Onit Security
Israeli exposure management startup founded in 2025 whose AI agents investigate, prioritize, and remediate vulnerabilities based on business context rather than generic CVSS scores.
Visit Website ↗ + Add to CompareOverview
Onit Security builds an agentic exposure management platform that uses AI agents to investigate, triage, prioritize, and remediate vulnerabilities and other security exposures across an organization’s environment. Rather than ranking issues purely by CVSS severity, Onit’s agents map asset ownership across fragmented data sources and weigh exposures against actual business context, then attempt to execute remediation steps directly rather than simply generating another prioritized list for a human to act on.
The company was founded in 2025 by Elad Ben-Meir, Ofer Amitai, and Tom Winter, a team with a track record of prior cybersecurity exits including SCADAfence (acquired by Honeywell), Portnox (sold to private equity), and For-Each (acquired by Autodesk). Onit raised an $11 million seed round led by Hetz Ventures and Brightmind Partners, with participation from additional angel investors, shortly after founding. According to the founders, the idea grew out of a real incident in which attackers exploited a known but deprioritized vulnerability at a company one of the founders previously managed, following what was reported as an Iranian-linked cyberattack.
Onit is entering a crowded vulnerability and exposure management category where CVSS-based prioritization has long been criticized as disconnected from real business risk, and its bet is that autonomous, context-aware remediation agents can meaningfully cut the widely cited industry averages of roughly a month to remediate an issue and enterprise backlogs exceeding 100,000 open exposures. As a company only months old at the time of this profile, its product claims are not yet independently validated by named customer deployments.
Innovation Matrix Assessment
Onit launched with a defined agentic exposure management product concept and closed seed funding within months of founding in 2025, indicating a fast initial build-out, though there is not yet a track record to judge sustained release velocity.
As a company founded in 2025, Onit has essentially no operational track record yet; its credibility rests on the founders' prior exits (SCADAfence, Portnox, For-Each) rather than on Onit's own proven execution.
An $11 million seed round led by Hetz Ventures and Brightmind Partners closed shortly after founding is a strong early signal, reflecting investor confidence in the founding team, though it is a single early data point rather than sustained growth.
Using autonomous agents to both prioritize exposures against business context and execute remediation, rather than stopping at a ranked list, is a meaningfully more ambitious approach than most vulnerability management tools currently offer.
The company is too new to have public, named case studies or independent validation of its remediation claims; efficacy here rests on the founders' prior track record rather than evidence from Onit's own product in production.
Vulnerability backlogs and slow, CVSS-driven prioritization are widely documented industry problems, and the specific incident motivating Onit's founding (a deprioritized vulnerability exploited in an Iranian-linked attack) illustrates the real-world stakes of the problem it targets.
Why CISOs Should Care
CISOs facing vulnerability backlogs in the tens of thousands, where generic CVSS scoring routinely deprioritizes issues that turn out to matter, get a bet on autonomous, business-context-aware triage and remediation from a team with a credible track record in the space.
What Makes It Different
Unlike most vulnerability management tools that stop at prioritized reporting, Onit's agents are designed to also execute remediation steps and automatically map asset ownership across fragmented data sources.
The Matrix Verdict
53/100 — INCREMENTAL INNOVATOR
Onit Security is a very early-stage bet, credible mainly because of its founders' prior successful exits and a strong seed round, on a genuinely important problem in vulnerability remediation; its actual product efficacy is unproven and should be evaluated directly by prospective buyers rather than assumed from funding alone.
Editorial Note: Claims vs. Verified Findings
Onit's remediation capabilities, the founding narrative involving an Iranian-linked attack, and the founders' prior company outcomes are self-reported in company and investor materials (Hetz Ventures portfolio page, Calcalist/Ctech coverage); the $11 million seed round and investor names are independently reported by Ctech. No independent customer validation of the product's actual remediation performance exists yet given the company's age.
Sources
Alternatives to Onit Security
Unknown Cyber Inc.
Malware genomics platform using automated deep static analysis and code-lineage comparison to identify unseen malware, variants, and supply-chain…
Synack Inc
A penetration-testing-as-a-service platform pairing a vetted researcher community with AI-driven attack surface discovery for continuous security validation.
Horizon3.ai
Autonomous penetration testing company whose NodeZero platform self-attacks networks without persistent agents, aiming to replace annual manual pentests…
Airlock Digital
Application allowlisting (deny-by-default) platform that blocks unapproved executables, scripts, and processes to prevent ransomware and malware execution.
Cogent Security
Agentic AI platform that autonomously triages, investigates, and remediates vulnerabilities as a force multiplier for security teams.
Reality Defender
Deepfake and synthetic media detection company offering real-time detection across voice, video, image, and text for enterprises and…