Dossier · Private startup · 1 independent source

vlno

Cybersecurity Dual-Use Technology Priority Signal

Last updated: Sep 8, 2026

vlno is a Tel Aviv AI-security startup building a model-robustness layer for open and agentic AI. Its pipeline generates adaptive attacks, sandboxed evaluations, and post-training artifacts that harden models against indirect prompt injection and related manipulation before they reach sensitive production workflows.

Visit Website

Company Overview

**Product and the concrete problem it solves.** vlno is addressing a specific failure mode in the transition from chatbots to autonomous software: an agent can be given a legitimate goal and then encounter hostile instructions hidden inside a web page, email, PDF, retrieved document, or tool response. Because the malicious text is presented as data rather than as an explicit user prompt, conventional instruction filters and gateway guardrails can miss it. The resulting risk is not merely an incorrect answer. An agent with access to files, code, payment systems, identity providers, or operational APIs can be manipulated into exfiltrating information, changing state, or taking an action that its human operator never authorized. vlno's thesis is that organizations need to harden the model itself, not only surround it with runtime controls. The company's public product is therefore a security-training layer for open-weight and agentic models: it measures how a model behaves under adaptive attack, produces the examples and trajectories needed to change that behavior, and keeps re-testing as the model or attack surface changes. This is particularly relevant to sovereign AI programs that want the control and economics of open models without accepting an unmeasured robustness gap.

**Core technology and how it actually works.** The public architecture describes a continuous attack-and-hardening loop rather than a one-time red-team report. First, an adaptive attacker generates indirect prompt-injection scenarios tailored to the customer's agentic workflow and executes them against sandboxed enterprise surfaces. The system measures an attack-success rate and identifies the conditions under which the agent confuses an instruction with untrusted content. Second, vlno converts successful attack trajectories into training data, including reinforcement-learning and preference-optimization material, or into a hardening LoRA that the customer can apply inside its own fine-tuning pipeline. Third, the modified checkpoint is tested again, and its robustness is re-certified when a new model version, fine-tune, or attack class appears. The joint reference architecture with Wand AI places this capability at two control points: admission testing before a model enters an open-model registry, and weight-level hardening for models that do not meet the required threshold. The artifact is training data or a LoRA, not the customer's weights or workflow content, which is designed to keep sensitive material inside the customer's trust boundary. This is a materially different position from an inference proxy: runtime filters still have a role, but vlno aims to make the model less likely to follow the malicious instruction in the first place.

**Market, customers, and go-to-market.** vlno sits at the intersection of AI security, post-training infrastructure, and sovereign compute. Its immediate buyer is likely to be a frontier-model team, an enterprise AI platform group, or a government and regulated-industry program that wants to deploy an open-weight model with measurable security evidence. The customer does not need to replace its orchestration layer: the advertised outputs are intended to plug into an existing fine-tuning path, while the public benchmark provides a low-friction way to measure a model before procurement or production approval. The August 2026 Wand AI integration gives vlno a concrete channel into sovereign deployments, where model control, local hosting, and accountable security posture are procurement requirements rather than optional features. Other plausible buyers include defense contractors, intelligence organizations, banks, healthcare systems, and critical-infrastructure operators that cannot send operational context to a third-party frontier API. Public sources do not identify paying customers, annual recurring revenue, contract sizes, or a formal sales pipeline, so the commercial stage should not be overstated. The best near-term go-to-market motion is ecosystem-led: become the robustness gate for sovereign model registries and the hardening component in agent platforms, while using the public benchmark to establish a common measurement vocabulary with security and ML teams.

**Traction, validation, and financing posture.** The strongest disclosed validation is technical and ecosystem-based rather than financial. vlno's own site says it is already hardening agents used in real enterprise environments and working with leading companies on governed deployments, but it does not name those companies or publish independent benchmark results. Its public partnership with Wand AI is more concrete: the two companies describe an architecture in which Wand operates the sovereign agentic stack and vlno supplies admission testing, adaptive attack generation, hardening artifacts, and continuous re-certification. The partnership also identifies a real buyer problem: governments and regulated enterprises may prefer open weights for sovereignty and cost, while security teams need evidence that those models can withstand manipulation. Crunchbase lists vlno as an active private company in Tel Aviv with the vlno.ai domain, and public LinkedIn material identifies Hertzel Tokgoz-Kuriel, also referred to in company material as Hertzel Kuriel, as co-founder and CEO. No public source reviewed for this record discloses a funding round, valuation, total capital raised, customer count, patents, certifications, or independently reproducible attack-success benchmarks. That absence is not a defect to hide; it is the central diligence constraint. The company has a credible public ecosystem entry and a defined technical product, but the record should distinguish partnership availability and company-stated production work from audited scale.

