DragonSec

Munich-built agentic application security

AI-speed security for the software, data, and agents your business depends on.

DragonSec validates exploitable paths, blocks risky packages, finds exposed credentials, and gives AI agents enforceable runtime boundaries before attackers turn speed into business risk.

Born from a research project at Oxford University and the Technical University of Munich.

112K monthly OSS downloads / 51 enterprise accounts / 64 paying customers / Germany's open-source-first agentic AppSec leader
dragonsec.ai / live validation

AgentBouncer

Validated exploit chain in live API tenant boundary

critical
Recon agent: passed Exploit agent: confirmed Reporter agent: ready

Network Shield

4.8M dependency install events evaluated

Credential Watch

318K credential-like exposures triaged

Agent Gate

1.2M AI and tool-call interactions evaluated

scope = app.dragonsec-customer.example

mode = live, gray-box, api, ai-agent

report = evidence-backed, retestable, exec-ready

Live red teaming PR security review Prompt injection Indirect prompt injection SSRF chains Auth & tenant bypass RAG abuse Tool-call misuse Typosquatting Dependency confusion Malicious packages Hardcoded secrets Non-human identities Runtime guardrails Exploit validation Live red teaming PR security review Prompt injection Indirect prompt injection SSRF chains Auth & tenant bypass RAG abuse Tool-call misuse Typosquatting Dependency confusion Malicious packages Hardcoded secrets Non-human identities Runtime guardrails Exploit validation

Traction in the first year

112K
monthly open-source downloads
~2K
GitHub stars
14
employees
64
paying customers
51
enterprise accounts
#1
Germany's open-source-first agentic AppSec company
EUR 18.7M
estimated customer risk exposure reduced

Open-source ecosystem

Germany's largest open-source-first agentic AppSec presence by monthly downloads across security, architecture governance, and agent-safety tooling.

DragonSec
DragonBreath
ArchUnit Python
ArchUnit TS
KubeShark
TerraShark
DragonSec
DragonBreath
ArchUnit Python
ArchUnit TS
KubeShark
TerraShark

Platform

One security operating layer from pull request to live agent runtime.

DragonSec is built for B2B teams that need evidence, not alert theater. Start with the highest-pain workflow, then expand into a platform that keeps proving and reducing risk.

Why now

AI changed the throughput of software and offense at the same time.

The market data is no longer theoretical. Read it as one argument: more code is written by AI, that code ships with flaws, attackers now automate too, and supply-chain plus credential exposure are compounding faster than manual security can absorb.

  1. 01
    24%

    of production code is AI-written globally

    Aikido State of AI in Security & Development 2026

  2. 02
    69%

    of organizations found vulnerabilities introduced by AI-generated code

    Aikido State of AI in Security & Development 2026

  3. 03
    42%

    of committed code is already AI-generated or AI-assisted by developer estimate

    Sonar AI coding survey

  4. 04
    45%

    of AI-generated coding tasks introduced risky flaws in Veracode testing

    Veracode GenAI Code Security Report

The conclusion is operational: enterprises need agentic security that can test, block, and govern at the same speed software is now written.

See the full evidence

Go-to-market

Vision-led, sales-led, service-led, then productized.

DragonSec enters through urgent customer pain, deploys with field security engineers, and turns repeated patterns into reusable platform modules.

01

Sales-led discovery

DragonSec enters with executive and technical workshops to map the real bottleneck: live VAPT, PR review, AI-agent safety, dependency exposure, credential sprawl, audit pressure, or enterprise customer trust.

02

Service-led deployment

Field security engineers connect DragonSec to repositories, build systems, package networks, SIEM, ticketing, AI gateways, and scoped test environments so the first deployment produces proof quickly.

03

Agentic validation

Security agents test, replay, and validate exploitable paths. Findings include evidence, reproduction, confidence, business impact, and remediation guidance.

04

Productized patterns

Repeated customer requests become reusable policy packs, integrations, playbooks, dashboards, and release gates so services work compounds into platform margin.

Authorized testing, EU-first deployment, and audit-ready evidence built for enterprise security reviews.

SOC 2ISO 27001GDPREU-only hostingSSO / SAML / SCIM

Mission

Our mission is to give every enterprise AI-speed security for the software, data, and agents their business depends on.

The company is not selling another scanner. DragonSec sells security that keeps digital business moving: authorized agents that test first, controls that block unsafe build inputs, credential intelligence that reduces blast radius, and runtime guardrails for AI systems.

Get started

See how DragonSec would test your product.

Book a discovery session. We will map the right entry point, show a tailored demo, and scope the first deployment sprint.