All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Cyata's product finds the AI agents at work across a customer's cloud, software-as-a-service, and identity systems, shows what each one does, and limits what each is allowed to touch. Its founders previously worked at Check Point, Cellebrite, and the Israeli military-intelligence Unit 8200. Its researchers had published flaws in agent tooling, including a critical bug in LangChain, software used to build AI applications. About six and a half months after Cyata's public launch, Check Point announced its purchase in a set of deals estimated at around 150 million dollars. Cyata's customer proof is one eCapital case study, alongside homepage endorsements it does not call customers. Cyata's homepage now calls it a Check Point company and routes its demo link to Check Point's contact page.
| Description | Cyata is a control plane for AI agent identity. It helps organizations discover every AI agent across their environment, explain what each agent did and why, and enforce policies that control agent behavior. | [f1] |
|---|---|---|
| Acquisition | Check Point Software Technologies, announced 2026-02-12 | [f2] |
| Founded | 2024 | [f3] |
| HQ | Tel Aviv, Israel | [f4] |
| Funding | $8.5M total | [f5] |
| Latest funding | Seed, $8.5M led by TLV Partners (2025) | [f5] |
| Deployment | SaaS | [f6] |
| Product | What it does |
|---|---|
| Cyata | Cyata: Agentic identity control plane that discovers AI agents across SaaS and cloud environments, records each agent interaction for forensics, and enforces least-privilege access policies. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Cyata is an agentic identity control plane that discovers AI agents across SaaS and cloud environments, records each agent interaction for forensics, and enforces least-privilege access policies. It is mapped to the AI Defense Matrix. [f7]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Cyata names the security team buyer and the agentic identity gap, but Calcalist (s4) frames that gap qualitatively without independent quantification of the pain, leaving the buyer clear and the pain unquantified. [s1, s4] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 3/5 | The product pages describe discovery and least-privilege enforcement, and the team's disclosures now recorded in NVD and cve.org (LangGrinch as CVE-2025-68664, HashiCorp Vault code execution as CVE-2025-6000) show offensive depth, but those findings evidence the team rather than an external validation of Cyata's own product, which still has no docs portal, demo, or third-party evaluation. [s1, s11, s12] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | Enterprise AI agent and MCP adoption since 2024 is a credible enabler, but the buyer-side demand stays indirect (one customer, the founders' research argument, and the Check Point purchase per s5), short of multiple corroborated demand signals. [s7, s5, s4] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | Senior Check Point, Cellebrite, and Unit 8200 pedigree (s4) now pairs with a sustained, independently recorded disclosure stream: Vault Fault found 14 flaws in CyberArk and HashiCorp secret managers (s14), including HashiCorp Vault code execution as CVE-2025-6000 (s12), LangGrinch in LangChain Core as CVE-2025-68664 (s11), and three flaws in Anthropic's official Git MCP server (s15). That record in NVD and cve.org lifts the prior 3 to 4, above same-asset peers whose credentialed teams show no comparable published disclosure record. [s4, s14, s12, s11, s15] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 | The homepage carries one named public reference, an eCapital case study with a video testimonial from its VP of Technology and Compliance, behind a logo wall whose brands appear only as images that no text confirms as customers. One vendor-hosted reference plus TLV Partners backing and an acquisition indicate real interest, short of the multiple named references from several sources that earn a 4. [s1, s9, s4, s5] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | The 8.5 million dollar TLV Partners seed (s4) is proportional to an early stage with visible shipping, but the 150 million dollar Check Point deal covered Cyclops and a third startup alongside Cyata (s5, s6), so output per dollar is not independently confirmed. [s4, s5, s6, s1] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 | Cyata sells into agentic identity, a category still forming rather than an established budget line, and Calcalist (s4) frames it in the same emerging terms, so placement stays undifferentiated. [s1, s4, s5] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Discovering and governing AI agent identities sits close to the identity platforms and security suites that already hold the buyer, and the capability is absorbable by a larger vendor. Check Point acquiring Cyata rather than letting it stand alone shows that absorption pressure is real. [s5, s1, s4] |
Cyata treats the AI agents an enterprise runs as a new identity class that traditional access controls were never built to handle. The homepage frames the problem as agents querying data, calling APIs, and acting autonomously across cloud and SaaS, which security and IT teams cannot fully see or govern. The buyer is the security team standing up agents inside core business processes.
Independent reporting corroborates the gap beyond vendor marketing. Calcalist described a new class of digital worker that executes code, queries sensitive databases, and triggers automated workflows while operating outside the identity frameworks applied to human employees or service accounts. That framing establishes the oversight problem as real rather than vendor-invented.
Cyata positions autonomous action as the consequence that matters. The company argues that agents act at scale yet no one watches what they do, and that discovering, recording, and controlling each agent is what closes the gap before an unmonitored agent causes harm. [s1, s4]
The Cyata product is positioned as a control plane for agentic identity built around three jobs. The homepage describes discovering every AI agent in the organization, recording and explaining what each agent does, and controlling agent access through least-privilege policy, human-in-the-loop approvals, and real-time guardrails. It is meant to integrate with existing cloud, SaaS, and identity infrastructure rather than replace it.
The control layer is where the product claims to act. Cyata describes enforcing safer operational defaults such as least privilege and isolation boundaries, and gating sensitive capabilities like secret access and high-privilege tool execution in untrusted contexts. These are the controls a security buyer evaluating an agent-governance product would test against its own agents.
The research output demonstrates the same capability the product sells. Cyata researchers disclosed the Vault Fault flaws in CyberArk and HashiCorp secret managers, LangGrinch in LangChain Core, and three flaws in Anthropic's official Git MCP server, work now recorded in independent vulnerability databases. This original adversarial work on the identity and agent infrastructure the platform governs validates that the team finds the weaknesses the product is built to catch. [s1, s3, s14, s15]
Cyata competes in agentic identity against both independents and the identity platforms moving toward the same work. Token Security, Clutch Security, Astrix Security, and Oasis Security cover overlapping discovery, governance, and least-privilege enforcement for AI agents and non-human identities, while broader identity and security platforms are building adjacent controls. The category Cyata sells into is one larger vendors are validating by building toward it.
Cyata's visible differentiator is the offensive depth of its team, shown through research. The Vault Fault disclosures in CyberArk and HashiCorp secret managers, LangGrinch in LangChain Core, and the flaws in Anthropic's official Git MCP server give the company a public profile larger than its first funding round would otherwise support, and that research brand is harder for a bundled competitor to reproduce quickly.
The structural question is who owns the buyer, and the Check Point acquisition answered it for Cyata. A platform vendor bought the capability rather than letting it stand alone, which is the same pressure every independent in this group faces from identity platforms and cloud providers that already sit inside the enterprise stack. [s1, s6, s14]
Research is Cyata's clearest go-to-market engine, and it points outward rather than at named customers. The Vault Fault disclosures in CyberArk and HashiCorp secret managers and LangGrinch in LangChain Core drew attention to the founders as researchers worth following and opened enterprise conversations. This is demand generation through research rather than evidence of paid deployments.
Named commercial proof is still thin in the public record. The homepage carries one customer reference, an eCapital case study with a video testimonial from its VP of Technology and Compliance, alongside a logo wall whose brands, identifiable as Mercury, Nayax, Trigo, and Seemplicity from their image files, appear without any text naming them as customers. TLV Partners led the seed, which is investor conviction rather than buyer proof.
The acquisition itself is the strongest external signal. Check Point agreed to buy Cyata about seven months after it left stealth, which a larger vendor does only when it sees value, though it leans on an acquirer's judgment more than on a deep public roster of named references. [s8, s14, s9, s5]
The founders pair offensive-security craft with prior operating experience at established security companies. The team are alumni of Unit 8200, Cellebrite, and Check Point, and CEO and co-founder Shahar Tal was a senior executive at Cellebrite and Check Point before starting the company. Israel's Corporations Authority registers the business as Cyata Security Ltd, an active private company incorporated in 2024, and co-founders Dror and Baruch round out a small founding team.
The research record is the team's strongest public signal, and independent vulnerability databases now carry it. Cyata's Vault Fault project found 14 flaws in CyberArk and HashiCorp secret managers, including a HashiCorp Vault code-execution flaw that had been exploitable for over nine years, tracked as CVE-2025-6000. The team also disclosed LangGrinch in LangChain Core, tracked as CVE-2025-68664, and three flaws in Anthropic's official Git MCP server, a pattern of disclosures in the company's own product domain recorded in NVD and cve.org rather than a single covered event.
The acquisition adds outside recognition. Check Point agreeing to buy the company months after it left stealth is the kind of third-party validation that separates a research claim from a research record, and it ties the team's standing to a concrete commercial outcome. [s4, s13, s14, s12, s15]
Cyata's trust posture centers on the data its product handles when it inspects agent activity. The platform is positioned to observe agent actions in real time and enforce policy, which raises the question a buyer asks when a security product sees proprietary AI traffic, and the company answers it by emphasizing least-privilege and guardrail controls rather than broad data collection.
Cyata claims a SOC 2 Type II attestation on its own homepage. The footer carries a SOC 2 badge, an image at wp-content/uploads/2025/07/soc_2.svg that renders as a SOC 2 Type II mark, displayed beside the company's NVIDIA Inception badge.
What is missing is anything a procurement team can inspect behind that claim. The trust.cyata.ai subdomain resolves to an empty Notion shell with no controls list, and there is no downloadable report or self-serve trust portal, so a buyer can see the badge but cannot pull the audit period, scope, or auditor without a sales conversation. Sitting inside Check Point could improve that posture if the acquirer folds Cyata into its compliance program and supplies the artifacts an early independent had displayed but not yet made inspectable, though the public record does not yet document that coverage. [s1, s10]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Token Security | competes with | Discovers AI agents and non-human identities, governs their access, and enforces least privilege for the same enterprise buyer, the closest same-asset independent. | |
| Clutch Security | competes with | Secures non-human and AI agent identities with discovery and governance across the enterprise, overlapping Cyata's full motion. | |
| Astrix Security | competes with | Covers non-human identity and AI agent security with discovery and access governance for the same CISO buyer. | |
| Oasis Security | competes with | Manages non-human and AI agent identities with posture and least-privilege enforcement, contesting Cyata's governance layer. | |
| Okta | adjacent | Identity platform that already holds the buyer and could extend native governance to AI agents, absorbing the third-party budget line. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Microsoft | adjacent | Ships identity and agent security inside a broad platform and could bundle agent governance into deals enterprises already sign. | N/AMicrosoft is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product. |
Add analyzed competitors to compare them side by side with Cyata.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
pivot urgently
The clearest non-product asset is the research team's public record of breaking agent tooling, which the sources do not show holding rivals off. Agent discovery and least-privilege policy are engineering another security company can rebuild, the agent inventory is per-customer and rebuildable from the same telemetry, and the lone self-displayed SOC 2 badge is assurance a substitute can also earn. The fetched pages describe scanning and governing agents across SaaS, cloud, and identity systems without documenting agents authenticating through Cyata, so the analysis does not credit Cyata with sitting in the path agents use to authenticate, the position credential vaults and brokers occupy. A customer that has wired agent policy through Cyata faces real re-plumbing before it can leave.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Customers buy software that discovers, records, and governs AI agents and run it against their own environment, with no managed service, judgment layer, or accountability acceptance in the offer. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | A customer that adopts Cyata's agent discovery, dynamic identities, and least-privilege policy would need to rebuild that inventory, policy, and integration work to move elsewhere, friction inferred from the product's role rather than documented migrations, and no residency lock or network effect appears in fetched sources. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | Cyata publicly displays a SOC 2 badge, but the fetched record provides no inspectable report, audit scope, or broader held certifications, table-stakes assurance at the floor, and no mandate for this product class appears in the record. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Discovering active and latent agents across SaaS, cloud, and identity infrastructure through behavioral signals and enforcing least-privilege policy under adversarial pressure is applied security engineering, the specialty Cyata's research team demonstrated with the LangGrinch disclosure in langchain-core. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 | The named buyer is the enterprise CISO organization governing AI agents, with one public reference in eCapital, and the homepage routes buyers to a demo rather than a self-serve signup, so an enterprise sales motion and procurement review of the replacement path are inferred rather than documented. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Cyata discovers and governs agents by scanning the SaaS, cloud, and identity systems it reads from, and the fetched sources do not document agents authenticating through Cyata to function, so the record does not establish that Cyata is infrastructure the agents depend on to operate. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | The agent inventory Cyata builds is per-customer and rebuildable from the same telemetry, its research is published CVE work rather than a non-public corpus, and no named proprietary dataset or benchmark appears in fetched sources. |
Cyata aims at the enterprise security team standing up AI agents inside core business processes. The company frames the gap as a new class of digital worker that executes code, queries sensitive databases, and triggers workflows while operating outside the identity controls applied to human employees or service accounts. The buyer is the CISO organization that has to govern agents it cannot fully see.
The sprawl-discovery use case fits organizations whose agent use is already operational, and Cyata publicly positions the product for buyers just beginning to explore AI as well as those with agents deployed. Cyata describes discovering orphaned, shadow, and overly privileged agents across SaaS, cloud, and identity infrastructure, which presumes a buyer with enough agent sprawl to have lost track of it. That use case fits larger enterprises more naturally than small teams running a single copilot.
Named demand is thin but real. The homepage carries one public case study, an eCapital reference naming its VP of Technology and Compliance, alongside practitioner endorsements from a Tenable cloud-security leader and an Everon CIO, beside a wall of logo images that no text confirms as paying customers. The open question is how many of those logos convert to references now that Check Point owns the roadmap.
Cyata builds its capability claim around seeing agents other tools miss. The product discovers AI agents by scanning SaaS, cloud, and identity infrastructure and analyzing behavioral signals such as tool usage, API activity, and MCP interactions, catching active and latent agents including orphaned, shadow, and overly privileged ones. Discovery is the entry point, with recording and least-privilege enforcement layered on top.
The team's research is the strongest external proof that the capability is grounded in real agent behavior. Cyata researchers disclosed LangGrinch, a critical langchain-core flaw tracked as CVE-2025-68664 with a CVSS score of 9.3 that SiliconANGLE reports can exfiltrate secrets and potentially reach remote code execution, and the company's own research posts describe further work on Anthropic's official MCP server. That is original adversarial work on the exact agent infrastructure the platform governs.
The public research record is the clearest non-product asset the fetched sources demonstrate, rather than a unique technical artifact. Discovery by behavioral scanning and least-privilege policy is engineering a funded rival can also build, and no named non-public dataset or third-party accuracy benchmark appears in fetched sources. What the record shows is original adversarial work published in public. It does not show buyers choosing Cyata for that work, or how long a rival would need to build a comparable research profile.
Cyata's go-to-market engine is research that points outward rather than at named customers. Its LangGrinch disclosure against langchain-core drew independent coverage from SiliconANGLE, and Cyata's own research posts describe further work on agent tooling such as Anthropic's official MCP server, building a profile larger than a seed-stage company would otherwise hold. That coverage made Cyata's research team worth following, an attention and credibility engine rather than evidenced buyer demand.
Commercial proof in the public record stays light. The homepage shows one named case study, the eCapital reference, plus a set of practitioner testimonials and a logo wall whose brands appear only as images, and TLV Partners led the $8.5 million seed, which is investor conviction rather than buyer proof. There is no published customer count or revenue figure in fetched sources.
The acquisition short-circuits the usual go-to-market path. Check Point announced the purchase about six and a half months after Cyata left stealth, and Globes reports the technology will be integrated into Check Point's AI Security platform. No fetched source states what drove the deal, so the headline external event is an acquirer adding Cyata's capability rather than a deep roster of references the company built itself.
Cyata publishes no pricing in fetched sources, so the charged unit and list price stay private. The homepage routes a buyer to a demo and contact flow rather than a self-serve signup, which now points to Check Point's contact-us page. That demo-led entry reads as a negotiated enterprise motion aimed at the larger organizations the discovery pitch targets, though no fetched page states a charged unit, list price, or negotiated terms, so the enterprise-pricing read is an inference rather than a sourced fact. The absence withholds the budget-anchoring signal some peers publish.
Neither the price nor the charged unit is publicly disclosed. No fetched page names seats, events, agent count, or any other value meter, so the basis on which the platform charges stays unknown.
The hidden-price posture fits the stage and the buyer. An early company selling a governance layer to enterprise security teams typically negotiates each deal. How Cyata is packaged, priced, and contracted under Check Point does not appear in fetched sources, which describe the deal and a planned technology integration without addressing the commercial motion.
Cyata delivers as software the customer connects to its own environment. The product scans SaaS, cloud, and identity infrastructure to discover agents, assigns dynamic identities, records what each agent does, and enforces least-privilege policy, all running against systems the customer already operates. No managed-service or analyst-staffed option appears in fetched sources, so delivery reads as customer-connected software rather than an operated service.
The fetched pages describe an observe-and-govern operational footprint without documenting where enforcement sits. Cyata says it assigns dynamic identities, enforces policy guardrails that include automatic shutdowns and predefined human interventions, and feeds its agent logs into SIEM, SOAR, and compliance systems, so it depends on the SaaS, cloud, and identity sources it reads from. No fetched page describes deployment effort, topology, published uptime, or support SLAs.
The acquisition reshapes the delivery question going forward. Globes reports Cyata's technology will be integrated into Check Point's AI Security platform, while hosting, support, and packaging under that owner stay public unknowns in fetched sources.
Cyata displays one security attestation for a product that inspects privileged agent activity. The homepage footer carries a SOC 2 badge, an image at wp-content/uploads/2025/07/soc_2.svg with empty alt text, beside an NVIDIA Inception partner badge and an OWASP membership tier badge that are program affiliations rather than security certifications. That is a single self-displayed mark, not a broad attestation set.
Nothing behind the badge is inspectable in fetched sources. Beyond the SOC 2 badge, the homepage FAQ says Cyata logs support frameworks such as PCI, SOC 2, and ISO 27001, which is framework-support language rather than a held certification. No displayed ISO 27001 certification, downloadable report, audit scope, or inspectable trust portal appears in the cited public sources. A buyer can see the SOC 2 claim, and the cited public pages do not expose the audit period, scope, or auditor behind it.
The product handles sensitive material, which raises the assurance bar the single badge does not clear. Because Cyata observes agent actions, API activity, and identity data across a customer's environment, a buyer should resolve data-handling, retention, and model terms in a formal review. Post-acquisition packaging may change, but fetched sources do not show Check Point trust coverage extended to Cyata.
Cyata markets itself as a control plane for agentic identity, but the product reads as a layer on top of the existing stack. It scans SaaS, cloud, and identity infrastructure to find and govern agents, depending on those source systems, and the fetched sources do not document agents authenticating through Cyata to function. The control-plane claim is grounded in the governance view, while the sources leave the credential path unresolved.
Whatever its exact position, the capability is absorbable by larger owners. Discovery and least-privilege enforcement for agents is adjacent to the identity platforms and security suites that already sit inside the enterprise, so the governance layer Cyata builds is ground a larger owner can contest by extending products the buyer already runs.
A platform vendor bought Cyata months after its public launch, and Globes reports the technology is slated for integration into Check Point's AI Security platform. The packaging and timing of the product under its new owner are not yet public.
Cyata's credibility comes from a founding team with both offensive-security craft and prior operating experience. The company was founded in 2024 by CEO Shahar Tal, who previously worked at Check Point and was a senior executive at Cellebrite, together with CTO Baruch Weitzman and VP of R&D Dror Roth, and the wider team includes alumni of Unit 8200. That is verifiable in-domain pedigree rather than LinkedIn-only background.
The research record is the team's strongest public signal. Cyata published a sustained stream of adversarial findings in its own domain, from LangGrinch in langchain-core to its research on Anthropic's official MCP server, a pattern of disclosures rather than a single covered event. SiliconANGLE covered the LangGrinch work independently.
The acquisition ties the team's standing to a commercial outcome. Check Point announced the purchase months after Cyata left stealth, and the acquirer is a company the CEO previously worked for, though no fetched source states what drove the deal. Depth below the principals stays the open question fetched sources do not settle.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Cyata: The Control Plane for Agentic Identity | official | 2026-07-09 |
| f2 | CTech on Check Point acquiring Cyclops and Cyata | press | 2026-06-10 |
| f3 | Globes on Check Point acquiring three Israeli startups | press | 2026-06-14 |
| f4 | Times of Israel on Check Point acquisitions | press | 2026-06-14 |
| f5 | Calcalist on Cyata emerging from stealth with seed funding | press | 2026-06-13 |
| f6 | AI Defense Matrix Catalog entry | other | 2026-06-10 |
| f7 | AI Defense Matrix Catalog mapping | other | 2026-06-23 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Cyata homepage, control plane for agentic identity “Cyata helps you discover, explain, and control every AI agent in your organization” | official | 2026-06-13 |
| s2 | Cyata research and blog index “Cyata Research: LangGrinch Vulnerability in LangChain” | official | 2026-06-13 |
| s3 | Cyata research on LangGrinch in LangChain Core CVE-2025-68664 “marker-based serialization, untrusted model output, and later deserialization is a recurring risk shape” | official | 2026-06-13 |
| s4 | Calcalist on Cyata emerging from stealth with $8.5M seed “Cyata, a cybersecurity startup founded by alumni of Unit 8200, Cellebrite, and Check Point, has launched from stealth with $8.5 million in Seed funding led by TLV Partners.” | press | 2026-06-13 |
| s5 | Calcalist on Check Point acquiring Cyclops and Cyata “Check Point to acquire Cyclops and Cyata for $150 million in strategic Israeli cyber push” | press | 2026-06-13 |
| s6 | SecurityWeek on Check Point trio of acquisitions “Check Point Announces Trio of Acquisitions Amid Solid 2025 Earnings Beat” | press | 2026-06-13 |
| s7 | SiliconANGLE on Cyata's LangGrinch langchain-core disclosure “A new report out today from artificial intelligence security startup Cyata Security Ltd. details a recently uncovered critical vulnerability on langchain-core” | press | 2026-06-13 |
| s8 | The Hacker News on the critical LangChain Core serialization injection “Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection” | press | 2026-06-13 |
| s9 | Cyata homepage eCapital case study and customer logo wall “Case study Securing AI Agents at eCapital Stefan Lesaru VP, Technology & Compliance, eCapital Corp, beside logo wall img src wp-content/uploads/2026/02/mercury.svg, nayax.svg, trigo.svg, and seemplicity.svg” | official | 2026-06-16 |
| s10 | Cyata homepage footer SOC 2 Type II and NVIDIA Inception badges “img src wp-content/uploads/2025/07/soc_2.svg, empty alt, in block-footer image-logo block beside the NVIDIA Inception program badge” | official | 2026-06-16 |
| s11 | NVD CVE-2025-68664: LangChain Core serialization injection (LangGrinch) “Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerability exists in LangChain's dumps() and dumpd() functions. The functions do not escape dictionaries with 'lc' keys when serializing free-form dictionaries.” | regulatory | 2026-06-29 |
| s12 | CVE-2025-6000: arbitrary remote code execution in HashiCorp Vault via plugin catalog abuse “A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a plugin directory is set in Vault's configuration.” | other | 2026-06-29 |
| s13 | Israel Corporations Authority registry record: Cyata Security Ltd (company 516994662) “CYATA SECURITY LTD, company number 516994662, Israeli private company, status active, incorporated 06/06/2024, Tel Aviv-Yafo.” | regulatory | 2026-06-29 |
| s14 | The Hacker News on Cyata's Vault Fault disclosures in CyberArk and HashiCorp secret managers “The 14 vulnerabilities, collectively named Vault Fault, affect CyberArk Secrets Manager, Self-Hosted, and Conjur Open Source and HashiCorp Vault, according to a report from an identity security firm Cyata.” | press | 2026-06-29 |
| s15 | The Hacker News on Cyata's three flaws in Anthropic's official Git MCP server “A set of three security vulnerabilities has been disclosed in mcp-server-git, the official Git Model Context Protocol (MCP) server maintained by Anthropic, that could be exploited to read or delete arbitrary files and execute code under certain conditions.” | press | 2026-06-29 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Cyata homepage: control plane for agentic identity “See every agent in your organization. Instantly. Turn on the lights. In moments, you have full visibility of every agent across your environment, even those hiding behind tokens, ephemeral session, or SaaS apps.” | official | 2026-06-18 |
| s2 | Cyata homepage FAQ on agent discovery and policy enforcement “Cyata automatically discovers AI agents by scanning your SaaS, cloud, and identity infrastructure. It analyzes behavioral signals, such as tool usage, API activity, and MCP interactions, to detect active and latent agents. This includes orphaned, shadow, and overly privileged agents.” | official | 2026-06-18 |
| s3 | Cyata homepage eCapital case study and field testimonials “Case study Securing AI Agents at eCapital Stefan Lesaru VP, Technology & Compliance, eCapital Corp. Robert Burns Chief Security. Ryan Fritts CIO at Everon. Liat Hayun VP Product Management & Research, Cloud Security at Tenable.” | official | 2026-06-18 |
| s4 | Cyata homepage footer SOC 2 and NVIDIA Inception badges “img src cyata.ai/wp-content/uploads/2025/07/soc_2.svg (empty alt) beside cyata.ai/wp-content/uploads/2025/08/nvidia-inception-program-badge-rgb-1c-blk-for-screen-1.svg and 2025/10/OWASP_Tier.svg” | official | 2026-06-18 |
| s5 | Calcalist on Cyata emerging from stealth with seed funding “Cyata, a cybersecurity startup founded by alumni of Unit 8200, Cellebrite, and Check Point, has launched from stealth with $8.5 million in Seed funding led by TLV Partners.” | press | 2026-06-17 |
| s6 | Calcalist on the agent oversight gap (CEO Shahar Tal) “a new class of digital worker has begun executing code, querying sensitive databases, and triggering automated workflows. But these agents often operate outside traditional identity frameworks, lacking the controls, traceability, and accountability applied to humans or service accounts.” | press | 2026-06-17 |
| s7 | CTech on Check Point acquiring Cyclops and Cyata “Among the targets are Cyclops Security and Cyata. The valuation of the deals was not disclosed but is estimated at around $150 million in total, with around $85 million going towards the purchase of Cyclops, according to estimates.” | press | 2026-06-17 |
| s8 | Globes on Check Point acquiring three Israeli startups “The second acquisition is of Cyata, which was founded in 2024 by CEO Shahar Tal, who formerly worked for Check Point, together with CTO Baruch Weitzman, and VP R&D Dror Roth.” | press | 2026-06-17 |
| s9 | SiliconANGLE on Cyata LangGrinch langchain-core disclosure “A new report from Cyata Security Ltd. details a critical vulnerability on langchain-core, tracked as CVE-2025-68664 and dubbed LangGrinch, with a CVSS score of 9.3. The vulnerability can allow attackers to exfiltrate sensitive secrets and could potentially escalate to remote code execution.” | press | 2026-06-17 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.