
Fleuret AI raises €4 million to develop continuous agentic penetration testing
The AMW Read
The pre-seed round adds an early entrant to enterprise security operations AI, with a specific exploit-to-remediation workflow but no reported traction or measured outcomes demonstrating broader impact.
Fleuret AI raises €4 million to develop continuous agentic penetration testing
French cybersecurity startup Fleuret AI has raised €4 million in pre-seed funding led by RAISE Ventures, with participation from Auriga Cyber Ventures, Wind, Better Angle and cybersecurity business angels. Founded by CEO Yanis Grigy and CTO Augustin Ponsin, the company is developing an agentic platform spanning attack-surface mapping, vulnerability discovery, exploitation, remediation support and verification. The funding will support hiring across AI, software development and offensive cybersecurity, alongside platform development.
The market opportunity sits in enterprise security operations: replacing a periodic assessment with testing that responds to changes in applications, APIs and infrastructure. Fleuret AI's agents, Emile and Champollion, attempt to exploit vulnerabilities and attach proof of compromise, connecting discovery to demonstrated exploitability. That makes the proposed value more specific than generating additional security alerts: helping teams prioritize issues and verify fixes. The company says its agents operate from Europe on European infrastructure to address sovereignty requirements, particularly for regulated customers; the article does not establish regulatory compliance.
For builders and investors, the concrete evaluation point is whether this workflow can reliably carry a finding through remediation and successful retesting. Fleuret AI is developing prioritization, integrations with technical teams' tools, automatic retesting and resolution reports. Those capabilities would make the product part of ongoing security operations rather than a standalone audit. The reported funding supports that ambition, but the article provides no customer counts, revenue figures or measured testing outcomes to establish commercial traction or effectiveness.