Build1 publisher3 min readPublished
FAZE Security raises $6M to keep rerunning the exploit after the fix ships
Formerly CYTRIX, the company says more than 25 agents exploit, rank, route and then retest customer systems continuously. The accuracy and growth figures are self-reported, and the 0.1% false-positive rate comes without a sample or a period.
The Engineer · Build desk

What happened
- FAZE Security left stealth on Friday, 11 September with a $6 million seed announced through PR Newswire, led by New Era Capital Partners with Lockstep VC participating.
- The platform, sold previously as CYTRIX, has agents exploit vulnerabilities in applications, APIs and cloud environments, rank findings by demonstrated business impact, route the fix to an owner and then rerun the exploit.
- Its homepage shows a 0.1% false-positive rate, and the sample, testing methodology and measurement period behind that number are not published.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- capability A finding that ships with a reproduced exploit lets an engineering manager rank remediation by what an attacker actually achieved, instead of by a scanner's severity field.
- exposure Standing authorization to exploit continuously puts availability risk inside the customer estate, so the deterministic boundary rules are the document that decides whether production credentials get issued.
- constraint With no valuation on the round and no starting revenue behind the 20X, a buyer weighing this against an annual penetration test line item has to run diligence on references it sources itself.
The fourth step is the one a buyer can check. FAZE's agents attempt an exploit, rank the finding by demonstrated business impact, route the fix to an owner, then run the same attack again after the fix lands [3]. A retest returns one of two answers: the exploit still works, or it does not.
That also sets the hard requirement. Re-exploitation verifies something only if the retest reproduces the preconditions of the first attempt, which means the same authenticated session, the same account state and the same data the original chain needed. Where the first exploit ran through a seeded record or a token minted mid-run, the retest has to mint them again.
The accuracy claims read differently in that light. FAZE says customers report close to zero false positives and more than 50% faster mean time to remediation than scanners and point-in-time penetration tests [10], and its homepage shows a 0.1% false-positive rate [11]. A finding that arrives with a working exploit attached is close to true by construction, so a very low false-positive rate is what the design should produce. To transfer that number to your own environment you would need the denominator and the population: findings out of what, across how many applications, over what window. FAZE has not published the sample, the testing methodology or the measurement period [11]. Runtimewire's account of the launch notes that an autonomous system which creates another queue of weak findings just moves the bottleneck [18].
The growth figure has the same shape. FAZE says it has 50 enterprise customers, several of them Fortune 500, and that annual recurring revenue grew roughly 20X in 18 months [6]. Twenty times over eighteen months works out to about 18% compounded per month [17]. Runtimewire notes that the multiple comes without the starting or ending revenue needed to measure the scale behind it [7], and with no revenue base against 50 customers, contract value per account cannot be worked out. The company's public customer stories name Hippo Insurance, Cellebrite and OurCrowd [9].
The agent count is the least useful number in the launch. FAZE describes a swarm of more than 25 AI agents that plan attacks, select tools, analyze evidence and score severity, with deterministic controls providing boundaries for operations inside customer environments [12]. Agents are easy to count. The boundary rules are what a security team will ask to read before it hands over production credentials, because the failure mode of a continuous exploitation platform is an outage it caused itself.
On the team, Avitan is the CTO, and Lockstep's profile of the founders describes her as a cybersecurity researcher, developer and penetration tester with over 14 years of experience who has taught at the Technion, disclosed vulnerabilities in open-source software and earned the Offensive Security Web Expert certification [14]. Shirazi, the CEO, co-founded EasySend, whose founders wrote that they had raised $71.5 million by late 2021 [13]. Vaknin, the COO, ran Ness' outsourcing division, which Lockstep says exceeded $200 million [15]. Cohen, the CBO, is a former lieutenant colonel in the Israel Defense Forces special forces [16].
Runtimewire's read of the sale is that adoption in large regulated organizations depends on integration and auditability as much as technical performance [19]. The retest is the auditable part. Everything else in the launch is a number FAZE reported about itself.
What to watch
- A published methodology behind the 0.1% figure: sample size, application population and measurement window.
- A starting ARR number or a round valuation, either of which would put scale behind the 20X claim.
- A named customer stating on the record that FAZE's loop replaced an annual penetration test engagement.