Jobs with Startups
JobsStartupsInvestorsMCP
Startups

Gecko Security

Gecko Security logo

Gecko Security

The AI Security Engineer to Find and Fix Vulnerabilities

gecko.security
HQ: San Francisco, CA, USA
1-10
B2B

Company research

Public company, workplace, funding, and market signals

Updated Jul 29, 2026

Overview

Gecko Security is an AI-native application security platform that acts like an "AI security engineer": it analyzes code, logic, infrastructure, and documentation to find real exploitable vulnerabilities, verify exploitability, and generate fixes, with a strong focus on business-logic flaws and multi-step attack chains [official site; YC]. Public sources conflict on headquarters: LinkedIn says San Francisco, YC says London, and the privacy policy lists a Sarasota mailing address.

Primary product

AI Security Engineer / AI SAST for finding and fixing exploitable vulnerabilities

Founded

2024

Headquarters

San Francisco, California, United States (LinkedIn company page; public sources also mention London and a Sarasota mailing address)

Team size

1-10 employees

Industry

Computer and Network Security

Sub-industry

AI application security / AI SAST / vulnerability management

Offices

London, United Kingdom (YC company profile)
Sarasota, Florida, United States (privacy-policy mailing address)

Business model

SaaS subscription
free tier
pro tier
enterprise licensing
self-hosted / on-prem enterprise deployments

Funding

Stage

Seed / YC-backed

Total raised

$500K

Latest round

Seed · Sep 2024

Latest amount

$500K

Seed

Sep 2024 · Y Combinator

$500K

People & investors

Leadership

Jeevan Jutla

CEO & Co-Founder

Artemiy Malyshau

CTO & Co-Founder

Investors

Chris Howard
EWOR
Garage VC
Liquid 2
Maiora Ventures
Rebel Fund
Ritual Capital
Y Combinator
Z Fellows

Work & culture

Mission-driven, technical, security-heavy team with founders from intelligence/cyber backgrounds. Public messaging emphasizes accuracy, low false positives, exploit verification, fast remediation, and private/self-hosted deployments over noisy pattern-matching scanners.

Product & market

Pricing

Freemium SaaS with Free, Pro ($100/month), and custom Enterprise annual contracts

Differentiators

  • —Finds business-logic flaws and multi-step attack chains rather than only pattern-matching bugs
  • —Verifies exploitability before flagging issues
  • —Provides one-click autofix / working fixes
  • —Compiler-accurate indexing preserves code semantics
  • —Lower false positives than traditional static analysis
  • —Supports private AI models and self-hosted deployments
  • —Scans code, infrastructure, and documentation together

Technology

LLMs
multi-agent systems
compiler-accurate indexer
semantic name bindings
language-server-protocol-like graph navigation
fuzzers
symbolic executors
static analysis
GitHub integration
GitLab integration
CI/CD scanning
PR/MR automation
Jira integration
Linear integration
Slack integration
ClickUp integration
Shortcut integration
private AI models
self-hosted deployment
on-prem / private cloud

Competitors

Traditional SAST tools
Static analysis scanners
Manual penetration testing services
Legacy AppSec platforms
Pattern-matching vulnerability scanners

Scale & contact

Estimated revenue

$92K-$507K estimated ARR range (third-party estimate; other public profiles vary widely)

Estimated monthly visits

2.2K

Traffic estimate as of Apr 2026

gecko@gecko.security+1 202-548-8889

Signals & risks

Other
Oct 2025

Public dispute over overlapping CVE disclosures and alleged backdating/attribution issues; Gecko published a correction post and BleepingComputer reported the controversy.

Source

Latest news

Building an AI AppSec Engineer

Resilient Cyber · Jul 2026

Interview discussing Gecko’s reasoning across code, architecture, and runtime, and how the product changes AppSec prioritization and remediation.

Updating the Attributions on Some Of The CVEs We Found

Gecko Security blog · Oct 2025

Gecko says it corrected attributions on several CVE disclosures after learning some findings had already been reported elsewhere.

Security firms dispute credit for overlapping CVE reports

BleepingComputer · Oct 2025

Reports the public dispute between Gecko Security and FuzzingLabs over overlapping vulnerability disclosures and backdating accusations.

How Gecko Discovered 30 0-Day Vulnerabilities No AppSec Tool Found

Gecko Security blog · Jul 2025

Official research post claiming 30+ previously unknown 0-days, describing the company’s compiler-accurate indexer, threat-modeling workflow, and example CVEs.

How Jeevan Jutla built an AI that thinks like a hacker (and why that’s a good thing)

VentureBeat · Apr 2025

Profile of CEO Jeevan Jutla and Gecko Security’s AI-driven approach to finding subtle flaws and multi-step attack paths; notes early traction and YC backing.

Demo bookingDocsGitHub organizationHomepageLinkedIn company pageResearch blogTrust CenterX / TwitterYC company profileYC launch post
SourcesOfficial websiteDocsResearch blog0-day vulnerability writeupPrivacy policyYC company profileYC launch postGitHub organizationLinkedIn company pageJeevan Jutla LinkedInArtemiy Malyshau LinkedInVentureBeat profileBleepingComputer dispute articleAIBase traffic pageStartupHub revenue estimateProspeo company pageCB Insights company pagePitchBook company profile

Jobs and careers at Gecko Security

0 jobs at Gecko Security

No open positions

Check back later for new openings

Explore startup hiring

Startup Hiring PulseBrowse all startup jobsJobs at Y Combinator startupsJobs at AI startupsJobs at early-stage startupsJobs at venture-backed startupsB2B startup jobs

Jobs with Startups © 2026

Browse jobsMCP guideAboutPowered by Supabase