All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
The Onyx Guardian Agent supervises every other AI agent and can block or redirect an action before it reaches a downstream system. The rest of Onyx Security's record is specific in the places a procurement team checks first. Its founders are named and pedigreed, a CEO out of Unit 8200 and an AI researcher who reported to the CTO of Nvidia. Its money is documented, 40 million dollars from Conviction and Cyberstarts. The homepage now carries two named CISO testimonials, Eli Edelkind beside the CAVA logo and Kyle Weckman, alongside unnamed Fortune 500 use. Those references are vendor-displayed, not spoken on the record in independent reporting, so the next signal is an enterprise confirming its deployment outside Onyx's own page.
| Description | Onyx: Control plane that discovers sanctioned and shadow AI agents, monitors prompts and agent actions in real time, and enforces security and governance policies across enterprise AI use. | [f1] |
|---|---|---|
| Founded | 2024 | [f2] |
| HQ | Tel Aviv, Israel and New York, USA | [f3] |
| Funding | $153M total | [f4] |
| Latest funding | Series B, $113M (July 2026) | [f5] |
| Deployment | Hybrid, SaaS, Self-hosted | [f6] |
| Product | What it does |
|---|---|
| Onyx | Onyx: Control plane that discovers sanctioned and shadow AI agents, monitors prompts and agent actions in real time, and enforces security and governance policies across enterprise AI use. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Onyx is a control plane that discovers sanctioned and shadow AI agents, monitors prompts and agent actions in real time, brokers model-access traffic, and enforces and governs security policy across enterprise AI use. It is mapped to the AI Defense Matrix. [f7]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Onyx names a specific buyer but the pain (agents reaching critical systems) is qualitative and unquantified, and SiliconANGLE and SecurityWeek corroborate the agent attack surface only as general category framing rather than independently quantified pain, so it sits at the present-but-unproven default. [s8, s4, s5] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 3/5 | SecurityWeek describes a concrete mechanism, the Onyx Guardian Agent discovering agents across cloud, endpoints, code, and SaaS and approving or correcting their actions at runtime. So soon after launch there are no public technical docs, no open-source code, and no third-party evaluation, so the depth comes from press description rather than independent validation. [s4, s2, s6] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | The two same-week $40 million raises and Conviction and Cyberstarts backing are investor signals rather than buyer-side demand, and the rest is general awareness of agent adoption since 2024, indirect signals that match the plausible-timing default rather than multiple corroborated buyer demand signals. [s5, s3, s8] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 | Bar Kogan's Unit 8200 service and Elbaz's Nvidia and IDF AI research background are elite in-domain pedigree but carry no prior exit and no sustained publication record. [s7, s3] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 | Onyx says Fortune 500 companies already use the control plane and SecurityWeek reports work with multiple large companies, and its homepage now shows named CISO testimonials beside customer logos rather than anonymous quotes. That proof is still vendor-displayed rather than spoken on the record in independent reporting, so the reference gap is common across the category, not an Onyx-specific weakness. Backing from Conviction and Cyberstarts supports real undisclosed interest, an indirect signal beyond design-partner mentions alone. [s8, s4, s3] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | The $40 million total ($5 million seed and $35 million Series A) is broadly proportional to an enterprise go-to-market at launch, matched by peer Bold's identical raise, with visible shipping in a control plane and a team of 70, but no disclosed revenue leaves output per dollar unconfirmed at the default. [s3, s8, s4] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 | AI agent security and the AI control plane are a nascent and contested slot that launch-coverage press only began naming as Onyx and Bold surfaced, an emerging category rather than an established budget line buyers place without coaching, which holds it at the default. [s5, s4, s8] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Discovering and governing AI agents is a capability platform vendors and identity providers can build toward, so the standalone purchase is exposed to bundling. The supervisory Guardian Agent that oversees other agents raises replication cost but is not independently validated, so it is not a structural moat. [s2, s4, s5] |
Onyx Security treats the autonomous AI agents an enterprise runs as systems it must discover, watch, and constrain before they act on critical infrastructure. CEO Maxim Bar Kogan frames the problem as the loss of control when something the company depends on can make decisions it cannot fully understand. The buyers, per the homepage, are the security, governance, and AI teams adopting agents across departments.
