Monday, 28 September 2026

Where technology leaders come to think out loud

Harry Wetherald
Image: Maze

The VETTDD 50 · UK startups · 2026Cybersecurity

No.37

Harry Wetherald

Co-founder and CEO, Maze · mazehq.com ↗

Maze’s AI agents separate the vulnerabilities attackers can use from the noise. Its co-founder has now taken them from cloud infrastructure into the code teams write

Series A led by Theory Ventures, June 2025
$25m
Maze Code launched
Jun 2026
share of CVEs Maze says are not exploitable in context
90%

Harry Wetherald co-founded Maze in London in 2024 with Adrian Jozwik and Santiago Castineira and is its chief executive. The company builds AI agents that investigate security vulnerabilities the way a security engineer would, then decide which ones can be exploited in a customer’s environment. The three founders previously held product and engineering leadership roles at Tessian, Elastic and Amazon.

A fast start on funding

Maze raised a $25m (£18.6m) Series A led by Theory Ventures in June 2025, less than a year after it was founded, with Cherry Ventures and Tapestry VC following on. The round took total funding to $31m after a $6m seed. At the time Maze said it had onboarded more than 10 enterprises, including two Fortune 200 companies.

Wetherald said then that the founders had talked to hundreds of security professionals before starting the company and “heard the same complaint again and again – dealing with vulnerabilities is a nightmare”.

From cloud to code

Maze’s first product, Maze Cloud, investigates vulnerabilities in cloud infrastructure. On 23 June 2026 the company launched Maze Code, which applies the same agents to the code teams write and the open-source dependencies they use. Maze says the agents weigh each finding against the customer’s configuration and controls, trace the root cause of anything exploitable and deliver a verified fix to the developer or coding agent that owns the code. It says it trained them on millions of real investigations over two years of building Maze Cloud, and that early results suggest about 90% of common vulnerabilities and exposures (CVEs) are not exploitable in context. The fintech Alloy is among its customers.

“Code security must move from rules to AI, but it’s unpredictable,” Wetherald said at the launch. “Maze Code shares our cloud product’s foundation, proven on millions of investigations, so teams get AI code security they can rely on.”

A week later he set out the thinking behind the launch in a blog post, “Code security isn’t dead”. His argument: as AI gets better at writing code it also gets better at exploiting it, so the volume of code to secure is rising at the same time as attacks speed up.

Why it matters to UK buyers

Maze’s launch release describes application security as squeezed from two directions: attackers using frontier AI models to find and exploit flaws faster, and coding agents letting teams ship more code with less review. Its answer is an agent that does the triage a senior engineer would, at a cost that lets every finding be checked rather than only the critical ones.

For chief information security officers, that changes the buying question from how many vulnerabilities a tool finds to how many it can rule out with evidence. Because Maze can take in findings from the scanners a business already runs, it can sit on top of existing tools rather than replace them.

Wetherald has taken Maze from founding to a two-product platform in about two years. His bet is that security teams will act on agents that show their evidence faster than on scanners that only match rules.

Harry Wetherald’s leader profile →The full 2026 list →