Dossier · Private startup · 4 independent sources

Willow

Cybersecurity Dual-Use Technology Priority Signal

Last updated: Aug 31, 2026

Willow is an Israeli cybersecurity startup building an identity and access control plane for enterprise AI agents. Its platform gives agents scoped permissions, runtime guardrails, shadow-AI discovery, and human-attributed audit trails so organizations can deploy agentic workflows without granting autonomous software uncontrolled access to internal systems.

Visit Website

Company Overview

**Product and the concrete problem it solves.** Willow addresses a security gap created when software stops merely answering questions and starts taking actions. An enterprise AI agent may read a private repository, query a database, change a ticket, send a message, or invoke an internal API on a human's behalf, while the existing identity stack generally knows about the employee or service account but not the agent's task, tool chain, or decision boundary. The practical failure mode is not only a malicious prompt. It is standing access that is too broad, an unapproved Model Context Protocol (MCP) server, an extension that silently exfiltrates data, or a legitimate agent performing a dangerous action without a usable audit trail. Willow presents itself as an "Agentic Access Platform" and an AI Basecamp: every agent checks in, receives an identity, obtains only the tools required for a task, operates under policy, and leaves an action trail tied back to a real human. This lets a security team move from the binary choice of blocking enterprise AI or allowing it to run freely toward controlled adoption.

**Core technology and how it actually works.** The product is a control plane assembled around five concrete functions. First, Willow creates an identity at the agent layer and can inherit identity context from existing providers including Okta, Microsoft Entra, Active Directory, and JumpCloud. Second, it generates tools and permissions at runtime for the task rather than issuing a blanket OAuth grant to an agent or organization. That is an important distinction: the authorization decision can be narrowed to a particular action, data scope, and user context before the agent executes. Third, runtime controls include PII redaction, prompt-injection protection, application-aware permissions, and approval workflows for risky actions. Fourth, a browser extension and endpoint agent expose unsanctioned AI tools, MCP servers, skills, and agents as shadow-AI activity. Fifth, every action can be streamed to a SIEM with attribution to the human behind the agent. Willow also advertises more than 1,000 connectors, over 100 skills and plugins, internal-API wrapping as MCP, and deployment options spanning SaaS, dedicated cloud, self-hosted, and fully air-gapped environments. Those claims describe a plausible enterprise architecture, but public sources do not provide independent penetration-test results, formal certification evidence, or benchmark data for detection precision, latency, or policy enforcement.

**Market, customers, and go-to-market.** Willow is selling into the intersection of identity security, AI governance, developer infrastructure, and enterprise enablement. Its primary buyer can be a CISO worried about uncontrolled tool access, an AI-platform leader trying to make internal agents usable, or an IT administrator responsible for identity, endpoint rollout, and audit. The company’s wedge is unusually pragmatic: it was first used inside Wix, where a central catalog could let engineers and non-engineers use approved tools without separately designing an MCP integration or reopening a security review for every workflow. The Wix case study describes Git, Jira, Slack, Figma, Grafana, Google Workspace, internal documentation, and custom infrastructure tools as examples of the systems that required a common access pattern. Public launch materials say deployments are expanding across cybersecurity, real estate, fintech, adtech, and the United States and Europe; the company names Innovid and Riskified as customers or production deployments in its launch announcement and also describes Agora in a founder post. Customer counts, contract values, annual recurring revenue, retention, and sales-cycle data are not public. The likely go-to-market is land through AI enablement or developer-platform teams, then expand into security governance, compliance, endpoint discovery, and privileged workflow control.

**Traction, funding, and third-party validation.** Willow announced a $7 million Seed round on June 4, 2026 led by Hetz Ventures. Wix co-founder and CEO Avishai Abrahami and Wix president Nir Zohar provided early angel backing, which creates both a valuable channel and an important independence caveat because the flagship deployment is linked to the founders’ former employer and early investors. Willow’s official launch post reports that the platform was already running in production at Wix across approximately 5,000 weekly active users, 600-plus governed tools, and more than 300,000 governed tool calls per week, spanning engineering, product, design, HR, finance, legal, and other business teams. A separate case study confirms the nearly 600-tool and 300,000-plus weekly-call figures and describes the internal deployment as enterprise MCP infrastructure. The public record is not perfectly consistent: a founder LinkedIn post cited roughly 3,000 weekly active Wix users, while the later official case study and launch post cite approximately 5,000. That discrepancy does not erase the deployment signal, but it means the numbers should be treated as company-reported directional metrics until Wix publishes an independent reference. CTech and Techtime corroborate the seed round, Hetz leadership, Wix deployment, Herzliya base, and agent-governance positioning. No patents, government contracts, certifications, audited security attestations, or independently measured customer outcomes were found in the reviewed sources.

