Scantist: Interview With Co-Founder And COO Charles Huang About Autonomous Offensive Security And AI Security

Scantist is a Singapore-based cybersecurity company focused on application security, software supply chain risk, DevSecOps, autonomous offensive security, and AI security. Its portfolio includes AppDefender for defensive application and software supply chain security, PAIStrike for autonomous agentic penetration testing, and AIDefender for AI runtime security. Pulse 2.0 interviewed Scantist Co-Founder and COO Charles Huang to learn more.

Charles Huang’s Background

When asked about his background, Huang shared:

My background combines financial services, compliance technology, and cybersecurity. Before joining Scantist, I worked in the banking sector across several key domains, including Institutional Banking Group, Consumer Banking Group, and Compliance. During that time, I was involved in areas such as AML, CDD, and transaction monitoring solutions, which gave me strong exposure to regulatory requirements, risk management, and enterprise technology adoption.

That experience shaped the way I look at cybersecurity today. In banking, security and compliance are not just technical requirements; they are business-critical functions that directly affect trust, resilience, and customer protection.

Today, at Scantist, I focus on bringing research-driven cybersecurity technologies into real enterprise use cases. This includes working with customers and partners on application security, software supply chain risk, DevSecOps, AI security, and our autonomous offensive security platform, PAIStrike. My role sits at the intersection of product strategy, business development, customer engagement, and ecosystem partnerships.

How Scantist Started

When asked how the idea for the company came together, Huang explained:

Scantist started from a very practical problem: modern software is increasingly built from open-source components, third-party libraries, cloud services, and complex CI/CD pipelines. While this helps companies build faster, it also creates a large amount of hidden security and compliance risk.

The company was founded to help organizations identify and manage those risks in a more automated and scalable way. Initially, our focus was strongly around software composition analysis, vulnerability management, and DevSecOps. Over time, as customer needs evolved, we expanded into broader application security, software supply chain governance, AI security, and autonomous offensive security.

Today, our mission is still very consistent: we help organizations clear security debt across their software and AI ecosystems before attackers can exploit it.

Primary Responsibilities

When discussing his primary responsibilities at Scantist, Huang detailed:

My primary responsibilities include product strategy, business development, customer engagement, and partnerships. I work closely with our technical team to translate market needs into product capabilities, especially around our key solutions such as AppDefender, PAIStrike, and AIDefender.

I also spend a lot of time speaking with CISOs, security teams, system integrators, penetration testing providers, and ecosystem partners to understand where the market is heading. A major part of my role is helping customers see how Scantist’s technology can fit into their security programs, whether that is for DevSecOps, software supply chain security, AI governance, or proactive security validation.

Global Recognition

When asked about his favorite memory working for the company so far, Huang recalled:

One of my favorite memories was seeing our technology being recognized beyond Singapore and used in global cybersecurity discussions. A recent example is PAIStrike, our autonomous penetration testing platform, achieving strong performance in competitive cybersecurity benchmarks and CTF-style environments.

For me, the most meaningful part was not just the ranking itself, but the validation that a Singapore-built cybersecurity company can develop deep, advanced technology that competes globally. It was also encouraging to see the team’s years of research, engineering, and product thinking come together into something that customers and partners can immediately understand and value.

Another memorable moment was participating in international cybersecurity events such as RSAC, GovWare and meeting global security leaders. It showed us that the problems we are solving are not just local problems; they are global problems.

Core Products And Features

When asked about Scantist’s core products and features, Huang explained:

Scantist’s core product portfolio is built around two complementary areas: defensive application security and offensive security validation.

Our defensive product is AppDefender, which helps organizations secure their software applications and software supply chains throughout the development lifecycle. It provides capabilities such as software composition analysis, vulnerability detection, license compliance review, SBOM generation, VEX reporting, CI/CD integration, and continuous dependency monitoring. The goal is to help development and security teams identify risks early, prioritize remediation, and maintain visibility over their software supply chain.

Our offensive solution is PAIStrike, an autonomous agentic penetration testing platform. PAIStrike is designed to test applications from an attacker’s perspective by performing reconnaissance, identifying potential attack paths, validating exploitability, and generating evidence-based findings. Compared with traditional scanning tools, PAIStrike focuses more on reasoning, multi-step validation, and practical exploitability, helping organizations understand which vulnerabilities truly matter.

Going forward, PAIStrike will also extend into AI-related application security, including penetration testing for AI chatbots, AI agents, and LLM-powered applications. This will include testing against risks aligned with the OWASP LLM Top 10, such as prompt injection, sensitive information disclosure, insecure plugin or tool usage, and excessive agency.

In simple terms, AppDefender helps customers build and maintain secure software, while PAIStrike helps customers validate their real-world exposure through attacker-informed testing.

Evolving Cybersecurity Threats

When asked about recent challenges in the cybersecurity sector and how Scantist has addressed them, Huang noted:

Yes. One major challenge is that cybersecurity threats are evolving much faster than traditional security processes. Many organizations still rely on periodic assessments, manual testing, or compliance-driven checklists. Those methods are still useful, but they are no longer enough when applications change weekly or even daily.

Another challenge is the rapid rise of AI. AI creates new productivity opportunities, but it also introduces new attack surfaces. Organizations are still trying to understand how to secure AI systems, how to govern LLM usage, and how to prevent sensitive data leakage or prompt-based attacks.

We address these challenges by investing continuously in research and product development. For example, PAIStrike was created to help security teams test more continuously and think from an attacker’s perspective. AIDefender was created to help companies secure AI usage at runtime, not just through policy documents. We also work closely with customers and partners so that our solutions solve practical enterprise problems, not just theoretical risks.

Technology Evolution

When asked how Scantist’s technology has evolved since launching, Huang explained:

When Scantist first started, our technology was mainly focused on software composition analysis and helping organizations identify vulnerabilities in open-source dependencies. That was already a major problem because modern applications rely heavily on third-party components.

Since then, our technology has evolved significantly. We expanded from vulnerability detection into broader software supply chain governance, including SBOM, license compliance, VEX, CI/CD integration, and continuous monitoring. We also added deeper analysis capabilities beyond traditional source-code scanning.

More recently, we moved into autonomous offensive security with PAIStrike and AI security governance with AIDefender. This reflects how the market has changed. Security is no longer only about finding known vulnerabilities. It is about understanding real exploitability, attack paths, runtime behavior, and AI-driven risks.

So the company has evolved from a software security scanning provider into a broader application, software supply chain, and AI security company.

Major Company Milestones

When asked about some of Scantist’s most significant milestones, Huang said:

There are several milestones we are proud of.

First, Scantist was founded from NTU’s Cyber Security Lab, which gave us a strong research foundation from day one. We have also grown into a Singapore-based cybersecurity company serving real enterprise and government-related customers.

Second, our software composition analysis capabilities have been recognized in the application security ecosystem, including being listed among recognized SCA tools by OWASP.

Third, we achieved ISO 27001 certification, which is important for building trust with enterprise & public sector customers.

Fourth, we have conducted DevSecOps enablement and training for government and enterprise teams, helping organizations improve their secure software development practices.

More recently, the development and launch of PAIStrike and AIDefender have been important milestones. They represent our move into the next generation of cybersecurity: autonomous offensive validation and AI runtime security.

Customer Success Stories

When asked to share specific customer success stories, Huang explained:

Yes, although for confidentiality reasons we may not be able to disclose all customer names publicly.

One example is our work with a major Singapore government agency, where Scantist supported large-scale DevSecOps adoption across the organization. The platform is used by around one thousand developers, helping them integrate security checks into their software development lifecycle, identify vulnerabilities earlier, and improve remediation efficiency without slowing down delivery.

Another example is a leading Tier-1 automotive solution provider. The customer faced significant security challenges due to the scale and complexity of its software environment, including a codebase of around 3TB and more than 1,000 third-party libraries. They also needed to comply with increasingly strict regulations such as the EU Cyber Resilience Act, which added further complexity to software supply chain security management.

With our AI-powered AppDefender solution, we helped them automate vulnerability analysis, SBOM dependency risk management, and compliance reporting, reducing their average manpower cost by around 90%.

For PAIStrike, our autonomous offensive security platform, we are currently working with a global leading healthcare company and two worldwide audit firms on proof-of-value engagements. These organizations are exploring how PAIStrike can help them conduct more scalable, attacker-informed security validation, identify exploitable risks more efficiently, and complement traditional penetration testing workflows.

Overall, the common theme across these customer stories is that organizations are no longer looking only for vulnerability reports. They want measurable security outcomes, better automation, stronger compliance visibility, and practical evidence of what risks truly matter.

Funding And Growth

When asked about funding and revenue metrics, Huang shared:

Yes, we are able to share some high-level funding information. From our seed round through to Series A, Scantist has cumulatively raised over S$10 million in funding. This has supported our product development, R&D, enterprise adoption, and regional market expansion.

We are also very open to speaking with new strategic investors who can support our next stage of growth. In particular, we are looking to further expand and scale our future development and R&D efforts in AI-driven cybersecurity, including autonomous offensive security, AI application security testing, and secure software supply chain governance.

Our focus now is on scaling our next-generation products, especially PAIStrike, into regional and global markets. We are seeing strong market interest because organizations are looking for more proactive ways to secure applications, software supply chains, and AI systems.

