Funding

FAZE Security exits stealth with $6M and an agentic red team. Valuation Undisclosed.

$6M seed led by New Era Capital (+Lockstep). 50 enterprise customers, ~20X ARR in 18 months (company). Agentic Red Team for continuous exploit-and-retest. Formerly CYTRIX.

Sep 11, 2026 · 4 min read

FAZE just put agentic offense on the seed tape. The round is small. The backlog thesis is not.

On September 11 FAZE Security announced it emerged from stealth with $6 million in seed funding led by New Era Capital Partners, with participation from Lockstep VC. The company is based in New York and Tel Aviv and was formerly known as CYTRIX. Those are the capital facts in the PR Newswire release; post-money, ARR dollars, and TAM: Undisclosed.

Traction claims in the same release: 50 enterprise customers, including several Fortune 500 companies, and roughly 20X ARR growth in 18 months. Treat those as company statements. The product framing is Offensive Security Orchestration. At the core sits an Agentic Red Team (ART): autonomous agents trained on proprietary attack data from thousands of white-hat hackers, running continuously against customer web applications, APIs, and cloud environments inside “strict guardrails.” Agents are said to discover novel exposures, exploit them the way a real attacker would, and rank findings by proven business impact rather than theoretical severity. Every finding ships with working proof, an assigned owner, and a remediation path; FAZE automatically re-tests until the exploit fails. Customer-report claims in the release: close to zero false positives and more than 50% faster Mean Time To Remediate versus scanners and point-in-time pentests.

The problem statement FAZE opens with is the industry’s remediation tax. Annual pentests are out of date the day the report lands. Scanners generate thousands of unranked findings. Security teams triage noise while attackers — increasingly armed with AI — exploit gaps in hours. That framing is not unique to FAZE; it is the same wedge continuous validation and ASM vendors have been selling. What FAZE adds is the agentic full-cycle claim: discovery through exploit through ranked remediation through automated re-test, trained on proprietary white-hat attack data rather than CVSS-only severity.

New Era partner Ziv Conen’s quote lands where investors want it: proprietary data from thousands of white-hat hackers plus agentic coverage across discovery through re-test, sustained growth while serving Fortune 500 security teams. That is a thesis about continuous validation beating annual pentests and scanner noise — not a proof that offensive security is a standalone budget line forever. Platforms, ASM vendors, and validation startups already on CyberMerge’s tape are circling the same backlog.

POV: a $6M seed with fifty logos and a ~20X ARR claim is a loud stealth exit for offensive orchestration — and a thin mark sheet. Valuation is Undisclosed. ARR: Undisclosed. Do underwrite the product bet: continuous exploit-and-retest with business-impact ranking versus CVSS theater. Question whether “agentic red team” becomes a category or a feature inside exposure platforms and MSSP bundles. Source: the September 11 release. Formerly CYTRIX is the rebrand footnote, not the underwrite.

Underwrite sheet — sourced only: $6M seed led by New Era Capital Partners; Lockstep VC participates; NY + Tel Aviv; formerly CYTRIX; 50 enterprise customers incl. several Fortune 500; ~20X ARR growth in 18 months (company); Agentic Red Team on proprietary white-hat attack data; continuous discover / exploit / rank / remediate / re-test; near-zero FP claim; >50% faster MTTR claim vs scanners and point-in-time pentests (PR Newswire, Sep 11, 2026). Traction is the story. The blank valuation is not.

Sources