Native Security

Security for AI Cloud Security also known as Native

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2024
Funding $42M
Last updated 2026-07-12

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Native Security sells a platform that turns the security controls already built into AWS, Azure, Google Cloud, and OCI into enforced policy. A security team states an outcome, such as no path from the internet to regulated data, and Native translates it into each provider’s enforcement mechanisms, simulates the change against past cloud activity, and watches for drift. Founders who led Amazon GuardDuty, AWS Security Hub, and Check Point’s cloud security line left stealth in March 2026 with $42 million and press reports of unnamed enterprise customers. Because Native configures controls the customer already owns rather than inserting agents, the coupling looks looser, its removal behavior undocumented. Renewal then depends on continued operation, catching drift, and covering new services.

Sourced Details

Description Native Security operates a multi-cloud policy enforcement platform that translates security intent into the built-in security controls of AWS, Azure, Google Cloud, and OCI, simulates policy impact before deployment, and detects drift afterward. [f1]
Founded 2024 [f2]
HQ Tel Aviv, Israel [f3]
Funding $42M total [f2]
Latest funding Series A, $31M (March 2026) [f2]

Products

Product What it does
Native Discovers cloud accounts, workloads, and identities, converts stated security outcomes into provider-native controls across AWS, Azure, Google Cloud, and OCI, and simulates impact before enforcing.

Matrix Coverage

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

Native discovers the accounts, workloads, and identities in the customer's cloud estate and enforces provider-native identity, network, and data perimeter controls across AWS, Azure, Google Cloud, and OCI. The company is mapped to the Cyber Defense Matrix. [f4]

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

The AI Enforcement at the Source capability governs which managed AI services and models can be provisioned across AWS Bedrock, Azure AI Foundry, and GCP Vertex AI and protects the data those services can reach. This capability is mapped to the AI Defense Matrix. [f5]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 26 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 CTech and Dark Reading corroborate the qualitative gap of unused built-in controls, but the quantified urgency, a Mandiant time-to-exploit figure, reaches buyers only through Native and its lead investor, so the pain stays qualitatively corroborated rather than independently quantified. [s8, s10, s12, s1]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 The platform page details each lifecycle stage, including impact simulation that replays historical cloud activity, and Dark Reading independently describes the same mechanisms. No public documentation portal or third-party technical evaluation appears in the public record, and trial access runs through AWS Security Hub Extended rather than the site. [s2, s10, s1]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 4/5 Four independent outlets covered the March 2026 launch as a shift from detection to enforcement, Fortune 100 production use is reported from launch day onward, and AWS gave the product an in-console procurement path within two months. The newest demand evidence is from the current quarter. Mandiant reported that average time-to-exploit reached minus one day in 2024, and the vendor and its lead investor cite that attacker acceleration as the case for preventive enforcement. [s8, s9, s10, s11, s5, s12, s13]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 4/5 Multiple outlets state in their own voice that Amit Megiddo led Amazon GuardDuty product, Gal Ordo led AWS Security Hub, and Eyal Faingold ran Dome9 R&D and then Check Point's cloud security portfolio, prior builds in exactly this domain. Phil Venables joining the board adds independent senior endorsement. [s9, s8, s10, s13]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 3/5 Customers are Fortune 100 organizations in finance, technology, and media per press accounts, named only at the level of sector, which the anchors read as reference traction that is real but largely undisclosed. The score includes a small upward adjustment for verifiable AWS and Google Cloud marketplace listings plus the investor and board pedigree that suggests real traction, and the homepage now adds named security leaders whose customer status still needs confirming. [s8, s13, s1, s5]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 A $42 million total raise supports a 41-person team that reached claimed Fortune 100 production deployments and two cloud marketplace listings within two years of founding, a reasonable output pace for the stage. Revenue is undisclosed and the deployment claims are company-stated, so efficiency cannot be confirmed either way. [s8, s11, s9]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 Cloud security control plane is the vendor's own coinage, and although Dark Reading repeats it in a headline, no fetched source shows buyers or analysts placing the product on an existing budget line without coaching. The nearest stack slot, enforcement alongside CNAPP detection, still requires explanation. [s10, s11, s5, s8]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 Multi-cloud equivalence is structurally awkward for any single hyperscaler to copy, since none has an incentive to operationalize a competitor's controls, but CNAPP vendors adding enforcement face no such barrier. Guardrails deploy as the customer's own provider-native policies and can export as code, so the product accumulates little that locks anyone in. [s2, s10, s13]
Business Risks Wiz, Orca Security, and Palo Alto Networks are extending cloud posture products toward remediation…
  • Wiz, Orca Security, and Palo Alto Networks are extending cloud posture products toward remediation. If their enforcement reaches parity before Native confirms reference customers, the differentiation narrows to simulation safety.
  • AWS could fold intent-based multi-account enforcement into its own console, and the Security Hub Extended relationship gives it full visibility into Native's traction. The same channel that validates the company could absorb its single-cloud value.
  • Press coverage names customers only by sector, and the homepage testimonials from named security leaders still need confirming as paying customers rather than advisors. If that confirmation does not arrive by mid-2027, go-to-market progress has not kept pace with the $42 million raise.
  • Enforcement artifacts persist in the customer's cloud and can export as code, so a customer could complete initial hardening and then operate the guardrails without Native, capping renewal revenue.
  • CTech reports plans to grow from 41 to around 90 employees by the end of 2026. Doubling headcount before confirmed reference proof exists would repeat the premature-scaling pattern if references do not materialize.
Problem & Market Native Security targets enterprises that run security across several clouds at once…

