🧔♂️ A friendly human may check it before it goes live. More news here
Israeli cloud startup Blast Security nets $10m funding
Blast Security, a cloud security startup based in Tel Aviv, has raised US$10 million in seed funding co-led by 10D and MizMaa Ventures.
The company was founded by Boris Vaynberg, Ido Bukra, and Roi Panai, who previously worked at Solebit and served in elite Israeli military units.
Blast Security says its platform aims to prevent cloud misconfigurations by testing and enforcing every change before deployment, rather than relying on detection and remediation after the fact.
The founders developed the idea while leading a national-level cloud security project during reserve military duty.
Blast Security claims its approach can reduce cloud risk in production environments.
Solebit, the founders’ previous company, was acquired by Mimecast in 2018 for about US$100 million.
🔗 Source: Calcalist
🧠 Food for thought
Implications, context, and why it matters.
Blast’s prevention claims lack customer validation or ARR signals
- Blast Security says it is “working with global enterprises to secure production environments” 1. Beyond a quote from Via (a transit technology company)’s chief information security officer (CISO), the release shares no customer logos or design partners or Annual Recurring Revenue (ARR) or deployment metrics.
- Blast cites “over 90%” prevention of cloud risk 1 without method or measurement details. Blast says results come from production, yet it never defines how “cloud risk” is counted or the time window.
- Via’s Oren Hogery, the chief information security officer, backs the product 1. Without broader proof or install details, buyers cannot tell if continuous enforcement harms production or needs heavy engineering to run.
Policy-as-code rulepacks (security and compliance rules written as code) create new revenue channels for ISVs and consultancies
- GitHub Marketplace (GitHub’s app store for integrations) carries Infrastructure as Code (IaC) security apps like Qualys CloudView 2, Tenable 3, Orca 4 and Snyk 5. The store and GitHub Actions (GitHub’s workflow automation) offer a channel for compliance rulepacks that map to frameworks like SOC 2, PCI or HIPAA.
- The security automation vendor Jit offers to automate “GitHub marketplace security best practices” 6. The cloud security platform Prisma Cloud pitches a “single tool securing IaC” 7. These moves signal demand for unified orchestration and let Independent Software Vendors (ISVs) bundle preventive guardrails with existing Continuous Integration/Continuous Delivery (CI/CD) integrations.
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




