Dossier · Private startup · 1 independent source

Tamnoon

Cybersecurity Dual-Use Technology Priority Signal Founded 2022

Last updated: Jul 31, 2026

Tamnoon is an AI-assisted cloud security remediation platform and managed service that turns CNAPP and CSPM findings into prioritized, investigated, production-safe fixes. Its Tami agent combines cloud-context analysis and remediation skills with human CloudPro supervision so security teams can reduce exposure without handing unreviewed changes to an autonomous system.

Visit Website

Company Overview

Tamnoon addresses the operational gap between cloud-security detection and verified remediation. Its platform aggregates findings from existing CNAPP, CSPM, vulnerability, and cloud-provider tools, enriches them with environmental and business context, deduplicates related alerts into initiatives, and prioritizes work using risk, asset criticality, exploitability, and ownership signals. Tami, the company’s AI cloud-security agent, can investigate findings and produce engineering-ready remediation plans. Those plans may include CLI commands, infrastructure-as-code changes, validation scripts, and prevention controls. The current product messaging describes a Remediation Confidence Indicator that separates safer automated paths from risky or data-insufficient cases, with CloudPros available to investigate and supervise higher-impact actions.

The commercial problem is credible and persistent: cloud security teams can buy extensive visibility but still lack the engineering capacity and context needed to close the resulting backlog. Tamnoon sells into security and platform teams operating AWS, Azure, and GCP environments, including organizations that already own a CNAPP and need better outcomes from that investment. Its workflow connects to cloud providers, security platforms, identity and ownership context, ticketing systems such as Jira and ServiceNow, and developer or infrastructure workflows. The value proposition is therefore not another scanner; it is lower effective exposure, faster mean time to remediate, less analyst and developer triage, and evidence that a fix was tested and did not simply reappear on the next scan.

The company has public commercialization signals beyond an early product concept. Tamnoon announced a $12 million Series A in September 2024 led by Bright Pixel Capital, with participation from Blu Ventures, Mindset Ventures, Merlin Ventures, Secret Chord Ventures, Inner Loop Capital, and Elron Ventures; the company said that brought total funding above $18 million. Its own case-study and product materials report reductions in alert backlog, exposure, and remediation time, but these are company-reported outcomes and should be validated by customer references, cohort data, renewal rates, gross margin, and independently reproducible measurement. The hybrid model can create a strong data and workflow learning loop, but it also creates a key execution question: how much of each remediation initiative is truly repeatable software versus expert labor.

Competition comes from several directions. Wiz, Orca Security, Palo Alto Networks Prisma Cloud, CrowdStrike Falcon Cloud Security, and other CNAPP vendors can extend from detection into workflow, prioritization, and remediation, while cloud providers continue to add native policy, posture, and guardrail capabilities. MSSPs and specialist cloud-security consultancies remain substitutes when customers prefer people and projects to another platform. Tamnoon’s potential edge is the combination of multi-tool normalization, remediation-specific context, human-supervised AI, and prevention feedback rather than a single-vendor alert queue. That edge will be durable only if Tamnoon can show safe automation, broad integration coverage, low rework, and materially better outcomes than a customer’s existing CNAPP or internal platform team.

The national-security relevance is real but bounded. Tamnoon does not provide offensive cyber capability, weapons, intelligence collection, or mission-specific defense systems. Its core capability can nevertheless harden cloud-hosted mission-support, defense-industrial, healthcare, financial, and public-sector workloads by reducing exploitable misconfigurations, improving identity and ownership handoffs, and preserving validation evidence. This is dual-use operational resilience, not proof of defense contracts or classified deployment. Strategic diligence should therefore focus on deployment boundaries, privileged-access design, data residency, support for regulated or isolated environments, auditability of AI-generated changes, and whether the company can meet procurement and assurance requirements outside ordinary commercial cloud estates.

Dual-Use Assessment

Military & Commercial Applications

Tamnoon’s core remediation and cloud-posture workflow has substantive commercial and defense-adjacent applicability: the same risk prioritization, identity/ownership context, IaC-aware fixes, validation, and prevention controls can reduce exploitable exposure in enterprise and mission-support cloud environments. The relevance is defensive and operational rather than offensive. Public evidence supports a cloud-security business and reported commercial customers, not defense contracts, classified deployment, or government accreditation; those would require separate diligence.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

Tamnoon has a credible strategic fit with cloud resilience and dual-use cybersecurity: it targets the expensive last mile after detection, has a documented Series A, and combines software with expert-supervised execution. The opportunity is conditional rather than a recommendation. Diligence should test recurring revenue quality, customer retention, gross margin by service tier, automation rate, remediation safety, integration depth, and whether reported exposure and MTTR improvements are independently measured. Large CNAPP vendors, cloud providers, and MSSPs can all compress pricing or reproduce adjacent functionality, so durable value depends on outcome data, workflow adoption, and a scalable software-to-services mix.

Strategic Value to U.S.-Israel Alliance

Tamnoon can improve defensive cloud resilience by turning security telemetry into owned, tested, and preventable engineering work. For defense-adjacent users, its value is greatest where commercial-cloud mission-support systems need continuous posture improvement and evidence of controlled changes; the record does not establish defense contracts, classified use, or government certification.

Key Technologies

  • AI cloud-security agent for alert investigation and remediation planning
  • CNAPP, CSPM, vulnerability, and cloud-provider finding aggregation
  • Risk, exploitability, asset-criticality, and ownership-based prioritization
  • Remediation Confidence Indicator with safe, risky, and awaiting-data paths
  • IaC-aware remediation plans, CLI commands, validation scripts, and retesting
  • Human-supervised execution through CloudPros and approval workflows
  • Cloud guardrails and prevention controls for recurring misconfigurations

Use Cases & Applications

  • Consolidating duplicate findings from multiple CNAPP and CSPM tools
  • Prioritizing exploitable issues affecting production or crown-jewel assets
  • Generating and validating Terraform, cloud-policy, and CLI remediation changes
  • Routing fixes to the correct engineering owner through Jira or ServiceNow
  • Reducing cloud vulnerability and misconfiguration backlogs for lean security teams
  • Providing retest and remediation evidence for audits and compliance programs
  • Applying guardrails to prevent insecure cloud configurations from recurring
  • Hardening defense-industrial and other mission-support workloads hosted in commercial clouds

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.

This record lists 7 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

  • tamnoon.io Public source used for profile verification.
  • tamnoon.io Public source used for profile verification.
  • tamnoon.io Public source used for profile verification.
  • tamnoon.io Public source used for profile verification.
  • tamnoon.io Public source used for profile verification.
  • LinkedIn company page Public source used for profile verification.
  • calcalistech.com Public source used for profile verification.
  • Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.