Sweet Security Unveils the First Unified Runtime CNAPP for Cloud and AI Security with Orel Ben Ishay
Sweet Security has secured $75 million in Series B funding led by Evolution Equity Partners, bringing its total funding to $120 million. The investment will fuel global expansion and accelerate product innovation to address rising enterprise demand for real-time protection across cloud, AI, and production environments. Its new AI security capabilities safeguard models, agents, and the full AI lifecycle, positioning the company at the forefront of next-generation cloud and AI security.
Transcript
Hey everyone. Welcome back here to Tech Drunk tv. I'm happy to introduce you to my next guest.
This guest, it's his first time on with us. His name is Orel Ben. Benny Shai Orel is a co-founder as well as the VP of r and d at a company called Sweet, sweet Orel.
Welcome to Tech Drunk tv. How are you, man? Great.
Thank you for having Melan. It's a great opportunity to tell about suite security. Yes.
Yeah. Well, thank you. I know, you know, we had some last minute kind of dancing around here and you know, I appreciate you coming on on short notice and, and talking with us.
I much, much appreciated. Re before we get into the news we want to talk about, and even before we talk about Sweet, let's talk a little bit about you. You're a co-founder.
Mm-hmm. You know, I had the pleasure of co-founding four or five venture-backed companies in my career. It's not something you do lightly, right?
You, you put everything into a company because you really believe in it, what you know, but starting a new company is so often built on everything else you've done in your life prior to it. Mm-hmm. So give us an idea of kinda what your journey has been that led to you co-founding Suite.
Mm-hmm. Yeah, so let me tell about, uh, about my journey. So I've spent my career in cybersecurity, uh, beginning with over than 12 years in the Israeli spatial operations division.
I think like most of the Israeli entrepreneurs, uh, where I was deeply involved in offensive operations. Um, and this is my passion, you know, at the end of the day, and, and before founding Suite, I also led a research group at an Israeli company, uh, called, um, and I think that, uh, when we founded Suite Security almost, um, three years ago, um, it was, you know, kind of a moment that I, I understood, okay, this is my patient. That's what what I want to do, you know, bring all the best guys out there that we, we work together, you know, uh, in the Army, uh, to build, you know, the next cloud security solution, uh, the next cloud security platform.
And, uh, we founded Three Security, um, with, uh, my partners, uh, bro Kati, our, uh, CEO and former, uh, CSO of the entire IDF and the l Fisher of CPO, who led one of the largest offensive cyber divisions in Unit eight hundreds. And I think that, um, this is a kind of a glimpse to the magic, I think, behind the scenes you're in suite security, the combination, you know, of the offensive and the defensive, you know, aspect of cloud security. And I truly believe that we bring something, something new for, you know, organization in how, you know, to secure the cloud environment from, you know, the offensive perspective.
So this is a little bit, you know, about the story behind Sweet and my, my, myself and my journey. Excellent. Very cool.
So you mentioned Sweet was, uh, founded about three years ago, and it really combines sort of, you know, using offensive security techniques and technology. But really, if I, if I asked you Orel, what, what is the mission of Suite? What's the mission there?
Mm-hmm. How would you answer that? Well, Mm-hmm.
Okay. So to answer that question, I think that we should tell, I need to tell about, you know, the, the journey, uh, in more detail. So we started Suite as a cloud detection and response company, built around two main key ideas.
Uh, the first one is that, you know, microservices and non-human identities are deterministic creatures. It means that you can build a baseline for, for their behavior. And the second thing is that based on our experience, we can tell that attacks don't happen, you know, within a single attack surface.
The attacker need to open a reversal, get a persistency, the lateral movement and other stuff. And by combining these insights together, we develop behavioral baselines for cloud applications based on the runtime signals. And it allows us to, to, to understand our workloads actually behave.
Now since then, we've expanded our capabilities to become a runtime signal because we realize at, at some moment that runtime visibility is crucial for understanding, you know, the real risk that you have in your environment, you know, from active vulnerabilities and then to live attack that you have to the exploitation, you know, context itself. Um, and today we cover all the core cloud security domains you would expect from synap, whether it's about data, API detection response, of course, network analysis, misconfiguration, and so on. Um, both from the static analysis perspective to the runtime protection.
