XBOW
XBOW is the best-funded autonomous pentest pure-play, with a genuinely qualified headline claim behind the hype.
XBOW is the most visible company in autonomous offensive security: past a $1B valuation, backed by Accenture, Samsung, and NVIDIA, and holder of a genuinely impressive but heavily qualified HackerOne leaderboard claim. It is the clearest test case for whether "AI hacker" marketing survives contact with independent scrutiny. Some of it does. Most of the caveats matter more than the headline. For the wider field it sits in, see Offensive AI security companies; for the ceiling it is implicitly benchmarked against, see What the frontier labs do themselves.
#Founding and team
XBOW, Inc. was founded in January 2024 by Oege de Moor (CEO) and Nico Waisman (CISO) (GeekWire; XBOW). De Moor's pedigree is real and relevant: he created GitHub Copilot and founded Semmle (the semantic code-analysis company later acquired by GitHub/Microsoft and folded into what became CodeQL — see The open-source stack), giving him direct prior experience building both an AI coding product and a static-analysis engine before founding a company that does the offensive-security inverse of both. Waisman is a longtime offensive-security veteran, formerly at Lyft.
The "Seattle HQ" claim deserves a caveat of its own: GeekWire's own reporting found the address is a mailbox at a Pioneer Square coworking space, de Moor reportedly lives in Malta, and only a small fraction of XBOW's 250+ employees are actually Seattle-based (GeekWire). This is not a scandal, but it is a useful reminder that "headquarters" claims in funding press cycles often serve regional VC deal-flow bragging rights more than they describe where the company actually operates — treat any competitor's "HQ" line with the same skepticism.
#Funding, round by round
| Round | Date | Amount | Lead / participants | Source |
|---|---|---|---|---|
| Series B | ~June 2025 | $75M | Altimeter (Apoorv Agrawal), with Sequoia Capital and Nat Friedman returning | XBOW blog |
| Series C | March 18, 2026 | $120M | DFJ Growth and Northzone, with Sofina, Alkeon Capital, plus Altimeter/NFDG/Sequoia returning; valuation over $1B | Bloomberg, XBOW, SecurityWeek |
| Series C extension | May 6, 2026 | $35M | Accenture Ventures, DNX, Liberty Global, NVentures (NVIDIA), Samsung, SentinelOne | GeekWire, TechFundingNews |
The two 2026 rounds alone sum to $155M. XBOW has done five rounds total per Crunchbase, but no source found in this research pass discloses a reliable cumulative total — any "XBOW has raised $237M+" or similar aggregate figure should be treated as unverified; it does not reconcile against the individually confirmed round amounts. Do not repeat a specific total-funding number for XBOW without a primary source.
Separately from the priced rounds, Accenture took a strategic investment on undisclosed terms and is embedding XBOW into its "Cyber.AI" offering (Accenture newsroom) — the most concrete Big-4-adjacent endorsement any autonomous-pentest vendor has secured to date. See the section below on what that signals.
#The HackerOne #1 claim: what happened and what it means
What actually happened: XBOW topped the US-specific HackerOne leaderboard, ranked by reputation-point gain, during the April–June 2025 quarter (XBOW) — not the global leaderboard, not an all-time ranking, and not a "business impact" or "critical reputation" ranking. HackerOne subsequently split its leaderboards to separate individual hunters from companies specifically because of cases like this one; co-founder Michiel Prins noted publicly, "XBOW is a company, there's multiple people working behind it... it's not just one person" (CyberScoop) — a structurally different competitive unit than a solo researcher, which is exactly why the comparison drew criticism.
The substantive criticisms, mostly from HackerOne's own leadership and outside security professionals:
- Volume over impact. Prins again: XBOW "excel[s] in volume … [but] it does not yet excel in business impact... It's a workflow, and there's a loophole in the workflow so that an adversary can accomplish something that is unintended. That is very hard for an AI to find" (CyberScoop).
- Shallow bug categories. Amélie Koran (ex-Walmart/EA security) characterized XBOW's findings as "more 'surface material' as opposed to more in-depth campaigns" — basic data leaks and XSS, not novel or business-logic vulnerabilities.
