Ox Security
Last updated: Jul 31, 2026
Ox Security provides a code-to-runtime application and software supply-chain security platform that connects code, dependencies, CI/CD, cloud, APIs, and runtime context to prioritize exploitable risk and secure AI-assisted development.
Visit WebsiteCompany Overview
Ox Security is an Israeli-founded application security company established in 2021 by Neatsun Ziv and Lior Arzi. Its core proposition is to reduce the operational gap between the volume of findings produced by modern AppSec tooling and the much smaller set of issues that are reachable, exploitable, and consequential to a particular business. The platform correlates signals across source code, open-source dependencies, build pipelines, infrastructure-as-code, cloud resources, APIs, containers, and runtime behavior. That code-to-cloud lineage is intended to give security teams a more useful answer than a severity score alone: where a risk originated, whether it can actually be reached, what is exposed, and which remediation action is likely to reduce real attack surface.
The current product direction extends beyond conventional post-generation scanning. OX Code covers application security workflows including SAST, software composition analysis, secrets detection, and related lifecycle checks. OX Cloud adds cloud posture, infrastructure-as-code, runtime, API exposure, and source-to-runtime mapping capabilities. The company also markets OX VibeSec for AI-assisted coding workflows, using organizational context and policy signals to identify or prevent risky generated code, dependencies, and agent interactions closer to the point of creation. Its software supply-chain materials describe SBOM and provenance-oriented outputs, while the company positions its autonomous agentic pentesting capability as a way to test whether identified weaknesses can be exploited and connect findings back to source.
The customer problem is credible and commercially important. Enterprises have accumulated overlapping scanners and security controls while development teams increasingly ship code through cloud-native pipelines and AI coding assistants. The resulting backlog creates a prioritization and remediation bottleneck for AppSec, product security, and cloud security teams. OX says it serves more than 200 customers and supports more than 120 native integrations; these are company-reported traction indicators rather than independently audited operating metrics. Gartner Peer Insights lists the company in the application security posture management category and reports a 51-200 employee range. In May 2025, Ox announced a $60 million Series B led by DTCP, bringing the company-reported total raised to $94 million, with participation from IBM Ventures, Microsoft, Swisscom Ventures, Evolution Equity Partners, and Team8. These signals indicate a venture-backed growth company with meaningful commercialization, although retention, recurring revenue quality, deployment depth, and customer concentration remain diligence questions.
Competitive pressure is substantial. Ox competes with integrated AppSec and cloud-security platforms as well as specialist SAST, SCA, ASPM, CNAPP, and automated testing vendors. Its differentiator is not simply another scanner; it is the attempted synthesis of context, lineage, prioritization, and prevention across the software lifecycle. That advantage will depend on the quality of its integrations, asset and dependency graph, exploitability models, remediation accuracy, and ability to prove fewer material incidents or less engineering time. Larger vendors can bundle adjacent controls, while focused competitors may offer deeper analysis in one workflow. OX VibeSec is strategically timely because AI-generated code and agent-driven development create new supply-chain and governance questions, but the category is still developing and claims about preventing vulnerabilities at generation time require technical and customer validation.
The defense and national-security case is credible but indirect. Military, intelligence, and critical-infrastructure organizations increasingly depend on complex software supply chains, cloud services, APIs, and developer tooling; reducing exploitable exposure in those pipelines can improve resilience. OX could be relevant to secure development environments, defense contractors, mission software, and regulated operators, including settings where scarce security personnel need high-confidence triage. However, there is no evidence in the reviewed sources of a defense contract, classified deployment, or specialized air-gapped product. The dual-use thesis should therefore be treated as an adjacency based on the technology and customer problem, not as demonstrated defense traction.
Dual-Use Assessment
Ox Security's core code-to-runtime security and software-supply-chain capabilities have substantive commercial and security-sector applicability. The same lineage, prioritization, IaC, API, runtime, and AI-code controls can help defense contractors and critical-infrastructure operators reduce exploitable exposure in complex development pipelines. The relevance is indirect: public sources reviewed here do not establish defense contracts, classified deployments, or air-gapped-specific functionality, so the defense case should be validated through customer and deployment diligence rather than assumed.
Strategic Fit Assessment
Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.
Ox Security is a private, independent startup with a clearly defined enterprise AppSec problem, a broadened code-to-runtime product, reported traction of 200+ customers and 120+ integrations, and a reported $60 million Series B in 2025. Its strategic fit comes from software supply-chain integrity, AI-development security, and risk prioritization rather than from a proven defense sales channel. The principal diligence work is to verify net retention, recurring revenue, gross margins, deployment and remediation outcomes, data-handling boundaries, model and graph quality, and differentiation against bundled security platforms. The flag reflects internal strategic relevance, not an investment recommendation.
Strategic Value to U.S.-Israel Alliance
Ox Security could help organizations that build sensitive software focus limited security capacity on risks with a credible path to exploitation. Its cross-lifecycle mapping is relevant to defense and critical-infrastructure supply chains where a vulnerability in source code, a build artifact, an API, or a cloud configuration may only become meaningful in combination with other context. VibeSec also addresses governance of AI-assisted development, an emerging supply-chain concern. Strategic value remains conditional on proving deployment in constrained environments, integration with existing identity and CI/CD controls, data residency and telemetry options, and reliable operation without weakening developer velocity.
Key Technologies
- Code-to-runtime application and software-supply-chain risk graph
- Contextual exploitability, reachability, and business-impact prioritization
- SAST, software composition analysis, secrets detection, and dependency analysis
- AI-assisted coding security and agent policy controls through OX VibeSec
- Cloud security posture, infrastructure-as-code, API exposure, and runtime mapping
- SBOM, provenance, PBOM, attestation, and pipeline-integrity tracking
- Automated agentic penetration testing with source-linked findings
Use Cases & Applications
- Reduce enterprise AppSec backlog by ranking reachable and exploitable findings
- Trace production cloud and API exposure back to source, dependency, or pipeline changes
- Govern AI-generated code, dependencies, MCP integrations, and coding-agent workflows
- Validate software supply-chain provenance, SBOMs, build integrity, and deployment changes
- Scan Terraform and other infrastructure-as-code before cloud deployment
- Coordinate application, cloud, and product-security remediation in one workflow
- Harden defense-contractor and critical-infrastructure software development pipelines, subject to deployment validation
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.
This record lists 9 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- ox.security Public source used for profile verification.
- ox.security Public source used for profile verification.
- ox.security Public source used for profile verification.
- ox.security Public source used for profile verification.
- ox.security Public source used for profile verification.
- LinkedIn company page Public source used for profile verification.
- gartner.com Public source used for profile verification.
- techcrunch.com Public source used for profile verification.
- Official website
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Investor Lens
What this entry is
Private startup
Why it may matter
Ox Security may matter as a Cybersecurity entry with direct private-company diligence for Israeli technology research.
How an independent investor should read this
Direct private-company diligence. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.
Evidence to verify
- Verify current status
- Verify traction
- Verify cap table/funding
- Verify technical claims
- Verify regulatory/export-control issues
- Verify customer concentration
Main investor questions
- Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
- What customer, revenue, product, and technical evidence supports the company story?
- What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
- Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
- What evidence would change the thesis or show that the profile is stale?
What not to infer
- Inclusion does not imply endorsement.
- Inclusion does not imply allocation availability or current fundraising.
- Scores do not indicate investment suitability or expected returns.
- Strategic importance does not automatically imply venture return potential.
Diligence questions
- What evidence verifies Ox Security's current customer traction, deployment status, and revenue concentration?
- Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
- Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
- How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
- What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.
Related companies
Need a diligence readout?
Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.