Lema
Last updated: Jul 31, 2026
Lema is an Israel-founded cybersecurity startup building an agentic third-party risk management platform. Its software combines forensic analysis of vendor artifacts, open-source reconnaissance, and monitoring of real vendor access and data relationships to identify supply-chain risks that questionnaire-led programs can miss.
Visit WebsiteCompany Overview
Lema sells an agentic third-party risk management and supply-chain security platform for security, risk, procurement, and compliance teams. Its stated thesis is that a vendor can satisfy a questionnaire and still expose an organization through a vulnerable product, excessive permissions, risky data flows, or changes in public commitments. The platform is organized around three capabilities: forensic AI assessment of vendor documents and security artifacts; open-source reconnaissance across public technical, legal, and security information; and blast-radius monitoring of how a third party connects to an organization's assets, data, identities, and business processes. The Agentic Risk Engineer framing is important because it describes an investigation workflow, not just a language-model chat interface: Lema aims to correlate evidence, validate vendor claims, surface a concrete threat scenario, and recommend remediation.
The product addresses a real operational gap in conventional TPRM. Static questionnaires and security ratings are useful for intake and reporting but can be slow, dependent on vendor assertions, and weak at representing the customer's actual exposure. Lema's public integration catalog shows a practical enterprise deployment model: it can ingest cloud-security findings from Wiz, identity and permission data from Okta, Microsoft Entra ID, and Google Workspace, application activity from Netskope, procurement records from tools such as Ramp, Zip, Vendr, Asana, and OneTrust, and route findings into Jira or ServiceNow. The commercial value proposition is faster vendor review, continuous detection of scope drift, and better prioritization of remediation. Public customer testimonials on Lema's site describe time savings and an increase in the number of vendors actively monitored, but those statements are marketing evidence rather than independently audited performance data.
Lema operates in a crowded market that includes security-rating providers, questionnaire and GRC platforms, vendor-risk specialists, and broader ITSM suites. SecurityScorecard, BitSight, UpGuard, Panorays, Whistic, OneTrust, ServiceNow, and AuditBoard represent relevant competitors or substitutes, although they do not all offer the same combination of technical evidence, relationship mapping, and agentic investigation. Lema's differentiation is therefore a product and execution claim that must be tested in diligence: whether its agents discover material risks that incumbent workflows miss, whether findings are reproducible and evidence-backed, and whether integrations provide enough context to model actual blast radius rather than simply produce another vendor score. The company says it is not a generic GRC or security-ratings product, which sharpens its positioning but also concentrates the burden of proving a distinct category.
Public reporting provides meaningful but limited commercialization signals. Calcalist reported in February 2026 that Lema raised a $17.5 million Series A led by Team8 after an approximately $6.5 million seed led by F2 Venture Capital with Salesforce Ventures participating. The same report described a team of about 35 people, with offices in New York and Israel, and stated that the platform analyzes supplier activity, sensitive-asset access, data movement, and permission changes. Lema's own website names co-founders Eddie Dovzhik, Tomer Roizman, and Omer Yehudai and displays customer references including Klaviyo, SCI, Well Health, OPENLANE, AlphaSense, Cresta, and Delta Dental. These are useful traction signals, but the database should not infer revenue, retention, certification, contract size, or broad product-market fit from them. The company remains an early-stage private startup scaling product, sales, integrations, and trust infrastructure.
The strategic and dual-use case is credible but indirect. Third-party compromise is a shared problem for enterprises, critical infrastructure operators, and government organizations, and a system that maps supplier access, detects scope drift, validates security evidence, and produces actionable remediation can strengthen cyber resilience in those environments. The same technology could support defense supply-chain assurance, contractor risk review, and protection of sensitive data dependencies, subject to procurement, data-residency, and deployment constraints. There is no public evidence here of defense customers or government contracts, so the relevance should be treated as capability adjacency rather than demonstrated defense adoption. The central diligence questions are model reliability, false-positive and false-negative rates, evidence provenance, handling of sensitive vendor and identity data, customer willingness to connect privileged systems, and whether the company can sustain accurate monitoring as the vendor graph changes.
