All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Cato acquired Aim Security in September 2025 for an estimated 300 to 350 million dollars. The public record shows strong research and technical signals but limited standalone traction evidence, and it does not reveal how Cato apportioned the price. The runtime AI firewall and that research each take years of specialized expertise to build. Against that, the firewall is configurable screening software a larger vendor can ship, the cited record identifies no compliance certification earned by Aim itself, and EchoLeak was published as a public CVE rather than kept as a private dataset. The one edge that is hard to take away is the difficulty of the problem itself. For a buyer, Aim is now one capability inside Cato's network platform.
| Description | Aim Security, now Cato's AI Security for Applications, protects the AI apps and agents a company builds in-house. Its AI-Firewall inspects prompts, responses, and agent actions at runtime to detect jailbreaks and prompt injection. | [f1] |
|---|---|---|
| Acquisition | Cato Networks, announced 2025-09-03 , now Cato AI Security | [f2] |
| Founded | 2022 | [f3] |
| HQ | Tel Aviv, Israel | [f4] |
| Funding | $28M total | [f5] |
| Latest funding | Series A, $18M, June 2024 (led by Canaan Partners) | [f5] |
| Deployment | SaaS | [f6] |
| Product | What it does |
|---|---|
| Aim Security | Aim Security: AI security platform that secures employee use of public AI applications, shields private AI apps and agents with an AI firewall, and covers the AI development lifecycle with AI-SPM. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Aim Security secures employee use of public AI applications, shields private AI apps and agents with an AI firewall, and covers the AI development lifecycle with AI-SPM. It is mapped to the AI Defense Matrix. [f7]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Aim names a specific buyer, the enterprise security team enabling generative AI, and EchoLeak (CVE-2025-32711) shows the data-exposure risk is real in production, cataloged by NIST and summarized by the SANS NewsBites. The pain is demonstrated by a single severe exploit rather than independently quantified at enterprise scale, the present-but-unproven level. [s6, s8, s9] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 3/5 | The acquisition release and SecurityWeek both describe three use cases on one engine, and Aim Labs' EchoLeak probes the in-domain prompt-injection mechanism the AI Firewall defends. No third-party product benchmark or open-source code validates the capability, and the standalone documentation was absorbed after the acquisition, so concrete detail sits without an external validation point. [s1, s4, s8] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 | Demand signals cluster within the period: CTech frames the acquisition as part of an AI security arms race for technology and talent, and EchoLeak, cataloged by NIST as CVE-2025-32711, demonstrates a real production threat that pulls enterprise budgets toward AI security. The timing enabler is enterprise generative-AI adoption since 2023 and indirect prompt injection emerging as a demonstrated threat in 2025. [s10, s8, s6] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 | Founders Matan Getz and Adir Gruss bring IDF Unit 8200 backgrounds, and CTech reports angel investment from some Wiz founders and executives at Google and Palo Alto Networks, while Aim Labs' EchoLeak is a notable in-domain disclosure. The founders show no prior in-domain exit and a single disclosure is a public signal rather than a sustained publication record, matching the verifiable-experience level. [s4, s10, s6] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 | Finance of America is the one named reference customer, quoted by its CISO, and the roughly 300 to 350 million dollar acquisition CTech reports is a strong indirect signal that the company was worth buying. The public record stops short of multiple named references, so the score reflects one named customer plus the allowed indirect-signal adjustment. [s7, s10, s1] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | Aim raised 28 million dollars, and CTech reports a roughly 30-person team and a swift exit estimated at 300 to 350 million dollars, signals of a lean operation. The exit value is an estimate and no revenue or margin is disclosed, so the raise reads as proportional with visible shipping rather than independently confirmed efficiency. [s7, s10, s1] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 | SecurityWeek and the acquisition coverage place Aim in enterprise AI security, a category buyers recognize, but placement still leaned on vendor framing while the category was forming. The fold into Cato's network-security platform tends to blend it with that category, though Cato still markets the capability both standalone and platform-integrated. [s4, s1, s5] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | The acquisition shows the category being absorbed into an adjacent network-security platform rather than resisting it, and the research brand raised the cost of matching Aim's profile without building a structural moat that bundling could not eventually replicate. This is friction without a compounding advantage. [s1, s10, s4] |
Aim Security treats the enterprise rollout of AI as the asset under attack and sells a platform to secure it. The acquisition release frames three jobs on one engine: discovering and monitoring how employees use public AI tools such as Microsoft Copilot and Cursor, protecting a company's own AI applications and agents at runtime with an AI Firewall, and securing the AI development lifecycle with posture management. The buyer is the enterprise security team enabling AI use without losing control of its data.
Independent records corroborate the pain beyond vendor marketing. Aim Labs disclosed EchoLeak, a zero-click flaw in Microsoft 365 Copilot that NIST's National Vulnerability Database catalogs as CVE-2025-32711, where a single crafted email could make Copilot leak organizational data with no user click. The SANS NewsBites summarized the same finding for defenders, and The Hacker News reported Microsoft's own description of it as AI command injection rated critical, which shows the data-exposure risk Aim sells against is real rather than speculative.
The problem points at a structural weakness, not one product's bug. EchoLeak abused how an AI assistant mixes untrusted input with trusted internal data, the same trust-boundary failure that applies to any AI app or agent reaching into enterprise systems, which is the surface Aim's platform watches. [s1, s8, s9, s6]
The Aim platform runs three use cases on one core engine rather than a single point feature. The acquisition release describes shadow AI discovery across end-user AI interactions, an AI Firewall that enforces policy on traffic between users, agents, and internal AI applications at runtime, and AI Security Posture Management spanning the development lifecycle from training models to building custom agents. SecurityWeek, reporting independently, describes the same three use cases, which corroborates the scope beyond the vendor's own page.
The research output probes the mechanism the product defends. Aim Labs published EchoLeak and showed external untrusted input could manipulate Microsoft 365 Copilot's retrieval to exfiltrate data. Because that work targets the prompt-injection mechanism the AI Firewall is built to stop, it is in-domain validation, now independently cataloged by NIST and summarized by the SANS NewsBites, rather than a marketing claim.
A third-party product evaluation is still missing. No public benchmark, open-source code, or independent test of the AI Firewall's efficacy appears in the record, and after the acquisition the standalone Aim documentation was absorbed into Cato's platform site, so a buyer assessing depth today works from the acquisition release and press coverage more than a dedicated Aim docs portal. [s1, s4, s6, s8]
Aim competed in enterprise AI security against same-asset independents and the platforms now bundling the category. Lasso Security, Prompt Security, and Lakera contested the same buyer with runtime AI protection and employee-AI controls, and Noma Security covered adjacent discovery and governance. CTech describes a 2025 AI security arms race for technology and talent in which several of these independents were themselves acquired, putting overlapping capability inside larger suites.
Aim's visible differentiator was research depth. The EchoLeak disclosure gave a small company a public profile larger than its headcount, and that brand raised the cost for a rival to match Aim's standing, though it is a head start rather than a structural barrier. It positioned Aim as a credible independent while buyers were still learning which AI problems mattered.
The exit resolved the positioning in the platforms' favor. Cato, a network-security vendor that disclosed surpassing 300 million dollars in annual recurring revenue, bought Aim as its first acquisition and folded the product into its SASE platform. A company that warned enterprises about AI risk now ships as one capability of a network-security subscription, the bundling outcome independents in this category caution buyers about. [s10, s1, s5]
Research was Aim's clearest source of market visibility, and it pointed outward as much as at named accounts. The EchoLeak disclosure drew coverage across the security press and a SANS NewsBites summary, building inbound awareness and positioning Aim Labs as a serious research team. This is demand generation through a public finding that ran alongside the deployment evidence.
