All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Maze builds AI agents that investigate vulnerability findings across a customer's cloud and source code. The agents judge which findings an attacker could reach and deliver a fix to the engineer who owns that code. Maze reports that Maze Code found a login-enforcement bug in the open-source Langfuse project. The Langfuse release notes record a matching fix to its sign-in enforcement. Security leaders at Alloy, Forge and PartsSource speak for the product on Maze's site. Maze publishes a price on AWS Marketplace: $120,000 for a 500-asset cloud environment. The London company had raised $31 million by June 2025. Maze disclosed pilots inside more than ten organizations including two Fortune 200 companies at its Series A, so a buyer weighing customer count works from the company's own number.
| Description | Maze builds AI agents that investigate vulnerabilities across a customer's cloud infrastructure and source code, judge which findings are exploitable in that environment, and deliver verified fixes to the engineers who own the code. | [f1] |
|---|---|---|
| Founded | 2024 | [f2] |
| HQ | London, United Kingdom | [f3] |
| Funding | $31M total | [f3] |
| Latest funding | Series A | [f2] |
| Product | What it does |
|---|---|
| Maze Cloud | Triages and remediates CVEs in cloud containers and virtual machines, with agents that gather runtime context to judge which findings are exploitable. |
| Maze Code | Investigates vulnerabilities in third-party dependencies and first-party code, traces reachability and business-logic flaws, then delivers a verified fix. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Maze Cloud triages and remediates CVEs in containers and virtual machines, and Maze Code investigates dependency and first-party code flaws before delivering a fix. Both apply AI to vulnerability identification and mitigation on conventional assets, and are mapped to the Cyber Defense Matrix. [f1]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Maze names a concrete buyer in security and engineering teams and a specific pain, the share of flagged vulnerabilities that turn out not to be exploitable, but the quantification comes from the company's own launch coverage rather than independent research. [s17, s10] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 3/5 | The product pages carry architecture-level detail on runtime context gathering, validation layers, and model routing, and a Langfuse release carries a fix matching the bug Maze reports its agents found, but no public documentation portal, open-source code, or third-party evaluation of the agents exists in the record. [s2, s11, s14] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | The enabler is dated and credible. SecurityWeek reported in June 2025 that Maze and its investors were betting large language models had matured enough to reason through individual cloud deployments, and Maze frames AI-written code as the reason vulnerability volume keeps climbing. Buyer-side demand amounts to one funded launch plus the press interest around it, and the reviewed record adds no analyst or budget-line evidence. The window narrows if scanner vendors add the reasoning step themselves. [s9, s14] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 | Companies House lists Harry Wetherald, Adrian Jozwik, and Santiago Castiñeira Fernández as directors, and press records senior product, design, and engineering roles at Tessian, Elastic, and Amazon, verifiable in-domain experience without the prior exits or publication record a 4 requires. [s8, s10] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | Three customers speak on the record with titles and employers, Nathan Cooke at Alloy, Jonathan Mattey at Forge, and Ted Kieffer at PartsSource. The motion is visible in two further places, a paid AWS Marketplace listing and a Wiz-published integration page, and press relays the company's own account of pilots beyond the reference set. Multiple named references plus marketplace and partner motion meet the bar a 4 asks for. [s1, s18, s12, s13, s9] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | Maze raised $31 million across a seed and a Series A within roughly a year of founding, with no disclosed revenue, and the visible output against it is two shipped product lines and a published list price, so the raise is proportional to an early enterprise motion rather than confirmed as efficient. [s22, s13, s14] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 | Vulnerability management is an established budget line a buyer places without coaching, but Maze spans cloud posture and application security at once and has to explain how investigating findings differs from the scanners that produce them. [s2, s14] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 2/5 | Maze reads findings from the scanners a customer already runs, and Wiz, whose findings it ingests, already ranks risk in the same workflow, so the reasoning step is a plausible release for a platform that owns both the finding and the buyer. [s12, s2] |
Maze sells to security and engineering teams that receive more vulnerability findings than they can work through. The company frames the pain as wasted investigation rather than missing detection. The company reports that roughly 90% of the vulnerabilities its agents analyze turn out not to be exploitable once investigated.
