Dossier · Private startup · 4 independent sources
Sun Security
Last updated: Sep 8, 2026
Sun Security is an Israeli cybersecurity startup building a control layer for autonomous AI agents. Its platform discovers agents across workstations, cloud, and SaaS, maps their purpose and access, and checks tool calls, connections, and resource use against policy at runtime.
Visit WebsiteCompany Overview
**Product and the concrete problem.** Sun Security is focused on the security problem that appears when AI software stops merely answering questions and starts acting as an employee with access to business systems. An agent built in Copilot Studio, AWS Bedrock, a coding environment, or an internal workflow can read sensitive records, call APIs, create documents, send messages, alter cloud resources, or hand work to another agent. Traditional security consoles can show that a valid identity made an API call, but they generally do not explain whether the action was consistent with the agent's assigned purpose. Sun's product is intended to close that gap. The company describes a three-part platform: discovery of every agent and agentic tool, posture management that determines what an agent was built to do and what it can reach, and runtime control that checks every tool call, connection, and resource draw before execution. The concrete enterprise outcome is narrower and more useful than generic AI governance: a security team can allow useful automation to run while constraining an agent that drifts, leaks information, reaches across a tenant boundary, or begins using an unapproved tool. The official site illustrates the problem with operational examples such as a cleanup agent scanning production resources, an AWS Bedrock agent returning one patient's results in another patient's chat, a coding assistant spawning a reverse shell from a suggestion, and an agent emailing an entire customer list.
**Core technology and how it actually works.** Public material describes Sun as sitting in the path of agent activity and checking behavior against the agent's purpose rather than relying only on a static inventory or a prompt filter. Its discovery layer is designed to find agentic tools and agents across workstations, cloud services, and SaaS surfaces, including unmanaged or shadow agents. Its posture layer aggregates the agent's instructions, system prompt, tools, data, connections, and observed usage to form an operational picture of intended and actual behavior. At the runtime boundary, the company says that tool calls, connections, and resource access are checked before they execute. The resulting architecture can be understood as an agent-specific policy and observation plane: identify the agent, infer or record its authorized purpose, observe the proposed action and its context, then permit, block, or flag the action according to a defined boundary. Sun's site also presents a business-intelligence graph for agent activity and outcomes, which could give security teams a way to prioritize risk rather than treating every agent as equally dangerous. The exact implementation is not public. The reviewed sources do not disclose the sensor design, whether enforcement uses API mediation, host instrumentation, identity hooks, model-side controls, or a combination, nor do they publish latency, detection precision, or false-positive rates. Those are central diligence questions because an agent-security product must see enough context to make a useful decision without becoming a brittle bottleneck.
**Market, customers, and go-to-market.** Sun is selling into enterprise security, identity, cloud, and AI-platform teams that are being asked to approve agent deployments before the organization understands the inventory or the permission graph. The likely initial wedge is an assessment of an organization's hidden agent population followed by posture management and runtime enforcement for the most privileged workflows. This can support several buying motions: a CISO can use discovery to inventory shadow agents, a cloud or platform team can enforce boundaries around production automation, and an application owner can demonstrate that an agent's behavior is constrained before expanding its access. Sun's official website shows example integrations or agent surfaces including Copilot Studio, AWS Bedrock, Cursor, Claude, and other enterprise tools, but it does not name paying customers. It presents testimonials from an unnamed Fortune 500 enterprise, a public insurance organization, and a public financial-services organization. These are useful signals that the company is speaking with security buyers, while remaining company-published and anonymized. The site claims that teams can get started in five minutes, a positioning choice designed to reduce deployment friction in a fast-moving category. Sun's commercial model appears to be enterprise SaaS. AWS Marketplace lists Sun Platform as an enterprise software product deployed on AWS, with a 12-month enterprise-plan price of $250,000. The public listing does not establish actual bookings or customer count, but it does indicate a concrete procurement route and a product packaged for enterprise purchase.
