Public dispute over overlapping CVE disclosures and alleged backdating/attribution issues; Gecko published a correction post and BleepingComputer reported the controversy.
SourceThe AI Security Engineer to Find and Fix Vulnerabilities
Public company, workplace, funding, and market signals
Updated Jul 29, 2026
Gecko Security is an AI-native application security platform that acts like an "AI security engineer": it analyzes code, logic, infrastructure, and documentation to find real exploitable vulnerabilities, verify exploitability, and generate fixes, with a strong focus on business-logic flaws and multi-step attack chains [official site; YC]. Public sources conflict on headquarters: LinkedIn says San Francisco, YC says London, and the privacy policy lists a Sarasota mailing address.
Primary product
AI Security Engineer / AI SAST for finding and fixing exploitable vulnerabilities
Founded
2024
Headquarters
San Francisco, California, United States (LinkedIn company page; public sources also mention London and a Sarasota mailing address)
Team size
1-10 employees
Industry
Computer and Network Security
Sub-industry
0 jobs at Gecko Security
Check back later for new openings
AI application security / AI SAST / vulnerability management
Offices
Business model
Stage
Seed / YC-backed
Total raised
$500K
Latest round
Seed · Sep 2024
Latest amount
$500K
Sep 2024 · Y Combinator
Investors
Mission-driven, technical, security-heavy team with founders from intelligence/cyber backgrounds. Public messaging emphasizes accuracy, low false positives, exploit verification, fast remediation, and private/self-hosted deployments over noisy pattern-matching scanners.
Pricing
Freemium SaaS with Free, Pro ($100/month), and custom Enterprise annual contracts
Differentiators
Technology
Competitors
Estimated revenue
$92K-$507K estimated ARR range (third-party estimate; other public profiles vary widely)
Estimated monthly visits
2.2K
Traffic estimate as of Apr 2026
Public dispute over overlapping CVE disclosures and alleged backdating/attribution issues; Gecko published a correction post and BleepingComputer reported the controversy.
SourceResilient Cyber · Jul 2026
Interview discussing Gecko’s reasoning across code, architecture, and runtime, and how the product changes AppSec prioritization and remediation.
Gecko Security blog · Oct 2025
Gecko says it corrected attributions on several CVE disclosures after learning some findings had already been reported elsewhere.
BleepingComputer · Oct 2025
Reports the public dispute between Gecko Security and FuzzingLabs over overlapping vulnerability disclosures and backdating accusations.
Gecko Security blog · Jul 2025
Official research post claiming 30+ previously unknown 0-days, describing the company’s compiler-accurate indexer, threat-modeling workflow, and example CVEs.
VentureBeat · Apr 2025
Profile of CEO Jeevan Jutla and Gecko Security’s AI-driven approach to finding subtle flaws and multi-step attack paths; notes early traction and YC backing.