Vorlon

Security for AI

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software.
Founded 2022
Funding $15.7M
Last updated 2026-09-10

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Vorlon sells software that protects data moving between a company's AI agents and the applications they use. It sells to enterprise security teams and names CarGurus, ThoughtSpot, OPENLANE, and Dutchie as customers. Its founders are veterans of Demisto, an incident-response automation company Palo Alto Networks bought for $560 million in 2019. Vorlon, founded in 2022, has raised $15.7 million, and Accel led its 2024 Series A. Vorlon has not disclosed revenue or a customer count. Its Guardian gateway can block an agent's data flow, mask it, or limit it to read-only. SaaS security, data loss prevention, and identity vendors its buyers already use could add that control as a feature. Vorlon therefore needs buyers to fund that control as a separate product.

Sourced Details

Description Vorlon is a data security platform that protects the data moving between a company's AI agents and the SaaS apps, cloud data stores, and other enterprise systems they connect to. [f1]
Founded 2022 [f2]
HQ Mountain View, California, US [f3]
Funding $15.7M total [f4]
Latest funding Series A, $15.7M (April 2024) [f4]
Deployment SaaS [f5]
Compliance SOC 2 Type 2 [f5]

Products

Product What it does
Vorlon Vorlon: AI Agent Flight Recorder and Action Center capture a cross-application forensic audit trail of agent actions, surface behavioral anomaly findings, and route coordinated response.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

Vorlon's AI Agent Flight Recorder and Action Center capture a cross-application forensic audit trail of agent actions, surface behavioral anomaly findings, and route coordinated response. It is mapped to the AI Defense Matrix. [f6]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Emerging 24 /40 Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Vorlon names CISOs and security teams as the buyer, but the quantified pain comes down to one figure, the Akamai statistic that app-to-app traffic exceeds 80 percent of internet traffic, which CTech relays and Vorlon's own press release credits to Akamai, a generic stat rather than pain quantified across multiple independent sources, so it reads as present but unproven. [s7, s17, s1, s4]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 The platform documents specific mechanics: AI Agent Runtime Security with blocking, masking, and read-only enforcement, MCP-server governance, anomaly and UEBA detection, token revocation, and a patented DataMatrix simulation engine. The evidence is detailed but almost entirely official, with no public docs portal or third-party technical evaluation, which holds it at adequate. [s2, s4, s5, s6]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 Enterprise AI-agent adoption since 2024 is a credible enabler, but the demand signals cited are Accel backing both the seed and Series A rounds and Demisto-network investors joining, which are investor-side rather than buyer-side, and the named customers are vendor-published, so independent buyer demand within the year is indirect. [s7, s9, s4]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 4/5 Khayat and Spivak are Demisto veterans. CTech reports that both worked at Demisto and then at Palo Alto Networks after the $560 million acquisition in 2019, and Vorlon's About page credits them with building the product that became XSOAR. Senior roles through a verifiable exit in the adjacent incident-response domain clear the bar for a strong team score. [s3, s18, s9]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 3/5 Vorlon names reference customers (CarGurus, ThoughtSpot, OPENLANE, Dutchie) with leader testimonials on its site, which lifts it above the unnamed-customer floor, but the proof is vendor-controlled with no independently reported deployment outcomes, and the outside coverage that exists is 2024 funding-round reporting. Reputable backing from Accel and Demisto-founder investors adds a real indirect signal. Named but vendor-published references without external validation place it in the middle of the range. [s11, s12, s10]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 The $15.7 million total is sized to an early enterprise motion at a small team in the 11-50 band that LinkedIn lists, and shipping output is visible in the DataMatrix patent and the 2026 Flight Recorder and Action Center launch. Output per dollar is evident, but with traction proof limited to vendor-published references the efficiency case stays at adequate rather than strong. [s7, s5, s13]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 Vorlon has moved from third-party API security to agentic ecosystem security, a label it is helping define rather than one buyers already place. The data-layer framing is coherent, but a buyer would need coaching to map it to a budget line, unlike the recognized non-human-identity category its closest peers occupy. [s1, s8, s4]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 2/5 Securing data in motion across SaaS and agents overlaps the territory of SaaS-security, DLP, and identity platforms that already sit in the buyer's stack, including Palo Alto Networks, which acquired the founders' former employer. The patented DataMatrix engine is a partial barrier, but no proprietary data flywheel or procurement lock is visible. [s4, s9, s2]
Business Risks SaaS-security, DLP, and identity platforms could add data-in-motion monitoring as a feature, and Palo Alto Networks, which acquired the founders' former employer Demisto, sells to the same buyers…
  • SaaS-security, DLP, and identity platforms could add data-in-motion monitoring as a feature, and Palo Alto Networks, which acquired the founders' former employer Demisto, sells to the same buyers.
  • Vorlon's named customer references are vendor-published with no independently reported deployment, so actual traction for the agentic-ecosystem framing could be thinner than the platform messaging implies.
  • Vorlon has repositioned twice in two years, and a third pivot or a stalled raise after the April 2024 Series A would signal it has not found a durable foothold.
  • Emerging agent-identity and gateway standards could let cloud and identity providers govern agent data flows natively, shrinking the standalone need Vorlon sells against.
Problem & Market Vorlon targets the data that moves between applications, integrations, and AI agents rather than the access event at the perimeter…

Vorlon targets the data that moves between applications, integrations, and AI agents rather than the access event at the perimeter. The company frames the exposure around third-party data flow: CTech reports that app-to-app communication now represents over 80% of internet traffic, a figure Vorlon's own press release credits to Akamai, and Vorlon argues that the APIs and integrations carrying that traffic often grant over-permissive access to sensitive data with no monitoring of what actually moves.

The buyer is the CISO and the security team, and the pitch lands on a real gap. The company positions legacy DLP as blind to data in motion between SaaS apps, since endpoint and network tools watch the edges rather than the flows. As enterprises wire AI agents into SaaS and homegrown systems, that gap widens, because agents move data at machine speed across boundaries the older tools never instrumented.

The problem is well defined, and the headline statistic is Akamai's rather than Vorlon's own, though buyers meet it in the company's press release and CTech's funding coverage rather than in independent research. What the public record does not yet show is how many buyers are funding a dedicated line for it rather than expecting their existing SaaS-security or identity vendor to cover it. [s7, s17, s4, s1]

Product Capabilities The Vorlon platform centers on watching and governing data as it moves…

The Vorlon platform centers on watching and governing data as it moves. Its AI Agent Runtime Security combines blocking, data masking in transit, and read-only enforcement, and the company says any cloud, SaaS, or homegrown system with an API or MCP server becomes a governed endpoint in minutes. Detection rests on baselining data and identity activity and flagging anomalies with UEBA, and response includes revoking or rotating risky tokens, API keys, and service accounts.

Two pieces give the product specificity. DataMatrix, which Vorlon describes as a patented simulation engine that maps agents, integrations, and data in motion, is the underlying technology. The AI Agent Flight Recorder and Action Center, launched in 2026, pairs an immutable audit trail of agent actions with a coordinated response path, which extends the platform from detection into forensics and remediation.

The capability claims are concrete, but the supporting evidence is almost entirely the company's own pages. There is no public documentation portal, open-source code, or third-party technical evaluation to validate the mechanics independently, which keeps the depth at adequate rather than strong. [s2, s4, s5, s6]

Competitive Positioning Vorlon spans several established categories rather than occupying a clean one of its own…

Vorlon spans several established categories rather than occupying a clean one of its own. Its data-in-motion claim overlaps SaaS-security posture management, data-loss prevention, and non-human-identity tooling, each of which is already sold by vendors in the buyer's stack. Identity peers such as Token Security, Oasis Security, and Entro Security approach the adjacent problem from the credential and machine-identity angle, while Vorlon approaches it from the data-flow angle.

The differentiation is the data layer. Vorlon argues that anchoring detection to sensitive-data movement, rather than to access or identity events, catches exposures the others miss. That is a defensible foothold if buyers accept that the data flow is the right control point, and a weakness if they treat it as a feature their identity or SaaS-security platform should absorb.

The sharpest competitive pressure comes from the platforms. Palo Alto Networks, which acquired Demisto, the founders' former employer, is one of the large platform vendors already selling into the same security buyers, and a move by any of them to monitor data in motion natively would compress Vorlon's standalone space. [s4, s8, s9]

Go-to-Market & Traction The go-to-market evidence is the thinnest part of Vorlon's public record…

The go-to-market evidence is the thinnest part of Vorlon's public record. The company has raised $15.7 million in total, led by Accel across a 2023 seed and an April 2024 Series A, with Shield Capital and a roster of Demisto-founder investors joining. That backing is a genuine signal, since the investors worked with Vorlon's founders before the Palo Alto acquisition and chose to follow them again.

Named customers do exist, but the proof is vendor-controlled. The Vorlon site names CarGurus, ThoughtSpot, OPENLANE, and Dutchie as customers and carries testimonials attributed to Anthony Lee-Masis (CISO and VP of IT, ThoughtSpot), Ran Landau (CTO, Splitit), and Eric Richard (SVP Engineering, Dutchie), plus a Splitit customer story link. What the public record still lacks is independent validation of that proof. The press coverage that exists reports the 2024 funding round under a third-party API security framing rather than the agentic-ecosystem pitch, and no analyst report or independent press details a deployment outcome at any named account.

The result is a company with credible financial backing and on-site customer references but no externally reported traction for its current positioning, which is why the traction score stays low despite the named logos and the strong investor signal. [s11, s12, s10]

Team & Credibility The team is Vorlon's strongest asset…

The team is Vorlon's strongest asset. Co-founders Amir Khayat and Amichay Spivak are veterans of Demisto, the security orchestration, automation, and response platform that Palo Alto Networks acquired in 2019. CTech reports that both worked at Demisto and then at Palo Alto Networks after the acquisition, which Pulse 2.0 puts at $560 million, and Demisto co-founders who worked closely with the pair there, including Slavik Markovich and Rishi Bhargava, invested in Vorlon.

Senior experience through a verifiable exit in the adjacent incident-response domain places Vorlon ahead of identity peers whose founders show no comparable history. The founders are working a problem one step removed from the response automation they helped ship, which lends credibility to the platform's forensics-and-response direction.

The caution is that pedigree predicts execution capacity, not market fit for the new thesis. The team's history explains why Accel funded the company twice, but it does not by itself confirm that the data-in-motion category will support a standalone business. [s3, s18, s9]

Trust Readiness Vorlon positions trust and compliance as a core part of the value, not an afterthought…

Vorlon positions trust and compliance as a core part of the value, not an afterthought. The platform advertises continuous compliance posture monitoring across global frameworks, and the Flight Recorder is pitched as an immutable, audit-defensible record of every agent action and data movement, which speaks directly to the regulatory review that enterprise buyers face.

The privacy-preserving design is a notable detail: Vorlon says it classifies sensitive data without content inspection, which lowers the trust barrier for security teams wary of a tool that reads the data it watches. That choice fits a buyer who needs visibility into data flows without handing a vendor the contents.

Vorlon does carry a real attestation. The homepage footer displays a SOC 2 Type II badge, an AICPA SOC seal in an image named Certification Content Container.png labeled “SOC 2 Type II Certified,” and the Vorlon Trust page states the company holds a SOC 2 Type II report and offers a copy through a request form routed to the account manager. The badge sits beside award and membership marks (AWS Partner, CRN Stellar Startups, Latio AI Security Innovator, FS-ISAC Affiliate) that are recognition rather than security attestations. For an early-stage security vendor the SOC 2 Type II is table stakes, the price of entry to enterprise procurement rather than a differentiator.

What a buyer still cannot do is inspect the proof on demand. There is no self-serve trust portal, the report is gated behind a request form rather than downloadable, and neither trust.vorlon.io nor security.vorlon.io resolves while /trust-center and /compliance return 404. No ISO 27001, ISO 42001, HIPAA, PCI, FedRAMP, or HITRUST attestation is displayed, and no independently validated customer reference exists.

A July 2026 fetch of the homepage shows the same surfaces, with the SOC 2 seal rendering beside the award and membership marks, and the sole ISO-lettered element on the page is the CISO Report resource tile rather than a certification badge. The patented technology and the audit-trail framing are encouraging, but the readiness story depends on the SOC 2 attestation plus the company's own description, with the audit artifact available only through sales. [s4, s6, s2, s14, s15, s16, s19]

Competitors Token Security, Oasis Security, Entro Security, Palo Alto Networks…
Company Relationship Note Compare
Token Security competes with Non-human and AI-agent identity security platform addressing the adjacent credential-governance angle of the same buyer problem.
Oasis Security competes with Non-human identity security platform that governs service accounts, keys, and agents from the identity layer rather than the data layer.
Entro Security competes with Non-human identity and secrets discovery vendor that has also repositioned toward AI-agent security. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Palo Alto Networks adjacent Acquirer of Demisto, the founders' former employer, and a large security-platform vendor positioned to add data-in-motion monitoring as a feature. N/AWe scored these companies at different scopes, so the totals measure different things.

Add analyzed competitors to compare them side by side with Vorlon.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Exposed 12 /21 Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software. pivot urgently

A customer can leave Vorlon two ways. Cancelling costs coverage: Guardian enforces over data flows Vorlon does not own, and the record does not detail the unwind path. A customer replacing Vorlon pays more: the gateway runs inline, so the customer must stand up a substitute for the connections it governs. The engineering, real-time inline enforcement with the patented DataMatrix engine, is specialized machine-learning work a funded rival can rebuild, and the record names no cross-customer dataset that would slow it. The lone SOC 2 Type II attestation, supplied through sales, is table stakes a rival can also earn. Watch whether the SaaS security, identity, and data-loss-prevention vendors it overlays, or Palo Alto Networks, ship enforcement at the same control point.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Vorlon is software the customer connects and operates, the Guardian gateway, detection, and response workflows run by the security team itself, with no managed service, judgment layer, or liability acceptance in the public offer.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Vorlon Guardian sits inline as an enforcement gateway in the data path, and integrations across SaaS, APIs, and MCP servers create real re-integration friction once embedded, an inline lock that no network effect or data-residency lock raises further.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 Vorlon publishes a single SOC 2 Type II attestation gated behind a sales request form with no inspectable portal, table-stakes assurance that eases procurement without blocking substitutes, and the cited record identifies no regulation mandating this product class.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Real-time inline inspection and enforcement on data in motion across heterogeneous SaaS, APIs, and MCP servers, with behavioral baselining and UEBA under the patented DataMatrix simulation engine, is applied machine-learning and real-time-systems engineering, adjacent to the incident-response automation the founders built at Demisto.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3 The named buyers are CarGurus, ThoughtSpot, OPENLANE, and Dutchie, alongside unnamed Fortune 500 companies the vendor claims, with a demo-led procurement motion, a mixed commercial roster rather than a regulated-only base.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 Vorlon Guardian is an inline enforcement gateway and middleware in the data path, more than a point tool, but it enforces over flows it does not own and is not infrastructure other software depends on to function or a credential-issuing control plane.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 The per-customer data-flow maps are switching friction rather than a cross-customer corpus, and the patented DataMatrix engine is engineering IP a funded rival can rebuild, with no named non-public dataset quoted in fetched sources.
Strategic Market Segmentation Vorlon sells to the enterprise CISO and security team buying for AI-agent rollouts that move sensitive data across SaaS, cloud, and homegrown systems…

Vorlon sells to the enterprise CISO and security team buying for AI-agent rollouts that move sensitive data across SaaS, cloud, and homegrown systems. The about page frames the gap as the moment after access: existing tools govern who gets in, while Vorlon enforces what an agent does with data once inside. That positions the buyer as a security org already deploying agents and worried about the blast radius rather than a team evaluating whether to adopt AI at all.

The named segment skews to mid-market and large commercial technology companies. Vorlon lists CarGurus, ThoughtSpot, OPENLANE, and Dutchie as customers and references Fortune 500 logos, with testimonial leaders at Splitit and ThoughtSpot, a roster of recognizable software and marketplace brands rather than a regulated-only base. The original entry point was third-party API security, and the company has since reframed the same data-flow monitoring as data-centric SaaS security and now agentic ecosystem security.

The open question is whether the buyer funds a dedicated line for agent data-flow security or expects an existing SaaS-security or identity vendor to cover it. The repositioning across three labels in roughly two years suggests Vorlon is still locating the budget line its buyer will name without coaching.

Product Capabilities & AI Advantages Vorlon's claimed advantage is enforcing on data movement rather than on the access event…

Vorlon's claimed advantage is enforcing on data movement rather than on the access event. The platform combines blocking, data masking in transit, and read-only enforcement, and the company says any cloud, SaaS, or homegrown system with an API or MCP server becomes a governed endpoint in minutes. Detection baselines data and identity activity and flags anomalies with UEBA, and response can revoke or rotate risky tokens, API keys, and service accounts.

Two pieces give the product specificity. DataMatrix, which Vorlon describes as its patented intelligent simulation engine, maps agents, integrations, and data in motion as the underlying technology, and Vorlon Guardian is the real-time enforcement gateway that acts at the protocol layer before a transaction completes. The Flight Recorder and Action Center, which Vorlon announced on March 25, 2026, pair an audit trail of agent actions with a coordinated response path, extending the product from detection into forensics and remediation.

The capability claims are concrete, and the patent is a real engineering signal, but the supporting evidence is almost entirely Vorlon's own pages. No public documentation portal, open-source code, or third-party technical evaluation validates the mechanics, and the reasoning underneath rests on detection logic a funded rival could rebuild rather than a named non-public corpus.

Sales Engagement & Go-to-Market Vorlon runs a demo-led enterprise motion with the named proof concentrated on its own site…

Vorlon runs a demo-led enterprise motion with the named proof concentrated on its own site. Site calls to action in July 2026 route to a booked demo, a contact form, or a Talk to Sales prompt, and the site navigation carries an Instant Preview item, a posture that still fits a security product sold into procurement-gated enterprises. The funding is a seed round less than two years before the April 2024 Series A, both led by Accel, totaling $15.7 million, with Shield Capital and a roster of Demisto-founder investors joining.

Named traction exists but the proof is vendor-controlled. Vorlon names CarGurus, ThoughtSpot, OPENLANE, and Dutchie as customers and runs testimonials attributed to Anthony Lee-Masis at ThoughtSpot and Ran Landau at Splitit, plus a Splitit reference. What the public record lacks is independent validation: the outside coverage that exists reports the 2024 Series A under the older third-party API framing, and no analyst report or press details a deployment outcome at any named account.

The investor signal is the strongest indirect evidence. Accel led twice and the Demisto co-founders who worked with the team before the Palo Alto acquisition invested again, backing that lifts the traction read above the named logos alone. That confidence still outruns any externally reported revenue or customer-count figure in fetched sources.

Pricing Model Vorlon publishes no pricing in fetched sources, so the charged unit and list price stay private…

Vorlon publishes no pricing in fetched sources, so the charged unit and list price stay private. The site directs buyers to a demo rather than a price page, the posture of a vendor pursuing large negotiated enterprise deals, which fits the CISO buyer and the procurement-gated motion. The absence withholds the budget-anchoring signal that some peers publish.

The charged unit is not stated, but the product's framing points at what Vorlon believes buyers pay for. The pitch centers on governed endpoints, agents, integrations, and the data flows between them, so the value meter is plausibly the breadth of the agentic ecosystem under coverage rather than seats or query volume. Confirming whether the meter is connected systems, data volume, or a flat platform fee would require a sales conversation.

The hidden-price posture holds on the current pages. The reviewed record shows no published price under the current agentic-ecosystem framing, which signals the intended path to purchase is the sales motion rather than a published list.

Product Delivery & Operations Public collateral presents Vorlon as connected software the customer operates, with no managed-service offering surfaced in fetched pages…

Public collateral presents Vorlon as connected software the customer operates, with no managed-service offering surfaced in fetched pages. The company says any system with an API or MCP server becomes a governed endpoint in minutes and that one connection to platforms like Claude Cowork governs every agent immediately, which describes a fast-integrating overlay the security team runs itself. There is no analyst-staffed service tier or accountability layer in the public offer.

The operational surface spans detection and enforcement on one path. Vorlon Guardian acts inline at the protocol layer to block, mask, and read-only-enforce before a transaction completes, while the Flight Recorder logs agent actions for forensics and the Action Center routes response. Vorlon describes classifying sensitive data without content inspection, a stated design choice that could lower the operational risk of granting a tool visibility into data flows.

Operational collateral remains thin beyond a customer support portal linked in the site navigation, with no published uptime, support SLA, or status page surfacing in fetched pages. The inline enforcement position raises the stakes of reliability, since a gateway that blocks transactions sits in the path of production agent traffic, yet the public record does not document how Vorlon manages that latency and availability risk.

Earning Customers' Trust Vorlon carries one real attestation gated behind sales…

Vorlon carries one real attestation gated behind sales. The homepage footer displays a SOC 2 Type II badge, and the Vorlon Trust page states the company holds a SOC 2 Type II report available through a request form routed to the account manager. For an early-stage security vendor handling privileged data flows, SOC 2 Type II eases enterprise procurement without differentiating the company.

The privacy-preserving design is the more distinctive trust signal. Vorlon classifies sensitive data, PII, PHI, PCI, credentials, and IP, and ties each flow to the identities and integrations involved without inspecting content, which lowers the barrier for a security team wary of a tool that reads the data it watches. The Flight Recorder's audit trail of agent actions speaks to the regulatory review enterprise buyers face.

What a buyer cannot do is inspect the proof on demand. There is no self-serve trust portal, the SOC 2 report is gated behind a request form rather than downloadable, and no ISO 27001, HIPAA, PCI, FedRAMP, or HITRUST attestation appears. A July 2026 probe found no trust-center host either, with neither trust.vorlon.io nor security.vorlon.io resolving, and a homepage fetch the same day shows the SOC 2 seal beside award and membership marks with no other certification badge. The audit artifact resolves only through sales, so the readiness story depends on the single attestation plus the company's own description.

Platform Strategy & Ecosystem Positioning Vorlon positions itself as the enforcement and visibility layer across the agentic ecosystem rather than a point tool…

Vorlon positions itself as the enforcement and visibility layer across the agentic ecosystem rather than a point tool. It connects to any cloud, SaaS, or homegrown system with an API or MCP server, governs platforms like Claude Cowork through a single connection, and maps agents, integrations, and data in motion through DataMatrix. The platform claim rests on covering the full integration layer that agents act across.

That breadth is an overlay over systems Vorlon does not own. Guardian enforces at the protocol layer over the data flows of the SaaS apps, clouds, and agent platforms it integrates with, so the platform depends on those source systems and the connectors into them. The value compounds with the breadth of an individual customer's ecosystem under coverage rather than across customers.

The exposure is that the platforms it overlays sit closer to the data. SaaS-security, identity, and DLP vendors already in the buyer's stack could extend to the same data-flow control point, and Palo Alto Networks is an adjacent platform vendor that acquired Demisto, where the founders previously worked.

Team & Execution Capability Vorlon's credibility comes from a security team seasoned through a large exit…

Vorlon's credibility comes from a security team seasoned through a large exit. Co-founders Amir Khayat and Amichay Spivak are veterans of Demisto, the security orchestration, automation, and response platform that Palo Alto Networks acquired in 2019. CTech reports that both worked at Demisto and then at Palo Alto Networks after the acquisition, which Pulse 2.0 puts at $560 million, verifiable senior experience in the adjacent incident-response domain.

The investor bench reinforces the founder signal. Accel led both the seed and the Series A, and the Demisto co-founders Slavik Markovich, Rishi Bhargava, Dan Sarel, and Guy Rinat, who worked with the pair before the Palo Alto acquisition, invested again. That repeat backing across two rounds is itself evidence the people who knew the team's prior work chose to follow them.

The caution is that pedigree predicts execution capacity, not market fit for the new thesis. The founders are working a problem one step from the response automation they helped ship at Demisto, which lends credibility to the forensics-and-response direction, but the pedigree does not by itself confirm the data-in-motion category supports a standalone business.

Sources

Company Detail Sources (6)
Id Source Tier Accessed
f1 Vorlon: Agentic Ecosystem Security Platform official 2026-07-09
f2 SiliconANGLE: Vorlon raises $15.7M to tackle third-party API risks press 2026-06-13
f3 Vorlon contact page official 2026-06-14
f4 SiliconANGLE: Vorlon raises $15.7M to tackle third-party API risks press 2026-06-14
f5 AI Defense Matrix Catalog entry other 2026-06-13
f6 AI Defense Matrix Catalog mapping other 2026-06-23
Profile Analysis Sources (19)
Id Source Tier Accessed
s1 Vorlon homepage
“Vorlon helps enterprises deploy AI at scale without exposing sensitive data. Secure the data between your agents and enterprise systems in real time, across every app, integration, and identity.”
official 2026-06-13
s2 Vorlon platform page
“Data classification without content inspection: PII, credentials, IP, and custom tagging”
official 2026-06-13
s3 Vorlon About page
“Vorlon was founded in 2022 by Amir Khayat and Amichay Spivak. Before Vorlon, Amir and Amichay built Demisto. Demisto (now Palo Alto Networks XSOAR) transformed how security teams respond to incidents, and its 2019 acquisition by Palo Alto Networks remains one of the largest in cybersecurity history.”
official 2026-06-13
s4 Vorlon Data-Centric SaaS Security page
“Ecosystem-Wide Threat Detection: Baseline data and identity activity. Detect active attacks with anomaly detection and UEBA. Proactive Breach Prevention: Revoke or rotate risky tokens, API keys, and service accounts instantly.”
official 2026-06-13
s5 Vorlon DataMatrix patented technology blog
“Vorlon's DataMatrix technology is now patented. Learn how this intelligent simulation engine secures the agentic ecosystem by mapping AI agents, SaaS integrations, and data in motion.”
official 2026-06-13
s6 Vorlon AI Agent Flight Recorder and Action Center announcement
“The Flight Recorder and the Action Center are not two separate products. They are two halves of the same motion. Detection without response is frustration. Response without forensics is guesswork.”
official 2026-06-13
s7 CTech: Vorlon completes Series A, total $15.7 million (James Spiro, 2024-04-17)
“Vorlon, a platform for comprehensive third-party API security, has announced that it has completed a Series A funding round led by Accel, bringing its total capital to $15.7 million. With app-to-app communication now representing over 80% of internet traffic.”
press 2026-06-13
s8 SiliconANGLE: Vorlon raises $15.7M to tackle third-party API risks (2024-04-17)
“Founded in 2022, Vorlon offers a comprehensive third-party API security platform. Accel Partners led the Series A round, with Shield Capital and various individual investors also participating.”
press 2026-06-13
s9 Pulse 2.0: Vorlon Closes $15.7 Million (Amit Chowdhry, 2024-04-20)
“Accel and Shield Capital are joined by several notable cybersecurity investors, such as Demisto co-founders Slavik Markovich, Rishi Bhargava, Dan Sarel, and Guy Rinat. These investors worked closely with Vorlon's co-founders at Demisto before Palo Alto Networks acquired it for $560 million in 2019.”
press 2026-06-13
s10 Vorlon Series A press release (2024-04-17)
““Vorlon’s ability to reduce the timeline between threat detection and remediation to minutes is what makes this technology so powerful,” said Steve Loughlin, Partner at Accel.”
official 2026-06-13
s11 Vorlon homepage customer testimonials
““Vorlon helped us identify critical third-party risks we didn't even know existed.” Ran Landau, Chief Technology Officer, Splitit. “How do you find keys that aren't being used? Vorlon helps with all of those.” Eric Richard, SVP Engineering, Dutchie. Anthony Lee-Masis, CISO & VP of IT, ThoughtSpot.”
official 2026-06-16
s12 Vorlon About page customer list
“Customers include Fortune 500 companies and fast-moving innovators like CarGurus, ThoughtSpot, OPENLANE, and Dutchie.”
official 2026-06-16
s13 Vorlon LinkedIn company page
“Company size 11-50 employees. View all 33 employees. Founded 2022. Mountain View, CA.”
official 2026-06-16
s14 Vorlon homepage footer attestation badge (SOC 2 Type II)
“Certification Content Container.png renders an AICPA SOC seal labeled SOC 2 Type II Certified, shown in the footer beside the AWS Partner, CRN Stellar Startups, Latio AI Security Innovator, and FS-ISAC Affiliate badges.”
official 2026-06-17
s15 Vorlon Trust page SOC 2 Type II statement
“SOC 2 Type II. Our SOC 2 report offers assurances to our customers. If you require a copy of our SOC 2 Type II audit report, please fill out the request form. Your Account Manager will respond.”
official 2026-06-17
s16 Vorlon homepage probe: rendered navigation, calls to action, footer badges
“Get a Demo. Talk to Sales. Customer Support: Access our customer support portal. Footer badge images: soc-type-2, aws partner, 2025-CRN-Stellar-Startups, latio innovators, FS-ISAC-Seal_Affiliate. CISO Report Resource Tile.”
official 2026-07-02
s17 Vorlon Series A press release: Akamai traffic attribution
“App-to-app communication now represents over 80% of internet traffic (Source: Akamai), and the third-party APIs an org consumes pose a great security risk”
official 2026-07-02
s18 CTech: Vorlon founders' Demisto roles (James Spiro, 2024-04-17)
“Khayat founded Vorlon with CTO Amichay Spivak. Both Khayat and Spivak worked at Demisto and then Palo Alto Networks after the latter acquired the former for $560 million in 2019.”
press 2026-07-02
s19 Vorlon trust-center subdomain probe (trust and security hosts)
“DNS lookups for trust.vorlon.io and security.vorlon.io return no records, and HTTPS requests to both hosts fail with could-not-resolve errors.”
official 2026-07-02
Deep-Dive Sources (13)
Id Source Tier Accessed
s1 Vorlon homepage: Agentic Ecosystem Security Platform
“Vorlon helps enterprises deploy AI at scale without exposing sensitive data. Secure the data between your agents and enterprise systems in real time, across every app, integration, and identity in your ecosystem.”
official 2026-06-18
s2 Vorlon About page: founders, DataMatrix, Guardian, customers
“Vorlon was founded in 2022 by Amir Khayat and Amichay Spivak, who before Vorlon built Demisto (now Palo Alto Networks XSOAR), acquired by Palo Alto Networks in 2019. Vorlon Guardian, the real-time enforcement gateway, applies blocking, masking, and read-only enforcement at the protocol layer.”
official 2026-06-18
s3 Vorlon platform page: AI Agent Runtime Security mechanics
“Sensitive data classification without content inspection, privacy-preserving by design. Behavioral detection anchored to data movement, not access events. Any cloud, SaaS, or homegrown system with an API or MCP server becomes a governed endpoint in minutes.”
official 2026-06-18
s4 Vorlon Data-Centric SaaS Security: detection, response, DLP framing
“Baseline data and identity activity. Detect active attacks with anomaly detection and UEBA. Revoke or rotate risky tokens, API keys, and service accounts instantly, stopping attackers mid-stream. Endpoint and network-centric DLP tools don't secure sensitive data flowing between SaaS apps.”
official 2026-06-17
s5 Vorlon AI Agent Flight Recorder and Action Center announcement
“The Flight Recorder and the Action Center are not two separate products. They are two halves of the same motion. Detection without response is frustration. Response without forensics is guesswork. You need the complete record of what happened and a coordinated path to fix it.”
official 2026-06-17
s6 Vorlon platform page: contextual data classification and remediation testimonials
“Every data flow classified, PII, PHI, PCI, credentials, IP, and tied to the identities and integrations involved. Ran Landau, CTO, Splitit. Anthony Lee-Masis, CISO and VP of IT, ThoughtSpot.”
official 2026-06-18
s7 CTech: Vorlon completes Series A, total 15.7 million (James Spiro, 2024-04-17)
“Vorlon, a platform for comprehensive third-party API security, has completed a Series A funding round led by Accel, bringing its total capital to $15.7 million. App-to-app communication now represents over 80% of internet traffic.”
press 2026-06-17
s8 SiliconANGLE: Vorlon raises 15.7M to tackle third-party API risks (2024-04-17)
“Founded in 2022, Vorlon offers a comprehensive third-party API security platform. Vorlon's solution focuses on enabling organizations to manage third-party APIs proactively, monitor data in motion, identify legitimate versus illegitimate traffic and quickly remediate issues as they occur.”
press 2026-06-17
s9 Pulse 2.0: Vorlon Closes 15.7 Million (Amit Chowdhry, 2024-04-20)
“Accel and Shield Capital are joined by several notable cybersecurity investors, such as Demisto co-founders Slavik Markovich, Rishi Bhargava, Dan Sarel, and Guy Rinat. These investors worked closely with Vorlon's co-founders at Demisto before Palo Alto Networks acquired it for $560 million in 2019.”
press 2026-06-18
s10 Vorlon Trust page: SOC 2 Type II by request
“SOC 2 Type II. If you require a copy of our SOC 2 Type II audit report, please fill out the request form. Your Account Manager will respond.”
official 2026-06-18
s11 Vorlon homepage probe: rendered navigation, calls to action, footer badges
“Get a Demo. Talk to Sales. Customer Support: Access our customer support portal. Footer badge images: soc-type-2, aws partner, 2025-CRN-Stellar-Startups, latio innovators, FS-ISAC-Seal_Affiliate. CISO Report Resource Tile.”
official 2026-07-02
s12 CTech: Vorlon founders' Demisto roles (James Spiro, 2024-04-17)
“Khayat founded Vorlon with CTO Amichay Spivak. Both Khayat and Spivak worked at Demisto and then Palo Alto Networks after the latter acquired the former for $560 million in 2019.”
press 2026-07-02
s13 Vorlon trust-center subdomain probe (trust and security hosts)
“DNS lookups for trust.vorlon.io and security.vorlon.io return no records, and HTTPS requests to both hosts fail with could-not-resolve errors.”
official 2026-07-02

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.