Koi

Security for AI Endpoint SecurityApplication Security acquired also known as Koi Security, Koi Security Ltd.

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2024
Funding $48M
Last updated 2026-07-12

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Koi is an Israeli endpoint-security company that Palo Alto Networks bought in April 2026, roughly two years after its January 2024 founding. It secures the software employees and developers install on their own, from browser extensions and code packages to AI models, AI agents, and the MCP servers that connect AI agents to company tools. Its Wings engine scores each item's risk in real time, and a Supply Chain Gateway approves or blocks installs by policy before they reach a machine. Koi showed traction before the sale: named customers including OpenAI, Fireblocks, and FHLBank Dallas among roughly forty to fifty accounts. Palo Alto Networks keeps Koi's capabilities standalone and plans a Cortex XDR module and Prisma AIRS integration for a category it calls agentic endpoint security.

Sourced Details

Description Koi is an endpoint-security platform that discovers, risk-scores, and gates installs of self-provisioned software across endpoints, including browser extensions, code and OS packages, AI models, AI agents, and MCP servers. [f1]
Acquisition Palo Alto Networks, announced 2026-02-17 [f2]
Founded 2024 [f3]
HQ Tel Aviv, Israel [f4]
Funding $48M total [f5]
Latest funding $38M Series A (September 2025, led by Battery Ventures and Team8) [f5]

Products

Product What it does
Koi Agentless platform that inventories self-provisioned software, risk-scores it with the Wings engine, and gates installs of extensions, packages, AI models, agents, and MCP servers by policy.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

Koi discovers and inventories MCP servers, AI agents, and extensions across endpoints, risk-scores them with the Wings engine, gates risky installs by policy, and vets AI models from registries such as Hugging Face before they reach endpoints. These capabilities are mapped to the AI Defense Matrix. [f6]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 30 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 4/5 Koi defines a specific buyer, enterprise security and platform teams, and a demonstrated pain: its founders exposed a security gap in the Visual Studio Code extension marketplace, and an independent Dell'Oro analyst frames extensions and packages as an expanding enterprise blind spot. That demonstrated problem is independently corroborated rather than only vendor-asserted, which places it above a credible but self-reported case. [s4, s9, s2]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 4/5 Koi's Wings engine correlates code diffs, runtime behavior, ownership changes, update channels, network egress, and install source to flag malware and impersonation in real time, and a Supply Chain Gateway screens installs from marketplaces such as Hugging Face and the Visual Studio Code and Chrome stores. An independent analyst validates the install and supply-chain-layer mechanism. [s1, s2, s9]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 4/5 Koi is young, so the timing thesis names the enabler: the 2024 to 2026 surge in AI coding agents and Model Context Protocol servers that put executable, self-updating software on every endpoint. Buyer-side demand is corroborated by a Dell'Oro analyst calling the agent-tooling layer a growing blind spot and by roughly forty to fifty enterprise accounts signed within about a year. [s2, s9, s8]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 4/5 Koi's three founders are Israeli Unit 8200 alumni, with CEO Amit Assaraf a repeat founder and CPO Itay Kruk drawn from Sygnia and Zscaler. A completed Palo Alto Networks acquisition within two years of founding is a verifiable in-domain exit. [s4, s7]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 4/5 Koi shows multiple named reference customers from independent reporting, including OpenAI, Fireblocks, and FHLBank Dallas among roughly forty to fifty accounts, plus reported revenue over one million dollars in eight months and more than 500,000 protected endpoints. That named, multiply sourced traction goes beyond anonymized customer references. [s8, s6, s13]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 Koi raised $48 million across a 2025 seed and Series A, proportional to an enterprise motion that shipped a deployed product and early revenue, but public margins and growth-efficiency figures are absent, so efficiency itself is unconfirmed. That places it at the honest default. [s5, s6]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 4/5 Koi fits a clearly-emerging category that buyers and analysts place without vendor coaching: a Dell'Oro analyst and Palo Alto Networks both frame it as securing the agentic endpoint, and Palo Alto Networks named an agentic endpoint security category around the deal. That analyst-plus-acquirer placement is strong but short of the top score, because the named category is new and vendor-coined. [s9, s10]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 A major incumbent valued Koi's capability enough to buy rather than build it, which shows real friction to absorption, but the same acquirer is now folding the technology into its Cortex XDR endpoint product, and the risk data and features carry no structural moat a bundler could not replicate. [s7, s10, s1]
Business Risks Palo Alto Networks could deprioritize Koi's standalone product as it folds the technology into Cortex XDR and Prisma AIRS, leaving standalone customers with a slower roadmap…
  • Palo Alto Networks could deprioritize Koi's standalone product as it folds the technology into Cortex XDR and Prisma AIRS, leaving standalone customers with a slower roadmap.
  • Koi's core capability is reproducible software, and Palo Alto Networks is already building an equivalent Cortex XDR module, so rival endpoint vendors could add the same non-binary software governance.
  • Koi's traction covers only a short early window of roughly forty to fifty accounts, with no public multi-year retention record, so early-customer churn would undercut the growth story.
  • Koi scores risk from public marketplace metadata and behavioral analysis a funded competitor could reconstruct rather than from a named non-public dataset, so the underlying data is not a durable advantage.
  • Sold as an agentless overlay that complements endpoint detection and response, Koi risks being treated as a feature rather than a standalone platform, which would pressure independent pricing.
Problem & Market Koi sells to enterprise security and platform teams that have lost visibility into the software their own people install…

Koi sells to enterprise security and platform teams that have lost visibility into the software their own people install. Browser extensions, code and operating-system packages, AI models, AI agents, and Model Context Protocol servers now arrive on endpoints outside the antivirus and device-management tools built for static binaries. Because each of these can run code and reach data, self-provisioned software becomes an attack surface most controls never inspect.

The founders demonstrated the gap before building the product. They uncovered a security hole in the Visual Studio Code extension marketplace and used a planted extension to breach organizations, which became the origin of Koi. Independent reporting now frames extensions and packages as an expanding enterprise blind spot, and a Dell'Oro analyst places the agent-tooling layer among the next endpoint attack surfaces. [s4, s9, s2]

Product Capabilities Koi combines continuous discovery with a risk engine and a policy gate, delivered agentlessly across macOS, Windows, and Linux…

Koi combines continuous discovery with a risk engine and a policy gate, delivered agentlessly across macOS, Windows, and Linux. It catalogs every binary and non-binary artifact on an endpoint, then its Wings engine scores each one by correlating code diffs, runtime behavior, ownership changes, update channels, network egress, and install source to flag malware, impersonation, and policy drift in real time.

A Supply Chain Gateway screens installs before they reach the endpoint. It curates incoming software from marketplaces and registries such as GitHub, Hugging Face, the Chrome Web Store, the Visual Studio Code Marketplace, and Homebrew, approving safe items and blocking or quarantining risky ones by policy. After install, Koi keeps watching for malware, sideloading, and risky update channels, and it can roll back versions or remove items in one step. [s1, s2, s3]

Competitive Positioning Koi positions itself as a new endpoint layer that complements rather than replaces existing controls…

Koi positions itself as a new endpoint layer that complements rather than replaces existing controls. It governs the self-installed software that endpoint detection and response and device-management tools were not designed to inspect, and it markets the result as agentic endpoint security. Palo Alto Networks adopted that framing when it acquired Koi and built a category around it.

The competitive reality is that the capability is attractive to larger platforms. Palo Alto Networks now sells Koi standalone and folds it into Cortex XDR and Prisma AIRS, and other endpoint and software-supply-chain vendors work adjacent ground, governing agent connectors, build-pipeline dependencies, or container images rather than the installed software on the endpoint. [s10, s2, s9]

Go-to-Market & Traction Koi reached enterprise traction quickly for a company founded in 2024…

Koi reached enterprise traction quickly for a company founded in 2024. Independent reporting names OpenAI, Fireblocks, and FHLBank Dallas among roughly forty to fifty accounts, and the company reported passing one million dollars in revenue within eight months while protecting more than 500,000 endpoints. Its own account of early customers points to Fortune 50 organizations and large financial institutions.

The motion is direct enterprise sales rather than self-service purchase. Koi publishes threat research on live supply-chain compromises to build awareness among security teams, and buyers reach the product through a sales conversation rather than a public price or signup. [s8, s6, s13]

Team & Credibility Koi's founders come from Israel's Unit 8200 with prior security-industry experience…

Koi's founders come from Israel's Unit 8200 with prior security-industry experience. CEO Amit Assaraf earlier founded the real-estate startup Landa, CTO Idan Dardikman leads the engineering, and CPO Itay Kruk came from Sygnia and Zscaler. The team built Koi after demonstrating a security gap in the Visual Studio Code extension marketplace.

