Dossier · Private startup · 4 independent sources

Pluto Security

Cybersecurity Dual-Use Technology Priority Signal Founded 2025

Last updated: Sep 1, 2026

Pluto Security is a Tel Aviv-founded cybersecurity startup building an AI Workspace Security Platform for the software, workflows, agents, and connected tools that employees create with AI. Its agentless visibility, risk understanding, and real-time governance model is intended to let organizations support AI-driven building without either blocking innovation or accepting unmanaged exposure.

Visit Website

Company Overview

**Product and the concrete problem it solves.** Pluto Security is addressing a security gap created when software creation moves outside the traditional engineering workflow. Its public materials describe a world in which employees in engineering, marketing, sales, IT, and other functions can use AI builders, browser-based development environments, no-code tools, and autonomous agents to create applications, automations, workflows, and customer-facing experiences. Those artifacts can reach production systems, sensitive data, and external users without passing through a conventional software-development lifecycle, security review, secrets-management process, or access-control design. Pluto's product thesis is that CISOs should not have to choose between blocking these tools and allowing them without supervision. The company presents its AI Workspace Security Platform as a control layer that gives security teams visibility into what is being built, an understanding of the associated risk, and real-time guardrails that can enforce policy while work is happening. The concrete buyer problem is therefore not simply whether an employee used an AI assistant; it is whether the organization knows which AI builders and agents exist, what artifacts they produced, which extensions or connectors they rely on, what permissions they can reach, and how to enable useful work without creating a new ungoverned application estate.

**Core technology and how it actually works.** Pluto's public documentation is deliberately product-level rather than an engineering white paper, so the precise implementation of its discovery, risk scoring, and enforcement logic is not disclosed. The official and Israeli export-ecosystem descriptions do establish an architecture centered on agentless visibility and automated governance. The monitored surface includes AI builders such as Lovable, Cursor, Replit, and n8n; the artifacts those tools create; MCP servers and connectors; AI browsers; IDE extensions; browser extensions; and the broader workspace around them. Agentless operation is strategically important because the relevant activity often occurs in browser sessions, third-party SaaS workspaces, local developer tools, and business-user workflows where installing and maintaining a conventional endpoint agent may be difficult or politically costly. Pluto says it connects to existing security and infrastructure systems rather than requiring the organization to replace its current stack, then applies contextual risk understanding and guardrails to creation workflows. The public record does not confirm whether discovery relies on identity-provider telemetry, browser or SaaS APIs, endpoint signals, network controls, direct integrations, or a combination of these methods. It also does not disclose the model architecture, policy language, latency, action granularity, or false-positive controls. Those unknowns are material: a security product that merely inventories approved tools is less valuable than one that reliably links a builder to its generated artifact, permissions, dependencies, and runtime exposure, while a product that blocks legitimate work too aggressively will drive users toward shadow workarounds.

**Market, customers, and go-to-market.** Pluto sells into the emerging overlap of AI security, application governance, endpoint visibility, software supply-chain risk, and identity or access control. The natural economic buyer is a CISO or security leader responsible for allowing generative-AI adoption across an enterprise, with adjacent stakeholders in IT, application security, engineering, data protection, compliance, and business-unit operations. The product can be positioned as an additive control layer because its stated purpose is to govern workflows that conventional security programs do not fully see, rather than to replace every EDR, DLP, IAM, or cloud-security investment. Startupim describes the business model as B2B subscription SaaS and reports a Tel Aviv-Yafo headquarters, which is consistent with a software-led enterprise motion. Pluto's own site emphasizes integration and invites organizations to bring their existing tools into the platform, suggesting that frictionless deployment and broad connector coverage are central to the go-to-market strategy. The likely path is design-partner-led enterprise selling: identify uncontrolled AI-building activity, demonstrate the exposure in a customer environment, establish policy guardrails, and expand from a small security team deployment into broader workspace governance. No named paying customers, annual recurring revenue, renewal data, deployment count, or contract values are publicly disclosed. Until those metrics appear, the market case should be framed as a credible and fast-growing security need rather than proven product-market fit.

