All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Daylight runs security operations for companies that would otherwise staff a round-the-clock security team. AI agents investigate the alerts, and Daylight's own senior responders own the verdicts under a contract that commits the company to resolving them. Nine reviews of the service sit on Gartner Peer Insights, averaging 4.8. One reviewer chose Daylight in May 2026 after evaluating several vendors. Another rated it 3.0 in July 2026, under a headline about limited AI features. That is the thing to press in a reference call. Daylight shows SOC 2 and ISO 27001 badge images, and the trust page at its own trust subdomain answers Trust Center Unavailable, so neither report is readable there. Against 40 million dollars raised, no revenue or retention figure is in the reviewed record.
| Description | Managed security operations provider that runs detection, investigation, and response as a service, pairing AI agents with in-house security experts across endpoint, identity, cloud, SaaS, phishing, and data-loss alerts. | [f1] |
|---|---|---|
| Founded | 2024 | [f2] |
| HQ | Tel Aviv, Israel | [f3] |
| Funding | $40M total | [f4] |
| Latest funding | Series A, $33M (November 2025), led by Craft Ventures with Bain Capital Ventures and Maple VC | [f5] |
| Product | What it does |
|---|---|
| Daylight Managed Agentic MDR | Managed detection and response service where AI agents run investigations end to end and Daylight security experts own escalation and resolution under a contractual accountability commitment. |
| Daylight Managed Agentic Threat Hunting | Continuous threat hunting service where a Daylight expert sets the hypothesis and coordinated AI agents run IOC-based and hypothesis-based hunts across up to 90 days of customer telemetry. |
| Daylight Security Data Lake Service | Managed telemetry retention and search layer for Daylight MDR customers, with 90 days of hot storage, archival storage beyond that, and an agent that answers plain-English questions or runs KQL. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Daylight Managed Agentic MDR ingests endpoint, identity, cloud, and business-tool telemetry into a central data lake, then investigates and resolves the resulting alerts, with separate coverage for phishing and data-loss findings. It is mapped to the Cyber Defense Matrix. [f6]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Daylight states a specific buyer and a specific pain, that alert triage returns to the team the service was meant to relieve, and a verified buyer review on Gartner Peer Insights independently describes choosing an MDR provider to get round-the-clock monitoring without building an internal security operations center. No non-vendor source measures how much triage comes back, so only accounts Daylight publishes give the scale of the pain. [s2, s20, s16, s17] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 3/5 | The service pages set out a specific architecture, with task-scoped agents under a central orchestrator, a per-customer context layer Daylight calls Daylight Knowledge, a two-tier data lake reachable in plain English or KQL, and an MCP server that hands investigation context to outside AI assistants. No third-party technical evaluation, inspectable code, or public documentation portal appears in the reviewed sources, so a buyer has only the vendor's account of how it works. [s2, s4, s23, s5] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | One buyer-side stream in the record is independently documented, the nine verified ratings of the MDR service on Gartner Peer Insights, among them a May 2026 review from a transportation-sector manager who selected Daylight after evaluating multiple vendors. The enabler is agentic AI applied to managed security operations, which the record dates to 2025, the year Daylight left stealth and closed a Series A in November. Independent coverage of enterprise adoption traces to that funding announcement, so the record carries one kind of buyer-side signal rather than several. [s19, s20, s8, s10, s11] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 | Hagai Shapira and Eldad Rudich hold one prior in-domain build between them, the earliest engineering and product roles at Torq, with no exit in the reviewed record. Daylight lists Amnon Kushnir as head of security operations and publishes threat research under Oren Biderman's byline, and a SANS profile records people of those names presenting together in 2024, a link the reviewed sources do not make. That leaves a senior bench, short of plural prior builds or an independently recognized publication record. [s7, s24, s26, s11] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | SecurityWeek and Ctech articles each carry Cresta, McKinsey Investment Office, and The Motley Fool among dozens of enterprises, four published customer stories put Lusha, LiveView Technologies, Antidote Health, and The Motley Fool on the record with their security leaders quoted, and Gartner Peer Insights carries nine verified buyer ratings. No third-party revenue figure, retention figure, or analyst placement appears in the sources, so the scale behind the names stays unverified. [s8, s10, s18, s17, s13, s16, s19] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 2/5 | Daylight raised a 33 million dollar Series A three months after a 7 million dollar