**Founders and team background.** Willow was founded by former Wix engineers Eyal Ben Ezra, Shalev Shalit, and Idan Chetrit. Ben Ezra is CEO and the official biography describes him as a second-time founder who bootstrapped Conversion Bear to an eight-figure exit in two years; that prior operating history gives him evidence of shipping and commercializing software, although the transaction details are not independently documented in the reviewed sources. Shalit is CTO and is credited by Willow with building the Wix AI Gateway and leading Wix OS, its Business Platform, and Dev Center, giving him directly relevant experience in authentication platforms, integrations, and internal AI infrastructure. Chetrit is VP Platform, with a background leading multiple R&D teams and working in cyber and web technologies; Willow identifies prior development roles at NSO and Kodem. The founders’ shared Wix context is strategically useful because they have lived through the problem at enterprise scale, including the organizational friction between fast AI adoption and security review. It also concentrates key commercial proof around a network they already know. Public sources mention active hiring across engineering, product, design, and go-to-market, including six open roles, but do not disclose total headcount, employee retention, broader technical leadership, or the company’s long-term balance between Israeli engineering and U.S. sales.

**Competitive dynamics.** Willow competes in a fast-converging category rather than a vacant market. (1) **Runlayer** provides enterprise infrastructure and governance for MCP and AI-agent connections, making it a close alternative for organizations seeking a managed gateway. (2) **Archestra** and **Obot** compete through agent gateways, observability, policy, and enterprise MCP management. (3) **Cloudflare** can bundle AI Gateway, Zero Trust, browser, and edge controls into a much larger network-security distribution platform. (4) **Okta** and Microsoft Entra are identity incumbents with the customer relationships and policy primitives needed to extend identity toward non-human agents. (5) **Koi Security** and **Capsule Security**, both Israeli security startups already in this database, attack adjacent agent, endpoint, runtime, and tool-governance problems. Willow’s plausible edge is the combination of identity, task-scoped tool generation, runtime enforcement, shadow-AI visibility, and human attribution in one neutral layer, plus product lessons earned from a large internal deployment. That is a strong integration and workflow thesis, not yet a proven proprietary moat. Connectors and MCP gateways can be replicated; identity-provider APIs are widely available; hyperscalers and platform incumbents can bundle overlapping controls. The durable advantage would have to come from policy data, low-friction rollout, cross-agent neutrality, reliable attribution, and a reference base that proves Willow can reproduce Wix-scale usage in accounts where the founders have no prior organizational leverage.

**Defense, security, and resilience dual-use relevance.** Willow’s core technology qualifies as dual-use in a defensive-security and resilience sense, although there is no public evidence of a defense customer or classified deployment. Defense contractors, intelligence organizations, government departments, hospitals, utilities, and critical-infrastructure operators are all likely to adopt AI agents under stricter requirements for compartmentalization, data residency, least privilege, continuous monitoring, and accountable human control. In those environments, the ability to issue an agent only the tools needed for one mission, require approval before a sensitive write, detect an unmanaged MCP server, redact protected information, and attribute every action to a human operator could reduce both attack surface and operational ambiguity. The air-gapped and self-hosted deployment claims are particularly relevant to restricted networks, but they are product-positioning statements rather than proof of accreditation or fielded use. The same control plane could support a defense software factory, logistics planning system, cyber-defense workflow, or emergency-response organization, while remaining separate from weapons targeting or autonomous use-of-force decisions. The security case is therefore credible and direct at the infrastructure layer: Willow governs how autonomous software touches mission systems. The ceiling is equally clear. No public source reviewed here establishes military procurement, government authorization, classified handling, MIL-STD compliance, FedRAMP status, or operation through disconnected and intermittently connected tactical networks.

