Gomboc.AI
New York-based cloud security startup applying deterministic AI, not generative-AI guesswork, to auto-remediate cloud misconfigurations at scale, aiming to clear the backlog of unresolved cloud security findings that piles up behind most CSPM tools.
Visit Website ↗ + Add to CompareOverview
Gomboc.AI is a cloud security remediation startup founded in 2022 by CEO Ian Amit, a former security leader at Rapid7 and Cimpress, and CTO Jonathan Desrocher. The company is headquartered in New York and builds what it calls a deterministic AI system for fixing cloud infrastructure misconfigurations, deliberately positioned against the generative-AI approach of asking a language model to guess a remediation. Gomboc’s engine instead generates infrastructure-as-code fixes (Terraform and similar) that are validated to be correct and non-breaking before they reach an engineer for review.
The company targets a specific, well-documented pain point: cloud security posture management (CSPM) and cloud-native application protection (CNAPP) tools generate large volumes of findings, but most organizations lack the engineering capacity to actually remediate them, producing a growing backlog of known, unresolved risk. Gomboc’s pitch to security and platform engineering teams is that automated, deterministic remediation can close that gap faster than manual ticket triage.
Gomboc has raised a total of roughly $13 million in seed funding, including an initial $5 million round from Glilot Capital Partners and Hetz Ventures and a subsequent $8 million extension led by Ballistic Ventures, and was selected for Google’s 2024 growth academy for cybersecurity startups. For CISOs and platform engineering leaders drowning in unactioned CSPM findings, Gomboc’s deterministic, verifiable remediation approach is a genuine attempt to close the fix gap; as an early-stage, single-product startup, its main risk is unproven staying power against larger CNAPP vendors that are adding their own remediation automation.
Innovation Matrix Assessment
Two seed rounds and a named enterprise-relevant use case within about two years of founding, plus a Google cybersecurity growth-academy selection, indicate a reasonably fast build-and-iterate pace for an early-stage company.
Small team (~20 people per public estimates), single-product focus, early-stage go-to-market; too early to demonstrate durable operational scale.
Raised an $8M seed extension in February 2025 on top of an earlier $5M round, and was selected for Google's growth academy, both independently reported signals of investor and ecosystem traction.
Explicitly rejects the generative-AI-guesses-a-fix approach in favor of deterministic, validated remediation output, a meaningfully different technical bet than most 'AI for cloud security' competitors in 2025-2026.
Public claims about remediation speed and correctness come primarily from company and investor press material; no independent third-party benchmark of the remediation engine's accuracy was found.
Addresses a widely acknowledged, growing problem (unremediated CSPM/CNAPP findings piling up faster than teams can fix them), which is highly relevant to cloud-heavy enterprises regardless of Gomboc's own scale.
Why CISOs Should Care
CISOs and platform engineering leaders sitting on a large backlog of unactioned cloud misconfiguration findings get an automated, deterministic remediation layer that generates reviewable infrastructure-as-code fixes rather than another dashboard of unresolved alerts.
What Makes It Different
Positions its remediation engine as deterministic rather than generative-AI-based, aiming for verifiably correct, non-breaking infrastructure-as-code fixes instead of LLM-suggested changes that still require heavy manual verification.
The Matrix Verdict
58/100 — INCREMENTAL INNOVATOR
A well-funded, technically differentiated early-stage bet on closing the cloud remediation gap; genuinely relevant problem and a credible founding team, but still unproven at scale against larger CNAPP platforms building similar remediation features.
Editorial Note: Claims vs. Verified Findings
Total funding ($13M across two seed rounds) and the February 2025 $8M raise are corroborated across multiple independent outlets (SiliconANGLE, PR Newswire, Calcalist/Ctech). Headquarters location (New York) is based on Crunchbase's listed address; some secondary aggregator listings inconsistently show Tel Aviv, likely reflecting the founders' prior Israeli VC relationships rather than the registered HQ.
Sources
Alternatives to Gomboc.AI
Wiz
Agentless, graph-based cloud security platform that maps multi-cloud risk end-to-end, now owned by Google after a record $32B…
Chainguard
Provides hardened, minimal, continuously-rebuilt container images and software packages to eliminate vulnerabilities before they reach production.
Microsoft Defender for Cloud
Microsoft's built-in cloud-native application protection platform, unifying CSPM, workload protection, and DevOps security natively across Azure, AWS, and…
Sysdig
The company behind Falco, the CNCF's runtime security standard, offering an eBPF/kernel-level CNAPP built on live syscall-based threat…
Obsidian Security
Obsidian Security provides a SaaS security posture management (SSPM) platform that detects identity-centric threats and misconfigurations across enterprise…
Upwind Security
Fast-growing, venture-backed CNAPP startup combining agentless scanning with eBPF runtime sensors for real-time cloud and AI workload risk…