设为首页加入收藏
  • 首页
  • Start up
  • 当前位置:首页 >Start up >【】

    【】

    发布时间:2025-09-13 08:38:17 来源:都市天下脉观察 作者:Start up

    Latest

    AI

    Amazon

    Apps

    Biotech & Health

    Climate

    Cloud Computing

    Commerce

    Crypto

    Enterprise

    EVs

    Fintech

    Fundraising

    Gadgets

    Gaming

    Google

    Government & Policy

    Hardware

    Instagram

    Layoffs

    Media & Entertainment

    Meta

    Microsoft

    Privacy

    Robotics

    Security

    Social

    Space

    Startups

    TikTok

    Transportation

    Venture

    More from TechCrunch

    Staff

    Events

    Startup Battlefield

    StrictlyVC

    Newsletters

    Podcasts

    Videos

    Partner Content

    TechCrunch Brand Studio

    Crunchboard

    Contact Us

    Rogue Esc key running from keyboard ... escaping
    Image Credits:Yagi Studio / Getty Images
    Security

    Escape dynamically scans APIs to find security flaws

    Romain Dillet 9:00 PM PDT · June 5, 2023

    French startup Escape has raised a $3.9 million (€3.6 million) funding round shortly after ending Y Combinator’s winter 2023 cohort. The company provides a cybersecurity product focused on securing APIs before they are rolled out publicly.

    French VC firm Iris is leading the round with Frst also participating once again after leading the pre-seed round. Existing investors Irregular Expressions, Tiny Supercomputers and Kima Ventures are participating in the round. Some of the company’s angel investors include Philippe Langlois, Mehdi Medjaoui and Roxanne Varza.

    “We decided to create a custom algorithm powered by artificial intelligence that can simulate cyberattacks. Once it has found security flaws, it will give you remediations,” co-founder and CEO Tristan Kalos told me. He founded the startup with Antoine Carossio, and there are now 10 people working for Escape.

    In more technical terms, Escape is an agentless solution as it integrates directly in your development pipeline. Every time the dev team commits some new lines of code in the code repository, it will trigger Escape using an integration in the continuous integration/continuous delivery flow (CI/CD).

    For instance, Escape can identify an issue with rate limiting. That means that a bad actor could leverage this flaw to extract large volumes of data. Escape can also see if invalid actions are properly blocked to prevent data manipulation. It integrates with Snyk so that Escape issues appear in your Snyk’s code issues.

    “These are dynamic tests. We don’t test the source code itself, but rather the application as it runs. What’s complicated with an API is the business logic — how to interact and how to attack the API. We use reinforcement learning, a mix of deep learning and heuristics,” Kalos said.

    Escape first decided to focus on GraphQL APIs as the startup identified that it would be the best go-to-market strategy. But the company is currently rolling out support for REST APIs, which are more widespread than GraphQL-based APIs.

    Techcrunch event

    Join 10k+ tech and VC leaders for growth and connections at Disrupt 2025

    Netflix, Box, a16z, ElevenLabs, Wayve, Sequoia Capital, Elad Gil — just some of the 250+ heavy hitters leading 200+ sessions designed to deliver the insights that fuel startup growth and sharpen your edge. Don’t miss the 20th anniversary of TechCrunch, and a chance to learn from the top voices in tech. Grab your ticket before Sept 26 to save up to $668.

    Join 10k+ tech and VC leaders for growth and connections at Disrupt 2025

    Netflix, Box, a16z, ElevenLabs, Wayve, Sequoia Capital, Elad Gil — just some of the 250+ heavy hitters leading 200+ sessions designed to deliver the insights that fuel startup growth and sharpen your edge. Don’t miss the 20th anniversary of TechCrunch, and a chance to learn from the top voices in tech. Grab your ticket before Sept 26 to save up to $668.

    San Francisco | October 27-29, 2025 REGISTER NOW

    The company has already convinced around 20 clients, such as Sorare, Shine and Neo4J. As you can see, Escape wants to focus on bigger clients working in sensitive industries, including banks and financial services companies. Each contract could potentially be worth tens of thousands of euros per year.

    Before Escape, making sure that your company’s APIs were secured was mostly a manual process. Every now and then, big companies work with security analysts to conduct a penetration test (or pentest, for short).

    “Once or twice a year, they come in, look at everything that’s going on and hand you a security report. Companies review the findings internally and list the issues: we’ve got to resolve this, we’ve got to resolve that,” Kalos told me.

    But then, companies have to find the developers who are in charge of this specific part of the product or that API in particular. In other words, it’s a reactive and imperfect process.

    Escape doesn’t want to replace pentests altogether. Pentests don’t just focus on APIs either, they are much larger than that. Escape just wants to surface security flaws at the API level so that they are fixed when they first appear. This way, most issues are already fixed when a security firm conducts a pentest. It’s a more proactive and dynamic security model, and that could be a nice selling point.

    • 上一篇:Doorstead closes on $21.5M to make sure you always have a tenant for your rental property
    • 下一篇:24 hours left to apply to volunteer at TechCrunch Disrupt and attend for free

      相关文章

      • Is the modern data stack just old wine in a new bottle?
      • Last call to volunteer at TC All Stage 2025
      • College social app Fizz expands into grocery delivery
      • Meta acquires voice startup Play AI
      • The unbearable lightness of being asset
      • Wonder Dynamics co
      • Introducing the Going Public Stage at Disrupt 2025
      • Only 2 days left to save $675 on your Disrupt 2025 ticket
      • Guidewheel lands $9M Series A
      • The startups rolling out of Europe’s early

        随便看看

      • As healthcare goes remote, Equipt Health brings medical hardware to the home
      • Suno snaps up WavTool for its AI music editing tools amid ongoing dispute with music labels
      • In just 3 months, Ramp's valuation jumped to $16B, up from $13B
      • Charles Hudson and Navin Chaddha join the Builders Stage at Disrupt 2025
      • Revere is creating a ratings system for the venture capital industry
      • Rainmaker partners with Atmo to squeeze more rain from clouds
      • Figma's IPO price hit a $19.3B valuation out of the gate
      • Next set of VC judges locked in for Startup Battlefield 200 at Disrupt 2025
      • Katana, an ERP for SMB manufacturers, raises $34M
      • Meta acquires AI audio startup WaveForms
      • Copyright © 2025 Powered by 【】,都市天下脉观察   辽ICP备198741324484号sitemap