Pi
Also known as: Pi Security
Agentic product security platform that builds a security brain of a company's code, cloud, and history, then autonomously finds and ships fixes for vulnerabilities across the software development lifecycle.
Pi, also known as Pi Security, is an agentic product security company based in San Francisco and founded in 2025. Chief executive Guy Arazi spent years as a security researcher at Microsoft, working on Defender, Azure and the Microsoft Security Response Center, and earlier at Palo Alto Networks; chief product officer Yoni Ramon led offensive security at Tesla for more than a decade. In June 2026 the company announced thirty five million dollars led by Brightmind Partners and Third Point Ventures. Pi's premise is that AI has made finding vulnerabilities cheap while fixing them remains the hard part.
At its center is a security brain, a living inventory of the customer's security history built from its codebase, past incidents, pentest reports and security tickets. An agent named Sloane draws on it to triage findings, trace each vulnerability to its architectural source and hunt every variant across the organization, then works inside developer workflows, in the IDE and on pull requests during design and coding, opening tickets and pull requests with contextual fixes and blocking insecure patterns before code lands. Pi names Lemonade, Teramind and Navan among its customers and reports outcomes such as most vulnerabilities blocked before production; those are its own figures.
Pi's pages do not document an approval step of its own (fixes land as pull requests the customer's engineers merge), access controls, hosting options, model providers or an API, and it publishes no pricing. For an engineering organization shipping quickly with AI in the loop that wants remediation grounded in its own security history rather than a wall of generic findings, Pi is built for that job; a team that needs point in time scanning or a self hosted deployment will find it a different kind of product.
Vendor details
Canonical URL
https://www.pi.security
Category
Security / SOC agent
Subcategory
Agentic product security
Funding status
Independent, based in San Francisco, founded in 2025 by Guy Arazi (CEO, formerly a security researcher at Microsoft across Defender, Azure, and MSRC) and Yoni Ramon (CPO, who led offensive security at Tesla for over a decade). In June 2026 Pi announced thirty five million dollars led by Brightmind Partners and Third Point Ventures, with participation from CrowdStrike chief executive George Kurtz and Armis founders Yevgeny Dibrov and Nadir Izrael. Early customers reportedly include a frontier AI lab, cybersecurity firms, and category leaders in travel and insurance.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Pi integrates deeply with the software development environment, ingesting source code, cloud infrastructure, design documents, and engineering discussions in Slack and Microsoft Teams, along with the history of past security incidents. It ships fixes by opening pull requests and adjusting configurations directly in the development workflow. Integration centers on the code, cloud, and collaboration surfaces of the SDLC rather than a broad third party connector catalog.
In practice
A code scanner floods the team with findings, most of them noise. Pi's security brain uses the company's own context to tell real risk from false positives and ships fixes for the ones that matter.
AI coding agents are shipping features faster than security can review them. Pi gives those agents the institutional knowledge to keep what they build secure by design.
The same class of vulnerability keeps recurring across services. Pi remediates it at the source and validates that the fix holds without breaking functionality.
Sources & related URLs
Agentic Index coverage score
6.0 / 14 capabilities · 43%
| Integrations & Tool Calling | Full |
|---|---|
|
Pi works inside developer workflows, in the IDE and on pull requests, and it acts there. It opens and manages tickets and pull requests with contextual fixes and posts to Slack. Sourcepi.securityread 2026-09-28 |
|
| Workflow Orchestration | Partial |
|
Triage, root cause analysis back to the architectural source, variant hunting and the fix run as the product's own multi step sequence. No branching the buyer designs, multi agent handoff or workflow surface is documented. Sourcepi.securityread 2026-09-28 |
|
| Knowledge Grounding & RAG | Full |
|
The security brain is a living inventory of the customer's security history built from its codebase, past incidents, pentest reports and security tickets. The Sloane agent draws on it to trace each vulnerability to its source and to hunt every variant across the organization. Sourcepi.securityread 2026-09-28 |
|
| Human Oversight & Guardrails | Partial |
|
Fixes arrive as pull requests and tickets that engineers act on, and insecure patterns are blocked before code lands. The merge gate belongs to the customer's code host, and no Pi approval step before an action commits is documented. Sourcepi.securityread 2026-09-28 |
|
| Security, Identity & Governance | Partial |
|
The homepage appears to carry a SOC 2 badge image, but no page states the attestation in text. No SSO, SCIM or role model is documented, and Pi has no trust subdomain. No SOC 2 report is published, so that badge is the only compliance evidence. Sourcepi.securityread 2026-09-28 |
|
| Observability & Auditability | Partial |
|
Each finding carries automated triage and root cause analysis explaining why it is real. No trace or audit log of the agent's own steps is documented. Sourcepi.securityread 2026-09-28 |
|
| Memory & State Persistence | Partial |
|
The security brain holds the customer's knowledge, which grounds the agent's work rather than serving as agent memory. Beyond it, the Sloane assistant holds conversation state, and no agent memory with a stated scope or lifetime is documented. Sourcepi.securityread 2026-09-28 |
|
| Deployment & Data Residency | Not documented |
|
No hosting region, self hosted option or customer environment is published, and Pi has no trust subdomain. Sourcepi.securityread 2026-09-28 |
|
| Prebuilt Agents, Templates & Packs | Partial |
|
One named agent, Sloane, ships ready to use. No set of separately adoptable agents or templates is documented. Sourcepi.securityread 2026-09-28 |
|
| Triggers & Channel Coverage | Full |
|
Pi runs on development events, in the IDE and on pull requests during design and coding, and blocks insecure patterns before code is introduced, so work starts on the change rather than on someone asking. Sourcepi.securityread 2026-09-28 |
|
| Model Flexibility & Routing | Not documented |
|
The models behind Sloane are not named, and no model choice is offered. Sourcepi.securityread 2026-09-28 |
|
| APIs, SDKs & MCP Extensibility | Not documented |
|
No API, SDK or MCP server for Pi is documented. Sourcepi.securityread 2026-09-28 |
|
| Testing, Debugging & Optimization | Not documented |
|
No page documents how Pi's fixes or agent behavior are tested, scored or gated. Outcome figures on the homepage are the vendor's own claims. Sourcepi.securityread 2026-09-28 |
|
| Browser & Computer Use | Not documented |
|
No page documents an agent driving a browser, desktop or remote computer. Pi works through the IDE, pull requests and tickets. Sourcepi.securityread 2026-09-28 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Pi now reads Claude's Compliance API, so it sees every Claude Code session in a Claude Enterprise organization, not only those of developers who installed it. Security gates such as playbooks and dependency advisories reach the coding agent while it works, and Pi reports which ones fired, whether the agent followed them and where a developer overrode them.
Bears on: Observability / auditability
View sourcePricing
Not public; quoted through sales after a demo
not published
What is public
No list prices, tiers, or entry point are published.
Billing mechanics
Sold through sales after a demo; the billing unit is not published.
Cost watchouts
Deep access to code and collaboration tools may require security review and onboarding effort.
Variable cost rationale
No billing unit is published; as an inference, scope may follow the codebase and engineering footprint secured.
Additional watchouts
The billing unit is not published. Ask sales how scope is metered, for example by repositories, services or developers covered.
Sales call required
Yes, required for paid access
Free / trial
No public free tier
Key ambiguities
No public anchor for entry price or scope units.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Pi
The closest documented capability profiles to Pi among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Linx Security6.5 / 14Fuller documented coverage on Human Oversight & Guardrails and Observability & Auditability
- Portal265.5 / 14Fuller documented coverage on Observability & Auditability
- Token Security6.5 / 14Adds documented APIs, SDKs & MCP Extensibility
- AirMDR6.0 / 14Fuller documented coverage on Human Oversight & Guardrails and Security, Identity & Governance
- Clutch Security6.0 / 14Adds documented Deployment & Data Residency and APIs, SDKs & MCP Extensibility
- Exaforce8.0 / 14Fuller documented coverage on Workflow Orchestration and Human Oversight & Guardrails
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded