Security Startups

Directory

Company directory

148 companies. Sorted by name. No paid boost.

Reset

42Crunch

Dublin, Ireland

OpenAPI-first API security that audits the contract, tests it, then wraps a micro-firewall around the live endpoint.

Released OAS 3.1 support for API Protection in the 42Crunch platform, February 2026

API and runtimeFounded 2016

7AI

Boston, USA

Series A

Swarming AI agents that take over the investigation work human SOCs cannot staff.

Raised $130M Series A led by Index Ventures, December 2025

Detection and response$166M raisedFounded 2024

Abnormal AI

San Francisco, United States

Series D

API-native email and SaaS defense that baselines human behavior to catch BEC and account takeover.

Raised $250M Series D at a $5.1B valuation, August 2024

Email and collaboration$546M raisedFounded 2018

Action1

Houston, USA

Bootstrapped

Cloud-native patch management that remediates endpoints without a VPN or on-prem console.

H1 2026 ARR from six-figure deals grew 275% year over year

Aembit

Silver Spring, United States

Series A

Workload IAM that issues short-lived, secretless credentials for services, scripts, and AI agents.

Raised $25M Series A led by Acrew Capital, September 2024

Secrets and non-human identity$45M raisedFounded 2021

Aevral

Listed by Better ISMS (same rules as everyone) · Coming soon

Seed

GitHub App that scans an owned default-branch SHA for authz, IDOR, and business logic. By ISMS Copilot.

Product brand Aevral and aevral.com purchased 2026-08-23, launch imminent

Aikido Security

Ghent, Belgium

Series B

One platform that scans code, cloud, and runtime, then triages and auto-fixes what is actually reachable.

Raised $60M Series B at a $1B valuation, January 2026

Application security$84M raisedFounded 2022

Akeyless

Ramat Gan, Israel

Series B

SaaS vault for secrets, keys, and certificates that never stores the master key in the customer's cloud.

Took a strategic investment from Deutsche Bank Ventures, October 2024

Secrets and non-human identity$79M raisedFounded 2018

Anchore

Santa Barbara, USA

Series B

Open-source Syft/Grype plus enterprise SBOM management for containers and the pipeline that builds them.

Published the 2025 Anchore supply-chain blog series, December 2025

Apiiro

New York, USA

Series B

Code-to-runtime ASPM graph that ranks material application risk, not every scanner finding.

Joined Chainguard's Athena coalition and made AutoFix free for OSS maintainers, August 2026

Application security$135M raisedFounded 2019

Apono

Tel Aviv, Israel

Series B

Just-in-time cloud access that kills standing privileges for humans, machines, and agents.

Raised $34M Series B led by USVP, November 2025

Identity and access$54.5M raisedFounded 2022

AppOmni

San Mateo, United States

Series C

SaaS security posture for Salesforce, ServiceNow, Microsoft 365, and the agents now living inside them.

Reported 43% year-over-year revenue growth and five of the top 10 Fortune 500 as customers, February 2025

Email and collaboration$123M raisedFounded 2018

Aqua Security

Burlington, United States

Series E

Code-to-runtime CNAPP that ranks CVEs by live workload behavior and can stop an exploit without waiting for a patch.

Raised $60M at a $1B-plus valuation, January 2024

Cloud security$265M raisedFounded 2015

Arctic Wolf

Eden Prairie, USA

Series F

Concierge MDR on the Aurora platform, now with its own endpoint prevention.

Launched Aurora Endpoint Security and acquired Cylance from BlackBerry in 2025

Detection and response$900M raisedFounded 2012

ARMO

Tel Aviv, Israel

Series A

Kubernetes-rooted CNAPP and CADR, built on CNCF Kubescape, that uses eBPF runtime to decide which CVEs and misconfigs matter.

Kubescape 4.0 released with runtime threat detection GA, March 2026

Cloud security$35M raisedFounded 2019

ArmorCode

Palo Alto, USA

Series B

Scanner-agnostic ASPM that correlates hundreds of tools into the findings that actually matter.

Raised $16M strategic round, taking total funding to $81M, March 2026

Application security$81M raisedFounded 2020

Arnica

Alpharetta, USA

Seed

Pipelineless SAST, SCA, secrets, and IaC that scans every push and talks to the developer in Slack.

Shipped PR secrets scanning and secrets-in-HEAD detection, June 2026

Application security$7M raisedFounded 2021

Aryon Security

Tel Aviv, Israel

Series A

Cloud policy enforcement that blocks misconfigs and over-privilege at deploy time, before CSPM has anything to scan.

Raised $29M Series A, June 2026

Cloud security$38M raisedFounded 2024

AttackIQ

Los Altos, USA

Series C

Security control validation platform built around MITRE ATT&CK and purple-team testing.

Named among 2026 CTEM and BAS alternatives in independent vendor comparisons

Backslash Security

Tel Aviv, Israel

Series A

Reachability-aware AppSec now aimed at AI coding agents, IDEs, MCPs, and the packages they pull.

Raised $19M Series A led by KOMPAS VC, February 2026

Software supply chain$27M raisedFounded 2022

Bedrock Data

Menlo Park, United States

Series A

Metadata lake DSPM that classifies petabyte estates in place, then governs AI access in plain language.

Raised $25M Series A led by Greylock, November 2025

Data security$35M raisedFounded 2023

BigID

New York, United States

Series D

Hybrid DSPM and data intelligence platform for discovery, privacy, and AI risk across cloud and on-prem.

First DSPM vendor to cross $100M in annual revenue, 2024

Data security$308M raisedFounded 2016

Boost Security

Montreal, Canada

Seed

Pipeline and package gates that block supply-chain junk before AI-written code swallows it.

Raised $4M and acquired SecureIQx and Korbit.ai, May 2026

Software supply chain$16M raisedFounded 2020

Censys

Ann Arbor, USA

Series D

Internet-wide map of exposed infrastructure used for ASM, threat hunting, and exposure management.

Raised $40M Series D plus $30M debt led by Morgan Stanley Expansion Capital, March 2026

Offensive and exposure$198M raisedFounded 2017

Chainguard

Kirkland, USA

Series D

Zero-to-low CVE container images and language libraries rebuilt from verified source.

Closed $280M growth round from General Catalyst at a $3.5B valuation, October 2025

Software supply chain$892M raisedFounded 2021

Cloudsmith

Belfast, United Kingdom

Series C

Universal artifact control plane for what AI and humans actually put into production.

Raised $72M Series C led by TCV and Insight Partners, April 2026

Software supply chain$124M raisedFounded 2016

Clover Security

New York, USA

Series A

Design-led product security agents that review PRDs, architecture, and specs before code exists.

Emerged from stealth with $36M seed and Series A, November 2025

Application security$36M raisedFounded 2023

Clutch Security

Tel Aviv, Israel

Series A

Zero Trust for non-human identities: discover the secret, then make stolen static credentials useless.

Raised $20M Series A led by SignalFire, January 2025

Secrets and non-human identity$28.5M raisedFounded 2023

Conceal

Augusta, USA

Series B

Browser-native SSE that gives zero-trust access without a VPN, VDI, or backhauled proxy.

Raised $26M Series B led by Two Bear Capital, October 2025

Endpoint and browser$36M raisedFounded 2012

Concentric AI

San Mateo, United States

Series B

Semantic DSPM that labels unstructured data by meaning, then remediates oversharing on-prem and in the cloud.

Raised $45M Series B led by Top Tier Capital and HarbourVest, October 2024

Data security$67M raisedFounded 2018

ConductorOne

San Francisco, United States

Series B

AI-native identity platform that folds IGA, IAM, and PAM into one access control plane.

Raised $79M Series B led by Greycroft, October 2025

Identity and access$111M raisedFounded 2020

Conifers

Dallas, USA

Series A

MSSP-first agentic SOC that wires intel, hunting, detections, investigation, and response into one loop.

Raised $25M Series A led by SYN Ventures, January 2025

Detection and response$25M raisedFounded 2024

Contrast Security

Los Altos, United States

Series E

IAST, RASP, and ADR that instrument the running app so exploits are seen in the code path, not the packet.

Published the Software Under Siege 2025 report on application-layer attacks, August 2025

API and runtime$269M raisedFounded 2014

Corgea

San Francisco, USA

Seed

AI SAST that hunts broken auth and business-logic bugs, then writes a patch developers can merge.

Raised $2.6M seed led by Shorooq, with Y Combinator participating, November 2024

Application security$2.6M raisedFounded 2023

Corsha

Washington, United States

Series A

Machine identity provider for operational technology, factories, and defense networks that still run API keys.

Raised $18M Series A-1 led by SineWave Ventures, April 2025

Secrets and non-human identity$30M raisedFounded 2017

Cyberhaven

Palo Alto, United States

Series D

Data detection and response that traces lineage as files move, transform, and hit AI tools.

Raised $100M Series D at a $1B valuation, April 2025

Data security$250M raisedFounded 2016

Cycode

New York, USA

Series B

ASPM with its own SAST, SCA, and pipeline scanners, plus a graph for AI-written code.

Named a Leader in Gartner's first Magic Quadrant for Software Supply Chain Security, June 2026

Application security$81M raisedFounded 2019

CyCognito

Palo Alto, United States

Series C

Seedless external attack-surface discovery that finds cloud, subsidiary, and third-party assets attackers can actually reach.

Named a Leader and Outperformer in the 2026 GigaOm Radar for Attack Surface Management

Cloud security$153M raisedFounded 2017

Cyera

New York, United States

Series G

AI-native DSPM that classifies sensitive data, then governs what people and agents can do with it.

Raised $600M Series G at a $12B valuation, June 2026

Data security$2.3B raisedFounded 2021

Cymulate

Tel Aviv, Israel

Series D

BAS-born exposure validation that now pushes findings into automated control updates.

Shipped Vero AI for agentic cyber defense engineering on the live platform, 2026

Offensive and exposure$141M raisedFounded 2016

Cynet

Boston, USA

Series C

All-in-one XDR agent for teams that cannot staff a SOC or buy seven point products.

Named Leader and Outperformer in the 2026 GigaOm Radar for XDR

Endpoint and browser$79M raisedFounded 2014

Defakto

Palo Alto, United States

Series B

SPIFFE-based non-human IAM that replaces static secrets with short-lived workload identities.

Raised $30.75M Series B led by XYZ Ventures, October 2025

Secrets and non-human identity$50M raisedFounded 2022

Descope

Los Altos, United States

Seed

Customer identity workflows that let product teams ship login, MFA, and agent auth without an IAM rebuild.

Closed $35M seed extension, $88M total, September 2025

Identity and access$88M raisedFounded 2022

Detectify

Stockholm, Sweden

Series B

Hacker-powered surface monitoring for domains, apps, and APIs, now with an MCP server for AI workflows.

Launched a Detectify MCP server for AI security workflows, 2026

DoControl

New York, United States

Series B

SaaS data security that watches sharing in Google Workspace, Slack, and Box, then revokes it automatically.

Launched Dot, an AI SaaS data security assistant, June 2025

Email and collaboration$45M raisedFounded 2020

Doppler

San Francisco, United States

Series A

Developer-first secrets platform that syncs env vars, rotates them, and logs who changed what.

Launched Change Requests for approved secret edits, October 2024

Secrets and non-human identity$29M raisedFounded 2018

Dropzone AI

Seattle, USA

Series B

Software-only AI SOC analyst that investigates alerts without a managed service attached.

Raised $37M Series B led by Theory Ventures, July 2025

Detection and response$57M raisedFounded 2023

EasyDMARC

Los Angeles, United States

Series A

Self-serve DMARC, SPF, and DKIM platform for teams that need enforcement without a mail consultant.

Raised $20M Series A led by Radian Capital, September 2024

Email and collaboration$22.3M raisedFounded 2017

Endor Labs

Palo Alto, USA

Series B

Reachability-first AppSec: SAST and SCA that only page you when the vulnerable function is actually called.

Raised $93M Series B led by DFJ Growth, April 2025

Application security$163M raisedFounded 2021

Escape

Paris, France

Series A

AI pentesting for APIs and web apps that proves exploitability, including IDOR and business logic, not just crawler noise.

Raised $18M to expand agentic pentesting for APIs and business logic, March 2026

API and runtime$22M+ raisedFounded 2020

Exaforce

San Jose, USA

Series B

Real-time knowledge graph plus Exabot agents that investigate and stop attacks as they happen.

Raised $125M Series B at a $725M valuation, May 2026

Detection and response$200M raisedFounded 2023

Expel

Herndon, USA

Series E

Vendor-agnostic MDR that works on the SIEM and EDR you already bought.

Launched MDR coverage for the full AI attack surface, August 2026

Detection and response$289M raisedFounded 2016

Finite State

Columbus, USA

Series B

Product and firmware SBOM platform for the devices you buy and the binaries you did not compile.

Won Cybersecurity Stars award for firmware security leadership, June 2026

Fleet

San Francisco, USA

Series B

Open-source osquery control plane for Mac, Windows, Linux, and phones, cloud or self-hosted.

Raised $27M Series B led by Ten Eleven Ventures, June 2025

Endpoint and browser$52M raisedFounded 2020

Fortanix

Santa Clara, United States

Series C

Confidential computing and key management so data stays encrypted while AI and apps use it.

Joined Cisco Secure AI Factory with NVIDIA for Confidential AI inference, June 2026

Data security$122M raisedFounded 2016

GitGuardian

Paris, France

Series C

Secrets detection plus NHI lifecycle, from leaked keys in git to the agents still using them.

Raised $50M Series C led by Insight Partners, February 2026

Secrets and non-human identity$108M raisedFounded 2017

Gray Swan

Pittsburgh, USA

Series A

Frontier-lab red teaming (Shade) and runtime defense (Cygnal) trained on unpublished attacks.

Raised $40M Series A co-led by Wing and Madrona, May 2026

AI security$40M raisedFounded 2024

Guardio

Tel Aviv, Israel

Series B

Consumer browser protection that treats everyday users like they deserve an enterprise SOC.

Raised $80M Series B led by ION Crossover Partners, November 2025

Endpoint and browser$127M raisedFounded 2018

Hadrian

Amsterdam, Netherlands

Seed

Outside-in autonomous hacker that discovers, exploits, and validates external exposure continuously.

Shipped Sense, Plan, Attack AI agents to operationalize CTEM, November 2025

Offensive and exposure$14M raisedFounded 2021

HarfangLab

Paris, France

Series A

ANSSI-certified French EDR for buyers who cannot put a US cloud agent on sensitive endpoints.

Added Attack Surface Management to its endpoint platform, September 2025

Endpoint and browser$33M raisedFounded 2018

HiddenLayer

Austin, USA

Series A

Model scanner, attack simulation, and runtime firewall for agentic, generative, and predictive AI.

Selected to support the US DOE Prometheus initiative under the Genesis Mission, August 2026

AI security$56M raisedFounded 2022

Horizon3.ai

San Francisco, USA

Series E

NodeZero autonomous pentest that exploits live networks the way an attacker would, continuously.

Raised $250M Series E at a $2B-plus valuation, August 2026

Offensive and exposure$429M raisedFounded 2019

Huntress

Columbia, USA

Series D

Managed EDR, identity, and SIEM for businesses that do not run a 24/7 SOC.

Surpassed $250M ARR and 270,000 businesses protected, July 2026

Detection and response$300M raisedFounded 2015

Infisical

San Francisco, United States

Series A

Open-source secrets manager you can self-host or run as SaaS, now adding agent-safe credential proxying.

Raised $16M Series A led by Elad Gil, June 2025

Secrets and non-human identity$19M raisedFounded 2022

Intezer

New York, USA

Series C

Forensic-grade AI SOC that investigates 100% of alerts, including the low-severity ones MDR skips.

Expanded AI SOC platform for teams outgrowing MDR, March 2026

Detection and response$60M raisedFounded 2016

IONIX

Tel Aviv, Israel

Series A

External attack-surface platform that discovers cloud, subsidiary, and supply-chain assets, then validates which exposures are actually exploitable.

Added $15M to Series A, bringing total funding to $50.3M, February 2024

Cloud security$50M raisedFounded 2016

IRONSCALES

Atlanta, United States

Series C

AI email security that mixes automated remediation with a network of admin-reported phishing.

Launched Winter 2026 agentic release with Red Teaming, Phishing SOC, and Simulation agents, March 2026

Email and collaboration$80M raisedFounded 2013

Island

Dallas, United States

Series E

Enterprise browser that embeds DLP, ZTNA, and last-mile control into Chromium instead of another VDI farm.

Raised $250M Series E at a $4.8B valuation, March 2025

Email and collaboration$730M raisedFounded 2020

JumpCloud

Louisville, United States

Series F

Cloud directory that binds workforce identity, devices, and access without living on Active Directory.

Acquired Breez to add identity threat detection, October 2025

Identity and access$400M+ raisedFounded 2012

Keep Aware

Austin, USA

Seed

Browser detection and response that watches behavior inside existing Chrome and Edge sessions.

Published The State of Browser Security Report 2026 from production telemetry

Endpoint and browser$2.4M raisedFounded 2022

Knostic

Tel Aviv, Israel

Seed

Need-to-know access control so Copilots, coding agents, and MCP tools stop oversharing.

Raised $11M to ship need-to-know controls for enterprise AI, March 2025

AI security$11M raisedFounded 2023

Kodem

Tel Aviv, Israel

Series A

Runtime-backed AppSec that proves a CVE is loaded in memory before it hits the backlog.

Published Rapyd case study showing runtime-led AppSec without extra headcount, July 2025

Application security$25M raisedFounded 2021

Lasso Security

Tel Aviv, Israel

Seed

Discovery, posture, automated red team, and gateway runtime for models and agents.

Published Securing Agentic AI: The Intent Security Framework, March 2026

AI security$6M raisedFounded 2023

Legit Security

Tel Aviv, Israel

Series B

AI-native ASPM that discovers the software factory, then VibeGuard blocks bad AI code in the IDE.

Shipped VibeGuard to secure AI-generated code at the developer endpoint, 2026

Application security$70M raisedFounded 2020

Levo.ai

San Francisco, United States

Runtime API and AI security with eBPF visibility, agentless discovery, and inline protection that stays off the data path for privacy.

Shipped Launch Week 2026 with AI Firewall, AI Gateway, and MCP discovery and testing, February 2026

API and runtimeFounded 2021

Lineaje

Santa Clara, USA

Series A

AI-driven lineage of every component, including the ones hiding in firmware and public-sector stacks.

Raised $20M Series A co-led by Prosperity7, Neotribe, and Hitachi, July 2024

Software supply chain$27M raisedFounded 2021

Lumos

San Francisco, United States

Series B

Autonomous IGA that reviews, provisions, and rightsizes access for people, NHIs, and AI agents.

Launched Identity Agent Force to govern human, NHI, and AI access, June 2026

Identity and access$65M raisedFounded 2020

Manifest

Washington, USA

Series A

SBOM and AIBOM intelligence so you can actually use the bills of materials you generate.

Raised $15M Series A led by Ensemble VC, April 2025

Software supply chain$23M raisedFounded 2022

Material Security

San Francisco, United States

Series C

Workspace security for Google and Microsoft 365 that assumes the mailbox will get owned and limits the blast.

Published original analysis of the May 2026 Composio Gmail OAuth token breach, June 2026

Email and collaboration$100M+ raisedFounded 2017

MIND

Seattle, United States

Series A

AI-native DLP and insider risk that classifies, then blocks exfil at the endpoint without a policy farm.

Raised $30M Series A seven months after stealth, June 2025

Data security$40M+ raisedFounded 2023

Mindgard

London, United Kingdom

Series A

Attacker-style recon and automated red team for models, agents, IDEs, and the systems around them.

Raised $30M Series A led by Album VC, August 2026

AI security$42M raisedFounded 2022

Mitiga

New York, United States

Series B

Cloud, SaaS, identity, and AI detection and response with a forensic lake built for attacks that never touch an endpoint agent.

Raised $30M Series B led by SYN Ventures, January 2025

Cloud security$82M raisedFounded 2019

NetRise

Austin, USA

Series A

Firmware and binary SBOM that unpacks what vendors actually shipped, not what the datasheet claimed.

Raised $10M Series A, taking total funding to about $25M, April 2025

Software supply chain$25M raisedFounded 2020

Nightfall AI

San Francisco, United States

Series B

AI-native DLP for SaaS, endpoints, browsers, and GenAI prompts that learns from investigations.

Launched Nyx, an autonomous DLP copilot, July 2025

Data security$60M raisedFounded 2018

Noma Security

New York, USA

Series B

AI-SPM, agent access control, red team, and AI-DR in one control plane for homegrown and SaaS agents.

Raised $100M Series B led by Evolution Equity Partners, July 2025

AI security$132M raisedFounded 2023

Obsidian Security

Palo Alto, United States

Series D

SaaS identity and agent governance inside the third-party apps where work actually happens.

Raised $85M Series D at $1.1B valuation, August 2026

Identity and access$204M raisedFounded 2017

Oligo Security

Tel Aviv, Israel

Series B

Application detection and response that watches live code execution and blocks exploits as they run.

Raised $60M, crossing $140M in total funding, August 2026

API and runtime$140M raisedFounded 2022

Opal Security

New York, United States

Series B

Policy-as-code access control plane for employees, service accounts, and AI agents.

Raised $23M and hired a new product bench, June 2026

Identity and access$59M raisedFounded 2020

Orca Security

Portland, United States

Series C

Agentless CNAPP that SideScans cloud disks and APIs for the full estate without installing a workload agent.

Named a Strong Performer in The Forrester Wave: Cloud Native Application Protection Solutions, Q1 2026

Cloud security$640M raisedFounded 2019

OX Security

New York, USA

Series B

Prompt-to-runtime AppSec that tries to show only the 5 percent of findings that can actually breach you.

Raised $60M Series B led by DTCP, taking total funding to $94M, May 2025

Application security$94M raisedFounded 2021

P0 Security

San Francisco, United States

Series A

Cloud IGA and PAM that answers who or what can touch production, then enforces it at runtime.

Closed $15M Series A led by SYN Ventures, September 2024

Identity and access$20M raisedFounded 2022

Pentera

Burlington, USA

Series D

Automated security validation that actually exploits attack paths inside the customer's network.

Raised $60M Series D led by Evolution Equity Partners, March 2025

Offensive and exposure$250M raisedFounded 2015

Picus Security

San Francisco, USA

Series C

Breach-and-attack simulation plus autonomous pentest that scores whether controls actually stop the attack.

Raised $45M Series C to lead adversarial exposure validation, September 2024

Pillar Security

Miami, USA

Seed

Inventory, agentic red team, and self-improving runtime guardrails for the agent lifecycle.

Named a 2026 Gartner Cool Vendor in AI Software Security

AI security$9M raisedFounded 2023

Pixee

Baltimore, USA

Seed

Agentic AppSec that triages scanner noise and opens mergeable fix PRs in your house style.

Raised $15M seed led by Decibel and Wing VC, May 2025

Application security$15M raisedFounded 2022

Privacera

Newark, United States

Series B

Fine-grained data access and AI governance from the team that built Apache Ranger.

Shipped major PAIG updates aligned to the NIST AI RMF, February 2025

Data security$63.5M raisedFounded 2016

Prophet Security

Menlo Park, USA

Series A

Agentic SOC platform covering investigation, hunting, and detection engineering in one mesh.

Raised $30M Series A led by Accel, July 2025

Detection and response$41M raisedFounded 2023

Push Security

Boston, United States

Series B

Browser-native ITDR that stops phishing, token theft, and account takeover where the session lives.

Raised $30M Series B led by Redpoint Ventures, April 2025

Identity and access$49M raisedFounded 2019

Qevlar AI

Paris, France

Series A

European agentic SOC that turns every alert investigation into posture insight.

Raised $30M co-led by Partech and Forgepoint Capital International, March 2026

Detection and response$45M raisedFounded 2023

RAD Security

San Francisco, United States

Series A

Behavioral runtime CDR for Kubernetes and AI workloads, fingerprinting what a cluster should do so zero-days show up as drift.

Raised $14M Series A, February 2025

Cloud security$20M raisedFounded 2021

Reco

New York, United States

Series B

SaaS and agent security that maps every app, identity, and AI connector, then remediates the risky ones.

Raised $30M Series B, total funding $85M, February 2026

Email and collaboration$85M raisedFounded 2020

Red Sift

London, United Kingdom

Series B

Email authentication and brand protection that gets domains to DMARC enforcement without a DNS circus.

Won a 2025 Cybersecurity Excellence Award for OnDMARC, March 2025

Email and collaboration$70M raisedFounded 2015

Relyance AI

San Francisco, United States

Series B

Data-flow DSPM that shows how customer data actually moves through products, vendors, and AI features.

Raised $32.1M Series B led by Thomvest Ventures, October 2024

Data security$50M+ raisedFounded 2020

Runlayer

New York, USA

Seed

MCP gateway plus identity, observability, and threat detection for enterprise agents.

Emerged from stealth with $11M seed from Khosla (Keith Rabois) and Felicis, November 2025

AI security$11M raisedFounded 2025

SAFE

Palo Alto, USA

Series C

Cyber risk quantification platform that added an agentic CTEM loop on top of CRQ and TPRM.

Raised $70M Series C and launched a fully autonomous CTEM offering, July 2025

Offensive and exposure$170M raisedFounded 2012

Salt Security

Palo Alto, United States

Series D

Runtime API security that discovers shadow and zombie APIs, then spots business-logic abuse in live traffic.

Published a year of monthly API and AI security releases, December 2025

API and runtime$281M raisedFounded 2016

Seal Security

Tel Aviv, Israel

Series A

Backports security patches onto the exact open-source versions you already run, including EOL.

Raised $13M Series A led by Vertex Israel, July 2025

Software supply chain$20M raisedFounded 2022

Semgrep

San Francisco, USA

Series D

Rules-plus-AI SAST, SCA, and secrets that developers run in seconds and AppSec can actually tune.

Raised $100M Series D led by Menlo Ventures, February 2025

Application security$204M raisedFounded 2017

Semperis

Hoboken, United States

Growth

Identity threat detection and forest recovery for Active Directory, Entra ID, and Okta.

Secured $125M growth financing at a $1B+ valuation, June 2024

Identity and access$325M raisedFounded 2013

Sentra

New York, United States

Series B

Cloud-native DSPM that discovers, classifies, and readies enterprise data for AI without agents.

Closed $50M Series B, bringing total funding over $100M, April 2025

Data security$100M+ raisedFounded 2021

Silverfort

Plano, United States

Series D

Runtime identity protection that puts MFA and least privilege on systems IAM vendors leave naked.

Acquired Fabrix Security for autonomous runtime identity security, April 2026

Identity and access$222M raisedFounded 2016

Simbian

Mountain View, USA

Seed

Self-improving AI SOC that unifies defense, hunting, and offense on one agent family.

Named to the CB Insights AI 100, May 2026, after 15x customer growth in 2025

Detection and response$10.5M raisedFounded 2023

SixMap

Columbia, USA

Series A

Internet-scale IPv4/IPv6 discovery that maps what an attacker can actually see of you.

Launched new product capabilities for AI-driven attack-surface change, December 2025

Offensive and exposure$24M raisedFounded 2020

Skyhawk Security

Tel Aviv, Israel

Series A

AI purple team that replays CNAPP and SIEM findings against a digital twin to prove which cloud CVEs are actually weaponizable.

Named a CRN 2025 Stellar Startup for the third consecutive year, November 2025

Cloud security$35M raisedFounded 2022

Smallstep

San Francisco, United States

Series A

Private CA and device identity so internal TLS, SSH, and laptops get short-lived certificates instead of passwords.

Published hardware-bound device identity essay, May 2026

Secrets and non-human identity$26M raisedFounded 2016

Snyk

Boston, USA

Series G

Developer-first SAST, SCA, container, and IaC platform now wrapping AI agents and models too.

Launched Evo Agentic Development Security to govern coding agents, June 2026

Socket

San Francisco, USA

Series C

Behavioral SCA that blocks malicious packages at install time, before a CVE exists.

Raised $60M Series C at a $1B valuation led by Thrive Capital, May 2026

Software supply chain$125M raisedFounded 2022

Sonrai Security

New York, United States

Series C

Cloud permissions firewall that enforces least privilege on humans, machines, and AI identities using native AWS, Azure, and GCP controls.

Reported 4x ARR growth as Cloud Permissions Firewall adoption surged, January 2026

Cloud security$89M raisedFounded 2017

StackHawk

Denver, United States

Series B

Developer-first API DAST that runs in CI so AI-generated endpoints get tested before they ship.

Raised $12M strategic round from Sapphire and Costanoa, total $47.3M, May 2025

API and runtime$47.3M raisedFounded 2019

Straiker

Mountain View, USA

Series A

Discover, adversarially test, and kill-switch AI agents and MCP connections in production.

Raised $64M Series A, taking total funding to $85M, June 2026

AI security$85M raisedFounded 2025

Stream Security

Tel Aviv, Israel

Series B

Cloud detection and response on a live CloudTwin of every workload, identity, and network path.

Raised $30M Series B, October 2024

Cloud security$55M raisedFounded 2020

Sublime Security

Washington, United States

Series C

Agentic email security with open detection rules and AI that writes new coverage in hours.

Raised $150M Series C led by Georgian, October 2025

Email and collaboration$244M raisedFounded 2019

Sweet Security

Tel Aviv, Israel

Series B

Runtime CNAPP that watches cloud and AI agents as they act, then turns the finding into a guardrail.

Raised $75M Series B, November 2025

Cloud security$120M raisedFounded 2023

Sysdig

San Francisco, United States

Series G

Runtime CNAPP built on kernel-level system calls, Falco detections, and AI agents that act inside the tools you already run.

Named a Leader in The Forrester Wave: Cloud Native Application Protection Solutions, Q1 2026

Cloud security$744M raisedFounded 2013

Tamnoon

Sammamish, United States

Series A

Human-plus-AI cloud remediation that closes CNAPP findings without breaking the workload that owns them.

Raised $12M Series A, September 2024

Cloud security$17M raisedFounded 2022

Teleport

Oakland, United States

Series C

Infrastructure identity for SSH, Kubernetes, databases, and MCP servers without standing secrets.

Launched Beams trusted runtimes for AI agents, March 2026

Identity and access$169M raisedFounded 2015

Teleskope

New York, United States

Series A

Agentic data security that classifies with business context and remediates without a ticket queue.

Raised $25M Series A led by M13, total funding $32.2M, November 2025

Data security$32.2M raisedFounded 2022

TENEX.AI

Sarasota, USA

Series B

AI-native MDR that triages every alert in under a minute, with humans on the loop.

Raised $250M Series B led by Crosspoint, March 2026

Detection and response$277M raisedFounded 2024

Terra Security

Tel Aviv, Israel

Seed

Agentic pentest platform with a human in the loop across web, API, network, and AI surfaces.

Raised $8M (Q2 2025) to scale agentic continuous pentesting

Offensive and exposure$8M raisedFounded 2024

ThreatLocker

Orlando, USA

Series F

Default-deny allowlisting that stops unapproved software and AI agents from running at all.

Raised $190M Series F led by Elephant, July 2026

Endpoint and browser$480M raisedFounded 2017

Tigera

San Francisco, United States

Series B

Calico-powered Kubernetes network security and microsegmentation, plus Lynx for governing AI agent calls on the cluster.

Shipped the Winter 2026 Calico Cloud release with an AI assistant and multi-cluster traffic observability, March 2026

Cloud security$65M raisedFounded 2016

Tines

Dublin, Ireland

Series C

Workflow automation that security teams actually own, now with agentic AI on top.

Raised $125M Series C at a $1.13B valuation, February 2025

Detection and response$271M raisedFounded 2018

Token Security

Tel Aviv, Israel

Series A

Machine-first identity security that finds every NHI, names an owner, and cuts leftover privilege.

Named to Rising in Cyber 2026 after a $20M Series A, May 2026

Secrets and non-human identity$27M raisedFounded 2023

Torq

Tel Aviv, Israel

Series D

Hyperautomation platform turning SOAR playbooks into an agentic SOC.

Raised $140M Series D at a $1.2B valuation, January 2026

Detection and response$332M raisedFounded 2020

Truffle Security

San Francisco, United States

Series B

Verified secret scanning that proves a leaked key still works, then helps you kill it.

Raised $25M Series B led by Intel Capital and a16z, November 2025

Secrets and non-human identity$40M+ raisedFounded 2021

Unosecur

Berlin, Germany

Seed

Agentless identity fabric for human, machine, and AI identities across hybrid cloud and on-prem.

Raised $5M seed led by VentureFriends and DFF Ventures, April 2025

Identity and access$5M raisedFounded 2021

Upwind

San Francisco, United States

Series B

Runtime-first CNAPP that ranks cloud risk from what is actually running, not from a static CVE dump.

Raised $250M Series B at a $1.5B valuation, January 2026

Cloud security$430M raisedFounded 2022

Veza

Los Gatos, United States

Series D

Access graph that shows what every identity can actually do, not just which group it sits in.

Raised $108M Series D at $808M valuation, April 2025

Identity and access$235M raisedFounded 2020

Vicarius

New York, USA

Series B

Vulnerability remediation that actually patches, not another scanner that files tickets.

Named in Forrester's Q1 2026 Proactive Security Platforms Landscape

Endpoint and browser$60M raisedFounded 2016

Vijil

Menlo Park, USA

Series A

Continuous trust tests so enterprise agents stay reliable after they leave the lab.

Raised $17M Series A led by BrightMind Partners, November 2025

AI security$23M raisedFounded 2024

Wallarm

San Francisco, United States

Series C

Inline API and agent security that blocks abuse in real time instead of paging after the request lands.

Raised $55M Series C led by Toba Capital, July 2025

API and runtime$75M raisedFounded 2013

WitnessAI

Mountain View, USA

Series B

Observe, control, and protect employees, models, apps, and agents from one AI security plane.

Raised $58M led by Sound Ventures, January 2026

AI security$86M raisedFounded 2023

WorkOS

San Francisco, United States

Series C

Enterprise identity APIs so product companies can ship SSO, SCIM, and audit without becoming an IAM vendor.

Raised $100M Series C at $2B valuation, March 2026

XM Cyber

Tel Aviv, Israel

Series B

Hybrid attack-path graph that shows how an identity, cloud, or on-prem foothold becomes a breach.

Named a Challenger in the first Gartner Magic Quadrant for Exposure Assessment Platforms, 2025

Offensive and exposure$49M raisedFounded 2016

Xygeni

Pamplona, Spain

Seed

SCA plus malware and pipeline security for teams whose code is increasingly written by agents.

Won Global Infosec awards for ASPM and GenAI application security, 2026

Software supply chain$4M raisedFounded 2021

Zafran

New York, USA

Series C

CTEM that proves which CVEs are exploitable, then mitigates with the controls you already own.

Raised $60M Series C led by Menlo Ventures, December 2025

Offensive and exposure$130M raisedFounded 2022

Zenity

New York, USA

Series C

Agent security that watches the decision, not just the prompt, across SaaS, cloud, and endpoint.

Raised $125M Series C led by Norwest, August 2026

AI security$185M raisedFounded 2021

ZeroPath

San Francisco, USA

Seed

AI-native SAST for business logic, auth bypasses, and chained exploit paths, with generated patches.

Named an RSAC 2026 Innovation Sandbox Top 10 finalist