Bonfy.AI
Last updated: Jul 31, 2026
Bonfy.AI develops Bonfy Adaptive Content Security (ACS), an AI-native data security platform that applies business context, entity awareness, and policy enforcement to unstructured content across email, SaaS applications, collaboration tools, copilots, custom AI workflows, and AI agents. Its current product thesis is to control sensitive data before it enters an AI workflow, while it is being used, and before an output or communication leaves the organization.
Visit WebsiteCompany Overview
Bonfy.AI is building a security control plane for the content flows created and consumed by modern AI systems. Its Bonfy Adaptive Content Security (ACS) platform combines content classification, business-context and entity-aware analysis, behavioral signals, policy logic, risk scoring, and automated remediation. The company describes coverage across data in motion, data at rest, and data in use: email and attachments, file stores, SaaS and collaboration applications, browser and shadow-AI activity, copilots, custom GenAI applications, and agent workflows. A notable newer capability is Contextual Data Enforcement, in which an MCP server can inspect content during an agent's reasoning or tool-use path, rather than relying only on static permissions or a final-output filter. This is a more specific proposition than generic LLM moderation: the protected object is enterprise content and its surrounding business context, whether the author is a person, service account, or AI agent.
The commercial buyer problem is the gap between rapid AI adoption and legacy data-loss-prevention controls designed around files, channels, and keyword or pattern matching. Bonfy targets security, privacy, compliance, data, and AI leaders that need to enable Microsoft 365 Copilot, Claude, ChatGPT, other assistants, and internal agents without allowing confidential information, personal data, intellectual property, or regulated content to be exposed or misrouted. The platform lists integrations including Microsoft 365, Entra, Purview, Google Workspace, Salesforce, HubSpot, Slack, mail flows, on-premises stores, and S3. The value proposition is therefore a unified enforcement and visibility layer that can reduce investigation noise and support auditability, rather than a point solution limited to one model provider.
Bonfy emerged from stealth with a June 2025 launch and a reported $9.5 million seed round led by TLV Partners, with participation from Saban Ventures and other investors. The founders identified publicly are Gidi Cohen, CEO and co-founder, and Danny Kibel, CTO and co-founder; both are described as security-industry veterans. The company lists 11-50 employees and Mountain View as its LinkedIn headquarters, while its public materials also reflect Israeli roots. Public evidence supports product development, integrations, launch activity, and security/compliance positioning, but does not establish revenue, customer concentration, retention, deployment scale, or a later financing round. Those missing metrics are central diligence items for a seed-stage enterprise-security company.
Competition is broad and strategically difficult. Bonfy overlaps with AI security and data-security vendors such as Lakera, Prompt Security, Nightfall, Cyberhaven, Netskope, and Protect AI, as well as incumbent DLP, DSPM, CASB, identity, SIEM, and cloud-platform capabilities. Its possible edge is the combination of content-level policy enforcement, business/entity context, multi-channel coverage, and an agent-facing inspection path, especially where conventional DLP sees a file or a destination but not the intent and data lineage around an AI action. That edge must be demonstrated through measurable precision, latency, policy coverage, deployment effort, and outcomes against incumbent tools; product breadth alone can also create integration and implementation burden.
The defense and national-security relevance is credible but indirect. Defense organizations, intelligence teams, and public-sector operators face the same risks around sensitive data entering assistants, agents, collaboration systems, and external communications, and they require stronger policy enforcement, audit trails, identity context, and deployment controls. Bonfy's security architecture and optional BYOC positioning could be relevant to those environments, but public sources reviewed do not demonstrate defense customers, classified deployment, government contracts, or certification for those use cases. The strongest present thesis is dual-use security infrastructure that could support high-assurance AI adoption; the record should not imply that military validation has already occurred.
Dual-Use Assessment
Bonfy's core technology is enterprise data and AI security rather than a military product, but its controls have substantive security and public-sector applicability. Content inspection, contextual policy enforcement, identity-aware risk scoring, agent data-use checks, audit trails, and flexible deployment can help protect sensitive workflows in government, defense, intelligence, and regulated infrastructure. The public record supports a credible dual-use adjacency, not evidence of defense contracts, classified deployments, or military-specific validation.
Strategic Fit Assessment
Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.
Bonfy.AI is a credible strategic-fit startup for an AI-security and dual-use infrastructure database because it addresses a concrete bottleneck to enterprise AI adoption: controlling sensitive content as it moves through human and agent workflows. The $9.5 million seed round, experienced security founders, expanding integration surface, and MCP-based data-in-use inspection are positive signals. The thesis remains early and evidence-calibrated: public materials do not disclose recurring revenue, customer counts, retention, win rates, or defense contracts. Further diligence should test whether Bonfy's contextual detection and enforcement produce materially better precision and coverage than incumbent DLP, DSPM, CASB, and AI-security products, and whether the product can scale across complex enterprise environments without becoming a services-heavy deployment.
Strategic Value to U.S.-Israel Alliance
Bonfy could become an enabling layer for trustworthy AI adoption by connecting content security, data governance, identity context, and agent controls in one policy plane. That is strategically relevant as enterprises and public-sector organizations expose more sensitive data to copilots and autonomous workflows. Its potential value is greatest where native model safeguards and access permissions do not answer what data an agent should retrieve, use, or transmit in a particular business context. The strategic case is tempered by dependence on integrations, evolving platform APIs, customer security architecture, and the ability to prove low-latency enforcement without disrupting useful AI workflows.
Key Technologies
- Entity-aware content classification and risk scoring
- Adaptive knowledge graphs and business-context modeling
- Policy and business-logic enforcement across data flows
- Input, output, and data-in-use controls for AI workflows
- MCP-server inspection for AI-agent reasoning and tool use
- Multi-channel connectors for Microsoft 365, Google Workspace, SaaS, files, and messaging
- Real-time detection, remediation, audit reporting, and SIEM integration
Use Cases & Applications
- Preventing sensitive data from entering prompts, embeddings, indexes, and agent context
- Inspecting Copilot, Claude, ChatGPT, and custom-agent outputs before external sharing
- Detecting and remediating IP leakage, privacy exposure, oversharing, and non-compliant communications
- Governing data access and tool calls during AI-agent workflows through contextual enforcement
- Monitoring shadow AI and content risk across email, files, browsers, SaaS, and collaboration systems
- Supporting GDPR, HIPAA, PCI, CCPA, and organization-specific policy reporting
- Protecting high-sensitivity government or defense information systems where AI use requires auditable controls
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.
This record lists 8 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- bonfy.ai Public source used for profile verification.
- bonfy.ai Public source used for profile verification.
- bonfy.ai Public source used for profile verification.
- bonfy.ai Public source used for profile verification.
- blog.bonfy.ai Public source used for profile verification.
- blog.bonfy.ai Public source used for profile verification.
- LinkedIn company page Public source used for profile verification.
- ebnlaw.co.il Public source used for profile verification.
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Investor Lens
What this entry is
Private startup
Why it may matter
Bonfy.AI may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.
How an independent investor should read this
Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.
Evidence to verify
- Verify current status
- Verify traction
- Verify cap table/funding
- Verify technical claims
- Verify regulatory/export-control issues
- Verify customer concentration
Main investor questions
- Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
- What customer, revenue, product, and technical evidence supports the company story?
- What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
- Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
- What evidence would change the thesis or show that the profile is stale?
What not to infer
- Inclusion does not imply endorsement.
- Inclusion does not imply allocation availability or current fundraising.
- Scores do not indicate investment suitability or expected returns.
- Strategic importance does not automatically imply venture return potential.
Diligence questions
- What evidence verifies Bonfy.AI's current customer traction, deployment status, and revenue concentration?
- Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
- Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
- How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
- What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.
Related companies
Need a diligence readout?
Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.