Ocean
Also known as: Ocean Security, Ocean Ray
Agentic email security platform whose network of AI agents, led by an autonomous investigation engine called Ray, inspects every message in real time to catch phishing and social engineering that evade legacy filters.
Ocean is an agentic email security company headquartered in New York City and Tel Aviv, founded in 2024 by Shay Shwartz and Oran Moyal, both former Israeli military intelligence operators who later led offensive social engineering operations. It emerged from stealth in May 2026 with twenty eight million dollars in total funding, an eight million dollar seed led by Picture Capital followed by a Series A led by Lightspeed Venture Partners. Its thesis is that generative AI has made fluent, context rich spear phishing cheap to produce, which breaks detection built on rules and anomalies.
Ray, Ocean's central engine, coordinates a swarm of purpose built agents that investigate every inbound message the way an analyst would, following the evidence across sender identity, content, links and infrastructure.
Ocean groups the work as agentic protection against phishing, BEC, vendor compromise and malware; agentic automation that triages reported phishing, handles quarantine release requests and removes campaigns without human intervention; and on demand agentic investigation for incident responders.
It connects to Microsoft 365 and Google Workspace by API, and an MCP server in early access, announced in September 2026, lets assistants such as Claude, ChatGPT and Cursor query the threats caught, the emails reported and the decisions made.
Ocean publishes no pricing, and its readable pages do not document attestations, access controls, hosting regions, model providers or an approval step before the agents act; its trust center renders only in a browser. For an enterprise losing ground to AI generated impersonation that wants autonomous investigation instead of rule tuning, Ocean is built for that problem; a buyer wanting a broad, multi channel security platform will find it deliberately narrow, deep on email and light everywhere else.
Vendor details
Canonical URL
https://ocean.security
Category
Security / SOC agent
Subcategory
Agentic email security
Funding status
Independent, dual headquartered in New York City and Tel Aviv, founded in 2024 by Shay Shwartz (CEO) and Oran Moyal (CTO), both former Israeli intelligence operators with offensive social engineering backgrounds. Ocean emerged from stealth in May 2026 with twenty eight million dollars total, an eight million dollar seed led by Picture Capital and a Series A led by Lightspeed Venture Partners, with Cerca Partners and angels including Assaf Rappaport of Wiz and Armis founders Yevgeny Dibrov and Nadir Izrael. The company reports seven figure revenue and roughly thirty five employees.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Ocean connects to Microsoft 365 and Google Workspace through their APIs, deploying in minutes and immediately running both live inspection and retrospective analysis of prior mail. Its agents cross reference sender identities against multiple external data sources and can reach out through alternative channels to verify legitimacy. The platform is API first and focused on the email channel rather than a broad connector catalog.
In practice
An attacker sends a flawless impersonation of a trusted colleague with no obvious anomalies. Ocean's Ray engine reads the intent behind the message and quarantines it before the employee ever acts.
A security team wastes hours chasing low value alerts while real threats blend in. Ocean investigates every email autonomously and surfaces only the messages that carry genuine malicious intent.
A finance employee receives a payment change request that looks legitimate. Ocean cross references the sender identity across sources and verifies out of band before the transfer can proceed.
