Dossier · Private startup · 3 independent sources
Reclaim Security
Last updated: Aug 31, 2026
Reclaim Security is an Israeli cybersecurity company building an autonomous exposure-remediation platform that identifies exploitable weaknesses, simulates the operational effect of proposed fixes, and applies business-aware security changes without relying on slow ticket-driven patch cycles.
Visit WebsiteCompany Overview
**Product and the concrete problem it solves.** Reclaim Security addresses the last and most operationally difficult step in enterprise defense: closing a known exposure without breaking the business. Modern security programs already generate extensive lists of vulnerabilities, misconfigurations, policy gaps, and weak controls from endpoint, cloud, identity, email, firewall, and security-platform tooling. The bottleneck is deciding which finding is exploitable in the customer’s actual environment, predicting what a change will disrupt, obtaining enough confidence to act, and then implementing the fix across systems that change continuously. The result is a remediation backlog that can remain open for weeks while attackers increasingly automate discovery and exploitation. Reclaim positions its product as an autonomous exposure-remediation layer, not another dashboard. It analyzes exposure, prioritizes the fixes most likely to reduce real attack paths, determines a tailored corrective action, and executes that action with human approval or automation according to the customer’s policy. The company’s public site explicitly frames the goal as eliminating exposure rather than merely managing it, with use cases covering configuration drift, misconfigurations, vulnerability management, ransomware defense, phishing defense, insider risk, and business-email compromise.
**Core technology and how it works.** The technical center of the platform is PIPE, the Productivity Impact Prediction Engine. Reclaim describes PIPE as a simulation engine that predicts how a proposed security change will affect applications, workloads, user productivity, and business processes before deployment. The workflow is therefore simulation-first: the platform scans existing security tools and configurations, maps the observed gaps against real-world attacker techniques, models the likely consequences of candidate changes, and then selects or suggests a remediation that fits the organization’s architecture and business logic. This is materially different from simple severity ranking or faster ticket creation. The company says its system can understand how an attack would traverse a specific environment, evaluate the defenses already in place, and reason about whether a change would block an attack path or create an unacceptable operational side effect. Its continuous adaptive-deployment layer is intended to keep controls aligned as environments evolve. Reclaim also emphasizes integration with an existing security stack rather than replacement of every incumbent tool, listing Microsoft, Apple, CrowdStrike, Axonius, Palo Alto Networks, Jamf, Proofpoint, Google, Jira, Qualys, Imperva, Tanium, and F5 as ecosystem touchpoints. The public record does not disclose the proprietary model architecture, training data, simulation fidelity, or independent benchmark methodology.
**Market, customers, and go-to-market.** Reclaim sells to CISOs, security engineering teams, and IT or operations leaders who own both security posture and business continuity. The immediate buyer pain is strongest in large organizations with many overlapping controls, significant configuration drift, limited security-engineering capacity, and high costs when a well-intended change interrupts revenue or mission operations. The company’s materials point to enterprise and professional-services customers and to optimization of tools already purchased, including Microsoft E3/E5 security, CrowdStrike Falcon, and Palo Alto Cortex environments. That creates a land-and-expand path: begin with a narrow remediation or security-stack optimization project, demonstrate faster closure and fewer manual hours, then extend into additional controls, threat categories, and business units. Reclaim’s public one-pager includes a named customer reference from Itzik Menashe, CISO and Global VP IT at Telit Cinterion, who describes saving weeks of manual work with zero business disruption. The company’s March 2026 funding announcement says early enterprise customers span financial services, healthcare, government, and critical infrastructure, but does not name those accounts or disclose contract values, recurring revenue, retention, deployment counts, or whether each result is independently measured. North America and Europe are the stated expansion markets.
