A security scanner can be excellent at finding a door and quite poor at understanding who is allowed through it. Consider a service that gives every customer an invoice URL. The page loads; the endpoint replies; the conventional scan is satisfied. Yet if Customer A can change an identifier and read Customer B's invoice, the interesting fact is not the URL. It is the broken relationship between identity and data. Escape has built its business around testing that relationship.
- Escape discovers exposed applications and APIs, tests their behavior, and helps route proven flaws to engineers.
- Its original specialty was GraphQL. Its current platform spans attack-surface management, DAST and AI pentesting.
- The strongest customer evidence concerns coverage, fewer noisy findings and faster paths from detection to a fix.
The company began in 2020, when Tristan Kalos and Antoine Carossio founded Escape around a stubborn problem: GraphQL was becoming common in modern products, while much of the security tooling treated it as an oddly shaped version of a traditional web page. Kalos had worked as a GraphQL developer; Carossio brought security engineering experience, including work at Apple and for the French government. Their first answer was deliberately specific. Make it easier to find weaknesses in GraphQL APIs, then make common protections easier to install.

A free tool with a serious job
GraphQL Armor, released in 2022, is the revealing early product. It is open-source middleware for GraphQL servers, with controls intended to blunt expensive queries and other avoidable mistakes. A developer can install it into Apollo Server or GraphQL Yoga. The tool did something commercially useful for Escape as well: it put the company in the hands of the very engineers it hoped to serve. Escape joined the GraphQL Foundation that year and entered Y Combinator's Winter 2023 cohort.
The limits of a neat niche soon became visible. A company's customer data rarely sits behind just one kind of API. A modern application can scatter access rules across a GraphQL gateway, a REST service, a single-page interface and a third-party identity provider. A scanner that knows GraphQL syntax but misses the whole route through the business may still miss the bug. Escape expanded accordingly. By 2023, it described a platform combining attack-surface monitoring with dynamic application security testing, and raised a $3.9 million seed round led by IRIS.

“It was a sink that I was not even watching for months.”Varun Singh, Sigma Computing, describing an earlier scanner
The weekly scan nobody watched
Sigma Computing offers a useful view of what failed first. Its application relies heavily on GraphQL. The security team had a scanner running weekly, but the same few false positives kept returning. Varun Singh, a security engineer there, described the scan as background noise. Sigma wanted real GraphQL support, including internal endpoints, and results it could verify without a second investigation. Four or five vendors were considered, according to Escape's published case study. GraphQL-native coverage was the filter that removed most of them.
With Escape, Sigma moved to focused CI/CD scans against new schema mutations. One year into the deployment, the team said it had full confidence in endpoint coverage and could test as the code changed instead of waiting for the weekly ritual. That is a sharper claim than “AI finds bugs”: the work moved closer to the moment a new behavior appeared. It also describes a condition for copying the approach. The team needed a known schema, a release process it could hook into, and someone prepared to tune what a useful finding looks like.
Thinkific, the education platform, had a related concern when it opened federated GraphQL APIs to the public. It needed to test access control across Apollo subgraphs and see what the newly exposed system was revealing. Escape says Thinkific reduced its GraphQL API security risk by 54 percent in the first weeks of use. The figure is a customer case-study result, not a universal forecast. What generalizes is the sequence: choose the boundary that matters, test it in the actual architecture, and make the result legible to the team that owns the code.

The product is a loop
Escape now sells three connected products. Attack Surface Management finds APIs, single-page applications and other exposed assets without an installed agent, including the neglected “shadow” endpoints that arrive when teams ship faster than inventories are updated. Business-logic-aware DAST tests running applications, with attention to authentication, access control and the multi-step actions that make a real business transaction. Cascade, introduced in 2026, is the AI pentesting layer: multiple agents explore an application, attempt attack chains and attach proof to findings. Escape says validated findings can become regression tests run in later builds.
Map applications, APIs and owners, including assets missing from the inventory.
Test roles and business flows. Keep the request path that demonstrates a real flaw.
Route the finding to its owner, repair it, and rerun the check as code changes.
The point is continuity: a proved bug should teach the next scan something.
The difference from a conventional scanner is a matter of context. A payload-only test asks whether a field reacts to a suspicious string. Escape also asks whether a doctor can see another doctor's patient, whether one tenant can enumerate another tenant's records, or whether a payment flow obeys its own pricing rule. Such tests demand authenticated sessions, multiple roles and enough application knowledge to follow a transaction. They are more useful when those pieces exist, and less persuasive when the environment cannot provide them. Even Escape's technical writing acknowledges that automated agents can miss unusual chains or stumble on custom authentication; live validation and human judgment still have work to do.
An inventory is only useful if it has an owner
DoubleVerify shows the other half of the problem. The ad-tech company has APIs spread across different environments and systems, some outside an API gateway. Its application security team wanted a fuller inventory without adding latency to those services. It connected Wiz's cloud view with Escape's application testing: Wiz supplied discovered resources and ownership context; Escape classified and scanned the applications; findings flowed back. DoubleVerify described a daily cycle for that exchange. This is less theatrical than an AI agent breaking into an app, but it solves a common organizational failure: a good finding can sit untouched if nobody knows whose service it is.
Escape's commercial model follows that organizational buyer. It sells software to security and engineering teams through demos and enterprise engagements while keeping GraphQL Armor freely available. It competes with web and API scanners, API security platforms, external asset inventories, manual pentest firms and newer automated pentesting vendors. Its argument is that these jobs belong in one workflow. A customer with a small, simple app may need only a focused scanner or a careful manual review. A company with many teams, fast releases and uncertain ownership has more reason to pay for the whole loop.
The company made that ambition explicit in March 2026, announcing an $18 million Series A led by Balderton Capital and a broader identity as an offensive security engineering platform. It said the money would deepen AI agent work and expand its US and European teams. Later that summer, Cascade gained a source-aware mode for selected customers, allowing it to use a codebase as a map before proving findings against a live application. Escape also joined verified cyber-access programs run by OpenAI and Anthropic for authorized security work.
What stays after the report
A useful lesson from Escape is modest enough to copy without buying the product. List the assets that actually exist. Give each an owner. Identify the roles and transactions whose boundaries matter most. When a tester proves a flaw, preserve the exact request sequence and turn it into a recurring check. Then run that check when the behavior changes, not merely when the calendar says it is time for another report.
That is the plot Escape is trying to follow. The protagonist is not the scanner. It is the relationship among a user, an action and the data the application promised to protect. A machine that can read that relationship will be valuable. A security team that can explain it to the right engineer will be more valuable still.