FAZE Security raises $6M to turn pentesting into a continuous software loop
EasySend co-founder Omer Shirazi leads the former CYTRIX, which claims 50 enterprise customers and 20X ARR growth without publishing the revenue base.
By RuntimeWire Staff · Published
Primary source: PR Newswire
Why it matters
FAZE Security is betting that penetration testing becomes a continuous operational system owned by software. If its enterprise claims hold, security spending could move away from annual consulting projects and high-noise scanners.

Omer Shirazi, Sahar Avitan, Yaniv Vaknin and Udi Cohen brought FAZE Security out of stealth on Friday, September 11th, with a $6 million seed round announced through PR Newswire. New Era Capital Partners led the financing, with Lockstep VC participating.
FAZE Security, previously called CYTRIX, sells an offensive security platform that continuously attacks customers' applications, APIs and cloud environments. Its agents attempt to exploit vulnerabilities, prioritize findings by demonstrated business impact, route remediation work to an owner and rerun the exploit after a fix.
The pitch is built around a familiar failure inside security organizations: scanners can generate more findings than engineering teams can process, while annual penetration tests capture a system at a single point in time. FAZE Security wants to own the full loop from discovery through verification, replacing a collection of reports, tickets and manual retests with one continuous system.
A four-founder bet on the remediation backlog
Shirazi, FAZE Security's CEO, previously co-founded EasySend, a no-code platform for digitizing customer interactions in insurance and financial services. EasySend's founders wrote that they had raised $71.5 million by late 2021.
That background gives Shirazi experience selling workflow software into large, regulated organizations, where adoption depends on integration and auditability as much as technical performance. At FAZE Security, the workflow begins with an exploit and ends only when the same attack stops working.
Avitan, FAZE Security's CTO, supplies the offensive security depth. Lockstep's profile of the founding team describes her as a cybersecurity researcher, developer and penetration tester with over 14 years of experience. Lockstep also says she has taught at the Technion, disclosed vulnerabilities in open-source software and earned the Offensive Security Web Expert certification.
Vaknin, the COO, previously ran Ness' outsourcing division, an operation that Lockstep says exceeded $200 million. Cohen, the CBO, is a former lieutenant colonel in the Israel Defense Forces special forces who has worked across sales, customer success and go-to-market operations. The four founders cover the difficult parts of an enterprise security sale: product, offensive research, delivery and commercial adoption.
FAZE Security leads with a multiplier
FAZE Security says it has 50 enterprise customers, including several Fortune 500 companies, and grew annual recurring revenue by roughly 20X in 18 months. Those figures come from FAZE Security, and the ARR multiple lacks the starting or ending revenue needed to measure the scale behind it.
A 20X increase can describe a meaningful commercial expansion or movement from an early pilot base. The multiplier alone cannot distinguish between them. FAZE Security also did not attach a valuation to the seed round.
FAZE Security's public customer stories identify Hippo Insurance, Cellebrite and OurCrowd. The examples help establish the buyer profile behind the launch: regulated or security-sensitive organizations that need authenticated testing, compliance reporting and integration with development pipelines. They do not independently substantiate the full customer count or the Fortune 500 portion of the claim.
The performance figures need the same qualification. FAZE Security says customers report close to zero false positives and over 50% faster mean time to remediation than scanners and point-in-time penetration tests. Its homepage displays a 0.1% false-positive rate, without publishing the sample, testing methodology or measurement period.
False positives are central to the product's economics. An autonomous system that creates another queue of weak findings merely moves the bottleneck. FAZE Security's value depends on proving that an exploit works, assigning the fix and reliably confirming that remediation closed the attack path.
The agents still need rules
FAZE Security says its platform combines deterministic controls with a swarm of over 25 AI agents. The agents plan attacks, select tools, analyze evidence and score severity, while deterministic rules provide boundaries for operations inside customer environments.
That hybrid architecture reflects the practical limits of deploying probabilistic models in security testing. Enterprise customers need reproducible evidence and predictable guardrails before permitting software to run exploits against production systems, authenticated applications or internal infrastructure.
FAZE Security has also published an internal benchmark of 13 AI models across 82 vulnerability findings and 1,066 agent runs. The research measured verification, false-positive behavior, errors, latency and cost per finding. FAZE Security acknowledged that the test used no external ground-truth labels, so it should be read as product research rather than independent validation. It still shows where Avitan and the engineering group are concentrating: model reliability and operating cost matter alongside raw model capability when every finding may be retested repeatedly.
Autonomous pentesting already has a field
FAZE Security is entering a market with established autonomous testing vendors. XBOW focuses on AI-driven offensive testing for applications and APIs. Horizon3.ai's NodeZero runs autonomous tests across internal networks, cloud systems and identity infrastructure, then helps customers verify fixes. Pentera sells automated security validation and expanded into AI red teaming through its November 2025 acquisition of EVA Information Security.
FAZE Security is positioning its breadth and remediation workflow as the distinction. Its listed coverage spans applications, APIs, infrastructure, code, networks, operational technology and AI agents, including systems behind login walls, multifactor authentication and CAPTCHA flows. The product can send remediation work into Jira, Azure DevOps, Monday, Slack or Git before retesting the affected system.
New Era partner Ziv Conen backed the round around FAZE Security's proprietary attack data and its ability to automate the offensive cycle from discovery through retesting. That is the investor case. The commercial case will depend on whether FAZE Security can make those capabilities dependable enough for security leaders and quiet enough for engineering teams.
Shirazi has previously helped build an enterprise workflow product around a process companies handled manually. FAZE Security applies a similar playbook to offensive security, with Avitan's research forming the technical core. The founders now have to convert their claimed early traction into durable recurring revenue and prove that continuous agentic testing earns a permanent place in security budgets after the initial AI interest fades.