Dossier · Private startup · 3 independent sources

AIR Security

Cybersecurity Dual-Use Technology Priority Signal

Last updated: Sep 2, 2026

AIR Security is an Israeli cybersecurity startup building a context firewall for enterprise AI agents. Its platform discovers agent fleets, continuously vets skills, plugins, MCP servers and other add-ons, and filters malicious or untrusted content before it can influence an agent's decisions or actions.

Visit Website

Company Overview

**Product and the concrete problem it solves.** AIR Security targets a security gap created by the way enterprise AI agents are assembled. An agent is no longer only a model behind a chat interface: it can load reusable Skills, plugins, Model Context Protocol (MCP) servers, sub-agents, hooks and external instructions, then browse websites, read internal files, query databases and act through enterprise systems. Those additions behave like an application and software supply chain, but they are often installed from registries, repositories or individual configurations without the signing, ownership checks and lifecycle monitoring expected for conventional software. AIR's answer is a context firewall that sits between an agent and the outside world. Its thesis is that filtering malicious instructions, untrusted information and compromised tools before they enter the agent's context can prevent attacks earlier than a control that only watches the agent after it has already reasoned over poisoned input. The public product is organized into AIR Control for discovering and governing sanctioned and shadow agents, AIR Filter for continuously vetting add-ons, AIR Defend for real-time action protection, and AIR Marketplace for providing pre-vetted external and certified internal add-ons.

**Core technology and how it actually works.** AIR's public architecture is a policy and analysis layer around an agent fleet rather than a new foundation model. The company says it continuously analyzes inputs to an agent's context, including Skills, MCPs, plugins, websites and internal data, and vets add-ons before deployment, after updates and while they are running. In the enforcement path, AIR can discover agents across the environment, identify unapproved personal or shadow AI use, intercept actions such as loading a Skill or fetching content from the internet, and apply allow or block decisions against a maintained set of evaluated tools and add-ons. The proposed mechanism matters because an already-approved dependency can become risky when its downloaded package changes, its developer account is compromised, or a service endpoint changes ownership. AIR's research describes MCP hijacking through expired domains: a still-listed endpoint can be reclaimed and then return instructions to an agent that trusts the original registry entry. AIR Filter is intended to monitor exactly this kind of drift, while AIR Defend handles runtime actions and AIR Marketplace creates a controlled distribution path. The public material does not disclose a proprietary model architecture, formal detection benchmarks, or the exact mix of static analysis, dynamic execution, behavioral testing and human review behind its risk decisions; those are important technical diligence questions.

**Market, customers, and go-to-market.** The initial buyer is an enterprise security organization responsible for AI governance, application security, data protection and identity or access controls. AIR can enter through an urgent visibility problem, such as discovering agents and MCP servers that employees adopted outside IT approval, then expand into pre-deployment add-on review, continuous supply-chain monitoring and runtime policy enforcement. The company says it has more than 20 customers, with roughly one quarter described by its CEO as large enterprises, and that demand has been strongest in heavily regulated financial-services and pharmaceutical organizations. These are company-reported figures, not audited revenue or retention data. The product's marketplace positioning gives AIR a second go-to-market lever: instead of telling developers to stop using agent extensions, it can offer a safer approved source for them. Its public ScanAir scanner and research publications also act as technical marketing and developer adoption channels by turning new attack patterns into a concrete evaluation tool. An official company update says AIR became available as a deployed-on-AWS offering in AWS Marketplace, which can reduce procurement friction for AWS customers, although the public record does not establish the depth of that integration or the number of deployments through it. The likely expansion path is from agent inventory and add-on scanning into policy, runtime defense and enterprise-wide marketplace control.

**Traction, funding, and third-party validation.** AIR emerged from stealth on September 1, 2026 with $50 million raised across two seed rounds, according to TechCrunch: a $10 million round led by Sequoia Capital and a $40 million round led by Greenoaks, with participation from Swish, Netz and named angels including Zach Frankel of Cognition, Yinon Costica of Wiz, Ofir Ehrlich of Eon, Anne Neuberger, Omer Adam and Varun Anand of Clay. Calcalist separately reports the $50 million financing and says AIR had 40 employees in Israel at launch; LinkedIn lists the company in Tel Aviv with an 11-50 employee range. The Sequoia investment memo provides unusually specific third-party validation of the founding team's prior work: before AIR, they built MOAK, an agentic workflow that produced working exploits for newly published vulnerabilities, including a demonstration that exploited a React vulnerability in 21 minutes versus roughly six days for a typical enterprise patch rollout. AIR's own research adds attack-surface evidence rather than product revenue evidence. Its public studies report more than 17,800 AI add-ons representing approximately 6.7 million installations that relied on untrusted external sources, and a separate MCPJacking study reports 155 hijackable MCP entries. TechCrunch reports AIR's claim that its current evaluation process filters about 27% of add-ons and Skills it finds online. These signals show strong investor, research and early-customer momentum, but no public source reviewed here discloses ARR, gross margin, renewal rates, customer names, independent efficacy testing or a formal certification.

**Founders and team background.** AIR was founded in February 2026 by Yair Saban, CEO, and Niv Hoffman, CTO. Calcalist says the founders met about a decade earlier in the military and came from offensive cybersecurity, enterprise infrastructure and AI-security research. Sequoia's account is more specific: Hoffman led a major Unit 8200 vulnerability-research department and built a network of technical talent, while references from former Israeli intelligence commanders gave unusually strong endorsements of Saban's leadership potential. Their pre-AIR project, MOAK, is strategically relevant because it was designed to show how quickly an AI-enabled attacker can turn a newly disclosed vulnerability into an actionable exploit. That offensive-to-defensive progression gives AIR a credible understanding of how agentic systems can be manipulated, although it does not by itself prove that the company's defensive product catches real attacks at enterprise scale. The broader team includes security practitioners and researchers, and Calcalist reports that Ryan Knisley joined as chief strategy officer after serving as chief information security officer at The Walt Disney Company and Costco Wholesale. AIR's public LinkedIn page identifies a Tel Aviv headquarters and shows named employees, but the company has not published a complete leadership roster, engineering composition, advisory structure or detailed biographies for the full 40-person Israeli team. Team quality is therefore a strong positive signal, while organizational depth and the ability to support regulated deployments remain open diligence items.

**Competitive dynamics.** AIR is entering a fast-forming market with several overlapping control points. Noma Security offers agent discovery, access controls and runtime monitoring across agents, MCP servers and Skills; Zenity combines AI security posture management and governance; Astrix Security approaches agents and MCP servers through identity and non-human access management; Operant AI offers runtime agent protection and an MCP gateway; Protect AI applies software-supply-chain and machine-learning security methods to AI systems; and Pillar Security focuses on testing and protecting generative-AI applications. Large cloud, endpoint, identity and application-security vendors can also bundle partial controls into existing contracts. AIR's claimed edge is not simply asset discovery, which its CEO acknowledges is relatively easy to reproduce. The more ambitious moat is continuous vetting of the external add-on ecosystem: keeping track of changing repositories, domains, downloaded packages, instructions and behavior, then converting that evaluation into a trusted marketplace and enforceable policy. The public research program may help AIR accumulate threat intelligence and credibility at the moment the category is being defined. The risk is that a marketplace and scanning corpus become features of a broader platform, while competitors with deeper enterprise distribution win the control-plane budget. AIR must prove lower false positives, faster discovery of novel supply-chain compromise and better operational outcomes than point tools or bundled security suites.

**Defense, security, and resilience dual-use relevance.** AIR's core technology has credible dual-use relevance because software supply-chain compromise, untrusted instructions, excessive agent permissions and data exfiltration are not limited to commercial enterprises. Defense contractors, intelligence organizations, critical-infrastructure operators and public agencies are likely to deploy AI agents for software development, logistics, intelligence analysis, knowledge retrieval, maintenance and administrative workflows. In those settings, a capability that inventories hidden agents, evaluates the tools they load, filters external context and records or blocks consequential actions could reduce a pathway from a compromised add-on to sensitive data access or mission disruption. The company's Israeli Unit 8200 provenance and offensive-security research background also make the national-security adjacency technically credible. However, the evidence must be calibrated: the sources reviewed do not establish an AIR defense contract, classified deployment, government program, air-gapped product, public-sector certification or use in an operational mission. The public internet-facing research and enterprise SaaS posture should not be mistaken for a hardened defense deployment. AIR's dual-use case is therefore a strong security and resilience adjacency in the control layer for AI infrastructure, not demonstrated fielded defense capability. Diligence should test offline or sovereign deployment, tenant isolation, evidence retention, identity integration, supply-chain provenance, human approval controls and performance when communications or upstream services are degraded.

**Growth stage, trajectory, and key diligence risks.** AIR is classified as early despite its unusually large capitalization: it was incorporated in February 2026, emerged from stealth roughly six months later, and has public evidence of early customers and a 40-person Israeli team but no disclosed revenue, retention or long-term deployment metrics. The trajectory is potentially important. If enterprises move from pilots to agents that can change code, access sensitive records or operate business processes, the context around an agent may become a new security control plane, and AIR could expand from a scanner into the approval, monitoring and revocation layer for the agent fleet. The principal risks are (1) category risk, because buyers may consolidate agent security into existing cloud, identity or endpoint platforms; (2) efficacy risk, because false negatives in malicious Skills and false positives that block legitimate work both have serious consequences; (3) ecosystem risk, because millions of changing repositories, domains and add-ons are expensive to evaluate continuously; (4) architecture risk, because runtime interception can add latency, availability dependencies and policy complexity to critical workflows; (5) evidence risk, because the strongest attack-surface statistics are company-produced and public customer metrics are limited; (6) compliance risk, because regulated and government buyers will demand isolation, auditability and data-governance controls; and (7) execution risk, because a very large seed round creates pressure to scale research, product, sales and customer support before the category's procurement standards are settled. The milestones to watch are independently validated detection and prevention results, retention and expansion across the reported customer base, named regulated deployments, the depth of AWS Marketplace adoption, formal security attestations, and any verified defense or critical-infrastructure evaluation.

Dual-Use Assessment

Military & Commercial Applications

AIR's core control layer has substantive commercial and defense or resilience applicability because both environments increasingly depend on AI agents that can load external tools, consume untrusted context and act across sensitive systems. Its agent discovery, continuous add-on vetting, context filtering, runtime action controls and revocation workflow could help defense contractors, intelligence organizations, critical-infrastructure operators and regulated enterprises reduce AI supply-chain compromise and data-exfiltration risk. The technical transfer is credible, but public evidence does not establish a defense contract, classified deployment, government certification, air-gapped operation or operational mission use. This is a high-value AI-security and resilience adjacency rather than demonstrated fielded defense capability, so diligence should focus on sovereign deployment, tenant isolation, auditability, identity integration and degraded-connectivity behavior.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

AIR merits a strong internal priority signal because it combines a sharply timed AI-infrastructure security problem with an unusually credible founding team and substantial early validation. (1) The company has raised $50 million across two seed rounds led by Sequoia and Greenoaks within months of its February 2026 founding, while reporting more than 20 customers and a 40-person Israeli team. (2) Its pre-runtime context-firewall thesis addresses a gap that conventional identity and runtime controls may miss: an agent can be manipulated by a Skill, MCP server, website or internal document before it performs the final action. (3) The founders' MOAK research and AIR's public MCPJacking and add-on studies demonstrate threat-model fluency and create a useful research-to-product loop. The counterweights are equally important: revenue, retention, customer names, independent detection efficacy and formal assurance are undisclosed; the category is crowded; continuous vetting at internet scale may be expensive; and large security or cloud platforms can bundle partial substitutes. This flag is a strategic diligence priority, not an investment recommendation.

Strategic Value to U.S.-Israel Alliance

AIR's strategic value is concentrated in the control plane around AI agents, a layer that is becoming important as enterprises allow models to read sensitive data and invoke tools with real permissions. (1) It can provide visibility into an agent fleet that otherwise fragments across AI platforms, code repositories, MCP registries and employee configurations. (2) Its pre-runtime filtering thesis aims to stop harmful context before an agent reasons over it, complementing identity, endpoint, application and runtime controls. (3) Continuous monitoring of add-on ownership and behavior is directly relevant to software-supply-chain resilience, including the expired-domain and service-hijacking failure mode described in AIR's MCPJacking research. (4) The same mechanisms could support high-assurance AI adoption in defense, government and critical infrastructure, but only after proving isolated deployment, strong audit evidence and reliable policy enforcement. AIR's strategic importance is therefore high as an enabling security layer, while its public-sector maturity remains unverified.

Key Technologies

  • Pre-runtime context firewall that analyzes and filters content before it reaches an AI agent
  • Continuous security vetting of Skills, plugins, MCP servers, sub-agents and other agent add-ons
  • Agent-fleet discovery covering sanctioned and shadow agents, configurations, identities and permissions
  • Runtime interception and policy enforcement for agent actions, tool loading and external content retrieval
  • MCP and AI add-on supply-chain monitoring for expired domains, hijacked services, malicious instructions and behavioral drift
  • Pre-vetted AI add-on marketplace with governance, approval, monitoring and organization-wide revocation

Use Cases & Applications

  • Discovering shadow AI agents, MCP servers and personal AI accounts operating outside enterprise approval
  • Screening open-source Skills, plugins and sub-agents before they are installed into coding or business workflows
  • Continuously re-evaluating approved add-ons after repository, domain, package or maintainer changes
  • Blocking prompt injection, untrusted external instructions and malicious content from entering agent context
  • Monitoring and stopping unauthorized agent actions, data access and attempted exfiltration at runtime
  • Providing regulated financial-services and pharmaceutical organizations with governed AI-agent deployment paths
  • Hardening defense-contractor, government and critical-infrastructure AI workflows against software-supply-chain compromise, subject to deployment validation
  • Offering a trusted internal marketplace for approved external and organization-built agent extensions

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.

This record lists 7 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Investor Lens

What this entry is

Private startup

Why it may matter

AIR Security may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.

How an independent investor should read this

Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.

Evidence to verify

  • Verify current status
  • Verify traction
  • Verify cap table/funding
  • Verify technical claims
  • Verify regulatory/export-control issues
  • Verify customer concentration

Main investor questions

  • Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
  • What customer, revenue, product, and technical evidence supports the company story?
  • What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
  • Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
  • What evidence would change the thesis or show that the profile is stale?

What not to infer

  • Inclusion does not imply endorsement.
  • Inclusion does not imply allocation availability or current fundraising.
  • Scores do not indicate investment suitability or expected returns.
  • Strategic importance does not automatically imply venture return potential.

Diligence questions

  • What evidence verifies AIR Security's current customer traction, deployment status, and revenue concentration?
  • Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
  • Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
  • How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
  • What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.

Need a diligence readout?

Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.