**Traction, funding, and third-party validation.** Reclaim emerged publicly with evidence beyond a concept deck but still with a relatively short operating history. Calcalist reported that the company was founded in 2024, employed about 30 people with roughly 25 in Israel, and raised a $20 million Series A led by Acrew Capital with participation from Ibex Investors and QP Ventures, bringing total funding to $26 million including a prior Seed round. Startup Nation Finder records a slightly different founding date, August 2023, and lists a $6 million June 2024 Seed led by Ibex and QP followed by the March 2026 $20 million Series A; the discrepancy should remain visible in diligence rather than being silently normalized. Reclaim’s own PRNewswire announcement confirms the $26 million total, the Series A syndicate, PIPE, the AI Security Engineer framing, and plans to expand engineering, integrations, and go-to-market across North America and Europe. Its official platform pages provide a coherent product description, a named customer quote, a concrete integration list, and published claims of substantial reductions in manual effort and remediation time. Those are meaningful validation signals, but the strongest performance figures remain company-reported. No independent technical evaluation, government contract, security certification beyond badges displayed on the site, patent portfolio, valuation, ARR, customer count, or audited outcome data was found in the reviewed public sources.
**Founders and team background.** Reclaim’s founding team combines prior Israeli cybersecurity company-building with exposure to large-scale product and security operations. CEO and co-founder Barak Klinghofer previously founded Hexadite, an Israeli autonomous security-orchestration company acquired by Microsoft, giving him direct experience with automated investigation, enterprise security workflows, and an exit into a major platform vendor. Chief Product Officer and co-founder Roy Peretz previously sold WhiteBox Security, according to Calcalist coverage and the company’s public ecosystem profile. The public founding group also includes Yaniv Waksman as VP Engineering and Or Virnik as VP Research. The team’s thesis is shaped by a practical observation: security tools have become effective at producing findings, while the human organization responsible for changing production systems remains slow, risk-sensitive, and fragmented. That experience is relevant to Reclaim’s emphasis on business-aware fixes and simulation before deployment. The company’s small headcount relative to its ambitious integration surface is an asset for focus but a constraint for support, product assurance, regional sales, and safe execution across heterogeneous customer environments. Specific academic credentials, military service details, total engineering composition, and patent ownership are not confirmed in the reviewed public sources.
**Competitive dynamics.** Reclaim operates between exposure-management platforms, vulnerability-remediation automation, security-control optimization, and attack-path analysis. **XM Cyber** models attack paths and prioritizes exposure reduction, but Reclaim differentiates its public positioning around actually executing a business-aware fix. **Pentera** validates exploitable weaknesses through automated security testing and can inform remediation, whereas Reclaim’s central promise is continuous change simulation and control deployment. **Tenable**, **Qualys**, and **Rapid7** own large vulnerability-management datasets and scanning relationships, giving them natural routes into remediation workflows. **Wiz**, **Palo Alto Networks Prisma Cloud**, and **Microsoft Defender for Cloud** can bundle cloud exposure context, identity, workload, and configuration controls into larger security platforms. Reclaim’s plausible edge is the combination of heterogeneous stack optimization, attack-path reasoning, PIPE’s claimed impact prediction, and a closed loop from finding to safe change. That edge is not automatically durable: integrations are expensive to maintain, security platforms can add native remediation, and customers may prefer advisory automation when they do not trust an external system to change production controls. The decisive evidence would be lower change-failure rates, faster verified risk reduction, better coverage across customer architectures, and durable use after the initial proof of value.
**Defense, security, and resilience dual-use relevance.** Reclaim’s dual-use relevance is direct at the defensive-cyber and critical-infrastructure layer, even though no public source establishes a military customer or classified deployment. Defense contractors, government agencies, hospitals, utilities, financial institutions, and communications providers all operate environments in which unclosed exposures can become a mission outage, a ransomware entry point, or a path into sensitive systems. A platform that models business impact before a security change can help those operators reduce attack surface while preserving availability, a central resilience requirement for systems that cannot simply be taken offline for patching. Attack-path prioritization is also useful where the most important question is not how many vulnerabilities exist but which reachable path connects an exposed account, workload, or control plane to a critical asset. The same capability could support defensive operations centers, sovereign networks, emergency services, and defense-industrial supply chains, particularly when scarce cyber engineers must maintain many sites and toolsets. The calibration is important: Reclaim is not a weapons system, does not publicly claim autonomous offensive action, and has not shown operation in disconnected tactical networks, classified environments, or under military accreditation. Its strategic value is therefore cyber-resilience enablement with credible defense-market optionality, not proven fielded defense technology.