Dual-Use Assessment
Lema's core capability has substantive commercial and security applicability because supplier compromise, excessive third-party permissions, data leakage, and software supply-chain exposure affect enterprises, critical infrastructure, and government organizations alike. The defense relevance is indirect: the platform could support contractor and supply-chain assurance, but no public evidence confirms defense deployment or government contracts. Its dual-use value therefore rests on the underlying risk-analysis and relationship-monitoring capability, not on an established military customer base.
Strategic Fit Assessment
Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.
Lema is a credible strategic-priority signal within a dual-use cybersecurity database because it targets a large and increasingly consequential attack surface: external vendors and software dependencies. The February 2026 Series A, named founders, public product surface, integration breadth, and customer references indicate meaningful early validation. the diligence case is not established by funding alone; diligence should establish recurring revenue quality, deployment depth, renewal behavior, measurable discovery advantage over ratings and questionnaire tools, and gross-margin implications of agentic analysis. The company remains high risk because it must earn trust for sensitive integrations and defend a differentiated position against both specialist TPRM vendors and platform incumbents.
Strategic Value to U.S.-Israel Alliance
Lema could improve cyber resilience by turning third-party risk from periodic compliance collection into continuous, technically grounded exposure analysis. Its strongest strategic value is the ability to connect vendor evidence with the customer's real asset, identity, data, and procurement context, then translate findings into remediation actions. That is relevant to enterprises and potentially to critical-infrastructure or defense supply chains where a contractor's compromise can create outsized downstream exposure. The value is conditional on secure data handling, explainable findings, deployment flexibility, and proof that its monitoring catches material risks without overwhelming analysts.
Key Technologies
- Agentic investigation and risk-engineering workflows
- Forensic analysis of vendor security, privacy, and compliance artifacts
- Open-source reconnaissance and continuous public-footprint monitoring
- Third-party access, data-flow, and permission graph mapping
- Blast-radius and scope-drift monitoring
- Cloud, identity, procurement, and ITSM integrations
- Evidence-backed remediation recommendations
Use Cases & Applications
- Continuous third-party risk assessment beyond questionnaire responses
- Forensic review of vendor penetration tests, trust-center material, contracts, and policies
- Monitoring vendor access to production assets, identities, and sensitive data
- Detecting supplier permission expansion, shadow applications, and scope drift
- Prioritizing remediation for procurement and TPRM teams
- Automating Jira or ServiceNow workflows from vendor-risk findings
- Supply-chain assurance for critical-infrastructure and government contractors
- Assessing AI vendors for data-use, subprocessor, and source-code exposure
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.
This record lists 6 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- lema.ai Public source used for profile verification.
- lema.ai Public source used for profile verification.
- lema.ai Public source used for profile verification.
- lema.ai Public source used for profile verification.
- calcalistech.com Public source used for profile verification.
- team8.vc Public source used for profile verification.
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Investor Lens
What this entry is
Private startup
Why it may matter
Lema may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.
How an independent investor should read this
Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.
Evidence to verify
- Verify current status
- Verify traction
- Verify cap table/funding
- Verify technical claims
- Verify regulatory/export-control issues
- Verify customer concentration
Main investor questions
- Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
- What customer, revenue, product, and technical evidence supports the company story?
- What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
- Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
- What evidence would change the thesis or show that the profile is stale?
What not to infer
- Inclusion does not imply endorsement.
- Inclusion does not imply allocation availability or current fundraising.
- Scores do not indicate investment suitability or expected returns.
- Strategic importance does not automatically imply venture return potential.
Diligence questions
- What evidence verifies Lema's current customer traction, deployment status, and revenue concentration?
- Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
- Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
- How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
- What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.
Related companies
Need a diligence readout?
Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.