Back to vendors
P

Parameter

Also known as: Hex Security

Visit site
Entry priceContact for pricing. Three pentest tiers are published without prices: Single App, Rightsized and Continuous.Full pricing detail

Autonomous offensive security agents, renamed Parameter in July 2026, that pentest apps and APIs, trace cloud and supply chain attack paths and review pull requests, proving each finding with a working exploit.

Hex Security renamed itself Parameter on 30 July 2026; the company, Anytool, Inc., says the same agents run the same pentests, and hex.co now redirects to parameter.ai. Parameter sells autonomous offensive security agents across four products, plus a fifth, Secrets Detection, which finds leaked credentials across repositories and their history. Pentesting runs many agents in parallel against a customer's applications, APIs, auth flows and business logic, then verifies each finding from a clean state and delivers it with reproduction steps, a working proof of concept and remediation guidance.

Cloud Security connects to AWS, Google Cloud and Azure through a read only role, maps resources, identities and trust relationships to trace attack paths, and proposes fixes as Terraform pull requests. Supply Chain resolves the dependency graph, flags malicious and vulnerable packages, keeps an SBOM current and opens version bump pull requests. Sentinel reviews each pull request in GitHub, GitLab or Bitbucket Cloud as it opens, posts findings as inline comments and turns developer feedback into reusable rules.

Agents stay inside the targets the customer authorizes, test non-destructively, and hold after proving a finding unless the customer opts in to chaining or escalation. Parameter states a SOC 2 Type I report with Type II underway, SSO, MFA, role based access and audit logging, and US data processing. The founders are Huzaifa Ahmad, Ahmad Khan and Prama Yudhistira, and the company is backed by Y Combinator. It is distinct from the Hex data analytics company at hex.tech.

Vendor details

Canonical URL

https://www.parameter.ai

Category

Security / SOC agent

Funding status

Private, early stage. Y Combinator Winter 2026 batch, backed by Y Combinator and Pioneer Fund. Founders Huzaifa Ahmad (ex-PlayAI and AWS), Ahmad Khan (ex-OpenAI), and Prama Yudhistira (ex-PlayAI and AWS).

Company status

independent

Use cases & customers

Primary use cases

Continuous autonomous penetration testingVulnerability discovery and verificationProof-of-concept exploit generationAttack-surface coverage for fast-shipping teams

Target customers

StartupsMid-market companiesSecurity-conscious engineering teams

Deployment options

SaaS

Integrations

GitHub, GitLab and Bitbucket Cloud (pull request review and fix pull requests), Linear and Jira (issues and tickets), and AWS, Google Cloud and Azure through a read only role, with Oracle Cloud and Kubernetes also covered. Supply chain testing covers npm, Yarn, pnpm, Bun, pip, Poetry, uv, Go modules, Maven, Gradle, Cargo, Bundler and Composer. There is no public API, SDK, CLI or MCP server.

In practice

Your team ships to production several times a day, but the pentest happens once a year. Parameter's Continuous tier runs an autonomous pentest on every deploy and reports only findings it has reproduced with a working exploit.

Your AWS and Google Cloud accounts have grown faster than anyone can review. Parameter's cloud agents map every resource and identity through a read only role and open Terraform fixes as pull requests.

Developers merge code before security sees it. Sentinel reviews each pull request as it opens and leaves inline comments on exploitable issues in GitHub, GitLab or Bitbucket.

Agentic Index coverage score

7.5 / 14 capabilities · 54%

Integrations & Tool Calling Full

Sentinel posts findings as inline comments on pull requests in GitHub, GitLab and Bitbucket Cloud. Findings open Linear issues and fix pull requests (Terraform patches and dependency bumps), and cloud agents connect to AWS, Google Cloud and Azure through a read only role. Developers can also open Jira tickets from a comment, cloud agents now cover Oracle Cloud and Kubernetes too, and a findings dashboard tracks every connected repository.

SourceParameter, parameter.ai/sentinel and /cloud-securityread 2026-10-05

Workflow Orchestration Full

Hundreds of agents work real attack paths in parallel, split across probe, exploit and verify stages. They map every endpoint, parameter and auth flow, try to break expected behavior the way an attacker would, then reproduce each issue from a clean state. Cloud agents reason about how misconfigurations chain together into attack paths.

SourceParameter, parameter.ai/pentesting and /cloud-securityread 2026-10-05

Knowledge Grounding & RAG Partial

Agents build a model of the customer's estate. Cloud agents map every resource, identity and trust relationship, supply chain agents resolve the full dependency graph and keep an SBOM current, and Sentinel reads the diff, surrounding code and execution paths. Parameter names no retrieval store it maintains for the agents. Testing can run whitebox, greybox or blackbox, from just a URL and credentials up to full source code access, and cloud agents map more than 100 services such as EC2, S3, IAM, Lambda and RDS.

SourceParameter, parameter.ai/cloud-security, /pentesting and /sentinelread 2026-10-05

Human Oversight & Guardrails Partial

Agents stay inside the targets the customer authorizes, and testing is nondestructive. After proving a finding the agent confirms it and holds, with no chaining or escalation unless the customer opts in, and researchers can choose a deeper follow up on any finding. Beyond that scope and opt in, Parameter names no approval step for each action. Fix pull requests merge in the customer's repository.

SourceParameter, parameter.ai/pentesting and parameter.airead 2026-10-05

Security, Identity & Governance Full

A SOC 2 Type I report is in place, with the Type II observation period underway. Parameter also offers a HIPAA BAA and GDPR DPA. SSO, MFA, role based access controls and audit logging cover the whole platform. Data is encrypted in transit and at rest, staff are background checked, and Parameter is tested continuously by its own agents alongside independent third party review.

SourceParameter, parameter.ai/securityread 2026-10-05

Observability & Auditability Full

Each finding comes with reproduction steps and proof of concept. The agents keep their own action record, and every action an agent takes is logged and reviewable, so the customer can see exactly what happened. Each cloud run produces a shareable report of validated findings with evidence, and pentest reports map findings to SOC 2 and ISO 27001 controls for auditors.

SourceParameter, parameter.ai, /cloud-security and /pentestingread 2026-10-05

Memory & State Persistence Partial

In Sentinel, feedback from developers becomes reusable Rules that teach Sentinel the codebase and improve its next review. The Rules are stored and scoped to the codebase. Parameter does not say how the Rules are viewed, edited or expire. Sentinel improves with every review.

SourceParameter, parameter.ai/sentinelread 2026-10-05

Deployment & Data Residency Not documented

Processing sits in one fixed region. Data is processed in the US and never leaves the customer's assigned infrastructure. Customers cannot choose the region, and the product is SaaS only, with no customer hosted option. Personal data is kept only as long as the service, the customer's instructions or the law require, and EEA, UK and Swiss transfers run under Standard Contractual Clauses.

SourceParameter, parameter.ai/securityread 2026-10-05

Prebuilt Agents / Templates / Packs Full

Parameter sells four agent products, each with its own job. Pentesting covers application and API attack paths, Cloud Security covers AWS, Google Cloud and Azure attack paths, Supply Chain covers the dependency graph and SBOM, and Sentinel reviews pull requests. A fifth product, Secrets Detection, finds leaked credentials across repositories and their history.

SourceParameter, parameter.airead 2026-10-05

Triggers & Channel Coverage Full

Code and deploy events start the work without a person. Sentinel reviews each pull request the moment it opens, the Continuous tier runs a pentest on every deploy, supply chain testing reruns on every push, and cloud runs go on demand or on every release. First findings land within 24 hours, and a newly connected cloud account shows findings within 15 minutes.

SourceParameter, parameter.ai/sentinel, /pentesting, /cloud-security and parameter.airead 2026-10-05

Model Flexibility & Routing Not documented

Parameter names no model provider and offers no customer model choice or routing. Customer personal data is never used to train foundation models. The agents reason through attack paths rather than running down a checklist.

SourceParameter, parameter.ai/security and /pentestingread 2026-10-05

APIs / SDKs / MCP Extensibility Not documented

Parameter publishes no public API, SDK, CLI or MCP server. Its only free tool is a browser CVSS calculator. Teams work with Parameter through its code host integrations, Jira and Linear instead.

SourceParameter, parameter.ai and /sentinelread 2026-10-05

Testing, Debugging & Optimization Not documented

Findings are verified by reproducing them from a clean state with a working exploit, and unproven findings are dropped. That check tests the customer's estate inside Parameter's own pipeline, and Parameter names no way to evaluate the agents themselves. It reports under 1% false positives.

SourceParameter, parameter.ai/pentesting and parameter.airead 2026-10-05

Browser / Computer-use Not documented

Agents test web apps, APIs, auth flows and business logic. Parameter names no browser or computer use by the agents.

SourceParameter, parameter.ai/pentestingread 2026-10-05

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Pricing

Contact for pricing. Three pentest tiers are published without prices: Single App, Rightsized and Continuous.

Rightsized tests are scoped from repos, endpoints and roles; Continuous runs a pentest on every deploy.

Cost watchouts

Inference, not stated by the vendor: Continuous coverage on every deploy likely costs more than a single time-boxed test as release frequency rises.

Variable cost rationale

Rightsized pricing is sized from repos, endpoints and roles, so cost tracks the size of the attack surface; no rate is published.

Sales call required

Yes, required for paid access

Free / trial

No free pentest or trial stated; the Single App tier includes free re-testing.

Key ambiguities

No prices are published for any tier.

Agentic Index verified 2026-09-28

Alternatives to Parameter

The closest documented capability profiles to Parameter among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Exaforce8.0 / 14Fuller documented coverage on Knowledge Grounding & RAG and Human Oversight & Guardrails
  • 7AI8.5 / 14Adds documented Deployment & Data Residency
  • Magnitude8.5 / 14Adds documented APIs, SDKs & MCP Extensibility and Testing, Debugging & Optimization
  • Abnormal AI9.0 / 14Adds documented Deployment & Data Residency and APIs, SDKs & MCP Extensibility, among others
  • AirMDR6.0 / 14Fuller documented coverage on Human Oversight & Guardrails
  • Astelia8.0 / 14Adds documented APIs, SDKs & MCP Extensibility

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Head to head

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.