Verax AI

Cybersecurity Dual-Use Technology Priority Signal Founded 2023

Last updated: Jul 21, 2026

Verax AI is an Israeli-founded enterprise AI-security and governance company whose runtime platform gives organizations visibility and control over generative-AI and large-language-model usage in production — discovering shadow AI, catching hallucinations and unsafe outputs, and enforcing identity-aware policy across every GenAI interaction.

Visit Website

Company Overview

**Product and the concrete problem it solves.** Verax AI sits in the fast-forming category of *GenAI security and assurance* — the control layer that enterprises need before they can safely put large language models (LLMs) into production. The concrete problem is that LLMs are non-deterministic and cannot themselves distinguish a verified fact from a confident fabrication, so as organizations move generative AI from sandbox pilots into live, customer- and employee-facing workflows they inherit a new class of operational risk: hallucinated or factually wrong answers, data leakage, prompt-injection and jailbreak attempts, biased or off-policy responses, and "shadow AI" — employees quietly piping sensitive corporate data into unsanctioned third-party models. Traditional MLOps and model-development tooling optimizes models *before* deployment; it does little once a model is live and behaving unpredictably in the wild. Verax's pitch is a purpose-built layer that closes that gap. Its platform — described across the company's materials as the **Verax Control Center** and the security-hardened **Verax Protect** — provides organization-wide discovery of where and how GenAI is actually being used, real-time monitoring of model behavior in production, and automated correction or blocking of unwanted outputs, so that CISOs and risk owners can say "yes" to AI adoption without accepting uncontrolled exposure.

**Core technology and how it actually works.** Architecturally, Verax deploys as an intermediary control plane *inside the customer's environment*, positioned between users/applications and the LLMs they call. Rather than retraining or fine-tuning models, the system observes traffic and enforces policy at runtime, which lets it work across heterogeneous model estates. Two design choices matter most. First, the platform is described as **LLM-agnostic and requiring no pre-training or lengthy configuration** — a deliberate bet that enterprises will run many models (commercial APIs, open-weight models, and internally hosted ones) and need one horizontal governance layer rather than per-model bespoke guardrails. Second, it emphasizes **lineage and traceability**: when a response is generated, Verax traces the relationship between the AI's output and its source data so that deviations, hallucinations, or unsafe content can be flagged, diagnosed, and — per the company — auto-corrected in real time without human intervention or slow manual tuning. On the security side, Verax Protect adds **shadow-AI discovery, prevention of unauthorized model training on corporate data, runtime protection, and identity-aware access and usage control** — i.e., tying every GenAI action back to who is doing it and enforcing organizational policy on that basis. The honest technical caveat is that runtime LLM guardrailing is a young discipline; the effectiveness of automated hallucination detection and auto-correction is workload-dependent and not something the public record independently benchmarks.

**Market, customers, and go-to-market.** Verax targets the enterprise buyer — specifically CISOs, heads of AI/data governance, and risk and compliance owners in organizations that want to deploy GenAI "in a secure and compliant fashion." The go-to-market is classic top-down enterprise security software: land with security and governance teams who are the internal gatekeepers for AI rollout, then expand as GenAI usage proliferates across business units. Notably, the founders report having validated demand by interviewing CISOs across diverse industries *before* building the product, which is the right sequencing for an enterprise-security company. The addressable market is large and expanding quickly — every regulated and data-sensitive enterprise adopting GenAI is a candidate — and it is being pulled forward by regulatory pressure (the EU AI Act, sectoral compliance regimes, and internal audit requirements) that makes an auditable AI control layer a near-necessity. The calibrated counterpoint: the public record does not disclose named production customers, revenue, or logo references, so commercial traction beyond the seed round should be treated as unproven, and the category is being contested by dozens of well-funded entrants simultaneously.

**Traction, funding, and third-party validation.** Verax was **founded in 2023** and announced a **$7.6 million seed round on October 30, 2024, led by TQ Ventures**, with participation from Concept Ventures, Cardumen Capital, Seedcamp, XTX Ventures, and **InMotion Ventures** (the corporate venture arm associated with Jaguar Land Rover). The syndicate is a meaningful signal: it blends specialist seed investors with a strategic corporate backer, and InMotion published a public thesis explaining that it invested because the market for *practical, commercial* LLM-assurance solutions "remains sparse" despite heavy research interest — an investor articulating genuine white space rather than a crowded me-too bet. The company launched its enterprise platform publicly in late October 2024. Beyond the seed round and platform launch, third-party validation is still early-stage: there are no publicly disclosed enterprise contracts, certifications (SOC 2, ISO, FedRAMP), or defense/government engagements in the record, and headcount is not publicly confirmed. This is a seed-stage company whose validation to date is investor conviction and founder pedigree rather than disclosed revenue or marquee customers.

**Founders and team background.** The strongest asset in the Verax story is its team. Co-founder and CEO **Leonid ("Leo") Feinberg** is a third-time founder with a real exit track record: he co-founded **CloudEndure**, where he served as VP of Product, and CloudEndure was **acquired by Amazon Web Services for a reported ~$250 million**; an earlier venture produced an exit to Limelight (~$25M). Co-founder and CTO **Oren Gev** worked alongside Feinberg at CloudEndure and subsequently at AWS before the pair left in 2023 to build Verax. That background — enterprise infrastructure and cloud-scale software, a prior category-defining product, deep AWS operating experience, and demonstrated enterprise-sales muscle — is precisely the profile that de-risks an early enterprise-security company. The team operates with an Israel R&D core (Tel Aviv) and a U.S. commercial presence (reported across Dallas and New York, with additional London footprint in some accounts), the standard Israeli-founded, U.S.-facing enterprise-software structure. The principal open question is scaling a go-to-market and research organization fast enough to keep pace with a category expanding — and consolidating — in real time.

**Competitive dynamics.** Verax competes in one of the most crowded frontiers in enterprise software, and its differentiation rests on being a horizontal, runtime, LLM-agnostic control layer rather than a point tool. (1) Against **AI-security specialists** such as Protect AI (acquired by Palo Alto Networks), Lakera, CalypsoAI, WitnessAI, and Israel's own Prompt Security, Verax competes on breadth (discovery + monitoring + auto-correction + access control in one plane) versus depth in a single threat like prompt injection. (2) Against **AI-governance/compliance platforms** (Credo AI, Holistic AI, Robust Intelligence — the latter acquired by Cisco), it competes on being a live runtime enforcement layer rather than a documentation/assessment tool. (3) The most serious structural threat is **platform absorption**: hyperscalers and model providers are shipping native guardrails (Azure AI Content Safety, AWS Bedrock Guardrails, Google/OpenAI safety tooling), and security incumbents are acquiring their way into AI security, so a horizontal startup must prove it is materially better and genuinely model-agnostic to avoid being commoditized by "good-enough" native controls. Verax's plausible edges are its no-pre-training/LLM-agnostic deployment, its lineage-based hallucination tracing, and a founding team that has built and sold enterprise infrastructure before.

**Defense, security, and resilience dual-use relevance.** Verax's dual-use relevance should be read as *real on the security/resilience axis and adjacency-grade on the defense axis.* The technology is, at its core, security software: it governs how sensitive organizations adopt a powerful and unpredictable new capability, prevents proprietary data from leaking into external models, discovers unsanctioned AI usage, and enforces identity-based policy and auditability. Those functions map directly onto the requirements that defense, intelligence, and critical-infrastructure operators will impose before they can field LLMs in mission contexts — trustworthy-AI assurance, hallucination and data-exfiltration control, red-team/jailbreak resistance, provenance, and policy enforcement are exactly the guardrails that make generative AI usable in high-stakes, low-error-tolerance environments. As allied governments push "responsible/assured AI" mandates, an independent, model-agnostic control plane is strategically relevant national-security infrastructure in the abstract. The calibration that keeps this honest: Verax has *no publicly disclosed defense or government customers, no fielded classified deployments, and no security certifications on the public record*. Its dual-use case today is the enterprise-security-and-resilience thesis, with defense as a credible future adjacency rather than a demonstrated capability.

**Growth stage, trajectory, and key diligence risks.** Verax reads as an **early-stage** company: founded 2023, one disclosed $7.6M seed (October 2024), a launched platform, a strong syndicate, and an exceptional founding team, but without disclosed revenue, named customers, certifications, or a Series A on the public record. The trajectory is promising precisely because the founders have run this playbook before and are early to a category that regulators and enterprise risk owners are forcing into existence. The key diligence risks are, in order: (1) **category commoditization** — hyperscaler-native guardrails and security-incumbent acquisitions could compress the standalone opportunity; (2) **crowding and consolidation** — dozens of AI-security startups are chasing the same CISO budget, and shakeout is likely; (3) **unproven traction** — commercial validation beyond investor conviction is not public, so revenue, retention, and logos remain unverified; (4) **efficacy risk** — automated hallucination detection and real-time auto-correction are hard technical claims whose production performance is not independently benchmarked; and (5) **positioning risk** — the "Control Center" vs. "Protect" framing suggests an evolving product identity that will need to settle into a durable wedge. Progression from here would be evidenced by a Series A, disclosed enterprise customers (ideally in regulated or public-sector verticals), security certifications, and independent evidence that the runtime guardrails materially outperform native alternatives.

Dual-Use Assessment

Military & Commercial Applications

Verax's dual-use relevance is genuine on the security/resilience axis and adjacency-grade on the defense axis. (1) The core product is security software: it governs enterprise adoption of generative AI, prevents sensitive/proprietary data from leaking into external models, discovers unsanctioned 'shadow AI,' and enforces identity-aware policy with auditability — capabilities that map directly onto the assurance requirements defense, intelligence, and critical-infrastructure operators impose before fielding LLMs. (2) Trustworthy-AI functions — hallucination detection, jailbreak/prompt-injection resistance, output provenance, and real-time policy enforcement — are precisely the guardrails that make generative AI usable in high-stakes, low-error-tolerance mission contexts, and allied 'responsible/assured AI' mandates make an independent, model-agnostic control plane strategically relevant in the abstract. (3) Calibration: Verax has no publicly disclosed defense or government customers, no fielded classified deployments, and no security certifications (SOC 2/ISO/FedRAMP) on the public record. Its realized dual-use case today is enterprise security and organizational resilience; defense is a credible future adjacency, not a demonstrated capability.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

Verax is an early-stage priority-signal candidate whose appeal rests on team quality and category timing, offset by seed-stage unproven traction and intense competition. (1) Exceptional founders: CEO Leonid Feinberg is a third-time founder who co-founded CloudEndure (acquired by AWS for a reported ~$250M) and previously exited to Limelight (~$25M); CTO Oren Gev worked alongside him at CloudEndure and AWS — enterprise-infrastructure builders with a demonstrated exit and enterprise-sales experience, exactly the profile that de-risks an early enterprise-security company. (2) Category timing and white space: GenAI security/assurance is a genuine, regulator-pushed need, and strategic backer InMotion Ventures publicly argued that practical commercial LLM-assurance solutions 'remain sparse' despite heavy research — an diligence thesis of real white space. (3) Right wedge: a horizontal, runtime, LLM-agnostic control layer (discovery + monitoring + auto-correction + access control) is a defensible position IF it proves materially better than native alternatives. Counterweights that should dominate assessment: (a) the category is extremely crowded and consolidating, with hyperscaler-native guardrails and security-incumbent acquisitions (e.g., Palo Alto/Protect AI, Cisco/Robust Intelligence) threatening commoditization; (b) commercial traction is unproven — no public customers, revenue, retention, or certifications; (c) automated hallucination detection/auto-correction is a hard claim not independently benchmarked; and (d) product identity ('Control Center' vs. 'Protect') is still settling. This is a strategic/technical-fit signal, not an investment recommendation.

Strategic Value to U.S.-Israel Alliance

Verax's strategic value sits in the trustworthy-AI assurance layer rather than in a fielded product. (1) Enabling capability: an independent, model-agnostic runtime control plane for generative AI is horizontal infrastructure that can serve enterprise, regulated-industry, critical-infrastructure, and — in principle — government/defense adopters simultaneously, making it high-leverage if it becomes a standard. (2) Security-and-resilience thesis: preventing data leakage into external models, discovering shadow AI, enforcing identity-based policy, and providing auditability are organizational-resilience functions directly relevant as institutions become dependent on unpredictable AI systems. (3) Sovereign/allied relevance: as allied governments mandate 'responsible/assured AI,' independent assurance tooling that is not owned by a single hyperscaler or model vendor has abstract national-security value. (4) Founder leverage: a team that has built and sold cloud-scale enterprise infrastructure raises the odds of converting a technical wedge into durable platform value. The realized strategic weight depends on Verax proving production efficacy, winning regulated/public-sector customers, and avoiding commoditization by native guardrails; absent those, its strategic value is real on the enterprise-security axis but remains an adjacency on the defense axis.

Key Technologies

  • Runtime GenAI/LLM control plane deployed inside the customer environment (governs traffic between users/apps and models rather than retraining them)
  • LLM-agnostic guardrailing requiring no pre-training or lengthy configuration, designed to span commercial, open-weight, and self-hosted models
  • Real-time monitoring of live model behavior with automated correction/blocking of unwanted or unsafe outputs
  • Output-to-source lineage and traceability for diagnosing hallucinations and factual deviations
  • Shadow-AI discovery and prevention of unauthorized model training on corporate data
  • Identity-aware AI access and usage governance with organization-wide policy enforcement
  • Enterprise-wide visibility and audit of generative-AI usage for security and compliance owners

Use Cases & Applications

  • Enforcing guardrails on customer- and employee-facing LLM applications before production rollout
  • Detecting and correcting hallucinations or factually wrong outputs in live generative-AI workflows
  • Discovering and controlling 'shadow AI' — unsanctioned employee use of external models with corporate data
  • Preventing sensitive/proprietary data from being leaked into or used to train third-party models
  • Defending against prompt-injection, jailbreak, and off-policy behavior at runtime
  • Providing CISOs and risk owners auditable visibility and policy enforcement across a multi-model estate
  • Supporting regulatory compliance for AI usage (e.g., EU AI Act and sectoral risk regimes)
  • Assuring generative-AI deployments in regulated, data-sensitive, or security-conscious organizations

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.

This record lists 7 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Investor Lens

What this entry is

Private startup

Why it may matter

Verax AI may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.

How an independent investor should read this

Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.

Evidence to verify

  • Verify current status
  • Verify traction
  • Verify cap table/funding
  • Verify technical claims
  • Verify regulatory/export-control issues
  • Verify customer concentration

Main investor questions

  • Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
  • What customer, revenue, product, and technical evidence supports the company story?
  • What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
  • Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
  • What evidence would change the thesis or show that the profile is stale?

What not to infer

  • Inclusion does not imply endorsement.
  • Inclusion does not imply allocation availability or current fundraising.
  • Scores do not indicate investment suitability or expected returns.
  • Strategic importance does not automatically imply venture return potential.

Diligence questions

  • What evidence verifies Verax AI's current customer traction, deployment status, and revenue concentration?
  • Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
  • Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
  • How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
  • What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.

Need a diligence readout?

Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.