
Veria Labs, a Y Combinator-backed security startup, has closed a $3.2 million seed round to scale its autonomous offensive security testing platform. The funding was led by Y Combinator, with participation from Paul Graham, Gokul Rajaram, and Auth0 co-founder Matias Woloski, alongside MA 7 Ventures, Seaplane Ventures, Amino Capital, and several other investors.
The company spun out from what it describes as the top-ranked hacking team in the United States. The founding team spent years conducting penetration tests for billion-dollar companies, including discovering a vulnerability that could have enabled attackers to steal over $1 billion if left unpatched.
Every company serious about security eventually hires a penetration testing team. The best firms command premium rates, stay booked months in advance, and when they finally arrive, they typically get two weeks to assess an entire application.
No matter how skilled the team, two weeks isn't enough time. Pentesters must make difficult decisions about where to focus. They can only cover so much ground. Something always gets missed.
Meanwhile, the codebase keeps evolving. New features ship weekly. New attack surface appears constantly. That pentest report from three months ago becomes outdated almost immediately. This creates a fundamental problem: companies pay significant money for a snapshot of their security posture that starts degrading the moment it's delivered.
Veria Labs built software that uses artificial intelligence to run offensive security testing continuously, not just during short engagement windows. The platform does more than surface potential issues from static analysis. It explores applications, tests whether vulnerabilities are actually exploitable, and connects related weaknesses into complete attack paths.
During one engagement, Veria's AI autonomously found six different methods to take over any user's account on a popular web application. After identifying these flaws, it suggested fixes for every single one. This wasn't a controlled demonstration. This was a production application with a dedicated security team behind it.
So far, the AI has discovered high-severity vulnerabilities in every company the startup has worked with.
The Veria team automated the repeatable parts of the workflow they used in manual engagements. The platform maps attack surface, identifies areas worth investigating, formulates hypotheses about potential weaknesses, and tests them systematically.
When it finds something, it doesn't just flag the issue. It attempts to escalate privileges, chain findings together, and demonstrate real impact.
The key advantage is continuous operation with the ability to test many hypotheses simultaneously. It covers the breadth that human pentesters often must skip due to time constraints and goes deep where it matters most. When vulnerabilities are discovered, the platform provides detailed reproduction steps and recommended fixes—the same deliverables expected from top-tier pentest firms, generated continuously rather than once per quarter.
Veria is targeting teams at every stage of growth. For startups without dedicated security personnel, the platform provides offensive security testing that would otherwise be financially out of reach. Companies shouldn't need Fortune 500 budgets to know whether their applications are secure.
For larger organizations with mature security programs, Veria works alongside internal teams. Annual penetration tests still serve a purpose, but they leave long gaps in coverage. The platform continuously tests areas those engagements can't fully examine in two weeks and retests as products change.
The company believes security shouldn't depend on whether an organization can afford a six-figure retainer.
Veria Labs was founded by security engineers who previously operated as the highest-ranked hacking team in the United States. The company participated in Y Combinator's Fall 2025 batch and has positioned itself to address what the founders see as a fundamental gap in how companies approach application security.
The founding team brings years of experience breaking into well-engineered products at billion-dollar companies. That hands-on offensive security experience now informs the AI models and testing methodologies built into the platform.
The company operates as a small, highly specialized team and plans to maintain that structure as it scales.
Beyond Y Combinator, Paul Graham, Gokul Rajaram, and Matias Woloski, the seed round included participation from MA 7 Ventures, Seaplane Ventures, Amino Capital, Karman Ventures, Lombard Street Ventures, Liquid 2 Ventures, Schema VC, Hypersphere Ventures, BLAST, Unpopular Ventures, Metsu Capital, Antigravity Capital, Rock Yard Ventures, Eight Capital, BBQ Capital, Kevin Moore, Aarthi Ramamurthy, and the Hyperplane founders (now at Nubank).
The investor group brings expertise across enterprise software, security infrastructure, and startup scaling. Woloski's experience building and scaling Auth0 into a major authentication platform adds particularly relevant domain knowledge to Veria's advisory network.

