The archive · Developer & Business Tools · Product decision · 2025–2026
Hex Security's 24/7 AI-pentest bet: $1M ARR in 8 weeks, YC W26 favorite, now Parameter
Three ex-PlayAI/AWS founders sell continuous AI pentesting; YC W26 favorite hits $1M ARR in eight weeks, rebrands to Parameter.
Parameter (fka Hex Security)
What the business is
Parameter (formerly Hex Security) sells AI agents that run continuous penetration tests against companies' applications and infrastructure, finding vulnerabilities, chaining exploits, and delivering proof-of-concept findings with remediation steps.
Starting capital:$500K YC standard deal (W26); investors were described as 'fighting' to invest, with $100M+ valuations reported for the fastest W26 growers
How it started
Huzaifa Ahmad, Ahmad Khan, and Prama Yudhistira built Hex Security through YC's Winter 2026 batch after their agents found critical vulnerabilities in dozens of YC companies — SQL injection exposing billions of records, a demonstrated proof-of-concept worm, and access to hundreds of codebases. The company claims this prevented an estimated $3B+ in potential damages based on exposed record counts and IBM breach-cost benchmarks.
What happened
The go-to-market was the batch itself: fellow W26 companies were technical, in pain, and willing to let agents run on live infrastructure, so no customer education was needed. Hex crossed $1M ARR in eight weeks and was named one of the eight most sought-after startups at W26 Demo Day by TechCrunch, where investors were described as 'fighting' to invest; valuations of $100M+ were reported for the fastest W26 growers. In August 2026 the company rebranded to Parameter with the launch tagline 'AI that Hacks before Attackers do.'
How it ended up
As of September 2026 Parameter was live and scaling, marketing continuous AI pentesting to security-conscious startups and mid-market companies, with roughly ten employees. Revenue quality remained an open question — whether the $1M ARR was sticky recurring security contracts or batch-pilot money — and the company faced Cobalt, Pentera, and NodeZero in a crowded space.
Background
Hex Security emerged from YC's Winter 2026 batch with a pitch that was almost insultingly simple: companies run a penetration test once a year, while attackers probe their systems 24/7. Huzaifa Ahmad, Ahmad Khan, and Prama Yudhistira — ex-PlayAI and AWS engineers, an ex-OpenAI intern, and a Codegen alum — built AI agents that act as continuous penetration testers, probing APIs, auth flows, and business logic, chaining exploits together, and delivering proof-of-concept findings with reproduction steps.
The wedge was the batch itself. Fellow W26 companies were technical, already worried about security, and trusted the founders enough to let agents run on live infrastructure. The company says its agents found critical vulnerabilities in dozens of YC companies during the batch, including SQL injection exposing billions of records and a demonstrated worm that could infect entire networks, and that this prevented an estimated $3B+ in potential damages based on exposed record counts and IBM's breach-cost benchmarks.
Traction came fast: Hex crossed $1M ARR in eight weeks, and TechCrunch named it one of the eight startups investors chased at W26 Demo Day, reporting that investors 'were fighting' to invest. The Year One podcast documented the counter-argument: eight weeks of revenue on recurring security contracts is different from one-time project fees, and batch customers may not renew. In August 2026 the company rebranded to Parameter, launching with the tagline 'AI that Hacks before Attackers do.'
The bet is that penetration testing is fundamentally a reasoning problem — exactly what LLMs got good at — and that continuous agentic testing will replace annual manual engagements in a market the company pegs at $15B. The open questions are false positives at scale, liability when agents touch production systems, and whether the distribution that worked inside YC — trusted peers, no education cycle — extends to mid-market enterprises.
What has to be true
- Founders had offensive-security and AI credibility (PlayAI, AWS, OpenAI, Codegen), so buyers believed agents could actually hack before attackers did.
- The asymmetry framing — pentest once a year versus attackers 24/7 — required zero customer education and made the sales cycle collapse.
- Using the YC batch as the first market gave free, high-trust distribution: peers let agents run on live infrastructure during the batch.
- Delivering proof-of-concept exploits with remediation steps, not just vulnerability lists, made findings actionable for developers and defensible for security buyers.
What can be applied
When the buyer is already in pain, distribution beats education: selling to YC peers who knew the founders collapsed the sales cycle and made $1M ARR possible in eight weeks.
Aftermath
As of September 2026 Parameter (formerly Hex Security) was live and scaling: continuous AI pentesting for security-conscious startups and mid-market companies, roughly ten employees, and a launch post describing agents that found critical vulnerabilities in dozens of YC companies. The reported $1M ARR in eight weeks and $100M+ valuation talk from Demo Day remained company- and investor-reported; the durability test was whether batch peers renewed and whether enterprise buyers trusted autonomous agents to remediate without human review. Competitors included Cobalt, Pentera, and NodeZero.
Sources
- From moon hotels to cattle herding: 8 startups investors chased at YC Demo Day
- Launch YC: Parameter — AI that Hacks before Attackers do
- Hex Security: $1M ARR in 8 Weeks — Year One
spotted an error? The archive wants to know.
Your turn
You just read one. Describe what you are building, and see who is betting on the same thing.
Free account · 3 free questions · no card