Clover Security

Application SecurityDeveloper Tools also known as Clover, Clover AI Inc.

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software.
Founded 2023
Funding $36M
Last updated 2026-09-11

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Clover Security sells AI agents that find security flaws before code is committed. Its customers are in banking, enterprise technology, and fintech, including Fortune 500 organizations. The agents work in Confluence, Jira, GitHub, Cursor, and Slack and read engineering teams' specs, tickets, and code. Named customers include Udemy, ServiceTitan, Lemonade, Virgin Money, Plaid, Notion, PROS, Neo4j, Clari, and Lead Bank. Founded in 2023, it raised a $6 million seed led by Team8 and a $30 million round led by Notable Capital. Team8 says it reached millions in annual recurring revenue before leaving stealth. Clover discloses no patent or proprietary dataset behind the agents. A rival would take longest to reproduce Clover's customer roster and its integrations with those developer tools.

Sourced Details

Description Product security company whose AI agents work inside developer tools such as Confluence, Jira, GitHub, Cursor, and Slack to catch design flaws early and review code changes before issues reach production. [f1]
Founded 2023 [f2]
HQ Tel Aviv, Israel [f3]
Funding $36M total [f3]
Latest funding $30M round led by Notable Capital (November 2025) [f4]

Products

Product What it does
Discovery agent Surfaces critical changes and blind spots, collects missing information from builders, and prioritizes risky features for security review.
Design review agent Runs autonomous or assisted reviews for any change, providing business-logic checks, actionable feedback, and guidance to keep systems secure.
Security policy agent Turns organization standards into clear, shippable requirements and streamlines security checklists and questionnaires.
Threat modeling agent Auto-generates continuous application-level and code-level threat models from the existing codebase, diagrams, and documents.
Developer guidance agent Provides builders with secure, reusable patterns and instant feedback right where they work.
Governance agent Reports design posture, measures adherence to standards, and tracks the maturity and impact of secure-design activities.
MCP agent Gives visibility into AI-generated code, enforces organizational policies for coding agents, and secures MCPs across AI-driven development.
Vibe coding agent Continuously evaluates vibe-coding output and shadow AI for misconfigurations, excessive permissions, and missing controls to enforce policy-driven guardrails.

Matrix Coverage

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

Clover's discovery and design review agents read specs, tickets, and code across developer tools to surface insecure designs, then guide builders toward secure patterns before code ships. These capabilities use AI to defend conventional software and are mapped to the Cyber Defense Matrix. [f5]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Emerging 24 /40 Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 The buyer, product security teams, is named, but the 49 percent to 100 percent review-coverage figure is a customer testimonial published on Clover's own site, and the lead investor Team8 is not independent, so the pain is customer-supplied rather than independently quantified. [s1, s4, s6]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 The product page names eight agents spanning discovery, design review, threat modeling, policy, governance, and AI-generated-code coverage, embedded across Confluence, Jira, GitHub, Cursor, and Slack, and Team8 corroborates the workflow-embedded design. No public technical documentation, architecture page, or third-party evaluation was fetched, holding the evidence at adequate rather than strong. [s2, s3]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 The enabler is AI-assisted development, which the founders set out to address when they started Clover in 2023, but buyer-side demand traces to the company's own customer adoption and the lead investor's framing rather than an analyst category or budget-line signal, and no such category exists yet. [s1, s4, s6]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 Co-founders Alon Kollmann and Or Chen are described as product security veterans, and Chen's prior startup was acquired by Checkmarx, a verifiable same-domain exit. That is one prior exit rather than the sustained multi-exit or publication record a higher score requires, so the team signal is adequate. [s5, s6]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 4/5 Clover publishes many named reference customers, including Udemy, ServiceTitan, Lemonade, Virgin Money, Plaid, Notion, Neo4j, and Lead Bank, with CISOs quoted, and press and Team8 corroborate millions in recurring revenue reached during stealth. The named traction across multiple sources meets the bar a 4 requires. [s4, s6, s1]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 Clover raised a 30 million dollar round on top of a 6 million dollar seed and reached millions in recurring revenue with dozens of customers at an early stage, visible output per dollar. The raise is sized to the enterprise motion the named customers imply, but private margins leave efficiency unconfirmed from outside. [s4, s6]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 Buyers can place Clover in the existing product security and application security budget line without coaching. Clover and Team8 use the design-led product security framing, and no analyst-recognized category by that name was retrieved in this review, so placement is adequate rather than category-defining. [s5, s2]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 2/5 Application-security and ASPM platforms whose scanners already operate one step downstream could extend upstream into design-stage review. Clover's embedding across developer tools is real friction, but no proprietary cross-customer data asset is evidenced in the record, leaving the core value absorbable by an adjacent platform. [s2, s4]
Business Risks Application-security and ASPM platforms whose scanners customers already run could add design-stage review and remove the standalone reason to buy Clover…
  • Application-security and ASPM platforms whose scanners customers already run could add design-stage review and remove the standalone reason to buy Clover.
  • GitHub and Cursor are integration surfaces today and could ship native security review inside the same developer tools Clover depends on.
  • The millions in recurring revenue and the share of review Clover automates are vendor and investor figures from Clover's own deployments, not independently audited.
  • Design-led product security is Clover's own phrasing rather than an analyst-recognized category, so the budget line it occupies could stay contested.
  • Clover's trust center shows a SOC 2 Type II report but no ISO 27001 certification, a narrower compliance gap than a full absence for a tool that reads source code and internal design documents.
  • No proprietary cross-customer data asset is evidenced in the reviewed record, so nothing yet locks customers in beyond the workflow embedding itself.
Problem & Market Clover addresses security review at the design stage rather than after code is written. It names a concrete buyer in the product security team and a quantified pain a customer CISO states on the record: manual review covered 49 percent of tickets, and with Clover's automation that reached 100 percent. The framing is that AI-native development has moved faster than security can follow. Engineering and product teams make security-relevant decisions daily in tickets, docs, and AI-assisted editors, and a small product security team cannot keep up. Clover's lead investor and independent press describe the same detection-too-late condition the company is built to address, so the problem is a recognized industry pain rather than a vendor invention…

Clover addresses security review at the design stage rather than after code is written. It names a concrete buyer in the product security team and a quantified pain a customer CISO states on the record: manual review covered 49 percent of tickets, and with Clover's automation that reached 100 percent.

The framing is that AI-native development has moved faster than security can follow. Engineering and product teams make security-relevant decisions daily in tickets, docs, and AI-assisted editors, and a small product security team cannot keep up. Clover's lead investor and independent press describe the same detection-too-late condition the company is built to address, so the problem is a recognized industry pain rather than a vendor invention. [s1, s4, s6]

Product Capabilities Clover runs AI agents inside the tools where software is designed and built, rather than in a separate security console. The product page names eight agents covering discovery of risky changes, design review, security policy, threat modeling, developer guidance, governance reporting, an MCP agent for AI-driven development, and a vibe coding agent that evaluates AI-generated code and shadow AI for misconfigurations and missing controls. The agents work across Confluence, Jira, GitHub, Cursor, and Slack, reading the same specs, tickets, and code that product and engineering teams use, and layering security review on top. Team8's investment writeup describes the same workflow-embedded design. No public technical documentation, architecture page, or third-party evaluation was fetched this analysis to validate the agent behavior beyond these descriptions…

Clover runs AI agents inside the tools where software is designed and built, rather than in a separate security console. The product page names eight agents covering discovery of risky changes, design review, security policy, threat modeling, developer guidance, governance reporting, an MCP agent for AI-driven development, and a vibe coding agent that evaluates AI-generated code and shadow AI for misconfigurations and missing controls.

The agents work across Confluence, Jira, GitHub, Cursor, and Slack, reading the same specs, tickets, and code that product and engineering teams use, and layering security review on top. Team8's investment writeup describes the same workflow-embedded design. No public technical documentation, architecture page, or third-party evaluation was fetched this analysis to validate the agent behavior beyond these descriptions. [s2, s3]

Competitive Positioning Clover positions one step upstream of the application-security scanners enterprises already run. The established application-security and ASPM vendors act once a code artifact exists, while Clover's claim is to review the design before code is committed, in the tickets and docs those tools never see. The pressure runs in two directions. The scanner and ASPM vendors downstream could extend their reach upstream into design review, and the developer platforms Clover integrates with, GitHub and Cursor among them, could ship native security review inside the same tools. Clover's embedding across the design workflow is real friction, but the position is upstream of incumbents who own the adjacent budget rather than insulated from them…

Clover positions one step upstream of the application-security scanners enterprises already run. The established application-security and ASPM vendors act once a code artifact exists, while Clover's claim is to review the design before code is committed, in the tickets and docs those tools never see.

The pressure runs in two directions. The scanner and ASPM vendors downstream could extend their reach upstream into design review, and the developer platforms Clover integrates with, GitHub and Cursor among them, could ship native security review inside the same tools. Clover's embedding across the design workflow is real friction, but the position is upstream of incumbents who own the adjacent budget rather than insulated from them. [s2, s4]

Go-to-Market & Traction Clover's commercial traction is its strongest signal…

Clover's commercial traction is its strongest signal. The company publishes many named reference customers, including Udemy, ServiceTitan, Lemonade, and Virgin Money among public companies and Plaid, Notion, Neo4j, PROS, Clari, and Lead Bank among private ones, with CISOs quoted by name. That is a deeper named-customer roster than most companies show this early.

Press and Team8 report that Clover reached millions in annual recurring revenue while still operating in stealth, and the lead investor at Notable Capital calls that rare for a seed-stage security company. The named customers corroborate the adoption, while the revenue figures themselves remain the company's and its investors' own statements rather than audited numbers. [s4, s6, s1]

Team & Credibility Clover was founded in 2023 by Alon Kollmann, the CEO, and Or Chen, the chief product officer, both described by Team8 and press as product security veterans. The two met in 2022 while Kollmann was pursuing an MBA in France and Chen was finishing his tenure at Checkmarx. The verifiable signal is that Chen's prior startup was acquired by Checkmarx, a same-domain exit before Clover. That is a single prior exit rather than the repeat-founder record or sustained publication standing that marks the strongest teams in this cluster, so the founder signal supports the company without carrying it…

Clover was founded in 2023 by Alon Kollmann, the CEO, and Or Chen, the chief product officer, both described by Team8 and press as product security veterans. The two met in 2022 while Kollmann was pursuing an MBA in France and Chen was finishing his tenure at Checkmarx.

The verifiable signal is that Chen's prior startup was acquired by Checkmarx, a same-domain exit before Clover. That is a single prior exit rather than the repeat-founder record or sustained publication standing that marks the strongest teams in this cluster, so the founder signal supports the company without carrying it. [s5, s6]

Trust Readiness Clover reads source code and internal design documents across a customer's developer tools, which makes its own security posture a procurement question. The privacy policy describes a software-as-a-service product that includes a Clover plugin for Claude Code, so its reach extends into AI coding assistants. Clover's trust center at trust.clover.security publishes a SOC 2 Type II report and application and corporate penetration-test reports, so a public compliance posture exists for a tool that ingests design documents and code. The remaining gap is ISO 27001, which the trust center does not show, and the named enterprise customers suggest some buyers have already cleared their own review…

Clover reads source code and internal design documents across a customer's developer tools, which makes its own security posture a procurement question. The privacy policy describes a software-as-a-service product that includes a Clover plugin for Claude Code, so its reach extends into AI coding assistants.

Clover's trust center at trust.clover.security publishes a SOC 2 Type II report and application and corporate penetration-test reports, so a public compliance posture exists for a tool that ingests design documents and code. The remaining gap is ISO 27001, which the trust center does not show, and the named enterprise customers suggest some buyers have already cleared their own review. [s7, s2, s8]

Competitors Apiiro, Snyk, Semgrep…
Company Relationship Note Compare
Apiiro competes with Listed as an analyst comparison: an application security posture vendor in the same budget line as Clover, the nearest catalog neighbor to its design-stage motion.
Snyk competes with Listed as an analyst comparison: a developer-first application security incumbent in the adjacent budget line Clover sells into.
Semgrep competes with Listed as an analyst comparison: a code-stage application security scanner adjacent to Clover's earlier design-stage motion. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.

