Breaking
ammune.ai auto-discovers APIs in seconds and protects them inline Formerly L7 Defense - rebranded to ammune.ai in May 2023 ammune™ blocks 60+ API attack types in real time Runs on NVIDIA BlueField-2 DPUs and Intel NetSec Accelerator $4M Series A led by TRUMPF Venture with Quick Heal Technologies Frost & Sullivan Product Leadership Award winner ammune.ai auto-discovers APIs in seconds and protects them inline Formerly L7 Defense - rebranded to ammune.ai in May 2023 ammune™ blocks 60+ API attack types in real time Runs on NVIDIA BlueField-2 DPUs and Intel NetSec Accelerator $4M Series A led by TRUMPF Venture with Quick Heal Technologies Frost & Sullivan Product Leadership Award winner
Company Profile · Cybersecurity · AI

ammune.ai

The immune system for the age of APIs and AI - autonomous, self-learning, inline.

Formerly L7 Defense
60+Attack types stopped
2015Founded
$7.75MTotal funding
~12Team size
ammune™ API security dashboard by ammune.ai
THE PRODUCT. The ammune™ console - traffic, threats and geography at a glance,
the readout of an AI that learns each API for itself.
Share this profile LinkedIn Twitter / X Facebook Instagram

APIs quietly became the connective tissue of modern software - and, with that, the softest part of the attack surface. Every mobile app, banking integration and cloud service talks through them, which means every one of them is a door. ammune.ai, the cybersecurity company known until 2023 as L7 Defense, was built on a single, contrarian idea about how to guard those doors: stop writing rules, and let an AI learn each API on its own.

Founded in 2015 by Dr. Doron Chema and Yisrael Gross, the company set out to defend the application layer - Layer 7 of the network stack, where business logic lives and where signature-based tools tend to go blind. Its flagship platform, ammune™, deploys plug-and-play, auto-discovers the APIs on a network within seconds, and builds a tailored protection layer for each service inline, from the very first request. It does this without labeled attack data and without pre-training, using unsupervised machine learning to separate legitimate traffic from more than sixty different attack types in real time.

"L7 Defense's solution truly disrupts the way APIs are protected. Our ammune platform presents a significant breakthrough."

- Dr. Doron Chema, Co-founder & CEO
What it does

Protection that adapts to traffic, not the other way around

Most API-security products ask defenders to describe the threat first - upload signatures, tune rules, feed the model labeled examples of good and bad. That approach struggles with the problems that matter most today: business-logic abuse that looks exactly like a normal user, credential-stuffing bots that rotate faster than any blocklist, and applicative-layer DDoS that hides inside legitimate-looking requests. ammune™ inverts the model. It watches unlabeled, live traffic, identifies and prioritizes patterns on its own, and starts protecting immediately - then keeps adapting as the API and its attackers change.

The practical payoff is operational as much as technical. Because the platform discovers APIs automatically - including the shadow and forgotten "zombie" endpoints that security teams rarely inventory - and runs day-to-day on autopilot, it does not need a full-time analyst babysitting rules. The company positions the whole approach as an immune system: something that learns and reacts to threats rather than standing as a fixed wall waiting to be climbed.

Autonomy - deploy to protect
Unsupervised learning coverage
Attack-type breadth
Deployment flexibility
Bots, DDoS & injection
Business-logic abuse
Emerging & AI-era threats

Illustrative breakdown of ammune™'s protection surface - the platform advertises coverage of 60+ API attack types.

Products & services

One platform, modular defense

Core platform

ammune™

Autonomous, AI-based API protection. Auto-discovers services and builds a tailored inline shield for each one, from the first request.

Modules

apiBOT · apiWAF · apiDDoS · apiBL

Bot mitigation, web-application-firewall functions, applicative-layer DDoS mitigation and business-logic abuse detection - at API resolution.

Visibility

API Discovery

Real-time discovery and inventory of every API, including shadow and zombie endpoints, as the foundation for protection.

Edge / DPU

Node-based deployment

The AI workload offloaded onto NVIDIA BlueField-2 DPUs and Intel's NetSec Accelerator to guard Kubernetes clusters with minimal host CPU.

Air-gapped

Offline AI Protection

Detection, real-time isolation and analytics that run entirely offline - for data-sovereign environments and AI-system defense.

Model

Platform-agnostic

On-premises, cloud, containers or DPU. The same engine, wherever the APIs and AI workloads actually live.

Customers & business model

Where APIs are business-critical

ammune.ai is a business-to-business company. It licenses ammune™ to enterprises and public-sector organizations in the sectors where an exposed API is an existential risk - financial services and open banking, healthcare, government and defense, telecom, and critical national infrastructure. Revenue comes from software licensing and subscriptions, complemented by OEM and reference-design integrations that embed the technology into partners' hardware and platforms. Customer names are largely undisclosed, as is common in the security industry.

That reach is notable for a company of roughly a dozen people. ammune.ai punches above its headcount precisely because the AI does the heavy lifting and because it has partnered where distribution and performance matter: chipmakers for speed, and industry bodies for standards. In 2020 it took a strategic investment from India's Quick Heal Technologies; it later joined the Financial Data Exchange (FDX) to bring autonomous API protection into open-finance standards.

B2BGo-to-market
5+Core industries
Cloud→DPUDeployment span
Newark, NJHQ (Israeli R&D roots)
How it's different

Unsupervised, inline, and close to the metal

The API-security field has grown crowded - Salt Security, Noname Security (now part of Akamai), Traceable, Cequence, Wallarm, Imperva and F5 all compete for the same buyers. ammune.ai's differentiation rests on three choices. First, it leans on unsupervised learning, so it does not depend on labeled data or a library of known signatures - useful against novel and business-logic attacks that have no signature. Second, it protects inline from the first request, building per-API models rather than applying one generic policy. Third, it runs unusually close to the metal: the same AI can be offloaded onto a network card (a DPU), keeping server CPUs free for the applications that generate revenue.

"From APIs to AI - the immune system for the digital age."

- ammune.ai

That last capability points to where the company is heading. Its 2023 rename from L7 Defense to ammune.ai was not cosmetic; it signaled a widening of scope from APIs to AI systems and data centers, including protection against data poisoning and model theft, and offline detection for air-gapped environments. The same immune-system logic that guards an API is now being pointed at the models themselves.

The story so far

A decade at Layer 7

2015

L7 Defense founded

Established to tackle application-layer attacks with AI, out of Israel.

2019

ammune™ takes shape

The autonomous, AI-based API protection platform emerges as the flagship product.

2020

Recognition & investment

Wins a Frost & Sullivan Product Leadership Award; Quick Heal Technologies invests strategically.

2021

$4M Series A

Round led by TRUMPF Venture with Quick Heal Technologies participating.

2022

NVIDIA BlueField-2

First to offload a real-time API-security AI workload onto NVIDIA's DPU.

2023

Rebrand & Intel integration

Renames to ammune.ai and integrates with Intel's NetSec Accelerator Reference Design.

2024

Toward AI & air-gapped defense

Extends protection to AI systems, data centers and offline, data-sovereign environments.

Backing & partnerships

Small team, heavyweight allies

ammune.ai has raised roughly $7.75M in total, headlined by a $4M Series A in 2021 led by Germany's TRUMPF Venture with India's Quick Heal Technologies. Its partner list reads larger than its cap table: NVIDIA for DPU offload, Intel for Kubernetes-node protection, Amdocs in the telecom ecosystem, and the Financial Data Exchange in open finance.

Series A · 2021

$4M

Led by TRUMPF Venture; Quick Heal Technologies participating.

Strategic · 2020

$2M

Strategic investment from Quick Heal Technologies.

Recognition

Frost & Sullivan

Product Leadership Award for unsupervised-learning API protection; earlier anti-DDoS commendation.

"API security becomes critical for all major industries. L7 Defense represents a unique combination of leading technology and a favorable market."

- Dieter Kraft, TRUMPF Venture
Good questions

Frequently asked

What does ammune.ai do?

It provides ammune™, a fully autonomous, AI-based platform that discovers and protects APIs - and increasingly AI systems and data centers - from cyberattacks in real time.

Is ammune.ai the same company as L7 Defense?

Yes. L7 Defense rebranded as ammune.ai in May 2023 to reflect a broader focus on AI security.

How is ammune different from other API security tools?

It uses unsupervised machine learning that needs no labeled data or pre-training, auto-discovers APIs, and builds a tailored inline protection layer for each service - blocking 60+ attack types automatically.

Where can ammune be deployed?

It is platform-agnostic: on-premises, in the cloud, in Kubernetes, offloaded onto DPUs such as NVIDIA BlueField-2, and in offline / air-gapped environments.

Who funded ammune.ai?

It raised a $4M Series A in 2021 led by TRUMPF Venture with Quick Heal Technologies, part of roughly $7.75M in total funding.

Explore & connect

Links, social & watch

Watch: product demos and founder interviews are published on the company's YouTube channel. Press coverage includes the rebrand announcement and the NVIDIA BlueField-2 integration.