Learn more about Straiker
Here to stay. Straiker raised a $64 million Series A in June 2026 from Marathon Management Partners, Citi Ventures, Illuminate Financial, and Workday Ventures, with continued backing from Lightspeed Venture Partners and Bain Capital Ventures. Total funding stands at $85 million. Straiker is US-based, SOC 2 and ISO/IEC 27001 certified, and deployed at enterprises across financial services, health-tech, technology, and retail.
STAR Labs. Straiker's AI and security research team works with frontier AI labs, which gives Straiker attack data on real agent behavior that is not available anywhere else. That research is the foundation of the product rather than an output of it. What STAR Labs finds becomes an Ascend AI evaluation and a Defend AI detection, continuously. Research to product to protection.
Across dozens of agent evaluation campaigns, STAR Labs found that 85% of successful attacks caused an agent to silently do something it was never authorized to do. On coding agents, 36% of successful attacks ended in remote code execution. On productivity and consumer agents, 91% ended in silent data exfiltration. The pattern is consistent: agentic attacks rarely take an agent down. They get the agent to act on someone else's behalf.
The technology. Discover AI maps the agentic estate and governs what agents can reach, across any framework, builder platform, or cloud. Ascend AI deploys an autonomous agentic red teamer that probes, adapts, and chains attacks until it succeeds. Every attack it lands becomes a Defend AI policy, which is how Straiker turns offense into defense. Defend AI enforces those policies at runtime with 98.1% accuracy at under 300ms. The AI Agent Kill Switch takes rogue agents offline in seconds.
What are Straiker's most important features?
Discover AI: visibility and governance
-
Meets your environment where it is. Multiple insertion modes across endpoints, APIs, gateways, SaaS, and inference hooks. No single required integration point.
-
Vendor agnostic by design. Covers agents wherever they run: any framework, any builder platform, any cloud. LangGraph, CrewAI, AutoGen, Vercel, AWS Bedrock AgentCore, Azure AI Foundry, Microsoft Copilot Studio, Google Vertex AI, Databricks, Snowflake, and applications built in-house.
-
Maps what each agent can actually reach: the models, tools, MCPs, skills, data, permissions, and systems behind it.
-
Shows the full agentic trace, surfacing risky permissions, unsanctioned connections, and malicious components.
-
Governs the connections. Block or revoke risky MCP and tool access directly, rather than filing a ticket about it.
-
Finds shadow agents, including browser and SaaS agents an employee turned on without telling anyone.
Ascend AI: AI adversarial testing
-
An autonomous agentic red teamer, purpose-built to attack AI agents and applications. Not a scanner running a fixed test list.
-
Probes, adapts, and chains attacks across prompts, tools, MCPs, skills, memory, and connected systems, the way a human attacker would if a human attacker never got tired.
-
Keeps attacking until it succeeds or reaches the limits of the assessment.
-
Reports real impact, not severity scores: remote code execution, data exfiltration, tool abuse, and unauthorized actions the agent was talked into taking.
- Highest attack success rate in the industry.
-
Continuously fed by STAR Labs, which turns new attack research into production evaluations as it lands.
Defend AI: agentic runtime defense
-
98.1% accuracy at under 300ms, so enforcement sits in the production request path without slowing the agent down.
-
Detects what the agent actually does, not only what was said to it: remote code execution, file access violations, suspicious outbound access, destructive commands, and data exfiltration.
-
Stops the threats that make agentic risk different, including indirect prompt injection, tool manipulation, malicious skills and MCPs, and memory poisoning. These do not look like traditional attacks and traditional controls do not see them.
-
Detect or Protect modes, with security policies you write yourself.
-
Decides using the full agentic trace plus user, tool, network, and data context, so enforcement understands what the agent was doing and why.
- Protects agents across models, frameworks, clouds, gateways, and architectures.
AI Agent Kill Switch: take rogue agents offline in seconds
-
Cut off tool access. Sever what the agent can reach without stopping the agent itself.
-
Suspend the session. Freeze what is happening right now.
-
Isolate the agent while an investigation runs.
-
Stop one agent or your entire agentic estate, depending on how far the problem has spread.
-
Preserve the evidence so the incident can be reconstructed afterward.
STAR Labs: the research and team underneath all of it
-
AI and security researchers working with frontier AI labs, which produces attack data on agent behavior that is not available anywhere else.
-
Research feeds the product continuously. An attack STAR Labs discovers becomes an Ascend AI evaluation and a Defend AI detection. Research to product to protection.
-
The findings are the product's foundation, not a marketing output. Detection quality depends on knowing what agentic attacks actually look like in the wild.
What benefits and ROI should buyers look for in Straiker reviews?
-
Attack to defend. Every attack Ascend AI lands becomes a Defend AI policy, so what the red teamer proved on Tuesday is blocked in production on Wednesday. Most teams run testing and runtime as separate programs with a human handoff between them. This removes the handoff.
-
One answer for both halves of the problem. Most organizations have nothing covering the agents employees brought in and something partial covering the agents they built. Straiker covers both from one place.
-
A real agent inventory, in days. Security teams stop estimating how many agents are in production and get a counted list with owners, permissions, and connections attached. Usually the first question a board asks and the one most teams cannot answer.
-
Attack findings a developer can act on. Ascend AI reports that an agent was talked into executing a command or leaking a record, with the path it took. That lands differently than a severity score.
-
Testing that keeps pace with deployment. Quarterly manual red team engagements cannot cover agents that ship weekly. An autonomous red teamer can, without adding headcount.
-
Containment measured in seconds. The kill switch bounds the blast radius. Incident response for an agent failure stops being a scramble to find who has permission to turn it off.
-
Evidence for auditors and regulators. Inventory, agentic traces, test history, policy logs, and kill switch actions map to EU AI Act, NIST AI RMF, and ISO 42001 obligations.
-
Fewer blocked launches. Product teams get findings and fixes during development instead of a security veto at the release gate.
Straiker is used by banks and financial services firms, health-tech companies and healthcare providers, technology and AI companies, media and entertainment businesses, and retail and ecommerce operators. Companies launching customer-facing AI products use Ascend AI to attack those agents before customers can. Engineering organizations running coding agents use Defend AI to stop remote code execution and repository data exfiltration, the two outcomes STAR Labs sees most often on that agent class. Security teams in regulated industries use Discover AI for governance evidence and to revoke risky MCP and tool access, and deploy Defend AI on premises to keep agent traffic inside their own environment. Straiker holds SOC 2 and ISO/IEC 27001 certification.