**Growth stage, trajectory, and key diligence risks.** Willow is classified as **early** because it was publicly launched in 2026, has a Seed financing, limited disclosed customer breadth, and no public revenue or retention metrics, even though the product appears to have moved beyond a laboratory prototype. Its trajectory is attractive if the Wix deployment reflects repeatable product-market fit rather than a highly customized founder-led implementation: the company can become an access layer for an expanding population of human-directed and autonomous software, with security, IT, developer, and compliance budgets converging around one control point. The key diligence questions are: (1) can Willow reproduce 600-tool and 300,000-call scale at non-founder-connected customers; (2) do runtime controls stop real prompt-injection, excessive-permission, and data-exfiltration paths without unacceptable latency or developer friction; (3) how are agent identities, delegated credentials, secrets, and revocation handled under failure; (4) does the endpoint and browser discovery layer cover unmanaged tools without creating privacy or employee-monitoring liability; (5) can the company defend against identity-suite bundling and open-source gateway substitutes; (6) does the $7 million seed support the connector, support, compliance, and enterprise-sales burden implied by the product surface; and (7) can self-hosted or air-gapped deployments retain feature parity while meeting sovereign data and supply-chain requirements. The record merits monitoring as a high-quality Israeli cyber-resilience signal, but public traction remains concentrated, performance claims are company-reported, and strategic value should rise only after independent customer references, security evidence, and non-Wix expansion are documented.

Dual-Use Assessment

Military & Commercial Applications

Willow has direct defensive-security and resilience dual-use relevance because its core product governs how autonomous software receives identity, reaches tools and data, and performs actions. (1) Defense contractors, intelligence organizations, government agencies, utilities, hospitals, and emergency operators all face the same problem: AI agents need useful access to internal systems, but standing permissions and opaque tool chains create unacceptable cyber and operational risk. (2) Task-scoped permissions, runtime approvals, prompt-injection protection, PII redaction, shadow-MCP discovery, and human-attributed audit can support zero-trust adoption of agents in high-consequence environments. (3) Self-hosted and fully air-gapped deployment options are relevant to sovereign or restricted networks if the claims survive technical and accreditation diligence. The connection is infrastructure-level rather than weapons-level, and no reviewed source confirms a defense customer, classified deployment, military contract, FedRAMP authorization, MIL-STD qualification, or disconnected tactical-network operation. Willow should therefore be treated as a credible strategic cyber-enabler with unrealized defense-market optionality, not as a fielded defense supplier.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

Willow is a high-signal early cybersecurity company whose value proposition is tied to a structural change in enterprise computing: non-human software is acquiring permissions and acting across systems faster than conventional identity governance can adapt. (1) The product addresses a concrete control-plane problem rather than a generic AI feature, combining identity, task-scoped access, runtime policy, shadow-AI discovery, and audit attribution. (2) Hetz Ventures led a $7M Seed, with Wix’s top executives as early angels, and the company reports production use at Wix across thousands of users, hundreds of tools, and hundreds of thousands of weekly calls. (3) The founders bring unusually direct experience from building Wix AI infrastructure, authentication and integrations, web platforms, and cybersecurity systems. (4) Strategic upside is meaningful because the same access controls matter to defense contractors and critical-infrastructure operators adopting agents. Counterweights are substantial: the flagship reference is relationship-linked, public metrics are inconsistent and company-reported, the market includes identity incumbents and open gateways, total headcount and recurring revenue are undisclosed, and the company’s moat may be integration quality rather than unique underlying primitives. This is an internal strategic-priority assessment, not an investment recommendation.

Strategic Value to U.S.-Israel Alliance

Willow’s strategic value lies in placing a policy and accountability layer between autonomous software and the systems that organizations depend on. (1) AI adoption creates a new class of machine identity that can be probabilistic, multi-tool, delegated by a human, and capable of taking consequential actions; existing IAM and endpoint tools do not automatically provide task-level attribution or runtime control. (2) A neutral access plane can reduce dependence on provider-specific agent security and provide one governance surface across ChatGPT, Claude, Gemini, Cursor, Codex, custom agents, and MCP-based tools. (3) For resilience, the product can help keep AI-enabled operations usable while limiting blast radius when an agent, connector, prompt, or credential is compromised. (4) For Israeli and allied cyber ecosystems, the founders’ Wix platform experience and the company’s potential for self-hosted or air-gapped deployment are relevant, though neither proves sovereign or defense adoption. Strategic value remains conditional on independent control validation, non-Wix customer expansion, secure secret handling, and evidence that policy enforcement works under degraded, restricted, and high-consequence operating conditions.

