A bank can encrypt a customer file before storing it. It can encrypt that file again while sending it across a network. Yet a fraud model cannot inspect a ciphertext and make a useful decision. At some point, the numbers have to wake up. For a moment, a server is doing work on the real thing. That moment is where Anjuna Security makes its living.
The short version
- Anjuna sells software that runs sensitive applications inside hardware-protected computing environments.
- Seaglass handles the workload; Northstar gives multiple parties a place to analyze data together; Overwatch governs AI agents.
- Its named users include JUMO and Ascendo AI. The company says three of the world's ten largest banks also use its products.
- The useful test is practical: can a team protect a real application without rebuilding it?
An old lock with a new weak spot
Anjuna's co-founders came at the problem from different directions. Ayal Yogev had worked in enterprise security product roles, including at Imperva, OpenDNS and SafeBreach. Yan Michalevsky was researching security and applied cryptography at Stanford. They founded Anjuna in 2018 and joined Y Combinator's winter class. The business idea was less romantic than the technology: a security primitive is of limited use if every customer must become an expert in it.
The primitive is confidential computing. Modern processors can create a trusted execution environment, often called an enclave, that isolates code and data during processing. Other software on the machine, and even people with administrative access to the host, should not be able to inspect the protected memory. The machine can also produce an attestation - cryptographic evidence of what code is running - before a policy releases secrets to it.
The three places a secret travels
The last box is the awkward one: useful computation needs access to data. A trusted execution environment narrows who else can look.
That is a different proposition from the usual perimeter pitch. A firewall decides who enters. Anjuna asks what an intruder, an administrator or a cloud operator could learn after entry. The distinction matters most when the information is valuable enough to make everyone nervous: payment records, proprietary algorithms, medical data or an AI model that cost a fortune to train.
Make the enclave boring
There was a catch. The chips were available, but using them could require rewriting applications for a particular processor and cloud. AWS Nitro Enclaves, for example, lack ordinary networking and persistent storage; teams may have to split applications and wire them together in unfamiliar ways. Anjuna's response was Seaglass, a software layer intended to package existing container applications, deploy them across cloud and private infrastructure, and manage attestation and secrets without changing their source code.

The product's appeal is the removal of specialist labor. A security architect can take a workload that already runs in a container, choose appropriate confidential-computing hardware, set a trust policy and test whether the protected version behaves. Seaglass spans AWS, Azure and Google Cloud and has gained Kubernetes and Red Hat OpenShift support. In August 2026 Anjuna announced support for bare-metal data centers using AMD SEV-SNP. The old question - which cloud can we trust? - becomes a more manageable question about which code, hardware and policies can be verified.
This does not make every threat disappear. An enclave does not decide whether a model's answer reveals too much, whether a data scientist is authorized to ask a question, or whether an application contains a bug. It protects a particular boundary. The boundary is valuable precisely because it is specific.
“We didn't invent confidential computing - we're just here to make it extremely easy.”Ayal Yogev, speaking to Forbes in 2024
The meeting nobody wanted to host
A good example comes from lending. JUMO builds financial technology for digital credit in African markets. Its partners hold customer transaction data; JUMO has its own models and know-how. Combining those assets could improve credit decisions. Handing either side's raw property to the other is another matter. This is the small, stubborn problem behind Anjuna Northstar, which became generally available in December 2024.
That product did not spring from a slide deck. In the 2024 preview, Anjuna described customers and partners who had already made Seaglass work for collaboration but had to build their own governance controls and architecture around it. The first thing to fail was ease of adoption. Northstar packages the repeated work into a product. For another company, that is a useful pattern to copy: watch for the scaffolding customers keep building beside your tool.
Northstar is an AI data fusion clean room built on Seaglass. Data owners and analysts can bring datasets, code and models into a protected environment; analysts can use familiar Jupyter notebooks. JUMO is a design partner, as is Ascendo AI, which applies the product to customer-support information from tickets and internal documents. These are more concrete uses than the phrase “secure collaboration” usually supplies. The point is to let a team learn from a combined dataset without requiring either party to surrender its inputs.
Traditional clean rooms can be restrictive about the questions users may ask or the code they may run. Anjuna's competitive claim is flexibility: bring your own model and analytical tools into an attested environment. That flexibility makes the product appealing and places more weight on output rules. If a query can simply print every underlying record, protected processing has not solved the data-sharing problem. A sensible pilot therefore tests the output policy alongside the enclave.
Who pays for a narrower circle of trust?
Anjuna sells to organizations that already understand the cost of exposing data: banks, government bodies, software vendors and other regulated enterprises. In 2025 it said three of the world's ten largest banks were customers, without naming them. The U.S. Navy tested Llama 3 models on confidential NVIDIA H100 GPUs with Anjuna software. That test showed a serious use case, though a test is not the same thing as a fleet-wide deployment.
The commercial arrangement is enterprise software. Seaglass has a 30-day trial, with applicants expected to know their way around a shell and Docker. Production pricing is handled through contracts, sales and cloud marketplaces; there is no current public list price to quote. Anjuna raised a $25 million Series B2 in August 2024, led by M Ventures, SineWave Ventures and AI Capital Partners. Publicly described seed, A, B and B2 rounds add to $67 million. Investors bought into a simple market observation: companies cannot fully exploit shared cloud and AI infrastructure while believing that infrastructure can see all their best information.
There are alternatives. A sophisticated team can build directly on a cloud provider's confidential-computing service. Fortanix and other specialists sell related platforms. An ordinary clean room may be sufficient for a narrow analytical task. Anjuna's place is the middle layer: software that makes protected hardware usable across multiple environments, then turns it into specific workflows.
The next person at the controls
In June 2026 the company introduced Overwatch, a trusted control plane for autonomous AI agents. It is a logical extension. If an agent can call tools, move data and spend money, the policy engine watching it must be harder to manipulate than the agent itself. Anjuna proposes to put that control layer inside the same kind of hardware-backed boundary it uses for workloads. The announcement is recent, so the telling measure will be what customers actually put under its control.
The practical lesson travels well beyond Anjuna. Start with the precise instant when a secret becomes visible. Name the people and systems that can see it. Then test one real workload, its attestations, its secret delivery, its outputs and its performance. Confidential computing is most persuasive when the protected process does something useful that an organization had been unable to approve. The cleverness is not in building a stronger box. It is in letting two parties work inside it and leave with the right answer - and with each other's secrets still their own.