ZioSec
Steamboat Springs, US · Founded 2024 · Delaware corporation · 7 employees on LinkedIn · 9 known investors
ZioSec provides an autonomous AI red-teaming platform that runs continuous, deep-chained attacks (such as prompt injection, tool misuse, privilege escalation, and exfiltration) against AI agents across any framework, then converts findings into audit-ready evidence with remediation guidance. It targets enterprise security teams, CISOs, and platforms serving TPRM and insurance use cases, and offers delivery via a self-serve platform, an API, and scoped expert-led pentests.
Also known as ZioSec
Founders & leadership
Board
Investors · 9
Also in the syndicate · 4
Reported raises · per SEC filings
Form D private placements$1.2M disclosed across 1 of 2 rounds · 2025
▶$1.2MraisedJun 2025 · 6 investors · Other TechnologyRule 506(b)
- Andrius UseckasExecutive Officer, Director
- V. Frank Mendicino IIIDirector
- Aaron WallsExecutive Officer, Director
- Offering amount
- $2.1M
- Amount sold
- $1.2M
- Proceeds to insiders
- $260K
- First sale
- Jun 2025
- Incorporated
- Corporation, Delaware, 2024
- Federal exemptions
- 06b
Source: SEC EDGAR Form D. Amounts as filed; amended filings shown once at their latest values.
Company profile
researched Aug 2026ZioSec is a cybersecurity company that builds an autonomous offensive-security ("red team") platform for AI agents and multi-agent systems. The platform fingerprints each target agent — its model, tools, memory and connections — then generates and executes a bespoke, deep-chained attack tree against it, chaining prompt injection into tool misuse, privilege escalation and data exfiltration rather than firing single-shot prompts. Testing is continuous: campaigns re-run on a schedule and whenever a model, prompt or tool changes. Destructive actions are simulated or approval-gated, with rate limits, a one-click stop and a full audit log so the platform can be pointed at production agents.
Every finding is recorded with severity, deterministic reproduction steps, remediation guidance covering immediate and long-term fixes, and a classification in ZioSec's own A2OSF taxonomy, described as 8 attack layers, 10 tactics and 62 techniques. That internal record is exported to six external frameworks — OWASP AISVS, MITRE ATLAS, NIST AI RMF, ISO 42001, the EU AI Act and AIUC-1 — so results can be used as audit evidence. The product also presents fleet-level views: per-agent risk, top risky attacks and attack-path coverage. ZioSec says it can test any agent that runs a model and calls tools, including custom agents, Claude Code, and agents exposed over MCP or A2A, with no agent SDK required.
ZioSec positions itself against adjacent categories it says do not attack a live agent: runtime guardrails that block known-bad inputs inline, evaluation tools that score model quality against fixed test sets, and model/supply-chain scanners.
Founding story
ZioSec was founded by security veterans and engineers who identified a gap in which AI agents were shipping faster than the tooling needed to test them. Co-founder and CTO Andrius Useckas previously founded ThreatX, an API and application security company acquired by A10 Networks, and has over 25 years of experience as a pentester; co-founder and CEO Aaron Walls is a Techstars and Cornell alumnus and multi-time founder.
Business model
ZioSec sells its offensive testing engine through three delivery modes: a self-serve platform for continuous validation across an agent fleet (inventory, campaigns, per-agent policy, executive risk posture); an API that accepts an agent endpoint and returns audit-ready evidence, aimed at TPRM, insurance and security platforms; and fixed-scope, expert-led pentest engagements.
Platform subscriptions and API access, plus fixed-scope expert-led pentest engagements priced from $10,000, which are credited 100% toward a platform subscription if the customer continues.
Traction
ZioSec reported running pilots with large enterprises and AI-forward security teams as of July 2025. Its site cites a finding-density dataset of n = 2,318 findings across attack layers and tactics, and lists a five-person team of security veterans and engineers.
