Dux
Also known as: Dux Security
Agentic exposure management from IDF Talpiot veterans whose AI workers analyze exploitability across the environment, check whether controls already block the path, suggest lightweight mitigations and route targeted remediation to owners.
Dux is an agentic exposure management company founded by three graduates of the IDF's Talpiot program, CEO Or Latovitz, CPO Amit Nir and CTO Nadav Geva, and launched from stealth in December 2025 with a nine million dollar seed led by Redpoint, TLV Partners and Maple Capital. It operates in the United States and Israel, with offices in Tel Aviv and New York. Its premise is that the time between disclosure and exploitation has collapsed, so periodic scans, long remediation cycles and manual prioritization no longer keep pace.
Dux sells AI agents, which it calls AI workers, for three jobs: exploitability analysis that maps how vulnerabilities, assets and controls connect to separate the reachable from the breachable; lightweight mitigations, such as configuration changes and missing controls deployable in the existing security stack, when a full patch is not needed; and remediation acceleration, which auto tags assets, ties data sources together and routes targeted remediation to identified owners only when necessary. When a zero day lands, customers spin up AI workers to investigate it across their environment within minutes.
The public estate is a single page and a launch release: no integration list, approval model, activity log, attestation, deployment option or developer surface is published, and the models behind the workers are not named. It fits enterprise security teams buried in scanner findings who want exploitability and control aware mitigation first; a buyer who needs documented integrations, oversight controls or security attestations before a demo will find none on the public site.
Vendor details
Canonical URL
https://dux.io
Category
Security / SOC agent
Subcategory
Agentic exposure management with continuous exploitability analysis
Funding status
Independent, with offices in Tel Aviv and New York; the site footer names Dux, Inc. Emerged from stealth on December 16, 2025 with a nine million dollar seed round led by Redpoint, TLV Partners and Maple Capital, with participation from cybersecurity executives from CrowdStrike, Okta and Armis. Founded by CEO Or Latovitz, CPO Amit Nir and CTO Nadav Geva, all graduates of the IDF's Talpiot program.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Dux says its agents tie together data sources, auto tag every asset and identify mitigations deployable within the existing security stack, routing remediation to identified owners; no specific integration, connector or target system is named on its public pages.
In practice
A team is buried under scanner findings it cannot triage. Dux's AI workers determine which are actually exploitable in context and which are already blocked by existing controls, cutting the noise dramatically.
A zero day hits the news. The team spins up Dux AI workers to investigate it across the entire environment within minutes, rather than waiting on manual research.
A fix is urgent but a full patch is slow. Dux surfaces a lightweight control or configuration mitigation that eliminates the risk faster and routes remediation to the right owner.
Sources & related URLs
Related / legacy domains
Research sources
Agentic Index coverage score
3.0 / 14 capabilities · 21%
| Integrations & Tool Calling | Partial |
|---|---|
|
Dux's agents tie data sources together, auto tag assets, identify mitigations "deployable within existing security stacks" and route targeted remediation to identified owners, but no integration, connector or system the agents act in is named. Sourcedux.ioread 2026-09-28 |
|
| Workflow Orchestration | Partial |
|
AI workers run a fixed sequence, exploitability analysis, a check on whether controls block the path, a lightweight mitigation, then remediation routed to owners "only when necessary"; no buyer configured flow, branching or coordinating agents is documented. Sourcebusinesswire.com/news/home/20251216193951/en/dux-launches-from-stealth-with-$9m-seed-round-to-bring-agentic-exposure-management-to-modern-cyber-defenseread 2026-09-28 |
|
| Knowledge Grounding & RAG | Partial |
|
Exploitability analysis "maps vulnerability-asset-control connections" and auto tags every asset, grounding in the customer's environment, but no maintained store or retrieval structure the agents query is described. Sourcedux.ioread 2026-09-28 |
|
| Human Oversight & Guardrails | Partial |
|
Remediation is routed to identified owners "only when necessary", which leaves fixes with people, but no approval step before an agent applies a mitigation is documented. Sourcebusinesswire.com/news/home/20251216193951/en/dux-launches-from-stealth-with-$9m-seed-round-to-bring-agentic-exposure-management-to-modern-cyber-defenseread 2026-09-28 |
|
| Security, Identity & Governance | Not documented |
|
The one page site and the launch release name no attestation, SSO, role model or trust page. Security is what Dux sells, but nothing published covers how the product itself is secured. Sourcedux.ioread 2026-09-28 |
|
| Observability & Auditability | Not documented |
|
No log, trace or record of what the AI workers did is documented. Continuous exploitability analysis and asset tagging report on the customer's estate instead. Sourcedux.ioread 2026-09-28 |
|
| Memory & State Persistence | Not documented |
|
The vulnerability, asset and control map grounds the analysis rather than serving as memory, and no agent memory with a stated scope and lifetime is documented. Sourcedux.ioread 2026-09-28 |
|
| Deployment & Data Residency | Not documented |
|
No hosting region, region choice, customer environment or on premises option is named on the site or in the launch release. Sourcedux.ioread 2026-09-28 |
|
| Prebuilt Agents, Templates & Packs | Partial |
|
Customers "spin up AI-workers" for exploitability analysis, lightweight mitigations and remediation acceleration, but no worker is named or packaged as a template. Sourcedux.ioread 2026-09-28 |
|
| Triggers & Channel Coverage | Partial |
|
AI workers "continuously analyze exploitability", and when a zero day drops "customers spin up AI-workers", which is a run a user starts. No event, feed or schedule that wakes the workers on its own is named. Sourcebusinesswire.com/news/home/20251216193951/en/dux-launches-from-stealth-with-$9m-seed-round-to-bring-agentic-exposure-management-to-modern-cyber-defenseread 2026-09-28 |
|
| Model Flexibility & Routing | Not documented |
|
No model behind the AI workers is named and no customer choice of provider is documented. Sourcedux.ioread 2026-09-28 |
|
| APIs, SDKs & MCP Extensibility | Not documented |
|
No API, SDK, MCP server or developer documentation is published; the site is a single page with a contact form. Sourcedux.ioread 2026-09-28 |
|
| Testing, Debugging & Optimization | Not documented |
|
Exploitability analysis tests the customer's estate; no harness, scored test cases or quality gate for the AI workers is documented. Sourcedux.ioread 2026-09-28 |
|
| Browser & Computer Use | Not documented |
|
No agent operating a browser or desktop is documented. Sourcedux.ioread 2026-09-28 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
No public pricing; enterprise contracts are quoted through sales
not published
What is public
Nothing numeric. The product, founding team, funding, and enterprise traction are public, but no rates are published.
Billing mechanics
Enterprise sales led motion through a contact form; no tiers or billing basis disclosed.
Cost watchouts
Inference, not stated by the vendor: cost may scale with the assets, scanners and integrations under continuous analysis.
Variable cost rationale
Inference, not stated by the vendor: exposure management platforms typically scale with environment size and asset count; Dux publishes no mechanics, so treat exposure as unquantified and quoted per deal.
Additional watchouts
Exposure management contracts typically scale with environment size, so large asset inventories should expect pricing to reflect that scope; confirm directly.
Sales call required
Yes, required for paid access
Free / trial
No free tier or trial is documented on retrieved pages
Key ambiguities
Whether pricing scales by assets, environment size, or a platform fee, none of which is published.
Missing data
No published rates, tiers, minimums, or contract terms were retrievable from company pages.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Dux
The closest documented capability profiles to Dux among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Ocean5.0 / 14Adds documented Observability & Auditability and APIs, SDKs & MCP Extensibility
- Equixly4.5 / 14Adds documented Security, Identity & Governance and Observability & Auditability
- Vulnetic5.5 / 14Adds documented Observability & Auditability and Deployment & Data Residency
- AirMDR6.0 / 14Adds documented Security, Identity & Governance and Observability & Auditability
- Pi6.0 / 14Adds documented Security, Identity & Governance and Observability & Auditability, among others
- Radiant Security6.0 / 14Adds documented Security, Identity & Governance and Observability & Auditability, among others
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded