Maro

Security for AI Data SecurityGovernance Risk Compliance also known as Cyberlume

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2024
Funding $4.3M
Last updated 2026-09-12

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Maro sells a browser extension that watches how employees use AI tools, coaches or blocks risky actions such as pasting sensitive data into a chatbot, and reports AI usage to security teams. Pricing climbs from a 5 dollar per user self-service plan to a managed plan where Maro's own team tunes policies and reviews violations, then to an operated AI governance program with a dedicated virtual chief AI officer at 10,000 dollars or more per month. Maro sells security expertise on subscription, with software as the entry point. Co-founder Jen Andre previously built Komand, acquired by Rapid7, and Threat Stack, acquired by F5. A 4.3 million dollar seed came from Downing Capital Group in July 2025. The customers named so far appear only on the vendor's own site.

Sourced Details

Description Maro is a browser extension that helps security teams manage the risk of AI use across their workforce. It discovers which AI and SaaS tools employees use and intervenes in real time to guide or block risky data sharing. [f1]
Founded 2024 [f2]
HQ New York, New York, US [f2]
Funding $4.3M total [f3]
Latest funding Seed ($4.3M, Downing Capital Group, announced July 2025) [f3]

Products

Product What it does
Maro Browser extension and security-team console that observe employee AI usage, enforce prompt-level data-loss policies, intervene with real-time coaching or blocking, and report on AI governance.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

Maro applies semantic data-loss controls to employee prompts and browser interactions in real time, and discovers shadow AI usage across the workforce down to the tool, use case, and prompt. These capabilities are mapped to the AI Defense Matrix. [f4]

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

Maro also protects employees against browser-level deception and social engineering, detects risky and insider behavior early, and prevents sensitive data loss in the browser. These conventional capabilities are mapped to the Cyber Defense Matrix. [f2]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Emerging 24 /40 Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Maro names a clear buyer (security leaders) and a specific problem (ungoverned employee AI use plus human error and social engineering), but the pain is quantified only by a vendor-cited Verizon DBIR figure and vendor-gathered input from 50 CISO and CIO leaders, not by independent quantification. [s4, s8]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 The vendor pages describe concrete capabilities (prompt-level data-loss detectors, use-case classification, decision traces, interventions), but the public record offers no documentation portal, demo environment, or third-party technical evaluation. [s2, s3, s12]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 The enabler is real and dated: the vendor's July 2025 announcement ties the product to the acceleration of generative AI, remote work, and shadow SaaS. Buyer-side demand in the record is indirect: vendor-gathered input from 50 CISO and CIO leaders and one funding press cycle. [s4, s8]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 4/5 The three co-founders previously worked together at Rapid7 and Komand, and CTO Jen Andre built two prior security companies that were acquired (Komand by Rapid7, Threat Stack by F5 in a deal TechCrunch reported at $68 million), verifiable in-domain builds and exits. [s4, s5, s10]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 3/5 Named customer testimonials (Newbury Partners, PDG, Coral AI) and a Goliath Cyber Security Group partnership appear on the vendor's own pages, but no independent source corroborates traction, so the evidence stays below the multiply-sourced bar. [s1, s5]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 A $4.3 million seed is proportional to a company shipping a generally available product with published self-service pricing within a year of founding, but no revenue or growth-efficiency signal is disclosed. [s8, s3]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 Maro brands its own category (cognitive security) while the product places into recognizable human-risk-management and AI-usage governance budget lines. Buyers still need the vendor's explanation to position it, and the category remains nascent and contested. [s4, s2]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 2/5 Prompt-level AI usage controls and employee coaching in the browser are a plausible feature release for secure-browser, network-security, and human-risk incumbents already adjacent to the same buyer. Tuned policies add friction, but no structural moat appears in the record. [s2, s3]
Business Risks Secure-browser and network-security vendors already selling to the same buyer could ship employee AI-usage coaching and prompt-level data-loss controls as platform features, folding Maro's standalone value into suites the buyer already owns…
  • Secure-browser and network-security vendors already selling to the same buyer could ship employee AI-usage coaching and prompt-level data-loss controls as platform features, folding Maro's standalone value into suites the buyer already owns.
  • Vendors of security awareness training and human-risk management could add real-time browser interventions and compete for the same budget line with far larger installed bases.
  • AI usage in native desktop apps and through APIs bypasses a browser-extension control point, so rivals with endpoint or network coverage could position Maro's visibility as partial.
  • Maro's evidenced customers are mid-market firms on its own site. If referenceable enterprise deployments do not appear, the company competes on price in a segment where incumbents can bundle.
Problem & Market Maro targets the human side of security failures: employees pasting sensitive data into AI chatbots, falling for browser-level deception, and working around policies nobody enforces in the moment. The vendor frames the problem with Verizon's 2025 Data Breach Investigations Report, which it cites for breaches involving a human element at 60%, and argues that awareness training and static policy cannot reach an employee at the moment of a risky decision. The company says it developed the product with input from 50 CISO and CIO leaders in financial technology, healthcare technology, and retail, who ranked ungoverned AI usage as the most pressing human risk factor, ahead of targeted social engineering and insider risk. That input process is vendor-run, so it evidences problem framing rather than independent demand. The buyer Maro names is the security leader who must let employees use AI tools without losing oversight…

