Investors

The market validated itself, then left the mid market on the table.

Wiz bought Dazz. Armis bought Silk. Zafran raised a Series C from Menlo. Three proof points for the same thesis in eighteen months, and every one of them is cloud native, enterprise priced, and sold direct to a Fortune 500 security team. None of them run inside a plant with no internet. None of them are packaged so a single managed provider can serve every client in its book from one console. CVEasy is the local first version of the capability the market just paid three times for, and it reaches its buyer through the channel that already owns the relationship.

5 / 5
Gartner CTEM stages, one application
121
Integrations live, 16 categories
158,271
Attack simulation payloads
12
Provisional patents filed

Your materials

Everything below is already unlocked for you. Nothing else to request.

The thesis

A proven category, an unserved buyer, and a channel that sells for us.

Three things have to be true for this to be a large company rather than a good product. All three are true today, and only the third one needs capital.

01 The category

Somebody else already paid to prove the demand

We are not asking anyone to believe a new category exists, or to take a bet on whether security teams will eventually want their findings turned into verified fixes. Two acquisitions and a Series C in eighteen months already settled that question, with other people's money and other people's diligence.

What those transactions did not settle is who serves the companies underneath the Fortune 500. The acquirers all moved upmarket, because that is where their pricing already worked. The answer for everyone else is currently nobody.

Risk retired: does anyone want this

02 The buyer

Too big to ignore the problem, too small to buy the answer

A 900 person manufacturer has the same CVE backlog as a bank and none of the staff. Enterprise exposure platforms price per asset and assume a cloud estate, so the quote arrives at a number the buyer will not pay for a tool that still hands them a list.

They also cannot send vulnerability data off site, because the plant floor, the hospital, and the defense supplier all say no. Local first is not a preference for this buyer. It is the entry requirement.

Risk retired: can we build for them

03 The channel

One contract, an entire book of clients

Selling mid market direct is a customer acquisition cost problem nobody has solved elegantly. Selling through the managed providers who already run security for those companies is a different business: the relationship, the trust, and the renewal already exist, and we arrive as margin rather than as another line item.

Tenant workspaces, per client isolation, and white labelable reporting are already shipped, so a single operator runs a whole portfolio from one console. Each signed provider is distribution that compounds, not a logo that churns.

Risk remaining: this is what the raise funds

Read the three together and the shape of the company is clear. The technology risk is behind us, the market risk was retired by other people's acquisitions, and what is left is a distribution problem with a known channel and a product already packaged for it. That is the specific thing seed capital is good at buying.

The evidence

The category proved itself by getting bought.

Exposure management stopped being a feature request and became an acquisition target. Cyber venture funding rose 47 percent in 2025 to roughly 14 billion dollars across 392 rounds. The specific wedge inside it, turning findings into fixes, is where the money moved.

Acquisition

Wiz bought Dazz

Reported near 450 million dollars. The largest cloud security platform decided remediation was worth buying rather than building.

Acquisition

Armis bought Silk

Reported 150 million dollars on roughly 12.5 million raised. Exposure prioritization as the missing layer of an asset platform.

Series C

Zafran raised from Menlo

60 million dollar round in December 2025, roughly 130 million total, tripled ARR, around 120 employees. The standalone path is funded and working.

Every one of those companies is cloud native and enterprise priced. None of them run inside a building with no internet. None of them are sold in a shape an MSSP can resell across 40 clients. That is the opening.

CVEasy AI
CVEasy AI
The flagship platform

What we built

We are the scanner. We are also the layer above every scanner they already bought.

Most companies in this category picked one side. The scanners tell you what is wrong and stop. The prioritization startups sit on top of somebody else's scan data and have no product without it. CVEasy does both, which means a customer can rip out their scanner or keep it, and either way we are the exposure management layer.

