# Cantina

> Cantina is an agentic security company, operated by Spearbit Labs Inc., that evolved from a web3 smart-contract audit marketplace into an AI-driven platform using autonomous agents to manage and remediate vulnerabilities across regulated industries.

- Canonical URL: https://iq.wiki/wiki/cantina
- Categories: Organizations
- Tags: ResearchLab
- Created: 2026-10-06T21:21:42.766Z
- Last updated: 2026-10-06T21:21:42.766Z
- Source: IQ.wiki — the world's largest blockchain and crypto encyclopedia (https://iq.wiki)

---

**Cantina** is an agentic security company that builds autonomous artificial-intelligence agents to find, prioritize, fix, and verify software and infrastructure vulnerabilities on behalf of corporate security teams. The business began in 2021 as Spearbit, a smart-contract security collective that later developed a [web3](https://iq.wiki/wiki/web3) audit marketplace branded as Cantina, and it now operates under the legal name Spearbit Labs Inc. headquartered in Miami, Florida.[\[8\]](#cite-id-644ea3rxrp) Cantina markets itself as an "Agentic Security Platform" designed to let a small security team "carry the coverage of a team ten times their size."[\[1\]](#cite-id-ohtwbhj0wp)​[\[2\]](#cite-id-vbf5sndj9k)&#x20;

## Overview

Cantina launched its branded marketplace in 2023 as a [web3](https://iq.wiki/wiki/web3) security platform backed by SpearbitDAO, with the stated goal of connecting organizations that need security reviews with expert auditors and teams. According to an August 2023 overview by Johnny Time published on Medium, the platform let clients book security services by selecting a team, a price, and a timeframe, and promoted the idea that an audit "shouldn't feel like buying a house."[[3]](#cite-id-3lv5pkhp2g) Its operations centered on "Guilds," defined as teams of auditors responsible for reviewing protocols, a structure the article compared to the Watsons and Wardens of competitors Sherlock and [Code4rena](https://iq.wiki/wiki/code4rena).[[3]](#cite-id-3lv5pkhp2g) The marketplace built on earlier work begun in 2021 under the Spearbit name, when the founders organized a collective of security researchers focused on digital-asset protocols and [smart contracts](https://iq.wiki/wiki/smart-contract).[[8]](#cite-id-644ea3rxrp)

In that early period Cantina offered two models. Under "Cantina Managed," the company selected the team and streamlined the audit process, and the review carried the Cantina logo; under "Cantina Guilds," clients chose a specific Guild, each with its own standards, requirements, pricing, and branding, which produced price variability across Guilds. Spearbit operated as a Guild within the marketplace, focused on niche protocol reviews, while Cantina positioned itself as the wider marketplace spanning many providers.[[3]](#cite-id-3lv5pkhp2g)

The company later rebuilt itself around autonomous [AI agents](https://iq.wiki/wiki/ai-agents), describing its origin in the observation that "security teams are drowning in alerts, overwhelmed by tool sprawl, and losing the battle against AI-powered threats."[[4]](#cite-id-r4o5fm577a)[[5]](#cite-id-qr3yopbhy8) On July 30, 2026 Cantina launched from stealth with an $8 million funding round led by [Framework Ventures](https://iq.wiki/wiki/framework-ventures), bringing its total funding at that time to $16.5 million and introducing Clarion, a community-powered agentic security platform described as an autonomous security workforce for vulnerability management and remediation.[[9]](#cite-id-6rjhqec2u0)[[10]](#cite-id-9tmvlcl0d8)[[11]](#cite-id-5u7pciuaey)[[12]](#cite-id-et9v3syybe)[[8]](#cite-id-644ea3rxrp) The company has since framed its mission as "reinventing what security can be" rather than "adding AI to security."[[4]](#cite-id-r4o5fm577a)