**Growth stage, trajectory, and key diligence risks.** Reclaim is best classified as **mid-stage** within a startup database: it has a defined commercial platform, a named customer reference, ecosystem integrations, a Seed and a Series A totaling $26 million, and a reported team of about 30, but it remains early relative to the scale and assurance expected of an autonomous system allowed to modify enterprise security controls. Its trajectory depends on converting the remediation gap into a repeatable category rather than a high-touch consulting workflow. Key diligence points are: (1) verify whether PIPE’s predictions correlate with production outcomes across cloud, endpoint, email, identity, and network changes; (2) measure false-safe and false-dangerous decisions, rollback behavior, and approval controls; (3) separate company-reported resilience and productivity claims from independently referenceable customer results; (4) determine whether Reclaim has durable access to configuration and telemetry data without creating a new privileged attack surface; (5) test integration maintenance, latency, and support economics as the stack expands; (6) assess competition from CNAPP, vulnerability-management, endpoint, and platform vendors that can bundle remediation; and (7) establish recurring revenue, renewal, customer concentration, security attestations, data residency, export-control posture, and government procurement readiness. The upside is a control-plane position that makes existing security spend more effective. The principal risk is that safe autonomous remediation proves too difficult to trust, leaving Reclaim as an expensive recommendation layer in a market increasingly able to copy its workflow.
Dual-Use Assessment
Reclaim’s core capability has credible commercial and defensive-security use because it reduces exploitable exposure while preserving the availability of systems that organizations cannot safely interrupt. (1) Defense contractors, government agencies, hospitals, utilities, financial institutions, and communications operators face the same operational problem: security findings accumulate faster than teams can safely change production controls. Simulation of business impact, attack-path prioritization, controlled approval, and continuous adaptation can improve cyber resilience in those environments. (2) A reduction in reachable attack paths is relevant to ransomware defense, supply-chain continuity, mission-system protection, and recovery readiness, not only to ordinary IT hygiene. (3) The Israeli founding team and the company’s stated customer coverage across government and critical infrastructure make the strategic transfer plausible. The evidence ceiling is clear: no public source reviewed confirms a military customer, classified deployment, tactical-network operation, government contract, defense certification, or independent assessment of PIPE. Reclaim should therefore be treated as a cyber-resilience enabler with defense-market optionality, not as a proven defense supplier or autonomous offensive platform.
Strategic Fit Assessment
Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.
Reclaim Security is a strong strategic-priority signal because it targets the operational gap between discovering a security problem and safely eliminating it. (1) The product thesis is specific: PIPE simulates business impact, attack-path analysis prioritizes what matters, and the platform can move from detection to execution rather than stopping at a recommendation. (2) The company has raised $26M across Seed and Series A rounds, with Acrew Capital, Ibex Investors, and QP Ventures publicly associated with the financing. (3) The founders bring relevant prior exits and experience building autonomous enterprise-security workflows, while a named Telit Cinterion CISO reference supports real-world value claims. (4) The dual-use case is credible because defense-industrial and critical-infrastructure operators need remediation that does not create downtime. Counterweights are material: performance metrics are mostly company-reported, customer breadth and recurring revenue are undisclosed, safe autonomous change is a high-consequence trust problem, and CNAPP, vulnerability-management, endpoint, and security-platform incumbents can bundle adjacent functionality. strategically relevant is a legacy internal priority signal, not an investment recommendation.
Strategic Value to U.S.-Israel Alliance
Reclaim’s strategic value lies in turning cyber defense from a backlog of findings into a continuously managed control loop. (1) The platform potentially improves resilience by reducing the time an exploitable path remains open, while its simulation layer addresses the operational fear that causes security teams to delay fixes. (2) It can make existing security investments more effective by coordinating controls from multiple vendors rather than requiring an organization to replace its stack. (3) For Israeli and allied critical infrastructure, the capability is relevant to maintaining availability during ransomware, supply-chain compromise, and high-tempo threat campaigns when security staff are scarce. (4) A trusted remediation layer could become a valuable interface between human security owners and increasingly automated attackers. Strategic value remains conditional on evidence that PIPE predicts real disruption accurately, that privileges and rollback are secure, and that the product can operate in regulated or sovereign environments without becoming a new concentration point for failure.
