Parameter
Also known as: Hex Security
Autonomous offensive security agents, renamed Parameter in July 2026, that pentest apps and APIs, trace cloud and supply chain attack paths and review pull requests, proving each finding with a working exploit.
Hex Security renamed itself Parameter on 30 July 2026; the company, Anytool, Inc., says the same agents run the same pentests, and hex.co now redirects to parameter.ai. Parameter sells autonomous offensive security agents across four products, plus a fifth, Secrets Detection, which finds leaked credentials across repositories and their history. Pentesting runs many agents in parallel against a customer's applications, APIs, auth flows and business logic, then verifies each finding from a clean state and delivers it with reproduction steps, a working proof of concept and remediation guidance.
Cloud Security connects to AWS, Google Cloud and Azure through a read only role, maps resources, identities and trust relationships to trace attack paths, and proposes fixes as Terraform pull requests. Supply Chain resolves the dependency graph, flags malicious and vulnerable packages, keeps an SBOM current and opens version bump pull requests. Sentinel reviews each pull request in GitHub, GitLab or Bitbucket Cloud as it opens, posts findings as inline comments and turns developer feedback into reusable rules.
Agents stay inside the targets the customer authorizes, test non-destructively, and hold after proving a finding unless the customer opts in to chaining or escalation. Parameter states a SOC 2 Type I report with Type II underway, SSO, MFA, role based access and audit logging, and US data processing. The founders are Huzaifa Ahmad, Ahmad Khan and Prama Yudhistira, and the company is backed by Y Combinator. It is distinct from the Hex data analytics company at hex.tech.
Vendor details
Canonical URL
https://www.parameter.ai
Category
Security / SOC agent
Funding status
Private, early stage. Y Combinator Winter 2026 batch, backed by Y Combinator and Pioneer Fund. Founders Huzaifa Ahmad (ex-PlayAI and AWS), Ahmad Khan (ex-OpenAI), and Prama Yudhistira (ex-PlayAI and AWS).
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
GitHub, GitLab and Bitbucket Cloud (pull request review and fix pull requests), Linear and Jira (issues and tickets), and AWS, Google Cloud and Azure through a read only role, with Oracle Cloud and Kubernetes also covered. Supply chain testing covers npm, Yarn, pnpm, Bun, pip, Poetry, uv, Go modules, Maven, Gradle, Cargo, Bundler and Composer. There is no public API, SDK, CLI or MCP server.
In practice
Your team ships to production several times a day, but the pentest happens once a year. Parameter's Continuous tier runs an autonomous pentest on every deploy and reports only findings it has reproduced with a working exploit.
Your AWS and Google Cloud accounts have grown faster than anyone can review. Parameter's cloud agents map every resource and identity through a read only role and open Terraform fixes as pull requests.
Developers merge code before security sees it. Sentinel reviews each pull request as it opens and leaves inline comments on exploitable issues in GitHub, GitLab or Bitbucket.
Sources & related URLs
Agentic Index coverage score
7.5 / 14 capabilities · 54%
| Integrations & Tool Calling | Full |
|---|---|
|
Sentinel posts findings as inline comments on pull requests in GitHub, GitLab and Bitbucket Cloud. Findings open Linear issues and fix pull requests (Terraform patches and dependency bumps), and cloud agents connect to AWS, Google Cloud and Azure through a read only role. Developers can also open Jira tickets from a comment, cloud agents now cover Oracle Cloud and Kubernetes too, and a findings dashboard tracks every connected repository. SourceParameter, parameter.ai/sentinel and /cloud-securityread 2026-10-05 |
|
| Workflow Orchestration | Full |
|
Hundreds of agents work real attack paths in parallel, split across probe, exploit and verify stages. They map every endpoint, parameter and auth flow, try to break expected behavior the way an attacker would, then reproduce each issue from a clean state. Cloud agents reason about how misconfigurations chain together into attack paths. SourceParameter, parameter.ai/pentesting and /cloud-securityread 2026-10-05 |
|
| Knowledge Grounding & RAG | Partial |
|
Agents build a model of the customer's estate. Cloud agents map every resource, identity and trust relationship, supply chain agents resolve the full dependency graph and keep an SBOM current, and Sentinel reads the diff, surrounding code and execution paths. Parameter names no retrieval store it maintains for the agents. Testing can run whitebox, greybox or blackbox, from just a URL and credentials up to full source code access, and cloud agents map more than 100 services such as EC2, S3, IAM, Lambda and RDS. SourceParameter, parameter.ai/cloud-security, /pentesting and /sentinelread 2026-10-05 |
|
| Human Oversight & Guardrails | Partial |
|
Agents stay inside the targets the customer authorizes, and testing is nondestructive. After proving a finding the agent confirms it and holds, with no chaining or escalation unless the customer opts in, and researchers can choose a deeper follow up on any finding. Beyond that scope and opt in, Parameter names no approval step for each action. Fix pull requests merge in the customer's repository. SourceParameter, parameter.ai/pentesting and parameter.airead 2026-10-05 |
|
| Security, Identity & Governance | Full |
|
