Pillar Security

Security for AI

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software.
Founded 2023
Funding $9M
Last updated 2026-07-10

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Pillar Security makes a platform that finds the AI agents an enterprise runs, tests them the way an attacker would, and blocks hostile prompts and data leaks in production. Its standout public proof is three named customers: the Times of Israel reports Similarweb, Eleos Health, and AvidXchange among them, though nothing public documents the depth of any deployment. The founders back the pitch with published exploits, a Cursor coding-assistant flaw cataloged as CVE-2026-22708 and an attack on a Google AI coding tool that Google confirmed and fixed. Rivals can study each finding once published. The AI vendors an enterprise already pays could bundle similar controls, so the named accounts and early reputation are a head start rather than a durable advantage.

Sourced Details

Description Pillar is a security platform for enterprise AI applications and agents. It inventories the agents, models, and MCP servers running in an environment, tests them for attacks such as prompt injection, and applies runtime guardrails. [f1]
Founded 2023 [f2]
HQ Miami, Florida, USA (with operations in Tel Aviv, Israel) [f2]
Funding $9M total [f3]
Latest funding Seed (2025), led by Shield Capital [f4]
Deployment SaaS [f5]
Compliance SOC 2 Type 2 [f5]

Products

Product What it does
Pillar AI security platform for the agentic workforce that inventories agents, models, and MCP servers, red-teams them, and runs adaptive runtime guardrails to block prompt attacks and data egress.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

Pillar is an AI security platform for the agentic workforce that inventories agents, models, and MCP servers, red-teams them, and runs adaptive runtime guardrails to block prompt attacks and data egress. It is mapped to the AI Defense Matrix. [f6]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 26 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 The buyer and problem are clear, the agents and MCP servers teams cannot fully see, and SiliconANGLE, Palo Alto Unit 42, and a Deloitte survey of 1,200 CISOs reported by the Times of Israel corroborate the concern, but that survey measures AI worry broadly rather than quantifying the unseen-agent problem, so the pain stays vendor-framed at the default. [s2, s7, s14, s8]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 The platform page carries concrete module detail across discovery, red teaming, taint analysis, and adaptive guardrails, but no third-party technical evaluation, docs portal, or open-source code validates the product itself, so the team's research about other companies' tools lifts team_credibility rather than the product, holding this at the present-but-unproven default. [s2, s1, s10]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 Enterprise adoption of AI agents and MCP tooling created the attack surface, and Palo Alto Unit 42 documented indirect prompt injection against agents in the wild while a Deloitte survey reported by the Times of Israel shows broad CISO concern, but these are indirect demand signals rather than the multiple fresh buyer-side signals a 4 requires. The enabler is enterprise agent adoption documented across 2025 and 2026 by Unit 42's report and the Cursor and Antigravity disclosures. [s14, s8, s9, s10]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 4/5 Co-founder Dor Sarig built security products at Perimeter81 and Cymulate, co-founder Ziv Karliner came from IBM Trusteer and Aqua Security, and the team has a sustained in-domain disclosure record across Cursor, GitHub Copilot, and Google Antigravity, with the Rules File Backdoor independently covered by The Hacker News and a separate Cursor Auto-Run flaw cataloged by NIST as CVE-2026-22708. That sustained in-domain pattern is a track record rather than a single covered event. [s3, s9, s11, s10]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 4/5 The Times of Israel independently names Similarweb, Eleos Health, and AvidXchange as customers beyond vendor copy, so multiple named references confirmed by an independent press source meet the bar for a 4. Depth holds it off a 5, with no public deployment metrics, contract sizes, or case studies. Shield Capital backing adds an indirect signal of real interest. [s8, s5, s6, s1]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 The $9 million seed is proportional to an early motion with visible shipping across the four modules and a plan to triple headcount from ten to thirty, but no revenue or margin is disclosed, so efficiency stays unconfirmed at the funded-startup default rather than an outsized raise that would score lower. [s5, s6, s8]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 A Gartner Market Guide for Guardian Agents (2026) lists Pillar as a Representative Vendor, and independent press frames the product within the enterprise AI security stack, so analysts can place it in a clearly-emerging category. A Market Guide representative listing signals a category that is recognizable but still forming rather than established. [s15, s7, s6]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 Agent discovery, red teaming, and runtime guardrails are absorbable by platform vendors and model providers building the same controls, and the team's research brand raises replication cost without forming a structural moat, since the 50 million interactions Pillar cites have undisclosed ownership and composition rather than being a named cross-customer data asset. [s2, s9, s8]
Business Risks Platform vendors such as Palo Alto Networks and Microsoft could fold agent discovery, red teaming, and runtime guardrails into suites enterprises already buy, undercutting a standalone Pillar purchase before it proves deployment depth at its named customers…
  • Platform vendors such as Palo Alto Networks and Microsoft could fold agent discovery, red teaming, and runtime guardrails into suites enterprises already buy, undercutting a standalone Pillar purchase before it proves deployment depth at its named customers.
  • Model providers could ship native security for the agents built on their own platforms, removing the third-party budget line Pillar depends on.
  • Named customers exist but no deployment depth is published, so buyers who require evidenced production references or case studies could stall enterprise deals for a company still in its first funding round.
  • Pillar has disclosed only a single $9 million seed, and a capital-heavy fight for enterprise runtime deployments could force a raise on weak terms or a sale before the motion proves out.
  • The differentiation rests heavily on the team's offensive research output, so a slowdown in that disclosure stream or a key departure could erode the main reason a buyer chooses Pillar over a bundled competitor.
  • A customer can cancel the runtime subscription and reabsorb the guardrail work into existing controls, which keeps switching cost low while the product is an overlay rather than embedded infrastructure.
Problem & Market Pillar Security treats the AI agents an enterprise runs as assets it cannot fully see or control, and sells a platform to inventory, test, and guard them…