We scan

Full native collection, no agent required

Credentialed collection over LDAP, WMI, SSH, and SNMP pulls installed software, patch levels, and configuration off every asset, then matches it against a 330,000 CVE corpus enriched with KEV, EPSS, and OSV. On top of that: network and port discovery, web application testing, Active Directory attack paths, 204 CIS checks across AWS, Azure, and GCP, software composition analysis, container image scanning, and secrets detection. 147 modules across 32 categories.

We unify

One canonical finding out of six scanners

The average enterprise runs three to six scanners concurrently and gets six different answers about the same host. Our correlation engine resolves asset identity across hostname, IP, MAC, and serial, then collapses duplicate findings from Tenable, Qualys, Rapid7, and Wiz into one canonical record with every source attached. It is fed by 121 integrations across 16 categories: 27 live API pulls, 57 file formats, 14 push endpoints, 6 feeds, and 15 outbound paths that push the fix back into ServiceNow, Jira, and the patch tooling. All of them work today. The customer keeps the tools they already paid for and finally gets one number.

Findings flow in from the tools they already run

Tenable Qualys Rapid7 CrowdStrike SentinelOne GitHub

A sample of 121 integrations across 16 categories. Logos are the property of their respective owners and denote an integration, not a partnership or endorsement.

Both halves feed the same engine.

Gartner defined the five stages of exposure management in 2022. Most vendors sell one or two and partner for the rest. We run all five in a single application, on the customer's hardware, with no cloud in between.

  1. 01ScopeBusiness context and crown jewels define what matters
  2. 02DiscoverNative scanning plus every tool they already run
  3. 03PrioritizeTRIS 12 layer scoring against the real environment
  4. 04ValidateAttack the finding to prove it is reachable
  5. 05MobilizeWrite the fix, then verify it held
PILLAR 01

TRIS scoring

Twelve layer threat and risk scoring that reranks findings against the customer's actual environment, exploit reality, and threat actor activity. CVSS says 63 percent of CVEs are high or critical. TRIS tells a team which of them can actually be reached in their building.

PILLAR 02

BASzy validation

158,271 attack simulation payloads across 120 categories and 242 intruder sets, plus around 150 attack modules and 17 threat actor emulation profiles. They prove whether a finding is exploitable in the environment and whether the fix actually held. Validation is a native stage, not a separate vendor and a separate invoice.

PILLAR 03

Local AI remediation

A quantized model on the endpoint writes the OS specific fix, groups vulnerabilities into single work orders, and never sends customer vulnerability data anywhere. That last part is why regulated, defense, and air gapped buyers can say yes.

The obvious objection

Why does Rapid7 not just ship this next quarter?

This is the first hard question in every meeting, so here is the answer up front. It is not that we are faster. It is that following us costs them the three things a public company will not give up to chase a smaller customer.

Constraint 01

The delivery model

Their product is a cloud console. Ours installs on the customer's hardware and never phones home. Shipping a real air gapped build means a second product line with its own release train, its own support model, and no telemetry to run it on. That is a rebuild, not a feature flag.

Constraint 02

The data model

Their analytics, their benchmarking, and increasingly their AI features all assume customer data pooled in their tenant. Our entire promise is that it never leaves the building. They cannot offer both without undermining the one they already sold to the enterprise.

Constraint 03

The pricing model

Per asset pricing is how they hit their number, and it is exactly what prices them out of the mid market. Moving to flat annual pricing for smaller accounts cannibalizes the enterprise book and invites every existing customer to renegotiate. Public companies do not do that voluntarily.

The market has already run this experiment. When the largest cloud security company on earth wanted remediation, it did not build it, it bought Dazz. When Armis wanted exposure prioritization, it bought Silk. The incumbents in this category demonstrably prefer to acquire this capability rather than build it, which is the same reason we can win the segment they will not reach and the reason the eventual exit path is well established.

Original invention

Twelve provisional patents, all filed the same day.

