Back to vendors
D

Dux

Also known as: Dux Security

Visit site
Entry priceNo public pricing; enterprise contracts are quoted through salesFull pricing detail

Agentic exposure management from IDF Talpiot veterans whose AI workers analyze exploitability across the environment, check whether controls already block the path, suggest lightweight mitigations and route targeted remediation to owners.

Dux is an agentic exposure management company founded by three graduates of the IDF's Talpiot program, CEO Or Latovitz, CPO Amit Nir and CTO Nadav Geva, and launched from stealth in December 2025 with a nine million dollar seed led by Redpoint, TLV Partners and Maple Capital. It operates in the United States and Israel, with offices in Tel Aviv and New York. Its premise is that the time between disclosure and exploitation has collapsed, so periodic scans, long remediation cycles and manual prioritization no longer keep pace.

Dux sells AI agents, which it calls AI workers, for three jobs: exploitability analysis that maps how vulnerabilities, assets and controls connect to separate the reachable from the breachable; lightweight mitigations, such as configuration changes and missing controls deployable in the existing security stack, when a full patch is not needed; and remediation acceleration, which auto tags assets, ties data sources together and routes targeted remediation to identified owners only when necessary. When a zero day lands, customers spin up AI workers to investigate it across their environment within minutes.

The public estate is a single page and a launch release: no integration list, approval model, activity log, attestation, deployment option or developer surface is published, and the models behind the workers are not named. It fits enterprise security teams buried in scanner findings who want exploitability and control aware mitigation first; a buyer who needs documented integrations, oversight controls or security attestations before a demo will find none on the public site.

Vendor details

Canonical URL

https://dux.io

Category

Security / SOC agent

Subcategory

Agentic exposure management with continuous exploitability analysis

Funding status

Independent, with offices in Tel Aviv and New York; the site footer names Dux, Inc. Emerged from stealth on December 16, 2025 with a nine million dollar seed round led by Redpoint, TLV Partners and Maple Capital, with participation from cybersecurity executives from CrowdStrike, Okta and Armis. Founded by CEO Or Latovitz, CPO Amit Nir and CTO Nadav Geva, all graduates of the IDF's Talpiot program.

Company status

independent

Use cases & customers

Primary use cases

Continuous exploitability analysis across the environmentDetermining whether existing controls already block an attack pathLightweight, control based mitigation faster than full patchingRapid environment specific investigation when a zero day drops

Target customers

Enterprise security and vulnerability management teamsSOC and exposure management programsCISOs facing fast time to exploitLarge U.S. enterprises with sprawling asset inventories

Deployment options

Cloud

Integrations

Dux says its agents tie together data sources, auto tag every asset and identify mitigations deployable within the existing security stack, routing remediation to identified owners; no specific integration, connector or target system is named on its public pages.

In practice

A team is buried under scanner findings it cannot triage. Dux's AI workers determine which are actually exploitable in context and which are already blocked by existing controls, cutting the noise dramatically.

A zero day hits the news. The team spins up Dux AI workers to investigate it across the entire environment within minutes, rather than waiting on manual research.

A fix is urgent but a full patch is slow. Dux surfaces a lightweight control or configuration mitigation that eliminates the risk faster and routes remediation to the right owner.

Agentic Index coverage score

3.0 / 14 capabilities · 21%

Integrations & Tool Calling Partial

Dux's agents tie data sources together, auto tag assets, identify mitigations "deployable within existing security stacks" and route targeted remediation to identified owners, but no integration, connector or system the agents act in is named.

Sourcedux.ioread 2026-09-28

Workflow Orchestration Partial

AI workers run a fixed sequence, exploitability analysis, a check on whether controls block the path, a lightweight mitigation, then remediation routed to owners "only when necessary"; no buyer configured flow, branching or coordinating agents is documented.

Sourcebusinesswire.com/news/home/20251216193951/en/dux-launches-from-stealth-with-$9m-seed-round-to-bring-agentic-exposure-management-to-modern-cyber-defenseread 2026-09-28

Knowledge Grounding & RAG Partial

Exploitability analysis "maps vulnerability-asset-control connections" and auto tags every asset, grounding in the customer's environment, but no maintained store or retrieval structure the agents query is described.

Sourcedux.ioread 2026-09-28

Human Oversight & Guardrails Partial

Remediation is routed to identified owners "only when necessary", which leaves fixes with people, but no approval step before an agent applies a mitigation is documented.

Sourcebusinesswire.com/news/home/20251216193951/en/dux-launches-from-stealth-with-$9m-seed-round-to-bring-agentic-exposure-management-to-modern-cyber-defenseread 2026-09-28

Security, Identity & Governance Not documented

The one page site and the launch release name no attestation, SSO, role model or trust page. Security is what Dux sells, but nothing published covers how the product itself is secured.

Sourcedux.ioread 2026-09-28

Observability & Auditability Not documented

No log, trace or record of what the AI workers did is documented. Continuous exploitability analysis and asset tagging report on the customer's estate instead.

Sourcedux.ioread 2026-09-28

Memory & State Persistence Not documented

The vulnerability, asset and control map grounds the analysis rather than serving as memory, and no agent memory with a stated scope and lifetime is documented.

Sourcedux.ioread 2026-09-28

Deployment & Data Residency Not documented

No hosting region, region choice, customer environment or on premises option is named on the site or in the launch release.

Sourcedux.ioread 2026-09-28

Prebuilt Agents, Templates & Packs Partial

Customers "spin up AI-workers" for exploitability analysis, lightweight mitigations and remediation acceleration, but no worker is named or packaged as a template.

Sourcedux.ioread 2026-09-28

Triggers & Channel Coverage Partial

AI workers "continuously analyze exploitability", and when a zero day drops "customers spin up AI-workers", which is a run a user starts. No event, feed or schedule that wakes the workers on its own is named.

Sourcebusinesswire.com/news/home/20251216193951/en/dux-launches-from-stealth-with-$9m-seed-round-to-bring-agentic-exposure-management-to-modern-cyber-defenseread 2026-09-28

Model Flexibility & Routing Not documented

No model behind the AI workers is named and no customer choice of provider is documented.

Sourcedux.ioread 2026-09-28

APIs, SDKs & MCP Extensibility Not documented

No API, SDK, MCP server or developer documentation is published; the site is a single page with a contact form.

Sourcedux.ioread 2026-09-28

Testing, Debugging & Optimization Not documented

Exploitability analysis tests the customer's estate; no harness, scored test cases or quality gate for the AI workers is documented.

Sourcedux.ioread 2026-09-28

Browser & Computer Use Not documented

No agent operating a browser or desktop is documented.

Sourcedux.ioread 2026-09-28

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Pricing

No public pricing; enterprise contracts are quoted through sales

not published

What is public

Nothing numeric. The product, founding team, funding, and enterprise traction are public, but no rates are published.

Billing mechanics

Enterprise sales led motion through a contact form; no tiers or billing basis disclosed.

Cost watchouts

Inference, not stated by the vendor: cost may scale with the assets, scanners and integrations under continuous analysis.

Variable cost rationale

Inference, not stated by the vendor: exposure management platforms typically scale with environment size and asset count; Dux publishes no mechanics, so treat exposure as unquantified and quoted per deal.

Additional watchouts

Exposure management contracts typically scale with environment size, so large asset inventories should expect pricing to reflect that scope; confirm directly.

Sales call required

Yes, required for paid access

Free / trial

No free tier or trial is documented on retrieved pages

Key ambiguities

Whether pricing scales by assets, environment size, or a platform fee, none of which is published.

Missing data

No published rates, tiers, minimums, or contract terms were retrievable from company pages.

Agentic Index verified 2026-09-28

Alternatives to Dux

The closest documented capability profiles to Dux among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Ocean5.0 / 14Adds documented Observability & Auditability and APIs, SDKs & MCP Extensibility
  • Equixly4.5 / 14Adds documented Security, Identity & Governance and Observability & Auditability
  • Vulnetic5.5 / 14Adds documented Observability & Auditability and Deployment & Data Residency
  • AirMDR6.0 / 14Adds documented Security, Identity & Governance and Observability & Auditability
  • Pi6.0 / 14Adds documented Security, Identity & Governance and Observability & Auditability, among others
  • Radiant Security6.0 / 14Adds documented Security, Identity & Governance and Observability & Auditability, among others

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Head to head

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.