Earlier this year, SafeHill announced the acquisition of Arcane Security, a fast-growing offensive security firm founded by Trevor Baines and Diego Briceno. The acquisition formally brings Trevor and Diego onto the SafeHill team, where they’re now leading two of the most important new product initiatives inside the SecureIQ platform: Helix and Sentinel, our AI-powered code security agents purpose-built for vibe coding security, and HygenIQ, our next-generation internal network pentesting and Active Directory audit engine.
Beyond those flagship products, Trevor and Diego also bring deep expertise in web application penetration testing, AWS cloud assessments, CTF environment development, and cybersecurity curriculum design. Their work as Arcane Security has already shaped a meaningful part of SafeHill’s research and development roadmap.
This post tells the story of how the acquisition came to be, why we made it, and what comes next.
About the team
TL;DR: Trevor and Diego met at Grand Canyon University, built Arcane Security from a campus cyber range into a real offensive security business, and grew into SafeHill product leadership through the work itself.
Trevor and Diego came at security from different angles. Diego’s path started early. By eight, he was taking apart Motorola flip phones and putting them back together. By high school, he was placing third in regional cybersecurity competitions and ranking top 50 in an international competition. By college, the choice felt obvious. Trevor’s route looked different. He started out wanting to build video games, attended a coding bootcamp at Stanford, then stumbled into a two-week hacking course at Harrisburg University the summer before his senior year of high school. That was it. He went to GCU, joined the SOC at his first job, and ground his way into pentesting.
Both of them eventually narrowed in on what they were genuinely good at. For Trevor, that meant web application and cloud penetration testing, plus the AI development work he’d been doing on the side. For Diego, it was internal networks, scanner development, and methodology automation, the kind of deep technical specialization that’s increasingly rare to find in someone his age.
They met through GCU’s student tech club, the Information x Technology Community, or IXT. Trevor grew the club from 15 to 20 students into a multi-track organization filling the GCU cyber range with more than 100 students per event. When he needed a new cybersecurity committee lead, Diego, who was already tutoring his classmates on subnetting in library whiteboard rooms, stepped in. They were already operating as a team inside IXT, building CTFs, co-hosting events, and tutoring students, before there was a company to operate inside.
Arcane Security started shortly after. Trevor needed an LLC to legally invoice a few small clients the GCU cyber range was sending his way, and Diego was the obvious person to bring in. The company grew through bootstrapped client work: pentests, capture-the-flag environments, and cybersecurity course curriculum for universities and high schools. A multi-year engagement with the University of Arizona’s MESA program eventually touched more than 40 high schools and over 1,000 student identities by the end of its run. Along the way, they were accepted into Canyon Ventures, GCU’s startup incubator, where they got early B2B experience and learned, fast, what works and what doesn’t when you’re bootstrapping a startup.
That’s the version that explains the resume. The version that explains the acquisition is what happened after they started working with SafeHill.
Arcane was first introduced to SafeHill co-founder and CEO Mike Pena through a mutual industry connection, shortly after SafeHill came out of Techstars. The initial scope was simple: help build out SafeHill’s services arm with external and internal network pentests while the product team focused on platform engineering.
From there, the relationship grew, project by project. Trevor and Diego added web application pentesting and AWS cloud assessments. Diego took over the internal network side of the business and started building proprietary tooling. Then together they built Tome, an all-in-one LMS and cyber range that let students spin up a Kali Linux instance directly in their browser.
That’s the project that shifted the conversation.
Mike saw that we had a project where we actually built out code. It worked. We had a POC for it. And then through there we started helping out with little efficiency projects here and there. I helped build out what's now called Pathfinder. They started seeing that we could build out actual applications. And then from there we started conversations about the different AI stuff we were doing.
- Trevor Baines, Director of AI Engineering at SafeHill
From there, the work expanded into AI-driven research and development. Trevor began building what would become Helix and Sentinel. Diego began leading research and automation for HygenIQ. The conversation about a formal partnership wrote itself.
About Arcane Security: why Helix, Sentinel, and HygenIQ were created
TL;DR: AI-accelerated development has broken the assumptions that legacy security tools were built on. Trevor and Diego built Helix, Sentinel, and HygenIQ to close the gap, with vibe coding security, validated findings, and unified internal network testing all within a single platform.