We do not present these as the moat, because no seed company is defended by a provisional filing. We present them as evidence that the methods above are genuinely novel rather than assembled from open source, and as the asset that sets the price if this company is acquired the way Dazz and Silk were. Filed 2026 07 24 with the USPTO. These are application numbers, not intentions.

64/019,079TRIS layered vulnerability scoring system
64/118,968Secure threat intelligence bundle delivery with two key signing
64/118,841Locally executed quantized LLM generation of OS specific remediation
64/118,922AI adaptive breach and attack simulation, multi strategy
64/118,961Evidence bound multi step attack chain construction
64/118,979Autonomous threat actor aware vulnerability re prioritization
64/118,984Cross campaign correlation and defense gap identification
64/118,972Adaptive defense capability fingerprinting via Bayesian detection
64/118,810Adversarial remediation verification via campaign re execution
64/118,943Vulnerability weaponization forecasting, predictive threat timing
64/118,881Fix centric remediation orchestration via stateless read time projection
64/118,890Coupled provenance, quarantine, and egress enforcement gateway
What actually defends the business is narrower and more boring than the patents. It is 121 working integrations that each took a real customer environment to get right, an attack corpus of 158,271 payloads that grows every week we run engagements, and a delivery model the incumbents cannot copy without breaking their own economics. The filings raise the cost of a direct clone and set the floor in an acquisition. The integration surface and the validation corpus are what a competitor would actually have to out spend us on.

Where we actually are

The honest version.

You are going to ask these questions in the first meeting. Here are the answers before you ask.

Who we work with today

Named references available under NDA

  • Manufacturing
  • Construction and building
  • Architecture
  • Healthcare and pharmacy
  • Managed service providers

Live purple team and vulnerability management engagements, running now. These are the accounts our paid pilots convert from, and we will introduce you to them once there is mutual interest and the client consents.

Built

The product ships today

Signed desktop application, 204 cloud compliance checks, MSSP tenant workspaces, and all 121 integrations live: 27 live API pulls, 57 file import formats, 14 push endpoints, 6 data feeds, and 15 outbound dispatch paths for ticketing, patching, and webhooks. Every one of them resolves to real code, enforced by a test suite that fails the build otherwise. This is not a prototype seeking build capital.

Built

Live security services revenue

Those engagements pay us today and they are the reason the product is shaped the way it is. Every feature above came out of a real environment, not a roadmap workshop. They are also the warmest pipeline we have: the buyer already trusts us and has seen the output on their own data.

The gap

Product revenue starts now, not last year

Licensing is built and verified end to end but was intentionally held dormant while the platform finished. Stripe, key issuance, and delivery all tested. We are switching monetization on and converting service clients into paid pilots. The first revenue dollar is a switch flip rather than a build, but it has not been switched yet and we will not present ARR history we do not have.

The gap

Two founders, both still splitting time

Everything above was built with no outside capital, which is the capital efficiency argument and the key person risk in the same sentence. We are not going to dress that up: the raise is what takes the founding team full time and funds the first commercial hires. Timing, the services business transition, and what full time looks like for each of us is a conversation we will have with you directly and in writing.

What we will report to you every month

We do not have an ARR chart yet, so we are not going to wave a static number at you instead. These are the four measures we instrument from day one, and they are the ones we expect to be held to.

  • PilotsPaid pilots started and the conversion rate from services client to platform contract
  • ChannelManaged providers signed, and client environments live underneath each one
  • ProofFindings validated by actual exploitation, and fixes verified to have held
  • SignalDuplicate findings collapsed per customer, the number that justifies replacing the stack

Team

Practitioners, not a pivot.

This product exists because one of us does vulnerability management at Fortune 100 scale every week and got tired of the tooling.

Co Founder and CEO

Joe Cox

Runs the company, the commercial motion, and the partner and MSSP relationships. Owns pricing, packaging, and the path from services engagement to platform contract.

