Every cloud scanner is great at finding problems. Tamnoon built a business on the boring part nobody wanted: fixing them - and doing it without taking production down.
SubImage is a San Francisco security startup building an open-core security graph that maps a company's cloud and SaaS infrastructure so teams can see who can access what, and why. Built by the original team behind Cartography, the open-source graph tool created at Lyft and now a CNCF project, SubImage sells a managed, agentless platform for attack path analysis, asset inventory, and misconfiguration detection. Backed by a $4.2M seed round, it positions itself as an open-core alternative to Wiz.
Aqua Security is a cloud native security company founded in 2015 that helps enterprises protect containerized and cloud native applications from development to production. Its Aqua Platform is a Cloud Native Application Protection Platform (CNAPP) that combines agent and agentless technology to scan code and images, enforce policies, manage cloud posture, and stop attacks at runtime. Aqua is also the creator of Trivy, the widely adopted open source vulnerability and misconfiguration scanner. Headquartered in Boston and Ramat Gan, Israel, the company protects more than 500 large enterprises and has raised $325M in total funding at a valuation above $1 billion.
SecLogic is a Boston-based cybersecurity company building an AI-driven cyber risk orchestration platform for the cloud era. Its two flagship products - CyberQ Shield, an agentless Cloud Native Application Protection Platform (CNAPP) that finds and auto-remediates misconfigurations and vulnerabilities across AWS, Azure, GCP and beyond, and CyberQ ORO, an Organization Risk Orchestration tool that quantifies human risk through multi-vector phishing simulation and awareness training - aim to give security leaders a single pane of glass across both their machines and their people. Founded in 2021 and backed by pre-seed funding, SecLogic operates across the US, Europe and India.
Tigera is the creator of Calico, the open-source standard for Kubernetes networking and security that powers more than a million clusters every day. From its San Jose headquarters, the company sells Calico Cloud and Calico Enterprise - SaaS and on-prem platforms that bolt active runtime security, zero-trust microsegmentation, and observability onto container environments at any scale.
Upwind is a runtime-first Cloud Native Application Protection Platform (CNAPP) that unifies cloud and AI security across the full lifecycle. Founded in 2022 by the team behind Spot.io, the company uses eBPF-based runtime telemetry to give security teams real-time context on what's actually exploitable in production - cutting noise, surfacing real threats, and protecting cloud-native and AI workloads at the speed they run.