**Traction, funding, and third-party validation.** Sun has a stronger verification trail than a name appearing only in a conference list, although it remains an early company with limited public operating disclosure. IVC identifies the legal entity as Sun Cyber Security Technologies 2026 Ltd., classifies it as a Seed-stage enterprise-software and infrastructure company, records five employees, and names Matan Yemini as CEO and co-founder and Itay Ovadia as CTO and co-founder. A public Israeli company-registry data source lists the entity as incorporated in January 2026 in Tel Aviv and identifies Yemini and Ovadia as directors. The company's public website is active and presents a defined product architecture, a trust-center section, and customer-facing workflows rather than only a landing-page slogan. AWS Marketplace provides additional third-party distribution evidence: the product is described as an AI Agent Security platform that discovers agents, maps permissions and data access, analyzes execution flows, enforces real-time guardrails, and monitors anomalous activity. The marketplace listing also exposes an enterprise price, although price availability is not proof of sales. Lynx Events publicly described Sun as an early-stage Israeli cybersecurity startup founded in 2026 and said it was contributing open-source research on agentic threats. Sun was also represented in a Team8 CISO community context, according to a public post by co-founder Itay Ovadia. No closed financing amount, named institutional investor, valuation, revenue, customer logo, certification audit report, or independent performance benchmark was confirmed in the reviewed sources. The right conclusion is active venture-backed product formation with a credible market signal, not commercial scale.
**Founders and team background.** The public record identifies Matan Yemini as Sun's co-founder and CEO and Itay Ovadia as its co-founder and CTO. IVC names both executives and places the company in Tel Aviv. A Calcalist conference profile describes Yemini as a software architect and cybersecurity entrepreneur with a background in engineering for F-16 fighter jets, senior R&D leadership experience, and current responsibility for a venture-backed cyber startup. That background is relevant to Sun's target problem because secure agent deployment combines software architecture, operational trust, and failure containment rather than only language-model performance. Ovadia's public professional profile associates him with Sun and with the Team8 CISO community, while public posts show him discussing agent-risk assessment, the difference between risk scoring and execution enforcement, and Sun's presence at security-leader forums. The Israeli company record also confirms that Yemini and Ovadia are the named directors of the 2026 legal entity. The broader team is not publicly documented in the sources reviewed. IVC reports five employees, but there is no disclosed engineering breakdown, senior product leader, government-sales executive, formal advisory board, or biography of additional researchers. That small team can be an advantage when a new category is still being defined, allowing fast iteration with early design partners. It is also a material execution risk: the company will need detection engineering, policy and identity expertise, agent-framework compatibility, cloud operations, privacy controls, and enterprise support as the product moves beyond pilots.
**Competitive dynamics.** Sun competes in a crowded but unsettled AI-security market, where buyers may assemble controls from several existing categories instead of selecting a single agent-security vendor. Zenity and Onyx Security address AI-agent visibility, governance, and security posture; Prompt Security and Lakera focus on protecting enterprise generative-AI interactions and model inputs; Protect AI and HiddenLayer cover machine-learning and model-security lifecycles; Microsoft, AWS, Google, and other cloud providers can bundle agent permissions, logging, identity, and model controls into platforms customers already use. Conventional substitutes include identity governance, API gateways, data-loss prevention, cloud security posture management, sandboxing, and custom policy code around each agent. Sun's claimed differentiation is the combination of agent discovery, purpose-aware posture, and action-level enforcement across workstations, cloud, and SaaS. The product narrative is also intentionally broader than prompt filtering: it attempts to understand what an agent is meant to do and compare that purpose with what the agent actually attempts. The possible competitive edge has four parts: (1) a vendor-neutral control plane across different model providers and agent surfaces; (2) visibility into shadow agents and ungoverned tool sprawl; (3) runtime checks at the execution boundary; and (4) a graph of actions and outcomes that can prioritize operational risk. None is yet a proven moat. Large platform vendors own identity and telemetry, while specialist startups can converge on similar capabilities through different architectures. Sun must show that it catches meaningful violations with low latency, explains decisions to analysts, and can be deployed without forcing customers to rewrite agent workflows.
**Defense, security, and resilience dual-use relevance.** Sun's core technology qualifies as dual-use because the same control problem exists in commercial enterprises and in defense, government, healthcare, utility, and other critical-infrastructure environments. An autonomous agent with permission to query intelligence stores, coordinate logistics, update a network, triage incidents, or operate an industrial workflow can be manipulated through an external document, tool response, compromised connector, or poisoned data source. Discovery and posture management can expose where such agents exist and what they can reach; runtime checks can constrain the action before it becomes a data breach, unsafe configuration change, or unauthorized cross-domain operation. For defense-industrial suppliers and government agencies, the ability to document agent purpose, authorized tools, data boundaries, and intervention decisions could support cyber resilience and accountable automation. Sun's focus on controlling every action is strategically relevant to environments where a valid credential is not enough evidence that a sequence is legitimate. The assessment must remain calibrated. No reviewed source confirms an IDF contract, defense customer, classified deployment, critical-infrastructure installation, FedRAMP authorization, or operation in an air-gapped network. The public evidence is commercial and ecosystem-oriented, with Israeli cyber provenance and an F-16 engineering background supporting a plausible transfer path rather than fielded defense capability. Defense diligence would need to test data residency, disconnected operation, tamper resistance, human approval boundaries, policy provenance, supply-chain controls, incident auditability, and whether runtime enforcement behaves safely when the security layer itself is unavailable.
**Growth stage, trajectory, and key diligence risks.** Sun is classified as early. The legal company was incorporated in January 2026, IVC lists five employees and Seed stage, and the public product presence is recent enough that the company is still building category awareness through CISO events, marketplace distribution, and founder-led technical messaging. At the same time, the product is more concrete than an idea: the official site describes a full discovery-to-runtime workflow, AWS Marketplace provides a deployable product and enterprise price, and the company has public testimonials and ecosystem participation. Its plausible trajectory is to win a narrow deployment with a security-conscious enterprise, prove that visibility and policy enforcement prevent real agent incidents, expand from a few high-value workflows to the organization's entire agent estate, and then move into regulated and sovereign environments. Key diligence risks are: (1) discovery coverage across proprietary and fast-changing agent frameworks; (2) false positives or latency that lead operators to disable enforcement; (3) incomplete context, since agents may take harmful actions through individually permitted calls; (4) platform bundling by Microsoft, AWS, Google, and incumbent security vendors; (5) dependence on evolving standards and connector ecosystems such as MCP; (6) small-team capacity to support high-trust deployments; and (7) absence of public proof on revenue, retention, named customers, independent benchmarks, and defense readiness. Milestones worth tracking are a disclosed paid customer, repeatable blocked-incident evidence, quantified coverage across agent surfaces, formal security attestations, and a government or critical-infrastructure deployment. Sun is strategically interesting because autonomous software is becoming a new privileged computing layer, but its priority should rise only as the public evidence moves from product claims to measured operating outcomes.
Dual-Use Assessment
Sun's agent discovery, purpose-aware posture management, and runtime action enforcement can serve commercial enterprises as well as defense-industrial, government, healthcare, utility, and other critical-infrastructure environments. Autonomous agents in those settings may hold privileged access to sensitive data, operational tools, and production workflows, so a control layer that checks actions before execution has direct cyber-resilience value. The Israeli company identity and founders' security and aerospace background support a credible transfer path into national-security use. The public record does not confirm an IDF or government customer, classified deployment, critical-infrastructure installation, FedRAMP authorization, or air-gapped operation. Dual-use is therefore justified by the core security technology and mission adjacency, not by demonstrated fielded defense capability.
Strategic Fit Assessment
Sun is a priority-signal record for strategic diligence, not an investment recommendation. (1) It targets a specific and accelerating control gap: organizations are deploying agents with access to data and tools before they have reliable inventory or action-level governance. (2) The product spans discovery, posture, and runtime enforcement, which is a more complete operating workflow than a narrow prompt filter. (3) IVC verifies a 2026 Israeli legal entity, Seed stage, five employees, and the Yemini-Ovadia founding team; AWS Marketplace provides a concrete enterprise product and published annual-plan price. (4) Public CISO-community participation and anonymized testimonials indicate active buyer engagement. Counterweights are material: no disclosed financing amount, named customer, revenue, retention, independent benchmark, or defense deployment was confirmed; five employees creates support and execution risk; and Microsoft, AWS, Google, and established security vendors can bundle overlapping controls. The key diligence question is whether Sun's purpose-aware runtime enforcement produces measurable incident prevention without unacceptable latency or false positives.
