EN
返回档案库

档案库 · 开发与企业工具 · 产品决策 · 2025–2026

Hex Security 的 24/7 AI 渗透测试赌注:8 周内实现 100 万美元年经常性收入,YC W26 热门,现更名为 Parameter

三位前 PlayAI/AWS 创始人销售持续 AI 渗透测试;YC W26 热门在八周内达到 100 万美元年经常性收入,并更名为 Parameter。

Parameter(前身为 Hex Security)

它在赌什么渗透测试是一个推理问题:24/7 运行的 AI 代理可以串联漏洞并交付 PoC 发现,取代昂贵的一年一次的人工渗透测试。在扩

做的是什么生意

Parameter (formerly Hex Security) sells AI agents that run continuous penetration tests against companies' applications and infrastructure, finding vulnerabilities, chaining exploits, and delivering proof-of-concept findings with remediation steps.

启动资金$500K YC standard deal (W26); investors were described as 'fighting' to invest, with $100M+ valuations reported for the fastest W26 growers

起因

Huzaifa Ahmad, Ahmad Khan, and Prama Yudhistira built Hex Security through YC's Winter 2026 batch after their agents found critical vulnerabilities in dozens of YC companies — SQL injection exposing billions of records, a demonstrated proof-of-concept worm, and access to hundreds of codebases. The company claims this prevented an estimated $3B+ in potential damages based on exposed record counts and IBM breach-cost benchmarks.

经过

The go-to-market was the batch itself: fellow W26 companies were technical, in pain, and willing to let agents run on live infrastructure, so no customer education was needed. Hex crossed $1M ARR in eight weeks and was named one of the eight most sought-after startups at W26 Demo Day by TechCrunch, where investors were described as 'fighting' to invest; valuations of $100M+ were reported for the fastest W26 growers. In August 2026 the company rebranded to Parameter with the launch tagline 'AI that Hacks before Attackers do.'

结果

As of September 2026 Parameter was live and scaling, marketing continuous AI pentesting to security-conscious startups and mid-market companies, with roughly ten employees. Revenue quality remained an open question — whether the $1M ARR was sticky recurring security contracts or batch-pilot money — and the company faced Cobalt, Pentera, and NodeZero in a crowded space.

背景

Hex Security 从 YC 2026 冬季批次中脱颖而出,其卖点简单得几乎不可置信:公司每年进行一次渗透测试,而攻击者全天候探测系统。Huzaifa Ahmad、Ahmad Khan 和 Prama Yudhistira——前 PlayAI 和 AWS 工程师、前 OpenAI 实习生和 Codegen 校友——构建了充当持续渗透测试员的 AI 代理,探测 API、认证流程和业务逻辑,串联漏洞,并交付带有复现步骤的概念验证发现。

切入点是批次本身。同期 W26 公司技术能力强,已经担心安全性,并且信任创始人,允许代理在实时基础设施上运行。该公司表示,在批次期间,其代理在数十家 YC 公司中发现了严重漏洞,包括 SQL 注入暴露数十亿条记录,以及一个可感染整个网络的演示蠕虫,基于暴露记录数和 IBM 泄露成本基准,这防止了估计超过 30 亿美元的潜在损失。

牵引力来得很快:Hex 在八周内跨越了 100 万美元的 ARR,TechCrunch 将其列为 W26 Demo Day 上投资者追逐的八家初创公司之一,并报道投资者“争抢”投资。Year One 播客记录了反驳论点:八周的收入在经常性安全合同上与一次性项目费用不同,并且批次客户可能不会续约。2026 年 8 月,公司更名为 Parameter,以“AI 在攻击者之前入侵”的口号推出。

赌注是渗透测试本质上是一个推理问题——正是 LLM 擅长的——并且持续代理测试将取代年度人工参与,在一个公司估计为 150 亿美元的市场中。悬而未决的问题是规模上的误报、代理接触生产系统时的责任,以及在 YC 内部有效的分销模式——信任的同行,无教育周期——是否能扩展到中型企业。

这件事要成立,得有什么

  • 创始人有进攻性安全和 AI 的可信度(PlayAI、AWS、OpenAI、Codegen),因此买家相信代理真的可以在攻击者之前入侵。
  • 不对称的框架——每年一次渗透测试与攻击者 24/7——无需客户教育,并使销售周期崩溃。
  • 利用 YC 批次作为第一个市场,提供了免费、高信任度的分销:同行在批次期间允许代理在实时基础设施上运行。
  • 交付带有修复步骤的概念验证漏洞利用,而不仅仅是漏洞列表,使发现对开发人员可操作,对安全买家可辩护。

可借鉴之处

当买家已经有痛点时,分销胜过教育:向认识创始人的 YC 同行销售压缩了销售周期,使八周内实现 100 万美元 ARR 成为可能。

后续进展

截至 2026 年 9 月,Parameter(前身为 Hex Security)已上线并扩展:为注重安全性的初创公司和中等规模公司提供持续 AI 渗透测试,员工约十人,发布文章描述了在数十家 YC 公司中发现严重漏洞的代理。报告称八周内 100 万美元 ARR 和 Demo Day 上超过 1 亿美元估值的言论仍是公司和投资者报告;持久性测试是批次同行是否续约,以及企业买家是否信任自主代理在没有人工审查的情况下进行修复。竞争对手包括 Cobalt、Pentera 和 NodeZero。

资料来源

发现哪里写错了?告诉我们。

轮到你了

你刚读完一家。说说你在做什么,看看谁在赌同一件事。

免费账号 · 3 次免费提问 · 不用绑卡

相关案例