Add analyzed competitors to compare them side by side with Clover Security.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Exposed 12 /21 Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software. pivot urgently

Clover is durable where it is early and embedded. Its agents plug into the developer tools where software is designed, so a customer that drops Clover reabsorbs the design-review coverage and rebuilds that workflow wiring, a real cost in effort though nothing breaks in production. That embedding, and a named-customer roster across banking, fintech, and enterprise technology, is the hardest part to take away. The rest a funded competitor could rebuild: the product is AI agents pointed at each customer's own specs and code, with no patent, outside technical validation, or proprietary cross-customer dataset, and its SOC 2 attestation is what any code-reading vendor carries. Watch whether the scanners downstream or the developer tools Clover rides on add design-stage review of their own.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Clover delivers software the customer configures and runs, AI agents that produce reviews, findings, and guidance against the customer's own artifacts. That output is the product, not a human-expertise service that accepts accountability for the result.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Clover embeds across Confluence, Jira, GitHub, Cursor, and Slack, so a customer that leaves reabsorbs the design-review coverage and rebuilds that workflow wiring. The cost is real in effort rather than in broken production, and the integration depth is early rather than a proven multi-year system of record.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 Clover holds a SOC 2 Type 2 attestation, the table-stakes credential a vendor reading source code and design documents is expected to carry. No ISO 27001 or line-specific regulatory mandate that would lock buyers in or bar rivals appears on the public trust center.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 2/3 Reasoning about design intent and business-logic flaws from unstructured specs and tickets is a non-trivial problem. The public record shows no patent, third-party technical evaluation, or architecture detail evidencing a durable engineering barrier, and the observable approach is AI agents across developer-tool integrations rather than proprietary program-analysis a funded rival could not readily reproduce.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 Clover sells top-down to product security leaders through an evaluation-led motion with no self-serve tier, and its named references cluster in banking, fintech, and enterprise technology, including Fortune 500 organizations. That is an evidenced demanding buyer rather than an aspirational one.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 Clover's agents sit in the design and delivery path, reading specs, tickets, and code across the developer tools where software is built. They are a review-and-guidance overlay, though, whose removal would not break a customer's running production systems.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 The product is AI agents pointed at each customer's own documents and code, with no named non-public dataset or cross-customer data asset in the record. A funded rival could rebuild that approach without a proprietary corpus to overcome.
Strategic Market Segmentation Clover sells to product security teams inside companies that build software quickly with AI assistance. The buyer is a small security function that has to keep pace with far larger engineering and product organizations, and Clover's pitch is to reach the design stage those teams cannot manually cover. The segment is the pre-code phase that application-security scanners never see. Team8 frames the gap plainly: products now start life in documents, tickets, chats, and AI-assisted editors, while product security stays anchored at the end, scanning code and triaging findings. Clover positions itself where design and architecture decisions are still being shaped. The customers named in the public record cluster in banking, fintech, and enterprise technology, including Fortune 500 organizations, which points Clover at regulated, high-stakes buyers rather than individual developers…

Clover sells to product security teams inside companies that build software quickly with AI assistance. The buyer is a small security function that has to keep pace with far larger engineering and product organizations, and Clover's pitch is to reach the design stage those teams cannot manually cover.

The segment is the pre-code phase that application-security scanners never see. Team8 frames the gap plainly: products now start life in documents, tickets, chats, and AI-assisted editors, while product security stays anchored at the end, scanning code and triaging findings. Clover positions itself where design and architecture decisions are still being shaped.

The customers named in the public record cluster in banking, fintech, and enterprise technology, including Fortune 500 organizations, which points Clover at regulated, high-stakes buyers rather than individual developers.

Product Capabilities & AI Advantages Clover's product is a set of AI agents that read the same specs, tickets, discussions, and code engineering teams already work in, and layer security reasoning on top. The platform names eight agents covering discovery of risky changes, design review with business-logic checks, security policy, threat modeling, developer guidance, governance reporting, an MCP agent for AI-driven development, and a vibe coding agent that watches AI-generated code for misconfigurations and missing controls. The claimed advantage is reasoning about design intent rather than pattern-matching code. A design review agent that reads a Jira ticket and flags an insecure business-logic decision does something a downstream scanner cannot, because the scanner acts only once code exists. Clover describes its agents as context-aware, detecting risks and running reviews inside the developer's workflow. The limit is evidence. No public technical documentation, architecture page, or independent evaluation was found in the reviewed sources to test how well the agents reason, so the capability rests on the vendor's own descriptions and its customers' testimonials rather than an outside benchmark…

Clover's product is a set of AI agents that read the same specs, tickets, discussions, and code engineering teams already work in, and layer security reasoning on top. The platform names eight agents covering discovery of risky changes, design review with business-logic checks, security policy, threat modeling, developer guidance, governance reporting, an MCP agent for AI-driven development, and a vibe coding agent that watches AI-generated code for misconfigurations and missing controls.

The claimed advantage is reasoning about design intent rather than pattern-matching code. A design review agent that reads a Jira ticket and flags an insecure business-logic decision does something a downstream scanner cannot, because the scanner acts only once code exists. Clover describes its agents as context-aware, detecting risks and running reviews inside the developer's workflow.

The limit is evidence. No public technical documentation, architecture page, or independent evaluation was found in the reviewed sources to test how well the agents reason, so the capability rests on the vendor's own descriptions and its customers' testimonials rather than an outside benchmark.

Sales Engagement & Go-to-Market Clover sells top-down to security leaders through an evaluation-led motion, with no self-serve tier or public trial. The primary call to action on the site is to book a demo, and the proof it offers is named customers with their security leaders quoted, including a CISO, David Fox, quoted on the homepage. The traction is unusual for the company's age. Team8, which led Clover's seed round, reports Clover reached millions in annual recurring revenue while still in stealth at seed stage, and calls that rare for a security startup. The named roster spans banking, fintech, and enterprise technology, deeper evidence of adoption than most companies show this early. The figures come with a caveat. The revenue and the share of review Clover automates are the company's and its investors' own statements, not independently audited, so the traction is well-attested by named logos but unverified in its numbers…

Clover sells top-down to security leaders through an evaluation-led motion, with no self-serve tier or public trial. The primary call to action on the site is to book a demo, and the proof it offers is named customers with their security leaders quoted, including a CISO, David Fox, quoted on the homepage.

The traction is unusual for the company's age. Team8, which led Clover's seed round, reports Clover reached millions in annual recurring revenue while still in stealth at seed stage, and calls that rare for a security startup. The named roster spans banking, fintech, and enterprise technology, deeper evidence of adoption than most companies show this early.

The figures come with a caveat. The revenue and the share of review Clover automates are the company's and its investors' own statements, not independently audited, so the traction is well-attested by named logos but unverified in its numbers.

Pricing Model Clover publishes no pricing…

Clover publishes no pricing. The site carries no plans, no per-unit rates, and no free tier, and routes every visitor to a book-a-demo request instead.

Hidden pricing usually signals a negotiated enterprise motion, where deals are sized per customer rather than listed, which fits the named roster of banks and large software companies. What Clover charges by, whether seats, repositories, or review volume, is not disclosed, so a buyer cannot anchor the cost to the unit it uses to measure the problem before contacting sales.

Product Delivery & Operations Clover delivers its agents as software that plugs into the tools a customer already runs, not as a separate security console. The agents work across Confluence, Jira, GitHub, Cursor, and Slack, reading the artifacts in place and returning reviews and guidance where builders already are. Reviews run autonomously or with a person in the loop, and Clover describes the threat-modeling coverage as continuous rather than a point-in-time scan. That in-workflow delivery is the core of the product experience: security review arrives as in-workflow feedback inside the developer's existing flow instead of a task in a separate queue…

Clover delivers its agents as software that plugs into the tools a customer already runs, not as a separate security console. The agents work across Confluence, Jira, GitHub, Cursor, and Slack, reading the artifacts in place and returning reviews and guidance where builders already are.

Reviews run autonomously or with a person in the loop, and Clover describes the threat-modeling coverage as continuous rather than a point-in-time scan. That in-workflow delivery is the core of the product experience: security review arrives as in-workflow feedback inside the developer's existing flow instead of a task in a separate queue.

Earning Customers' Trust Clover's own security posture is a live procurement question, because its agents read source code and internal design documents across a customer's tools. A vendor with that level of access has to clear its buyers' security reviews before it can deploy. Clover runs a trust center that publishes a SOC 2 Type 2 report. That is the table-stakes attestation a code-reading vendor is expected to hold, and the public compliance page shows no ISO 27001 or AI-specific certification alongside it. The named enterprise customers, several in regulated banking and fintech, suggest buyers have already put Clover through their own vendor reviews, which is a form of validation even where the formal certificate set is thin…

Clover's own security posture is a live procurement question, because its agents read source code and internal design documents across a customer's tools. A vendor with that level of access has to clear its buyers' security reviews before it can deploy.

Clover runs a trust center that publishes a SOC 2 Type 2 report. That is the table-stakes attestation a code-reading vendor is expected to hold, and the public compliance page shows no ISO 27001 or AI-specific certification alongside it.

The named enterprise customers, several in regulated banking and fintech, suggest buyers have already put Clover through their own vendor reviews, which is a form of validation even where the formal certificate set is thin.

Platform Strategy & Ecosystem Positioning Clover's reach depends on the developer platforms it integrates with rather than infrastructure it owns. The agents ride on Confluence, Jira, GitHub, Cursor, and Slack, and an MCP agent extends the same idea to AI coding tools, giving security visibility into AI-generated code and enforcing policy for coding agents. That embedding cuts both ways. Sitting inside the tools where work already happens is what makes Clover sticky, but the same tools are controlled by companies large enough to add design-stage checks themselves. GitHub and Cursor are integration surfaces today and possible competitors tomorrow if either ships native security review where Clover operates. The AI-development ecosystem is also where Clover places its newest bets, with agents aimed at securing coding assistants and the MCP connections they use, an area still forming rather than settled…

Clover's reach depends on the developer platforms it integrates with rather than infrastructure it owns. The agents ride on Confluence, Jira, GitHub, Cursor, and Slack, and an MCP agent extends the same idea to AI coding tools, giving security visibility into AI-generated code and enforcing policy for coding agents.

That embedding cuts both ways. Sitting inside the tools where work already happens is what makes Clover sticky, but the same tools are controlled by companies large enough to add design-stage checks themselves. GitHub and Cursor are integration surfaces today and possible competitors tomorrow if either ships native security review where Clover operates.

The AI-development ecosystem is also where Clover places its newest bets, with agents aimed at securing coding assistants and the MCP connections they use, an area still forming rather than settled.

Team & Execution Capability Clover was founded in 2023 by Alon Kollmann, the CEO, and Or Chen, the chief product officer, both product security veterans. The two met in 2022 while Kollmann was pursuing an MBA in France and Chen was finishing his tenure at Checkmarx, which had acquired Chen's previous startup before Clover. The company is small and scaling, employing about 40 people, roughly 30 in Israel, with plans to double headcount in 2026. It was seeded by Team8 and later raised a Series A led by Notable Capital. The backing carries unusual signal. Beyond the institutional investors, The Notable Capital round also drew the Wiz co-founders Assaf Rappaport and Yinon Costica, Shlomo Kramer of Cato Networks, and senior executives from Snyk, CrowdStrike, Palo Alto Networks, Atlassian, and Google, a concentration of security-industry operators that is itself a credibility marker for a company this young…

Clover was founded in 2023 by Alon Kollmann, the CEO, and Or Chen, the chief product officer, both product security veterans. The two met in 2022 while Kollmann was pursuing an MBA in France and Chen was finishing his tenure at Checkmarx, which had acquired Chen's previous startup before Clover.

The company is small and scaling, employing about 40 people, roughly 30 in Israel, with plans to double headcount in 2026. It was seeded by Team8 and later raised a Series A led by Notable Capital.

The backing carries unusual signal. Beyond the institutional investors, The Notable Capital round also drew the Wiz co-founders Assaf Rappaport and Yinon Costica, Shlomo Kramer of Cato Networks, and senior executives from Snyk, CrowdStrike, Palo Alto Networks, Atlassian, and Google, a concentration of security-industry operators that is itself a credibility marker for a company this young.

Sources

Company Detail Sources (5)
Id Source Tier Accessed
f1 Clover Security homepage official 2026-06-24
f2 Design-Led Product Security: Why We Invested in Clover (Team8) press 2026-06-24
f3 Clover Security Raises $36 Million to Secure Software by Design (SecurityWeek) press 2026-06-24
f4 With support from Wiz founders and Shlomo Kramer, Clover raises $30 million (CTech) press 2026-06-24
f5 The Clover Platform product page official 2026-06-24
Profile Analysis Sources (8)
Id Source Tier Accessed
s1 Clover Security homepage
“Manual review covered 49% of tickets, but with Clover's automation we hit 100%. That's not just pretty impressive, that is impressive. David Fox, CISO”
official 2026-06-24
s2 The Clover Platform product page, eight named agents
“Discovery agent. Design review agent. Security policy agent. Threat modeling agent. Developer guidance agent. Governance agent. MCP agent: gain comprehensive visibility into AI-generated code. Vibe coding agent: continuously evaluate vibe-coding and shadow AI for misconfigurations.”
official 2026-06-24
s3 Team8: How Clover works, agents inside the product workflow
“Clover's AI agents work across the systems where design and delivery already happen, Confluence, Jira, GitHub, Cursor, Slack and more. They read the same specs, tickets, discussions and code that product and engineering teams use every day, and layer security reasoning directly on top.”
press 2026-06-24
s4 CTech: Clover funding, founders, and traction
“Clover Security has raised $30 million in a round led by Notable Capital, with participation from Team8, which led the company's $6 million Seed round in 2023. Clover was founded in 2023 by Alon Kollmann (CEO) and Or Chen (CPO).”
press 2026-06-24
s5 CTech: Clover founders met in 2022, Chen at Checkmarx
“The two met in 2022, when Kollmann was pursuing an MBA in France and Chen was completing his tenure at Checkmarx, which had acquired Chen's previous startup.”
press 2026-06-24
s6 Team8: Clover customers and ARR in stealth
“Its customers include public leaders such as Udemy, ServiceTitan, Lemonade, and Virgin Money, and high-growth innovators such as Plaid, Notion, PROS, Neo4j, Clari, and Lead Bank. It is rare for a security startup to reach millions in ARR while still in stealth and at seed stage.”
press 2026-06-24
s7 Clover Security privacy policy
“our proprietary software as-a-service solution, including the Clover Plugin for Claude Code”
official 2026-06-24
s8 Clover Trust Center
“Compliance: SOC 2 Type 2. Resources: Application Penetration Testing, Corporate Penetration Testing.”
official 2026-06-24
Deep-Dive Sources (10)
Id Source Tier Accessed
s1 Clover Security homepage
“Manual review covered 49% of tickets, but with Clover's automation we hit 100%. That's not just pretty impressive, that is impressive. David Fox, CISO”
official 2026-07-08
s2 The Clover Platform product page, eight named agents
“Context-aware agents detect risks, run reviews, guide builders in workflows, and verify in code without slowing delivery.”
official 2026-07-08
s3 Team8: How Clover works, agents inside the product workflow
“Clover's AI agents work across the systems where design and delivery already happen, Confluence, Jira, GitHub, Cursor, Slack and more. They read the same specs, tickets, discussions and code that product and engineering teams use every day, and layer security reasoning directly on top.”
press 2026-07-08
s4 CTech: Clover founders and the Checkmarx exit
“Clover was founded in 2023 by Alon Kollmann (CEO) and Or Chen (CPO). The two met in 2022, when Kollmann was pursuing an MBA in France and Chen was completing his tenure at Checkmarx, which had acquired Chen's previous startup.”
press 2026-07-08
s5 Clover Trust Center, compliance
“Compliance: SOC 2 Type 2.”
official 2026-07-08
s6 Team8: Clover customer roster and segments
“banking, enterprise technology, and fintech, including Fortune 500 organizations. Its customers include public leaders such as Udemy, ServiceTitan, Lemonade, and Virgin Money, and high-growth innovators such as Plaid, Notion, PROS, Neo4j, Clari, and Lead Bank.”
press 2026-07-08
s7 CTech: Clover funding round
“Clover Security has raised $30 million in a round led by Notable Capital, with participation from Team8, which led the company's $6 million Seed round in 2023.”
press 2026-07-08
s8 Team8: Clover ARR reached in stealth
“It is rare for a security startup to reach millions in ARR while still in stealth and at seed stage.”
press 2026-07-08
s9 CTech: Clover angel investors
“Additional investors included SVCI, and several angel investors, including Wiz co-founders Assaf Rappaport and Yinon Costica, Shlomo Kramer of Cato Networks, and senior executives from Snyk, CrowdStrike, Palo Alto Networks, Atlassian, and Google.”
press 2026-07-08
s10 CTech: Clover headcount and hiring plan
“The company employs about 40 people, roughly 30 of them in Israel, and plans to double its workforce in 2026.”
press 2026-07-08

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.