Hadrian announced $40 million in funding on October 6, 2026 to expand its offensive-security business across EMEA and the United States and invest in engineering and research. For security teams assessing the platform, the useful question is how continuous discovery and a targeted penetration test fit together—and how tightly the customer can define that test.
The company announcement names Forgepoint Capital International and Smartfin as co-leads and puts total funding at $65 million. The Next Web reported the round on October 6. This is funding for an existing offering: Hadrian's Nova launch dates to March 24, rather than the October financing announcement.
Mapping an estate and testing one application
Hadrian describes Atlas as continuously discovering internet-facing assets and validating exposures. The intended starting point is the external estate: which systems are visible and which findings warrant attention.
Nova is the on-demand penetration-testing component. Its product page describes evidence and reproduction steps for findings, along with human-reviewed results. A penetration test goes beyond listing a possible weakness by investigating what an attacker could do within the selected scope. Those are the supplier's descriptions of the service, not results from a TechKili test.
The distinction helps define an evaluation. Finding an overlooked application and testing the application's behavior are related tasks, but success at one does not establish coverage of the other. A buyer should ask which assets were discovered, which were actually tested and what remained outside the engagement.
Read the scope controls before starting a test
Hadrian's Nova Standalone Terms, updated May 6, define one target URL, permit incidental visits elsewhere and treat written exclusions as guidance without guaranteeing strict compliance (clauses 3.3–3.4). They also provide for rate limits and place authorization responsibility on the customer (clauses 3.5 and 4.1).
Our assessment is that a written exclusion should not be assumed to be a technically enforced boundary. Before launching a test, resolve required restrictions with the supplier and establish the necessary authorization over the target and affected services. Ask how a redirect, shared login or dependency will be handled in the proposed engagement. Those questions turn a broad promise of customer control into a decision about the application the team actually wants to test.
Judge the finding-to-repair workflow
The funding release's visibility, return and resolution-speed figures are company claims. The inspected sources do not supply an independent comparison that establishes those outcomes for a reader's environment. The terms also expressly decline to guarantee that Nova will identify every vulnerability.
A useful pilot would follow a finding through reproduction, repair and a repeat check, while recording the scope and excluded assets. That tests the part of the proposition a security team needs to use. More capital can support Hadrian's expansion plans; it does not itself demonstrate comprehensive protection or make the customer's testing decisions automatic.