Runsybil

RunSybil is an AI-native autonomous offensive security platform. Sybil — a system of AI agents — continuously penetration tests live applications and infrastructure, finding, exploiting, and validating real vulnerabilities without a human in the loop. It tests live applications black-box by default (no source code required), integrates with GitHub and GitLab to trigger targeted change testing on every code push, and validates every finding through a multi-agent pipeline before it surfaces, aiming to eliminate triage and false positives. RunSybil positions as a replacement for point-in-time penetration testing, legacy DAST/SAST scanners, and bug bounty programs, and also offers white-box testing for deeper codebase exploration. Founded in 2023 by Ari Herbert-Voss (OpenAI's first security hire) and Vlad Ionescu (Offensive Security Tech Lead at Meta), the company raised $40M led by Khosla Ventures and is trusted by security teams at Notion, Cursor, Turbopuffer, Baseten, and Thinking Machines Lab. No public developer API, SDK, or API documentation surface is published at this time.

Runsybil is profiled on the APIs.io network. Tagged areas include Company, Security, Offensive Security, Penetration Testing, and Application Security.

Runsybil’s developer surface includes engineering blog, signup flow, and 9 more developer resources.

14.2/100 minimal ▬ flat Agent 0/100 human only Full breakdown ↓
scored 2026-07-27 · rubric v0.5
0 APIs
CompanySecurityOffensive SecurityPenetration TestingApplication SecurityVulnerability ManagementArtificial IntelligenceAI AgentsDevSecOps

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 14.2/100 · minimal
Contract Quality 0.0 / 25
Developer Ergonomics 0.4 / 20
Commercial Clarity 6.3 / 20
Operational Transparency 0.7 / 13
Governance 0.0 / 12
Discoverability 6.8 / 10
Agent readiness — 0/100 · human only
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 15
MCP Server 0 / 12
Machine-Readable Auth 0 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/runsybil: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

Security Posture 1

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Runsybil Domain Security

TLSv1.3 · HSTS

SECURITY

Resources

Get Started 1

Portal, sign-up, and the first successful call

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 1

Pagination, idempotency, versioning, errors, and events

Build 1

SDKs, sample code, and the tooling you integrate with

Access & Security 2

Authentication, authorization, and security posture

Commercial 1

Pricing, plans, and the legal terms of use

Company 4

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: runsybil
name: Runsybil
description: RunSybil is an AI-native autonomous offensive security platform. Sybil — a system of AI agents — continuously
  penetration tests live applications and infrastructure, finding, exploiting, and validating real vulnerabilities without
  a human in the loop. It tests live applications black-box by default (no source code required), integrates with GitHub and
  GitLab to trigger targeted change testing on every code push, and validates every finding through a multi-agent pipeline
  before it surfaces, aiming to eliminate triage and false positives. RunSybil positions as a replacement for point-in-time
  penetration testing, legacy DAST/SAST scanners, and bug bounty programs, and also offers white-box testing for deeper codebase
  exploration. Founded in 2023 by Ari Herbert-Voss (OpenAI's first security hire) and Vlad Ionescu (Offensive Security Tech
  Lead at Meta), the company raised $40M led by Khosla Ventures and is trusted by security teams at Notion, Cursor, Turbopuffer,
  Baseten, and Thinking Machines Lab. No public developer API, SDK, or API documentation surface is published at this time.
url: https://raw.githubusercontent.com/api-evangelist/runsybil/refs/heads/main/apis.yml
accessModel:
  pricing: unknown
  onboarding: unknown
  trial: false
  try_now: false
  public: false
  label: Unknown
  confidence: low
  source: []
  generated: '2026-07-22'
  method: derived
image: https://cdn.prod.website-files.com/65f0bacd8d542276115a3910/696aa2cbcc07aa7c68427d3b_sybil-og.png
x-type: company
x-source: vc-portfolio
x-backed-by:
- menlo-ventures
x-tier: stub
x-tier-reason: portfolio-lead
specificationVersion: '0.20'
created: '2026-07-17'
modified: '2026-07-21'
tags:
- Company
- Security
- Offensive Security
- Penetration Testing
- Application Security
- Vulnerability Management
- Artificial Intelligence
- AI Agents
- DevSecOps
apis: []
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
common:
- type: Website
  url: https://www.runsybil.com
- type: About
  url: https://www.runsybil.com/company
- type: Blog
  url: https://www.runsybil.com/blog
- type: SignUp
  url: https://www.runsybil.com/schedule-a-demo
- type: TermsOfService
  url: https://www.runsybil.com/terms-of-conditions
- type: GitHubOrganization
  url: https://github.com/runsybil
- type: LinkedIn
  url: https://www.linkedin.com/company/runsybil
- type: Compliance
  url: https://www.runsybil.com/company
- type: Conformance
  url: conformance/runsybil-conformance.yml
- type: DomainSecurity
  url: security/runsybil-domain-security.yml
- type: LLMsTxt
  url: llms/runsybil-llms.txt
x-enrichment:
  date: '2026-07-21'
  status: minimal
  artifacts_added: 3
  pass: local-v1