01
US businesses to watch in India
Every Uber has found its Ola. Every Toast has found its Posist.
We identify US businesses that may work in India, then show the evidence, competitors, and fastest test.
Why this exists
Every year, hundreds of software companies quietly prove a business model in one market. Stripe, then Razorpay. Uber, then Ola. DoorDash, then Swiggy. Those are the ones everyone remembers.
The ones that matter more are the thousands nobody's watching: $1M-$20M ARR companies with a working playbook, still nowhere near India.
Most teams either wait for these to become obvious on Twitter, or treat “find an opportunity” as a brainstorming exercise. We find the model, investigate the local customer, test the economics, and write down what would prove us wrong.
That process is what shows up in your inbox every week.
What you get each week
02
Every claim, sourced
Source and access date on every observation. Where we don't know something, the brief says so.03
Built to be disproven
Every brief ends with a quick test designed to rule it out.04
Clear scoring
See why each company ranks where it does. No hidden formula.What one week's research looks like
Hex Security
Hex Security launched in YC's Winter 2026 batch with AI agents that penetration-test web apps, APIs, and infrastructure continuously. The US pitch is simple: annual consultant pentests are stale by the time the PDF arrives. We mapped whether that thesis has room in India, or whether the category is already taken.
US signal
- Hex Security
- Founded 2026, San Francisco, ~10 people. Autonomous offensive security: continuous AI-driven pentesting vs. once-a-year manual engagements. Self-reported $1M ARR within eight weeks of founding; $125K disclosed pre-seed (YC standard check). [1][2][3]
- US competitive context
- Pentera and NodeZero already sell autonomous continuous pentesting with years of funding. Hex is a fast new entrant, not an uncontested category. [4]
India checked
Astra Security (New Delhi, founded 2018) sells AI-powered continuous pentesting to 800+ engineering teams across 70+ countries. $2.82M raised; customers include Mamaearth and Dream11. 45% of its client base is in the US. [5][6]
Astra is CERT-In empanelled, CREST-accredited, and a PCI Approved Scanning Vendor. RBI, SEBI, and IRDAI require regulated banks, NBFCs, insurers, and brokers to use empanelled auditors for mandated VAPT. That accreditation takes years. A 10-person US startup cannot sell into India's largest compliance-driven buyer segment on day one. [7][8]
Astra also names TAC Security and a long tail of empanelled VAPT firms as domestic competition. [5]
Where a wedge might still exist
- Engineering-led Indian SaaS startups selling into enterprise on SOC2 posture, not RBI/SEBI mandates
- GCCs of US/EU companies that inherit parent procurement and may prefer a YC-backed US vendor
- Teams wanting CI/CD-native retesting after every deploy, vs. traditional PTaaS dashboards
Limits on this brief
- Hex is ~8 weeks old at time of research. ARR and “$3B damages prevented” are self-reported, not independently verified. [4]
- Desktop research only. No calls with Indian CISOs yet.
- Post-Demo-Day round size and valuation were not confirmed in public sources.
Next test
Interview 10 CTOs or security leads at Indian SaaS companies closing US enterprise deals. Ask what they bought for continuous testing, whether CERT-In empanelment mattered, and whether they chose Astra, a US tool, or a manual VAPT vendor.
Drop if most say compliance credentials drove vendor choice, or they already use Astra and would not switch for deploy-time agentic testing alone.
Why it matters
Will it work in India?
Finding a promising US company is the easy part. Plenty of tools already do that.
We show whether the model survives India's regulation, distribution, and price sensitivity.
Start with a shortlist
We build the ranked shortlist before you have an idea to pitch.