Back to directory
AI & ML · AI Agents

Mindfort

Autonomous security agents that prove exploits — and ship fixes

co-founder and ceo @mindfort (YC X25) - building autonomous security agents
Los Angeles, CA625 followers
TLVC Rating

Just an overly explanatory video with no real story behind it. No hook.

Community Rating
No ratings yet
Your rating
Sign in to rate this launch.

About

Mindfort deploys autonomous AI agents that continuously find, validate, and patch security vulnerabilities in web applications, operating as a 24/7 AI red team for engineering and security teams at startups and public companies. The launch marks MindFort's $3M+ seed announcement , which founder Brandon Veiseh says will fund infrastructure to meet growing demand and expand the team into new security verticals. It arrives as pressure mounts on companies to prepare defenses for AI-driven attacks, with quarterly manual pentests and noisy traditional scanners struggling to keep pace. Teams point Mindfort at a live web app and thousands of agents run in parallel to surface exploitable vulnerabilities, then ship automated pull requests to fix them. The platform can run continuously, on a schedule, or inside CI, and its API exposes the same agents for tasks like triaging bug reports, validating findings, and running targeted security reviews. This launch also introduces Hill Climb, a recursive learning system that lets agents consolidate memories across runs so they become more efficient at finding real exploits over time, which addresses the false-positive problem where traditional scanners generate 30-50% false positives that typically drown engineering teams in noise. Mindfort is a Y Combinator X25 company founded in 2025 by Akul Gupta and Brandon Veiseh , based in Los Angeles, with Sam Akhavan rounding out the founding team. Veiseh leads as CEO and Gupta as CTO, both with backgrounds spanning AI and cybersecurity. Soma Capital and Y Combinator are among the backers supporting the company's push to turn continuous, autonomous pentesting into a default part of the software delivery pipeline.
Tags
<500KAI agentSeedB2BDemoUSFunding announcementFounder-led
Comments (7)
Sign in to join the discussion.
Priya Ravindran4/23/2026

Proving the exploit before shipping the fix is the correct order of operations. Half of security tooling skips step one and calls it 'detection'.

latentsloth4/23/2026

Every pentest firm charging by the hour just felt a cold breeze.

Kosta Zervas4/23/2026

The landing page video pacing is weirdly good for a security launch. Most infra companies still think a terminal gif counts as a hero asset.

Mingfei Wu4/23/2026

How autonomous are we talking when the agent hits a finding that needs codebase context it doesn't have? Curious where the human loop actually sits.

Dario Okafor4/23/2026

Autonomous agents plus compute-heavy exploit generation sounds like a gross margin conversation I'd want to have before scaling the team.

Hadil Qureshi4/23/2026

Tweet copy is three bullets and a raise announcement with zero drama. Respect for not turning it into a 14-post thread.

Venkat Ramanathan4/23/2026

The hard part isn't finding the vuln, it's the PR not breaking the build. Curious what the merge rate looks like on real repos.