**Traction, funding, and third-party validation.** Pluto has unusually strong ecosystem visibility for a company that remains early and private, but its public evidence is mostly qualitative. The official website says the company is backed by security and cloud ecosystems and is part of accelerator programs including AWS, CrowdStrike, and NVIDIA. The Israel Innovation Summit at RSA lists Pluto as an endpoint-security exhibitor and gives a concrete description of its visibility and governance coverage across AI builders, artifacts, MCPs, AI browsers, IDE extensions, and browser extensions; it also identifies Tal Ofer Regev as CPO and co-founder. Startupim reports a seed round led by TLV Partners with participation from Ariel Maislos in 2025, while leaving the amount undisclosed. That report also identifies Pluto Security Ltd. and presents Tel Aviv-Yafo as the headquarters; its page contains inconsistent founding metadata, listing 2022 in one header and August 2025 in its detailed Q&A and Israeli-company registry section. The safer conclusion is that the operating venture was publicly formed in 2025 and that the Israeli legal entity was incorporated on 31 August 2025, while the earlier date may reflect preliminary formation or directory error. Forbes Israel's December 2025 interview with Shahar Bahat provides independent validation of the problem urgency: she describes AI-generated applications reaching production, accessing sensitive systems, and bypassing secrets management, access control, and logging. These sources validate a real problem, a live company, an identifiable product thesis, and early investor or ecosystem support; they do not validate revenue scale, customer retention, benchmark efficacy, or production outcomes.

**Founders and team background.** The strongest public evidence concerns the founding team's security and product provenance. Shahar Bahat is identified by Forbes Israel as a Pluto co-founder and is described as a former Unit 8200 operator and product leader at Microsoft and at earlier startups. Her public framing of the market is specific: business users are becoming software builders, and security teams need contextual guidance and guardrails rather than blanket blocking. Gil Maman is identified by the SANS Institute as Pluto's CTO and co-founder. SANS reports that Maman spent more than six years in Israeli Military Intelligence in technical leadership roles spanning advanced cyber R&D and operational security engineering; it also describes earlier work as a founding engineer, engineering roles at eBay involving machine learning systems, security tooling, and OSINT-oriented tools, and academic research in static analysis, software integrity, and OSINT methods. He holds a BSc in Computer Science and an MBA from Tel Aviv University. The Israel Innovation Summit identifies Tal Ofer Regev as CPO and co-founder, while Startupim likewise lists Bahat and Regev as co-founders. Pluto's own about page summarizes the broader team as coming from Unit 8200, Microsoft, and Palo Alto Networks, but does not map each background to a named executive. This combination is well matched to a product that sits between cyber defense, developer tooling, and human behavior. It is not proof that the team has solved the harder scaling questions: the current headcount, engineering depth, customer-success capacity, and experience taking an agentless platform through large regulated deployments are not publicly quantified.

**Competitive dynamics.** Pluto enters a crowded market, but its exact category is still forming. Microsoft Defender for Endpoint, Intune, Defender for Cloud Apps, and Entra can bundle endpoint, identity, application, and SaaS governance into existing enterprise agreements. CrowdStrike and SentinelOne have installed endpoint agents, security telemetry, and partner ecosystems that could be extended toward AI-builder monitoring. Palo Alto Networks can approach the problem through Prisma Cloud, Cortex, browser security, and AI-security products, while Cisco AI Defense and Lakera compete around the policy, inspection, and runtime-governance layers of enterprise AI. Israeli companies such as Prompt Security and Noma Security pursue adjacent AI-use and AI-application controls, and application-security vendors can extend from code, dependency, or runtime analysis into the artifacts created by AI tools. Pluto's potential differentiation is not a new cryptographic primitive; it is the combination of an agentless discovery surface, an AI-builder-specific inventory, risk interpretation for artifacts and surrounding extensions or MCPs, and enforcement designed for non-developer workflows. The product may be easier to adopt than an endpoint replacement if it genuinely connects to tools that existing controls miss. The potential edges are: (1) seeing AI creation as a workspace and supply-chain problem rather than only a prompt or model problem; (2) translating technical findings into guardrails that business users can understand; (3) covering the surrounding ecosystem of extensions, connectors, and agents; and (4) using integration rather than rip-and-replace as the first enterprise wedge. Those edges remain hypotheses until Pluto publishes connector breadth, policy precision, time-to-value, independent evaluations, and evidence that customers keep the controls enabled after the initial AI-risk audit.