To understand why these products exist, you have to understand what’s changed in the last couple of years. AI coding assistants like Claude Code, Codex, GitHub Copilot, and Cursor have moved from novelty to default. According to Sonar’s 2026 State of Code Developer Survey, 42% of all code committed by developers today is AI-generated or AI-assisted, up from just 6% in 2023, and developers expect that share to grow by more than half by 2027. Stack Overflow’s 2025 Developer Survey backs this up: 84% of developers now use or plan to use AI tools, and 51% of professional developers use them daily.
That’s the productivity story. Here’s the security story.
Veracode’s 2025 GenAI Code Security Report found that 45% of AI-generated code contains known security flaws. By mid-2025, teams adopting AI coding assistants were reporting 4x faster code generation but 10x more security findings. A separate large-scale analysis of public GitHub repositories identified 4,241 CWE-mapped vulnerabilities across 77 distinct vulnerability types in AI-generated code samples. Vibe coding has dramatically accelerated how fast software ships and dramatically expanded the attack surface security teams are responsible for defending.
Legacy security tools weren’t built for this. They were built for a world where humans wrote code at human speed and security review cycles had time to catch up. That world is gone. Trevor recognized this earlier than most, and he was deliberate about how to respond.
Helix really came about as an answer to client needs. We had a lot of clients who were saying that they were doing a lot of vibe coding. They were building out software really fast using things like Claude Code or Codex. Helix's whole purpose is to keep up with the expedited pace of development and have AI that can actually help secure the code while you're building it out.
- Trevor Baines, Director of AI Engineering at SafeHill
He was also clear about what he didn’t want to build. Most products in the AI security space today are wrappers around a third-party model API. That approach limits the security posture, caps the technical depth of what’s possible, and forces customers to send source code outside their environment to be analyzed.
I didn't want to make a wrapper for Claude Code or around Codex. I didn't just want to make some API wrap around it. Honestly, both because there's the security impact of it and the business case reason, but also just kind of out of a hacker's pride.
- Trevor Baines, Director of AI Engineering at SafeHill
What he built instead is a true research and development pipeline. Helix is an 8-stage assessment engine: parse, filter, prompt, score, runbook, validate, output, report. It runs on a custom-tuned model trained on SafeHill’s own curated security corpus rather than the public internet. It runs locally on SafeHill-controlled GPUs with zero data egress. It’s GitHub-native (so it drops directly into GitHub projects – a rare feature), maps every pull request inline, and can gate merges if configured. Every finding ships with reasoning, CWE classification, file and line, and a suggested fix.
Then there’s Sentinel. This is the part of the pipeline that closes the loop. Sentinel is a validation agent that questions every finding Helix produces by proving it live against the running application. HTTP probes, browser-driven payloads, Active Directory and LDAP checks across all OWASP Top 10 categories. If Sentinel can exploit it, the finding ships as confirmed. If not, it’s downgraded as a false positive before it ever reaches the developer. The result is an agentic AI inference system that delivers assessment and validation in one closed pipeline.
The results speak for themselves. Helix and Sentinel currently score 91.3% on XBOW, the industry-standard benchmark of 104 containerized vulnerable web apps with explicit ground truth. That beats XBOW’s own score of 85%, beats every open-source agent, and does it on a local model with zero API spend. Pointed at 300 popular open-source repositories, Helix surfaced 22 previously-undisclosed vulnerabilities, all under responsible disclosure. These are live findings, not synthetic benchmarks.
On the internal network side, Diego is leading the research and automation for HygenIQ, SafeHill’s next-generation internal scanner. The focus is on automating the methodology where it makes sense while preserving the parts that genuinely require human judgment.
Currently what we have is a very in-depth Active Directory scanner that we've built proprietary, as well as attack path chaining that we're building out. And then part of that is going to be an AI-driven engine that's similar to Bloodhound.
