# Antigen: continuous offensive security with human-reviewed remediation

Canonical: https://mudpie.ai/companies/antigen/
Breadcrumb: [Home](https://mudpie.ai/) / [Companies](https://mudpie.ai/companies/) / [Antigen: continuous offensive security with human-reviewed remediation](https://mudpie.ai/companies/antigen/)
Author: Ali Abouelatta (https://mudpie.ai/authors/ali-abouelatta/)
Published: 2026-09-19
Updated: 2026-09-19
Research type: Company profile
Method: Company and accelerator sources checked 2026-09-19. Product claims are attributed to their sources; this is research, not a hands-on product trial.

Antigen is selling a continuous attack loop, not another PDF pentest.

## What it does

Antigen describes itself as an AI adversary for enterprise security. Its current [homepage](https://antigen.sh/) says the system maps and attacks an organization’s surface, reproduces vulnerabilities, opens fixes and retests them. Findings are shown with traces, reproduction steps and remediation context, and can flow into GitHub, Linear or the Antigen platform.

The [documentation](https://antigen.sh/docs) makes the workflow clearer. Teams connect services, resources and identities in an Asset Map; an offensive agent attacks approved targets; a finding keeps its evidence and work history; then a human task is created when an agent needs access, review or a decision. The docs also say fixes are prepared for review and deployed by the customer, after which the agent tests whether the issue was resolved.

That human boundary is the important one. Antigen’s public material says it opens pull requests, but nothing merges on its own. This profile is describing the company’s documented workflow, not reporting an independent security result and not recommending that a reader authorize testing against a third party.

## Why I’d look closer

The product fits a security team that has a changing production surface and cannot wait for a point-in-time audit to become stale. Its stated sectors include financial services, healthcare, retail and government, where evidence and approval matter as much as finding a bug.

The founders’ public backgrounds support the technical ambition. The YC profile describes Saad Jamal’s ML infrastructure work at Tesla Autopilot and Nuro, plus earlier model work, and Abdullah Nauman’s product and ML work at Google Ads and Google Search. That explains the company’s emphasis on agent behavior, large systems and integration into engineering workflows. It does not certify Antigen’s findings or security claims.

## What I’d ask

I would ask how approved targets and identities are scoped, how destructive or high-impact actions are blocked, which evidence is retained, how customer data is isolated, and how the team distinguishes a reproduced exploit from a hypothesis. The public docs answer the workflow shape better than they answer pricing or a full control matrix.

## My editorial take

Shortlist Antigen if your security team wants an always-on loop from exploit evidence to reviewed remediation. It is not a drop-in substitute for understanding your authorization model or approving an attack scope. The strongest product decision is the review boundary: the agent can investigate and prepare work, while the customer still decides what runs and what ships.

## Quick facts

| Field | Sourced detail |
| --- | --- |
| Product | Continuous offensive-security agents and remediation workflow |
| Buyer | Enterprise security and engineering teams |
| Workflow | Asset map → approved attack → evidence → human review → fix → retest |
| Pricing | Not published in the checked pages |
| Safety boundary | Company says fixes are reviewed and merged by customer engineers |

## Sources checked

| Source | Checked |
| --- | --- |
| [YC company profile](https://www.ycombinator.com/companies/antigen) | 2026-09-19 |
| [Antigen homepage](https://antigen.sh/) | 2026-09-19 |
| [Antigen documentation](https://antigen.sh/docs) | 2026-09-19 |

## Cohort context

Antigen is listed in Fall 2025. In our 2026-09-18 directory snapshot, 90 of 146 listed companies in that cohort have YC’s primary industry label B2B (61.6%). This is a current-directory comparison, not an original intake count or a performance ranking. [Nine-cohort dataset](https://mudpie.ai/research/yc-cohorts-2026-09-19.json).

## Public website snapshot

Observed 2026-09-19T16:14:53.421Z in raw homepage HTML. This records visible metadata and advertised links, not agent execution or product quality.

| Signal | Homepage observation |
| --- | --- |
| Product description metadata | Observed |
| Canonical link | Observed |
| H1 or H2 heading | Observed |
| Typed structured data | Not observed in this response |
| Docs/developer link | Observed |
| Pricing link | Not observed in this response |
| llms.txt link | Not observed in this response |
| Markdown alternate | Not observed in this response |

[Public observations](https://mudpie.ai/research/yc-homepage-links-2026-09-19.json) · [Collection method](https://mudpie.ai/research/yc-homepage-methods/README.md). Missing links here do not establish that a capability or file is absent elsewhere.


## Author disclosure

I cofound Lazyweb and publish Mudpie. This is an owner-written publication, not an independent testing organization. Research notes distinguish observations, sourced reporting and editorial judgment.