Palo Alto Networks validated the team by acquiring Koi within roughly two years of its founding, in a reported deal near $400 million, a rare in-domain outcome for founders this early. [s4, s7]

Trust Readiness Koi publishes no inspectable security attestation…

Koi publishes no inspectable security attestation. Its homepage footer shows image-only ISO 27001, SOC, and GDPR badges, but a probe on 2026-07-06 found no trust portal on a trust or security subdomain and no security page, and no third-party audit report is public. The self-display is a credibility floor rather than evidence of an independent audit.

For a control that screens software before it reaches endpoints, that missing report is a procurement question a security review will raise. Koi runs agentlessly and installs no software agent on the endpoint, which lowers one class of operational risk, but buyers evaluating it still lack an external assurance document. [s11, s1, s2]

Competitors Stacklok, Endor Labs, Chainguard…
Company Relationship Note Compare
Stacklok adjacent Both secure software that AI agents and developers pull in, with Stacklok focused on running and governing Model Context Protocol servers rather than endpoint installs.
Endor Labs adjacent Both govern software supply-chain risk, with Endor Labs focused on open-source dependencies in the build pipeline rather than software on the endpoint.
Chainguard adjacent Both address software supply-chain risk, with Chainguard focused on minimal, low-vulnerability container images rather than endpoint installs.

Add analyzed competitors to compare them side by side with Koi.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 13 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

Koi's technology was worth buying rather than rebuilding, yet little in the product is hard for a funded rival to copy. Its risk signals span code diffs, runtime behavior, ownership, and marketplace metadata, drawn partly from marketplaces a rival can also crawl, and the record shows no independent attestation beyond self- displayed badges. The Wings engine and install-time gate are strong engineering, not a data or compliance barrier, and Palo Alto Networks says the deal enables a Cortex XDR module with it. Koi's firmest hold is the wiring inside its customers. Security teams rely on it to vet which software reaches thousands of machines, so replacing it is costly. That wiring, plus an early lead in a category incumbents are just now naming, is a head start, not yet a durable barrier.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Koi is a software product, an agentless platform that scores risk and enforces install policy, with no analyst-staffed service layer that accepts accountability. Automated risk scoring and remediation are software output, so delivery sits at the software-product level.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Once Koi's policies, allow and block lists, and Supply Chain Gateway govern which software reaches an organization's endpoints, replacing it means rebuilding that governance and its accumulated rules across the fleet. That embedding is real friction, but the agentless overlay leaves a rival able to serve the same policy interface.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 Koi self-displays ISO 27001, SOC, and GDPR badges in its site footer, but a probe on 2026-07-06 found no inspectable trust portal or third-party audit report, so the display is a credibility floor rather than a certification moat.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Scoring self-provisioned software in real time by correlating code diffs, runtime behavior, ownership changes, update channels, network egress, and install source, agentlessly across three operating systems and the marketplaces and registries its homepage names and more, is security-critical engineering.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 Koi sells to large, security-conscious enterprises, and independent reporting names OpenAI, Fireblocks, and FHLBank Dallas, a regulated financial institution, among its customers. That named regulated and financial buyer base is the strongest demand evidence in the record.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 Koi is an agentless overlay that inventories, scores, and gates self-provisioned software, but removing it costs governance coverage rather than breaking production, since endpoints and agents keep running without it. That out-of-runtime position places it below a runtime control whose removal would stop agents from reaching tools.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 Koi's risk data comes from tracking extensions, packages, and models across public marketplaces a funded rival could crawl, plus behavioral and sandbox analysis rather than a named non-public corpus. No proprietary dataset a competitor could not assemble appears in the record.
Strategic Market Segmentation Koi sells to the enterprise security and platform teams that must govern software their own employees and developers install…

Koi sells to the enterprise security and platform teams that must govern software their own employees and developers install. That buyer runs a growing sprawl of browser extensions, code and operating-system packages, AI models, AI agents, and Model Context Protocol servers, some of it able to execute code and reach sensitive data outside the antivirus and device-management tools built for static binaries.

The product is aimed at large organizations rather than individual developers. Independent reporting names OpenAI, Fireblocks, and FHLBank Dallas among roughly forty to fifty accounts, and Koi's own account points to Fortune 50 companies and large financial institutions. The design, an agentless control that spans macOS, Windows, and Linux and enforces org-wide policy, fits a centralized security team rather than one developer's tooling choice.

Product Capabilities & AI Advantages Koi's claimed advantage is a real-time risk engine that judges software by behavior and provenance rather than signatures alone…

Koi's claimed advantage is a real-time risk engine that judges software by behavior and provenance rather than signatures alone. The Wings engine correlates code diffs, runtime behavior, ownership changes, update channels, network egress, and install source to detect malware, impersonation, and policy drift as software changes, and Koi describes it as an agentic AI risk engine.

A Supply Chain Gateway pairs the engine with enforcement. It screens incoming software from marketplaces and registries such as GitHub, Hugging Face, the Chrome Web Store, the Visual Studio Code Marketplace, and Homebrew, approving safe items and blocking or quarantining the rest by policy before they reach a machine. An independent Dell'Oro analyst locates that value at the install and supply-chain layer, where extensions and packages are a growing blind spot.

The depth is real engineering rather than a proprietary data or model moat. The risk signals come from public marketplace metadata and behavioral analysis a funded rival could reconstruct, so the advantage is the breadth of coverage and the real-time enforcement. A cross-customer telemetry signal could sharpen detection over time, but the public record does not evidence Koi pooling behavior across its customer base as a realized advantage.

Sales Engagement & Go-to-Market Koi runs a direct enterprise sales motion…

Koi runs a direct enterprise sales motion. Buyers reach the product through a sales conversation rather than a public price or self-service signup, which points at negotiated enterprise deals. The founders' original research, which surfaced a major security gap in the VS Code extension marketplace, seeded credibility with security teams before a commercial conversation.

Named demand is unusually strong for the company's age. Independent reporting names OpenAI, Fireblocks, and FHLBank Dallas among roughly forty to fifty accounts, and Koi reported passing one million dollars in revenue within eight months while protecting more than 500,000 endpoints. The CEO also said every early customer stayed, an own-voice retention claim that independent sources do not yet corroborate.

Pricing Model The reviewed pages show no pricing…

The reviewed pages show no pricing. It routes buyers to a demo request and a sales conversation, which signals negotiated enterprise deals rather than self-service purchase, and it names no billing unit such as per endpoint or per user.

Without a public price or meter, what Koi charges for and how it scales cannot be read from the site, and a buyer gets no budget anchor before contacting sales. The enterprise motion and the reported early revenue points toward annual contracts, but the public record does not state the pricing model.

Product Delivery & Operations Koi runs as an agentless service across macOS, Windows, and Linux…

Koi runs as an agentless service across macOS, Windows, and Linux. It is agentless per its positioning, discovering and scoring software and enforcing policy centrally, a design that leaves no per-endpoint agent in the deployment path.

Because the Supply Chain Gateway can block an install, its decisions affect whether software reaches endpoints at all. That enforcement raises the operational stakes: a wrong block can stop a developer's tool, so approvals, cooldowns, and allow and block lists are the controls a change-management review will examine before the gate governs production installs.

Earning Customers' Trust Koi publishes no inspectable security attestation…

Koi publishes no inspectable security attestation. Its homepage footer shows image-only ISO 27001, SOC, and GDPR badges, but a probe on 2026-07-06 found no trust portal on a trust or security subdomain and no security page, and no third-party audit report appears in the reviewed record. The self-display is a credibility floor rather than an independent audit a buyer can read.

For a control that decides which software reaches endpoints, the missing report is a procurement question a security review will raise. Koi runs agentlessly, which limits one class of risk, but a buyer evaluating the product still lacks an external assurance document, and the acquisition may fold Koi under a Palo Alto Networks trust program the standalone brand does not yet publish.

Platform Strategy & Ecosystem Positioning Koi presents itself as a horizontal control across every software marketplace rather than a single-marketplace tool…

Koi presents itself as a horizontal control across every software marketplace rather than a single-marketplace tool. It tracks and gates software from GitHub, Hugging Face, the Chrome Web Store, the Visual Studio Code Marketplace, Homebrew, and more, positioning as the checkpoint any of these feed rather than a point product tied to one store.

Its ecosystem position is now defined by the acquisition. Palo Alto Networks says the acquisition enables a new Cortex XDR module and prospective Prisma AIRS integration, and keeps Koi's capabilities available standalone alongside existing endpoint detection and response. That places Koi inside a large security platform's roadmap, where the acquirer decides how deeply the standalone offering and the bundled capability diverge.

Team & Execution Capability Koi's founders come from Israel's Unit 8200 with prior security-industry experience…

Koi's founders come from Israel's Unit 8200 with prior security-industry experience. CEO Amit Assaraf earlier founded the real-estate startup Landa, CTO Idan Dardikman leads the engineering, and CPO Itay Kruk came from Sygnia and Zscaler. The three built Koi after demonstrating a security gap in the Visual Studio Code extension marketplace.

Palo Alto Networks validated the team's execution by acquiring Koi within roughly two years of its founding in a reported deal near $400 million, and the founders join a larger platform. That speed of exit is a rare in-domain outcome, though it also reflects an acquirer choosing to buy the capability rather than let it grow independent.

Sources

Company Detail Sources (6)
Id Source Tier Accessed
f1 Koi homepage: unified platform to secure all software official 2026-07-06
f2 Palo Alto Networks Completes Acquisition of Koi to Secure the Agentic Endpoint official 2026-07-06
f3 Ctech: Palo Alto Networks completes $400 million acquisition of Koi press 2026-07-06
f4 SDxCentral: Palo Alto Networks collects Koi in completed acquisition press 2026-07-06
f5 Ctech: Cyber startup Koi raises $38M Series A press 2026-07-06
f6 AI Defense Matrix Catalog mapping (aligned to catalog) other 2026-07-06
Profile Analysis Sources (13)
Id Source Tier Accessed
s1 Koi homepage: Wings agentic AI risk engine
“Wings, our agentic AI risk engine, correlates code diffs, runtime behavior, ownership changes, update channels, network egress, and install source to detect malware, impersonation, and policy drift in real time.”
official 2026-07-06
s2 Koi homepage: Supply Chain Gateway registries
“A Supply Chain Gateway (SCG) is a new architectural layer that acts as a single, proactive network-based gate for curating incoming software from marketplaces, app stores, or registries like Github, Hugging Face, Chrome Web Store, Visual Studio Code Marketplace, Homebrew, and more.”
official 2026-07-06
s3 AI Defense Matrix Catalog: Koi
“Endpoint security for software supply chains that inventories, risk-scores, and gates installs of MCP servers, AI models, AI agents, extensions, and packages by policy.”
other 2026-07-06
s4 Ctech: Cyber startup Koi raises $38M Series A (founders)
“Koi was founded in 2024 by IDF's 8200 intelligence unit alumni Amit Assaraf (CEO, founder of real estate startup Landa), Idan Dardikman (CTO), and Itay Kruk (CPO), ex-Sygnia, Zscaler, after uncovering a major security gap in the VSCode Marketplace.”
press 2026-07-06
s5 Ctech: Cyber startup Koi raises $38M Series A (funding)
“Koi has raised $38 million in a Series A round. The investment was led by Battery and Team8, with Picture Capital, NFX, and Cerca Partners participating in the company's Seed round. Koi has raised a total of $48 million to date.”
press 2026-07-06
s6 Ctech: Koi CEO on early revenue and retention
“We exceeded seven-figure revenues in eight months. We are now generating over $1 million in revenue, and every organization we began with is still our client.”
press 2026-07-06
s7 Ctech: Palo Alto Networks completes $400 million acquisition of Koi
“Palo Alto Networks has completed its acquisition of Israeli cybersecurity startup Koi, finalizing a deal previously estimated at around $400 million.”
press 2026-07-06
s8 SDxCentral: Koi named customers
“Koi counts between 40 and 50 clients, including OpenAI, Fireblocks, FHLBank Dallas, as well as Palo Alto Networks itself.”
press 2026-07-06
s9 SDxCentral: Dell'Oro analyst on Koi's install and supply-chain layer
“Koi's value is at the install and supply-chain layer on the endpoint, where extensions and packages are becoming an expanding blind spot for many enterprises.”
press 2026-07-06
s10 Palo Alto Networks Completes Acquisition of Koi (Agentic Endpoint Security)
“By integrating Koi's technology with Prisma AIRS, Palo Alto Networks will extend visibility and security to agentic AI on the endpoint ... this acquisition enables Palo Alto Networks to introduce a new module for Cortex XDR.”
official 2026-07-06
s11 Koi trust-surface probe 2026-07-06: footer badges, no trust./security. subdomain or /security page
“Footer badges served as image files gdpr.svg, soc.svg, and ico.svg reading ISO 27001, SOC, and GDPR. No trust. or security. subdomain resolves and /security returns 404 (probe 2026-07-06).”
other 2026-07-06
s12 Koi blog: early customers
“It is this approach that our early customers, Fortune 50 organizations, BFIS, and the world's biggest tech and cybersecurity vendors, are excited about.”
official 2026-07-06
s13 FinSMEs: Koi raises $48M (endpoint scale)
“The company has rapidly scaled to protect more than 500,000 endpoints worldwide. Its platform is already securing some of the world's largest enterprises, from Fortune 50 companies to leading financial enterprises and major technology companies.”
press 2026-07-06
Deep-Dive Sources (13)
Id Source Tier Accessed
s1 Koi homepage: Wings agentic AI risk engine
“Wings, our agentic AI risk engine, correlates code diffs, runtime behavior, ownership changes, update channels, network egress, and install source to detect malware, impersonation, and policy drift in real time.”
official 2026-07-06
s2 Koi homepage: Supply Chain Gateway registries
“A Supply Chain Gateway (SCG) is a new architectural layer that acts as a single, proactive network-based gate for curating incoming software from marketplaces, app stores, or registries like Github, Hugging Face, Chrome Web Store, Visual Studio Code Marketplace, Homebrew, and more.”
official 2026-07-06
s3 AI Defense Matrix Catalog: Koi
“Endpoint security for software supply chains that inventories, risk-scores, and gates installs of MCP servers, AI models, AI agents, extensions, and packages by policy.”
other 2026-07-06
s4 Ctech: Cyber startup Koi raises $38M Series A (founders)
“Koi was founded in 2024 by IDF's 8200 intelligence unit alumni Amit Assaraf (CEO, founder of real estate startup Landa), Idan Dardikman (CTO), and Itay Kruk (CPO), ex-Sygnia, Zscaler, after uncovering a major security gap in the VSCode Marketplace.”
press 2026-07-06
s5 Ctech: Cyber startup Koi raises $38M Series A (funding)
“Koi has raised $38 million in a Series A round. The investment was led by Battery and Team8, with Picture Capital, NFX, and Cerca Partners participating in the company's Seed round. Koi has raised a total of $48 million to date.”
press 2026-07-06
s6 Ctech: Koi CEO on early revenue and retention
“We exceeded seven-figure revenues in eight months. We are now generating over $1 million in revenue, and every organization we began with is still our client.”
press 2026-07-06
s7 Ctech: Palo Alto Networks completes $400 million acquisition of Koi
“Palo Alto Networks has completed its acquisition of Israeli cybersecurity startup Koi, finalizing a deal previously estimated at around $400 million.”
press 2026-07-06
s8 SDxCentral: Koi named customers
“Koi counts between 40 and 50 clients, including OpenAI, Fireblocks, FHLBank Dallas, as well as Palo Alto Networks itself.”
press 2026-07-06
s9 SDxCentral: Dell'Oro analyst on Koi's install and supply-chain layer
“Koi's value is at the install and supply-chain layer on the endpoint, where extensions and packages are becoming an expanding blind spot for many enterprises.”
press 2026-07-06
s10 Palo Alto Networks Completes Acquisition of Koi (Agentic Endpoint Security)
“By integrating Koi's technology with Prisma AIRS, Palo Alto Networks will extend visibility and security to agentic AI on the endpoint ... this acquisition enables Palo Alto Networks to introduce a new module for Cortex XDR.”
official 2026-07-06
s11 Koi trust-surface probe 2026-07-06: footer badges, no trust./security. subdomain or /security page
“Footer badges served as image files gdpr.svg, soc.svg, and ico.svg reading ISO 27001, SOC, and GDPR. No trust. or security. subdomain resolves and /security returns 404 (probe 2026-07-06).”
other 2026-07-06
s12 Koi blog: early customers
“It is this approach that our early customers, Fortune 50 organizations, BFIS, and the world's biggest tech and cybersecurity vendors, are excited about.”
official 2026-07-06
s13 FinSMEs: Koi raises $48M (endpoint scale)
“The company has rapidly scaled to protect more than 500,000 endpoints worldwide. Its platform is already securing some of the world's largest enterprises, from Fortune 50 companies to leading financial enterprises and major technology companies.”
press 2026-07-06

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.