That number is Maze's own measurement from its own deployments, which is the limit of the problem evidence in the reviewed record. Press coverage of the Series A carried the same framing, that vulnerability exploitation rose sharply in 2024 while most enterprises fix a fraction of their open vulnerabilities, and it names no study behind those figures. [s17, s10]
Maze runs two product lines on one engine. Maze Cloud triages and remediates CVEs in containers and virtual machines, and Maze Code investigates dependencies and first-party code, building call graphs to trace whether a vulnerable function is reachable and reading code structure to surface the business-logic flaws the vendor says pattern-matching scanners miss. Deployment needs a read-only role in the cloud account or repository, with no sensors to install, and Maze Cloud also connects to a scanner the customer already runs.
Maze points to the engineering it says makes its agents dependable. Maze describes agents trained on domain-specific tasks, several layers of validation that catch errors as the agents work, and routing that picks an expensive model only when a cheaper technique will not do. One of the agents' findings appears outside the vendor's pages. Maze reports that Maze Code found a login-enforcement bug in the open-source Langfuse project, and the Langfuse v3.174.0 release notes carry a matching fix. Maze is the source for the claim that its agents found the bug. No public documentation portal, open-source code, or third-party evaluation of the agents appears in the reviewed record, so a buyer judging how well the agents work has the vendor's description and that one matching fix. [s2, s20, s11, s14, s15]
Maze layers investigation on top of the scanners a customer already runs. Its distinguishing claim is coverage across cloud and code on one engine, so a dependency flaw and the container running it resolve as a single investigation instead of arriving as two tickets from separate tools.
Maze depends on the scanner vendors that could also build what it sells. It reads findings from the scanners a customer already runs, and Wiz, one of those vendors, publishes the integration on its own site. Wiz's customers can find Maze on that page. The page also sets out publicly what ingesting those findings involves. How long that investigation step stays Maze's own is open, so a buyer should read the coverage claim as a head start of unknown length. [s12, s2, s14]
Three customers vouch for Maze by name, with titles and employers attached. Nathan Cooke is an engineering manager for product security at Alloy, Jonathan Mattey is the chief information security officer at Forge, and Ted Kieffer leads information security and risk management at PartsSource. Those quotes describe use rather than intent, and a prospective buyer can approach the people who gave them.
The wider figures are older and vendor-stated, so a buyer weighing Maze's scale today has to discount them. SecurityWeek reported in June 2025 that Maze said early pilots were running inside more than ten organizations including two Fortune 200 companies, and the reviewed record carries no independent confirmation since. The sales channels are easier to verify, because Maze sells through AWS Marketplace with a published list price and Wiz documents the integration from its side. [s1, s18, s9, s13, s12]
Companies House lists four directors of Maze AI Limited. Harry Wetherald and Adrian Jozwik have served since incorporation, Santiago Castiñeira Fernández since May 2024, and Andrew Triedman since June 2025, the Theory Ventures partner whose board seat the Series A announcement described. The founders led product, design, and engineering teams at Tessian, Elastic, and Amazon before starting the company.
What the record does not show is a prior exit or a sustained publication history, the signals that separate a credible operating team from a proven one. The same registry shows the entity was incorporated in October 2023 as Canvas Software Limited and renamed in July 2025. Press coverage dates the founding to 2024, a year after the entity itself began. [s7, s8, s10, s22]
Maze states on both product pages that it has passed its ISO 27001 accreditation and is in its SOC 2 Type 2 observation window. A trust center runs at trust.mazehq.com, and it asks a visitor to request access, so whatever that trust center documents is not open to inspection as of 2026-07-27.