Independent reporting corroborates the gap beyond vendor marketing. SiliconANGLE described organizations deploying AI across their infrastructure and creating new attack surfaces and operational risks that traditional security tools struggle to address. That framing places the pain Onyx sells against in the words of a non-vendor source rather than the company's own pitch.
The risk Onyx emphasizes is autonomous action on real systems. An agent given access to critical systems can make a serious mistake or be compromised through a crafted prompt, which turns a reasoning error into a live operational incident. Discovery and runtime control are meant to catch that before it reaches a downstream system. [s2, s5, s4]
The Onyx platform centers on a supervisory agent rather than a single control point. SecurityWeek describes the Onyx Guardian Agent continuously discovering AI agents across cloud, endpoints, code, and SaaS deployments, then monitoring them and approving or correcting their actions to enforce security and governance policies. The catalog entry adds that it covers sanctioned and shadow AI and monitors prompts and agent actions in real time.
The runtime layer is where the product claims to act. The Guardian Agent can block an unsafe action, require human approval, narrow an agent's scope, or redirect it toward a safer path before anything reaches a downstream system, per the launch announcement. The same announcement positions the Guardian Agent as the supervisory layer overseeing every other agent in the environment.
Public technical depth stops at that description. So soon after launch there are no architecture docs, no open-source components, and no third-party evaluation in the pages reviewed, so a buyer evaluating the Guardian Agent would start from sales conversations rather than testable artifacts. [s4, s2, s6]
Onyx competes in AI agent security against both independents and the platforms building toward the same controls. SiliconANGLE reported that Bold Security surfaced the same week with the same $40 million. Several other funded independents cover overlapping discovery, monitoring, and runtime enforcement for the enterprise AI buyer.
Onyx's visible differentiator is its founding team and its supervisory Guardian Agent. Bar Kogan came from Unit 8200 and Gil Elbaz reported to the CTO of Nvidia, per CTech, and the company positions a Guardian Agent that oversees other agents that rivals would have to reproduce. That pedigree is the asset a bundled competitor cannot quickly copy.
The structural risk is who owns the buyer relationship. Platform vendors can bundle agent governance into deals an enterprise already signs, and identity providers can extend agent access governance from the credentials they already manage. Onyx's independence is both its neutrality pitch and its exposure. [s5, s3, s4]
Onyx points to enterprise traction that is now partly named. The launch announcement says Fortune 500 companies already use the control plane to govern their agents, and SecurityWeek reports it is working with multiple large companies, which is more than design-partner language. The homepage closes part of that gap with named CISO testimonials shown beside customer logos, including Eli Edelkind beside the CAVA logo.
Investor conviction is the clearer signal. Conviction, founded by Sarah Guo, led the $35 million Series A and Cyberstarts backed the earlier seed, per CTech, which is capital betting on the motion rather than buyer proof. The launch drew coverage in SiliconANGLE, SecurityWeek, and CTech, which builds awareness at the moment of entry.
The motion is early and direct. Onyx routes prospects to a demo request and plans to spend the raise on product, engineering, new AI models, and go-to-market, per CTech. The remaining proof gap is a named customer organization or case study with deployment scope, not merely named individual testimonials. [s2, s3, s10]
The founders pair offensive-security and AI-research backgrounds. CTech reports that CEO Maxim Bar Kogan is a security leader and technology executive who served in Unit 8200 of the IDF, the country's signals intelligence unit. Co-founder and Chief AI Officer Gil Elbaz is a veteran AI researcher who previously reported to the CTO of Nvidia and served in an IDF AI research unit.
The pedigree is in-domain and verifiable through press. What is not yet public is a prior exit or a sustained research publication record under the Onyx name, so the credibility comes from background rather than a track record the company has built together.
The team has scaled quickly. Onyx reached about 70 employees across Israel, the US, and Canada in roughly 18 months of building, per SecurityWeek and the launch announcement, which shows the founders can recruit at the pace the funding implies. [s3, s4, s2]
Onyx sells a product that inspects enterprise AI traffic, so the handling of that data is the trust question a buyer raises first. The launch materials describe runtime monitoring of prompts and agent actions and enforcement of governance policies, which means proprietary AI activity flows through the control plane.
Onyx publishes a SafeBase trust center at trust.onyx.security that lists SOC 2 Type 2, ISO/IEC 27001:2022, GDPR, and HIPAA compliance, with SOC 2, ISO 27001, HIPAA, and penetration-test reports available for download after a security review request. The compliance frameworks are stated on the page, while the underlying reports are access-gated rather than open, so a procurement team can confirm the attestations exist but still works through Onyx to read them. The page does not state the SOC 2 reporting period or the trust-service criteria its report covers, so those scope details remain a sales-cycle question. A responsible-disclosure policy is also listed, answering the vulnerability-reporting question a security review raises. [s9, s4, s2]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Pillar Security | competes with | Covers AI agent discovery, testing, and runtime guarding for the same enterprise security buyer, the closest same-asset independent. | |
| Lasso Security | competes with | Runs discovery and runtime enforcement over enterprise AI and agent traffic, overlapping Onyx's monitoring and control motion. | |
| Capsule Security | competes with | Discovers enterprise AI agents and blocks unsafe actions at runtime, the same supervise-and-intervene approach Onyx sells. | |
| Bold Security | competes with | Surfaced the same week with the same $40 million, contesting the AI security budget Onyx targets though weighted toward the endpoint layer. | N/AThese companies operate in different domains, so the scores reflect readiness in different markets. |
| Palo Alto Networks | adjacent | Ships AI runtime security inside a broad platform and could bundle agent governance into deals enterprises already sign. | N/AWe scored these companies at different scopes, so the totals measure different things. |
| Okta | adjacent | Identity provider that could extend agent identity and access governance into the control-plane role Onyx is selling. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
Add analyzed competitors to compare them side by side with Onyx Security.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
pivot urgently
Onyx is durable where supervising AI agents in real time is hard engineering, and soft wherever it relies on claims a buyer cannot yet verify or on software a platform vendor could absorb. The part a funded rival could not quickly reproduce is a supervisory layer driven by proprietary AI models that intercepts an agent's action before it executes. What Onyx does not yet hold is anything that locks a buyer in. It sells software a platform vendor could bundle, holds no certification forcing a buyer to choose it, names no proprietary dataset that grows with use, and so soon after its March 2026 launch has no install base that makes leaving costly. Its durability today is the problem's difficulty and the founders' Unit 8200 and Nvidia pedigree, not a moat the market has tested.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Customers buy a runtime enforcement layer and a Guardian Agent, software that discovers, monitors, and controls agents, rather than a managed judgment-and-accountability outcome a buyer cannot reproduce in-house. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Placing the Guardian Agent in the live path of agent actions and wiring Onyx into browser, CNAPP, SASE, and EDR feeds embeds it in a security team's workflow, real friction once in place, but as a new entity it has not built the system-of-record install base that puts established peers at 3. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | Onyx publishes SOC 2 Type 2, ISO/IEC 27001:2022, GDPR, and HIPAA attestations in its trust center, table-stakes assurance that eases procurement, but no regulation mandates buying this product and holding the same certifications every rival can earn locks no buyer in. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Supervising every agent with proprietary AI models that understand AI reasoning and intercept non-deterministic actions in real time is genuinely hard engineering, the same order of complexity the AI-security cohort scores at 3, and the founders' Unit 8200 and Nvidia-research backgrounds reflect that depth. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 | The buyer is the large-enterprise security, governance, and AI team, and the customer evidence is two vendor-displayed CISO testimonials, Eli Edelkind shown beside the CAVA logo and Kyle Weckman without a named employer, plus unnamed Fortune 500 use, testimonials that still live on Onyx's own page rather than independently confirmed accounts. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Onyx is a control plane that sits above the models, agents, and clouds an enterprise runs rather than infrastructure the AI traffic is forced through. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | SecurityWeek reports Onyx uses proprietary AI models, a claim-only signal with no sourced dataset behind it, and the public record shows no accumulating cross-customer telemetry flywheel, so there is no data corpus. |
Onyx aims the control plane at the enterprise teams standing up AI agents across departments. The homepage names the buyer as security, governance, and AI teams that need to protect, optimize, and measure AI agent adoption across the enterprise. That is a defined buyer with a budget owner rather than a generic enterprise audience, and the launch framing ties the buyer to a dated trigger, the spread of autonomous agents into production in 2026.
The segment skews to the large, regulated enterprise. CEO Maxim Bar Kogan says the control plane is already used by Fortune 500 companies to govern their agents, and SecurityWeek reports Onyx is working with multiple large companies, which points the motion at negotiated enterprise deals rather than self-serve buyers. A Cyberstarts partner frames the same target, calling the team well-positioned to win AI security for large enterprises.
The segmentation risk is breadth inside that enterprise. Onyx pitches observability, security, governance, and orchestration to security, governance, and AI teams at once, three buyers with different priorities, so the open question is which of those teams opens its budget. A company this soon after its March 2026 stealth exit still has to prove which department owns the budget line it is selling into.
The Onyx platform centers on a supervisory agent rather than a single inspection point. The launch announcement describes a single, unified enforcement layer that continuously discovers every AI asset across the enterprise, agents, models, applications that embed AI, and MCP-connected tool ecosystems, and turns governance policies into enforceable controls that operate at runtime. SecurityWeek adds that the system discovers AI agents across cloud, endpoints, code, and SaaS deployments and then monitors and corrects their actions.
The Guardian Agent is the capability Onyx leans on hardest. The company positions it at the heart of the platform, overseeing all other AI agents and able to block an unsafe action, require human approval, narrow an agent's scope, or redirect it toward a safer path before anything reaches a downstream system. SecurityWeek reports that Onyx uses supervisory agents and proprietary AI models to understand AI reasoning and react in real time, which is the differentiator a discover-and-monitor rival would have to reproduce.
Public technical depth stops at that description. So soon after the March 2026 stealth exit there are no architecture docs, no open-source components, and no third-party evaluation of the Guardian Agent or the proprietary models in the pages reviewed, so a buyer assessing how the supervision actually works would start from sales conversations rather than testable artifacts. The proprietary-models claim raises the replication cost, but no benchmark lets a buyer confirm it.
Onyx runs a direct enterprise motion anchored by founder visibility and investor credibility. The CEO wrote the launch announcement and routes prospects to a single call to action, a demo request, which fits a company still proving a repeatable sales motion rather than one running a built-out quota-carrying team. Founder-fronted selling at this stage is the expected signal, not a weakness.
The traction Onyx shows is now partly named. The launch says Fortune 500 companies already use the control plane and SecurityWeek reports work with multiple large companies, stronger than design-partner language, though those accounts stay unnamed in independent reporting. The homepage closes part of that gap with two named CISO testimonials, one from Eli Edelkind shown beside the CAVA logo and a second from Kyle Weckman, whose employer the page does not name, named-CISO testimonials rather than anonymous quotes. They are still vendor-displayed, so the proof a rival cannot also claim is the same buyer speaking on the record outside Onyx's own page.
Investor conviction carries the rest of the early signal. Conviction, the firm Sarah Guo founded, led the 35 million dollar Series A and Cyberstarts backed the seed, and a Cyberstarts partner went on the record calling the team well-positioned to lead AI security for large enterprises. That is capital betting on the motion, and a named enterprise customer speaking publicly is the signal that would convert launch attention into proof of deployment.
Onyx publishes no prices, which itself signals the deal it wants. The homepage and launch materials route every prospect to a demo request rather than a pricing page, the negotiated-enterprise default for a vendor selling into Fortune 500 buyers. Hidden pricing fits the large, custom deal the segmentation targets, and it is the norm for the AI agent security cohort at this stage.
The product framing hints at what Onyx believes the buyer pays for. The homepage describes opt-in governance coverage and policy controls defined in natural language, and the company sells the ability to protect, optimize, and measure AI agent adoption, which points the value toward the scale of an enterprise's agent fleet rather than a seat count. Charging by the governed agent or the enterprise would tie the price to the exposure a security team is trying to contain.
What a buyer cannot do yet is compare. With no published price and no disclosed packaging in the pages reviewed, an enterprise evaluating Onyx against the several funded rivals in the same slot has no public anchor, so the pricing conversation happens entirely inside the sales cycle. For a first priced round, that opacity is conventional but leaves the unit of value unstated in public.
Onyx delivers control as a runtime layer woven through the enterprise's existing tooling rather than a standalone scanner. The AI Defense Matrix Catalog's Onyx entry describes integration with browser, AI platforms, CNAPP, SASE, and EDR discovery sources so nothing is invisible, which means Onyx rides the discovery feeds an enterprise already runs to find agents across its environment. The enforcement runs in real time, protecting AI systems and the data they touch without disrupting workflows, per the same entry.
The runtime posture is the operational heart of the product. The Guardian Agent acts before an action reaches a downstream system, blocking, pausing for human approval, or redirecting it, which places Onyx in the live path of agent decisions rather than in a periodic audit. That continuous interception is what turns governance policy into enforcement, and it is also what raises the bar on the platform's own reliability and latency.
The operational depth a buyer can verify stays shallow in public. The pages reviewed describe discovery, monitoring, and enforcement but expose no public documentation, status page, or service-level commitment, so a security review would have to probe latency, failure modes, and how Onyx handles the agent traffic it inspects through direct conversation. For a product sitting in the live path of enterprise AI, those operational answers are the ones procurement will press hardest.
Onyx sells a product whose job is to make an enterprise's AI auditable, so its own data handling is the trust question a buyer raises at the outset. The platform inspects every prompt, response, and agent action to enforce policy, which means proprietary AI activity flows through the control plane. The homepage positions governance, enforcement, and auditability as the value, and a displayed CISO testimonial frames Onyx as what lets a security team manage AI risk across copilots and other tools.
Regulatory alignment is the company's trust narrative. Onyx says it helps buyers satisfy AI security standards and regulatory requirements with opt-in coverage and policy controls defined in natural language. That positions the product as the layer that produces the compliance evidence legal and risk teams require, which is a credible pitch to a regulated enterprise.
The attestations a procurement team wants are published. Onyx runs a SafeBase trust center at trust.onyx.security that lists SOC 2 Type 2, ISO/IEC 27001:2022, GDPR, and HIPAA compliance and offers SOC 2, ISO 27001, HIPAA, and penetration-test reports for download after a security review request. The frameworks are stated openly while the reports sit behind an access gate, so a buyer can confirm the attestations exist but reads the evidence through Onyx, and the page lists a responsible-disclosure policy for vulnerability reporting. What the page does not state is the SOC 2 reporting period or the trust-service criteria the report covers, so the depth and scope of the audit remain a sales-cycle question rather than a settled fact for a company this soon after its March 2026 stealth exit.
Onyx is building a control plane that sits above the AI an enterprise already runs rather than a feature inside one vendor's stack. The launch announcement positions a single, unified enforcement layer across agents, models, applications, and MCP-connected tools, and the catalog describes integration with browser, AI platforms, CNAPP, SASE, and EDR sources. That neutral, cross-vendor position is the pitch a platform vendor's bundled control cannot fully match.
The ecosystem exposure runs in two directions. Onyx depends on the discovery feeds of the security platforms it integrates with, which is leverage those platforms hold, and the same control-plane role is one the platform vendors and identity providers could ship themselves into deals an enterprise already signs. Gili Raanan calls AI agents the biggest enterprise platform shift since cloud on the Onyx homepage, which is the prize that also draws the incumbents toward the same control point.
The structural advantage Onyx claims is the supervisory layer itself. A Guardian Agent that oversees every other agent using proprietary models is a harder position to bundle than a discovery scan, and no marketplace listing or named partner program a copycat could match by writing software appears in the public record yet. The bet is that owning the runtime control point compounds faster than a platform vendor can extend its suite into it.
Onyx pairs an offensive-security founder with an AI-research founder. CTech reports that CEO Maxim Bar Kogan served in Unit 8200 of the IDF, and co-founder Gil Elbaz is a veteran AI researcher who previously reported to the CTO of Nvidia and served in an IDF AI research unit. That split maps directly onto the product, security supervision built on proprietary AI models.
The pedigree is in-domain and verifiable through press, which matches the same-asset peers in this category. What is not yet public is a prior startup exit or a sustained research publication record under the Onyx name, so the credibility comes from background rather than a track record the two founders have built together as operators.