- Human filtering, undisclosed in the headline. XBOW's own disclosure states: "All findings were fully automated, though our security team reviewed them pre-submission to comply with HackerOne's policy on automated tools." The "#1, fully autonomous" framing already has a human quality-control gate baked in, and XBOW does not publish rejection or false-positive rates, so the raw model accuracy behind the human-filtered output is opaque (Rawsec).
- Structural, not purely skill-based, advantage. An always-on system mechanically outpaces human researchers who sleep, on a leaderboard that rewards volume.
- Real infrastructure behind the "autonomous" label. Reporting describes roughly 25 security/AI researchers and continuous model refinement behind the system — a legitimate engineering achievement, but not the unsupervised, zero-human system the marketing language implies.
XBOW's public marketing and much secondary press coverage compressed "#1 on a US-scoped, company-eligible, quarterly, volume-weighted leaderboard, with human pre-submission review" into "AI is now the best hacker in America." The underlying result is genuine — it found real, valid, in-scope vulnerabilities at a low enough false-positive rate for HackerOne to accept them at scale — but it is a narrower and more human-assisted achievement than the framing suggests.
#Architecture, as far as it's public
XBOW's own writeup describes exploit chains running up to 48 steps — for example, escalating a blind SSRF into full compromise — and claims to match "a principal pentester's 40-hour assessment" in 28 minutes (synthesis via appsecsanta). The pipeline covers recon, hypothesis generation, exploit-chain construction, and proof-of-exploit validation against live targets, explicitly modeled on human attacker workflows.
See Verification ledger for the full set of corrections applied to this dossier. XBOW does not publicly disclose its base model(s). Its own funding-round language talks about "pairing autonomous systems with top security professionals who train the AI" (XBOW) — ambiguous marketing language, not a model-card-level disclosure. No public statement confirms whether XBOW runs Claude, GPT, Gemini, an open-weight model, or some blend, and whether it fine-tunes or post-trains anything itself. This opacity is consistent across nearly the entire offensive-AI sector — see Offensive AI security companies — but it means every capability claim XBOW makes is unverifiable at the architecture level; you are evaluating outputs, not a disclosed system.
#Customers and revenue
XBOW does not disclose customer counts or ARR in any primary source found. Secondary reporting cites "100+ customers" including Moderna (softwarestrategiesblog) — this rests on a single secondary source and should be treated as [unverified] pending a primary XBOW disclosure.
#Pricing
XBOW lists on AWS Marketplace (AWS) but does not publish list pricing. Third-party comparison sites — not XBOW itself — cite roughly $4,000 per test for its enterprise/AWS offering, against budget competitors like Hacktron AI at $350 (Penetrify; Hacktron). These come from competitor marketing pages running comparison SEO — directional at best, not confirmed list price. See Who buys, and what they pay for how this compares to the broader $2,000–$50,000 traditional pentest-engagement range and to Horizon3.ai's and Pentera's equally undisclosed quote-only pricing.
#The Accenture investment and what it signals
Accenture's strategic investment, paired with folding XBOW into its "Cyber.AI" delivery offering, is the clearest Big-4-adjacent validation any autonomous-pentest vendor has secured. No evidence surfaced of Deloitte, PwC, EY, or KPMG building or acquiring a comparable proprietary capability — their public messaging in 2026 is uniformly about advising clients on AI security risk and reselling/integrating third-party tools, not building a competitor (absence of evidence, flagged in source research).
What this actually signals is narrower than "the consulting industry has endorsed autonomous pentesting." Accenture separately partnered with Anthropic specifically to help clients "secure and scale AI-driven cybersecurity operations" (Accenture newsroom) — Accenture is positioning itself as the delivery and integration layer sitting on top of both a startup (XBOW) and a frontier lab (Anthropic), not building its own competing product. That is consistent with a systems integrator hedging across the stack rather than making a high-conviction technology bet on XBOW specifically. It is real distribution leverage for XBOW regardless of Accenture's motive — a Big 4 firm now has commercial reason to route client engagements through XBOW — but it should not be read as an independent technical endorsement of XBOW's capability relative to Horizon3.ai, Pentera, or RunSybil, none of which Accenture has publicly evaluated against XBOW.
#Is the moat technology, distribution, or narrative?
Take these in order of how defensible each one actually is.
