
Hadrian Raises $40M—Offensive AI Becomes a Funding Category

On October 6, 2026, Amsterdam-based Hadrian raised $40 million in a round co-led by Forgepoint Capital International and SmartFin, with HV Capital, Motive Partners, Picus Capital and Oetker Ventures also participating, bringing its total funding to $65 million. The proceeds are intended for expansion across Europe, the Middle East, Africa and the United States, alongside more engineering and research investment.
The financing gives an automated offensive security company fresh capital to sell and develop a platform that looks for exposed assets continuously, then runs deeper tests when a customer requests them. In Forgepoint’s investment note, partner Damien Henault wrote that “we haven’t seen another solution that combines this breadth and depth in a single platform.” That is a funder’s assessment of Hadrian’s competitive position, not an independent product comparison.
Why investors backed the expansion
The capital plan combines a wider presence in EMEA and the United States with further work on the product itself. The company has not disclosed how it will divide the money between market expansion and engineering, or when the additional investment will be complete. Its existing customer list spans European and US enterprises, giving the expansion plan a commercial base.
The investment case centers on a gap between collecting vulnerability alerts and knowing which exposures can actually be used. Scanners can leave teams with more findings than they can investigate, while periodic manual penetration tests provide only intermittent coverage. A service that maps exposed assets continuously and validates selected risks could change how teams allocate testing time. The round establishes investor interest in that approach; it does not establish that every deployment will outperform an existing testing program.
For the co-leads, the round makes a specific funding thesis concrete: broad exposure management and on-demand offensive testing sold together to enterprises. If the discovery layer passes useful context to a deeper test, analysts may spend less time rebuilding an asset picture for each engagement and more time deciding which findings warrant remediation. Whether that operational benefit appears consistently is a question for customer evaluations.
What Atlas and Nova actually do
Hadrian’s products perform related but distinct jobs. Tech.eu’s platform account describes Atlas as continuously mapping an organization’s external attack surface and using AI agents to assess exploitable exposures; Nova performs on-demand agentic penetration tests. The products share context, so a risk surfaced in broad monitoring can become the subject of a more focused test.
That split matters when comparing the service with manual testing. Discovering an asset absent from an inventory is a visibility result; confirming that a weakness is exploitable is a validation result; demonstrating an attack path in a defined penetration test is a deeper assessment. Combining those results into one headline measure would obscure which component produced which benefit and whether a human tester would have covered the same assets.
People still set the objectives and make consequential decisions in the operating model described for the platform. Because an externally visible system is not automatically an authorized test target, a deployment needs an explicit scope for active probing, clear ownership of targets and a way to stop or review unexpected behavior. Those boundaries are especially relevant when an automated test could interact with a live service rather than merely observe it.
How much weight to give the performance figures
Hadrian’s funding announcement names Leroy Merlin and Damen Shipyards among its customers and attributes to customers 10x greater visibility into critical exposures, 80% faster time to resolution and 5x return on investment compared with manual penetration testing. These are customer-derived vendor claims, not independent benchmarks. The published figures do not identify a common sample, assessment period or calculation method for reproducing the comparisons.
Each outcome requires its own baseline. Visibility depends on which assets and critical exposures were counted before deployment; resolution speed depends on whether the clock stopped at a proposed fix or a verified one. Return on investment depends on subscription and implementation costs, staff time, manual testing expense and the value assigned to risks found. A large improvement in one measure cannot establish an equivalent improvement in another.
A comparable evaluation would hold asset scope and assessment period constant across automated and manual approaches, then record independently verified exploitable findings, missed findings and false positives. It would separate continuous discovery from requested penetration tests and document which actions required human approval. That evidence would show whether the combined workflow adds coverage, reduces triage work or moves that work to another part of the security team.
For buyers, the immediate consequence of the round is a better-funded supplier pursuing a broader market, while a decision about replacing manual tests still turns on measured results in their own environments. The next meaningful evidence will be customer comparisons that disclose scope, baseline and review method, particularly where an automated test finds a risk that periodic testing missed or produces a finding a human reviewer rejects.
Also read:
Related articles


Nettle Raises $4.8M—Its Fivefold Speed Claim Is Still Vendor-Reported

7 Signs You've Outgrown Spreadsheet-Based Cap Table Management

Supabase Raises $150M and Buys Turso—Agent Databases Get Two Engines

Cohere North 2 Gives Agents Memory—and Admins Token Caps

Google Pauses OSS Bug Reports After Automated Submissions Flood Triage
Subscribe to our newsletter
Get the latest Web3, AI, and crypto news delivered straight to your inbox.