The named commercial proof is real but narrow. Finance of America is identified as a reference account, with its CISO Drew Robertson quoted that Aim secures the entire breadth of its GenAI use across public SaaS apps, enterprise chats, and internal developments. Beyond that one account, the company's claimed deployments across the Fortune 500 and Forbes Global 2000 appear without further named customers speaking publicly. The remaining signal is indirect and comes from CTech, which reports Cato paid an estimated 300 to 350 million dollars for a roughly 30-person team.
The motion ended in a sale rather than a scaled independent book of business. Aim raised 28 million dollars, emerged from stealth in January 2024, and was acquired in September 2025, a short arc across which the public record names one customer speaking publicly. [s7, s10, s1]
The founding team pairs Israeli intelligence pedigree with strong investor validation. Co-founders Matan Getz, the chief executive, and Adir Gruss, the chief technology officer, came from the IDF's Unit 8200, and CTech reports angel investment from some founders of Wiz and executives from Google and Palo Alto Networks. That participation is a credibility signal from people who have built and sold security companies.
The research record is the team's strongest public signal. Aim Labs published EchoLeak, an in-domain disclosure against a production AI assistant credited with a critical CVE, work that NIST cataloged and the security press covered widely. This is research in the company's own product category, which supports the team's standing, though one disclosure is a public signal rather than a sustained publication record.
The team's pace reinforces the signal. Dark Reading reported the 18 million dollar Series A closing within months of Aim leaving stealth, an unusually quick raise, though SecurityWeek dates the same round to June 2025. The founders sold the company within about three years of its 2022 founding. [s4, s6, s10]
Aim's trust posture now inherits Cato's, and Cato's is well documented. The Aim site redirects to Cato content and the product ships as Cato AI Security, so a buyer assesses assurance through Cato's public Trust Center rather than a standalone Aim page. The Trust Center presents named, downloadable attestations and a security questionnaire rather than a blank assurance page.
That program is company-level and substantial. The rendered Trust Center lists SOC 2 Type II, SOC 3, ISO 27001:2022, ISO 27017, ISO 27018, ISO 27701, PCI DSS, a NIST SP 800-53 attestation, HIPAA, TISAX, and GDPR. The open readiness item is whether these certificates explicitly scope the AI Security line rather than the network platform around it, a detail a careful security review would confirm in the Trust Center documents.
The research record adds to that assurance. The EchoLeak disclosure against a production AI assistant is public evidence the team understands the attacks the product defends, an in-domain signal a buyer can weigh alongside the inherited Cato attestations. [s11, s3, s6]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Lasso Security | competes with | Same-asset independent contesting the runtime AI protection and employee-AI control buyer that Aim served. | |
| Prompt Security | competes with | Same-asset independent covering employee AI use and app and agent runtime security, the closest analog to Aim's motion. | |
| Lakera | competes with | Runtime AI security specialist, acquired by Check Point, overlapping Aim's AI Firewall and guardrail positioning. | |
| Noma Security | adjacent | Covers AI discovery, posture, and runtime protection for the same enterprise AI buyer, adjacent to Aim's three use cases. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Microsoft | adjacent | Model and assistant provider that could ship native protection for the Copilot and agent surfaces Aim's firewall defends, removing the third-party budget line. | N/AMicrosoft is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product. |
Add analyzed competitors to compare them side by side with Aim Security.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
pivot urgently
Aim Security is hard to copy on the difficulty of the AI security problem and little else. Building a runtime AI firewall that screens AI interactions and producing the EchoLeak research that found a zero-click flaw in Microsoft 365 Copilot each take years of specialized expertise. Everywhere else the work is reproducible: a larger vendor can ship the same configurable screening software, the cited record shows no certification earned by Aim itself and leaves the scope of Cato's attestations for a buyer to confirm, the named regulated reference is a single finance CISO rather than a broad roster, and EchoLeak was published as a public CVE rather than banked as a private dataset. Cato acquired the company after a short standalone period, and the cited record documents no Aim revenue.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Aim delivers software the customer configures and runs, shadow AI discovery, an AI firewall, and posture management, the software-product level. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | The AI Firewall runs inline, enforcing policy on traffic between users, agents, and internal AI applications, so leaving means re-integrating and re-tuning, meaningful friction short of data residency or network effects. The lock-in basis is drawn from vendor architecture material rather than a named deployment. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | The cited record shows no compliance certification earned by Aim itself and names no regulation mandating an AI firewall, so it evidences no standalone compliance moat. The rendered Cato Trust Center is parent-level procurement cover whose scope over the AI Security line a buyer must confirm, not an Aim-earned position. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | A real-time AI firewall enforcing policy on interactions between users, agents, and internal AI applications, plus the Aim Labs research that found EchoLeak in Microsoft 365 Copilot, cataloged by NIST as CVE-2025-32711, sits in machine-learning and real-time territory that takes years of specialized expertise. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 | One named regulated reference appears in the record, Finance of America's CISO quoted on securing the breadth of GenAI use, alongside vendor-claimed work with organizations in the Fortune 500 and Forbes Global 2000. A single named regulated reference is thin footing. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | The AI Firewall is middleware that users, agents, and internal AI applications route traffic through, deployable as a standalone capability a customer can swap, a control layer beside the workload rather than infrastructure other software cannot replace. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | The EchoLeak disclosure that built Aim's name was published as a public CVE, cataloged by NIST, not a private corpus. The reviewed vendor pages identify no named non-public dataset behind the product, so the cited record does not establish a proprietary-data moat. Aim's co-founder is quoted in the acquisition release describing a platform grounded in research and patented technology, a claim that names neither a patent nor a dataset. |
Aim Security sold to the enterprise security team standing up generative AI without losing control of its data. The acquisition release frames the buyer as organizations in the Fortune 500 and Forbes Global 2000 that want to harness AI with trust and control, and the three use cases name the surfaces that team owns: employee use of public AI tools, internal AI applications and agents, and the AI development lifecycle.
The public positioning targets large enterprises and exposes a demo-led contact path. No public pricing or free tier appears in the record, so a direct enterprise motion into the regulated upper enterprise is an inference from that positioning rather than a documented sales model, and the named-target language points at large organizations where AI data exposure carries direct liability.
The segmentation widened across surfaces rather than buyers. By spanning employee AI, private applications and agents, and posture management on one engine, Aim addressed any enterprise adopting AI regardless of which models it ran, which broadened reach but placed it against both AI-security independents and the network and endpoint platforms now shipping their own AI controls.
The Aim platform ran three use cases on one core engine rather than a single point feature. The acquisition release claims shadow AI discovery across end-user AI interactions, an AI Firewall that enforces policy on traffic between users, agents, and internal AI applications, and AI Security Posture Management covering the development lifecycle from training models to building custom agents, with the unified engine as the common layer. SecurityWeek describes the same three use cases independently.
The research output probed the exact mechanism the product defends. Aim Labs disclosed EchoLeak, a zero-click flaw in Microsoft 365 Copilot that NIST catalogs as CVE-2025-32711, where external untrusted input could manipulate Copilot's retrieval to exfiltrate data. Because that work targets the prompt-injection mechanism the AI Firewall is built to stop, it is in-domain validation, independently summarized by the SANS NewsBites, rather than offensive research about an unrelated product.
The cited record contains no third-party product evaluation. The capability now appears as Cato's AI Security for Applications, blocking runtime AI attacks as a standalone capability or inside the SASE platform, so a buyer evaluating depth today works from the acquisition release and the Cato platform page rather than an independent benchmark or a dedicated Aim docs portal.
Research was Aim Security's clearest source of market visibility, and it pointed outward more than at named accounts. The EchoLeak disclosure drew wide coverage and a SANS NewsBites summary and positioned Aim Labs as a serious research team, demand generation through a public finding rather than a roster of paid deployments. The named-customer evidence is thin: one named pre-acquisition Aim customer quote, a finance CISO at Finance of America in the Series A announcement, on securing the breadth of the firm's GenAI use.
