Fundraising Fox

CodeAnt AI

YC W24Entrepreneur First '24

San Francisco, US Β· Founded 2023 Β· 25 employees Β· Hiring Β· 7 known investors

CodeAnt is a code security platform that identifies and prioritizes security vulnerabilities in applications using AI to surface the most critical issues from thousands of findings. The company serves software development teams and enterprises building with both human-written and AI-generated code.

Also known as CodeAnt Β· CodeAnt AI Inc. Β· CodeAnt AI, Inc.

AI & Machine LearningCybersecurityDeveloper ToolsEnterprise SoftwareUnited States of AmericaAmerica / CanadaPartly Remote

Founders & leadershipΒ· Y Combinator alumni (W24)

CodeAnt AI was founded in 2023 by Amartya Jha and Chinmay Bharti.

AJAmartya Jha
Amartya Jhain𝕏Co-Founder & CEOHe has discovered multiple security vulnerabilities, including CVE-2026-29000 and CVE-2026-28292, across widely-used open source packages.
CBChinmay Bharti
Chinmay Bhartiin𝕏Co-FounderHe previously worked in high-frequency trading and studied electrical engineering at IIT Bombay.

Investors Β· 7

Also in the syndicate Β· 3

angel investorsBrian ShinTranspose Platform

Funding

SEC filings, press & company announcements

$4M disclosed across 2 of 3 rounds Β· 2025

Source: company announcements and press reports β€” follow each round's link for the claim.

Valuation Β· disclosed

Disclosed events
$20Mvaluation at SeedMay 2025
filing β†—

Source: SEC prospectus filings, and round valuations the company or its investors disclosed β€” follow each entry's link for the claim.

Company profile

researched Aug 2026

CodeAnt AI operates an agentic security platform that spans both defensive and offensive application security. On the defensive side, the product reviews pull requests line by line with full codebase context, runs a unified AI static analysis pass across source code, infrastructure-as-code, dependencies and secrets, detects cloud misconfigurations across AWS, GCP and Azure, and surfaces issues in the IDE, CLI, PR and CI/CD stages. A Control Center aggregates security and code-health posture across repositories. On the offensive side, the platform maps a customer's public attack surface and runs what the company describes as 500+ exploit agents that chain recon, injection, access-control and business-logic attacks against the running application, plus DAST behind authentication and cloud threat detection.

The stated operating model is to build a single context graph from source, IaC, dependencies, secrets, endpoints, cloud configuration and commit history, derive a threat model of auth boundaries, trust assumptions and data flows, then attack those paths and report only findings that were actually exploited, accompanied by the request, the proving response and reproduction steps. The company frames this as a response to two problems it identifies in the market: SAST and SCA tools producing roughly 10,000 findings of which few matter, and annual human penetration tests leaving organizations without coverage for the rest of the year.

Earlier positioning, as of the 2025 seed announcement, centered on AI code review and code quality: a proprietary, language-agnostic Abstract Syntax Tree engine covering more than 30 languages, integrated with GitHub, GitLab, Bitbucket and Azure DevOps, providing PR summaries, one-click fixes, code-smell/complexity/duplication/dead-code detection, and SAST, SCA, IaC and secret scanning aligned to OWASP and CWE. Prior YC launches also included a developer engineering-metrics product.

Founding story

Amartya Jha and Chinmay Bharti started CodeAnt in June 2023 after experiencing slow and error-prone code review firsthand: Jha previously worked at Zeta and ShareChat, where rushed code changes created operational risk, and Bharti built high-frequency trading systems where a single bug could be costly. The founders describe a formative discovery in which Bharti found a way to forge JWT signatures in a widely shipped library (CVSS 10), a reasoning flaw that pattern-matching scanners had missed for years, motivating a platform that reasons like an attacker rather than matching patterns.

