Dossier · Private startup · 2 independent sources
MazeBolt Technologies
Last updated: Sep 1, 2026
MazeBolt Technologies is an Israeli cybersecurity company building RADAR, a patented DDoS vulnerability-management platform that continuously and non-disruptively tests live online services across network, transport, and application layers, then prioritizes remediation before an attack causes damaging downtime.
Visit WebsiteCompany Overview
**Product and the concrete problem it solves.** MazeBolt addresses a specific weakness in the DDoS-defense market: buying a mitigation service or appliance does not prove that the deployed configuration will withstand the attack paths an adversary can use. Online services change constantly as applications, APIs, DNS records, cloud routes, WAF policies, and traffic patterns evolve. A rule can be correct when configured and ineffective after a release, migration, provider change, or new service is exposed. Traditional DDoS penetration testing is periodic, limited in coverage, and often requires a maintenance window because it deliberately generates disruptive traffic. MazeBolt’s RADAR product is positioned as an independent validation layer that continuously tests the protection already in place, identifies misconfigurations and gaps, and provides actionable remediation guidance. The commercial promise is therefore business continuity rather than another mitigation network: a bank, gaming service, government portal, telecom service, or cloud application can obtain ongoing evidence that its existing defenses are working.
**Core technology and how it actually works.** Public MazeBolt material describes a closed workflow of map, test, identify, prioritize, remediate, and validate. RADAR maps public-facing services through IP addresses and fully qualified domain names, tests the layers of the customer’s existing DDoS protection, and runs thousands of nondisruptive attack simulations against known vectors. The company’s documentation describes coverage across Layer 3, Layer 4, and Layer 7, including volumetric, low-and-slow, carpet-bombing, and multi-vector patterns, with examples spanning TCP, UDP, IP, HTTP/S, DNS, NTP, and SIP. Instead of replacing an organization’s CDN, scrubbing provider, WAF, or appliance, the system is designed to sit downstream of those controls and expose what still passes through. It groups findings by risk, recommends changes, and reruns validation to detect recurrence. MazeBolt calls RADAR patented technology and says it can operate on live production services without downtime. Those claims are supported by company technical material, but independent benchmark data, patent numbers, algorithmic detail, false-positive rates, and the exact safety guardrails for simulations are not publicly disclosed.
**Market, customers, and go-to-market.** MazeBolt sells into organizations for which a DDoS outage carries more than a temporary inconvenience: financial institutions, payment providers, cloud and communications providers, online gaming platforms, government services, and other internet-dependent enterprises. The buyer can be a CISO, network-security leader, DDoS-service owner, risk executive, or managed-security provider responsible for proving availability to customers and regulators. The route to market is complementary rather than purely adversarial. RADAR can be introduced through DDoS-mitigation providers, resellers, security consultancies, or direct enterprise sales because it validates and improves protections that customers have already purchased. MazeBolt’s alliance material names Microsoft and multiple security partners, and describes remediation-vendor relationships intended to help customers close identified gaps. Its public customer references include ING Bank Romania, Payoneer, the Government of Israel, and Clal Insurance, while a case study describes a leading European bank with more than 10 million customers and 1,500 branches. The company also publishes industry material for gaming and financial services, suggesting verticalized messaging around uptime and regulatory exposure rather than a generic vulnerability-scanner motion.
**Traction, funding, and third-party validation.** MazeBolt has a longer operating history than a typical newly launched cyber startup. Startup Nation Finder reports an October 2013 founding, a released product, 11–50 employees, and approximately $10.06 million across six funding rounds; it also records an undisclosed July 2026 investment led by CerraCap Ventures. The Jerusalem Post reported a $10 million equity financing in 2022 and identified former NSA general counsel Glenn Gerstell and Imperva co-founder Amichai Shulman as additions to the advisory board. The company’s own customer-facing evidence is unusually concrete for a private cybersecurity vendor: its alliance page carries attributed statements from Payoneer’s chief security officer and an Israeli government IT manager, and its published insurance case study reports that RADAR identified more than 2,800 DDoS vulnerabilities and helped eliminate over 93% of them in less than six months. Those results are company-reported and anonymized, so they should not be treated as independently audited performance. There is no public revenue, renewal, valuation, patent-number, or current financing disclosure. Even so, a decade of continued operation, a released product, named references, partner material, and recurring current activity are stronger signals than a concept-stage record.
**Founders and team background.** Founder and CEO Matthew Andriani is publicly described as a DDoS specialist with more than two decades of cybersecurity experience. MazeBolt’s own biography says he previously held roles at Radware, Check Point, and Corrigon, including leadership of Radware’s Emergency Response Team and Security Operations Center, before founding MazeBolt. That background is directly relevant to the product’s problem: the company is built around the operational reality of stabilizing services during attacks and then converting incident lessons into durable protection, rather than around a purely academic simulation model. Public company profiles also identify co-founder Maxim Derkach and chairman/CFO Martin Gerstel, while Startup Nation Finder lists additional founding participants including Parham Eftekhari, Dr. Paul, and Imperva co-founder Amichai Shulman; the public record is not fully consistent about which early participants remain active. LinkedIn places the company in the 11–50 employee range and lists Ramat Gan as headquarters. The team’s main diligence question is scale: a specialist organization can build unusually deep DDoS know-how, but enterprise expansion requires customer success, safe testing operations, integrations, compliance support, and global channel coverage beyond the founder’s expertise.
