its core offering is built on a "Total Context Security" methodology in which AI-driven agents ingest an application's source code, business logic, policies, and runtime behavior to discover, attempt real exploits against, and remediate vulnerabilities in running software. Every finding the platform produces is shipped with a working exploit, an execution trace, and a PR-ready code patch, with the company claiming zero false positives and a 99% reduction in scanner noise (e.g., reducing 590 scanner-flagged candidates to six proven exploitable vulnerabilities in an anonymized pilot).

The product is commercialized through three primary tiers: a one-time "Run" cycle at $4,900, a self-serve "Pro" subscription at $25,000/year, and a managed "Validated" subscription at $54,000/year that includes named-expert review and externally shareable, signed "Receipts." An Enterprise tier adds VPC/self-hosted deployment, dedicated TAM support, and custom contracting for regulated buyers. Staris runs a hybrid go-to-market combining enterprise field sales with 30-minute technical scoping calls, a self-serve inside-sales motion, and a partner-led channel through which security consultants integrate Staris into their service offerings (Staris reportedly handles ~80% of validation volume while partners retain triage, niche testing, and certificate sign-off). Named customers include OpsHelm, Atlas Networks, AMI Asset Track, and First Stop Health; the company is led by CEO Adam Cecchetti (previously founder of Deja Vu Security, acquired by Accenture) and CTO Austin Fath (formerly of AWS), with a CISO (Daniel Herrera) and CRO/Advisor (Steve Curtis) rounding out the executive team.

Short descriptiontext

Staris provides AI-driven continuous application security validation that proves exploitable vulnerabilities in running applications and ships PR-ready patches. The platform serves AppSec leaders at software companies and security consultants through subscription tiers ($25K–$54K annually) and a $4,900 one-time cycle.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
11–50
akta.pro rankint
HeadquartersSeattle, United States
HQ citystring
Seattle
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Offices1 record

Each record includes

City, Country, Type, Description, Source

Keyword5 values
application security validation, penetration testing, vulnerability management, security automation, exploit validation
Industry2 codes
1Application Security Testing (SAST/DAST/IAST/SCA)
CodeHDADACACPrimaryYes
2App Security, Compliance & Review Automation Platforms
CodeBPAMADAJPrimaryNo
NAICS code1 code
  • Computer Systems Design and Related Services54151
SIC code1 code
  • Services-Computer Programming Services7371
Product category
Application Security Validation Software
GTM motion3 records

Each record includes

Type, Description, Source

Revenue model5 records
1Subscription - Pro Tier
TypeSubscription Recurring
Description

Self-serve continuous validation platform subscription. Includes continuous validation engine, PR-ready patches with confidence labels, operator dashboard, SSO, advanced RBAC, advanced CI/CD integration, email + Slack support. Annual billing at $25,000/year.

staris.tech
2Subscription - Validated Tier
TypeSubscription Recurring
Description

Managed validation with named expert reviewing every cycle. Includes everything in Pro plus monthly signed Receipt, quarterly readout call, remediation refinement, volume discounts at 5+ apps. Annual billing at $54,000/year or $4,500 per cycle.

staris.tech
3Enterprise Subscription
TypeSubscription Recurring
Description

Custom scope and terms for multi-team or regulated buyers. Includes VPC/self-hosted deployment, custom validation frequency, dedicated TAM, custom RBAC + CI/CD integrations, volume + custom contract terms.

staris.tech
4Single Cycle Purchase
TypeOne Time License
Description

One full validation cycle on one application for $4,900. Includes the Receipt, PR-ready patches, and operator report. Credits roll into first Validated contract if continued.

staris.tech
5Forward-Deployed Engineering
TypeProfessional Services
Description

Optional paid add-on for forward-deployed engineering support in Pro and Validated tiers.

staris.tech
Marketing channels5 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels3 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Personnel, Technology or R&D, Infrastructure, Marketing or Sales, Operations
Pricing details4 tiers
1Single Cycle - One-time validation for $4,900
ModelUnit PricingBilling cadencePay-as-you-go
Notes

$4,900 per validation cycle on one application. Includes Receipt, PR-ready patches, and operator report. Credits roll into first Validated contract if customer continues. ~40% less than comparable one-off pentest.

