Pi raises $35M to automate the hardest part of cybersecurity
What's the deal? Pi, an agentic product security platform based in San Francisco, has raised $35M in funding led by Brightmind PartnersDealroom has a profile for this one. Try Dealroom → and Third Point VenturesDealroom has a profile for this one. Try Dealroom →. CrowdStrike chief executive officer George KurtzDealroom has a profile for this one. Try Dealroom → and Armis founders Yevgeny DibrovDealroom has a profile for this one. Try Dealroom → and Nadir IzraelDealroom has a profile for this one. Try Dealroom → also backed the round. Pi builds what it calls a "security brain" — a system that absorbs an organisation's entire codebase, design documents, cloud infrastructure, and internal communications to remediate vulnerabilities autonomously and at machine speed.
Its customers already include a frontier AI lab, major cybersecurity firms, a large social network, and category leaders in travel and insurance. The company says customers have cut triage time by up to 80%.
Why now? AI has compressed software development cycles dramatically — review periods that once took ten days now take two, and most of the Fortune 100 already build with AI. Security hasn't kept pace. Detection tools, including new AI models like AnthropicDealroom has a profile for this one. Try Dealroom →'s Claude-Mythos, can now surface flaws at a scale no human team can match. But finding bugs was never the bottleneck; fixing them is.
Real remediation means producing a fix that withstands attack, doesn't break surrounding systems, and catches the same weakness wherever else it lurks. "If even the most powerful, best-resourced organisations on earth keep chasing the same recurring vulnerabilities across their code and infrastructure, the problem has no real solution today," said Guy AraziDealroom has a profile for this one. Try Dealroom →, Pi's co-founder and chief executive officer.
What could go wrong? Autonomous remediation at scale is a bold promise. A system that pushes code fixes across an entire codebase without human review introduces its own risk — one bad patch could cascade. Pi also faces a crowded market: legacy application-security vendors are racing to bolt AI onto their own products, and well-funded startups are targeting adjacent parts of the same workflow.
Convincing security teams to trust an AI agent with write access to production code requires a level of confidence that takes time to build, no matter how strong the underlying technology.
The signal: Pi's raise reflects a broader shift in cybersecurity from detection to remediation as the defining challenge. As AI-generated code floods enterprise systems, the volume of vulnerabilities is growing faster than human teams can fix them. The emerging bet is that security itself must become agentic — not just flagging problems but resolving them.
"Pi approaches the problem from a completely different angle, building an agentic system that understands the full development environment and ships fixes autonomously," said Sapir Harosh, partner at Third Point Ventures. If that thesis holds, the value in security tooling shifts from scanning to action — and the companies that own remediation could own the category.
Read more: ACCESS Newswire