Key Technologies
- PIPE Productivity Impact Prediction Engine for simulating operational and business consequences of proposed security changes
- Attack-path analysis that models how real attacker techniques could traverse a specific enterprise environment
- AI-driven exposure analysis across existing endpoint, cloud, identity, email, firewall, and security-control configurations
- Business-aware remediation selection that tailors fixes to application dependencies, workloads, user productivity, and IT architecture
- Continuous adaptive deployment that updates security configurations as business and threat conditions change
- Integration layer for Microsoft, CrowdStrike, Palo Alto Networks, Axonius, Proofpoint, Jira, Qualys, Tanium, F5, and related tools
Use Cases & Applications
- Closing high-risk cloud and endpoint misconfigurations after attack-path and exploitability analysis
- Optimizing Microsoft E3/E5, CrowdStrike Falcon, or Palo Alto Cortex controls without buying a replacement security stack
- Reducing ransomware exposure by simulating and deploying changes across identity, endpoint, email, and network controls
- Automating phishing and business-email-compromise defenses while checking user and workflow disruption before rollout
- Maintaining security-policy consistency and correcting configuration drift across large enterprise environments
- Helping government, healthcare, utility, and defense-industrial operators reduce reachable exposure while preserving mission continuity
- Giving security engineers an approval-gated autonomous remediation workflow instead of manual Jira-ticket execution
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.
This record lists 8 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- Reclaim Security official platform page Verifies the platform’s exposure-analysis, business-aware remediation, continuous-adaptation workflow, PIPE positioning, use cases, named customer quote, and listed integrations.
- Reclaim Security official about page Verifies the company’s remediation-first mission, intelligent exposure analysis, tailored fixes, continuous adaptive deployment, and publicly stated security use cases.
- Reclaim Security funding announcement, PRNewswire Verifies the $26M total funding, $20M Series A led by Acrew Capital with Ibex Investors and QP Ventures, PIPE mechanics, AI Security Engineer positioning, reported customer sectors, and North America/Europe expansion plans.
- Reclaim Security raises $20M Series A, CTech Verifies the March 2026 Series A, total funding, founding team names and prior exits, reported approximately 30-person team, Tel Aviv operating context, product purpose, and the 27-second versus 27-day remediation gap framing.
- Reclaim Security company profile, Startup Nation Finder Verifies the Israeli startup profile, August 2023 founding record, 11–50 employee range, $26M across two rounds, PIPE description, sector classification, and round-level investor data.
- Reclaim Security one-pager, September 2025 Verifies the company’s stated remediation and resilience use cases, automated-work claims, security-stack optimization examples, and the named Telit Cinterion CISO reference.
- Reclaim Security LinkedIn ecosystem reference Provides an additional public company identity and operating-presence reference linked from Startup Nation Finder; used cautiously because public LinkedIn data does not independently verify performance or financing claims.
- Official website
- Profile update timestamp Last updated in the Claw & Talon database on Aug 31, 2026.
Investor Lens
What this entry is
Private startup
Why it may matter
Reclaim Security may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.
How an independent investor should read this
Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.
Evidence to verify
- Verify current status
- Verify traction
- Verify cap table/funding
- Verify technical claims
- Verify regulatory/export-control issues
- Verify customer concentration
Main investor questions
- Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
- What customer, revenue, product, and technical evidence supports the company story?
- What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
- Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
- What evidence would change the thesis or show that the profile is stale?
What not to infer
- Inclusion does not imply endorsement.
- Inclusion does not imply allocation availability or current fundraising.
- Scores do not indicate investment suitability or expected returns.
- Strategic importance does not automatically imply venture return potential.
Diligence questions
- What evidence verifies Reclaim Security's current customer traction, deployment status, and revenue concentration?
- Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
- Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
- How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
- What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.
Related companies
Need a diligence readout?
Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.