Fleuret AI

AI-powered automated pentesting for web applications and APIs, with audit-ready results for compliance.

Website: https://fleuret.ai/

Cover Block

Open sources

Field Value
Name Fleuret AI
Tagline AI-powered automated pentesting for web applications and APIs, with audit-ready results for compliance [Fleuret AI, Unknown]
Headquarters Paris, France [LinkedIn, Unknown]
Founded 2026 [Crunchbase]
Stage Seed [Fleuret AI, May 2026]
Business Model SaaS
Industry Security
Technology AI / Machine Learning
Geography Western Europe
Growth Profile Venture Scale
Founding Team Co-Founders (2)
Funding Label Seed
Total Disclosed €3.5 million total, including €2.8 million in equity and a €700,000 Bpifrance innovation loan [Fleuret AI, May 2026]

Links

Open sources

What an Investor Needs First

PUBLIC Fleuret AI is a Paris-based cybersecurity startup building an AI-driven platform for automated penetration testing of web applications and APIs, and it merits investor attention now because it paired that product thesis with a freshly announced €3.5 million financing in May 2026 [Fleuret AI, May 2026] [Fleuret AI, Unknown]. The company was formed in 2026, with public materials and secondary profiles naming Yanis Grigy, Augustin Ponsin, and Macky Dabo among the founders, while French company-registration references cited in the research identify Grigy as president and Ponsin as managing director from January 26, 2026 [Shaan Narain - Qonto | LinkedIn, 2026] [VivaTech, June 2026].

The product, branded around the "Emile" framework, is positioned as more than a scanner: Fleuret says it simulates real attacks, verifies exploitability through controlled proof-of-concept workflows, and produces audit-ready reporting mapped to compliance regimes such as DORA and NIS2 [Fleuret AI, Unknown] [Paul GIRAL - Clustor | LinkedIn, 2026]. That combination, if it performs as advertised, gives the company a distinct wedge into European regulated buyers who want evidence-generation and compliance workflow support, not only alerting [Fleuret AI, Unknown].

The founding bench is still early and only partly independently documented, but the available public record does show Grigy tied to HEC Paris through VivaTech programming and Ponsin publicly presented as a co-founder on LinkedIn [VivaTech, June 2026] [Augustin Ponsin - Co-Founder & CPO @ Fleuret AI | X HEC, 2026]. That leaves investors with a familiar seed-stage pattern: an interesting product claim and clear market pain point, against a management dossier that still needs fuller third-party substantiation.

On financing, the cleanest public disclosure is Fleuret's own May 2026 announcement of €2.8 million in equity led by RAISE Capital, with Auriga Cyber Ventures and Wind Capital participating, plus a €700,000 Bpifrance innovation loan, for €3.5 million total [Fleuret AI, May 2026] [Bpifrance.com, 2026]. The commercial model appears to be SaaS with product-led entry points and partner-assisted distribution, although public pricing signals are still mostly company-published, including a €4,000 pentest entry point and wholesale partner pricing references that have not been independently corroborated [Fleuret AI, Unknown] [Stork.AI, 2026].

Over the next 12 to 18 months, the key items to watch are straightforward: whether Fleuret can convert compliance-oriented positioning into named enterprise adoption, whether its hiring plan from roughly five to about 12 employees is actually executed, and whether "agentic" pentesting translates into repeatable, trusted outcomes rather than a compelling demo layer [Fleuret AI, May 2026] [Indeed]. The setup is promising, but most of the operational proof points remain company-sourced at this stage, which keeps the underwriting burden on customer validation and product efficacy.

Claim stands unchecked -- This section relies materially on company-published funding, product, pricing, and hiring claims, with partial corroboration from VivaTech, LinkedIn profiles, and Bpifrance context.

Taxonomy Snapshot

Axis Value
Stage Seed
Business Model SaaS
Industry / Vertical Security
Technology Type AI / Machine Learning
Geography Western Europe
Growth Profile Venture Scale
Founding Team Co-Founders (2)
Funding Seed, total disclosed ~US$4.2M

Inside the Company

PUBLIC

Fleuret AI presents itself as a Paris-based cybersecurity startup focused on automated penetration testing for web applications and APIs, using agentic AI to produce audit-ready results for compliance workflows [Fleuret AI] [Crunchbase]. The company is categorized by Crunchbase as a security software business headquartered in Paris, with a 2026 founding date and seed-stage financing status [Crunchbase]. Public company materials frame the initial wedge clearly: lower-cost, faster pentesting for regulated European organizations that need recurring validation rather than periodic consultant-led audits [Fleuret AI].

