All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Raven sells enterprise security teams software that runs inside production applications. The software monitors which code libraries and functions execute and blocks exploits before they run, whether or not the vulnerability is public. Founded in 2023, Raven raised $20 million in seed and post-seed funding led by Norwest and Elron Ventures. It reports 11 enterprise customers, primarily large insurance and financial firms, and its named customers are SageSure and Favor Delivery. Co-founders Roi Abitboul and Guy Franco built Javelin Networks, an endpoint protection company Symantec acquired. Four other vendors, Oligo, Miggo, ARMO and Kodem, sell the same library-level detection. That monitoring, its execution fingerprints and three U.S. patents are what a rival has to engineer around.
| Description | Raven runs inside production applications, observing real code execution down to libraries, functions, and call paths to detect and block known and unknown attacks in real time, and adds runtime vulnerability prioritization, developer attribution, and AI-agent visibility. | [f1] |
|---|---|---|
| Founded | 2023 | [f2] |
| HQ | Palo Alto, California, United States | [f3] |
| Funding | $20M total | [f3] |
| Latest funding | Seed and post-seed, $20M | [f4] |
| Product | What it does |
|---|---|
| Runtime Prevention | Stops zero-day exploits and malicious code before execution by comparing live application behavior against learned execution fingerprints, without code changes or signatures. |
| Runtime ADR | Application detection and response that observes execution down to libraries and call paths and traces each runtime attack to the owning code commit, author, and service. |
| Runtime AI-Agents | Discovers approved and shadow AI agents running inside production applications, monitors their behavior, and enforces policy before unsafe actions execute. |
| Runtime SCA | Runtime vulnerability management that uses function-level reachability to deprioritize vulnerabilities that never execute, cutting backlog noise by up to 99%. |
| Runtime Gatekeeper | CI/CD gatekeeper that enforces security policy during artifact and image build across containerized and VM-based environments before code reaches runtime. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Raven Runtime Prevention blocks exploits before execution, Runtime ADR detects application-layer attacks and traces them to the owning code change, and Runtime SCA ranks vulnerabilities by runtime reachability. These capabilities are mapped to the Cyber Defense Matrix. [f1]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Raven names the buyer, security teams that own applications already running in production, and the pain is concrete: the analyst James Berthoty calls the ability to see inside application functions a much clearer gap from existing players than what separates cloud detection vendors from legacy endpoint tools. Independent press repeats that framing rather than testing it, and no reviewed source sizes the exposure. [s15, s9, s11] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 3/5 | The mechanism is documented in detail on Raven's pages and in independent press: execution broken into structured chains and behavioral fingerprints, function-level reachability, and eBPF instrumentation. Two of Raven's three granted U.S. patents describe the library-identification and runtime-exploitation-assessment methods, which evidences the engineering rather than validating the product. The reviewed sources carry no third-party benchmark and no open-source implementation, and the one independent hands-on note covers a six-vendor set rather than testing Raven on its own. [s11, s3, s16, s17, s13] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | The enabler is AI-accelerated exploit generation outrunning the CVE publication cycle, which SiliconANGLE documented in March 2026. Buyer-side demand shows up as one kind of signal only, an analyst category note: Berthoty called application detection and response very new in April 2025 and put the vendor set at a handful. The reviewed sources carry no regulatory driver, budget-line movement, or independent buyer record, so demand is forming rather than proven. [s11, s13, s15] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | Roi Abitboul and Guy Franco built Javelin Networks and sold it to Symantec, an exit Calcalist documents independently, and Raven's own announcement says the three co-founders then led the acquirer's endpoint and cloud protection products. Raven describes the team as veterans of Symantec and elite IDF intelligence units. The prior domain is endpoint security, so the record carries an in-domain cybersecurity exit rather than application-security specialization. [s9, s12, s2] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 | Two customers speak on the record, SageSure and Favor Delivery, each quoted with a named security leader on Raven's own pages. The 11-company production base is Raven's own figure from its March 2026 funding announcement, and no reviewed independent source corroborates adoption scale. Investor backing from Norwest and SentinelOne is applied here as the permitted indirect-signal adjustment, which lifts the row inside this rung rather than to the multiply sourced traction the next one asks for. [s1, s12, s10] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | The 20 million dollars of combined seed and post-seed money is modest for the stage rather than outsized, and the output against it is visible: five product modules shipped and a mechanism SiliconANGLE describes in detail, built in under three years by Raven's own account. The reviewed sources disclose no revenue, margin, or growth figure, so output per dollar stays unconfirmed. [s10, s12, s11, s1] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 | Raven fits application detection and response, and Berthoty places it in a cloud application detection and response grouping with ARMO, Sweet, Upwind, Oligo and Operant. He also calls the category very new, and Raven's own site leans on five comparison pages against web application firewalls, legacy runtime protection, composition analysis, posture management and endpoint detection, so buyers still need the vendor's help placing it. [s13, s1, s3] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Runtime instrumentation, tuned behavioral fingerprints and two granted U.S. patents on the library-identification and exploitation-assessment methods add friction a quarterly feature release would not clear. Berthoty names four other vendors delivering library-level detection from an agent, and he treats visibility inside application functions as a gap the existing players still carry, so absorption is contested rather than blocked and no structural moat appears in the record. [s13, s15, s16, s17] |
Raven sells to security teams that own applications already running in production. Its founding argument is that enterprise security matured to protect endpoints and cloud infrastructure while the application layer stayed comparatively exposed. CEO Roi Abitboul put it plainly when announcing the funding, saying that endpoint tools protect workstations and cloud-posture tools protect infrastructure while nobody was protecting what actually runs the business.
An independent analyst frames the same gap. James Berthoty writes that being able to see inside application functions is a much clearer gap from existing players than what separates cloud detection vendors from legacy endpoint tools. He adds that the older runtime application self-protection space has very few players left because instrumentation proved so difficult.
The timing argument depends on how attacks are now built. SiliconANGLE reports that Raven's technology addresses limitations in traditional vulnerability-based models as AI accelerates exploit development. Raven's own prevention page states that attackers now weaponize vulnerabilities within hours of discovery, often before a CVE, patch, or detection rule exists. [s9, s11, s15, s4]
Raven runs inside the application and watches real execution rather than matching known signatures. SiliconANGLE describes the mechanism as monitoring internal execution paths, breaking them into structured execution chains, and generating behavioral fingerprints of expected behavior, then flagging deviations that may indicate an attack. Raven says this needs no code changes and adds negligible runtime overhead, using eBPF instrumentation at the library and function level.
Five modules are built around that common runtime approach, all as the vendor describes them. Runtime Prevention blocks exploits and malicious code before execution, Runtime ADR detects application-layer attacks and traces each one to the owning code commit and author, and Runtime SCA uses function-level reachability to deprioritize vulnerabilities that never execute. Runtime AI-Agents discovers approved and shadow AI agents inside applications and can alert on or block unsafe agent behavior, and Runtime Gatekeeper enforces policy during artifact and image builds.
Developer attribution is the recurring differentiator. Raven maps a runtime attack back to the exact code change, author, deployment, and service that introduced the risk, which turns a detection into an engineering task rather than a generic alert. [s11, s3, s5, s6, s8]
Raven competes in application detection and response, and its clearest independent placement comes from the analyst James Berthoty. He writes that library-level detection from an agent exists from five providers, naming Oligo, Raven, Miggo, ARMO and Kodem, and separately places Raven with Oligo and Operant on the application-detection side of a cloud application detection and response grouping that ARMO, Sweet and Upwind approach from the cloud-detection side.
That puts Raven inside a small but contested set rather than a category it owns. Its own site argues the case through comparison pages against web application firewalls, legacy runtime application self-protection, software composition analysis, application security posture management, and endpoint detection and response, which signals a category buyers still need help placing.
Large endpoint and cloud platforms are the adjacent threat. Berthoty calls the ability to see inside application functions a much clearer gap from existing players than what separates cloud detection vendors from legacy endpoint tools, and he says that level of visibility sets the vendors who have it apart from legacy providers. On his reading the adjacency is a capability those platforms would have to build. Two of the three U.S. patents granted to Raven cover parts of that route, identifying the libraries an application runs and assessing exploitation at runtime. [s13, s15, s16, s1]
Raven names early reference customers and reports a broader production base. Ed Vazquez, a security engineering manager at SageSure, credits Raven as an invaluable part of its code security program, and Favor Delivery's security leader Pippin Wallace vouches for Raven blocking execution deviations. Raven's March 2026 funding announcement says the platform runs in production with 11 enterprise customers, primarily large insurance and financial organizations, and names none of them. Both testimonials sit on Raven's own pages and no reviewed independent source confirms the wider count.
The purchase motion is enterprise sales with published packaging and unpublished prices. Raven charges per protected server, virtual machine or node across three annual tiers, and every tier routes to a sales conversation rather than a listed price, the pattern of a vendor running negotiated deals.
Investor backing carries part of the credibility argument. SecurityWeek reports that Norwest and Elron Ventures led the two rounds with support from CyberFuture, Dnipro VC, Jibe Ventures, RedSeed, SentinelOne, Unusual Ventures and UpWest. The endpoint vendor SentinelOne joining is an indirect signal of traction beyond the two named references rather than evidence of it. [s1, s12, s10, s7]
The founding team is Raven's strongest independently documented asset. CEO Roi Abitboul and CTO Guy Franco previously built Javelin Networks, which Symantec acquired, and Omer Yair joined them as chief research officer for the new company. Calcalist reports that their experience there shapes Raven's central argument about the exposed application layer.
What that experience covers is worth stating precisely. Javelin Networks was an endpoint protection company, and Raven's own announcement says the founders went on to lead the acquirer's endpoint detection and cloud protection products, so the record documents a cybersecurity second act rather than a prior specialization in application security.
Raven describes the team as serial entrepreneurs and veterans of Symantec and elite IDF intelligence units, and its announcement calls the three co-founders alumni of elite cyber and technological units in the Israel Defense Forces. Chief revenue officer Lori Brigg leads the commercial organization. [s9, s2, s12]
Raven asks customers to run its sensor inside production applications, so operational trust matters as much as paperwork. The design is low-overhead runtime instrumentation that observes execution and intervenes where prevention policies are enabled: Raven states it makes no code changes and no injection, describes the runtime overhead as negligible with no impact on application latency or stability, and says setup takes five minutes.
Public compliance collateral is thin for a company this young. No trust portal, published attestation, or certification badge appears on the probed surfaces, so the operational trust case today comes from the vendor's own performance claims and the founders' track record rather than an inspectable audit. [s14, s5, s4, s2]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Oligo Security | competes with | The analyst James Berthoty names it with Raven among five providers of library-level detection from an agent, and places both on the application-detection side of his cloud application detection and response grouping. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Miggo Security | competes with | Berthoty names it with Raven among the five providers he describes as delivering library-level detection from an agent. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| ARMO | competes with | Berthoty names it with Raven both in his cloud application detection and response grouping and among the five providers of library-level detection from an agent. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Kodem | competes with | Berthoty names it with Raven among the five providers he describes as delivering library-level detection from an agent. |
Add analyzed competitors to compare them side by side with Raven.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
Raven sells software the customer deploys and operates, priced per protected node, so what it delivers is a product rather than an outcome someone else carries. Its strongest asset is three granted U.S. patents covering how Raven identifies the libraries an application runs, judges exploitation at runtime, and reconstructs call stacks, which a rival has to engineer around. Leaving costs a team the detection and response work it tuned plus the setup that traces each alert to the code change behind it, an effort the cited record never sizes. The behavioral fingerprints are described as specific to each application, and the reviewed record names no shared cross-customer data. Only two customers are named publicly, so the record does not yet show that adoption makes Raven harder to displace.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Raven's customer deploys the sensor, sets the prevention policies and acts on the findings, with pricing tied to protected nodes rather than to an outcome someone else carries. Automated detection, prevention and developer attribution are software output, which places delivery at the product level. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | A team that wires Raven into detection, response and developer-attribution workflows reabsorbs that tuning and process on the way out, meaningful friction of the kind data history, integrations and learned workflows create. The cited record documents no non-portable state, no network participation, and no vendor-bound obligation, and it does not size the migration. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | No attestation, trust portal, or certification badge appears on the probed surfaces, and the cited record identifies no mandate requiring Raven or this product category. Compliance therefore blocks no substitute here and eases no procurement. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Observing execution as structured call chains and behavioral fingerprints at the library and function level in production, at the overhead Raven reports, is real-time systems work. Three granted U.S. patents on library identification, exploitation assessment and compact call-stack unwinding evidence that the depth took years of specialized engineering. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 | SageSure is a named reference with a named security engineering manager, and Raven's March 2026 announcement describes 11 enterprise customers primarily in insurance and financial services. It names no customer inside that group, and the regulated-buyer breadth rests on Raven's own count, so the evidenced buyer is an enterprise with governance rather than a documented regulated-procurement position. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | The sensor runs inside production applications and can block execution, deeper than an out-of-band scanner. Raven states that it deploys without code changes or injection, so removing it ends coverage and unwinds tuned policy rather than stopping the application, which holds it below the infrastructure level. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 2/3 | Three U.S. patents assigned to R.C. Raven Cloud Ltd are granted on the patent record. Two cover mechanisms Raven sells, identifying libraries in an application runtime environment and assessing exploitations at runtime, and the third covers compact call-stack unwinding. That is a retained asset accruing to the vendor rather than one inferred from operating at scale. The record still describes the behavioral fingerprints as specific to each application and names no cross-customer corpus, so the asset raises the engineering cost of copying without being shown as the moat. |
Raven sells to security and application security teams that own applications running in production, positioning itself for cloud-native estates: it states that its coverage extends across Kubernetes clusters, containers and compute instances. Its founding pitch names the application layer as the under-protected gap between endpoint and cloud tooling.
Two customers are named. SageSure credits Raven inside its code security program and Favor Delivery's security leader vouches for its runtime blocking. Raven's March 2026 announcement puts the platform in production with 11 enterprise customers, primarily large insurance and financial organizations, a count it reports without naming the rest.
A single runtime approach fronts the product line, and Raven's pages describe the modules as built around it rather than stating that they share one engine. Raven monitors internal execution paths, breaks them into structured execution chains, and builds behavioral fingerprints of normal behavior, then flags deviations that may signal an attack, working at the library and function level through eBPF instrumentation. Developer attribution ties each detected attack to the exact code change, author, and service that introduced it.
AI appears in Raven's threat narrative and in one module. Runtime AI-Agents applies the same runtime view to discover approved and shadow AI agents inside applications and can alert on or block unsafe agent behavior. Raven's own announcement argues that attackers can now weaponize new vulnerabilities faster than the CVE system can identify, validate and publish them, which is the shift its signature-free detection is built for. AI agent protection is one module of five rather than the platform's center.
Raven runs a direct enterprise motion with a demo-request funnel and no published price. It charges per protected server, virtual machine or node across three annual tiers that add detection and then prevention on top of vulnerability deprioritization, and every tier routes to sales, the pattern of a vendor selling negotiated deals into larger accounts.
Named references and investor backing supply the go-to-market credibility. SageSure and Favor Delivery appear as testimonial customers with named security leaders, Norwest led the seed, Elron Ventures led a post-seed extension, and the endpoint vendor SentinelOne joined the round. Raven says the money funds product development, United States go-to-market expansion, and hiring in engineering and research.
Raven prices by the unit it protects. The published model is per server, virtual machine or node, billed annually, and every quote is custom.
Packaging is public even though price is not. Three tiers stack in order: vulnerability deprioritization with build-time gating and AI-agent control at the base, runtime detection above it, and real-time prevention at the top. Charging by protected node signals that Raven meters the estate it instruments rather than seats or events, and holding the price back points to negotiated enterprise deals rather than self-service adoption.
Raven says its runtime sensor needs no code changes and no injection, calls the runtime overhead negligible with no impact on application latency or stability, and describes the sensor as engineered to run continuously with minimal CPU utilization. The prevention modules block abnormal execution in real time, so the sensor observes and, where configured, intervenes.
Language coverage is part of the deployment story. Raven states it is language-agnostic by design and works across Java, JavaScript, Python, Go, Ruby, C, C++, Rust, PHP, Scala and Kotlin without language-specific agents, and it notes that companies run applications across an average of nine programming languages. Setup is described as taking five minutes with either a cloud-based or an on-premises deployment.
Raven asks customers to run its sensor inside production applications, so operational trust is central. Its answer is low-overhead runtime instrumentation that observes execution and can intervene when prevention policies are enabled, with no code changes and no injection, and Raven states that it does not send application data, prompts, or payloads out for external analysis.
Formal compliance collateral is thin for a company this young. No trust portal, published attestation, or certification badge appears on the probed surfaces, so the trust case today comes from the design, the founders' record, and vendor performance claims nobody outside Raven has verified.
Raven's ecosystem surface is deployment breadth rather than a partner program. The sensor hooks applications at runtime, Runtime Gatekeeper enforces build policies for cloud-native platforms, traditional VM-based deployments, and on-prem or hybrid environments, and the CI/CD hook means Raven reaches code both before and after it ships. Gatekeeper feeds on runtime intelligence collected from production environments to predict which components in a new build will run.
The reviewed sources list alerting and workflow integrations such as Slack, Teams, email and Jira and describe no formal partner program or marketplace listing. Runtime AI-Agents extends the platform toward securing AI agents in production, an adjacency Raven can grow into rather than an operating ecosystem today.
The founding team is Raven's clearest asset. CEO Roi Abitboul and CTO Guy Franco built Javelin Networks, which Symantec acquired, and chief research officer Omer Yair joined them for the new company. Calcalist frames Raven as a second cyber venture by the Javelin founders after their Symantec exit.
The prior domain was endpoint protection. Raven's own announcement says the founders led the acquirer's endpoint detection and cloud protection products after the deal, so the pedigree is cybersecurity broadly rather than application security specifically. Raven's announcement describes the founders as alumni of elite cyber and technological units in the Israel Defense Forces, Raven puts their combined experience at over 30 years, and chief revenue officer Lori Brigg leads the commercial organization.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Raven Runtime ADR product page: application-level runtime visibility | official | 2026-08-30 |
| f2 | SiliconANGLE: Raven Cloud Inc. founded 2023, raises $20M for runtime application security | press | 2026-08-30 |
| f3 | SecurityWeek: Raven emerges from stealth (Palo Alto, California-based) | press | 2026-08-30 |
| f4 | Calcalist: Raven combines a Norwest-led seed with an Elron Ventures post-seed extension | press | 2026-08-30 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Raven homepage: Runtime Application Prevention that Outpaces AI, with SageSure and Favor Delivery testimonials “Raven runs inside the application, stopping exploits before they ever execute, whether a CVE exists or not.” | official | 2026-08-30 |
| s2 | Raven company page: co-founders Roi Abitboul, Guy Franco and Omer Yair, CRO Lori Brigg, Symantec and IDF backgrounds “Backed by top Silicon Valley investors, the Raven team includes serial entrepreneurs and cyber security veterans from Symantec (Broadcom) and elite IDF intelligence units.” | official | 2026-08-30 |
| s3 | Raven Runtime ADR product page: library-level forensics, developer attribution, language coverage “Raven provides runtime application security and application security monitoring by observing real execution inside the application down to libraries, functions, dependencies, and call paths.” | official | 2026-08-30 |
| s4 | Raven Runtime Prevention product page: blocking abnormal execution without signatures “Raven prevents abnormal execution at runtime before malicious code executes.” | official | 2026-08-30 |
| s5 | Raven Runtime SCA product page: function-level reachability, eBPF instrumentation, workflow integrations “It analyzes execution at the library and function level using eBPF-based instrumentation, with negligible runtime overhead and no impact on application latency or stability.” | official | 2026-08-30 |
| s6 | Raven Runtime AI-Agents product page: discovery, behaviour monitoring and policy enforcement for AI agents “Raven Runtime AI Agents provides real-time visibility and control over AI agents operating inside production applications. It discovers both approved and shadow AI agents, monitors their real behavior at runtime, and enforces security policies before unsafe actions cause damage.” | official | 2026-08-30 |
| s7 | Raven pricing page: three per-node tiers, annual pricing, quotes on request “Raven pricing is based on the number of protected servers or nodes and the level of runtime protection you need.” | official | 2026-08-30 |
| s8 | Raven Runtime Gatekeeper product page: build-time policy enforcement driven by runtime intelligence “It enforces security policies during artifact and image build for cloud-native platforms, traditional VM-based deployments, and on-prem or hybrid environments” | official | 2026-08-30 |
| s9 | Calcalist: After Symantec exit, Javelin founders raise $20 million for new cyber bet Raven “The three previously worked together at Javelin Networks, founded by Abitboul and Franco, a cybersecurity company that was acquired by Symantec in 2022.” | press | 2026-08-30 |
| s10 | SecurityWeek: Raven Emerges From Stealth With $20 Million in Funding “Raven, a cybersecurity startup that protects cloud-native applications at runtime, has emerged from stealth mode with $20 million in combined seed and post-seed funding.” | press | 2026-08-30 |
| s11 | SiliconANGLE: Cybersecurity startup Raven raises $20M for runtime application security platform “The platform monitors internal execution paths within a running application and breaks them down into structured execution chains. The chains are then used to generate behavioral fingerprints that represent expected application behavior under normal conditions.” | press | 2026-08-30 |
| s12 | PR Newswire (News provided by RAVEN.IO): $20M raise, 11 enterprise customers, three registered U.S. patents “Norwest led the seed round, with a post-seed investment led by Elron Ventures. RedSeed, UpWest, SentinelOne, Jibe Ventures, Dnipro VC, Unusual Ventures, CyberFuture and Descope CEO Slavik Markovich also participated in the seed round.” | press | 2026-08-30 |
| s13 | Latio Pulse (James Berthoty, Apr 08 2025): Runtime Cloud Security in 2025, on CADR and library-level ADR “The following vendors are in my opinion the closest to CADR: ARMO , Sweet , Upwind , Oligo , Operant and Raven .” | research | 2026-08-30 |
| s14 | Trust surface probe: trust.raven.io and security.raven.io do not resolve, /security and /trust return 404, no attestation badge in served HTML (2026-08-30) | official | 2026-08-30 |
| s15 | Latio Pulse (James Berthoty, May 21 2024): ADR, The Future of Runtime, on function-level visibility as the gap “Despite Miggo and Oligo having radically different instrumentation methods, both differentiate by having visibility into function executions at runtime.” | research | 2026-08-30 |
| s16 | Google Patents: US12517706B1, System and method for identifying libraries for application runtime environment “A system and method for identifying open source software (OSS) libraries for an application runtime environment is presented.” | regulatory | 2026-08-30 |
| s17 | Google Patents: US12524534B1, Techniques for assessing exploitations in a runtime environment “A system and method for efficiently detecting an exploitation during a workload runtime is presented.” | regulatory | 2026-08-30 |
| s18 | Google Patents: US12619449B1, System and method for generating a compact unwinding table for reconstructing call stacks “A system and method for generating a compact unwinding table for call stack unwinding is provided.” | regulatory | 2026-08-30 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Raven homepage: Runtime Application Prevention that Outpaces AI, with SageSure and Favor Delivery testimonials “Raven runs inside the application, stopping exploits before they ever execute, whether a CVE exists or not.” | official | 2026-08-30 |
| s2 | Raven company page: co-founders Roi Abitboul, Guy Franco and Omer Yair, CRO Lori Brigg, Symantec and IDF backgrounds “Backed by top Silicon Valley investors, the Raven team includes serial entrepreneurs and cyber security veterans from Symantec (Broadcom) and elite IDF intelligence units.” | official | 2026-08-30 |
| s3 | Raven Runtime ADR product page: library-level forensics, developer attribution, language coverage “Raven provides runtime application security and application security monitoring by observing real execution inside the application down to libraries, functions, dependencies, and call paths.” | official | 2026-08-30 |
| s4 | Raven Runtime Prevention product page: blocking abnormal execution without signatures “Raven prevents abnormal execution at runtime before malicious code executes.” | official | 2026-08-30 |
| s5 | Raven Runtime SCA product page: function-level reachability, eBPF instrumentation, workflow integrations “It analyzes execution at the library and function level using eBPF-based instrumentation, with negligible runtime overhead and no impact on application latency or stability.” | official | 2026-08-30 |
| s6 | Raven Runtime AI-Agents product page: discovery, behaviour monitoring and policy enforcement for AI agents “Raven Runtime AI Agents provides real-time visibility and control over AI agents operating inside production applications. It discovers both approved and shadow AI agents, monitors their real behavior at runtime, and enforces security policies before unsafe actions cause damage.” | official | 2026-08-30 |
| s7 | Raven pricing page: three per-node tiers, annual pricing, quotes on request “Raven pricing is based on the number of protected servers or nodes and the level of runtime protection you need.” | official | 2026-08-30 |
| s8 | Raven Runtime Gatekeeper product page: build-time policy enforcement driven by runtime intelligence “It enforces security policies during artifact and image build for cloud-native platforms, traditional VM-based deployments, and on-prem or hybrid environments” | official | 2026-08-30 |
| s9 | Calcalist: After Symantec exit, Javelin founders raise $20 million for new cyber bet Raven “The three previously worked together at Javelin Networks, founded by Abitboul and Franco, a cybersecurity company that was acquired by Symantec in 2022.” | press | 2026-08-30 |
| s10 | SecurityWeek: Raven Emerges From Stealth With $20 Million in Funding “Raven, a cybersecurity startup that protects cloud-native applications at runtime, has emerged from stealth mode with $20 million in combined seed and post-seed funding.” | press | 2026-08-30 |
| s11 | SiliconANGLE: Cybersecurity startup Raven raises $20M for runtime application security platform “The platform monitors internal execution paths within a running application and breaks them down into structured execution chains. The chains are then used to generate behavioral fingerprints that represent expected application behavior under normal conditions.” | press | 2026-08-30 |
| s12 | PR Newswire (News provided by RAVEN.IO): $20M raise, 11 enterprise customers, three registered U.S. patents “Norwest led the seed round, with a post-seed investment led by Elron Ventures. RedSeed, UpWest, SentinelOne, Jibe Ventures, Dnipro VC, Unusual Ventures, CyberFuture and Descope CEO Slavik Markovich also participated in the seed round.” | press | 2026-08-30 |
| s13 | Latio Pulse (James Berthoty, Apr 08 2025): Runtime Cloud Security in 2025, on CADR and library-level ADR “The following vendors are in my opinion the closest to CADR: ARMO , Sweet , Upwind , Oligo , Operant and Raven .” | research | 2026-08-30 |
| s14 | Trust surface probe: trust.raven.io and security.raven.io do not resolve, /security and /trust return 404, no attestation badge in served HTML (2026-08-30) | official | 2026-08-30 |
| s15 | Latio Pulse (James Berthoty, May 21 2024): ADR, The Future of Runtime, on function-level visibility as the gap “Despite Miggo and Oligo having radically different instrumentation methods, both differentiate by having visibility into function executions at runtime.” | research | 2026-08-30 |
| s16 | Google Patents: US12517706B1, System and method for identifying libraries for application runtime environment “A system and method for identifying open source software (OSS) libraries for an application runtime environment is presented.” | regulatory | 2026-08-30 |
| s17 | Google Patents: US12524534B1, Techniques for assessing exploitations in a runtime environment “A system and method for efficiently detecting an exploitation during a workload runtime is presented.” | regulatory | 2026-08-30 |
| s18 | Google Patents: US12619449B1, System and method for generating a compact unwinding table for reconstructing call stacks “A system and method for generating a compact unwinding table for call stack unwinding is provided.” | regulatory | 2026-08-30 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.