SoatDev IT Consulting
SoatDev IT Consulting
  • About us
  • Expertise
  • Services
  • How it works
  • Contact Us
  • News
  • June 6, 2023
  • Rss Fetcher

French startup Escape has raised a $3.9 million (€3.6 million) funding round shortly after ending Y Combinator’s winter 2023 cohort. The company provides a cybersecurity product focused on securing APIs before they are rolled out publicly.

French VC firm Iris is leading the round with Frst also participating. Existing investors Irregular Expressions, Tiny Supercomputers and Kima Ventures are participating in the round. Some of the company’s angel investors include Philippe Langlois, Mehdi Medjaoui and Roxanne Varza.

“We decided to create a custom algorithm powered by artificial intelligence that can simulate cyber attacks. Once it has found security flaws, it will give you remediations,” co-founder and CEO Tristan Kalos told me. He founded the startup with Antoine Carossio and there are now 10 people working for Escape.

In more technical terms, Escape is an agentless solution as it integrates directly in your development pipeline. Every time the dev team commits some new lines of code in the code repository, it will trigger Escape using an integration in the continuous integration/continuous delivery flow (CI/CD).

For instance, Escape can identify an issue with rate limiting. That means that a bad actor could leverage this flaw to extract large volumes of data. Escape can also see if invalid actions are properly blocked to prevent data manipulation. It integrates with Snyk so that Escape issues appear in your Snyk’s code issues.

“These are dynamic tests. We don’t test the source code itself, but rather the application as it runs. What’s complicated with an API is the business logic — how to interact and how to attack the API. We use reinforcement learning, a mix of deep learning and heuristics,” Kalos said.

Escape first decided to focus on GraphQL APIs as the startup identified that it would be the best go-to-market strategy. But the company is currently rolling out support for REST APIs, which are more widespread than GraphQL-based APIs.

The company has already convinced around 20 clients, such as Sorare, Shine and Neo4J. As you can see, Escape wants to focus on bigger clients working in sensitive industries, including banks and financial services companies. Each contract could potentially be worth tens of thousands of euros per year.

Before using Escape, making sure that your company’s APIs are secured was mostly a manual process. Every now and then, big companies work with security analysts to conduct a penetration test (or pentest, for short).

“Once or twice a year, they come in, look at everything that’s going on and hand you a security report. Companies review the findings internally and list the issues: we’ve got to resolve this, we’ve got to resolve that,” Kalos told me.

But then, companies have to find the developers who are in charge of this specific part of the product or that API in particular. In other words, it’s a reactive and imperfect process.

Escape doesn’t want to replace pentests altogether. Pentests don’t just focus on APIs either, they are much larger than that. Escape just wants to surface security flaws at the API level so that they are fixed when they first appear. This way, most issues are already fixed when a security firm conducts a pentest. It’s a more proactive and dynamic security model, and that could be a nice selling point.

Escape dynamically scans APIs to find security flaws by Romain Dillet originally published on TechCrunch

Previous Post
Next Post

Recent Posts

  • After Shopify bought his last startup, Birk Jernström wants to help developers build one-person unicorns
  • Smarter teams, brighter insights: Stack Overflow for Teams Business summer bundle
  • Senate passes GENIUS stablecoin bill in a win for the crypto industry
  • Police shut down Cluely’s party, the ‘cheat at everything’ startup
  • Sam Altman says Meta tried and failed to poach OpenAI’s talent with $100M offers

Categories

  • Industry News
  • Programming
  • RSS Fetched Articles
  • Uncategorized

Archives

  • June 2025
  • May 2025
  • April 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023

Tap into the power of Microservices, MVC Architecture, Cloud, Containers, UML, and Scrum methodologies to bolster your project planning, execution, and application development processes.

Solutions

  • IT Consultation
  • Agile Transformation
  • Software Development
  • DevOps & CI/CD

Regions Covered

  • Montreal
  • New York
  • Paris
  • Mauritius
  • Abidjan
  • Dakar

Subscribe to Newsletter

Join our monthly newsletter subscribers to get the latest news and insights.

© Copyright 2023. All Rights Reserved by Soatdev IT Consulting Inc.