## Products

Cantina's platform is organized around an architecture it describes as "one security brain, shared by every agent." The company states that the system rests on a single shared security memory layer spanning every connected tool, autonomy policies configured per action and integration, auditable logging of every decision, and verification of actions from a fix pull request through to containment.[[2]](#cite-id-vbf5sndj9k) It presents its work as a four-step loop: discover what is real across code, cloud, identity, and endpoints; prioritize weak signals down to the few that are real and reachable; fix by carrying an issue to a shipped change rather than a ticket; and verify on record by confirming the fix holds.[[4]](#cite-id-r4o5fm577a) The company states the platform ingests findings, alerts, signals, and submissions from across a customer's existing security stack and integrates with tools including GitHub, GitLab, Okta, Auth0, CrowdStrike, Datadog, Splunk, Grafana, Snyk, Sentry, Elastic, Slack, Cloudflare, Jira, Linear, Notion, PagerDuty, Jenkins, Terraform, Kubernetes, Docker, AWS, Azure, and Google Cloud.[[2]](#cite-id-vbf5sndj9k)

### Apex

Apex is Cantina's autonomous penetration-testing and vulnerability-research agent. The company self-reports that Apex ranks "#1 on HackerOne US" and claims to have found bugs in Apple, Anthropic, [Coinbase](https://iq.wiki/wiki/coinbase), and other organizations.[[6]](#cite-id-vkp69p1to7) In a September 2026 post the company claimed its agent took the number-one spot on HackerOne's US leaderboard with more points than the second, third, and fourth-ranked participants combined.[[1]](#cite-id-ohtwbhj0wp) Cantina has used Apex to generate not only findings but detailed remediation instructions for other coding agents; in a September 17, 2026 post it described testing four models across 52 vulnerabilities and reported that Claude Opus 5 produced "58.3% fewer fixes wrong" when given those instructions.[[1]](#cite-id-ohtwbhj0wp)

### Clarion and The Brain

Clarion is a platform component that reads telemetry to inventory and track the assets that agents touch. Cantina states that Clarion reads Claude Code telemetry and "turns every MCP server your agents touch into an audited and tracked asset," referring to the [Model Context Protocol](https://iq.wiki/wiki/model-context-protocol) used by [AI agents](https://iq.wiki/wiki/ai-agents) to access tools and data.[[1]](#cite-id-ohtwbhj0wp) The company also integrated GitHub's Dependabot into Clarion so that agents can draw on its dependency alerts.[[1]](#cite-id-ohtwbhj0wp) In late September 2026 Cantina announced "The Brain," a shared context and memory layer for its agents that connects identities, devices, repositories, and cloud services with operating context and records of prior investigations, described as the foundation for "security intelligence that compounds through shared context and memory."[[1]](#cite-id-ohtwbhj0wp)[[6]](#cite-id-vkp69p1to7)

### apex-flash-1

On October 1, 2026, Cantina released apex-flash-1, which it described as its first open-weights model for security research. The company stated the model was post-trained on real vulnerabilities its agents had found and been paid for — the same work that took its pentester to the top of the HackerOne US leaderboard — and that it simultaneously released an "abliterated" variant intended for researchers who want "fewer refusals in their own authorized workflows."[[6]](#cite-id-vkp69p1to7)[[1]](#cite-id-ohtwbhj0wp)

### Self-Reported Performance

Cantina publishes several performance figures as its own claims. On its about page the company states it has secured more than 200 companies, eliminated 98% of false positives, achieved 95% faster remediation, and prevented more than $80 billion in breaches.[[4]](#cite-id-r4o5fm577a) It describes a typical time to remediation of two to five minutes and states that "thousands of raw signals collapse into the handful of issues that are real, and almost all of them are resolved before anyone has to look."[[2]](#cite-id-vbf5sndj9k) The company frames its products against three recurring customer problems — "volume without priority," "tool sprawl, team sprawl," and "discovery without resolution" — and cites Verizon's Data Breach Investigations Report (2023–2026) for industry figures, stating that the share of incidents becoming breaches rose from 32% in 2023 to 71%, while the share of critical vulnerabilities patched fell to 26% from 38% in 2025.[[2]](#cite-id-vbf5sndj9k)