Key Technologies

  • Agent-layer identity and delegated credentials inherited from enterprise identity providers such as Okta, Entra, Active Directory, and JumpCloud
  • Runtime task-scoped tool generation and least-privilege authorization instead of blanket OAuth grants or standing agent access
  • AI-agent gateway for MCP servers, internal APIs, third-party tools, skills, plugins, and custom agents across multiple model providers
  • Runtime guardrails including prompt-injection protection, PII redaction, app-aware permissions, and pre-action approval workflows
  • Shadow-AI discovery through browser extension and endpoint agent for unsanctioned agents, MCP servers, skills, and external integrations
  • Human-attributed, real-time audit trails streamed to SIEM systems with SaaS, dedicated-cloud, self-hosted, and air-gapped deployment modes

Use Cases & Applications

  • Governing developer agents that access Git, Jira, Slack, Figma, Grafana, documentation, and internal infrastructure tools
  • Allowing finance, HR, legal, and operations staff to use approved AI workflows without manually configuring MCP integrations
  • Detecting and controlling shadow AI tools, MCP servers, browser extensions, and skills installed on corporate endpoints
  • Enforcing task-specific least privilege and approval gates before an agent changes production data, identity settings, or business records
  • Creating a human-attributed audit trail for autonomous software actions in regulated enterprise environments
  • Operating an AI access gateway for defense-industrial, government, utility, healthcare, or emergency-response networks with restricted deployment requirements
  • Connecting custom internal APIs and multi-model agents through one policy and connector control plane

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.

This record lists 8 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

  • Willow — Official Website Primary company site for Willow's Agentic Access Platform positioning, mission, platform navigation, enterprise audience, and official identity.
  • About Willow — The Basecamp for AI Agent Work Verifies the company mission, agent identity and access concept, founders Eyal Ben Ezra, Shalev Shalit, and Idan Chetrit, their roles, and the stated Wix, AI, identity, integration, and cybersecurity backgrounds.
  • Willow Launches with $7M to Build the Future of Enterprise AI Agent Governance Official launch and financing source verifying the June 2026 $7M Seed led by Hetz Ventures, the former Webrix name, the Wix production deployment, reported user/tool/call metrics, listed additional deployments, deployment modes, connector and guardrail claims, and company-reported headquarters.
  • How Wix scaled AI-native work to 5,000 employees with Willow Official customer case study verifying the Wix use case, nearly 600 tools, more than 300,000 weekly tool calls, cross-functional deployment, Git/Jira/Slack/Figma/Grafana and internal-tool integrations, enterprise MCP gateway requirements, and Willow's identity, access, audit, shadow-MCP, and prompt-injection positioning.
  • Wix CEO backs Willow as startup raises $7 million for AI agent control layer Independent CTech coverage verifying the $7M Seed, Hetz Ventures lead, early backing from Avishai Abrahami and Nir Zohar, former Wix founding team, Herzliya base, platform purpose, and public development-partner context.
  • בוגרי Wix הקימו את Willow וגייסו 7 מיליון דולר Hebrew Calcalist coverage corroborating the Seed financing, Hetz Ventures lead, founders, Herzliya location, and the platform's management, visibility, access-control, and AI-agent security thesis.
  • Willow גייסה 7 מיליון דולר לפיתוח פלטפורמת פיקוח על סוכני AI בארגונים Israeli technology-trade coverage corroborating the Seed round, Agentic Access category, support for ChatGPT, Claude, Gemini, Cursor, Codex and custom agents, more than 1,000 connectors, Wix deployment among more than 5,000 employees, and expansion toward cybersecurity, fintech, and real estate customers.
  • Willow — Cyber Company Profiles Secondary research profile used cautiously to cross-check the former Webrix identity, a 2024 founding-year discrepancy, the $7M June 2026 Seed, Herzliya location, Wix concentration, Innovid reference, and the governed-gateway product description; its analysis is not treated as independent audit evidence.
  • Profile update timestamp Last updated in the Claw & Talon database on Aug 31, 2026.

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.