**Competitive dynamics.** MazeBolt competes in several overlapping budgets. **Cloudflare** and **Akamai** sell globally distributed DDoS mitigation and edge services, often with the strongest network scale and incumbent customer relationships. **Radware** and **F5** compete with appliances, cloud scrubbing, application delivery, and security controls that can be validated or expanded inside existing enterprise architectures; Radware is also part of Andriani’s prior operating background. **NETSCOUT Arbor** competes in high-volume network protection and service-provider environments. **Catchpoint** and similar availability platforms address monitoring and outage visibility, but generally do not provide MazeBolt’s DDoS-specific control-validation workflow. **SafeBreach**, **Cymulate**, and **AttackIQ** represent the broader breach-and-attack-simulation substitute, while **Picus Security** offers automated validation of security controls across many adversary techniques. MazeBolt’s claimed edge is focus: it tests the entire DDoS attack surface continuously, across the layers and services that a mitigation vendor may not see as one system, without requiring a disruptive red-team window. That focus is useful but contestable. Mitigation vendors can add validation, general BAS platforms can expand into DDoS, and a mature enterprise may prefer a bundled service. Durability depends on proprietary attack knowledge, safe execution, integrations, and proof that its findings prevent outages.
**Defense, security, and resilience dual-use relevance.** MazeBolt’s dual-use case is direct at the resilience layer. The same continuous validation and remediation workflow can protect commercial websites and payment systems, government portals, defense contractors, intelligence-related services, telecom networks, public-safety platforms, and critical-infrastructure operators whose externally reachable systems must remain available during an attack. DDoS can be used for nuisance, extortion, distraction, election interference, or disruption of an essential service, and an organization cannot infer readiness from the presence of a mitigation contract alone. RADAR’s vendor-neutral positioning could help a security team test whether a layered defense still works after a topology or policy change, produce evidence for an auditor or government customer, and prioritize the systems whose outage would affect a mission or public service. MazeBolt’s public references to the Government of Israel and regulated financial institutions make the security relevance more than an abstract possibility, but they do not establish military deployment or classified use. The company does not publicly disclose defense contracts, national-security programs, security clearances, or operation in classified environments. Strategic value should therefore be credited to cyber resilience and availability assurance, not to offensive capability or fielded defense systems.
**Growth stage, trajectory, and key diligence risks.** MazeBolt is best classified as mature within the startup ecosystem but still a private growth-stage company rather than a public-company incumbent. It has operated since 2013, has a released product, maintains an 11–50 employee footprint, reports enterprise and government references, and continues to publish current product and threat material. Its trajectory depends on turning DDoS validation into a standard control requirement and expanding from specialist buyers into channel-led global distribution. The main diligence risks are consequential. (1) **Safety and trust:** nondisruptive simulations against live production systems must have rigorous authorization, throttling, isolation, and rollback controls; an unsafe test could itself cause an outage. (2) **Evidence quality:** the strongest performance numbers are company-reported and anonymized, so independent validation and customer renewal data are needed. (3) **Platform compression:** Cloudflare, Akamai, Radware, F5, and general security-validation vendors can bundle adjacent capabilities. (4) **Market education:** customers may continue to treat a mitigation SLA as sufficient, making the validation category harder to budget. (5) **Scale:** a 11–50 person company must support global time zones, integrations, partner enablement, and regulated procurement. (6) **Disclosure:** current revenue, valuation, financing terms, patent portfolio, exact headcount, and customer concentration remain unclear. (7) **Threat evolution:** AI-assisted attack orchestration and encrypted application-layer traffic may increase the value of continuous testing while also making safe simulation and attribution harder. The company is a credible resilience asset, but future diligence should focus on independently measured reduction in outages and repeatable commercial scale.
Dual-Use Assessment
MazeBolt is credibly dual-use at the cyber-resilience layer because its core product continuously validates DDoS protections for both commercial online services and government, defense-supplier, telecom, and critical-infrastructure networks. The same workflow can test layered controls, expose configuration drift, prioritize remediation, and generate evidence of availability readiness without changing the underlying technology. Public references include Payoneer and the Government of Israel, which support security-sensitive applicability, but the company does not publicly establish military deployment, classified work, defense contracts, or security-clearance posture. The strategic case is therefore defensive continuity and availability assurance, not offensive cyber capability or fielded military systems.
Strategic Fit Assessment
Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.