Maro targets the human side of security failures: employees pasting sensitive data into AI chatbots, falling for browser-level deception, and working around policies nobody enforces in the moment. The vendor frames the problem with Verizon's 2025 Data Breach Investigations Report, which it cites for breaches involving a human element at 60%, and argues that awareness training and static policy cannot reach an employee at the moment of a risky decision.

The company says it developed the product with input from 50 CISO and CIO leaders in financial technology, healthcare technology, and retail, who ranked ungoverned AI usage as the most pressing human risk factor, ahead of targeted social engineering and insider risk. That input process is vendor-run, so it evidences problem framing rather than independent demand. The buyer Maro names is the security leader who must let employees use AI tools without losing oversight. [s4, s8]

Product Capabilities The product is a browser extension paired with a security-team console…

The product is a browser extension paired with a security-team console. The extension observes employee activity in the browser, classifies the intent and business context of each AI interaction, and intervenes in real time: coaching the employee toward a safer action or blocking the risky one. The console gives security teams usage insight down to the business case and prompt, decision traces for violations, policy management with team-level exceptions, and weekly governance reporting.

The marketing pages describe the mechanism concretely (out-of-the-box AI policy and sensitive-data detectors, context graphs across people, apps, actions, and data) and the vendor displays a Patent Pending badge, but the public record carries no documentation portal, sandbox, or independent technical evaluation of detection quality. Use cases the vendor names beyond AI governance include data loss prevention, insider risk, browser protection against clickjacking and typosquatting, and security behavior and culture programs. [s1, s2, s4, s12]

Competitive Positioning Maro competes for buyers who are already offered several ways to govern employee AI use, and it differentiates by leading with behavior: the extension is positioned as a coach that shapes what employees do, a replacement for awareness training, rather than another traffic filter. The company brands this position as cognitive security, its own label. The label straddles two budget lines a buyer already recognizes, human risk management and AI governance, which gives Maro two doors into an account and two sets of incumbents that could absorb its capability as a feature…

Maro competes for buyers who are already offered several ways to govern employee AI use, and it differentiates by leading with behavior: the extension is positioned as a coach that shapes what employees do, a replacement for awareness training, rather than another traffic filter.

The company brands this position as cognitive security, its own label. The label straddles two budget lines a buyer already recognizes, human risk management and AI governance, which gives Maro two doors into an account and two sets of incumbents that could absorb its capability as a feature. [s2, s4, s11]

Go-to-Market & Traction Maro publishes its prices and lets small buyers purchase by credit card, which is uncommon in security. The 5 dollar per user per month visibility plan and the 10 dollar enforcement plan check out through Stripe, while the 25 dollar managed plan and the operated governance program at 10,000 dollars or more per month route through sales. The vendor also announced a partnership with Goliath Cyber Security Group in May 2025, a channel signal. Evidenced traction is early and vendor-published: homepage testimonials whose speakers pair with Newbury Partners, PDG, and Coral AI, alongside STC Health and Elevate customer logos, including a chief executive crediting Maro as AI adoption grew from 5% to 20% in a few months. No independent reporting corroborates customer scale, and press coverage in the record is limited to the seed announcement…

Maro publishes its prices and lets small buyers purchase by credit card, which is uncommon in security. The 5 dollar per user per month visibility plan and the 10 dollar enforcement plan check out through Stripe, while the 25 dollar managed plan and the operated governance program at 10,000 dollars or more per month route through sales. The vendor also announced a partnership with Goliath Cyber Security Group in May 2025, a channel signal.

