Legion

Cybersecurity Dual-Use Technology Priority Signal Founded 2024

Last updated: Jul 31, 2026

Legion is a browser-native agentic security operations platform that observes how analysts investigate alerts, converts that operational knowledge into workflows, and progressively automates triage, investigation, and response across browser-accessible security tools.

Visit Website

Company Overview

Legion is building an AI security-operations companion around a browser extension rather than a conventional integration-heavy SOAR deployment. Its product observes analyst activity in the browser, including the sequence of tools consulted, evidence gathered, and decisions made, then turns those patterns into reusable agentic workflows. The official product framing separates a learning mode, in which Legion captures context from investigations, playbooks, runbooks, and past cases; a companion mode, in which it executes workflows with the analyst supervising; and an autonomous mode, in which the customer can allow trusted workflows to run at scale. This is a specific attempt to encode local SOC expertise instead of assuming that a generic model or fixed playbook transfers cleanly between organizations.

The customer problem is credible and economically important: security teams face high alert volume, fragmented tools, bespoke processes, and shortages of experienced investigators. Legion's browser-native approach is intended to work with SIEMs, threat-intelligence services, email systems, and homegrown applications that may be difficult or expensive to integrate through APIs. That can shorten deployment and preserve the team's existing operating environment, but it also places unusual importance on browser permissions, page-state understanding, reliable action execution, and protection against sensitive data capture. The product is therefore best understood as an AI analyst and workflow layer for enterprise SOCs, not as a replacement for the underlying detection, identity, endpoint, or case-management systems.

Legion emerged publicly in July 2025 with reported seed and Series A funding totaling $38 million: an $8 million seed round led by Picture Capital and Accel followed by a $30 million Series A led by Coatue, with Accel and Picture Capital participating. Calcalist reported 25 employees split between Israel and New York at that time and identified founders Ely Abramovitch, Michael Gladishev, and Eyal Fisher; the company describes the team as including Microsoft Sentinel and Cambridge AI research experience. The official website displays testimonials from security leaders in finance, healthcare, education, and other enterprise settings, while the launch release reported customer claims of materially shorter investigation times. These are useful commercialization signals, but they remain a mix of company-selected testimonials and reported customer statements rather than independently audited retention, revenue, deployment, or accuracy data.

Competition is broad. Legion overlaps with AI SOC specialists such as Dropzone AI and Radiant Security, workflow and automation platforms such as Tines and Torq, and security-platform incumbents such as Microsoft Security Copilot and Palo Alto Networks Cortex. Its proposed edge is the combination of browser-level observation, organization-specific workflow learning, and a graduated autonomy model that does not require customers to encode every process in advance. That edge will only be durable if learned workflows generalize across analysts, survive UI and tool changes, produce measurable quality improvements, and create enough proprietary operational context to offset the copying and bundling power of larger vendors.

The national-security and defense relevance is substantive but primarily defensive. Faster, more consistent alert investigation can support public-sector cyber defense, critical-infrastructure monitoring, incident response, and security operations for organizations with scarce cleared or domain-specialist personnel. The technology is not publicly presented as an offensive capability or military-unique system, and there is no verified public evidence here of defense contracts or government deployments. Strategic diligence should consequently concentrate on secure deployment, data residency and access controls, human override, action reversibility, evaluation against false positives and missed threats, and whether the product can meet government-grade procurement and assurance requirements without losing its low-friction browser advantage.

Dual-Use Assessment

Military & Commercial Applications

Legion's core capability is defensive cyber operations automation with credible commercial and public-sector applicability. Workflow capture, investigation support, evidence summarization, and controlled response can improve enterprise SOCs, critical-infrastructure defense, and government incident response, although the public record does not establish offensive, military-specific, or government-contract traction.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

Legion is a credible strategic-priority signal for a dual-use technology database because it addresses a persistent cyber-defense labor bottleneck with a differentiated browser-native delivery model and reported Series A financing. The company has meaningful technical and market promise, but this is not an investment recommendation: diligence must establish recurring revenue, deployment depth, outcome measurement, customer retention, security-assurance scope, and whether browser-native workflow learning is a durable moat rather than a faster route to an easily copied feature set.

Strategic Value to U.S.-Israel Alliance

Legion could become a force multiplier for security teams that cannot replace fragmented tools or hire enough experienced investigators. Its strongest strategic value is in converting tacit SOC expertise into visible, repeatable, and controllable automation while leaving customers in charge of the progression from observation to assistance to autonomy. That is relevant to regulated enterprises, critical infrastructure, and public-sector defense, but the value depends on trustworthy operation under adversarial conditions, careful data handling, and proof that automation reduces risk rather than merely moving analyst work into an opaque system.

Key Technologies

  • Browser extension for observing and executing analyst workflows
  • Vision-model interpretation of browser-based security interfaces
  • Organization-specific workflow and decision-pattern learning
  • Agentic alert triage and threat investigation
  • Human-in-the-loop and graduated autonomy controls
  • Workflow transparency, action logging, masking, and data-loss-prevention controls

Use Cases & Applications

  • Triage and investigate phishing, malware, DLP, and account-takeover alerts
  • Learn and replicate senior analysts' browser-based investigation procedures
  • Summarize evidence and document cases for handoff and audit
  • Run repeatable threat investigations across SIEM, email, and threat-intelligence tools
  • Provide supervised automation for understaffed enterprise SOCs
  • Support continuous monitoring and incident response for critical infrastructure
  • Increase public-sector cyber-defense coverage where specialist analysts are scarce
  • Standardize onboarding and operational knowledge transfer for junior analysts

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.

This record lists 5 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Investor Lens

What this entry is

Private startup

Why it may matter

Legion may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.

How an independent investor should read this

Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.

Evidence to verify

  • Verify current status
  • Verify traction
  • Verify cap table/funding
  • Verify technical claims
  • Verify regulatory/export-control issues
  • Verify customer concentration

Main investor questions

  • Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
  • What customer, revenue, product, and technical evidence supports the company story?
  • What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
  • Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
  • What evidence would change the thesis or show that the profile is stale?

What not to infer

  • Inclusion does not imply endorsement.
  • Inclusion does not imply allocation availability or current fundraising.
  • Scores do not indicate investment suitability or expected returns.
  • Strategic importance does not automatically imply venture return potential.

Diligence questions

  • What evidence verifies Legion's current customer traction, deployment status, and revenue concentration?
  • Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
  • Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
  • How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
  • What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.

Need a diligence readout?

Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.