Akamai began with a pixel hidden on Disney's website. Twenty-seven years later, the network built to beat the 'World Wide Wait' is becoming a security perimeter and an AI cloud - without giving up the pipes that made it matter.
Most security tools inspect the code developers write. Appknox follows the app that users actually touch - from compiled binary and real-device behavior to the moment a counterfeit copy appears in an app store.
Casco is a San Francisco cybersecurity startup that runs autonomous, AI-driven penetration tests on web apps, APIs, cloud infrastructure, and AI systems. Founded in 2025 by ex-AWS engineers Rene Brandel and Ian Saultz, it pairs continuous machine-driven attack simulation with human security experts, delivering compliance-ready reports for standards like SOC 2, ISO 27001, and the EU AI Act. A Y Combinator (X25) company, Casco says it serves 300+ companies and secures AI systems used across a majority of the Fortune 500.
ammune.ai (formerly L7 Defense) is a cybersecurity company that builds ammune™, a fully autonomous, AI-based platform for protecting APIs - and, increasingly, AI systems and data centers - from cyberattacks. Using unsupervised machine learning, ammune auto-discovers APIs and builds a tailored protection layer for each one inline from the first request, blocking dozens of attack types (bots, DDoS, business-logic abuse, injection) in real time without pre-training or rule-writing. The platform is platform-agnostic, running on-premises, in the cloud, in Kubernetes clusters, and offloaded onto DPUs such as NVIDIA BlueField-2, and it recently expanded toward offline, air-gapped protection for AI workloads.
Mend.io, formerly WhiteSource, is a Boston- and Tel Aviv-based application security company that helps development and security teams find and fix vulnerabilities in open source dependencies, custom code, and AI-generated code. Its platform spans software composition analysis (SCA), static and dynamic testing (SAST/DAST), API security, automated dependency updates via Renovate, and a growing suite of AI security tools. Serving more than 1,000 customers including a quarter of the Fortune 100, Mend.io emphasizes automated remediation - producing exact code fixes rather than long lists of alerts - to help teams reduce security debt without slowing delivery.
應援科技 OenTech is a Taipei-based fintech that runs a one-stop integrated payment cloud platform combining third-party payment processing with a CRM-style supporter management system. Tailored for nonprofits, creators, political campaigns, temples and merchants, it lets organizations accept donations, sell tickets and merchandise, manage memberships and issue receipts on a single, security-certified stack. Certified to PCI-DSS Level 1, ISO 27001 and ISO 27701, Oen positions itself as one of Taiwan's most secure payment platforms and now serves more than 1,000 organizations.
Contrast Security is a Pleasanton, California-based cybersecurity company that secures software from the inside out. Founded in 2014 by OWASP veterans Jeff Williams and Arshan Dabirsiaghi, it pioneered an instrumentation-based approach that embeds security sensors directly into running applications to detect vulnerabilities and block live attacks in real time. Its runtime security platform spans Interactive Application Security Testing (IAST), Runtime Application Self-Protection (RASP), static analysis (SAST), software composition analysis (SCA), and Application Detection and Response (ADR), serving Fortune 500 enterprises and government agencies.
Yisi Gross (Yisrael Gross) is an Israeli-rooted, New York-based technology entrepreneur and investor. He co-founded L7 Defense (now ammune.ai), an AI-driven API security company that raised Series A backing from TRUMPF Venture and Quick Heal, and today works as a Managing Partner at TYH Investments, backing early-stage high-tech startups. He built his reputation on the unglamorous frontier of API-borne attacks, arguing that autonomous, machine-learning defense - not human-tuned rules - is the only way to keep pace with modern cyberattacks.
MirrorTab is a San Francisco cybersecurity startup that stops browser-based attacks by moving the browser session server-side. Its isolation technology intercepts and sanitizes a web session at the edge before it ever reaches a user's device, so malware, malicious extensions, bots, and AI-driven automation never touch the application's code, data, or APIs. Founded in 2021 by Honey co-founder Brian Silverstein, the company raised an $8.5M seed round led by Valley Capital Partners in February 2025 and targets financial services, e-commerce, and government.
Impart Security is a San Francisco cybersecurity company building a unified runtime protection platform for AI, APIs, and web applications. Founded in 2020 by Signal Sciences veterans Jonathan DiVincenzo, Marc Harrison, and Brian Joe, the company merges WAF, API security, Cloud Application Detection & Response, and AI Runtime Protection into one engine that runs autonomous defense agents inside production traffic.
Brian Silverstein is the founder and CEO of MirrorTab, a San Francisco cybersecurity company that treats the browser as the new battleground and tries to take it off the table entirely. Using server-side isolation, MirrorTab strips the client-side attack surface so malware, malicious extensions, and bots never touch the real code, data, or APIs behind a web session. Before MirrorTab he was an early co-founder and CTO of Honey, the shopping-rewards browser extension acquired by PayPal, and an engineer at Apple, Nest, Broadcom, and Freescale. A Cornell-trained electrical engineer with eight patents, he raised an $8.5M seed in 2025 led by Valley Capital Partners with GV and others.

Dan Temkin is a Senior Technical Product Marketing Manager at Kong (formerly Mashape), one of the world's leading API management platforms. With over a decade of experience in API strategy spanning roles at IBM and Kong, Temkin sits at the intersection of complex distributed systems and the business language needed to explain them. Based in Madison, Wisconsin, he shapes how enterprises think about API security, AI governance, and the economics of running LLMs at scale - authoring widely-read Kong blog posts, speaking at Apidays and AWS re:Invent, and helping translate the architecture of Kong's $424M-funded platform into decisions that matter to engineering and executive teams alike.
Ivan Novikov is the founder and CEO of Wallarm, an AI-powered API security platform that has raised over $70 million in funding including a $55M Series C in 2025. With 24+ years in cybersecurity, he is recognized as the inventor of memcached injection attacks and a pioneer of SSRF research, having earned bug bounty awards from Google, Facebook, Twitter, Tesla, and Yandex. A Y Combinator S16 alumnus with a physics background from Moscow State University, Novikov transformed hands-on offensive security expertise into a company protecting APIs for enterprises worldwide.
Wallarm is a San Francisco-based API and application security company protecting more than half of public-facing APIs at large enterprises with a unified platform for API discovery, attack prevention, and AI-era threat protection.
Shay Levi is the Co-Founder and CEO of Unframe, an enterprise AI platform that delivers working AI solutions to large organizations in days rather than months. A Unit 8200 alumnus, he previously co-founded Noname Security, scaling it to $40M ARR and a $500M acquisition by Akamai in 2024. Undeterred, he immediately founded Unframe in January 2024, which has since reached $100M in total contract value, raised $100M in total funding, and earned the #2 spot on Calcalist's 50 Most Promising Startups of 2026.
Stepan Ilyin is the Co-Founder and COO of Wallarm, a San Francisco-based API and application security company that raised $55M in Series C funding in 2025. A former whitehat hacker and Bauman Moscow State Technical University graduate, he co-founded Wallarm in 2013 alongside Ivan Novikov and others, with the company graduating from Y Combinator's S16 batch. Wallarm now protects Fortune 500 enterprises with AI-powered API security, real-time threat detection, and CI/CD-integrated vulnerability management. Ilyin has authored over 500 publications on DevSecOps, API security, and AI threat prevention, and is a recognized conference speaker at Black Hat, RSA, and similar venues.
Gadi Bashvitz is the Co-founder and CEO of Bright Security (formerly NeuraLegion), a San Rafael-based developer-centric Dynamic Application Security Testing (DAST) platform. A veteran of the Israeli Defense Forces' elite Unit 8200, he brings 25+ years of cybersecurity, product, and go-to-market experience to his mission of making application security accessible to every developer. Under his leadership, Bright Security raised a $20M Series A in 2022 and launched the Bright STAR autonomous security testing and remediation platform at RSA Conference 2025, achieving approximately 85% auto-remediation rates for its customers.
Jonathan DiVincenzo is the CEO and Co-Founder of Impart Security, a San Francisco-based AI-native runtime protection platform for applications, APIs, and LLM workloads. A veteran of Signal Sciences - where he served as VP of Product through the company's $825M acquisition by Fastly - DiVincenzo founded Impart in 2021 alongside Marc Harrison and Brian Joe to tackle what they saw as the broken 'last mile' of application security. His platform has deployed over 2,400 security rules across enterprise customers, cutting deployment time from 18 days to 45 minutes. In June 2025, Impart raised a $12M Series A led by Madrona Ventures.