Cloud security has a paperwork problem disguised as a technology problem. A scanner finds an exposed data store. A dashboard turns red. A ticket crosses the organizational tundra from security to engineering. Somebody eventually changes a policy - unless a release, an exception or simple fatigue gets there first. Native, a Seattle company founded in 2024, is built around a blunt observation: another finding is not the same thing as a defense.
Its product is a cloud security control plane for large enterprises. A team states an outcome such as “production data cannot be reached from the public internet.” Native maps the estate, translates that sentence into the distinct policy machinery of Amazon Web Services, Microsoft Azure, Google Cloud and Oracle Cloud Infrastructure, tests what the proposed controls would interrupt, and deploys them through existing infrastructure-as-code pipelines or its own console. Then it watches for drift.
The failure that arrived before the company
The origin story contains a useful little absurdity. Gal Ordo led product management for AWS Security Hub. Later, he tried to install the product the way a customer would. It took five days. “It was so hard for me to install,” he recalled. “And I'm within AWS!” If a person sitting near the source could lose most of a working week, the average enterprise was not suffering from a shortage of controls. It was suffering from controls that demanded scarce, provider-specific expertise.
Ordo became Native's chief product officer. CEO Amit Megiddo had led Amazon GuardDuty from its inception and watched customers struggle to operationalize AWS's security capabilities at scale. CTO Eyal Faingold had been vice president of research and development at Dome9, then led cloud security at Check Point after it acquired the company. Their change of mind was collective: detection products mattered, but the bottleneck had moved. Customers could see risk. They could not safely and continuously turn standards into architecture across several clouds.
“The visibility problem is frankly pretty solved. The imperative now is to be proactive.”Mark Crane, General Catalyst partner
What the machine actually does
Native starts above the individual misconfiguration. Its unit of thought is “intent”: the business outcome a security team wants to remain true. Underneath, the platform discovers accounts, subscriptions, projects, compartments, identities, resources and access paths. It groups that moving inventory into zones - production, development, sensitive data, shared services - and compares desired architecture with what every provider is enforcing now.
Translation is the tricky part. An AWS outcome might compile into Service Control Policies, Resource Control Policies, endpoint policies and KMS key policies. OCI uses compartments, IAM conditions, Security Zones and Network Security Groups. Azure and Google Cloud have their own policy hierarchies and exceptions. Native's claim is not magical sameness. It is that a single control plane can preserve the same outcome while respecting those differences.
- Define intent
- Map reality
- Translate
- Simulate
- Deploy
- Watch drift
The safety rehearsal matters. Before an AWS rule ships, Native can replay historical CloudTrail activity and list the actions it would have blocked. Teams can stage a rollout, route approvals, document exceptions and roll back. This is the difference between an elegant policy generator and something a CISO might permit near production. Security automation becomes useful only when the operator can see its likely collateral damage.
Who pays - and what it costs
This is enterprise software with an enterprise-sized trust requirement. Native says Fortune 100 organizations in finance, technology and media are early customers. Renaissance Learning CISO and CIO Drew Robertson appears on the company's site, as does Huy Li, head of global IT infrastructure and security at Monolithic Power Systems. The day-to-day users are cloud-security architects, platform teams, governance leaders and the engineers who inherit the guardrails.
Private offers and negotiated terms are also available. This is a public list offer, not a disclosed average customer bill.
The business model is contracted B2B SaaS sold directly and through cloud marketplaces. The current AWS Marketplace page displays a $1 million 12-month contract and invites buyers to request custom private offers. Microsoft describes custom pricing through Azure Marketplace. The public number is useful less as a rate card than as a neon sign over the intended segment: Native is selling to estates where cloud inconsistency, specialist headcount and a bad production policy can already cost seven figures.
The company emerged from stealth in March 2026 with $42 million: an earlier $11 million seed investment from General Catalyst, YL Ventures and Merlin Ventures, followed by a $31 million Series A led by Ballistic Ventures. Former Google Cloud CISO Phil Venables joined the board. Public reporting counted 41 employees at launch and a plan to reach roughly 90 by year-end; more recent company-data estimates put the team around 62.
That hiring plan is not decorative. Native has to maintain a living dictionary of security mechanisms across four providers, then explain consequential changes to both security specialists and engineers trying to ship software. The company recruits from the obvious talent pools - AWS, Google, Microsoft, CrowdStrike and Palo Alto Networks - and describes its culture in less polished terms than most careers pages: blunt honesty, mutual accountability and shared responsibility when something breaks. The team is distributed across the United States, Israel and the United Kingdom.
A new layer, not a new firewall
Native sits in an awkward but potentially valuable space beside cloud-native application protection platforms and cloud-security posture management tools. Wiz, Palo Alto Networks Prisma Cloud, Orca Security, CrowdStrike and Microsoft Defender for Cloud are prominent alternatives for enterprise security budgets. Many are excellent at discovering risky combinations, prioritizing findings and monitoring workloads. Native's chosen wedge is enforcement: make the provider's own architecture carry the rule.
That distinction can be complementary. A data-security product such as Cyera can identify where regulated information lives; Native says it can match that data to the underlying cloud resource and activate the controls meant to protect it. A CNAPP can still find risks. Native can be the route from an approved outcome to a maintained policy. The danger is budgetary and organizational overlap: buyers may ask an incumbent platform, an internal Terraform team or the cloud provider to do enough of the same job.
The bit anyone can copy
Native's best transferable idea is not “use AI” or “be proactive.” It is a six-part operating loop: write the outcome in language the business can inspect; map the system you actually have; translate intent into native mechanisms; replay history to expose collateral damage; stage the rollout; and monitor drift. Product teams can use the same loop for permissions, compliance, data retention or financial controls. It replaces blind automation with observable automation.
There is also a clear lesson in the company's positioning. Native does not insult the cloud providers' products. It argues those products are powerful, numerous and difficult to coordinate. That lets a startup build above giant platforms instead of pretending to replace them. The value is abstraction with fidelity: make complexity usable without erasing the details that make enforcement correct.
Conditions that help
- Several clouds or many accounts
- Reliable audit history
- Central security intent
- Infrastructure-as-code discipline
- Costly policy drift
Conditions that fight it
- One small, simple cloud
- No authority to change controls
- Sparse or dirty telemetry
- Highly bespoke unsupported services
- Zero tolerance for automated action
The lock can jam
Native's hardest problem is trust. It asks an enterprise to let a young vendor influence policy across the most sensitive layer of its cloud estate. A detection mistake creates noise; an enforcement mistake can stop legitimate work. Simulation reduces that risk but cannot perfectly predict a novel workload, missing telemetry or an interaction that never appeared in historical logs. Every abstraction also trails the providers occasionally, because AWS, Azure, Google and Oracle keep shipping new services and policy features.
The model is less persuasive for a small team running one uncomplicated cloud, or for organizations without a coherent security standard to encode. It will struggle where ownership is fragmented and nobody can approve a shared outcome. It also depends on the customer embracing native provider controls; a business committed to external enforcement layers or manual review may see the same architecture as an uncomfortable concentration of authority.
By August, Native was demonstrating the control plane at Black Hat and extending its public argument to AI agents. The point is practical: an agent can behave unpredictably, but the surrounding cloud architecture can still limit which models, systems and data it reaches. This does not make an agent trustworthy. It puts a fence around the consequences. Native is also publishing guidance on data perimeters, zero trust and multi-cloud enforcement - category education for a product whose buyers may not yet have a budget line named “control plane.”
Still, Native has chosen the honest difficulty. The cloud does not need another red badge beside a resource if nobody closes the path. The company is betting that prevention can become an operating system rather than a quarterly cleanup project. If it works, the result is almost boring: fewer tickets, fewer heroic fixes and fewer dangerous routes available in the first place. In security, boring is a respectable payoff.