Excellent. Alright. Um, let's talk a little bit about now three years in, you have a a, a real product with real customers.
We're going to get into from fundraising in a minute, but how, how, how does the, how do your customers, how, how do potential customers kind of interact? How did, what's the on-ramp? What, you know, like, you know, is it, is it a SaaS kind of solution?
Is it, you know? Yeah, So, so, uh, we support both, uh, SaaS and on-prem. Um, it depends on, you know, the, the customer environment.
But in general, our runtime technology is based on both the cloud service provider audit log and the sensor that we have. We have a sensor that is written in RAs, very, very effective, and it helps us to get visibility into the application. So it's a combination of these, uh, tool, let's say hooks that we have in the cloud environment.
Alright. Now, so what is the engagement look like? Does it mm-hmm.
So customer says, you know, I heard about this company suite, this is a kind of solution I'm looking for. What comes next? Can they go to the website and download a trial?
Do they engage with the sales team? Is there a POC? You know, what, what does that on-ramp look like if, yeah.
Okay. So they need to, to, uh, they can, uh, go to the websites with, uh, that security. Um, and then there is an engagement process with, uh, um, the sales team.
Um, and after that, there is a POC, um, a deployment that, uh, we are doing in the customer, uh, in customer's environment. Um, and from there they can see the, the beauty and all the e inside that we can bring, um, based on our technology. Uh, yeah, this is the process.
Yeah. Good, good. All right.
Let us turn. Now, you guys recently announced a, a, a nice healthy raise. Tell us a little bit about it.
Yeah, so, uh, maybe I'll, I'll start, you know, with what help us, you know, to, to, to secure the round. Okay. Because I think that, that, it's interesting.
So I think that the market feedback, uh, has been outstanding. I think that over the past year we've seen a clear trend where an organization now, you know, they, they see the runtime layer as a core, not as an optional, you know, component with your, with, you know, their, their synapse strategy. And, and I think that the reason is simple, the, the ROI is higher than ever when you focus, you know, on active threats, on active risks in your environment.
Um, and I think that once we reach that milestone of, you know, maintaining a low false positive ratio across the board, uh, we, and we decided to add on top of it an AI layer, not just, you know, for prioritization, but also, you know, to help understand the root cause and guide you in solving the problem. So as a result, from a business perspective, we have achieved, you know, sixfold increase in a RR and a tenfold growth in, you know, enterprise customers, including multiple Fortune 1000th organization. And it, it, you know, it made, you know, the, the, the, the be round very, uh, easy for us, to be honest.
Um, and I think that, you know, on the investment side, so all of our existing investors from the A round doubled down, you know, for our B round. Uh, the round by the way, was led by Evolution Equity Partners together with GLO capital a RV Q1 capital, and other, you know, great partners. Um, and I think that now an an interesting, I think question is what is it it'll be used for?
You know what I mean? Mm-hmm. I think that's what people, you know, our audience, but very nice, and I should mention it was a $75 million series be round, which is a, in, especially in today's world, that's a very substantial, you know, vote of confidence.
But you're right, people want to know, okay, now that they have capital behind them, what, what are they gonna do with it? Mm-hmm. Yeah.
So this investment will accelerate our global expansion and, and of course, product innovation, both in runtime seen up, okay. And AI security. So our vision, you know, for runtime C up, and we, we, we just started, you know what I mean?
So the vision is, is to eliminate, to break the wall between the static misconfiguration and the runtime signals. We, we believe that context remains the biggest gap in cloud security and leveraging AI based on, you know, the most contextual signals, and this is the run type signals, is that we are pushing the boundaries on know what's of what's possible. So this is like the first thing that we are going, you know, to focus on the runtime CNO.
The second thing is, uh, the ai AI security. So our goal is to secure the, the entire life life cycle of AI models and agents. As agent AI becomes more prominent in organization workflows and gains access, you know, to business critical data sources, it brings with it a new world of challenges.
