Dossier · Private startup · 1 independent source
Zest Security
Last updated: Jul 31, 2026
Zest Security is a 2023-founded cybersecurity startup building an agentic exposure-management and risk-resolution platform. It correlates cloud, code, application, container, infrastructure-as-code, and software-supply-chain findings, then proposes prioritized remediation or mitigation paths for security and engineering teams.
Visit WebsiteCompany Overview
Zest Security sells an operational layer for organizations that already have substantial security telemetry but struggle to turn findings into closed risks. Its platform is designed to ingest findings from cloud-security, vulnerability-management, software-composition-analysis, application-security, and related tools; construct a data fabric representing assets, services, deployments, controls, policies, and owners; and trace a finding toward its root cause. The company describes a multi-agent architecture with separate functions for data modeling, root-cause analysis, risk prioritization, impact simulation, Security-as-Code generation, cloud-policy analysis, guardrail analysis, and resolution building. The product's stated output is a reviewable path to a patch, package update, configuration change, Terraform or CloudFormation change, or cloud-native compensating control. That focus on resolution distinguishes the product proposition from a dashboard that only aggregates alerts, although the commercial value depends on the accuracy, explainability, and adoption of the recommended changes.
The customer problem is credible and expensive: cloud environments change quickly, scanners produce overlapping findings, and security teams must coordinate with developers and cloud operators to determine exploitability, ownership, blast radius, and a safe fix. Zest says it supports AWS, Azure, and Google Cloud, operates as an AWS-hosted SaaS service with customer tenants in the US or Europe, and offers more than 50 integrations. Its FAQ states that the platform uses read-only cloud access and does not directly modify production, leaving execution to customer-controlled workflows. The company also says that customer data is not sent to external AI services, that an internal LLM runs within its AWS environment, and that it is SOC 2 compliant. These are relevant trust signals, but diligence should verify the scope and recency of the certification, tenant-isolation model, data-retention policy, model-evaluation process, and the controls around generated infrastructure changes.
Commercialization evidence is stronger than a purely conceptual or stealth-stage profile. Zest announced a $5M seed round from Hanaco Ventures, Silvertech Ventures, and angel investors in July 2024, exited stealth at the same time, and announced AWS Marketplace availability in April 2025. Its current site presents free-trial, security-team, and enterprise packages, and lists integrations, multi-cloud support, remediation pathways, mitigation pathways, Security-as-Code, validation, and ticketing or communication workflows. The company cites an 86% improvement in mean time to remediation and publishes customer commentary, including a quote attributed to Odyssey Therapeutics; these remain company-reported signals rather than independently verified operating metrics. The important diligence questions are the number and quality of production deployments, conversion from trial to paid subscription, renewal and expansion, accepted-fix rates, false-positive rates, and whether the platform reduces exploitable exposure rather than merely reorganizing tickets.
The competitive field spans CNAPP suites, vulnerability-remediation platforms, exposure-management vendors, and security workflow products. Zest may earn a wedge by connecting cloud and application context to a concrete, environment-specific path that addresses many related findings at once, including a mitigation option when patching is unavailable. The edge is not yet durable from public evidence: incumbents can bundle prioritization and AI assistance, while focused competitors can win on deeper data quality, narrower integrations, or established enterprise distribution. Its founders bring relevant backgrounds in enterprise security, cloud security, and Israeli intelligence, and the company has added leadership in AI research and data science, but the public record does not establish organizational scale or repeatable go-to-market execution.
Dual-use relevance is credible but indirect. Commercial enterprises, regulated organizations, public-sector agencies, and defense units all face cloud misconfiguration, vulnerability, software-supply-chain, and remediation-governance problems. A read-only, auditable system that helps prioritize and validate fixes could support defense DevSecOps and public-sector cloud hardening without requiring the product itself to be a weapons system. There is no public confirmation here of classified deployments, defense contracts, FedRAMP or equivalent accreditation, or government customers. Strategic relevance therefore rests on adaptable infrastructure-security workflow technology and the founders' security background, subject to deployment isolation, approval gates, evidence retention, procurement, and accreditation requirements.
Dual-Use Assessment
Zest has substantive but indirect dual-use potential: cloud exposure prioritization, root-cause analysis, Security-as-Code, and compensating-control workflows apply to commercial, regulated, public-sector, and defense DevSecOps environments. No defense customer, government contract, classified deployment, or government accreditation is publicly confirmed in the reviewed sources, so the score reflects adaptability rather than demonstrated defense traction.
Strategic Fit Assessment
Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.
Zest is a credible internal priority signal because it addresses a persistent security-operations bottleneck, has a live multi-cloud product, announced a $5M seed round, and established AWS Marketplace distribution. The signal is strategic and is not an investment recommendation. The strongest diligence questions are whether generated resolution paths are safe and accepted in production, whether customers achieve durable exposure reduction beyond ticket consolidation, how much proprietary environment and workflow data improves the system, and whether the company can sell against CNAPP incumbents. Public evidence supports product activity and early commercialization, but not yet revenue scale, retention, or repeatable enterprise distribution.
Strategic Value to U.S.-Israel Alliance
Zest could serve as a remediation and control-plane layer between security telemetry and engineering action. Its value is highest where organizations operate multiple clouds and scanners, have large vulnerability backlogs, and need to choose among patching, configuration changes, and temporary controls. For public-sector or defense users, the same workflow could improve cloud and software-supply-chain hygiene under staffing constraints. Strategic value remains conditional on tenant isolation, deployment boundaries, human approval, integration with authoritative asset inventories, evidence retention, model governance, and the security or procurement requirements of the target environment.
Key Technologies
- Multi-agent AI for exposure analysis, prioritization, and resolution planning
- Technical data fabric linking assets, services, deployments, owners, controls, and policies
- Root-cause, exploitability, reachability, business-criticality, and blast-radius analysis
- Impact simulation and digital-twin validation of proposed fixes
- Security-as-Code generation for Terraform, CloudFormation, and related IaC workflows
- Cloud-native mitigation using guardrails, policies, and existing security controls
- Agentless multi-cloud integrations across AWS, Azure, GCP, Kubernetes, code, and security tooling
Use Cases & Applications
- Prioritize exploitable cloud vulnerabilities using reachability, asset criticality, and remediation impact
- Correlate duplicate or related findings across CSPM, vulnerability, SCA, ASPM, container, and code tools
- Trace runtime or cloud exposures back to IaC, repositories, packages, configurations, and responsible owners
- Generate reviewable Terraform or CloudFormation changes for engineering approval
- Recommend cloud guardrails or compensating controls when a direct patch is delayed or unsafe
- Reduce Kubernetes, container-image, cloud-configuration, and software-supply-chain exposure
- Coordinate remediation context with CI/CD, ticketing, messaging, and ITSM workflows
- Support auditable cloud hardening and exposure governance in regulated or defense-adjacent environments
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.
This record lists 8 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- zestsecurity.io Public source used for profile verification.
- zestsecurity.io Public source used for profile verification.
- zestsecurity.io Public source used for profile verification.
- zestsecurity.io Public source used for profile verification.
- zestsecurity.io Public source used for profile verification.
- LinkedIn company page Public source used for profile verification.
- finsmes.com Public source used for profile verification.
- Official website
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.