What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Staris, a Seattle application-security startup founded by Adam Cecchetti and Austin Fath, raised approximately $5.7 million in seed funding led by Freestyle VC in January 2025. The company is developing AI systems it calls “virtual security engineers”—software designed to continuously identify, validate and help fix vulnerabilities in applications.
The financing was reported by GeekWire on January 27, 2025. It is a historical funding event, not a newly announced round.
What Staris is building
Staris is not a general-purpose AI-agent company. Its focus is application security: checking software for vulnerabilities and helping development teams determine which findings represent real, exploitable risk.
Recommended Free Tools
The company’s current public positioning describes a process of continuous, exploit-proven security validation. According to Staris, the platform analyzes an application’s code, architecture and business context, attempts to exploit suspected weaknesses, and supplies evidence such as execution traces. It can also provide remediation guidance or a pull-request-ready patch.
#1 Best Overall
That approach is intended to address a familiar problem in application security. Conventional scanners can produce large volumes of potential findings, leaving human security and engineering teams to investigate false positives, reproduce issues and decide what to fix first.
What “virtual security engineers” means
“Virtual security engineers” is Staris’s product framing, not a standardized industry category or evidence that the software performs every task of a human security professional.
In practical terms, the system is intended to automate or accelerate several parts of the AppSec workflow:
- Understanding how an application works and what its functions are supposed to do.
- Finding potential vulnerabilities in code and running applications.
- Testing whether suspected flaws can actually be exploited.
- Prioritizing confirmed issues rather than treating every scanner alert equally.
- Generating remediation recommendations or proposed code changes.
- Creating evidence that can support reviews, audits and security questionnaires.
Staris has described the concept as an “immune system” for applications. The more concrete test for customers, however, is whether its exploit evidence and proposed fixes reduce the amount of manual triage without creating new security or reliability problems.
Founders and company background
Chief Executive Officer and co-founder Adam Cecchetti previously founded and led Deja Vu Security, which was acquired by Accenture in 2019. Staris’s biography also lists prior work at Amazon, Accenture and Peach Tech, a company later acquired by GitLab. Staris’s About page provides the company’s current biography.
Chief Technology Officer and co-founder Austin Fath is a longtime engineering leader and a former Carnegie Mellon University classmate of Cecchetti. His listed experience includes Soft Tech Consulting, BIzy, AddThis, Amazon Web Services and Assertive. Carnegie Mellon’s Information Networking Institute identifies both founders as alumni and describes Staris’s use of large language models to help identify code vulnerabilities.
Staris was founded in 2023. At the time of the funding announcement, the company had six employees. That figure described the January 2025 team and should not be treated as its current headcount.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallWho invested and how much?
Freestyle VC led the seed round. GeekWire reported the amount as $5.7 million, consistent with a Form D record showing $5,769,656 in securities sold by Staris AI, Inc.
Rank #3
GeekWire said Cecchetti declined to identify additional investors. A later LinkedIn post from Cecchetti thanked Freestyle’s Maria Palma and Vermilion Cliffs Ventures’ Ashley Smith, suggesting Vermilion Cliffs participated. That post is not a complete, independently confirmed investor list.
What the funding was for
The company said it planned to use the financing to expand its six-person team. That supports a broad description of the proceeds as funding additional product and engineering capacity and further platform development.
Freestyle general partner Maria Palma framed the investment partly around the shortage of qualified cybersecurity professionals. That is the investor’s rationale, not an independently measured result showing that Staris has solved the industry’s staffing problem.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsDoes Staris replace security engineers?
The available evidence supports an augmentation model, not wholesale replacement. Staris may automate repetitive investigation, validation and remediation work, but people still need to set security policy, determine acceptable risk, review generated patches and approve production changes.
Rank #4
Human expertise also remains important for unusual architectures, subtle business-logic flaws, incident response, threat modeling and testing outside the platform’s supported scope. Organizations may still need manual penetration testing where regulators, customers, insurers or auditors require an independent human assessment.
What Staris says it offers now
Staris’s current website emphasizes “Total Context Security,” exploit-proven findings, execution traces and PR-ready fixes. It also advertises private-VPC and self-hosted deployment options and says customer data is not used to train its models. These are vendor-stated capabilities and policies; a buyer should confirm their technical scope, contractual terms and treatment of data from third-party integrations.
The homepage publicly lists a starting price of $4,900 for one full validation cycle. The About page separately references economics as low as $2,083 per application per test in another pricing context. Those figures should not be treated as equivalent plans or as a complete enterprise price.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Staris also markets examples including 99% noise reduction, a case in which 590 scanner findings became six proven vulnerabilities, and “zero false positives.” These are company-published examples and claims, not independent comparative benchmarks.
Best Value
What a buyer should evaluate
| Question | Why it matters |
|---|---|
| What does it test? | Confirm support for the organization’s languages, frameworks, APIs, authentication flows, business logic and deployment models. |
| How is exploitation proved? | Ask whether findings include reproducible evidence and whether chained attacks or authorization flaws are covered. |
| What does a patch change? | Generated code still requires review for regressions, altered business behavior and incomplete fixes. |
| Where does data run? | Clarify source-code access, credentials, test data, runtime permissions, isolation and model-training policies. |
| How does it fit existing workflows? | Check integrations with source control, CI/CD, issue tracking, identity providers and role-based access controls. |
| What does the price measure? | Compare cost per application, test or validation cycle with the desired testing frequency and internal labor savings. |
| What requirements remain? | Determine whether customers, regulators or insurers still require human penetration tests or formal reports. |
How Staris fits the AppSec market
Staris’s proposed model sits between several established approaches rather than automatically replacing them:
- SAST and DAST scanners: Conventional static and dynamic tools can provide broad, repeatable coverage, but often require substantial human triage.
- Automated security validation: Platforms such as Pentera generally address broader breach-and-attack or infrastructure validation, while Staris presents itself as application-focused.
- Human-led testing: Cobalt combines a platform with human penetration testers and may be preferable when expert manual testing and formal deliverables are central.
- Developer AppSec platforms: Snyk and GitHub Advanced Security emphasize security controls embedded in development workflows, code, dependencies and related assets.
- Conventional web scanning: Burp Suite Enterprise Edition is an established automated web-application scanning option for teams seeking a more traditional DAST workflow.
These products are not presented here as feature-for-feature equivalents. The relevant choice depends on whether a team needs continuous testing, point-in-time assessment, human expertise, exploit evidence, patch generation, broader infrastructure coverage or compliance documentation.
The significance of the round
Staris’s opportunity is to reduce the labor needed to move from a scanner alert to a confirmed vulnerability and an acceptable fix. That is especially relevant as development teams release software more frequently and security teams face persistent staffing constraints.
The central risk is that automation can move mistakes faster as well as fixes. Exploit validation must be carefully authorized and scoped, particularly against production-like systems, while generated patches need human ownership and review.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

