Dossier · Acquired asset · 4 independent sources

Build.Security

Cybersecurity Acquired asset Dual-Use Technology Founded 2020

Last updated: Jul 31, 2026

Build.Security was a Tel Aviv authorization-policy-management startup that used Open Policy Agent (OPA) and policy-as-code to deliver fine-grained RBAC and ABAC for cloud-native applications. Elastic completed its acquisition in September 2021, so this record now describes an acquired security technology rather than an independent startup.

Company Overview

Build.Security developed an authorization-as-a-service platform for application teams that needed consistent, fine-grained access decisions across APIs, services, and application portfolios. Its core approach used Open Policy Agent (OPA) and policy-as-code to separate authorization logic from application business logic. That separation can make policies easier to review, test, change, and audit than bespoke authorization code embedded throughout a distributed system. The product addressed both role-based access control (RBAC) and attribute-based access control (ABAC), with API-based data sources intended to provide context to policy decisions.

The target problem was commercially important but technically difficult: modern applications distribute identity, data, and business logic across microservices, containers, Kubernetes clusters, and cloud control planes. Teams must enforce least privilege without creating inconsistent rules in every service, while also proving that access controls match internal and regulatory requirements. Build.Security's developer-oriented positioning, reusable policies, and OPA foundation were intended to reduce integration effort and let security teams apply controls earlier in the software lifecycle. The company emerged from stealth in 2020 with seed backing from YL Ventures, but public sources do not establish a durable independent customer base, recurring revenue scale, or post-acquisition standalone product trajectory.

Elastic announced an agreement to acquire Build.Security in August 2021 and announced completion on September 2, 2021. Elastic described the technology as a policy-definition and enforcement platform for cloud-native security, with intended integration into Kibana, Elastic Agent, Elasticsearch, and Kubernetes admission controls. Elastic's later financial reporting classified Build Security Ltd. as an acquired business and stated that it was consolidated from the acquisition date. These facts provide credible evidence of strategic and technology validation, but they should not be read as proof of independent product-market fit or of current Build.Security availability. The original company website is not currently confirmable as a live canonical destination, and public evidence does not support a current employee count.

The competitive field included authorization platforms such as AuthZed, Aserto, Oso, and Permit.io, as well as direct substitutes including self-managed OPA, cloud IAM and policy services, and authorization features built into application platforms. Build.Security's historical edge was the combination of a developer workflow, open policy standards, and a managed control-plane concept around a difficult cross-application problem. That edge was also exposed to commoditization: OPA is open source, cloud vendors control adjacent enforcement points, and enterprise buyers may prefer identity suites or platform-native controls. Acquisition by Elastic improved distribution and integration potential, while ending the company's status as an independent vendor whose roadmap, pricing, and customer support can be diligenced separately.

The technology has credible dual-use relevance because authorization policy enforcement is a foundational control for commercial cloud systems, government networks, and defense mission-support software. It can support least privilege, separation of duties, policy compliance, and auditable access decisions in sensitive environments. The dual-use case remains architectural rather than evidence of defense deployment: no reliable public source reviewed here establishes a Build.Security defense customer, classified deployment, government contract, or security certification. For Claw & Talon, the record is therefore most useful as an acquired cyber capability and market signal around policy-driven cloud security, not as an strategically relevant independent defense startup.

Dual-Use Assessment

Military & Commercial Applications

Authorization policy infrastructure has substantive commercial and defense-adjacent applicability: the same least-privilege, separation-of-duties, context-aware policy, and audit mechanisms can protect SaaS, cloud infrastructure, government networks, and mission-support applications. The assessment is architectural rather than deployment-proven; reviewed public sources do not establish a defense customer, classified use, government contract, or certification.

Strategic Fit Assessment

Build.Security is not an independent investment or priority-screening target because Elastic completed its acquisition in 2021 and public filings treat Build Security Ltd. as part of Elastic's consolidated business. The transaction is useful diligence evidence for the strategic value of authorization policy infrastructure, but any current commercial, product, or personnel assessment must be conducted through Elastic. No recommendation is implied.

Strategic Value to U.S.-Israel Alliance

The asset's strategic value was its ability to connect policy-based authorization with Elastic's cloud-security, analytics, and enforcement stack. Elastic identified uses spanning policy management, Elastic Agent enforcement, Elasticsearch evidence, Kubernetes admission control, and cloud-configuration checks. For national-security analysis, this supports a credible zero-trust and least-privilege adjacency, but the public record does not demonstrate defense deployment or sovereign-control suitability.

Key Technologies

  • Open Policy Agent (OPA) policy engine
  • Policy-as-code definition and enforcement
  • Fine-grained RBAC and ABAC
  • API-driven authorization decision-making
  • Distributed policy evaluation and caching
  • CI/CD and deployment pipeline integration

Use Cases & Applications

  • Fine-grained authorization for APIs and microservices
  • Kubernetes admission and cloud-configuration policy enforcement
  • Least-privilege controls across multi-tenant SaaS applications
  • Policy testing and compliance evidence in CI/CD workflows
  • Context-aware access decisions using API-backed application data
  • Government and defense mission-support application access governance
  • Separation of duties for sensitive administrative operations
  • Continuous audit of authorization decisions and policy changes

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Open-web verification is limited. Readers should confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.

This record lists 4 public references used for company identity, status, positioning, or material-claim review.

Verification note: public information is limited; this entry is retained for ecosystem-mapping purposes and should not be relied on without further confirmation.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.