Dux
Agentic exposure management platform using AI workers to determine which vulnerabilities are truly exploitable and mitigate them faster than a patch cycle.
Visit Website ↗ + Add to CompareOverview
Dux is building what it calls agentic exposure management: a platform where AI agents continuously analyze exploitability across an enterprise’s assets, determine whether existing controls already block a given attack path, and surface lightweight mitigations that can reduce risk faster than waiting for a full patch. Rather than adding another list of vulnerabilities to a security team’s backlog, the platform is designed to shift organizations from periodic scanning and manual triage toward continuous, automated investigation of what is actually exploitable in a specific environment.
Founded in 2025 by Or Latovitz, Amit Nir, and Nadav Geva — all graduates of the Israel Defense Forces’ Talpiot technology program — Dux operates out of Tel Aviv and New York. The company emerged from stealth in December 2025 with a $9 million seed round led by Redpoint, TLV Partners, and Maple Capital, with participation from security executives at CrowdStrike, Okta, and Armis.
Dux’s core argument is that the average time-to-exploit for newly disclosed vulnerabilities has collapsed dramatically in recent years, making traditional patch-cycle timelines insufficient — a trend the company is positioning its exposure-management approach directly against.
Innovation Matrix Assessment
Talpiot-program founders moved from founding to a $9M seed round and a working exposure-management platform within roughly six months.
Directly targets a well-known operational pain point — vulnerability backlogs security teams cannot realistically triage — with a control-aware exploitability lens.
Backed by Redpoint, TLV Partners, and Maple Capital with participation from named CrowdStrike, Okta, and Armis executives, a credible early signal without yet being large-scale.
Moving from static vulnerability lists to continuous, control-aware exploitability analysis is a meaningful operating-model shift, though it sits adjacent to existing exposure-management and BAS categories.
No independent benchmarks or named customer results are public yet; claims about faster remediation than patch cycles are company-stated.
Faster exploitation timelines are a well-documented industry trend (cited from Mandiant data), making continuous exposure management a durable need over the next several years.
Why CISOs Should Care
It tells a CISO's team which vulnerabilities are actually exploitable right now given existing controls, so scarce remediation effort goes to what matters.
What Makes It Different
It factors in whether existing security controls already block an attack path before recommending remediation, rather than scoring vulnerabilities in isolation.
The Matrix Verdict
62/100 — INCREMENTAL INNOVATOR
Dux is an Incremental Innovator: a strong founding team and credible early backers addressing a genuine gap in exposure management, still awaiting independent proof points.
Editorial Note: Claims vs. Verified Findings
Funding, founders, and investor participation are independently reported (SecurityWeek, VentureBeat, Calcalist). The cited Mandiant time-to-exploit statistic is an independent industry data point; platform-specific efficacy claims are vendor-sourced.
Sources
- SecurityWeek — https://www.securityweek.com/dux-emerges-from-stealth-mode-with-9-million-in-funding/
- VentureBeat — https://venturebeat.com/business/dux-launches-from-stealth-with-9m-seed-round-to-bring-agentic-exposure-management-to-modern-cyber-defense
- SiliconANGLE — https://siliconangle.com/2025/12/16/dux-launches-9m-seed-round-tackle-ai-driven-cyber-exposure/
Alternatives to Dux
Unknown Cyber Inc.
CISO ReviewedMalware genomics platform using automated deep static analysis and code-lineage comparison to identify unseen malware, variants, and supply-chain…
Synack Inc
A penetration-testing-as-a-service platform pairing a vetted researcher community with AI-driven attack surface discovery for continuous security validation.
Horizon3.ai
Autonomous penetration testing company whose NodeZero platform self-attacks networks without persistent agents, aiming to replace annual manual pentests…
Cogent Security
Agentic AI platform that autonomously triages, investigates, and remediates vulnerabilities as a force multiplier for security teams.
Airlock Digital
Application allowlisting (deny-by-default) platform that blocks unapproved executables, scripts, and processes to prevent ransomware and malware execution.
ReversingLabs
Software supply chain security and binary analysis vendor that inspects compiled software and packages for malware and unauthorized…