Dossier · Private startup · 1 independent source
Backslash Security
Last updated: Jul 31, 2026
Backslash Security is an Israeli cybersecurity startup securing the agentic AI fabric on developer and citizen-developer endpoints. Its platform inventories AI agents, MCP servers, skills, plugins, hooks, and related activity, then applies governance, runtime protection, and audit controls.
Visit WebsiteCompany Overview
Backslash Security focuses on a security layer that traditional application-security, endpoint, and network products do not model well: the agentic AI fabric running inside employee workstations. The company describes a platform that continuously discovers AI coding agents, copilots, MCP servers, skills, hooks, plugins, rules, and the models and tools they invoke. It combines inventory and posture scoring with policy controls such as allowlists, blocklists, approval workflows, configuration hardening, and contextual permissions. Its protection layer is intended to detect or block prompt injection, tool poisoning, unsafe scope or privilege use, suspicious agent behavior, and data or source-code exfiltration before an agent's action reaches an external system. The product also records harness-layer events, including MCP communications, agent network access, and file access, for investigation and compliance reporting.
The commercial problem is becoming more concrete as enterprises move from chat assistants to autonomous coding and workforce agents. Claude Code, Cursor, GitHub Copilot, Windsurf, Gemini CLI, OpenAI Codex, and similar tools can read files, execute commands, call APIs, install extensions, and use MCP-connected services. That creates a control problem for CISOs: the organization may need to permit rapid AI adoption while still knowing which tools are present, which identities or permissions they hold, what data they can reach, and whether a workflow is behaving as intended. Backslash's public positioning therefore sits between AI security, endpoint security, developer security, and software-supply-chain governance. The free MCP Server Security Hub and Skills Security Scanner also function as public educational and assessment surfaces, while the enterprise platform is sold around visibility, governance, and real-time protection.
The competitive case is plausible but not yet proven. Backslash differentiates itself by asserting that it observes agent intent and tool activity at the workstation or harness layer, rather than only processes, network traffic, repositories, generated code, or model inputs. That can complement GitHub Advanced Security, Snyk, Semgrep, Apiiro, Wiz, Palo Alto Networks, CrowdStrike, and AI gateway products, but the same adjacency creates buyer and budget ambiguity. Platform vendors can add controls to their own agents and IDEs, while endpoint and identity vendors can extend existing telemetry. Backslash must demonstrate that its cross-agent and cross-endpoint coverage remains materially better than combinations of native controls, EDR, DLP, identity policy, and software-supply-chain tools. The company's public materials identify enterprise users and a growing supported-tool set, but they do not provide independently verified revenue, retention, deployment scale, or customer concentration data.
Commercial momentum is supported by the company's February 2026 announcement of a $19 million Series A led by KOMPAS VC, with Maniv, Artofin Venture Capital, StageOne Ventures, and First Rays Capital participating; the announcement says this followed an $8 million seed round. The same release says funding is intended to expand research and development, deepen the platform, and scale go-to-market in the United States and Europe. LinkedIn currently lists the company in the 11-50 employee range, with a Tel Aviv headquarters and a 2022 founding year. Those are useful maturity signals, but they should not be treated as proof of product-market fit. Relevant diligence includes paid production deployments, endpoint-agent installation and bypass resistance, false-positive rates, support for regulated environments, renewal and expansion behavior, and whether the company can convert public research and assessments into durable enterprise contracts.
The dual-use case is credible but indirect. The core technology protects software-development and knowledge-work endpoints, not weapons or military systems. Nevertheless, defense contractors, government software factories, critical-infrastructure operators, and other mission-critical organizations increasingly face the same risks from autonomous agents, untrusted extensions, data access, and software supply-chain compromise. A platform that can inventory and constrain agentic actions could support secure development environments and contractor governance, subject to deployment, sovereignty, procurement, and classified-environment requirements. There is no public evidence in the reviewed sources of defense contracts or military deployments, so national-security relevance should be treated as an addressable market and diligence hypothesis rather than established traction.
Dual-Use Assessment
Backslash's endpoint and harness-layer controls have substantive applicability to commercial software development, defense contractors, government software factories, and critical infrastructure that use autonomous agents. The dual-use case is security-infrastructure adjacency rather than direct defense technology, and public evidence does not establish military customers or classified deployments.
Strategic Fit Assessment
Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.
Backslash is a credible strategic-priority signal because it targets a fast-forming security control point created by autonomous AI agents and has publicly announced a $19 million Series A after an $8 million seed round. Its product thesis is specific: inventory and govern agentic activity at the endpoint and harness layer, where conventional EDR, DLP, network controls, and code scanning may lack semantic context. The opportunity is supported by rapid enterprise adoption of coding agents and by the need to control shadow AI. The case remains diligence-dependent: the category is immature, platform vendors can bundle adjacent features, and public sources do not establish revenue scale, retention, or defense adoption. This flag is an internal strategic-fit signal, not an investment recommendation.
Strategic Value to U.S.-Israel Alliance
Backslash could provide strategic visibility and control over autonomous software-production activity, including the agents, MCP services, permissions, files, and external tools connected to enterprise endpoints. That is relevant to software supply-chain resilience, AI governance, and secure development in critical industries. Its value for national-security users would depend on endpoint deployment in constrained environments, evidence of low-friction enforcement, procurement readiness, data handling, and support for organizations with strict network or sovereignty requirements.
Key Technologies
- Agentic AI endpoint discovery and inventory
- MCP server, skill, plugin, and hook risk assessment
- Policy enforcement, allowlisting, blocklisting, and approval workflows
- Harness-layer monitoring of prompts, tool calls, file access, and network activity
- Real-time detection and prevention of prompt injection, tool poisoning, and exfiltration
- AI development posture scoring, audit trails, and forensic investigation
Use Cases & Applications
- Discovering shadow AI agents and MCP integrations across developer endpoints
- Governing Claude Code, Cursor, Copilot, Codex, Windsurf, and similar coding agents
- Vetting MCP servers, skills, plugins, and hooks before enterprise installation
- Blocking prompt injection, tool poisoning, excessive permissions, and data exfiltration
- Auditing autonomous agent activity for incident response and AI governance
- Protecting software-factory and contractor development environments in regulated sectors
- Supporting secure adoption of AI-assisted development without banning approved tools
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.
This record lists 5 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- backslash.security Public source used for profile verification.
- backslash.security Public source used for profile verification.
- LinkedIn company page Public source used for profile verification.
- resources.backslash.security Public source used for profile verification.
- backslash.security Public source used for profile verification.
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.