12 / AI security
Straiker
When AI can take action, security has to follow the action too.

Met with
- Ankur Shah · co-founder & CEO
Testing the agent before an attacker does
Straiker’s Ascend AI performs against AI applications and agents. Its published testing scope includes prompt injection, tool misuse and data leakage. Tests can run as models, prompts or configurations change.
Protecting the running system
Straiker describes Defend as the protection layer for agents already operating. Its role includes checking unsafe access, malicious instructions and unintended actions. The testing and protection products address different moments in the same agent’s life.
What I would test
I would put a malicious instruction inside a document the agent is allowed to read. Then I would see whether the agent treats that instruction as data or follows it. This is , and it tests the boundary between information and authority.
A useful defence needs to understand what the agent can actually do. Reading a file, sending it outside the company and deleting it carry different risks. I would test the chain of tool calls, not only the final text response.
I would also run legitimate tasks through the same controls. Blocking everything would look secure and be unusable. The interesting measure is how much harmful behaviour is stopped while valid work still gets through.
The business model and moat
The buyer wants to deploy useful agents with more confidence. Continuous changes to prompts, tools and models create a reason for repeat testing. That can support an ongoing product relationship.
The potential moat is a growing understanding of real attack paths, paired with controls that developers can apply. I would look for the learning loop: a test finds a failure, the team fixes it, and a regression test prevents it from returning.
Integration quality matters as much as attack coverage. If checks are too slow or hard to interpret, teams may avoid them. The product needs to make the safe path practical.
My take
I like the connection between finding a weakness and defending against it. The strongest direction would keep those two halves close as agents gain more permissions. A clear explanation of what failed and how to fix it would be a valuable part of that product.
Public financing
Straiker announced a $64 million Series A on 29 June 2026, bringing disclosed total funding to $85 million. The round included new investors and continued backing from Bain Capital Ventures and Lightspeed.
- Marathon Management Partners
- Citi Ventures
- Illuminate Financial
- Workday Ventures
- Bain Capital Ventures
- Lightspeed
Gold marks my selection of established, tier-one VC backers. It is a personal classification.
There’s more to talk about.
Contact me to discuss Straiker and explore these ideas in more depth.
Talk to Matthias