Kai
Also known as: Kai Cyber
Agentic AI cybersecurity platform that unifies threat intelligence, exposure management, detection, and response into one autonomous machine speed pipeline across IT and OT.
Kai is an agentic AI cybersecurity platform, Kai Cyber Inc. of San Jose, that aims to do the security work itself: validating exposures, gathering context, remediating, and running threat intelligence, threat hunting and detection engineering as one machine speed pipeline rather than another dashboard on a fragmented stack. Founded in 2025 by Galina Antova, a co founder of industrial security company Claroty, and Damiano Bolzoni, who co founded SecurityMatters before its acquisition by Forescout, Kai emerged from stealth in March 2026 with one hundred twenty five million dollars in seed and Series A funding led by Evolution Equity Partners, with N47 and strategic investors participating.
The platform puts a deterministic harness in front of the model: raw security data is ingested, cleansed, deduplicated, validated and chunked before it reaches the reasoning layer, which Kai runs on Anthropic's Claude. Exposures are validated for reachability and exploitability in context before anything is automated, and then agents act: they open pull requests for code vulnerabilities, deploy EDR and SIEM rules and remediate exposures, handing work from agent to agent.
The customer decides which classes of finding close with no human in the loop, which are staged for review and which are never touched automatically; everything outside the autonomous boundary arrives as a remediation plan for the owner to decide. Kai reports outcomes such as millions of findings triaged and remediated and mean time to remediate cut from weeks to minutes; those are its own figures.
Kai names SOC 2 Type 2 and ISO 27001:2022 on its trust center, with SSO and access control as platform features. It does not publish hosting regions, a developer API, an agent audit trail or pricing. For a large enterprise that wants exposures validated and closed at machine speed within limits it sets, Kai is an ambitious option; a team looking for a narrow, proven single function tool may prefer a more established specialist.
Vendor details
Canonical URL
https://www.kai.security
Category
Security / SOC agent
Subcategory
Agentic security operations
Funding status
Independent, headquartered in San Jose, California, founded in 2025 by Galina Antova and Damiano Bolzoni. Antova co founded industrial cybersecurity company Claroty, and Bolzoni co founded SecurityMatters, which Forescout acquired in 2018. Kai emerged from stealth in March 2026 with one hundred twenty five million dollars in combined seed and Series A funding led by Evolution Equity Partners, with N47 and strategic investors participating. Within about ten months of writing its first code, it signed several large enterprise customers and generated more than seven figures in bookings across energy, pharmaceuticals, automotive, and hospitality.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Ingests telemetry and data from enterprise networks, cloud services, endpoints, security tools, and threat intelligence feeds across information technology and operational technology environments, then correlates events with an organization's vulnerabilities, assets, and infrastructure. Agents act in the customer's systems: they open pull requests for code vulnerabilities, deploy EDR and SIEM rules and remediate exposures, routing the rest to assisted remediation.
In practice
Your SOC runs a dozen disconnected tools and attackers slip through the seams while analysts drown in alerts. Kai unifies threat intelligence, exposure, detection, and response into one autonomous pipeline that acts at machine speed.
A new threat intelligence report drops and you have no fast way to know if it affects you. Kai extracts the tactics and techniques, correlates them against your own vulnerabilities and assets, and prioritizes what to fix first.
Remediation drags on for months across many team handoffs. Kai's agents pick the most effective fix, eliminate false positives, and can execute containment like isolating an asset or revoking credentials in about an hour.
