Software changes every day. Novee’s wager is that security testing should follow every change, produce a working exploit, and stay long enough to check the repair.
Annual pentests produce a report. NodeZero keeps coming back, proves which weaknesses actually lead somewhere, and checks the repair - a simple loop that helped Horizon3.ai reach 7,000 customers and a $2 billion valuation.
Most companies discover whether their defenses work when someone breaks in. SimSpace built a safer place to find out first - a digital double where teams, tools and AI agents can be attacked on purpose.
Security teams had plenty of alerts and too little proof. Pentera built a machine that attacks safely, shows what is actually exploitable, and turns an annual pentest into a repeatable operating habit.
SCYTHE grew from a one-off tool built with Target into a platform for continuously testing the security stack companies already own. Its sharpest idea is also its least comfortable: a control is only as good as the last realistic attack it caught.
Picus Security is the cybersecurity company behind the Picus Security Validation Platform - an Adversarial Exposure Validation system that continuously simulates real-world attacks against an organization's defenses to expose which ones actually work. Founded in 2013 by three Turkish mathematicians and now headquartered in San Francisco, Picus serves 500+ enterprise customers including Mastercard and is the official Exposure Validation Partner of Juventus.