Terra Security

Application SecurityNetwork SecuritySecurity Operations also known as Terra Security Inc.

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2024
Funding $38M
Last updated 2026-07-10

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Terra Security sells continuous penetration testing in which a swarm of AI agents attacks a customer’s web applications, networks, and AI systems. Credentialed humans approve risky steps and sign the findings, and that signature matters more than the automation. The deliverable is an audit-ready report that auditors accept, which puts Terra in the manual-pentest budget rather than beside scanners. Terra holds an AWS security competency its announcement presents as the inaugural approval for autonomous security validation, sells through the AWS marketplace, and hired an ex-AWS executive to lead partner strategy. Press in September 2025 cited Fortune 100 clients, and the named endorsements, Riskified’s CISO among them, sit on Terra’s pages, so customer evidence trails partner evidence.

Sourced Details

Description Terra Security runs an agentic offensive security platform that uses a swarm of fine-tuned AI agents, with human oversight, to continuously pentest web applications, external networks, infrastructure, and AI systems. [f1]
Founded 2024 [f2]
HQ New York, United States, and Tel Aviv, Israel [f3]
Funding $38M total [f2]
Latest funding Series A ($30M, September 2025, led by Felicis) [f2]

Products

Product What it does
Terra Platform Agentic pentesting platform whose AI agents continuously test web apps, external networks, infrastructure, and AI systems, validating findings through real exploitation rather than scoring.
Terra Offensive Research Collaboration Hub (TORCH) Collaboration hub that lets security teams work directly with Terra's agents and apply human-on-the-loop control at each step of a pentest run.

Matrix Coverage

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

Terra Platform uses AI agents to continuously pentest customers' web applications, external networks, and infrastructure, surfacing exploitable weaknesses, and is mapped to the Cyber Defense Matrix. [f4]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Emerging 22 /40 Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Terra names security teams running pentest programs and the point-in-time testing gap, but the pain is qualitative and the independent grounding is Ctech funding-round coverage that echoes the vendor's framing, without quantification across multiple non-vendor sources. [s1, s3, s4]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 The platform's four-surface coverage and exploit-driven validation are detailed on vendor pages, and press relays the vendor's framing at two scales, Ctech reporting dozens of AI agents and SecurityWeek a swarm running thousands of tests. Terra advertises a vendor-controlled benchmark and vendor-reported AWS recognition as a validated provider, but the cited record includes no directly cited independent technical evaluation or independently run benchmark. [s1, s2, s3, s6, s14]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 The fast seed-to-Series-A sequence is investor demand rather than buyer demand, and the 2025 accelerator win is an ecosystem signal, so the credible AI-driven-testing enabler lacks the multiple independent buyer-side signals the higher rung needs. [s3, s4, s6, s16]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 2/5 Shahar Peled and Gal Malachi are named co-founders with plausible backgrounds, but the cited record verifies nothing beyond their current titles: no senior in-domain role, prior build, exit, or sustained publication record for either founder. [s4, s7]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 3/5 Terra cites Fortune 500 clients only in the aggregate with no named reference, so the strongest disclosed traction is the Felicis-led investor group, top angels including a former Google security chief, and a 2025 accelerator win, an indirect-signal adjustment applied here. [s3, s4, s5, s15, s16]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 2/5 The $8M seed and $30 million Series A closed within about five months with no disclosed revenue and no named customer, so the capital outruns the verifiable commercial results even though the Terra Offensive Research Collaboration Hub and the network-pentesting launch show shipping. [s2, s3, s4, s8]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 Penetration testing is an established budget line but continuous agentic pentesting is a forming category, and the placement rests on vendor and press framing rather than independent category confirmation, so it needs explanation to slot cleanly. [s1, s4, s6]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 Agentic pentesting is absorbable by exposure-management platforms and by the AI red-teaming startups, and per-customer business-context training raises switching cost without yet forming a cross-customer data moat visible in the record. [s1, s3]
Business Risks Rapid7, Tenable, or another exposure-management platform could add continuous agentic pentesting and reach Terra's buyers through an existing footprint…
  • Rapid7, Tenable, or another exposure-management platform could add continuous agentic pentesting and reach Terra's buyers through an existing footprint.
  • AI red-teaming specialists such as Dreadnode and Mindgard could deepen on the AI-systems surface faster than Terra, which spreads across four surfaces at once.
  • Terra's reliance on per-customer business-context training could prove a feature rather than a switching cost if agents are quick to retrain elsewhere.
  • The lack of a named public reference customer could stall enterprise deals where buyers require peer validation before purchase.
Problem & Market Terra Security sells into security teams that already run a pentest program and feel the gap between annual manual tests and systems that change continuously. The company argues that gap widens as attackers themselves adopt AI, so testing that happens once or twice a year leaves exposure undiscovered between runs. Press frames the problem rather than only the vendor. Coverage of the Series A describes Terra as scaling offensive security beyond manual and costly methods, positioning continuous validation as the response to a testing cadence buyers already find too slow…

Terra Security sells into security teams that already run a pentest program and feel the gap between annual manual tests and systems that change continuously. The company argues that gap widens as attackers themselves adopt AI, so testing that happens once or twice a year leaves exposure undiscovered between runs.

Press frames the problem rather than only the vendor. Coverage of the Series A describes Terra as scaling offensive security beyond manual and costly methods, positioning continuous validation as the response to a testing cadence buyers already find too slow. [s1, s3, s4]

Product Capabilities Terra Platform deploys a swarm of fine-tuned AI agents that the company describes as designed to think and act like ethical hackers, with a human-on-the-loop approving steps that could affect production. Terra validates each finding through real exploitation rather than a hypothetical severity score, and trains agents on a customer's business context so results map to that organization's risk profile. The platform spans four surfaces: web applications, external networks, internal applications and infrastructure, and customers' own AI systems through red teaming. Ctech reports the platform runs dozens of AI agents, and SecurityWeek relays Terra's description of a swarm of AI agents continuously running thousands of tests. The Terra Offensive Research Collaboration Hub, which the company's blog shortens to TORCH, gives security teams a place to work directly with the agents and control every step of the process…

Terra Platform deploys a swarm of fine-tuned AI agents that the company describes as designed to think and act like ethical hackers, with a human-on-the-loop approving steps that could affect production. Terra validates each finding through real exploitation rather than a hypothetical severity score, and trains agents on a customer's business context so results map to that organization's risk profile.

The platform spans four surfaces: web applications, external networks, internal applications and infrastructure, and customers' own AI systems through red teaming. Ctech reports the platform runs dozens of AI agents, and SecurityWeek relays Terra's description of a swarm of AI agents continuously running thousands of tests. The Terra Offensive Research Collaboration Hub, which the company's blog shortens to TORCH, gives security teams a place to work directly with the agents and control every step of the process. [s1, s2, s3, s6, s8, s14, s17]

Competitive Positioning Terra's central bet, stated on its own pages, is consolidation: replacing the separate scanners and point tools teams buy per surface with one agentic platform that spans web, network, infrastructure, and AI red teaming. That breadth is the positioning and also the exposure. Each surface Terra spans has an established specialist, and the specialists are converging on Terra's own method. ProjectDiscovery markets Neo as a platform of autonomous AI agents that pentest every app, Dreadnode sells AI infrastructure for security agents spanning AI red teaming and penetration testing, and Mindgard sells automated AI red teaming for AI systems and agents. The larger competitive pressure comes from exposure-management platforms: Rapid7 markets attack-surface visibility with proactive exposure mitigation across hybrid environments, and Tenable positions its platform as exposure management for the AI era. Either could add continuous agentic pentesting as a feature and reach Terra's buyers through an existing footprint…

Terra's central bet, stated on its own pages, is consolidation: replacing the separate scanners and point tools teams buy per surface with one agentic platform that spans web, network, infrastructure, and AI red teaming. That breadth is the positioning and also the exposure.

Each surface Terra spans has an established specialist, and the specialists are converging on Terra's own method. ProjectDiscovery markets Neo as a platform of autonomous AI agents that pentest every app, Dreadnode sells AI infrastructure for security agents spanning AI red teaming and penetration testing, and Mindgard sells automated AI red teaming for AI systems and agents. The larger competitive pressure comes from exposure-management platforms: Rapid7 markets attack-surface visibility with proactive exposure mitigation across hybrid environments, and Tenable positions its platform as exposure management for the AI era. Either could add continuous agentic pentesting as a feature and reach Terra's buyers through an existing footprint. [s1, s2, s9, s10, s11, s12, s13]

Go-to-Market & Traction Terra's capital and endorsements are strong and specific…

Terra's capital and endorsements are strong and specific. A $30 million Series A led by Felicis, with Dell Technologies Capital, SVCI, SYN Ventures, FXP, and Underscore VC, followed an $8M seed whose angels included a former Google security chief and the founders of Talon Security. Terra also won a 2025 accelerator backed by two platform vendors.

The customer proof is thinner than the capital. Terra states it serves Fortune 500 clients but names none on the record, so the strongest disclosed traction is the quality of the investor and angel group rather than a buyer speaking in its own voice. For a company selling into security teams that scrutinize references, the absence of a named customer is the evidence a prospective buyer should press on. [s3, s4, s5, s15, s16]

Team & Credibility Terra was founded in 2024 by CEO Shahar Peled and CTO Gal Malachi, and press names both as co-founders running a company of roughly two dozen people across Israel and the United States at the time of the Series A. What the public record does not yet show is a verifiable prior exit or a sustained in-domain publication record for either founder. The investor and angel group vouches for the team indirectly, but the founders' own public track record does not yet include a named prior build or exit…

Terra was founded in 2024 by CEO Shahar Peled and CTO Gal Malachi, and press names both as co-founders running a company of roughly two dozen people across Israel and the United States at the time of the Series A.

What the public record does not yet show is a verifiable prior exit or a sustained in-domain publication record for either founder. The investor and angel group vouches for the team indirectly, but the founders' own public track record does not yet include a named prior build or exit. [s4, s7]

Trust Readiness Terra operates a human-on-the-loop control model precisely because autonomous offensive testing against production carries risk, and the company positions that human checkpoint as its safety and compliance guarantee. The platform's stated purpose is to run continuously without breaking the systems it tests. The cited Terra homepage and Series A post, reviewed July 10, 2026, do not document a trust center, third-party security attestation, or compliance certification for Terra. Enterprise buyers evaluating a tool that actively exploits their systems will look for that collateral, and its absence from the public record is a readiness gap to weigh against the company's stage…

Terra operates a human-on-the-loop control model precisely because autonomous offensive testing against production carries risk, and the company positions that human checkpoint as its safety and compliance guarantee. The platform's stated purpose is to run continuously without breaking the systems it tests.

The cited Terra homepage and Series A post, reviewed July 10, 2026, do not document a trust center, third-party security attestation, or compliance certification for Terra. Enterprise buyers evaluating a tool that actively exploits their systems will look for that collateral, and its absence from the public record is a readiness gap to weigh against the company's stage. [s1, s3]

Competitors ProjectDiscovery, Dreadnode, Mindgard, Rapid7…
Company Relationship Note Compare
ProjectDiscovery competes with Markets Neo, a platform of autonomous AI agents that pentest applications, overlapping Terra's agentic pentesting approach directly. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Dreadnode competes with Sells AI infrastructure for security agents spanning AI red teaming and penetration testing, overlapping Terra's AI-systems testing. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Mindgard competes with Provides automated AI red teaming, competing for Terra's AI red-teaming capability. N/AThese companies operate in different domains, so the scores reflect readiness in different markets.
Rapid7 adjacent An exposure-management platform positioned to absorb continuous pentesting into an existing security footprint.

Add analyzed competitors to compare them side by side with Terra Security.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 13 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

Terra’s moat today is accountability rather than accumulation. A credentialed pentester signs each report in a form auditors accept, which lifts the product above scanners a customer runs alone, and Fortune-scale buyers put procurement and legal review between an incumbent and its replacement. Nothing else in the public record compounds on its own. Public sources name no cross-customer attack dataset behind the agents. The ISO 27001 and SOC 2 Type 2 badges on Terra’s site are certifications a funded rival can also obtain, and the product runs outside the production path, so a customer who cancels loses coverage rather than operations. The thing for a buyer to watch is whether the supervising-professional model keeps pace as the customer count grows.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 2/3 Terra assigns each client target a credentialed security professional who owns the engagement, and the deliverable is an audit-ready report signed by certified pentesters and accepted by compliance auditors, so code and expertise blend in what the customer buys.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Continuous engagements accumulate findings history, remediation workflow wiring, and agents tuned to each organization’s profile, meaningful friction to re-create with a rival, while no network effect or data-residency lock appears in the record.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 The ISO 27001, SOC 2 Type 2, GDPR, and HIPAA marks on Terra’s site are self-displayed badge images with no inspectable trust portal found by probe as of 2026-07-07, assurance that eases procurement rather than blocking a determined replacement.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Orchestrating swarms of exploitation agents that run thousands of tests tailored to each organization, gated by humans against production damage, is specialist offensive-security engineering, and Terra’s researchers showed the bench by finding CVE-2026-25724 in Anthropic’s Claude Code.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3 Press reports Fortune 100 clients and the seed announcement cited Fortune 500 companies, buyers whose purchases pass procurement and legal review, while the named public references are CISO endorsements on the vendor’s own pages.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 Terra Platform is offensive-security tooling with a portal that security teams work in, a platform with application features that runs outside the production path rather than infrastructure other applications depend on.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 Agents are tuned per customer on that organization’s context, and no named cross-customer attack corpus or non-public dataset appears in the public record, so a funded rival could reach parity by building and hiring.
Strategic Market Segmentation Terra sells continuous penetration testing to enterprise security teams that already buy pentests, an entry through an established budget line rather than a new category pitch. Press coverage places its earliest customers at the top of that market. Ctech reports 25 employees serving Fortune 100 clients, and the seed announcement cited Fortune 500 companies among early clients. The segment has widened with the product. Terra started with web applications, added an AI penetration-testing module in February 2026 after months of testing copilots and AI-built applications, and opened a network-infrastructure public preview in May 2026. The company now describes itself as a pioneer in agentic continuous threat exposure management, so it sells against consolidated exposure-management budgets rather than against tools bought one attack surface at a time. The buyer inside the enterprise is the team that owns the pentest program and its audit obligations. Terra’s homepage promises audit-ready reports signed by certified pentesters, language aimed at buyers who must hand pentest evidence to auditors as much as at engineers who fix the findings…

Terra sells continuous penetration testing to enterprise security teams that already buy pentests, an entry through an established budget line rather than a new category pitch. Press coverage places its earliest customers at the top of that market. Ctech reports 25 employees serving Fortune 100 clients, and the seed announcement cited Fortune 500 companies among early clients.

The segment has widened with the product. Terra started with web applications, added an AI penetration-testing module in February 2026 after months of testing copilots and AI-built applications, and opened a network-infrastructure public preview in May 2026. The company now describes itself as a pioneer in agentic continuous threat exposure management, so it sells against consolidated exposure-management budgets rather than against tools bought one attack surface at a time.

The buyer inside the enterprise is the team that owns the pentest program and its audit obligations. Terra’s homepage promises audit-ready reports signed by certified pentesters, language aimed at buyers who must hand pentest evidence to auditors as much as at engineers who fix the findings.

Product Capabilities & AI Advantages Terra Platform attacks four surfaces, web applications, external networks, internal infrastructure, and customers’ AI systems, with what the company describes as a swarm of fine-tuned AI agents. SecurityWeek relays Terra’s claim that the agents continuously run thousands of advanced tests tailored to each organization’s profile, and a human checkpoint approves steps that could disturb production. The company’s offensive research is the strongest public evidence of technical depth. Terra researchers discovered CVE-2026-25724, a permission-control bypass in Anthropic’s Claude Code that Anthropic fixed after disclosure, and the February 2026 research release reported AI-related vulnerabilities in 100% of tested applications embedding AI chats or copilots. Terra shipped its AI penetration-testing module in response to that testing. Terra’s differentiation claim is that findings are exploited for real before they are reported, so the customer sees demonstrated risk rather than a severity guess. The network launch extended that model to infrastructure as a public preview in May 2026, with verified findings across web, AI, and network appearing in one view. A platform that watches its agents’ attacks succeed and fail across many customer environments could accumulate cross-customer attack-technique telemetry that no single tenant could match. The public record does not yet evidence such an asset, so it stays a latent path rather than a current advantage…

Terra Platform attacks four surfaces, web applications, external networks, internal infrastructure, and customers’ AI systems, with what the company describes as a swarm of fine-tuned AI agents. SecurityWeek relays Terra’s claim that the agents continuously run thousands of advanced tests tailored to each organization’s profile, and a human checkpoint approves steps that could disturb production.

The company’s offensive research is the strongest public evidence of technical depth. Terra researchers discovered CVE-2026-25724, a permission-control bypass in Anthropic’s Claude Code that Anthropic fixed after disclosure, and the February 2026 research release reported AI-related vulnerabilities in 100% of tested applications embedding AI chats or copilots. Terra shipped its AI penetration-testing module in response to that testing.

Terra’s differentiation claim is that findings are exploited for real before they are reported, so the customer sees demonstrated risk rather than a severity guess. The network launch extended that model to infrastructure as a public preview in May 2026, with verified findings across web, AI, and network appearing in one view.

A platform that watches its agents’ attacks succeed and fail across many customer environments could accumulate cross-customer attack-technique telemetry that no single tenant could match. The public record does not yet evidence such an asset, so it stays a latent path rather than a current advantage.

Sales Engagement & Go-to-Market Terra’s visible go-to-market strategy concentrates on Amazon…

Terra’s visible go-to-market strategy concentrates on Amazon. In March 2026 the company announced AWS Security Competency status in application security and presented itself as the inaugural partner approved for the newly launched autonomous security validation use case, alongside an AI competency and a listing in AWS’s marketplace. Days later Terra hired Anna Sarnek, who previously led cyber-startup and venture-capital business development at AWS, as vice president of business and strategy for what the announcement calls ecosystem-led growth.

An accelerator win reinforces the channel story. Terra won the 2025 CrowdStrike/AWS/NVIDIA cybersecurity accelerator, and its release boilerplate now lists Capital One Ventures among its backers alongside the announced Series A syndicate.

Customer proof is improving but still leans on the vendor’s own pages. Riskified’s CISO, Yossi Yeshua, endorses the model on Terra’s site alongside other named security leaders and an unnamed Fortune 100 security director, while the press corroboration remains Ctech’s report that Terra already serves Fortune 100 clients. At 25 people, with the founders still writing the launch posts, the Sarnek appointment is the one named senior addition on the commercial side so far.

Pricing Model Terra publishes no pricing…

Terra publishes no pricing. A probe of the site as of 2026-07-07 found no price list, and the calls to action route to demo requests, the pattern of negotiated enterprise deals rather than self-serve adoption.

The value framing prices Terra against the manual pentest budget rather than a scanner subscription. The homepage sells audit-ready signed reports and continuous coverage, and the customer outcome the vendor displays is a Fortune 100 security director reporting that Terra doubled the web-application attack surface tested without doubling costs, a vendor-displayed claim rather than independent reporting.

The AWS marketplace listing adds a second procurement path, letting enterprise buyers transact through committed cloud spend. Which unit Terra charges by, per application, per surface, or per engagement, does not appear in the public record.

Product Delivery & Operations Delivery pairs software with named human accountability…

Delivery pairs software with named human accountability. Terra describes assigning each client target a credentialed, experienced security professional who owns the testing engagement, while agents carry reconnaissance and routine execution and a human approves actions that could affect production.

The platform closes the loop from finding to fix. Terra Portal is where security teams work with the agents and control runs, findings verified for exploitability arrive in a single connected view across web, AI, and network, and the company markets a remediation workflow that takes a confirmed vulnerability to a verified fix. The audit-ready reporting doubles as compliance evidence customers keep continuously current.

The operational model keeps humans in the loop. A supervising professional oversees each engagement, and Ctech’s September 2025 report of 25 employees serving Fortune 100 clients implies the model ran lean at that headcount.

Earning Customers' Trust Trust signals are present but thin for a vendor whose agents attack production systems. The homepage displays ISO 27001, SOC 2 Type 2, GDPR, and HIPAA badge images, and no inspectable trust portal or report was found by a probe of the trust and security subdomains and the /trust and /security paths as of 2026-07-07, so the public evidence is self-displayed badges. The safety argument is the human checkpoint. Terra positions human-on-the-loop approval as the guarantee that continuous testing does not break the systems it tests, and the signed report gives the customer a named professional accountable for what ships. Terra’s public disclosure record supports the trust story. The company reported CVE-2026-25724 to Anthropic, which fixed it, and published its analysis of the flaw…

Trust signals are present but thin for a vendor whose agents attack production systems. The homepage displays ISO 27001, SOC 2 Type 2, GDPR, and HIPAA badge images, and no inspectable trust portal or report was found by a probe of the trust and security subdomains and the /trust and /security paths as of 2026-07-07, so the public evidence is self-displayed badges.

The safety argument is the human checkpoint. Terra positions human-on-the-loop approval as the guarantee that continuous testing does not break the systems it tests, and the signed report gives the customer a named professional accountable for what ships.

Terra’s public disclosure record supports the trust story. The company reported CVE-2026-25724 to Anthropic, which fixed it, and published its analysis of the flaw.

Platform Strategy & Ecosystem Positioning Terra is building its ecosystem position almost entirely inside AWS…

Terra is building its ecosystem position almost entirely inside AWS. The company holds AWS Security and AI competencies, a listing in AWS’s marketplace, the 2025 CrowdStrike/AWS/NVIDIA accelerator win, and a vice president hired from AWS’s cyber-startup organization. The alignment runs deep for a company founded in 2024, and it concentrates the channel in a single cloud.

The platform ambition is consolidation. Terra’s own blog argues for replacing the separate tools teams buy for each attack surface with one offensive-security product spanning web, AI, and network, a platform strategy in the product sense. The ecosystem around it, marketplace transactions and partner-led distribution, is still early beyond Amazon.

Public sources document no MSSP program, reseller network, or second marketplace, so buyers today encounter Terra mainly through its own selling and Amazon’s endorsement.

Team & Execution Capability Terra was founded in 2024 by CEO Shahar Peled and CTO Gal Malachi and employed 25 people across Israel and the United States as of Ctech’s September 2025 report. Public sources introduce the founders by role rather than by prior company and document no earlier exit for either. The offensive bench shows up in output rather than in bios. The company’s researchers found and disclosed CVE-2026-25724 in Anthropic’s Claude Code, and its head of offensive security publishes the research openly. The senior layer is thickening around the founders. Anna Sarnek joined from AWS as vice president of business and strategy after a year advising the company, and the seed round’s angels included a former Google security chief and the founders of Talon Security, an investor bench that vouches for the team where the founders’ own track record is not yet public…

Terra was founded in 2024 by CEO Shahar Peled and CTO Gal Malachi and employed 25 people across Israel and the United States as of Ctech’s September 2025 report. Public sources introduce the founders by role rather than by prior company and document no earlier exit for either.

The offensive bench shows up in output rather than in bios. The company’s researchers found and disclosed CVE-2026-25724 in Anthropic’s Claude Code, and its head of offensive security publishes the research openly.

The senior layer is thickening around the founders. Anna Sarnek joined from AWS as vice president of business and strategy after a year advising the company, and the seed round’s angels included a former Google security chief and the founders of Talon Security, an investor bench that vouches for the team where the founders’ own track record is not yet public.

Sources

Company Detail Sources (4)
Id Source Tier Accessed
f1 https://www.terra.security official 2026-07-10
f2 https://www.calcalistech.com/ctechnews/article/awdq1yv5k press 2026-06-24
f3 https://www.prnewswire.com/il/news-releases/terra-security-raises-8m-in-seed-round-for-its-agentic-ai-pen-testing-solution-302434301.html press 2026-06-24
f4 https://www.terra.security official 2026-06-24
Profile Analysis Sources (17)
Id Source Tier Accessed
s1 Terra Security: Agentic Offensive Security Platform
“Terra Platform unifies continuous agentic pentesting across AI systems, external networks, and web apps, with a Human-on-the-Loop to ensure production safety and compliance.”
official 2026-07-10
s2 Terra Security Blog: Insights
“Terra Platform is the first agentic Offensive Security platform to cover network, web, and internal app pentesting, as well as AI red teaming.”
official 2026-07-10
s3 Terra Security Raises $30M Series A From Felicis
“Terra combines a swarm of fine-tuned AI agents, each designed to think and act like ethical hackers, with expert human oversight to continuously test an organization's full attack surface.”
official 2026-07-10
s4 Ctech: AI startup Terra Security raises $30M Series A for continuous penetration testing
“Terra Security, a provider of AI-driven penetration testing platforms, has raised $30 million in Series A funding. The round was led by Felicis, with participation from Dell Technologies Capital, SVCI, and existing investors SYN Ventures, Lama Partners (FXP), and Underscore VC.”
press 2026-07-10
s5 PR Newswire: Terra Security raises $8M in Seed round for its agentic AI pen testing solution
“raises $8M in a seed round led by SYN Ventures and FXP Ventures with participation from Underscore VC and notable angel investors including former Google CISO Gerhard Eschelback and Ofer Ben-Noon and Ohad Bobrov, founders of Talon Security”
press 2026-07-10
s6 SecurityWeek: Terra Security Raises $30 Million for AI Penetration Testing Platform
“According to Terra, the solution uses a swarm of AI agents that continuously run thousands of advanced tests tailored to each organization's unique profile.”
press 2026-07-10
s7 Ctech: Terra founders and headcount
“Founded in 2024 by CEO Shahar Peled and CTO Gal Malachi, Terra employs 25 people in Israel and the United States and already serves Fortune 100 clients.”
press 2026-07-10
s8 Terra Security homepage: Terra Offensive Research Collaboration Hub
“The Terra Offensive Research Collaboration Hub lets you work directly with Terra agents, and control every step of the process.”
official 2026-07-10
s9 ProjectDiscovery: Neo autonomous AI pentesting platform (competitor page)
“Introducing Neo by ProjectDiscovery, a platform of autonomous AI agents that pentest every app, review every PR, manage your vulnerability backlog, and retest every fix.”
official 2026-07-10
s10 Dreadnode: AI Infrastructure for Security Agents (competitor page)
“AI red teaming, penetration testing, and vulnerability research at machine speed and scale.”
official 2026-07-10
s11 Mindgard: Automated AI Red Teaming and Security Testing (competitor page)
“The Mindgard AI security platform discovers exploits, assesses risk, and defends AI systems and agents.”
official 2026-07-10
s12 Rapid7: The Command Platform, Exposure Command (competitor page)
“Attack surface visibility with proactive exposure mitigation and remediation prioritization across your hybrid environment.”
official 2026-07-10
s13 Tenable: Vulnerability and exposure management (competitor page)
“Exposure management for the AI era”
official 2026-07-10
s14 Ctech: Terra platform powered by dozens of AI agents
“Terra has developed a platform for continuous penetration testing powered by dozens of AI agents.”
press 2026-07-10
s15 PR Newswire: Terra seed announcement, Fortune 500 clients
“Already serving multiple clients, including Fortune 500 companies, Terra will use the funds to advance its platform”
press 2026-07-10
s16 Terra Security Series A post: accelerator win
“Won the 2025 CrowdStrike & AWS Cybersecurity Accelerator in collaboration with Nvidia”
official 2026-07-10
s17 Terra Security Blog: TORCH announcement
“Terra Offensive Research Collaboration Hub (TORCH) is the first software built to enable human and agent collaboration in pentesting.”
official 2026-07-10
Deep-Dive Sources (14)
Id Source Tier Accessed
s1 Terra Security: Agentic Offensive Security Platform
“Audit-ready reports, signed by certified pentesters, accepted by the highest compliance standards.”
official 2026-07-07
s2 Terra Security: About, Our Story
“Empower enterprises with continuous Offensive Security at scale, combining AI with human judgment and the business context needed to reduce exposure dwell time.”
official 2026-07-07
s3 Terra Security: Terra Security Raises $30M Series A From Felicis
“has raised a $30M Series A round, led by Felicis with participation from Dell Technologies Capital, SVCI, and existing investors SYN Ventures, LAMA Partners (FKA FXP), and Underscore VC. This brings Terra’s total funding to date to $38M.”
official 2026-07-07
s4 Ctech: AI startup Terra Security raises $30M Series A for continuous penetration testing
“Founded in 2024 by CEO Shahar Peled and CTO Gal Malachi, Terra employs 25 people in Israel and the United States and already serves Fortune 100 clients.”
press 2026-07-07
s5 SecurityWeek: Terra Security Raises $30 Million for AI Penetration Testing Platform
“According to Terra, the solution uses a swarm of AI agents that continuously run thousands of advanced tests tailored to each organization’s unique profile.”
press 2026-07-07
s6 PR Newswire: Terra Security raises $8M in Seed round for its agentic AI pen testing solution
“including former Google CISO Gerhard Eschelback and Ofer Ben-Noon and Ohad Bobrov, founders of Talon Security, Travis McPeak and Itamar Friedman. Already serving multiple clients, including Fortune 500 companies”
press 2026-07-07
s7 Terra Security: Terra Security Becomes First AWS Partner to Achieve Security Competency for Autonomous Security Validation, March 2026
“it has achieved Amazon Web Services (AWS) Security Competency status in the Application Security category, including Static Code Analysis and Autonomous Security Validation. Terra is the first AWS partner approved for the newly launched Autonomous Security Validation use case.”
official 2026-07-07
s8 Terra Security: Terra Security Appoints Anna Sarnek as Vice President of Business & Strategy to Accelerate Ecosystem-Led Growth, March 2026
“the appointment of Anna Sarnek as Vice President of Business & Strategy. Sarnek has served as a strategic advisor to Terra over the past year, helping shape the company’s strategic direction, growth trajectory, and ongoing partnership with Amazon Web Services (AWS).”
official 2026-07-07
s9 Terra Security: Terra Security Finds Widespread Exploitable Flaws in AI-Driven Applications, Copilots, and AI-Generated Code, February 2026
“The research has identified that in 100% of applications that embed AI chats or copilots, AI-related security vulnerabilities were discovered.”
official 2026-07-07
s10 Terra Security: Terra Security Redefines Penetration Testing for the AI Era with Terra Portal
“Winner of the 2025 CrowdStrike/AWS/NVIDIA Cybersecurity Accelerator, and backed by SYN Ventures, Felicis, Lama Partners, SVCI, Underscore VC, Dell Technologies Capital, and Capital One Ventures.”
official 2026-07-07
s11 Terra Security: When AI Becomes the Attack Surface: CVE-2026-25724
“CVE-2026-25724 was discovered in Anthropic’s Claude Code by Terra Security Researchers.”
official 2026-07-07
s12 Terra Security: The Human Behind the Machine: What Human-in-the-Loop Really Means at Terra Security
“Yossi Yeshua, Riskified’s CISO, highlighted how the combination of agentic AI and human oversight delivers the depth and scale a modern security organization needs while increasing accuracy and vulnerability validation.”
official 2026-07-07
s13 Terra Security: Network Pentesting Launch for Web Apps, AI Systems, and Infrastructure, May 2026
“today announced the public preview of continuous exploitation validation for network infrastructure, available immediately to all customers within the Terra Platform”
official 2026-07-07
s14 Probe 2026-07-07 via curl: homepage badge alts ISO 27001, SOC 2 Type 2, GDPR, HIPAA. No trust portal at trust./security. subdomains, /trust, /security, /pricing other 2026-07-07

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.