The team has scaled at the pace the funding implies. Onyx reached about 70 employees across Israel, the US, and Canada in roughly 18 months of quiet building, per SecurityWeek and the launch announcement, which shows the founders can recruit quickly. Converting that headcount into named, referenceable enterprise deployments is the execution test the next year sets.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Onyx Security homepage | official | 2026-06-10 |
| f2 | CTech on the Onyx Security $35M Series A (March 12, 2026) | press | 2026-06-14 |
| f3 | SecurityWeek on the Onyx Security launch | press | 2026-06-14 |
| f4 | SecurityWeek on the Onyx Security $113M Series B (July 2026) | press | 2026-07-30 |
| f5 | Ctech on the Onyx Security $113M Series B (July 30, 2026) | press | 2026-07-30 |
| f6 | AI Defense Matrix Catalog entry | other | 2026-06-10 |
| f7 | AI Defense Matrix Catalog mapping | other | 2026-08-21 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Onyx Security homepage | official | 2026-06-18 |
| s2 | Onyx Security launch announcement by CEO Maxim Bar Kogan “The Onyx Guardian Agent is at the heart of the platform. It oversees all other AI agents in the customer's environment, and can block unsafe actions, require human approval, narrow an agent's scope, or redirect it toward a safer path, all before anything reaches a downstream system.” | official | 2026-06-18 |
| s3 | CTech on the Onyx Security $35M Series A (March 12, 2026) “has raised $35 million in a Series A funding round led by Conviction, an AI-native venture capital firm founded in 2022 by Sarah Guo, a former General Partner at Greylock. The company's total funding now stands at $40 million, including a $5 million Seed round from Cyberstarts in 2024” | press | 2026-06-14 |
| s4 | SecurityWeek on the Onyx Security launch and product “The solution was designed to continuously discover AI agents across cloud, endpoints, code, and SaaS deployments, to monitor them, and to approve or correct their actions, enforcing the enterprise's security and governance policies.” | press | 2026-06-14 |
| s5 | SiliconANGLE on Bold Security and Onyx Security each raising $40M “Bold Security Ltd. and Onyx Security Inc. each revealed $40 million in funding as organizations deploy AI across their infrastructure and, in doing so, create new attack surfaces and operational risks that traditional security tools struggle to address.” | press | 2026-06-14 |
| s6 | AI Defense Matrix Catalog entry for Onyx “Control plane that discovers sanctioned and shadow AI agents, monitors prompts and agent actions in real time, and enforces security policies across enterprise AI use.” | other | 2026-06-14 |
| s7 | CTech on the Onyx Security founders' backgrounds “Bar Kogan is a cyber security leader and experienced technology executive who served in Unit 8200 of the IDF. Elbaz is a veteran AI researcher, previously reporting to the CTO of Nvidia, and a former member of one of the IDF's AI research units.” | press | 2026-06-14 |
| s8 | Onyx Security launch announcement on stealth exit and traction “After a year and a half of quietly building, today we're stepping out of stealth with $40 million in funding from Conviction Partners and Cyberstarts, a team of 70, and an AI control plane that's already being used by Fortune 500 companies to govern their AI agents.” | official | 2026-06-18 |
| s9 | Onyx Security Trust Center (SafeBase) listing SOC 2 Type 2 and ISO/IEC 27001:2022 “Welcome to Onyx's Trust Center. ... Compliance, ISO/IEC 27001:2022, SOC 2 Type 2, GDPR, HIPAA. Reports, SOC 2 Report, ISO 27001: 2022, HIPAA Report, Pentest Report.” | official | 2026-06-16 |
| s10 | Onyx Security homepage CISO testimonial from Eli Edelkind, shown beside the CAVA logo “Onyx provides the visibility, governance, enforcement, and auditability we need to effectively manage AI risk across copilots and other tools, while still empowering teams to move fast.” | official | 2026-06-18 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Onyx Security homepage (The Secure AI Control Plane) “Onyx is the secure control plane for AI agents and models. With the right structure, you're free to build without limits.” | official | 2026-06-18 |
| s2 | Onyx Security launch announcement by CEO Maxim Bar Kogan “The Onyx Guardian Agent is at the heart of the platform. It oversees all other AI agents in the customer's environment, and can block unsafe actions, require human approval, narrow an agent's scope, or redirect it toward a safer path, all before anything reaches a downstream system.” | official | 2026-06-18 |
| s3 | CTech on the Onyx Security $35M Series A (March 12, 2026) “has raised $35 million in a Series A funding round led by Conviction, an AI-native venture capital firm founded in 2022 by Sarah Guo, a former General Partner at Greylock. The company's total funding now stands at $40 million, including a $5 million Seed round from Cyberstarts in 2024.” | press | 2026-06-14 |
| s4 | SecurityWeek on the Onyx Security launch and product “Onyx uses supervisory agents and proprietary AI models to understand AI reasoning and react in real time, providing organizations with visibility, control, optimization capabilities, and means to measure AI agent adoption.” | press | 2026-06-14 |
| s5 | SiliconANGLE on Bold Security and Onyx Security each raising $40M “Bold Security Ltd. and Onyx Security Inc. each revealed $40 million in funding as organizations deploy AI across their infrastructure and, in doing so, create new attack surfaces and operational risks that traditional security tools struggle to address.” | press | 2026-06-14 |
| s6 | AI Defense Matrix Catalog Onyx entry (coverage rows) “Integrates with browser, AI platforms, CNAPP, SASE, and EDR discovery sources so nothing is invisible. Protect your AI systems and the data they touch from prompt injection, jailbreaks, data exfiltration, and adversarial manipulation in real time, without disrupting workflows.” | other | 2026-06-14 |
| s7 | Onyx Security launch announcement on what the company built and ships “Onyx provides a single, unified enforcement layer that continuously discovers every AI asset across the enterprise, agents, models, AI-powered applications, MCP-connected tool ecosystems, and turns governance policies into enforceable controls that operate at runtime.” | official | 2026-06-18 |
| s8 | Onyx Security launch announcement on the stealth exit and traction “After a year and a half of quietly building, today we're stepping out of stealth with $40 million in funding from Conviction Partners and Cyberstarts, a team of 70, and an AI control plane that's already being used by Fortune 500 companies to govern their AI agents.” | official | 2026-06-18 |
| s9 | SecurityWeek on Onyx discovery coverage and base of operations “The solution was designed to continuously discover AI agents across cloud, endpoints, code, and SaaS deployments, to monitor them, and to approve or correct their actions. Based in Tel Aviv and New York, Onyx has over 70 employees in Israel, the US, and Canada.” | press | 2026-06-14 |
| s10 | CTech on the Onyx Security founders' backgrounds “Founded in 2024 by Maxim Bar Kogan and Gil Elbaz. Bar Kogan is a cyber security leader and experienced technology executive who served in Unit 8200 of the IDF.” | press | 2026-06-14 |
| s12 | CTech on the Onyx co-founder Gil Elbaz's AI research background “Elbaz is a veteran AI researcher, previously reporting to the CTO of Nvidia, and a former member of one of the IDF's AI research units.” | press | 2026-06-14 |
| s11 | Onyx Security homepage product pillars and customer testimonial “Satisfy AI security standards and regulatory requirements with opt-in coverage and define specific policy controls in natural language.” | official | 2026-06-18 |
| s13 | Onyx Security homepage CISO testimonial from Eli Edelkind, shown beside the CAVA logo “Onyx gives us end-to-end oversight over AI, across SaaS, cloud, and endpoints, with a secure control plane that can consistently enforce our policies. This enables us to double down on AI adoption across the company.” | official | 2026-07-10 |
| s14 | Onyx Security Trust Center (SafeBase) listing SOC 2 Type 2 and ISO/IEC 27001:2022 “Welcome to Onyx's Trust Center. ... Compliance, ISO/IEC 27001:2022, SOC 2 Type 2, GDPR, HIPAA. Reports, SOC 2 Report, ISO 27001: 2022, HIPAA Report, Pentest Report.” | official | 2026-06-16 |
| s15 | Onyx Security homepage second named CISO testimonial from Kyle Weckman “Onyx provides the visibility, governance, enforcement, and auditability we need to effectively manage AI risk across copilots and other tools, while still empowering teams to move fast.” | official | 2026-07-10 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.