Market Opportunity

When discussing the total addressable market Scantist is pursuing, Huang explained:

Scantist operates across several fast-growing cybersecurity markets, including application security, software supply chain security, DevSecOps, penetration testing, external attack surface validation, and AI security.

For AppDefender, the market opportunity is tied to the global need for software supply chain security, SBOM management, vulnerability management, and DevSecOps adoption. For PAIStrike, the opportunity sits in the penetration testing, offensive security, and continuous security validation market. For AIDefender, the market is emerging quickly as enterprises adopt LLMs and AI applications and need runtime security, governance, and monitoring.

We see this as a multi-billion-dollar global opportunity. More importantly, we believe the market is moving toward convergence: organizations no longer want isolated scanners or point solutions. They want platforms that can help them build securely, test continuously, and operate AI systems safely. That is the market Scantist is pursuing.

Competitive Differentiation

When asked what differentiates Scantist from its competition, Huang emphasized:

Scantist’s key differentiation is that we combine deep cybersecurity research with practical enterprise deployment experience. We are not building generic security tools; we focus on solutions that can be adapted to real customer environments, operational workflows, and compliance needs.

For AppDefender, our advantage is that it is more cost-effective and flexible, especially for organizations that require customization around their internal security policies, compliance workflows, reporting formats, and deployment environments. Many large enterprises do not want a one-size-fits-all security platform. They need tools that can fit their existing governance model, integrate with their development pipelines, and produce reports aligned with internal or regulatory requirements. AppDefender is designed with that flexibility in mind.

For PAIStrike, our differentiation is accessibility, operational practicality, and proven autonomous offensive capability. PAIStrike is designed to support both enterprise internal security teams and certified penetration testers. Our goal is not to replace professional testers, but to assist them by automating repetitive reconnaissance, testing, validation, and evidence collection. This allows human experts to spend more time on higher-value analysis, complex attack scenarios, and strategic remediation guidance.

We have also achieved strong technical validation for PAIStrike. In our benchmark testing, PAIStrike achieved a 93.27% overall pass rate across 104 test cases, including 100% success on Level 3 stateful attacks, which represent authenticated, multi-step, real-world exploitation scenarios. By comparison, XBOW achieved an 85% overall pass rate and 50% on Level 3 attacks in the same benchmark context.

PAIStrike also ranked #16 globally in a Hack The Box CTF against 1,704 teams, while achieving Top 1 in Southeast Asia, and this was completed in a fully autonomous manner. For us, this is an important proof point that PAIStrike is not just a scanner orchestration tool, but an autonomous system capable of reasoning, adapting, and validating real-world attack paths.

Overall, Scantist differentiates itself by offering solutions that are research-driven, enterprise-ready, customizable, and practical for real-world security operations. Our defensive solution, AppDefender, helps organizations build and maintain secure software, while PAIStrike helps them validate real-world exposure through attacker-informed testing.

Future Goals

When discussing Scantist’s future goals, Huang concluded:

Our future goal is to grow Scantist into a leading cybersecurity company from Singapore with global impact, especially in application security, software supply chain security, autonomous penetration testing, and AI-related cybersecurity.

For PAIStrike, we will continue expanding its autonomous offensive security capabilities. Beyond traditional web application penetration testing, PAIStrike will also cover red team testing for AI-related applications, including AI chatbots, AI agents, and LLM-powered applications. This includes testing against AI security risks such as prompt injection, sensitive data leakage, insecure tool usage, and excessive agency.

We also want PAIStrike to support deeper white-box testing, where it can analyze application source code to identify the root cause of vulnerabilities and provide recommended fixes, not just surface-level findings.

For AppDefender, we will continue strengthening its role as our defensive application security and software supply chain platform. Going forward, we plan to leverage more agentic AI capabilities to perform source code analysis, open-source dependency review, and software risk assessment, especially for AI-generated code.

As more software is written with AI coding assistants, organizations will need stronger ways to understand whether generated code is secure, maintainable, compliant, and aligned with internal policies.

Another important direction for Scantist is professional services. We are not only selling tools; we are also bringing our expertise to customers in application security, software supply chain risk management, red team and penetration testing, and the scaling of agentic SaaS solutions.

With the rise of AI code assistants and vibe coding, more applications are being built rapidly by agents or semi-technical users. However, many application owners may lack deep software architecture and cybersecurity knowledge.

This is where Scantist can help. We want to support customers not only in finding vulnerabilities, but also in helping them scale, secure, and mature their applications. That includes improving performance, strengthening governance, implementing DevSecOps practices, and setting up continuous security monitoring across the software lifecycle.

In short, our goal is to help organizations move from simply building applications faster to building applications that are secure, scalable, compliant, and enterprise-ready.