Enclave
Autonomous security agent team that scans code, pen tests live applications, reviews configurations, monitors CVEs, triages and prepares verified fixes, taking jobs in Slack or Teams and running on the customer's choice of frontier or open weight models.
Enclave sells what it calls an autonomous security team for the enterprise: a team of security agents that finishes scoped security jobs end to end across a customer's code, infrastructure and live applications. Its specialist agents cover code scanning, penetration testing, configuration review, network inventory, CVE monitoring, intrusion detection, triage and remediation; triage reproduces findings, and remediation prepares a fix, sends it for review and retests after deployment, for example by replaying an expired webhook request and recording the rejected response.
Teams assign scoped jobs and review evidence in Slack or Microsoft Teams, and the agents work from GitHub pull requests and commits, AWS Security Hub and scanners such as Wiz, Snyk, Semgrep, Dependabot and Socket. Customers choose frontier models or open weight models on US inference providers, through Enclave's inference or their own keys, and Enclave's forward deployed engineers build custom agents for a customer's environment and stay until the team runs them on its own.
Enclave came out of stealth in March 2026 with a six million dollar seed led by 8VC; its founders, CEO Tal Hoffman, CTO Dvir Segev and CPO Yanir Tsarimi, worked together in application security, and Hoffman and Tsarimi served in Israel's Unit 8200. Its trust center renders only in a browser, and the site documents no attestation, deployment option, API or run trace of the agents. It fits engineering and security teams that want an agent team to find, verify and fix exploitable issues across code, cloud and running applications with their own choice of model; a buyer who needs documented attestations or a self hosted option before a pilot will need to ask for them.
Vendor details
Canonical URL
https://enclave.ai
Category
Security / SOC agent
Funding status
Launched from stealth on 26 March 2026 with six million dollars backed by 8VC and angels including Patrick Collison, Aaron Levie, Diane Greene, Matt Huang, Jeremy Stoppelman and Marc Benioff (Enclave's launch post). Founded by Tal Hoffman (CEO), Dvir Segev (CTO) and Yanir Tsarimi (CPO), who built application security tooling together at Enso Security; Hoffman and Tsarimi served in Israel's Unit 8200.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Slack and Microsoft Teams for jobs and evidence; GitHub for pull request review, commit analysis and fixes; AWS Security Hub; scanners and security tools including Wiz, Snyk, Semgrep, Dependabot and Socket. No API, SDK or MCP server is documented.
In practice
A pull request changes Terraform in a way that would let every AWS account restore a production snapshot. Enclave's code review flags it before merge and lays out the evidence in Slack.
Wiz, Snyk and Dependabot raise more findings than the team can check. Enclave's Triage agent reproduces each one, and Remediation prepares a fix as a pull request and retests it after deployment.
A small security team wants scoped work done overnight. It assigns a job in Slack or Teams, and the agents keep working after people sign off for the day.
Sources & related URLs
Related / legacy domains
Agentic Index coverage score
7.0 / 14 capabilities · 50%
| Integrations & Tool Calling | Full |
|---|---|
|
Enclave takes jobs and reports evidence in Slack or Microsoft Teams, works from GitHub (pull request review and commit analysis), AWS Security Hub and scanners such as Wiz, Snyk, Semgrep, Dependabot and Socket, and prepares fixes as pull requests and tickets. In one example it flags a Terraform change in a pull request that would let every AWS account restore a production snapshot. SourceEnclave, enclave.airead 2026-10-06 |
|
| Workflow Orchestration | Full |
|
Enclave describes "an autonomous team of security agents that finishes scoped security jobs end to end". Specialist agents for code, infrastructure and live application testing run in parallel, Triage verifies and reproduces findings, and Remediation prepares fixes and retests them after deployment. The agents keep working when people sign off. SourceEnclave, enclave.airead 2026-10-06 |
|
| Knowledge Grounding & RAG | Partial |
|
The agents work from the customer's code, infrastructure, scanners and security tools, and a Network Inventory agent maps the attack surface. Enclave describes no maintained knowledge store the agents retrieve from. SourceEnclave, enclave.airead 2026-10-06 |
|
| Human Oversight & Guardrails | Partial |
|
Jobs are scoped by the customer in Slack or Teams, evidence is reviewed there, and "a draft fix goes to review" as a pull request, so the team decides what merges through its own code host. Enclave documents no approval step inside the product before an agent acts. SourceEnclave, enclave.airead 2026-10-06 |
|
| Security, Identity & Governance | Partial |
|
