Pi Raises $25 Million for Agentic Product Security
The San Francisco and Tel Aviv company wants security agents to find and help fix software risks throughout the development lifecycle.

SAN FRANCISCO, Calif. - Pi has raised $25 million in Series A financing for an agentic platform that helps software teams identify and remediate security weaknesses. This latest capital infusion, led by Third Point Ventures, brings the Israeli-American startup's reported total funding to approximately $35 million. The round signals a shifting priority in the venture capital landscape as investors move from supporting basic scanning tools toward more sophisticated, autonomous systems capable of bridging the gap between security auditing and engineering implementation.
Founded by a group of veteran security leaders with experience at major technology corporations including Microsoft and Tesla, Pi operates with a dual presence in San Francisco and Tel Aviv. This geographical footprint allows the company to tap into both the specialized cybersecurity talent pool of Israel and the cloud-computing leadership of the Bay Area. The team is leveraging this pedigree to build a product designed to follow software through its entire lifecycle, moving beyond the traditional model of late-stage security reviews that often delay product launches.
The core of Pi’s strategy relies on the deployment of security agents that are integrated from the initial design phase through final deployment. These agents are tasked with examining source code, cloud configurations, and application behavior in real-time. By coordinating these findings directly with developers, the platform seeks to integrate security tasks into existing engineering workflows rather than treating them as an external set of obstacles. This is particularly relevant as modern software architectures become increasingly decentralized and complex.
The emergence of agentic security tools comes at a critical juncture for the technology sector. Security teams globally are struggling to review software at the speed that generative AI coding tools can now produce it. This acceleration in the volume of code being committed to production has created a bottleneck in traditional security operations. Industry analysts have noted that the sheer scale of modern codebases makes manual review nearly impossible for all but the most critical vulnerabilities, leaving a massive surface area of unreviewed logic.
Pi is betting that autonomous agents can perform much of the routine investigation and suggest specific remediations in the same environment where engineers are already working. In theory, this approach could reduce the chronic backlogs of security findings that currently plague enterprise security departments. These backlogs often persist because findings lack necessary context or clear ownership, causing developers to ignore them in favor of shipping new features. By providing contextualized fixes, Pi aims to lower the friction between security requirements and development speed.
The application security market has historically been saturated with tools that generate thousands of alerts, many of which are false positives or low-priority issues. The industry term 'alert fatigue' describes a phenomenon where critical security risks are buried under a mountain of noise. Pi’s agent-led approach intends to solve this by focusing on 'remediation' rather than just 'detection.' Providing a suggested path for a fix is inherently more valuable to an engineering team than simply pointing out a flaw, provided the suggestion is accurate and safe to implement.
Despite the promise of automation, the transition to agentic security carries significant operational risks. Automated remediation needs strict boundaries, as a suggested fix can inadvertently introduce a new defect into the production environment. There is also the concern that an autonomous agent with broad access to a company's codebase and cloud infrastructure may itself become a security risk if it is compromised. Consequently, customers in high-stakes industries like finance or healthcare will require rigorous evidence and built-in approval steps before allowing these tools to touch production code.
Transparency will be a major factor in the adoption of these tools. For Pi to gain widespread trust, it must provide a complete record of every change suggested and executed by its agents. This audit trail is essential for compliance and for ensuring that the development team maintains a 'human-in-the-loop' oversight model. The platform will need to demonstrate that it can measurably reduce exploitable risk rather than simply providing another layer of automated alerts that require manual triage, which would negate its efficiency gains.
The competitive landscape in which Pi operates is increasingly crowded, with both legacy security vendors and well-funded startups racing to incorporate AI into the software development life cycle. However, the transition to AI-assisted development is fundamentally rewriting the rules of the category. This shift is creating room for new approaches that were not possible five years ago, specifically tools that can understand the intent of code and how different parts of a cloud application interact with one another during runtime.
The new financing will be used to support ongoing research and development, accelerate hiring across its two main offices, and scale customer expansion efforts. As Pi moves out of its early stages, its success will depend on whether its agents can effectively work alongside engineers without being perceived as an intrusion. The ability of the platform to learn from real-world security incidents and apply those lessons to its scanning and remediation logic will be a significant competitive differentiator as the market matures.
Market analysts are looking for several key performance indicators as Pi expands its footprint. The first is the conversion rate of suggested fixes into implemented code, which measures how much developers trust the platform's outputs. The second is the platform's ability to handle high-velocity development environments where code is committed several times per day. If Pi can prove that its agents make security faster without making the underlying infrastructure more opaque, it could define a new standard for how software is protected in the AI era.
Looking forward, the broader trend toward 'SecOps' and 'DevSecOps' integration suggests that the wall between developers and security engineers is finally beginning to crumble. Pi sits at the center of this cultural and technical shift. By focusing on the entire lifecycle—rather than just the static code at rest—the company is positioning itself as an essential part of the modern cloud-native stack. The coming months will be a test of how well the startup can translate its technical promise into enterprise-scale deployments that can withstand the scrutiny of sophisticated threat actors.
Sources
Written by
The Company Wire Staff
Reporting from The Company Wire newsroom. Staff bylines cover funding rounds, product launches and company news verified against primary sources.


