Vezran builds the command layer for agentic intelligence — and funds the thesis through proof.
A crowded category with one underserved job. We're raising $4M pre-seed to close the wedge in mid-market through Zyberpol, our operating company in security, establish the PROVE differentiator, and put a 12-person team into Phase 3 within 18 months.
The thesis in one sentence: the agentic-SOC category will be won by whoever owns the proof layer — and almost no competitor is building it.
Three inflections collided. $300M+ followed.
The category is on fire because three forces converged. We don't need to convince an investor that the timing is right — capital already voted.
Claude, GPT, and Gemini now do tier-1 triage reliably enough to delegate. The agent layer is no longer a research demo.
95% of 2025 intrusions used automation at some stage. Human-paced defense vs machine-paced offense is a losing math problem.
Dropzone $37M Series B (300+ orgs). Prophet $30M Series A. Exaforce $125M (~$725M val). Torq $1.2B val. 7AI $700M val. TENEX.AI $250M. Arctic Wolf Aurora. The category is the most-funded space in security right now.
The market thesis is settled. What's contested is who wins the lane.
The category is crowded. The lane we run in is not.
Most well-funded entrants compete for tier-1 triage. Zyberpol does too — but the unsolved job is one layer deeper. After the alert is correlated, decided, and acted on, somebody still has to PROVE it happened the way the team says it did.
The audit-and-insurance evidence layer.
What underwriters now demand (per 2024 industry reports):
- Provable controls during the incident window
- Active response (not just policy)
- Human accountability on response decisions
The lane is open.
Two motions, one lane: mid-market wedge (proof for the auditor) → enterprise expansion (proof for the underwriter).
Honest TAM. Real SAM.
We don't inflate the addressable market. Two stacked panels — the broad AI-in-security TAM (where the gravitational pull is) and the narrower agentic-security SAM (where the spend actually flows in our 36-month window).
Comfortable with the math: SAM is large enough to build a meaningful business in; TAM is large enough that adjacent expansion (vulnerability prioritization, threat-intel auto-hunt, self-healing pipelines) is real.
Wedge + expansion. Self-serve + co-managed.
One platform. Two GTM motions. The first funds the second. The second compounds the first.
We're not running enterprise SOCs today. Enterprise is the expansion that the wedge funds.
Four moats. The compound one matters most.
Not “AI is hard to copy” — that's not a moat. Four specific defensibilities, the compound one being what we're actually building.
4-agent split + frontier reasoning orchestration. Multi-provider model routing (Claude / GPT / Gemini). Not a single-vendor monoculture. Hard to copy because it's a system-design choice, not a feature.
Each deployment trains on per-customer signal: their alerts, their tools, their false-positive history. Creates real switching cost. After 6 months, ripping us out means re-tuning every adjacent tool.
The audit/insurance evidence layer is the underserved lane. First mover gets the format right. Underwriters adopt one schema; that schema wins.
Each new vertical we add (vuln prioritization, threat-intel auto-hunt, self-healing pipelines) makes the platform more valuable. Mifal orchestration scales horizontally; new domain = same harness + new agents. Platform leverage compounds with every customer and every vertical.
Architecture, data, lane, and compound — in that order of cost-to-replicate.
Pre-revenue. No inflation.
Honest reads only. The website carries the same “no fake social proof” rule.
The honest read: we have what an investor at this stage should expect — working product, working team, working thesis, no signed pilots yet. We'll show you the receipts the moment they exist. That's the whole point of the PROVE layer.
$4M. 18 months. PROVE the wedge works.
Use of funds. Lead structure. What the round buys. What it doesn't.