QuestorAI raises $3M to bring autonomous vulnerability remediation to enterprises in a round led by Paladin Capital Group with participation by Denver Ventures.
The founders Rob, Graham and Dan lived the pain engineers face every day. Engineers are drowning in tickets and PRs typically with limited context and ambiguous findings. Engineers constantly use to ask us, “Can’t you just fix this for us?”. Generative AI opened the door to combine a deterministic computer science approach with LMMs to do just that. Our entire goal is to remove the toil from engineers plates, and let them get on with building products.
The funding will be used to accelerate development of QuestorAI’s analysis and autonomous remediation platform, expand its work with enterprise design partners, and build out the team as the company moves toward broader availability.
Software development has changed forever. AI enables engineering teams to create software at an accelerated rate and scale, while simultaneously increasing the speed and efficiency with which attackers can exploit software. Security can no longer afford to become a growing backlog of engineering work.
Organizations need to identify and remediate exploitable vulnerabilities at the pace software is now created.
Traditional application security tools generate lists of findings for engineers to resolve. Each finding must be triaged, investigated, validated/dismissed, remediated and tested. These workflows were already a burden on engineering teams; they do not scale to a world where AI is dramatically accelerating software development. Simply generating more findings faster does not solve the problem.
QuestorAI removes that burden from engineers, it does not create security work for engineers, it removes it. It gives engineering and security teams the evidence and control needed to build confidence in autonomous remediation progressively, rather than asking them to trust automation on day one.
QuestorAI’s analysis engine combines deterministic code analysis with the precise use of foundational or locally deployed LLMs. Rather than overwhelming engineers with potential findings, QuestorAI focuses on vulnerabilities that analysis shows can affect the application. Engineers are provided with rich context of the issues and are given validated fixes that preserve the intended behavior of the code. As teams build confidence in the system, those fixes can be applied autonomously. Dramatically reducing the ticket/PRs queues.
For security teams, QuestorAI is designed for easy deployment without proprietary rule languages, rule-package maintenance or complex configuration. With locally deployed models, source code can remain entirely within the customer environment. When external models are used, QuestorAI minimizes the amount of code and context sent for inference. This targeted use of language models reduces both inference cost and unnecessary data exposure.
“Security shouldn’t be another system engineers have to operate,” said Graham Calladine, CEO and co-founder of QuestorAI. “It should behave more like infrastructure: always there, continuously working and increasingly autonomous. Engineers should spend their time designing and building products, not responding to security tools.”
QuestorAI is currently working with design partners across major technology companies and regulated enterprises to validate the platform against real-world production codebases.
About QuestorAI
QuestorAI is an application security company built to remove security toil from engineering teams. Our autonomous remediation platform identifies vulnerabilities that matter, determines whether they can be exploited, generates and validates fixes, and can apply those fixes automatically. Allowing engineers to spend their time building software rather than responding to security tools.
