With Wings

Security for AI Identity AccessGovernance Risk ComplianceCloud Security also known as Wing Security, WithWings, Wing

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software.
Founded 2020
Funding $26M
Last updated 2026-08-15

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

With Wings sells security teams software that inventories the AI agents running inside their business, maps what each one can reach, and acts when one moves outside policy. It operated as Wing Security until 12 August 2026, when it renamed itself to match the new product. The old domain no longer serves its own pages: its root and its about, trust, security, privacy and terms paths all resolve to the new marketing homepage. The reviewed sitemap and path probes surfaced no pricing page, no technical documentation and no leadership page. A buyer looking at the company in August 2026 finds customer stories for At-Bay and Monte Carlo and a security review portal that still carries the former name.

Sourced Details

Description With Wings deploys security agents that learn an organization's environment, monitor how its AI agents behave, enforce approved controls, and respond when agent access or behavior moves outside policy. [f1]
Founded 2020 [f2]
HQ Tel Aviv, Israel [f3]
Funding $26M total [f2]
Latest funding Series A ($20M, March 2022, led by GGV Capital) [f2]

Products

Product What it does
Wing An AI security posture management platform whose observability, control, detection, enforcement, mitigation and notification agents govern the AI agents an organization runs.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

Wing inventories the AI agents and identities running across an organization, evaluates their permissions against policy, analyses their behavior for suspicious activity, and triggers approved enforcement when it drifts. These capabilities are mapped to the AI Defense Matrix. [f1]

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

Wing also surfaces AI agents operating outside approved governance, including unsanctioned deployments and unknown AI activity, and maps every API key, token, authentication method, integration and connected service tied to each agent. These capabilities are mapped to the Cyber Defense Matrix. [f4]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Emerging 22 /40 Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 The buyer and the problem are stated plainly. With Wings sells security teams a way to find AI agents that staff connected without telling them and to see what each one can reach, and its pages argue that a static list of agents does not say what any of them is doing or whether it sits inside policy. The one sized demand figure in the reviewed sources comes from a survey another vendor published, so the scale of the problem stays the company's assertion. [s1, s4, s16]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 The platform pages carry feature-level detail: six named agents covering observability, control, detection, enforcement, mitigation and notification, a platform map naming Okta, GitHub, Slack, Snowflake and Salesforce, and per-agent mapping of API keys, tokens and connected services. No documentation portal, architecture write-up or outside technical evaluation appears in the reviewed sources, so the mechanism behind the context layer is the company's own account of it. [s1, s3, s21, s10]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 The dated enabler is the arrival of AI agents in ordinary business workflows. The company announced an AI-first strategy on 30 September 2025 and completed the turn with the 12 August 2026 rename. Buyer-side demand in the reviewed sources stays indirect, because the coverage of that announcement quotes the chief executive rather than buyers, and no analyst category note, budget-line evidence or regulatory mandate for agent security appears. [s16, s17, s6]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 4/5 Both founders ran national cyber organizations first. TechCrunch reported that Noam Shaar had been chief information security officer for the Israeli Defense Forces and that Galit Lubitsky had headed its cyber operations, and Ctech reported that both hold the Israel Defense Award. That is independent recognition of in-domain work, and it rests on reporting from 2022. [s12, s13, s15]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 3/5 The company publishes customer stories for two named companies, At-Bay and Monte Carlo, and the At-Bay story quotes two of its people under their titles. The AWS Marketplace carries a Wing Security seller profile. The homepage names ten further companies without saying what they are, and no revenue figure, customer count or outside report of deployment scale appears in the reviewed sources. [s7, s8, s20, s1]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 2/5 Ctech reported total funding of 26 million dollars, of which a 20 million dollar Series A closed in March 2022, and no later round appears in the reviewed sources. In the four years since, the company has repositioned twice and published no revenue, margin or growth figure, so the reviewed record shows no commercial output a reader can set against the capital raised. [s13, s12, s16, s6]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 2/5 Three surfaces fetched on one day describe the company three different ways. Its AWS Marketplace profile describes software-as-a-service security covering more than 350,000 third-party applications, October 2025 coverage describes an AI-centric expansion of that same platform, and the current site sells agent-based security under a new name. A buyer placing the product in a budget line has to choose among those three descriptions. [s20, s16, s1, s6]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 2/5 The reviewed sources disclose no accumulated dataset, no workflow a customer could not unwind and no purchasing requirement that would sit between a buyer and a replacement. The record therefore shows none of the friction that would slow a larger platform from absorbing this capability, and it also documents no incumbent that has added it. [s1, s3, s11]
Business Risks The rename to With Wings is days old and no independent source in the reviewed record reports it, so a buyer has only the company's account of what changed and what carried over from the software-as-a-service product…
  • The rename to With Wings is days old and no independent source in the reviewed record reports it, so a buyer has only the company's account of what changed and what carried over from the software-as-a-service product.
  • The previous wing.security site no longer serves its own pages, so the product documentation, pricing and legal terms a buyer would read before purchase do not appear anywhere in the reviewed sources.
  • Notable Capital established the Rising in Cyber 2025 list and its own page places its managing partner Oren Yunger on the company's board. The Times of Israel reported that 150 security executives voted on the final roster, so the board tie is context for weighing that recognition rather than evidence about how the roster was chosen.
  • Notable Capital's page places Oren Yunger on Monte Carlo's board as well, and Monte Carlo is one of the two companies whose customer stories With Wings publishes, so that reference and the company share a director.
  • No later funding round appears in the reviewed sources and the positioning has changed twice since the March 2022 Series A, so the reviewed record does not show what is paying for the current build.
  • The platform page states 10,000 agents managed per tenant, 180 native integrations, 50,000 policy decisions per second and seven years of audit retention, and no method, customer or outside measurement behind those figures appears in the reviewed sources.
Problem & Market With Wings sells to security teams whose staff have connected AI agents and tools to company systems without telling them. Its pages frame the gap as one of context rather than count, arguing that a static list of agents does not reveal what each one is doing, who owns it, or whether it sits inside policy. The buyer it addresses is the team that has to answer for that access. The company arrived at this problem from an earlier one. Ctech reported it was founded in 2020, and its own pages say it was created to secure software-as-a-service applications and that it built an identity-centric platform for managing their security posture. It announced a shift to an AI-first strategy on 30 September 2025, and on 12 August 2026 it renamed itself to match. How large the new problem is remains the company's assertion. The one survey in the reviewed sources was published by another security vendor, AppOmni, and it measured confidence in software-as-a-service security rather than agent sprawl: 91 percent of 800 security leaders called themselves confident while 75 percent reported an incident in the past year…

With Wings sells to security teams whose staff have connected AI agents and tools to company systems without telling them. Its pages frame the gap as one of context rather than count, arguing that a static list of agents does not reveal what each one is doing, who owns it, or whether it sits inside policy. The buyer it addresses is the team that has to answer for that access.

The company arrived at this problem from an earlier one. Ctech reported it was founded in 2020, and its own pages say it was created to secure software-as-a-service applications and that it built an identity-centric platform for managing their security posture. It announced a shift to an AI-first strategy on 30 September 2025, and on 12 August 2026 it renamed itself to match.

How large the new problem is remains the company's assertion. The one survey in the reviewed sources was published by another security vendor, AppOmni, and it measured confidence in software-as-a-service security rather than agent sprawl: 91 percent of 800 security leaders called themselves confident while 75 percent reported an incident in the past year. [s1, s4, s2, s6, s16, s13]

Product Capabilities Wing is sold as six named security agents running over a five-part control plane the company calls modules. The observability agent continuously discovers, inventories and maps every AI agent across the environment. The control agent evaluates each agent's identities and permissions against policy and flags drift. The detection agent analyses behavior and identity signals. Enforcement, mitigation and notification act on and route what those three find. Beneath them the company describes one control plane covering discovery, identity, policy, orchestration and audit. Its platform map puts Claude, Copilot, n8n, Glean, Codex, AWS, Ramp, Cursor and Domo above that plane as agents and Okta, GitHub, Slack, Snowflake, Salesforce, Notion, Jira and Confluence below it as systems. The observability agent's page says its discovery is read-only and changes no configurations. What the reviewed sources do not carry is any account of how the context layer works. There is no documentation portal and no architecture description beyond a diagram, so the capability claims rest on the product pages themselves. The four headline numbers on the platform page, 10,000 agents per tenant, 180 native integrations, 50,000 policy decisions per second and seven years of audit retention, carry no stated basis…

Wing is sold as six named security agents running over a five-part control plane the company calls modules. The observability agent continuously discovers, inventories and maps every AI agent across the environment. The control agent evaluates each agent's identities and permissions against policy and flags drift. The detection agent analyses behavior and identity signals. Enforcement, mitigation and notification act on and route what those three find.

Beneath them the company describes one control plane covering discovery, identity, policy, orchestration and audit. Its platform map puts Claude, Copilot, n8n, Glean, Codex, AWS, Ramp, Cursor and Domo above that plane as agents and Okta, GitHub, Slack, Snowflake, Salesforce, Notion, Jira and Confluence below it as systems. The observability agent's page says its discovery is read-only and changes no configurations.

What the reviewed sources do not carry is any account of how the context layer works. There is no documentation portal and no architecture description beyond a diagram, so the capability claims rest on the product pages themselves. The four headline numbers on the platform page, 10,000 agents per tenant, 180 native integrations, 50,000 policy decisions per second and seven years of audit retention, carry no stated basis. [s1, s3, s21, s9, s10]

Competitive Positioning The company positions against two categories rather than against named rivals. Its homepage runs a capability table comparing itself with legacy posture tools and with generic AI governance, and neither category is attached to a named vendor. The record puts the company beside named peers twice, and neither placement is a comparison. The Times of Israel reported that Notable Capital's Rising in Cyber 2025 roster listed Wing Security alongside Cyera, Island, Axonius, Noma Security, Token Security, Gomboc, Descope and Astrix Security. The company's own blog lists Wing Security first among tools for monitoring non-human identity activity, beside Cyberhaven, Operant AI, Akeyless, GitGuardian, Entro Security and Astrix Security. The rename left three artifacts carrying two identities. They are a security review portal still headed Wing Security, an AWS Marketplace profile still describing software-as-a-service security across more than 350,000 third-party applications, and a website selling agent security under a new name…

The company positions against two categories rather than against named rivals. Its homepage runs a capability table comparing itself with legacy posture tools and with generic AI governance, and neither category is attached to a named vendor.

The record puts the company beside named peers twice, and neither placement is a comparison. The Times of Israel reported that Notable Capital's Rising in Cyber 2025 roster listed Wing Security alongside Cyera, Island, Axonius, Noma Security, Token Security, Gomboc, Descope and Astrix Security. The company's own blog lists Wing Security first among tools for monitoring non-human identity activity, beside Cyberhaven, Operant AI, Akeyless, GitGuardian, Entro Security and Astrix Security.

The rename left three artifacts carrying two identities. They are a security review portal still headed Wing Security, an AWS Marketplace profile still describing software-as-a-service security across more than 350,000 third-party applications, and a website selling agent security under a new name. [s1, s18, s5, s11, s20]

Go-to-Market & Traction The customer evidence is published by the company…

The customer evidence is published by the company. Two companies have full stories: At-Bay, which quotes Mike Scutt as its vice president of managed detection and response operations and Travis Mercier as its head of managed detection and response, and Monte Carlo, whose story attributes its quotations to an unnamed security leader. The homepage names ten further companies, among them Carrefour, Apollo and accessiBe, without saying what they are.

Two distribution signals appear, and neither is a proven channel. The homepage lists SOC and exposure teams, risk and AI adoption teams, and MDR and MSSP teams among the groups it addresses, and the AWS Marketplace carries a Wing Security seller profile that still describes the software-as-a-service product.

One reference carries a second relationship. Notable Capital's page for Oren Yunger places him on the boards of both the company and Monte Carlo, so one of its two published customer stories comes from a company that shares a director with it. No revenue figure, customer count or outside report of deployment scale appears in the reviewed sources. [s1, s7, s8, s20, s19]

Team & Credibility Two founders with verifiable national-scale backgrounds anchor the team record. TechCrunch reported that Noam Shaar had been chief information security officer for the Israeli Defense Forces and that Galit Lubitsky had headed its cyber operations, and Help Net Security reported that both had held leadership positions in the 8200 unit. Ctech reported that both hold the Israel Defense Award. Leadership has changed since. Ctech quoted Shaar as chief executive in March 2022, and MSSP Alert named Galit Lubetzky Sharon as co-founder and chief executive in October 2025. Those two sources render her name differently, as Lubitsky and as Lubetzky Sharon, and the reviewed record does not say when the change happened. The reviewed sitemap and path probes surfaced no leadership page and no team page, though the sitemap does list blog posts announcing executive appointments, so the roster has to be assembled from elsewhere. Headcount appears once in the reviewed sources, as the 30 employees Ctech reported at the March 2022 raise, a figure now four years old…

Two founders with verifiable national-scale backgrounds anchor the team record. TechCrunch reported that Noam Shaar had been chief information security officer for the Israeli Defense Forces and that Galit Lubitsky had headed its cyber operations, and Help Net Security reported that both had held leadership positions in the 8200 unit. Ctech reported that both hold the Israel Defense Award.

Leadership has changed since. Ctech quoted Shaar as chief executive in March 2022, and MSSP Alert named Galit Lubetzky Sharon as co-founder and chief executive in October 2025. Those two sources render her name differently, as Lubitsky and as Lubetzky Sharon, and the reviewed record does not say when the change happened.

The reviewed sitemap and path probes surfaced no leadership page and no team page, though the sitemap does list blog posts announcing executive appointments, so the roster has to be assembled from elsewhere. Headcount appears once in the reviewed sources, as the 30 employees Ctech reported at the March 2022 raise, a figure now four years old. [s12, s13, s15, s16, s10]

Trust Readiness The assurance package has three layers, and they are not equally checkable. A trust centre hosted on Conveyor displays SOC 2 Type II and ISO 27001 badges. Beneath them the portal answers ten control questions affirmatively: annual third-party audits, annual penetration testing, a disaster recovery plan, a subprocessor list, cyber insurance, device management, identity and access management, data deletion on request, a privacy policy and a willingness to sign a data processing agreement. Those entries are the company's own answers rather than documents, and the portal gates its document access behind a Get Access control. It also carries the old identity. The portal sits on the former domain and its header reads Wing Security, while the new website's privacy and terms links resolve to nothing. A buyer running a vendor review in August 2026 gets the attestations under one name and the product under another. The product's own safety claims are narrow and stated. The observability agent's page says discovery is read-only and modifies no configurations, and the platform page describes a replayable audit trail of agent decisions and side effects. No outside test of either claim appears in the reviewed sources…

The assurance package has three layers, and they are not equally checkable. A trust centre hosted on Conveyor displays SOC 2 Type II and ISO 27001 badges. Beneath them the portal answers ten control questions affirmatively: annual third-party audits, annual penetration testing, a disaster recovery plan, a subprocessor list, cyber insurance, device management, identity and access management, data deletion on request, a privacy policy and a willingness to sign a data processing agreement. Those entries are the company's own answers rather than documents, and the portal gates its document access behind a Get Access control.

It also carries the old identity. The portal sits on the former domain and its header reads Wing Security, while the new website's privacy and terms links resolve to nothing. A buyer running a vendor review in August 2026 gets the attestations under one name and the product under another.

The product's own safety claims are narrow and stated. The observability agent's page says discovery is read-only and modifies no configurations, and the platform page describes a replayable audit trail of agent decisions and side effects. No outside test of either claim appears in the reviewed sources. [s11, s21, s3, s10]

Competitors AppOmni, Valence Security, Reco, Grip Security, Nudge Security, Astrix Security, Token Security…
Company Relationship Note Compare
AppOmni competes with Sells security for the same applications and AI usage to the same buyer, and the coverage of the company's 2025 repositioning drew its market evidence from AppOmni's own survey.
Valence Security competes with Competes for the same security team's budget for governing applications, identities and AI usage across a company's software estate. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Reco competes with Competes for the discovery and posture budget of the same security team. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Grip Security competes with Competes for the discovery-first entry point into the same buyer. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Nudge Security competes with Competes on discovering the tools and AI services employees adopt without approval, the problem With Wings also enters through.
Astrix Security adjacent Adjacent because it is bought for the machine-identity problem rather than for agent discovery and control. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Token Security adjacent Works the machine-identity side of the same buyer's problem rather than agent discovery and control. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.

Add analyzed competitors to compare them side by side with With Wings.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Exposed 11 /21 Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software. pivot urgently

With Wings holds credentials a funded rival can also obtain. Its SOC 2 Type II and ISO 27001 attestations are earned by many vendors, and the reviewed record names no dataset it holds that others cannot gather. What it does hold is the discovery work it has built since 2020 across the software employees adopt on their own, now pointed at AI agents. That may be a head start rather than a barrier, and the reviewed record does not show how much of the earlier work carried into the new product.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Customers buy software. The company sells six named agents that run against a customer's own environment, and the reviewed sources describe no analyst service beside the product, no expert work included in the offer and no outcome the vendor accepts responsibility for. The software is the thing being paid for.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 A customer accumulates an inventory of agents, identities and connections, policies expressed inside the platform, an audit trail the company says it retains for seven years, and integrations into Okta, GitHub, Slack, Snowflake and Salesforce. Those are the data history and integrations the middle level names. Whether workflows come to depend on the product is not established in the reviewed record, and neither is whether the inventory or the policies can be exported.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 The trust centre displays SOC 2 Type II and ISO 27001 badges above answers asserting annual third-party audits and annual penetration testing, and both the badges and the practices behind them are things a funded rival can obtain as well. The reviewed sources name no regulation that requires this product class and no liability the vendor accepts, so the attestations reassure buyers rather than block a replacement.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 2/3 Reading agent platforms and identity providers through their interfaces, mapping the keys, tokens and connected services behind each agent, and testing them against policy is the non-trivial integration work the middle level names. The reviewed sources carry no patent, no published method and no outside technical evaluation, so the depth of any algorithm behind the context layer is unknown.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3 The two companies with published stories are a cyber insurer that also sells managed security and a data-observability vendor, and the At-Bay story quotes a vice president and a head of managed detection and response, which is the security governance the middle level asks for. The 2025 coverage describes intended technical scale rather than observed buyers. No government customer, sector rule or purchasing requirement appears in the reviewed sources.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 The company describes one control plane spanning discovery, identity, policy, orchestration and audit, with a platform map placing agents above it and enterprise systems below, which is platform surface alongside application features. The reviewed sources name no application that depends on it at runtime and no consumer of its data, and its discovery is described as read-only.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 The AWS Marketplace profile claims the product identifies and resolves vulnerabilities across more than 350,000 third-party applications, which is a coverage claim rather than a disclosed dataset. The current site claims no dataset, names no exclusive input and describes no cross-customer learning, so the reviewed record shows no accumulated asset behind the product.
Strategic Market Segmentation The homepage lists three groups among those it addresses: SOC and exposure teams, risk and AI adoption teams, and MDR and MSSP teams. It tells the third what it offers them, contextual agent observability, enforcement insight and access-risk context added to managed detection and response, and the At-Bay story shows a provider doing exactly that, building Wing into its MDR operations and running managed SaaS security for its own customers. What the reviewed sources do not establish is scale: no partner count, no revenue split, nothing that separates a documented motion from a proven channel. The named customer evidence is two companies. At-Bay's story gives its industry as cyber insurance and managed security, and Monte Carlo's gives data observability. The homepage names ten further companies, among them Carrefour, Apollo, Driivz, Doxim, Tripledot, Electra, accessiBe, Billie, Elco and Covenant Eyes, without saying what any of them does. Company size is not established. The 2025 press coverage said the architecture scales from 1,000 to more than 50,000 employees, which describes intended technical scale rather than observed deployments, and no customer count, revenue figure or regional breakdown appears in the reviewed sources…

The homepage lists three groups among those it addresses: SOC and exposure teams, risk and AI adoption teams, and MDR and MSSP teams. It tells the third what it offers them, contextual agent observability, enforcement insight and access-risk context added to managed detection and response, and the At-Bay story shows a provider doing exactly that, building Wing into its MDR operations and running managed SaaS security for its own customers. What the reviewed sources do not establish is scale: no partner count, no revenue split, nothing that separates a documented motion from a proven channel.

The named customer evidence is two companies. At-Bay's story gives its industry as cyber insurance and managed security, and Monte Carlo's gives data observability. The homepage names ten further companies, among them Carrefour, Apollo, Driivz, Doxim, Tripledot, Electra, accessiBe, Billie, Elco and Covenant Eyes, without saying what any of them does.

Company size is not established. The 2025 press coverage said the architecture scales from 1,000 to more than 50,000 employees, which describes intended technical scale rather than observed deployments, and no customer count, revenue figure or regional breakdown appears in the reviewed sources.

Product Capabilities & AI Advantages The product is packaged as six agents over a learning surface the company calls the Wing Context Layer. Observability continuously discovers, inventories and maps every AI agent across the environment. Control evaluates each agent's identities and permissions against policy and flags drift. Detection analyses behavior and identity signals. Enforcement, mitigation and notification act on and route what those three find. AI sits on both sides of the product. The company's llms.txt describes wrapping Anthropic's model and GitHub Copilot in a policy and audit envelope, which is the clearest statement in the reviewed sources of what the product interposes. Its platform map places a wider set of agent platforms above the control plane without saying which of them the product protects. The evidence stops at the description. There is no documentation portal, no architecture write-up beyond a diagram and no outside technical evaluation, so the context layer the company presents as its differentiator is named rather than explained. Four figures on the platform page, 10,000 agents per tenant, 180 native integrations, 50,000 policy decisions per second and seven years of audit retention, carry no stated basis…

The product is packaged as six agents over a learning surface the company calls the Wing Context Layer. Observability continuously discovers, inventories and maps every AI agent across the environment. Control evaluates each agent's identities and permissions against policy and flags drift. Detection analyses behavior and identity signals. Enforcement, mitigation and notification act on and route what those three find.

AI sits on both sides of the product. The company's llms.txt describes wrapping Anthropic's model and GitHub Copilot in a policy and audit envelope, which is the clearest statement in the reviewed sources of what the product interposes. Its platform map places a wider set of agent platforms above the control plane without saying which of them the product protects.

The evidence stops at the description. There is no documentation portal, no architecture write-up beyond a diagram and no outside technical evaluation, so the context layer the company presents as its differentiator is named rather than explained. Four figures on the platform page, 10,000 agents per tenant, 180 native integrations, 50,000 policy decisions per second and seven years of audit retention, carry no stated basis.

Sales Engagement & Go-to-Market The site's calls to action ask for a demo or a walkthrough…

The site's calls to action ask for a demo or a walkthrough. Its navigation carries a Get a demo control and the platform page a Book a walkthrough control, and the reviewed sources show no trial and no self-service sign-up.

Two distribution signals appear, and neither is sized. The homepage offers MDR and MSSP teams a defined role, and the At-Bay story shows one provider running it in production, but no partner count appears in the reviewed sources. The AWS Marketplace carries a Wing Security seller profile. That profile still describes the software-as-a-service product rather than the agent platform, and the reviewed sources show no product listing or subscription path beneath it.

Demand generation runs on the company's own publishing. The blog carries dated posts through 2026, including ones on 6 April, 6 May, 9 June, 13 July and 1 August, with guides on agentic AI governance and on non-human identity. One of them lists Wing Security first among the tools it names for monitoring non-human identity activity.

Pricing Model No price appears anywhere in the reviewed sources…

No price appears anywhere in the reviewed sources. The site publishes no pricing page, the sitemap lists none, and the AWS Marketplace seller profile carries no figure a buyer could act on.

The charging unit is equally unstated. The 2025 press coverage describes an architecture that scales from 1,000 to more than 50,000 employees, which is a statement about deployment size rather than about what the company bills for, and the reviewed sources name no unit of charge.

The site's calls to action ask for a demo or a walkthrough, so what a buyer can learn about price before contacting the company is nothing.

Product Delivery & Operations Delivery is software-as-a-service reached through interfaces rather than installed agents. The 2025 press coverage described an agentless, API-first architecture that integrates quickly, and the observability agent's page says its discovery is read-only and modifies no configurations. The operational surface the company describes is an audit trail. The platform page promises a replayable, evidence-grade record of every agent decision and side effect, with seven years of retention, and it describes human approval hooks on agent-to-agent handoffs. What a buyer cannot check is how the service runs. No service level commitment, status page, support tier or incident history appears in the reviewed sources, and the sitemap lists no page that would carry them…

Delivery is software-as-a-service reached through interfaces rather than installed agents. The 2025 press coverage described an agentless, API-first architecture that integrates quickly, and the observability agent's page says its discovery is read-only and modifies no configurations.

The operational surface the company describes is an audit trail. The platform page promises a replayable, evidence-grade record of every agent decision and side effect, with seven years of retention, and it describes human approval hooks on agent-to-agent handoffs.

What a buyer cannot check is how the service runs. No service level commitment, status page, support tier or incident history appears in the reviewed sources, and the sitemap lists no page that would carry them.

Earning Customers' Trust The assurance package has three layers, and they are not equally checkable. A trust centre hosted on Conveyor displays SOC 2 Type II and ISO 27001 badges. Beneath them the portal answers ten control questions affirmatively: annual third-party audits, annual penetration testing, a disaster recovery plan, a subprocessor list, cyber insurance, device management, identity and access management, data deletion on request, a privacy policy and a willingness to sign a data processing agreement. Those entries are the company's own answers rather than documents, and the portal gates its document access behind a Get Access control. The identities on those artefacts do not match. The trust centre sits on the former domain and its header reads Wing Security, while the new site's privacy and terms links resolve to nothing. A buyer running a vendor review in August 2026 collects the attestations under one name and the product under another. The product's own safety claims are narrow and stated rather than tested. Discovery is read-only, enforcement actions are described as approved before they fire, and the audit trail is presented as evidence-grade. No outside test of any of those claims appears in the reviewed sources…

The assurance package has three layers, and they are not equally checkable. A trust centre hosted on Conveyor displays SOC 2 Type II and ISO 27001 badges. Beneath them the portal answers ten control questions affirmatively: annual third-party audits, annual penetration testing, a disaster recovery plan, a subprocessor list, cyber insurance, device management, identity and access management, data deletion on request, a privacy policy and a willingness to sign a data processing agreement. Those entries are the company's own answers rather than documents, and the portal gates its document access behind a Get Access control.

The identities on those artefacts do not match. The trust centre sits on the former domain and its header reads Wing Security, while the new site's privacy and terms links resolve to nothing. A buyer running a vendor review in August 2026 collects the attestations under one name and the product under another.

The product's own safety claims are narrow and stated rather than tested. Discovery is read-only, enforcement actions are described as approved before they fire, and the audit trail is presented as evidence-grade. No outside test of any of those claims appears in the reviewed sources.

Platform Strategy & Ecosystem Positioning The integration list is the ecosystem…

The integration list is the ecosystem. The platform map places Claude, Copilot, n8n, Glean, Codex, AWS, Ramp, Cursor and Domo above the control plane as agents and Okta, GitHub, Slack, Snowflake, Salesforce, Notion, Jira and Confluence below it as systems. The observability agent's page adds Azure AD, Google Workspace and ServiceNow to what it reads.

What the company does not offer is a way for others to build on it. The reviewed sources describe no public interface, no software development kit and no partner-built extensions, so the orchestration the platform page advertises stays inside the product.

Distribution beyond direct sales rests on two signals. The homepage lists MDR and MSSP teams among the groups it addresses, and the AWS Marketplace carries a seller profile, though that profile still describes the earlier product and the reviewed sources show no purchasable listing under it.

Team & Execution Capability The founders are the part of the team record that outside sources corroborate. TechCrunch reported that Noam Shaar had been chief information security officer for the Israeli Defense Forces and that Galit Lubitsky had headed its cyber operations. Help Net Security reported that both had held leadership positions in the 8200 unit, and Ctech reported that both hold the Israel Defense Award. Who runs the company now is harder to read from the record. Ctech quoted Shaar as chief executive in March 2022 and MSSP Alert named Galit Lubetzky Sharon as co-founder and chief executive in October 2025. Those two sources render her name differently, as Lubitsky and as Lubetzky Sharon, and the reviewed record does not say when the change happened. The reviewed sitemap and path probes surfaced no leadership page, no team page and no careers page, though the sitemap does list blog posts announcing executive appointments, so the roster has to be assembled from elsewhere. Headcount appears once in the reviewed sources, as the 30 employees Ctech reported at the March 2022 raise…

The founders are the part of the team record that outside sources corroborate. TechCrunch reported that Noam Shaar had been chief information security officer for the Israeli Defense Forces and that Galit Lubitsky had headed its cyber operations. Help Net Security reported that both had held leadership positions in the 8200 unit, and Ctech reported that both hold the Israel Defense Award.

Who runs the company now is harder to read from the record. Ctech quoted Shaar as chief executive in March 2022 and MSSP Alert named Galit Lubetzky Sharon as co-founder and chief executive in October 2025. Those two sources render her name differently, as Lubitsky and as Lubetzky Sharon, and the reviewed record does not say when the change happened.

The reviewed sitemap and path probes surfaced no leadership page, no team page and no careers page, though the sitemap does list blog posts announcing executive appointments, so the roster has to be assembled from elsewhere. Headcount appears once in the reviewed sources, as the 30 employees Ctech reported at the March 2022 raise.

Sources

Company Detail Sources (4)
Id Source Tier Accessed
f1 With Wings: homepage official 2026-08-15
f2 Ctech: Wing Security, led by IDF cyber vets, raises $20 million Series A press 2026-08-15
f3 SecurityWeek: SaaS Security Startup Wing Emerges From Stealth With $26 Million in Funding press 2026-08-15
f4 With Wings: Observability Agent official 2026-08-15
Profile Analysis Sources (22)
Id Source Tier Accessed
s1 With Wings: homepage official 2026-08-15
s2 With Wings: about page official 2026-08-15
s3 With Wings: platform overview official 2026-08-15
s4 With Wings: use cases official 2026-08-15
s5 With Wings: blog index listing post dates official 2026-08-15
s6 With Wings: Wing Security becomes WithWings official 2026-08-15
s7 With Wings: At-Bay customer story official 2026-08-15
s8 With Wings: Monte Carlo customer story official 2026-08-15
s9 With Wings: llms.txt official 2026-08-15
s10 With Wings sitemap: probe for pricing, documentation, careers, leadership and legal pages, 2026-08-15, none listed and /privacy and /terms return 404 official 2026-08-15
s11 Wing Security Trust Center on Conveyor: probe of trust. and security. subdomains plus /trust and /compliance, rendered 2026-08-15, labels client-rendered official 2026-08-15
s12 TechCrunch: Wing Security launches its end-to-end SaaS security platform, raises $26M press 2026-08-15
s13 Ctech: Wing Security, led by IDF cyber vets, raises $20 million Series A press 2026-08-15
s14 SecurityWeek: SaaS Security Startup Wing Emerges From Stealth With $26 Million in Funding press 2026-08-15
s15 Help Net Security: Wing Security emerges from stealth and raises $26 million to accelerate growth press 2026-08-15
s16 MSSP Alert: Wing Security Expands SaaS Security Platform with AI-Centric Strategy press 2026-08-15
s17 Security Systems News: Wing Security makes shift to AI security-centric company press 2026-08-15
s18 The Times of Israel: 11 Israeli startups dominate list of most promising global cybersecurity firms press 2026-08-15
s19 Notable Capital: Oren Yunger partner page other 2026-08-15
s20 AWS Marketplace: Wing Security seller profile other 2026-08-15
s22 Wing Security legacy domain: probe of wing.security root plus about-us, trust, security, privacy-policy and terms-of-service paths, 2026-08-15, all redirect official 2026-08-15
s21 With Wings: Observability Agent official 2026-08-15
Deep-Dive Sources (22)
Id Source Tier Accessed
s1 With Wings: homepage official 2026-08-15
s2 With Wings: about page official 2026-08-15
s3 With Wings: platform overview official 2026-08-15
s4 With Wings: use cases official 2026-08-15
s5 With Wings: blog index listing post dates official 2026-08-15
s6 With Wings: Wing Security becomes WithWings official 2026-08-15
s7 With Wings: At-Bay customer story official 2026-08-15
s8 With Wings: Monte Carlo customer story official 2026-08-15
s9 With Wings: llms.txt official 2026-08-15
s10 With Wings sitemap: probe for pricing, documentation, careers, leadership and legal pages, 2026-08-15, none listed and /privacy and /terms return 404 official 2026-08-15
s11 Wing Security Trust Center on Conveyor: probe of trust. and security. subdomains plus /trust and /compliance, rendered 2026-08-15, labels client-rendered official 2026-08-15
s12 TechCrunch: Wing Security launches its end-to-end SaaS security platform, raises $26M press 2026-08-15
s13 Ctech: Wing Security, led by IDF cyber vets, raises $20 million Series A press 2026-08-15
s14 SecurityWeek: SaaS Security Startup Wing Emerges From Stealth With $26 Million in Funding press 2026-08-15
s15 Help Net Security: Wing Security emerges from stealth and raises $26 million to accelerate growth press 2026-08-15
s16 MSSP Alert: Wing Security Expands SaaS Security Platform with AI-Centric Strategy press 2026-08-15
s17 Security Systems News: Wing Security makes shift to AI security-centric company press 2026-08-15
s18 The Times of Israel: 11 Israeli startups dominate list of most promising global cybersecurity firms press 2026-08-15
s19 Notable Capital: Oren Yunger partner page other 2026-08-15
s20 AWS Marketplace: Wing Security seller profile other 2026-08-15
s22 Wing Security legacy domain: probe of wing.security root plus about-us, trust, security, privacy-policy and terms-of-service paths, 2026-08-15, all redirect official 2026-08-15
s21 With Wings: Observability Agent official 2026-08-15

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.