Maze answers the enterprise deployment questions directly. Maze hosts in AWS, offers single-tenant as well as multi-tenant hosting, and says it uses orchestrators such as AWS Bedrock and Google Vertex that keep customer data out of model-provider training. Maze connects through a read-only role rather than software installed in the workload. The fixes the agents produce still reach production through the customer's own pull-request and ticketing paths. [s3, s16, s19, s21]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Backline | competes with | Backline pursues the same outcome with a fleet of AI agents that remediate vulnerabilities across code and configuration. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| ZEST Security | competes with | ZEST Security resolves cloud risk with agents that correlate findings and generate remediation paths. | |
| Seemplicity | competes with | Seemplicity aggregates, deduplicates, and prioritizes scanner findings, then drives remediation through automated workflows and its own AI agents. | |
| Wiz | adjacent | Wiz publishes the integration that feeds its cloud vulnerability findings into Maze, and it also ranks risk in the same workflow. |
Add analyzed competitors to compare them side by side with Maze.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
pivot urgently
Maze reads findings from scanners its customers already run, Wiz among them, and judges which vulnerabilities an attacker could reach. Wiz publishes that integration from its own side and ranks risk itself, so a scanner vendor could add the judgment step for a buyer it already serves. Maze describes agents trained on millions of investigations and several validation layers behind them. The reviewed record documents no non-public data set behind those agents. One finding is traceable outside Maze's pages, a login-enforcement fix Langfuse shipped for a bug Maze says its agents found. A buyer should read that investigation engineering as a head start rather than a durable lead.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Maze delivers software the customer's team connects, operates, and owns the outcomes for, priced per asset on a cloud marketplace, the software-product level. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Scanner, ticketing, and coding-agent integrations plus accumulated investigation history create real friction, and the reviewed record evidences no network effect or data-residency requirement that would push migration cost higher. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | Maze reports ISO 27001 and an in-progress SOC 2 Type 2 behind an access-gated trust center, credentials a determined rival can obtain, and no regulation in the reviewed record mandates this product class. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 2/3 | Running non-deterministic agents over every finding with reachability analysis, validation layers, and cost-aware model routing is substantial engineering, though the reviewed record documents the design through vendor description rather than independent evaluation. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 | The record names three reference customers with titles and employers but evidences no regulated-enterprise buyer whose compliance and legal review would slow a vendor swap, and the Fortune 200 claim is unnamed and vendor-stated. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Maze sits between the scanners and the developers as a platform with its own integrations and asset model, and nothing in production depends on it, so removing it costs coverage and reabsorbed triage work rather than uptime. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | The company describes agents trained on millions of investigations, an unnamed internal corpus rather than a documented non-public dataset, and the reviewed record shows no cross-customer asset a funded rival could not accumulate. |
Maze sells to security and engineering teams whose scanners produce more findings than the team can work through. Three reference customers speak on the company's site, an engineering manager for product security at Alloy, a chief information security officer at Forge, and a security and risk leader at PartsSource. Each names a title rather than a sector, so the record shows the role Maze sells to and not the industries it sells into.
A buyer cannot tell from the record how many customers Maze has now. In June 2025 the company said pilots were running inside more than ten organizations including two Fortune 200 companies, a floor rather than a count, and no independent source has confirmed either the count or the segment.
Maze Cloud triages and remediates CVEs in containers and virtual machines, and Maze Code investigates dependency and first-party code flaws. The dependency agents build call graphs to trace reachability through the dynamic calls the vendor says a parser gives up on, and the code agents read structure and data flow to reach business-logic flaws rather than matching known patterns.
Maze points to the engineering it says makes its agents reliable. Maze describes agents trained on domain-specific tasks, several validation layers that catch errors as agents work, and routing that reserves an expensive model for the cases that need one. One of the agents' findings appears outside the vendor's own pages. Maze reports that Maze Code found a login-enforcement bug in the open-source Langfuse project, and the Langfuse v3.174.0 release notes carry a matching fix on the email-OTP path. Maze is the source for the claim that its agents found the bug, and its account records that a person then validated the finding and coordinated disclosure.
Maze's product pages ask a visitor to book a demo rather than to start a trial. Maze also sells through AWS Marketplace as Maze Vulnerability Management, a procurement route cloud buyers already use. Wiz publishes the integration from its own side.
Maze publishes vulnerability research of its own, including the Langfuse bug its agents found and a person validated before disclosure. That gives a prospective buyer published work from the agents to read alongside the product description.
Maze publishes a list price on AWS Marketplace. A twelve-month contract to protect a cloud environment of 500 assets is listed at $120,000.00, with private offers available for custom terms.
The AWS listing sets a price for a fixed estate size and publishes no unit rate and no second tier. A buyer can therefore see what 500 assets cost and cannot work out from the listing what a larger or smaller estate would cost. Maze's own site points a buyer to a demo booking rather than to that published price, so the marketplace listing is where a buyer sees a number without contacting sales.
Deployment is light. Maze asks for a read-only role in the cloud account or repository, with no sensors or anything else to install, and the company says the setup takes minutes. Maze Cloud also connects to a scanner the customer already runs. Maze gathers runtime context without deploying anything into the workload.
Maze delivers findings and fixes where engineers already work. Maze Code runs in the CI/CD pipeline and surfaces findings at the pull request, and fixes can be pulled into an AI coding agent, with a full audit trail behind each decision so a deprioritized finding carries its reasoning. The customer's team still operates the product and owns the outcome.
Maze states on both product pages that it has passed its ISO 27001 accreditation and is in its SOC 2 Type 2 observation window. Its trust center runs at trust.mazehq.com, and a probe of that surface on 2026-07-27 returned an access-request form, so whatever that trust center documents sits behind that request. The 90% figure in the public record comes from Maze's own announcement of Maze Code, and it counts how many findings turn out unexploitable rather than how often the calls are right.
Maze answers the hosting and data-handling questions directly. Maze hosts in AWS and offers single-tenant hosting, and it says it uses orchestrators such as AWS Bedrock and Google Vertex that keep customer data out of model-provider training.
Maze layers investigation on top of the scanners a customer already runs. It reads findings from those tools, adds its own runtime and static context, and returns a verdict plus a fix. Wiz supplies those findings and ranks risk itself, so the vendor that feeds Maze could add the step Maze sells.
Maze returns its findings and fixes to the CI/CD pipeline, the pull request, and AI coding agents rather than to a separate console. Running both product lines on one engine lets a CVE that appears in code, image, and cloud resolve as a single investigation. Maze pitches that single investigation as the reason to buy both lines, and a customer reaches it by connecting the code side and the cloud side.
Companies House lists four directors of Maze AI Limited. Harry Wetherald and Adrian Jozwik have served since incorporation in October 2023, Santiago Castiñeira Fernández since May 2024, and Andrew Triedman since June 2025, the Theory Ventures partner whose board seat the Series A announcement described. The registry also records Canvas Software Limited as the entity's previous name, changed in July 2025.
The founders led product, design, and engineering teams at Tessian, Elastic, and Amazon before starting the company, which is directly relevant operating experience. The reviewed record shows no prior exit and no sustained publication history behind that experience, which is the part a buyer weighing an unproven product would want.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Maze homepage: AI agents that secure code and cloud | official | 2026-07-27 |
| f2 | Silicon Canals: London-based Maze secures 22.5M through an AI agent | press | 2026-07-27 |
| f3 | SecurityWeek: Maze Series A investors and total funding | press | 2026-07-27 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Maze homepage: named customer references at Forge and PartsSource “Jonathan Mattey Chief Information Security Officer, Forge Vulnerability scanners analyze a system in a vacuum. Maze shows you what's actually on fire. Ted Kieffer Head of Information Security and Risk Management, PartsSource” | official | 2026-07-27 |
