The first thing Runtime Ventures wants from a cybersecurity founder is not revenue. It is not a 40-page market map or a polished tour of an imaginary sales pipeline. The firm will invest before a company has meaningful sales. What it does want is a real product, or at least a strong minimum viable one, in the hands of people who might use it. Design partners count. Paying customers earn extra credit. Then comes the question that separates a promising security trick from an investable business: is this a company, or is it the next bullet point in an incumbent's release notes?
That distinction is the spine of Runtime's strategy. Founded in 2023 by David Endler and Michael Sutton, the firm invests only in B2B cybersecurity companies, globally, at pre-seed and seed. It will write $250,000 to $1 million checks at pre-seed and $750,000 to $2 million at seed. It can lead, negotiate a term sheet or join somebody else's round. In April 2025, Runtime announced the final close of its first fund at $32 million. Eleven investments were already out the door.
The firm's customers, in the practical sense, are founders caught in cybersecurity's least photogenic stretch: the months when a technically credible product still lacks a repeatable way into enterprise budgets. Their buyers are cautious, integrations are messy, and the market is crowded with vendors that sound identical from 30 feet away. A generalist investor can supply capital. Runtime is selling the judgment of people who have built, bought, broken, marketed and sold security software.
01 / The operatorsA fund built from scar tissue
Endler spent about 25 years in cybersecurity before Runtime. He co-founded account-takeover and anti-ransomware company SpyCloud in 2016, and earlier started anti-malware developer Jumpshot, acquired by Avast in 2013. His resume also runs through the National Security Agency, MIT, Deloitte, iDEFENSE and TippingPoint. He has written security books and holds patents. Sutton arrived by another long road through the same industry. He was an early Zscaler operator and its chief information security officer, helped build SPI Dynamics and iDEFENSE, and then founded StoneMill Ventures, which backed more than 40 early cyber companies.
The overlap matters. These are not investors who discovered security because artificial intelligence made the pitch decks livelier. They worked in the field when software-as-a-service security was still a contrarian proposition, built research and product teams, sat with buyers and lived through acquisitions. That history gives them a shared language with technical founders and a useful memory of how quickly accepted wisdom can expire. Their published team now also includes operating partner Ruoting Sun, a GreyNoise executive who previously worked in product at Secureframe and helped launch Zero Trust offerings at Duo Security, plus analyst Elisa Yan.
“We love companies that give us homework, gives us things to do.”David Endler, describing Runtime's preferred founder relationship
It is an appealing line because it makes the vague venture promise of “value add” measurable. Runtime lists the assignments it expects: introduce early adopters, sharpen product development, recruit key people, plan fundraising, prepare for board meetings and help a founder decide what comes first. If Runtime leads a round, it expects a board seat. On a non-lead investment above $1 million, it may ask for observer rights. The arrangement is hands-on without pretending that an investor should become the chief executive. Endler has said the partners offer suggestions, not instructions.
02 / The filterPre-revenue is not pre-evidence
Runtime's application filter is unusually legible. The company must sell security to businesses. The initial round must be pre-seed or seed. A founding group should show technical and commercial balance - the firm's shorthand is a “hacker and a hustler.” The market needs room for a standalone company and an honest go-to-market path, preferably with a product-led growth opportunity. And while revenue is optional, a strong MVP with design partners is not.
This solves a recurring problem in security startups. Technical founders can identify a genuine vulnerability yet misjudge who owns the budget, how urgent the fix feels, or whether Microsoft, Palo Alto Networks, CrowdStrike or another platform can neutralize the startup with one bundled capability. Sutton puts the risk plainly on Runtime's site: a feature is not a business. The firm looks for markets where the go-to-market potential can keep pace with the engineering.
Its limited partners add another layer to that test. At the 2025 fund announcement, Runtime described a base containing 26 founders, 61 cybersecurity operators, 18 CEOs and three public companies. Names are not the important part of that arithmetic. Jobs are. A practitioner can look at a product and say, with budget-owning clarity, “interesting, but I would not buy it.” That feedback is useful before a young company spends two years proving it the expensive way.
03 / The portfolioFrom hot-dog hacks to actual exits
The portfolio spans the parts of security currently being rebuilt: AI-powered security operations, code analysis, browser security, application detection and response, observability, next-generation SIEM, software-supply-chain protection, attack-surface management, compliance, fraud orchestration and AI application testing. This is not a product suite. Runtime earns management fees and, if the portfolio performs, a share of investment gains. Its founders earn access to checks, networks and labor. The companies themselves sell the software.
A small product test captures the firm's style better than a thesis diagram. While considering SPLX, an AI-security startup, Endler built a chatbot for the fictional Acme Hotdog Company. The bot had two firm rules: never mention competitors and never reveal the secret ingredient, roasted red peppers. SPLX's Probe product persuaded the bot to break both rules in several languages and formats, while finding prompt-injection weaknesses. Runtime invested. In November 2025, Zscaler acquired SPLX to add AI asset discovery, automated red teaming, runtime guardrails and governance to its platform.
More recent investments show the same preference for large workflows rather than decorative features. RunReveal raised $7 million in July 2025 to build an AI-native security-data platform positioned against costly, complicated legacy SIEM stacks. AiStrike announced a $7 million seed round in January 2026 for a system that unifies threat intelligence, detection engineering, investigation and response. Runtime participated in both. The recurring target is an overworked security team with too much noise, too many tools and too little time.
04 / The positionNarrow by design, early by choice
Runtime competes with specialist firms such as Ballistic Ventures, SYN Ventures, Forgepoint Capital, YL Ventures, Cyberstarts and Rain Capital, along with security practices inside broader seed funds. Plenty of angels are former chief security officers. Capital is not scarce for a convincing cyber pitch. Runtime's distinction is the combination of a rigid category boundary, small early checks, founders who have both operated and exited, and an investor community engineered to participate in diligence and mentoring.
That model has constraints. A $32 million fund cannot keep supporting every winner deep into growth rounds. Concentrating on one industry concentrates risk when cyber funding cools or buyers consolidate vendors. Operator pattern recognition can also become nostalgia if yesterday's playbook is applied too neatly to an AI-shaped market. The counterweight is the firm's willingness to invest globally and to back first-time founders, not only repeat entrepreneurs with familiar pedigrees.
Where Runtime fits, then, is between an experienced angel syndicate and a conventional institutional seed fund. It offers institutional mechanics - term sheets, boards, follow-on planning - while trying to preserve the specificity and speed of a practitioner writing a personal check. Its public process promises a direct pass or a quick path through one or two partner meetings. For founders, that transparency saves the resource they possess least: attention.
The clever part is not predicting every new attack. It is building a network that can recognize when a defense is buyable.
The $32 million matters because it gives Runtime room to place multiple bets. The more interesting asset is accumulated scar tissue: knowing when a security buyer will tolerate another dashboard, when a clever capability belongs inside a larger platform, and when a founder needs a customer introduction more than another hour of advice. Runtime's wager is that those judgments compound at the earliest stage. Its invitation to founders makes the promise nicely concrete: bring a strong product, a large problem and some homework.