CodeAnt AI
YC W24Entrepreneur First '24San Francisco, US Β· Founded 2023 Β· 25 employees Β· Hiring Β· 7 known investors
CodeAnt is a code security platform that identifies and prioritizes security vulnerabilities in applications using AI to surface the most critical issues from thousands of findings. The company serves software development teams and enterprises building with both human-written and AI-generated code.
Also known as CodeAnt Β· CodeAnt AI Inc. Β· CodeAnt AI, Inc.
Founders & leadershipΒ· Y Combinator alumni (W24)
CodeAnt AI was founded in 2023 by Amartya Jha and Chinmay Bharti.
Investors Β· 7
Also in the syndicate Β· 3
Funding
SEC filings, press & company announcements$4M disclosed across 2 of 3 rounds Β· 2025
- $2MSeed FundingMay 2025 Β· 3 sourcesSource β
- $2MraisedMay 2025 Β· 3 sourcesSource β
Source: company announcements and press reports β follow each round's link for the claim.
Valuation Β· disclosed
Disclosed eventsSource: SEC prospectus filings, and round valuations the company or its investors disclosed β follow each entry's link for the claim.
Company profile
researched Aug 2026CodeAnt AI operates an agentic security platform that spans both defensive and offensive application security. On the defensive side, the product reviews pull requests line by line with full codebase context, runs a unified AI static analysis pass across source code, infrastructure-as-code, dependencies and secrets, detects cloud misconfigurations across AWS, GCP and Azure, and surfaces issues in the IDE, CLI, PR and CI/CD stages. A Control Center aggregates security and code-health posture across repositories. On the offensive side, the platform maps a customer's public attack surface and runs what the company describes as 500+ exploit agents that chain recon, injection, access-control and business-logic attacks against the running application, plus DAST behind authentication and cloud threat detection.
The stated operating model is to build a single context graph from source, IaC, dependencies, secrets, endpoints, cloud configuration and commit history, derive a threat model of auth boundaries, trust assumptions and data flows, then attack those paths and report only findings that were actually exploited, accompanied by the request, the proving response and reproduction steps. The company frames this as a response to two problems it identifies in the market: SAST and SCA tools producing roughly 10,000 findings of which few matter, and annual human penetration tests leaving organizations without coverage for the rest of the year.
Earlier positioning, as of the 2025 seed announcement, centered on AI code review and code quality: a proprietary, language-agnostic Abstract Syntax Tree engine covering more than 30 languages, integrated with GitHub, GitLab, Bitbucket and Azure DevOps, providing PR summaries, one-click fixes, code-smell/complexity/duplication/dead-code detection, and SAST, SCA, IaC and secret scanning aligned to OWASP and CWE. Prior YC launches also included a developer engineering-metrics product.
Founding story
Amartya Jha and Chinmay Bharti started CodeAnt in June 2023 after experiencing slow and error-prone code review firsthand: Jha previously worked at Zeta and ShareChat, where rushed code changes created operational risk, and Bharti built high-frequency trading systems where a single bug could be costly. The founders describe a formative discovery in which Bharti found a way to forge JWT signatures in a widely shipped library (CVSS 10), a reasoning flaw that pattern-matching scanners had missed for years, motivating a platform that reasons like an attacker rather than matching patterns.
Business model
B2B software sold to engineering and security teams, with self-serve entry (a free pentest requiring no credit card) alongside enterprise sales via demos and scoping calls. The platform is offered as a cloud service and can also be deployed in the customer's own environment / on-premise for security-conscious buyers, with the company stating that customer code does not train models or leave the customer boundary.
Per-developer subscription pricing was reported at the time of the seed round: from $10 per developer per month for basic AI code review up to $40 per developer per month for the full suite including code quality analysis, security monitoring and compliance tooling. For agentic pentesting the company advertises no engagement fee, with payment only if high or critical issues are found and low/medium findings provided free.
Traction
The company reports having run penetration tests for 200+ companies and disclosing 100+ zero-day CVEs affecting packages with 1.85 billion+ monthly downloads, including a CVSS 10.0 authentication bypass in pac4j-jwt (CVE-2026-29000) and a CVSS 9.8 RCE in simple-git (CVE-2026-28292). At the time of the 2025 seed round the company said it scanned over 50 million lines of code, auto-fixed more than 500,000 issues and saved over 100,000 developer hours per day. Team size is listed at 25. Customer quotes come from 11x, Autajon Group and Motorq.
Latest developments
As of 2026 the company has repositioned its homepage around exploit-based agentic security, launched Agentic Pentest (March 2026), disclosed CVE-2026-29000 (pac4j-jwt auth bypass, CVSS 10.0) and CVE-2026-28292 (simple-git RCE, CVSS 9.8), surpassed 100+ disclosed CVEs by May 2026, and cites a Gartner Cool Vendor 2026 recognition in application security along with SOC 2 Type II and HIPAA compliance.
βΈFull profile β market position, technology, go-to-market, geography, history, risks & controversies
Market position
Positions itself as combining offensive and defensive security in one self-learning platform, contrasting with point tools that only scan (SAST/SCA) or with periodic human penetration-testing engagements. Its own site benchmarks the product against SonarQube, Snyk, CodeRabbit and GitHub Copilot, and a prior YC launch compared its engineering-metrics product to LinearB. External validation cited includes a Gartner Cool Vendor 2026 designation in application security and coverage in Forbes, Economic Times, Fintech Global, Cybernews and Analytics India Magazine.
