Deep dive
Company Spotlight: 42Crunch
Adara Team
February 11, 2026
Min read

APIs are the connective tissue of modern software, and its weakest point

Every modern application, and now every AI agent, gets things done by calling APIs. That connective tissue has grown faster than most organizations' ability to secure it. Internal APIs expose microservices, external APIs hand functionality to third-party developers, and a growing share of traffic now comes from AI agents and large language models calling those same endpoints on a company's behalf. Each new connection is a new door, and most enterprises cannot say with confidence how many of those doors are actually locked. An unsecured API is a direct path into the systems behind it, and as the number of APIs multiplies, so does that exposure.

Building security into the API itself, not around it

42Crunch, based in London, takes a different starting point than most application security vendors: instead of bolting protection on top of an API after the fact, secure it at the level of its own contract. The platform reads an API's OpenAPI definition, checks it against a large library of security rules, and enforces those same policies at every later stage: while the API is being written, while it is tested, and while it is running in production. That gives development and security teams a shared, machine-readable definition of what “secure” means for a given API, rather than a set of manual reviews that fall out of date the moment the API changes.

That approach has taken on new relevance with the rise of AI agents that call enterprise APIs directly and often autonomously. 42Crunch now positions its platform explicitly around what it calls the “last mile” between an AI agent and the enterprise systems it reaches through an API, including validating Model Context Protocol (MCP) servers, the connective layer a growing number of agents use to reach tools and data. The goal is the same one the company started with: give an API a security contract it cannot violate, whether the caller is a human developer, another service, or an autonomous agent.

From a London security startup to an established name in API security

Founded in 2016 and headquartered in London, 42Crunch operates as an independent vendor focused squarely on API security, and its work is recognized by industry analysts covering that category. The conviction underneath it is simple: API security should be enforced by design, not left to a checklist.

Two founders out of the enterprise security world

42Crunch counts two active co-founders on its management team, who bring decades of enterprise security experience to the problem. Jacques Declas, CEO, has spent more than twenty years building and scaling enterprise software and security businesses, including earlier roles at Forum Systems and Vordel. Philippe Leothaud, CTO, leads the company's engineering and R&D organization and has focused his career on securing API infrastructure built around standards like OpenAPI, OAuth, and OpenID Connect.

When we invested, and what followed

We first backed 42Crunch in 2020, as one of the earliest institutional investors in the company, drawn to a team that understood both the scale of the API security problem and the specific, technical way to solve it. That conviction was reinforced in 2021, when 42Crunch closed a $17 million Series A round led by Energy Impact Partners, with our continued participation, moving from seed to Series A in eleven months. The round was earmarked to expand the platform's coverage and its go-to-market outside Europe.

That capital extended the platform from a design-time and runtime API security tool into a security layer built for how enterprises actually consume APIs, including through AI agents and MCP servers. The core idea that drew us in is unchanged: security enforced automatically, at the level of the API contract, rather than left to hope.