Fleuret AI, a Paris based cybersecurity startup that uses agentic artificial intelligence to automate penetration testing, announced a 4 million euro pre seed financing on October 5, 2026. The round was led by RAISE Ventures and included Auriga Cyber Ventures, Wind Capital, Better Angle and a group of European cybersecurity business angels.
What Fleuret builds
The company’s platform runs autonomous attack agents that map an organisation’s web applications, APIs and infrastructure, attempt to exploit discovered vulnerabilities, and produce proof of compromise and audit ready reports. Fleuret describes its product as moving penetration testing from a sparse, manual snapshot into a continuous, automated security process that also integrates remediation tracking and automatic re testing after fixes.
Fleuret’s public announcement names two agents, Emile and Champollion, which perform reconnaissance, exploitation, and evidence collection. The startup positions those capabilities as a way to keep pace with rapidly changing attack surfaces, where code deployments and configuration changes can make a single, periodic pentest obsolete within days.
Why investors backed it now
Investors cited a growing market need for automating offensive security as organisations face more sophisticated, AI assisted attacks and tighter compliance regimes. French and European regulations such as NIS2 and DORA are increasing the number of organisations required to demonstrate ongoing cyber resilience, creating demand for repeated, auditable testing rather than one off audits.
RAISE Ventures and participating backers said Fleuret’s combination of traditional pentesting expertise and agentic AI models could scale offensive security to more customers, at lower cost and with more frequent verification. The founders say the product is already running in production for several customers, and the round will be used to hire engineers, expand AI and product work, and accelerate go to market across Europe.
Sovereignty and regulation as a feature
Fleuret stresses its European hosting and data residency as a selling point for regulated sectors. The startup frames that design choice as a response to European concerns about data sovereignty, and as a practical compliance argument for firms subject to EU cybersecurity rules. Telecom Paris highlighted that many of Fleuret’s first customers are customers that must meet NIS2 and ISO 27001 obligations, and that the startup aims to map findings directly to compliance frameworks to help customers demonstrate remediation to regulators and auditors.
That regulatory backdrop is material. Under NIS2, thousands of entities across critical sectors must strengthen security and show evidence of testing and mitigation. Fleuret says the timing of its funding reflects the coming wave of compliance deadlines and controls that will push organisations to adopt more continuous testing models.
Market and technical tradeoffs
Automating pentests with agentic AI brings potential benefits and risks. On the upside, continuous automated testing can catch regressions quickly, reduce blind spots between infrequent audits, and produce repeatable evidence for compliance. For customers that cannot afford regular manual engagements, automation lowers the barrier to regular security verification.
On the other hand, security practitioners will scrutinise the accuracy, safety and explainability of agentic tools. False positives and false negatives in vulnerability discovery have operational and business consequences. Producing exploit proofs that are reliable, legally acceptable for compliance, and safe to run against production systems is also a non trivial engineering challenge. Fleuret emphasizes integration with existing developer workflows, zero false positive tolerance, and repeatable proof of compromise as central design priorities.
Why this matters for France and Europe
The round illustrates two parallel trends in the French tech ecosystem. First, continued investor appetite for AI enabled security startups, especially those that tie product claims to practical compliance pain points and European data governance preferences. Second, a push to build cybersecurity capabilities inside Europe rather than relying solely on non European vendors, driven by sovereignty concerns and regulatory changes.
Fleuret’s founders are alumni of French engineering schools and count early enterprise customers and security industry operators among their angel backers. The company will use the new capital for hiring and product development, while aiming to expand sales into larger enterprise and regulated customers across Europe.
Outlook
Whether agentic pentesting becomes a mainstream complement to manual red team work will depend on real world outcomes, including reliability under varied production environments, the ability to prioritise and reduce noise, and rigorous safety controls to prevent dangerous automated actions. For now, Fleuret has captured investor attention by tying agentic AI to a concrete compliance cycle, and by arguing that continuous offensive testing can reduce exposure windows at scale.
The announcement joins a string of French AI and cybersecurity stories this year that show founders and investors are betting on Europe focused, regulation aware AI tools rather than purely export oriented products. For security teams watching the market, the development is a concrete example of how AI is being applied to automate traditionally manual security practices, and how regulation and data sovereignty are shaping product roadmaps.




