Fleuret AI, a French cybersecurity startup, has secured €4 million in pre-seed funding to build a platform that automates penetration testing through agentic AI, a move that could reshape how companies defend their digital infrastructure.
The investment arrives when traditional security audits increasingly fail to match the pace of modern software development. Companies deploy code and infrastructure changes daily, yet penetration tests remain periodic snapshots that quickly become outdated. A system assessed as secure on Monday might expose new vulnerabilities by Friday.
RAISE Ventures led the round. Auriga Cyber Ventures, Wind, Better Angle, and several cybersecurity-focused angel investors also participated.
Founded by CEO Yanis Grigy and CTO Augustin Ponsin, Fleuret AI wants to transform pentesting from a one-time examination into an always-on security process. The platform focuses on five core capabilities: mapping exposed systems, pinpointing vulnerabilities, proving they can be exploited, supporting remediation, and verifying fixes actually work.
The company built two AI agents, Emile and Champollion, to handle much of what human penetration testers do manually. These agents explore applications, APIs, and infrastructure across a company’s environment. When they identify a vulnerability, they attempt to exploit it and attach proof of compromise, demonstrating real risk rather than theoretical weakness.
Meanwhile, the platform keeps watching the attack surface after the initial assessment. As systems change, it triggers new tests automatically. Fleuret AI also prioritizes vulnerabilities based on actual exploitability, integrates with tools development teams already use, and generates reports confirming whether repairs succeeded.
Grigy frames the ambition broadly. Rather than merely automating existing pentest workflows, the company intends to create an offensive cybersecurity layer that keeps companies protected year-round, regardless of size.
The startup targets the European market specifically. Its AI agents operate on European infrastructure, a design choice meant to satisfy sovereignty requirements in heavily regulated sectors. As a result, organizations that lack resources for regular penetration testing could gain access to continuous security coverage.
The new capital will fund hiring across AI, software development, and offensive security roles, alongside accelerated platform development.















