What the business is
A French cybersecurity startup whose agentless product dynamically scans APIs for security flaws and suggests remediations, integrated into CI/CD.
Starting capital
$3.9M (€3.6M) round; earlier pre-seed led by Frst
How it started
Founded by Tristan Kalos and Antoine Carossio, Escape went through Y Combinator's winter 2023 cohort, then raised $3.9M led by Iris with Frst and angels including Roxanne Varza. The team stood at 10 people.
What happened
The product integrates directly into the development pipeline: every commit triggers Escape through the CI/CD flow. A custom AI algorithm simulates cyberattacks — spotting missing rate limits that could leak large data volumes, or unblocked invalid actions — using reinforcement learning, a mix of deep learning and heuristics, and feeds findings into Snyk.
What has to be true
Pentests happen once or twice a year and end in reports; Escape catches flaws at commit time, when the responsible developer is one slack message away.
Testing the running API rather than source code captures business-logic attacks static tools miss.
GraphQL-first focus matched an underserved format with high-value users, before expanding to REST.
Reinforcement learning makes the scanner act like an attacker — probing interactions rather than pattern-matching signatures.
What can be applied
Don't compete with the annual pentest — automate the 364 days between them, and start with the niche API format where you can be the default.
Aftermath
As of 5 June 2023, Escape had around 20 clients including Sorare, Shine and Neo4J, was rolling out REST API support alongside GraphQL, and aimed at banks and financial services companies with contracts worth tens of thousands of euros per year.
FOLLOW THE EVIDENCE
The sources
- Escape dynamically scans APIs to find security flaws techcrunch.com