Technology. XBOW's 48-step chain examples and speed claims (28 minutes vs. 40 human-hours) are real demonstrated capability, but they are self-reported and not benchmarked against RunSybil, Terra Security, or MindFort by any independent third party found in this research. Given that the model stack is undisclosed, there is no way to attribute XBOW's results to a proprietary technical edge versus simply being an early, well-funded, well-staffed team running a strong frontier model with good agent scaffolding — which any of its competitors, or a new entrant with sufficient capital, could plausibly replicate. Nothing here reads as a durable technical moat.
Distribution. This is XBOW's strongest asset. AWS Marketplace presence, an Accenture channel relationship, and a war chest that dwarfs every competitor except Horizon3.ai and Pentera give it real go-to-market advantages that compound — enterprise buyers increasingly want to draw against an existing cloud commit rather than run new procurement (see Who buys, and what they pay), and XBOW is positioned for exactly that motion.
Narrative. This is where XBOW has genuinely outperformed every competitor in the space. The HackerOne #1 claim, however qualified, generated more press coverage, more inbound interest, and more fundraising momentum than any other autonomous-pentest company's proof point — including Horizon3.ai's larger, better-substantiated NSA CAPT program participation. XBOW is winning the fundraising and mindshare race; it is not clearly winning on independently verified technical superiority.
XBOW's moat today is distribution and narrative, not demonstrated technical superiority. That is a legitimate business asset — narrative compounds into deal flow, deal flow compounds into data, data can eventually compound into a real technical moat — but it means a well-capitalized, well-benchmarked competitor is not obviously locked out. See What could actually be defensible.
#What XBOW proves
- LLM-agent pentesting at meaningful scale is fundable at over $1B in venture capital, with strategic validation from a hyperscaler-adjacent chip maker (NVIDIA), a consumer electronics giant (Samsung), and a Big 4 firm (Accenture).
- An AI system can produce enough valid, in-scope bug-bounty submissions to top a national leaderboard by volume within a single quarter, with a low enough false-positive rate that a marketplace as strict as HackerOne accepted the results at scale.
- Founder pedigree from adjacent AI-coding work (Copilot, Semmle/CodeQL) transfers credibly into offensive-security fundraising, even without disclosing the underlying model architecture.
#What XBOW does not prove
- That its results generalize beyond the bug classes HackerOne researchers already excel at finding (data leaks, XSS, injection) into deep business-logic or chained exploits — the criticism from HackerOne's own co-founder is specifically that this is where XBOW has not yet shown strength.
- That it outperforms Horizon3.ai, Pentera, RunSybil, or any other competitor on any independently measured benchmark — no such benchmark exists publicly for this claim to be tested against.
- That the system operates with meaningfully less human oversight than its competitors — XBOW's own disclosure confirms a human pre-submission review gate, the same kind of human-in-the-loop control most of its "fully autonomous"-branded competitors also quietly retain.
- Which model(s) power it, whether it fine-tunes anything, or what its actual false-positive rate looks like before human filtering — all foundational technical questions that remain undisclosed as of August 2026.
#What this means for us
- XBOW is the loudest name in this market but not obviously the best one on a like-for-like technical basis — do not let its press volume set your baseline expectation for what "AI pentesting" can do.
- The Accenture/Samsung/NVIDIA strategic money is a distribution and credibility signal for XBOW specifically, not evidence that any of those companies has technically diligenced XBOW against its competitors.
- The undisclosed model stack is the single biggest gap in XBOW's public story — if you ever need to evaluate a partnership, acquisition interest, or competitive threat from XBOW, that is the first question to press on.
- The HackerOne #1 claim is citable as a real, if narrow, capability signal — but repeat it with the qualifiers (US leaderboard, one quarter, company-eligible category, human-reviewed submissions), not as "AI's best hacker" shorthand.
- For a defensive-side founder building defensive tooling, XBOW's fundraising success is the strongest existing evidence that investors will fund an AI security story on narrative and a strong founding team well before independent benchmarks exist — a pattern worth exploiting for your own raise, and one to price in when evaluating competitors' claims. See Who funds this and at what price, Go to market, and Where the gaps actually are for where XBOW's opacity leaves room for a more disclosed, more verifiable competitor.