| s18 | Maze homepage: named customer reference at Alloy “Nathan Cooke Engineering Manager, Product Security, Alloy” | official | 2026-07-27 |
| s17 | CIO Influence: Maze Launches Maze Code, exploitability figure and early findings “Early results suggest that ~90% of CVEs are not exploitable in context.” | press | 2026-07-27 |
| s2 | Maze platform page: agent design, context, and cost routing “Maze can be deployed in minutes, with a read-only role to your cloud or repository, and an integration with your scanner.” | official | 2026-07-27 |
| s3 | Maze Cloud: enterprise readiness questions “Maze has been built for enterprise from day one. We have passed our ISO 27001 accreditation and are currently in our SOC 2 Type 2 observation window.” | official | 2026-07-27 |
| s4 | Maze Code: where findings and fixes reach developers “It runs in your CI/CD pipeline (GitHub Actions, GitLab CI, CircleCI) and surfaces findings right at the pull request. We have simple ways of pulling the fixes into AI coding agents and aim to support all coding agents.” | official | 2026-07-27 |
| s19 | Maze Cloud: model orchestration and training-data handling “No, we only use orchestrators that guarantee your data is not shared with the model provider for training. For example, AWS Bedrock and Google Vertex.” | official | 2026-07-27 |
| s5 | Maze: Why are we building Maze? “So, in 2024, we decided to start a security company after all.” | official | 2026-07-27 |
| s7 | Companies House: MAZE AI LIMITED incorporated 11 October 2023, previously CANVAS SOFTWARE LIMITED “Incorporated on 11 October 2023” | regulatory | 2026-07-27 |
| s8 | Companies House: MAZE AI LIMITED directors and appointment dates “TRIEDMAN, Andrew Correspondence address” | regulatory | 2026-07-27 |
| s9 | SecurityWeek, 11 June 2025: Maze Banks 25M to Tackle Cloud Security With AI Agents “Maze said early pilots are running inside more than 10 organizations, including two Fortune 200 companies.” | press | 2026-07-27 |
| s10 | Silicon Canals: Maze founders, funding history, and market framing “Founded by Harry Wetherald, Adrian Jozwik, and Santiago Castineira in 2024, the startup has now raised a total of $31M (approximately €27.9M), coming less than a year after the company's founding and 9 months after a $6M seed round.” | press | 2026-07-27 |
| s11 | Langfuse v3.174.0 release notes: SSO enforcement fix on the email-OTP path “fix(auth): enforce AUTH_DOMAINS_WITH_SSO_ENFORCEMENT on the email-OTP path” | research | 2026-07-27 |
| s12 | Wiz integration listing for Maze, published by Wiz “Maze ingests Wiz vulnerability findings and investigates whether each one is actually exploitable in your environment.” | official | 2026-07-27 |
| s13 | AWS Marketplace: Maze Vulnerability Management listing and contract pricing “Protect cloud environment - 500 assets $120,000.00” | official | 2026-07-27 |
| s14 | Maze: Introducing Maze Code “Maze Code uses AI agents to investigate every vulnerability in your dependencies (AI-SCA) and the code your team writes (AI-SAST).” | official | 2026-07-27 |
| s15 | Maze: Maze Code found a Langfuse SSO bug “A human then validated the finding and coordinated disclosure. But the discovery was the tool's.” | official | 2026-07-27 |
| s16 | Maze trust surface probe: Vanta trust center at trust.mazehq.com rendered 2026-07-27, access-gated | official | 2026-07-27 |
| s21 | Maze Cloud: hosting and tenancy questions “Yes, Maze is cloud-hosted in AWS. Customers can choose between multi-tenant and single-tenant hosting.” | official | 2026-07-27 |
| s22 | SecurityWeek: Maze Series A investors and total raised “The London-based company said the Series A financing was provided by Theory Ventures, Cherry Ventures and Tapestry VC. Maze has raised a total of $31 million since launching nine months ago.” | press | 2026-07-27 |
| s20 | Maze platform page: deployment requirements “Maze can be deployed in minutes, with a read-only role to your cloud or repository, and an integration with your scanner.” | official | 2026-07-27 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Maze homepage: named customer references at Forge and PartsSource “Jonathan Mattey Chief Information Security Officer, Forge Vulnerability scanners analyze a system in a vacuum. Maze shows you what's actually on fire. Ted Kieffer Head of Information Security and Risk Management, PartsSource” | official | 2026-07-27 |
| s18 | Maze homepage: named customer reference at Alloy “Nathan Cooke Engineering Manager, Product Security, Alloy” | official | 2026-07-27 |
| s17 | CIO Influence: Maze Launches Maze Code, exploitability figure and early findings “Early results suggest that ~90% of CVEs are not exploitable in context.” | press | 2026-07-27 |
| s2 | Maze platform page: agent design, context, and cost routing “Trained on millions of real investigations, Maze's agents know when to use a frontier model and when a more cost-efficient technique will do, so you can finally run agents over every finding.” | official | 2026-07-27 |
| s3 | Maze Cloud: enterprise readiness questions “Maze has been built for enterprise from day one. We have passed our ISO 27001 accreditation and are currently in our SOC 2 Type 2 observation window.” | official | 2026-07-27 |
| s4 | Maze Code: where findings and fixes reach developers “It runs in your CI/CD pipeline (GitHub Actions, GitLab CI, CircleCI) and surfaces findings right at the pull request. We have simple ways of pulling the fixes into AI coding agents and aim to support all coding agents.” | official | 2026-07-27 |
| s19 | Maze Cloud: model orchestration and training-data handling “No, we only use orchestrators that guarantee your data is not shared with the model provider for training. For example, AWS Bedrock and Google Vertex.” | official | 2026-07-27 |
| s5 | Maze: Why are we building Maze? “Marketing designed to confuse rather than inform. Salespeople who treat you like a fool.” | official | 2026-07-27 |
| s7 | Companies House: MAZE AI LIMITED incorporated 11 October 2023, previously CANVAS SOFTWARE LIMITED “Incorporated on 11 October 2023” | regulatory | 2026-07-27 |
| s8 | Companies House: MAZE AI LIMITED directors and appointment dates “TRIEDMAN, Andrew Correspondence address” | regulatory | 2026-07-27 |
| s9 | SecurityWeek, 11 June 2025: Maze Banks 25M to Tackle Cloud Security With AI Agents “Maze said early pilots are running inside more than 10 organizations, including two Fortune 200 companies.” | press | 2026-07-27 |
| s10 | Silicon Canals: Maze founders, funding history, and prior employers “The founding team previously led product, design, and engineering teams at Tessian, Elastic, and Amazon, working alongside veteran engineers from Meta, Adyen, and Nvidia.” | press | 2026-07-27 |
| s11 | Langfuse v3.174.0 release notes: SSO enforcement fix on the email-OTP path “fix(auth): enforce AUTH_DOMAINS_WITH_SSO_ENFORCEMENT on the email-OTP path” | research | 2026-07-27 |
| s12 | Wiz integration listing for Maze, published by Wiz “Maze ingests Wiz vulnerability findings and investigates whether each one is actually exploitable in your environment.” | official | 2026-07-27 |
| s13 | AWS Marketplace: Maze Vulnerability Management listing and contract pricing “Protect cloud environment - 500 assets $120,000.00” | official | 2026-07-27 |
| s14 | Maze: Introducing Maze Code “Maze Code uses AI agents to investigate every vulnerability in your dependencies (AI-SCA) and the code your team writes (AI-SAST).” | official | 2026-07-27 |
| s15 | Maze: Maze Code found a Langfuse SSO bug “A human then validated the finding and coordinated disclosure. But the discovery was the tool's.” | official | 2026-07-27 |
| s16 | Maze trust surface probe: trust center at trust.mazehq.com, browser-rendered, access-gated “Maze's Trust Center. First name. Last name. Email. Company name. Reason. Request access. Already have access? Reclaim access” | official | 2026-08-01 |
| s21 | Maze Cloud: hosting and tenancy questions “Yes, Maze is cloud-hosted in AWS. Customers can choose between multi-tenant and single-tenant hosting.” | official | 2026-07-27 |
| s20 | Maze platform page: deployment requirements “Maze can be deployed in minutes, with a read-only role to your cloud or repository, and an integration with your scanner.” | official | 2026-07-27 |
| s22 | SecurityWeek: Maze Series A investors and total raised “The London-based company said the Series A financing was provided by Theory Ventures, Cherry Ventures and Tapestry VC. Maze has raised a total of $31 million since launching nine months ago.” | press | 2026-07-27 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.