And I think that the most basic one is having visibility. So here as well, we are applying our runtime expertise to detect, understand, and control AI agents. And I think that most of the underlying risks like vulnerabilities, misconfiguration, you know, expose NPIs and and so on, are fundamentally, you know, the same.
But in AI systems, the scale and the impact are far greater. I think that with, with iGen ai, the risks can come know not just from an attacker, but also from a developer, for example, who push, I don't know, like an unsafe or misbehaving AI agent into production. And I think that, you know, a recent, uh, uh, example that illustrates, uh, this perfectly, I think was about a developer was, is AI coding assistant to optimize a database query.
Okay? And when the agent, you know, failed to do so, he decided, you know, to, to delete the entire database instead. And that's why we believe, uh, that the future lies, you know, in unified security plethora, uh, on, you know, one that, that leverage, uh, existing risks and, and behavioral insights.
But we believe that you need to extend the protection seamlessly, almost from cloud workloads to all, you know, the agents out there. So this is our mission, and this is what we, uh, uh, plan to do, um, with the money. Absolutely.
Al that's interesting. So it was a, it was a long question for, uh, a long, long answer or for a short question, but, uh, well, That, that's why I like to sit on this side of the camera. I, I get to just ask short things and you gotta do all the explaining, right?
Um, but you know, I wanna talk a little bit about AI security, right? Mm-hmm. Three years ago, we weren't talking about AI security.
Now we talk a lot about ai. We, that's all we talk about is AI and ands security, AI security. Do you envision a time where you, when we talk about suite, you don't talk about, uh, AI security and cmap security, that AI security is sort of built into that cnap security, right?
AI security gets built into everything, because everything uses ai. So of course, you gotta have AI security as part of, whether it's cmap or regular, you know, cloud security or endpoint security dev DevSecOps, or, you know, now everything in DevOps, we, we say AI native dev all of a sudden is the hot word, right? And AI enable platform.
Um, that's, you know, so it's one platform. It's mm-hmm. What we do here, and then AI security is over there somewhere.
Yeah. It's, it's one platform. We believe that you must have a unified platform.
You know, at the end of the day, the agent is another workload. You know what I mean? It's another non-human identity, it's another model that could have misconfiguration.
It's another model that have, you know, uh, that has, uh, um, vulnerabilities. So if we had software build of materials like sbo, so now we have AI bomb, you know what I mean? So yes, there are new challenges out there.
For example, the detection response, in my opinion, is quite bit, uh, is going to be a little bit different, uh, than, you know, the standard detection response and attacks out there, for example, attacks like prompt injection and, and, and such kind of attacks. But in general, we believe that we are going to leverage the same insights that we have. Okay.
But adding on top of it, the visibility for all the agent AI that you have out there, and of course, to do all the adoption that are required in order to secure the agents and the models that you have in your environment. But I think that you, you, I totally agree with, with your take on it. Appreciate very good.
You know, IRA, we we're coming down or almost outta time here, but, um, first of all, if I didn't before, congratulations to you and, and Yal and, and the whole sweet team actually right on, on this raise. You know, I, I've, uh, as I said, I've done four or five venture backed startups. And first of all, the, the first rule always is right.
Don't raise money when you need money. Raise money when they'll give you money. And it sounds like that when You can Yes.
Right. When you get, that's what sounds good there. Secondly, as I said, we're in this, in this climate.
This is a very healthy raise. It's a good sign that people are, are bullish on, on, you know, what you guys are doing. Um, just keep doing what you're doing, right?
We're living in a very interesting time where things are changing so quickly, but the mission stays the same. We still have to protect, we still secure just how we're doing it. And what we're doing it from is, is, you know, changing day to day.
So you need this kind of capital to, you know. Mm-hmm. But I wish you all a bunch of luck again.
It was sweet. That's S-W-E-E-T, like can suite Yes. Security.
Yes. Yes. All right.
Good luck. Thank you, Alan. Appreciate Thank you.
Sweet Security here on Text Drunk tv. We're gonna take a break. We'll be back in a bit.