Native Security targets enterprises that run security across several clouds at once. The company argues that AWS, Azure, Google Cloud, and OCI already ship strong security primitives, and that customers struggle to operationalize them consistently, which leaves posture tools reporting problems that nobody converts into preventive controls. The homepage states the thesis directly, that the industry has gotten good at finding risks in the cloud and now needs to build defenses.

Independent coverage corroborates the gap in its own voice. CTech writes that the product addresses the accelerating pace of change in cloud and AI infrastructure, and Dark Reading frames the platform around keeping controls consistent when teams lack deep expertise in every cloud environment they use.

The urgency argument depends on attacker speed and arrives through interested voices. The launch release cites Google's Mandiant finding that average time-to-exploit hit minus one day in 2024, and Ballistic, the lead investor, repeats the same figure, so the quantified pain is third-party research curated by the vendor rather than buyer-side evidence. [s1, s8, s10, s12, s13]

Product Capabilities Native discovers the estate before it enforces anything…

Native discovers the estate before it enforces anything. The platform page describes a live topology of every account, workload, identity, and resource, with zones auto-discovered and actors mapped, which the product then uses as the basis for control decisions.

Intent translation is the core mechanism. A security team states an outcome such as no path from the public internet to regulated data, and Native generates the provider-specific enforcement, service control and resource control policies on AWS, network security perimeters on Azure, organization policies with VPC Service Controls on Google Cloud, and security zones on OCI. Teams can deploy guardrails directly, export them as code, or follow guided implementation.

Safety tooling addresses the reason enterprises fear preventive controls. Dark Reading describes pre-deployment impact simulation, intelligent rollout strategies, and built-in approval workflows, and the platform page details replaying historical cloud activity to model enforcement impact, plus post-deployment visibility into blocked actions. Drift detection and managed exceptions keep installed controls aligned over time.

Public technical depth stops at structured marketing. The site offers no public documentation portal, and trial access runs through AWS Security Hub Extended, where every activating AWS customer gets a 30-day free trial with full product access, rather than through a general website signup. Capability assessment therefore depends on the platform page and press briefings. An AI enforcement pillar extends the same model to managed AI services, governing which services and models can be provisioned across AWS Bedrock, Azure AI Foundry, and GCP Vertex AI. [s2, s1, s10, s5]

Competitive Positioning Native positions against the detect-and-react cycle rather than against a named vendor…

Native positions against the detect-and-react cycle rather than against a named vendor. The homepage dismisses inspecting the cloud and telling teams to fix what is wrong as reactive, and the company's blog sharpens the claim into a category argument, that seeing and detecting is mature and enforcement is what comes next.

The crowded side of the market is detection. Wiz, Orca Security, and Palo Alto Networks sell cloud-native application protection platforms that find and prioritize risk, and each is extending toward remediation. Native's bet is that enforcement through the providers' own control frameworks, simulated before deployment so it does not break production, is a different engineering discipline from generating fixes for findings. Sonrai Security's permissions firewall runs the nearest enforcement-first motion, scoped to identity.

