Offensive security startup RunSybil Inc. has raised $40 million to advance its AI-native platform that automates black-box penetration testing.
Led by Khosla Ventures, the round included Menlo Ventures, Anthropic’s Anthology Fund, S32, Conviction, and prominent angels such as Elad Gil, Nikesh Arora, Amit Agarwal, and Jeff Dean.
Unlike conventional scanners that rely on source code access or infrequent human-led tests, RunSybil’s autonomous AI agents interact with live systems through standard interfaces. They mimic sophisticated attackers by chaining minor flaws into critical exploits-finding hidden paths to sensitive data that legacy tools overlook.
Traditional bug bounty programs often yield superficial findings, while manual penetration testing is costly and rare-typically conducted only once or twice a year. RunSybil claims its AI reduces false positives by 90% and continuously improves through system interactions.
The platform has already identified critical vulnerabilities for AI firms like Cursor and Notion Labs, plus unnamed Fortune 500 companies-flaws previously missed by both bounty hunters and pen testers.
Co-founder and CEO Ari Herbert-Voss says: “We’re the first to provide comprehensive black-box testing using AI to reason like a security researcher-without ever seeing a line of code.”
Khosla Ventures founder Vinod Khosla called the technology a “fundamental shift” in software protection amid rising complexity and AI-driven development.
RunSybil will use the capital to accelerate R&D, expand its agentic testing capabilities, and scale go-to-market operations.