I recently sat down with Rene Brandel and Ian Saultz, the founders of Casco, to talk about what they’re building and why we were excited to lead their Series A at Standard Capital.

At a high level, Casco is an agentic security engineer that hacks your software 24/7 and tells you how to patch it.

Penetration testing has always been one of those security categories every serious company eventually needs. Sometimes the immediate reason is procurement: a large customer wants proof that your product has been tested before signing a contract. Sometimes the reason is even simpler: your business depends on customer trust, and a single serious vulnerability can be existential.

Historically, solving this meant hiring humans to hack your software. That is useful, but slow. A traditional pentest can take weeks to schedule and weeks more to complete, and the output depends heavily on who you get. Even good pentesters are constrained by time and attention: they can look broadly, form hunches, and go deep on a few areas, but they cannot exhaustively test every part of a modern attack surface all the time.

Casco changes that. By using AI agents to perform offensive security work, Casco can start immediately, test continuously, and return results in hours rather than weeks. More importantly, it can run on every deployment. Instead of discovering your security posture once a year, you can understand it continuously.

The why-now is very strong. AI is causing the amount of code being written to explode. A lot of that code will be lightly reviewed, generated by agents, or shipped faster than traditional engineering processes were designed to handle. At the same time, vulnerabilities are being exploited faster than ever. What used to take months to reverse engineer can now happen in days, hours, or eventually minutes. More code, more vulnerabilities, faster exploitation. Those curves multiply.

One thing Rene and Ian said that stuck with me was the idea of “security slop.” We all understand code slop: gigantic AI-generated PRs where nobody really knows what changed. Security has its own version. If you ask an automated system to find security issues and it gives you a thousand alerts, 99% of which are false positives, it has not really helped you. It has created more work for security teams that are already drowning. Casco’s product philosophy is the opposite: high-signal findings, clear reproduction steps, and actionable guidance on what actually needs to be fixed.

That is also why compliance matters. Companies do not just need a scanner; they often need a report they can use with real customers. Casco combines agentic testing with human security review and certification, including CREST-certified pentesting and PCI-compliant pentests. That combination gives customers the speed of automation without losing the accountability required for procurement and compliance.

The team is unusually well suited to this problem. Rene spent years at Microsoft and AWS and helped build Kiro, AWS’s agentic IDE. Ian was a software engineer at AWS and worked deeply on application security review and external penetration testing. They saw the tension from the inside: companies want to ship faster, but security review slows everything down. With AI-generated software, that tension only gets more intense.

Casco’s early trajectory has been impressive. The company went through YC, pivoted into this idea within the first couple of weeks, hired quickly, and is now building an in-person team in San Francisco with an additional engineering hub in Seattle. In roughly the first 15 months, Casco has already found critical vulnerabilities in over 400 companies it pentested — often in companies that were already using other security tools. That is a powerful signal that runtime, agentic testing is catching issues existing tools miss.

Security is one of the clearest examples of a category where AI can be better than the old workflow, not just cheaper or faster. The bad actors are getting faster. The codebase is getting larger. The attack surface is expanding to web apps, APIs, infrastructure, mobile, and AI agents. Every company will need a way to test itself continuously.

Casco is on the right side of that shift. We’re thrilled to partner with Rene, Ian, and the Casco team as they build the agentic security company for the AI era.