Rebuilding vendor risk as a security problem, not a compliance checklist - one continuous, behavior-based assessment at a time.
Every enterprise runs on vendors - the payroll processor, the analytics tool, the cloud service quietly holding customer records. And every year, security teams try to keep those vendors honest with the same instrument: a questionnaire. Lema AI, a New York cybersecurity startup that emerged from stealth in February 2026 with roughly $24 million in funding, was built on the belief that the questionnaire is theater.
"Third-party risk needs to be treated like a security problem, not a compliance checklist," says co-founder and CEO Eddie Dovzhik. "The industry is relying on manual assessments that miss real-time business context." It is a pointed critique of a market that has, for two decades, graded suppliers on paperwork rather than behavior. A vendor can hold a spotless SOC 2 report and still be a live wire inside your systems. As Lema puts it in its own bluntest phrasing: you can be fully compliant and still be completely exposed.
Lema's answer is a platform it describes as an "Agentic Risk Engineer" - an AI trained to investigate a vendor the way an elite vulnerability researcher would, rather than to read and summarize documents. Instead of asking a supplier what it does, Lema watches what that supplier can actually reach: which critical assets it touches, how data moves, and - crucially - how permissions and scope drift over time. The company claims it can produce a full assessment of a new vendor in under five minutes.
The product sits on top of a simple but under-served idea: risk is not a snapshot, it is a movie. A vendor onboarded with a clean review in January can accumulate new integrations, new permissions and new access by June - a phenomenon Lema calls "risk drift" or "scope drift." Traditional tools, which reassess annually, are structurally blind to it. Lema's engine monitors continuously, combining telemetry about how a vendor is used inside the enterprise with agentic AI that validates threat scenarios and maps realistic attack paths.
That approach reframes the core question of vendor security. Where a security-ratings company asks "is this vendor compliant?", Lema asks "if this vendor is breached, what happens to us?" It is the difference between a credit score and a stress test.
AI trained to investigate like a vulnerability researcher, not a document reader - validating threat scenarios and returning concrete remediation steps.
Analyzes vendor reports and documents to uncover the hidden risks that static questionnaires routinely miss.
Continuously monitors public vendor information, external intelligence feeds and data-breach disclosures.
Tracks how each vendor is actually used - access to critical assets, data movement, and permission scope drift over time.
Lema's founding team shares a background in Israel's elite signals-intelligence unit, and it shows in the product's offensive-security posture. The company's whole thesis inverts the usual assumption that the threat is outside the walls - your vendors, after all, are already inside.
Former Major in Unit 8200; previously led product at Noname Security, the API-security firm acquired by Akamai. Member of the Forbes Technology Council.
Unit 8200 veteran with a prior research and product role at Noname Security. Leads Lema's engineering and its agentic-analysis engine.
Unit 8200 veteran shaping Lema's product direction and its "think outside the checkbox" approach to third-party risk.
| Dimension | Legacy TPRM tools | Lema AI |
|---|---|---|
| Cadence | Point-in-time, often annual | Continuous monitoring |
| Primary signal | Questionnaires & outside-in ratings | In-environment vendor behavior |
| Question asked | Is the vendor compliant? | What can this vendor actually reach? |
| Scope drift | Largely invisible between reviews | Tracked as it happens |
| New vendor review | Days to weeks | Under 5 minutes |
Competitors in the space - BitSight, SecurityScorecard, UpGuard, Panorays, Whistic - largely score vendors from the outside or automate the questionnaire itself. Lema's differentiator is that it links a vendor's behavior directly to the customer's business-critical assets. "Lema is the first platform to solve this by directly linking third-party behavior to business-critical assets," says Liran Grinberg of Team8, which led the Series A.
Lema is entering a large and fast-growing category. The third-party risk management market is estimated at roughly $8 billion in 2026 and is projected to reach about $15 billion by 2030 - a crowded field of GRC suites and security-rating vendors that most buyers quietly know is due for a rethink.
"Third-party risk needs to be treated like a security problem, not a compliance checklist."
Eddie Dovzhik · CEO"You can be fully compliant and still be completely exposed."
Lema AI"Lema is the first platform to solve this by directly linking third-party behavior to business-critical assets."
Liran Grinberg · Team8Lema is a B2B SaaS company selling annual subscriptions to enterprise security, GRC and third-party-risk teams, largely in regulated sectors such as financial services and healthcare. It goes to market through a demo-request motion; pricing is not public.
Named customers on Lema's site include Klaviyo, AlphaSense, Cresta, OPENLANE, Well Health, Delta Dental and SCI - a mix of high-growth software firms and regulated enterprises. The exact customer count has not been disclosed.
Eddie Dovzhik, Tomer Roizman and Omer Yehudai - three Unit 8200 veterans - start the company to rethink third-party risk.
Lema raises roughly $6.5M seed led by F2 Venture Capital with Salesforce Ventures, growing its R&D team in Israel while building in stealth.
Lema emerges from stealth in February with a $17.5M Series A led by Team8 - about $24M total - and names customers including Klaviyo and Delta Dental.
Lema AI provides an agentic AI platform for third-party risk management, continuously analyzing how vendors behave inside an enterprise to surface real security risks instead of relying on static questionnaires.
Lema was founded by Eddie Dovzhik (CEO), Tomer Roizman (CTO) and Omer Yehudai (CPO), all veterans of Israel's Unit 8200 intelligence unit.
Approximately $24M in total, including a $17.5M Series A led by Team8 announced in February 2026 and an earlier seed round led by F2 Venture Capital with Salesforce Ventures.
Enterprise security and third-party risk teams, especially in regulated sectors. Named customers include Klaviyo, AlphaSense, Cresta, OPENLANE, Well Health, Delta Dental and SCI.
Rather than issuing outside-in security ratings or automating questionnaires, Lema monitors how vendors actually behave inside the customer's environment - tracking access, scope drift and blast radius - to validate claims and model real attack paths.
Note: No official Lema AI accounts were found on Twitter/X, Instagram, Facebook, GitHub, YouTube or TikTok at time of filing. Demo videos are available via the "Get a demo" flow on lema.ai.
Profile compiled from public sources · Facts current as of the February 2026 stealth-exit announcement