Neosec

Cybersecurity Dual-Use Technology Founded 2020

Neosec was an Israeli API security startup that developed a SaaS platform for discovering, analyzing, and securing APIs by applying behavioral analytics and XDR principles to API traffic, enabling organizations to detect API abuse, business logic attacks, and data leakage.

Visit Website

Company Overview

Neosec built a cloud-based API security platform that treated APIs as an attack surface requiring behavioral analysis rather than traditional perimeter defenses. The platform automatically discovered all APIs in an organization's environment (including shadow and undocumented APIs), profiled normal API usage patterns, and applied behavioral analytics to detect anomalous activity—including business logic abuse, credential stuffing, data scraping, and API-specific attacks that signature-based WAFs cannot catch.

Commercially, Neosec competed in the rapidly growing API security market alongside Salt Security, Noname Security, and Traceable AI. Founded in 2020 in Herzliya by Giora Engel (CEO, co-founder of LightCyber, which was acquired by Palo Alto Networks for $105M) and Ziv Sivan (CTO), the company raised $20.7M from investors including TLV Partners, New Era Capital Partners, and TRUE Ventures. In April 2023, Akamai Technologies acquired Neosec to bolster its API security capabilities within the Akamai Connected Cloud platform.

From a defense and national security perspective, API security is critical as military and government systems increasingly rely on API-connected architectures for cloud services, inter-agency data sharing, and mobile applications. The ability to discover, monitor, and protect APIs from abuse directly supports defense digital transformation and zero trust initiatives.

Dual-Use Assessment

API security is critical for protecting military and government API-connected systems, including cloud services, inter-agency data sharing, and defense mobile applications. Behavioral analytics for API abuse detection supports zero trust architecture for defense digital transformation.

Key Technologies

  • Automated API discovery and inventory (including shadow APIs)
  • API behavioral analytics and anomaly detection
  • Business logic attack detection for API abuse
  • XDR-inspired approach applied to API traffic analysis
  • API data leakage and sensitive data exposure detection
  • SaaS-based API security with agentless deployment

Use Cases & Applications

  • Enterprise API discovery and shadow API identification
  • API abuse detection via behavioral analytics
  • Business logic attack prevention for API-driven applications
  • API data leakage and PII exposure monitoring
  • Defense API security for cloud and inter-agency systems (dual-use)
  • Military zero trust API protection (dual-use)

Strategic Value to U.S.-Israel Alliance

API security is essential as defense systems transition to API-connected cloud architectures. Behavioral analytics for API abuse detection addresses a blind spot in traditional WAF/gateway-based defense network security.

Interested in this startup?

Learn more about our investment approach or get in touch to discuss opportunities in dual-use technology.