HomeCompaniesCorgea
Corgea

Corgea finds, and fixes insecure code and packages autonomously.

Corgea is an autonomous application security platform that finds and validates vulnerabilities, then generates safe code fixes developers can apply in their existing workflow. In production customers like Zapier and Yageo, see ~20% more true positives and ~90% fewer false positives (vs their prior tooling), reducing triage and speeding remediation without adding headcount.
Active Founders
Ahmad Sadeddin
Ahmad Sadeddin
Founder
Ahmad is the founder and CEO of Corgea, which is his 3rd startup. His last one was acquired by Coupa. He spent the last 3 years of his tenure there leading the payments product where he worked on making sure their products were secure.
Company Launches
Corgea: Agentic Pentesting
See original launch post

Corgea AI Pentesting: an autonomous penetration testing engine that uses AI agents to plan, execute, validate, and report security tests. It doesn’t run a checklist. It reasons about your application.

https://www.youtube.com/watch?v=wzvUiEr8I2c

The numbers

In a recent pentest:

  • Corgea found 25 findings. The human pentester found 6.
  • Delivery time: 4-8 hours. The human pentest took 2 weeks.

Corgea AI Pentesting findings overview

How it works

Most autonomous pentesting tools are black-box scanners with better marketing. They probe endpoints against a generic vulnerability checklist and produce a PDF full of theoretical findings that security teams have to triage manually.

Corgea takes a fundamentally different approach. The engine operates like a real pentesting team.

Multi-agent architecture. Not a single scanner. Corgea spawns a coordinator agent that assigns specialized sub-agents (an authentication discovery agent, an API exploration agent, a SQL injection expert agent) based on what it discovers. These agents collaborate, share findings, and build on each other’s discoveries. For complex targets, Corgea can spawn hundreds of agents.

Corgea AI Pentesting multi-agent execution view

Code-aware, not black-box. The engine ingests code context, dependency data, infrastructure configuration, and business logic. It uses your existing AI SAST findings for white-box pentesting, exploiting vulnerabilities at runtime that static analysis already identified. This combination of static insight and dynamic testing dramatically amplifies what the engine can find.

Dynamic adaptation. Corgea’s agentic architecture is not fixed. The system continuously adapts its strategy based on what it learns about the target, dynamically scaling the number of agents, their responsibilities, and their specialization. It doesn’t follow a one-size-fits-all workflow.

Exploitability validation built in. Corgea doesn’t report theoretical vulnerabilities. Agents validate exploitability during the test itself, confirming a finding can be triggered, capturing evidence, and explaining business impact. This eliminates the triage burden that makes traditional pentest reports a firehose of unverified findings.

Corgea AI Pentesting exploit reproduction script

The pipeline

  1. Environment setup. Corgea provisions a Linux-based sandbox with a full suite of security tools for crawling, discovery, reconnaissance, and exploit validation.
  2. Scope and context ingestion. Target scope, endpoints, API documentation, auth flows, user roles, business logic context, and optional code/repo context. Both authenticated and unauthenticated.
  3. Attack surface discovery. Maps reachable routes, APIs, parameters, forms, auth boundaries, authorization-sensitive workflows, and exposed services.
  4. Autonomous test planning. AI agents reason about application structure and generate test plans for broken access control, IDOR, authentication bypass, injection, SSRF, insecure file handling, sensitive data exposure, and business logic abuse.
  5. Safe execution and validation. Hundreds of sub-agents execute probes, observe responses, adapt based on application behavior, and validate exploitability.
  6. Evidence generation. For confirmed issues: affected endpoint, payload or request sequence, response evidence, exploitability reasoning, severity, business impact, and remediation recommendation.
  7. Developer-native remediation. Findings go directly into developer workflows (PR comments, Jira tickets, Slack notifications, CI/CD pipelines) with reproduction steps, code context, and suggested fixes.
  8. Reporting. Findings converted into reports for management, auditors, and customers.

Supervised autonomy

Autonomous doesn’t mean uncontrolled. Humans remain in control of:

  • Defining and approving test scope
  • Setting rules of engagement
  • Approving aggressive or potentially disruptive testing
  • Reviewing sensitive findings
  • Accepting final pentest reports
  • Making risk decisions for production environments

Corgea automates the repetitive and technically complex parts. Humans own the risk decisions.

Continuous, not point-in-time

Traditional pentesting delivers a PDF report weeks after testing begins. By the time you read it, your application has changed.

Corgea supports both one-time and continuous autonomous pentesting. Retesting is automatic after remediation. Findings close the loop between discovery, fix, and verification in hours, not waiting for the next quarterly cycle.

Ready to Ditch Security Theater?

If you're tired of checkbox pentests:

Book a call: https://corgea.com/demo

Email us: sales@corgea.com

Previous Launches
We make it easy for companies fix vulnerable code by automating away 80% of the engineering work needed.
Empowering enterprises to secure sensitive data
Jobs at Corgea
San Francisco, CA, US / San Mateo, CA, US / Remote (CA, US)
$120K - $200K
0.50% - 2.00%
6+ years
JO / Remote (JO)
$20K - $65K
0.10% - 2.00%
6+ years
JO / Remote (JO)
$17K - $40K
0.10% - 2.00%
1+ years
San Francisco, CA, US / San Mateo, CA, US / Remote (CA, US)
$100K - $180K
0.25% - 2.00%
1+ years
San Francisco, CA, US / San Mateo, CA, US / Remote (US)
$120K - $220K
0.25% - 0.75%
6+ years
Corgea
Founded:2023
Batch:Summer 2023
Team Size:6
Status:
Active
Location:San Francisco
Primary Partner:Diana Hu