Onyx Security

Cybersecurity Dual-Use Technology Priority Signal Founded 2024

Last updated: May 25, 2026

AI-native cyber provider building a secure control plane for enterprise AI agents with visibility, policy enforcement, and real-time intervention across SaaS, cloud, endpoints, and code environments.

Visit Website

Company Overview

Onyx Security is a 2024-founded startup with operational presence in Tel Aviv and New York that positions itself around a single urgent enterprise problem: AI systems are shifting from assistive tools to autonomous actors, but security control surfaces were still designed for humans and traditional software workflows. The company argues this produces a structural governance gap when agents can trigger actions, access production systems, integrate into APIs, and modify data flows with limited oversight. Its public positioning frames the core thesis as infrastructure-level control for this new operational paradigm, rather than another threat feed, endpoint add-on, or narrow policy product. The company says its mission is to help security, governance, and infrastructure teams govern AI agents with consistent guardrails while preserving adoption speed, which is a meaningful distinction in modern enterprise AI programs where risk and velocity are often in direct tension.

At the product level, Onyx describes a supervisory platform that continuously discovers active AI agents and tracks their reasoning steps, then enforces policies before and as actions execute. This is more akin to a control-plane layer than a perimeter-only security appliance: the system is marketed as a single surface spanning security, compliance, and engineering operations in one policy workflow. Public statements repeatedly emphasize three recurring functions: visibility into AI agent activity, policy governance across tool and data access boundaries, and runtime intervention when risky behavior is detected. Public materials also show a focus on cost, latency, and operational governance for AI deployments, indicating a design that blends assurance with manageability for production teams managing hundreds or thousands of agents across departments.

The technology stack appears centered on agent observability and intervention mechanics rather than only retrospective auditing. Messaging in the launch materials and follow-up coverage describes proprietary supervisory agents and models designed to classify agent behavior, reason about context, and respond in real time with approvals, corrections, or blocks. That model matters because it aligns with how AI systems are now used: code-generation workers in engineering, support copilots in customer operations, and autonomous workflows in operations tooling can all create similar policy and containment questions but at different risk levels. In this sense, Onyx’s approach is less about a single application and more about a normalization layer for AI-native controls, which is strategically different from classic SIEM, zero-trust, or identity tooling that does not deeply treat agents as first-class operational principals.

Commercially, Onyx’s stated value proposition is a practical one: enterprises need a mechanism to move AI from pilot to scale without losing auditability. Sources describing the launch indicate demand for this capability in teams that are already deploying enterprise AI widely but are now seeing policy sprawl, inconsistent approval patterns, and uneven tool-level governance. The company cites customers across sectors and says teams in security, governance, and infrastructure can use one shared system to avoid each function inventing separate controls. For strategic readers, this is not only a product claim but a workflow claim: if true, Onyx can reduce process friction and create a standard operating model for what used to be fragmented shadow AI governance. That can increase defensibility in highly regulated domains where one operational model must satisfy multiple risk owners.

The company’s strategic relevance is strongest in dual-use and resilience contexts because the same controls problem appears in defense-adjacent environments: mission systems increasingly integrate AI functions that can interpret, decide, and act; critical infrastructure teams inherit similar risks around unauthorized actions, policy drift, and model-enabled mis-sequencing; and resilience planning now requires real-time evidence of what autonomous systems did and why. A platform that centralizes visibility and intervention offers defensive value in both commercial and security-sensitive settings, even though it is not itself a direct weapon system. This dual-use profile is therefore in the defensive and governance layer rather than in offensive capability. The launch coverage also points to founders with cyber and AI-military-adjacent backgrounds, reinforcing operational credibility for high-assurance environments where attack surface expansion and policy interpretation are inseparable.

Early traction signals are mainly launch-stage but with meaningful strategic positioning. Funding coverage in March 2026 indicates substantial seed-and-Series-A-backed capital to scale product and hiring, with reported 70+ employees across Israel, the United States, and Canada soon after launch. In this part of the AI-control category, early revenue validation and customer depth are still developing compared with incumbents in adjacent cybersecurity categories, so the execution risk is less about concept fit and more about whether policy control abstractions stay tractable as models, tools, and runtime integrations evolve monthly. Another key risk is that AI governance as an emerging category can look clear at product demo level but lose clarity under enterprise integration pressures, especially where policy semantics differ by workload, data sensitivity, and regulatory context.

