Invest1 publisher2 min readPublished
Hackuity raises $19M to help security teams prioritize which vulnerabilities to fix first
Forgepoint led the Lyon company's round, taking total funding to $38 million, under half what each of its two Palo Alto rivals has raised, into a market where 99% of one AI preview's 10,000 critical findings sat unpatched.
The Investor · Invest desk

What happened
- Forgepoint Capital International led a $19 million round in the Lyon vulnerability management company Hackuity, with earlier backers Bright Pixel, Bpifrance and Seventure Partners taking part.
- Anthropic let a small group of partners run a preview of its Mythos model against their own codebases in April 2026, and they turned up more than 10,000 high- or critical-severity flaws, 99% of them unpatched.
- Hackuity's platform holds 1 billion findings across 2 million assets for more than 6,000 users, including the Fortune 500 clients ENGIE and BPCE.
- The company employs more than 40 people, most in Lyon, and runs a go-to-market office in Singapore that Samson set up after living in the region for six years.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- constraint A prioritisation vendor sells into a queue its customers cannot clear: with 99% of the preview findings still open, the binding limit is engineer hours and change windows, so better ranking only converts into fewer exploited flaws where remediation capacity already exists.
- decision Anyone switching on model-based code review has to fund the downstream fix work in the same budget cycle, because discovery is cheap to turn on and a 3x remediation gain is bought separately.
- contradiction Reading the round as AI-created demand sits awkwardly against the company's own account, in which Samson calls the model output a validation of a backlog he was already handling by hand in Excel.
- exposure The 10,000-flaw number reaches the market through the fundraising company's chief revenue officer in one publisher's account, so an investor underwriting demand on it is underwriting unnamed partner codebases.
Take the discovery number at face value and the delivery problem gets harder. More than 10,000 high- or critical-severity flaws came out of a small set of partner codebases in two months, or about 5,000 a month [5][6][1], and 99% of them were still unpatched [5]. Hackuity says its platform makes remediation three times faster [12]. Three times faster keeps pace with 5,000 new criticals a month only if those teams were already closing about 1,667 of them a month before the preview [3].
Samson does not treat the Anthropic result as news [8]. "That is a validation; it amplifies what was already there," the co-founder and chief revenue officer told Tech Funding News [7]. He and chief executive Patrick Ragaru were both managing directors at a cybersecurity services company that Orange later merged into Orange Cyberdefense [9], and Samson said of his time there that "SOC services were mature back then, but vulnerability management was not" [10]. Orange Cyberdefense is now a go-to-market partner [14].
One billion findings across 2 million assets works out at 500 findings per asset [13][5]. Hackuity says its scoring cuts critical alerts to 0.01% [12]. Applied to that billion, the filtered list still runs to 100,000 items [6]. Those are two separate company figures, and multiplying one by the other is not a claim Hackuity made.
On money the comparison is unflattering. Seemplicity has raised $80 million in total and ArmorCode $81 million, both out of Palo Alto [17][18], against Hackuity's $38 million, which is under half of either [3][4]. The $19 million funds connectors and 40-odd staff in Lyon plus one sales office in Singapore [19]; the two rivals have $161 million between them [8]. At that ratio a US field organisation stays out of reach. What it sells against the big platforms is neutrality: Samson counts fewer than 10 specialists worldwide [15] and said that "if a company comes from the scanner sector, it is difficult for them to remain neutral, since they generally give priority to the noise that they generate" [16].
The clearest route to being wrong runs through the same models. If the systems that surface 10,000 findings also produce the patches, the queue Hackuity ranks stops being the constraint, and 130 connectors [11] matter less than a scanner vendor's installed base. The 10,000 figure also arrives through the fundraising company's own chief revenue officer in a single publication. That account named no partner codebases and put no valuation on the round [20]. While the fix work stays human, the ranking layer prices well, and the one fix rate in the account is 1% in two months [9].
What to watch
- Whether Anthropic or its preview partners publish the Mythos results with named codebases and patch rates. That is the only way the 10,000 figure stops being a vendor's retelling.
- Whether a scanner or suite vendor buys one of the fewer than 10 specialists Samson counts. Such a deal would settle whether neutrality is a product or an acquisition target.
- Disclosure of Hackuity's revenue or the round's valuation: until one of those lands, the $38 million cannot be priced against $161 million of rival capital.