staris.tech
2Pro - Self-serve continuous validation starting at $2,083/month
ModelSubscriptionBilling cadenceAnnual
Notes

Starting at $2,083/month ($25,000/year, billed annually). Self-serve continuous validation run in-house. Includes: continuous validation engine, PR-ready patches with confidence labels, operator dashboard, SSO, advanced RBAC, advanced CI/CD, email + Slack support. Forward-deployed engineering available as paid add-on.

staris.tech
3Validated - Managed validation with expert sign-off starting at $4,500/month
ModelSubscriptionBilling cadenceAnnual
Notes

Starting at $4,500/month ($54,000/year, billed annually). Managed validation with named expert reviewing every cycle. Includes everything in Pro plus: named Staris expert signs every cycle, monthly signed Receipt (externally shareable), quarterly readout call, remediation refinement, volume discounts at 5+ apps. $4,500 per cycle all-in vs ~$8K for comparable one-off pentest.

staris.tech
4Enterprise - Custom scope and terms, contact sales
ModelSubscriptionBilling cadenceMulti-year contract
Notes

Custom scope, custom terms for multi-team or regulated buyers. Includes everything in Pro plus: VPC/self-hosted deployment, custom validation frequency, dedicated TAM, custom RBAC + CI/CD integrations, volume + custom contract terms.

staris.tech
GTM typeB2B
B2B
Offering typeSoftware
Software
Core offering1 text field

Staris sells a continuous application security validation platform that uses AI agents to discover, exploit-validate, and remediate vulnerabilities in running applications. Every shipped finding includes a working exploit, an execution trace, and a PR-ready code-level patch, and the platform produces named-expert signed monthly Receipts for external stakeholders such as insurers, customers, and boards.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 7 values shown
  • 99% noise reduction - from 590 vulnerability candidates to 6 proven exploitable vulnerabilities
+6 more records
Product overview1 text field

Staris is a unified continuous application security validation platform built on its Total Context Security methodology. The core platform combines AI-driven autonomous exploitation, white-box source analysis, and automated patch generation into a single continuous validation loop. The offering is structured across three commercial tiers: Run (one-time cycle at $4,900), Pro ($2,083/month for self-serve continuous validation), and Validated ($4,500/month for managed validation with named expert review and signed Receipts). Enterprise adds custom VPC/self-hosted deployment and dedicated support. Two solution tracks address different buyers: Consultants/Partners (partner-led program architecture with Staris as volume-validation engine) and App Security Leaders (internal portfolio validation integrated into CI/CD). Every tier delivers the same core outputs: exploit-proven findings with working exploits, execution traces, and PR-ready patches.

Product and service2 records
1Staris Continuous Application Security Validation Platform
CategoryApplication Security Software
Description

Continuous application security validation platform for AppSec teams and CISOs at software companies. Uses AI agents to discover vulnerabilities in source code and running applications, exploit-validate each finding with a working exploit and execution trace, and generate PR-ready code-level patches. Produces named-expert signed monthly Receipts that can be shared externally with customers, insurers, and boards, and supports VPC/self-hosted deployment with an internal LLM for regulated environments.

2Staris Partner Validation Program for Security Consultants
CategoryChannel Partner Program
Description

Partner-led program that embeds Staris continuous exploit-proven validation into security consulting firms' service offerings. Staris handles the volume validation work while the partner firm retains triage, routing, niche-asset expert testing, oversight, and certificate sign-off, enabling consultancies to deliver continuous coverage without adding headcount.

Scale indicator7 records

Each record includes

Type, Value, Description, Source

Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight5 records

Each record includes

Type, Description

Peers10 records
TypeBroad incumbent
Description

Established enterprise AppSec platform for SAST/DAST/SCA. Targets the same AppSec leaders and CISOs Staris sells to, with broader portfolio and channel reach.

TypeBroad incumbent
Description

Broad developer-security platform offering SAST, SCA, container, and IaC scanning; directly overlaps Staris in AppSec testing for engineering teams. Larger incumbent adding AI-driven remediation features.

TypeBroad incumbent
Description

Enterprise SAST/AppSec leader competing for the same CISO/AppSec buyer. Comparable in target market and core functionality (application security testing) though typically black-box/pattern-based versus Staris' exploit-proven approach.

TypeDirect peer
Description

Crowdsourced security testing platform combining human testers with automation. Competes with Staris for pentest replacement budgets at enterprise security buyers.

TypeEmerging player
Description

AI-driven application security focused on dependency and code risk. Adjacent competitor in AI-first AppSec for fast-moving engineering organizations.

TypeDirect peer
Description

Pentest-as-a-service platform delivering manual and data-driven pentests on demand. Directly competes with Staris' positioning to replace traditional pentests with faster, scalable validation.

TypeEmerging player
Description

Code risk platform using AI to prioritize application risks across SDLC. Comparable in shifting AppSec from raw scanner output to context-driven prioritization for engineering teams.

TypeDirect peer
Description

IAST/runtime application security platform instrumenting running applications to confirm exploitability—directly analogous to Staris' 'prove it' approach for in-application validation.

TypeEmerging player
Description

AI-native application security testing targeting fast-shipping dev teams; comparable in applying AI agents to AppSec validation, though focused more on code-context analysis than active exploitation.

TypeDirect peer
Description

DAST and AppSec platform for enterprise web applications. Comparable buyer (AppSec leaders), comparable category (exploit-driven web app testing), competing on automation and accuracy.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat4 records

Each record includes

Type, Details

Key risks6 records

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers4 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment3 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile2 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
No

Docs URL, Description

AI capability7 records

Each record includes

Type, Description, Source

AI maturity
App detail

Has app

Feature6 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles4 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
Compliance1 record

Each record includes

Name, Class, Description

Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds1 record

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors2 records

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Staris

Application Security Validation Softwarestaris.tech

Staris provides AI-driven continuous application security validation that proves exploitable vulnerabilities in running applications and ships PR-ready patches. The platform serves AppSec leaders at software companies and security consultants through subscription tiers ($25K–$54K annually) and a $4,900 one-time cycle.

What Staris does

Staris is a Seattle-based application security company, founded in 2023, that operates a continuous security validation platform positioned as an "immune system" for software applications. Its core offering is built on a "Total Context Security" methodology in which AI-driven agents ingest an application's source code, business logic, policies, and runtime behavior to discover, attempt real exploits against, and remediate vulnerabilities in running software. Every finding the platform produces is shipped with a working exploit, an execution trace, and a PR-ready code patch, with the company claiming zero false positives and a 99% reduction in scanner noise (e.g., reducing 590 scanner-flagged candidates to six proven exploitable vulnerabilities in an anonymized pilot).

The product is commercialized through three primary tiers: a one-time "Run" cycle at $4,900, a self-serve "Pro" subscription at $25,000/year, and a managed "Validated" subscription at $54,000/year that includes named-expert review and externally shareable, signed "Receipts." An Enterprise tier adds VPC/self-hosted deployment, dedicated TAM support, and custom contracting for regulated buyers. Staris runs a hybrid go-to-market combining enterprise field sales with 30-minute technical scoping calls, a self-serve inside-sales motion, and a partner-led channel through which security consultants integrate Staris into their service offerings (Staris reportedly handles ~80% of validation volume while partners retain triage, niche testing, and certificate sign-off). Named customers include OpsHelm, Atlas Networks, AMI Asset Track, and First Stop Health; the company is led by CEO Adam Cecchetti (previously founder of Deja Vu Security, acquired by Accenture) and CTO Austin Fath (formerly of AWS), with a CISO (Daniel Herrera) and CRO/Advisor (Steve Curtis) rounding out the executive team.

Staris firmographics

Firmographics
Name
Staris
Legal name
Staris AI, Inc.
Website
https://staris.tech
Company type
Private
Founded year
2023
Operating status
Operating
Headcount range
11–50 employees
Short description
Staris provides AI-driven continuous application security validation that proves exploitable vulnerabilities in running applications and ships PR-ready patches. The platform serves AppSec leaders at software companies and security consultants through subscription tiers ($25K–$54K annually) and a $4,900 one-time cycle.
Ownership category
akta.pro rank