Business model

B2B software sold to engineering and security teams, with self-serve entry (a free pentest requiring no credit card) alongside enterprise sales via demos and scoping calls. The platform is offered as a cloud service and can also be deployed in the customer's own environment / on-premise for security-conscious buyers, with the company stating that customer code does not train models or leave the customer boundary.

Per-developer subscription pricing was reported at the time of the seed round: from $10 per developer per month for basic AI code review up to $40 per developer per month for the full suite including code quality analysis, security monitoring and compliance tooling. For agentic pentesting the company advertises no engagement fee, with payment only if high or critical issues are found and low/medium findings provided free.

Traction

The company reports having run penetration tests for 200+ companies and disclosing 100+ zero-day CVEs affecting packages with 1.85 billion+ monthly downloads, including a CVSS 10.0 authentication bypass in pac4j-jwt (CVE-2026-29000) and a CVSS 9.8 RCE in simple-git (CVE-2026-28292). At the time of the 2025 seed round the company said it scanned over 50 million lines of code, auto-fixed more than 500,000 issues and saved over 100,000 developer hours per day. Team size is listed at 25. Customer quotes come from 11x, Autajon Group and Motorq.

Latest developments

As of 2026 the company has repositioned its homepage around exploit-based agentic security, launched Agentic Pentest (March 2026), disclosed CVE-2026-29000 (pac4j-jwt auth bypass, CVSS 10.0) and CVE-2026-28292 (simple-git RCE, CVSS 9.8), surpassed 100+ disclosed CVEs by May 2026, and cites a Gartner Cool Vendor 2026 recognition in application security along with SOC 2 Type II and HIPAA compliance.

β–ΈFull profile β€” market position, technology, go-to-market, geography, history, risks & controversies

Market position

Positions itself as combining offensive and defensive security in one self-learning platform, contrasting with point tools that only scan (SAST/SCA) or with periodic human penetration-testing engagements. Its own site benchmarks the product against SonarQube, Snyk, CodeRabbit and GitHub Copilot, and a prior YC launch compared its engineering-metrics product to LinearB. External validation cited includes a Gartner Cool Vendor 2026 designation in application security and coverage in Forbes, Economic Times, Fintech Global, Cybernews and Analytics India Magazine.

Emphasis on exploit-proof over severity scoring: findings are reported only when an agent reproduced them, with the triggering request, the proving response and reproduction steps, which the company positions against high-volume SAST/SCA output and once-a-year pentest PDFs. Other stated differentiators are the combination of offensive and defensive layers in one system, grey-box re-attack informed by codebase knowledge, a whole-codebase AST engine instead of snippet-level analysis, on-premise deployability, and a commercial model where pentests carry no engagement fee.

Technology

A proprietary language-agnostic Abstract Syntax Tree engine that models an entire codebase rather than isolated snippets underpins the code-analysis layer, supporting more than 30 languages. The security platform builds a unified context graph across source, infrastructure-as-code, dependencies, secrets, endpoints, cloud configuration and commit history, derives a ranked threat model, and executes attacks with a fleet of 500+ autonomous exploit agents covering categories such as BOLA, IDOR, SSRF and auth bypass, fusing black-box and white-box (grey-box) knowledge. Findings are validated by reproduction rather than scored by CVSS alone. The company states code is not used to train models and offers self-hosted deployment.

Go-to-market

Product-led entry through a free, no-credit-card pentest and free low/medium findings, combined with a direct enterprise sales motion (book-a-demo, contact sales, scoping calls) and hiring of founding GTM roles such as a Founding Account Executive and Founding Business Development Representative in San Francisco. Distribution also leans on integration into existing developer tooling (GitHub, GitLab, Bitbucket, Azure DevOps, IDE, CLI, CI/CD) rather than a separate console, plus security-research publicity from disclosed CVEs and press coverage.

Software engineering and application security teams, ranging from startups to Fortune 100 enterprises, including regulated sectors such as healthcare, finance and defense where SOC 2, HIPAA and on-premise deployment matter. Named references include 11x, Autajon Group and Motorq.

Geography

Headquartered at 355 Bryant St, San Francisco, CA 94107, incorporated as CodeAnt AI, Inc., with an additional office in Bengaluru, India reported at the time of the seed round. Hiring for founding GTM roles is based in San Francisco.

History

Founded June 2023 by Amartya Jha (Co-founder and CEO) and Chinmay Bharti (Co-founder and CTO, IIT Bombay electrical engineering, previously in high-frequency trading). The company joined Y Combinator's Winter 2024 batch in February 2024 with Tom Blomfield as primary partner, and raised a $2M seed round in May 2025 at a reported $20M valuation. Its own timeline then lists a $60M valuation in January 2026, disclosure of a CVSS 10.0 authentication bypass in February 2026, the launch of Agentic Pentest in March 2026, and 100+ CVEs disclosed by May 2026. Product scope evolved from AI code review and developer engineering metrics toward a combined offensive/defensive agentic security platform.

Risks & controversies

Several headline claims β€” 200+ companies pentested, 100+ CVEs, the $60M valuation, daily scanning and hours-saved figures, and the Gartner Cool Vendor designation β€” originate from the company's own website, YC profile or funding-announcement coverage rather than independent verification. Disclosed funding is small ($2M seed) relative to a competitive application-security market that includes Snyk, SonarQube and CodeRabbit. The company's positioning also depends on the accuracy and safety of autonomous agents actively attacking customers' live production systems.

Compiled by commissioned research from 8 cited public sources β€” announcements, filings, and press listed under research sources below.

Key figures

latest reported
Companies pentestedJan 2026200+ companies
Developer hours saved dailyMay 2025100,000 hours/day
Entry priceMay 2025$10
Exploit agentsJan 2026500 agents (500+)
Full suite priceMay 2025$40
HeadcountAug 202632
Issues auto fixed dailyMay 2025500,000 issues/day
Lines of code scanned dailyMay 202550,000,000 lines/day
Monthly downloads of affected packagesJan 20261,850,000,000 downloads/month
Post money valuationMay 2025$20M
Programming languages supportedMay 202530 languages (30+)
Team sizeJan 202625 employees
Valuation stated by companyJan 2026$60M
Zero day CVEs disclosedMay 2026100 CVEs (100+)

Company-reported or press-reported figures, each dated to when it was claimed β€” not independently audited.

Images

CodeAnt AI photo

Competitors Β· 10

by search overlap
Qodo321 shared keywordsQodo provides AI-powered code review and code quality governance for enterprise engineering teams, using specialized review agents and a context engine that reason over a full codebase to flag bugs, rule violations, and requirement gaps. Its platform enforces self-learning, machine-readable coding standards across developers, reviewers, and AI agents throughout the software development lifecycle.
Snyk308 shared keywordsSnyk is a developer-focused security platform that identifies and fixes vulnerabilities in code, dependencies, containers, and cloud infrastructure using AI-powered analysis. The company serves organizations of all sizes looking to integrate security into their software development process.
Codacy280 shared keywordsCodacy provides a platform for code quality, security, and AI coding policy enforcement, letting engineering teams define coding standards and apply them across projects, IDEs, and AI coding agents. It offers automated pull request reviews, SAST, secret scanning, dependency/CVE scanning, AI guardrails, and audit-ready reports for compliance frameworks like SOC2 and ISO27001.
Netezza255 shared keywordsIBM is a global technology company whose business spans enterprise software (including Red Hat, HashiCorp, and Confluent), IT infrastructure such as mainframes, servers, and storage, and IT consulting services. The company is also investing heavily in quantum computing and AI-based enterprise offerings, including its Lightwell open-source software security clearinghouse and the Anderon quantum wafer foundry.
Cycode241 shared keywordsCycode provides an application security and product security platform focused on securing the software development lifecycle, including risks from AI-generated code and shadow AI. The company serves CISOs and security teams, offering research and tooling for AppSec and code security.
Aikido Security240 shared keywordsAikido provides integrations that deliver notifications from its security platform directly into team messaging applications.
Legit Security204 shared keywordsLegit Security provides an application security platform that helps organizations identify and manage software vulnerabilities and risks across their development environments. The platform serves enterprise security teams seeking to reduce alert fatigue and improve visibility into their application attack surface.
Atlassian198 shared keywordsAtlassian offers a teamwork platform combining project planning, knowledge management, and AI orchestration tools for teams and their AI agents. Its products help organizations plan, execute, and deliver work at scale.
Wiz197 shared keywordsWiz provides cloud security platform that identifies and removes critical risks across multi-cloud environments. The company offers a unified security layer for organizations to manage risks and accelerate business operations on major cloud providers.
Veracode, Inc.195 shared keywordsVeracode provides an application security platform for scanning, identifying, and remediating software flaws across the software development lifecycle and supply chain. The company serves enterprises and software development teams seeking to build secure software from development through deployment.