The site footer carries an AICPA SOC 2 badge, and Enclave lists a trust center at trust.enclave.ai. No SSO or role model is published on the site. Security material from unrelated companies named Enclave does not describe this product. SourceEnclave, enclave.ai and trust.enclave.airead 2026-10-06 |
|
| Observability & Auditability | Partial |
|
Enclave traces the evidence behind each finding and records verification results. After one fix was deployed, for example, it replayed the expired webhook request and recorded the HTTP 401 response. That evidence shows what the agents concluded, but no run trace of the agents' own steps and tool calls is documented. SourceEnclave, enclave.airead 2026-10-06 |
|
| Memory & State Persistence | Not documented |
|
Enclave describes no memory its agents keep from one job to the next, what it would hold or how long it would last. Each job starts from the scope a person sets in Slack or Teams. SourceEnclave, enclave.airead 2026-10-06 |
|
| Deployment & Data Residency | Not documented |
|
Open weight models run on US inference providers, and customers can use Enclave's own inference or bring their own keys. Beyond where inference runs, Enclave publishes no hosting region or customer environment for the platform itself, and it lists a trust center at trust.enclave.ai. SourceEnclave, enclave.ai; trust.enclave.airead 2026-10-06 |
|
| Prebuilt Agents / Templates / Packs | Full |
|
Eight named specialist agents have stated jobs, covering Code Scanning, Pen Testing, Config Review, Network Inventory, CVE Monitoring, Intrusion Detection, Triage and Remediation. Forward deployed engineers also "build custom agents for your environment". SourceEnclave, enclave.airead 2026-10-06 |
|
| Triggers & Channel Coverage | Full |
|
Pull request review and commit analysis on GitHub, CVE Monitoring and continuous penetration testing wake the agents on repository events and new disclosures, besides jobs assigned in Slack or Teams; the event wiring itself is not documented. SourceEnclave, enclave.airead 2026-10-06 |
|
| Model Flexibility & Routing | Full |
|
"Choose frontier models or open weights running on US inference providers. Use Enclave inference or bring your own keys." The model list names GPT-6 Astra, Luna and Sol and Claude Opus 5.5 and Claude Sonnet 5, OpenAI and Anthropic frontier models, beside open weight options, so customers choose among providers and can bring their own keys. SourceEnclave, enclave.airead 2026-10-06 |
|
| APIs / SDKs / MCP Extensibility | Not documented |
|
No API, SDK, MCP server or developer documentation is published. Custom agents are built by Enclave's forward deployed engineers, who embed with the customer's team and stay until the team runs the agents on its own. SourceEnclave, enclave.airead 2026-10-06 |
|
| Testing, Debugging & Optimization | Not documented |
|
Triage reproduction and retests after deployment check the customer's systems and fixes. Enclave's Hacking Arena posts benchmark frontier models on hacking tasks, reporting for example that GPT-6 Sol went four for four without faking a single flag. Customers get no harness, scored test cases or quality gate for testing Enclave's agents themselves. SourceEnclave, enclave.airead 2026-10-06 |
|
| Browser / Computer-use | Not documented |
|
Live application tests replay requests and record responses; no agent operating a browser or desktop is documented. SourceEnclave, enclave.airead 2026-10-06 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
Contact sales; no public pricing
not disclosed
What is public
No prices. The site states the model options (frontier or open weights, Enclave inference or your own keys) and that forward deployed engineers build custom agents.
Cost watchouts
Inference, not stated by the vendor: cost may scale with the code, cloud and application surface under continuous testing; bringing your own keys moves model costs onto your provider bill.
Variable cost rationale
Inference, not stated by the vendor: likely scales with the attack surface in scope; the BYOK option means model usage can be billed by the customer's own provider rather than by Enclave.
Sales call required
Yes, required for paid access
Free / trial
No public free tier; access via the vendor
Lowest paid plan
Not public
Key ambiguities
No public pricing and no disclosed billing model for this recently unstealthed company.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Enclave
The closest documented capability profiles to Enclave among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Crogl9.0 / 14Adds documented Security, Identity & Governance and Deployment & Data Residency
- Ocean5.0 / 14Adds documented APIs, SDKs & MCP Extensibility
- Quantro Security7.0 / 14Adds documented Security, Identity & Governance
- Airrived8.5 / 14Adds documented Security, Identity & Governance and APIs, SDKs & MCP Extensibility, among others
- Equixly4.5 / 14Adds documented Security, Identity & Governance
- Parameter7.5 / 14Adds documented Security, Identity & Governance and Memory & State Persistence
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded