SQUR is one of five finalists for the ATHENE Startup Award UP26@it-sa. ATHENE, Europe's largest research centre for IT security, announced the shortlist on 27 August 2026. The final is a live pitch on 28 October at it-sa Expo&Congress in Nuremberg.
The award
UP26@it-sa is awarded by ATHENE, the National Research Center for Applied Cybersecurity in Darmstadt, and presented each year at it-sa Expo&Congress. ATHENE calls it the most important startup prize for cybersecurity in the DACH region.
Five companies are on this year's shortlist, and between them they cover most of what the field currently worries about: Blindsight (Zurich) on monitoring AI systems, Complioty (Munich) on CRA compliance for machinery, Fuzzware (Bochum) on fuzzing embedded software, RedCastle (Heubach) on SOC services for mid-sized companies, and SQUR (Weingarten) on autonomous pentesting.
What happens next
The five finalists introduced themselves in a digital preview on it-sa 365 on 22 September. The final is on 28 October 2026, 15:30 to 16:30, live on stage at it-sa Expo&Congress in Nuremberg, in front of the jury and the audience. The fair itself runs 27 to 29 October at the Nuremberg Exhibition Centre.
Meet us at it-sa
Our founder Adam Lundqvist is at the fair for all three days, 27 to 29 October. We do not have a booth, so a time has to be agreed in advance. If you want to watch an autonomous pentest run against something of your own, or talk through what an exploit-proven finding looks like in front of an auditor, book a slot and mention it-sa.
What we are pitching
Two questions decide what a security test is actually worth. How often does your software change? And how often do you check whether it is still secure? The gap between those two answers is the window in which a vulnerability is already in your product and nobody knows it yet. Test once a year and that window averages six months. Test every month and it is two weeks.
SQUR closes it by attacking web applications and APIs the way an attacker would. Every finding is proven with a working exploit rather than inferred from a signature, the report is written for an auditor, and the certificate updates with every clean run.