Hex Security
Hex Security is a Y Combinator (W26) security startup building autonomous AI agents that perform continuous penetration testing against web applications, APIs, and infrastructure. Instead of point-in-time annual pentests, Hex's agents probe systems around the clock — chaining exploits together, validating each finding with a working proof-of-concept, and delivering triaged, reproducible results with no false positives. The product surfaces high-severity issues such as SQL injection, broken access control / IDOR, authentication bypass, and unauthenticated remote code execution. Founded by Ahmad Khan, Huzaifa Ahmad, and Prama Yudhistira. As of this profile Hex Security is pre-public-API: it operates a marketing site (hex.co) and a product application (app.hex.co) but does not yet publish a developer portal, OpenAPI definition, or public API surface.
Hex Security is profiled on the APIs.io network. Tagged areas include Company, Security, Penetration Testing, Application Security, and API Security.
Kin Score
Security Posture 1
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Resources
Get Started 1
Portal, sign-up, and the first successful call
Access & Security 1
Authentication, authorization, and security posture
Company 1
The organization behind the API