**Defense, security, and resilience dual-use relevance.** Pluto's dual-use case is credible through cyber-resilience and software assurance, not through a disclosed weapons or military product. Defense ministries, government agencies, defense contractors, hospitals, banks, utilities, and other critical operators are all beginning to let non-specialists use AI systems to write code, create automations, query sensitive data, or connect services. An unmanaged AI-built application can expose credentials, create unauthorized integrations, expand lateral-movement paths, or become an opaque dependency in a mission-support workflow. A visibility and governance layer that identifies these builders and artifacts could help a security team distinguish approved experimentation from a production-relevant risk, require review for sensitive actions, constrain dangerous connectors, and preserve an audit trail for software that never entered a conventional CI/CD pipeline. That is strategically relevant to allied digital sovereignty because defense and resilience increasingly depend on the integrity of software assembled from commercial AI tools and third-party components. The calibration is important. Pluto does not publicly claim a defense contract, classified deployment, government authorization, or critical-infrastructure customer. It has not disclosed disconnected or sovereign deployment, secure update procedures, data-residency controls, endpoint behavior under degraded connectivity, or compliance beyond the trust badges displayed on its site. A defense buyer would also require assurance that the guardrail layer cannot itself become a privileged control-plane attack surface. Pluto should therefore be classified as a commercial cyber-resilience capability with meaningful defense adjacency, not as a fielded defense technology.

**Growth stage, trajectory, and key diligence risks.** Pluto is best classified as early. The company appears to have been incorporated in Israel in 2025, reports a seed financing with undisclosed terms, remains small in public ecosystem profiles, and has only recently established a visible product and thought-leadership footprint. Its trajectory could be attractive if AI-built software becomes a permanent enterprise governance category rather than a temporary policy concern. The expansion path is coherent: start with agentless discovery of AI builders and their ecosystem, add contextual risk scoring and safe defaults, then move toward artifact review, least-privilege enforcement, continuous monitoring, and governance for autonomous agents operating in sensitive environments. The principal diligence questions are: (1) whether Pluto can discover activity without invasive agents or fragile integrations; (2) how accurately it maps a user, builder, artifact, connector, permission, and downstream data path; (3) whether policy actions are explainable and safe enough for production; (4) how it handles browser-based and local tools that change rapidly; (5) whether customers will pay for a distinct platform while Microsoft and larger security vendors bundle adjacent controls; (6) whether the founders can build enterprise distribution and support beyond early Israeli ecosystem access; and (7) whether the company can demonstrate operation in regulated, sovereign, or disconnected environments. Additional risk comes from sparse disclosure: the public record does not establish funding size, headcount, named customers, revenue, retention, product benchmarks, patent filings, or the exact division of responsibilities among the founders. The key milestones to track are named reference customers, a published integration catalog, measured reduction in shadow AI exposure, safe enforcement case studies, audited security posture, and a government or defense-industrial evaluation.

Dual-Use Assessment

Military & Commercial Applications

Pluto's core capability has credible commercial and strategic cyber-resilience applicability because the same AI builders, agents, extensions, connectors, and generated artifacts used by ordinary enterprises are increasingly entering defense-industrial, government, healthcare, financial, energy, and other critical environments. Agentless inventory and governance could help security teams discover unmanaged software creation, constrain sensitive integrations, and preserve control over applications that bypass conventional development pipelines. The defense relevance is capability-based and prospective: no public source reviewed here confirms a defense contract, classified deployment, government authorization, or critical-infrastructure customer. Restricted-network operation, data minimization, secure updates, policy safety, and integration with government security operations would need separate validation.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

Pluto is a high-upside, high-uncertainty cyber priority signal rather than a recommendation to invest. (1) It targets a sharply defined problem: AI and no-code tools let non-developers create software and agents outside the security workflows built for professional engineering teams. (2) Its proposed wedge is differentiated enough to merit diligence because it combines agentless workspace discovery, visibility into artifacts and surrounding MCP or extension ecosystems, and real-time governance rather than treating AI security as only model filtering or prompt inspection. (3) The team has credible security and product provenance through Unit 8200, Microsoft, Palo Alto Networks, Israeli Military Intelligence, eBay, and earlier startup-building experience. (4) Early ecosystem signals include AWS, CrowdStrike, and NVIDIA accelerator affiliation, an Israel Innovation Summit at RSA exhibit, and a reported seed round led by TLV Partners. The constraints are equally important: the financing amount, customer names, revenue, retention, headcount, implementation details, and independent efficacy data are not public. The market is exposed to fast incumbent bundling from Microsoft, CrowdStrike, Palo Alto Networks, and Cisco, while the product may face a difficult trust boundary if its controls can block legitimate business work. Diligence should focus on deployment evidence, integration durability, policy precision, privacy posture, and whether the company can turn visibility into measurable reductions in risky AI-built software.

Strategic Value to U.S.-Israel Alliance

Pluto's strategic value is concentrated in governance for a new software-production layer. (1) Control-plane value: if AI-built applications and agents become normal enterprise infrastructure, the organization needs a way to know what exists and which actions are permitted before those artifacts become embedded in business or mission workflows. (2) Resilience value: agentless discovery can potentially expose software and integrations that conventional asset inventories, CI/CD controls, and endpoint telemetry miss. (3) Allied-technology value: an Israeli cyber company operating at the boundary of AI adoption and security governance could become relevant to defense suppliers and public-sector organizations seeking trusted controls for commercial AI tools. (4) Human-factor value: enabling rather than blanket-blocking may reduce shadow adoption and the insecure workarounds caused by rigid policy. The strategic case remains option value, not demonstrated national capability. There is no public evidence of a defense deployment, sovereign installation, classified-network operation, or government accreditation, and the product's technical enforcement model is not sufficiently disclosed to assess robustness in high-consequence environments.

Key Technologies

  • Agentless discovery of AI builders, developer tools, no-code platforms, and autonomous agents across enterprise workspaces
  • AI-workspace asset graph covering generated applications, workflows, artifacts, MCP servers, connectors, IDE extensions, AI browsers, and browser extensions
  • Contextual risk understanding for AI-created software and the permissions, data access, integrations, and dependencies around it
  • Real-time policy guardrails and automated governance for AI-building activity
  • Integration layer connecting existing security and infrastructure systems without requiring a rip-and-replace endpoint deployment
  • Human-oriented security guidance designed to enable non-developer builders while preserving CISO oversight

Use Cases & Applications

  • Discovering employee-built AI applications and workflows that bypass conventional CI/CD and application-security review
  • Governing Cursor, Lovable, Replit, n8n, and similar AI or no-code builders across engineering and business teams
  • Reviewing and constraining MCP servers, connectors, IDE extensions, browser extensions, and AI-browser integrations
  • Preventing AI-generated applications from reaching sensitive production systems without required controls
  • Monitoring AI-built automations in financial-services, healthcare, and regulated enterprise environments
  • Supporting software-supply-chain and shadow-AI risk programs for defense contractors and critical-infrastructure operators
  • Giving CISOs auditable guardrails that enable safe experimentation instead of blocking organization-wide AI adoption

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.

This record lists 7 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

  • Pluto Security homepage Verifies the canonical website, AI Workspace Security Platform positioning, the problem of every endpoint becoming an AI workspace, the enablement-versus-blocking thesis, supported builder examples, and the company's active 2026 product and technical-publication footprint.
  • Pluto Security About Us Verifies the company's mission, visibility and risk-understanding positioning, real-time guardrails, stated team provenance from Unit 8200, Microsoft, and Palo Alto Networks, and stated AWS, CrowdStrike, and NVIDIA accelerator ecosystem affiliation.
  • Pluto Security at the Israel Innovation Summit at RSA Verifies the Israeli ecosystem listing, endpoint-security category, agentless visibility and automated governance across AI builders, artifacts, MCPs, AI browsers, IDE extensions, and browser extensions, plus Tal Ofer Regev as CPO and co-founder.
  • Gil Maman profile, SANS Institute Verifies Gil Maman's role as Pluto CTO and co-founder, more than six years in Israeli Military Intelligence, technical cyber leadership, eBay engineering experience, software-integrity and OSINT research, and Tel Aviv University degrees.
  • The New Security Frontier of AI-Driven Creation, Forbes Israel Verifies Shahar Bahat as Pluto co-founder, her Unit 8200 and Microsoft product background, the problem of non-developers creating production software with AI, and risks involving sensitive data, secrets, access control, logging, and unauthorized integrations.
  • Pluto Security company profile and funding report, Startupim Reports Pluto Security's Tel Aviv-Yafo location, B2B subscription SaaS model, 2025 seed round led by TLV Partners with Ariel Maislos participation, undisclosed funding amount, named co-founders, small early-stage profile, and the Israeli legal-entity incorporation date reported in its registry section.
  • Pluto Security LinkedIn company profile Provides a current company profile and public team signal, including Pluto's AI-workspace security positioning and the identification of Shahar Bahat and Gil Maman as co-founders.
  • Profile update timestamp Last updated in the Claw & Talon database on Sep 1, 2026.

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.