**Founders and team background.** vlno presents itself as being built by people who previously hardened models inside leading frontier labs and who have experience in adversarial research, model evaluation, and reinforcement-learning-based post-training. The company has publicly named Hertzel Tokgoz-Kuriel as co-founder and CEO in the Wand integration announcement, while the official site describes a small senior team spanning adversarial research, platform engineering, ML/post-training, and operations. Public material also associates Ismail Kharoub with the company's sovereign-AI reference-architecture announcement, although his exact corporate title is not established in the sources used here. That profile is strategically relevant because the technical challenge is not generic application security: it requires understanding how model behavior changes under data poisoning, adversarial instruction search, tool-use evaluation, fine-tuning, and deployment-time serving differences. The team's claimed frontier-lab experience is a credible founder-market-fit signal, but it remains largely self-described and does not substitute for published biographies, named prior employers, peer-reviewed work, or third-party performance evidence. Headcount is not disclosed beyond the official description of a small senior team. Diligence should therefore test whether the company has enough research depth to maintain adaptive attackers, enough systems engineering to integrate with customer training stacks, and enough security-program experience to translate an attack-success metric into a procurement-grade assurance artifact.

**Competitive dynamics.** vlno competes against several different approaches rather than one direct incumbent. Model-evaluation and red-team firms find vulnerabilities but generally return reports, not modified weights. Runtime AI-security vendors place filters, policy engines, or observability in front of model calls and can stop some attacks without changing the underlying behavior. Frontier labs such as Anthropic, OpenAI, Google DeepMind, and Meta conduct their own safety training and red teaming, creating a make-versus-buy threat for the largest model builders. AI-security platforms such as Robust Intelligence, HiddenLayer, Protect AI, and Lakera compete for adjacent model testing, model supply-chain, or prompt-injection budgets. vlno's proposed edge is the closed loop between adaptive attack discovery and weight-level remediation, combined with a deployment model that can keep sensitive data and model artifacts inside a sovereign environment. Its distinction is meaningful only if the hardening generalizes beyond the exact attacks used for training; otherwise it risks optimizing a benchmark while leaving the agent vulnerable to a new attacker. The company also faces a channel conflict with platform vendors that may treat robustness as a feature of their own model registry or agent runtime. Sustainable differentiation will require a trusted measurement protocol, strong transfer across models and frameworks, low operational friction, and evidence that customers improve robustness without sacrificing capability or latency.

**Defense, security, and resilience relevance.** vlno has credible dual-use relevance because the core capability applies to both commercial AI and high-assurance national systems. In a defense or intelligence setting, an open model may be attractive because the operator needs local control over weights, data, compute, and policy, but an agent that consumes battlefield reporting, intelligence feeds, maintenance documents, or tool output also faces a large indirect-instruction attack surface. Weight-level robustness can complement runtime authorization, sandboxing, provenance, and human approval by reducing the probability that hostile content changes the agent's interpretation before those controls are invoked. The same pattern applies to critical infrastructure, emergency management, healthcare, and financial systems where an agent may be allowed to query or update sensitive operational state. The Wand reference architecture explicitly describes ministries, regulated enterprises, and sovereign infrastructure as target contexts, which makes the defense and resilience adjacency more than a generic claim. It still does not prove a fielded military deployment, government contract, security clearance, or certification. Strategic value is therefore best described as enabling infrastructure for trustworthy sovereign AI, not as an existing defense product. Key security questions include whether the hardening survives adaptive attackers, whether training artifacts can introduce new backdoors, how the system handles multilingual and multimodal content, and how a customer proves that a model update has not invalidated its robustness certificate.

**Growth stage, trajectory, and diligence risks.** vlno is classified as early because it is publicly described as a stealth-era company with a small team, no disclosed financing or headcount, and an initial ecosystem partnership rather than a transparent record of scaled commercial deployment. Its trajectory could be important: if open-weight models become the default for sovereign and regulated AI, a repeatable robustness gate could become a required piece of national compute infrastructure in the same way that vulnerability scanning and identity controls became standard in enterprise software. The upside depends on turning a compelling security thesis into a measurable, trusted workflow that works across model families and customer-owned environments. The major diligence risks are concentrated. First, the public evidence is mostly company and partner material, with no independent benchmark replication or named customer references. Second, adversarial training can overfit to known attack classes while missing novel attacks, and a claimed attack-success rate is meaningful only when the attacker budget, model serving path, sample distribution, and confidence interval are disclosed. Third, model hardening can degrade useful capabilities or create hidden bias, and LoRA or post-training artifacts may be difficult to govern across versioned deployments. Fourth, the market could be absorbed by frontier labs, cloud providers, model registries, or runtime security vendors. Fifth, sovereign programs have slow procurement and high assurance burdens. vlno merits close monitoring because it targets a foundational security layer for agentic AI, but the next proof points should be independent evaluations, named production customers, repeatable integration evidence, disclosed financing and team depth, and a demonstrated ability to harden models without materially reducing capability.