Pillar Security treats the AI agents an enterprise runs as assets it cannot fully see or control, and sells a platform to inventory, test, and guard them. The platform page frames the problem as agents, models, and MCP servers spreading across code, cloud, SaaS, and endpoints faster than security teams can track, including shadow AI nobody approved. The buyer is the enterprise security team standing up agents inside core business processes.

Independent evidence corroborates the gap beyond vendor marketing. SiliconANGLE describes Pillar securing AI applications across the full lifecycle from development to production, and Palo Alto Unit 42 documented web-based indirect prompt injection against AI agents observed in the wild, which establishes agent compromise as a demonstrated risk rather than a projection.

The buyer-side concern is partly quantified. The Times of Israel cites a Deloitte survey of 1,200 chief information security officers in which 77 percent expressed concern about AI threats, a signal that the worry Pillar names is felt at the level it sells to, though that figure measures AI concern broadly rather than the unseen-agent problem specifically. [s2, s7, s14, s8]

Product Capabilities The Pillar platform spans four modules rather than a single control point…

The Pillar platform spans four modules rather than a single control point. The product page describes AI discovery and posture that inventories every agent, model, and MCP server, red teaming that tests multi-turn attacks and tool hijacking through real agent configurations, runtime guardrails that block prompt attacks and data egress, and governance that flags agents operating outside policy. The vendor positions adaptive guardrails that adjust per agent.

The runtime layer is where the product claims to act in production. Pillar describes taint analysis that traces PII and secrets from source to destination and blocks unauthorized egress in real time, plus behavior monitoring that logs tool invocations and decisions for audit. These are the controls a security buyer evaluating a runtime product would test against its own agents, though no third-party technical evaluation of the platform itself appears in the public record.

The team's research demonstrates depth in the same domain the product addresses. Pillar disclosed the Rules File Backdoor, in which attackers hide malicious instructions in the configuration files that Cursor and GitHub Copilot read so the assistants generate attacker-chosen code. A separate Cursor flaw that Pillar reported, cataloged by NIST as CVE-2026-22708 and fixed in Cursor 2.3, let prompt injection poison shell environment variables so that commands ran without appearing in the Auto-Run allowlist. In a third finding, Pillar chained prompt injection into remote code execution in Google's Antigravity, and Google accepted the report through its AI VRP and marked it fixed. That work validates the researchers' offensive craft more than the product a customer buys. [s2, s10, s11, s9]

Competitive Positioning Pillar competes in agentic AI security against both independents and the platforms building the same controls…

Pillar competes in agentic AI security against both independents and the platforms building the same controls. Independent rivals sell into the same discovery, testing, and runtime stack for the enterprise AI buyer, and platform vendors could fold AI runtime security into the broader suites they already sell, a prospective bundling risk rather than a documented current offering in the cited record.

Pillar's visible differentiator is the offensive depth of its founders, shown through research. The team's attacks on the AI coding tools developers use every day give it a public profile larger than a company on a single seed round would otherwise hold. A bundled competitor cannot quickly reproduce that research brand, but a published finding is free to copy once it is out.

The structural risk is who owns the buyer. Model providers could secure the agents built on their own platforms, and platform vendors can fold agent security into deals an enterprise already signs. Pillar's independence is both its neutrality pitch and its exposure, because the buyer relationship sits with the vendors it works beside. [s2, s7, s9]

Go-to-Market & Traction Research is Pillar's loudest go-to-market engine…

Research is Pillar's loudest go-to-market engine. The team's Rules File Backdoor finding drew coverage in The Hacker News, and the Antigravity finding is published vendor research, which together build inbound awareness and position the team as researchers worth following. That visibility plausibly feeds inbound enterprise interest, though this is an inference, and no public source documents how Pillar's deals actually originate.

Named customers now back that attention. The Times of Israel reports Similarweb, Eleos Health, and AvidXchange among Pillar's customers, the named-account proof that sits in independent press rather than vendor copy alone. Shield Capital led the seed and Golden Ventures and Ground Up Ventures joined, which is investor conviction layered on the buyer proof.

The depth behind the names is what the public record still lacks. Pillar routes prospects to a demo request, and no deployment metric, contract size, or customer case study is published, so the references read as logos rather than documented production use. Disclosure of how broadly these customers run Pillar would be the signal that the attention has converted into scale. [s9, s8, s1, s5]

Team & Credibility The founders pair offensive-security craft with product-building experience…

The founders pair offensive-security craft with product-building experience. Co-founder Dor Sarig developed security products for Fortune 500 companies and worked with Israel's Ministry of Defense, Perimeter81, and Cymulate. Co-founder Ziv Karliner worked on financial cybercrime, cloud, and software supply-chain security at IBM Trusteer and Aqua Security after serving in the Israeli intelligence forces. The company site lists conflicting current executive titles for the two, so the settled public fact is their co-founder roles.

The research record is the team's strongest public signal. The Hacker News covered the Rules File Backdoor, in which hidden instructions in configuration files steer Cursor and GitHub Copilot into generating attacker-chosen code, and NIST cataloged a separate Cursor Auto-Run allowlist bypass that Pillar reported as CVE-2026-22708. A later finding chained prompt injection into remote code execution in Google's Antigravity. This is a sustained publication pattern in the company's own product domain rather than a single covered event.

The public record documents headcount only as of the seed coverage. In April 2025 the Times of Israel reported Pillar raising $9 million to triple its workforce from 10 to 30 employees by the end of that year, and no fetched source gives a later number. Research bylines on the company blog extend beyond the two founders, with the Antigravity disclosure credited to researcher Dan Lisichkin. The verifiable strength remains the founders' domain track record and the disclosure stream the team sustains. [s3, s9, s10, s11, s8, s4]

Trust Readiness Pillar publishes a Scytale-powered Trust Center that lists SOC 2 Type II and ISO 27001:2022 entries…

Pillar publishes a Scytale-powered Trust Center that lists SOC 2 Type II and ISO 27001:2022 entries. The portal names a Pillar Security SOC2 Type II 2025 report, a Pillar Security ISO27001 2026 report, and an external penetration testing report, each behind a request-access step rather than open download.

Runtime data handling backs the attestations. The product describes taint analysis and detection of PII and secrets that keep sensitive data from leaving the environment, which addresses the exposure question a buyer raises when a security product inspects proprietary AI traffic. For Fortune 500 and financial-services buyers, the two named attestations are the artifacts procurement requests first, though the reports stay gated. [s13, s2]

Competitors Lasso Security, Noma Security, Lakera, HiddenLayer, Palo Alto Networks, OpenAI…
Company Relationship Note Compare
Lasso Security competes with Covers the same discovery, red teaming, and runtime enforcement stack for the enterprise AI buyer, the closest same-asset independent.
Noma Security competes with Discovers AI assets, red-teams them, and runs runtime guardrails for the same enterprise CISO, overlapping Pillar's full motion. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Lakera competes with Offers automated AI red teaming and runtime guardrails that contest Pillar's testing and runtime layers.
HiddenLayer adjacent AI security platform weighted toward model attack and detection, adjacent to Pillar's agent-centric discovery and runtime focus.
Palo Alto Networks adjacent Ships AI runtime security inside a broad platform and could bundle agent protection into deals enterprises already sign. N/AWe scored these companies at different scopes, so the totals measure different things.
OpenAI adjacent Model provider that could ship native security for agents built on its platform, removing the third-party budget line. N/AWe scored these companies at different scopes, so the totals measure different things.

Add analyzed competitors to compare them side by side with Pillar Security.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Exposed 12 /21 Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software. pivot urgently

Pillar Security's firmest hold on a customer is the work of removing it. Runtime guardrails, taint analysis, and discovery wired across a customer's AI agents take real re-integration and re-tuning to replace, a head start rather than a lasting lead. A funded rival could reproduce the rest. The NIST-cataloged Cursor disclosure, CVE-2026-22708, proves the team builds at depth, but a published finding is free to copy. Pillar cites insights from over 50 million AI application interactions, with the data's ownership and composition undisclosed. SOC 2 Type II and ISO 27001 ease procurement without mandating the product, and the agents run with or without it. Pillar is most defensible inside accounts already deep in deployment, weakest where platform and model vendors bundle the same coverage.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 The reviewed pages describe a software platform, discovery, red teaming, and runtime guardrails, with no managed-service model in which Pillar accepts accountability for the safety outcome, so customer operation is the inferred delivery mode, the software-product level.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Runtime guardrails that block unauthorized egress in real time, taint analysis, and discovery integrated across an enterprise's agents create real re-integration and re-tuning cost to replace. No data residency, network effect, or accumulated dataset appears in fetched sources to push the friction past re-integration toward a 3.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 Pillar publishes SOC 2 Type II and ISO 27001:2022 through an inspectable Scytale-powered trust portal with named gated reports, but these are table-stakes assurance that eases procurement without blocking substitutes, no regulation mandates this product class, and a determined rival could clear the same bars.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Real-time monitoring of agent traffic, taint analysis that blocks data egress, and red teaming through live agent configurations sit in machine-learning and real-time territory, and the NIST-cataloged Cursor disclosure CVE-2026-22708 and the Antigravity RCE prove the team builds at that depth.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3 Three named enterprise customers appear, Similarweb, Eleos Health, and AvidXchange, confirmed by the Times of Israel beyond vendor copy, but the fetched record does not characterize them as a procurement-gated regulated roster.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 Pillar is a control layer beside the workload that inspects and guards a customer's agent traffic, deployable and swappable, rather than infrastructure other software depends on to function, since the agents and applications run without it.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 The threat intelligence Pillar cites from over 50 million AI application interactions has undisclosed ownership and composition rather than being a named non-public attack corpus, and the disclosures that distinguish the team are published rather than banked, so any detection advantage is reproducible.
Strategic Market Segmentation Pillar Security sells to the enterprise security team standing up AI agents inside core business processes…

Pillar Security sells to the enterprise security team standing up AI agents inside core business processes. The platform frames the buyer as defenders who cannot fully see the agents, models, and MCP servers spreading across code, cloud, SaaS, and endpoints, including the shadow AI nobody approved. SiliconANGLE describes the company securing AI applications across the full lifecycle from development to production.

The segment is the large enterprise reached through a sales-led motion rather than self-serve. The named customers point at sizable software buyers, Similarweb, Eleos Health, and AvidXchange, and the founder background centers on products built for Fortune 500 companies. No free tier or public price appears in fetched pages, which fits a negotiated enterprise sale.

The widening of the segment comes from covering the whole AI lifecycle on one platform rather than from reaching new buyers. By spanning discovery, testing, runtime guarding, and governance, Pillar addresses any enterprise adopting agents regardless of which models it runs, which broadens reach but places it against both AI-security independents and the platform vendors now shipping their own AI controls.

Product Capabilities & AI Advantages Pillar runs four modules across the AI lifecycle rather than a single control point…

Pillar runs four modules across the AI lifecycle rather than a single control point. The platform page describes AI discovery and posture that inventories every agent, model, and MCP server, red teaming that tests multi-turn attacks and tool hijacking through real agent configurations, runtime guardrails that block prompt attacks and data egress, and governance that flags agents operating outside policy. The vendor positions adaptive guardrails that adjust per agent so controls match what each agent is meant to do.

The runtime layer is where the product claims to act in production. Pillar describes taint analysis that traces PII and secrets from source to destination and blocks unauthorized egress in real time, plus behavior monitoring that logs tool invocations and decisions for audit. These are the controls a buyer evaluating a runtime product tests against its own agents, though no third-party technical evaluation of the platform itself surfaces in fetched pages.

The team's research demonstrates depth in the same domain the product addresses. Pillar disclosed the Rules File Backdoor, in which attackers hide malicious instructions in the configuration files that Cursor and GitHub Copilot read so the assistants generate attacker-chosen code. A separate Cursor flaw that Pillar reported, cataloged by NIST as CVE-2026-22708 and fixed in Cursor 2.3, let prompt injection poison shell environment variables so that commands ran without appearing in the Auto-Run allowlist.

Pillar carried the same craft to Google's own tooling. It chained prompt injection into remote code execution in Google's Antigravity, and Google accepted the report through its AI VRP and marked it fixed. That adversarial work, covered independently, is the verifiable proof that the team finds the agent vulnerabilities the platform is built to catch, though it validates the researchers more than the product a customer buys.

Sales Engagement & Go-to-Market Research is Pillar's loudest go-to-market engine…

Research is Pillar's loudest go-to-market engine. The Rules File Backdoor finding drew coverage in The Hacker News, with the company's CTO quoted directly, and the Antigravity disclosure ran through Google's AI VRP, both of which generate inbound awareness and position the founders as researchers worth following. That visibility plausibly feeds inbound enterprise interest, though this is an inference, and no fetched source documents how Pillar's deals actually originate.

Named customers now back that attention. The Times of Israel independently reports Similarweb, Eleos Health, and AvidXchange among Pillar's customers, the named-account proof that sits in press rather than vendor copy. Shield Capital led the seed and Golden Ventures and Ground Up Ventures joined, which is investor conviction layered on the buyer proof.

The depth behind the names is what the public record still lacks. Pillar routes prospects to a demo request, and no deployment metric, contract size, or customer case study appears in fetched sources, so the references read as logos rather than documented production use. Disclosure of how broadly these customers run Pillar would be the signal that the attention has converted into scale.

Pricing Model Pillar publishes no price in fetched sources, so the charged unit and list price stay private…

Pillar publishes no price in fetched sources, so the charged unit and list price stay private. The homepage and platform pages route every prospect to a demo request, the posture of a vendor selling large negotiated enterprise deals rather than a self-serve product. The absence withholds the budget-anchoring signal some peers publish.

One plausible value meter is the volume of AI traffic the product inspects, though that is inference rather than a stated unit. Because the runtime guardrails block threats in real time and log every prompt, response, and tool call, cost would plausibly track interaction volume or the number of agents and applications covered, but no fetched page names the meter.

The hidden-price posture signals the intended buying path. Confirming whether Pillar charges by seats, agents, telemetry volume, or a flat platform fee, and whether consumption is capped, would require a sales conversation, which is the route the demo-request funnel is built to force.

Product Delivery & Operations The reviewed pages present Pillar as a software platform rather than an analyst-staffed managed service…

The reviewed pages present Pillar as a software platform rather than an analyst-staffed managed service. The product covers discovery, red teaming, runtime guardrails, and governance, and no managed-service operating model or outcome accountability is described in the cited pages, so the buyer appears to configure the policies and run the controls. The runtime guardrails block threats in production AI traffic in real time and log every prompt, response, and tool call for audit.

The runtime layer is the operationally heavy part of the offer. Pillar describes taint analysis and real-time blocking of unauthorized data egress, plus behavior monitoring across agentic workflows, so the operational job is enforcement that follows a moving attack surface rather than a static rule set. Published uptime figures or support SLAs do not surface in fetched pages.

The real-time enforcement role raises the dependency question a careful buyer examines. A guardrail that blocks unauthorized egress as agents run becomes an operational dependency for the AI it protects, and the fetched pages describe the capability without documenting how Pillar deploys into a customer's environment or an operational track record a buyer could weigh against it.

Earning Customers' Trust Pillar publishes a Scytale-powered Trust Center that names both SOC 2 Type II and ISO 27001:2022…

Pillar publishes a Scytale-powered Trust Center that names both SOC 2 Type II and ISO 27001:2022. The portal lists a Pillar Security SOC2 Type II 2025 report, a Pillar Security ISO27001 2026 report, and an external penetration testing report, each behind a request-access step rather than open download, alongside control summaries across product, access, data, and endpoint security.

Runtime data handling backs the attestations. The product describes taint analysis and detection of PII and secrets that keep sensitive data from leaving the environment, which addresses the exposure question a buyer raises when a security product inspects proprietary AI traffic. For Fortune 500 and financial-services buyers, the two named attestations are the artifacts procurement reviews commonly request.

The attestations are enterprise-grade but table-stakes rather than a moat. The certifications ease procurement without blocking a substitute, no regulation mandates this product class, and a determined rival could clear the same bars, so the trust posture removes friction from a sale rather than defending the position.

Platform Strategy & Ecosystem Positioning Pillar positions itself as the security control point an enterprise places over the AI it adopts…

Pillar positions itself as the security control point an enterprise places over the AI it adopts. It inventories agents, models, and MCP servers, tests them, guards them at runtime, and governs them from one platform, so the platform claim rests on covering the whole AI lifecycle rather than a single point feature. Adaptive guardrails per agent are the runtime expression of that breadth.

Outward, the company reaches buyers as model-agnostic coverage that works regardless of which AI tools an enterprise runs. By spanning the coding assistants developers use, internal agents, and the MCP servers that connect them, Pillar pitches neutral coverage across the AI estate rather than a feature of one model vendor.

Inward, that neutrality is also the exposure. The platform runs beside the source tools and consoles it inspects and depends on the frontier models it does not own, and the structural risk is who owns the buyer, because platform vendors can bundle the same controls into deals an enterprise already signs and model providers can secure the agents built on their own platforms.

Team & Execution Capability Pillar's two founders pair offensive-security craft with product-building experience…

Pillar's two founders pair offensive-security craft with product-building experience. Dor Sarig and Ziv Karliner anchor the team, Sarig with offensive-security work for Fortune 500 companies alongside Israel's Ministry of Defense, Perimeter81, and Cymulate, and Karliner with financial cybercrime, cloud, and supply-chain security at IBM Trusteer and Aqua Security after the Israeli intelligence forces. The Israeli Companies Registry records the entity as incorporated in 2023.

The research record is the team's strongest public signal. The Hacker News covered the Rules File Backdoor, in which hidden instructions in configuration files steer Cursor and GitHub Copilot into generating attacker-chosen code, and NIST cataloged a separate Cursor Auto-Run allowlist bypass that Pillar reported as CVE-2026-22708. A later finding chained prompt injection into remote code execution in Google's Antigravity. This is a sustained publication pattern in the company's own product domain rather than a single covered event.

The public record documents headcount only as of the seed coverage. In April 2025 the Times of Israel reported Pillar raising $9 million to triple its workforce from 10 to 30 employees by the end of that year, and no fetched source gives a later number. Research bylines on the company blog extend beyond the two founders, with the Antigravity disclosure credited to researcher Dan Lisichkin. The verifiable strength remains the founders' domain track record and the disclosure stream the team sustains.

Sources

Company Detail Sources (6)
Id Source Tier Accessed
f1 Pillar Security: One Platform to Secure your AI Stack official 2026-07-09
f2 SiliconANGLE on Pillar Security funding press 2026-06-13
f3 SecurityWeek on Pillar Security $9M seed round press 2026-06-13
f4 Calcalist on Pillar Security seed round investors press 2026-06-13
f5 AI Defense Matrix Catalog entry other 2026-06-13
f6 AI Defense Matrix Catalog mapping other 2026-06-23
Profile Analysis Sources (15)
Id Source Tier Accessed
s1 Pillar Security homepage: Securing the Agentic Workforce
“Pillar is recognized by industry-leading organizations and trusted by Fortune 500 companies and AI Vertical startups to protect and accelerate mission-critical AI initiatives.”
official 2026-06-29
s2 Pillar Security platform overview
“Full inventory of agents, models, MCP servers, and tools, including shadow AI. Taint analysis traces PII and secrets from source to destination, blocks unauthorized egress in real time. Adaptive guardrails adjust per agent.”
official 2026-07-10
s3 Pillar Security about page with founder profiles
“Dor's expertise spans offensive security, product development and research, honed through his work with Israel's Ministry of Defense and leading security companies like Perimeter81 and Cymulate.”
official 2026-06-29
s4 Pillar Security research and news blog index
“By Dan Lisichkin”
official 2026-07-10
s5 SecurityWeek on Pillar Security $9M seed round
“Pillar Security, a startup building security controls for enterprise AI deployments, has deposited $9 million in seed funding from Shield Capital.”
press 2026-06-29
s6 Calcalist on Pillar Security $9M seed round and category
“Pillar Security, an Israeli startup focused on end-to-end AI application protection, has emerged from stealth with $9 million in Seed funding to tackle what it sees as a widening security gap in the enterprise AI stack.”
press 2026-06-29
s7 SiliconANGLE on Pillar Security funding and lifecycle scope
“Founded in 2023, Pillar Security specializes in securing AI applications and infrastructure through the entire AI lifecycle, from development to production.”
press 2026-06-29
s8 Times of Israel on Pillar Security launch, customers, and hiring plan
“Among Pillar's customers are tech companies Similarweb, Eleos Health and AvidXchange. The Tel Aviv-based startup said it raised $9 million in seed funding to expand its research & development operations and triple its workforce from 10 to 30 employees by the end of the year.”
press 2026-07-10
s9 The Hacker News on Pillar's Rules File Backdoor attack
“This technique enables hackers to silently compromise AI-generated code by injecting hidden malicious instructions into seemingly innocent configuration files used by Cursor and GitHub Copilot, Pillar security's Co-Founder and CTO Ziv Karliner said in a technical report.”
press 2026-07-10
s10 Pillar Security research: prompt injection RCE in Google Antigravity (AI VRP)
“As we documented in our earlier research on Cursor (CVE-2026-22708), the pattern repeats across agentic IDEs: tools designed for constrained operations become attack vectors when their inputs are not strictly validated.”
official 2026-07-10
s11 NVD record for CVE-2026-22708 (Cursor Auto-Run allowlist bypass disclosed by Pillar)
“This allows an attacker via indirect or direct prompt injection to poison the shell environment by setting, modifying, or removing environment variables that influence trusted commands. This vulnerability is fixed in 2.3.”
research 2026-07-10
s12 Israeli Companies Registry record for PILLAR SECURITY LTD (no. 516871324)
“"שם באנגלית":"PILLAR SECURITY LTD","סטטוס חברה":"פעילה","תאריך התאגדות":"14/09/2023","שם עיר":"תל אביב - יפו"”
regulatory 2026-06-29
s13 Pillar Security Trust Center (SOC 2 Type II, ISO 27001:2022, powered by Scytale)
“Reports and Documents: SOC 2 Type II, ISO 27001:2022, Penetration Testing conducted. Pillar External Penetration Testing Report, Pillar Security SOC2 Type II 2025, Pillar Security ISO27001 2026. Powered by Scytale.ai”
official 2026-06-29
s14 Palo Alto Unit 42 on web-based indirect prompt injection against AI agents
“Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild”
research 2026-06-29
s15 Pillar Security homepage analyst-recognition section (vendor-displayed)
“Gartner named Pillar Security a Representative Vendor in their 2026 Market Guide for Guardian Agents.”
official 2026-06-29
Deep-Dive Sources (15)
Id Source Tier Accessed
s1 Pillar Security homepage: Securing the Agentic Workforce
“Pillar is recognized by industry-leading organizations and trusted by Fortune 500 companies and AI Vertical startups to protect and accelerate mission-critical AI initiatives.”
official 2026-06-29
s2 Pillar Security platform: discovery, red teaming, runtime guardrails, governance
“Full inventory of agents, models, MCP servers, and tools, including shadow AI. Taint analysis traces PII and secrets from source to destination, blocks unauthorized egress in real time. Adaptive guardrails adjust per agent.”
official 2026-07-10
s3 Pillar Security about page (Sarig at Perimeter81 and Cymulate, Karliner at IBM Trusteer and Aqua Security)
“Dor's expertise spans offensive security, product development and research, honed through his work with Israel's Ministry of Defense and leading security companies like Perimeter81 and Cymulate.”
official 2026-06-29
s4 Pillar Security research and news blog index
“By Dan Lisichkin”
official 2026-07-10
s5 SecurityWeek on Pillar Security $9M seed round
“Pillar Security, a startup building security controls for enterprise AI deployments, has deposited $9 million in seed funding from Shield Capital.”
press 2026-06-29
s6 Calcalist on Pillar Security seed round and category
“Pillar Security, an Israeli startup focused on end-to-end AI application protection, has emerged from stealth with $9 million in Seed funding to tackle what it sees as a widening security gap in the enterprise AI stack.”
press 2026-06-29
s7 SiliconANGLE on Pillar Security funding and lifecycle scope
“Founded in 2023, Pillar Security specializes in securing AI applications and infrastructure through the entire AI lifecycle, from development to production.”
press 2026-06-29
s8 Times of Israel on Pillar Security launch, customers, and hiring plan
“Among Pillar's customers are tech companies Similarweb, Eleos Health and AvidXchange. The Tel Aviv-based startup said it raised $9 million in seed funding to expand its research & development operations and triple its workforce from 10 to 30 employees by the end of the year.”
press 2026-07-10
s9 The Hacker News on Pillar's Rules File Backdoor attack
“This technique enables hackers to silently compromise AI-generated code by injecting hidden malicious instructions into seemingly innocent configuration files used by Cursor and GitHub Copilot, Pillar security's Co-Founder and CTO Ziv Karliner said in a technical report.”
press 2026-07-10
s10 Pillar Security research: prompt injection RCE in Google Antigravity (AI VRP)
“As we documented in our earlier research on Cursor (CVE-2026-22708), the pattern repeats across agentic IDEs: tools designed for constrained operations become attack vectors when their inputs are not strictly validated.”
official 2026-07-10
s11 NVD record for CVE-2026-22708 (Cursor Auto-Run allowlist bypass disclosed by Pillar)
“This allows an attacker via indirect or direct prompt injection to poison the shell environment by setting, modifying, or removing environment variables that influence trusted commands. This vulnerability is fixed in 2.3.”
research 2026-07-10
s12 Israeli Companies Registry record for PILLAR SECURITY LTD (no. 516871324)
“"שם באנגלית":"PILLAR SECURITY LTD","סטטוס חברה":"פעילה","תאריך התאגדות":"14/09/2023","שם עיר":"תל אביב - יפו"”
regulatory 2026-06-29
s13 Pillar Security Trust Center (SOC 2 Type II, ISO 27001:2022, powered by Scytale)
“Reports and Documents: SOC 2 Type II, ISO 27001:2022, Penetration Testing conducted. Pillar External Penetration Testing Report, Pillar Security SOC2 Type II 2025, Pillar Security ISO27001 2026. Powered by Scytale.ai”
official 2026-06-29
s14 Palo Alto Unit 42 on web-based indirect prompt injection against AI agents
“Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild”
research 2026-06-29
s15 Pillar Security runtime guardrails page: real-time blocking and interaction logging
“Log every prompt, response, and tool call with metadata for audits and threat hunting.”
official 2026-07-10

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.