aid: hex-security name: Hex Security description: >- Hex Security is a Y Combinator (W26) security startup building autonomous AI agents that perform continuous penetration testing against web applications, APIs, and infrastructure. Instead of point-in-time annual pentests, Hex's agents probe systems around the clock — chaining exploits together, validating each finding with a working proof-of-concept, and delivering triaged, reproducible results with no false positives. The product surfaces high-severity issues such as SQL injection, broken access control / IDOR, authentication bypass, and unauthenticated remote code execution. Founded by Ahmad Khan, Huzaifa Ahmad, and Prama Yudhistira. As of this profile Hex Security is pre-public-API: it operates a marketing site (hex.co) and a product application (app.hex.co) but does not yet publish a developer portal, OpenAPI definition, or public API surface. url: https://raw.githubusercontent.com/api-evangelist/hex-security/refs/heads/main/apis.yml accessModel: pricing: unknown onboarding: unknown trial: false try_now: false public: false label: Unknown confidence: low source: [] generated: '2026-07-22' method: derived image: https://framerusercontent.com/images/Hioh4DamknpQbzzIX7Z0Xt1PAk0.webp x-type: company x-source: vc-portfolio x-backed-by: - y-combinator x-yc-batch: W26 x-tier: stub x-tier-reason: portfolio-lead specificationVersion: '0.20' created: '2026-07-17' modified: '2026-07-19' tags: - Company - Security - Penetration Testing - Application Security - API Security - Vulnerability Management - Artificial Intelligence - AI Agents - DevSecOps - Y Combinator apis: [] common: - type: Website url: https://hex.co - type: Login url: https://app.hex.co/login - type: DomainSecurity url: security/hex-security-domain-security.yml maintainers: - FN: Kin Lane email: kin@apievangelist.com - FN: APIs.json email: info@apis.io x-enrichment: date: '2026-07-19' status: backfilled pass: local-v1 note: backfilled from .gitignore signal + verified work evidence