Strategic Value to U.S.-Israel Alliance
Sun's strategic value is the possibility of becoming a vendor-neutral control point for autonomous software with privileged access. (1) It could make agent adoption safer by showing what exists, what each agent is intended to do, and which actions actually occur. (2) Runtime enforcement addresses a resilience problem that identity logs alone cannot solve: a valid agent can still be manipulated into a harmful sequence. (3) The same control plane can apply to commercial systems, government workflows, defense-industrial networks, hospitals, utilities, and other critical services. (4) A Tel Aviv-based company with a focused AI-security product adds to Israel's cyber innovation base and could become an allied-ecosystem supplier if it develops sovereign and disconnected deployment options. The ceiling is constrained by the absence of public defense traction, formal authorizations, independent results, and evidence that Sun can maintain broad framework coverage as agent architectures change.
Key Technologies
- Cross-surface discovery of AI agents and agentic tools across workstations, cloud services, and SaaS environments
- Agent-purpose and posture graph built from instructions, system prompts, tools, data, connections, and observed usage
- Runtime enforcement of tool calls, connections, and resource access against agent-specific policy boundaries
- Shadow-agent and ungoverned MCP or connector discovery for agent supply-chain visibility
- Behavioral monitoring and action logging for anomalous or non-compliant agent execution
- Business-intelligence graph linking agent activity, actions, outcomes, and operational risk
- AWS-deployed enterprise SaaS packaging with policy controls for autonomous-agent adoption
Use Cases & Applications
- Discovering and governing shadow AI agents deployed across enterprise workstations, cloud accounts, and SaaS applications
- Constraining coding agents that read repositories, process observability data, and execute commands or pull requests
- Protecting customer-support and business-workflow agents that access regulated records and invoke enterprise APIs
- Monitoring AWS Bedrock, Copilot Studio, and other cloud agents that can alter production resources or sensitive data
- Blocking cross-tenant data exposure, unauthorized tool use, anomalous connections, or agent intent drift at runtime
- Providing security evidence for regulated organizations expanding autonomous workflows
- Protecting defense-industrial, government, hospital, utility, and critical-infrastructure automation from agent manipulation
- Establishing auditable human-control boundaries for privileged autonomous software in sovereign or resilience-sensitive environments
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.
This record lists 8 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- Sun Security — Official Website Verifies the company's canonical website, agent discovery, posture management, runtime action controls, supported agent surfaces, anonymized enterprise testimonials, trust-center positioning, and five-minute deployment claim.
- Sun Platform — AWS Marketplace Verifies Sun's enterprise AI-agent security product, discovery, permission and data-access mapping, runtime guardrails, anomaly monitoring, AWS deployment, SaaS delivery, and the listed $250,000 12-month enterprise plan.
- Sun Cyber Security Technologies 2026 Ltd. — IVC Data & Insights Verifies the Israeli legal entity's 2026 establishment, Seed stage, five-employee listing, enterprise software and infrastructure classification, Tel Aviv address, and Matan Yemini and Itay Ovadia as CEO/CTO co-founders.
- Sun Cyber Security Technologies 2026 Ltd. — Company registry record Verifies the active Israeli private-company identity, registration number, January 2026 incorporation date, Tel Aviv address, and Yemini and Ovadia as directors.
- Matan Yemini — Calcalist NXT profile Verifies Yemini's role as CEO of Sun Security, software-architecture and cybersecurity background, engineering work related to F-16 fighter jets, and senior R&D leadership description.
- Sun Security Sponsors AI Security Summit 2026 — Lynx Events LinkedIn Verifies public ecosystem recognition of Sun as an early-stage Israeli cybersecurity startup founded in 2026, its agent-security focus, co-founder Matan Yemini, and stated open-source research activity.
- Itay Ovadia — Team8 CISO community post Verifies Ovadia's public founder activity around AI-agent risk, execution-boundary enforcement, and Sun's engagement with security leaders and the AIVSS community.
- Itay Ovadia — Sun Security and Team8 CISO Summit post Provides supplementary public evidence of Ovadia representing Sun Security at a Team8 CISO Summit and the company's engagement with enterprise security practitioners.
- Profile update timestamp Last updated in the Claw & Talon database on Sep 8, 2026.
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.