French cybersecurity startup Fleuret AI raises €4 million to automate penetration testing with AI agents

Fleuret AI, a Paris-based cybersecurity startup automating penetration testing with agentic AI, has closed a €4 million pre-Seed round to hire AI,

Written by
Rahul Raj
Published by
EU-Startups
Published
Length
515 words · 2 min
French cybersecurity startup Fleuret AI raises €4 million to automate penetration testing with AI agents

Fleuret AI, a Paris-based cybersecurity startup automating penetration testing with agentic AI, has closed a €4 million pre-Seed round to hire AI, software engineering, and offensive security talent and accelerate platform development. 

The round was led by RAISE Ventures, with participation from Auriga Cyber Ventures, Wind Capital, Better Angle, and leading business angels from the cybersecurity world, including Jules Veyrat, co-founder and CEO of Stoïk; Alexandre Andreini, Chief Risk Officer of Stoïk; Eric Fourrier, CEO of GitGuardian; Georges Lotigier, co-founder at Vade; and Olivier Pantaleo and Jean-François Aliotti, the co-founders of Almond. 

“AI has changed the nature of cyberattacks by putting powerful tools within everyone’s reach, often for free. Organisations have to test their security against every attack technique, including the newest. Fleuret built its platform to evolve continuously and stay a step ahead of attackers, with a team that puts AI to work for deep offensive expertise. We are convinced Fleuret can become the reference in offensive security in Europe,” said Thibaut Schlaeppi, co-head of RAISE Ventures. 

Founded in 2026 by Yanis Grigy (CEO) and Augustin Ponsin (CTO), Fleuret combines AI and offensive expertise to make pentesting accessible, continuous, and sovereign. The platform is built to move penetration testing from a one-off audit to continuous security across five pillars: know the exposed systems, identify vulnerabilities, prove they can be exploited, help fix them, and verify they are fixed.

According to the company, companies change their systems every day while security requirements keep rising. It highlighted that under NIS2 in particular, a growing number of organisations have to demonstrate how robust their security is. However, penetration testing still relies largely on one-off audits, which include a snapshot of a system at a given moment, even though a new deployment a few days later can already have changed its attack surface.

Fleuret claims to automate the pentester’s work with two AI agents, Emile and Champollion. They map a company’s environment, explore its applications, APIs and infrastructure, then try to exploit the vulnerabilities they find. It notes that every finding includes a proof of compromise demonstrating how it can be exploited. The platform then keeps watching the attack surface and can trigger new tests as the system changes.

The French startup further notes that, beyond finding vulnerabilities, it is building tools to see them through to resolution: prioritisation by exploitability, integration with the tools engineering teams already use, automatic re-testing, and reports that verify a vulnerability has been fixed.

“We do not simply want to automate penetration testing as it exists today. Our ambition is to build the offensive security layer that will keep companies secure all year round, whatever their size. This round gives us the means to accelerate that vision and to build a platform designed for enterprise environments from day one,” said Grigy, CEO and co-founder of Fleuret. 

The company currently employs about ten people and counts several customers, including Brevo, Stoïk, and Yogosha. “From the start, the ambition is European: make offensive security accessible to every company, including those that cannot afford regular penetration tests,” the company said. 

Where this came from

This story was reported by Rahul Raj and first published by EU-Startups on 5 October 2026. HUE Legacy Ventures did not write it.

Carried in full with attribution and a link to the original. Rights remain with the publisher, who may request removal at any time.

Read it at eu-startups.com →