The hyperscalers are partners, channel, and latent competitors at once. Native distributes through the AWS and Google Cloud marketplaces and joined AWS Security Hub Extended, while each provider also builds the single-cloud version of the same enforcement. Cross-cloud equivalence is the structural defense, because no provider has an incentive to operationalize a competitor's controls. [s1, s5, s10, s2]

Go-to-Market & Traction Customer evidence is substantial in description and not yet confirmed at the named level…

Customer evidence is substantial in description and not yet confirmed at the named level. The press release and CTech report Fortune 100 organizations in finance, technology, and media, and Ballistic, the lead investor, describes deployments at a major global streaming service and a major chip manufacturer. The homepage now carries video testimonials from named security leaders, including Drew Robertson, CISO and CIO at Renaissance Learning, and Huy Li, Head of Global IT Infrastructure and Security at Monolith Power Systems, whose status as paying customers rather than advisors still needs confirming.

Distribution leans on the cloud providers themselves. Native lists on the AWS and Google Cloud marketplaces, both linked from the site footer, and in May 2026 the company announced availability through AWS Security Hub Extended, which puts procurement in the AWS console with pay-as-you-go pricing on the AWS bill. Amit Megiddo writes that AWS selected two vendors for the cloud security category, a curation the company presents as validation.

Founders front the selling at a stage where that fits. Megiddo authors the company blog and is the quoted voice across the launch coverage, and CTech reports plans to grow from 41 people to around 90 employees by the end of 2026, which implies the commercial organization is still forming underneath the founders. [s12, s8, s13, s1, s5, s6]

Team & Credibility The founders previously built the controls Native now operationalizes…

The founders previously built the controls Native now operationalizes. Amit Megiddo led product for Amazon GuardDuty, Gal Ordo led AWS Security Hub, and Eyal Faingold was VP of R&D at Dome9 and then led the cloud security portfolio at Check Point, roles that GeekWire, CTech, and Dark Reading each state in their own voice. The match between résumé and product is as direct as it gets in this category.

Senior endorsement around the company is dense for a Series A. Phil Venables, former CISO of Google Cloud, joined the board, and CTech lists Zohar Alon of Dome9, Doug Merritt of Aviatrix and formerly Splunk, and Udi Mokady of CyberArk among investors and advisors. The press release says the 41-person team draws from the major cloud providers, Israeli military cyber units, and companies including Palo Alto Networks, Lacework, Axonius, and Cyera. [s9, s8, s10, s12, s13]

Trust Readiness Trust collateral matches what enterprise procurement screens for…

Trust collateral matches what enterprise procurement screens for. Native runs a SafeBase trust center listing SOC 2 Type 2 and ISO/IEC 27001 alongside GDPR, CCPA, HIPAA, and CIS Controls postures, with a SOC 2 report, ISO 27001 attestation, and pentest report available on request. The homepage carries AICPA SOC and ISO 27001 marks. For a 2024-founded company requesting write-level control over enterprise cloud policy, that posture answers the procurement screening question before it is asked.

The remaining trust hurdle is operational rather than compliance-shaped. A platform that changes organization-level policies can break production, so the impact simulation, approval workflows, and staged rollouts that Dark Reading relays are the real counterparty argument. No SLA, status page, or public vulnerability disclosure policy appears in fetched sources, and customers named only by sector leave third-party risk teams leaning on certifications and founder pedigree. [s7, s1, s10, s2]

Competitors Wiz, Orca Security, Palo Alto Networks, Sonrai Security…
Company Relationship Note Compare
Wiz competes with CNAPP incumbent whose detection-and-remediation estate holds the cloud security budget line Native wants to split toward enforcement.
Orca Security competes with Agentless cloud posture platform competing for the same cloud security spend with a find-and-prioritize motion. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Palo Alto Networks competes with Platform incumbent whose Cortex Cloud line bundles cloud posture and remediation for enterprises Native targets. N/AWe scored these companies at different scopes, so the totals measure different things.
Sonrai Security competes with Cloud permissions firewall vendor running an enforcement-first motion adjacent to Native's, scoped to identity and access. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.