- Diego Briceno, Director of Offensive Security at SafeHill
Diego is also rethinking the economics of internal testing. The old model, shipping a $700 to $800 hardware appliance to a customer site, hoping it doesn’t get damaged in transit, and waiting for it to come back, is expensive and slow. His new approach delivers full internal access through a downloadable agent that sets up the test environment automatically. Cost per engagement drops dramatically without sacrificing depth.
The pattern in these comparisons is the part that matters most. Legacy tools are great at narrow, point-in-time scans of human-written code, but the modern security stack is increasingly fragmented across a dozen siloed vendors that don’t talk to each other. Helix, Sentinel, and HygenIQ are built to do the opposite: validate findings end-to-end, integrate where developers already work, and live alongside the broader solutions that already operate within SecureIQ.
Why we acquired Arcane Security
TL;DR: Vibe coding security and internal network automation are two of the biggest gaps in modern threat exposure management. No other TEM provider offers vibe coding security today. Arcane’s work, combined with the people behind it, made this acquisition an obvious next step in SafeHill’s mission.
Continuous Threat Exposure Management is the framework that’s reshaping how enterprises think about cyber risk. Introduced by Gartner in 2022 and ranked second in their Top Strategic Technology Trends for 2024 (just behind AI security itself), CTEM is built on the idea that exposure management has to be continuous, risk-centric, and validated, not a once-a-year report that sits in a drawer.
SafeHill has spent the last two years building the most comprehensive CTEM-aligned platform on the market. Today, SecureIQ unifies threat exposure management, internal network security, cloud security, secure code review, and web application & API testing – all in a single platform. The acquisition of Arcane Security added two important differentiators to SafeHill’s platform capabilities.
The first gap is vibe coding security. No other TEM provider on the market today offers a true vibe coding security capability, the kind that can keep pace with AI-accelerated development, validate findings live against the running application, and drop natively into the developer’s existing GitHub workflow. Helix and Sentinel give SafeHill that capability on day one. As more enterprises adopt AI coding assistants across customer-facing and mission-critical code, the ability to secure that code at the speed it’s being generated becomes a defining competitive differentiator. We wanted to lead on it, not follow.
The second gap is the internal network and Active Directory side of the assessment story. Internal pentesting has historically been the most operationally expensive part of an engagement: shipping hardware, coordinating logistics, training customer staff to deploy a physical box. Diego’s HygenIQ work collapses that overhead through a downloadable agent model while deepening the technical capability through proprietary Active Directory scanning and AI-driven attack path chaining. That’s a step-change improvement, not an incremental one.
Both products fit SafeHill’s core conviction that the most defensible security companies of the next decade will be AI-driven with humans in the loop. We don’t believe in AI-only security, and we don’t believe in human-only security. AI scales the repetitive validation work. Human experts provide the judgment, the relationships, the novel finding development, and the context that customers value most. Trevor and Diego share that conviction in a way that’s grounded in how they actually work.
AI is really, really good at anything that has to do with pattern recognition or if you already have done something and you want it to reproduce that, it's fantastic at that. But specifically for anything in cybersecurity, especially with pen testing, that has to do with novel findings, AI can't do anything it hasn't seen before. That's the biggest thing, that AI isn't magic, at least not yet.
- Trevor Baines, Director of AI Engineering at SafeHill
The best security professionals today are the ones who know how to leverage AI while still having the technical ability to challenge its output. We can't just take AI's word most of the time. A lot of times even with our code scanners and stuff like that, we still have to go in and actually do the novel finding and write the actual vulnerability. But we have to be the ones to review it, to make sure that it's not just hallucinating something.
- Diego Briceno, Director of Offensive Security at SafeHill
That’s the philosophy that drives the AI-human hybrid validation model across SecureIQ. It’s also the philosophy that drives Helix, Sentinel, and HygenIQ. The fit was unmistakable from the first time we sat down to talk about it.
The other half of the decision is the people. Both Trevor and Diego have an unusual combination of qualities that’s hard to find and impossible to manufacture: technical depth that goes well beyond their years, an obsessive drive to build things others say aren’t possible, the discipline to bootstrap a real company, and the humility to keep learning from people further down the road. Those are the kinds of people you don’t pass on.
