Sweet Security provides a runtime-first cloud and AI security platform built to protect modern production environments. Its approach combines unified cloud visibility, deep runtime context, and AI-driven analysis to help security teams detect, investigate, and remediate threats across applications, workloads, identities, data, and infrastructure.
Sweet Security centers its portfolio on Runtime CNAPP and AI security, extending from posture and vulnerability management to live detection and response. The platform is designed to secure both traditional cloud-native applications and emerging agentic AI systems, giving organizations a single environment for understanding risk, enforcing guardrails, and responding to active attacks.
Offerings, Capabilities, and Integrations
Sweet Security emphasizes runtime context as the common layer across cloud, application, identity, API, and AI security. Its platform correlates telemetry from runtime sensors, cloud activity, and application behavior to baseline normal operations, surface toxic combinations, prioritize exploitable risk, and assemble investigation-ready incident context.
The platform is modular and spans the lifecycle from build to deploy to run. Sweet Security supports multi-cloud, Kubernetes, virtual machine, and hybrid environments, and integrates with surrounding security and engineering workflows across CI/CD, SIEM, ticketing, notification, SSO, privileged access, and automation tools such as GitHub, GitLab, Splunk, Microsoft Sentinel, Chronicle, AWS Security Hub, ServiceNow, Jira, Torq, CyberArk, and Slack.
Products and Services
- Runtime CNAPP: Sweet Security’s flagship runtime-native CNAPP that unifies insights from applications, workloads, identities, and cloud infrastructure to prioritize risk and speed remediation.
- AI Security Platform (AISP): A flagship AI security offering for models, agents, and AI control planes, with capabilities for AI asset discovery, posture management, runtime guardrails, permissions control, red teaming, and AI detection and response.
- Cloud Detection and Response (CDR): Cloud-layer detection and response that identifies, investigates, and helps contain attacks across infrastructure using behavioral baselines and correlated incident context.
- Cloud Application Detection & Response (CADR): A multi-layer detection capability that correlates cloud, workload, and application activity into a single investigation context for faster response to complex attacks.
- Unified Cloud Visibility: Cloud mapping and visibility capability for topology, asset inventory, dependencies, network connections, and runtime risk across hybrid and multi-cloud environments.
- Vulnerability Management: Runtime-powered vulnerability prioritization that focuses teams on active and exploitable risk, with CI/CD context and environment-specific remediation guidance.
- Identity Threat Detection and Response (ITDR): Identity security capability for discovering human and non-human identities and detecting suspicious access, privilege misuse, anomalous behavior, and secrets-related threats.
- Runtime CSPM: Runtime-backed posture management for misconfigurations, drift, compliance monitoring, and risk prioritization using real-time cloud and workload context.
- API Security: API protection that combines Layer 7 visibility, API cataloging, posture analysis, and real-time detection and response for API-driven threats.
- SweetX: An embedded AI agent for cloud security investigation that connects alerts into full attack context, answers analyst questions, and supports faster response actions.
- Dynamic Application Security Testing (DAST): Live application testing to uncover exploitable weaknesses and identify application risk in running environments.
- Data Security: Data security capabilities that help teams see and manage data at rest and data in motion within cloud environments.
Target Customers
Sweet Security targets organizations running cloud-native and AI-driven production environments across AWS, Microsoft Azure, Google Cloud, Kubernetes, virtual machines, and hybrid infrastructure. Its fit is strongest for teams that need real-time visibility and response rather than posture-only tooling.
Primary users include CISOs, CloudSec and DevSecOps teams, SOC and incident response teams, and AppSec teams. Sweet Security is well suited to enterprises that want to reduce alert noise, prioritize runtime-exploitable risk, and investigate incidents across cloud, workload, application, identity, and AI layers in one platform.
Cloud Integrations and Marketplace
- AWS Marketplace: Sweet Security Suite is available for procurement and deployment through AWS Marketplace.
- AWS: Sweet Security supports AWS environments including EC2, EKS, ECS, Fargate, cross-account tracing, and integration with AWS Security Hub.
- Microsoft Azure: Sweet Security supports Azure environments including AKS and Azure virtual machines, and integrates with Microsoft Sentinel and Azure AI services.
- Google Cloud: Sweet Security supports Google Cloud environments including GKE and Google Compute Engine, and integrates with Chronicle and Google Vertex AI.
Key People
- Dror Kashti: Co-Founder & CEO
- Eyal Fisher: Co-Founder & CPO
- Orel Ben Ishay: Co-Founder & VP R&D
- Tomer Filiba: CTO
- Bryan Whorton: SVP of Sales
- Yigael Berger: Head of AI
- Noa Glumcher: VP of Marketing
- Batel Luzia Rabin: Head of Customer Success
- Ricki Harell: Head of People
- Roni Cohen: Chief of Staff
- Sarah Elkaim: Head of Product Marketing
Key Facts
- Headquarters: Tel Aviv, Israel
- Employees: 100-119
- Annual Revenue: Undisclosed
- Parent Company: None
- Subsidiaries: None
- Publicly Listed: Private
Analyst Recognitions
- Gartner: 2023 Emerging Tech: Mitigate Advanced Persistent Threats in SaaS and Cloud – Sample Provider for Runtime and Workload Security.