Add analyzed competitors to compare them side by side with Native Security.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 13 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

Native Security is hardest to displace in its cross-provider engineering, the system that keeps four clouds' enforcement rules aligned and replays activity to simulate a change before it ships. That work is deep, the kind the founders built inside AWS and Check Point. But it is reproducible rather than an accumulating asset. A funded rival could rebuild the translation logic, per-customer topology stays tenant-specific, and Native holds no cross-customer data. The guardrails run as the customer's own provider-native policies and export as code through Terraform or native IaC, an architecture that suggests removal leaves installed policies in place, though uninstall behavior is undocumented. What a buyer pays for is that engineering and an early lead, not yet a durable advantage.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Customers buy a software platform and keep the enforcement decisions, with approval workflows and deployment choices under their control. No managed service, judgment layer, or accountability acceptance is part of the public offer.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Operational embedding through drift detection, managed exceptions, and simulation builds real friction, but enforcement artifacts are the customer's own provider-native policies and can export as code through Terraform or native IaC, so the product deliberately forgoes the data-gravity lock a proprietary control layer would hold.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 SOC 2 Type 2 and ISO/IEC 27001 attestations are table stakes for the access the product requires, and no compliance regime mandates this product class. Nothing in fetched sources shows a regulatory position a competitor could not match by getting audited.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Maintaining semantic equivalence across four providers' distinct control frameworks while simulating enforcement impact against historical activity is deep, provider-specific engineering, work adjacent to the systems the founders led inside AWS and Check Point.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 Reported customers are Fortune 100 organizations in finance, technology, and media plus regulated institutions, and there is no self-service path outside the AWS console listing, so procurement and legal gate the relationships on both sides.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 Native operates as a management layer spanning the customer's cloud estate, more than a point application, and the reviewed record identifies no system that depends on Native being present, though post-removal guardrail behavior is undocumented.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 The intent-to-control translation maps and replay-based simulation are engineered vendor IP a copycat could rebuild, and per-customer topology stays tenant-specific. No cross-customer dataset or licensed corpus is claimed, so the data position is replicable rather than a non-public accumulating corpus moat.
Strategic Market Segmentation Native sells to enterprises whose estates span several clouds, and the visible customer base begins with Fortune 100 organizations…

Native sells to enterprises whose estates span several clouds, and the visible customer base begins with Fortune 100 organizations. Press reports those customers in finance, technology, and media, and the company’s blog adds fast-growing technology companies and regulated institutions, which together describe buyers with sprawling multi-cloud estates and heavyweight procurement processes.

The newest public proof of demand is current. The company left stealth on March 17, 2026, and announced AWS Security Hub Extended availability on May 15, 2026, so the record shows shipping into the present cloud and AI adoption cycle rather than a launch left to age.

The operating persona is the cloud security engineer, and the economic buyer is the leadership above that person. Megiddo’s blog pitches elite architecture leverage delivered to a small team, and the pay-as-you-go AWS channel is the one motion in the record that could eventually reach buyers below the enterprise tier.

Product Capabilities & AI Advantages The claimed mechanism is consistent everywhere it appears…

The claimed mechanism is consistent everywhere it appears. Vendor pages and press describe the same pipeline, a discovered topology of accounts, workloads, and identities, intent translated into provider-native controls across the four clouds, impact simulation that replays historical activity, and drift detection once guardrails are installed.

The claimed AI advantage is translation rather than a proprietary corpus. The homepage shows security intent expressed in natural language and converted into provider-specific policies, and the platform page applies the same enforcement model to managed AI services, defining which AI services can be provisioned and which models can be called and preventing those services from reaching sensitive data or PII, enforced through provider-native controls the page names as Bedrock policies on AWS, Vertex AI restrictions on Google Cloud, and Azure AI Foundry guardrails on Azure. No cross-customer data flywheel is claimed in fetched sources.

Demonstrated capability is hard to separate from structured marketing. With no public documentation, sandbox, or independent technical evaluation, the verifiable footprint reduces to consistent press descriptions, the investor’s account of a streaming-service customer enforcing preventive controls after simulation, and the SafeBase trust center certifications, which fetched sources list without dating against the customer relationships.

Sales Engagement & Go-to-Market Native runs an enterprise sales-assisted motion with founders out front…

Native runs an enterprise sales-assisted motion with founders out front. The direct site’s commercial calls to action are demo booking and contact, CEO Amit Megiddo is the quoted company voice in launch coverage, joined by investor and board quotes, and Amit Megiddo authors the company blog, a stage-appropriate posture for a company whose disclosed customers arrived early, with sales roles open on its careers page. The AWS Security Hub Extended motion adds a self-serve path the direct site lacks, with every AWS customer activating Native there getting a 30-day free trial with full product access.

