Category and buyer
Vulnerability management teams pay for workflow that turns an ever-growing backlog of findings into prioritized, actionable remediation. Hackuity is selling into that pain with what it calls an AI-powered Vulnerability Operations Center, aiming to reduce the time and effort it takes to decide what to fix first and prove progress.
Deal news
Lyon-based cybersecurity company Hackuity has raised $19 million (around ~EUR 18m) in a funding round led by Forgepoint Capital International. The round also included Bright Pixel, Bpifrance and Seventure Partners.
Hackuity framed the funding as support for expanding its AI capabilities and accelerating product innovation. The company positioned the round against a backdrop of rising AI-driven security vulnerabilities and a growing volume of unresolved exposures.
Notably, Hackuity said the participating investors were existing backers returning for this round, with Forgepoint Capital International leading as a specialist cybersecurity investor alongside the continuing European syndicate.
Why this is with-trend
Security buyers are increasingly treating vulnerability operations as a core control plane rather than a periodic compliance exercise. The market signal in this round is less about a new product category and more about a maturing one: investors are backing tooling that makes vulnerability work tractable at scale, especially as attack surfaces expand and AI increases both the pace and complexity of exposures.
Two elements stand out:
- AI is being funded as a workflow accelerator, not a feature. Hackuity’s stated use of proceeds focuses on AI capabilities and product innovation. That aligns with where CISOs and security operations leaders are willing to spend: reducing analyst time spent triaging, deduplicating and arguing about severity.
- Syndicate continuity suggests strategic priority. Existing investors re-upping signals that vulnerability operations is being treated as durable, even across cycles. It also typically implies a higher bar for progress visibility, such as measured reductions in time-to-remediate, backlog size, or false positives.
GTM implications: where retention gets built
Vulnerability operations products can be sticky when they are deeply embedded in remediation workflows. In practice, retention and expansion are usually driven by:
- Integration depth. The more a platform connects into scanners, ticketing and IT workflows, the higher the switching cost. A “Vulnerability Operations Center” framing implies orchestration across tools rather than replacing them.
- Proof loops with security and IT. Tools that help security teams justify priorities to infrastructure and application owners tend to expand seat count and module adoption. The core value is not just visibility, but negotiated action.
- International rollout discipline. Hackuity has indicated it is scaling internationally across Europe and Asia. That expansion typically requires repeatable channel and partner motions, plus regional security credibility. The ability to land in one geography and expand into others is often constrained by implementation capacity and local customer success coverage.
Competitive context
Vulnerability management is a crowded space, with incumbents and newer platforms competing on prioritization, automation and how well they fit into existing security stacks. Hackuity’s differentiation claim is its AI-led vulnerability operations positioning. The key commercial question is whether it can consistently deliver measurable remediation outcomes across heterogeneous environments, not just improved dashboards.
Outlook
This funding round reinforces ongoing investor momentum around AI-driven security tooling, particularly where AI is positioned as a practical lever to reduce operational load and accelerate remediation decisions. For Hackuity, the near-term execution test will be translating product innovation into predictable deployments as it scales beyond its home market.
What this enables
- Faster product iteration around AI-based prioritization and remediation workflows
- Broader international go-to-market across Europe and Asia
- Deeper integrations into the security and IT toolchain to increase switching costs
What to watch
- Whether AI capabilities translate into measurable backlog reduction and faster time-to-remediate
- The pace and repeatability of international expansion beyond France
- How the company balances orchestration across existing tools versus displacement positioning
- Evidence of expansion within accounts as vulnerability operations becomes a shared security-IT workflow