THE LATEST
●MAR 2026 · $20M SERIES A · $26M TOTAL FUNDING●JUL 2026 · CYBER VERIFICATION PROGRAM●AUG 2026 · US SALES EXPANSION
Company / Enterprise security01 · The execution gap

Reclaim Security wants you to stop fearing the fix

A security flaw is alarming. A fix that stops the business can be worse. Reclaim Security builds an AI Security Engineer to predict the consequences, then help teams make the change.

A security team can own the right tools and still dread the next configuration change. The dashboard says a setting is unsafe. The engineer knows an application may depend on it. Somewhere between those two facts, a ticket acquires the peculiar immortality of enterprise paperwork. Everyone agrees it matters. Nobody wants to be the person who stops the business.

The useful version
  • Reclaim works on the security stack a company already owns.
  • Its PIPE engine predicts what a proposed fix could disrupt.
  • Execution stays within customer approval boundaries, with reversible changes.
  • The buyer is an enterprise security team with more findings than time.

Reclaim Security has made that hesitation its business. Its AI Security Engineer analyzes exposures, plans tailored changes and helps execute them. The appealing promise is less time spent translating a warning into a safe action. The interesting question is whether software can supply the confidence that another severity score cannot.

The queue is where the trouble starts

A vulnerability scanner can identify a flaw. An exposure-management system can rank it. Neither answer automatically tells an engineer whether changing a permission will strand a service account, or whether an endpoint policy will interfere with an essential application. The dangerous setting may also be a working setting. That is an inconvenient quality in something you wish to remove.

Reclaim calls the distance between identifying a problem and safely fixing it the security execution gap. Its market sits where continuous threat exposure management, or CTEM, has to become operational work. Discovery and prioritization feed the queue; remediation must get something out of it. A beautifully organized backlog remains a backlog.

The alternatives include manual engineering, IT tickets, native platform controls and security orchestration playbooks. Remedio, for example, also markets automated remediation, impact previews and rollback. Reclaim’s argument is that execution needs context across systems, impact analysis and verification. It offers an additional layer over existing tools. Whether that layer earns its place depends on how much work it removes and how safely it makes changes.

A rehearsal before the real thing

The mechanism at the center is PIPE: Productivity Impact Prediction Engine. It uses behavioral information to model the operational consequences of a proposed security change. The product’s sequence is understandable: inspect the environment, design a fix that fits, evaluate its impact, then deploy within the organization’s rules. Continued validation watches for settings drifting away from the intended state.

There is a revealing qualification to the AI label. In its July announcement about joining Anthropic’s Cyber Verification Program, Reclaim says models inform research and intelligence. Production fixes remain deterministic, governed and reversible. An enterprise buyer can ask about reasoning and execution separately, rather than accepting the word “autonomous” as an explanation of both.

“The model informs our intelligence, it never runs the fix.”

Barak Klinghofer · Reclaim’s July 2026 announcement
Reclaim’s published product illustration compares security gains and potential productivity impact across remediation options
Look before you lock. Reclaim’s platform illustration puts productivity and security on the same decision screen. The awkward trade-offs get a place at the table.

The tools were already in the building

The company’s Pine Gate Renewables case study gives the proposition a concrete setting. The renewable-energy business needed to improve its Microsoft security configuration without consuming its team’s capacity. Reclaim describes an API-connected assessment followed by staged changes to email, endpoint, operating-system and identity controls. The intervention strengthened an existing stack.

Over four months, the account reports 587 hours of manual work avoided and no business disruption. Those are vendor-reported outcomes. Its resilience improvements are assessment measures, rather than observed reductions in successful attacks. The distinction matters: a security score can support a decision without becoming a prediction of the next breach.

587hours

Manual work saved in the published four-month Pine Gate engagement.Vendor-reported estimate, not an independently audited result.

The useful detail is the combination of work removed and changes actually made. A cautious team needs evidence that protection improves while ordinary work continues. A faster recommendation alone would leave the original hesitation intact.

A second act in security automation

The founders brought experience in building security businesses. CEO Barak Klinghofer previously sold Hexadite to Microsoft. Chief Product Officer Roy Peretz previously sold WhiteBox Security. Yaniv Waksman leads engineering; Or Virnik leads research. They established Reclaim in 2024. Product judgment, engineering and threat research are all represented in the founding group.

The four Reclaim Security founders photographed together
Four founders, one stubborn handoff. Reclaim’s founding team has chosen the moment when a security recommendation must become a production change. Photograph: Reclaim Security.

In March 2026, the company announced a $20 million Series A led by Acrew Capital, with QP Ventures and Ibex Investors participating. Total funding reached $26 million. The stated uses were engineering, integrations and expansion in North America and Europe. In August, Reclaim appointed Stephen Wadsworth VP of Sales to lead its US go-to-market work.

The commercial model is enterprise B2B software with a demo-led sales process and a proof-of-value offer. Funding tells us what investors committed; it does not tell a buyer what a deployment costs. The more useful purchasing exercise is to test a defined set of exposures, then measure the labor, approved changes and operational effects.

Its customer announcements name businesses including Telit Cinterion, Competitive Power Ventures and Eastern Pacific Shipping. The careers page emphasizes ownership, learning from senior colleagues and measuring outcomes. That last preference fits a company whose sales argument depends on completed work. Buyers should expect the same discipline in a demonstration.

Borrow the method before buying the machine

Reclaim’s practical lesson travels beyond its product. Before a change, identify dependencies and preserve the previous state. Define what failure would look like. Limit the initial scope. Afterward, check that the exposure closed and that users can still do their jobs. A completed ticket is evidence of administrative activity; a verified result is evidence of a fix.

This approach requires access to the relevant systems and enough information about how the business operates. An undocumented dependency or an unsupported tool can leave a prediction incomplete. Reclaim’s own recent writing stresses blast radius, rollback and outcome validation. Those requirements belong in the evaluation, alongside speed. The product becomes useful when a team can see why a particular change is safe enough to approve.

The small revolution here is a change in the question. Security teams routinely ask, “How bad is the flaw?” Reclaim asks them to examine the fix with equal seriousness. For the engineer holding a ticket open because an application might stop working, that is a question worth paying attention to.

Open the next tab