The public record on formation is still thin, but there is enough to sketch the opening chronology. Fleuret's own materials identify Yanis Grigy as co-founder and CEO and Augustin Ponsin as co-founder, while French corporate-registration reporting cited in the research identifies Grigy as president and Ponsin as managing director from January 26, 2026 [Fleuret AI] [Crunchbase]. By May 2026, the company announced a €3.5 million financing package composed of €2.8 million in equity led by RAISE Capital, with Auriga Cyber Ventures and Wind Capital participating, plus a €700,000 Bpifrance innovation loan [Fleuret AI, May 2026].

That financing announcement is the clearest public milestone to date, because it ties the company, product, and hiring plan into one dated event. Fleuret said the capital would support product development, hiring, and compliance-oriented product work around frameworks including NIS2, DORA, and ISO 27001, and it said headcount was expected to grow from five to roughly twelve by year-end 2026 [Fleuret AI, May 2026]. The external record beyond that point remains company-led rather than independently reported, so the operating history should be treated as early and still lightly corroborated.

Partially corroborated -- Relies primarily on company website and company financing announcement, with partial corroboration from Crunchbase.

Under the Hood

Reported and inferred

Fleuret is selling a narrower promise than most security automation startups: not generic exposure management, but repeatable pentesting for web applications and APIs with evidence that a security or compliance team can use immediately [Fleuret AI] [Fleuret AI, May 2026]. Its public materials describe an agentic system called Emile that simulates real attacks, targets specific classes of web risk such as authentication flaws, injection, IDOR, and business-logic abuse, and only reports issues it can reproduce with proof of concept [Fleuret AI] [LinkedIn, 2026]. The company also frames the output as operational rather than archival, with findings hosted in Europe on Scaleway in Paris, retesting workflows, and reporting designed to map to NIS2, DORA Article 24, and ISO 27001-oriented audit processes [Fleuret AI].

The useful distinction here is that Fleuret is positioning itself between a scanner and a human-led consultancy, with more validation than the former and materially lower stated cost than the latter [Fleuret AI]. On its homepage, the company claims a pentest can be delivered in hours rather than weeks and marketed at about €4,000 versus €15,000 to €30,000 for a traditional firm, although those economics remain company-reported and should be read as positioning rather than independently verified market pricing [Fleuret AI]. Public pricing and partner materials also point to a freemium entry point and reseller-oriented wholesale terms, which suggests the product is being designed for both direct use and channel distribution, but the available public evidence does not yet establish how much of the workflow is fully autonomous in production environments versus analyst-reviewed before delivery [Stork.AI, 2026] [Fleuret AI].

A small amount of implementation detail is visible from public hiring and founder-adjacent posts, but the stack should still be treated cautiously. Fleuret and related LinkedIn references say Emile is built on open-source models hosted on sovereign French cloud, while an Indeed listing for a Full Stack Developer described work spanning architecture, infrastructure, product, and the AI pipeline, which supports the view that model orchestration and product engineering are core to the platform rather than an add-on layer [LinkedIn, 2026] [Indeed]. Beyond that, any deeper stack description would be inference, and the public record is not yet rich enough to separate durable technical differentiation from early go-to-market packaging.

Claim stands unchecked -- Material product claims in this section rely primarily on company website content and company-published funding materials, with limited partial corroboration from LinkedIn and Indeed.

Market Research

Open sources The market matters because European security teams are being pushed toward more frequent, better-documented validation work at the same time application attack surfaces keep expanding across web apps and APIs [Fleuret AI, Unknown] [Fleuret AI, May 2026].

The public record here is thinner than an institutional buyer would want on formal market sizing. No named third-party TAM, SAM, or SOM estimate for automated pentesting, continuous security validation, or AI-led offensive security appears in the supplied research, so the safer read is qualitative: Fleuret is aiming at the overlap between application security testing, compliance-oriented cyber assurance, and managed or automated penetration testing for European enterprises and scale-ups [Fleuret AI, Unknown] [Fleuret AI, May 2026]. Its own materials consistently frame the buyer as CISOs, CTOs, and DPOs in regulated environments, which suggests the initial reachable market is narrower than the full cybersecurity budget pool and more closely tied to firms with external audit pressure and internet-facing software estates [Fleuret AI, Unknown] [Fleuret AI, May 2026].

Demand drivers are easier to substantiate than market size. Fleuret's product and financing materials repeatedly anchor the need around NIS2, DORA, and ISO 27001 readiness, with positioning that emphasizes audit-ready evidence, repeatability, and faster testing cycles for web applications and APIs [Fleuret AI, Unknown] [Fleuret AI, May 2026]. Bpifrance's support for innovation loans to French SMEs investing in new technology is also relevant at the ecosystem level, because it shows domestic policy support for early cyber tooling in France even if it does not validate end-customer demand on its own [Bpifrance.com, 2026].

