Forty million is an awkward number to put on a to-do list. In July 2026, Astelia described an enterprise deployment with approximately 40 million vulnerability findings. Its analysis narrowed them to fewer than 2,000 that were actually reachable.
- Maps network connections and checks what an exploit requires.
- Helps enterprises prioritize reachable exposure and choose practical fixes.
- Works with existing scanners; adds agents for the follow-through.
These are Astelia’s reported figures from one deployment, rather than an independently audited benchmark. They nevertheless introduce the company’s central proposition rather neatly. A vulnerability finding tells you that a weakness exists. It does not, by itself, establish that an attacker has a usable route to it. Astelia sells enterprises software for investigating that missing connection.
The men who used to look for a way in
Alon Noy, Nadav Ostrovsky and Roy Rajwan founded Astelia in 2024. Noy is CEO, Ostrovsky CTO and Rajwan CPO. All three bring experience from Israel’s National Red Team. In his founding essay, Noy describes alternating between simulating attacks on critical infrastructure and working with the security and IT teams responsible for defending it.
The attackers could search for one overlooked route. The defenders had to make sense of a mountain of warnings. Noy recalls building network maps under pressure, with incomplete visibility, and learning to spot paths through misconfigured rules and forgotten assets. That experience supplied the company’s starting point: understand the connections before deciding which weakness deserves attention.
Astelia emerged publicly in February 2026 with $35 million in financing. The total comprised a $10 million seed round led by Team8 with Holly Ventures, followed by a $25 million Series A led by Index Ventures with both earlier investors participating. Team8’s venture creation model helped establish the business.

“Defenders were buried in noise, while attackers needed just one reachable path.”Alon Noy / founding essay
A score has no idea where your firewall is
Consider an illustrative case: two servers carry the same vulnerable software. One service is exposed through an accessible port. The other sits behind controls that block the required traffic. The flaw may receive the same severity score on both machines, yet the practical work differs. This is the distinction Astelia’s platform is designed to make visible.
It integrates with infrastructure tools in read-only mode, analyzes configurations and policy rules, and builds a model of network topology. AI analysis examines what exploitation requires, including execution context and attack vectors. The platform correlates those requirements with asset and runtime information. Its output explains why a finding represents exposure in that particular environment, with attack-path views showing the route to vulnerable hosts.
There is another useful consequence of following connections. Astelia’s coverage-gap capability aggregates endpoint detection and vulnerability-tool data, including processes, network activity and installed software. It also examines third-party access that could enable lateral movement. A map can reveal that the inventory itself needs attention, before anyone debates the order in which to repair it.
The patch is one item on the menu
For an IT team, “fix it” can conceal an unpleasant amount of work. Astelia’s remediation offering puts firewall rules, access controls and asset isolation alongside patches. It supplies reasoning for each recommendation and continuously checks whether the relevant attack paths have been blocked. The point is to give security and infrastructure teams a practical choice grounded in the same evidence.
The lesson is easy to borrow even without buying the software. For a finding that demands attention, ask for the route, the exploit prerequisites and the control that would interrupt them. Compare the operational burden of the available fixes. Then check the result. A closed ticket is an administrative achievement; whether the route remains open is a separate question.
After the shortlist, somebody still has to act
By July, Astelia was expanding the work after prioritization. Its product team described two additions: agents that carry vulnerabilities through triage, remediation and validation, and an MCP interface for organizations using their own AI assistants. MCP connects an assistant to tools and data; here, the attraction is access to Astelia’s environment-specific analysis.
The agent workflow can begin with a natural-language specification. A planner proposes steps, tools and permissions, while more than 100 MCP integrations provide enterprise context. Human checkpoints and auditability are part of the design. The product team also describes continuous workflow testing, including checks for results that drift even when execution appears successful.
An enterprise sale, with an existing stack attached
Astelia addresses CISOs, vulnerability-management teams and the IT people who implement changes. Its public testimonials include Syniverse, AlphaSense and Bilfinger. Their comments emphasize network and runtime context across complicated environments. The company said it was working with dozens of customers, including Fortune 500 organizations, when it announced its funding.
This is a demo-led enterprise software business, with customer contracts and channel distribution. In September, Astelia announced availability through GuidePoint Security and said several large customers had renewed. Its deployment pitch allows enterprises to keep their existing scanners and add reachability analysis above them.
The surrounding market is busy. Tenable One, for example, combines broad attack-surface coverage with exposure analytics and prioritization. Astelia’s emphasis is the specific route an attacker can use, and the evidence required to shut it. Buyers should compare the quality of that analysis against their own networks and workflows. A memorable percentage is an introduction to a demonstration, not a substitute for one.
“Astelia gives us the network context needed to understand which vulnerabilities actually matter in our environment”Ben Bachmann / CISO, Bilfinger / company-published testimonial
The map must keep up with the territory
Astelia now advertises the “reachable 1%”; its February launch materials used 2%. Those figures belong to the company’s positioning, not to a law governing every network. The larger analytical caution follows from the method: a reachability conclusion depends on the environment represented in the model. Stale runtime data, missing connections or changed access rules can weaken that conclusion.
The company is extending its defensive AI access too. It announced participation in Anthropic’s Cyber Verification Program in June and OpenAI’s Trusted Access for Cyber in September. Its thesis remains grounded in a stubbornly concrete detail: exploit code needs the conditions to run. For the reader facing tomorrow’s backlog, that is the useful question to carry away. Which path exists, and what would close it?