MazeBolt is a strategic-priority signal, not an investment recommendation. (1) **Problem quality:** DDoS mitigation is widely purchased but rarely validated continuously across the customer’s actual, changing service topology; that creates a concrete resilience gap. (2) **Product specificity:** RADAR is focused on live-production DDoS validation, with a map-test-remediate-validate workflow and coverage across network and application layers. (3) **Evidence:** Startup Nation Finder reports a 2013 founding, released product, 11–50 employees, approximately $10.06M raised, and an undisclosed 2026 CerraCap investment; public company material includes references to Payoneer, ING Bank Romania, the Government of Israel, and Clal Insurance. (4) **Strategic fit:** availability assurance for public-sector, defense-supplier, telecom, and critical-infrastructure services is directly relevant to cyber resilience. Counterweights are material: current revenue and retention are undisclosed, the strongest outcome metrics are company-reported, the category can be compressed into DDoS mitigation or broad BAS platforms, and safe testing of live services creates operational liability. Diligence should prioritize independent customer validation, renewal and expansion evidence, simulation safety controls, patent scope, partner economics, and the ability to scale beyond founder-led specialist expertise.
Strategic Value to U.S.-Israel Alliance
MazeBolt’s strategic value is the conversion of assumed DDoS protection into measurable, repeatable evidence of resilience. That capability can improve the readiness of financial services, public portals, telecom networks, defense suppliers, and critical-infrastructure operators whose outages can create cascading operational and public-safety effects. Its vendor-neutral position is useful because organizations often operate multiple mitigation layers and need to know whether the complete path works, not merely whether a provider is contractually available. The Government of Israel and regulated-enterprise references strengthen the security relevance, while the company’s long operating history and released product reduce early technical-execution risk. The ceiling on strategic value is set by verification: public evidence does not establish classified defense deployment, independent performance testing, current scale, or durable differentiation against mitigation vendors and general security-validation platforms.
Key Technologies
- Continuous non-disruptive DDoS attack simulation on live production services
- Layer 3, Layer 4, and Layer 7 DDoS vulnerability identification
- Coverage of volumetric, low-and-slow, carpet-bombing, and multi-vector attack patterns
- Public-facing service and DDoS attack-surface mapping across IPs and FQDNs
- Risk-based vulnerability prioritization with remediation recommendations
- Post-remediation validation and recurrence monitoring across deployed mitigation layers
- Vendor-neutral integration with existing CDN, WAF, scrubbing, and DDoS mitigation systems
Use Cases & Applications
- Continuous DDoS-readiness validation for banks, payment providers, and online financial services
- Availability assurance for government portals, election-related services, and public-sector websites
- Protection testing for telecom, cloud-service-provider, DNS, and internet-exchange infrastructure
- Always-online multiplayer gaming, esports, and real-time entertainment services
- Defense-contractor and critical-infrastructure internet-facing service resilience
- Post-migration validation after cloud, CDN, WAF, DNS, routing, or network-policy changes
- Managed-security and DDoS-mitigation partner offerings that need independent customer validation
- Audit and board reporting on measurable DDoS exposure, remediation, and continuity readiness
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.
This record lists 9 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- MazeBolt RADAR - Official Product Page Verifies RADAR's continuous DDoS attack simulations, live attack-surface visibility, Layer 3/4/7 coverage, risk prioritization, remediation guidance, and compatibility with existing DDoS protection.
- Test and Validate DDoS Protections on Live Production Services - MazeBolt datasheet Verifies the map-test-identify-prioritize-remediate-validate workflow, public-service mapping by IP and FQDN, continuous testing of deployed protections, and the company's live-production, non-disruptive positioning.
- MazeBolt Technology Alliance Partner Page Verifies partner-oriented deployment, the RADAR remediation ecosystem, and attributed references from ING Bank Romania, Payoneer, the Government of Israel, and Clal Insurance.
- Insurance Company Avoids Damaging DDoS Downtime - MazeBolt case study Verifies the anonymized insurance-company case study, three-data-center deployment, more than 2,800 identified vulnerabilities, reported elimination of over 93% of vulnerabilities, and company-reported reduction of exposure to below 10%.
- MazeBolt LinkedIn Company Profile Verifies the active Israeli company identity, Ramat Gan headquarters, 2013 founding, 11-50 employee range, DDoS-resilience positioning, and current public activity.
- MazeBolt - Startup Nation Finder Verifies the Israeli startup identity, October 2013 founding, released product, 11-50 employees, reported approximately $10.06M across six rounds, the undisclosed July 2026 CerraCap Ventures investment, company number, founders, and business models.
- Cyber Sec startup MazeBolt raises $10m to stop DDoS attacks - The Jerusalem Post Verifies the May 2022 $10M equity financing, MazeBolt's Israeli identity and DDoS focus, RADAR's patented positioning, and advisory additions Glenn Gerstell and Amichai Shulman.
- Matthew Andriani - MazeBolt DDoS resilience biography Verifies founder and CEO Matthew Andriani's DDoS expertise, prior roles at Radware, Check Point, and Corrigon, Radware ERT/SOC leadership, and the company's description of RADAR as patented technology.
- Official website
- Profile update timestamp Last updated in the Claw & Talon database on Sep 1, 2026.
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.