Skip to content

Dux

Agentic exposure management platform using AI workers to determine which vulnerabilities are truly exploitable and mitigate them faster than a patch cycle.

Visit Website ↗ + Add to Compare
62/100Incremental Innovator

Overview

Dux is building what it calls agentic exposure management: a platform where AI agents continuously analyze exploitability across an enterprise’s assets, determine whether existing controls already block a given attack path, and surface lightweight mitigations that can reduce risk faster than waiting for a full patch. Rather than adding another list of vulnerabilities to a security team’s backlog, the platform is designed to shift organizations from periodic scanning and manual triage toward continuous, automated investigation of what is actually exploitable in a specific environment.

Founded in 2025 by Or Latovitz, Amit Nir, and Nadav Geva — all graduates of the Israel Defense Forces’ Talpiot technology program — Dux operates out of Tel Aviv and New York. The company emerged from stealth in December 2025 with a $9 million seed round led by Redpoint, TLV Partners, and Maple Capital, with participation from security executives at CrowdStrike, Okta, and Armis.

Dux’s core argument is that the average time-to-exploit for newly disclosed vulnerabilities has collapsed dramatically in recent years, making traditional patch-cycle timelines insufficient — a trend the company is positioning its exposure-management approach directly against.

Innovation Matrix Assessment

Innovation Velocity 7/10

Talpiot-program founders moved from founding to a $9M seed round and a working exposure-management platform within roughly six months.

Operational Value 7/10

Directly targets a well-known operational pain point — vulnerability backlogs security teams cannot realistically triage — with a control-aware exploitability lens.

Market Momentum 6/10

Backed by Redpoint, TLV Partners, and Maple Capital with participation from named CrowdStrike, Okta, and Armis executives, a credible early signal without yet being large-scale.

Category Disruption 6/10

Moving from static vulnerability lists to continuous, control-aware exploitability analysis is a meaningful operating-model shift, though it sits adjacent to existing exposure-management and BAS categories.

Real-World Efficacy 4/10

No independent benchmarks or named customer results are public yet; claims about faster remediation than patch cycles are company-stated.

Enduring Relevance 7/10

Faster exploitation timelines are a well-documented industry trend (cited from Mandiant data), making continuous exposure management a durable need over the next several years.

Why CISOs Should Care

It tells a CISO's team which vulnerabilities are actually exploitable right now given existing controls, so scarce remediation effort goes to what matters.

What Makes It Different

It factors in whether existing security controls already block an attack path before recommending remediation, rather than scoring vulnerabilities in isolation.

The Matrix Verdict

62/100 — INCREMENTAL INNOVATOR

Dux is an Incremental Innovator: a strong founding team and credible early backers addressing a genuine gap in exposure management, still awaiting independent proof points.

Editorial Note: Claims vs. Verified Findings

Funding, founders, and investor participation are independently reported (SecurityWeek, VentureBeat, Calcalist). The cited Mandiant time-to-exploit statistic is an independent industry data point; platform-specific efficacy claims are vendor-sourced.

Sources