Dual-Use Assessment

Military & Commercial Applications

vlno's model-robustness layer has credible commercial and defense/security applicability because it hardens open and agentic models against indirect prompt injection while preserving deployment inside a customer's trust boundary. The official Wand integration explicitly targets sovereign infrastructure, ministries, and regulated enterprises, making resilience relevance concrete. No public source reviewed here establishes a fielded military deployment, government contract, certification, or defense customer, so the defense case is enabling infrastructure and sovereign-AI adjacency rather than proven battlefield traction.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

vlno is a high-priority strategic screening signal because it addresses the layer that determines whether organizations can safely deploy open and agentic models, rather than adding another generic AI wrapper. (1) Product specificity: the company describes an adaptive attack, evaluation, and weight-level hardening loop with concrete outputs such as RL/DPO-ready trajectories and LoRAs. (2) Strategic timing: sovereign and regulated buyers want model control but cannot accept an unmeasured prompt-injection posture. (3) Ecosystem validation: the Wand AI integration creates a credible route into sovereign deployments and is more substantive than a launch-only claim. (4) Evidence limits: no financing, revenue, named customer, independent benchmark, patent, or certification is disclosed in the reviewed public record. Diligence should prioritize reproducible robustness improvements, generalization to unseen attacks, capability-retention measurements, customer conversion, and the company's ability to scale research and integration. This legacy flag is a strategic monitoring signal, not an investment recommendation.

Strategic Value to U.S.-Israel Alliance

vlno could provide strategic value as a sovereign-AI assurance layer for models that governments, defense organizations, and critical-infrastructure operators want to host and control themselves. (1) Trust-boundary fit: its stated artifact-based workflow can keep sensitive weights and agent context inside the customer environment. (2) Control-plane leverage: a model-registry admission test can make robustness a deployment gate instead of an informal vendor promise. (3) Resilience: continuous re-certification is relevant when models, fine-tunes, tools, and attack methods change faster than annual compliance cycles. (4) Allied technology relevance: a Tel Aviv team focused on adversarial AI security fits Claw & Talon's Israeli strategic-technology thesis. The ceiling is constrained by the lack of public defense customers, government accreditation, independent test data, and disclosed scale; strategic value is presently credible potential rather than proven national capability.

Key Technologies

  • Adaptive adversarial attack generation for indirect prompt injection
  • Sandboxed agentic-workflow security evaluation and attack-success measurement
  • Reinforcement-learning and preference-optimization training trajectories
  • Hardening LoRA artifacts for customer-controlled model fine-tuning
  • Continuous robustness re-certification bound to model checkpoints
  • Sovereign AI model-registry admission and deployment integration

Use Cases & Applications

  • Pre-production security certification of open-weight models for sovereign AI registries
  • Hardening retrieval-augmented agents against malicious instructions in documents and web content
  • Protecting defense and intelligence agents that consume untrusted operational reporting
  • Securing regulated banking and healthcare agents with customer-controlled training artifacts
  • Reducing prompt-injection risk in coding agents with repository and tool access
  • Continuous re-testing of fine-tuned enterprise models after new attack classes or checkpoints
  • Robustness assurance for critical-infrastructure and emergency-response AI workflows

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.

This record lists 6 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

  • vlno — We train the threat out (official website) Verifies the canonical website, Tel Aviv base, model-robustness thesis, indirect prompt-injection focus, adaptive attack and re-hardening loop, production-oriented claims, and the small senior team profile.
  • WAND AI adds VLNO as a Model Robustness Layer (vlno official blog) Verifies Hertzel Kuriel as co-founder and CEO, the August 2026 Wand integration, sovereign-AI and regulated-enterprise use case, adaptive attack pipeline, RLHF/DPO-ready trajectories, hardening LoRAs, continuous re-certification, and customer trust-boundary design.
  • Wand AI × vlno — Joint Reference Architecture (official technical material) Verifies the two deployment points: model-registry admission certification and weight-level hardening; explains the model checkpoint binding, attack-success measurement, sandbox execution, and the division between Wand's sovereign stack and vlno's robustness layer.
  • vlno company profile (Crunchbase) Independently corroborates vlno as an active private company in Tel Aviv, Israel, using the vlno.ai domain, and categorizes its work across agentic AI, AI infrastructure, cybersecurity, machine learning, penetration testing, and model-quality assurance.
  • Hertzel Tokgoz-Kuriel LinkedIn profile and public VLNO posts Corroborates the public CEO identity and shows the company's open-model robustness work, adaptive adversarial testing, and the distinction between measuring model weakness and hardening the weights.
  • Ismail Kharoub — VLNO sovereign-AI partnership announcement Provides public corroboration of VLNO's Wand AI sovereign-AI partnership and explains the intended use in government and regulated environments without treating the partnership as proof of a government contract.
  • Profile update timestamp Last updated in the Claw & Talon database on Sep 8, 2026.

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.