Dossier · Private startup · 3 independent sources
Cyngular Security
Last updated: Sep 2, 2026
Cyngular Security is an Israeli cybersecurity company building an agentic SOC for cloud and hybrid environments. Its ClouDFIR/THIRDhub platform combines agentless investigation, threat hunting, deception, response, and auditable reporting to move security teams from alert queues to evidence-backed resolution.
Visit WebsiteCompany Overview
**Product and the concrete problem it solves.** Cyngular Security targets the part of security operations that remains painfully manual after a detection fires: determining what happened, how far an attacker moved, which systems are affected, what evidence supports the conclusion, and what response is safe. Its public materials describe a cloud and hybrid-cloud platform that can uncover threats, investigate them, contain them, and produce a report for leadership and regulators. The current product message calls this an agentic SOC, while earlier materials describe ClouDFIR and the THIRDhub platform for cloud hunting, investigation, response, and deception. The buyer problem is operational rather than merely analytical. More cloud accounts, identities, workloads, SaaS connections, and security tools create an alert volume that grows faster than a human SOC can investigate. Cyngular's proposed answer is to make the investigation workflow itself executable by specialized agents, so analysts receive a resolved case and an auditable explanation instead of another queue item. The product is therefore positioned as a control and decision layer across an existing security environment, not as a replacement for every detection source.
**Core technology and how it actually works.** Cyngular describes six specialized agents operating as a coordinated mesh rather than one general-purpose chatbot. Its site identifies roles including an observer, threat hunter, investigator, deceptor, resolver, and reporter, with the broader platform claim that agents can detect, hunt, investigate, deceive, resolve, and report end to end. The agentless, read-only onboarding model connects to a customer's cloud environment without installing an endpoint agent, and the site says a deployment can be live in under fifteen minutes. The intended workflow is concrete: collect approved cloud and security context; correlate identity, configuration, activity, and threat signals; reconstruct an incident and root cause; use deception or investigation to clarify attacker behavior; recommend or execute a policy-bounded response; and preserve an explanation for the customer. Cyngular's public platform page claims 95% of threats resolved autonomously in under three minutes, but that is a company-reported outcome rather than an independently benchmarked result. The architecture's defensible question is not whether an LLM can summarize an alert, but whether the mesh has reliable tool permissions, evidence provenance, failure thresholds, escalation paths, and repeatable integrations across AWS, Azure, GCP, on-premises systems, and existing SOC tooling.
**Market, customers, and go-to-market.** The primary market is enterprise security operations, incident response, cloud-security teams, and managed security service providers that need more investigative capacity without adding an analyst for every new tenant or alert source. Cyngular's partner page makes the MSSP route explicit: one multi-tenant agentic squad can operate across client environments, with white-label delivery, per-tenant assessments against NIST, HIPAA, PCI-DSS, and SOC 2 frameworks, and an agentless onboarding motion intended to reduce deployment friction. The direct enterprise motion is aimed at CISOs, heads of incident response, and security-operations leaders in environments spanning cloud, on-premises, and hybrid infrastructure. The company website displays anonymous customer evidence from insurance, MSSP, telecom, and a Nasdaq-traded company; those testimonials suggest product engagement and a broad buyer set, but they do not establish customer names, contract values, renewal rates, or revenue. This is a sensible wedge because cloud investigation is a high-consequence pain point and read-only access lowers the initial trust barrier. Expansion depends on proving that investigation quality, containment safety, compliance reporting, and analyst-time savings are materially better than an incumbent SIEM, XDR, SOAR, or managed service.
**Traction, funding, and third-party validation.** Cyngular is not a purely unverified stealth name. Startup Nation Finder identifies it as an active Israeli company founded in 2021, with a Tel Aviv-Yafo headquarters, a reported team of 28 within an 11-50 employee range, and a released product. The same profile records a January 2022 Seed round involving Springtide Ventures, ST Engineering Ventures, and VentureIsrael, followed by a March 2024 undisclosed round led by Tachles VC. Neither the amounts nor a complete cap table are public, so the record uses an undisclosed seed/follow-on description rather than inventing a dollar figure. ST Engineering's 2025 investor-day materials identify Cyngular's CIRA, or Cloud Investigation and Response Automation, as a startup collaboration and show its positioning around autonomous cloud incident readiness and response. The company also states that it holds SOC 2 Type II, and a public company post attributes the certification to EY. Its Israeli service agreement names Cyngular Security Ltd. as an Israeli corporation, providing legal-entity evidence beyond marketing copy. These are useful validation signals, while the absence of audited revenue, named reference accounts, independent efficacy testing, and disclosed financing totals remains material.
**Founders and team background.** The founding team is unusually relevant to the operational problem. Paul Moskovich is identified by the company as co-founder and CEO, with 25 years defending large enterprises across aerospace and defense, finance, and communications as a CISO; the company also states that he served as Deputy Director-General and Chief Executive Director of Israel's National Cyber Directorate at the Prime Minister's Office. Co-founder and CTO Itzik Berrebi is described as a cybersecurity leader with more than a decade across defense, finance, and technology, including work as CISO at an Israeli blockchain company and leadership of incident-response and R&D teams at an aerospace and defense enterprise. Amir Skouri, listed as VP of R&D, is described as a former Unit 8200 and Matzov R&D leader with defensive and offensive cybersecurity experience and aerospace-defense research background. This combination supplies buyer empathy, public-sector cyber context, and hands-on incident-response experience. It also creates diligence questions: the public record does not disclose the current engineering organization beyond selected leaders, the balance between Israel and U.S. operations, or the proportion of product engineering versus services and integration work. A strong executive résumé can open enterprise doors, but only a deep bench and disciplined agent evaluation process can support reliable autonomous response at scale.
**Competitive dynamics.** Cyngular competes across several overlapping budgets. CrowdStrike Falcon and Palo Alto Networks Cortex XSIAM combine telemetry, detection, investigation, and response inside large installed platforms; Microsoft Defender XDR and Sentinel benefit from Microsoft 365 and Azure distribution; Google SecOps and Mandiant bring cloud-scale telemetry and incident-response expertise; and Wiz competes for cloud-security visibility and risk-management ownership. Tines and Torq automate security workflows, while Hunters and other SIEM/XDR vendors compete for the investigation and detection-engineering layer. Cyngular's claimed edge is the end-to-end agent mesh and its focus on completing the case rather than generating another alert. Its agentless, read-only onboarding and MSSP white-label model could also lower adoption friction and create leverage through service providers. These advantages are not yet a durable moat. Large platforms can add AI investigators to data they already control, SOAR vendors can package comparable playbooks, and professional-services firms can supply human investigation. Cyngular must prove that its agents reconstruct incidents with fewer false conclusions, preserve evidence, respect customer authorization boundaries, and reduce total cost across heterogeneous clouds. The critical competitive metric is resolved, trusted incidents per analyst hour, not the number of agents in the interface.
**Defense, security, and resilience dual-use relevance.** Cyngular's core technology has substantive dual-use relevance because cloud incident readiness and response protect commercial enterprises, defense contractors, government agencies, telecommunications providers, hospitals, and critical infrastructure alike. The founders' aerospace-defense and National Cyber Directorate backgrounds make the security adjacency credible, and the Israeli legal entity and Tel Aviv operating base place the company inside an ecosystem with direct exposure to national cyber defense. An agentic investigation layer could help an understaffed national CERT, utility SOC, or defense-industrial security team reconstruct attacks faster, contain compromised identities or workloads, and produce defensible evidence for commanders, regulators, and executives. Its read-only onboarding is relevant where a public-sector buyer wants analysis before granting automated write permissions. The calibration is important: public sources reviewed do not establish a classified deployment, Israeli Ministry of Defense contract, military customer, or government accreditation. Deception and autonomous response also carry elevated safety and governance obligations in mission-critical environments; a mistaken containment action can interrupt a service or destroy evidence. The strategic case is therefore cyber-resilience infrastructure that could transfer into allied and public-sector use, not a claim that Cyngular is already a fielded defense system.
**Growth stage, trajectory, and key diligence risks.** Cyngular is best classified as early-to-mid commercial stage, with the schema's **early** label reflecting limited financial disclosure despite a released product, institutional backers, SOC 2 Type II, and reported enterprise and MSSP usage. Its trajectory is toward an agentic operating layer for security operations: first automate cloud investigation and evidence assembly, then expand into threat hunting, deception, response, compliance reporting, and multi-tenant MSSP delivery. The most important diligence points are: (1) independently validate the 95%-resolved and under-three-minute claims by incident class, severity, and false-resolution rate; (2) establish whether autonomous actions are recommendation-only, customer-approved, or policy-bounded execution, and measure rollback and escalation behavior; (3) obtain named customer references, retention, deployment counts, gross margin, and services intensity; (4) test integration depth across AWS, Azure, GCP, Kubernetes, identity providers, SIEMs, EDRs, and ticketing systems; (5) review model-provider dependence, prompt-injection resistance, data isolation, and evidence integrity; (6) assess whether the 2024 follow-on financing and current U.S. expansion provide enough runway for enterprise sales cycles; and (7) determine whether government, defense-industrial, or critical-infrastructure adoption can meet procurement, residency, export, and high-assurance requirements. The team and product are credible, but the company must convert strong operational positioning into independently verifiable outcomes before its strategic importance can be scored as more than high-potential cyber resilience.
Dual-Use Assessment
Cyngular's core cloud investigation, threat hunting, deception, evidence assembly, and response capabilities have substantive commercial and security applicability. The same platform can help enterprises, defense contractors, telecom operators, hospitals, utilities, government agencies, and national cyber teams investigate attacks across cloud and hybrid environments. The founders' aerospace-defense and Israeli National Cyber Directorate backgrounds make the transfer path credible. The public evidence is stronger for commercial and MSSP positioning than for defense adoption: no classified deployment, military contract, Israeli Ministry of Defense customer, or government accreditation was found in the reviewed sources. Autonomous response and deception also require strict authorization, auditability, data isolation, and rollback controls in mission-critical environments, so dual-use describes the technology's application range rather than confirmed military fielding.
Strategic Fit Assessment
Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.
Cyngular merits a positive legacy priority signal because it addresses the operational bottleneck between detection and trustworthy resolution, has an Israeli legal entity and strategically relevant founding team, and shows product, financing, and compliance evidence beyond a concept-stage profile. (1) The platform's agentic mesh is aimed at a measurable buyer pain: cloud alert volume and investigation time. (2) Paul Moskovich, Itzik Berrebi, and Amir Skouri combine national cyber leadership, aerospace-defense security, incident response, and offensive/defensive research backgrounds. (3) Startup Nation Finder records a 2022 seed round and 2024 undisclosed follow-on, while ST Engineering materials and the company's SOC 2 Type II claim provide third-party validation signals. (4) The MSSP route could scale distribution if the multi-tenant product reduces cost to serve. Counterweights are material: funding amounts, revenue, retention, named customers, and independent efficacy results are not public; CrowdStrike, Palo Alto Networks, Microsoft, Google, and specialist SOAR vendors can bundle overlapping functionality; and autonomous response creates asymmetric trust and safety risk. This is a strategic diligence assessment, not an investment recommendation.
Strategic Value to U.S.-Israel Alliance
Cyngular's strategic value is concentrated in cyber resilience at the cloud and hybrid-infrastructure layer. (1) Speed: an agentic investigation capability could reduce the time between an alert and a defensible attack narrative when adversaries move faster than human queues. (2) Workforce leverage: national CERTs, defense contractors, utilities, and regulated enterprises all face shortages of experienced investigators, making evidence-backed automation strategically useful. (3) Sovereign applicability: an Israeli company with a National Cyber Directorate leader and aerospace-defense practitioners could become relevant to allied security operations if it proves data isolation, deployment control, and procurement readiness. (4) Ecosystem leverage: agentless onboarding and MSSP delivery could spread the capability across many smaller organizations that cannot staff a full SOC. The current evidence supports high-potential resilience infrastructure, not a confirmed government or military capability; strategic value should rise only with named public-sector or defense-industrial deployments, high-assurance authorizations, and independent proof that autonomous decisions are safe.
Key Technologies
- Agentless, read-only cloud and hybrid-environment investigation across AWS, Azure, GCP, and connected security systems
- Specialized agent mesh for observation, threat hunting, digital forensics, investigation, deception, resolution, and reporting
- Cloud Digital Forensics and Incident Response (ClouDFIR) evidence collection and attack-timeline reconstruction
- AI-assisted root-cause analysis, threat correlation, and policy-bounded autonomous response
- Cloud deception workflows for clarifying attacker behavior and generating high-confidence investigative evidence
- Multi-tenant MSSP orchestration with white-label delivery and per-tenant compliance assessments
- Auditable incident reporting and security-posture outputs mapped to NIST, HIPAA, PCI-DSS, and SOC 2 frameworks
Use Cases & Applications
- Agentless investigation and root-cause analysis of cloud account compromise
- Automated triage and evidence assembly for SOC and incident-response teams
- Threat hunting across multi-cloud identities, workloads, configurations, and activity logs
- Deception-assisted investigation of attacker movement inside cloud environments
- Policy-bounded containment and response after validation of a high-confidence incident
- White-label, multi-tenant SOC automation for managed security service providers
- Compliance-ready incident reporting for regulated financial, healthcare, telecom, and public-sector environments
- Potential cyber-resilience support for defense contractors, utilities, and national cyber teams
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.
This record lists 9 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- Cyngular Security official website Verifies the agentic SOC positioning, six-agent workflow, anonymous customer testimonials, 95% autonomous-resolution claim, under-three-minute claim, SOC 2 Type II claim, and Tel Aviv/New York/Atlanta locations.
- Cyngular platform overview Verifies the agentless read-only deployment model, under-15-minute onboarding claim, threat-detection/investigation/resolution workflow, and specialized agent roles.
- Cyngular company and leadership page Verifies the company narrative, ClouDFIR origins, founders Paul Moskovich and Itzik Berrebi, VP R&D Amir Skouri, and their national cyber, aerospace-defense, and incident-response backgrounds.
- Cyngular MSSP partner program Verifies the multi-tenant, white-label MSSP go-to-market model, agentless tenant connection, six-agent workflow, and NIST/HIPAA/PCI-DSS/SOC 2 assessment positioning.
- Cyngular Security Services Agreement Verifies the legal entity name Cyngular Security Ltd. and identifies it as an Israel corporation in a customer-facing agreement.
- Startup Nation Finder company profile: Cyngular Security Verifies 2021 founding, Tel Aviv-Yafo headquarters, reported 28-person team, released product, 2022 seed investors, 2024 undisclosed Tachles VC-led round, and Israeli company-registration details.
- ST Engineering 2025 Investor Day presentation Verifies ST Engineering's public startup collaboration reference to Cyngular's CIRA Cloud Investigation and Response Automation positioning.
- Cyngular Security SOC 2 Type II announcement Verifies the company's public announcement of SOC 2 Type II certification accredited by EY.
- Singapore Trade Marks Journal entry for Cyngular Security Provides an independent legal and IP record naming Cyngular Security Ltd. as the Israeli proprietor of a cloud digital-forensics and incident-response SaaS mark.
- Profile update timestamp Last updated in the Claw & Talon database on Sep 2, 2026.
Investor Lens
What this entry is
Private startup
Why it may matter
Cyngular Security may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.
How an independent investor should read this
Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.
Evidence to verify
- Verify current status
- Verify traction
- Verify cap table/funding
- Verify technical claims
- Verify regulatory/export-control issues
- Verify customer concentration
Main investor questions
- Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
- What customer, revenue, product, and technical evidence supports the company story?
- What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
- Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
- What evidence would change the thesis or show that the profile is stale?
What not to infer
- Inclusion does not imply endorsement.
- Inclusion does not imply allocation availability or current fundraising.
- Scores do not indicate investment suitability or expected returns.
- Strategic importance does not automatically imply venture return potential.
Diligence questions
- What evidence verifies Cyngular Security's current customer traction, deployment status, and revenue concentration?
- Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
- Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
- How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
- What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.
Related companies
Need a diligence readout?
Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.