Co Founder and CTO

Chris Boker

Architect of CVEasy, TRIS, and BASzy. MS in Cybersecurity and Information Assurance, 20 plus security certifications, named inventor on all twelve provisional filings. Works threat and vulnerability management at a Fortune 100 retailer, which is where the product requirements come from.

Investor FAQ

Questions we get asked first.

Are you raising right now?

We are in conversations with angels, syndicates, and seed funds who invest in security infrastructure. Round structure, size, and terms are discussed directly and are not published here. Submit the form and we will tell you exactly where we are.

How is this different from Tenable, Qualys, or Rapid7?

Two answers, because we compete with them on two fronts. On scanning, we collect the same credentialed inventory they do, over the same protocols, without an agent, and match it against a 330,000 CVE corpus. We are not claiming a decade of vendor advisory content depth, and we do not need to, because a scanner that finds 100 percent of your problems and ranks them by CVSS still leaves the team guessing. On everything after the scan, they are not really in the fight: they do not simulate the attack to prove exploitability, they do not write the fix, and they do not verify the fix held. And a customer running Tenable and Qualys and Rapid7 at the same time, which is most enterprises, gets three answers from them and one from us.

What if an incumbent bundles this in for free?

It is the right question, and it is the one that kills most security startups. Two things make it survivable here. First, bundling works when the feature is a checkbox on a renewal, and validation is not: proving exploitability requires an attack corpus, a simulation engine, and a safety model that took us years and 158,271 payloads to build, so a bundled version is a worse version and the buyer can tell in a single scan. Second, and more important, they can only bundle it to customers they already have. The mid market and MSSP segment we sell into is not on their renewal list, because their pricing never got them in the door. You cannot give something away for free to someone who was never your customer.

How does this become a large outcome and not a good small business?

The channel is the answer. Direct mid market sales cap out at whatever the founding team can personally close, which is a nice services company and not a venture return. Each managed provider we sign carries its whole client book, expands on its own as that book grows, and renews on the provider's contract cycle rather than ours. The comparable exits are already on the board: Silk sold for a reported 150 million dollars having raised roughly 12.5 million, and Dazz sold for a reported figure near 450 million dollars. We are building the same capability for the segment those companies never addressed, with the IP position to price an acquisition and the option to stay standalone the way Zafran has.

Are the founders full time?

Not yet, and we are not going to pretend otherwise. Everything on this page was built alongside other work, with no outside capital, which we think says something useful about the team. The raise is what takes the founding team full time and funds the first commercial hires. We will give you the specific timing and the plan for the services business directly, in writing, before you commit anything.

What does the capital do?

Go to market. The product is built. Capital buys sales motion into the MSSP channel, design partner conversion, and the compliance work, SOC 2 and FedRAMP path, that unlocks the regulated buyers our architecture is already suited for.

Can you name customers, or talk to them?

We run live engagements across manufacturing, construction, architecture, healthcare and pharmacy, and managed service providers. We do not publish their names, because we have not asked them for that and we are not going to spend a client relationship on a marketing page. Under NDA and with the client's consent we will make direct introductions, and reference calls are part of how we expect you to diligence us. Logo and reference rights are something we are negotiating into the paid pilot conversions now.

What can I see before a call?

If you are reading this page you already have access to all of it: the investor deck, the one page overview, and the data room covering patent filings, integration matrix, architecture, security posture, and the TRIS methodology paper. A live 3 minute product demo is available on request.

Investor inquiry

Start the conversation.

The materials are already open to you above, so this form is not a gate. It tells us who we are talking to, so the first reply is a real answer about the round rather than a calendar link. Both founders read every submission personally. No mailing list, no drip sequence, no gated webinar.

What happens next

  • A direct answer on where the round actually stands, structure and timing included
  • A live demo run against a real environment, not a recorded walkthrough
  • Technical diligence with the CTO, including anything in the data room that needs an NDA
  • Reference calls with live clients, under NDA and with their consent
Received. We will review and reply personally within one business day.
Something went wrong. Email us directly at investors@blueteamautomation.com.