Competitively, Onyx is entering a market where adjacent players have stronger install bases, but many are still adapting older architectures to agent-native workflows. That can be a disadvantage for incumbents and an opportunity for a category-native platform, yet it also creates pressure on Onyx to demonstrate durable integrational advantage and not only strong messaging. Its potential strength is speed of policy orchestration for practical business units, while a likely challenge is proving model-level security decisions are explainable enough for regulated organizations that demand deterministic audit trails and clear incident attribution. If the execution holds, Onyx can become a reference-layer platform for enterprises trying to operationalize AI in mission-critical workflows; if not, it risks being displaced by tighter bundles from larger vendors.

Diligence questions that remain open include model-level transparency, integration latency under high-volume agent workloads, and the governance burden of policy automation itself. The enterprise risk is not only whether one can block unsafe actions, but whether one can prove that the control layer itself remains robust when AI tooling evolves and attackers test edge-case prompts, tool-chain abuse, or policy bypass patterns. It is also important to verify whether Onyx’s controls map cleanly to specific national and sectoral standards in long-term deployments, especially for critical infrastructure teams where false positives, control drift, and rollout fatigue can be as damaging as cyber breaches. Those are standard resilience controls questions, but they become materially sharper when AI agents are treated as operational staff.

Dual-Use Assessment

Military & Commercial Applications

The core mission is to govern autonomous AI agents with security, compliance, and policy controls. That is directly relevant to defense-adjacent and resilience-sensitive environments where AI is embedded in operations, but the dual-use is defensive and governance-focused rather than mission-actuating. The same control model could improve oversight in critical infrastructure and government workflows if deployed with strict regime-specific assurance.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

Onyx targets a real budget category: secure AI operationalization. Its thesis is not speculative AI novelty but infrastructure for enterprise control, so traction can become measurable through reduced incident response ambiguity and clearer governance workflows. This is strategically relevant for defense-linked resilience programs because AI is no longer isolated to test environments. The principal diligence point is execution speed across integrations and policy explainability under adverse conditions, not product-market mismatch.

Strategic Value to U.S.-Israel Alliance

The startup is relevant to national-security-adjacent and critical-infrastructure ecosystems because it can standardize how autonomous software systems are governed, observed, and contained. Commercially, it addresses a category in which many organizations already face governance pain and fragmented tooling. Strategic value improves if Onyx can convert conceptual governance into durable controls, measurable policy outcomes, and regulator-facing evidence for enterprises using AI in sensitive domains.

Key Technologies

  • AI agent discovery and runtime inventory
  • Supervisory AI models for behavioral reasoning and intervention
  • Policy enforcement for enterprise AI workflows
  • Cross-surface AI observability across SaaS, cloud, endpoints, and code
  • Runtime control layer for approval, block, and correction actions
  • AI governance and compliance reporting
  • Agent-specific risk scoring and posture management

Use Cases & Applications

  • Enterprise AI safety governance for engineering copilots and autonomous DevOps assistants
  • Customer support automation with policy controls over data access and action scope
  • Financial and government operations where AI agent actions must be auditable
  • Critical infrastructure readiness checks for AI-assisted operational workflows
  • AI program governance across regulated teams that share the same stack
  • MCP and tool integration control for production AI assistants
  • Incident detection and policy remediation for prompt-driven attacks on AI agents
  • Cost and performance governance for high-volume AI automation programs

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Investor Lens

What this entry is

Private startup

Why it may matter

Onyx Security may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.

How an independent investor should read this

Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.

Evidence to verify

  • Verify current status
  • Verify traction
  • Verify cap table/funding
  • Verify technical claims
  • Verify regulatory/export-control issues
  • Verify customer concentration

Main investor questions

  • Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
  • What customer, revenue, product, and technical evidence supports the company story?
  • What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
  • Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
  • What evidence would change the thesis or show that the profile is stale?

What not to infer

  • Inclusion does not imply endorsement.
  • Inclusion does not imply allocation availability or current fundraising.
  • Scores do not indicate investment suitability or expected returns.
  • Strategic importance does not automatically imply venture return potential.

Diligence questions

  • What evidence verifies Onyx Security's current customer traction, deployment status, and revenue concentration?
  • Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
  • Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
  • How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
  • What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.

Need a diligence readout?

Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.