The adjacent markets are broad enough to matter for distribution and competition. Fleuret's wedge sits next to traditional human-led pentesting, vulnerability management, application security testing, compliance tooling, and cyber-insurance services, and the company has said it intends to work through cyber insurers and specialist security firms as well as direct sales [Fleuret AI, May 2026]. That matters because substitute products do not need to look identical to compete: a buyer trying to satisfy DORA or NIS2 evidence requirements could allocate budget to a consulting-led pentest, an AppSec platform, or a managed assessment service rather than an autonomous testing product [Fleuret AI, Unknown] [Fleuret AI, May 2026].

Regulation is the clearest macro tailwind in the available evidence, but it cuts both ways. On the positive side, Fleuret's claim that reports map to DORA Article 24 and NIS2 Annex I indicates a go-to-market strategy built around compliance deadlines and board-level reporting needs, which can shorten the path from technical testing to budget approval if the mapping holds up in practice [Fleuret AI, Unknown]. The harder part is that regulation also raises the proof burden: buyers in financial services and other regulated sectors usually need reproducibility, safe execution controls, and audit-grade documentation before they trust an automated offensive workflow in production environments [Fleuret AI, Unknown].

Market lens Public evidence Implication for Fleuret
Core category Automated pentesting for web applications and APIs [Fleuret AI, Unknown] Focuses the company on application-layer security budgets rather than general security spend.
Buying trigger NIS2, DORA, ISO 27001 compliance needs [Fleuret AI, Unknown] [Fleuret AI, May 2026] Compliance may accelerate initial adoption if reports are accepted by auditors and internal risk teams.
Substitute spend Traditional pentesting, AppSec tooling, specialist firms, cyber-insurance workflows [Fleuret AI, May 2026] The product competes for budget against services and platforms, not only against direct automated-pentest peers.
Geographic context Paris-based, Europe-hosted findings, sovereign positioning [Fleuret AI, Unknown] Data residency and European hosting are part of the commercial argument, especially for regulated buyers.

The picture that emerges is a market with visible need but limited public sizing in the current source set. The most credible near-term opportunity appears to be the compliance-linked segment of AppSec validation in Europe, where speed, documentation, and hosting jurisdiction can matter as much as raw detection depth [Fleuret AI, Unknown] [Fleuret AI, May 2026].

Claim stands unchecked -- This section relies primarily on company materials for market framing, buyer definition, regulatory mapping, and adjacent-market positioning, with limited independent corroboration from Bpifrance on the innovation-loan context.

Competition and Substitutes

MIXED

Fleuret AI is positioning itself against a crowded security stack by selling a narrower promise than most platform vendors: automated pentesting for web applications and APIs, with evidence formatted for compliance and hosted in Europe [Fleuret AI, Unknown] [Fleuret AI, May 2026].

Company Positioning Stage / Funding Notable Differentiator Source
Fleuret AI Agentic AI pentesting for web applications and APIs, aimed at continuous validation and audit-ready reporting Seed, €3.5 million total financing announced in May 2026, including €2.8 million equity and a €700,000 Bpifrance innovation loan Pitches reproducible proofs of concept, audit-ready reports, and hosting on Scaleway in Paris [Fleuret AI, May 2026] [Fleuret AI, Unknown]
GitGuardian Security company named by Fleuret among operators associated with its investor group Not established in the available public inputs Acts here less as a direct product analogue than as a signal that Fleuret is adjacent to developer-security and AppSec buying centers [Fleuret AI, May 2026]
Stoïk Cyber insurer named by Fleuret among operators associated with its investor group Not established in the available public inputs Relevant as a potential channel or adjacent buyer influence, especially if automated validation becomes part of underwriting or risk review [Fleuret AI, May 2026]
Patrowl Named competitor in the structured research set Not established in the available public inputs Included in public research as a pentesting or offensive-security comparison point [LinkedIn]
Escape Named competitor in the structured research set Not established in the available public inputs Included in public research as an application-security comparison point [LinkedIn]
Pentera Named competitor in the structured research set Not established in the available public inputs Included in public research as an automated offensive-security comparison point [LinkedIn]

The competitive map breaks into three lanes. The first lane is classic pentest firms and consultants, which Fleuret is plainly trying to undercut on speed and price, with homepage claims of a €4,000 pentest versus €15,000 to €30,000 for a firm [Fleuret AI, Unknown]. The second lane is application-security and exposure-management software, where named companies such as GitGuardian and Escape sit closer to developer workflow and continuous monitoring than to human-led offensive testing [Fleuret AI, May 2026]. The third lane is adjacent risk infrastructure, including insurers such as Stoïk, where the product itself may matter less than whether Fleuret can become a compliance or underwriting input rather than a stand-alone tool [Fleuret AI, May 2026].

Its edge today appears to be product packaging more than entrenched distribution. The company is not claiming a broad security platform. It is claiming that an autonomous framework called Emile can simulate real attacks on web apps and APIs, confirm exploitability through controlled challenges, and produce outputs mapped to DORA Article 24 and NIS2 Annex I, with findings hosted in Paris on Scaleway [Fleuret AI, Unknown] [LinkedIn, 2026]. That is a credible wedge for regulated European buyers if procurement is being shaped by data-sovereignty and auditability requirements, but it is still a perishable edge because the public record does not yet show named enterprise customers, signed channel partners, or a scale advantage in data that would be difficult for better-capitalized AppSec vendors to reproduce [Fleuret AI, May 2026].

The main exposure is that Fleuret is trying to occupy a middle ground that stronger neighbors could compress. Pentera, on the offensive-automation side, is the clearest named threat if buyers want an established attack-simulation category leader rather than a new compliance-forward entrant [LinkedIn]. GitGuardian and other developer-security vendors are a different kind of threat, because they already live closer to code, secrets, and remediation workflows, which can make the pentest artifact only one module in a larger budget line rather than the buying center itself [Fleuret AI, May 2026]. Stoïk is not a direct product competitor, but it illustrates a channel Fleuret does not own: if cyber insurers or brokers become the gatekeepers for continuous validation spend, the insurer relationship may matter as much as detection quality [Fleuret AI, May 2026].

Over the next 18 months, the most plausible scenario is not winner-take-all but budget sorting by use case. Fleuret has a path to win in regulated mid-market and upper-SMB European accounts if compliance evidence, sovereign hosting, and lower-cost repeat testing matter more than a broad AppSec suite. In that case, Stoïk looks like the winner if insurer-led distribution becomes real and automated pentesting starts to support underwriting or renewal workflows, because the channel would gain pricing power over tool selection [Fleuret AI, May 2026]. The loser if that does not happen could be a stand-alone challenger such as Patrowl, assuming buyers consolidate toward either full-platform AppSec vendors or insurer-influenced point solutions rather than maintaining multiple narrow offensive-testing products. That remains a conditional view, because the public evidence on customer adoption across these named vendors is thin in the materials reviewed.

Reasoned from indirect evidence -- This section combines company-published positioning and financing details with a limited set of publicly named competitors in the research inputs. Several competitor rows are name-level only, without independently verified stage, funding, or product detail in the available sources.

Opportunity

PUBLIC The prize here is not a better pentest shop, it is a credible chance to become the European control layer for continuous application-security validation if automated offensive testing shifts from an annual purchase to an always-on compliance workflow [Fleuret AI, May 2026] [Fleuret AI].

The largest plausible outcome is that Fleuret becomes the default pentesting platform for regulated European software and financial infrastructure teams that need evidence, not just findings, for DORA, NIS2, and adjacent audit processes [Fleuret AI] [Fleuret AI, May 2026]. That is reachable, not merely rhetorical, because the company is already framing the product around concrete buying frictions: conventional pentests are positioned as slower and materially more expensive, while Fleuret claims audit-ready output, reproducible proofs of concept, and hosting on Paris-based infrastructure through Scaleway, all of which align with a European buyer set that is sensitive to both compliance burden and data-residency posture [Fleuret AI] [Fleuret AI, May 2026]. The financing also matters at this stage. Fleuret said in May 2026 that it raised €3.5 million total, including €2.8 million in equity led by RAISE Capital and a €700,000 Bpifrance innovation loan, with hiring plans aimed at engineering and early go-to-market buildout, which is the minimum resourcing needed to test whether this can become a repeatable software motion rather than a services overlay [Fleuret AI, May 2026] [Bpifrance.com, 2026].

The upside paths are still narrow, but they are legible from the public record.

