Aqua Security
Burlington, United States
Code-to-runtime CNAPP that ranks CVEs by live workload behavior and can stop an exploit without waiting for a patch.
Raised $60M at a $1B-plus valuation, January 2024
CNAPP, CSPM, and workload startups that map cloud attack surface for companies that do not want another console from a network-security incumbent.
16 companies. Catalog last reviewed 2026-08-23. Page copy reviewed 2026-08-23. Next review by 2026-09-23. Ordered by name. No paid placement.
Cloud security here means independent CNAPP, CSPM, and workload companies, not another console from a network-security incumbent. This index maps every company whose primary product is mapping or defending cloud attack surface. Public mega-caps stay off this list. Every entry carries a 2024 to 2026 proof-of-life signal recorded with a source link, and membership is taxonomy from the research pass.
What they build. Companies here build cloud posture and workload platforms, identity-aware cloud graphs, runtime sensors for VMs and containers, and CNAPP suites aimed at teams that do not want to buy the incumbent stack. Some specialize in one cloud; others sell a multi-cloud graph. Network firewalls and public EDR floors live elsewhere.
Who this is for. Cloud security engineers and CISOs shortlisting independent CNAPP or CSPM vendors, and investors mapping the field by what each company actually ships rather than by booth adjacency.
How order works. Listings are the full live catalog slice for this primary category, sorted alphabetically by name. This is not a scored quality ranking and there is no paid placement. Aevral is a disclosed house listing under the same rules (coming soon, no pin). See /transparency.
Burlington, United States
Code-to-runtime CNAPP that ranks CVEs by live workload behavior and can stop an exploit without waiting for a patch.
Raised $60M at a $1B-plus valuation, January 2024
Tel Aviv, Israel
Kubernetes-rooted CNAPP and CADR, built on CNCF Kubescape, that uses eBPF runtime to decide which CVEs and misconfigs matter.
Kubescape 4.0 released with runtime threat detection GA, March 2026
Tel Aviv, Israel
Cloud policy enforcement that blocks misconfigs and over-privilege at deploy time, before CSPM has anything to scan.
Raised $29M Series A, June 2026
Palo Alto, United States
Seedless external attack-surface discovery that finds cloud, subsidiary, and third-party assets attackers can actually reach.
Named a Leader and Outperformer in the 2026 GigaOm Radar for Attack Surface Management
Tel Aviv, Israel
External attack-surface platform that discovers cloud, subsidiary, and supply-chain assets, then validates which exposures are actually exploitable.
Added $15M to Series A, bringing total funding to $50.3M, February 2024
New York, United States
Cloud, SaaS, identity, and AI detection and response with a forensic lake built for attacks that never touch an endpoint agent.
Raised $30M Series B led by SYN Ventures, January 2025
Portland, United States
Agentless CNAPP that SideScans cloud disks and APIs for the full estate without installing a workload agent.
Named a Strong Performer in The Forrester Wave: Cloud Native Application Protection Solutions, Q1 2026
San Francisco, United States
Behavioral runtime CDR for Kubernetes and AI workloads, fingerprinting what a cluster should do so zero-days show up as drift.
Raised $14M Series A, February 2025
Tel Aviv, Israel
AI purple team that replays CNAPP and SIEM findings against a digital twin to prove which cloud CVEs are actually weaponizable.
Named a CRN 2025 Stellar Startup for the third consecutive year, November 2025
New York, United States
Cloud permissions firewall that enforces least privilege on humans, machines, and AI identities using native AWS, Azure, and GCP controls.
Reported 4x ARR growth as Cloud Permissions Firewall adoption surged, January 2026
Tel Aviv, Israel
Cloud detection and response on a live CloudTwin of every workload, identity, and network path.
Raised $30M Series B, October 2024
Tel Aviv, Israel
Runtime CNAPP that watches cloud and AI agents as they act, then turns the finding into a guardrail.
Raised $75M Series B, November 2025
San Francisco, United States
Runtime CNAPP built on kernel-level system calls, Falco detections, and AI agents that act inside the tools you already run.
Named a Leader in The Forrester Wave: Cloud Native Application Protection Solutions, Q1 2026
Sammamish, United States
Human-plus-AI cloud remediation that closes CNAPP findings without breaking the workload that owns them.
Raised $12M Series A, September 2024
San Francisco, United States
Calico-powered Kubernetes network security and microsegmentation, plus Lynx for governing AI agent calls on the cluster.
Shipped the Winter 2026 Calico Cloud release with an AI assistant and multi-cluster traffic observability, March 2026
San Francisco, United States
Runtime-first CNAPP that ranks cloud risk from what is actually running, not from a static CVE dump.
Raised $250M Series B at a $1.5B valuation, January 2026