The acquisition is strategic context, not standalone traction. CTech reports Cato paid an estimated 300 to 350 million dollars for a roughly 30-person team that had raised 28 million, and the acquisition release says Cato surpassed 300 million dollars in annual recurring revenue. Those figures speak to the buyer's capacity and to Aim's strategic relevance, not to a scaled book of Aim-line business, because the cited record carries one named pre-acquisition Aim customer quote and broad vendor claims about Fortune 500 and Forbes Global 2000 organizations. The Cato platform page now displays customer references from Dayforce and MoonPay, and the Dayforce quote names Cato AI Security, the post-acquisition product name, though the page dates neither reference.
The company sold after a short standalone period. Aim raised 28 million dollars in total, closing an 18 million dollar Series A whose date the cited sources report inconsistently, the June 2024 announcement giving 2024 and SecurityWeek June 2025, and the company emerged from stealth in January 2024 and was acquired in September 2025. The cited record discloses no Aim revenue.
Aim Security published no public price, consistent with a negotiated enterprise motion. No rate card, metering unit, or free tier appears in the record, and the entry point was a sales conversation aimed at large organizations, the shape of a vendor selling to the Fortune 500 buyer it named.
The buying unit is not publicly answerable from the record. Because the AI Firewall inspects traffic between users, agents, and AI applications inline, cost would plausibly track the volume of AI interactions screened, but that is inference rather than a published unit.
After the acquisition the commercial terms move into Cato's selling motion. The capability is offered standalone or as part of Cato's converged SASE platform, with a migration path for standalone deployments; the early-2026 platform plan is acquisition-era history rather than current status. Whether it carries a separate price is not stated in the cited record.
Aim Security was delivered as an inline control the enterprise routed its AI traffic through, configuring policy rather than running detection itself. The AI Firewall enforces corporate security and governance policies on all interactions between users, AI agents, and internal AI applications and models, whether on premises or in a cloud data center, so a security team chose where the enforcement sat.
The operational promise tracks a moving attack surface. The platform pairs shadow AI discovery across employee tools such as Microsoft Copilot and Cursor with runtime guardrails and posture scans, so the operational job is enforcement that follows new risks rather than a static rule set.
The inline path raises the heavier operational question. A firewall in the production AI request flow becomes a dependency whose latency and availability a careful buyer examines. A converged deployment inherits Cato's platform posture, which the captured page marketed as low-latency security processing, while a standalone buyer must still confirm the AI-security service's own latency and service-level terms, which the cited record does not scope to that line.
The Aim line now answers its trust questions through the parent's program. The Aim site redirects to Cato content and the product ships as Cato AI Security, so a buyer assesses assurance through Cato's public Trust Center rather than a standalone Aim page.
That Trust Center presents company-level assurance, and it is substantial. The rendered page lists SOC 2 Type II, SOC 3, ISO 27001:2022, ISO 27017, ISO 27018, ISO 27701, PCI DSS, a NIST SP 800-53 attestation, HIPAA, TISAX, and GDPR, and it exposes downloadable reports and a security questionnaire. A procurement reviewer finds named attestations rather than a blank page, but the page does not prove the certificates scope the AI Security line rather than the network platform around it, so confirming report scope is a step the buyer must take.
The research record adds to that assurance. The EchoLeak disclosure against a production AI assistant is public evidence the team understands the attacks the product defends, an in-domain signal a buyer can weigh alongside the inherited Cato attestations.
Aim Security was built to be the runtime control point an enterprise placed over the AI it adopted, spanning employee tools, private applications and agents, and the development lifecycle from one engine. That breadth across three surfaces on a unified engine was the platform claim, a single layer rather than a point tool.
Outward, the company reached buyers across several named assistants, agent frameworks, and model platforms rather than tying to one model vendor. By covering public assistants such as Microsoft Copilot, coding agents such as Cursor, and local agents using Model Context Protocol servers, Aim worked across multiple vendors' AI tools rather than tying to one model vendor.
Inward, that neutrality is what the acquisition puts in tension. The product now belongs to one network-platform vendor whose pitch is converging security into a single-vendor SASE subscription, so the acquisition sets the firewall's vendor-neutrality against Cato's single-vendor pitch, a fit a buyer committed to a different network platform would weigh.
