Astelia
AI native exposure management platform from Israeli National Red Team veterans that maps an enterprise's real network, isolates the reachable vulnerabilities, and runs Astelia Agents workflows that draft tickets, propose firewall rules and drive patches across 100+ MCP integrations behind a human approval queue.
Astelia is an AI native exposure management platform founded by leaders of Israel's National Red Team, the unit that stress tests the country's critical infrastructure defenses. It launched in February 2026 with thirty five million dollars in combined seed and Series A funding led by Index Ventures and Team8. The founders' view, drawn from years on offense and defense, is that most vulnerabilities defenders track are irrelevant to how attacks actually work, and that teams need to see their environment the way an attacker does.
Astelia maps each customer's network topology, segmentation, existing controls and internet facing systems down to the port level through read only integrations, analyzes the technical prerequisites for exploiting each vulnerability, and correlates exploitability with real reachability and attack paths to surface what it calls the reachable 1%, then recommends remediation beyond patching, including compensating controls and network configuration changes.
In July 2026 it launched Astelia Agents, which carry that analysis through the vulnerability lifecycle: a planner agent turns a workflow written in natural language into steps, teams build agents from scratch or adapt marketplace templates, and a routine can run on every new advisory, assessing reachability, drafting a ticket for the asset owner, proposing firewall and IPS rules, and driving patches through the customer's patch management tool across more than 100 MCP integrations. Drafted tickets and proposed rules wait in an approval queue for a human click, every step lands in an execution log and every decision in an audit log, and Astelia MCP exposes the platform's data to customers' own AI assistants.
Astelia's trust center lists SOC 2 Type 2 and ISO 27001:2022, with SSO, role based access control and audit logging, on AWS. It does not document a hosting region or customer environment option, name the model behind its agents, or publish the Astelia MCP endpoint and tools. It fits enterprise security teams buried in vulnerability backlogs that want provable reachability and approval gated remediation workflows across their existing tools; buyers wanting published pricing or self hosted deployment will find neither.
Vendor details
Canonical URL
https://www.astelia.io
Category
Security / SOC agent
Subcategory
AI native exposure management with agentic exploitability analysis
Funding status
Independent, headquartered in New York and founded by leaders of Israel's National Red Team roughly a year before its February 2026 launch. Raised thirty five million dollars in combined seed and Series A funding announced February 24, 2026, led by Index Ventures and Team8 with participation from Holly Ventures. Co founders are CEO Alon Noy, former leader of Israel's National Red Team who worked with US Cyber Command, CTO Nadav Ostrovsky, and CPO Roy Rajwan, all from the Israeli intelligence community and National Red Team. Already works with dozens of customers including Fortune 500 organizations such as Syniverse.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Astelia maps network topology through read only integrations with infrastructure and network tools, capturing segmentation, controls, third party connections, VPN accessible infrastructure and internet facing systems to the port level. Astelia Agents act across more than 100 MCP integrations, opening tickets, proposing firewall and IPS rules and driving patches through patch management tools after approval, and Astelia MCP exposes Astelia's data to customers' own AI assistants.
In practice
A security team faces millions of flagged vulnerabilities. Astelia analyzes exploitability and reachability against the real environment and surfaces the small set that an attacker could actually reach, so the team fixes what matters.
A critical advisory drops for an edge appliance. An Astelia Agents routine triggered by the advisory checks for reachable instances, drafts a ticket for the asset owner and proposes an interim firewall rule, both waiting in the approval queue for a human click.
An IT team is tired of patching everything. Astelia recommends compensating controls and network configuration changes that reduce exposure without forcing unnecessary production patches.
Sources & related URLs
Related / legacy domains
Research sources
Agentic Index coverage score
8.0 / 14 capabilities · 57%
| Integrations & Tool Calling | Full |
|---|---|
|
More than 100 MCP integrations connect Astelia to the enterprise tech stack. Agent workflows open a ticket for the asset owner, propose firewall and IPS rules at the right choke point, and drive patches through the customer's patch management tool, so Astelia acts in those outside systems. Read only integrations with infrastructure and network tools feed its network map. SourceAstelia, astelia.io/post/closing-the-exposure-loop and astelia.ioread 2026-10-05 |
|
| Workflow Orchestration | Full |
|
Teams write a workflow spec in natural language, and the planner agent turns it into a step by step workflow. Teams can create agents from scratch or adjust marketplace templates to their own processes, so the customer configures the flow. Workflows run in several steps, carrying a vulnerability from triage through remediation to validation. SourceAstelia, astelia.io/post/closing-the-exposure-loopread 2026-10-05 |
|
| Knowledge Grounding & RAG | Full |
|
Astelia maps each customer's network topology, segmentation, existing controls and internet facing systems down to the port level, and correlates exploitability with reachability over that model. Its agents and Astelia MCP, which exposes every Astelia data point, draw on this maintained map of the customer's own estate. The map also covers third party connections and infrastructure reachable over VPN, and attack paths are analyzed as graphs. SourceAstelia, astelia.io and the Closing the exposure loop postread 2026-10-05 |
|
| Human Oversight & Guardrails | Full |
|
The drafted ticket and the proposed firewall rule wait in an approval queue until a person clicks to approve, so a human approves before the agent acts. Workflows run with fine grained tool scopes and human in the loop checkpoints, and people approve the key decisions. SourceAstelia, astelia.io/post/closing-the-exposure-loop and astelia.ioread 2026-10-05 |