Marketplace distribution is unusually developed for a company this young. Native lists on AWS Marketplace and shows Google Cloud as a partner, and in May 2026 it became available through AWS Security Hub Extended, in-console procurement on the AWS bill that the company says removes the friction of buying from startups. Megiddo notes that AWS selected two vendors for the cloud security category, which makes the slot itself a scarce distribution asset an imitator cannot simply buy.

The channel map now extends past the providers. The partners page publishes a reseller and channel track for VARs, MSPs, consultancies, and distributors with deal registration and co-selling, alongside a technology alliances track for integration partners, so the program reads as scaffolding more than evidence of an active partner roster. Distribution today rests on direct demo-led sales plus the providers’ storefronts, with the reseller and alliance program a stated intent whose live partner list is not visible in the reviewed record.

Pricing Model Native publishes no pricing for its direct motion, which signals negotiated enterprise deals…

Native publishes no pricing for its direct motion, which signals negotiated enterprise deals. The website’s only commercial calls to action are demo scheduling and contact, and no fetched source reports deal sizes, so the direct revenue model stays opaque beyond the enterprise posture it implies.

The AWS channel discloses what the website withholds. Security Hub Extended sells Native with pay-as-you-go pricing on the customer’s AWS bill, which the company describes as transparent pricing a few clicks from deployment, opening with a 30-day free trial. The consumption unit behind that price does not appear in fetched sources, and the choice matters, because charging by accounts or resources covered would scale with estate size while charging by enforcement activity would penalize the proactive behavior the product exists to create.

Cost behavior over time is the question buyers will press. A guardrail estate grows with each provider service the customer adopts, and no fetched source explains how spend tracks that growth or what happens to price when coverage expands.

Product Delivery & Operations Native delivers as a managed platform that connects to the customer’s cloud control planes…

Native delivers as a managed platform that connects to the customer’s cloud control planes. A login portal at app.native.security fronts the product, and enforcement lands inside customer environments as provider-native policies, deployable directly, through Terraform or native IaC pipelines, or rolled out through guided implementation.

Blast-radius control is the operational core rather than an afterthought. The platform replays historical cloud activity to model enforcement impact, recommends rollout sequencing, routes changes through approval workflows, and reports blocked actions after deployment, the mechanisms Dark Reading relays as the answer to enforcement breaking production. Managed exceptions with documented approvals and expiration handle the cases policy cannot anticipate.

Public operational collateral lags the architecture. No SLA, status page, or deployment documentation appears in fetched sources, a normal gap at this age but a real one for a product whose failure mode is blocking legitimate business activity.

Earning Customers' Trust Native publishes a SafeBase trust center that lists SOC 2 Type 2 and ISO/IEC 27001 alongside GDPR, CCPA, HIPAA, and CIS Controls postures, and the homepage carries the audit marks, collateral that a young company rarely shows this early and that write access to organization policy makes mandatory…

Native publishes a SafeBase trust center that lists SOC 2 Type 2 and ISO/IEC 27001 alongside GDPR, CCPA, HIPAA, and CIS Controls postures, and the homepage carries the audit marks, collateral that a young company rarely shows this early and that write access to organization policy makes mandatory. The portal also exposes a stack of security documentation behind access requests, including a pentest report, a privacy whitepaper, an SBOM, a data processing agreement, a master services agreement, and a subprocessor list.

The product’s design is the second trust argument. Native configures controls the customer already owns instead of inserting an agent or proxy into runtime paths, keeps humans in approval workflows, and simulates before enforcing, which converts the scariest part of the pitch into the most defensible part of the architecture.

The gaps are the ones certifications cannot cover. No public vulnerability disclosure policy appears in the reviewed sources, and the public customer case studies stay unnamed. The homepage does carry named security-leader testimonials, including Drew Robertson of Renaissance Learning and Huy Li of Monolith Power Systems, but it does not label them as production customers, so a third-party risk reviewer still leans on founder pedigree and audit reports rather than a clearly named reference to call.

Platform Strategy & Ecosystem Positioning Native’s ecosystem motion runs through the cloud providers rather than around them…

Native’s ecosystem motion runs through the cloud providers rather than around them. The product is a layer over four providers’ control frameworks, the company distributes through AWS Marketplace and shows Google Cloud as a partner, and the partners page frames partnership as enforcing secure-by-design together with the providers’ own mechanisms.

The AWS Security Hub Extended slot doubles as ecosystem validation. Megiddo writes that AWS selected two vendors for the cloud security category and frames the split as detection on one side and enforcement on the other, positioning Native as the enforcement half of a category AWS just created inside its console.

Third-party builder mechanics stay thin even as a partner program exists. The partners page now invites integration and joint go-to-market through a technology alliances track for platforms, CNAPPs, IAM, CIEM, and data and developer tools, yet the reviewed pages expose no public API documentation, SDK, or integration directory for companies building on Native, so the platform claim currently rests on architectural breadth, provider distribution, and an early alliance program rather than network effects.

Team & Execution Capability The founding trio covers both halves of the product’s requirement, insider knowledge of the providers’ security machinery and experience building and shipping cross-cloud security for enterprises…

The founding trio covers both halves of the product’s requirement, insider knowledge of the providers’ security machinery and experience building and shipping cross-cloud security for enterprises. Amit Megiddo led product for Amazon GuardDuty, Gal Ordo led AWS Security Hub, and Eyal Faingold led Check Point’s cloud security portfolio after Dome9, where the lead investor’s post places him as VP of R&D. Independent outlets state the Check Point and AWS backgrounds in their own voice.

The organization was 41 people across Israel, the UK, and the US in CTech's March 2026 reporting, with plans to reach around 90 by the end of 2026. The careers page shows on-site Tel Aviv hiring including AI and ML engineering roles, and the press release says the team draws from the major cloud providers, Israeli military cyber units, and companies including Palo Alto Networks, Lacework, Axonius, and Cyera.

Senior validation around the company is dense for its stage. Phil Venables, former CISO of Google Cloud, sits on the board, and CTech lists Zohar Alon of Dome9, Doug Merritt of Aviatrix and formerly Splunk, and Udi Mokady of CyberArk among investors and advisors, operators who have built and bought in exactly this market.

