SERIES A  Tamnoon raises $12M led by Bright Pixel Capital ZINNIA  72% cut in critical-alert MTTR, ~24,000 alerts closed NEW  Managed Cloud Detection & Response + AI SecOps agent PATENT PENDING  Tamnoon Prevent stops bad AWS configs pre-deploy FOUNDED 2022  By Dome9 veterans, Seattle & Tel Aviv ZERO  Production incidents across millions of workloads SERIES A  Tamnoon raises $12M led by Bright Pixel Capital ZINNIA  72% cut in critical-alert MTTR, ~24,000 alerts closed NEW  Managed Cloud Detection & Response + AI SecOps agent PATENT PENDING  Tamnoon Prevent stops bad AWS configs pre-deploy FOUNDED 2022  By Dome9 veterans, Seattle & Tel Aviv ZERO  Production incidents across millions of workloads

Company Profile Cloud Security

The Cloud Security Company That Actually Fixes the Alerts

Every cloud scanner is great at finding problems. Tamnoon built a business on the boring part nobody wanted: fixing them - and doing it without taking production down.

Buy any modern cloud security tool and it will do one thing beautifully: hand you a list of everything wrong with your cloud. Thousands of misconfigured buckets, over-permissioned roles, unencrypted databases, ports left open to the internet. The dashboard glows red. And then, in most companies, almost nothing happens. The list gets bigger. This is the quiet failure at the center of cloud security, and it is the exact spot where Tamnoon decided to pitch its tent.

Tamnoon, based in the Greater Seattle area with a second base in Israel, is a cloud security company built around a single unglamorous verb: remediate. Not detect. Not alert. Fix. Its managed service takes the firehose of findings coming out of a customer's existing scanners and turns them into resolved problems - triaged, prioritized by real business impact, and driven to root cause by a blend of AI agents and human cloud engineers. The company calls the discipline "RemOps." Most of the industry had been treating it as somebody else's job.

"Automation for cloud security is not the panacea it is often made out to be." Marina Segal, CEO & Co-Founder

01The gap everyone could see and nobody sold


The founding team - CEO Marina Segal, CTO Idan Perez, and chairman Zohar Alon - did not arrive at this from the outside. All three worked together at Dome9 Security, one of the pioneers of cloud security posture management, which Check Point acquired in 2018. Segal had spent roughly two decades in cloud protection, including a stretch helping Sysdig grow. They had, in other words, spent years building the very scanners that produce the red dashboards.

What they kept seeing was a mismatch. The number of CNAPP and CSPM tools was exploding, but the number of people who could safely act on their output was not. Automated fixes, sold as the cure, had a habit of breaking production - close the wrong port, revoke the wrong role, and an application falls over at 2 a.m. So teams did the rational thing: they snoozed alerts, suppressed them, and let the backlog grow. Finding problems had become cheap. Fixing them was still expensive, slow, and scary.

Segal has been blunt about the diagnosis. The industry had oversold automation as a cure-all, and in doing so had skipped the hardest part of the problem. Three specific pain points kept recurring at Dome9: the sprawl of CNAPP and CSPM tools outran the humans available to run them; automated fixes lacked the business context to be trusted; and remediation itself was slow, manual and disruptive when it happened at all. Tamnoon is essentially those three complaints turned into a company.

up to 95%
Reduction in MTTR
25x
More alerts investigated
0
Production incidents

02What Tamnoon actually does


Tamnoon deliberately does not try to replace your Wiz, Orca, Prisma Cloud or Sysdig deployment. It sits on top of them. The scanners keep finding; Tamnoon takes it from there. A hybrid team - AI doing the heavy, repetitive lifting and human experts doing the judgment - deduplicates and correlates the noise, figures out which handful of alerts actually threaten the business, writes a remediation plan for each, and either executes it or hands engineering a ticket precise enough to act on in minutes rather than days.

Tamnoon remediation ticket showing expert-validated, safe-to-remediate steps flowing into a ServiceNow ticket
The unglamorous middle, productized. A single alert - "AWS MFA not enabled for IAM users" - moves from expert-validated to safe-to-remediate to a ServiceNow ticket. The whole company is a bet on this one boring pipeline.

The design principle is "safe to remediate." Before a change touches a live environment, Tamnoon simulates the fix, checks the blast radius, and validates it with a human. That is the reason customers can quote the number that usually sounds too good to be true: zero production incidents across millions of workloads and thousands of remediations. The point of putting people in the loop is not nostalgia. It is that context - what this database does, who depends on that role - is exactly what pure automation lacks.

Tamnoon consolidating three separate cloud alerts into one prioritized RDS remediation task
Three screams, one fix. A "critical" from one scanner, a "high" from another, a "medium" from a third - all pointing at the same exposed RDS instance - collapse into a single task. Deduplication is where alert fatigue quietly goes to die.

03How the work flows


Under the hood, Tamnoon frames remediation as a repeatable, five-stage motion - the same shape whether a human or an agent is holding the pen.