|
| Security, Identity & Governance | Full |
|
Certifications include SOC 2 Type 2 and ISO/IEC 27001:2022, alongside SSO, role based access control, MFA and audit logging, all listed in Astelia's SafeBase trust center. GDPR and HIPAA, encryption at rest and application penetration testing are listed too, with the reports available on request. SourceAstelia, trust.astelia.ioread 2026-10-05 |
|
| Observability & Auditability | Full |
|
Every step lands in the execution log and every decision in the audit log, on infrastructure built for full human control and auditing during execution and after it, so the agents leave their own record of each run. Every action is logged and auditable. SourceAstelia, astelia.io/post/closing-the-exposure-loop and astelia.ioread 2026-10-05 |
|
| Memory & State Persistence | Not documented |
|
The agents have no memory that Astelia describes, nor any statement of what it would hold or how long it would last; the persistent model of the environment and its attack paths is the knowledge layer, not agent memory. Routines run again on every new advisory, but Astelia does not say what carries from one run to the next. SourceAstelia, astelia.io/post/closing-the-exposure-loopread 2026-10-05 |
|
| Deployment & Data Residency | Not documented |
|
Hosting is SaaS on AWS with no region named, and neither the site nor the trust center describes a region choice, customer VPC or on premises option. Customers can buy Astelia through AWS Marketplace, and its integrations read the network without write access. SourceAstelia, trust.astelia.io and astelia.ioread 2026-10-05 |
|
| Prebuilt Agents, Templates & Packs | Partial |
|
A marketplace offers ready made agents and skills built on the same infrastructure, plus templates to adjust. Astelia names no template or its job beyond the new advisory workflow example, and it does not publish the marketplace list. That example finds every affected asset, checks whether each is reachable, opens a ticket for the asset owner and proposes a firewall rule. SourceAstelia, astelia.io/post/closing-the-exposure-loopread 2026-10-05 |
|
| Triggers & Channel Coverage | Full |
|
A workflow can run as a routine triggered by every new advisory, so a newly published vulnerability starts work without a person, and the agents run continuously through the vulnerability lifecycle, from triage through remediation to validation. SourceAstelia, astelia.io/post/closing-the-exposure-loop and astelia.ioread 2026-10-05 |
|
| Model Flexibility & Routing | Not documented |
|
The model behind Astelia's agents is not named, and no choice of provider is offered; Astelia MCP serves customers' own assistants rather than offering a model choice. Agentic AI extracts the technical requirements of each vulnerability for the reachability analysis. SourceAstelia, astelia.io and the Closing the exposure loop postread 2026-10-05 |
|
| APIs, SDKs & MCP Extensibility | Partial |
|
Astelia MCP exposes every Astelia data point to organizations that already run their own AI assistants, as the vendor's own MCP server. No endpoint, auth scheme or tool list is published for it yet, since Astelia says it deserves a post of its own, and no REST API or SDK is described. Astelia's agents reach other tools through more than 100 MCP integrations. SourceAstelia, astelia.io/post/closing-the-exposure-loopread 2026-10-05 |
|
| Testing, Debugging & Optimization | Not documented |
|
Exploitability and reachability validation tests the customer's estate, and agent workflows end by validating that the fix worked. Astelia describes no harness, scored test cases, dry run or quality gate for the agents or for the workflows the planner builds. SourceAstelia, astelia.io/post/closing-the-exposure-loop and astelia.ioread 2026-10-05 |
|
| Browser & Computer Use | Not documented |
|
Work runs through read only infrastructure integrations and MCP connections, and Astelia describes no agent operating a browser or desktop. Its network map comes from integrations with infrastructure and network tools. SourceAstelia, astelia.ioread 2026-10-05 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Astelia has introduced agentic capabilities to its reachability analysis platform to automate vulnerability management across the entire lifecycle. The new workflow evaluates newly disclosed vulnerabilities, assesses operational impact, and coordinates evidence-based remediation across IT and security teams. The platform integrates with over 100 MCP-enabled systems and requires human approval at key decision points.
Bears on: Agent capability
View sourcePricing
No public pricing; enterprise contracts are quoted through sales
enterprise contract; basis not disclosed
What is public
Nothing numeric. The product, customer base, and funding are public, but no rates are published.
Billing mechanics
Enterprise sales led motion to security teams, already serving dozens of customers including Fortune 500 organizations.
Cost watchouts
Inference, not stated by the vendor: cost may scale with the number of assets, network size and integrations under analysis.
Variable cost rationale
Inference, not stated by the vendor: exposure management platforms typically scale with environment size, asset count and integrations; Astelia publishes no mechanics, so treat exposure as unquantified and quoted per deal.
Additional watchouts
Inference, not stated by the vendor: exposure management contracts often scale with the size of the environment, so large or complex networks should ask how assets and integrations are counted toward price.
Sales call required
Yes, required for paid access
Free / trial
No free tier or trial is documented on retrieved pages
Key ambiguities
Whether pricing scales by assets, hosts, environment size, or a platform fee.
Missing data
No rates, tiers, minimums or contract terms are published.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Astelia
The closest documented capability profiles to Astelia among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Anvilogic8.5 / 14Adds documented Deployment & Data Residency
- Linx Security6.5 / 14A lighter documented profile than Astelia
- Token Security6.5 / 14A lighter documented profile than Astelia
- AirMDR6.0 / 14A lighter documented profile than Astelia
- Capsule Security9.0 / 14Adds documented Testing, Debugging & Optimization
- Exaforce8.0 / 14Adds documented Memory & State Persistence
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded