Dossier · Private startup · 5 independent sources

Arrakis Security

Cybersecurity Dual-Use Technology Priority Signal Founded 2025

Last updated: Aug 31, 2026

Arrakis Security is an Israeli cybersecurity startup building a behavioral-governance layer for autonomous AI agents. Its platform discovers agent activity, profiles expected behavior, enforces policies before and during tool use, and provides real-time detection and response across enterprise SaaS, cloud, and workflow environments.

Visit Website

Company Overview

**Product and the concrete problem it solves.** Arrakis Security addresses the gap between an enterprise knowing that an AI agent exists and knowing what that agent is actually doing. Traditional identity, endpoint, and application-security controls are designed around human users, deterministic software, or static permissions. An autonomous agent can instead chain tool calls, query internal systems, change records, send data, invoke another agent, or adapt its behavior to new context without a person approving each intermediate step. That creates a practical visibility problem: a security team may see that an agent is connected to Salesforce, GitHub, an internal API, or an automation platform, but not whether it is using the intended resources, following the intended workflow, or crossing a dangerous boundary. Arrakis calls this the **visibility illusion**. Its product treats the agent, its workflow, and the surrounding SaaS graph as a security object, with the goal of making autonomous software observable and controllable without requiring organizations to abandon useful automation.

**Core technology and how it works.** The platform is presented as a three-stage architecture. First, Arrakis discovers and inventories agents across SaaS, cloud, and endpoint environments, tracks ownership, and builds a behavioral baseline for each non-human actor. Second, its AI Security Posture Management layer applies pre-execution controls, including static analysis, Model Context Protocol gateway enforcement, allow-lists, data-loss-prevention rules, and correlation with vulnerability frameworks such as OWASP, NIST, and MITRE ATLAS. Third, its AI Detection and Response layer treats agent outputs as untrusted and compares live activity with the expected profile, looking for anomalous intent, privilege abuse, data exfiltration, cross-agent contagion, and other deviations. The company says customers can connect through a Python or TypeScript SDK or a transparent HTTP proxy, with no need to fork agent code or replace the underlying model provider. The proxy and SDK model is technically important because it gives Arrakis a chance to observe tool calls and resource accesses at runtime while leaving model choice and application architecture intact. Public material does not establish independent accuracy, latency, false-positive, or coverage benchmarks, so these claims remain product assertions that require customer validation.

**Market, customers, and go-to-market.** Arrakis is selling into the rapidly forming market for AI-agent security, but its wedge is narrower and more operational than generic responsible-AI governance. Its buyers are likely to include CISOs, security-operations leaders, platform-engineering teams, AI program owners, and compliance managers who must permit agents to act inside business systems while preserving least privilege and an audit trail. The initial target environments are enterprises using a mix of SaaS automation, coding agents, no-code platforms, internal copilots, and custom agent frameworks. Arrakis explicitly names environments such as Workday, Salesforce, Make, n8n, Copilot Studio, Claude, GitHub, Cursor, and other agentic systems as examples of where autonomous behavior is accumulating. The go-to-market motion appears to start with a fast instrumentation assessment that inventories unknown agents and surfaces policy violations, then expands into continuous monitoring, gateway enforcement, red teaming, and response. The company says it has early enterprise customers and design partners, but it has not publicly named those customers, disclosed contract values, or reported recurring revenue, retention, or conversion rates. That makes the product's enterprise relevance credible but its repeatability and sales efficiency unproven.

**Traction, funding, and third-party validation.** Arrakis emerged from stealth on August 2, 2026 with an $8 million Seed round led by Hetz Ventures. The official announcement identifies participation from ElevenLabs CEO Mati Staniszewski, Torq CEO Ofer Smadari, Pentera founder Amitai Ratzon, and senior Palantir executives. Hetz's portfolio page independently describes the company's three-stage approach: discovery and behavioral baselines, pre-execution controls through an MCP gateway, and real-time monitoring of agent outputs and cross-agent behavior. The official launch post says Arrakis has a 20-person team, is expanding R&D and product teams in Israel, and is using the financing to strengthen detection and response and accelerate deployments. Geektime reported a concrete early proof point from a customer evaluation: after connection, the platform mapped more than 1,000 active AI agents in under an hour, most previously unknown to the security team, and identified dozens of policy violations and critical exposures during the proof of concept. That is a company-reported result rather than a published independent benchmark, but it is more informative than a logo wall because it tests the discovery problem at the heart of the thesis. There is no public evidence yet of a later financing round, audited revenue, government contract, security certification, or independently reproducible efficacy study.

**Founders and team background.** Arrakis was founded by Tal Baron, Omer Efrat, and Ron Shani, with the company and investor materials describing the group as veterans of Torq and Palantir. Baron is CEO, Efrat is CPO, and Shani is CTO. Their prior experience is unusually relevant to the problem: Torq worked on enterprise security automation, while Palantir exposed the founders to large-scale data infrastructure, complex workflows, and high-consequence deployments where system behavior must be explainable and controllable. The founders say they saw the gap while building automation and AI-security systems for large organizations, and Shani has described work on a large energy-company project that connected millions of sensors in real time and required attention to model reliability and operational safety. Arrakis Labs adds a research dimension, with the company describing personnel from Microsoft security research and elite military-technology backgrounds who study agent-specific threats and feed new patterns into product controls. The launch announcement gives a total team size of 20, which is substantial for a company founded in late 2025 but still small relative to the breadth of agent frameworks, integrations, threat research, and enterprise support it is attempting to cover. Specific employee counts by function, founders' military units, customer references, and retention data are not publicly confirmed and should not be inferred.

**Competitive dynamics.** Arrakis competes in a crowded and rapidly converging category where the control point is still unsettled. **Zenity** (Israeli AI-security platform spanning low-code applications, agents, posture, and runtime controls) has greater disclosed funding and broader enterprise history. **Willow** (Israeli agentic access platform focused on identities, scoped permissions, tool governance, and human-attributed audit trails) competes for the same CISO and AI-platform budgets from the access-control side. **Prompt Security** (Israeli AI-security gateway for employee use, applications, coding assistants, and agents) overlaps in inspection and policy enforcement. **Koi Security** (acquired Israeli endpoint platform governing AI agents, MCP servers, extensions, and software supply-chain risk) attacks the endpoint and agent perimeter. **Microsoft Entra, Defender, and Copilot controls** (bundled identity, endpoint, and AI governance from the incumbent productivity stack) are the most important distribution threat. **Okta** (identity and access incumbent extending toward non-human identities and agent governance) can own the authorization layer. **Palo Alto Networks Prisma AIRS and Cortex** (security-platform approach combining AI application controls with endpoint and SOC distribution) can bundle monitoring and response. Arrakis's claimed edge is the behavioral layer: it seeks to understand what a permitted agent does at runtime, not only whether the agent has access. That edge becomes durable only if its behavioral baselines, attack research, policy data, and integrations produce better decisions than bundled controls without introducing unacceptable blocking or analyst workload.

**Defense, security, and resilience relevance.** Arrakis has direct dual-use relevance because autonomous software is becoming part of the digital infrastructure of defense contractors, government agencies, utilities, hospitals, financial institutions, and emergency-response organizations. In a high-assurance environment, an agent that can read sensitive material, write to operational systems, or invoke tools with inherited credentials is a non-human insider whose behavior must be attributable, bounded, and interruptible. Discovery can reveal unauthorized or forgotten agents in a mission-support environment; behavioral profiles can identify drift from an approved workflow; MCP gateway controls can restrict tool servers and data paths; and a runtime kill switch or policy block can stop a dangerous action before it propagates. These capabilities could support secure coding agents in defense supply chains, intelligence-analysis workflows, critical-infrastructure operations, cyber-defense automation, and logistics planning while preserving human authority over consequential actions. The connection is defensive and infrastructural, not a claim that Arrakis supplies weapons autonomy or has fielded a military system. No public source reviewed establishes a defense customer, classified deployment, government accreditation, FedRAMP authorization, or operation on disconnected tactical networks. Its strategic relevance is therefore credible at the control-plane layer but still an adjacency until high-assurance deployments are documented.

**Growth stage, trajectory, and key diligence risks.** Arrakis is classified as **early**: the company was incorporated in Israel on December 31, 2025 according to a public company registry, emerged from stealth less than a year later, raised a first $8 million Seed round, and publicly reports a 20-person team. It has a live product architecture, early enterprise proof-of-concept evidence, and a research publication stream, so it is beyond an idea or purely pre-product phase. The trajectory depends on whether autonomous agents become a durable enterprise operating layer and whether security buyers accept a dedicated behavioral-control product instead of waiting for identity, cloud, endpoint, or AI-platform vendors to bundle it. Key diligence points are: (1) independently verify the 1,000-agent discovery result and measure precision, recall, latency, and deployment effort; (2) determine whether anomaly detection can distinguish legitimate workflow changes from attacks without blocking useful automation; (3) test coverage across custom agents, no-code platforms, MCP servers, multi-agent chains, and browser or coding workflows; (4) examine how credentials, tenant isolation, data residency, and policy failure modes behave in self-hosted or restricted environments; (5) establish whether named customers, renewal behavior, and expansion exist beyond founder-network design partners; (6) assess the cost of maintaining threat research and integrations against competitors with larger platforms; and (7) clarify the legal entity, U.S. commercial presence, certification roadmap, and public-sector procurement path. The company is a high-quality strategic watch candidate, but the market is young, the product claims are largely vendor-reported, and the most important moat remains to be proven in production.

Dual-Use Assessment

Military & Commercial Applications

Arrakis's core technology is directly useful for both commercial enterprise security and defensive government, defense-industrial, and critical-infrastructure environments. Its agent discovery, behavioral baselining, policy enforcement, MCP gateway, audit trail, anomaly detection, and response controls address the non-human insider problem created when autonomous software can access sensitive systems and execute workflows without a human approving every intermediate action. That transfer path is credible for secure coding, intelligence-analysis support, cyber-defense automation, logistics, utilities, healthcare, and emergency-response systems. The assessment must remain calibrated: public sources show no named defense customer, classified deployment, government accreditation, or tactical disconnected-network operation. Arrakis is therefore dual-use at the defensive infrastructure layer, with strategic relevance that is promising but not yet demonstrated in a national-security deployment.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

Arrakis is a high-signal but high-uncertainty early-stage company whose main asset is the timing and specificity of its thesis. (1) The underlying problem is real: organizations are deploying software that can reason, call tools, and change systems, while legacy controls still center on human identities and static permissions. (2) The founding team has unusually direct experience in enterprise security automation and large-scale operational data systems through Torq and Palantir. (3) The $8M Hetz-led Seed round and participation from leaders at ElevenLabs, Torq, Pentera, and Palantir provide relevant ecosystem validation rather than generic capital. (4) The reported proof-of-concept discovery of more than 1,000 agents and dozens of policy violations is a concrete signal, though it remains company-reported. (5) The product can occupy a valuable runtime control point if it turns behavioral telemetry into reliable prevention and response. Counterweights are material: identity, endpoint, cloud, and AI-platform incumbents can bundle adjacent capabilities; the category overlaps with several well-funded Israeli startups; the 20-person team must cover research, integrations, product, and enterprise support; customer names and commercial metrics are undisclosed; and no defense deployment or certification is public. This is a strategic diligence assessment, not an investment recommendation.

Strategic Value to U.S.-Israel Alliance

Arrakis's strategic value is concentrated in the control of autonomous software before it becomes an unaccountable operational actor. (1) Sovereign and resilience value: government, defense-industrial, utility, healthcare, and emergency-response operators increasingly need agents that can work with sensitive systems without receiving unrestricted standing authority. (2) Control-plane value: behavioral monitoring and runtime enforcement sit between access permission and actual action, a boundary that is not fully covered by identity or endpoint products. (3) Threat-intelligence value: Arrakis Labs can turn new agent-specific attack research into detection patterns, policy templates, and response logic, although the durability of that feedback loop is unproven. (4) Israeli ecosystem value: the company combines Israeli cyber talent, a Hetz-led financing network, and founders with experience in global enterprise deployments. (5) Allied-technology value: a portable agent-governance layer could support organizations that need model choice, data-residency control, and human accountability across cloud and self-hosted environments. The strategic ceiling depends on production efficacy, high-assurance deployment, and independent customer proof; absent those, Arrakis remains a promising cyber-resilience vendor rather than an established national capability.

Key Technologies

  • Cross-environment AI-agent discovery and inventory across SaaS, cloud, endpoint, and workflow systems
  • Dynamic behavioral baselines for non-human agents, their workflows, owners, permissions, and surrounding SaaS graph
  • Pre-execution AI Security Posture Management with static analysis, MCP gateway enforcement, allow-lists, and data-loss controls
  • Runtime AI Detection and Response using intent-aware anomaly detection and cross-agent contagion tracking
  • Python and TypeScript SDK instrumentation plus transparent HTTP proxy interception of agent tool calls and API requests
  • Granular policy enforcement, action blocking, permission revocation, kill switches, and audit-ready event trails
  • Arrakis Labs threat research mapping prompt injection, tool poisoning, privilege abuse, data exfiltration, and agent-specific attack patterns

Use Cases & Applications

  • Discovering and governing unsanctioned AI agents created in Salesforce, Workday, n8n, Make, or internal automation systems
  • Monitoring coding agents and MCP servers that can read repositories, access credentials, modify infrastructure, or affect software supply chains
  • Enforcing least-privilege tool access and approval boundaries for enterprise agents handling finance, HR, legal, or customer data
  • Detecting prompt injection, tool poisoning, privilege escalation, data exfiltration, or behavioral drift during live agent sessions
  • Providing security operations teams with attributable traces of agent actions, policy decisions, approvals, and blocked events
  • Testing agent resilience through red-team simulations before production deployment and during continuous posture review
  • Securing defense-contractor, government, utility, hospital, and emergency-response AI workflows where autonomous software touches high-consequence systems
  • Containing a rogue or compromised agent through runtime blocking, permission revocation, workflow suspension, or a granular kill switch

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.

This record lists 8 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Investor Lens

What this entry is

Private startup

Why it may matter

Arrakis Security may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.

How an independent investor should read this

Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.

Evidence to verify

  • Verify current status
  • Verify traction
  • Verify cap table/funding
  • Verify technical claims
  • Verify regulatory/export-control issues
  • Verify customer concentration

Main investor questions

  • Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
  • What customer, revenue, product, and technical evidence supports the company story?
  • What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
  • Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
  • What evidence would change the thesis or show that the profile is stale?

What not to infer

  • Inclusion does not imply endorsement.
  • Inclusion does not imply allocation availability or current fundraising.
  • Scores do not indicate investment suitability or expected returns.
  • Strategic importance does not automatically imply venture return potential.

Diligence questions

  • What evidence verifies Arrakis Security's current customer traction, deployment status, and revenue concentration?
  • Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
  • Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
  • How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
  • What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.

Need a diligence readout?

Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.