Dossier · Private startup · 1 independent source
Kanopy Security
Last updated: Jul 31, 2026
Kanopy Security, formerly Nokod Security, provides visibility, risk detection, governance, and runtime protection for applications, automations, and AI agents built by business users across enterprise platforms.
Visit WebsiteCompany Overview
Kanopy Security is building an application-security and governance layer for software that is assembled outside the traditional developer-owned software development lifecycle. The company began as Nokod Security, focused on low-code/no-code applications and robotic process automation, and now presents the same control problem through the broader Shadow AI and business-built software lens. Its public product material describes discovery and inventory across platforms such as Microsoft Power Platform and Copilot Studio, Salesforce, ServiceNow, and UiPath, with visibility into agents, flows, integrations, owners, permissions, and connected data sources. The newer agent-security proposition adds runtime behavioral profiling, policy enforcement, anomaly detection, and the ability to block or intervene when an agent takes a risky action.
The underlying customer problem is concrete. A business user can create an internal application, workflow, connector, or AI agent that accesses sensitive data and triggers consequential actions without passing through AppSec review. Traditional scanners generally inspect source code, endpoints, or infrastructure and therefore miss much of this business-built layer. Kanopy’s value depends on turning opaque platform metadata and runtime activity into an inventory that security teams can prioritize, then giving platform owners and citizen developers practical remediation paths. Relevant findings include orphaned assets, tenant-wide sharing, excessive permissions, exposed credentials, unsafe webhooks, prompt or data injection, insecure external calls, and data moving through an unintended connector. The product is most compelling where a large enterprise has thousands of distributed builders and cannot govern each asset manually.
The commercial market is expanding but crowded. Kanopy sits between SaaS security posture management, identity and entitlement governance, data-security posture management, application security, and native governance products from Microsoft, Salesforce, ServiceNow, and other platform owners. Its differentiation is therefore not simply that it inventories low-code assets; it must maintain deep integrations, understand workflow topology and business context, and provide controls that work across several ecosystems. The company’s public materials cite enterprise and Fortune 500 use cases, a Salesforce integration announced in May 2026, a Retool expansion reported in March 2026, and research around Power Apps and Power BI exposure. These are useful commercialization and product-velocity signals, but they do not independently establish recurring revenue, customer retention, or category leadership.
The team has credible cybersecurity experience: the official company profile identifies CEO Yair Finzi as a SecuredTouch co-founder and CTO Amichai Shulman as an Imperva co-founder and former CTO. Kanopy also disclosed an $8 million seed round in June 2023 led by Acrew Capital, Meron Capital, and Flint Capital. Public LinkedIn information places the company in the 11–50 employee range and identifies Tel Aviv as its headquarters; a 2025 company announcement also described a U.S. headquarters in Boulder. This supports an early venture-backed company with meaningful product development and go-to-market activity, but public evidence remains insufficient to infer scale from the disclosed employee range or to confirm current revenue, customer concentration, certifications, or deployment in sensitive government environments.
The national-security relevance is credible at the technology and control-plane level, not yet proven by public defense contracts. Defense, intelligence, healthcare, financial, and critical-infrastructure organizations increasingly use sanctioned SaaS platforms and are likely to face the same hidden agent, connector, identity, and data-flow risks. A platform that maps and constrains those workflows could reduce accidental disclosure and operational misuse in such environments. Diligence should test whether Kanopy supports tenant isolation, private or customer-controlled deployment, detailed audit exports, data minimization, incident response integration, and the operational latency and reliability required for high-consequence environments. the diligence case is consequently an interesting strategic fit with substantial execution and category-definition risk rather than a validated defense-market thesis.
Dual-Use Assessment
Kanopy's core technology for inventorying, mapping, governing, and protecting business-built applications and AI agents has substantive commercial and defense/security applicability. Defense, intelligence, and critical-infrastructure users also operate sanctioned SaaS platforms whose agents, connectors, permissions, and data flows can become hidden exposure paths. Public materials do not establish defense customers or government contracts, so the dual-use case is based on transferable security capabilities rather than demonstrated defense traction.
Strategic Fit Assessment
Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.
Kanopy has a credible strategic fit with a dual-use cybersecurity thesis: a disclosed seed round, experienced AppSec founders, an expanding enterprise integration footprint, and a timely problem created by business-built AI and automation. The opportunity is still early and the public record does not verify revenue quality, retention, deployment depth, or government adoption. Diligence should concentrate on integration durability, measurable risk reduction, buyer ownership, pricing, and whether runtime controls are differentiated enough to survive platform-native competition.
Strategic Value to U.S.-Israel Alliance
Kanopy could serve as a focused control and visibility layer between enterprise security teams and the business-built software created inside approved SaaS platforms. Its strategic value is strongest where organizations have substantial automation or AI-agent sprawl but lack centralized ownership, and where a cross-platform view complements rather than duplicates native Microsoft, Salesforce, ServiceNow, or identity controls.
Key Technologies
- Cross-platform discovery and inventory of low-code apps, workflows, automations, and AI agents
- Agent identity, ownership, permission, connector, and data-access mapping
- Runtime behavioral profiling and adaptive anomaly detection for AI agents
- Policy enforcement and intervention for risky agent actions, sharing, and external triggers
- Prompt-injection, data-injection, exposed-secret, webhook, and data-leakage detection
- Enterprise integrations across Power Platform, Copilot Studio, Salesforce, ServiceNow, UiPath, and Retool
Use Cases & Applications
- Discovering shadow AI and citizen-built software across large enterprise tenants
- Finding orphaned apps, overshared agents, excessive permissions, and unmanaged owners
- Tracing sensitive data from Dataverse, SharePoint, OneDrive, SQL Server, Snowflake, and business systems through agents
- Blocking or investigating prompt injection, command abuse, unsafe webhooks, and unexpected runtime behavior
- Prioritizing remediation of vulnerable Power Apps and other business-built applications
- Providing audit evidence and policy controls for regulated enterprise automation programs
- Assessing workflow and agent exposure in defense, intelligence, healthcare, and critical-infrastructure environments
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.
This record lists 7 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- kanopysecurity.com Public source used for profile verification.
- kanopysecurity.com Public source used for profile verification.
- kanopysecurity.com Public source used for profile verification.
- kanopysecurity.com Public source used for profile verification.
- kanopysecurity.com Public source used for profile verification.
- LinkedIn company page Public source used for profile verification.
- prnewswire.co.uk Public source used for profile verification.
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.