## Funding

Cantina has reported total funding of US$24.3 million raised across four rounds. The earliest was a pre-seed round of $1.5 million recorded in December 2021, which funded development of the Spearbit-led smart-contract security marketplace that later operated under the Cantina brand, followed by a seed round of $7.0 million in August 2023.[\[1\]](#cite-id-ohtwbhj0wp)​[\[8\]](#cite-id-644ea3rxrp) A $7.8 million venture round closed in November 2025, and an $8.0 million venture round followed in July 2026, the latter led by [Framework Ventures](https://iq.wiki/wiki/framework-ventures) and timed with the launch of the agentic security platform.[\[1\]](#cite-id-ohtwbhj0wp)​[\[9\]](#cite-id-6rjhqec2u0)​[\[11\]](#cite-id-5u7pciuaey) Multiple outlets reported the July 2026 raise, including Pulse 2.0's "Cantina Raises $8 Million Led By [Framework Ventures](https://iq.wiki/wiki/framework-ventures) And Launches Agentic Security Platform" and FinSMEs and PR Newswire coverage describing the capital as funding an AI-powered, community-powered agentic security workforce and bringing total funding at that time to $16.5 million.[\[10\]](#cite-id-9tmvlcl0d8)​[\[12\]](#cite-id-et9v3syybe)​

## Research and Disclosures

Cantina conducts vulnerability research and responsible disclosure that it publishes alongside the platform. In April 2026 the company disclosed a bug in XZ Utils, and it later reported that Apex had found a memory-safety flaw in the compression utility that it said affected millions of systems and could allow attackers to crash an application and trigger a persistent denial of service via malformed files — a bug it characterized as having "slept" in the code for 14 years before the separate, well-known XZ backdoor incident.[[1]](#cite-id-ohtwbhj0wp)[[6]](#cite-id-vkp69p1to7)

Much of the company's 2026 research focused on healthcare software, which it tied to a 2027 Centers for Medicare & Medicaid Services mandate pushing healthcare teams to ship FHIR (Fast Healthcare Interoperability Resources) application programming interfaces quickly. Cantina stated that it pointed Apex at Pathling and identified three high-severity issues that became six public CVEs — a token scoped to a single patient that could access records it was not entitled to, credentials that could be exfiltrated to an attacker's server, and exposed export files containing patient records — and offered free scans to teams building FHIR endpoints.[[1]](#cite-id-ohtwbhj0wp) In October 2026 the company reported that Apex found nine bugs in the open-source electronic health records platform OpenEMR, two rated high and seven medium, including a flaw letting a logged-in patient retrieve another patient's file; it stated the two high-severity issues were fixed in OpenEMR 8.3.0 and the remaining seven in 8.4.0.[[1]](#cite-id-ohtwbhj0wp)

Cantina has published a body of data it attributes to its platform, which it brands Apex. These include a field report of 4,032 findings across 612 production applications, described as the first empirical report covering severity, reachability, and vulnerability-class data; a benchmark drawn from 1,610 production runs measuring detection performance and compute scaling against human penetration tests; a checklist framing how to govern MCP access, permissions, approvals, and identity before agents can act; and a running set of responsibly disclosed public vulnerabilities with vendor advisories and remediation details.[[2]](#cite-id-vbf5sndj9k)

## Smart Contract and Protocol Security

Alongside its agentic platform, Cantina retains its roots in [smart-contract](https://iq.wiki/wiki/smart-contract) and protocol security, which it delivers through what it describes as Spearbit's top researchers combined with AI-native review, hybrid audits, expert triage, and live bounties.[\[2\]](#cite-id-vbf5sndj9k) The company runs Cantina Competitions, which are time-bound audit contests where researchers review a client's codebase and compete for rewards while judges score and prioritize findings.[\[7\]](#cite-id-u7xccxeyej) Competitions typically last from a few weeks to a couple of months depending on codebase complexity.[\[7\]](#cite-id-u7xccxeyej)​

