Dossier · Private startup · 1 independent source

Zenity

Cybersecurity Dual-Use Technology Priority Signal Founded 2021

Last updated: Jul 31, 2026

Zenity is a private cybersecurity company building an AI agent security and governance platform for agents running across SaaS, cloud, and end-user devices. Its controls cover discovery, posture management, execution context, threat detection, policy enforcement, and response for enterprise agents, copilots, and low-code applications.

Visit Website

Company Overview

Zenity began in 2021 as a security and governance company for low-code and no-code development, then expanded that same control problem into enterprise AI agents. The product is now presented as an agent-centric security platform with three connected functions: surface the agents and applications an organization has, enforce guardrails over what they can access and do, and protect them through detection and response. This is more specific than generic AI governance. Zenity focuses on the execution layer, including agent identity, tools, permissions, memory, data access, control flow, and the sequence of actions that leads to an outcome. Its current coverage claims include Microsoft Copilot and Copilot Studio, Salesforce Agentforce, AWS Bedrock, Google Vertex AI, ChatGPT Enterprise, Claude Enterprise, ServiceNow, Power Platform, and coding assistants such as GitHub Copilot, Cursor, and Claude Code.

The customer problem is credible and expanding. Enterprises are deploying agents made by professional developers, business users, and employees using low-code platforms, often across environments that were previously governed by separate AppSec, identity, endpoint, data-loss-prevention, and cloud tools. An inventory of models or prompts is insufficient when an agent can retain context, call external tools, read sensitive records, execute code, or chain actions over time. Zenity's proposed answer is continuous visibility and policy at the decision point: identify who owns an agent, what it can reach, how it behaves, whether the action is consistent with its intended task, and whether to allow, flag, redact, or block it. The low-code heritage is strategically useful because citizen-built automations remain a major source of undocumented applications and over-broad access, but it also creates a positioning challenge as the company competes for budgets labeled AI security, application security, identity, or data security.

Zenity has stronger commercialization signals than the prior Series A label implied. Its official timeline records a $5M seed in 2021, a $16.5M Series A led by Intel Capital in September 2023, a strategic investment from Microsoft's M12 in July 2024, and a $38M Series B co-led by Third Point Ventures and DTCP in October 2024. The company says it serves large enterprises across financial services, technology, manufacturing, energy, and pharmaceuticals, and its website publishes anonymized customer outcome metrics; these are company-reported signals rather than independently audited revenue or retention evidence. A current LinkedIn company profile places Zenity in the 201–500 employee band and identifies New York as its primary headquarters with a Tel Aviv location. Current hiring and product material suggest an international go-to-market operation, but public sources do not establish exact headcount, ARR, customer concentration, renewal rates, or deployment scale.

The competitive field is converging quickly. Zenity competes with AI security and AI-SPM vendors such as Protect AI, HiddenLayer, Lakera, Prompt Security, and Noma Security, while also facing substitutes from Microsoft, cloud providers, identity vendors, EDR/XDR platforms, DSPM products, and internal security engineering. Its potential edge is the combination of agent inventory, low-code governance, execution-path telemetry, and preventative runtime controls across SaaS, cloud, and endpoint surfaces. Its AgentFlayer research and public work on prompt injection and agent behavior may strengthen credibility with security practitioners, but research visibility is not the same as durable product differentiation. The key diligence question is whether customers receive reliable cross-platform enforcement and measurable reduction in risky actions, or mainly another discovery and alerting layer.

For defense, intelligence, and critical-infrastructure users, the dual-use case is substantive but indirect. The platform could help govern copilots, coding agents, workflow automation, and mission-support applications that handle sensitive documents, credentials, operational data, or privileged tools. Context-aware monitoring and the ability to interrupt unsafe actions are relevant where an accidental disclosure, poisoned context, or destructive autonomous step can have operational consequences. However, public evidence does not show a defense contract, classified deployment, security accreditation, or mission-specific integration. Strategic relevance therefore rests on the transferability of commercial agent controls into high-assurance environments, subject to procurement, isolation, logging, supply-chain, and authorization requirements that are not demonstrated in the public record.

Dual-Use Assessment

Military & Commercial Applications

Zenity's core capability is security governance and runtime protection for autonomous software, not a defense-specific product. That capability has credible dual-use relevance because defense, intelligence, and critical-infrastructure organizations are also deploying copilots, coding agents, and workflow automation with access to sensitive data and privileged tools. The transfer case is strongest for agent inventory, least-privilege policy, execution-path monitoring, prompt-injection detection, and blocking unsafe actions. Public sources do not establish defense contracts, classified deployments, accreditation, or mission-specific performance, so the defense thesis should remain a strategic adjacency rather than a proven revenue vertical.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

Zenity is a credible strategic-fit startup for a dual-use technology database because it addresses a fast-forming security control point created by autonomous software, while its low-code governance origin provides a practical enterprise wedge. The Series B, named institutional investors, public product expansion, research program, and current hiring indicate meaningful commercial maturity. This remains a diligence priority signal rather than an investment recommendation: the principal questions are net-new platform differentiation, enforceable coverage across rapidly changing agent frameworks, customer retention and expansion, gross-margin impact of integrations, and whether the product can win against bundled controls from cloud and security incumbents.

Strategic Value to U.S.-Israel Alliance

Zenity could become a control layer for autonomous software in enterprises and regulated environments. Its strategic value is highest where organizations need one view of agent identity, permissions, context, and behavior across SaaS, homegrown cloud systems, and endpoints, then need to intervene before a risky action completes. That is relevant to commercial AI adoption, cyber resilience, and future defense or critical-infrastructure deployments. The value is not yet proven as a defense franchise: buyers would need evidence of high-assurance deployment, integration with existing security operations, reliable policy enforcement under adversarial conditions, and support for strong isolation and audit requirements.

Key Technologies

  • Agent discovery and inventory across SaaS, cloud, and endpoint environments
  • Agent security posture management for permissions, tools, memory, and configuration
  • Execution-path telemetry covering tool calls, data access, context, and control flow
  • Intent-aware detection and response for prompt injection and unintended agent actions
  • Policy-based prevention, redaction, alerting, and runtime action blocking
  • Low-code/no-code application and automation governance
  • Cross-platform integrations for enterprise copilots, coding agents, and agentic cloud services

Use Cases & Applications

  • Inventorying sanctioned and shadow AI agents built in Copilot Studio, Salesforce, cloud platforms, and internal applications
  • Detecting over-permissioned agents and remediating risky tools, connectors, secrets, and data paths before deployment
  • Monitoring coding assistants in IDEs, CLIs, and cloud environments for sensitive-file access, tool misuse, and unsafe changes
  • Detecting prompt injection, poisoned context, data exfiltration, and destructive autonomous actions at runtime
  • Applying governance to citizen-built low-code apps, workflows, automations, and enterprise copilots
  • Reducing exposure of regulated customer, financial, health, operational, and credential data to agent actions
  • Providing auditable guardrails for public-sector, defense-support, and critical-infrastructure automation where high-impact actions require oversight

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.

This record lists 6 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

  • zenity.io Public source used for profile verification.
  • zenity.io Public source used for profile verification.
  • Company announcement Public source used for profile verification.
  • LinkedIn company page Public source used for profile verification.
  • zenity.io Public source used for profile verification.
  • zenity.io Public source used for profile verification.
  • Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.