A French cybersecurity startup whose agentless product dynamically scans APIs for security flaws and suggests remediations, integrated into CI/CD.

$3.9M (€3.6M) round; earlier pre-seed led by Frst

Founded by Tristan Kalos and Antoine Carossio, Escape went through Y Combinator's winter 2023 cohort, then raised $3.9M led by Iris with Frst and angels including Roxanne Varza. The team stood at 10 people.

The product integrates directly into the development pipeline: every commit triggers Escape through the CI/CD flow. A custom AI algorithm simulates cyberattacks — spotting missing rate limits that could leak large data volumes, or unblocked invalid actions — using reinforcement learning, a mix of deep learning and heuristics, and feeds findings into Snyk.

Pentests happen once or twice a year and end in reports; Escape catches flaws at commit time, when the responsible developer is one slack message away.

Testing the running API rather than source code captures business-logic attacks static tools miss.

GraphQL-first focus matched an underserved format with high-value users, before expanding to REST.

Reinforcement learning makes the scanner act like an attacker — probing interactions rather than pattern-matching signatures.

Don't compete with the annual pentest — automate the 364 days between them, and start with the niche API format where you can be the default.

As of 5 June 2023, Escape had around 20 clients including Sorare, Shine and Neo4J, was rolling out REST API support alongside GraphQL, and aimed at banks and financial services companies with contracts worth tens of thousands of euros per year.

FOLLOW THE EVIDENCE

The sources

  1. Escape dynamically scans APIs to find security flaws techcrunch.com