Staris industry classification

Industry
Product category
Application Security Validation Software
NAICS
Computer Systems Design and Related Services (54151)
SIC
Services-Computer Programming Services (7371)
akta.pro primary industry
Application Security Testing (SAST/DAST/IAST/SCA) (HDADACAC)
akta.pro secondary industry
App Security, Compliance & Review Automation Platforms (BPAMADAJ)

Keywords

  • Application security validation
  • Penetration testing
  • Vulnerability management
  • Security automation
  • Exploit validation

Where Staris is headquartered

Location

Headquarters

HQ city
Seattle
HQ country
United States
HQ region
North America

Offices1 record

Markets served

Staris business model

Business model
GTM type
B2B
Offering type
Software
Cost components
Personnel, Technology or R&D, Infrastructure, Marketing or Sales, Operations

Revenue model

  1. Subscription - Pro Tier: Self-serve continuous validation platform subscription. Includes continuous validation engine, PR-ready patches with confidence labels, operator dashboard, SSO, advanced RBAC, advanced CI/CD integration, email + Slack support. Annual billing at $25,000/year.
  2. Subscription - Validated Tier: Managed validation with named expert reviewing every cycle. Includes everything in Pro plus monthly signed Receipt, quarterly readout call, remediation refinement, volume discounts at 5+ apps. Annual billing at $54,000/year or $4,500 per cycle.
  3. Enterprise Subscription: Custom scope and terms for multi-team or regulated buyers. Includes VPC/self-hosted deployment, custom validation frequency, dedicated TAM, custom RBAC + CI/CD integrations, volume + custom contract terms.
  4. Single Cycle Purchase: One full validation cycle on one application for $4,900. Includes the Receipt, PR-ready patches, and operator report. Credits roll into first Validated contract if continued.
  5. Forward-Deployed Engineering: Optional paid add-on for forward-deployed engineering support in Pro and Validated tiers.

Pricing tiers

ModelBillingPrice
Unit PricingPay-as-you-goSingle Cycle - One-time validation for $4,900
SubscriptionAnnualPro - Self-serve continuous validation starting at $2,083/month
SubscriptionAnnualValidated - Managed validation with expert sign-off starting at $4,500/month
SubscriptionMulti-year contractEnterprise - Custom scope and terms, contact sales

Go-to-market motion3 records

Distribution channels3 records

Marketing channels5 records

Staris product offering

Product offering

Core offering

Staris sells a continuous application security validation platform that uses AI agents to discover, exploit-validate, and remediate vulnerabilities in running applications. Every shipped finding includes a working exploit, an execution trace, and a PR-ready code-level patch, and the platform produces named-expert signed monthly Receipts for external stakeholders such as insurers, customers, and boards.

Product overview

Staris is a unified continuous application security validation platform built on its Total Context Security methodology. The core platform combines AI-driven autonomous exploitation, white-box source analysis, and automated patch generation into a single continuous validation loop. The offering is structured across three commercial tiers: Run (one-time cycle at $4,900), Pro ($2,083/month for self-serve continuous validation), and Validated ($4,500/month for managed validation with named expert review and signed Receipts). Enterprise adds custom VPC/self-hosted deployment and dedicated support. Two solution tracks address different buyers: Consultants/Partners (partner-led program architecture with Staris as volume-validation engine) and App Security Leaders (internal portfolio validation integrated into CI/CD). Every tier delivers the same core outputs: exploit-proven findings with working exploits, execution traces, and PR-ready patches.

Differentiator

Problem solved

Functional benefit

Products and services

  • Staris Continuous Application Security Validation Platform Continuous application security validation platform for AppSec teams and CISOs at software companies. Uses AI agents to discover vulnerabilities in source code and running applications, exploit-validate each finding with a working exploit and execution trace, and generate PR-ready code-level patches. Produces named-expert signed monthly Receipts that can be shared externally with customers, insurers, and boards, and supports VPC/self-hosted deployment with an internal LLM for regulated environments.
  • Staris Partner Validation Program for Security Consultants Partner-led program that embeds Staris continuous exploit-proven validation into security consulting firms' service offerings. Staris handles the volume validation work while the partner firm retains triage, routing, niche-asset expert testing, oversight, and certificate sign-off, enabling consultancies to deliver continuous coverage without adding headcount.

