Why We're Raising Our Seed Round: Building the Autonomous Future of Penetration Testing | Lorikeet Security Skip to main content
Back to Blog

Why We're Raising Our Seed Round: Building the Autonomous Future of Penetration Testing

Ryan Wilke, Founder & CEO Company & Vision 7 min read September 24, 2026

Today, software engineering teams are building and deploying code faster than at any point in history. AI-assisted IDEs, autonomous code generators, and continuous delivery pipelines have compressed release cycles from quarterly milestones into continuous hourly deployments. A single engineer today can ship what used to require an entire engineering department.

Yet the way companies test the security of that software remains stubbornly, dangerously obsolete.

In 2026, the standard enterprise penetration test still looks like it did in 2012: you contact a boutique consultancy, sign a Statement of Work with a six-week lead time, hand over staging credentials, and wait. Two weeks after the window closes, an encrypted 70-page PDF lands in your inbox. By that time, your engineers have merged three dozen pull requests, refactored core API endpoints, and invalidated half the report's recommendations.

Even worse: for the remaining 364 days of the year, you operate in the dark.

"We did not start Lorikeet Security to make PDF pentest reports 10% prettier. We started Lorikeet to replace the entire concept of the periodic pentest with continuous, autonomous offensive security intelligence."

The Shift from Periodic Audits to Continuous Offensive Proof

For years, the cybersecurity industry treated penetration testing as an annual compliance checkbox needed to satisfy auditors for SOC 2, ISO 27001, or PCI-DSS. But compliance is a floor, not a ceiling.

Adversaries do not wait for your annual testing window. They do not run scans once a year. When new zero-days break, or when a developer inadvertently pushes an unauthenticated microservice route with a broken object-level authorization (BOLA) flaw, attackers exploit it within hours.

To defend modern infrastructure, defensive security teams need an offensive partner that moves at the exact same speed as their development cycle. That requires two critical breakthroughs:

  1. Continuous PTaaS Telemetry: Moving penetration testing out of static PDFs and into a live, interactive software platform where findings are ingested in real time, mapped directly to engineering issue trackers (Jira, GitHub), and verified with 1-click on-demand retests.
  2. Autonomous Agentic Intelligence: Deploying autonomous offensive agents that don't just dump noisy regex matches or vulnerability scanner alerts, but actively crawl complex SPAs, construct realistic attack graphs, chain multi-step exploits, and produce deterministic proof-of-concept (PoC) code with zero false positives.
364
Days of blind spots eliminated
< 4h
Autonomous assessment turnaround
0
False positives tolerated

What We've Built: Talon & Lory AI

Over the past two years, we built and battle-tested the infrastructure to make this vision reality:

The Talon Platform

Talon is our unified PTaaS (Penetration Testing as a Service) console. It connects security leadership, developers, and compliance auditors in one collaborative hub. Instead of parsing static spreadsheets, engineering teams receive streaming vulnerability alerts, reproduce findings with verified proof-of-concept scripts, track remediation SLAs, and generate instant auditor-ready attestations.

Lory AI Pentester

Lory is our autonomous offensive security intelligence. Powered by a multi-tier agent architecture, Lory conducts zero-token perimeter reconnaissance, executes headless Chromium browser exploration against modern single-page applications, maps API endpoints, and chains complex attack paths. Unlike conventional scanners that flood engineers with theoretical noise, Lory verifies every vulnerability before reporting it, outputting real reproduction code in Python, Bash, and HTML.

Lory Mesh & Zero-Knowledge Execution

Real security doesn't stop at the external IP. With Lory Mesh, our WireGuard-based distributed testing fabric, Lory safely conducts internal network penetration testing, Active Directory privilege escalation analysis, and Kubernetes security audits inside private client VPCs—without customer credentials or proprietary intellectual property ever leaving their perimeter.

Customer Traction & Proven Product-Market Fit

Up to this point, Lorikeet Security has operated with deliberate capital discipline. We grew organically through customer revenue, word-of-mouth among CTOs and CISOs, and deep partnerships with leading compliance audit firms including Insight Assurance, Avantage Group, and H&M.

Our customers range from fast-scaling VC-backed startups needing rapid, audit-ready compliance attestations to enterprise organizations managing complex multi-cloud perimeters. They rely on Talon and Lory because we eliminate friction:

  • No six-week booking lags: Engagements dispatch instantly on-demand.
  • No developer fatigue: Every finding includes exact line-level remediation code and reproducible exploit harnesses.
  • 1-click re-testing: Developers deploy a patch and verify the fix immediately with no change orders or re-test surcharges.

In the last few months, demand for Lory AI and the Talon Platform has surged past our self-funded capacity. Engineering teams running AI coding agents are producing code at unprecedented rates, and their security teams are overwhelmed trying to audit it.

The window to define the category of autonomous offensive cybersecurity is open now. That is why we are raising our Seed round.

Where the Seed Capital Goes

We view fundraising as fuel for product velocity, not vanity. We are raising our Seed round to accelerate three foundational pillars:

1. Deepening Lory's Autonomous Reasoning & Exploit Chaining

LLMs alone cannot pentest. They hallucinate endpoints, generate syntax errors, and fail to navigate multi-step authentication state. Lory succeeds because we combine state-of-the-art foundation models with deterministic headless fuzzers, OpenAPI contract validators, and real-time AST parsers. We will invest heavily in expanding Lory's capability to discover deep business logic flaws—such as state machine race conditions, privilege escalation chains across microservices, and complex multi-tenant boundary escapes.

2. Enterprise Mesh & Ecosystem Integrations

Security tools fail when they create silos. We will expand Lory Mesh into a frictionless enterprise deployment model: native GitHub Actions and GitLab CI integrations that trigger scoped autonomous pentests on pull requests touching sensitive auth files, automated Jira ticket synchronization with bi-directional status updates, and native cloud security connectors across AWS, Azure, and Google Cloud.

3. Assembling an Elite Team of Offensive Researchers & AI Engineers

Building an autonomous hacker requires engineers who understand both deep offensive security tradecraft and scalable distributed systems. We are expanding our core team with world-class red team operators, vulnerability researchers, and systems architects who are passionate about building defensive technology that operates with attacker-level creativity.


The Road Ahead

The next decade of cybersecurity will not be won with static PDF reports or passive dashboards that display red alerts without solutions. It will be won by autonomous, active systems that continuously challenge your infrastructure, verify your resilience, and empower developers to fix issues before attackers can find them.

We are building the platform that makes that reality standard across the software industry.

Ryan Wilke

Ryan Wilke

Founder & CEO, Lorikeet Security

Join Us in Building the Future of Offensive Security

Whether you are an investor looking to partner on our seed round, an engineering leader seeking continuous offensive security assurance, or an offensive researcher ready to build the future of AI pentesting—we would love to speak with you.

263 views
Link copied!
Lorikeet Security

Lorikeet Security Team

Penetration Testing & Cybersecurity Consulting

Lorikeet Security helps modern engineering teams ship safer software. Our work spans web applications, APIs, cloud infrastructure, and AI-generated codebases — and everything we publish here comes from patterns we see in real client engagements.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!