Mate Security
Last updated: Jul 31, 2026
Israeli cybersecurity startup building an AI-native security operations platform that uses a Security Context Graph and agentic workflows to investigate, prioritize, respond to, and hunt threats with organizational context.
Visit WebsiteCompany Overview
Mate Security develops an AI-native platform for security operations centers (SOCs). Its central product thesis is that AI agents fail when they receive only human-oriented tables, logs, tickets, and documents without the operational context that experienced analysts carry in memory. Mate's Security Context Graph is intended to connect those sources into a living representation of organizational knowledge, including relationships among users, assets, policies, prior decisions, ownership, and investigative evidence. Agents can then retrieve context, correlate signals across tools, explain verdicts, and, subject to customer controls, take actions such as closing routine cases or escalating complex incidents. The company also describes a Reason Mining Engine and a broader continuous detection/continuous response architecture, but independent technical validation of these proprietary components is not publicly available.
The customer problem is concrete: enterprise SOCs face expanding alert volumes, fragmented security stacks, analyst shortages, and expensive SIEM and data operations. Mate integrates with existing SIEM, EDR, email-security, ticketing, and other security data sources rather than requiring a wholesale replacement of the stack. Its public positioning emphasizes learning an organization's tools, policies, homegrown systems, and prior investigations in hours, reducing repetitive evidence gathering and helping senior analyst knowledge persist. The company claims investigations that once took 45 minutes can take 45 seconds, and its newsroom cites pilots in financial services and critical-infrastructure organizations with reductions in mean time to respond and false positives; these are company-reported claims that require customer references, baseline definitions, and reproducible evaluation before being treated as proven performance.
Commercial evidence is stronger than the previous record indicated. Mate emerged from stealth in November 2025 with a reported $15.5M seed round from Team8 and Insight Partners, was selected for the 2026 CrowdStrike/AWS/NVIDIA cybersecurity accelerator, and announced a $35M Series A led by Canaan Partners in July 2026 with participation from Insight Partners, Team8, and Microsoft's M12. The company says more Fortune 500 organizations are deploying the platform and that growth increased by more than 500% since the third quarter of 2025, but detailed revenue, retention, deployment counts, and independently verified customer outcomes remain undisclosed. Its public materials identify founders Asaf Wiener, Oren Saban, and Guy Pergal, with backgrounds spanning Wiz, Microsoft, Axonius, and Apex; that is a credible domain and product pedigree, not proof of durable execution.
Competition includes incumbent SIEM/SOAR and XDR vendors with distribution, telemetry, and automation advantages, as well as AI-native SOC companies competing on autonomous investigation, response, and threat hunting. Mate's proposed edge is the context layer and institutional-memory model rather than a generic chat interface or a collection of static playbooks. The strategic question is whether that graph produces materially better accuracy, explainability, adaptation, and time-to-value across heterogeneous customer environments, or whether larger platforms can reproduce the capability using their existing data and control planes. Defense and national-security relevance is credible but indirect: military, intelligence, government, and critical-infrastructure SOCs also need high-tempo investigation, analyst augmentation, and resilient knowledge transfer. Public evidence supports a defensive cyber dual-use case, not a claim of defense procurement or operational military deployment.
Dual-Use Assessment
Mate's core defensive SOC automation technology has substantive applicability to military, intelligence, government, and critical-infrastructure cyber defense because those environments also face alert overload, fragmented telemetry, and limited experienced analysts. The public record supports dual-use potential through the nature of the product and critical-infrastructure pilots, but does not establish defense contracts, classified deployment, or military users; the adjacency is therefore credible yet secondary to the enterprise market.
Strategic Fit Assessment
Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.
Mate fits the database's dual-use and deep-cyber thesis: it is an independent Israeli startup, has a technically specific context-first product thesis, and has moved from a $15.5M seed round to a reported $35M Series A in roughly eight months. The founding team brings relevant Wiz, Microsoft, Axonius, and Apex experience, while selection for the CrowdStrike/AWS/NVIDIA accelerator and reported enterprise and critical-infrastructure pilots provide useful validation signals. This remains a diligence priority signal rather than an investment recommendation. The principal questions are whether the Security Context Graph delivers measurable accuracy and autonomy gains, whether customers permit an agent to act on sensitive telemetry, and whether Mate can defend its position against SIEM, XDR, SOAR, and AI-SOC incumbents with much larger distribution and data advantages.
Strategic Value to U.S.-Israel Alliance
Mate could improve cyber resilience by compressing the path from detection to investigation, containment, and documented learning. A context layer that preserves organizational knowledge may reduce dependence on scarce senior analysts and help security teams operate through personnel turnover, surge events, and heterogeneous legacy environments. For defense and national-security users, this could support faster triage and more consistent defensive decisions across mission networks, but public evidence currently demonstrates product-market ambition and enterprise traction rather than government adoption. Strategic value is therefore highest as an enabling layer for defensive cyber operations, not as an offensive capability or a proven national-security program.
Key Technologies
- Security Context Graph linking alerts, assets, identities, policies, tickets, communications, and prior investigative decisions
- Agentic AI workflows for alert investigation, evidence gathering, triage, response, and threat hunting
- Large language models and reasoning models adapted for security operations
- Continuous detection and continuous response with feedback from investigations into detection tuning
- Federated integration across SIEM, EDR, email security, ticketing, cloud, scripts, and homegrown security tools
- Explainable verdicts, confidence signals, guardrails, and human-controlled escalation
- Reason Mining Engine for extracting reusable investigative knowledge from SOC activity
Use Cases & Applications
- Investigating and prioritizing enterprise alerts with organization-specific context
- Automatically gathering evidence and documenting routine incident findings
- Escalating ambiguous or high-impact incidents to analysts with correlated context
- Threat hunting across SIEM, EDR, identity, email, cloud, and custom data sources
- Preserving senior analyst knowledge when personnel change or teams scale
- Continuously improving detections and response procedures from resolved investigations
- Augmenting government, critical-infrastructure, military, or intelligence SOCs facing staffing and alert-volume constraints
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.
This record lists 8 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- mate.security Public source used for profile verification.
- mate.security Public source used for profile verification.
- mate.security Public source used for profile verification.
- mate.security Public source used for profile verification.
- mate.security Public source used for profile verification.
- LinkedIn company page Public source used for profile verification.
- securityweek.com Public source used for profile verification.
- axios.com Public source used for profile verification.
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Investor Lens
What this entry is
Private startup
Why it may matter
Mate Security may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.
How an independent investor should read this
Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.
Evidence to verify
- Verify current status
- Verify traction
- Verify cap table/funding
- Verify technical claims
- Verify regulatory/export-control issues
- Verify customer concentration
Main investor questions
- Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
- What customer, revenue, product, and technical evidence supports the company story?
- What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
- Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
- What evidence would change the thesis or show that the profile is stale?
What not to infer
- Inclusion does not imply endorsement.
- Inclusion does not imply allocation availability or current fundraising.
- Scores do not indicate investment suitability or expected returns.
- Strategic importance does not automatically imply venture return potential.
Diligence questions
- What evidence verifies Mate Security's current customer traction, deployment status, and revenue concentration?
- Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
- Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
- How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
- What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.
Related companies
Need a diligence readout?
Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.