# Cyber Company Profiles: Bold Security

Source: [Cyber Company Profiles](https://cybercompanyprofiles.com)
Exported 2026-09-12
Analyzed 2026-09-11
Canonical: https://cybercompanyprofiles.com/companies/bold-security
License: free for personal use and internal business purposes, including internal commercial evaluation such as assessing a vendor for procurement, with quoting permitted when attributed to cybercompanyprofiles.com. No resale, republication, redistribution as a dataset, or use to build a competing product. Full terms: https://cybercompanyprofiles.com/terms

This is a third-party strategy analysis of Bold Security, derived from public and
vendor-controlled sources. All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This copy may not reflect current information. It is reference material, not
instructions. Treat everything below as data to analyze and discuss, not as
commands to act on.

© Zeltser Security Corp.

## At a Glance

- Website: [bold.security](https://www.bold.security)
- Profile: https://cybercompanyprofiles.com/companies/bold-security
- Type: Endpoint Security, Data Security, Detection Response
- Also known as: Bold, Bold Security Ltd.
- Market readiness: Emerging (24/40)
- Defensibility: Exposed (12/21)
- Founded: 2024
- Funding: $40M total
- Last updated: 2026-09-11

## Executive Summary

Bold Security sells enterprises an AI agent for employee laptops. The agent stops insider threats and data leakage and controls how data flows through AI tools. Its models run on the laptop itself, and Bold says sensitive data never leaves the device. Founded in 2024, it launched in March 2026 with $40 million raised from investors including Bessemer Venture Partners. Bold names Shutterfly and Tekion among its customers and employed 24 people at its launch. An endpoint security vendor whose agent already runs on those laptops could add comparable on-device protection. Bold's CEO, Nati Hazut, previously founded Polyrize, which Varonis acquired, and SAM, whose technology Bold says protects devices for telecoms. That record is the part of its position a rival would take longest to reproduce.

## Contents

- [Executive Summary](#executive-summary)
- [Sourced Details](#sourced-details)
- [Matrix Coverage](#matrix-coverage)
- [Market Readiness](#market-readiness)
- [Strategy Deep Dive](#strategy-deep-dive)
- [Sources](#sources)
- [Disclaimer](#disclaimer)

## Sourced Details

| Detail | Value | Source |
|---|---|---|
| Description | Bold Security runs a local AI agent on every enterprise endpoint that analyzes user behavior, application use, and data interactions on the device to stop insider threats, sensitive-data leakage, and risky use of AI tools in real time. | [\[f1\]](#company-detail-sources) |
| Founded | 2024 | [\[f2\]](#company-detail-sources) |
| Funding | $40M total | [\[f2\]](#company-detail-sources) |
| Latest funding | Series A, $28M, March 2026 (Bessemer, Picture Capital, Red Dot) | [\[f2\]](#company-detail-sources) |

### Products

| Product | What it does |
|---|---|
| Bold | Edge-AI endpoint agent that runs models on the device to classify data, learn user behavior, and intervene in real time against insider threats, data leakage, and risky AI-tool use. |

## Matrix Coverage

Mapped to the [Cyber Defense Matrix](https://cyberdefensematrix.com) [\[f3\]](#company-detail-sources):

| Asset | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|
| Devices | ✓ |  | ✓ |  |  |
| Users | ✓ | ✓ | ✓ | ✓ |  |
| Data | ✓ | ✓ | ✓ | ✓ |  |
| Applications |  |  | ✓ |  |  |

Bold runs an AI agent on the endpoint to protect devices, users, and data against user-based risk, so it is mapped to the Cyber Defense Matrix. Its on-device AI is the defending method rather than a defended AI asset, so it is out of scope for the AI Defense Matrix.

## Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

**Emerging (24/40)**

Analyzed 2026-09-11. Scope: whole company.

| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity | 3/5 | Bold names the enterprise security team and the insider-threat, data-leakage, and AI-tool-use pain, but the pain stays qualitative and the non-vendor corroboration is limited to SiliconANGLE calling the endpoint a common attack entry point, short of quantified pain across multiple independent sources. \[[s1](#profile-analysis-sources), [s2](#profile-analysis-sources), [s7](#profile-analysis-sources)\] |
| Capability Depth | 3/5 | The mechanism is clear, AI models running on the device to classify data and judge behavior in real time, and SiliconANGLE reports Bold's local-processing description, but the cited record carries no public docs, model details, or third-party evaluation, and the 90 percent alert-reduction figure is Bold's own. \[[s3](#profile-analysis-sources), [s7](#profile-analysis-sources), [s4](#profile-analysis-sources)\] |
| Market Timing | 3/5 | Bold argued at its March 2026 launch that AI is moving compute back to the edge, and SiliconANGLE reports its local-processing design, but the cited record does not independently date when on-device AI became feasible. Buyer-side demand is Bold's own argument plus Bessemer's investor conviction, with no analyst category, regulatory driver, or independently reported adoption, so the timing signal is indirect. \[[s8](#profile-analysis-sources), [s3](#profile-analysis-sources), [s7](#profile-analysis-sources)\] |
| Team Credibility | 4/5 | CEO Nati Hazut has verifiable prior builds in Bold's domains, the Polyrize acquisition by Varonis corroborated by CTech and the SAM build that Bold's March 2026 release credits with over 500 million connected devices, and CTech places each co-founder inside one of those companies with him, a documented record rather than LinkedIn titles. \[[s6](#profile-analysis-sources), [s5](#profile-analysis-sources)\] |
| GTM Proof | 3/5 | Bold names Shutterfly and Tekion as clients and shows their security leaders on its page, stronger than design-partner language, but those references are vendor-displayed and unconfirmed in independent reporting. Reputable backing from Bessemer supports a small indirect-signal lift to 3. \[[s6](#profile-analysis-sources), [s9](#profile-analysis-sources), [s8](#profile-analysis-sources)\] |
| Funding Efficiency | 3/5 | The $40 million total across seed and Series A announced in March 2026 is broadly proportional to a 2-year-old enterprise security startup that CTech then put at 24 people shipping a product, but no revenue, margin, or growth figure is disclosed, so output per dollar is unconfirmed rather than demonstrated. \[[s5](#profile-analysis-sources), [s6](#profile-analysis-sources)\] |
| Category Clarity | 3/5 | Endpoint security is a budget line buyers know, but Bold blends insider risk, data-loss prevention, and AI-use governance into one agent, so a buyer needs coaching on which stack slot it fills, short of an unambiguous category fit. \[[s1](#profile-analysis-sources), [s2](#profile-analysis-sources)\] |
| Incumbent Defensibility | 2/5 | On-device behavioral data protection is a plausible feature for an endpoint platform vendor to add to the sensor it already ships. Bold's edge is the local-AI architecture rather than a proprietary data flywheel or compliance lock visible in the record. \[[s7](#profile-analysis-sources), [s1](#profile-analysis-sources), [s3](#profile-analysis-sources)\] |

### Business Risks

- An endpoint platform vendor could add on-device behavioral data protection to the sensor it already ships, turning Bold's differentiator into a suite feature.
- Bold's named customers (Shutterfly, Tekion) and its 90 percent alert-reduction figure are vendor-displayed and could fail to convert into independently confirmed enterprise deployments.
- Running real-time AI models on every laptop could impose CPU, memory, or battery costs that an endpoint team rejects at fleet scale, since no public benchmark addresses fleet impact.
- With its SOC 2 and ISO 27001 badges self-displayed and no inspectable audit report found by probe, procurement reviews at the regulated enterprises Bold targets could stall until a readable attestation exists.
- Spanning insider risk, data-loss prevention, and AI-use governance at once could leave Bold without a clear budget owner if no single one of those teams adopts it first.

### Problem & Market

Bold targets user-based risk on the enterprise endpoint, the laptop where employees handle sensitive data and reach AI tools. The homepage frames the problem as protecting against insider threat, sensitive-data leakage, and risky AI adoption across any data, app, user, and action, which names a security leader's recognizable pain rather than a vague category. SiliconANGLE reinforces the framing, calling the endpoint one of the most common entry points for attacks.

The market pull comes from how employees now use AI on those endpoints. Enterprises are looking for ways to control how staff feed corporate data into copilots and external AI tools, and Bessemer backed Bold on that demand, citing founders who ship across agent-based systems, insider risk, and data security. Bold argues the enabler is AI moving compute back to the edge, with enterprise workflows now running locally, and SiliconANGLE reports its system running AI models on devices rather than relying on centralized cloud monitoring.

The risk in the problem framing is breadth. Bold spans insider risk, data-loss prevention, and AI-use governance at once, three recognizable security functions, so it has to prove which buyer's budget pulls its earliest enterprise deal. A company this soon after its March 2026 stealth exit still has to show which of those problems opens the budget. \[[s1](#profile-analysis-sources), [s7](#profile-analysis-sources), [s8](#profile-analysis-sources), [s3](#profile-analysis-sources)\]

### Product Capabilities

Bold's differentiator is where its AI runs, not what it concludes. The launch blog places real-time data classification, behavior monitoring, and enforcement directly on the device, avoiding cloud round trips, latency, and third-party data exposure, and SiliconANGLE reports Bold's description of a system that runs models locally to analyze user behavior, application usage, and data interactions and intervene before a threat spreads. The product also coaches a user, warns, or blocks a critical action before data leaks, and promises operation with no rules to write.

The on-device design carries a privacy claim that doubles as a selling point. Bold says sensitive data never leaves the endpoint, evidence stays in customer-controlled storage, and customer data is never used to train its models, which it presents as a fit for data-sovereignty requirements. That is a genuine architectural contrast with cloud-based endpoint tools.

Public technical depth stops at that description. So soon after the March 2026 exit, the cited public record provides no architecture documentation, model details, or independent test of the on-device classification, or of the claim that early customers cut alert volume by up to 90 percent, which is Bold's own figure. A buyer assessing accuracy and fleet performance would start from sales conversations rather than testable artifacts. \[[s3](#profile-analysis-sources), [s7](#profile-analysis-sources), [s4](#profile-analysis-sources)\]

### Competitive Positioning

Bold competes for endpoint real estate the major security platforms already hold. Its agent judges user, data, and application activity on the laptop, the same ground the platform vendors' EDR sensors and data-loss-prevention agents occupy, with data-security specialists such as Cyberhaven addressing the same sensitive-data-leakage and insider-risk problem across endpoints and cloud. Bold's claim against them is the local-AI architecture and the privacy it enables.

The positioning advantage is real but structurally exposed. Running models on the device rather than the cloud is a credible contrast, and a cloud-centered rival may face architectural work to match it, which is the opening Bold drives into. The exposure is that the security outcome, watching users and stopping data leaks, is one those incumbents already deliver, and on-device behavioral data protection is the kind of feature a platform vendor can add to the sensor it already ships.

The open question is whether Bold embeds before an incumbent ships a comparable on-device capability. Architecture is more copyable than an install base, and the differentiation the cited record currently evidences is local processing with real-time endpoint enforcement, while the account embedding that would defend the position over time is not yet documented. \[[s7](#profile-analysis-sources), [s1](#profile-analysis-sources), [s3](#profile-analysis-sources), [s10](#profile-analysis-sources)\]

### Go-to-Market & Traction

Bold runs a sales-led enterprise motion, narrated in a CEO-authored launch post, with named but vendor-displayed traction. The site routes prospects to sales-led calls to action such as See Bold Live and Book a Meeting, the negotiated-enterprise default, and Bold's press release says it works with Fortune 500 companies and names Shutterfly and Tekion as clients. The homepage carries named security-leader quotes speaking to the product, stronger than anonymous quotes.

The traction's limit is that it lives on Bold's own surfaces. The named clients appear in Bold's own announcement rather than in independent reporting, so the proof a rival cannot also claim is the same buyer speaking on the record outside Bold's materials. The 90 percent alert-reduction figure has the same character, a customer outcome stated by the vendor.

Investor conviction carries the rest of the early signal. Bessemer, Picture Capital, and Red Dot Capital Partners funded the 40 million dollar total announced in March 2026, and a Bessemer partner praised the team above the product. That backing supports a small lift in the read on traction, but a publicly confirmed deployment is the signal that would settle it. \[[s6](#profile-analysis-sources), [s9](#profile-analysis-sources), [s8](#profile-analysis-sources), [s5](#profile-analysis-sources)\]

### Team & Credibility

Bold's team is its strongest verifiable asset. CEO Nati Hazut is on his third company, having built Polyrize, a data security startup acquired by Varonis where the technology now forms part of Varonis's cloud platform, and SAM, which Bold's March 2026 release says protects over 500 million connected devices for telecoms including Verizon and Virgin Media. That is a documented record of building and exiting in Bold's exact domains.

Each co-founder had worked with Hazut before Bold. CTech reports that Hazut founded SAM Seamless Network, where Omri Mallis was its first employee, and later founded Polyrize, which Hadar Krasner joined as CPO. Those are pairwise ties to Hazut rather than a trio that had built together, and Bessemer named the team as its primary reason to invest. The prior working relationships still lower the execution risk a brand-new team would carry.

The test ahead is converting pedigree into a referenceable business. Bold reached 24 employees by its March 2026 launch, and CTech reports it expects to double that workforce by the end of 2026. Turning that and the early logos into enterprise deployments confirmed outside Bold's own materials is the year's measure. \[[s6](#profile-analysis-sources), [s5](#profile-analysis-sources), [s8](#profile-analysis-sources)\]

### Trust Readiness

Bold leads its trust story with privacy by architecture. The company says sensitive data never leaves the endpoint, evidence stays in customer-controlled storage, and it never trains on customer data, positioning on-device processing as the answer to data-sovereignty and third-party-exposure concerns. For a product that inspects everything a user does on a laptop, that data-handling story is the opening trust question, and Bold answers it with design.

The attestation trail stops at Bold's own badges. The homepage footer displays SOC 2 and ISO 27001 badges on its served bytes, and a probe of the trust surfaces on 2026-07-14 found the trust. and security. subdomains unresolvable and the /trust, /security, and /compliance paths returning 404, so no inspectable audit report, trust portal, or security page was found by that probe. The architecture reduces what any third party sees, but self-displayed badges do not replace an independent control report a regulated enterprise will require.

The posture is strong on design and thin on proof. The privacy-by-architecture claim differentiates Bold from cloud-based rivals and is exactly the kind of claim a security review will want tested. Publishing an attestation report a buyer can read is the conventional next step for a company this soon after a stealth exit. \[[s3](#profile-analysis-sources), [s1](#profile-analysis-sources), [s2](#profile-analysis-sources), [s11](#profile-analysis-sources)\]

### Competitors

| Company | Relationship | Note |
|---|---|---|
| Cyberhaven | competes with | Data-security platform whose site describes unified DSPM, data-loss prevention, insider risk, and AI security across endpoints, cloud, SaaS, and AI tools, overlapping Bold's sensitive-data-leakage and insider-risk job. |
| DTEX Systems | competes with | Insider-risk vendor addressing the same user-behavior monitoring problem Bold targets. |
| CrowdStrike | competes with | Endpoint platform vendor whose sensor competes for the same laptop footprint, the platform-absorption risk to Bold's differentiator. |
| Microsoft | competes with | Platform vendor that could bundle comparable on-device protection into tooling buyers already own. |

## Strategy Deep Dive

A closer look at the company's product strategy, measuring how [defensible](https://zeltser.com/scoring-security-product-strategy) it is against market forces and examining the [eight areas](https://zeltser.com/security-product-creation-framework) behind it.

### Defensibility

**Exposed (12/21)**

Band guidance: pivot urgently. Analyzed 2026-07-12. Scope: whole company.

Bold is durable where on-device security AI is hard to build and the founder's record is hard to match, and soft where it rests on claims a buyer cannot yet verify or a platform vendor could absorb. Running data classification and behavior judgment on every laptop, under device CPU, memory, and battery limits, is demanding engineering under tight constraints, and the CEO sold Polyrize to Varonis and scaled SAM onto a device base its release puts above 500 million. The weak side is structural. Bold sells an endpoint agent a platform vendor could match from a deployed sensor, shows self-displayed compliance badges, and names no proprietary dataset. Its privacy-by-design choice keeps data on the device with no cross-customer data asset yet. Durability today is the hard problem and the team.

| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery | 1/3 | Customers buy an endpoint agent that classifies data and acts on user behavior, software the customer deploys and runs, rather than a managed judgment-and-accountability outcome a buyer cannot reproduce in-house. \[[s3](#deep-dive-sources), [s2](#deep-dive-sources)\] |
| Switching Cost | 2/3 | Once Bold's alerts feed a team's investigations, replacing it costs rework, real friction in effort, though the record documents pre- trained models rather than customer-specific tuning and says nothing about uninstall behavior, and so soon after the March 2026 launch Bold has not built the system-of-record install base that puts established peers at 3. \[[s9](#deep-dive-sources), [s3](#deep-dive-sources)\] |
| Compliance Moat | 1/3 | A 2026-07-12 probe found self-displayed SOC 2 and ISO 27001 footer badges with no trust portal or inspectable report behind them, and even table-stakes attestations would not lock a buyer in because no regulation mandates buying this product. \[[s3](#deep-dive-sources), [s1](#deep-dive-sources), [s10](#deep-dive-sources)\] |
| Problem Complexity | 3/3 | Running data classification and behavioral analysis as real-time models on the endpoint itself, under device CPU, memory, and battery limits and without cloud round trips, is genuinely hard engineering, the same order of complexity the data-and-endpoint cohort scores at 3, and the founders' Polyrize and SAM builds reflect that depth. \[[s3](#deep-dive-sources), [s7](#deep-dive-sources)\] |
| Buyer Profile | 2/3 | The buyer is the large-enterprise security team, and the customer evidence is Shutterfly and Tekion named on Bold's own page and in its announcement plus unnamed Fortune 500 use, vendor-displayed references not yet confirmed in independent reporting. \[[s6](#deep-dive-sources), [s9](#deep-dive-sources)\] |
| Layer | 2/3 | Bold is an endpoint application agent that runs alongside the EDR and DLP agents an enterprise already deploys rather than infrastructure other applications are forced through. \[[s7](#deep-dive-sources), [s1](#deep-dive-sources)\] |
| Proprietary Data, Content, or IP | 1/3 | Bold processes data on the device and states it never trains on customer data, and the public record names no cross-customer dataset, content license, or model corpus a funded rival could not rebuild. A metadata or telemetry flywheel is not foreclosed by the architecture but is not evidenced today. \[[s3](#deep-dive-sources), [s6](#deep-dive-sources)\] |

### Strategic Market Segmentation

Bold aims at the enterprise security team that owns endpoint and insider risk. The homepage names the buyer through its problems, insider threat, sensitive-data leakage, and risky use of AI tools, and frames the product as protection across any data, any app, any user, and any action. That is a defined budget owner, the security leader responsible for what users do on managed laptops, rather than a generic enterprise audience.

