Skip to content

XBow

1 viewer · 30d

Total raised

$120.9M

+$120.9M this year

1 filing since 2026 · latest Equity filed

Cumulative raised
LAST ROUND
Equity · $120.9M
ROUNDS
1
INVESTORS
13
FOUNDED
2024
HQ
Seattle, WA
SECTOR
Cybersecurity
EMPLOYEES
N/A
30D VIEWERS
1

AI overview

Updated

XBOW builds an autonomous offensive security platform that uses AI agents to perform penetration testing without human input. The system discovers, chains and exploits vulnerabilities across a customer's attack surface and proves each finding with a working exploit, completing a comprehensive pentest in hours rather than weeks. Founded in January 2024 by Oege de Moor, who previously created GitHub Copilot and GitHub Advanced Security at Microsoft, the company lists Seattle as its headquarters while operating as a distributed team of more than 250 people. In March 2026 it raised a $120M Series C led by DFJ Growth and Northzone at a valuation above $1 billion, later extended to $155M with participation from NVIDIA, Samsung and SentinelOne.

What sets it apart

It was the first autonomous system to reach #1 on the HackerOne US bug bounty leaderboard, and every vulnerability it reports comes with a validated working exploit, which removes the false-positive triage burden that conventional scanners create.

Funding history

1 round
EquityMar 16, 2026
Form D
+$120.9M$120.9M total

Latest SEC filings

via EDGAR · CIK 0002074263
Form D · Mar 16, 2026View on EDGAR

Products

1 tracked

XBOW Autonomous Offensive Security Platform

Offensive security / penetration testing platform

An AI-driven penetration testing platform that runs autonomous hackers against a customer's applications and infrastructure, reasoning through offensive security workflows the way a human pentester would, then confirming each vulnerability with a real exploit.

  • Fully autonomous operation requiring no human input
  • Discovers, chains and exploits vulnerabilities across the whole attack surface
  • Real exploit validation for every finding
  • Comprehensive penetration tests completed in hours