Sources

Company Detail Sources (5)
Id Source Tier Accessed
f1 Native Security homepage official 2026-06-11
f2 CTech on the Native Series A (March 17, 2026) press 2026-06-11
f3 FinSMEs on the Native Series A (March 17, 2026) press 2026-06-11
f4 Native platform page official 2026-06-11
f5 Native platform page official 2026-06-16
Profile Analysis Sources (13)
Id Source Tier Accessed
s1 Native Security homepage
“Turn your built-in cloud security controls into active, operational defenses across AWS, Azure, Google Cloud, and OCI.”
official 2026-06-18
s2 Native platform page
“Replay historical cloud activity against proposed controls before deployment.”
official 2026-06-12
s3 About Native page
“Built by a team that's lived cloud security from the inside out.”
official 2026-06-12
s4 Native careers page official 2026-06-12
s5 Security Hub Extended blog post (company blog, May 15, 2026)
“Security Hub Extended gives AWS customers direct access to curated security solutions inside the AWS console, on the AWS bill, with pay-as-you-go pricing and no long procurement cycle.”
official 2026-07-02
s6 Native partners page
“The footer links a live AWS Marketplace listing (prodview-r3qf44ptibrv6) and a Google Cloud Marketplace listing (native-marketplace/gcp-native-marketplace), and the page invites cloud providers and security platforms into a joint go-to-market motion.”
official 2026-07-02
s7 Native trust center
“Compliance list shows SOC 2 Type 2 and ISO/IEC 27001 alongside CCPA, GDPR, HIPAA, and CIS Controls 8.1, with a SOC 2 Report, ISO/IEC 27001, and pentest report available on request.”
official 2026-06-18
s8 CTech on the Native Series A (March 17, 2026)
“The company has raised a total of $42 million to date.”
press 2026-06-12
s9 GeekWire on the Native launch (March 17, 2026)
“Megiddo, who is based in Seattle, led Amazon GuardDuty within AWS”
press 2026-06-12
s10 Dark Reading on the Native launch (March 19, 2026)
“Native's platform also includes predeployment impact simulation, intelligent rollout strategies, and built-in approval workflows to ensure nothing disrupts business operations, the company said in a statement.”
press 2026-06-12
s11 FinSMEs on the Native Series A (March 17, 2026)
“The round, which brought total funding to $42m, was led by Ballistic Ventures, with participation from seed investors General Catalyst, YL Ventures, and Merlin Ventures.”
press 2026-06-12
s12 Native stealth-exit press release (ACCESS Newswire, March 17, 2026)
“Google's Mandiant reported that the average time-to-exploit hit minus one day in 2024”
press 2026-06-12
s13 Ballistic Ventures investment post on Native
“The platform is already deployed in large Fortune 100 global enterprises”
press 2026-06-12
Deep-Dive Sources (20)
Id Source Tier Accessed
s1 Native Security homepage
“Native translates it into enforceable identity and network controls through your providers' own architecture.”
official 2026-06-18
s2 Native platform page
“Define which AI services can be provisioned and which models can be called, by account and workload. Prevent AI services from accessing sensitive data or PII in prompts and training pipelines.”
official 2026-06-18
s3 About Native page
“Built by a team that's lived cloud security from the inside out.”
official 2026-06-11
s4 Native careers page official 2026-06-11
s5 Security Hub Extended blog post (company blog, May 15, 2026)
“Every AWS customer activating Native through Security Hub Extended gets a 30-day free trial. That's 30 days of full visibility into the current state of your security architecture and preventative controls across every cloud you run.”
official 2026-07-02
s6 Native partners page official 2026-07-02
s7 Native trust center
“Reports: Pentest Report, Privacy Whitepaper, SOC 2 Report. Documents: ISO/IEC 27001, SOC 2 Type 2, Software Bill of Materials (SBOM), Data Processing Agreement, Master Services Agreement, Subprocessors.”
official 2026-06-18
s8 CTech on the Native Series A (March 17, 2026)
“Native currently employs 41 people across Israel, the UK and the U.S., and plans to expand to around 90 employees by the end of 2026.”
press 2026-06-11
s9 GeekWire on the Native launch (March 17, 2026)
“Native has 41 employees across the U.S. and Israel, with a majority based in the Tel Aviv area, according to LinkedIn.”
press 2026-06-11
s10 Dark Reading on the Native launch (March 19, 2026)
“Native's platform also includes predeployment impact simulation, intelligent rollout strategies, and built-in approval workflows to ensure nothing disrupts business operations, the company said in a statement.”
press 2026-06-11
s11 FinSMEs on the Native Series A (March 17, 2026)
“The round, which brought total funding to $42m, was led by Ballistic Ventures, with participation from seed investors General Catalyst, YL Ventures, and Merlin Ventures.”
press 2026-06-11
s12 Native stealth-exit press release (ACCESS Newswire, March 17, 2026)
“Native today emerged from stealth with $42 million in funding, introducing the first cloud security control plane”
press 2026-06-11
s13 Ballistic Ventures investment post on Native
“With Native, they were able to simulate policy impact safely, then enforce preventive controls across all environments”
press 2026-06-11
s14 Native homepage hero (cloud coverage)
“Turn your built-in cloud security controls into active, operational defenses across AWS, Azure, Google Cloud, and OCI.”
official 2026-06-13
s15 Dark Reading on the Native founders' backgrounds
“Megiddo previously led Amazon GuardDuty at AWS, Ordo previously led AWS Security Hub, and Faingold was previously the vice president of cloud security at Check Point.”
press 2026-06-13
s16 Native platform page (AI provider-native controls)
“Those boundaries are enforced through provider-native controls: Bedrock policies on AWS, Vertex AI restrictions on Google Cloud, Azure AI Foundry guardrails on Azure.”
official 2026-06-18
s17 Native partners page (reseller and channel program)
“Best for firms that source, sell, and deliver Native in customer environments. Select for VARs, MSPs, consultancies, distributors.”
official 2026-07-02
s18 Native partners page (technology alliances and marketplace footer)
“Best for platforms and vendors that want an integration and a joint go-to-market motion. Select for Cloud providers, security platforms, CNAPPs, IAM, CIEM, data, developer tools.”
official 2026-07-02
s19 Native homepage (named security-leader testimonials)
“It's multi weeks or months to get a policy changed or updated. And you have that drift over time. Drew Robertson, CISO & CIO, Renaissance Learning. Create one policy and push it out to the rest of the cloud. Huy Li, Head of Global IT Infrastructure & Security, Monolith Power Systems.”
official 2026-06-18
s20 Native partners page (marketplace listing footer links)
“Footer links in the served HTML carry the AWS Marketplace listing at https://aws.amazon.com/marketplace/pp/prodview-r3qf44ptibrv6 and the Google Cloud Marketplace listing at https://console.cloud.google.com/marketplace/product/native-marketplace/gcp-native-marketplace, checked 2026-07-02.”
official 2026-07-02

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.