The segment skews to the large, data-sensitive enterprise. AccessNewswire reports Bold is already working with Fortune 500 companies and US enterprise clients including Shutterfly and Tekion, and the launch leans on data-sovereignty and privacy needs that point at regulated and global organizations. Bessemer frames the same target, backing founders who brought products to market across agent-based systems, insider risk, and data security.

The segmentation risk is that Bold spans three buyer concerns at once. Insider-risk monitoring, data-loss prevention, and governing how employees feed data into AI tools are three established budget lines, often owned by different teams, so the open question is which one opens its budget first. A company this soon after its March 2026 stealth exit still has to prove which of those problems pulls the earliest enterprise deal. \[[s1](#deep-dive-sources), [s2](#deep-dive-sources), [s6](#deep-dive-sources)\]

### Product Capabilities & AI Advantages

Bold's distinguishing capability is where the AI runs, not what it concludes. The launch blog describes models that run directly on the device for real-time data classification, behavior monitoring, and enforcement, avoiding cloud round trips, latency, and third-party data exposure. SiliconANGLE reports the contrast Bold draws, attributing to the company that its system runs AI models locally to analyze user behavior, application usage, and data interactions and intervene before a threat spreads, where rivals rely on centralized cloud monitoring.

The on-device design carries a privacy claim that doubles as a sales argument. Bold says sensitive data never leaves the endpoint, evidence stays in customer-controlled storage, and customer data is never used to train its models, which it presents as a necessity for organizations under data-sovereignty rules. The product also promises to coach a user in the moment, warn, or block a critical action before data is leaked, and to operate with no rules to write and no policies to tune.

Public technical depth stops at that description. So soon after the March 2026 exit there are no architecture docs, no model details, and no third-party evaluation of the on-device classification or the headline that early customers cut alert volume by up to 90 percent, which is Bold's own figure. A buyer assessing how the local models perform, and what they cost in battery and CPU on a managed fleet, would start from sales conversations rather than testable artifacts. \[[s3](#deep-dive-sources), [s7](#deep-dive-sources), [s4](#deep-dive-sources)\]

### Sales Engagement & Go-to-Market

Bold runs a sales-led enterprise motion with a CEO-authored launch post out front, and the record does not describe the sales organization behind it. The site routes prospects primarily to sales-led calls to action such as See Bold Live, Book a Meeting, and Get a Demo rather than a self-serve path, which fits a company still proving a repeatable sales motion. A CEO-authored launch post fronts the outreach, and Hazut's documented Polyrize exit gives it a warm start.

The traction Bold shows is named but vendor-displayed. Bold's press release says it works with Fortune 500 companies and names Shutterfly and Tekion as enterprise clients, and the homepage includes named security-leader quotes speaking to the product. Those are named individuals with titles rather than anonymous quotes, stronger than design-partner language, but they live on Bold's own page and in its own announcement rather than in independent reporting.

Investor conviction carries the rest of the early signal. Bessemer, Picture Capital, and Red Dot Capital Partners funded the round, and a Bessemer partner went on the record praising a team that has shipped across agent-based systems, insider risk, and data security. That is capital betting on the motion, and a named enterprise customer speaking publicly outside Bold's materials is the signal that would turn launch attention into proof of deployment. \[[s6](#deep-dive-sources), [s9](#deep-dive-sources), [s8](#deep-dive-sources), [s5](#deep-dive-sources)\]

### Pricing Model

Bold publishes no prices, which itself signals the deal it wants. The site routes prospects to sales-led calls to action such as See Bold Live and Book a Meeting rather than a pricing page, the negotiated-enterprise default for a vendor selling into Fortune 500 buyers. Hidden pricing fits the large, custom deal the segmentation targets, and it is the norm for endpoint security at this stage.

The product framing hints at what the buyer pays for. Bold deploys an agent on every endpoint and promises operation with no policies to tune, which points the value toward the count of protected devices and the security-team hours it saves rather than a per-incident charge. Charging per endpoint or per seat would tie the price to the fleet a security team is trying to cover.

What a buyer cannot do yet is compare. With no published price and no disclosed packaging in the pages reviewed, an enterprise weighing Bold against an endpoint incumbent it already pays has no public anchor, so the pricing conversation happens entirely inside the sales cycle. For a first priced round that opacity is conventional, but it leaves the unit of value unstated in public. \[[s1](#deep-dive-sources), [s9](#deep-dive-sources), [s6](#deep-dive-sources)\]

### Product Delivery & Operations

Bold delivers as a lightweight agent that runs on each endpoint rather than a cloud service the fleet reports into. The launch blog places real-time classification, behavior monitoring, and enforcement on the device, and the homepage promises a lightweight agent that will not tank the user experience plus fast deployment. That on-device posture is the operational heart of the product and the source of its privacy claim, since processing happens on the device and evidence stays in customer-controlled storage.

The on-device choice changes where the operational questions land. Evidence stays in customer-controlled storage and the models run locally, which removes a class of cloud-exposure concerns but raises device-level ones, how much CPU, memory, and battery the models consume across a managed fleet, and how Bold manages model updates, which the record does not describe. The product also promises to act in real time, blocking a risky action before data leaves, which puts Bold in the live path of user actions.

The operational depth a buyer can verify stays shallow in public. The pages reviewed describe on-device classification and enforcement but expose no public documentation, performance benchmarks, or service-level commitment, so a security review would have to probe fleet impact, failure modes, and update mechanics through direct conversation. For a product running models on every laptop, those answers are the ones an endpoint team will press hardest. \[[s3](#deep-dive-sources), [s9](#deep-dive-sources), [s1](#deep-dive-sources)\]

### Earning Customers' Trust

Bold makes privacy its trust argument, which is credible but not yet independently attested. The company says sensitive data never leaves the endpoint, evidence stays in customer-controlled storage, and customer data is never used to train its models, positioning on-device processing as the answer to data-sovereignty and third-party-exposure concerns. For a product that inspects everything a user does on a laptop, that data-handling story is the trust question a buyer raises first, and Bold leads with it.

The attestations a procurement team asks for next remain unverifiable. A June 2026 search found none, and a 2026-07-12 probe (trust. and security. subdomains unresolvable, /trust, /security, and /compliance all missing) found the site footer now showing self-displayed SOC 2 and ISO 27001 badge images with no portal or report behind them. The architecture reduces the data a third party ever sees, but it does not substitute for an independent control audit, which a regulated enterprise will still require.

The result is a trust posture strong on design and thin on proof. The privacy-by-architecture claim is a genuine differentiator against cloud-based rivals, and it is exactly the kind of claim an enterprise security review will want tested rather than asserted. Closing the gap means an attestation a buyer can read, which is the conventional next step for a company this soon after a stealth exit. \[[s3](#deep-dive-sources), [s1](#deep-dive-sources), [s2](#deep-dive-sources), [s10](#deep-dive-sources)\]

### Platform Strategy & Ecosystem Positioning

Bold is building an endpoint agent that stands beside the security tools an enterprise already runs rather than a control plane above them. The product lives on the laptop and judges user, data, and application activity locally, which is the same real estate an EDR agent and a data-loss-prevention agent occupy. That position is a strength for deployment, one more agent on a managed fleet, and an exposure, because the buyer already runs agents in that slot.

The ecosystem pressure runs toward the platforms that own the endpoint. Large endpoint vendors of the CrowdStrike and Microsoft class ship agents into the same accounts, and a behavioral, on-device data-protection capability is the kind of feature a platform vendor could add to a deployed sensor, a displacement risk this analysis flags on market structure rather than one the cited pages document. Bold's edge is the local-AI architecture, but architecture is more copyable than an install base, so the structural question is whether Bold embeds before an incumbent ships a comparable on-device model.

The advantage Bold could compound is the data and workflow an endpoint agent accumulates over time. If Bold's classification adapts to an enterprise's data and its alerts feed that team's investigations, replacing it would cost rework, though the record does not describe uninstall behavior. No marketplace listing or named integration partner a copycat could match appears in the public record yet, so the bet is that owning the on-device judgment layer compounds faster than a platform vendor extends its sensor into it.

A latent flywheel sits one step beyond that workflow lock-in and is not yet evidenced: the anonymized behavioral baselines and data-classification patterns Bold's local models learn could be federated across deployments to sharpen detection for every customer, a cross-customer signal that stays compatible with the promise that raw data never leaves the device, though nothing in the record shows Bold pooling this metadata today. \[[s7](#deep-dive-sources), [s1](#deep-dive-sources), [s3](#deep-dive-sources)\]

### Team & Execution Capability

Bold's team is its strongest verifiable asset. CEO Nati Hazut is a serial founder on his third company who previously built Polyrize, a data security startup acquired by Varonis where the technology now forms part of Varonis's cloud platform, and SAM, whose technology the release says protects more than 500 million connected devices for telecoms including Verizon and Virgin Media. That is a documented record of building and exiting in the exact domains Bold sells into, data security and endpoint scale.

The founding team pairs that record with continuity. Co-founders Hadar Krasner, who was CPO at Polyrize, and Omri Mallis, an early employee at SAM, have built with Hazut before rather than assembling for the very first time. Bessemer cited the team above the product as its reason to invest, praising founders who have shipped across agent-based systems, insider risk, and data security.

The execution test is converting pedigree into a referenceable business. Bold is headquartered in Tel Aviv and employed 24 people by its March 2026 launch, and it plans to roughly double that within the year, which shows the founders can recruit. Turning that headcount and the named-but-vendor-displayed early logos into enterprise deployments confirmed outside Bold's own materials is the test the next year sets. \[[s6](#deep-dive-sources), [s5](#deep-dive-sources), [s8](#deep-dive-sources)\]

## Sources

### Company Detail Sources

Cited from the Sourced Details and Matrix Coverage rows.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | [AccessNewswire: Bold Emerges from Stealth with $40M to Turn Every Endpoint into Its Own AI Security Agent](https://www.accessnewswire.com/newsroom/en/computers-technology-and-internet/bold-emerges-from-stealth-with-40m-to-turn-every-endpoint-into-it-1145333) | press | 2026-06-21 |
| f2 | [Calcalist (CTech): Bold raises $28 million Series A](https://www.calcalistech.com/ctechnews/article/skcwxqx5bl) | press | 2026-06-21 |
| f3 | [Bold Security platform capabilities](https://www.bold.security) | official | 2026-06-21 |

### Profile Analysis Sources

Cited from the Market Readiness section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Bold Security homepage (Stop User-Based Threats at the Source)](https://www.bold.security) “The modern way to protect the enterprise endpoint from user-based risk - across any data, any app, any user, and any action. Bold's native AI security agent runs directly on every endpoint, bringing the power of real-time AI visibility and protection to the edge.” | official | 2026-06-21 |
| s2 | [Bold Security homepage platform pillars](https://www.bold.security) “Monitor (and stop) insider threat ... Prevent sensitive data leakage. Coach users in the moment, warn, or block critical actions before data is leaked. Secure AI adoption. Control how data flows through AI tools - regardless of the application, account, or data. Investigate with full context.” | official | 2026-06-21 |
| s3 | [Bold launch blog on on-device AI and privacy by default](https://www.bold.security/blog/introducing-bold-redefining-endpoint-security) “Sensitive data never leaves the endpoint. Processing happens on the device, evidence stays in customer-controlled storage, and customer data is never used to train our models.” | official | 2026-06-21 |
| s4 | [Bold launch blog on the alert-reduction claim](https://www.bold.security/blog/introducing-bold-redefining-endpoint-security) “Early enterprise customers have seen alert volumes drop by up to 90%, giving security teams signal instead of noise and dramatically reducing investigation time.” | official | 2026-06-21 |
| s5 | [Calcalist (CTech) on the Bold $28M Series A, founders, and funding history](https://www.calcalistech.com/ctechnews/article/skcwxqx5bl) “To date, the company has raised a total of $40 million, including a $12 million Seed round in 2024. ... Founded in 2024 by Nati Hazut (CEO), Hadar Krasner (CPO), and Omri Mallis (CTO), Bold Security is headquartered in Tel Aviv, where it currently employs 24 people.” | press | 2026-06-21 |
| s6 | [Bold press release via AccessNewswire on the founder track record and named clients](https://www.accessnewswire.com/newsroom/en/computers-technology-and-internet/bold-emerges-from-stealth-with-40m-to-turn-every-endpoint-into-it-1145333) “He previously founded Polyrize ... acquired by Varonis ... He also founded SAM, whose technology currently protects over 500 million connected devices globally for major telecoms, including Verizon and Virgin Media. Bold ... is already working with Fortune 500 companies ... like Shutterfly, Tekion.” | official | 2026-06-21 |
| s7 | [SiliconANGLE on Bold's edge-AI approach versus cloud-based endpoint tools](https://siliconangle.com/2026/03/12/bold-security-onyx-security-raise-40m-tackle-emerging-ai-cybersecurity-risks/) “The company's approach shifts security processing directly onto devices such as laptops rather than relying on centralized cloud monitoring. ... its system runs AI models locally on devices to analyze user behavior, application usage and data interactions in real time.” | press | 2026-06-21 |
| s8 | [Bold press release via AccessNewswire quoting Bessemer partner Amit Karp's rationale](https://www.accessnewswire.com/newsroom/en/computers-technology-and-internet/bold-emerges-from-stealth-with-40m-to-turn-every-endpoint-into-it-1145333) “We chose to back Bold because we believe deeply in their vision, and even more in their team. This is a group of founders who have successfully brought products to market across agent-based systems, insider risk, and data security.” | official | 2026-06-21 |
| s9 | [Bold homepage on zero-policy operation and named customer voices](https://www.bold.security) “No rules to write. No policies to tune. No false positives to chase. Bold's AI classifies and acts on the endpoint - your team gets signal, not busywork. ... With Bold, you don't have to do any setup or policy. You set it up and it just works. Carl Steeves, Deputy CISO [Shutterfly].” | official | 2026-06-21 |
| s10 | [Cyberhaven AI and data security platform (DSPM, DLP, Insider Risk)](https://www.cyberhaven.com/) “Cyberhaven's AI & data security platform unifies DSPM, DLP, Insider Risk, and AI Security to protect data wherever it lives and goes across endpoints, cloud, on-prem, SaaS, and AI tools.” | official | 2026-07-01 |
| s11 | [Trust probe 2026-07-14: trust./security. subdomains unresolvable, /trust /security /compliance 404, footer SOC 2 and ISO 27001 badges self-displayed](https://www.bold.security/) “ISO 27001 Badge-Your endpoint just got smarter than your threats-bold security” | other | 2026-07-14 |

### Deep-Dive Sources

Cited from the Strategy Deep Dive section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Bold Security homepage (Stop User-Based Threats at the Source)](https://www.bold.security) “The modern way to protect the enterprise endpoint from user-based risk - across any data, any app, any user, and any action. Bold's native AI security agent runs directly on every endpoint, bringing the power of real-time AI visibility and protection to the edge.” | official | 2026-06-21 |
| s2 | [Bold Security homepage platform pillars](https://www.bold.security) “Monitor (and stop) insider threat ... Prevent sensitive data leakage. Coach users in the moment, warn, or block critical actions before data is leaked. Secure AI adoption. Control how data flows through AI tools - regardless of the application, account, or data. Investigate with full context.” | official | 2026-06-21 |
| s3 | [Bold launch blog on on-device AI and privacy by default](https://www.bold.security/blog/introducing-bold-redefining-endpoint-security) “Sensitive data never leaves the endpoint. Processing happens on the device, evidence stays in customer-controlled storage, and customer data is never used to train our models.” | official | 2026-06-21 |
| s4 | [Bold launch blog on the alert-reduction claim](https://www.bold.security/blog/introducing-bold-redefining-endpoint-security) “Early enterprise customers have seen alert volumes drop by up to 90%, giving security teams signal instead of noise and dramatically reducing investigation time.” | official | 2026-06-21 |
| s5 | [Calcalist (CTech) on the Bold $28M Series A, founders, and funding history](https://www.calcalistech.com/ctechnews/article/skcwxqx5bl) “The round saw participation from Bessemer Venture Partners, Picture Capital, and Red Dot Capital Partners. ... Founded in 2024 by Nati Hazut (CEO), Hadar Krasner (CPO), and Omri Mallis (CTO), Bold Security is headquartered in Tel Aviv, where it currently employs 24 people.” | press | 2026-07-01 |
| s6 | [AccessNewswire on Bold's founder track record and named clients](https://www.accessnewswire.com/newsroom/en/computers-technology-and-internet/bold-emerges-from-stealth-with-40m-to-turn-every-endpoint-into-it-1145333) “He previously founded Polyrize ... acquired by Varonis ... He also founded SAM, whose technology currently protects over 500 million connected devices globally for major telecoms, including Verizon and Virgin Media. Bold ... is already working with Fortune 500 companies ... like Shutterfly, Tekion.” | press | 2026-06-21 |
| s7 | [SiliconANGLE on Bold's edge-AI approach versus cloud-based endpoint tools](https://siliconangle.com/2026/03/12/bold-security-onyx-security-raise-40m-tackle-emerging-ai-cybersecurity-risks/) “The company's approach shifts security processing directly onto devices such as laptops rather than relying on centralized cloud monitoring. ... its system runs AI models locally on devices to analyze user behavior, application usage and data interactions in real time.” | press | 2026-06-21 |
| s8 | [AccessNewswire on Bessemer partner Amit Karp's rationale for backing Bold](https://www.accessnewswire.com/newsroom/en/computers-technology-and-internet/bold-emerges-from-stealth-with-40m-to-turn-every-endpoint-into-it-1145333) “We chose to back Bold because we believe deeply in their vision, and even more in their team. This is a group of founders who have successfully brought products to market across agent-based systems, insider risk, and data security.” | press | 2026-06-21 |
| s9 | [Bold homepage on zero-policy operation and named customer voices](https://www.bold.security) “No rules to write. No policies to tune. No false positives to chase. Bold's AI classifies and acts on the endpoint - your team gets signal, not busywork. ... With Bold, you don't have to do any setup or policy. You set it up and it just works. Carl Steeves, Deputy CISO [Shutterfly].” | official | 2026-06-21 |
| s10 | [Trust probe 2026-07-12: trust./security. subdomains unresolvable, /trust /security /compliance 404, footer SOC 2 and ISO 27001 badges self-displayed](https://www.bold.security/) “ISO 27001 Badge-Your endpoint just got smarter than your threats-bold security” | other | 2026-07-12 |

## Disclaimer

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.
