Skip to content

Invest1 publisher2 min readPublished

Bynario, seven-person Milan security startup, raises EUR2.1m pre-seed led by 360 Capital

The EUR2.1m pre-seed is roughly 0.16% of what 360 Capital and PranaVentures manage between them - a check sized to option a research method, before Bynario has a finished security platform to bet on.

The Investor · Invest desk

Photograph accompanying Bynario, seven-person Milan security startup, raises EUR2.1m pre-seed led by 360 Capital
Photo: techfundingnews.com

What happened

  • Bynario, founded in 2025 by Alfredo Pesoli, Giancarlo Russo and Lorenzo Cavallaro, raised EUR2.1m in pre-seed funding led by 360 Capital Partners, with PranaVentures also participating.
  • The company's platform, Atlas, scans code, cloud infrastructure and software supply chains for exploitable flaws.
  • The Financial Times reported in August that Apple began capping how many vulnerability reports each researcher could submit after fabricated AI-generated findings overwhelmed its review team.
  • Bynario's own macOS Screen Sharing report sat in that backlog before Apple reviewed and patched it, and Pesoli told the FT the flaw could have fetched up to $200,000 on the black market.
  • The money goes to engineering hires and enterprise build-out, with no hiring targets disclosed.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • constraint A pre-seed of this size funds research depth rather than sales coverage, so distribution stays the binding limit while three adjacent AI security companies have raised $78m between them.
  • decision Buyers now have to decide whether an autonomous agent may write fixes into production code and cloud configuration, and a refusal leaves Bynario selling prioritisation instead of the full loop it is building.
  • precedent If per-researcher submission quotas spread past Apple, proving exploitability before filing becomes the entry ticket to a bounty programme rather than a vendor differentiator.
  • cost Apple's cap makes honest researchers pay for the volume of fabricated reports, since a real macOS flaw waited in a rationed queue alongside the slop that caused the rationing.

Seven people sharing EUR2.1m is about EUR300,000 a head [1][2][1], which pays for research salaries and not much else, and the ratio against the capital standing behind it is starker: 360 Capital manages more than EUR700m [10], the platform PranaVentures formed by merging with P101 SGR oversees more than EUR600m [11], and the whole round is roughly 0.16% of the EUR1.3bn between them [2]. On those round numbers 360 has averaged something near EUR9m per company across its 80-plus holdings [10][5], one of which is Equixly, another Italian cybersecurity startup [10]. This is an option written on three founders and a method, small enough that a wrong bet would barely register in a fund report.

The pitch is subtraction. Most scanners flag every theoretical weakness; Atlas is built to confirm which flaws are actually reachable in a given customer environment before prioritising and helping close them [5], so what is being sold is partly a promise about what the customer will not be sent. Pesoli's own argument is that cheap AI lowers the cost of vulnerability research [17], and it lowers it symmetrically for the person fabricating findings and the person finding real ones, which is how a review queue ends up full of what researchers call AI slop [6]. A vendor whose design goal is fewer, provable reports is selling reviewer hours back.

Escape's $18m in March, Qevlar AI's $30m the same month and Mindgard's $30m in August come to $78m [13][14][15][3] of disclosed capital aimed at neighbouring problems, and by techfundingnews's reading none of the three runs the whole loop from discovery through proof of exploitability to remediation [18]. That gap is either a moat or a line item on a larger vendor's roadmap, and EUR2.1m does not buy the distribution that settles which. 360 partner Cesare Maifredi frames the requirement as autonomous discovery, validation, prioritisation and remediation [16], which is also a description of four separable products, any one of which an existing scanner can bolt on and sell to accounts it already has.

The weakest leg is the breach-vector story. Techfundingnews puts exploited vulnerabilities at 31% of breaches, ahead of stolen credentials, and names no study behind the figure [12]; on that same number, 69% of breaches begin with something other than an exploit [4], so the leader of this league table holds under a third of the field. What the evidence does carry is narrower and more useful: a company rationing its review queue by quota is a buyer putting a price on noise [6], and at this cheque size Bynario only has to be right about that price.

What to watch

  • Whether Bynario names enterprise design partners or hiring numbers, neither of which was disclosed with the round.
  • Whether bounty programmes beyond Apple start capping per-researcher submissions.
  • The size of Bynario's next round against the $18m to $30m Escape, Qevlar AI and Mindgard raised.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories