Sweet Security

Security for AI Cloud SecurityDetection Response

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2023
Funding $120M
Last updated 2026-08-28

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Sweet Security sells one platform for cloud and AI. The cloud half puts a sensor inside a customer's workloads, coverage an independent buyer guide lists beside Wiz, Prisma Cloud and Orca Security. The AI half routes agent traffic through a gateway that blocks a single risky operation as it runs, and a July 2026 release extended it to terminating unauthorized tool calls. Named customers appear on Sweet's own pages, Fireblocks, Kaltura, Lemonade and Hippo among them, and PeerSpot carries six reviews averaging 8.6 out of 10. Watch whether the agent gateway gathers a public customer record of its own, which today amounts to the one early customer SiliconANGLE names.

Sourced Details

Description Sweet Security's AI Security Platform gives companies visibility into the AI models and agents running in their environment. It routes agent traffic through an AI gateway to block prompt injection and holds agents to minimal permissions. [f1]
Founded 2023 [f2]
HQ Tel Aviv, Israel [f3]
Funding $120M total [f4]
Latest funding Series B, $75M (November 2025) [f5]
Deployment SaaS [f6]

Products

Product What it does
Sweet AI Security Platform Sweet AI Security Platform: Runtime detection and response for AI systems that inventories models and agents, blocks prompt injection through an AI gateway, and enforces least privilege for agents.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

The Sweet AI Security Platform is runtime detection and response for AI systems that inventories models and agents, blocks prompt injection through an AI gateway, and enforces least privilege for agents. It is mapped to the AI Defense Matrix. [f7]

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

Sweet's Runtime CNAPP uses AI to secure conventional cloud workloads, applications, and identities at runtime, with detection and response, posture and vulnerability inventory, API security, and identity threat detection. It is mapped to the Cyber Defense Matrix. [f4]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 27 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Sweet names the CISO and cloud security team and a runtime-attack pain, and SiliconANGLE frames the same gap independently, but no cited source quantifies the pain, which is what separates this rung from the next. [s6, s8, s1]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 4/5 Beyond Sweet's own detail on the AI gateway and operation-level enforcement, two non-vendor evaluations bear on the capability: an independent buyer guide that tested 10 platforms reports the sensor runs under 100 MB of memory and flags reporting and access-control gaps, and a PeerSpot reviewer describes the runtime and application-layer depth as where traditional platforms are weakest. [s10, s9, s2, s12]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 Enterprises putting AI agents into production is a credible enabler, and PeerSpot records buyer research on Sweet in the CNAPP category tripling to 1.5% between 2025 and August 2026. That is one kind of buyer-side signal rather than the several distinct kinds the next rung asks for. [s9, s2, s8]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 SiliconANGLE documents senior in-domain roles for all three founders, a retired brigadier general and former IDF CISO, a former head of the Unit 8200 cyber department, and a former Unit 81 research lead, and CTech independently describes the company as led by ex-IDF cyber chiefs. The cited record documents no prior product build, exit, or publication record under their names, which is what the next rung requires. [s8, s4, s7]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 4/5 Five named customers appear with attributed titles, among them the security chiefs of Fireblocks, Kaltura and ShipStation, the case-study index adds Lemonade, Firebolt and Hippo, and SiliconANGLE names Zoomd as an early customer. PeerSpot carries six reviews averaging 8.6 out of 10 from outside the vendor. Scale itself stays uncorroborated, which holds this below the top rung. [s1, s15, s8, s9]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 $120 million raised over two and a half years funds visible shipping, with a federal-market push announced in June 2026 and agent blocking in July 2026. CTech reports roughly $15 million of the Series B went to secondary deals rather than into the company, and no revenue or margin figure is disclosed, so output per dollar stays unconfirmed. [s4, s13, s11, s3]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 4/5 Four non-vendor sources place Sweet in the established CNAPP category: PeerSpot ranks it inside its CNAPP listing, an independent buyer guide includes it among 10 CNAPP platforms, CTech calls it a comprehensive CNAPP, and SecurityWeek puts it in the runtime CNAPP segment. No cited source recognizes Sweet as a definer or leader of the category, which keeps this off the top rung. [s9, s10, s4, s16]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 A PeerSpot reviewer evaluated Wiz and Palo Alto before choosing Sweet, so the overlap with platforms a buyer also considers is documented rather than assumed. Working against easy absorption are a deployed eBPF runtime sensor and the gateway that sits in the path of agent operations. The cited record shows no data asset or authorization that bundling could not eventually match. [s9, s10, s2, s12]
Business Risks A larger platform in the same category could add runtime coverage for AI agents to a suite it already sells, and a PeerSpot reviewer says he weighed Sweet against Wiz and Palo Alto before choosing it…
  • A larger platform in the same category could add runtime coverage for AI agents to a suite it already sells, and a PeerSpot reviewer says he weighed Sweet against Wiz and Palo Alto before choosing it.
  • The sixfold recurring-revenue and tenfold enterprise customer figures come from Sweet's own announcement, and no cited third party confirms either one.
  • Sweet announced FedRAMP Moderate as a pursuit in June 2026 with Coalfire engaged as assessor, and no cited source records the authorization as granted, so a federal buyer that requires an authorized cloud service has to check the current status directly.
  • An independent buyer guide reports that reporting and alert customization lag established platforms and that access-control permissions need refinement, which a buyer with strict access-control requirements would test before committing.
  • No completed attestation report or trust portal appears in the cited sources, and a probe of trust.sweet.security on 2026-08-28 returned the marketing homepage, so a buyer will have to request assurance documents directly.
Problem & Market Sweet Security sells to the security leader who owns production cloud risk…

Sweet Security sells to the security leader who owns production cloud risk. SiliconANGLE describes the platform as helping teams shut down cloud attacks when and where they occur with minimal business disruption, and the site groups its solutions under CISOs, cloud security and DevSecOps, SOC and incident response, and application security. An independent buyer guide places the product with mid-market and enterprise organizations in regulated industries that prioritize catching threats in production over managing vulnerability backlogs.

The problem widened when enterprises put AI agents into production. SiliconANGLE's 2026 reporting states the case in its own voice: agents hold their own identities and reach into sensitive systems, often with no human reviewing the individual actions they take, and detection tools describe what an agent has already finished doing. Sweet sells one platform across conventional workloads and those agents.

What the cited record does not carry is a number for the pain. No source here sizes the cost of runtime cloud attacks or of agent misbehavior, so the problem stays qualitative even where two independent outlets frame it the same way. [s6, s8, s1, s10]

Product Capabilities Sweet runs a Runtime CNAPP with a documented surface and an eBPF sensor at its base. SiliconANGLE reported in 2024 that the runtime sensor deploys in under five minutes, and an independent buyer guide that tested 10 CNAPP platforms reports the sensor needs under 100 MB of memory and builds a behavioral baseline the analytics compare against. CTech describes full visibility into systems at all stages of code execution. The AI Security Platform extends that base to models and agents. Sweet builds a bill of materials for every model, detects agents running in the environment including shadow or unmanaged ones, and funnels agent traffic through an AI gateway that analyzes prompts and blocks malicious operations. Enforcement happens at the level of a single operation, so Sweet can revoke one risky action without ending the session, and the July 2026 release added termination of unauthorized tool calls and blocking of data leaving through an agent. Independent validation now exists and it cuts both ways. The buyer guide credits the runtime-first approach and the incident narratives, and it reports that reporting and alert customization lag established platforms and that access-control permissions need refinement. A U.S. patent granted in December 2025 and assigned to Sweet Security Ltd covers using a language model over tokenized cloud session logs. Sweet separately credits a patented, LLM-driven detection engine with reducing alert noise to 0.04%, which is the company's own measurement…

Sweet runs a Runtime CNAPP with a documented surface and an eBPF sensor at its base. SiliconANGLE reported in 2024 that the runtime sensor deploys in under five minutes, and an independent buyer guide that tested 10 CNAPP platforms reports the sensor needs under 100 MB of memory and builds a behavioral baseline the analytics compare against. CTech describes full visibility into systems at all stages of code execution.

The AI Security Platform extends that base to models and agents. Sweet builds a bill of materials for every model, detects agents running in the environment including shadow or unmanaged ones, and funnels agent traffic through an AI gateway that analyzes prompts and blocks malicious operations. Enforcement happens at the level of a single operation, so Sweet can revoke one risky action without ending the session, and the July 2026 release added termination of unauthorized tool calls and blocking of data leaving through an agent.

Independent validation now exists and it cuts both ways. The buyer guide credits the runtime-first approach and the incident narratives, and it reports that reporting and alert customization lag established platforms and that access-control permissions need refinement. A U.S. patent granted in December 2025 and assigned to Sweet Security Ltd covers using a language model over tokenized cloud session logs. Sweet separately credits a patented, LLM-driven detection engine with reducing alert noise to 0.04%, which is the company's own measurement. [s6, s10, s2, s12, s13, s3]

Competitive Positioning Sweet competes for the CNAPP budget against platforms its buyers also evaluate. A PeerSpot reviewer says outright that he weighed Wiz and Palo Alto before choosing Sweet, and the independent buyer guide lists Sweet alongside Prisma Cloud, Wiz, Orca Security, Sysdig and CrowdStrike in the same category. Sweet's answer is a runtime-first read of the same problem, catching what happens after an application is live rather than scanning before it ships. The AI line moves part of that contest onto newer ground. Sweet puts a gateway in the path of agent operations and enforces least privilege as an action runs, which is a different position from watching agent traffic go by. Whether an incumbent can match that position quickly is not settled by any cited source. Buyer research is moving toward Sweet from a small base. PeerSpot puts its CNAPP mindshare at 1.5% in August 2026, up from 0.5% a year earlier, and ranks it 14th in that category. The company is closer to the edge of the field than to its center…

Sweet competes for the CNAPP budget against platforms its buyers also evaluate. A PeerSpot reviewer says outright that he weighed Wiz and Palo Alto before choosing Sweet, and the independent buyer guide lists Sweet alongside Prisma Cloud, Wiz, Orca Security, Sysdig and CrowdStrike in the same category. Sweet's answer is a runtime-first read of the same problem, catching what happens after an application is live rather than scanning before it ships.

The AI line moves part of that contest onto newer ground. Sweet puts a gateway in the path of agent operations and enforces least privilege as an action runs, which is a different position from watching agent traffic go by. Whether an incumbent can match that position quickly is not settled by any cited source.

Buyer research is moving toward Sweet from a small base. PeerSpot puts its CNAPP mindshare at 1.5% in August 2026, up from 0.5% a year earlier, and ranks it 14th in that category. The company is closer to the edge of the field than to its center. [s9, s10, s2]

Go-to-Market & Traction Named customers now appear on the record with titles attached…

Named customers now appear on the record with titles attached. The homepage carries Cast & Crew, ShipStation, Fireblocks, Kaltura and Engageli, quoting Fireblocks and Kaltura directly, the case-study index adds Lemonade, Firebolt and Hippo, and SiliconANGLE names Zoomd as an early customer of the agent-blocking capability. Eight named organizations appear across those two surfaces.

Two sources outside the vendor corroborate that customers run the product. PeerSpot carries six reviews rating Sweet 8.6 out of 10, all six saying they would recommend it, and one reviewer describes the runtime and application-layer depth as the place traditional platforms are weakest. An independent buyer guide reports customer feedback of its own. Neither speaks to how many customers Sweet has.

Scale remains Sweet's own claim. The Series B announcement reports a sixfold increase in annual recurring revenue, a tenfold rise in enterprise customers and multiple Fortune 1000 organizations, and the July 2026 release reports more than a billion runtime events analyzed daily. Every one of those figures is the company's own measurement, and SiliconANGLE attributes the same billion-event number to Sweet rather than reporting it independently. [s1, s15, s9, s3, s8]

Team & Credibility The three founders carry documented senior roles in offensive and defensive cyber. SiliconANGLE describes Dror Kashti as a retired brigadier general and former chief information security officer of the Israel Defense Forces, Eyal Fisher as the former head of the cyber department at Unit 8200, and Orel Ben-Ishay as the former head of the cybersecurity research and development center at Unit 81. CTech's own account of the Series B describes the company as led by ex-IDF cyber chiefs. The bench around them carries senior security operators. TechCrunch reports that Gerhard Eschelbeck, a former CISO at Google, and Travis McPeak, who led product security at Databricks, invested in the seed round, and the about page lists both as advisors alongside JPMorgan Chase's head of cloud security and a former director general of Israel's National Cyber Directorate. Those people advise rather than build the product. The military pedigree is verifiable and the commercial track record is not. No cited source establishes a prior product built, a prior exit, or a sustained public research record under any founder's name…

The three founders carry documented senior roles in offensive and defensive cyber. SiliconANGLE describes Dror Kashti as a retired brigadier general and former chief information security officer of the Israel Defense Forces, Eyal Fisher as the former head of the cyber department at Unit 8200, and Orel Ben-Ishay as the former head of the cybersecurity research and development center at Unit 81. CTech's own account of the Series B describes the company as led by ex-IDF cyber chiefs.

The bench around them carries senior security operators. TechCrunch reports that Gerhard Eschelbeck, a former CISO at Google, and Travis McPeak, who led product security at Databricks, invested in the seed round, and the about page lists both as advisors alongside JPMorgan Chase's head of cloud security and a former director general of Israel's National Cyber Directorate. Those people advise rather than build the product.

The military pedigree is verifiable and the commercial track record is not. No cited source establishes a prior product built, a prior exit, or a sustained public research record under any founder's name. [s8, s4, s5, s7]

Trust Readiness Sweet asks for deep access, and the assurance record in the cited pages is thin. The product holds runtime access to a customer's cloud workloads, identities and now agent operations, and the AI platform page publishes AICPA SOC 2, ISO and NIST badge images. No completed attestation report, audit letter or trust portal appears in the cited sources, and a probe of trust.sweet.security on 2026-08-28 returned the marketing homepage rather than a trust surface. The federal move is the clearest signal of where the assurance work is going. Sweet announced in June 2026 that it is pursuing FedRAMP Moderate authorization and has engaged Coalfire Systems, a third-party assessor, to benchmark its federal security program. No cited source records that authorization as granted. The technical on-ramp is light. SiliconANGLE reports that the sensor deploys in under five minutes, and an independent guide puts its memory footprint under 100 MB. Data handling, retention and attestation terms still have to be settled in a formal review…

Sweet asks for deep access, and the assurance record in the cited pages is thin. The product holds runtime access to a customer's cloud workloads, identities and now agent operations, and the AI platform page publishes AICPA SOC 2, ISO and NIST badge images. No completed attestation report, audit letter or trust portal appears in the cited sources, and a probe of trust.sweet.security on 2026-08-28 returned the marketing homepage rather than a trust surface.

The federal move is the clearest signal of where the assurance work is going. Sweet announced in June 2026 that it is pursuing FedRAMP Moderate authorization and has engaged Coalfire Systems, a third-party assessor, to benchmark its federal security program. No cited source records that authorization as granted.

The technical on-ramp is light. SiliconANGLE reports that the sensor deploys in under five minutes, and an independent guide puts its memory footprint under 100 MB. Data handling, retention and attestation terms still have to be settled in a formal review. [s2, s14, s11, s6, s10]

Competitors Wiz, Palo Alto Networks, Orca Security, Sysdig…
Company Relationship Note Compare
Wiz competes with A PeerSpot reviewer says he evaluated Wiz before choosing Sweet, and an independent buyer guide lists both among the top CNAPP platforms. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Palo Alto Networks competes with Prisma Cloud appears alongside Sweet in the same independent CNAPP buyer guide, and a PeerSpot reviewer weighed Palo Alto against Sweet. N/AWe scored these companies at different scopes, so the totals measure different things.
Orca Security competes with The independent CNAPP buyer guide lists Orca Security among the same 10 platforms, described as best for teams wanting agentless multi-cloud coverage with fast onboarding.
Sysdig competes with The same independent CNAPP buyer guide lists Sysdig Secure and Sweet among its 10 platforms, Sysdig for Kubernetes-heavy environments and Sweet for runtime-first detection and response. N/AWe scored these companies at different scopes, so the totals measure different things.

Add analyzed competitors to compare them side by side with Sweet Security.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 14 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

Sweet Security holds one evidenced asset and one source of friction. A U.S. patent published in December 2025 and assigned to Sweet Security Ltd claims a method that tokenizes cloud session logs and feeds them to a language model. That is retained intellectual property rather than a data set. The friction is the gateway in the path of agent operations and the sensor inside a customer's own workloads, and no cited source sizes what leaving either would cost. An independent guide places Sweet with regulated mid-market and enterprise teams, and Sweet announced FedRAMP Moderate as a pursuit in June 2026 that no cited source records as granted. Watch whether buyers take the agent gateway rather than only the cloud coverage.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Sweet delivers software the customer installs and operates, from the eBPF sensor in its workloads to the gateway in front of its agents, and the cited record describes no service Sweet runs on the customer's behalf.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Two mechanisms are documented. The gateway processes live agent traffic and blocks operations as they execute, and the sensor runs inside the customer's workloads with a behavioral baseline it learns there, so leaving means re-pointing agent traffic and relearning that baseline. No cited source sizes the migration, so the score stays at meaningful friction.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 The AI platform page carries badge images labelled AICPA SOC 2, ISO and NIST, which a funded competitor obtains through ordinary enterprise preparation, and the FedRAMP Moderate authorization Sweet announced in June 2026 is a pursuit with an assessor engaged rather than an authorization it holds.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 A granted patent claims tokenizing cloud session logs into a language model, the sensor is eBPF-based and runs under 100 MB of memory, and enforcement decides a single agent operation while the session continues. Real-time systems and applied machine learning of that kind take years of specialized engineering.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 An independent buyer guide places Sweet with regulated mid-market and enterprise teams in finance, healthcare and retail, and PeerSpot reports that large enterprises make up 35% of the people researching it and that financial services professionals account for 9% of views. Sweet is targeting U.S. federal agencies and pursuing FedRAMP Moderate authorization.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 The gateway enforces policy inside the path of agent operations, while the sensor and the CNAPP surface observe cloud a customer already runs, so the product is a platform with application features rather than infrastructure other software depends on to function.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 2/3 US12495057B1, published in December 2025 with Sweet Security Ltd as assignee, claims using a language model over tokenized cloud session logs to control access to a cloud, so the detection method is retained intellectual property rather than a technique the record only describes. The cited record identifies no cross-customer corpus and no named non-public data set beside it.
Strategic Market Segmentation Sweet Security sells to the security organization that owns live cloud risk…

Sweet Security sells to the security organization that owns live cloud risk. SiliconANGLE describes the platform as shutting down cloud attacks when and where they occur with minimal business disruption, and the site groups its solutions under CISOs, cloud security and DevSecOps, SOC and incident response, and application security. An independent buyer guide places Sweet with regulated mid-market and enterprise teams that prioritize runtime detection and response, naming finance, healthcare and retail.

Six people speak for customers in the cited record, and four of them are security chiefs. Fireblocks, Kaltura, Cast & Crew and ShipStation are represented that way on the homepage, while Engageli speaks through a VP of research and development and SiliconANGLE quotes Zoomd's chief technology officer. PeerSpot adds that large enterprises make up 35% of the people researching Sweet on its platform, with professionals from financial services firms accounting for 9% of the views.

The AI line reaches a second audience without a second budget on the record. Sweet describes the AI platform as serving teams that build with foundation models and orchestration frameworks, and the cited pages never say who signs for the agent controls. Which function pays is unresolved.

Product Capabilities & AI Advantages The AI platform organizes around knowing every model, seeing every agent and controlling every action. Sweet builds a bill of materials covering every model, public or fine-tuned, across an ecosystem it describes as spanning Bedrock, Claude and OpenAI plus orchestration frameworks such as LangChain and Vertex AI. It detects agents running in the environment, including shadow or unmanaged ones, and funnels agent traffic through an AI gateway that analyzes prompts and blocks malicious operations. Enforcement at the level of a single operation is what separates this line from watching agent traffic go by. Sweet links its workload sensors to the gateway so it can revoke one risky action in real time without ending the session, arguing that ordinary gateways see traffic rather than intent. The July 2026 release added termination of unauthorized tool calls and blocking of secrets and personal data leaving through an agent, and SiliconANGLE reported the capability in its own words. A granted patent anchors the detection claim in a record outside Sweet's own pages. US12495057B1, assigned to Sweet Security Ltd and published in December 2025, claims a method that tokenizes cloud session logs and feeds them to a language model. Sweet separately credits a patented, LLM-driven detection engine with reducing alert noise to 0.04%, a figure that remains the company's own measurement. What the cited record does not show is any pooling of runtime telemetry. SiliconANGLE reports Sweet's claim that its reasoning layer analyzes more than a billion runtime events daily, and the 2024 SiliconANGLE account describes sensors streaming application data to profile workload behavior. No cited page describes a cross-customer corpus, a right to reuse customer telemetry, or shared models trained on it…

The AI platform organizes around knowing every model, seeing every agent and controlling every action. Sweet builds a bill of materials covering every model, public or fine-tuned, across an ecosystem it describes as spanning Bedrock, Claude and OpenAI plus orchestration frameworks such as LangChain and Vertex AI. It detects agents running in the environment, including shadow or unmanaged ones, and funnels agent traffic through an AI gateway that analyzes prompts and blocks malicious operations.

Enforcement at the level of a single operation is what separates this line from watching agent traffic go by. Sweet links its workload sensors to the gateway so it can revoke one risky action in real time without ending the session, arguing that ordinary gateways see traffic rather than intent. The July 2026 release added termination of unauthorized tool calls and blocking of secrets and personal data leaving through an agent, and SiliconANGLE reported the capability in its own words.

A granted patent anchors the detection claim in a record outside Sweet's own pages. US12495057B1, assigned to Sweet Security Ltd and published in December 2025, claims a method that tokenizes cloud session logs and feeds them to a language model. Sweet separately credits a patented, LLM-driven detection engine with reducing alert noise to 0.04%, a figure that remains the company's own measurement.

What the cited record does not show is any pooling of runtime telemetry. SiliconANGLE reports Sweet's claim that its reasoning layer analyzes more than a billion runtime events daily, and the 2024 SiliconANGLE account describes sensors streaming application data to profile workload behavior. No cited page describes a cross-customer corpus, a right to reuse customer telemetry, or shared models trained on it.

Sales Engagement & Go-to-Market Sweet sells through a demo, with a fast technical on-ramp…

Sweet sells through a demo, with a fast technical on-ramp. SiliconANGLE reports a runtime sensor that deploys in under five minutes, an independent guide puts its memory footprint under 100 MB, and every call to action on the homepage asks for a demo or a 30-minute walkthrough, with no self-serve signup on the cited pages. The technical barrier to a first look is low.

Public references are now broad. Five customers speak on the homepage with names and titles, the case-study index carries Engageli, Kaltura, Fireblocks, Firebolt, Lemonade and Hippo, and SiliconANGLE names Zoomd as an early customer of the agent-blocking release. PeerSpot carries six reviews rating Sweet 8.6 out of 10 with all six saying they would recommend it, which corroborates use from outside the vendor.

Scale itself is still Sweet's own number. The Series B announcement reports a sixfold increase in annual recurring revenue and a tenfold rise in enterprise customers including multiple Fortune 1000 organizations, and CTech reports that around $15 million of the round went to secondary deals rather than into the company. SiliconANGLE relays the billion-events figure as something the company said, so no cited source confirms any growth or volume claim independently.

Pricing Model Sweet publishes no price and no billing unit in the cited pages…

Sweet publishes no price and no billing unit in the cited pages. The homepage asks for a demo and a 30-minute walkthrough, the integrations catalog and platform pages carry no packaging tiers, and an independent buyer guide that publishes a starting price for two rivals records Sweet as contact for quote with billing not disclosed. A buyer cannot anchor a budget before talking to sales.

The platform shape suggests value scales with the estate under protection. Sweet covers detection and response, posture, vulnerability management, identity, API security, data security and the AI line from one product, and an outside reader cannot tell whether it charges by workload, sensor, asset or tier. The cited record stops short of the meter.

A buyer therefore weighs Sweet on references and a demo rather than on a comparable quote. That fits the enterprise segment the independent guide describes, and it puts more weight on the named customers and the six PeerSpot reviews than a published price list would.

Product Delivery & Operations Sweet ships software the customer deploys and operates…

Sweet ships software the customer deploys and operates. The eBPF sensor installs in under five minutes, needs under 100 MB of memory, and streams application data to profile workload behavior, and Sweet extended that sensor to Windows environments in October 2025. Nothing in the cited record describes Sweet operating the product on a customer's behalf.

The AI line adds an enforcement component that stands in the path of agent actions. Sweet links workload sensors to the gateway for contextual, operation-level enforcement and blocks unauthorized actions without ending the session. SiliconANGLE names the operational hazard plainly, that enforcement misreading legitimate behavior takes down production, and reports Sweet's argument that this risk is why most of the industry has settled for alerting instead.

Sweet publishes no operating commitments. No uptime figure, support commitment or failure-mode description appears in the cited pages, which is what a careful review asks for before putting an enforcement layer in front of production agents.

Earning Customers' Trust Sweet asks for deep access, and the assurance record in the cited pages is thin. The AI platform page carries badge images labelled AICPA SOC 2, ISO and NIST, and no completed attestation report, audit letter or trust portal appears in the cited pages. A probe of trust.sweet.security on 2026-08-28 returned the marketing homepage rather than a trust surface. The federal move is where the assurance work is going. Sweet announced in June 2026 that it is pursuing FedRAMP Moderate authorization and has engaged Coalfire Systems, a third-party assessor, to benchmark its federal security program, and its CPO frames the work as continued investment in operational rigor and governance. No cited source records that authorization as granted. Sweet makes the rest of its trust case on architecture and people. It positions runtime context plus operation-level enforcement as the route to precise real-time protection, and its founders and advisors carry documented security careers. A buyer routing privileged cloud and agent activity through Sweet still has to settle data handling, retention and attestation terms in a formal review…

Sweet asks for deep access, and the assurance record in the cited pages is thin. The AI platform page carries badge images labelled AICPA SOC 2, ISO and NIST, and no completed attestation report, audit letter or trust portal appears in the cited pages. A probe of trust.sweet.security on 2026-08-28 returned the marketing homepage rather than a trust surface.

The federal move is where the assurance work is going. Sweet announced in June 2026 that it is pursuing FedRAMP Moderate authorization and has engaged Coalfire Systems, a third-party assessor, to benchmark its federal security program, and its CPO frames the work as continued investment in operational rigor and governance. No cited source records that authorization as granted.

Sweet makes the rest of its trust case on architecture and people. It positions runtime context plus operation-level enforcement as the route to precise real-time protection, and its founders and advisors carry documented security careers. A buyer routing privileged cloud and agent activity through Sweet still has to settle data handling, retention and attestation terms in a formal review.

Platform Strategy & Ecosystem Positioning Sweet positions itself as one platform across conventional cloud and AI…

Sweet positions itself as one platform across conventional cloud and AI. The Runtime CNAPP page lists detection and response, identity, application and API security, vulnerability management, posture, data security, entitlements and compliance checks under one product, and CTech describes a comprehensive CNAPP spanning the stages of code execution. Sweet frames that breadth as consolidation, calling itself ADR, CDR and CWPP combined.

Outward reach comes through two channels the cited pages document. The integrations catalog lists categories for CI/CD, cloud providers, code security, notifications, privileged access, security workflows, SIEM, SSO, third-party data and ticketing, with named entries such as CyberArk. The AI line reaches outward instead through the gateway that sits where agents call tools, which Sweet argues is where intent forms.

The exposure is bundling by a larger platform in the same category. A PeerSpot reviewer says he evaluated Wiz and Palo Alto before choosing Sweet, and an independent guide lists Sweet alongside Prisma Cloud, Wiz, Orca Security, Sysdig and CrowdStrike in the same category. The cloud coverage is the half those platforms contest most directly.

Team & Execution Capability Three founders with documented senior cyber careers run the company…

Three founders with documented senior cyber careers run the company. SiliconANGLE describes Dror Kashti as a retired brigadier general and former chief information security officer of the Israel Defense Forces, Eyal Fisher as the former head of the cyber department at Unit 8200, and Orel Ben-Ishay as the former head of the cybersecurity research and development center at Unit 81. CTech independently describes the company as led by ex-IDF cyber chiefs. Tomer Filiba is named as CTO and the cited pages state no prior background for him.

The advisory bench carries senior security operators. SiliconANGLE reported that Gerhard Eschelbeck, a former CISO at Google, and Travis McPeak, who led product security at Databricks, were investors in the seed round, and the about page lists both as advisors alongside JPMorgan Chase's head of cloud security and a former director general of Israel's National Cyber Directorate. Those people advise the company rather than build or buy the product.

What no cited source establishes is a company any founder built before this one. The military records are specific and verifiable, and a prior product, an exit, or a sustained public research record under a founder's name does not appear in the reviewed sources.

Sources

Company Detail Sources (7)
Id Source Tier Accessed
f1 Sweet Security: AI Security Platform for Agents and LLMs official 2026-08-28
f2 Sweet Security: Agentic AI Blocking announcement (July 29, 2026) official 2026-08-28
f3 TechCrunch: Sweet Security raises $12M seed round for its cloud security suite press 2026-08-28
f4 CTech on the Sweet Security $75M Series B (November 12, 2025) press 2026-06-14
f5 Sweet Security Series B press release (November 12, 2025) official 2026-06-14
f6 AI Defense Matrix Catalog entry other 2026-06-10
f7 AI Defense Matrix Catalog mapping other 2026-06-23
Profile Analysis Sources (16)
Id Source Tier Accessed
s1 Sweet Security: homepage (Autonomous Protection for the AI Enterprise) official 2026-08-28
s2 Sweet Security: AI Security Platform (AISP) product page official 2026-08-28
s3 Sweet Security: Series B announcement (November 12, 2025) official 2026-08-28
s4 CTech: Sweet Security, led by ex-IDF cyber chiefs, secures $75M Series B press 2026-08-28
s5 TechCrunch: Sweet Security raises $12M seed round for its cloud security suite press 2026-08-28
s6 SiliconANGLE: Israeli startup Sweet Security raises $33M to strengthen cloud security operations press 2026-08-28
s7 Sweet Security: About page (team and advisors) official 2026-08-28
s8 SiliconANGLE: Sweet Security debuts Agentic AI Blocking to stop rogue agents in real time press 2026-08-28
s9 PeerSpot: Sweet Security reviews, rankings and CNAPP mindshare other 2026-08-28
s10 Expert Insights: top cloud-native application protection platforms buyer guide other 2026-08-28
s11 Sweet Security: federal-market expansion and FedRAMP Moderate announcement (June 10, 2026) official 2026-08-28
s12 Google Patents: US12495057B1, Contextual anomaly detection in activity logs other 2026-08-28
s13 Sweet Security: Agentic AI Blocking announcement (July 29, 2026) official 2026-08-28
s14 Sweet Security: trust-subdomain probe (trust.sweet.security served the marketing homepage) official 2026-08-28
s15 Sweet Security: case-studies resource index official 2026-08-28
s16 SecurityWeek: Sweet Security Raises $75 Million for Cloud and AI Security press 2026-08-28
Deep-Dive Sources (19)
Id Source Tier Accessed
s1 Sweet Security: homepage (Autonomous Protection for the AI Enterprise) official 2026-08-28
s2 Sweet Security: AI Security Platform (AISP) product page official 2026-08-28
s3 Sweet Security: Runtime CNAPP platform page official 2026-08-28
s4 Sweet Security: integrations catalog page official 2026-08-28
s5 Sweet Security: About page (team and advisors) official 2026-08-28
s6 Sweet Security: Series B announcement (November 12, 2025) official 2026-08-28
s7 SiliconANGLE: Israeli startup Sweet Security raises $33M to strengthen cloud security operations press 2026-08-28
s8 SiliconANGLE: Sweet Security debuts Agentic AI Blocking to stop rogue agents in real time press 2026-08-28
s9 CTech: Sweet Security, led by ex-IDF cyber chiefs, secures $75M Series B press 2026-08-28
s10 SecurityWeek: Sweet Security Raises $75 Million for Cloud and AI Security press 2026-08-28
s11 Help Net Security: Sweet Security brings Runtime CNAPP visibility and protection to Windows environments press 2026-08-28
s12 PeerSpot: Sweet Security reviews, rankings and CNAPP mindshare other 2026-08-28
s13 Expert Insights: top cloud-native application protection platforms buyer guide other 2026-08-28
s14 Google Patents: US12495057B1, Contextual anomaly detection in activity logs other 2026-08-28
s15 Sweet Security: federal-market expansion and FedRAMP Moderate announcement (June 10, 2026) official 2026-08-28
s16 Sweet Security: Agentic AI Blocking announcement (July 29, 2026) official 2026-08-28
s17 Sweet Security: Sweet Attack launch announcement (May 13, 2026) official 2026-08-28
s18 Sweet Security: trust-subdomain probe (trust.sweet.security served the marketing homepage) official 2026-08-28
s19 Sweet Security: case-studies resource index official 2026-08-28

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.