Hex Security website screenshot

Hex Security

Hex Security is a Y Combinator (W26) security startup building autonomous AI agents that perform continuous penetration testing against web applications, APIs, and infrastructure. Instead of point-in-time annual pentests, Hex's agents probe systems around the clock — chaining exploits together, validating each finding with a working proof-of-concept, and delivering triaged, reproducible results with no false positives. The product surfaces high-severity issues such as SQL injection, broken access control / IDOR, authentication bypass, and unauthenticated remote code execution. Founded by Ahmad Khan, Huzaifa Ahmad, and Prama Yudhistira. As of this profile Hex Security is pre-public-API: it operates a marketing site (hex.co) and a product application (app.hex.co) but does not yet publish a developer portal, OpenAPI definition, or public API surface.

Hex Security is profiled on the APIs.io network. Tagged areas include Company, Security, Penetration Testing, Application Security, and API Security.

9.4/100 minimal ▬ flat Agent 0/100 human only Full breakdown ↓
scored 2026-07-27 · rubric v0.5
0 APIs
CompanySecurityPenetration TestingApplication SecurityAPI SecurityVulnerability ManagementArtificial IntelligenceAI AgentsDevSecOpsY Combinator

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 9.4/100 · minimal
Contract Quality 0.0 / 25
Developer Ergonomics 0.0 / 20
Commercial Clarity 2.6 / 20
Operational Transparency 0.0 / 13
Governance 0.0 / 12
Discoverability 6.8 / 10
Agent readiness — 0/100 · human only
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 15
MCP Server 0 / 12
Machine-Readable Auth 0 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/hex-security: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

Security Posture 1

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Hex Security Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Resources

Get Started 1

Portal, sign-up, and the first successful call

Access & Security 1

Authentication, authorization, and security posture

Company 1

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: hex-security
name: Hex Security
description: 'Hex Security is a Y Combinator (W26) security startup building autonomous AI agents that perform continuous
  penetration testing against web applications, APIs, and infrastructure. Instead of point-in-time annual pentests, Hex''s
  agents probe systems around the clock — chaining exploits together, validating each finding with a working proof-of-concept,
  and delivering triaged, reproducible results with no false positives. The product surfaces high-severity issues such as
  SQL injection, broken access control / IDOR, authentication bypass, and unauthenticated remote code execution. Founded by
  Ahmad Khan, Huzaifa Ahmad, and Prama Yudhistira. As of this profile Hex Security is pre-public-API: it operates a marketing
  site (hex.co) and a product application (app.hex.co) but does not yet publish a developer portal, OpenAPI definition, or
  public API surface.'
url: https://raw.githubusercontent.com/api-evangelist/hex-security/refs/heads/main/apis.yml
accessModel:
  pricing: unknown
  onboarding: unknown
  trial: false
  try_now: false
  public: false
  label: Unknown
  confidence: low
  source: []
  generated: '2026-07-22'
  method: derived
image: https://framerusercontent.com/images/Hioh4DamknpQbzzIX7Z0Xt1PAk0.webp
x-type: company
x-source: vc-portfolio
x-backed-by:
- y-combinator
x-yc-batch: W26
x-tier: stub
x-tier-reason: portfolio-lead
specificationVersion: '0.20'
created: '2026-07-17'
modified: '2026-07-19'
tags:
- Company
- Security
- Penetration Testing
- Application Security
- API Security
- Vulnerability Management
- Artificial Intelligence
- AI Agents
- DevSecOps
- Y Combinator
apis: []
common:
- type: Website
  url: https://hex.co
- type: Login
  url: https://app.hex.co/login
- type: DomainSecurity
  url: security/hex-security-domain-security.yml
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
x-enrichment:
  date: '2026-07-19'
  status: backfilled
  pass: local-v1
  note: backfilled from .gitignore signal + verified work evidence