Summary
- Fleuret has raised a €4 million pre-seed round led by RAISE Ventures.
- Its Emile and Champollion agents map applications, APIs and infrastructure and attempt to prove whether identified weaknesses can be exploited.
- The company wants to replace occasional penetration tests with continuous testing and automatic verification after vulnerabilities are fixed.
French cyber security startup Fleuret has raised €4 million to automate more of penetration testing, using AI agents to move security assessment from an occasional consultancy exercise towards a process that can be repeated as applications and infrastructure change.
Fleuret has closed a pre-seed round led by RAISE Ventures, with Auriga Cyber Ventures, Wind Capital, Better Angle and cyber security industry investors also participating. The Paris company employs around ten people and says customers include Brevo, Stoïk and Yogosha.
Its platform uses two AI agents, Emile and Champollion, to map a customer’s exposed environment, explore applications, APIs and infrastructure, identify vulnerabilities and then attempt to exploit them. Findings are accompanied by evidence intended to reproduce the weakness, after which the platform can monitor changes, trigger further testing and check whether remediation worked.
Automated scanners have existed for years, but they often generate long lists of theoretical weaknesses that security teams still have to investigate manually. Fleuret is attempting to automate part of the attacker’s reasoning as well as the initial detection.
A pentest is usually a snapshot
Traditional penetration testing places skilled security professionals in the position of an attacker for a defined period. Testers explore applications and infrastructure, combine weaknesses and attempt to demonstrate paths that could lead to unauthorised access or other damage.
Its main limitation is frequency. An organisation may complete a substantial penetration test and then deploy new code, add an API or change cloud infrastructure a few days later, creating an attack surface the finished report never examined.
Fleuret’s argument is that AI agents can make this deeper form of testing frequent enough to follow those changes. The company describes a five stage process covering discovery of exposed systems, vulnerability identification, proof of exploitation, remediation support and verification that the fix has worked.
Evidence of exploitability addresses one of security automation’s persistent problems because tools that report every possible weakness can overwhelm engineering teams with low value alerts, particularly when individual findings are technically valid but cannot be exploited in the actual environment.
A reproducible proof of compromise can improve prioritisation by demonstrating a path from the theoretical weakness to a real security outcome. It also raises the safety requirements placed on the platform because software designed to exploit vulnerabilities needs strict controls over where and how it operates.
Autonomous offensive testing needs boundaries
Skilled offensive security specialists are expensive, testing takes time and many organisations cannot afford to assess every application after every material change, giving AI led pentesting an obvious commercial appeal.
Greater autonomy also introduces another layer of risk because a penetration test deliberately performs actions that would be malicious without authorisation. An automated agent therefore needs precise scope boundaries to avoid affecting systems a customer did not intend to test.
Production environments add further sensitivity because aggressive security testing can interrupt services or alter data if techniques are not selected carefully. Experienced human testers make judgement calls about when to stop, when an exploit is too risky and whether demonstrating part of an attack chain provides enough evidence without completing every step.
Agentic systems have to encode equivalent constraints, making permissions, isolation and auditability as important as a model’s ability to discover vulnerabilities.
Fleuret says its findings include reproducible proofs and that its service can integrate remediation into engineering workflows before retesting corrected systems. Its public pricing also illustrates the economic argument: the company markets an automated web application pentest at €4,000 against the €15,000 to €30,000 it says a traditional consulting engagement can cost.
Those comparison figures are Fleuret’s own and manual penetration tests vary substantially in scope, duration and specialist expertise, so the services should not be treated as directly interchangeable in every case.
European compliance provides a ready market
Fleuret is positioning continuous testing partly against European regulatory pressure because NIS2 and DORA have increased expectations around cyber risk management and evidence that organisations are protecting important systems.
Automated testing can create more frequent evidence when systems are updated continuously through modern software development. A report produced months earlier provides limited reassurance if the application has changed significantly since the assessment was performed.
The company also emphasises European hosting, using Scaleway infrastructure in Paris for customer findings. That positioning may appeal to organisations concerned about placing vulnerability information inside services operated under non-European jurisdictions.
The larger competitive question is how much skilled offensive security can actually be automated. AI systems can increasingly navigate applications, interpret responses and chain actions together, but unusual business logic and complex environments still reward contextual understanding.
Automation may therefore alter where human penetration testers spend their time before it replaces them. Routine discovery and repeatable exploitation could move increasingly into software, leaving specialists to investigate unusual systems, design attack paths and validate higher risk findings.
Fleuret’s funding is an early bet on that transition. Its platform still has to prove that frequent automated testing produces useful evidence without replacing one source of noise with a more sophisticated one.
If it can, penetration testing starts to resemble a continuous engineering control rather than an audit event booked a few times each year.












