Summary
- Lyon-based Hackuity has raised $19 million in a round led by Forgepoint Capital International.
- Its platform aggregates vulnerability and asset information from more than 130 security-product integrations.
- The funding will support product development, AI capabilities, and expansion across Europe and Asia.
French cybersecurity company Hackuity has raised $19 million to expand a vulnerability-operations platform designed to consolidate security findings and coordinate remediation across complex enterprise environments.
The round was led by Forgepoint Capital International and brings Hackuity’s total funding to $38 million. The Lyon-based company plans to use the capital for product development, artificial intelligence capabilities, and expansion across Europe and Asia.
Hackuity operates in a part of the security market shaped by an increasingly familiar problem: organisations can generate vulnerability information more quickly than they can decide what should be fixed first.
Cloud platforms, application-security scanners, endpoint products, penetration tests, external attack-surface tools, and conventional vulnerability scanners can all identify overlapping weaknesses against the same assets. The resulting volume can make prioritisation and ownership as difficult as vulnerability discovery itself.
Hackuity says its platform supports more than 130 integrations, consolidating findings and asset information before adding threat intelligence, business context, and exploitability data. The platform then connects those findings with remediation workflows and ownership.
That reflects a broader shift from periodic vulnerability scanning towards continuous exposure management. A high CVSS score can indicate technical severity, but it does not necessarily show which issue presents the greatest immediate business risk.
Internet exposure, known exploitation, the importance of the affected asset, privileges available to an attacker, compensating controls, and the sensitivity of underlying data can all change the order in which vulnerabilities need attention.
The operating problem becomes harder as discovery speeds increase. Automated research and AI-assisted development can find defects more quickly, while cloud infrastructure and application delivery create new assets continuously. The benefit of faster discovery can therefore be lost if remediation remains dependent on manual triage and disconnected ticket queues.
Hackuity describes its model as Vulnerability Operations, combining aggregation, deduplication, prioritisation, remediation orchestration, and measurement. The company is also adding AI functions intended to assist with exploit validation, patch prioritisation, reporting, and the ingestion of penetration-test findings.
The platform retains explainable scoring as a core part of its proposition rather than handing prioritisation entirely to a black-box model. That is relevant where remediation decisions need to be justified to asset owners, auditors, regulators, or risk committees.
Hackuity also offers SaaS and on-premises deployment, giving European customers different options for where vulnerability and asset data is processed. Data location and third-party dependency have become more prominent considerations as exposure-management platforms collect increasingly detailed information about internal infrastructure.
The commercial challenge is that prioritisation software cannot fix organisational ownership problems by itself. Vulnerabilities often remain open because no team controls the affected asset, maintenance windows are unavailable, dependencies are poorly understood, or risk acceptance processes are unclear.
The $19 million round gives Hackuity additional capital to compete for that orchestration layer. Its growth will depend on whether customers see enough value in consolidating vulnerability operations above the security tools they already own — and whether prioritisation translates into measurable remediation rather than another layer of findings.