Sources & related URLs
Research sources
Agentic Index coverage score
7.0 / 14 capabilities · 50%
| Integrations & Tool Calling | Full |
|---|---|
|
Agents act in the customer's systems: they open pull requests for code vulnerabilities, deploy EDR and SIEM rules and auto remediate exposures, routing the rest to assisted remediation. Sourcekai.securityread 2026-09-28 |
|
| Workflow Orchestration | Full |
|
Six workstreams (exposure validation, context gathering, auto remediation, threat intelligence, threat hunting, detection engineering) hand work from agent to agent with no human hand off, behind a deterministic harness that validates data before the reasoning layer, and remediation branches by finding class into automatic, staged for review or untouched. Sourcekai.security/resources/autonomous-remediation-trust-barrierread 2026-09-28 |
|
| Knowledge Grounding & RAG | Partial |
|
A deterministic harness ingests, cleanses, deduplicates, validates and chunks the customer's security data before it reaches the reasoning layer, and a context gathering workstream checks reachability and what each asset does. No maintained, persistent index or graph over the customer's knowledge is documented. Sourcekai.security/resources/validation-before-automationread 2026-09-28 |
|
| Human Oversight & Guardrails | Full |
|
The customer decides which class of finding is closed with no human in the loop, which is staged for review and which is never touched automatically; findings outside the autonomous boundary get a remediation plan routed to the owner, who decides and executes. Sourcekai.security/resources/autonomous-remediation-trust-barrierread 2026-09-28 |
|
| Security, Identity & Governance | Full |
|
Kai's trust center shows SOC 2 Type 2 and ISO 27001:2022, with A-LIGN 2026 confirmations of examination, and names access control and single sign on as platform features. The access controls are named without further detail. Sourcetrust.kai.securityread 2026-09-28 |
|
| Observability & Auditability | Partial |
|
The homepage reports aggregate outcomes (findings triaged and auto remediated, rules deployed) and the vendor's writing stresses a clean account of what changed and why. No page documents a per run trace or audit log of the agents' actions; monitoring the customer's estate is the product's function, not observability of the agent. Sourcekai.securityread 2026-09-28 |
|
| Memory & State Persistence | Not documented |
|
Correlated asset and vulnerability context is the product's data model, not a memory the agents read across runs; no agent memory store, scope or lifetime is documented. Sourcekai.securityread 2026-09-28 |
|
| Deployment & Data Residency | Not documented |
|
The trust center says only that Kai works with best in class infrastructure providers, naming no provider, region or customer environment option, and the homepage names none. The IT, cloud and OT environments Kai covers describe its scope, not where Kai runs. Sourcetrust.kai.securityread 2026-09-28 |
|
| Prebuilt Agents, Templates & Packs | Partial |
|
Six workstreams of one pipeline (exposure validation, context gathering, auto remediation, threat intelligence, threat hunting, detection engineering) come built in. They are stages the platform chains together, not named agents or templates a customer adopts separately. Sourcekai.securityread 2026-09-28 |
|
| Triggers & Channel Coverage | Full |
|
Confirmed exposures and new findings start remediation with no one asking, machine to machine end to end, within the finding classes the customer has set to run autonomously. Sourcekai.securityread 2026-09-28 |
|
| Model Flexibility & Routing | Not documented |
|
Kai names Anthropic's Claude as its analysis layer, a single provider chosen by the vendor, with no customer model choice. Sourcekai.security/resources/how-kai-brings-customer-risk-to-zero-with-claude-as-the-analysis-layerread 2026-09-28 |
|
| APIs, SDKs & MCP Extensibility | Not documented |
|
The sitemap lists no developer or docs pages, and no API, SDK or MCP server for the Kai platform is documented. Sourcekai.security/sitemap.xmlread 2026-09-28 |
|
| Testing, Debugging & Optimization | Partial |
|
Kai writes that each remediation must be verified after the fact, confirming the exposure is closed rather than only applied. No page documents that check as a product gate, a harness or scored cases, and exploitability validation tests the customer's estate, not the agent. Kai Autonomous Remediation and Validation Before Automation posts, 28 Sep 2026. Sourcekai.security/resources/autonomous-remediation-trust-barrierread 2026-09-28 |
|
| Browser & Computer Use | Not documented |
|
No page documents agents driving a browser, desktop or remote computer; they act through pull requests, rule deployment and remediation integrations. Sourcekai.securityread 2026-09-28 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Kai launched Auto Remediation, a new capability for its agentic AI platform that automates the resolution of confirmed security vulnerabilities. The system evaluates findings to determine if they can be remediated without human intervention and applies fixes autonomously. If human approval is required, the platform builds a complete remediation plan and stages the change for technical teams to execute.
Bears on: Agent capability
View sourcePricing
Not public; enterprise pricing quoted through sales
not published
What is public
No list pricing. Kai quotes through enterprise sales, with no self serve tier disclosed at this early stage.
Billing mechanics
Sold through sales after a demo; the billing unit is not published.
Cost watchouts
Agentic security platforms can carry meaningful token and compute costs when processing large telemetry volumes, which may sit alongside the base subscription.
Variable cost rationale
As an agentic security platform that processes terabytes of telemetry, underlying AI token and compute consumption can move total cost, so heavy data and automation volumes may raise spend even under an enterprise subscription.
Additional watchouts
As a newly launched platform, confirm which security functions are included, how pricing scales with data volume, and whether AI or compute usage is metered separately.
Sales call required
Yes, required for paid access
Free / trial
Demo or evaluation on request; no public free tier
Key ambiguities
No public rate or pricing model is published; Kai emerged from stealth in March 2026 and sells through enterprise sales.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Kai
The closest documented capability profiles to Kai among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- AirMDR6.0 / 14A lighter documented profile than Kai
- Astelia8.0 / 14Adds documented APIs, SDKs & MCP Extensibility
- Intezer7.0 / 14Adds documented Memory & State Persistence and APIs, SDKs & MCP Extensibility
- Noma Security7.0 / 14Fuller documented coverage on Observability & Auditability and Testing, Debugging & Optimization
- Quantro Security7.0 / 14Fuller documented coverage on Knowledge Grounding & RAG and Prebuilt Agents, Templates & Packs
- Radiant Security6.0 / 14Adds documented APIs, SDKs & MCP Extensibility
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded