{"slug": "parameter", "title": "Parameter", "summary": "Parameter, a Y Combinator-backed security startup, launched a platform of AI agents that continuously find vulnerabilities in web apps, APIs, and infrastructure, claiming first findings within 24 hours and less than 1% false positives. The company says its agents have prevented more than $30 billion in breaches and pair autonomous pentesting with a pull-request reviewer called Sentinel, cloud misconfiguration checks, secrets detection, and dependency management. Parameter states its agents confirm a vulnerability and then stop, with no destructive actions and a full audit trail, positioning the product against traditional pentests that take weeks to scope and cost six figures per engagement.", "body_md": "Backed by Y Combinator\n\n# Security at the speedof development.\n\nAI agents that find vulnerabilities in your web apps, APIs, and infrastructure. Continuously, not once a year.\n\nSee first findings in 24 hours\n\n$30B+\n\nin breaches prevented\n\n<1%\n\nfalse positives\n\n24/7\n\ncontinuous coverage\n\nBuilt by the team that secured:\n\nBuilt by the team that secured:\n\n[ the problem ]\n\n## Software ships every day.Security testing hasn't kept up.\n\nOld Way\n\nWeeks to schedule\n\nand scope.\n\nSix figures per engagement.\n\nA PDF that's already stale on arrival.\n\nOne snapshot, then blind for 12 months.\n\nThe Parameter Way\n\nPoint us at your app,\n\neasy scoping.\n\nRuns continuously,\n\non demand.\n\nEvery finding ships a working proof-of-concept.\n\nProbes every hour, every day.\n\n[ how it works ]\n\n[ The product ]\n\n## Findings you can act on.Validated, prioritized, and ready to assign.\n\nBook a call\n\nSee first findings in 24 hours\n\nFindings\n\n›\n\nAcme API pentest\n\n›\n\nACME-142\n\nSQL injection in /api/users search param\n\nThe search parameter on GET /api/users is concatenated directly into a SQL query without parameterization. An attacker can inject arbitrary SQL to read or modify data belonging to other tenants.\n\nReproduction\n\nGET /api/users?search=' OR '1'='1\n\n→ 200 OK · returns all users across tenants\n\nThe vulnerable code interpolates the raw value into the WHERE clause in users-repository.ts:42.\n\nActivity\n\nJordan Lee\n\ncreated this finding\n\n3d ago\n\nAlex Rivera\n\nchanged status to In Progress\n\n2d ago\n\nMaya Chen\n\nassigned this to Jordan Lee\n\n1d ago\n\nAdd a comment...\n\nProperties\n\nStatus\n\nOpen\n\nSeverity\n\nCritical\n\nAssignee\n\nJ\n\nJordan Lee\n\nRating\n\nCWE\n\nCWE-89\n\nDeadline\n\nOverdue · Jun 12\n\nLocations\n\nusers-repository.ts:42\n\nOpen a fix PR\n\nCreate Linear Issue\n\nCopy AI Instructions\n\nSearch findings\n\nOpen\n\n21\n\nIn Progress\n\n6\n\nFixed\n\n15\n\nShowing 1 to 25 of 47 findings\n\n‹ Previous\n\nPage 1 of 2\n\nNext ›\n\n[ coverage ]\n\n## One platform.Every layer of your security.\n\nParameter runs continuously across your code, cloud, and dependencies, and puts everything it finds in one place.\n\n### Pentesting agent\n\nContinuous, autonomous pentesting, with a working proof-of-concept for every finding.\n\n### Sentinel\n\nAn AI reviewer on every pull request. Catches vulnerabilities before they merge.\n\n### Cloud security\n\nContinuous checks for cloud misconfigurations, exposed services, and takeover risk.\n\n### Secrets detection\n\nLeaked keys, tokens, and credentials found across your repos and history.\n\n### Dependency management\n\nVulnerable and outdated packages flagged, with a clear path to safe versions.\n\nMore detail on each surface\n\nLearn more\n\n[ safety ]\n\n## Aggressive testing.Zero blast radius.\n\nAll the findings of a real attack, none of the fallout.\n\nlearn more about safety\n\n### Confirm and hold\n\nAgents prove a vulnerability exists, then stop. No chaining or escalation without your explicit go-ahead.\n\n### Scoped, never stray\n\nAgents stay inside the targets you authorize. No wandering into systems that aren’t in scope.\n\n### No destructive actions\n\nNo dropped tables, no deleted data, no denial of service. Testing is safe against production by design.\n\n### Full audit trail\n\nEvery action an agent takes is logged and reviewable, so you can see exactly what happened.\n\n## Start testing today.\n\nA URL and credentials is all it takes.\n\nFirst findings land within 24 hours.", "url": "https://wpnews.pro/news/parameter", "canonical_source": "https://www.parameter.ai", "published_at": "2026-09-11 00:36:50+00:00", "updated_at": "2026-09-11 00:53:05.397065+00:00", "lang": "en", "topics": ["ai-agents", "ai-products", "ai-startups"], "entities": ["Parameter", "Y Combinator", "Sentinel", "Jordan Lee", "Alex Rivera", "Maya Chen"], "alternates": {"html": "https://wpnews.pro/news/parameter", "markdown": "https://wpnews.pro/news/parameter.md", "text": "https://wpnews.pro/news/parameter.txt", "jsonld": "https://wpnews.pro/news/parameter.jsonld"}}