Jit

Cybersecurity Acquired asset Dual-Use Technology Founded 2020

Last updated: Jul 31, 2026

Jit was a product security and agentic security-operations company that connected code, cloud, runtime, identity, data, policy, and scanner signals through a company-specific context graph. Torq announced its acquisition of Jit in May 2026 to incorporate that context technology and team into Torq's AI SOC platform.

Visit Website

Company Overview

Jit built a product-security execution layer for organizations that had accumulated scanners but still lacked context, prioritization, and follow-through. Its platform connected source-code and cloud systems with runtime, identity, data, compliance, internal-policy, and operational-workflow information. Jit described the resulting company-specific context graph as a continuously updated model that lets agents ground decisions in architecture, ownership, business importance, and policy rather than treating every scanner finding as equally urgent. Its agent layer covered investigation, triage, remediation validation, threat modeling, compliance operations, and custom workflow execution, with human approvals available for consequential actions.

The technical value proposition was therefore broader than another SAST, SCA, secrets, IaC, DAST, or CSPM product. Jit could ingest findings from an existing security stack, correlate them with code-to-cloud relationships and business context, and help determine whether a vulnerability was exploitable, important, and assigned to the right owner. Its public security documentation says static analysis can run in customer CI/CD environments while Jit receives vulnerability metadata, and that DAST and CSPM workflows use cloud trust relationships. That architecture can reduce the amount of sensitive source code copied into a vendor service, although customers still need to assess token scope, telemetry exposure, retention, and agent permissions.

The commercial market was crowded. Jit faced platform-native security from GitHub, GitLab, and cloud providers, as well as AppSec and product-security platforms such as Snyk, Semgrep, Apiiro, Legit Security, OX Security, Aikido, and ArmorCode. Its defensibility depended on the quality of its context graph, breadth and reliability of integrations, measurable reduction in false positives and triage time, and the safety of autonomous actions. The company’s public site reported thousands of AI security agents in production across nearly 100 enterprise customers; this is a company-reported traction signal, not independently audited revenue or retention evidence. The acquisition itself is stronger evidence that Torq valued Jit’s context technology and engineering capability, but it also means standalone ARR, product roadmap, and customer continuity should be diligenced through Torq rather than assumed from Jit’s historical marketing.

Jit’s May 2026 combination with Torq changes the record’s classification. It is no longer an independent startup seeking a new financing round: Torq says it acquired Jit to add an enterprise context graph to its agentic security-operations platform, and Jit’s announcement says the team and technology are joining Torq. Public reporting describes an approximately 30-person team transfer, while historical third-party company data reported a larger range and a 2022 seed round. Those figures should be treated as historical and not as current standalone headcount or capitalization. The official Jit site currently presents a Boston address, while the company originated in Israel, so the headquarters field is marked with the current public address and the historical Israeli footprint is retained in the rationale.

For defense and national-security users, the relevant adjacency is secure software-factory and SOC workflow infrastructure: correlating software supply-chain findings, validating cloud exposure, enforcing development policies, collecting audit evidence, and accelerating remediation across large engineering organizations. That is credible dual-use utility, but not evidence of defense customers or classified deployment. Additional diligence would need to establish whether Torq preserves Jit’s deployment model and supports sovereign, disconnected, or highly restricted environments, and whether agent actions remain bounded, explainable, reversible, and fully auditable when operating on mission-critical systems.

Dual-Use Assessment

Military & Commercial Applications

Jit's core context-graph and security-workflow automation had substantive commercial and defense-adjacent applicability: both enterprise software teams and secure software factories need to correlate code, cloud, identity, runtime, policy, and compliance signals. The acquisition provides strategic validation of the technology, but public evidence does not establish defense customers, classified use, or deployment in restricted environments.

Strategic Fit Assessment

Jit had credible strategic value and reportedly achieved enterprise deployment, but it is now an acquired asset rather than an independently actionable startup. The Torq transaction is a meaningful validation signal for its context-graph and agent technology; diligence should focus on the acquisition's product integration, customer migration or retention, technology ownership, and whether the capability produces differentiated outcomes inside Torq's larger platform.

Strategic Value to U.S.-Israel Alliance

Jit's strategic value is the context layer that can make security automation more accurate and operationally useful. Connecting organizational architecture, policies, ownership, and live security data can improve prioritization and explainability for enterprise SOCs and secure software factories. That value now accrues primarily to Torq, so the relevant question is how effectively Torq integrates the asset and preserves its controls for high-assurance users.

Key Technologies

  • Company-specific security context graph linking code, cloud, runtime, identity, data, policy, and business context
  • AI agents for investigation, triage, remediation validation, threat modeling, and compliance operations
  • Cross-tool security-signal ingestion and normalization across 30+ scanner integrations
  • Code-to-cloud-to-runtime relationship mapping for risk prioritization
  • Policy-aware workflow orchestration with human approvals and auditability
  • CI/CD-native SAST, SCA, secrets, IaC, DAST, CSPM, and SBOM controls
  • Custom security-agent and workflow templates

Use Cases & Applications

  • Correlating vulnerability findings with application ownership, runtime exposure, and business criticality
  • Triage and remediation validation across SAST, SCA, secrets, IaC, DAST, and CSPM findings
  • Secure software-factory release gates and policy enforcement
  • Threat modeling and secure-design review for cloud-native applications
  • Continuous software-supply-chain and SBOM risk monitoring
  • Compliance evidence collection and audit-ready security reporting
  • SOC investigation and response context enrichment after integration with Torq
  • Bounded security automation for regulated or defense-adjacent engineering environments

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.

This record lists 6 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

  • jit.io Public source used for profile verification.
  • jit.io Public source used for profile verification.
  • jit.io Public source used for profile verification.
  • jit.io Public source used for profile verification.
  • torq.io Public source used for profile verification.
  • finder.startupnationcentral.org Public source used for profile verification.
  • Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.

Investor Lens

What this entry is

Acquired asset

Why it may matter

Jit may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.

How an independent investor should read this

Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.

Evidence to verify

  • Verify current status
  • Verify technical claims
  • Verify regulatory/export-control issues

Main investor questions

  • Is this entry a benchmark, buyer, ecosystem node, acquired asset, or strategic reference rather than a live startup opportunity?
  • What does this reference clarify about buyers, sector structure, public-market context, or strategic demand?
  • Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
  • What evidence would change the thesis or show that the profile is stale?

What not to infer

  • Inclusion does not imply endorsement.
  • Inclusion does not imply allocation availability or current fundraising.
  • Scores do not indicate investment suitability or expected returns.
  • Strategic importance does not automatically imply venture return potential.

Diligence questions

  • What evidence verifies Jit's current customer traction, deployment status, and revenue concentration?
  • Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
  • Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
  • How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
  • Is the company a live venture opportunity, a mature strategic reference, an acquired asset, or primarily a market-mapping entry?

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.

Need a diligence readout?

Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.