Hex Security is a Y Combinator (W26) security startup building autonomous AI agents that perform continuous penetration testing against web applications, APIs, and infrastructure. Instead of point-in-time annual pentests, Hex's agents probe systems around the clock — chaining exploits together, validating each finding with a working proof-of-concept, and delivering triaged, reproducible results with no false positives. The product surfaces high-severity issues such as SQL injection, broken access control / IDOR, authentication bypass, and unauthenticated remote code execution. Founded by Ahmad Khan, Huzaifa Ahmad, and Prama Yudhistira. As of this profile Hex Security is pre-public-API: it operates a marketing site (hex.co) and a product application (app.hex.co) but does not yet publish a developer portal, OpenAPI definition, or public API surface.
Hex Security is profiled on the APIs.io network. Tagged areas include Company, Security, Penetration Testing, Application Security, and API Security.
Create-or-Update Ergonomics could not be measured. We hold no machine-readable contract for
this provider to read, so there is nothing to measure a write surface against. Excluded rather than scored zero:
never-measured and measured-empty are different facts. Publishing an OpenAPI is what makes this facet — and
several others — scorable at all.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. Every facet and dimension name above is a link: it opens that measurement's own page — what it means, the exact checks that feed it, how the whole catalog distributes on it, and the providers at the top of it. This rating is computed from github.com/api-evangelist/hex-security: open an issue to ask a question, or submit a pull request to add artifacts.
Submit an artifact on GitHub — free →Manage your own listing — the Influence plan, $499/mo →
aid: hex-security
name: Hex Security
description: 'Hex Security is a Y Combinator (W26) security startup building autonomous AI agents that perform continuous
penetration testing against web applications, APIs, and infrastructure. Instead of point-in-time annual pentests, Hex''s
agents probe systems around the clock — chaining exploits together, validating each finding with a working proof-of-concept,
and delivering triaged, reproducible results with no false positives. The product surfaces high-severity issues such as
SQL injection, broken access control / IDOR, authentication bypass, and unauthenticated remote code execution. Founded by
Ahmad Khan, Huzaifa Ahmad, and Prama Yudhistira. As of this profile Hex Security is pre-public-API: it operates a marketing
site (hex.co) and a product application (app.hex.co) but does not yet publish a developer portal, OpenAPI definition, or
public API surface.'
url: https://raw.githubusercontent.com/api-evangelist/hex-security/refs/heads/main/apis.yml
deliveryModel:
model: saas
open_source: false
commercial: true
callable_host: false
label: Hosted service · you call their endpoint
confidence: medium
source:
- pricing
generated: '2026-08-28'
method: derived
accessModel:
pricing: unknown
onboarding: unknown
trial: false
try_now: false
public: false
label: Unknown
confidence: low
source:
- url: https://hex.co
status: 301
note: declared website redirects to https://www.parameter.ai/?from=hex — a different registrable domain (hex.co -> parameter.ai),
possible rename or acquisition (probed 2026-09-03, roadmap#169)
generated: '2026-07-22'
method: derived
image: https://framerusercontent.com/images/Hioh4DamknpQbzzIX7Z0Xt1PAk0.webp
x-type: company
x-source: vc-portfolio
x-backed-by:
- y-combinator
x-yc-batch: W26
x-tier: stub
x-tier-reason: portfolio-lead
specificationVersion: '0.23'
created: '2026-07-17'
modified: '2026-07-19'
tags:
- Company
- Security
- Penetration Testing
- Application Security
- API Security
- Vulnerability Management
- Artificial Intelligence
- AI Agents
- DevSecOps
- Y Combinator
apis: []
common:
- type: Website
url: https://hex.co
- type: Login
url: https://app.hex.co/login
- type: DomainSecurity
url: security/hex-security-domain-security.yml
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com
- FN: APIs.json
email: info@apis.io
x-enrichment:
date: '2026-07-19'
status: backfilled
pass: local-v1
note: backfilled from .gitignore signal + verified work evidence
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.