TL;DR · 30-second read
The Short Version
A young cybersecurity company called FAZE Security came out of hiding on September 11 after building its product quietly. Its software turns loose automated attackers on a customer’s own websites and cloud systems, around the clock, to find weak spots before criminals do.
It then breaks in to prove the weak spot is real, hands the problem to a named person, and keeps checking until the fix holds.
FAZE says 50 large companies already pay for it, and investors have put in six million dollars. Most companies still get one security check a year.
FAZE Security emerged from stealth on September 11, 2026 with $6 million in seed funding led by New Era Capital Partners, with participation from Lockstep VC. In an announcement distributed by PR Newswire, the company said it has 50 enterprise customers, several of them Fortune 500 firms, and roughly 20 times growth in annual recurring revenue over 18 months.
The company operates from New York and Tel Aviv and was previously known as CYTRIX. It sells what it calls an Offensive Security Orchestration platform, built around an Agentic Red Team of autonomous software agents that continuously attack a customer’s web applications, application programming interfaces and cloud environments under defined guardrails.
Executive Summary
The announcement is a seed-stage milestone with an unusual shape. Most companies raise a seed round to go find customers. FAZE says it arrived at its public debut with 50 enterprise accounts already signed, which suggests the product was sold quietly for some time before the branding caught up with it.
The product thesis targets a genuine and worsening operational problem. Automated scanners produce large volumes of findings ranked by theoretical severity, while annual penetration tests, in which human testers attempt to break in, produce a snapshot that ages from the moment it is written. Neither output tells a security team which of the thousands of open items an attacker could actually use today. FAZE’s pitch is that an agent that successfully exploits a weakness has answered that question by demonstration rather than by scoring.
What the release establishes is commercial traction and investor conviction. What it does not establish is performance. The headline efficacy figures, close to zero false positives and more than 50 percent faster mean time to remediate, are presented as customer reports without a baseline, a sample size or a measurement method. Buyers evaluating the category should treat them as claims to be tested in a proof of concept, not as findings.
The Backlog Is the Market
Enterprise security teams have not been short of vulnerability data for a decade. They have been short of a defensible way to decide what to fix first. A scanner crawls an environment and flags known weaknesses against a database, then scores them on a standard severity scale. That scale describes how bad a flaw would be in the abstract. It says nothing about whether the flaw is reachable in your particular architecture, whether a control in front of it already neutralises the risk, or whether exploiting it would reach anything of value.
The result is a queue that grows faster than engineering capacity retires it. Remediation work competes with feature work for the same developer hours, and a ticket labelled critical by a scanner carries no evidence to win that argument. Annual penetration testing, often driven by compliance obligations rather than by risk, does produce evidence, but only for the systems in scope on the week the testers were engaged. Between reports, the estate changes continuously and the report does not.
FAZE is selling into the gap between those two instruments: the continuous coverage of a scanner combined with the demonstrated, working proof of a human test. That is a coherent product thesis and it is why several categories have converged on the same territory.
Proof of Exploit Is the Product, Not the Attack
The most substantive part of the company’s description is not the attacking. It is the loop that follows. FAZE says every finding arrives with working proof, an assigned owner and a remediation path, and that the system automatically re-tests until the exploit fails. That closes the accountability gap where most vulnerability programmes actually break down, which is between the moment a finding is raised and the moment someone can prove it is gone.
It is worth being precise about what this does and does not do. The platform as described does not remediate anything. It ranks by demonstrated business impact, routes work to a named owner and verifies the fix. The fixing remains human engineering work. For buyers, that distinction matters when modelling return on investment, because the savings come from triage effort avoided and from faster closure, not from headcount replaced.
The competitive moat the investor quote emphasises is the training data, described as proprietary attack material from thousands of white-hat hackers. That is a plausible advantage in a domain where public exploit corpora are thin and adversarial technique is tacit. It is also the hardest claim in the announcement for an outside party to evaluate, since neither the volume, the recency nor the coverage of that corpus is described.
A Crowded Lane With No Agreed Scoreboard
Autonomous offensive testing is not an empty field. Penetration testing delivered as a subscription service, breach and attack simulation, external attack surface management and continuous automated red teaming all approach the same buyer with overlapping promises, and the large vulnerability management incumbents have every incentive to add agentic testing to platforms already installed. A startup with $6 million has to win on depth of proof rather than breadth of platform.
The category’s structural weakness is that nobody can compare vendors on results. There is no accepted benchmark for offensive testing accuracy, no standard definition of a false positive when the finding comes with a working exploit, and no neutral body publishing comparative detection rates. That vacuum is what makes self-reported efficacy numbers so common across the sector, and it is why a serious evaluation still comes down to running two tools against the same environment and counting what each one finds and misses.
There is also an operational question specific to autonomous exploitation. Agents that genuinely exploit weaknesses in live web applications, interfaces and cloud accounts are performing actions that, without authorisation and controls, would be indistinguishable from an attack. FAZE says the agents operate within strict guardrails. The design of those guardrails, and the blast radius when one fails, is the thing a chief information security officer will ask about before the accuracy numbers.
What a $6 Million Seed Signals
Read as a market indicator, this round says less about FAZE than about where security capital is going. Investors are funding the layer that decides what to do with vulnerability data, not the layer that produces more of it. Detection has been commoditised; prioritisation backed by evidence has not.
The growth figure deserves a careful reading. Twenty times annual recurring revenue growth over 18 months is striking as a multiple and uninformative as a quantity, because the starting base is not disclosed. A company moving from a small pilot base to a modest one produces that ratio easily. The 50 enterprise customers, including Fortune 500 accounts, are the harder number to manufacture, since large-enterprise security procurement involves vendor risk review and security questionnaires that most 18-month-old companies fail. That FAZE cleared those reviews at Fortune 500 accounts is the most load-bearing fact in the announcement.
For buyers, the practical implication is timing. A seed-stage vendor at this size is early enough to negotiate favourable terms and early enough to carry real continuity risk. For competitors, the signal is that evidence-led prioritisation is being funded as a standalone category rather than a feature, and that the window to absorb it into existing platforms is narrowing.
Background
Enterprise vulnerability management has been built on two instruments for most of its history. Automated scanners, commercial since the late 1990s, compare systems against databases of publicly catalogued flaws and rank results on standardised severity scores. Penetration testing, in which authorised specialists attempt to break in, supplies evidence rather than inference but is periodic by nature, frequently scheduled annually because regulatory and contractual frameworks require it at that cadence. As enterprise estates moved to cloud platforms and continuous deployment, the interval between tests became the weak point: infrastructure now changes faster than the assessment cycle that is meant to describe it.
FAZE Security, previously CYTRIX, is one of a number of companies applying autonomous agents to that interval, positioning itself in what it calls Offensive Security Orchestration. Israel has long been a concentrated source of offensive security engineering talent, and New York and Tel Aviv dual headquarters are a familiar structure for firms selling into United States enterprise security budgets. The company says it spent its stealth period building customer traction before making its public debut on September 11, 2026. Source: FAZE Security emerged from stealth today with 50 enterprise customers, including several Fortune 500 companies, and ~20X ARR growth in 18 months. The company also announced $6M in seed funding led by New Era Capital Partners with participation from Lockstep VC, the company’s announcement of its public debut, funding round and reported customer traction, dated September 11, 2026.Sources