The founding team pairs Israeli intelligence pedigree with strong investor validation. Co-founders Matan Getz, the chief executive, and Adir Gruss, the chief technology officer, are alumni of the IDF's Unit 8200, and CTech reports the company drew angel investment from some founders of Wiz and executives from Google and Palo Alto Networks.
The research record is the team's strongest public signal. Aim Labs published EchoLeak, an in-domain disclosure against a production AI assistant credited with CVE-2025-32711, which NIST cataloged, research in the company's own product category rather than a single unrelated finding. The cited record contains one Aim Labs disclosure, EchoLeak, rather than evidence of a sustained research record.
The funding record is harder to read than it first appears. The June 2024 Series A announcement, carried on Dark Reading as a Business Wire press release rather than as independent reporting, dates the 18 million dollar round to 2024, where SecurityWeek dates the same round to June 2025. The founders sold the company within about three years of its 2022 founding, backed by cybersecurity founders and industry executives.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Cato Networks: AI Security for Applications | official | 2026-07-09 |
| f2 | Cato Networks acquires Aim Security | official | 2026-06-09 |
| f3 | Cato Networks acquires Aim Security | official | 2026-06-13 |
| f4 | Cato Networks Acquires AI Security Firm Aim Security | press | 2026-06-13 |
| f5 | Aim Security Closes 18M Series A to Secure Generative AI Enterprise Adoption | press | 2026-06-13 |
| f6 | AI Defense Matrix Catalog entry | other | 2026-06-09 |
| f7 | AI Defense Matrix Catalog mapping | other | 2026-06-23 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Cato Networks acquires Aim Security press release “Aim's leading AI security solution spans three AI security use cases, supported by a unified and advanced core engine” | official | 2026-06-29 |
| s2 | Cato AI Security for Applications platform page “Cato ensures the SASE cloud platform maintains optimal security posture, 99.999% service availability, and low-latency security processing for all users and locations, without any customer involvement.” | official | 2026-06-29 |
| s3 | Aim Security homepage (now redirects to Cato Networks content) “Cato's SASE platform converges networking, security, and access into a single, global, AI-powered cloud service that transforms enterprise infrastructure and empowers IT to securely and optimally connect users, sites, applications, and clouds anywhere business happens.” | official | 2026-06-29 |
| s4 | SecurityWeek: Cato Networks Acquires AI Security Firm Aim Security “Founded in 2022 to help organizations with the secure deployment of generative-AI utilities, Aim emerged from stealth in January 2024 with $10 million seed funding. The company raised an additional $18 million in June 2025.” | press | 2026-06-29 |
| s5 | SecurityWeek: EchoLeak AI Attack Enabled Theft of Sensitive Data via Microsoft 365 Copilot “'EchoLeak' AI Attack Enabled Theft of Sensitive Data via Microsoft 365 Copilot” | press | 2026-06-29 |
| s6 | The Hacker News: Zero-Click AI Vulnerability Exposes Microsoft 365 Copilot Data “The critical-rated vulnerability has been assigned the CVE identifier CVE-2025-32711 (CVSS score: 9.3). It requires no customer action and has been already addressed by Microsoft. There is no evidence that the shortcoming was exploited maliciously in the wild.” | press | 2026-06-29 |
| s7 | Dark Reading: Aim Security Closes 18M Series A to Secure Generative AI Enterprise Adoption “Aim secures the entire breadth of our GenAI use, no matter where it is applied, public SaaS apps, enterprise chats, or our own internal developments, said Drew Robertson, CISO at Finance of America.” | press | 2026-06-29 |
| s8 | NIST National Vulnerability Database: CVE-2025-32711 (EchoLeak) “Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.” | regulatory | 2026-06-29 |
| s9 | SANS NewsBites XXVII-45: EchoLeak Zero-Click Microsoft 365 Copilot Data Leak “EchoLeak: Zero-Click Microsoft 365 Copilot Data Leak. Microsoft fixed a vulnerability in Copilot that could have been abused to exfiltrate data from Copilot users. Copilot mishandled instructions an attacker included in documents inspected by Copilot and executed them.” | research | 2026-06-29 |
| s10 | CTech: Cyber unicorn Cato acquires Aim Security for $350 million “Cato Networks, is acquiring the young startup Aim Security for an estimated $300-350 million in cash and shares. This represents a swift and successful exit for a company founded just two and a half years ago, employing around 30 people and having raised $28 million to date.” | press | 2026-06-29 |
| s11 | Cato Networks Trust Center (rendered, lists SOC 2 Type II, ISO 27001, PCI DSS, NIST 800-53, HIPAA, TISAX) “Everything you need to complete your security review is here. Browse documents, certifications, and compliance details with confidence.” | official | 2026-06-29 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Cato Networks acquires Aim Security press release “Aim's leading AI security solution spans three AI security use cases, supported by a unified and advanced core engine” | official | 2026-06-29 |
| s2 | Cato AI Security for Applications platform page “Cato ensures the SASE cloud platform maintains optimal security posture, 99.999% service availability, and low-latency security processing for all users and locations, without any customer involvement.” | official | 2026-06-29 |
| s3 | Aim Security homepage (now redirects to Cato Networks content) “Cato's SASE platform converges networking, security, and access into a single, global, AI-powered cloud service that transforms enterprise infrastructure and empowers IT to securely and optimally connect users, sites, applications, and clouds anywhere business happens.” | official | 2026-06-29 |
| s4 | SecurityWeek: Cato Networks Acquires AI Security Firm Aim Security “Founded in 2022 to help organizations with the secure deployment of generative-AI utilities, Aim emerged from stealth in January 2024 with $10 million seed funding. The company raised an additional $18 million in June 2025.” | press | 2026-06-29 |
| s5 | SecurityWeek: EchoLeak AI Attack Enabled Theft of Sensitive Data via Microsoft 365 Copilot “'EchoLeak' AI Attack Enabled Theft of Sensitive Data via Microsoft 365 Copilot” | press | 2026-06-29 |
| s6 | The Hacker News: Zero-Click AI Vulnerability Exposes Microsoft 365 Copilot Data “The critical-rated vulnerability has been assigned the CVE identifier CVE-2025-32711 (CVSS score: 9.3). It requires no customer action and has been already addressed by Microsoft. There is no evidence that the shortcoming was exploited maliciously in the wild.” | press | 2026-06-29 |
| s7 | Business Wire release carried by Dark Reading: Aim Security Closes 18M Series A to Secure Generative AI Enterprise Adoption “Aim secures the entire breadth of our GenAI use, no matter where it is applied, public SaaS apps, enterprise chats, or our own internal developments, said Drew Robertson, CISO at Finance of America.” | press | 2026-06-29 |
| s8 | NIST National Vulnerability Database: CVE-2025-32711 (EchoLeak) “Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.” | regulatory | 2026-06-29 |
| s9 | SANS NewsBites XXVII-45: EchoLeak Zero-Click Microsoft 365 Copilot Data Leak “EchoLeak: Zero-Click Microsoft 365 Copilot Data Leak. Microsoft fixed a vulnerability in Copilot that could have been abused to exfiltrate data from Copilot users. Copilot mishandled instructions an attacker included in documents inspected by Copilot and executed them.” | research | 2026-06-29 |
| s10 | CTech: Cyber unicorn Cato acquires Aim Security for $350 million “Cato Networks, is acquiring the young startup Aim Security for an estimated $300-350 million in cash and shares. This represents a swift and successful exit for a company founded just two and a half years ago, employing around 30 people and having raised $28 million to date.” | press | 2026-06-29 |
| s11 | Cato Networks Trust Center (rendered, lists SOC 2 Type II, ISO 27001, PCI DSS, NIST 800-53, HIPAA, TISAX) “Everything you need to complete your security review is here. Browse documents, certifications, and compliance details with confidence.” | official | 2026-06-29 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.