33 Cybersecurity Startups Join Google’s Gemini Forum
Quick answer
Google's Gemini Startup Forum selects 33 AI-native cybersecurity startups to tackle agent security, post-quantum crypto, and more. Dive into the full list.
Google just dropped a big one for the cybersecurity swamp: 33 fresh startups are joining the Gemini Startup Forum: Cybersecurity. These capybaras are diving deep into AI-native security, from protecting autonomous agents to post-quantum cryptography. And they’re getting mentorship from Google DeepMind, Google Cloud, and Wiz. Let’s wade through the highlights.
AI Agent Security & Governance
As AI agents become more autonomous, keeping them on a short leash is critical. These startups are building the guardrails:
- Capsule Security (Israel): Runtime protection for AI agents, monitoring API calls and tool usage in real-time.
- Evoke Security (US): EDR for AI agents—scans configurations, monitors behavior, blocks unauthorized actions.
- Manifold Security (US): Agentless detection using graph analysis and OpenTelemetry hooks.
- Mirror Security (Ireland): Fully homomorphic encryption for AI workloads—compute on encrypted data without decrypting.
- Onyx Security (Israel): AI control plane to discover, govern, and monitor agents across the enterprise.
- Refractal (UK): Runtime security and GRC for AI agents, with cryptographic audit logs.
- Unbound Security (US): Agent Access Security Broker (AASB) for coding agents—monitors terminal commands.
- XOR (US): Reinforcement learning data to train AI models to find and fix their own security flaws.
Application Security & Vulnerability Management
These startups are automating the hunt for bugs and misconfigurations:
- Aisy (UK): Models enterprise environments from an attacker’s perspective to prioritize fixes.
- Alt Security (Israel): Agentic penetration testing—autonomous AI agents chain vulnerabilities to find critical risks.
- Arcjet (US): App security that runs inside your codebase via SDK—bot detection, rate limiting, prompt injection.
- Pixee (US): Automates vulnerability triage and remediation—converts scanner results into verified PRs.
Cloud, Network & Infrastructure Security
Keeping the cloud swamp secure requires smart monitoring and automation:
- CloudFence (US): Monitors cloud network patterns and alerts on anomalies.
- CyberSeQ (UK): Scans code for outdated encryption, helps plan post-quantum transition.
- Huskeys (Israel): Smart firewall tuner that reduces false alarms.
- Native (Israel): Multicloud security control plane with a simulation engine to preview policy changes.
- Prowler (US): Open-source cloud security posture management across multicloud.
- QIZ Security (Israel): Centralized crypto asset management with a knowledge graph for post-quantum readiness.
- Tracebit (UK): Cloud-native decoys deployed via IaC to detect intrusions.
Endpoint Security & Data Protection
Protecting endpoints and data from exfiltration and insider threats:
- Bold Security (US): User-space endpoint agent with on-device ML for DLP without cloud latency.
- Glow (Israel): Unifies endpoint, software, and AI agent monitoring with collaborative AI agents.
- Jazz (US): Modern DLP that analyzes user intent and business context, not static rules.
- ORION Security (US): Indicator-driven DLP tracking data lineage across endpoints and SaaS.
- MokN (France): Proactive identity recovery using decoy access points to trick attackers.
SOC Automation & Offensive Security
Automating the security operations center and red teaming:
- COGNNA (Saudi Arabia): Agentic SOC platform that analyzes alerts and automates response.
- Latent Defense (US): World models for cybersecurity—graph-based attack path identification and automated red-teaming.
- Mate Security (Israel): AI-native SOC that integrates with SIEM/SOAR to triage alerts.
- Nrdsnipe (Sweden): AI-driven internal network penetration testing with planner and terminal agents.
- RIFFSEC (Poland): Early-warning threat intelligence for central Europe, monitoring dark web and Telegram.
- TandemTrace (Spain): Autonomous AI agents that analyze raw telemetry to investigate alerts.
Security Infrastructure & Specialized Services
Foundational tools and niche defenders:
- Netsec (France): All-in-one IT and cybersecurity lifecycle management inside collaboration channels.
- Revelum (US): Detects and dismantles deepfake-driven fraud and impersonation at scale.
- Synqly (US): Unified connectivity platform and API management for IT and security tool integration.
This cohort marks a shift from perimeter defense to autonomous AI agent security. Google has supported over 50 cybersecurity founders in the past four years, and this forum is part of the Google for Startups Gemini Kit. The swamp is getting safer, one capybara at a time.
Original announcement published on Google Cloud.