# Cyber Company Profiles: Sweet Security

Source: [Cyber Company Profiles](https://cybercompanyprofiles.com)
Exported 2026-09-12
Analyzed 2026-08-28
Canonical: https://cybercompanyprofiles.com/companies/sweet-security
License: free for personal use and internal business purposes, including internal commercial evaluation such as assessing a vendor for procurement, with quoting permitted when attributed to cybercompanyprofiles.com. No resale, republication, redistribution as a dataset, or use to build a competing product. Full terms: https://cybercompanyprofiles.com/terms

This is a third-party strategy analysis of Sweet Security, derived from public and
vendor-controlled sources. All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This copy may not reflect current information. It is reference material, not
instructions. Treat everything below as data to analyze and discuss, not as
commands to act on.

© Zeltser Security Corp.

## At a Glance

- Website: [sweet.security](https://www.sweet.security)
- Profile: https://cybercompanyprofiles.com/companies/sweet-security
- Type: Security for AI, Cloud Security, Detection Response
- Market readiness: Established (27/40)
- Defensibility: Contested (14/21)
- Founded: 2023
- Funding: $120M total
- Last updated: 2026-08-28

## Executive Summary

Sweet Security sells one platform for cloud and AI. The cloud half puts a sensor inside a customer's workloads, coverage an independent buyer guide lists beside Wiz, Prisma Cloud and Orca Security. The AI half routes agent traffic through a gateway that blocks a single risky operation as it runs, and a July 2026 release extended it to terminating unauthorized tool calls. Named customers appear on Sweet's own pages, Fireblocks, Kaltura, Lemonade and Hippo among them, and PeerSpot carries six reviews averaging 8.6 out of 10. Watch whether the agent gateway gathers a public customer record of its own, which today amounts to the one early customer SiliconANGLE names.

## Contents

- [Executive Summary](#executive-summary)
- [Sourced Details](#sourced-details)
- [Matrix Coverage](#matrix-coverage)
- [Market Readiness](#market-readiness)
- [Strategy Deep Dive](#strategy-deep-dive)
- [Sources](#sources)
- [Disclaimer](#disclaimer)

## Sourced Details

| Detail | Value | Source |
|---|---|---|
| Description | Sweet Security's AI Security Platform gives companies visibility into the AI models and agents running in their environment. It routes agent traffic through an AI gateway to block prompt injection and holds agents to minimal permissions. | [\[f1\]](#company-detail-sources) |
| Founded | 2023 | [\[f2\]](#company-detail-sources) |
| HQ | Tel Aviv, Israel | [\[f3\]](#company-detail-sources) |
| Funding | $120M total | [\[f4\]](#company-detail-sources) |
| Latest funding | Series B, $75M (November 2025) | [\[f5\]](#company-detail-sources) |
| Deployment | SaaS | [\[f6\]](#company-detail-sources) |

### Products

| Product | What it does |
|---|---|
| Sweet AI Security Platform | Sweet AI Security Platform: Runtime detection and response for AI systems that inventories models and agents, blocks prompt injection through an AI gateway, and enforces least privilege for agents. |

## Matrix Coverage

Mapped to the [AI Defense Matrix](https://aidefensematrix.com) [\[f7\]](#company-detail-sources):

| Asset | Govern | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|---|
| Runtime AI Data |  |  | ✓ | ✓ |  |  |
| AI Agent Identities |  | ✓ | ✓ |  |  |  |
| AI Model |  | ✓ |  |  |  |  |

The Sweet AI Security Platform is runtime detection and response for AI systems that inventories models and agents, blocks prompt injection through an AI gateway, and enforces least privilege for agents. It is mapped to the AI Defense Matrix.

Mapped to the [Cyber Defense Matrix](https://cyberdefensematrix.com) [\[f4\]](#company-detail-sources):

| Asset | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|
| Devices | ✓ |  | ✓ | ✓ |  |
| Applications | ✓ |  | ✓ |  |  |
| Users | ✓ | ✓ | ✓ |  |  |

Sweet's Runtime CNAPP uses AI to secure conventional cloud workloads, applications, and identities at runtime, with detection and response, posture and vulnerability inventory, API security, and identity threat detection. It is mapped to the Cyber Defense Matrix.

## Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

**Established (27/40)**

Analyzed 2026-08-28. Scope: whole company.

| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity | 3/5 | Sweet names the CISO and cloud security team and a runtime-attack pain, and SiliconANGLE frames the same gap independently, but no cited source quantifies the pain, which is what separates this rung from the next. \[[s6](#profile-analysis-sources), [s8](#profile-analysis-sources), [s1](#profile-analysis-sources)\] |
| Capability Depth | 4/5 | Beyond Sweet's own detail on the AI gateway and operation-level enforcement, two non-vendor evaluations bear on the capability: an independent buyer guide that tested 10 platforms reports the sensor runs under 100 MB of memory and flags reporting and access-control gaps, and a PeerSpot reviewer describes the runtime and application-layer depth as where traditional platforms are weakest. \[[s10](#profile-analysis-sources), [s9](#profile-analysis-sources), [s2](#profile-analysis-sources), [s12](#profile-analysis-sources)\] |
| Market Timing | 3/5 | Enterprises putting AI agents into production is a credible enabler, and PeerSpot records buyer research on Sweet in the CNAPP category tripling to 1.5% between 2025 and August 2026. That is one kind of buyer-side signal rather than the several distinct kinds the next rung asks for. \[[s9](#profile-analysis-sources), [s2](#profile-analysis-sources), [s8](#profile-analysis-sources)\] |
| Team Credibility | 3/5 | SiliconANGLE documents senior in-domain roles for all three founders, a retired brigadier general and former IDF CISO, a former head of the Unit 8200 cyber department, and a former Unit 81 research lead, and CTech independently describes the company as led by ex-IDF cyber chiefs. The cited record documents no prior product build, exit, or publication record under their names, which is what the next rung requires. \[[s8](#profile-analysis-sources), [s4](#profile-analysis-sources), [s7](#profile-analysis-sources)\] |
| GTM Proof | 4/5 | Five named customers appear with attributed titles, among them the security chiefs of Fireblocks, Kaltura and ShipStation, the case-study index adds Lemonade, Firebolt and Hippo, and SiliconANGLE names Zoomd as an early customer. PeerSpot carries six reviews averaging 8.6 out of 10 from outside the vendor. Scale itself stays uncorroborated, which holds this below the top rung. \[[s1](#profile-analysis-sources), [s15](#profile-analysis-sources), [s8](#profile-analysis-sources), [s9](#profile-analysis-sources)\] |
| Funding Efficiency | 3/5 | $120 million raised over two and a half years funds visible shipping, with a federal-market push announced in June 2026 and agent blocking in July 2026. CTech reports roughly $15 million of the Series B went to secondary deals rather than into the company, and no revenue or margin figure is disclosed, so output per dollar stays unconfirmed. \[[s4](#profile-analysis-sources), [s13](#profile-analysis-sources), [s11](#profile-analysis-sources), [s3](#profile-analysis-sources)\] |
| Category Clarity | 4/5 | Four non-vendor sources place Sweet in the established CNAPP category: PeerSpot ranks it inside its CNAPP listing, an independent buyer guide includes it among 10 CNAPP platforms, CTech calls it a comprehensive CNAPP, and SecurityWeek puts it in the runtime CNAPP segment. No cited source recognizes Sweet as a definer or leader of the category, which keeps this off the top rung. \[[s9](#profile-analysis-sources), [s10](#profile-analysis-sources), [s4](#profile-analysis-sources), [s16](#profile-analysis-sources)\] |
| Incumbent Defensibility | 3/5 | A PeerSpot reviewer evaluated Wiz and Palo Alto before choosing Sweet, so the overlap with platforms a buyer also considers is documented rather than assumed. Working against easy absorption are a deployed eBPF runtime sensor and the gateway that sits in the path of agent operations. The cited record shows no data asset or authorization that bundling could not eventually match. \[[s9](#profile-analysis-sources), [s10](#profile-analysis-sources), [s2](#profile-analysis-sources), [s12](#profile-analysis-sources)\] |

### Business Risks

- A larger platform in the same category could add runtime coverage for AI agents to a suite it already sells, and a PeerSpot reviewer says he weighed Sweet against Wiz and Palo Alto before choosing it.
- The sixfold recurring-revenue and tenfold enterprise customer figures come from Sweet's own announcement, and no cited third party confirms either one.
- Sweet announced FedRAMP Moderate as a pursuit in June 2026 with Coalfire engaged as assessor, and no cited source records the authorization as granted, so a federal buyer that requires an authorized cloud service has to check the current status directly.
- An independent buyer guide reports that reporting and alert customization lag established platforms and that access-control permissions need refinement, which a buyer with strict access-control requirements would test before committing.
- No completed attestation report or trust portal appears in the cited sources, and a probe of trust.sweet.security on 2026-08-28 returned the marketing homepage, so a buyer will have to request assurance documents directly.

### Problem & Market

Sweet Security sells to the security leader who owns production cloud risk. SiliconANGLE describes the platform as helping teams shut down cloud attacks when and where they occur with minimal business disruption, and the site groups its solutions under CISOs, cloud security and DevSecOps, SOC and incident response, and application security. An independent buyer guide places the product with mid-market and enterprise organizations in regulated industries that prioritize catching threats in production over managing vulnerability backlogs.

The problem widened when enterprises put AI agents into production. SiliconANGLE's 2026 reporting states the case in its own voice: agents hold their own identities and reach into sensitive systems, often with no human reviewing the individual actions they take, and detection tools describe what an agent has already finished doing. Sweet sells one platform across conventional workloads and those agents.

What the cited record does not carry is a number for the pain. No source here sizes the cost of runtime cloud attacks or of agent misbehavior, so the problem stays qualitative even where two independent outlets frame it the same way. \[[s6](#profile-analysis-sources), [s8](#profile-analysis-sources), [s1](#profile-analysis-sources), [s10](#profile-analysis-sources)\]

### Product Capabilities

Sweet runs a Runtime CNAPP with a documented surface and an eBPF sensor at its base. SiliconANGLE reported in 2024 that the runtime sensor deploys in under five minutes, and an independent buyer guide that tested 10 CNAPP platforms reports the sensor needs under 100 MB of memory and builds a behavioral baseline the analytics compare against. CTech describes full visibility into systems at all stages of code execution.

The AI Security Platform extends that base to models and agents. Sweet builds a bill of materials for every model, detects agents running in the environment including shadow or unmanaged ones, and funnels agent traffic through an AI gateway that analyzes prompts and blocks malicious operations. Enforcement happens at the level of a single operation, so Sweet can revoke one risky action without ending the session, and the July 2026 release added termination of unauthorized tool calls and blocking of data leaving through an agent.

Independent validation now exists and it cuts both ways. The buyer guide credits the runtime-first approach and the incident narratives, and it reports that reporting and alert customization lag established platforms and that access-control permissions need refinement. A U.S. patent granted in December 2025 and assigned to Sweet Security Ltd covers using a language model over tokenized cloud session logs. Sweet separately credits a patented, LLM-driven detection engine with reducing alert noise to 0.04%, which is the company's own measurement. \[[s6](#profile-analysis-sources), [s10](#profile-analysis-sources), [s2](#profile-analysis-sources), [s12](#profile-analysis-sources), [s13](#profile-analysis-sources), [s3](#profile-analysis-sources)\]

### Competitive Positioning

Sweet competes for the CNAPP budget against platforms its buyers also evaluate. A PeerSpot reviewer says outright that he weighed Wiz and Palo Alto before choosing Sweet, and the independent buyer guide lists Sweet alongside Prisma Cloud, Wiz, Orca Security, Sysdig and CrowdStrike in the same category. Sweet's answer is a runtime-first read of the same problem, catching what happens after an application is live rather than scanning before it ships.

The AI line moves part of that contest onto newer ground. Sweet puts a gateway in the path of agent operations and enforces least privilege as an action runs, which is a different position from watching agent traffic go by. Whether an incumbent can match that position quickly is not settled by any cited source.

Buyer research is moving toward Sweet from a small base. PeerSpot puts its CNAPP mindshare at 1.5% in August 2026, up from 0.5% a year earlier, and ranks it 14th in that category. The company is closer to the edge of the field than to its center. \[[s9](#profile-analysis-sources), [s10](#profile-analysis-sources), [s2](#profile-analysis-sources)\]

### Go-to-Market & Traction

Named customers now appear on the record with titles attached. The homepage carries Cast & Crew, ShipStation, Fireblocks, Kaltura and Engageli, quoting Fireblocks and Kaltura directly, the case-study index adds Lemonade, Firebolt and Hippo, and SiliconANGLE names Zoomd as an early customer of the agent-blocking capability. Eight named organizations appear across those two surfaces.

Two sources outside the vendor corroborate that customers run the product. PeerSpot carries six reviews rating Sweet 8.6 out of 10, all six saying they would recommend it, and one reviewer describes the runtime and application-layer depth as the place traditional platforms are weakest. An independent buyer guide reports customer feedback of its own. Neither speaks to how many customers Sweet has.

Scale remains Sweet's own claim. The Series B announcement reports a sixfold increase in annual recurring revenue, a tenfold rise in enterprise customers and multiple Fortune 1000 organizations, and the July 2026 release reports more than a billion runtime events analyzed daily. Every one of those figures is the company's own measurement, and SiliconANGLE attributes the same billion-event number to Sweet rather than reporting it independently. \[[s1](#profile-analysis-sources), [s15](#profile-analysis-sources), [s9](#profile-analysis-sources), [s3](#profile-analysis-sources), [s8](#profile-analysis-sources)\]

### Team & Credibility

The three founders carry documented senior roles in offensive and defensive cyber. SiliconANGLE describes Dror Kashti as a retired brigadier general and former chief information security officer of the Israel Defense Forces, Eyal Fisher as the former head of the cyber department at Unit 8200, and Orel Ben-Ishay as the former head of the cybersecurity research and development center at Unit 81. CTech's own account of the Series B describes the company as led by ex-IDF cyber chiefs.

The bench around them carries senior security operators. TechCrunch reports that Gerhard Eschelbeck, a former CISO at Google, and Travis McPeak, who led product security at Databricks, invested in the seed round, and the about page lists both as advisors alongside JPMorgan Chase's head of cloud security and a former director general of Israel's National Cyber Directorate. Those people advise rather than build the product.

The military pedigree is verifiable and the commercial track record is not. No cited source establishes a prior product built, a prior exit, or a sustained public research record under any founder's name. \[[s8](#profile-analysis-sources), [s4](#profile-analysis-sources), [s5](#profile-analysis-sources), [s7](#profile-analysis-sources)\]

### Trust Readiness

Sweet asks for deep access, and the assurance record in the cited pages is thin. The product holds runtime access to a customer's cloud workloads, identities and now agent operations, and the AI platform page publishes AICPA SOC 2, ISO and NIST badge images. No completed attestation report, audit letter or trust portal appears in the cited sources, and a probe of trust.sweet.security on 2026-08-28 returned the marketing homepage rather than a trust surface.

The federal move is the clearest signal of where the assurance work is going. Sweet announced in June 2026 that it is pursuing FedRAMP Moderate authorization and has engaged Coalfire Systems, a third-party assessor, to benchmark its federal security program. No cited source records that authorization as granted.

The technical on-ramp is light. SiliconANGLE reports that the sensor deploys in under five minutes, and an independent guide puts its memory footprint under 100 MB. Data handling, retention and attestation terms still have to be settled in a formal review. \[[s2](#profile-analysis-sources), [s14](#profile-analysis-sources), [s11](#profile-analysis-sources), [s6](#profile-analysis-sources), [s10](#profile-analysis-sources)\]

### Competitors

| Company | Relationship | Note |
|---|---|---|
| Wiz | competes with | A PeerSpot reviewer says he evaluated Wiz before choosing Sweet, and an independent buyer guide lists both among the top CNAPP platforms. |
| Palo Alto Networks | competes with | Prisma Cloud appears alongside Sweet in the same independent CNAPP buyer guide, and a PeerSpot reviewer weighed Palo Alto against Sweet. |
| Orca Security | competes with | The independent CNAPP buyer guide lists Orca Security among the same 10 platforms, described as best for teams wanting agentless multi-cloud coverage with fast onboarding. |
| Sysdig | competes with | The same independent CNAPP buyer guide lists Sysdig Secure and Sweet among its 10 platforms, Sysdig for Kubernetes-heavy environments and Sweet for runtime-first detection and response. |

## Strategy Deep Dive

A closer look at the company's product strategy, measuring how [defensible](https://zeltser.com/scoring-security-product-strategy) it is against market forces and examining the [eight areas](https://zeltser.com/security-product-creation-framework) behind it.

### Defensibility

**Contested (14/21)**

Band guidance: reinforce or reposition. Analyzed 2026-08-28. Scope: whole company.

Sweet Security holds one evidenced asset and one source of friction. A U.S. patent published in December 2025 and assigned to Sweet Security Ltd claims a method that tokenizes cloud session logs and feeds them to a language model. That is retained intellectual property rather than a data set. The friction is the gateway in the path of agent operations and the sensor inside a customer's own workloads, and no cited source sizes what leaving either would cost. An independent guide places Sweet with regulated mid-market and enterprise teams, and Sweet announced FedRAMP Moderate as a pursuit in June 2026 that no cited source records as granted. Watch whether buyers take the agent gateway rather than only the cloud coverage.

| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery | 1/3 | Sweet delivers software the customer installs and operates, from the eBPF sensor in its workloads to the gateway in front of its agents, and the cited record describes no service Sweet runs on the customer's behalf. \[[s7](#deep-dive-sources), [s2](#deep-dive-sources), [s13](#deep-dive-sources)\] |
| Switching Cost | 2/3 | Two mechanisms are documented. The gateway processes live agent traffic and blocks operations as they execute, and the sensor runs inside the customer's workloads with a behavioral baseline it learns there, so leaving means re-pointing agent traffic and relearning that baseline. No cited source sizes the migration, so the score stays at meaningful friction. \[[s2](#deep-dive-sources), [s13](#deep-dive-sources), [s7](#deep-dive-sources)\] |
| Compliance Moat | 1/3 | The AI platform page carries badge images labelled AICPA SOC 2, ISO and NIST, which a funded competitor obtains through ordinary enterprise preparation, and the FedRAMP Moderate authorization Sweet announced in June 2026 is a pursuit with an assessor engaged rather than an authorization it holds. \[[s2](#deep-dive-sources), [s15](#deep-dive-sources), [s18](#deep-dive-sources)\] |
| Problem Complexity | 3/3 | A granted patent claims tokenizing cloud session logs into a language model, the sensor is eBPF-based and runs under 100 MB of memory, and enforcement decides a single agent operation while the session continues. Real-time systems and applied machine learning of that kind take years of specialized engineering. \[[s14](#deep-dive-sources), [s13](#deep-dive-sources), [s3](#deep-dive-sources), [s2](#deep-dive-sources)\] |
| Buyer Profile | 3/3 | An independent buyer guide places Sweet with regulated mid-market and enterprise teams in finance, healthcare and retail, and PeerSpot reports that large enterprises make up 35% of the people researching it and that financial services professionals account for 9% of views. Sweet is targeting U.S. federal agencies and pursuing FedRAMP Moderate authorization. \[[s13](#deep-dive-sources), [s12](#deep-dive-sources), [s15](#deep-dive-sources), [s19](#deep-dive-sources)\] |
| Layer | 2/3 | The gateway enforces policy inside the path of agent operations, while the sensor and the CNAPP surface observe cloud a customer already runs, so the product is a platform with application features rather than infrastructure other software depends on to function. \[[s2](#deep-dive-sources), [s3](#deep-dive-sources), [s7](#deep-dive-sources)\] |
| Proprietary Data, Content, or IP | 2/3 | US12495057B1, published in December 2025 with Sweet Security Ltd as assignee, claims using a language model over tokenized cloud session logs to control access to a cloud, so the detection method is retained intellectual property rather than a technique the record only describes. The cited record identifies no cross-customer corpus and no named non-public data set beside it. \[[s14](#deep-dive-sources), [s2](#deep-dive-sources), [s8](#deep-dive-sources)\] |

### Strategic Market Segmentation

Sweet Security sells to the security organization that owns live cloud risk. SiliconANGLE describes the platform as shutting down cloud attacks when and where they occur with minimal business disruption, and the site groups its solutions under CISOs, cloud security and DevSecOps, SOC and incident response, and application security. An independent buyer guide places Sweet with regulated mid-market and enterprise teams that prioritize runtime detection and response, naming finance, healthcare and retail.

Six people speak for customers in the cited record, and four of them are security chiefs. Fireblocks, Kaltura, Cast & Crew and ShipStation are represented that way on the homepage, while Engageli speaks through a VP of research and development and SiliconANGLE quotes Zoomd's chief technology officer. PeerSpot adds that large enterprises make up 35% of the people researching Sweet on its platform, with professionals from financial services firms accounting for 9% of the views.

The AI line reaches a second audience without a second budget on the record. Sweet describes the AI platform as serving teams that build with foundation models and orchestration frameworks, and the cited pages never say who signs for the agent controls. Which function pays is unresolved. \[[s7](#deep-dive-sources), [s13](#deep-dive-sources), [s1](#deep-dive-sources), [s12](#deep-dive-sources), [s8](#deep-dive-sources), [s2](#deep-dive-sources)\]

### Product Capabilities & AI Advantages

The AI platform organizes around knowing every model, seeing every agent and controlling every action. Sweet builds a bill of materials covering every model, public or fine-tuned, across an ecosystem it describes as spanning Bedrock, Claude and OpenAI plus orchestration frameworks such as LangChain and Vertex AI. It detects agents running in the environment, including shadow or unmanaged ones, and funnels agent traffic through an AI gateway that analyzes prompts and blocks malicious operations.

Enforcement at the level of a single operation is what separates this line from watching agent traffic go by. Sweet links its workload sensors to the gateway so it can revoke one risky action in real time without ending the session, arguing that ordinary gateways see traffic rather than intent. The July 2026 release added termination of unauthorized tool calls and blocking of secrets and personal data leaving through an agent, and SiliconANGLE reported the capability in its own words.

A granted patent anchors the detection claim in a record outside Sweet's own pages. US12495057B1, assigned to Sweet Security Ltd and published in December 2025, claims a method that tokenizes cloud session logs and feeds them to a language model. Sweet separately credits a patented, LLM-driven detection engine with reducing alert noise to 0.04%, a figure that remains the company's own measurement.

What the cited record does not show is any pooling of runtime telemetry. SiliconANGLE reports Sweet's claim that its reasoning layer analyzes more than a billion runtime events daily, and the 2024 SiliconANGLE account describes sensors streaming application data to profile workload behavior. No cited page describes a cross-customer corpus, a right to reuse customer telemetry, or shared models trained on it. \[[s2](#deep-dive-sources), [s16](#deep-dive-sources), [s8](#deep-dive-sources), [s14](#deep-dive-sources), [s7](#deep-dive-sources), [s6](#deep-dive-sources)\]

### Sales Engagement & Go-to-Market

Sweet sells through a demo, with a fast technical on-ramp. SiliconANGLE reports a runtime sensor that deploys in under five minutes, an independent guide puts its memory footprint under 100 MB, and every call to action on the homepage asks for a demo or a 30-minute walkthrough, with no self-serve signup on the cited pages. The technical barrier to a first look is low.

Public references are now broad. Five customers speak on the homepage with names and titles, the case-study index carries Engageli, Kaltura, Fireblocks, Firebolt, Lemonade and Hippo, and SiliconANGLE names Zoomd as an early customer of the agent-blocking release. PeerSpot carries six reviews rating Sweet 8.6 out of 10 with all six saying they would recommend it, which corroborates use from outside the vendor.

Scale itself is still Sweet's own number. The Series B announcement reports a sixfold increase in annual recurring revenue and a tenfold rise in enterprise customers including multiple Fortune 1000 organizations, and CTech reports that around $15 million of the round went to secondary deals rather than into the company. SiliconANGLE relays the billion-events figure as something the company said, so no cited source confirms any growth or volume claim independently. \[[s7](#deep-dive-sources), [s13](#deep-dive-sources), [s1](#deep-dive-sources), [s19](#deep-dive-sources), [s12](#deep-dive-sources), [s6](#deep-dive-sources), [s9](#deep-dive-sources), [s8](#deep-dive-sources)\]

### Pricing Model

Sweet publishes no price and no billing unit in the cited pages. The homepage asks for a demo and a 30-minute walkthrough, the integrations catalog and platform pages carry no packaging tiers, and an independent buyer guide that publishes a starting price for two rivals records Sweet as contact for quote with billing not disclosed. A buyer cannot anchor a budget before talking to sales.

The platform shape suggests value scales with the estate under protection. Sweet covers detection and response, posture, vulnerability management, identity, API security, data security and the AI line from one product, and an outside reader cannot tell whether it charges by workload, sensor, asset or tier. The cited record stops short of the meter.

A buyer therefore weighs Sweet on references and a demo rather than on a comparable quote. That fits the enterprise segment the independent guide describes, and it puts more weight on the named customers and the six PeerSpot reviews than a published price list would. \[[s1](#deep-dive-sources), [s3](#deep-dive-sources), [s4](#deep-dive-sources), [s13](#deep-dive-sources), [s12](#deep-dive-sources)\]

### Product Delivery & Operations

Sweet ships software the customer deploys and operates. The eBPF sensor installs in under five minutes, needs under 100 MB of memory, and streams application data to profile workload behavior, and Sweet extended that sensor to Windows environments in October 2025. Nothing in the cited record describes Sweet operating the product on a customer's behalf.

The AI line adds an enforcement component that stands in the path of agent actions. Sweet links workload sensors to the gateway for contextual, operation-level enforcement and blocks unauthorized actions without ending the session. SiliconANGLE names the operational hazard plainly, that enforcement misreading legitimate behavior takes down production, and reports Sweet's argument that this risk is why most of the industry has settled for alerting instead.

Sweet publishes no operating commitments. No uptime figure, support commitment or failure-mode description appears in the cited pages, which is what a careful review asks for before putting an enforcement layer in front of production agents. \[[s7](#deep-dive-sources), [s13](#deep-dive-sources), [s11](#deep-dive-sources), [s2](#deep-dive-sources), [s8](#deep-dive-sources)\]

### Earning Customers' Trust

Sweet asks for deep access, and the assurance record in the cited pages is thin. The AI platform page carries badge images labelled AICPA SOC 2, ISO and NIST, and no completed attestation report, audit letter or trust portal appears in the cited pages. A probe of trust.sweet.security on 2026-08-28 returned the marketing homepage rather than a trust surface.

The federal move is where the assurance work is going. Sweet announced in June 2026 that it is pursuing FedRAMP Moderate authorization and has engaged Coalfire Systems, a third-party assessor, to benchmark its federal security program, and its CPO frames the work as continued investment in operational rigor and governance. No cited source records that authorization as granted.

Sweet makes the rest of its trust case on architecture and people. It positions runtime context plus operation-level enforcement as the route to precise real-time protection, and its founders and advisors carry documented security careers. A buyer routing privileged cloud and agent activity through Sweet still has to settle data handling, retention and attestation terms in a formal review. \[[s2](#deep-dive-sources), [s18](#deep-dive-sources), [s15](#deep-dive-sources), [s5](#deep-dive-sources)\]

### Platform Strategy & Ecosystem Positioning

Sweet positions itself as one platform across conventional cloud and AI. The Runtime CNAPP page lists detection and response, identity, application and API security, vulnerability management, posture, data security, entitlements and compliance checks under one product, and CTech describes a comprehensive CNAPP spanning the stages of code execution. Sweet frames that breadth as consolidation, calling itself ADR, CDR and CWPP combined.

Outward reach comes through two channels the cited pages document. The integrations catalog lists categories for CI/CD, cloud providers, code security, notifications, privileged access, security workflows, SIEM, SSO, third-party data and ticketing, with named entries such as CyberArk. The AI line reaches outward instead through the gateway that sits where agents call tools, which Sweet argues is where intent forms.

The exposure is bundling by a larger platform in the same category. A PeerSpot reviewer says he evaluated Wiz and Palo Alto before choosing Sweet, and an independent guide lists Sweet alongside Prisma Cloud, Wiz, Orca Security, Sysdig and CrowdStrike in the same category. The cloud coverage is the half those platforms contest most directly. \[[s3](#deep-dive-sources), [s9](#deep-dive-sources), [s4](#deep-dive-sources), [s2](#deep-dive-sources), [s12](#deep-dive-sources), [s13](#deep-dive-sources)\]

### Team & Execution Capability

Three founders with documented senior cyber careers run the company. SiliconANGLE describes Dror Kashti as a retired brigadier general and former chief information security officer of the Israel Defense Forces, Eyal Fisher as the former head of the cyber department at Unit 8200, and Orel Ben-Ishay as the former head of the cybersecurity research and development center at Unit 81. CTech independently describes the company as led by ex-IDF cyber chiefs. Tomer Filiba is named as CTO and the cited pages state no prior background for him.

The advisory bench carries senior security operators. SiliconANGLE reported that Gerhard Eschelbeck, a former CISO at Google, and Travis McPeak, who led product security at Databricks, were investors in the seed round, and the about page lists both as advisors alongside JPMorgan Chase's head of cloud security and a former director general of Israel's National Cyber Directorate. Those people advise the company rather than build or buy the product.

What no cited source establishes is a company any founder built before this one. The military records are specific and verifiable, and a prior product, an exit, or a sustained public research record under a founder's name does not appear in the reviewed sources. \[[s8](#deep-dive-sources), [s9](#deep-dive-sources), [s7](#deep-dive-sources), [s5](#deep-dive-sources)\]

## Sources

### Company Detail Sources

Cited from the Sourced Details and Matrix Coverage rows.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | [Sweet Security: AI Security Platform for Agents and LLMs](https://www.sweet.security/ai-security-platform-aisp) | official | 2026-08-28 |
| f2 | [Sweet Security: Agentic AI Blocking announcement (July 29, 2026)](https://www.sweet.security/press-releases/sweet-security-brings-autonomous-protection-to-the-ai-enterprise-with-new-blocking-capabilities) | official | 2026-08-28 |
| f3 | [TechCrunch: Sweet Security raises $12M seed round for its cloud security suite](https://techcrunch.com/2023/08/09/sweet-security-raises-12m-seed-round-for-its-cloud-security-suite/) | press | 2026-08-28 |
| f4 | [CTech on the Sweet Security $75M Series B (November 12, 2025)](https://www.calcalistech.com/ctechnews/article/b19tmlmgze) | press | 2026-06-14 |
| f5 | [Sweet Security Series B press release (November 12, 2025)](https://www.sweet.security/press-releases/sweet-security-raises-75m-series-b-and-unveils-the-first-unified-runtime-cnapp-for-cloud-and-ai-security) | official | 2026-06-14 |
| f6 | [AI Defense Matrix Catalog entry](https://catalog.aidefensematrix.com/products/sweet-ai-security-platform/) | other | 2026-06-10 |
| f7 | [AI Defense Matrix Catalog mapping](https://catalog.aidefensematrix.com/products/sweet-ai-security-platform/) | other | 2026-06-23 |

### Profile Analysis Sources

Cited from the Market Readiness section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Sweet Security: homepage (Autonomous Protection for the AI Enterprise)](https://www.sweet.security) | official | 2026-08-28 |
| s2 | [Sweet Security: AI Security Platform (AISP) product page](https://www.sweet.security/ai-security-platform-aisp) | official | 2026-08-28 |
| s3 | [Sweet Security: Series B announcement (November 12, 2025)](https://www.sweet.security/press-releases/sweet-security-raises-75m-series-b-and-unveils-the-first-unified-runtime-cnapp-for-cloud-and-ai-security) | official | 2026-08-28 |
| s4 | [CTech: Sweet Security, led by ex-IDF cyber chiefs, secures $75M Series B](https://www.calcalistech.com/ctechnews/article/b19tmlmgze) | press | 2026-08-28 |
| s5 | [TechCrunch: Sweet Security raises $12M seed round for its cloud security suite](https://techcrunch.com/2023/08/09/sweet-security-raises-12m-seed-round-for-its-cloud-security-suite/) | press | 2026-08-28 |
| s6 | [SiliconANGLE: Israeli startup Sweet Security raises $33M to strengthen cloud security operations](https://siliconangle.com/2024/03/06/israeli-startup-sweet-security-raises-33m-strengthen-cloud-security-operations/) | press | 2026-08-28 |
| s7 | [Sweet Security: About page (team and advisors)](https://www.sweet.security/about) | official | 2026-08-28 |
| s8 | [SiliconANGLE: Sweet Security debuts Agentic AI Blocking to stop rogue agents in real time](https://siliconangle.com/2026/07/29/sweet-security-debuts-agentic-ai-blocking-stop-rogue-agents-real-time/) | press | 2026-08-28 |
| s9 | [PeerSpot: Sweet Security reviews, rankings and CNAPP mindshare](https://www.peerspot.com/products/sweet-security-reviews) | other | 2026-08-28 |
| s10 | [Expert Insights: top cloud-native application protection platforms buyer guide](https://expertinsights.com/application-security/the-top-cloud-native-application-protection-platforms-cnapps) | other | 2026-08-28 |
| s11 | [Sweet Security: federal-market expansion and FedRAMP Moderate announcement (June 10, 2026)](https://www.sweet.security/press-releases/sweet-security-expands-into-u-s-federal-market-pursues-fedramp-moderate-authorization) | official | 2026-08-28 |
| s12 | [Google Patents: US12495057B1, Contextual anomaly detection in activity logs](https://patents.google.com/patent/US12495057B1/en) | other | 2026-08-28 |
| s13 | [Sweet Security: Agentic AI Blocking announcement (July 29, 2026)](https://www.sweet.security/press-releases/sweet-security-brings-autonomous-protection-to-the-ai-enterprise-with-new-blocking-capabilities) | official | 2026-08-28 |
| s14 | [Sweet Security: trust-subdomain probe (trust.sweet.security served the marketing homepage)](https://trust.sweet.security) | official | 2026-08-28 |
| s15 | [Sweet Security: case-studies resource index](https://www.sweet.security/resources/case-studies) | official | 2026-08-28 |
| s16 | [SecurityWeek: Sweet Security Raises $75 Million for Cloud and AI Security](https://www.securityweek.com/sweet-security-raises-75-million-for-cloud-and-ai-security/) | press | 2026-08-28 |

### Deep-Dive Sources

Cited from the Strategy Deep Dive section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Sweet Security: homepage (Autonomous Protection for the AI Enterprise)](https://www.sweet.security) | official | 2026-08-28 |
| s2 | [Sweet Security: AI Security Platform (AISP) product page](https://www.sweet.security/ai-security-platform-aisp) | official | 2026-08-28 |
| s3 | [Sweet Security: Runtime CNAPP platform page](https://www.sweet.security/runtime-cnapp) | official | 2026-08-28 |
| s4 | [Sweet Security: integrations catalog page](https://www.sweet.security/integrations) | official | 2026-08-28 |
| s5 | [Sweet Security: About page (team and advisors)](https://www.sweet.security/about) | official | 2026-08-28 |
| s6 | [Sweet Security: Series B announcement (November 12, 2025)](https://www.sweet.security/press-releases/sweet-security-raises-75m-series-b-and-unveils-the-first-unified-runtime-cnapp-for-cloud-and-ai-security) | official | 2026-08-28 |
| s7 | [SiliconANGLE: Israeli startup Sweet Security raises $33M to strengthen cloud security operations](https://siliconangle.com/2024/03/06/israeli-startup-sweet-security-raises-33m-strengthen-cloud-security-operations/) | press | 2026-08-28 |
| s8 | [SiliconANGLE: Sweet Security debuts Agentic AI Blocking to stop rogue agents in real time](https://siliconangle.com/2026/07/29/sweet-security-debuts-agentic-ai-blocking-stop-rogue-agents-real-time/) | press | 2026-08-28 |
| s9 | [CTech: Sweet Security, led by ex-IDF cyber chiefs, secures $75M Series B](https://www.calcalistech.com/ctechnews/article/b19tmlmgze) | press | 2026-08-28 |
| s10 | [SecurityWeek: Sweet Security Raises $75 Million for Cloud and AI Security](https://www.securityweek.com/sweet-security-raises-75-million-for-cloud-and-ai-security/) | press | 2026-08-28 |
| s11 | [Help Net Security: Sweet Security brings Runtime CNAPP visibility and protection to Windows environments](https://www.helpnetsecurity.com/2025/10/29/sweet-security-windows-extension/) | press | 2026-08-28 |
| s12 | [PeerSpot: Sweet Security reviews, rankings and CNAPP mindshare](https://www.peerspot.com/products/sweet-security-reviews) | other | 2026-08-28 |
| s13 | [Expert Insights: top cloud-native application protection platforms buyer guide](https://expertinsights.com/application-security/the-top-cloud-native-application-protection-platforms-cnapps) | other | 2026-08-28 |
| s14 | [Google Patents: US12495057B1, Contextual anomaly detection in activity logs](https://patents.google.com/patent/US12495057B1/en) | other | 2026-08-28 |
| s15 | [Sweet Security: federal-market expansion and FedRAMP Moderate announcement (June 10, 2026)](https://www.sweet.security/press-releases/sweet-security-expands-into-u-s-federal-market-pursues-fedramp-moderate-authorization) | official | 2026-08-28 |
| s16 | [Sweet Security: Agentic AI Blocking announcement (July 29, 2026)](https://www.sweet.security/press-releases/sweet-security-brings-autonomous-protection-to-the-ai-enterprise-with-new-blocking-capabilities) | official | 2026-08-28 |
| s17 | [Sweet Security: Sweet Attack launch announcement (May 13, 2026)](https://www.sweet.security/press-releases/sweet-security-launches-sweet-attack-to-debunk-the-myth-before-mythos-ships) | official | 2026-08-28 |
| s18 | [Sweet Security: trust-subdomain probe (trust.sweet.security served the marketing homepage)](https://trust.sweet.security) | official | 2026-08-28 |
| s19 | [Sweet Security: case-studies resource index](https://www.sweet.security/resources/case-studies) | official | 2026-08-28 |

## Disclaimer

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.
