The next software customer might never visit a homepage or sit through a product demo. Coding agents like Claude Code, Codex and Cursor can already discover products, choose libraries, install SDKs and call APIs on a user’s behalf. Increasingly, software has to win over machines that can go from finding a product to using it.
Lightsage was built for that paradigm shift. Today, the San Francisco startup announced $4 million in funding led by Nexus Venture Partners, to build the infrastructure for what it calls Agent-Led Growth, or ALG. The round also includes backing from operators across the developer and AI ecosystem, including former Salesforce CTO Steven Tamm, Postman CEO Abhinav Asthana, Apollo CEO Matt Curl, DocuSign President and GM of Growth Robert Chatwani, former GitLab Head of Growth Hila, Resend CEO Zeno, Firecrawl Co-founder Eric, Daytona CEO Ivan, Tinyfish COO Shuhao, and Adam Frankl among others.
From product-led growth to agent-led growth
Software companies have spent decades learning how to convert humans. AI agents are creating a new buyer. A coding agent can now choose a database, API or authentication provider, then start integrating it without ever visiting a vendor’s website. That means visibility alone is no longer enough. The agent still has to understand the docs, choose the right SDK, authenticate and get the product working.
This is where existing GEO (Generative Engine Optimization) products fall short, and where LightSage closes the loop: ensuring agents can actually use and pay for the product.
How Lightsage works
Lightsage gives software companies a way to see their product through an agent’s eyes. The platform runs large-scale simulations across answer engines and coding agents, measuring where a company appears against competitors and what happens next. Agents are given real tasks that require them to navigate documentation, choose the right tooling and successfully use APIs, SDKs, CLIs, MCP servers and Agent Skills.
When they fail, Lightsage pinpoints why. The break might be discoverability, confusing documentation, authentication, an API endpoint, an SDK implementation or an incompatible MCP server. Teams can fix the issue, rerun the workflow and measure whether agent success improves.
Lightsage also provides analytics on real agent traffic: when agents visit a company’s website or docs, what they interact with and whether those journeys turn into product usage. The longer-term goal is to close the loop entirely, feeding those insights back into development and deployment workflows so products continuously improve for agents.
The platform currenty supports Claude Code, Codex, Cursor, GitHub Copilot, OpenCode and a growing range of other coding agents.
Early traction
Lightsage is starting with developer software, where agent behavior is already easy to observe. Customers including Firecrawl, Reducto, Daytona, Rime and Tinyfish use Lightsage to understand why agents choose certain products, where integrations break and how key workflows perform after product or documentation changes.
A typical use case starts with a coding agent repeatedly recommending a competitor. Lightsage reproduces the same task across products and agents to isolate the cause: visibility, documentation or the product experience itself.
A new growth discipline for software
Agent-Led Growth creates questions traditional analytics cannot answer. Human acquisition can be traced through searches, clicks and sign-ups. Agents may discover, evaluate and use a product without following any of those paths, making their traffic and revenue much harder to attribute.
Their behavior is also less predictable. Different coding agents can approach the same product in different ways, and those patterns shift as models and interfaces change. A workflow that works in one agent may fail in another.
Lightsage believes Agent Experience — how easily AI agents can understand, use and pay for a product — will become a core part of Agent-Led Growth, much as Developer Experience became critical to winning human developers.
What’s next
Lightsage will use this funding to deepen its agent evaluation, analytics, attribution and optimization capabilities across APIs, SDKs, CLIs, MCP servers and agent skills. Developer tools are just the starting point: as agents begin acting directly across B2B software, infrastructure and payments, Lightsage wants to become the infrastructure companies use to understand, improve and ultimately win the agent channel. To build it, Lightsage is growing its team across technical and commercial roles, and welcomes candidates who want to help define the agent channel at lightsage.com/careers.
A misconfigured database exposed 220 million traveler records tied to Vietnam
Posted in Commentary with tags Vietnam on September 8, 2026 by itnerdSecurity researchers found an exposed Elasticsearch cluster holding roughly 220.7 million passenger and crew records from a Vietnam-linked Advance Passenger Information System, spanning January 2017 through April 2026, reachable through a cloud-based path that accepted default credentials. Singapore Airlines’ security team helped coordinate the response, and the database was secured June 8, five days after researchers reported it, with no confirmed evidence anyone malicious got there first.
More details here: Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data
Jason Brown, Director of Customer Advisory Counter Fraud Lead, iCOUNTER had this to say:
“A passport number tied to a name, date of birth, and travel history is a complete identity kit, not a fragment. Stolen card numbers get frozen the moment a bank flags fraud. A passport record doesn’t expire that way. It stays useful for building a synthetic identity or supporting document fraud years after the original trip happened, which is why nine years of records sitting in one place matters more than the headline number suggests. Fraud is only half of it. Nation-state actors use exactly this kind of collection to track individuals of interest and their movement for espionage and other targeting. Travel history at this depth is a pattern of life record, not just an identity record.
What actually got this database exposed is almost mundane compared to what was in it. Direct access to the cluster was locked down, a second cloud path was not, and that one accepted default credentials. It is the same failure I chased for years on the law enforcement side, someone secures the route they built and never finds the one they inherited, and the route nobody documented is still running the password it shipped with. The good news here is narrower than the headlines suggest.
Researchers reported and it was secured within five days. That is not the same as knowing nobody else got there first, as there were no server logs and scanning platforms had the host indexed as a database years before anyone reported it. But a system like this is not Vietnam’s exposure alone. Every airline that fed passenger data into it, and every country whose citizens transited through, inherited that risk the moment it was accessible, whether or not anyone malicious got there first. The response should be the same as if this had been confirmed stolen: assume the exposure window was real, and go check what else in your own vendor chain is reachable by a path nobody documented and a password nobody rotated.”
This would be a really good time to check to see if you have the same issues. Because you do not wish to be sitting on a ticking time bomb now would you.
Leave a comment »