Breaking: AI agents inherited the keysVorlon moved from visibility to enforcementPrice check: $175K base contract on AWS MarketplaceDataMatrix maps the machine conversation Breaking: AI agents inherited the keysVorlon moved from visibility to enforcementPrice check: $175K base contract on AWS MarketplaceDataMatrix maps the machine conversation

Company profile / Enterprise security

AI Agents Have the Keys. Vorlon Wants to Watch What They Do Next

The Mountain View security startup began by watching third-party APIs. Then AI agents arrived, inherited the credentials, and made the overlooked space between apps the main event.

The suspicious character in Vorlon's world is rarely a person in a hoodie. It is a well-behaved API token carrying a valid badge. The token moves from Salesforce to HubSpot, asks a cloud store for a file, hands the result to an AI agent, and does all of it without tripping the alarms built to watch human logins. Every door opened properly. The data still went somewhere it should not.

That is the problem Vorlon has spent four years learning how to describe. Founded in 2022 by Amir Khayat and Amichay Spivak, the Mountain View company began as a specialist in third-party API security. Its early pitch was plain: businesses had filled themselves with SaaS applications, then connected those applications with OAuth grants, service accounts, and API keys that were too permissive and barely observed.

The founders had seen the inside of a security operations center before. Both came through Demisto, the incident-response automation company that Palo Alto Networks bought for $560 million in 2019. Demisto helped analysts act after an alert arrived. Vorlon's wager moves the camera upstream: first understand how the applications, identities, integrations, and sensitive data relate; then spot the strange movement; then contain it before the cleanup meeting begins.

Vorlon co-founder and CEO Amir Khayat
The repeat founderAmir KhayatThe sales-engineer-turned-CEO built Vorlon with CTO Amichay Spivak after their Demisto chapter. The company's name comes from the mysterious guardians in Babylon 5. Cybersecurity founders, it turns out, can be enormous sci-fi nerds too.

The first thing that failed was the map

Traditional SaaS security tends to inspect one building at a time: Is the tenant configured correctly? Is the user overprivileged? Is multifactor authentication switched on? Those are useful questions, but they miss the skybridges. Vorlon's first insight was that third-party connections formed their own attack surface. A token could pass every identity check and still extract too much data, at the wrong hour, through an integration nobody remembered approving.

Vorlon v2.0, released in August 2024, made the map visible. Customers could see where sensitive data traveled through connected applications. In April 2025, the company gave the underlying idea a name: DataMatrix. The engine assembles fragments from API traffic, apps, identities, agents, and Vorlon's own research into a continuously updated model of the environment. The company later announced that its intelligent-simulation approach had received a patent.

Vorlon product graphic illustrating discovery across connected applications
THE OFFICE GOSSIP GRAPH: Every app knows another app, and DataMatrix would like the full seating chart.
“Third-party API security is a massive gap in cybersecurity.”Amir Khayat, CEO and co-founder

DataMatrix is the differentiator on which the rest of Vorlon hangs. It is not merely an inventory of software or a list of bad settings. It is closer to a living relationship graph. When a service account behaves oddly, the useful answer is not only that the account fired an alert. An analyst wants to know which application authorized it, what class of data it touched, what “normal” looked like yesterday, and which downstream systems now sit inside the blast radius.

Then the bots got agency

What changed Vorlon's mind about the size of the opportunity was not a failed product. It was a changing customer environment. AI assistants became agents. Agents gained tools. Tools gained permission to call other tools. The old third-party integration problem suddenly had initiative. A workflow could read a ticket, query a wiki, update a CRM, draft a campaign, and send a payload to another service without pausing for a human.

In July 2025, Vorlon repositioned its offering as a unified SaaS and AI security platform. Shadow-AI discovery joined sensitive-data flow mapping, behavioral analysis, identity monitoring, and compliance reporting. At RSA Conference in March 2026, the company added Flight Recorder, an audit trail for agent actions and API calls, and Action Center, a place to triage findings and execute remediation. Ask Vorlon puts a natural-language interface over the model so an analyst can request the riskiest integrations instead of learning another query language.

1,000+Connected SaaS apps, AI tools and services the platform says it can observe or detect
24hClaimed time from connection to baseline visibility
93%Faster incident response reported in Splitit's case study

Guardian, launched in June 2026, completes the progression from diagram to traffic cop. Registered upstream of an agent platform, it can apply controls at the protocol layer: block a risky transaction, mask sensitive data while it moves, or force an integration into read-only mode. Vorlon's language here is carefully chosen. Access control asks whether an identity may enter. Guardian asks what that identity may do with the furniture once inside.

