Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Israeli cloud startup Blast Security nets $10m funding

Blast Security, a cloud security startup based in Tel Aviv, has raised US$10 million in seed funding co-led by 10D and MizMaa Ventures.

The company was founded by Boris Vaynberg, Ido Bukra, and Roi Panai, who previously worked at Solebit and served in elite Israeli military units.

Blast Security says its platform aims to prevent cloud misconfigurations by testing and enforcing every change before deployment, rather than relying on detection and remediation after the fact.

The founders developed the idea while leading a national-level cloud security project during reserve military duty.

Blast Security claims its approach can reduce cloud risk in production environments.

Solebit, the founders’ previous company, was acquired by Mimecast in 2018 for about US$100 million.

🔗 Source: Calcalist

🧠 Food for thought

Implications, context, and why it matters.

Blast’s prevention claims lack customer validation or ARR signals

  • Blast Security says it is “working with global enterprises to secure production environments” 1. Beyond a quote from Via (a transit technology company)’s chief information security officer (CISO), the release shares no customer logos or design partners or Annual Recurring Revenue (ARR) or deployment metrics.
  • Blast cites “over 90%” prevention of cloud risk 1 without method or measurement details. Blast says results come from production, yet it never defines how “cloud risk” is counted or the time window.
  • Via’s Oren Hogery, the chief information security officer, backs the product 1. Without broader proof or install details, buyers cannot tell if continuous enforcement harms production or needs heavy engineering to run.

Policy-as-code rulepacks (security and compliance rules written as code) create new revenue channels for ISVs and consultancies

  • GitHub Marketplace (GitHub’s app store for integrations) carries Infrastructure as Code (IaC) security apps like Qualys CloudView 2, Tenable 3, Orca 4 and Snyk 5. The store and GitHub Actions (GitHub’s workflow automation) offer a channel for compliance rulepacks that map to frameworks like SOC 2, PCI or HIPAA.
  • The security automation vendor Jit offers to automate “GitHub marketplace security best practices” 6. The cloud security platform Prisma Cloud pitches a “single tool securing IaC” 7. These moves signal demand for unified orchestration and let Independent Software Vendors (ISVs) bundle preventive guardrails with existing Continuous Integration/Continuous Delivery (CI/CD) integrations.

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.