CYBRET AI Wires a Knowledge Graph Into the Attack Path

A Stockholm pre-seed backed by Skyfall Ventures argues application security should reason semantically, not scan statically.

About CYBRET AI

Published

The pitch from CYBRET AI is that most application security tools still read code and cloud config the way a linter reads a file: line by line, rule by rule, without a model of what the running system actually is. The Stockholm company, founded in 2025 by Adrian De Gendt, wants to replace that with a single knowledge graph of code, cloud, identity, and APIs, and let agents reason across it at machine speed [CYBRET AI, retrieved 2024].

It is early. The company closed a $990,000 pre-seed in December 2025 led by Skyfall Ventures, with a further seed of undisclosed size logged the same month [Nordic9, Dec 2025] [Tracxn, Dec 2025]. Headcount sits at eleven [LinkedIn, retrieved 2026]. That is a very small team pointing at a very large problem, which is roughly the profile Nordic security angels seem to like.

From static rules to a live graph

The conceptual wedge is worth taking seriously. Traditional application security posture management stitches together SAST, DAST, cloud scanners, and identity tools, each producing its own alert stream. Security teams then spend most of their time deciding which of those alerts describe a path an attacker could actually walk. CYBRET's argument is that the reachability question should be answered by the system, not the analyst [CYBRET AI, retrieved 2024].

To do that, the product connects read-only sources across code, cloud, identity, and APIs to build a live graph, then reasons over it to reconstruct exploitable paths [CYBRET AI, retrieved 2024]. The company describes the shift as moving "from static to semantic" application security, powered by a reasoning engine rather than a rules catalog [CYBRET AI, retrieved 2024].

Three products, one graph

The platform is organized into three surfaces that share the underlying graph, which is the interesting architectural choice. Everything the company builds should compound on the same substrate rather than fork into disconnected scanners.

  • Exposure Intelligence. The graph layer that ingests code, cloud, identity, and API sources and reconstructs which attack paths are reachable in the running system [CYBRET AI, retrieved 2024].
  • Validation. Agents that re-attack the paths surfaced by Exposure Intelligence in a controlled way, continuously proving exploitability rather than inferring it from CVE scores [CYBRET AI, retrieved 2024].
  • Runtime Detection. A detection and response layer that operates at call-trace resolution, correlating live behavior back to the same graph [CYBRET AI, retrieved 2024].

Internally, the company frames these as a sensor layer, a reasoning layer, and an action layer [Tracxn, retrieved 2024]. The design bet is that a single semantic model of the environment is more valuable than three best-of-breed point tools, because it lets one product answer questions the others cannot: not just "is this vulnerable," but "is this reachable, exploitable, and worth waking someone up for."

Pricing built around a claim

CYBRET is charging on "paths closed," a unit that only makes sense if the product actually proves exploitability end to end. The published tiers are Startup at $990 per month for 25 applications, Scaleup at $4,800 per month for 200 applications, and a custom Enterprise annual contract [CYBRET AI, retrieved 2024].

That is aggressive positioning for a pre-seed. It also aligns incentives in a way that CISOs tend to like: the vendor gets paid when a reachable attack path is retired, not when an alert is generated. Whether the underlying agents can actually validate exploitability reliably enough to defend that pricing at contract renewal is the open question, and the one the next twelve months will answer.

The founder and the check

Adrian De Gendt is the sole publicly named founder. His public record includes a stint as a Junior Security Analyst at Telenor Cyberdefence in early 2025, described as the youngest hire in that unit's history, and a dropped Master's in AI [adriandegendt.com, retrieved 2026] [SignalHire, retrieved 2026]. He was accepted into YC's AI Startup School and went through FR8 Cohort 1.0, which focused on securing AI [adriandegendt.com, retrieved 2026].

The investor list is more of the story than the round size. Skyfall Ventures led, with participation from Inception Fund, Visionaries Club, Wave Ventures, FR8, and angels including Risto Siilasmaa and Peter Sarlin [Nordic9, Dec 2025]. Siilasmaa is the former F-Secure chairman; Sarlin co-founded Silo AI. That is a specific pocket of Nordic operator capital that understands both applied AI and the security buyer.

Pre-seed (Dec 2025) | 0.99 | M USD

What XBOW's shadow means

The named public comparable is XBOW, the US-based autonomous pentesting company that has raised at a valuation well beyond CYBRET's current scale. That matters for two reasons. It validates that enterprise buyers are willing to spend on autonomous offensive-security agents, and it means CYBRET is entering a category where the pace-setter already has a head start on customer proof points.

CYBRET's counter is that Validation is one of three surfaces, not the whole product. If the knowledge graph is real, Exposure Intelligence and Runtime Detection are the layers where a pure pentesting agent has no answer, because it doesn't own the semantic model of the environment. That framing is defensible on paper. It has to be proven with named design partners, and none are yet public.

Where this gets hard

On the technical side, the architecture inherits the failure modes of every graph-first security product before it. Build a live graph of code, cloud, identity, and APIs across a large enterprise and three things happen: ingestion breaks at the edges where source systems change schema, the graph gets stale between refreshes, and reasoning cost grows non-linearly as the graph does. The read-only integration posture helps with the first, but the second and third are the ones that quietly kill knowledge-graph products at the 500-service mark.

The Validation layer carries its own operational risk. Re-attacking paths in a customer environment, even carefully, is the kind of feature that generates one incident report and loses a logo. And Runtime Detection at call-trace resolution implies either an agent in the workload or deep integration with an eBPF-class collector, both of which put CYBRET into direct performance and reliability comparisons with incumbents that have spent years tuning overhead. Getting eleven people, a pre-seed budget, and a knowledge graph to hold up against that comparison at a Fortune 500's traffic volume is the scale problem the team has actually signed up for.

Sources

  1. [CYBRET AI, retrieved 2024] CYBRET AI product and pricing pages | https://www.cybret.ai/
  2. [LinkedIn, June 2024] CYBRET AI launch post | https://www.linkedin.com/posts/cybret_today-we-are-launching-a-new-era-of-autonomous-activity-7404490982739693568-knlb
  3. [LinkedIn, retrieved 2026] CYBRET AI company page | https://se.linkedin.com/company/cybret
  4. [Nordic9, Dec 2025] Cybret AI in a pre-seed equity deal with Skyfall Ventures | https://nordic9.com/news/cybret-ai-in-a-pre-seed-equity-deal-with-skyfall-ventures-wave-ventures-inception-fund-visionaries-club-fr8/
  5. [Tracxn, Dec 2025] Cybret company profile | https://platform.tracxn.com/a/d/company/693f9ed6634eba04c94f51a6/cybret
  6. [adriandegendt.com, retrieved 2026] Adrian De Gendt personal site | https://adriandegendt.com/
  7. [SignalHire, retrieved 2026] Adrian De Gendt employment history

Read on Startuply.vc