All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This analysis draws mostly on the vendor's own published materials, with limited outside corroboration.
Valence Security makes security software for the SaaS and AI applications an enterprise runs. Its platform, sold to enterprise security and identity teams, discovers those applications, flags risky settings and app-to-app integrations, detects identity threats, and automates the fixes. Founded in 2021, Valence has raised $32 million, most recently a 2022 Series A led by M12, Microsoft's corporate venture arm. It has not disclosed further funding since that round. In a Valence case study, customer ServiceTitan used Valence policies to revoke over 80% of its inactive integrations between SaaS applications within six months. A customer that replaces Valence has to recreate the automated policies it built on the platform, such as those revocation rules.
| Description | Valence Security secures SaaS and AI environments, unifying SaaS discovery, posture management, AI governance, and identity threat detection to find and remediate risks across business applications. | [f1] |
|---|---|---|
| Founded | 2021 | [f2] |
| HQ | Roots in Israel | [f3] |
| Funding | $32M total | [f2] |
| Latest funding | Series A ($25M, October 2022, led by M12) | [f2] |
| Product | What it does |
|---|---|
| Valence SaaS Security Platform | A platform combining SaaS discovery, SaaS security posture management (SSPM), AI governance, risk remediation, and identity threat detection and response (ITDR) for business applications. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
The Valence SaaS Security Platform discovers SaaS applications, surfaces misconfigurations and compliance gaps, governs AI usage, and detects identity threats across human and service accounts. These capabilities are mapped to the Cyber Defense Matrix. [f1]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | The quantified figures (over 150 SaaS apps per enterprise, roughly half of security teams unable to protect the supply chain) are generic market statistics relayed by a single TechCrunch article (s4), short of quantified pain corroborated across multiple independent non-vendor sources. [s2, s4] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 3/5 | Platform pages describe concrete mechanisms across SaaS discovery, SSPM, AI governance, risk remediation, and ITDR, but the public evidence is vendor marketing rather than deep architecture documentation or independent technical evaluation. [s2, s1] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | The crowded SSPM market (s5) and the 2023 RSA Innovation Sandbox finalist placement predate the recent demand window, and the agentic-era driver rests on Valence's own repositioning (s1, s2) rather than independently corroborated recent buyer demand. [s5, s4, s1, s2, s8] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 | Co-founder Yoni Shohet's prior build, SCADAfence (s3, s4), is a single venture in the adjacent operational-technology security domain with no exit or publication record cited. [s3, s4] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 | Valence names one reference customer (ServiceTitan, s6) in a vendor-hosted case study without independent corroboration, and the Microsoft M12 and Akamai backing (s4) supports a small indirect-signal adjustment that holds it at one named customer rather than the multiple-reference bar. [s6, s1, s4] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 2/5 | The $32 million total rests on an October 2022 Series A (s4, s5) with no financing disclosed in roughly three and a half years and no disclosed revenue or growth step-change, a stale raise past a normal cycle. [s4, s5, s7] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Valence fits SaaS security posture management, an established category a press account placed it in by name, and the company was a 2023 RSA Innovation Sandbox finalist, a third-party placement inside that recognized slot. [s5, s1, s2, s8] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 2/5 | SaaS discovery, posture, AI governance, and identity detection is a plausible feature addition for the identity, cloud, and posture platforms already next to the buyer, including Microsoft, whose M12 funded Valence and whose Microsoft 365 estate Valence secures, so no proprietary moat surfaces that bundling alone would not replicate. [s2, s4] |
Valence addresses the gap that opened when business units adopted SaaS faster than security teams could govern it. TechCrunch cites figures that large enterprises run more than 150 SaaS applications, each a target for misconfiguration, risky third-party integrations, and identity abuse.
The pain is concrete and corroborated rather than a marketing generality. A survey reported by TechCrunch found just over half of IT security teams report being able to protect their software supply chain, leaving a large remainder exposed and placing the problem in a budget line security leaders already recognize.
A second front has opened on top of that SaaS pain. Enterprises now route data through GenAI tools and grant autonomous agents access to business applications, an AI surface Valence has repositioned its platform to discover and govern. [s4, s2, s1]
The Valence SaaS Security Platform runs several functions on one product. It discovers SaaS applications and the human and service identities using them, applies SaaS security posture management to surface prioritized misconfigurations and compliance gaps, and governs AI usage including shadow AI and agents.
The platform pairs that visibility with risk remediation and identity threat detection and response, which Valence presents as collaborative, workflow-driven remediation rather than findings alone.
The public evidence for these mechanisms is vendor product pages rather than deep architecture documentation or independent technical evaluation, so the capabilities are described clearly but not independently validated in the sources reviewed. [s2, s1]
Valence sits in an established category it can name without coaching, which is both its strength and its exposure. SaaS security posture management is a slot buyers and analysts place readily, and Valence's 2023 RSA Innovation Sandbox finalist placement marks it inside that slot.
The same maturity invites consolidation pressure. A press account placed Valence in a lucrative but crowded SSPM market shared with several pure-play rivals, and platform vendors next to that buyer can fold SaaS posture management into a broader suite or acquire a pure-play to enter the category.
Valence's response is to push into the agentic-AI layer before incumbents reach it. The structural tension is that its lead investor is Microsoft's M12 while Valence's platform secures the Microsoft 365 estate Microsoft sells, so the same company is both a backer and an ecosystem owner whose roadmap could reach into the category. [s5, s1, s2, s4, s8]
Valence shows real traction, though much of it is vendor-presented. A published case study describes ServiceTitan automatically revoking over 80% of inactive SaaS-to-SaaS integrations within six months using the platform, a named customer with a measured outcome.
The funding motion carries strategic weight. Microsoft's M12 led the Series A with participation from Akamai Technologies, Porsche Ventures, YL Ventures, and former Symantec CEO Michael Fey, signaling investor confidence from inside the security industry.
The gap is buyers speaking independently. The customer evidence is framed by Valence rather than corroborated by third-party reporting in the sources reviewed, so the depth of recent traction is harder to verify than the case study suggests. [s6, s4, s7]
Valence's founders carry a verifiable prior build in security. Co-founder and CEO Yoni Shohet previously co-founded SCADAfence, an industrial and operational-technology security company, giving him a track record of building a security business before Valence.
Co-founder and CTO Shlomi Matichin is publicly named and speaks for the company in press coverage. The Series A backing from Microsoft's M12 and Akamai reflects industry-insider confidence in that founding team rather than financial investors alone. [s3, s4]
Valence presents as an enterprise-ready vendor, with a published case study showing ServiceTitan running the platform across core SaaS applications including Salesforce, Workday, and Snowflake in production.
The cited record does not document specific compliance attestations or an independent security evaluation, so those certifications are not verified. The named enterprise deployment is the strongest available readiness signal in the reviewed evidence rather than a named attestation. [s6, s2]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Obsidian Security | competes with | ||
| Reco | competes with | ||
| Grip Security | competes with | ||
| AppOmni | competes with | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. | |
| Adaptive Shield | competes with | ||
| Wing Security | competes with | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
Add analyzed competitors to compare them side by side with Valence Security.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
pivot urgently
Valence's durability is thin and mostly operational. Its capabilities, from discovery and posture management to AI governance and threat detection, are configurable software a rival could rebuild. The record shows no proprietary cross-customer dataset that compounds as Valence adds customers, so on the evidence each new customer brings revenue but no data asset a rival lacks. What holds a customer is the effort of wiring Valence into automated remediation and offboarding, which ServiceTitan's revocation of over 80 percent of inactive integrations shows. Dropping it costs coverage rather than breaking operations. SOC 2 Type II eases procurement but blocks no substitute. Identity and cloud platforms next to the same buyer could fold SaaS and AI posture into what they already sell.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Valence sells software that customers configure and operate across discovery, posture management, AI governance, remediation, and identity threat detection. Onboarding assistance aside, the automation output is the product rather than a managed service that accepts accountability for security outcomes. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Once a security team wires Valence into automated remediation and offboarding, as ServiceTitan did across its core applications and platform teams, reabsorbing that policy and integration work is expensive in effort. The lock is operational, since no data residency or network dependency binds the customer. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | Valence's trust center attests SOC 2 Type II and offers penetration test summaries on request, which ease enterprise procurement. The cited record identifies no product-specific mandate for SaaS or AI posture management, and a funded rival can earn the same attestation, so the mark assures buyers rather than blocks replacement. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 2/3 | Discovering SaaS and AI usage, baselining identities, and automating remediation across a broad catalog of applications is meaningful integration and detection engineering. The public evidence is vendor product material without independent technical validation, and it reads as standard visibility and governance work rather than the brittle inline automation a higher mark requires. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 | Valence's platform page names several enterprise customers, a detailed ServiceTitan deployment across its core business applications plus testimonials from several other named enterprises, and its backing includes Microsoft's M12. The enterprise buyers it addresses place procurement and security review between Valence and any replacement, but with one detailed production reference and lighter testimonials, the named base reflects the buyer identity it targets more than a demonstrated retention hold. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Valence runs as a discovery, posture, and governance overlay on the SaaS and AI estate, and its identity threat detection adds automated response. Removing it costs a customer visibility and coverage rather than breaking SaaS operations, so it sits beside the applications it secures rather than in their production path. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | The visible assets are a library of application connectors and detection policies that a funded rival could rebuild. No named non-public dataset or cross-customer telemetry advantage appears in the public record, so signing customers adds revenue without compounding a data asset competitors lack. |
Valence targets enterprises where SaaS and AI adoption has outrun the security team's ability to govern it. The buyers are security and identity operations groups accountable for applications the business bought without them and for the human and machine identities scattered across those applications. The entry pain is concrete: risky application-to-application integrations, misconfigurations, and accounts that sit outside single sign-on.
The ServiceTitan deployment shows the segment in practice. A software enterprise ran Valence across its core business applications, engaging several platform teams and application owners rather than a single administrator. That points Valence at organizations with sprawling SaaS estates and dedicated security staff, not small teams running a handful of tools.
The Valence SaaS Security Platform runs several functions on one product. It discovers SaaS and AI usage, applies posture management to surface and prioritize misconfigurations, governs AI tools and agents, automates remediation through workflows, and detects identity threats across connected applications.
Valence's newer positioning leans on AI. An AI posture module assesses and governs AI tool and AI agent usage, extending the same discovery-and-posture pattern to a new surface as buyers wire generative AI into their applications.
The advantage is workflow breadth rather than data. The public record shows no proprietary dataset that compounds as Valence adds customers, and the connector library and detection rules behind the platform are the kind a funded competitor could reproduce.
Valence sells through a demonstration-led motion aimed at enterprise security teams. Its platform and case-study pages route prospects to schedule a demo rather than to sign up directly, a path that fits negotiated enterprise deals over self-service adoption.
The funding roster doubles as a go-to-market signal. Microsoft's M12 led Valence's Series A, lending a young company credibility with security buyers who weigh who backs a vendor. The published proof of that motion working is concentrated in one detailed customer story rather than a broad, independently reported roster.
Valence does not publish prices on the reviewed pages. The platform and case-study pages show no prices and route prospects to a sales conversation, a pattern that signals large, negotiated contracts rather than transparent or self-service pricing.
Because no figures are public, the unit Valence charges by and whether it commands a premium over adjacent platforms cannot be read from the record. A demonstration-gated, quote-based motion is consistent with an enterprise sale where price follows the size of the customer's application estate.
Valence delivers its platform as SaaS that connects to a customer's applications, then discovers usage, flags risk, and drives remediation from a central console. Customers configure and operate the policies themselves rather than handing operations to Valence.
Onboarding is collaborative. In the ServiceTitan deployment, Valence connected across the customer's applications and worked with its platform teams to turn findings into automated policies, such as revoking inactive integrations. That model spreads the operational load across the customer's own owners rather than centralizing it in a managed service.
Valence presents security as core to the product and backs the claim with an attested posture. Its trust center states SOC 2 Type II compliance and offers penetration test summaries to customers on request, the table-stakes assurances an enterprise security buyer expects.
Beyond the attestation, a named production deployment carries the readiness signal. ServiceTitan runs the platform across its core business applications, which demonstrates enterprise operational fit. No broader certification portfolio surfaces in the public record.
Valence lives on top of the platforms it secures. It connects to a broad catalog of SaaS and AI applications and depends on their APIs for discovery, posture, and remediation, so its reach grows with the connectors it maintains rather than with a platform of its own.
That dependence carries a strategic tension. Microsoft's M12 led Valence's funding, and Microsoft 365 is among the applications Valence secures, so a major ecosystem owner is both an investor and adjacent to the posture work Valence sells. The reviewed record does not document a Microsoft product that provides equivalent SaaS and AI posture management. Valence also markets AI-agent security, extending the same posture pattern to that surface.
Valence's founders bring a prior security build. Chief executive Yoni Shohet co-founded the company after co-launching SCADAfence, an industrial security startup, and chief technology officer Shlomi Matichin co-founded Valence with him. That gives the company a repeat security founder alongside a technical co-founder.
Industry-insider capital reinforces the team signal. Microsoft's M12 led the Series A, backing that reflects confidence from inside the security and platform business rather than generalist investors alone. Shohet's prior venture is the security startup SCADAfence, and the reviewed record shows no exit for either founder.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | https://www.valencesecurity.com/platform | official | 2026-06-24 |
| f2 | TechCrunch: Valence Security Raises New Cash to Secure the SaaS App Supply Chain | press | 2026-06-24 |
| f3 | SecurityWeek: Microsoft M12 Leads $25 Million Valence Security Series A | press | 2026-06-24 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Valence: The Leader in SaaS and AI Security, Built for the Agentic Era | official | 2026-06-24 |
| s2 | Valence: SaaS Application Security Platform “Organizations leverage Valence's combined SaaS discovery, SaaS security posture management (SSPM), AI governance, risk remediation, and identity threat detection and response (ITDR) capabilities to protect business-critical applications and data” | official | 2026-06-24 |
| s3 | About Valence Security: Our Story, Leadership, and Investors | official | 2026-06-24 |
| s4 | TechCrunch: Valence Security Raises New Cash to Secure the SaaS App Supply Chain “raised $25 million in a Series A round led by M12, Microsoft's corporate venture arm, with participation from YL Ventures, Porsche Ventures, Akamai Technologies, Alumni Ventures and former Symantec CEO Michael Fey. The new capital brings the company's total raised to $32 million” | press | 2026-06-24 |
| s5 | SecurityWeek: Microsoft M12 Leads $25 Million Valence Security Series A “The latest funding brings the total raised by Valence Security to $32 million and provides a runway for the company to build out its SSPM (SaaS Security Posture Management) technology in a lucrative but crowded market.” | press | 2026-06-24 |
| s6 | Valence Case Study: How ServiceTitan Streamlines their SaaS Security with Valence “Through easy security policies, ServiceTitan was able to automatically revoke over 50% of inactive SaaS-to-SaaS integrations on day one, with this number increasing to over 80% within six months.” | official | 2026-06-24 |
| s7 | CTech: Cybersecurity Startup Valence Announces $25 Million Series A for Security Remediation Platform “Valence Security, which has developed a SaaS security remediation platform, announced on Wednesday its $25 million Series A round led by Microsoft's M12 venture fund.” | press | 2026-06-30 |
| s8 | DarkReading: AppSec Looms Large for RSAC 2023 Innovation Sandbox Finalists “Valence Security secures cloud workflows using SaaS security posture management (SSPM).” | press | 2026-06-30 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Valence: SaaS Application Security Platform “Organizations leverage Valence's combined SaaS discovery, SaaS security posture management (SSPM), AI governance, risk remediation, and identity threat detection and response (ITDR) capabilities to protect business-critical applications and data” | official | 2026-07-08 |
| s2 | Valence Case Study: How ServiceTitan Streamlines their SaaS Security with Valence “Through easy security policies, ServiceTitan was able to automatically revoke over 50% of inactive SaaS-to-SaaS integrations on day one, with this number increasing to over 80% within six months.” | official | 2026-07-08 |
| s3 | About Valence Security: Our Story, Leadership, and Investors “Yoni Shohet Co-Founder and CEO Shlomi Matichin Co-Founder and CTO” | official | 2026-07-08 |
| s4 | Valence: Security Is Integral To Everything We Do “This comes into effect into ensuring compliance early on with industry standards such as SOC 2 Type II, but also taking the extra mile to ensure security is embedded into everything we do.” | official | 2026-07-08 |
| s5 | TechCrunch: Valence Security Raises New Cash to Secure the SaaS App Supply Chain “A two-time entrepreneur, Shohet previously co-launched SCADAfence, an industrial Internet of Things security startup.” | press | 2026-07-08 |
| s6 | SecurityWeek: Microsoft M12 Leads $25 Million Valence Security Series A “Valence Security has closed a $25 million Series A funding round led by Microsoft's M12 venture fund. The latest funding brings the total raised by Valence Security to $32 million” | press | 2026-07-08 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.