Kodem

Cybersecurity Dual-Use Technology Priority Signal Founded 2021

Last updated: Jul 31, 2026

Kodem is an Israeli application-security startup that connects code, dependency, container, and in-workload runtime evidence to identify exploitable risk, prioritize remediation, and verify that fixes change the security outcome. Its Runtime Intelligence platform also discovers and attributes AI agents, models, tools, and data connections inside running applications.

Visit Website

Company Overview

Kodem sells an application-security platform built around Runtime Intelligence rather than scanner output alone. The company says its core evidence source is memory analysis of running processes, correlated with execution, operating-system, code, and dependency evidence. The platform is organized around runtime-aware SAST and SCA, secret detection, exposure discovery, a runtime bill of materials, and AI-assisted triage. Its practical proposition is to distinguish a vulnerable component or code path that merely exists from one that is loaded, reachable, executing, and relevant in a running application. The public technology material also identifies two US patents for the runtime-intelligence foundation. Kai Red, Kai Blue, and Kai Defend frame investigation, remediation, and protection as a connected workflow, but the published product claims should be tested feature by feature in diligence.

The company is addressing a real enterprise pain point: security teams accumulate more findings than developers can review, while application architecture and software supply chains change continuously. Kodem’s workflow is intended to cut noise, rank issues by reachable or exploitable risk, and connect the answer to existing engineering and security processes. Its self-healing-application positioning adds three coordinated functions: validate real risk, propose a source or runtime response, and verify that the risky path is gone. The company describes dynamic fixes as targeted, human-readable, reviewed, reversible mitigations for software that cannot immediately be patched. Its agent-aware material says discovery and action attribution ship today, while per-agent enforcement is still the direction of development; that distinction is important when assessing current capability rather than roadmap ambition.

Kodem competes with established SAST and SCA vendors such as Checkmarx, Veracode, Snyk, Mend, GitHub Advanced Security, and Semgrep, as well as runtime and cloud-security platforms such as Wiz and Contrast Security. Its potential edge is the closed loop from code and dependency context to runtime evidence and post-remediation verification, with a newer extension into agent-aware application security. That edge is only durable if memory analysis and sensors have low operational overhead, reachability and exploit validation materially outperform static heuristics, and integrations fit existing CI/CD, ticketing, cloud, and workload environments. The company website reports 51 employees and $40M+ raised to date; LinkedIn reports a broader 51-200 employee band and Tel Aviv headquarters. The site presents customer logos and case studies, including Rapyd, but public references do not establish retention, deployment scale, revenue quality, or independent benchmark leadership.

Kodem has credible defensive dual-use relevance. The same runtime evidence and remediation controls can help protect commercial SaaS, financial systems, regulated workloads, and sensitive government or defense software, especially where teams need to determine which vulnerable dependencies actually execute in production. The company says it supports Linux and Windows, can run with an in-host sensor or sensorless analysis, and can operate in restricted or air-gapped environments; those characteristics improve potential high-assurance fit but are not proof of deployment in such environments. Its agent-aware visibility is relevant to mission systems that combine models, tools, credentials, and delegated actions. This is defensive cyber applicability, not evidence of defense contracts or classified deployment. The strategic case therefore depends on secure deployment architecture, data isolation, operator controls, performance, and proof that runtime analysis can be trusted in high-consequence systems.

Dual-Use Assessment

Military & Commercial Applications

Kodem’s core technology is defensive application security with substantive dual-use applicability. Runtime reachability, exploit validation, software-supply-chain context, agent/action attribution, and reversible runtime mitigation can harden commercial services as well as sensitive government, infrastructure, and defense-adjacent software. No public evidence reviewed here establishes a defense contract or military deployment, so the case is capability adjacency rather than claimed defense traction.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

Kodem has a credible strategic fit with an internal dual-use and deep-cyber thesis: it targets a persistent AppSec bottleneck, has disclosed institutional backing, and is building around runtime evidence that can matter in high-consequence software. The opportunity is conditional rather than a recommendation. Diligence should focus on recurring revenue, customer retention, measurable noise reduction, sensor deployment friction, gross margins, and whether dynamic fixes and AI outputs are trusted in production. The crowded category and rapid platform bundling make distribution and independent proof of technical advantage as important as the product narrative.

Strategic Value to U.S.-Israel Alliance

Kodem could give security and engineering teams a more operationally grounded view of software risk by showing what code and dependencies actually execute, what an agent can reach, and whether a remediation worked. That supports resilience in enterprise, regulated, infrastructure, and defense-adjacent environments. Strategic value is highest where software changes quickly and manual evidence collection cannot keep pace; it is lower where restricted deployment, data residency, or runtime instrumentation is unacceptable.

Key Technologies

  • User-space memory analysis of running workloads
  • Linux and Windows runtime collection, including sensorless air-gapped analysis
  • Code, container, dependency, and runtime correlation
  • Reachability and exploit validation for SAST and SCA findings
  • AI-assisted vulnerability triage and natural-language investigation
  • Agent-aware runtime attribution across models, tools, MCP servers, and delegated actions
  • Guided pull-request remediation and validated reversible dynamic fixes
  • Post-remediation verification and continuous security-policy feedback

Use Cases & Applications

  • Prioritizing CVEs and code findings by production reachability and exploitability
  • Mapping vulnerable dependencies and secrets to services, images, and live workloads
  • Investigating incident or zero-day exposure with runtime-backed scope and urgency
  • Reviewing SAST findings and generating developer-oriented remediation guidance
  • Protecting unpatchable or legacy applications with reversible runtime mitigation
  • Attributing AI-agent, model, tool, credential, and network actions inside an application
  • Providing continuous software assurance for regulated, critical, or defense-adjacent systems
  • Reconstructing AI application posture, including agents, models, tools, credentials, and data connections

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.

This record lists 8 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Investor Lens

What this entry is

Private startup

Why it may matter

Kodem may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.

How an independent investor should read this

Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.

Evidence to verify

  • Verify current status
  • Verify traction
  • Verify cap table/funding
  • Verify technical claims
  • Verify regulatory/export-control issues
  • Verify customer concentration

Main investor questions

  • Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
  • What customer, revenue, product, and technical evidence supports the company story?
  • What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
  • Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
  • What evidence would change the thesis or show that the profile is stale?

What not to infer

  • Inclusion does not imply endorsement.
  • Inclusion does not imply allocation availability or current fundraising.
  • Scores do not indicate investment suitability or expected returns.
  • Strategic importance does not automatically imply venture return potential.

Diligence questions

  • What evidence verifies Kodem's current customer traction, deployment status, and revenue concentration?
  • Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
  • Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
  • How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
  • What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.

Need a diligence readout?

Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.