Dossier · Private startup · 1 independent source

Nagomi Security

Cybersecurity Dual-Use Technology Priority Signal Founded 2023

Last updated: Jul 31, 2026

Nagomi Security is a private cybersecurity startup developing an Agentic Exposure Operations platform that correlates security-tool data, investigates exploitable exposure paths, coordinates remediation, and continuously verifies that fixes remain effective.

Visit Website

Company Overview

Nagomi Security began as Vena Security and emerged from stealth in April 2024 with a Proactive Defense Platform. Its current product narrative has evolved into Agentic Exposure Operations: a closed-loop layer over the customer’s existing security stack. The platform uses read-only API connections to normalize and correlate asset, vulnerability, misconfiguration, identity, attack-surface, endpoint, network, and threat-intelligence signals. Nagomi’s stated workflow is always-on discovery, contextual investigation, targeted neutralization, and validated closure. In practical terms, the product is intended to decide which combinations of findings represent an exploitable exposure, identify the relevant owner and remediation path, and check again when the environment or defensive controls change.

The customer problem is credible and specific. Large security teams already own scanners, cloud-security products, endpoint detection, identity controls, ticketing, and configuration systems, but those products often produce disconnected findings. Nagomi is positioned between vulnerability management, attack-surface and exposure management, security-control assessment, and workflow automation. Its differentiation claim is that it does not stop at a risk list or a closed ticket: the Exposure Lens provides normalized context, while its agents investigate attack paths, account for compensating controls, route work, and re-open cases when drift or a failed control creates exposure again. The company’s integration catalog covers categories including vulnerability management, CSPM, EDR, IAM, network, OT/IoT, email security, device management, CMDB, ticketing, and threat intelligence, which supports an overlay strategy rather than a rip-and-replace sale.

Commercial evidence is encouraging but incomplete. Nagomi publicly announced $30 million in total funding, including a $23 million Series A led by TCV with participation from CrowdStrike Falcon Fund, Okta Ventures, and Team8, after a Team8 seed round. Its official site publishes customer quotes and case-study material involving organizations such as Topsoe, Applied, and WELL Health Technologies, and in 2026 announced product expansion, new executives, and a claim of 9x growth. These are useful traction signals, but they are company-controlled disclosures rather than audited performance evidence. Open sources do not establish recurring revenue, retention, deployment count, gross margin, or the share of customers using autonomous remediation. Diligence should test whether the value comes from durable data normalization and control-efficacy logic or from services-heavy implementation, and whether customers renew after the initial exposure-baselining project.

Competition is intense. Tenable, Rapid7, Qualys, XM Cyber, Bitsight, Wiz, Palo Alto Networks, CrowdStrike, and other platform vendors can cover pieces of exposure management, attack-path analysis, cloud posture, endpoint telemetry, or remediation orchestration. Larger vendors benefit from distribution, installed data, and bundling; specialist vendors may offer deeper analysis in one exposure domain. Nagomi’s potential edge is the breadth and quality of its cross-tool correlation, its focus on verified outcome rather than dashboard inventory, and a workflow that can preserve customers’ existing controls. That edge will matter only if integrations remain accurate under schema changes, agents can explain recommendations, false-positive rates are low, and closure verification is trusted by both security operators and infrastructure owners.

The national-security and defense-adjacent case is credible at the cybersecurity infrastructure level, not as proof of defense procurement. Continuous control assessment, attack-path prioritization, identity and asset context, and evidence-backed remediation are relevant to government, defense-industrial, critical-infrastructure, healthcare, and financial environments where a static vulnerability count is an inadequate measure of operational risk. The platform could help such organizations maintain a current view of whether defensive controls actually protect mission-critical assets. However, public materials reviewed here do not demonstrate classified deployment, FedRAMP or equivalent authorization, government contracts, or operation inside restricted networks. Strategic relevance therefore depends on security architecture, data residency, deployment isolation, auditability, and the company’s ability to serve high-assurance buyers without overstating commercial references as defense traction.

Dual-Use Assessment

Military & Commercial Applications

Nagomi’s core capability—correlating security telemetry, assessing control effectiveness, prioritizing exploitable exposure paths, and verifying remediation—has substantive commercial and defense-security applicability. It can support assurance for mission-critical and regulated environments, but no public evidence reviewed here confirms classified deployment, government contracting, or authorization for restricted workloads.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

Nagomi is a credible early-stage strategic-priority signal for a dual-use cybersecurity database, not an investment recommendation. The company addresses a persistent enterprise problem—turning fragmented findings into verified exposure reduction—and has disclosed substantial institutional backing, a named leadership team, a 72-person workforce, customer references, and continued product expansion. The principal diligence question is whether its correlation, control-assessment, and agentic workflow capabilities create durable retention and measurable customer outcomes before larger security suites absorb the category.

Strategic Value to U.S.-Israel Alliance

Nagomi could provide strategic value as an execution and assurance layer for security programs that already have many controls but cannot prove which ones protect which assets. Its relevance to national-security-adjacent environments comes from continuous evidence about exposure and control performance, potentially improving cyber readiness across complex enterprise or critical-infrastructure estates. That value is conditional on secure architecture, explainability, audit trails, data-governance controls, and evidence of operating in high-assurance environments.

Key Technologies

  • Cross-source exposure graph and asset normalization across vulnerability, identity, endpoint, cloud, network, and threat signals
  • Read-only API integration layer for vulnerability scanners, CSPM, EDR, IAM, CMDB, ticketing, and threat-intelligence systems
  • Attack-path and toxic-combination analysis that evaluates exploitability, reachability, asset criticality, and compensating controls
  • Automated security-control assessment mapped to threat behavior and defensive coverage
  • Agentic investigation and remediation orchestration with human authorization for consequential actions
  • Continuous post-remediation verification for control drift, configuration regression, and exposure reopening

Use Cases & Applications

  • Continuous threat exposure management for enterprises with fragmented security tooling
  • Risk-based replacement or augmentation of vulnerability-management triage using exploitability and business context
  • Continuous assessment of identity, endpoint, cloud, and network controls against relevant attack techniques
  • Remediation ownership, ticket routing, and evidence-backed closure for security and infrastructure teams
  • Board and executive reporting on exposure reduction, control coverage, and unresolved attack paths
  • Security assurance for regulated financial, healthcare, manufacturing, and SaaS environments
  • Cyber posture monitoring for critical-infrastructure and defense-industrial organizations, subject to deployment and authorization requirements

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.

This record lists 8 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.