Dossier · Private startup · 3 independent sources
Native Security
Last updated: Jul 31, 2026
Native Security is an Israeli cloud security startup that turns built-in provider controls into enforceable, secure-by-design architecture across multi-cloud environments. The company focuses on preventing configuration drift and making policy enforcement proactive rather than detective.
Visit WebsiteCompany Overview
Native Security is a cloud-security control-plane startup focused on turning capabilities already built into AWS, Azure, Google Cloud, and Oracle Cloud Infrastructure into active, enforceable defenses. Its central thesis is that cloud customers do not primarily lack security primitives; they lack a practical way to express an outcome once and operationalize it consistently across provider-specific control models. The public product message is therefore architecture-first: define an outcome such as keeping regulated data off public paths, then translate it into identity, network, perimeter, segmentation, and baseline controls that are enforced at the cloud-provider layer. This places Native closer to policy execution and secure-by-design infrastructure than to a conventional alerting dashboard.
The platform's differentiating workflow is the translation layer between security intent and implementation. Native says customers can express intent in natural language, align one security architecture across four clouds, and establish guardrails for cloud-service adoption, data perimeters, compliance, and AI engineering. Its AI-related positioning is especially relevant: the company frames the model an application calls, the data it can reach, and the actions an agent can take as architectural decisions rather than permissions that should be handled only at the application layer. Public materials also describe perimeter, segmentation, baseline-protection, and blast-radius-containment concepts. These claims establish a credible technical direction, but diligence should still test the breadth of supported controls, generated-policy correctness, preview quality, rollback behavior, and the operational boundary between Native's API access and customer data.
The customer problem is credible and commercially important. Multi-cloud teams must repeatedly translate similar security requirements into different organization policies, service controls, network constructs, and identity conditions; provider releases add further complexity. A control plane that reduces manual translation and keeps approved architecture aligned as environments change could lower remediation toil and make secure cloud adoption less dependent on scarce specialists. Native's public site cites support for all four providers and a Fortune 500 media-and-entertainment customer testimonial; its July 2026 Cyera integration article gives a concrete example of turning sensitive-data classification into an enforced perimeter. Those are useful commercialization signals, but they do not by themselves establish recurring revenue, retention, deployment scale, or a broad reference base. The company emerged from stealth in March 2026 with reported total funding of $42 million, including a $31 million Series A, and a reported launch team of 41 across Tel Aviv and the United States.
Native was founded in 2024 by Amit Megiddo, Gal Ordo, and Eyal Faingold, according to the company's about page and launch coverage. Investor and company materials emphasize prior cloud-security experience, including AWS-related work, which is relevant to the product's provider-native thesis. The market remains difficult: Wiz, Palo Alto Networks Prisma Cloud, Orca Security, Lacework, Aqua Security, cloud-provider policy services, and infrastructure-as-code tooling all compete for parts of the same security and platform-engineering budget. Native's proposed wedge is that it operationalizes controls rather than merely finding issues, but that wedge must survive feature convergence and prove that customers will buy a new control layer instead of extending existing CNAPP, CSPM, or cloud-native tooling.
The defense and national-security relevance is substantive but should be stated as applicability, not as proof of defense adoption. Provider-native enforcement can help government, defense-industrial, and critical-infrastructure operators constrain public exposure, segment environments, limit AI-agent reach, preserve least privilege, and control high-impact changes in cloud estates. It can also support resilience when teams operate across multiple providers or need auditable, repeatable policy changes. The open strategic questions are whether Native can satisfy sovereignty, procurement, assurance, and disconnected-environment requirements; whether its controls remain useful in hybrid or on-premises architectures; and whether it can demonstrate measurable reduction in attack paths and drift. Its Israeli base, cloud-security specialization, early funding, and architecture-level thesis justify continued strategic tracking, while the absence of independently verified scale metrics warrants medium risk rather than a fully mature rating.