Emphasis on exploit-proof over severity scoring: findings are reported only when an agent reproduced them, with the triggering request, the proving response and reproduction steps, which the company positions against high-volume SAST/SCA output and once-a-year pentest PDFs. Other stated differentiators are the combination of offensive and defensive layers in one system, grey-box re-attack informed by codebase knowledge, a whole-codebase AST engine instead of snippet-level analysis, on-premise deployability, and a commercial model where pentests carry no engagement fee.
Technology
A proprietary language-agnostic Abstract Syntax Tree engine that models an entire codebase rather than isolated snippets underpins the code-analysis layer, supporting more than 30 languages. The security platform builds a unified context graph across source, infrastructure-as-code, dependencies, secrets, endpoints, cloud configuration and commit history, derives a ranked threat model, and executes attacks with a fleet of 500+ autonomous exploit agents covering categories such as BOLA, IDOR, SSRF and auth bypass, fusing black-box and white-box (grey-box) knowledge. Findings are validated by reproduction rather than scored by CVSS alone. The company states code is not used to train models and offers self-hosted deployment.
Go-to-market
Product-led entry through a free, no-credit-card pentest and free low/medium findings, combined with a direct enterprise sales motion (book-a-demo, contact sales, scoping calls) and hiring of founding GTM roles such as a Founding Account Executive and Founding Business Development Representative in San Francisco. Distribution also leans on integration into existing developer tooling (GitHub, GitLab, Bitbucket, Azure DevOps, IDE, CLI, CI/CD) rather than a separate console, plus security-research publicity from disclosed CVEs and press coverage.
Software engineering and application security teams, ranging from startups to Fortune 100 enterprises, including regulated sectors such as healthcare, finance and defense where SOC 2, HIPAA and on-premise deployment matter. Named references include 11x, Autajon Group and Motorq.
Geography
Headquartered at 355 Bryant St, San Francisco, CA 94107, incorporated as CodeAnt AI, Inc., with an additional office in Bengaluru, India reported at the time of the seed round. Hiring for founding GTM roles is based in San Francisco.
History
Founded June 2023 by Amartya Jha (Co-founder and CEO) and Chinmay Bharti (Co-founder and CTO, IIT Bombay electrical engineering, previously in high-frequency trading). The company joined Y Combinator's Winter 2024 batch in February 2024 with Tom Blomfield as primary partner, and raised a $2M seed round in May 2025 at a reported $20M valuation. Its own timeline then lists a $60M valuation in January 2026, disclosure of a CVSS 10.0 authentication bypass in February 2026, the launch of Agentic Pentest in March 2026, and 100+ CVEs disclosed by May 2026. Product scope evolved from AI code review and developer engineering metrics toward a combined offensive/defensive agentic security platform.
Risks & controversies
Several headline claims β 200+ companies pentested, 100+ CVEs, the $60M valuation, daily scanning and hours-saved figures, and the Gartner Cool Vendor designation β originate from the company's own website, YC profile or funding-announcement coverage rather than independent verification. Disclosed funding is small ($2M seed) relative to a competitive application-security market that includes Snyk, SonarQube and CodeRabbit. The company's positioning also depends on the accuracy and safety of autonomous agents actively attacking customers' live production systems.
Compiled by commissioned research from 8 cited public sources β announcements, filings, and press listed under research sources below.
Key figures
latest reportedCompany-reported or press-reported figures, each dated to when it was claimed β not independently audited.
Competitors Β· 10
by search overlapCompanies competing with CodeAnt AI for the same Google search keywords, organic and paid, via search-intersection analysis.
Timeline Β· 8
launches, deals, and filingsCompany timeline records passing 100+ disclosed CVEs; YC profile states the disclosures affect packages with 1.85B+ monthly downloads.
CodeAnt AI launched its agentic penetration testing product, using 500+ exploit agents that chain attacks against a live attack surface and reproduce findings with request/response evidence.
CodeAnt AI disclosed a critical authentication bypass in pac4j-jwt (CVE-2026-29000, CVSS 10.0) that allowed impersonation using only a public key and had gone undetected for six years. YC's news feed dates the disclosure item to 2026-03-05.
CodeAnt AI states it was recognized as a Gartner Cool Vendor in application security for autonomous, verified testing.
The company's about-page timeline lists a $60M valuation in January 2026; no round details are given.
The website presents a combined offensive layer (agentic pentesting, attack surface management, DAST, cloud threat detection) and defensive layer (AI SAST, SCA/SBOM, secrets, IaC, CSPM) delivered in the PR and CI/CD workflow.
CodeAnt AI raised $2 million in seed funding led by Y Combinator, VitalStage Ventures and Uncorrelated Ventures, with participation from DeVC, Transpose Platform, Entrepreneur First and angel investors. Unite.AI reports the round valued the company at $20 million. Funds were earmarked for product development, engineering capacity and customer growth.
$2M source β
CodeAnt AI participated in Y Combinator's W24 batch; YC lists Tom Blomfield as primary partner.
Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.
In the news
βΈResearch sources Β· 8
primary sources listed
- CodeAnt AIcodeant.ai Β· web
8 public sources were cited for this profile; the first-party ones are listed here.
Frequently asked questions
- What does CodeAnt AI do?
- CodeAnt AI is a YC-backed agentic application security platform pairing AI code review with autonomous exploit-based pentesting.
- Who founded CodeAnt AI?
- CodeAnt AI was founded by Amartya Jha, Chinmay Bharti in 2023.
- Who are CodeAnt AI's investors?
- CodeAnt AI's investors include Entrepreneur First, Strategxy Ventures LLC, Transpose Platform Management, Y Combinator.
- How much funding has CodeAnt AI raised?
- CodeAnt AI has disclosed $4M raised across 2 of its 3 known rounds.
- Where is CodeAnt AI headquartered?
- CodeAnt AI is headquartered in San Francisco, US.






