Dossier · Private startup · 0 independent sources

Sweet Security

Cybersecurity Dual-Use Technology Priority Signal Founded 2022

Last updated: Jul 31, 2026

Sweet Security provides a runtime-first CNAPP and AI-security platform that correlates cloud, workload, identity, application, and AI activity to detect, investigate, and contain threats in production.

Visit Website

Company Overview

Sweet Security is building a runtime-first cloud security platform for applications, workloads, infrastructure, identities, APIs, and AI systems. Its stated product surface combines cloud visibility and posture management with runtime event collection, vulnerability management, identity threat detection and response, cloud application detection and response, and API security. The important architectural claim is that these controls are connected through live execution context: processes, file access, network traffic, memory use, cloud IAM events, policy changes, API activity, and relationships between identities and workloads. That can make a finding more operationally useful than an isolated configuration or vulnerability alert, because analysts can see what is actually executing, what access it used, and how an incident moved across layers.

The company also positions AI security as an extension of the same runtime model rather than as a completely separate governance product. Its public materials describe discovery of models, agents, LLM servers, and AI services; analysis of agent behavior; detection of prompt-injection and other adversarial activity; posture assessment; and guardrails that can block disallowed actions. SweetX and newer investigation-oriented capabilities are described as AI assistants that correlate signals, build incident narratives, and let responders search or reason over cloud and runtime events. These claims are strategically relevant, but buyers should distinguish product demonstrations and vendor-reported outcomes from independently validated efficacy, especially for fast-changing agentic attack techniques.

Sweet sells into a crowded and consolidating CNAPP market. Likely buyers include CISOs, cloud-security and DevSecOps teams, application-security groups, and SOC or incident-response teams that are trying to reduce tool sprawl and shorten the time from detection to containment. The company says its platform integrates with operational systems such as Slack, Jira, ServiceNow, webhooks, and SOAR tooling, and its site reports major reductions in investigation time for teams using the product. Those are useful commercialization signals, alongside the November 2025 announcement of a $75 million Series B led by Evolution Equity Partners and the company-reported expansion of enterprise customers and ARR. They remain self-reported signals: the public record does not establish customer retention, net revenue retention, gross margins, deployment friction, or whether the reported performance generalizes across environments.

Competitive pressure is substantial. Sweet must differentiate against broad platforms from Wiz, Palo Alto Networks, CrowdStrike, Microsoft, and other established security vendors, as well as focused runtime, cloud-detection, identity, API, and AI-security specialists. Its most credible edge is workflow-level correlation of runtime context with posture, identity, application, and AI behavior, potentially allowing a smaller security team to move from alert to attack story to response without stitching together multiple consoles. That edge will be durable only if the telemetry is sufficiently deep, the detections are precise, the agent footprint and cloud integrations are acceptable, and customers can quantify reduced investigation time or loss exposure.

The dual-use case is substantive but should be described as applicability, not evidence of defense adoption. Runtime monitoring, identity and workload analysis, attack-path reconstruction, automated containment, and AI guardrails are relevant to government clouds, defense contractors, critical infrastructure operators, and other mission-critical systems. Sweet's June 2026 announcement of a U.S. federal-market expansion and pursuit of FedRAMP Moderate authorization is a meaningful go-to-market signal, but it is not an authorization or a government contract. Strategic diligence should therefore focus on security architecture, data residency, product isolation, audit readiness, integration with existing SOC and cloud controls, and the company's ability to support high-assurance environments while scaling internationally.

Dual-Use Assessment

Military & Commercial Applications

Sweet's core runtime telemetry, identity and workload detection, incident investigation, automated containment, and AI guardrails have substantive commercial and public-sector applicability. They could support government, defense-contractor, critical-infrastructure, and other high-assurance cloud environments, although public evidence here demonstrates market pursuit rather than confirmed defense adoption.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

Sweet is a credible strategic-priority signal for a dual-use security database because it has a concrete runtime thesis, an expanding AI-security surface, disclosed Series B financing, and an announced federal-market and FedRAMP-readiness effort. The case depends on diligence rather than the funding headline: establish independent customer references, retention and expansion economics, detection precision, deployment overhead, data-handling controls, and whether runtime correlation produces durable advantage against larger CNAPP platforms.

Strategic Value to U.S.-Israel Alliance

Sweet could provide strategic value as a security-control layer for production cloud and AI systems, where runtime evidence can improve detection, investigation, least-privilege decisions, and containment. Its federal-market push increases relevance to public-sector modernization, but the current public evidence supports applicability and go-to-market intent, not confirmed government deployment or FedRAMP authorization.

Key Technologies

  • Runtime collection of process, file, network, memory, cloud IAM, and API events
  • Cross-layer correlation of cloud, workload, application, identity, and infrastructure signals
  • Behavior baselining, deviation analysis, IOC/TTP detection, and MITRE ATT&CK classification
  • LLM-driven detection and incident narrative generation
  • AI-agent discovery, behavior monitoring, prompt-injection detection, and runtime guardrails
  • Cloud Application Detection and Response with automated process termination and SOAR integrations
  • Identity entitlement analysis linking granted permissions to permissions used at runtime

Use Cases & Applications

  • Detecting anomalous cloud IAM activity, workload behavior, API calls, and lateral movement in production
  • Building a chronological attack story for SOC and incident-response investigations
  • Reducing alert noise by correlating runtime context with posture, vulnerability, and identity findings
  • Finding stale or overprivileged service accounts by comparing granted and observed permissions
  • Discovering shadow AI, mapping agents and LLM services, and enforcing policies on agent actions
  • Blocking malicious processes or disallowed AI behavior and handing containment actions to SOAR workflows
  • Monitoring regulated, government, defense-contractor, or critical-infrastructure workloads after cloud migration

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.

This record lists 6 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.