
Kagliostro.cloud provides an autonomous security agent that continuously hunts for vulnerabilities across a company's repositories and APIs, validates which are genuinely exploitable, and prepares tested fixes. The agent operates in a self-directed loop, moving from objective to verified correction without human intervention in the middle steps. It reports an average detection time of under 90 seconds and a 4.2-minute average for generating pull requests.
Funding
Funding not disclosed
Founders
Product
Problem
Security teams are overwhelmed by hundreds of untriaged alerts, often missing the one critical issue that matters. Traditional tools point out potential problems without verifying if they are actually reachable or dangerous, and they rarely prepare fixes, leaving vulnerabilities open for months. Annual security audits become obsolete quickly, creating noise that saturates developers while real risks remain exposed.
Solution
Kagliostro.cloud provides an autonomous security agent that takes a result-oriented mission rather than a predefined procedure. The agent analyzes authorized repositories and services, builds its own action plan, and determines what to examine and in what order. It investigates potential issues, proves exploitability in a sandbox environment, and prioritizes findings by explaining the urgency. Once a problem is confirmed, Kagliostro prepares the code fix, tests it to ensure no regressions, and presents the result for final approval. The entire loop—from objective to verified correction—runs autonomously, with the human retaining the last word before changes are applied.
Target Audience
Primary customers are technical teams and CISOs at demanding enterprises that need continuous, verified security remediation across their software development lifecycle.
Features
- Fully autonomous security loop: finds, verifies, prioritizes, fixes, and validates without manual step-by-step guidance
- Sandbox-based proof of exploitability, eliminating false positives with a 0% false positive rate (PoC required)
- Automatic pull request generation with an average delivery time of 4.2 minutes
- Continuous 24/7 monitoring of 2,500+ repositories and APIs
- Objective-driven interface where users state goals like "secure our login service" rather than configuring tools
- Regression testing built into the correction workflow to ensure fixes do not break existing functionality