News

ATHENE UP26@it-sa Finalists: An interview with SQUR

07/09/2026

SQUR is one of the five finalists for the ATHENE UP26@it-sa Award

SQUR is launching with the promise of letting AI agents carry out autonomous hacking and providing proof of every discovery, rather than merely assuming it. Developed in Germany, with data stored within the EU and at a price that is said to be affordable even for small and medium-sized enterprises. 

Your start-up in one sentence? 

SQUR replaces the annual penetration test with continuous security validation: AI agents attack web applications and APIs just like a real attacker, validate each finding through controlled exploitation, verify that the issue has been rectified, and certify the current status with a certificate that is updated with every successful run.

#ContinuousTrust #AutonomousPentesting #MadeInGermany 

How did your business idea come about? 

Adam was Director of Engineering at Cobalt, one of the major providers of penetration testing as a service, and there he saw the limitations of the model: it relies on human penetration testers – too few for too many systems. With AI, this imbalance has become even greater: code can now be written cheaply, but the number of people capable of testing it remains the same. This led to the creation of SQUR: security verification should be generated as continuously as the software itself – automatically rather than on an ad hoc basis. 

How big is your team, and who’s in it? 

Two people plus two advisers – a deliberately small team: Adam Lundqvist (founder, formerly of Cobalt) and Jan Oldörp (engineering, with experience in critical infrastructure, amongst other areas). The advisers bring scientific expertise in offensive security and AI to the table. 

Who benefits from your product, and why? 

Companies that develop their own software: typically with between 20 and 500 employees, without their own security team. They can start the test directly with SQUR, without a sales consultation, and receive a report in which every finding is substantiated rather than merely suspected. 

What are your next steps? 

Since August, SQUR has been running continuously as a subscription service rather than as a one-off test, with a certificate that is updated with every successful run. The next step is to introduce autonomous rectification: a bug report that includes a specific fix, which the engine verifies itself. We intend to expand first within the DACH region, then across Europe.

Why are you so convinced that you, of all people, will be successful? 

Because we don’t make assumptions – we provide proof: our agents exploit vulnerabilities in a controlled manner and only report what could actually be exploited. There is also a structural advantage: security certifications entail liability, and liability rests with a legal entity within a specific jurisdiction. The competitors with the strongest financial backing in this field are based in the USA. We are a European company, with EU data residency and a price that even a 20-person business can afford: from 995 euros a month. 

What have been the biggest successes and challenges so far? 

The platform has been live since October 2025 and has already identified over 200 vulnerabilities among customers. In 2026, it won several awards, including first place at the Black Forest Hackathon and the ECSO STARtup Award (Bochum qualifier, thereby qualifying for the 2027 European final). The biggest hurdle: we are competing against significantly better-funded US rivals with comparatively little capital – which leaves no room for a single month of lack of focus.

Why did you enter the ATHENE Startup Award UP26@it-sa? 

Because it-sa is where our target audience is anyway. And as Europe’s largest research centre for IT security, ATHENE is not just any organisation for us – autonomous penetration testing is precisely the interface between research and application that we are working on, including through a research partnership with the KASTEL Security Research Labs at KIT. 

show all news