Skip to content

Zafran Security

A fast-growing threat exposure management and vulnerability prioritization platform founded by former Israeli intelligence veterans, having raised roughly $130-140M including a $60M Series C led by Menlo Ventures, with Cisco reportedly investing in mid-2026.

Visit Website ↗ + Add to Compare
67/100Incremental Innovator

Overview

Zafran Security, founded in October 2022, builds an AI-native threat exposure management platform focused on vulnerability prioritization and remediation — correlating vulnerability data with actual compensating security controls already in place (firewalls, EDR, WAFs) to determine true exploitability and risk, rather than treating every unpatched CVE as equally urgent.

The company has raised roughly $130-140M across multiple rounds, including a $60M Series C in December 2025 led by Menlo Ventures that reportedly tripled the company’s ARR, and reporting in mid-2026 indicates Cisco invested in the company following a co-founder’s departure — notable given Cisco’s own exposure-management ambitions following its earlier acquisition of Kenna Security.

Innovation Matrix Assessment

Innovation Velocity 8/10

Rapid, multi-round funding progression and a reported tripling of ARR within a compressed timeframe indicate exceptionally fast product-market iteration.

Operational Value 7/10

Correlating vulnerabilities against actual deployed compensating controls provides genuinely more actionable prioritization than severity-score-only approaches.

Market Momentum 8/10

$130M+ raised, tripled ARR, and strategic investment interest from Cisco are strong, multiply-corroborated signals of significant market pull.

Category Disruption 6/10

Reframing vulnerability prioritization around actual control-based exploitability is a meaningful shift from traditional severity-only vulnerability scoring.

Real-World Efficacy 4/10

Founded in 2022 with strong growth metrics reported by the company, but independent third-party efficacy validation was not found.

Enduring Relevance 7/10

Control-aware vulnerability prioritization directly addresses the widely-acknowledged industry problem of remediation teams being overwhelmed by undifferentiated CVE volume.

Why CISOs Should Care

CISOs drowning in vulnerability findings get exploitability context based on their actual deployed compensating controls, helping teams focus limited patching capacity on vulnerabilities genuinely at risk rather than every theoretically-critical CVE.

What Makes It Different

Zafran correlates vulnerability data against an organization's actual existing security-control stack to assess real exploitability and prioritize remediation, rather than scoring vulnerabilities on severity alone.

The Matrix Verdict

67/100 — INCREMENTAL INNOVATOR

One of the best-capitalized and fastest-growing entrants in vulnerability prioritization and threat exposure management, with strategic investor interest (including Cisco) reinforcing strong momentum; still relatively young, moderating efficacy confidence.

Editorial Note: Claims vs. Verified Findings

Funding rounds, ARR growth claims (tripled ARR), and the Cisco investment are corroborated by CNBC, SecurityWeek, and Calcalist reporting; specific exploitability-scoring accuracy claims are vendor-stated and were not independently benchmarked.

Sources