Evidenced traction is early and vendor-published: homepage testimonials whose speakers pair with Newbury Partners, PDG, and Coral AI, alongside STC Health and Elevate customer logos, including a chief executive crediting Maro as AI adoption grew from 5% to 20% in a few months. No independent reporting corroborates customer scale, and press coverage in the record is limited to the seed announcement. [s1, s3, s5, s8]

Team & Credibility The founding team is the strongest fact in Maro's record…

The founding team is the strongest fact in Maro's record. CTO Jen Andre founded Komand, which Rapid7 acquired, and co-founded Threat Stack, which F5 acquired in a deal TechCrunch reported at 68 million dollars. CEO Jadon Montero led MDR product at Bitdefender and SOAR product at Rapid7, and Gwen Betts led UX at Rapid7 and was on Komand's founding team. The three have worked together before, across Rapid7 and Komand.

The advisory bench is broad for a seed company: the about page lists product, engineering, and security leaders from established security and technology companies as advisors. A 4.3 million dollar seed from Downing Capital Group is modest against this pedigree. [s4, s5, s10, s8]

Trust Readiness Maro publishes a Secureframe-hosted trust center reporting a SOC 2 Type 1 attestation with continuous monitoring, and the homepage badge states SOC 2 Type I complete with Type II pending. That is a credible posture for a company selling monitoring of employee behavior, where buyers will probe privacy handling before deployment. The legal entity behind Maro is Cyberlume, Inc., with New York governing law in its terms of service and the application served from app.seekmaro.com. For a product that observes employee activity in the browser, the trust collateral is table stakes rather than differentiation, and enterprise buyers will likely wait for the Type II report the vendor says is pending…

Maro publishes a Secureframe-hosted trust center reporting a SOC 2 Type 1 attestation with continuous monitoring, and the homepage badge states SOC 2 Type I complete with Type II pending. That is a credible posture for a company selling monitoring of employee behavior, where buyers will probe privacy handling before deployment.

The legal entity behind Maro is Cyberlume, Inc., with New York governing law in its terms of service and the application served from app.seekmaro.com. For a product that observes employee activity in the browser, the trust collateral is table stakes rather than differentiation, and enterprise buyers will likely wait for the Type II report the vendor says is pending. [s1, s6, s7]

Competitors Harmonic Security, WitnessAI, Prompt Security, Aurascape, LayerX Security…
Company Relationship Note Compare
Harmonic Security competes with Sells browser-based discovery of employee AI usage with data-loss controls and user nudges, overlapping Maro's core mechanism.
WitnessAI competes with AI usage governance platform that observes and polices employee AI activity for enterprises.
Prompt Security competes with Inline AI data-loss prevention across employee browser and application traffic.
Aurascape competes with AI activity visibility and data protection across sanctioned and shadow AI applications. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
LayerX Security competes with Enterprise browser-extension platform whose controls extend to generative AI usage governance.

Add analyzed competitors to compare them side by side with Maro.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 13 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

Maro's product is a browser extension for security teams that finds which AI tools employees use and applies data-loss rules at each prompt. Its top plan, Managed Maro Complete, is an AI governance program Maro delivers for $10,000 or more per month. At that plan Maro sells service as well as software. A customer that leaves could have to redo the team-level AI policy exceptions it set in Maro. Maro's SOC 2 Type I attestation, with Type II pending, eases procurement without blocking a substitute. Co-founder Jen Andre founded Komand and Threat Stack, which Rapid7 and F5 acquired. Maro competes on that service and that founder history, and neither yet gives it a durable lead.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 2/3 Maro sells self-run software at the lower tiers, but the Managed Maro and Managed Maro Complete tiers deliver Maro-operated policy tuning, violation triage, and a virtual chief AI officer, a code-and-expertise blend beyond delivered software alone.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Customer-specific policy tuning is documented while portability, migration, and removal behavior are not, so re-integration effort is inferred from the tuning and the managed relationship, short of a shown lock.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 A SOC 2 Type I attestation with Type II pending eases procurement without blocking substitutes, and the cited record shows no mandate for this product category.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Classifying employee intent and business context in real time at the point of a browser decision is specialized engineering per the vendor's contextual-classification descriptions, with a Patent Pending badge displayed for the approach.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3 The evidenced buyers are security and technology leaders, a CISO and technology executives in the homepage testimonials, at organizations whose size and procurement posture the record does not establish, and the 5 dollar self-service checkout routes around procurement, which blends the profile.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 The extension sits inline in the employee's AI interaction path at the endpoint, more than an end-user application, and the cited record shows no downstream software depending on it.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 No named non-public dataset appears in the record. Policy detectors and context graphs are per-customer configuration, and a pending patent is not yet an enforceable asset.
Strategic Market Segmentation Maro segments by role rather than by industry: the buyer is the security leader accountable for human risk and AI adoption, and the user is every employee with a browser. The vendor built the product with input from 50 CISO and CIO leaders in financial technology, healthcare technology, and retail, which signals regulated industries as the intended center of gravity. The published pricing widens the addressable range in both directions. A 5 dollar per user self-service plan could reach smaller teams and buyers avoiding a formal sales process, while the operated governance program at 10,000 dollars or more per month targets organizations that want an AI governance function without hiring one. The cited customer evidence does not establish large-enterprise traction…

Maro segments by role rather than by industry: the buyer is the security leader accountable for human risk and AI adoption, and the user is every employee with a browser. The vendor built the product with input from 50 CISO and CIO leaders in financial technology, healthcare technology, and retail, which signals regulated industries as the intended center of gravity.

The published pricing widens the addressable range in both directions. A 5 dollar per user self-service plan could reach smaller teams and buyers avoiding a formal sales process, while the operated governance program at 10,000 dollars or more per month targets organizations that want an AI governance function without hiring one. The cited customer evidence does not establish large-enterprise traction.

Product Capabilities & AI Advantages The core capability is real-time classification of employee intent and business context in the browser. The extension observes activity, matches it against out-of-the-box AI policy and sensitive-data detectors, and intervenes at the moment of a risky action with guidance or a block. The console adds usage insight down to the business case and prompt, decision traces for violations, team-level policy exceptions, and weekly governance reports. AI is the method here, not just the subject: Maro uses machine classification to read what an employee is trying to do, which the vendor contrasts with static rules. The vendor displays a Patent Pending badge for the approach. The public record carries no documentation portal, benchmark, or third-party technical evaluation, so detection quality rests on vendor description, and the site's own sitemap lists marketing and blog pages with no documentation portal path…

The core capability is real-time classification of employee intent and business context in the browser. The extension observes activity, matches it against out-of-the-box AI policy and sensitive-data detectors, and intervenes at the moment of a risky action with guidance or a block. The console adds usage insight down to the business case and prompt, decision traces for violations, team-level policy exceptions, and weekly governance reports.

AI is the method here, not just the subject: Maro uses machine classification to read what an employee is trying to do, which the vendor contrasts with static rules. The vendor displays a Patent Pending badge for the approach. The public record carries no documentation portal, benchmark, or third-party technical evaluation, so detection quality rests on vendor description, and the site's own sitemap lists marketing and blog pages with no documentation portal path.

Sales Engagement & Go-to-Market Maro runs a two-speed go-to-market…

Maro runs a two-speed go-to-market. The bottom of the funnel is self-service: the visibility and enforcement plans check out through Stripe at 5 and 10 dollars per user per month, so a security lead can deploy without a sales call. The managed plans route through sales, and a May 2025 partnership announcement with Goliath Cyber Security Group signals channel intent, its shape undescribed in the cited page.

Demand generation leans on content: a blog about AI governance and human risk, plus a newsletter and webinar series aimed at security practitioners. Evidenced traction is vendor-published testimonials paired with the customer names Newbury Partners, PDG, and Coral AI, including a chief executive crediting Maro as AI adoption grew from 5% to 20% in a few months. Independent corroboration of customer scale has not yet appeared.

Pricing Model Maro charges by the user per month, the same unit in which the buyer experiences the problem, since every employee is a potential source of risky AI usage. Published tiers run 5 dollars (visibility), 10 dollars (real-time enforcement), and 25 dollars (Maro's team manages policy and triage), each with a 20% discount for annual billing. The top tier breaks the per-user model: Managed Maro Complete is an operated AI governance program at 10,000 dollars or more per month, including a dedicated virtual chief AI officer. Publishing prices at all, let alone a services program with a sticker price, is a transparency posture that fits the self-service motion and lets a buyer size the spend before any sales conversation…

Maro charges by the user per month, the same unit in which the buyer experiences the problem, since every employee is a potential source of risky AI usage. Published tiers run 5 dollars (visibility), 10 dollars (real-time enforcement), and 25 dollars (Maro's team manages policy and triage), each with a 20% discount for annual billing.

The top tier breaks the per-user model: Managed Maro Complete is an operated AI governance program at 10,000 dollars or more per month, including a dedicated virtual chief AI officer. Publishing prices at all, let alone a services program with a sticker price, is a transparency posture that fits the self-service motion and lets a buyer size the spend before any sales conversation.

Product Delivery & Operations Delivery is SaaS plus a browser extension, and the vendor leans on how light the deployment is: one click and a simple sign-in for employees, ready-made policies that cover top AI risks on day one, and tuning to business context afterward. The application itself is served from app.seekmaro.com. At the managed tiers, delivery becomes an operation Maro runs: continuous policy management, critical alert triage and escalation by the company's FLARE team, and automated weekly AI usage briefings. That operated layer means Maro's own capacity to staff and scale service delivery, not just its software, determines how many managed customers it can carry. The vendor claims customers improve CIS coverage by 52% in as little as a week, a vendor-published figure without independent verification…

Delivery is SaaS plus a browser extension, and the vendor leans on how light the deployment is: one click and a simple sign-in for employees, ready-made policies that cover top AI risks on day one, and tuning to business context afterward. The application itself is served from app.seekmaro.com.

At the managed tiers, delivery becomes an operation Maro runs: continuous policy management, critical alert triage and escalation by the company's FLARE team, and automated weekly AI usage briefings. That operated layer means Maro's own capacity to staff and scale service delivery, not just its software, determines how many managed customers it can carry. The vendor claims customers improve CIS coverage by 52% in as little as a week, a vendor-published figure without independent verification.

Earning Customers' Trust For a product that watches employee behavior in the browser, trust is a gating question, and Maro's posture is credible for its stage. The homepage badge states SOC 2 Type I complete and SOC 2 Type II pending, and a Secureframe-hosted trust center reports the SOC 2 Type 1 attestation with continuous control monitoring. The corporate structure is plain in the legal pages: the entity is Cyberlume, Inc., operating as Maro, with New York governing law. The cited terms discuss deidentification, while deeper privacy handling of observed employee activity sits in a privacy policy the cited record does not include, and the SOC 2 Type II report remains pending…

For a product that watches employee behavior in the browser, trust is a gating question, and Maro's posture is credible for its stage. The homepage badge states SOC 2 Type I complete and SOC 2 Type II pending, and a Secureframe-hosted trust center reports the SOC 2 Type 1 attestation with continuous control monitoring.

The corporate structure is plain in the legal pages: the entity is Cyberlume, Inc., operating as Maro, with New York governing law. The cited terms discuss deidentification, while deeper privacy handling of observed employee activity sits in a privacy policy the cited record does not include, and the SOC 2 Type II report remains pending.

Platform Strategy & Ecosystem Positioning The ecosystem story is early…

The ecosystem story is early. The browser is Maro's platform dependency: the product lives as an extension, so distribution and capability both ride on what browser vendors allow extensions to see and do. Browser makers could change what extensions may observe, or ship native AI usage controls, and either move could reshape Maro's position.

Outbound, the record shows one channel relationship, the Goliath Cyber Security Group partnership announced in May 2025, and the public site names no integration catalog or public API. A documentation portal did not appear in the sitemap either, so integration depth cannot be assessed from public sources.

Team & Execution Capability The founding trio has worked together before, and its CTO carries two exits: Jen Andre founded Komand, acquired by Rapid7, and co-founded Threat Stack, acquired by F5 for 68 million dollars. CEO Jadon Montero led MDR product at Bitdefender and SOAR product at Rapid7, and CXO Gwen Betts led UX at Rapid7 after serving on Komand's founding team. The about page lists a chief of staff and an advisory bench of product, engineering, and security leaders from established security and technology companies. The public record does not yet show the operating team behind the founders, which matters for a company selling judgment-heavy managed governance services…

The founding trio has worked together before, and its CTO carries two exits: Jen Andre founded Komand, acquired by Rapid7, and co-founded Threat Stack, acquired by F5 for 68 million dollars. CEO Jadon Montero led MDR product at Bitdefender and SOAR product at Rapid7, and CXO Gwen Betts led UX at Rapid7 after serving on Komand's founding team.

The about page lists a chief of staff and an advisory bench of product, engineering, and security leaders from established security and technology companies. The public record does not yet show the operating team behind the founders, which matters for a company selling judgment-heavy managed governance services.

Sources

Company Detail Sources (4)
Id Source Tier Accessed
f1 Maro: Guardian Agent and Security Copilot official 2026-07-09
f2 Maro newsroom: seed funding announcement (founded late 2024) official 2026-07-03
f3 MSSP Alert: Maro Raises $4.3M to Tackle Human Risk with Real-Time Interventions press 2026-07-03
f4 AI Defense Matrix Catalog mapping other 2026-07-03
Profile Analysis Sources (12)
Id Source Tier Accessed
s1 Maro homepage (SOC 2 badge, Patent Pending badge, testimonials paired with Newbury Partners, PDG, Coral AI, plus STC Health and Elevate logos)
“SOC 2 Type I Complete ... SOC 2 Type II Pending ... Chris Scowden, Newbury Partners ... Colby Whitenack, PDG ... Sean Todd, Coral AI ... Managing team-level AI policy exceptions in Maro ... AI adoption grew from 5% to 20% in just a few months”
official 2026-07-03
s2 Maro: How Maro Works (browser agent; use cases: AI governance, DLP, insider risk, browser protection, behavior and culture)
“Maro lives in the browser as a cognitive security agent, silently observing intent, app context, and behavioral cues.”
official 2026-07-03
s3 Maro pricing (Illuminate $5, Intervene $10, Managed Maro $25 per user per month, $10,000+ Complete tier, FLARE team, Stripe checkout, save 20% annually)
“Managed Maro Complete The complete AI governance program: strategy, leadership, rapid response, and legal defensibility, delivered. $10,000+ per month ... buy.stripe.com”
official 2026-07-03
s4 Maro newsroom: $4.3M seed, July 24, 2025 (50 CISO and CIO leaders in financial technology, healthcare technology, retail, Verizon DBIR human element 60%)
“Maro was founded in late 2024 by Jadon Montero, Gwen Betts, and Jen Andre, a repeat cybersecurity founder team ... involving a human element at 60% ... Improve CIS coverage by 52% in as little as a week.”
official 2026-07-03
s5 Maro about-us (Montero ex Bitdefender MDR and Rapid7 SOAR, Betts ex Rapid7 UX and Komand founding team, Goliath Cyber Security Group partnership May 7, 2025)
“Jen Andre Co-founder, CTO Previously VP Product @ GreyNoise VP Product @ Rapid7 2x Founder (Komand - Acq. Rapid7, ThreatStack - Acq. F5)”
official 2026-07-03
s6 Maro Terms and Conditions (legal entity Cyberlume, Inc., New York governing law, app.seekmaro.com)
“These Terms of Service are entered into by and between you (“you” or “Customer”) and Cyberlume, Inc. (“Maro,” "Company," "we," or "us")”
official 2026-07-03
s7 Maro Trust Center on Secureframe (SOC 2 Type 1, continuous monitoring)
“SOC 2 Type 1 Monitoring Continuously monitored by Secureframe”
official 2026-07-03
s8 MSSP Alert: Maro Raises $4.3M to Tackle Human Risk with Real-Time Interventions (July 24, 2025, funding from Downing Capital Group)
“Maro has raised $4.3 million in seed funding to take on one of cybersecurity's most persistent weak points: people.”
press 2026-07-03
s9 RegTech Analyst: Cognitive security startup Maro raises $4.3m seed round
“Maro was born from our years spent inside broken security workflows where SOC analysts didn't have time to speak directly to every employee”
press 2026-07-03
s10 TechCrunch: F5 acquires cloud security startup Threat Stack for $68 million (September 20, 2021)
“Applications networking company F5 has announced it's acquiring Threat Stack, a Boston-based cloud security and compliance startup, for $68 million.”
press 2026-07-03
s11 AI Defense Matrix Catalog: Maro product entry (runtime-ai-data protect primary, ai-orchestration-tools identify secondary)
“Browser-extension platform that discovers employee AI-tool usage and applies semantic data-loss policies at each prompt, coaching or blocking risky sharing across AI tools.”
other 2026-07-03
s12 seekmaro.com sitemap (marketing pages and blog only, no documentation portal path) official 2026-07-03
Deep-Dive Sources (12)
Id Source Tier Accessed
s1 Maro homepage (SOC 2 badge, Patent Pending badge, testimonials paired with Newbury Partners, PDG, Coral AI, plus STC Health and Elevate logos)
“SOC 2 Type I Complete ... SOC 2 Type II Pending ... Chris Scowden, Newbury Partners ... Colby Whitenack, PDG ... Sean Todd, Coral AI ... Managing team-level AI policy exceptions in Maro ... AI adoption grew from 5% to 20% in just a few months”
official 2026-07-03
s2 Maro: How Maro Works (browser agent; use cases: AI governance, DLP, insider risk, browser protection, behavior and culture)
“Maro lives in the browser as a cognitive security agent, silently observing intent, app context, and behavioral cues.”
official 2026-07-03
s3 Maro pricing (Illuminate $5, Intervene $10, Managed Maro $25 per user per month, $10,000+ Complete tier, FLARE team, Stripe checkout, save 20% annually)
“Managed Maro Complete The complete AI governance program: strategy, leadership, rapid response, and legal defensibility, delivered. $10,000+ per month ... buy.stripe.com”
official 2026-07-03
s4 Maro newsroom: $4.3M seed, July 24, 2025 (50 CISO and CIO leaders in financial technology, healthcare technology, retail, Verizon DBIR human element 60%)
“Maro was founded in late 2024 by Jadon Montero, Gwen Betts, and Jen Andre, a repeat cybersecurity founder team ... involving a human element at 60% ... Improve CIS coverage by 52% in as little as a week.”
official 2026-07-03
s5 Maro about-us (Montero ex Bitdefender MDR and Rapid7 SOAR, Betts ex Rapid7 UX and Komand founding team, Goliath Cyber Security Group partnership May 7, 2025)
“Jen Andre Co-founder, CTO Previously VP Product @ GreyNoise VP Product @ Rapid7 2x Founder (Komand - Acq. Rapid7, ThreatStack - Acq. F5)”
official 2026-07-03
s6 Maro Terms and Conditions (legal entity Cyberlume, Inc., New York governing law, app.seekmaro.com)
“These Terms of Service are entered into by and between you (“you” or “Customer”) and Cyberlume, Inc. (“Maro,” "Company," "we," or "us")”
official 2026-07-03
s7 Maro Trust Center on Secureframe (SOC 2 Type 1, continuous monitoring)
“SOC 2 Type 1 Monitoring Continuously monitored by Secureframe”
official 2026-07-03
s8 MSSP Alert: Maro Raises $4.3M to Tackle Human Risk with Real-Time Interventions (July 24, 2025, funding from Downing Capital Group)
“Maro has raised $4.3 million in seed funding to take on one of cybersecurity's most persistent weak points: people.”
press 2026-07-03
s9 RegTech Analyst: Cognitive security startup Maro raises $4.3m seed round
“Maro was born from our years spent inside broken security workflows where SOC analysts didn't have time to speak directly to every employee”
press 2026-07-03
s10 TechCrunch: F5 acquires cloud security startup Threat Stack for $68 million (September 20, 2021)
“Applications networking company F5 has announced it's acquiring Threat Stack, a Boston-based cloud security and compliance startup, for $68 million.”
press 2026-07-03
s11 AI Defense Matrix Catalog: Maro product entry (runtime-ai-data protect primary, ai-orchestration-tools identify secondary)
“Browser-extension platform that discovers employee AI-tool usage and applies semantic data-loss policies at each prompt, coaching or blocking risky sharing across AI tools.”
other 2026-07-03
s12 seekmaro.com sitemap (marketing pages and blog only, no documentation portal path) official 2026-07-03

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.