Within a competition, researchers participate individually or in teams and submit findings in a standardized format that is scored for severity based on impact and likelihood of exploitation; high-severity issues earn the most points and prizes are allocated according to points accumulated.[\[7\]](#cite-id-u7xccxeyej) By default, all high- and medium-severity submissions from researchers with a reputation score below 80 must include a coded proof of concept before the competition ends.[\[7\]](#cite-id-u7xccxeyej) Researchers may appeal assigned severities through an escalation process limited to their own findings, and invalid escalations incur a $100 penalty deducted from future competition earnings credit, which is intended to discourage abusive appeals.[\[7\]](#cite-id-u7xccxeyej)​

Cantina continues to run bug bounties on its [web3](https://iq.wiki/wiki/web3) platform. In October 2026 the company announced it had been engaged by the [Centrifuge](https://iq.wiki/wiki/centrifuge) team to update the bug bounty scope for Centrifuge V3.3, with rewards of up to $250,000 [USDC](https://iq.wiki/wiki/usdc) available to researchers.[\[6\]](#cite-id-vkp69p1to7)​

## Leadership and Workforce

Cantina's leadership draws on experience the company says spans GitLab, Google, Mandiant, and Skype. Harikrishnan Mulackal serves as co-founder and chief executive officer, while Mike Leffer, co-founder and president, is described as a cybersecurity veteran with a US Army background and more than ten years across defense, security operations, and strategic leadership.[[4]](#cite-id-r4o5fm577a) The broader executive team includes Alireza Arjmand as head of security research, Henry Shen as vice president of go-to-market, Mike Leffer as president, Ren Yan Ng as head of APAC, James Smith as partner success lead, Mohammad Rayhan and Srinivas Teja as institutional go-to-market leads, and Vivrut Jayaram as founding go-to-market operations partner.[[1]](#cite-id-ohtwbhj0wp)

Of its 310 employees, Cantina's largest function is research, with 55 people, roughly 18% of staff, followed by technical, finance, and marketing teams. By seniority, specialists make up the largest group at 72 people. The workforce is geographically distributed, with the most employees in India (25), the United States (21), and Nigeria (16), and smaller groups in the United Kingdom, Spain, Brazil, France, Canada, Ghana, and Italy, among others.[[1]](#cite-id-ohtwbhj0wp) The company's hiring draws heavily from the competitive-audit and bug-bounty ecosystem, including [Code4rena](https://iq.wiki/wiki/code4rena), Cyfrin CodeHawks, Spearbit Labs, Sherlock, Immunefi, and HackerOne.[[1]](#cite-id-ohtwbhj0wp)

## Customers and Reception

Cantina lists among its customers and partners Nord Security, GitLab, NVIDIA, Anthropic, Salesforce, Apple, SAP, [Coinbase](https://iq.wiki/wiki/coinbase), and Spring.[\[2\]](#cite-id-vbf5sndj9k) The company publishes endorsements from security leaders who have used the platform. Matt Mock, a chief information security officer, is quoted saying Cantina is "the first platform we have used that carries the work through from finding an issue to driving the fix," and that it lets his team "operate like one far larger than it is."[\[2\]](#cite-id-vbf5sndj9k) Arash Afshar of Coinbase is quoted describing "subtle bugs that Cantina uncovered in an open-source cryptographic repository that I maintain, which had already gone through thorough reviews," calling the tool "a valuable safety net."[\[4\]](#cite-id-r4o5fm577a)​

The company articulates four stated values — security-first, AI-native, speed-focused, and human-centered — the last of which frames its agents as handling noise so that human analysts can focus on what matters rather than replacing them.[\[4\]](#cite-id-r4o5fm577a) Cantina describes itself as "the security workforce behind your security workforce," positioning its platform as a complement to existing security teams rather than a replacement.[\[5\]](#cite-id-qr3yopbhy8)​[\[2\]](#cite-id-vbf5sndj9k)​
