Verax

Security for AI Data SecurityGovernance Risk ComplianceNetwork Security also known as Verax AI, Verax AI Inc.

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2023
Funding $7.6M
Last updated 2026-09-02

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

This analysis draws mostly on the vendor's own published materials, with limited outside corroboration.

Executive Summary

Verax sells a self-hosted appliance that enterprises place between their staff and tools like ChatGPT and Copilot, so a security team can see which AI tools people use and stop sensitive text from reaching them. The product it sells today is not the one it launched with. Its $7.6 million seed round of October 2024 was announced alongside Verax Control Center, a tool for catching wrong or biased answers inside a company's own AI applications. The AWS Marketplace listing still carries that older name and its release notes, at $2,750 a month. No customer is named in the reviewed record, and no later funding round appears in it, so a buyer checking references and staying power starts by asking the vendor.

Sourced Details

Description Verax AI sells a self-hosted enforcement layer that carries employee traffic to generative AI tools, matches each request against identity-aware rules, and blocks or redacts sensitive content before it leaves the corporate network. [f1]
Founded 2023 [f2]
Funding $7.6M total [f2]
Latest funding USD 7.6 million seed round announced 2024-10-30, led by TQ Ventures with five other firms participating [f2]

Products

Product What it does
Verax Protect Enforcement layer deployed inside the customer network that inspects prompts to generative AI tools, applies identity-aware rules, and blocks or redacts sensitive content.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

Verax Protect carries employee traffic to generative AI tools, records which tools appear, allows or blocks them per rule, and inspects prompts for sensitive content before they leave the network. These capabilities are mapped to the AI Defense Matrix. [f3]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Emerging 23 /40 Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Verax states the problem in operational terms: new generative AI tools appear daily inside email, documents and code editors, employees send sensitive material to them, and the controls already in place do not inspect that traffic. It names the buyers as security leaders, infrastructure leaders, and compliance and risk teams. The pain is asserted by the vendor and by one anonymous customer quote, and no cited source sizes it. [s1, s6, s17, s19]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 The vendor's own surfaces carry mechanism-level detail rather than slogans: an ordered rule engine with a catch-all default, sensitivity thresholds on a 0 to 100 scale, condition types including topic similarity and regular expressions, and a marketplace listing that names the runtime as a proxy on a single Ubuntu VM. What the cited record lacks is an outside check on any of it, so the depth is documented and unexamined. [s8, s9, s11, s14, s19]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 The enabler is the arrival of generative AI tools inside ordinary work, which the vendor describes as a daily stream of new tools embedded in email, documents, collaboration platforms and code editors. The founders left Amazon Web Services in 2023 to start the company. The cited record carries no buyer-side demand signal that is documented independently rather than asserted. The window risk is that the platforms already in the network absorb the same inspection. [s20, s6, s18]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 One founder's exit is independently reported: Leo Feinberg co-founded CloudEndure, which Amazon Web Services bought for a reported $250 million, with an earlier sale of AcceloWeb recorded on the company's own page. Oren Gev's prior founder role and engineering leadership rest on the vendor page alone. The exits sit in cloud infrastructure rather than in security or AI, which is why this lands at experienced rather than at recognized standing in this category. [s20, s21, s5]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 3/5 The traction on record is a channel listing rather than a customer roster. Verax Protect is sold on AWS Marketplace at a published monthly price with one-click deployment, which is a real purchase path. No cited source names a customer, and the buyer voice on the site is an unnamed cybersecurity director at a Fortune 2000 company. [s19, s17]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 The disclosed capital is a single $7.6 million seed announced in October 2024, which is proportional to a two-founder company selling into enterprises. Against it, the company shipped a documented product, a marketplace listing, a documentation site and a free assessment offering, and the product on its site today is not the one its launch announcement described. No revenue, margin or growth figure appears in the cited record, so output per dollar stays unconfirmed. [s20, s19, s17, s2]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 A buyer can place the product quickly, because it behaves like data loss prevention pointed at AI tools and sits in a slot security teams already fund. The category itself is unsettled, and Verax's own comparison pages have to argue its difference from broad network platforms before a buyer can decide where it belongs. No independent placement of the company appears in the cited record. [s18, s19, s2]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 2/5 Verax's own comparison page records four platforms already selling this control to the same buyer, naming Palo Alto, Zscaler, Netskope and Microsoft, and argues about inspection depth rather than about whether they do it. What it claims above them is wider tool coverage and reach past the browser, which is engineering work a funded platform can add rather than a position it has to displace. [s18, s19]
Business Risks Verax's own comparison page places Palo Alto, Zscaler, Netskope and Microsoft in the same buying decision, so a buyer already running one of those platforms can switch on an adjacent AI module instead of adding a vendor…
  • Verax's own comparison page places Palo Alto, Zscaler, Netskope and Microsoft in the same buying decision, so a buyer already running one of those platforms can switch on an adjacent AI module instead of adding a vendor.
  • No cited source names a customer of Verax, so a buyer cannot check a reference.
  • The marketplace listing says the application server processes tasks on a third-party foundation model reached through AWS Bedrock, and the rules documentation has topic generation use a language model the customer connects, so part of the AI in the product comes from suppliers.
  • The AWS Marketplace listing describes the earlier Verax Control Center and its release notes, so a buyer arriving through that channel meets a description the current site no longer matches.
  • The disclosed capital is one $7.6 million seed announced in October 2024 and no later round appears in the reviewed record, which is thin for an enterprise sales motion two years on.
  • No attestation Verax itself holds appears on the reviewed trust surfaces, so an enterprise security review starts from a request rather than from published material.
Problem & Market Verax sells against a visibility problem that it frames as an inspection problem…

Verax sells against a visibility problem that it frames as an inspection problem. Its platform pages argue that new generative AI tools arrive daily inside email, documents, collaboration platforms and code editors, that employees send confidential material into them, and that the controls already deployed were not built to read that traffic.

The site names three buyers directly, addressing security leaders, infrastructure leaders, and compliance and risk teams in separate sections. That is a coherent buying committee rather than a single champion, and it puts the purchase in a budget line security teams already hold.

The pain is not sized anywhere in the cited record. The strongest buyer-side statement is an unnamed cybersecurity director at a Fortune 2000 company saying the volume of sensitive data reaching AI tools was larger than expected. That is the vendor quoting an anonymous customer, and no reviewed source quantifies what the exposure costs the buyers Verax addresses. [s6, s1, s19, s17]

Product Capabilities The product is an appliance that carries traffic…

The product is an appliance that carries traffic. Verax states that it sits in the path between users and generative AI tools, that each request is checked against configured rules, that the rule matching earliest in the list applies, and that a default rule catches everything else. The marketplace listing describes the same shape from the infrastructure side: a single virtual machine running Ubuntu, functioning at runtime as a proxy that routes or modifies requests.

Enforcement is graded rather than binary. Rules combine identity, the tool being used, and optional conditions on sensitivity score, topic similarity, keywords or regular expressions. Sensitivity runs on a 0 to 100 scale with three presets and a custom setting, and separate switches strip code and personal data out of requests before they leave. The product's configurable responses are to block, redact, warn, log or escalate. The dashboard shows each interaction with its score, its tool, its user and whatever action was taken.

Part of the AI in the product is supplied rather than built. The marketplace listing states that the application server processes tasks using Anthropic's Claude 3 Sonnet model through AWS Bedrock, in a delivery description that still names the earlier Control Center, and the rules documentation has topic and entity generation run on a language model the customer connects. No cited page describes a model Verax built for the scoring itself.

How traffic reaches the appliance is where the vendor's two surfaces read differently. The architecture page says integration happens at the network layer and no endpoint agent is required. The documentation site publishes a manual endpoint-configuration guide covering installation of a Verax certificate authority and traffic redirection per device, an installer for a Verax endpoint agent on Windows, macOS and Linux, and a note that Claude Code on macOS needs Node.js pointed at that certificate. A buyer should read the agentless claim as one deployment option rather than the whole picture. [s8, s19, s9, s11, s2, s15, s3, s13, s12]

Competitive Positioning Verax competes against products its buyers may already own…

Verax competes against products its buyers may already own. Its own comparison page describes Palo Alto delivering AI security through Prisma SASE with access security, data loss prevention, a browser and agent security, Netskope running real-time inspection of prompts and responses on the same inline proxy used for web and software as a service, Zscaler offering AI governance inside a consolidated platform, and Microsoft governing AI through Purview, Defender for Cloud Apps and Entra.

The argument Verax makes against them is about depth and reach rather than existence. It claims integrations with hundreds of AI tools rather than identification at the browser, reach into native desktop applications and agents that do not route through a web proxy, and the ability to chain off an existing secure web gateway through ICAP so a buyer keeps their platform. It also asserts that Palo Alto's own AI product is browser-only or needs an endpoint agent. Those are the vendor's claims about itself and about rivals, and no cited source tests them.

The narrower set of purpose-built rivals is visible in the shape of Verax's own comparison index, which lists pages against Cyera, Harmonic Security, Lasso Security and Nightfall AI alongside pages against Zscaler and Palo Alto. Choosing to publish against both groups is a statement that the company expects to be evaluated in two different conversations, one against a platform module and one against a specialist. [s18, s24, s2]

Go-to-Market & Traction The commercial evidence is a channel rather than a customer list…

The commercial evidence is a channel rather than a customer list. Verax Protect is listed on AWS Marketplace, delivered as a CloudFormation template launched in one click, and priced at a published $2,750 per month for unlimited usage. That published price lets a buyer size the purchase without a call.

The motion around it is self-service at the top and human below. A free AI risk assessment published on 19 April 2026 runs inside the customer environment, processes all data there, monitors without blocking, and is positioned as the step before prevention. Support is email during United States business hours.

What the record does not contain is a named customer. The buyer voice on the site is anonymous, and the independent coverage of the company is confined to its funding announcement of October 2024. A buyer wanting a reference has to ask for one. [s19, s17, s20, s21]

Team & Credibility One founder has done this before, in a different market…

One founder has done this before, in a different market. Leo Feinberg co-founded CloudEndure, raising $18 million before Amazon Web Services acquired it for a reported $250 million, and the company page adds an earlier sale of AcceloWeb to Limelight Networks. Oren Gev's record, more than twenty years of engineering leadership, a previous founder and chief technology officer role, and engineering leadership at Amazon Web Services, appears on that same page and nowhere independent.

Independent reporting confirms the pair rather than repeating the site. Both the Israeli and the Texas technology press covering the seed round record that the two met at CloudEndure in 2017, that Feinberg was its vice president of product, and that they stayed at Amazon Web Services together until leaving in 2023 to start Verax.

The pedigree is in cloud migration and disaster recovery rather than in security or AI, so it argues for the ability to build and sell enterprise infrastructure rather than for domain standing in this category. The company's own job postings describe hiring a marketing lead to define the category and a senior account executive to own the sales cycle, which reads as a team still assembling its commercial side. [s5, s20, s21]

Trust Readiness The architecture is the trust argument…

The architecture is the trust argument. Verax states that inspection and policy evaluation happen inside the customer's own infrastructure, that prompts and responses are not sent to external services for evaluation, and that retention is configured by the customer. For a buyer whose objection to a cloud service is that prompts would leave the network, that design answers the objection directly.

The compliance language on those pages points outward rather than inward. The security and compliance page says the product helps organizations use AI in alignment with GDPR, SOC 2, ISO 27001, HIPAA and PCI DSS where applicable, which describes what a customer can demonstrate, not what Verax has been assessed against. No attestation the company itself holds appears on the reviewed trust surfaces.

Two smaller signals bear on readiness. The documented minimum for the appliance is a virtual machine with 32 gigabytes of memory and 512 gigabytes of database storage, which is a real infrastructure commitment rather than a browser extension. And the marketplace listing still describes the previous product and its release notes, which suggests the channel material has not kept pace with the repositioning. [s3, s4, s23, s14, s19]

Competitors Harmonic Security, Lasso Security, Nightfall AI, Cyera, Netskope, Zscaler, Palo Alto Networks, Microsoft, Prompt Security…
Company Relationship Note Compare
Harmonic Security competes with Verax publishes a comparison page against it, which places the two in the same purchase decision for employee AI usage. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Lasso Security competes with Verax publishes a comparison page against it, which places the two in the same purchase decision for employee AI usage. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Nightfall AI competes with Verax publishes a comparison page against it, which places the two in the same purchase decision for preventing data loss into AI tools.
Cyera competes with Verax publishes a comparison page against its AI offering, which places the two in the same purchase decision. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Netskope competes with Verax's own comparison page describes it running real-time inspection of prompts and responses on an inline proxy, which is the same control Verax sells. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Zscaler competes with Verax's own comparison page names it as the network platform whose AI governance a buyer would weigh against a standalone purchase. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Palo Alto Networks competes with Verax's own comparison page describes its AI portfolio inside Prisma SASE as the incumbent case a buyer weighs against a standalone purchase. N/AWe scored these companies at different scopes, so the totals measure different things.
Microsoft competes with Verax's own comparison page describes it governing AI natively for customers standardized on its productivity and identity products. N/AMicrosoft is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product.
Prompt Security adjacent Works the same problem of governing employee generative AI use, from a different deployment position. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.

Add analyzed competitors to compare them side by side with Verax.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 13 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

What Verax owns is a position rather than an asset. The appliance runs inside the customer's network and the interaction records stay there. The one corpus the record names is the public AI tool risk database on its own site, which its terms describe as machine-generated and reviewed rather than verified, so little accumulates on Verax's side that a funded rival could not assemble. Sitting between employees and the AI tools they use is real friction: a replacement has to be inserted at the same point and trusted again by every device. The reviewed record does not size that work, and it names no certification Verax itself holds, so the friction is documented rather than measured. Palo Alto, Zscaler, Netskope and Microsoft sell overlapping controls today, by Verax's own account.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Verax delivers software the customer deploys and operates: a virtual machine in the customer's own network, rules the customer writes, thresholds the customer sets, and email support during business hours. No cited source describes Verax operating the control or accepting an outcome on the customer's behalf.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 The mechanism is real. Verax sits between employees and the AI tools they use, requires devices to trust its certificate authority and route AI traffic to it, and binds rules to users and groups synced from the identity provider, so leaving means putting a replacement at the same point. The cited record does not size that migration, so the friction is documented rather than measured.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 The compliance material describes frameworks a customer can align with rather than requirements that block a replacement, and no attestation Verax itself holds appears on the reviewed trust surfaces. Nothing in the cited record stands between a funded competitor and this buyer.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 The product decides in real time whether traffic may pass, combining identity, tool recognition, threshold scoring and semantic topic matching before a request is released. Building an inline control that inspects every prompt without breaking the tools people use is a real-time systems problem rather than a reporting one.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 The evidenced buyer is an enterprise: the product needs a dedicated virtual machine, a connected identity provider and authority over network routing, and Verax addresses security, infrastructure, and compliance and risk teams together. No cited source names a customer, so the buyer class rests on the deployment requirements and the vendor's own audience rather than on a roster.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 Verax runs as a platform with an administrative application on top: a console, a rules engine, dashboards and an interactions view over an appliance in the network path. Other applications do not build against it, and no cited source describes an API or a developer surface others depend on.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 The one corpus the record names is the AI tool risk database Verax publishes on its own site, which is public and which its terms describe as machine-generated and reviewed rather than independently verified. Interactions are inspected and stored inside the customer's infrastructure, and the vendor states that prompts and responses are not sent to it, so no non-public retained asset appears.
Strategic Market Segmentation Verax addresses an enterprise buying committee rather than a single owner…

Verax addresses an enterprise buying committee rather than a single owner. Its homepage carries a section for each of three audiences in turn: security leaders, infrastructure leaders, and compliance and risk teams.

The deployment requirements pick the segment more sharply than the marketing does. A buyer needs a virtual machine with 32 gigabytes of memory and 512 gigabytes of database storage, an identity provider to connect, and the authority to point AI traffic at it, which is step three of the documented setup. That combination rules out small companies and points at organizations with a network team and a working single sign-on deployment.

Sector focus is absent from the cited record. Verax names no vertical, publishes no industry pages, and the regulatory frameworks it lists are the general set. The one audience signal on the site is a testimonial from an unnamed cybersecurity director at a Fortune 2000 company, which points at large enterprises without establishing that any of them bought.

Product Capabilities & AI Advantages The capability is inline decision-making on live traffic…

The capability is inline decision-making on live traffic. Verax states that it sits in the path between users and generative AI tools, evaluates each request against configured rules, applies the rule that matches earliest in the list, and falls through to a default rule when none match. That design gives a security team something a monitoring product cannot: an answer that arrives before the data leaves.

The conditions available inside a rule are more varied than a keyword list. Sensitivity runs as a score from 0 to 100 with three presets, topic similarity matches a request against described topics and entities, and keyword and regular expression conditions handle the precise cases. Separate switches strip code and personal data out of requests. Actions are to block, redact, warn, log or escalate, and the interactions view records what happened to each request with its score and its user.

Part of the AI is supplied rather than owned. The marketplace listing states that the application server processes tasks using Anthropic's Claude 3 Sonnet model through AWS Bedrock, in a delivery description that still names the earlier Control Center, and the rules documentation has topic and entity generation run on a language model the customer connects. No cited page describes a model Verax built for the scoring. What the company builds around that is the placement, the rule engine, the identity binding and the tool coverage, and those are the parts a rival would have to reproduce.

Sales Engagement & Go-to-Market The motion starts with a free look and narrows to a conversation…

The motion starts with a free look and narrows to a conversation. The Verax AI Risk Assessment, published on 19 April 2026, runs inside the customer environment, processes all data there, monitors without blocking, and is framed as answering whether a problem exists before anyone is asked to buy. The rest of the site funnels to a demo booking.

Alongside that sits a self-service channel. Verax Protect is on AWS Marketplace with a published monthly price and a one-click CloudFormation deployment, which lets a buyer transact without a sales conversation.

Content is the demand engine. The company publishes an index of comparison pages against Palo Alto, Zscaler, Cyera, Harmonic Security, Lasso Security and Nightfall AI, alongside a risk database covering third-party AI tools that its own terms describe as machine-generated and reviewed rather than independently verified. That is a search strategy aimed at buyers already shopping, and it stands in for a reference list the company does not yet have.

Pricing Model Verax publishes its price…

Verax publishes its price. AWS Marketplace lists Verax Protect at $2,750 per month as a fixed subscription with unlimited usage, prorated, with no end date and cancellation at any time, launched from a one-click deployment.

A flat subscription rather than a per-seat or per-request meter has a specific consequence: the price does not grow as AI usage grows inside the customer. That favors a buyer expecting heavy adoption and costs Verax the expansion revenue a usage meter would capture. Additional AWS infrastructure charges sit on top, which the listing states plainly, and the appliance's stated minimum specification makes that a real rather than nominal addition.

The refund position is stated bluntly: no refunds, cancel any time. Nothing in the cited record describes enterprise tiering, volume discounting, or a direct contract, so a larger buyer negotiates against the marketplace figure as the one public anchor.

Product Delivery & Operations Delivery is an appliance the customer runs…

Delivery is an appliance the customer runs. The product ships as a CloudFormation template creating a single virtual machine, or as software on a virtual machine meeting the published minimum of 32 gigabytes of memory and 512 gigabytes of database storage running Ubuntu 24.04. Setup is three steps: activate a license, connect an identity provider, redirect AI traffic.

That third step is where the operational cost lives, and the vendor's surfaces describe it two ways. The architecture page says integration happens at the network layer and no endpoint agent is required. The documentation publishes a manual endpoint-configuration guide covering installation of a Verax certificate authority and traffic redirection per device, an installer for a Verax endpoint agent on Windows, macOS and Linux, and a note that Claude Code on macOS needs Node.js pointed at that certificate. Both descriptions are the vendor's own, and a buyer planning a rollout should treat the agentless path as one option rather than the whole story.

Coverage has a stated boundary that a buyer should read carefully. The documentation says shadow AI discovery requires traffic to be routed through Verax, and that tools which do not pass through it cannot be detected or controlled. Discovery is therefore as complete as the redirection is, which turns the deployment question into a coverage question.

Support is email during United States business hours, Monday to Friday. For an inline control that can block a request an employee is waiting on, business-hours support is a real operational constraint rather than a line item.

Earning Customers' Trust Verax's trust argument is architectural rather than documentary…

Verax's trust argument is architectural rather than documentary. It states that inspection and policy evaluation happen inside the customer's own infrastructure, that prompts and responses are not sent to external services for security evaluation, and that retention is configured by the customer's administrators. That answers the objection a security team raises first about a cloud inspection service.

The compliance language points at what customers can demonstrate rather than at what Verax has been assessed against. Its security and compliance page says the product helps organizations use AI in alignment with GDPR, SOC 2, ISO 27001, HIPAA and PCI DSS where applicable, and describes secure development practices in general terms. No attestation the company itself holds appears on the reviewed trust surfaces.

For a product that reads every prompt an employee sends, that gap matters more than it would elsewhere. The architecture reduces the exposure, since the vendor is not holding the data, but an enterprise review will still ask how the appliance itself is built and audited, and the published record does not answer it.

Platform Strategy & Ecosystem Positioning Verax positions itself as an addition to a security stack rather than a replacement for one. Its architecture page lists integration with identity providers, firewalls and network gateways, logging and security information and event management platforms, and governance workflows, and its comparison page offers to chain off an existing secure web gateway through ICAP so a buyer keeps the platform they have. That is a deliberate contrast with how the large platforms sell. The comparison page argues that adopting Zscaler's AI governance means adopting the wider platform, and that Palo Alto's AI product is browser-only or needs an endpoint agent, while Verax is standalone. Selling as an addition lowers the barrier to a first purchase and puts the company in the position of the layer above someone else's infrastructure. The tool-side ecosystem is the other half. Verax claims integrations with hundreds of AI tools rather than identification at the browser, and the marketplace listing names ChatGPT, Copilot, Claude and Gemini among them. Maintaining that coverage as tools change is recurring engineering work, and it is closer to a treadmill than to an asset…

Verax positions itself as an addition to a security stack rather than a replacement for one. Its architecture page lists integration with identity providers, firewalls and network gateways, logging and security information and event management platforms, and governance workflows, and its comparison page offers to chain off an existing secure web gateway through ICAP so a buyer keeps the platform they have.

That is a deliberate contrast with how the large platforms sell. The comparison page argues that adopting Zscaler's AI governance means adopting the wider platform, and that Palo Alto's AI product is browser-only or needs an endpoint agent, while Verax is standalone. Selling as an addition lowers the barrier to a first purchase and puts the company in the position of the layer above someone else's infrastructure.

The tool-side ecosystem is the other half. Verax claims integrations with hundreds of AI tools rather than identification at the browser, and the marketplace listing names ChatGPT, Copilot, Claude and Gemini among them. Maintaining that coverage as tools change is recurring engineering work, and it is closer to a treadmill than to an asset.

Team & Execution Capability Two founders, both operators, one with an independently reported exit…

Two founders, both operators, one with an independently reported exit. Leo Feinberg co-founded CloudEndure, raising $18 million before Amazon Web Services acquired it for a reported $250 million, and the company page adds an earlier sale of AcceloWeb to Limelight Networks. Oren Gev's record, more than twenty years of engineering leadership, a previous founder and chief technology officer role, and engineering leadership at Amazon Web Services, rests on that same vendor page. Independent coverage of the seed round confirms the pairing and dates their working relationship to 2017.

The relevant caution is domain rather than capability. The prior work is cloud migration and disaster recovery, so what the record establishes is the ability to build and sell enterprise infrastructure rather than standing in security or AI.

The commercial organization is still forming. The careers page advertises a marketing lead to define the category and a senior account executive to own the full sales cycle, alongside engineering and quality roles. Two years past the seed round, opening dedicated sales roles is a signal about how much of the go to market has been founder-led so far.

Sources

Company Detail Sources (3)
Id Source Tier Accessed
f1 Verax AI: Verax Protect product page official 2026-09-02
f2 Calcalist CTech: Verax AI raises $7.6 million in Seed funding to help enterprises control AI press 2026-09-02
f3 Verax documentation: Welcome to Verax official 2026-09-02
Profile Analysis Sources (24)
Id Source Tier Accessed
s1 Verax AI: homepage
“Gain real-time visibility and enforce identity-aware, content-aware policies across all Generative AI activity - before it can cause damage or leak sensitive data out of your organization.”
official 2026-09-02
s2 Verax AI: Verax Protect product page
“Verax Protect delivers identity-aware access control, shadow AI discovery, and real-time content inspection across all Generative AI activity.”
official 2026-09-02
s3 Verax AI: Architecture page
“Verax Protect is deployed within your private corporate network, operating as a centralized enforcement layer for all Generative AI activity.All inspection and policy evaluation occur inside your controlled infrastructure.”
official 2026-09-02
s4 Verax AI: Security and Compliance page
“Verax Protect operates as an in-network AI security enforcement layer.”
official 2026-09-02
s5 Verax AI: About page
“Verax was founded to address the security and governance challenges of enterprise AI adoption.”
official 2026-09-02
s6 Verax AI: Platform overview page
“The Verax Protect platform delivers an integrated AI security enforcement layer purpose-built for Generative AI.”
official 2026-09-02
s7 Verax AI: Use cases page
“Attribute every AI interaction to a verified corporate identity for full accountability”
official 2026-09-02
s8 Verax documentation: Welcome to Verax
“Verax sits in the traffic path between users and generative AI tools.”
official 2026-09-02
s9 Verax documentation: Rules
“Verax evaluates rules in order, from top to bottom. The first matching rule is applied. If no rules match, the default rule is applied.”
official 2026-09-02
s10 Verax documentation: How to Use Shadow AI
“**Note** Shadow AI discovery requires AI traffic to be routed through Verax. Tools that do not pass through Verax cannot be detected or controlled.”
official 2026-09-02
s11 Verax documentation: Data Security Settings
“**Strict (40)** - Blocks anything potentially inappropriate.”
official 2026-09-02
s12 Verax documentation: Installing the Verax Endpoint Agent
“This guide explains how to download and install the Verax endpoint agent on Windows, macOS, and Linux.”
official 2026-09-02
s13 Verax documentation: Endpoint Configuration (manual)
“This guide outlines the required steps to configure a Windows or macOS device to work with Verax Protect.”
official 2026-09-02
s14 Verax documentation: Prerequisites
“Verax runs on a VM with Ubuntu 24.04 LTS. Ensure that your VM meets the following system requirements:”
official 2026-09-02
s15 Verax documentation: Interactions
“Use the **Interactions** page to view all user Generative AI tool requests in your org.”
official 2026-09-02
s16 Verax AI: We're Out of Stealth, Introducing Verax Control Center
“Verax AI was created in 2023, by our co-founders Leo Feinberg and Oren Gev, with the mission to help organizations unlock the full potential of AI.”
official 2026-09-02
s17 Verax AI: Launching the Verax AI Risk Assessment
“Today, we're launching the Verax AI Risk Assessment , a free, self service way to understand how AI is actually used across your organization and what data is being exposed.”
official 2026-09-02
s18 Verax AI: Best Palo Alto AI Access Security Alternatives comparison page
“Palo Alto delivers AI security through Prisma SASE, and it has one of the broadest AI portfolios on the market, including Access Security, DLP, the Prisma Browser, and Prisma AIRS for agents.”
official 2026-09-02
s19 AWS Marketplace: Verax Protect listing
“Verax Protect provides real-time data loss prevention (DLP) for generative AI tools.”
official 2026-09-02
s20 Calcalist CTech: Verax AI raises $7.6 million in Seed funding to help enterprises control AI
“it has secured $7.6 million in Seed funding led by TQ Ventures with participation from Concept Ventures, Cardumen Capital, Seedcamp, InMotion Ventures, and XTX Ventures.”
press 2026-09-02
s21 Dallas Innovates: Dallas-Based Verax AI Raises $7.6M in Seed Funding, Aims to Mitigate AI Risks in Real Time
“Verax, with offices in Dallas, Tel Aviv, and London, is a developer of enterprise-grade software solutions that provide visibility and control of AI in production.”
press 2026-09-02
s22 Verax AI: Terms and Conditions
“Please read the following Terms of Use (the " Agreement ") carefully before using this Site so that you are aware of your legal rights and obligations with respect to Verax AI Inc.”
official 2026-09-02
s23 Verax trust probe 2026-09-02: trust. and security. subdomains DNS-fail against a control, /trust and /security 404, no badge in homepage markup official 2026-09-02
s24 Verax AI: AI Security Products comparison index
“Best Lasso Security Alternatives (2026)”
official 2026-09-02
Deep-Dive Sources (24)
Id Source Tier Accessed
s1 Verax AI: homepage
“Gain real-time visibility and enforce identity-aware, content-aware policies across all Generative AI activity - before it can cause damage or leak sensitive data out of your organization.”
official 2026-09-02
s2 Verax AI: Verax Protect product page
“Verax Protect delivers identity-aware access control, shadow AI discovery, and real-time content inspection across all Generative AI activity.”
official 2026-09-02
s3 Verax AI: Architecture page
“Verax Protect is deployed within your private corporate network, operating as a centralized enforcement layer for all Generative AI activity.All inspection and policy evaluation occur inside your controlled infrastructure.”
official 2026-09-02
s4 Verax AI: Security and Compliance page
“Verax Protect operates as an in-network AI security enforcement layer.”
official 2026-09-02
s5 Verax AI: About page
“Verax was founded to address the security and governance challenges of enterprise AI adoption.”
official 2026-09-02
s6 Verax AI: Platform overview page
“The Verax Protect platform delivers an integrated AI security enforcement layer purpose-built for Generative AI.”
official 2026-09-02
s7 Verax AI: Use cases page
“Attribute every AI interaction to a verified corporate identity for full accountability”
official 2026-09-02
s8 Verax documentation: Welcome to Verax
“Verax sits in the traffic path between users and generative AI tools.”
official 2026-09-02
s9 Verax documentation: Rules
“Verax evaluates rules in order, from top to bottom. The first matching rule is applied. If no rules match, the default rule is applied.”
official 2026-09-02
s10 Verax documentation: How to Use Shadow AI
“**Note** Shadow AI discovery requires AI traffic to be routed through Verax. Tools that do not pass through Verax cannot be detected or controlled.”
official 2026-09-02
s11 Verax documentation: Data Security Settings
“**Strict (40)** - Blocks anything potentially inappropriate.”
official 2026-09-02
s12 Verax documentation: Installing the Verax Endpoint Agent
“This guide explains how to download and install the Verax endpoint agent on Windows, macOS, and Linux.”
official 2026-09-02
s13 Verax documentation: Endpoint Configuration (manual)
“This guide outlines the required steps to configure a Windows or macOS device to work with Verax Protect.”
official 2026-09-02
s14 Verax documentation: Prerequisites
“Verax runs on a VM with Ubuntu 24.04 LTS. Ensure that your VM meets the following system requirements:”
official 2026-09-02
s15 Verax documentation: Interactions
“Use the **Interactions** page to view all user Generative AI tool requests in your org.”
official 2026-09-02
s16 Verax AI: We're Out of Stealth, Introducing Verax Control Center
“Verax AI was created in 2023, by our co-founders Leo Feinberg and Oren Gev, with the mission to help organizations unlock the full potential of AI.”
official 2026-09-02
s17 Verax AI: Launching the Verax AI Risk Assessment
“Today, we're launching the Verax AI Risk Assessment , a free, self service way to understand how AI is actually used across your organization and what data is being exposed.”
official 2026-09-02
s18 Verax AI: Best Palo Alto AI Access Security Alternatives comparison page
“Palo Alto delivers AI security through Prisma SASE, and it has one of the broadest AI portfolios on the market, including Access Security, DLP, the Prisma Browser, and Prisma AIRS for agents.”
official 2026-09-02
s19 AWS Marketplace: Verax Protect listing
“Verax Protect provides real-time data loss prevention (DLP) for generative AI tools.”
official 2026-09-02
s20 Calcalist CTech: Verax AI raises $7.6 million in Seed funding to help enterprises control AI
“it has secured $7.6 million in Seed funding led by TQ Ventures with participation from Concept Ventures, Cardumen Capital, Seedcamp, InMotion Ventures, and XTX Ventures.”
press 2026-09-02
s21 Dallas Innovates: Dallas-Based Verax AI Raises $7.6M in Seed Funding, Aims to Mitigate AI Risks in Real Time
“Verax, with offices in Dallas, Tel Aviv, and London, is a developer of enterprise-grade software solutions that provide visibility and control of AI in production.”
press 2026-09-02
s22 Verax AI: Terms and Conditions
“Please read the following Terms of Use (the " Agreement ") carefully before using this Site so that you are aware of your legal rights and obligations with respect to Verax AI Inc.”
official 2026-09-02
s23 Verax trust probe 2026-09-02: trust. and security. subdomains DNS-fail against a control, /trust and /security 404, no badge in homepage markup official 2026-09-02
s24 Verax AI: AI Security Products comparison index
“Best Lasso Security Alternatives (2026)”
official 2026-09-02

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.