Fundraising Fox

Firecompass

Founded 2019 · 102 employees on LinkedIn · 4 known investors

Find your way into Firecompass

40 people in our graph share verified history with the Firecompass team — schools, employers, funds. One of them is your warm intro.

Somnathunlockedknows Bikash Barai · together at Indian Institute of Technology, Kharagpur (overlapped)
×9knows the team · via Indian Institute of Technology, Kharagpur
knows the team · via Smokescreen [Acquired by Zscaler]
knows the team · via Firecompass

FireCompass provides autonomous AI agents that perform continuous penetration testing and red teaming of web applications, APIs, and infrastructure by discovering attack surfaces, exploiting vulnerabilities with proof-of-concept validation, and chaining findings into realistic attack paths. It serves security and development teams that need continuous validation of security posture as they ship code frequently.

Also known as FireCompass Technologies Inc. · FireCompass Technologies Pvt. Ltd.

Founders & leadership

Firecompass was founded in 2019 by Bikash Barai, Arnab Chattopadhayay, and Priyanka Aash.

BBBikash Barai
Bikash BaraiinFounder & CEOBikash Barai co-founded FireCompass, an autonomous penetration testing platform, and previously co-founded iViZ, which was acquired by Cigital and integrated into Synopsys.
ACArnab Chattopadhayay
Arnab ChattopadhayayinCo-founder & VP of Emerging Research
PAPriyanka Aash
Priyanka AashinCo-founder & VP of MarketingPriyanka Aash is a computer science engineer with experience building systems at Infosys, Bank of America, and Sony. She co-founded CISO Platform, a network of security leaders, and is co-founder and VP of Marketing at FireCompass, which develops AI-driven continuous automated red teaming and offensive security platforms.

Investors · 4

Also in the syndicate · 2

Bharat Innovation FundEC-Councillead

Company profile

researched Aug 2026

FireCompass is a cybersecurity software company that sells a SaaS platform for offensive security testing. Its agents discover an organization's external attack surface starting from the company name alone — including shadow applications, forgotten subdomains, API endpoints extracted from JavaScript files and traffic, exposed databases, cloud buckets, code leaks, risky open ports and credentials leaked on the deep and dark web — and then run penetration tests against web applications and APIs. Findings are exploit-validated: the platform attaches a working proof of exploit, steps to reproduce and ready-to-run Python, and maps issues to the OWASP Top 10 (2025) with severity and business impact.

Beyond single-issue testing, the platform chains validated findings into multi-stage attack paths that mimic real intrusions: credential reuse across services, app-to-app and app-to-network or app-to-identity lateral movement (including Active Directory), and privilege escalation to admin or root, visualized as a live MITRE ATT&CK-aligned attack-path graph. Published chains include an exposed .git directory leading to database credential extraction, SSH root access via credential reuse and database exfiltration; a UAT auth token in a JavaScript file granting production access; and WAF bypass through origin-server discovery. Testing is triggered by events such as a code push, a newly discovered asset, a newly disclosed CVE (validated within about 24 hours) or on demand, and can also be aligned to CI/CD. Governance features include transparency into agent plans and actions, scope control, safe exploitation designed not to disrupt production, and full audit trails intended to evidence SOC 2, PCI DSS 4.0 and ISO testing cadence requirements.

The broader product line spans web and API automated penetration testing, infrastructure penetration testing across networks, servers and cloud, Continuous Automated Red Teaming (CART), penetration testing as a service with an expert-in-the-loop option, and continuous threat exposure management (CTEM) with attack surface management. The company holds a USPTO-awarded patent for its automated red teaming technology.

Founding story

Founded in 2019 by Bikash Barai and Priyanka Aash, with Arnab Chattopadhayay as co-founder and VP of Emerging Research. Barai previously founded iViZ, an IDG Ventures-backed company acquired by Cigital (now part of Synopsys), described as the first company to move ethical hacking to the cloud; Aash previously co-founded CISO Platform. The founding premise was that organizations test only some assets some of the time while attackers probe all assets continuously, motivating continuous automated red teaming.

Business model

FireCompass sells a subscription SaaS platform, marketed on a per-application cost basis (it cites under $1,000 per application versus $2,400–$10,000 for manual testing) and offering an optional expert-in-the-loop service layer for business-logic testing and compliance acceptance.

Software-as-a-service subscriptions for continuous penetration testing, red teaming and attack surface management, with a paid expert-in-the-loop penetration-testing-as-a-service option.

Traction

The company reports Fortune 500 customers, 100% results on public benchmarks (XBEN 104/104, Acuart 12/12, DVWA), under 2% false positives, and internal evaluations in which its agents outperformed its own top researchers 60–70% of the time; it also states its AI agents reached HackerOne's Top 3 on $5,000 a month. A Fortune 500 case comparison cites a move from 200 of 2,000 applications tested annually at about $5,000 per app with 2+ week lead times to near-full surface coverage at under $1,000 per app with 1-day lead time.

Latest developments

FireCompass announced a $20 million strategic investment from EC-Council, creator of the Certified Ethical Hacker program, out of EC-Council's $100M Cybersecurity Innovation Fund, to fund R&D, hiring across engineering, research and customer-facing roles, and global go-to-market expansion. Its website now identifies the company as an EC-Council ecosystem company and markets an agentic AI penetration testing platform, citing inclusion in a leading research firm's 2026 Continuous Offensive Security Testing category.