Companies competing with CodeAnt AI for the same Google search keywords, organic and paid, via search-intersection analysis.

Timeline Β· 8

launches, deals, and filings
May 2026
Reaches 100+ disclosed zero-day CVEs

Company timeline records passing 100+ disclosed CVEs; YC profile states the disclosures affect packages with 1.85B+ monthly downloads.

source β†—

Mar 2026
Launches Agentic Pentest

CodeAnt AI launched its agentic penetration testing product, using 500+ exploit agents that chain attacks against a live attack surface and reproduce findings with request/response evidence.

source β†—

Feb 2026
Discloses CVSS 10.0 authentication bypass (CVE-2026-29000)

CodeAnt AI disclosed a critical authentication bypass in pac4j-jwt (CVE-2026-29000, CVSS 10.0) that allowed impersonation using only a public key and had gone undetected for six years. YC's news feed dates the disclosure item to 2026-03-05.

source β†—

Jan 2026
Named Gartner Cool Vendor 2026

CodeAnt AI states it was recognized as a Gartner Cool Vendor in application security for autonomous, verified testing.

source β†—

Jan 2026
Company cites $60M valuation

The company's about-page timeline lists a $60M valuation in January 2026; no round details are given.

source β†—

Jan 2026
Positions platform as exploit-based agentic security covering offense and defense

The website presents a combined offensive layer (agentic pentesting, attack surface management, DAST, cloud threat detection) and defensive layer (AI SAST, SCA/SBOM, secrets, IaC, CSPM) delivered in the PR and CI/CD workflow.

source β†—

May 2025
Raises $2M seed round at a $20M valuation

CodeAnt AI raised $2 million in seed funding led by Y Combinator, VitalStage Ventures and Uncorrelated Ventures, with participation from DeVC, Transpose Platform, Entrepreneur First and angel investors. Unite.AI reports the round valued the company at $20 million. Funds were earmarked for product development, engineering capacity and customer growth.

$2M source β†—

Feb 2024
Joins Y Combinator Winter 2024 batch

CodeAnt AI participated in Y Combinator's W24 batch; YC lists Tom Blomfield as primary partner.

source β†—

Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.

In the news

β–ΈResearch sources Β· 8

primary sources listed

8 public sources were cited for this profile; the first-party ones are listed here.

Frequently asked questions

What does CodeAnt AI do?
CodeAnt AI is a YC-backed agentic application security platform pairing AI code review with autonomous exploit-based pentesting.
Who founded CodeAnt AI?
CodeAnt AI was founded by Amartya Jha, Chinmay Bharti in 2023.
Who are CodeAnt AI's investors?
CodeAnt AI's investors include Entrepreneur First, Strategxy Ventures LLC, Transpose Platform Management, Y Combinator.
How much funding has CodeAnt AI raised?
CodeAnt AI has disclosed $4M raised across 2 of its 3 known rounds.
Where is CodeAnt AI headquartered?
CodeAnt AI is headquartered in San Francisco, US.