Latest developments
The $2.1 million seed round was announced in July 2025, with proceeds directed at product development, go-to-market and expanding offensive testing coverage; the company markets platform, API and scoped-pentest delivery options alongside its A2OSF taxonomy and six-framework evidence exports.
▸Full profile — market position, technology, go-to-market, geography, history
Market position
An early-stage, venture-backed entrant in the emerging AI agent security category, describing its product as the first offensive security platform purpose-built for testing AI agents and agent-to-agent workflows.
ZioSec's stated distinction is that it attacks the running agent continuously and adaptively — building a unique attack tree per agent and chaining multi-step exploits — where guardrails only defend inline, evals only measure quality against fixed test sets, and model scanners only inspect the model and its supply chain. It also emphasizes a lossless internal taxonomy (A2OSF) that exports to six compliance frameworks, so customers receive evidence in the framework they already report against.
Technology
An AI-driven red-teaming engine that fingerprints a registered agent endpoint, automatically generates a per-agent attack tree and executes multi-step exploits across tools, memory, data access and agent-to-agent trust relationships. Findings are classified under the proprietary A2OSF taxonomy (8 attack layers, 10 tactics, 62 techniques) and mapped control-by-control to six external frameworks from a single test run. Supported targets include agents on MCP and A2A frameworks and Claude Code.
Go-to-market
Direct enterprise sales via booked demos in which ZioSec runs a live attack campaign against a prospect's own agent, an entry-level scoped pentest that converts into subscription credit, an API channel for TPRM, insurance and security platforms, sample reports, published methodology content and a Discord community. The founders have also appeared on the This Week in Startups podcast (episode E2125) to discuss AI agent security.
Enterprise security, GRC and legal teams responsible for approving AI agents before production, AI-forward security teams, and platform companies serving third-party risk management (TPRM), insurance and security use cases.
Geography
Headquartered in Boulder, Colorado, with a fully remote team and quarterly team retreats in Colorado.
History
The company closed a $2.1 million seed round announced on July 17, 2025, led by Frank Mendicino of Access Venture Partners with participation from Jason Calacanis's LAUNCH Fund, Superhero Capital, Greater Colorado Venture Fund, Kickstart and angel investors. At announcement it was running pilots with large enterprises and AI-forward security teams and planned to use the capital for product development, expanded offensive testing coverage, and hiring full-stack engineers and security researchers.
Compiled by commissioned research from 7 cited public sources — announcements, filings, and press listed under research sources below.
Key figures
latest reportedCompany-reported or press-reported figures, each dated to when it was claimed — not independently audited.
Competitors · 3
by search overlapCompanies competing with ZioSec for the same Google search keywords, organic and paid, via search-intersection analysis.
Timeline · 2
launches, deals, and filingsZioSec announced the close of a $2.1 million seed round led by Frank Mendicino of Access Venture Partners, with participation from Jason Calacanis's LAUNCH Fund, Superhero Capital, Greater Colorado Venture Fund, Kickstart and angel investors. Funds are earmarked for product development, expanded offensive testing coverage and hiring engineers and security researchers.
$2.1M source ↗
At the time of its seed announcement, ZioSec said it was running pilots with large enterprises and AI-forward security teams.
Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.
Legal entities · 1
corporate structureIn the news
▸Research sources · 7
primary sources listed
- ZioSecziosec.com · web
7 public sources were cited for this profile; the first-party ones are listed here.
Frequently asked questions
- What does ZioSec do?
- ZioSec runs an autonomous AI red team that continuously attacks enterprise AI agents and turns findings into audit-ready evidence.
- Who are ZioSec's investors?
- ZioSec's investors include Access Venture Partners, Greater Colorado Venture Fund, Service Provider Capital, Superhero Capital, Access Ventures.
- How much funding has ZioSec raised?
- ZioSec has disclosed $1.2M raised across 1 of its 2 known rounds.
- Where is ZioSec headquartered?
- ZioSec is headquartered in Steamboat Springs, US.