Who buys a traffic cop for software?

The customers are enterprises with enough SaaS sprawl to have lost count and enough sensitive data to regret guessing. Public names include CarGurus, ThoughtSpot, OPENLANE, Dutchie, and payments company Splitit, alongside unnamed Fortune 500 organizations. The daily users sit across security operations, identity, IT, risk, compliance, and application teams. Vorlon pipes findings into tools such as Splunk, Google SecOps, ServiceNow, Jira, Okta, Slack, Tines, and Palo Alto Networks XSOAR, a clue that it would rather enrich an existing workflow than demand a new swivel chair.

ThoughtSpot's security chief said the company had answers in less than a day. CarGurus describes using Vorlon for visibility across apps, APIs, users, secrets, and data flows, as well as anomaly detection and breach assessment. Splitit's published case study says context-rich alerts cut incident-response time by 93 percent. Those are vendor-selected stories, but they make the buyer's job concrete: find forgotten keys, see unusual data movement, calculate exposure, and revoke access without touring twenty admin consoles.

The product moved steadily closer to the transaction

2024 · Map
See
2025 · Model
Know
2026 · Guardian
Act

What it costs, and what that tells you

Vorlon is enterprise software sold through demos and annual contracts. One unusually useful public marker sits on AWS Marketplace: a 12-month Base Platform contract is listed at $175,000, with 12 months of data retention listed at another $100,000. Contract terms can vary, but the sticker tells you who is not invited. This is not a browser extension for a 14-person startup with three SaaS subscriptions.

Public price marker$175K

Listed cost for a 12-month Base Platform contract on AWS Marketplace. Data retention is a separate listed dimension.

The company has raised $15.7 million in total capital as of its April 2024 Series A announcement. Accel led both the seed and Series A, with Shield Capital and several Demisto alumni participating. That funding bought time to build the model, add integrations, and follow the market from API posture into agentic runtime security. The current team is still small: supplied company data estimates 33 employees, while LinkedIn places it in the 11-to-50 band.

The crowded shelf, and the narrow opening

Vorlon sits where several security categories overlap. SaaS security posture management checks configuration. Identity threat detection watches accounts. Data-loss prevention classifies and controls sensitive material. API security monitors interfaces. Cloud access brokers govern use of cloud services. New agent-security gateways inspect AI workflows. Any serious customer will ask why one of those vendors cannot stretch into Vorlon's territory.

Vorlon's answer is scope plus context plus action. It claims to model the relationships across the full ecosystem, not stop at a single app or agent platform; to anchor anomalies in the data being moved; and, with Guardian, to enforce before a transaction finishes. The risk is equally clear. Platform companies love to describe adjacent tools as silos, while adjacent tools are busy adding platform features. Vorlon must prove that its cross-system model catches important behavior competitors miss, without adding friction or drowning the SOC in another species of alert.

What a reader can steal

  • Map the workflow before automating it. You cannot govern connections nobody has drawn.
  • Treat valid credentials as the beginning of investigation, not the end.
  • Attach business context to alerts: data touched, owner, downstream systems, and an available fix.
  • Move product value from visibility toward action. A beautiful warning is still only a warning.

When the model does not pay for itself

Vorlon's approach works best when complexity is real: hundreds of applications, a growing population of non-human identities, sensitive information moving between systems, autonomous agents in production, and a security team capable of acting on context. It weakens when the environment is small, the integrations are few, or existing controls already provide adequate visibility. Inline enforcement also demands care. A false positive that blocks a machine-speed workflow can become a machine-speed business interruption.

There is a broader lesson in the company's arc. Vorlon did not abandon its original API-security observation when AI arrived. It enlarged the frame around it. The overlooked connection between apps became the execution layer for agents; the data map became a simulation; the detection product acquired a flight recorder and then a gate. Good positioning often looks like that: the same stubborn problem, renamed at the moment the rest of the market finally notices it.

The Vorlons of Babylon 5 preferred to stay mysterious. This Vorlon cannot afford the same trick. Enterprise buyers will want to see exactly what the model sees, why it judged an action risky, and what happens when Guardian says no. In a market stuffed with confident AI-security labels, legibility may be the most persuasive feature of all.