Scenario What happens Catalyst Why it's plausible
Compliance system of record Fleuret becomes the recurring platform security teams use to generate pentest evidence for web apps and APIs across quarterly or weekly review cycles, rather than a one-off external engagement Regulated buyers standardize on continuous evidence collection for DORA, NIS2, and ISO 27001 workflows, and Fleuret's reporting surfaces such as signed PDFs, Jira flows, and board exports reduce audit friction [Fleuret AI] Public product materials already center on audit-ready reports, reproducible proofs of concept, and direct mapping to DORA Article 24 and NIS2 Annex I, indicating the company is designing around compliance operations rather than only vulnerability discovery [Fleuret AI]
Embedded channel through insurers and specialist firms Fleuret sells through cyber insurers and cybersecurity specialists that need scalable validation for portfolio companies or clients One or more channel partners formalize Fleuret into their underwriting, assessment, or remediation process [Fleuret AI, May 2026] Fleuret's financing announcement explicitly says it plans distribution through cyber insurers and specialized cybersecurity firms, which is a credible wedge because those intermediaries already aggregate demand and care about standardized evidence [Fleuret AI, May 2026]
European sovereign-security winner Fleuret becomes a preferred option for buyers that want offensive testing automation without relying on US cloud posture or black-box model infrastructure Increased procurement preference for European hosting and sovereign AI deployment in regulated sectors The company is already emphasizing that findings are hosted on Scaleway in Paris and that Emile is built on open-source models hosted on sovereign French cloud, which gives it a positioning angle that many broader security platforms do not lead with publicly [Fleuret AI] [Gabriel MONTEILLARD - Fleuret AI

Those scenarios get more attractive if the product compounds with use. Fleuret's public materials suggest the beginnings of a software flywheel: if buyers run pentests more frequently because the cost falls toward the company's advertised €4,000 level versus €15,000 to €30,000 for a traditional firm, they generate more historical exploit evidence, more retest cycles, and more embedded workflow touches inside engineering and compliance teams [Fleuret AI]. That can matter because a platform that sits in Jira, produces signed audit outputs, and runs on a weekly cadence is harder to remove than a consultant who appears once a year [Fleuret AI]. The more conservative read is that this is not a classic network effect. It is a workflow and evidence moat, where retention improves if historical findings, remediation trails, and compliance artifacts accumulate inside one system. The public hiring plan, from five people toward roughly twelve by year-end 2026, also suggests management sees product depth and distribution buildout as the next compounding step rather than immediate geographic expansion [Fleuret AI, May 2026].

The size of the win is easiest to frame through category economics rather than a direct public comparable, because the source set here does not establish a clean listed peer with the same product scope. Fleuret announced €3.5 million of total financing in May 2026 and is still at the team-building stage, so any value framing has to be conditional [Fleuret AI, May 2026]. If the "compliance system of record" scenario plays out and Fleuret proves that automated pentesting can become a recurring control for regulated application-security programs across Europe, the strategic value could resemble an infrastructure security asset rather than a boutique testing vendor. That could support a venture-scale outcome in the hundreds of millions of euros in enterprise value (scenario, not a forecast), particularly if channel distribution through insurers or specialist firms converts customer acquisition from direct-sale only to portfolio-level rollout [Fleuret AI, May 2026]. The key reason that range is worth entertaining at all is simple: Fleuret is trying to convert pentesting from episodic spend into repeat software spend, and categories that successfully make that transition usually create more durable revenue and stronger exit math than services-led security niches.

Claim stands unchecked -- This section relies heavily on company-published materials for product scope, pricing, compliance positioning, and go-to-market plans, with limited independent corroboration from Bpifrance and LinkedIn-profile evidence.

Sources

Open sources

  1. [Fleuret AI, May 2026] Fleuret raises €3.5M to industrialize agentic AI pentesting. | https://fleuret.ai/news/fleuret-raises-3-5m

  2. [VivaTech, June 2026] Yanis Grigy - Speakers. | https://vivatech.com/speakers/e89295ba-1261-f111-8fcb-6045bd954326

  3. [LinkedIn, 2026] Yanis Grigy posted on LinkedIn | https://www.linkedin.com/posts/yanis-grigy-793635237_apprentissage-aide-activity-7068182986168397824--EXl

  4. [LinkedIn, 2026] Yanis Grigy on LinkedIn: #télécomparis #étudiant #réussite #détermination #persévérance… | https://www.linkedin.com/posts/yanis-grigy-793635237_t%C3%A9l%C3%A9comparis-%C3%A9tudiant-r%C3%A9ussite-activity-7090366722926342146-4FkK

  5. [LinkedIn, 2026] Yanis Grigy - Paris, Île-de-France, France | Professional Profile | LinkedIn | https://www.linkedin.com/in/yanis-grigy-793635237/

  6. [LinkedIn, 2026] Augustin Ponsin - Co-Founder & CPO @ Fleuret AI | X HEC | https://fr.linkedin.com/in/augustinponsin

Articles about Fleuret AI

View on Startuply.vc