€4m · Pre-Seed · Cybersecurity · Paris, France
Paris-based Fleuret AI has raised €4m in pre-seed funding to develop its agentic-AI platform for automated penetration testing. The company and lead investor RAISE Ventures said the round also included Auriga Cyber Ventures, Wind Capital, Better Angle and business angels from the European cybersecurity industry. The capital will fund hiring across AI, software engineering and offensive security, alongside further platform development.
Turning a security snapshot into a repeatable workflow
Traditional penetration tests give a detailed view of a system at a particular moment, but software deployments can change an attack surface soon afterwards. Fleuret's agents, Emile and Champollion, map applications, APIs and infrastructure, attempt to exploit identified vulnerabilities, and attach a proof of compromise to each finding. The platform then connects findings to remediation work, re-tests corrected systems and produces reports intended to show that a vulnerability has actually been fixed.
That workflow is the commercial proposition, not automation alone. Fleuret prices a single web-application pentest at €4,000, compared with its stated €15,000–€30,000 range for a consulting firm, and offers an enterprise contract for testing multiple applications. If customers can launch tests after material releases and route findings into Jira, Linear or Slack, pentesting moves from an occasional consulting project towards a recurring part of software delivery. The evidence trail also gives security teams an operational output they can use for remediation and compliance reporting, rather than only a static audit document.
Fleuret says it has around ten employees and customers including Brevo, Stoïk and Yogosha. In a Télécom Paris founder interview, CEO Yanis Grigy said the product was live on real customer scopes and that three early customers came through the school's incubator. The company says its findings are hosted in Paris on European infrastructure, a positioning aimed at regulated buyers with data-sovereignty requirements.
The next test is breadth without losing proof
The founders, Grigy and CTO Augustin Ponsin, previously started a penetration-testing business while studying, according to the funding announcement. That background helps explain the product's emphasis on exploit evidence and remediation, but the company still has to broaden what its agents can test. Grigy identified cloud, Active Directory and mobile as coverage the team plans to add; Fleuret's own comparison of automated and manual testing says human teams remain stronger for complex internal networks, social engineering and some bespoke business logic.
The round therefore finances a specific execution challenge: extend automated coverage while preserving the reproducible proof that underpins customer trust. If Fleuret can do that, lower test costs may support a higher testing cadence; if broader coverage produces shallow or noisy results, buyers will still need separate manual engagements for the most consequential systems.