seed, reaching 40 million dollars within six months of leaving stealth, which a Ctech article puts down to investor urgency in the category. It shipped a data lake service, an MCP server, and a detection-visibility capability between June and July 2026. The record still carries no revenue, margin, or growth figure, against a team of 25 recorded in November 2025. [s10, s11, s21, s22, s23] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Gartner Peer Insights lists Daylight in one market, Managed Detection and Response, where nine reviews sit and the alternatives shown beside them are the Sophos, Arctic Wolf, and CrowdStrike managed detection products. SecurityWeek, Ctech, and SiliconANGLE articles each call the company MDR without prompting. Daylight markets a coined label of its own, and its service page still heads the offering a new model of MDR, so even the vendor keeps the category word. [s19, s20, s8, s10, s21, s2] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Running the service and accepting resolution accountability creates real friction, the context layer Daylight builds per customer deepens with use, and the data lake keeps the customer's telemetry on Daylight's side. The managed providers Daylight groups itself against already hold the customer relationship and can add the same agents, and the reviewed sources show no structural moat those providers could not eventually build. [s2, s14, s4] |
Daylight sells to security teams that want alert work finished rather than escalated. Its service page names the complaint plainly, that most alerts get escalated, that alerts arrive without the identity and cloud context needed to close them, and that the verdict arrives without the reasoning behind it. The buyer is a security leader who still ends up doing the triage.
Two published accounts describe that starting point. The Motley Fool had worked with established providers for several years, and its team compared what its provider had actually investigated against what its cloud security tool surfaced. LiveView Technologies ran an employee on-call rotation before it bought.
One account comes from outside the company. A verified buyer review on Gartner Peer Insights from May 2026 says the reviewer selected an MDR provider after evaluating multiple vendors, wanting round-the-clock monitoring without building an internal security operations center. What no non-vendor source supplies is a measure of how much triage returns to the buyer, so only accounts Daylight publishes give its size. [s2, s16, s17, s20]
Daylight describes a specific architecture on its service pages. Telemetry from identity, cloud, endpoint, and business systems flows into a central data lake. A central orchestrator dispatches task-scoped agents whose next step follows the evidence rather than a fixed playbook, and a context layer the company calls Daylight Knowledge holds policies, assets, and operations so an investigation reflects how the customer works.
Three services run on that base. The managed detection and response service covers detection through response, with security experts taking over complex or high-risk cases. The threat hunting service pairs an expert-defined hypothesis with agent execution across the customer's telemetry. The data lake keeps the last 90 days searchable and shifts older telemetry to archival storage that is rehydrated on demand, answering questions in plain English or in KQL directly.
Daylight extended the service twice in mid-2026. An MCP server, announced in June 2026, lets AI assistants such as Claude, Cursor, and VS Code Copilot pull investigation context through Daylight's APIs. Detection Program Visibility, announced in July 2026, shows customers the detections running for them, maps them to MITRE ATT&CK, and adds alert volume, case outcomes, overlap, and coverage gaps.
What the record lacks is validation from outside the company. No third-party technical evaluation and no public technical documentation appear in the reviewed sources. Daylight also writes detection rules against business tools such as Slack, GitHub, and Notion, and its coverage for AI systems rests on Claude Enterprise runtime telemetry, both of which a buyer has only the vendor's account of. [s2, s3, s4, s23, s22, s5, s1, s6]
Daylight names its own competitive set and sorts it into two groups. Its blog on SOC-as-a-service providers places Expel, ReliaQuest, Arctic Wolf, eSentire, Secureworks Taegis MDR, and Red Canary in the managed group, and it excludes Prophet Security and Dropzone AI from that comparison on the grounds that they are tools rather than managed services. The managed group holds the contract Daylight wants to replace.
Buyers reach for the same comparison. Gartner Peer Insights shows the top alternatives to Daylight's service as the Sophos, Arctic Wolf, and CrowdStrike managed detection products, which are all established providers rather than agentic newcomers.
Contractual ownership of the outcome is the difference Daylight leads with. It argues that established providers escalate too much and that AI tools leave the customer running the operation, and it offers to own the cycle from alert to resolution under a contractual commitment. Its service page heads the offering "A New Model of MDR" and says it is neither a traditional MDR nor an AI SOC tool, so a buyer meets the vendor's qualifications before meeting the service.
The established group already staffs and bills for the managed operation, so what Daylight adds on top of that model is the agentic investigation layer. A provider in that group could add the same layer to a service its customers already buy. [s14, s20, s2]
Daylight's traction shows up as named customers rather than numbers. SecurityWeek and Ctech articles each carry Cresta, McKinsey Investment Office, and The Motley Fool among dozens of enterprises, and place Daylight's operations across Asia, Europe, and North America. Four published customer stories add Lusha, LiveView Technologies, and Antidote Health, each with a named security leader on the record.
Independent buyer evidence now exists. Gartner Peer Insights carries nine verified ratings of the MDR service averaging 4.8, and one May 2026 reviewer says they selected the provider after evaluating multiple vendors. A July 2026 reviewer is critical, reporting slow onboarding of new alerts and AI capabilities that fall short of what they needed.
A buyer reaches Daylight through a sales conversation. The reviewed pages carry no price, no trial, and no self-service path, only a demo request. Gartner Peer Insights records the billing unit, a subscription typically structured by headcount and charged annually, and Lusha's proof-of-concept criteria asked for per-headcount or per-entity pricing rather than per-source or per-gigabyte. The amount stays undisclosed.
Revenue, retention, and contract-value figures are all absent from the reviewed sources. A buyer can confirm that enterprises bought and cannot tell what those accounts are worth or how long they last. An MSSP Alert brief states a reduction in false positives of up to 90 percent in its coverage of the funding round, and no buyer or independent evaluator states that figure in the reviewed record. [s8, s10, s18, s16, s17, s13, s19, s20, s12]
Both founders held the earliest technical and product roles at Torq, whose own founders press coverage groups among cybersecurity founders. Hagai Shapira and Eldad Rudich met at 18 in Israeli military intelligence, which press coverage identifies as Unit 8200, and later reunited at Torq, where Eldad Rudich was its earliest engineer and Hagai Shapira its earliest product manager. Neither has an exit in the reviewed record.
The investor roster reads as peer endorsement rather than ordinary venture interest. SiliconANGLE lists the individual investors as Assaf Rappaport of Wiz, three people from Torq, two from Cyera, two from Armis, and Ofir Ehrlich of EON, alongside Craft Ventures, Bain Capital Ventures, and Maple VC.
The operating bench is where the domain record sits. Daylight's leadership page lists Amnon Kushnir as head of security operations, and a SANS Institute profile records an Amnon Kushnir who directs incident response at Sygnia and presented at a 2024 SANS summit with Oren Biderman. Oren Biderman's byline runs on Daylight's own August 2026 threat research. The reviewed sources do not link the SANS records to the Daylight roles.
Daylight also describes the team that runs the service. A Times of Israel article states 25 employees across Tel Aviv, the United States, and Singapore at the November 2025 Series A, and Daylight advertises no junior analysts, no night shifts, four regions on a follow-the-sun rotation, and more than ten years of average security experience among its responders. [s7, s9, s11, s24, s26, s1, s2]
Daylight's homepage carries two attestation badge images. One image file is named SOC 2 and carries the alt text "aicpa soc 2 badge". The second carries that same alt text, and its file name and its rendered image identify an ISO 27001 certified seal.
Daylight points trust.daylight.ai at a SafeBase trust portal, and that portal answers "Trust Center Unavailable" to both a plain fetch and a browser render. A random subdomain of the same domain does not resolve, so the address is a deliberately configured portal rather than a wildcard answering everything. Security.daylight.ai does not resolve, and the /trust, /security, and /compliance paths return 404. A buyer therefore cannot read either report or its scope without asking.
Daylight ingests a customer's identity, cloud, endpoint, and business-tool telemetry into a data lake it manages, and its own experts define and maintain the detections that run against it. The privacy policy the record cites governs personal information tied to the website and the services, and it permits anonymized, aggregated, or de-identified personal information to be used for improving those services, including through artificial intelligence. Nothing in the reviewed sources sets out subprocessors or data residency for the telemetry the service ingests, so a buyer in a regulated sector such as Antidote Health would have to establish both in contracting. [s15, s27, s28, s25, s2, s13]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Arctic Wolf | competes with | Established managed security operations provider that Daylight groups with the SOC-as-a-service set it sells against, and that Gartner Peer Insights shows as an alternative buyers weigh. | |
| Expel | competes with | Managed detection and response provider Daylight names in the same SOC-as-a-service group it positions itself against. | |
| Red Canary | competes with | Managed detection and response provider Daylight names in the same SOC-as-a-service group it positions itself against. | |
| Dropzone AI | competes with | AI investigation vendor Daylight classifies as a tool rather than a managed service, reaching teams that keep operating their own security function. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Prophet Security | competes with | AI investigation vendor Daylight classifies as a tool rather than a managed service, reaching the same security teams with agent-run triage they run themselves. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
Add analyzed competitors to compare them side by side with Daylight Security.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
press the advantage
Daylight's own staff and agents do the investigating, so its customers consume verdicts rather than run investigations. Leaving means replacing the triage Daylight runs, the detections its experts maintain, and the context layer it builds. The reviewed pages publish no portability or offboarding terms. The technology under the service is reproducible by a funded rival. Its privacy policy permits aggregating and de-identifying personal information to improve the services, and the pages do not say whether ingested telemetry falls inside that. Its SOC 2 and ISO 27001 badges are attestations a rival can also obtain rather than a barrier to replacement. Senior responders in four regions with no junior tier are a head start rather than a durable lead.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 3/3 | What Daylight sells is a resolved alert rather than a tool. Its experts define the detections, take over complex and high-risk cases, and carry each one to closure under a contractual accountability commitment, while the customer's own team consumes the verdicts and searches the retained telemetry rather than running the investigations. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Leaving means replacing the triage Daylight runs, the detection rules its experts maintain, the business context layer it builds, and the retention layer that lets a customer drop a separate log platform. The reviewed pages document no ownership, portability, or offboarding terms, the cited record does not size the migration, and it shows no network effect and no residency requirement holding the customer in place. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | The SOC 2 and ISO 27001 seals are badge images, and the SafeBase portal at Daylight's own trust subdomain answers Trust Center Unavailable, so neither report nor its scope is published for inspection. Both are attestations an ordinary enterprise-market competitor can obtain, and the reviewed record names no regulation that mandates this service class. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Coordinating task-scoped agents across identity, cloud, endpoint, and business telemetry, holding a per-customer behavioural baseline, running a hot-and-archival data lake that stores telemetry unnormalized, and running hypothesis-driven hunts across that history is real-time systems work built by people with years of detection and response experience. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | The buyers on record are enterprise security leaders in finance, software, transportation, and health insurance, including Antidote Health in a highly regulated United States health insurance market, Lusha under GDPR and CCPA obligations, and a verified Gartner reviewer at a transportation business in the 1 to 10 billion dollar revenue band. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Daylight sits above the customer's existing tools, absorbs the log platform's retention role, and now exposes investigation context to outside AI assistants through an MCP server, which makes it more than a single-purpose application. The reviewed record identifies no downstream applications built on Daylight. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | The context layer that carries the technical advantage is built per customer from that customer's own telemetry, and the pages name detection rules its experts define and maintain rather than a retained corpus. The privacy policy's improvement permission is written about personal information, and the reviewed pages do not say whether the ingested telemetry falls inside it. Its AI-security rules are built on another vendor's exported runtime data. |
Daylight targets security teams that want alert work finished rather than escalated, whether they outsource it today or carry it in house. The published customer stories describe that profile precisely, with LiveView Technologies running an employee on-call rotation before it switched and The Motley Fool leaving established providers at renewal.
Company size in the evidence runs wide. Gartner Peer Insights carries a verified review from a manager at a transportation business in the 1 to 10 billion dollar revenue band. The named customers are Cresta, McKinsey Investment Office, The Motley Fool, LiveView Technologies, Antidote Health, and Lusha, which Daylight describes as a unicorn-stage business-to-business sales intelligence platform.
Regulated buyers are on the record twice. Antidote Health is a United States health insurance business that Daylight describes as operating in a highly regulated environment, and Lusha's story names strict GDPR and CCPA compliance requirements. Daylight operates across three continents, with a SecurityWeek article placing its operations across Asia, Europe, and North America and a Times of Israel article recording offices in Tel Aviv, the United States, and Singapore.
The technical claim is orchestration rather than a model. A central orchestrator dispatches AI agents each scoped to one task, and each next step follows the evidence rather than a fixed playbook. Daylight builds a context store it calls Daylight Knowledge, which records what normal looks like across a customer's users, devices, access patterns, and workflows, and Daylight staff feed findings back into it.
Daylight owns the data layer that feeds the agents. Telemetry from every integration lands in a managed data lake with 90 days of searchable storage and archival storage beyond that, stored in its original format rather than normalized on the way in. The threat hunting service runs agents against that history under an expert-defined hypothesis, and advanced users can query the lake in KQL directly.
Two capabilities arrived in mid-2026. An MCP server lets AI assistants pull investigation context through Daylight's APIs under scoped, logged access. Detection Program Visibility gathers a customer's detections from security tools, from SIEM content, and from what Daylight runs on their behalf, and Daylight says every investigation feeds back into which detections find real threats and which create noise.
Daylight builds each customer's context layer from that customer's own telemetry, and the product pages name no corpus that accumulates across accounts, though its own August 2026 research describes one detection firing at six unrelated customers. Its privacy policy separately permits anonymized, aggregated, or de-identified personal information to be used for analyzing, enhancing, testing, training, and improving its services, including through artificial intelligence. That clause is written about personal information, and the reviewed pages do not say whether the telemetry the service ingests falls inside it.
Coverage for AI systems is narrower still. It is built on Claude Enterprise runtime telemetry, so it reaches customers who run that product and changes when that vendor changes what it exports.
Daylight sells through a sales team. The reviewed pages carry no pricing page, no trial, and no self-service sign-up, only a demo request. The leadership page lists a vice president of sales alongside a head of product and a business development lead, which points to a hired go-to-market team rather than founder-only selling.
Displacement is the pattern the evidence shows. The Motley Fool switched at renewal after comparing what its provider had actually investigated against what its cloud security tool surfaced, and it evaluated an AI MDR vendor and an AI SOC tool alongside Daylight. Lusha set nine written proof-of-concept criteria before committing. Antidote Health ran a proof of concept in which Daylight integrated the stack and built detection rules before the decision.
Independent corroboration now reaches past customer names. SecurityWeek and Ctech articles both carry dozens of enterprises and the names Cresta, McKinsey Investment Office, and The Motley Fool. Gartner Peer Insights carries nine verified buyer ratings of the service averaging 4.8, one of them a May 2026 review describing a competitive evaluation and one a July 2026 review that is critical. Beyond that the record carries no revenue, retention, contract value, or analyst placement, so the size of the business stays unverified.
A buyer can learn how Daylight bills but not what it costs. Gartner Peer Insights records the service as a subscription typically structured by the number of headcount, charged on an annual recurring basis, with threat hunting and phishing investigation available as additions. Lusha's proof-of-concept criteria asked for per-headcount or per-entity pricing rather than per-source or per-gigabyte charges, and named that as the fix for tooling whose cost rose with every new data source.
Daylight makes a cost argument about the log platform it replaces. Its data lake page states that most organisations use a fraction of their log platform's functionality while paying for the whole thing, and that the operational burden grows faster than the value. A SiliconANGLE article carries the company saying the service is not meant to replace every SIEM deployment. The public pages do not say whether the data lake is bundled with the MDR service or priced separately.
Two inputs the pages describe are the agents that run each investigation and the senior staff across four regions with no junior tier. The reviewed pages do not say how either reaches the customer's bill, so a buyer cannot model what a heavy month of investigations would cost.
Deployment is integration-led and fast by the company's own account. A SiliconANGLE article carries the company's claim that the system goes live in under an hour, the integrations catalog spans thirteen categories from endpoint detection to threat intelligence enrichment, and Daylight states it can build new connectors within days. Lusha's story describes its full stack of AWS, Okta, Jira, and its own API telemetry onboarded within 48 hours during the evaluation.
Daylight runs the operational work rather than handing it to the customer. Its staff define and maintain the detection rules, build the context layer, take over complex cases, and drive them to resolution, and the service page states a contractual accountability commitment from alert ingestion through to closure. Benign alerts are closed at the source rather than forwarded. For LiveView Technologies, Daylight wrote customized detection rules on top of the team's existing coverage.
Two operational details reduce work for the customer's own team. Daylight talks to employees directly through Slack, Teams, or email to verify activity, which removes the internal chase that usually falls to the customer. Coverage runs continuously across four regions on a follow-the-sun rotation rather than through night shifts.
Daylight's homepage carries two attestation badge images. One image file is named SOC 2 and carries the alt text "aicpa soc 2 badge". The second carries that same alt text, and its file name and its rendered image identify an ISO 27001 certified seal.
Daylight points trust.daylight.ai at a SafeBase trust portal, and that portal answers "Trust Center Unavailable" to both a plain fetch and a browser render. A random subdomain of the same domain does not resolve, so the address is a deliberately configured portal rather than a wildcard answering everything. Security.daylight.ai does not resolve, and the /trust, /security, and /compliance paths return 404. A buyer therefore cannot read either report or its scope without asking.
Daylight ingests a customer's identity, cloud, endpoint, and business-tool telemetry into a data lake it manages, and its own experts define and maintain the detections that run against it. The privacy policy the record cites governs personal information tied to the website and the services, and it lists categories of service providers without naming them. Nothing in the reviewed sources sets out subprocessors or data residency for the telemetry the service ingests, so a regulated buyer such as Antidote Health or Lusha would have to establish both in contracting.
Daylight positions itself as a service on one architecture rather than as a platform others build on. The company states that every service it delivers runs on the same foundation of deep integration, agentic investigation, and expert operators, which is a shared-delivery argument rather than an ecosystem one. No partner programme and no marketplace listing appear in the reviewed sources.
One interface opened in June 2026. The Daylight MCP server lets MCP-compatible AI assistants connect and retrieve investigation context through Daylight's APIs, under authentication, scoped permissions, and logging. That extends Daylight's data into other vendors' tools rather than inviting other vendors to build on Daylight.
Its ecosystem role is otherwise that of a consumer of other vendors' telemetry. The integrations catalog is organised into thirteen categories covering endpoint detection and response, identity and access management, cloud security, email security, data security, network security, log aggregation, threat intelligence enrichment, and AI security, and Daylight also writes detections against business tools such as Slack, GitHub, and Notion.
Daylight reads from security platforms that could add more investigation to their own consoles. Its coverage for AI systems is built on one model vendor's published telemetry, so what that line covers depends on what the vendor chooses to expose. Daylight's answer is that it works across all of those tools rather than inside any one of them.
Both founders held the earliest technical and product roles at Torq, whose own founders press coverage groups among cybersecurity founders. Hagai Shapira and Eldad Rudich met at 18 in Israeli military intelligence and later reunited at Torq, where Eldad Rudich was the earliest engineer and Hagai Shapira the earliest product manager. Press coverage identifies them both as veterans of Unit 8200, and the reviewed record shows no exit behind either of them.
The investor list reads as peer endorsement. SiliconANGLE lists the individual investors as Assaf Rappaport of Wiz, three people from Torq, two from Cyera, two from Armis, and Ofir Ehrlich of EON, alongside Craft Ventures, Bain Capital Ventures, and Maple VC.
The operating bench carries the domain record. Daylight's leadership page lists Amnon Kushnir as head of security operations, and a SANS Institute profile records an Amnon Kushnir who directs incident response at Sygnia and presented at a 2024 SANS summit with Oren Biderman. Oren Biderman's byline runs on Daylight's own August 2026 threat research, which reconstructs a campaign that triggered the same detection at six unrelated customers. The reviewed sources do not link the SANS records to the Daylight roles.
Daylight delivers the service with its own staff. A Times of Israel article states 25 employees spread across Tel Aviv, the United States, and Singapore at the Series A in November 2025, and the about page names a head of security operations, a head of product, a business development lead, and a vice president of sales alongside the two founders. Daylight advertises no junior analysts, no night shifts, four regions on a follow-the-sun rotation, and more than ten years of average security experience.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Daylight homepage: Managed Security Services, Rebuilt for SecOps | official | 2026-08-25 |
| f2 | The Times of Israel on Daylight's Series A (late-2024 founding) | press | 2026-08-25 |
| f3 | SecurityWeek: Daylight Raises 33 Million for AI-Powered MDR Platform | press | 2026-08-25 |
| f4 | Calcalist CTech on Daylight's Series A | press | 2026-08-25 |
| f5 | SiliconANGLE on Daylight Security's 33 million Series A | press | 2026-08-25 |
| f6 | Daylight Managed Agentic MDR service page | official | 2026-08-25 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.