Formerly Litt

Overview

Israeli-founded, A Security (formerly Litt) is an autonomous offensive security platform that continuously finds, chains and remediates exploitable attack paths at machine speed. Aimed at regulated enterprises, it emerged from stealth in early June 2026 with $37M across two funding rounds.​

Key Technology Insights

Offensive AI agents behave like a real attacker, probing applications to find, chain and prove exploitable weaknesses with reproduction steps. This catches business logic flaws and Insecure Direct Object Reference (IDOR) chains that automated scanners and human testers often miss. This autonomous approach runs 3–5x faster than traditional methods, so a ten-day test now takes two to three days. Air-gapped deployment is currently unsupported, requiring LLM connectivity.​

Industry Application

The most mature use case is the company’s continuous agentic pen testing for regulated banking and finance. At one large bank, A Security uncovered a seven-year-old IDOR flaw exposing 1.2M records that earlier tests had missed. It replaces traditional Dynamic Application Security Testing (DAST) and pen testing, with code-level and web application firewall remediation. Mobile apps, internal infrastructure and OT remain on the 2026 roadmap.​

Strategic Perspective

A Security reframes penetration testing from a periodic snapshot into a continuous, adversary-like assessment. Its advantage lies in surfacing exploitable flaws others miss, with early regulatory acceptance from a major bank. As attackers weaponise AI, continuous autonomous testing may become standard.

Previous
Previous

Chainguard