Quantifiable outcome

  • 99% noise reduction - from 590 vulnerability candidates to 6 proven exploitable vulnerabilities
  • +6 more outcomes

Companies that use Staris

Customer profile

Named customers4 records

Segments3 records

Ideal customer profiles2 records

Staris technology and API

Technology

Technology focussed Yes

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

AI capability7 records

Feature6 records

Staris partnerships and signals

Strategic signal

Scale indicators7 records

Recent moves6 records

Expansion highlights5 records

Staris competitors and assessment

Company assessment

Broad incumbents

  • Veracode: Established enterprise AppSec platform for SAST/DAST/SCA. Targets the same AppSec leaders and CISOs Staris sells to, with broader portfolio and channel reach.
  • Snyk: Broad developer-security platform offering SAST, SCA, container, and IaC scanning; directly overlaps Staris in AppSec testing for engineering teams. Larger incumbent adding AI-driven remediation features.
  • Checkmarx: Enterprise SAST/AppSec leader competing for the same CISO/AppSec buyer. Comparable in target market and core functionality (application security testing) though typically black-box/pattern-based versus Staris' exploit-proven approach.

Direct peers

  • Synack: Crowdsourced security testing platform combining human testers with automation. Competes with Staris for pentest replacement budgets at enterprise security buyers.
  • Cobalt: Pentest-as-a-service platform delivering manual and data-driven pentests on demand. Directly competes with Staris' positioning to replace traditional pentests with faster, scalable validation.
  • Contrast Security: IAST/runtime application security platform instrumenting running applications to confirm exploitability—directly analogous to Staris' 'prove it' approach for in-application validation.
  • Invicti (formerly Netsparker): DAST and AppSec platform for enterprise web applications. Comparable buyer (AppSec leaders), comparable category (exploit-driven web app testing), competing on automation and accuracy.

Emerging players

  • Endor Labs: AI-driven application security focused on dependency and code risk. Adjacent competitor in AI-first AppSec for fast-moving engineering organizations.
  • Apiiro: Code risk platform using AI to prioritize application risks across SDLC. Comparable in shifting AppSec from raw scanner output to context-driven prioritization for engineering teams.
  • DryRun Security: AI-native application security testing targeting fast-shipping dev teams; comparable in applying AI agents to AppSec validation, though focused more on code-context analysis than active exploitation.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat4 records

Key risks6 records

Key highlights7 records

Customer concentration

Staris social profiles

Digital presence

Staris compliance and trust

Trust signal

Compliance1 record

Staris financial estimates

Financial estimate

Revenue estimate

Valuation estimate

Staris leadership team

Management profile

Number of profiles

Profiles4 records

Staris funding detail

Funding detail

Funding overview

Funding rounds1 record

Investors2 records

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

Staris M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about Staris

What does Staris do?

Staris sells a continuous application security validation platform that uses AI agents to discover, exploit-validate, and remediate vulnerabilities in running applications. Every shipped finding includes a working exploit, an execution trace, and a PR-ready code-level patch, and the platform produces named-expert signed monthly Receipts for external stakeholders such as insurers, customers, and boards.

Is Staris a public or private company?

Staris is a private company. It is classified as venture growth investor backed and is currently operating.

When was Staris founded?

Staris was founded in 2023. It employs 11 to 50 people.

Where is Staris based?

Staris is headquartered in Seattle, United States, in the North America region.

How does Staris make money?

Five revenue lines are on record. Subscription - Pro Tier is the primary driver. The others are subscription - Validated Tier, enterprise Subscription, single Cycle Purchase and forward-Deployed Engineering.

Who are Staris's main competitors?

Broad incumbents on record are Veracode, Snyk and Checkmarx. Direct peers are Synack, Cobalt, Contrast Security and Invicti (formerly Netsparker). Emerging players are Endor Labs, Apiiro and DryRun Security.

Does Staris have an API?

No public API is recorded for Staris.

What industry is Staris in?

Staris's product category is Application Security Validation Software. Its primary akta.pro industry code is HDADACAC, Application Security Testing (SAST/DAST/IAST/SCA), with a secondary code of BPAMADAJ, App Security, Compliance & Review Automation Platforms. Its NAICS code is 54151 and its SIC code is 7371.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales