Hex Security → India
Score49 / 100
ConfidenceSpeculative
EvidenceHypothesis
Researched2026-07-26
Score breakdown
YC W26, self-reported $1M ARR in 8 weeks; only $125K disclosed [1][2][3]
RBI/SEBI VAPT mandates; largest buyers are regulated BFSI [7][8]
Astra (800+ teams, CERT-In empanelled) plus TAC Security domestically [5]
CERT-In, CREST, PCI ASV credentials take years; blocks regulated sales
AI pentesting tailwind; Pentera and NodeZero already funded in US [4]
~10 people, pre-seed; wedge limited to SaaS startups and GCCs
Composite weights from our opportunity model (30 / 20 / 20 / 15 / 10 / 5). Whitespace and localization drag the score despite strong US traction signals.
US source traction
Hex Security (San Francisco, founded 2026, ~10 people). AI agents for continuous penetration testing of web apps, APIs, and infrastructure. Self-reported $1M ARR within eight weeks of founding. $125K disclosed pre-seed (YC standard check). One of the most fought-over companies at W26 Demo Day. [1][2][3]
India competitor map
Read: Direct overlap. CERT-In empanelled, CREST, PCI ASV. Mamaearth, Dream11.
Read: Named by Astra as domestic competitor; adds field density.
Read: Category already proven globally before Hex entered.
Localization checklist
Gaps Hex still needs for regulated India sales.
- CERT-In empanelment
For RBI / SEBI / IRDAI-regulated VAPT buyers
- Audit-ready reporting
Mapped to Indian regulator clauses
- CI/CD and deploy hooks
Integrations for Indian SaaS stacks
- India pricing
Single-product startups vs. enterprise PTaaS contracts
Coverage
Checked
- US company profile
Funding from YC, PitchBook, Crunchbase
- India competitor map
Astra, TAC, and empanelled VAPT firms
- Regulatory buyers
RBI, SEBI, and CERT-In requirements
- US category competitors
Pentera and NodeZero
Not checked
- Buyer interviews
Indian CISO or security-lead conversations
- ARR verification
Independent check of Hex $1M ARR claim
- Post-Demo-Day round
Size and valuation still undisclosed
- Spend and ERP vendors
India spend-management and ERP vendor map
Falsifying experiment
Test
Interview 10 CTOs or security leads at Indian SaaS companies closing US enterprise deals. Ask what they bought for continuous testing, whether CERT-In empanelment mattered, and whether they chose Astra, a US tool, or a manual VAPT vendor.
Kill signal
Most buyers say compliance credentials drove vendor choice, or they already use Astra and would not switch for deploy-time agentic testing alone.
Excerpt · full brief includes PDF export and linked evidence cards