01

Ingest

Pull findings from the customer's existing CNAPP/CSPM tools across AWS, Azure and GCP.

02

Correlate

Deduplicate overlapping alerts and cluster them by the real underlying asset.

03

Prioritize

Rank by business impact and exposure, not just raw severity scores.

04

Plan

Build a remediation path, simulate it, and confirm it is safe to apply.

05

Resolve

Execute or ticket the fix to root cause, verified by a human expert.

"We believe the solution is to combine humans and AI." Marina Segal, CEO & Co-Founder

04Who's actually using it


The clearest proof point is Zinnia, an insurtech company, where Tamnoon reported a 72% reduction in mean time to resolution for critical cloud alerts and roughly 24,000 alerts closed. A US dental-support organization cut alert noise by around 70% and had more than a thousand high-severity misconfigurations remediated inside three months. The target buyer is the cloud team at a Fortune 1000 company - in media and entertainment, healthcare, insurance, manufacturing - that already owns a scanner and is drowning in what it produces.

Customer-reported outcomes (illustrative, from public case data)
Zinnia MTTR cut
72%
Peak MTTR cut
95%
Ticket volume cut
95%
Alert noise cut
~70%

05How it's different from the competition


The obvious names in cloud security - Wiz, Orca Security, Palo Alto's Prisma Cloud, Sysdig - are detection companies. They are very good at telling you what is wrong. Tamnoon's whole positioning is that it lives one step downstream and does not compete with them at all. On the other side sit pure-automation remediation tools, the ones that promise to fix everything with no humans. Tamnoon's argument is that those are the tools most likely to break your production environment.

Detect-only scanners

  • Surface thousands of findings
  • Leave the fix to your team
  • No business context on impact
  • Backlog keeps growing

The Tamnoon layer

  • Sits on top of your scanners
  • Human + AI drive the actual fix
  • Prioritized by real business impact
  • Safe-to-remediate, verified first
Tamnoon on-demand CNAPP demos graphic surrounded by cloud security vendor logos
Friends, not rivals. Tamnoon deliberately orbits the CNAPP ecosystem rather than fighting it - the scanners find, Tamnoon fixes. Naming your company after an octopus and then wrapping your arms around the whole market is on-brand.

06Products, and a business model to match


The flagship is the Managed Cloud Security Remediation service that launched into revenue in 2023. Around it, the company has been building outward. Tamnoon Prevent, a patent-pending, browser-based control, stops a non-secure configuration from being deployed in the AWS console before it ever goes live - prevention rather than cleanup. In June 2025 the company added a Managed Cloud Detection and Response offering and an AI Cloud SecOps agent, nicknamed Tami, that automates the investigation and triage grunt work. Later that year it pushed further into agentic, skill-based remediation.

The business model is the quietly radical part. Tamnoon does not primarily sell software seats; it sells an outcome - a cloud that is measurably more secure - as a managed service. That framing is why the metrics it leads with are operational (MTTR, alerts closed, incidents avoided) rather than feature lists. It is also why the model can work at all: remediation is labor-shaped, and pairing scarce human experts with AI agents is how you make that labor scale without the headcount.

07Where it fits in the market


Tamnoon is small - roughly 50 people across Seattle and Tel Aviv - and it is early. It raised a $12 million Series A in September 2024, led by Bright Pixel Capital (formerly Sonae IM), with Blu Ventures, Mindset Ventures, Merlin Ventures, Secret Chord Ventures, Inner Loop Capital and Elron Ventures joining. The round pushed reported total funding past $18 million and is aimed at product roadmap and partnership expansion.

The bet underneath the fundraise is a timing bet. A decade of investment went into making cloud problems visible. Comparatively little went into resolving them, and the talent to do that resolution safely is scarce and expensive. If cloud security's next chapter is about closing the remediation gap rather than widening the detection lead, Tamnoon has planted itself squarely in it. The name helps tell the story: Tamnoon is the Hebrew word for octopus - many-handed, adaptive, and good at getting into tight spaces. For a company whose entire job is reaching into the messy parts of someone else's cloud, it is an unusually honest logo.

There is a lesson here that a reader can take without buying anything. The most valuable spot in a workflow is often not the flashy front end but the tedious step everyone routes around - the handoff, the cleanup, the fix. Tamnoon looked at a market obsessed with better detection and asked who was doing the follow-through. The answer, mostly, was nobody. That is a pattern worth copying in almost any field: find the part of the job that people quietly dread, and make that the product.

None of this is guaranteed to work. A managed model leans on scarce human expertise, and scaling that without diluting quality is the open question every services-plus-software company faces. The scanners it partners with today could decide to build the remediation layer themselves tomorrow. But for now Tamnoon has a clear, unclaimed piece of ground and a founding team that has walked this exact terrain before. In a field crowded with dashboards, it is selling something rarer: the thing after the dashboard.