Full profile — market position, technology, go-to-market, geography, history, risks & controversies

Market position

Positions itself in continuous offensive security testing against vulnerability scanners, human penetration-testing-as-a-service providers, attack-surface-management-only tools and single-shot AI testing tools. The company cites more than 30 analyst report coverages, Leader placement in the GigaOm Radar for 2023, 2024 and 2025, recognition by a global research and advisory firm five cycles in a row, and inclusion in a leading research firm's 2026 Continuous Offensive Security Testing category, alongside coverage by Forrester and IDC.

Combines full attack-surface discovery, exploit-validated findings with proof-of-concept code, autonomous chaining across applications, APIs and identity, live attack-path visualization and continuous trigger-based execution in one platform, with a stated false positive rate under 2% versus up to 70% for scanners.

Technology

Autonomous AI agents plan, execute and validate attacks, drawing on thousands of attack playbooks and continuous indexing of the deep, dark and surface web for asset and credential discovery. Adversary emulation is aligned to MITRE ATT&CK, exploitation is agentless and operational in minutes, and the company positions its differentiator as the orchestration, governance and repeatability layer around the models rather than the models themselves. It holds a USPTO patent covering automated red teaming.

Go-to-market

Direct enterprise sales supported by free entry points (a free AI pen test and free discovery scan), demo requests and expert consultations, a partner program, and content and analyst-driven marketing including whitepapers and conference presence. Proceeds from its funding rounds were earmarked for expanding go-to-market operations globally and hiring in engineering, research and customer-facing teams.

Enterprise security teams, including Fortune 500 organizations; named customers reported include T-Mobile, Sprint, Nykaa, Airtel Payments Bank, Hero and L&T Technology Services.

Geography

Headquartered in Wilmington, Delaware (FireCompass Technologies Inc.) with an Indian entity in Bangalore; the company has been described as Bengaluru- and Boston-based. Listed offices span Delaware, New Mexico, Florida and California in the US, Fredericton in Canada, plus London (UK), Kuala Lumpur (Malaysia), Jakarta (Indonesia) and Bangalore (India).

History

Established in 2019 in Bengaluru, FireCompass built a SaaS platform for continuous automated red teaming and external attack surface management. It raised $7 million in 2023 led by Cervin and Athera Venture Partners with existing investor Bharat Innovation Fund, then announced a $20 million strategic round from EC-Council's $100M Cybersecurity Innovation Fund, bringing total funding close to $30 million; the site now describes FireCompass as an EC-Council ecosystem company. Product positioning has shifted over time from CART and attack surface management toward agentic AI penetration testing for web applications and APIs.

Risks & controversies

Much of the performance evidence cited — including false-positive rates, cost and speed comparisons and agent-versus-researcher win rates — comes from the company's own benchmarks and internal evaluations rather than independent testing.

Compiled by commissioned research from 8 cited public sources — announcements, filings, and press listed under research sources below.

Key figures

latest reported
Agent win rate vs internal top researchersJan 202660-70% of the time in internal evaluations
Analyst report coveragesJan 202630 reports
Attack surface visibilityJan 2026scales from about 20% to over 99% of the surface
False positive rateJan 20262%
New CVE exposure identification timeJan 202624 hours
Public benchmark pass rateJan 2026100%
Total funding raisedJan 2026$30M

Company-reported or press-reported figures, each dated to when it was claimed — not independently audited.

Timeline · 4

launches, deals, and filings
Jan 2026
Named in a leading research firm's 2026 Continuous Offensive Security Testing category

The company states it is named in a leading global research firm's 2026 Continuous Offensive Security Testing (COST) category.

source ↗

Jan 2026
FireCompass raises $20 million from EC-Council for offensive security platform

FireCompass announced a $20 million strategic funding round from EC-Council, creator of the Certified Ethical Hacker program, as part of EC-Council's $100M Cybersecurity Innovation Fund, bringing total raised close to $30 million. Funds are earmarked for R&D, hiring and global go-to-market expansion.

$20M source ↗

Jan 2025
Leader in GigaOm Radar

FireCompass states it was named a Leader in the GigaOm Radar in 2023, 2024 and 2025, and cites more than 30 analyst report coverages including Forrester and IDC.

source ↗

Jan 2023
FireCompass raises $7 million led by Cervin and Athera Venture Partners

The company announced a $7 million round led by Cervin and Athera Venture Partners with participation from existing investor Bharat Innovation Fund, to expand operations across India, the US and other markets and hire in engineering, research and sales.

$7M source ↗

Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.

Research sources · 8

primary sources listed

8 public sources were cited for this profile; the first-party ones are listed here.

Frequently asked questions

What does Firecompass do?
FireCompass runs agentic AI penetration testing, automated red teaming and attack surface management for enterprises.
Who founded Firecompass?
Firecompass was founded by Bikash Barai, Arnab Chattopadhayay, Priyanka Aash in 2019.
Who are Firecompass's investors?
Firecompass's investors include Athera Venture Partners, Cervin.