A SOC 2 Type I report is in place, with the Type II observation period underway. Parameter also offers a HIPAA BAA and GDPR DPA. SSO, MFA, role based access controls and audit logging cover the whole platform. Data is encrypted in transit and at rest, staff are background checked, and Parameter is tested continuously by its own agents alongside independent third party review. SourceParameter, parameter.ai/securityread 2026-10-05 |
|
| Observability & Auditability | Full |
|
Each finding comes with reproduction steps and proof of concept. The agents keep their own action record, and every action an agent takes is logged and reviewable, so the customer can see exactly what happened. Each cloud run produces a shareable report of validated findings with evidence, and pentest reports map findings to SOC 2 and ISO 27001 controls for auditors. SourceParameter, parameter.ai, /cloud-security and /pentestingread 2026-10-05 |
|
| Memory & State Persistence | Partial |
|
In Sentinel, feedback from developers becomes reusable Rules that teach Sentinel the codebase and improve its next review. The Rules are stored and scoped to the codebase. Parameter does not say how the Rules are viewed, edited or expire. Sentinel improves with every review. SourceParameter, parameter.ai/sentinelread 2026-10-05 |
|
| Deployment & Data Residency | Not documented |
|
Processing sits in one fixed region. Data is processed in the US and never leaves the customer's assigned infrastructure. Customers cannot choose the region, and the product is SaaS only, with no customer hosted option. Personal data is kept only as long as the service, the customer's instructions or the law require, and EEA, UK and Swiss transfers run under Standard Contractual Clauses. SourceParameter, parameter.ai/securityread 2026-10-05 |
|
| Prebuilt Agents / Templates / Packs | Full |
|
Parameter sells four agent products, each with its own job. Pentesting covers application and API attack paths, Cloud Security covers AWS, Google Cloud and Azure attack paths, Supply Chain covers the dependency graph and SBOM, and Sentinel reviews pull requests. A fifth product, Secrets Detection, finds leaked credentials across repositories and their history. SourceParameter, parameter.airead 2026-10-05 |
|
| Triggers & Channel Coverage | Full |
|
Code and deploy events start the work without a person. Sentinel reviews each pull request the moment it opens, the Continuous tier runs a pentest on every deploy, supply chain testing reruns on every push, and cloud runs go on demand or on every release. First findings land within 24 hours, and a newly connected cloud account shows findings within 15 minutes. SourceParameter, parameter.ai/sentinel, /pentesting, /cloud-security and parameter.airead 2026-10-05 |
|
| Model Flexibility & Routing | Not documented |
|
Parameter names no model provider and offers no customer model choice or routing. Customer personal data is never used to train foundation models. The agents reason through attack paths rather than running down a checklist. SourceParameter, parameter.ai/security and /pentestingread 2026-10-05 |
|
| APIs / SDKs / MCP Extensibility | Not documented |
|
Parameter publishes no public API, SDK, CLI or MCP server. Its only free tool is a browser CVSS calculator. Teams work with Parameter through its code host integrations, Jira and Linear instead. SourceParameter, parameter.ai and /sentinelread 2026-10-05 |
|
| Testing, Debugging & Optimization | Not documented |
|
Findings are verified by reproducing them from a clean state with a working exploit, and unproven findings are dropped. That check tests the customer's estate inside Parameter's own pipeline, and Parameter names no way to evaluate the agents themselves. It reports under 1% false positives. SourceParameter, parameter.ai/pentesting and parameter.airead 2026-10-05 |
|
| Browser / Computer-use | Not documented |
|
Agents test web apps, APIs, auth flows and business logic. Parameter names no browser or computer use by the agents. SourceParameter, parameter.ai/pentestingread 2026-10-05 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
Contact for pricing. Three pentest tiers are published without prices: Single App, Rightsized and Continuous.
Rightsized tests are scoped from repos, endpoints and roles; Continuous runs a pentest on every deploy.
Cost watchouts
Inference, not stated by the vendor: Continuous coverage on every deploy likely costs more than a single time-boxed test as release frequency rises.
Variable cost rationale
Rightsized pricing is sized from repos, endpoints and roles, so cost tracks the size of the attack surface; no rate is published.
Sales call required
Yes, required for paid access
Free / trial
No free pentest or trial stated; the Single App tier includes free re-testing.
Key ambiguities
No prices are published for any tier.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Parameter
The closest documented capability profiles to Parameter among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Exaforce8.0 / 14Fuller documented coverage on Knowledge Grounding & RAG and Human Oversight & Guardrails
- 7AI8.5 / 14Adds documented Deployment & Data Residency
- Magnitude8.5 / 14Adds documented APIs, SDKs & MCP Extensibility and Testing, Debugging & Optimization
- Abnormal AI9.0 / 14Adds documented Deployment & Data Residency and APIs, SDKs & MCP Extensibility, among others
- AirMDR6.0 / 14Fuller documented coverage on Human Oversight & Guardrails
- Astelia8.0 / 14Adds documented APIs, SDKs & MCP Extensibility
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded