The immune system for the age of APIs and AI - autonomous, self-learning, inline.
APIs quietly became the connective tissue of modern software - and, with that, the softest part of the attack surface. Every mobile app, banking integration and cloud service talks through them, which means every one of them is a door. ammune.ai, the cybersecurity company known until 2023 as L7 Defense, was built on a single, contrarian idea about how to guard those doors: stop writing rules, and let an AI learn each API on its own.
Founded in 2015 by Dr. Doron Chema and Yisrael Gross, the company set out to defend the application layer - Layer 7 of the network stack, where business logic lives and where signature-based tools tend to go blind. Its flagship platform, ammune™, deploys plug-and-play, auto-discovers the APIs on a network within seconds, and builds a tailored protection layer for each service inline, from the very first request. It does this without labeled attack data and without pre-training, using unsupervised machine learning to separate legitimate traffic from more than sixty different attack types in real time.
"L7 Defense's solution truly disrupts the way APIs are protected. Our ammune platform presents a significant breakthrough."
- Dr. Doron Chema, Co-founder & CEOMost API-security products ask defenders to describe the threat first - upload signatures, tune rules, feed the model labeled examples of good and bad. That approach struggles with the problems that matter most today: business-logic abuse that looks exactly like a normal user, credential-stuffing bots that rotate faster than any blocklist, and applicative-layer DDoS that hides inside legitimate-looking requests. ammune™ inverts the model. It watches unlabeled, live traffic, identifies and prioritizes patterns on its own, and starts protecting immediately - then keeps adapting as the API and its attackers change.
The practical payoff is operational as much as technical. Because the platform discovers APIs automatically - including the shadow and forgotten "zombie" endpoints that security teams rarely inventory - and runs day-to-day on autopilot, it does not need a full-time analyst babysitting rules. The company positions the whole approach as an immune system: something that learns and reacts to threats rather than standing as a fixed wall waiting to be climbed.
Illustrative breakdown of ammune™'s protection surface - the platform advertises coverage of 60+ API attack types.
Autonomous, AI-based API protection. Auto-discovers services and builds a tailored inline shield for each one, from the first request.
Bot mitigation, web-application-firewall functions, applicative-layer DDoS mitigation and business-logic abuse detection - at API resolution.
Real-time discovery and inventory of every API, including shadow and zombie endpoints, as the foundation for protection.
The AI workload offloaded onto NVIDIA BlueField-2 DPUs and Intel's NetSec Accelerator to guard Kubernetes clusters with minimal host CPU.
Detection, real-time isolation and analytics that run entirely offline - for data-sovereign environments and AI-system defense.
On-premises, cloud, containers or DPU. The same engine, wherever the APIs and AI workloads actually live.
ammune.ai is a business-to-business company. It licenses ammune™ to enterprises and public-sector organizations in the sectors where an exposed API is an existential risk - financial services and open banking, healthcare, government and defense, telecom, and critical national infrastructure. Revenue comes from software licensing and subscriptions, complemented by OEM and reference-design integrations that embed the technology into partners' hardware and platforms. Customer names are largely undisclosed, as is common in the security industry.
That reach is notable for a company of roughly a dozen people. ammune.ai punches above its headcount precisely because the AI does the heavy lifting and because it has partnered where distribution and performance matter: chipmakers for speed, and industry bodies for standards. In 2020 it took a strategic investment from India's Quick Heal Technologies; it later joined the Financial Data Exchange (FDX) to bring autonomous API protection into open-finance standards.
The API-security field has grown crowded - Salt Security, Noname Security (now part of Akamai), Traceable, Cequence, Wallarm, Imperva and F5 all compete for the same buyers. ammune.ai's differentiation rests on three choices. First, it leans on unsupervised learning, so it does not depend on labeled data or a library of known signatures - useful against novel and business-logic attacks that have no signature. Second, it protects inline from the first request, building per-API models rather than applying one generic policy. Third, it runs unusually close to the metal: the same AI can be offloaded onto a network card (a DPU), keeping server CPUs free for the applications that generate revenue.
"From APIs to AI - the immune system for the digital age."
- ammune.aiThat last capability points to where the company is heading. Its 2023 rename from L7 Defense to ammune.ai was not cosmetic; it signaled a widening of scope from APIs to AI systems and data centers, including protection against data poisoning and model theft, and offline detection for air-gapped environments. The same immune-system logic that guards an API is now being pointed at the models themselves.
Established to tackle application-layer attacks with AI, out of Israel.
The autonomous, AI-based API protection platform emerges as the flagship product.
Wins a Frost & Sullivan Product Leadership Award; Quick Heal Technologies invests strategically.
Round led by TRUMPF Venture with Quick Heal Technologies participating.
First to offload a real-time API-security AI workload onto NVIDIA's DPU.
Renames to ammune.ai and integrates with Intel's NetSec Accelerator Reference Design.
Extends protection to AI systems, data centers and offline, data-sovereign environments.
ammune.ai has raised roughly $7.75M in total, headlined by a $4M Series A in 2021 led by Germany's TRUMPF Venture with India's Quick Heal Technologies. Its partner list reads larger than its cap table: NVIDIA for DPU offload, Intel for Kubernetes-node protection, Amdocs in the telecom ecosystem, and the Financial Data Exchange in open finance.
Led by TRUMPF Venture; Quick Heal Technologies participating.
Strategic investment from Quick Heal Technologies.
Product Leadership Award for unsupervised-learning API protection; earlier anti-DDoS commendation.
"API security becomes critical for all major industries. L7 Defense represents a unique combination of leading technology and a favorable market."
- Dieter Kraft, TRUMPF VentureIt provides ammune™, a fully autonomous, AI-based platform that discovers and protects APIs - and increasingly AI systems and data centers - from cyberattacks in real time.
Yes. L7 Defense rebranded as ammune.ai in May 2023 to reflect a broader focus on AI security.
It uses unsupervised machine learning that needs no labeled data or pre-training, auto-discovers APIs, and builds a tailored inline protection layer for each service - blocking 60+ attack types automatically.
It is platform-agnostic: on-premises, in the cloud, in Kubernetes, offloaded onto DPUs such as NVIDIA BlueField-2, and in offline / air-gapped environments.
It raised a $4M Series A in 2021 led by TRUMPF Venture with Quick Heal Technologies, part of roughly $7.75M in total funding.
Watch: product demos and founder interviews are published on the company's YouTube channel. Press coverage includes the rebrand announcement and the NVIDIA BlueField-2 integration.