As we continue to rapidly grow, naturally our growth engine is also skyrocketing! We want to give a huge welcome to Mitch Mershon, Anna Nabiullina, and Austin Tobey, who are joining us to scale our product marketing and go-to-market growth 🚀 We have got lots of incredibly exciting product updates coming up over the next couple of months, and these three are going to help us make sure you know about everything we're cooking up 👀 Security is a frontline operation, now more than ever, and we're excited to have them on board to ensure security teams feel heard, their pains are truly addressed, and no vulnerability is left to escape 😉
Escape
Computer and Network Security
San Francisco, California 8,110 followers
Escape automates the full offensive security lifecycle, multiplying the impact of every security engineer tenfold.
About us
Escape automates the full offensive security lifecycle, multiplying the impact of every security engineer tenfold. Our key products: 1. Attack Surface Management: Discover and validate exposure of modern applications, APIs, and infrastructure from code to cloud. 2. Business-logic-aware DAST: Replace legacy DAST with business-logic-aware testing that improves over time and helps your team remediate real, exploitable vulnerabilities. 3. AI Pentesting: Replace manual pentest and bug bounty programs with a solution that scales. Don’t let your vulnerabilities escape.
- Website
-
https://escape.tech/
External link for Escape
- Industry
- Computer and Network Security
- Company size
- 11-50 employees
- Headquarters
- San Francisco, California
- Type
- Privately Held
- Specialties
- API security, Application Security, API inventory, DAST, API Discovery, Attack Surface Management, and AI Pentesting
Products
Escape
Dynamic Application Security Testing (DAST) Software
Escape is the only DAST that works with your modern stack and tests business logic instead of missing headers. It fits right into your modern stack, supporting modern web frameworks, APIs, CI/CD, and Wiz without hassle. With Escape, you can: 1. Document all your APIs in minutes and enrich your API inventory with seamless integrations. 2. Discover vulnerabilities even at a business logic level with our proprietary AI-powered algorithm. 3. Ensure comprehensive coverage of GraphQL-specific vulnerabilities
Locations
-
Primary
Get directions
1524 Fell St
San Francisco, California 94117, US
-
Get directions
Paris, FR
Employees at Escape
Updates
-
We're extending eurosummer just a little longer and heading to the OWASP® Foundation Oslo meetup next week 🇳🇴 Here's the exciting lineup: 🍕 Food, drinks, and real AppSec chats, catchups and new connections 🎙️ Testing API Business Logic With AI Agents: What We Got Wrong First from Lucas Thietart, Solutions Architect at Escape 💬 From Patch to Pwn: Combining AI and static analysis to create a novel PoC for WP2Shell from Katie Paxton-Fear, Security Advocate at Semgrep As we trickle back in from summer vacations, start off your September with a relaxed evening of all things AppSec. Jean-Daniel PRINCE and Lucas Thietart are there for exactly that so be sure to come say hi if you're around! Link to register 👉 https://lnkd.in/eXRv-rs3
-
-
Escape reposted this
Always great to meet with customers in person. Schibsted is one of the major media companies in the Nordics, and we’ve been working with them for quite a while now. Gabriel B. is definitely one of those security practicioners who are passionate about their job and about using state-of-the-art tech to protect their company. (And a great guy on top of that, he still owes me a jiu-jitsu lesson) If you’re a security team in the Nordics looking to multiply your team’s impact with an AI-native offensive security platform, or if you’re just curious about agents applied to cyber, reach out. I’d be happy to chat 🔥
-
-
How can you build an engine that actually understands your business? By compounding the context it gathers. So that's exactly what we did. Cascade doesn't start from square one but builds on the knowledge and context it's gathered from every previous engagement, everything DAST already covers, and starts with a continuous model of your attack surface. Instead of shooting darts and hoping something lands, integrating with existing security, cloud, and developer tools means it can adapt its tests to how your systems actually work. The bottom line is with every engagement, Cascade becomes more of an expert in how your application, business, and environment actually operate. Instead of a stranger testing your application, it gives you an attacker with insider information. And that's what will really surface the critical vulnerabilities.
-
Escape reposted this
🚨 The Customer Success team is growing! 🚨 We are hiring for a Technical Account Manager to join me and the team in NYC. We’re looking for someone with an engineering degree and hands-on experience with APIs, integrations, scripting, and automation. You'll be working with the security engineers, developers, and AppSec teams who use Escape every day, helping them deploy, integrate, and get long-term value out of it. That takes someone who can be credible in those conversations from day one. And yes, you'd be joining the best team at Escape. I'm aware that the Head of Customer Success saying this is not admissible evidence, so please ask around. Just maybe skip the Paris office. They're biased. Apply below or share the link with someone you think would be a good fit. https://lnkd.in/eXCQAKWn
-
New CVEs, live production agents, and the same XSS in two completely unrelated chatbots. It's been a month of discovery at Escape 🚀 While we're discovering and developing every day, this month there were three standout instances we want to highlight for you to be aware of: ⚠️ New CVE-2026-17059 was discovered in Keycloak: A PII vulnerability that enabled restricted admin to read personal data. Given the recent critical password reset flaw in Keycloak, this is certainly one to be aware of 👀 . 💬 Our AI pentesting engine Cascade retrieved the full system prompt from an internal production agent, simply by reframing how it asked after learning from the initial rejection. ⏰ An XSS was found in the Markdown renderer of not one but two AI chatbots, ultimately giving an attacker much more privilege than they started with. As Arnaud Fanthomme dives into in his article, one of the most vital parts of developing AI-powered pentesting is investing in the research that powers it, so it's actually closing the vulnerability gaps that attackers are creating. And this month we've certainly dived into that ⭐️ When attackers are deploying AI to continuously probe your surface for these critical vulnerabilities and more, your security needs to be doing the same.
-
And the partnerships keep growing! 🚀 We're thrilled to announce our partnership with SHI International Corp.! SHI works with over 15,000 corporate, public sector, and education spanning software licensing to cloud to cybersecurity. We're excited to bring a continuous, evidence-backed offensive security layer to the security teams they work with, covering the application and API attack surface most teams are adding faster than they can manually test. If you work with SHI and are looking to slot automated offensive security into your stack, reach out to either the Escape or SHI International Corp. team!
-
-
Your two weeks starts now ⏰ Challenge 2 of our Pentester vs AI CTF is now live! Here’s your mission, if you choose to accept it: Your client Duck Store just signed off on a white-box pentest with one instruction: find the data they never handed over, which you can use to dive deeper into their network. After two weeks we'll reveal the AI's solve and the top solves from the leaderboard. Ready to race the machine? Try the challenge now 👉 https://lnkd.in/etGzMtzc