Hackuity raises $19M to tame the AI-driven vulnerability flood
Forgepoint Capital International leads a $19M round into Lyon's Hackuity, with Bpifrance and Seventure returning - a bet that AI-found vulnerabilities need triage at machine speed.
Also see more funding coverage: /category/funding/
Founded 2018 · Lyon, France
Lyon-based Hackuity has raised $19 million in a round led by Forgepoint Capital International, with Bright Pixel, Bpifrance and Seventure Partners all returning, to scale its AI-powered vulnerability management platform across Europe and Asia.
Security teams have never had more tools telling them what is broken, and never less capacity to fix any of it – and yet European cybersecurity keeps closing rounds this week. After Exein’s $270M for physical AI security on Monday, the cheque lands in Lyon. Below, I lay out the round, the company behind it, and what a US specialist fund keeps finding in French cyber.
Forgepoint leads, the French bench re-ups
The round, announced on 16 September 2026, is $19 million and carries no stage label from the company; Tech Funding News reads it as a Series B. It is led by Forgepoint Capital International, the London-based European arm of US cybersecurity specialist Forgepoint Capital, and joined by Bright Pixel, Bpifrance and Seventure Partners – all existing investors, per the company announcement. Total raised to date: $38 million.
The money goes to product development and the expansion of Hackuity‘s AI capabilities, plus international growth focused on Europe and Asia, the company says. “What we built before the wave arrived is exactly what enterprises need now that it’s here,” is how co-founder and CEO Patrick Ragaru frames it in the announcement.
Seven years of triage built in Lyon
Founded in June 2018 by Patrick Ragaru and Pierre Samson, Hackuity runs what it calls a Vulnerability Operations Center: a platform that pulls findings from more than 130 security tools, layers threat intelligence and business context on top, and tells a security team which of its thousands of open vulnerabilities actually deserve a human this week. Everything else waits, deliberately.
The company operates from Lyon and Paris with offices in Singapore and London, a team of more than 40 people per Tech Funding News, and customers that read like a French blue-chip roster: ENGIE, BPCE and Orange Cyberdefense are named in the announcement, which counts more than 6,000 users managing over 2 million assets and a billion findings on the platform.
That last number is the story. A billion findings is not a to-do list; it is a census of everything nobody will ever read. The product’s entire premise is that the list stopped being the point years ago.
A $19bn problem compounding at 6.93%
The segment Hackuity sells into is well sized: the global security and vulnerability management market stands at $19.14bn in 2026 and is projected to reach $32.71bn by 2034, a 6.93% CAGR (Fortune Business Insights, August 2026). Feeding that growth, the company points to roughly 350,000 known CVEs, a pile growing about 20% year on year – and AI models are now finding flaws faster than humans can patch them.
For scale from our own fundraising data: this is the third European cybersecurity round we have logged in three days, after Rome’s Exein raised $270 million on 15 September and the Dutch secure-processor company Fortaegis announced $50 million on 14 September. Three rounds, three countries, one sector – September is making its own argument.
What a specialist fund sees in French cyber
So why does US cyber money keep finding its way to France? Forgepoint opened its London hub precisely to catch European security companies at the growth stage, where our own funds still thin out – the well-documented gap between Europe’s strong seed benches and its scarce growth cheques. When a specialist with that mandate leads in Lyon rather than London or Tel Aviv, it is a signal about where the deep, unglamorous security engineering actually lives.
The good news is the French side of the table did not step back: Bpifrance and Seventure re-upping alongside a US lead is the pattern we want to see more of – domestic conviction holding its ground as international capital arrives. Worth watching next: whether Hackuity’s Asia push turns Singapore from an office into a second market, and whether the unlabelled round gets a Series C sequel with a European lead.
Lyon has spent seven years building the boring, load-bearing layer of security – the part that decides what gets fixed. The opportunity is clear: the flood of AI-found vulnerabilities is only rising, and the companies that triage it at machine speed will be the ones everyone else stands on. Keep building it here.