Dual-Use Assessment
Native Security's core technology is credibly dual-use because provider-native cloud policy enforcement applies to both commercial enterprise estates and defense/security/resilience contexts. The same architecture that prevents public access to regulated data, limits lateral movement, enforces segmentation, and reduces configuration drift in a Fortune 500 cloud environment also maps directly to government, defense-contractor, and critical-infrastructure workloads where least privilege, auditability, and safe change control are essential.
Strategic Fit Assessment
Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.
Native Security is a credible strategic-priority signal, not an investment recommendation. The evidence is strongest on product clarity, founder experience, early financing, and a problem that grows with multi-cloud and AI-agent adoption. The main diligence gap is commercialization proof: public materials do not establish recurring revenue, retention, deployment scale, or a durable moat. Its priority case therefore depends on validating policy coverage, production safety, measurable reduction in drift and attack paths, and willingness of enterprise buyers to fund a new control-plane category against CNAPP incumbents and cloud-provider tooling.
Strategic Value to U.S.-Israel Alliance
Native Security has strategic value because it moves cloud defense from finding misconfigurations toward enforcing architecture at the provider layer. That capability is relevant to critical infrastructure, government IT, defense-industrial cloud estates, and AI-enabled systems where public exposure, lateral movement, unsafe agent actions, and uncontrolled changes can have outsized consequences. The strategic thesis is applicability rather than demonstrated defense adoption: diligence should test sovereignty, assurance, procurement, hybrid-cloud, and disconnected-operation requirements before assigning national-security weight.
Key Technologies
- Provider-native cloud control plane
- Natural-language policy intent translation
- Multi-cloud guardrail generation
- Impact simulation before rollout
- Configuration drift detection
- Exception and approval workflows
- Architecture-level segmentation and zoning
Use Cases & Applications
- Enforcing secure-by-design cloud architecture
- Preventing public access to regulated data
- Reducing multi-cloud policy drift
- Simulating the blast radius of cloud policy changes
- Managing least-privilege controls across cloud providers
- Hardening AI workloads and AI service access
- Improving change control for regulated enterprises
- Protecting critical-infrastructure cloud environments
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.
This record lists 7 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- Native Security official website Verifies the canonical company presence, cloud security control-plane positioning, natural-language intent model, four-cloud coverage, architecture enforcement, AI-agent boundaries, and active-defense messaging.
- Native Security about page Verifies the company story, founders, cloud-security background, and investor logos presented by the company.
- Native Security Cyera integration Provides a current public example of mapping sensitive-data classification into an enforced perimeter across AWS, Azure, Google Cloud, and OCI.
- Native Security platform page Verifies the operational model, impact simulation, drift detection, and provider-native enforcement workflow where described.
- Globes: Native emerges from stealth with $42M funding Verifies funding, founders, employee count, and the Tel Aviv / US footprint.
- SecurityWeek: Native exits stealth with $42M Verifies the cloud-security-control-plane approach and the funding/board structure.
- Newswire: Native launches with $42M Verifies the official launch announcement, customer claims, and security-by-design messaging.
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Investor Lens
What this entry is
Private startup
Why it may matter
Native Security may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.
How an independent investor should read this
Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.
Evidence to verify
- Verify current status
- Verify traction
- Verify cap table/funding
- Verify technical claims
- Verify regulatory/export-control issues
- Verify customer concentration
Main investor questions
- Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
- What customer, revenue, product, and technical evidence supports the company story?
- What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
- Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
- What evidence would change the thesis or show that the profile is stale?
What not to infer
- Inclusion does not imply endorsement.
- Inclusion does not imply allocation availability or current fundraising.
- Scores do not indicate investment suitability or expected returns.
- Strategic importance does not automatically imply venture return potential.
Diligence questions
- What evidence verifies Native Security's current customer traction, deployment status, and revenue concentration?
- Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
- Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
- How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
- What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.
Related companies
Need a diligence readout?
Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.