Why Arcane believes in SafeHill's mission
TL;DR: For Trevor and Diego, the move to SafeHill is a chance to build at the speed they want, with the people they want to work with, on the problems they care about most. The culture, the pace, and the chance to work alongside Hector Monsegur were all decisive.
Both Trevor and Diego have worked at larger, more corporate pentesting firms before. The contrast with SafeHill is something they bring up unprompted.
My work and my efforts matter in the sense that if I put in extra work and I develop this cool tool over the weekend and I show it to Mike, Mike's gonna give me honest feedback. Not just tell me, 'Okay, go away. We'll look at this next quarter because that's when our board meeting is.' We want to improve the business, we want to move fast, we want to service clients in new and interesting ways.
- Trevor Baines, Director of AI Engineering at SafeHill
We're surrounded by people who genuinely love hacking. We're part of an actual team of researchers, and we're improving each other's methodologies. We even have all of our methodologies hosted for each other on one of our internal platforms. We sit there and improve each other's work.
- Diego Briceno, Director of Offensive Security at SafeHill
A major part of that team is Hector Monsegur, SafeHill’s co-founder and Chief Research Officer, better known to some by his former alias “Sabu.” Hector’s history (from one of the most controversial black hat hackers of his generation to a white hat who’s now helped prevent more than 300 cyber attacks on federal infrastructure) is part of what makes SafeHill’s offensive security work feel different from anything else in the industry. For Trevor and Diego, getting to work with him every day is a meaningful part of what made this decision easy.
The biggest thing that I really like about working with somebody like Hector, and excuse my French, but it feels like you're working with a fucking hacker. It is like the most raw experience. This was an adversary back in the day. This is what he sounds like, this is what it's like working with him, and this is what it's like building a business with him.
- Diego Briceno, Director of Offensive Security at SafeHill
My work and my efforts matter in the sense that if I put in extra work and I develop this cool tool over the weekend and I show it to Mike, Mike's gonna give me honest feedback. Not just tell me, 'Okay, go away. We'll look at this next quarter because that's when our board meeting is.' We want to improve the business, we want to move fast, we want to service clients in new and interesting ways.
- Trevor Baines, Director of AI Engineering at SafeHill
That perspective, having someone who’s been on both sides of the keyboard, isn’t a marketing line at SafeHill. It’s how product decisions get made. And for engineers who care as much about the work as Trevor and Diego do, that environment is rare enough to be worth joining permanently.
Looking ahead
The acquisition of Arcane Security marks a real inflection point for SafeHill. We’re adding two product lines that, together, define the next chapter of what threat exposure management looks like in an AI-accelerated world.
Helix and Sentinel give security teams the ability to keep pace with vibe coding at the speed it’s actually happening, with validated findings instead of false-positive noise, inside the developer workflow rather than yet another dashboard. HygenIQ collapses the cost and complexity of internal network and Active Directory testing while deepening the depth of what’s possible. Both products live inside the SecureIQ platform alongside our broader products and services line. The whole becomes greater than the sum of its parts.
More than the products, this acquisition reinforces the kind of company SafeHill is building. One where former adversaries, services-first pentesters, and AI engineers all work on the same problems in the same room. One where the people building the product are the people running real engagements against real adversaries. One where AI scales the work and humans provide the judgment. And one where the next generation of security talent, people like Trevor and Diego, get the room and the resources to do the best work of their careers.
There’s a lot more to come. New Helix and Sentinel capabilities are shipping. HygenIQ is rolling out to enterprise customers. The roadmap for SecureIQ has never looked more ambitious. If you’re a security leader thinking about how to operationalize CTEM, keep up with vibe coding, or modernize your internal network testing, we’d love to show you what we’re building.
Follow SafeHill on LinkedIn to stay in the loop, or book a demo to see Helix, Sentinel, HygenIQ, and the broader SecureIQ platform in action.
About the Author
Daniela Applegate is SafeHill's Marketing Manager and a former cybersecurity founder who's worn more hats than most people own. Before joining SafeHill, she built companies, taught college students, and worked as a consultant for startups small and large. She brings equal parts strategy and scrappiness to everything she does, and genuinely believes good marketing starts with saying something worth hearing.