Pluto Security

Security for AI Governance Risk ComplianceApplication Security also known as PLUTO SECURITY LTD

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2025
Last updated 2026-07-17

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Pluto Security, a Tel Aviv startup incorporated in 2025, targets a growing gap. Employees outside engineering now build apps and agents with AI tools and ship them to production unreviewed. Pluto connects agentlessly to find the AI coding assistants, no-code builders, and agents in use, scores their risk, and enforces guardrails so security teams can allow the building. Founders come from Unit 8200, Microsoft, and Palo Alto Networks, and 160 security leaders voted it Best Emerging Technology in 2026. That award and the AWS, CrowdStrike, and NVIDIA accelerators are its strongest public signals, since it names no customers and discloses no funding. It fits a team losing track of what staff build with AI, and is weakest if a larger platform adds the same discovery, a risk not yet evidenced.

Sourced Details

Description Pluto Security sells an AI workspace security platform that agentlessly discovers the AI builders, coding assistants, and agents employees use, scores their risk, and enforces guardrails, so security teams can permit AI-driven building instead of blocking it. [f1]
Founded 2025 [f2]
HQ Tel Aviv, Israel [f2]

Products

Product What it does
Pluto AI Workspace Security Platform Agentlessly discovers the AI builders, coding assistants, agents, and MCP tools employees use, scores their risk, and enforces real-time guardrails on AI building activity.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

The Pluto AI Workspace Security Platform agentlessly discovers the AI builders, agents, MCP servers, plugins, and IDEs employees use, scores their risk, and enforces real-time guardrails on AI building activity. These capabilities are mapped to the AI Defense Matrix. [f3]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Emerging 21 /40 Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Pluto names a clear buyer, the enterprise CISO, and a specific pain, non-developers shipping AI-built apps to production without controls, and an independent Forbes Israel interview repeats the framing, but the pain stays vendor-asserted, with no independent quantification of its scale in the reviewed sources. [s5, s6, s4]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 The award writeup and Pluto's own pages describe agentless discovery of AI builders, risk scoring, real-time guardrails, and a Claude Enterprise connector concretely, but the Anthropic integration is in private preview and no independent evaluation or documentation portal corroborates performance. [s4, s9, s1]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 The 2024 to 2025 spread of AI coding assistants and no-code builders that let non-developers ship apps is a credible enabler, and 160 CISOs and security executives voting Pluto Best Emerging Technology signals practitioner interest, but buyer-side signals stay indirect rather than multiple and independently verified. [s5, s3]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 CEO Shahar Bahat's Unit 8200 and Microsoft product background is senior and verifiable, the founding team draws on Unit 8200, Microsoft, and Palo Alto Networks, and the research team publishes threat findings, but no prior exit or sustained recognition lifts it past competent and credible. [s5, s2, s8]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 2/5 Pluto names no paying customers publicly, so its evidence is a Best-Emerging-Technology award voted by 160 security leaders plus places in the AWS, CrowdStrike, and NVIDIA accelerator programs, indirect signals that hold the score at 2 rather than lift it to the peer cluster with named traction. [s3, s2]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 2/5 Pluto discloses no funding amount and no revenue, and only accelerator backing is evidenced, so the raise and any output per dollar are unverifiable. [s2]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 Pluto fits an emerging AI-workspace-security category that a Best Emerging Technology award recognizes, but the category is nascent and contested, overlapping data-security posture, SaaS security, and AI governance, so buyers still need vendor explanation to place it. [s3, s4]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 2/5 Agentless AI-tool discovery, risk scoring, and guardrails are a plausible feature release for secure-access incumbents such as Netskope, Zscaler, and Palo Alto Networks and for Microsoft, an analyst inference no cited source documents, and no structural moat is evidenced this early. [s4, s1]
Business Risks Netskope, Zscaler, or Palo Alto Networks could add agentless AI-builder discovery and guardrails to their secure-access platforms, collapsing the case for a standalone tool…
  • Netskope, Zscaler, or Palo Alto Networks could add agentless AI-builder discovery and guardrails to their secure-access platforms, collapsing the case for a standalone tool.
  • Microsoft could extend its workspace governance tools to the AI coding assistants and no-code builders Pluto discovers.
  • Pluto names no paying customers publicly, leaving a CISO-voted award and accelerator backing as its only public evidence of traction.
  • Pluto discloses no funding amount, so a longer enterprise sales cycle could outrun a seed-stage balance sheet before named references accumulate.
  • The AI workspace security category overlaps data-security posture, SaaS security, and AI governance, so buyers may fold the need into an existing budget line rather than buy a new tool.
  • The Claude Enterprise integration is in private preview, so part of the platform's AI-assistant coverage is not yet generally available.
Problem & Market Pluto Security frames the problem as employees who are not engineers now building and shipping software with AI tools…

Pluto Security frames the problem as employees who are not engineers now building and shipping software with AI tools. Sales, marketing, HR, and finance staff use no-code builders, AI coding assistants, and agents to create apps and automations, often without security review. In a Forbes Israel interview, co-founder Shahar Bahat described AI-generated apps that reach production systems and sensitive data while secrets management, access control, and logging get skipped.

The buyer is the enterprise CISO caught between blocking AI adoption and losing control of it. Pluto positions itself as a third path that lets people build while security keeps oversight. The urgency is real to that buyer, since 160 CISOs and security executives voted Pluto the winner of an emerging-technology award at a 2026 industry summit, though the pain stays qualitative rather than independently quantified. [s6, s5, s3]

Product Capabilities Pluto connects agentlessly to a customer's existing security and infrastructure systems to discover which AI builders are in use…

Pluto connects agentlessly to a customer's existing security and infrastructure systems to discover which AI builders are in use. The award writeup lists Claude Code, Cursor, v0, Lovable, Cowork, and n8n among them, together with the plugins, skills, IDEs, and MCP servers around them. Pluto then scores the risk of what it finds and enforces real-time guardrails on AI building activity.

The platform also reaches specific AI assistants through direct integrations. Pluto built a connector to Claude Enterprise using Anthropic's Compliance API so security teams can monitor that activity inside the workflows they already use. That integration is in private preview, so it is early rather than proven at scale.

The public detail is concrete but vendor-described. Pluto's product and blog pages explain the discovery, scoring, and guardrail functions, and its research team publishes findings such as a live malicious extension campaign on Open VSX. No independent technical evaluation or public documentation portal corroborates how well the platform performs. [s4, s9, s8]

Competitive Positioning Pluto competes in an emerging cluster of AI-usage and shadow-AI governance startups…

Pluto competes in an emerging cluster of AI-usage and shadow-AI governance startups. Aurascape, WitnessAI, and Harmonic Security sell overlapping discovery, risk scoring, and control over how employees use and build with AI. Knostic works an adjacent slice, limiting what enterprise AI assistants reveal to each user.

Platform incumbents pose the structural threat, an analyst inference no cited source documents. Netskope, Zscaler, Palo Alto Networks, or Microsoft could add agentless AI-tool discovery and guardrails to their established platforms, contesting the control point Pluto wants.

Pluto's edge is being early and precise about what employees build with AI, plus the CISO recognition it has earned. That focus is a head start rather than a barrier a funded rival could not clear. Pluto holds the lead only while it stays ahead of incumbent release cycles. [s4, s3, s1]

Go-to-Market & Traction Pluto's public proof is recognition rather than revenue…

Pluto's public proof is recognition rather than revenue. It won the inaugural Best Emerging Technology award at the 2026 Innovate Cybersecurity Summit, first place in a vote by 160 CISOs and security executives across a field of roughly ten startups. Pluto names no paying customers publicly.

Accelerator backing is the main indirect signal of momentum. Pluto belongs to the AWS, CrowdStrike, and NVIDIA accelerator programs, which vet and support early companies. It discloses no funding amount, so its scale and runway stay unverified. [s3, s2]

Team & Credibility Co-founder and CEO Shahar Bahat gives Pluto a verifiable security background…

Co-founder and CEO Shahar Bahat gives Pluto a verifiable security background. She is a former Unit 8200 operator and was a product leader at Microsoft, where she saw teams told to move faster with generative AI. That experience is senior and in-domain, though the public record shows no prior exit or sustained recognition.

Pluto says its founders come from Unit 8200, Microsoft, and Palo Alto Networks. Yotam Perkal authors Pluto threat research such as the Open VSX extension campaign, a signal of active security research. No named exit or independent recognition lifts the team above competent and credible. [s5, s2, s8]

Trust Readiness Pluto displays SOC 2 Type 2 and ISO 27001 badges on its site…

Pluto displays SOC 2 Type 2 and ISO 27001 badges on its site. The homepage footer carries an image badge labeled for both, and a trust center resolves at trust.pluto.security. Such self-displayed badges are procurement table stakes for an enterprise security buyer rather than a differentiator.

A careful buyer will still ask for more than the badges. The trust center hosts compliance materials behind a portal, so a buyer confirms the report scope through it. Because the platform reads AI activity across the workspace, it concentrates sensitive data, and buyers will press on retention and handling terms. [s10, s11, s1]

Competitors Aurascape, WitnessAI, Harmonic Security, Knostic, Zenity, Netskope, Zscaler, Palo Alto Networks, Microsoft…
Company Relationship Note Compare
Aurascape competes with Secures how enterprises use and build AI, discovering AI apps and agents and enforcing policy, overlapping Pluto's discovery and guardrail functions. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
WitnessAI competes with Discovers AI apps, agents, and MCP servers and enforces use policy at the network level, an overlapping AI-usage governance play.
Harmonic Security competes with Gives security teams visibility and control over how employees and AI agents use AI, overlapping Pluto's governance pitch.
Knostic adjacent Limits what enterprise AI assistants reveal to each user, an adjacent need-to-know slice of the AI governance problem.
Zenity competes with Secures enterprise AI agents and low-code and no-code automations where they are built and run, overlapping the AI-building surface Pluto covers.
Netskope competes with Secure-access incumbent that could bundle AI-tool discovery and controls into its proxy platform.
Zscaler competes with Secure web gateway incumbent that could add AI-builder visibility and guardrails to its gateway platform.
Palo Alto Networks competes with Platform incumbent selling AI security controls, able to absorb the discovery layer as a feature. N/AWe scored these companies at different scopes, so the totals measure different things.
Microsoft competes with Workspace platform vendor that could extend its posture and governance tools to the AI builders Pluto discovers. N/AMicrosoft is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product.

Add analyzed competitors to compare them side by side with Pluto Security.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 13 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

Pluto's strongest asset is its buyer. It sells to enterprise CISOs who feel an urgent need to govern what staff build with AI, and 160 security leaders voted it Best Emerging Technology at a 2026 industry summit. The software itself is reproducible. Agentless discovery, risk scoring, and guardrails are functions a funded rival could rebuild, a competitive read the sources leave unevidenced, and SOC 2 Type 2 and ISO 27001 are table stakes. Keeping pace with fast-changing AI builders and the tools agents plug into takes real effort, so breadth of coverage is a head start rather than a durable lead. Pluto could build an asset from a cross-customer view of which tools prove risky, though none is evidenced yet. For now, its edge is being early to a real problem rather than a durable moat.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Pluto delivers a software platform, with no published pricing model and no managed-service or judgment layer that accepts accountability.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 The agentless platform overlays a customer's existing systems and builds some re-integration cost once its policies and guardrails run, but no residency lock, deep workflow embedding, or network effect is evidenced this early.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 Pluto self-displays SOC 2 Type 2 and ISO 27001 badges that ease procurement without blocking a substitute, and no cited source identifies a regulation mandating this control class.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Discovering AI builders, agents, and MCP servers agentlessly across heterogeneous tooling and enforcing real-time guardrails is hard applied engineering.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 The buyer is the enterprise CISO or security executive, a senior owner of security budget, and the 160-vote summit award evidences practitioner interest in the problem. Purchasing urgency, budget, and tier availability stay undisclosed.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 Pluto sits as a governance and guardrail layer over AI building activity, enforcing controls rather than only observing, but it is not infrastructure other software depends on to run.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 Pluto's discovery and risk scoring are reproducible and no named non-public dataset is cited. A cross-customer view of which AI tools prove risky is a plausible but unevidenced latent asset.
Strategic Market Segmentation Pluto sells to the security or compliance leader at an enterprise where staff build with AI…

Pluto sells to the security or compliance leader at an enterprise where staff build with AI. The pain is that non-engineers ship apps, agents, and automations to production using AI tools, outside the visibility and controls security relies on. Co-founder Shahar Bahat told Forbes Israel that these AI-generated apps reach production systems and sensitive data while secrets management, access control, and logging get skipped.

The segment is the enterprise whose CISO already feels the exposure. Pluto frames its pitch as letting people build while security keeps oversight, aimed at the buyer who cannot simply block AI adoption. The 160 CISOs and security executives behind its emerging-technology award are that audience, though Pluto discloses no named customer segments.

Product Capabilities & AI Advantages Pluto's claimed advantage is discovering AI building without agents…

Pluto's claimed advantage is discovering AI building without agents. It connects to a customer's existing security and infrastructure systems to find which AI builders are in use, from Claude Code and Cursor to Lovable and n8n, along with the plugins, skills, IDEs, and MCP servers around them. It then scores the risk of what it finds and enforces guardrails on the building activity.

Pluto also reaches named AI assistants through direct integrations. It built a connector to Claude Enterprise through Anthropic's Compliance API, so security teams can monitor that use inside their existing workflows. The connector is in private preview, so it is a direction rather than a capability shipped at scale.

The depth on public pages is real but unverified from outside. Pluto documents the discovery, scoring, and guardrail functions and publishes threat research such as the Open VSX campaign its team tracked. No independent benchmark or documentation portal is public, so the performance claims stay unconfirmed.

Sales Engagement & Go-to-Market Pluto's go-to-market proof is recognition ahead of disclosed revenue…

Pluto's go-to-market proof is recognition ahead of disclosed revenue. It won an emerging-technology award at the 2026 Innovate Cybersecurity Summit, first in a vote by 160 CISOs and security executives across a field of roughly ten startups, on its first appearance at the event. Pluto names no paying customers publicly.

Pluto leans on ecosystem backing to reach buyers. It is part of the AWS, CrowdStrike, and NVIDIA accelerator programs, an ecosystem-credibility signal, though the reviewed sources do not document what introductions or pipeline those programs produce. It also publishes educational content on AI workspace and supply-chain security that reaches the audience it sells to.

Funding and scale stay undisclosed. Pluto publishes no round size and no revenue, so its runway and efficiency cannot be assessed from the reviewed sources. The award and accelerator ties are the strongest public signals of buyer interest.

Pricing Model Pluto publishes no pricing in the public record…

Pluto publishes no pricing in the public record. There is no rate card and no stated unit of charge, which points toward sales-led contracting, though an undisclosed self-serve path cannot be ruled out. It also withholds the budget-anchoring signal some peers publish.

What Pluto charges by is not stated. The platform spans discovery, risk scoring, and guardrails across many AI tools, so seats, monitored tools, or covered environments are all plausible meters. The public pages leave the pricing model open.

Product Delivery & Operations Pluto describes an agentless platform that connects to a customer's existing security and infrastructure systems to see AI building activity…

Pluto describes an agentless platform that connects to a customer's existing security and infrastructure systems to see AI building activity. The reviewed sources do not document its hosting architecture or an endpoint-free footprint. Pluto pitches the agentless connection as lowering adoption cost, though the sources publish no implementation-effort evidence.

The operational surface is broad and fast-moving. Pluto tracks AI builders, coding assistants, agents, and their plugins and MCP servers, a set that changes as new tools appear. Keeping discovery current across that surface is continuous work rather than a one-time integration.

Watching AI building across the workspace hands the platform sensitive AI-activity context. Its Claude Enterprise integration ingests attachments and datasets connected to projects, so data-retention, uptime, and support terms matter to a careful buyer, who will look to Pluto's trust center for them.

Earning Customers' Trust Pluto shows SOC 2 Type 2 and ISO 27001 badges on its own site…

Pluto shows SOC 2 Type 2 and ISO 27001 badges on its own site. The homepage footer carries an image badge labeled for both, and a trust center resolves at trust.pluto.security. For an enterprise buyer weighing a tool that reads AI activity, those self-displayed badges are expected procurement assurance rather than a differentiator.

The trust center hosts compliance materials behind a portal at trust.pluto.security. A buyer will still confirm the report scope, the data-retention terms, and how the platform handles the AI activity it reads.

Platform Strategy & Ecosystem Positioning Pluto positions itself as a control point for AI building across the workspace rather than a single-tool scanner…

Pluto positions itself as a control point for AI building across the workspace rather than a single-tool scanner. It discovers the AI builders, agents, and MCP servers in use, scores their risk, and enforces guardrails, so its pitch is coverage of the whole building surface rather than one tool.

The position is a sharp read of where risk is moving. As non-developers build and ship with AI, the workspace becomes the place to govern it, and Pluto aims to sit across that activity agentlessly. It extends that reach one connector at a time, as with Claude Enterprise.

The reviewed sources document no direct competitor, so the competitive read is an analyst inference rather than a sourced finding: the workspace control point Pluto wants is one a larger platform could also claim, and AI building can move to surfaces a central view does not cover.

Team & Execution Capability CEO Shahar Bahat gives Pluto a verifiable security record…

CEO Shahar Bahat gives Pluto a verifiable security record. She is a former Unit 8200 operator and was a product leader at Microsoft, where she watched teams pushed to move faster with generative AI. That background is senior and in-domain, but the public record shows no prior exit or sustained recognition.

Pluto says its founders come from Unit 8200, Microsoft, and Palo Alto Networks. Yotam Perkal authors Pluto threat research such as the malicious Open VSX campaign it tracked, which signals active security research. That research is a general team signal rather than proof of depth in the company's own product category.

Diligence should probe technical depth beyond the CEO. Pluto publicly names its CEO and its research author, but the public record does not detail a broader engineering bench. A buyer betting on execution will want to see who builds the platform.

Sources

Company Detail Sources (3)
Id Source Tier Accessed
f1 Pluto Security homepage official 2026-07-04
f2 KYC Israel (commercial registry aggregator): PLUTO SECURITY LTD (reg. 517212452) other 2026-07-04
f3 AI Defense Matrix Catalog: Pluto Security official 2026-07-04
Profile Analysis Sources (11)
Id Source Tier Accessed
s1 Pluto Security homepage, product framing and AI-builder integrations
“Pluto is the AI Workspace Security Platform that lets you oversee and protect all AI building ventures in your organization”
official 2026-07-04
s2 Pluto Security about page, founding-team provenance and accelerators
“Pluto Security was founded by a world-class team from Unit 8200, Microsoft, and Palo Alto Networks, builders who have led security at global scale. Backed by leading security and cloud ecosystems, and part of top accelerators including AWS, CrowdStrike and NVIDIA”
official 2026-07-04
s3 Innovate Cybersecurity: Pluto Security wins Best Emerging Technology, voted by 160 CISOs and security executives
“Going up against 10 fellow startups, Pluto Security earned first place in a vote cast entirely by 160 CISOs and security executives in attendance.”
press 2026-07-04
s4 Innovate Cybersecurity: Pluto agentless discovery of AI builders and their ecosystem
“Pluto connects agentlessly to existing security and infrastructure systems to uncover which AI builders are in use, including Claude Code, Cursor, v0, Lovable, Cowork, and n8n, along with their ecosystem, such as MCPs, Skills, Plugins, IDEs, and extensions.”
press 2026-07-04
s5 Forbes Israel (Michael Matias): interview with co-founder Shahar Bahat
“Shahar, a former Unit 8200 operator and product leader at both startups and Microsoft, co-founded Pluto Security to address what might be the fastest-growing attack surface in the enterprise: software built by non-developers.”
press 2026-07-04
s6 Forbes Israel: Bahat on AI-generated apps reaching production without controls
“We're seeing AI-generated apps accessing production systems, integrating with sensitive data, and exposed to customers. Secrets management, access control, logging, it's all being skipped.”
press 2026-07-04
s7 KYC Israel (commercial registry aggregator): PLUTO SECURITY LTD (reg. 517212452), incorporated 2025, Tel Aviv
“Incorporation Date: 31/08/2025”
other 2026-07-04
s8 Pluto research (Yotam Perkal): Count Dooku malicious Open VSX campaign
“Over the last few days, Pluto Security has been tracking an active malicious extension campaign on Open VSX.”
official 2026-07-04
s9 Pluto blog: Claude Enterprise integration via Anthropic Compliance API, in private preview
“The Pluto integration with Anthropic's Compliance API is available in Private Preview for organizations using both Pluto and Claude Enterprise.”
official 2026-07-04
s10 Pluto homepage footer SOC 2 Type 2 / ISO 27001 badge (probe, 2026-07-04)
“The homepage footer displays an image badge (sec-badges.webp) with alt text SOC2 TYPE 2 / ISO27001.”
official 2026-07-04
s11 Pluto trust center probe: trust.pluto.security live (2026-07-04)
“A trust center resolves at trust.pluto.security (HTTP 200), a Trust Vault portal.”
official 2026-07-04
Deep-Dive Sources (11)
Id Source Tier Accessed
s1 Pluto Security homepage, product framing and AI-builder integrations
“Pluto is the AI Workspace Security Platform that lets you oversee and protect all AI building ventures in your organization”
official 2026-07-04
s2 Pluto Security about page, founding-team provenance and accelerators
“Pluto Security was founded by a world-class team from Unit 8200, Microsoft, and Palo Alto Networks, builders who have led security at global scale. Backed by leading security and cloud ecosystems, and part of top accelerators including AWS, CrowdStrike and NVIDIA”
official 2026-07-04
s3 Innovate Cybersecurity: Pluto Security wins the emerging-technology award, voted by 160 CISOs and security executives
“Going up against 10 fellow startups, Pluto Security earned first place in a vote cast entirely by 160 CISOs and security executives in attendance.”
press 2026-07-04
s4 Innovate Cybersecurity: Pluto agentless discovery of AI builders and their ecosystem
“Pluto connects agentlessly to existing security and infrastructure systems to uncover which AI builders are in use, including Claude Code, Cursor, v0, Lovable, Cowork, and n8n, along with their ecosystem, such as MCPs, Skills, Plugins, IDEs, and extensions.”
press 2026-07-04
s5 Forbes Israel (Michael Matias): interview with co-founder Shahar Bahat
“Shahar, a former Unit 8200 operator and product leader at both startups and Microsoft, co-founded Pluto Security to address what might be the fastest-growing attack surface in the enterprise: software built by non-developers.”
press 2026-07-04
s6 Forbes Israel: Bahat on AI-generated apps reaching production without controls
“We're seeing AI-generated apps accessing production systems, integrating with sensitive data, and exposed to customers. Secrets management, access control, logging, it's all being skipped.”
press 2026-07-04
s7 KYC Israel (commercial registry aggregator): PLUTO SECURITY LTD (reg. 517212452), incorporated 2025, Tel Aviv
“Incorporation Date: 31/08/2025”
other 2026-07-04
s8 Pluto research (Yotam Perkal): Count Dooku malicious Open VSX campaign
“Over the last few days, Pluto Security has been tracking an active malicious extension campaign on Open VSX.”
official 2026-07-04
s9 Pluto blog: Claude Enterprise integration via Anthropic Compliance API, in private preview
“The Pluto integration with Anthropic's Compliance API is available in Private Preview for organizations using both Pluto and Claude Enterprise.”
official 2026-07-04
s10 Pluto homepage footer SOC 2 Type 2 / ISO 27001 badge (probe, 2026-07-04)
“The homepage footer displays an image badge (sec-badges.webp) with alt text SOC2 TYPE 2 / ISO27001.”
official 2026-07-04
s11 Pluto trust center probe: trust.pluto.security live (2026-07-04)
“A trust center resolves at trust.pluto.security (HTTP 200), a Trust Vault portal.”
official 2026-07-04

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.