Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

Seattle cybersecurity startup Staris raised $5.7M to build AI-powered virtual security engineers

By TheFinanceBase Team6 min read

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Staris, a Seattle application-security startup founded by Adam Cecchetti and Austin Fath, raised approximately $5.7 million in seed funding led by Freestyle VC in January 2025. The company is developing AI systems it calls “virtual security engineers”—software designed to continuously identify, validate and help fix vulnerabilities in applications.

The financing was reported by GeekWire on January 27, 2025. It is a historical funding event, not a newly announced round.

What Staris is building

Staris is not a general-purpose AI-agent company. Its focus is application security: checking software for vulnerabilities and helping development teams determine which findings represent real, exploitable risk.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The company’s current public positioning describes a process of continuous, exploit-proven security validation. According to Staris, the platform analyzes an application’s code, architecture and business context, attempts to exploit suspected weaknesses, and supplies evidence such as execution traces. It can also provide remediation guidance or a pull-request-ready patch.

That approach is intended to address a familiar problem in application security. Conventional scanners can produce large volumes of potential findings, leaving human security and engineering teams to investigate false positives, reproduce issues and decide what to fix first.

What “virtual security engineers” means

“Virtual security engineers” is Staris’s product framing, not a standardized industry category or evidence that the software performs every task of a human security professional.

In practical terms, the system is intended to automate or accelerate several parts of the AppSec workflow:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Understanding how an application works and what its functions are supposed to do.
  • Finding potential vulnerabilities in code and running applications.
  • Testing whether suspected flaws can actually be exploited.
  • Prioritizing confirmed issues rather than treating every scanner alert equally.
  • Generating remediation recommendations or proposed code changes.
  • Creating evidence that can support reviews, audits and security questionnaires.

Staris has described the concept as an “immune system” for applications. The more concrete test for customers, however, is whether its exploit evidence and proposed fixes reduce the amount of manual triage without creating new security or reliability problems.

Founders and company background

Chief Executive Officer and co-founder Adam Cecchetti previously founded and led Deja Vu Security, which was acquired by Accenture in 2019. Staris’s biography also lists prior work at Amazon, Accenture and Peach Tech, a company later acquired by GitLab. Staris’s About page provides the company’s current biography.

Chief Technology Officer and co-founder Austin Fath is a longtime engineering leader and a former Carnegie Mellon University classmate of Cecchetti. His listed experience includes Soft Tech Consulting, BIzy, AddThis, Amazon Web Services and Assertive. Carnegie Mellon’s Information Networking Institute identifies both founders as alumni and describes Staris’s use of large language models to help identify code vulnerabilities.

Staris was founded in 2023. At the time of the funding announcement, the company had six employees. That figure described the January 2025 team and should not be treated as its current headcount.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who invested and how much?

Freestyle VC led the seed round. GeekWire reported the amount as $5.7 million, consistent with a Form D record showing $5,769,656 in securities sold by Staris AI, Inc.

GeekWire said Cecchetti declined to identify additional investors. A later LinkedIn post from Cecchetti thanked Freestyle’s Maria Palma and Vermilion Cliffs Ventures’ Ashley Smith, suggesting Vermilion Cliffs participated. That post is not a complete, independently confirmed investor list.

What the funding was for

The company said it planned to use the financing to expand its six-person team. That supports a broad description of the proceeds as funding additional product and engineering capacity and further platform development.

Freestyle general partner Maria Palma framed the investment partly around the shortage of qualified cybersecurity professionals. That is the investor’s rationale, not an independently measured result showing that Staris has solved the industry’s staffing problem.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does Staris replace security engineers?

The available evidence supports an augmentation model, not wholesale replacement. Staris may automate repetitive investigation, validation and remediation work, but people still need to set security policy, determine acceptable risk, review generated patches and approve production changes.

Human expertise also remains important for unusual architectures, subtle business-logic flaws, incident response, threat modeling and testing outside the platform’s supported scope. Organizations may still need manual penetration testing where regulators, customers, insurers or auditors require an independent human assessment.

What Staris says it offers now

Staris’s current website emphasizes “Total Context Security,” exploit-proven findings, execution traces and PR-ready fixes. It also advertises private-VPC and self-hosted deployment options and says customer data is not used to train its models. These are vendor-stated capabilities and policies; a buyer should confirm their technical scope, contractual terms and treatment of data from third-party integrations.

The homepage publicly lists a starting price of $4,900 for one full validation cycle. The About page separately references economics as low as $2,083 per application per test in another pricing context. Those figures should not be treated as equivalent plans or as a complete enterprise price.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Staris also markets examples including 99% noise reduction, a case in which 590 scanner findings became six proven vulnerabilities, and “zero false positives.” These are company-published examples and claims, not independent comparative benchmarks.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What a buyer should evaluate

Question Why it matters
What does it test? Confirm support for the organization’s languages, frameworks, APIs, authentication flows, business logic and deployment models.
How is exploitation proved? Ask whether findings include reproducible evidence and whether chained attacks or authorization flaws are covered.
What does a patch change? Generated code still requires review for regressions, altered business behavior and incomplete fixes.
Where does data run? Clarify source-code access, credentials, test data, runtime permissions, isolation and model-training policies.
How does it fit existing workflows? Check integrations with source control, CI/CD, issue tracking, identity providers and role-based access controls.
What does the price measure? Compare cost per application, test or validation cycle with the desired testing frequency and internal labor savings.
What requirements remain? Determine whether customers, regulators or insurers still require human penetration tests or formal reports.

How Staris fits the AppSec market

Staris’s proposed model sits between several established approaches rather than automatically replacing them:

  • SAST and DAST scanners: Conventional static and dynamic tools can provide broad, repeatable coverage, but often require substantial human triage.
  • Automated security validation: Platforms such as Pentera generally address broader breach-and-attack or infrastructure validation, while Staris presents itself as application-focused.
  • Human-led testing: Cobalt combines a platform with human penetration testers and may be preferable when expert manual testing and formal deliverables are central.
  • Developer AppSec platforms: Snyk and GitHub Advanced Security emphasize security controls embedded in development workflows, code, dependencies and related assets.
  • Conventional web scanning: Burp Suite Enterprise Edition is an established automated web-application scanning option for teams seeking a more traditional DAST workflow.

These products are not presented here as feature-for-feature equivalents. The relevant choice depends on whether a team needs continuous testing, point-in-time assessment, human expertise, exploit evidence, patch generation, broader infrastructure coverage or compliance documentation.

The significance of the round

Staris’s opportunity is to reduce the labor needed to move from a scanner alert to a confirmed vulnerability and an acceptable fix. That is especially relevant as development teams release software more frequently and security teams face persistent staffing constraints.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The central risk is that automation can move mistakes faster as well as fixes. Exploit validation must be carefully authorized and scoped, particularly against production-like systems, while generated patches need human ownership and review.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.