Sources & related URLs
Agentic Index coverage score
5.5 / 14 capabilities · 39%
| Integrations & Tool Calling | Partial |
|---|---|
|
Ocean acts inside Microsoft 365 and Google Workspace by API, quarantining mail, remediating campaigns and releasing quarantined messages, with Slack and SIEM connections named. The connector set is short and fixed within the email class, and no way to add others is documented. SourceOcean, ocean.security/platformread 2026-10-06 |
|
| Workflow Orchestration | Full |
|
Ray, the central engine, coordinates a swarm of purpose built agents, among them infrastructure, file, link, identity, financial, contact, quarantine and abuse mailbox agents, that understand intent, enrich context and follow the evidence on each message, then quarantine it, remediate a campaign or release it. That is a multi agent flow, and the buyer does not configure it. SourceOcean, ocean.security/platformread 2026-10-06 |
|
| Knowledge Grounding & RAG | Partial |
|
Investigations draw on the full context of the customer's environment and sender history, including which domains are writing for the first time. No maintained index or graph over the customer's knowledge is documented. SourceOcean, ocean.security/platform and /resources/blog/ocean-mcp; ocean.securityread 2026-10-06 |
|
| Human Oversight & Guardrails | Partial |
|
Some reported emails are left for manual review, while most triage, release and remediation runs without human intervention; Ocean says employees get an instant response to reported phishing and release requests and the SOC never touches them. No approval step or admin policy that gates an action is documented. SourceOcean, ocean.security/platform and /resources/blog/ocean-mcp; ocean.security/resources/blog/ocean-mcpread 2026-10-06 |
|
| Security, Identity & Governance | Not documented |
|
No attestation, SSO option or role model is named on Ocean's homepage, platform page or blog, and no security report is published openly. The trust center at trust.ocean.security is a separate site. SourceOcean, ocean.security, /platform and /resources/blog/ocean-mcp; trust.ocean.securityread 2026-10-06 |
|
| Observability & Auditability | Full |
|
Every verdict comes with the full reasoning behind it, every signal checked and every step taken, backed by evidence, and the threats Ocean caught, the remediation it performed on each one and the decisions it made on the customer's behalf can be queried through the MCP server. A separate audit log export is not documented. SourceOcean, ocean.security/platform and /resources/blog/ocean-mcpread 2026-10-06 |
|
| Memory & State Persistence | Not documented |
|
The platform page says Ocean builds a living memory of how the organization operates and communicates, adapting from day one and constantly learning, but no memory store, scope or lifetime is documented, so the claim has no stated mechanism behind it. SourceOcean, ocean.security/platformread 2026-10-06 |
|
| Deployment & Data Residency | Not documented |
|
Connections to Microsoft 365 and Google Workspace run by API, but no hosting region or customer environment option is published on the main site, and Ocean keeps a trust center at trust.ocean.security. SourceOcean, ocean.security and /platform; trust.ocean.securityread 2026-10-06 |
|
| Prebuilt Agents, Templates & Packs | Partial |
|
Ray and a swarm of purpose built agents come ready to run, grouped as protection, automation and investigation, and the platform names the agents in the swarm, from the link, file and identity agents to the financial, contact, quarantine and abuse mailbox agents. They work as parts of one investigation under Ray rather than as agents offered separately, and no templates are documented. SourceOcean, ocean.security/platformread 2026-10-06 |
|
| Triggers & Channel Coverage | Full |
|
Every inbound email and every phishing report or quarantine release request starts an investigation with no one at the buyer asking, and each email is investigated before a compromise rather than after. The agents wake on their own for messages arriving from outside, all through the one email channel, and through the MCP server an assistant can also ask Ocean its questions on a schedule. SourceOcean, ocean.security/platform and /resources/blog/ocean-mcpread 2026-10-06 |
|
| Model Flexibility & Routing | Not documented |
|
The agents run on SLMs and LLMs that Ocean says are built specifically for email security, but the models behind Ray are not named and the customer is offered no model choice. SourceOcean, ocean.security/platformread 2026-10-06 |
|
| APIs, SDKs & MCP Extensibility | Partial |
|
Ocean's own MCP server lets Claude, ChatGPT, Cursor and other MCP clients query the threats caught and the remediation performed on each, reported emails, sender history, domains seen for the first time, the platform's decisions and the metrics leadership asks for, and it is listed in the usual MCP directories. It is in early access, and no endpoint, auth scheme or tool list is published. SourceOcean, ocean.security/resources/blog/ocean-mcpread 2026-10-06 |
|
| Testing, Debugging & Optimization | Not documented |
|
No evaluation harness, scored test cases or gate for a change to the agents is documented. The head to head tests customers describe, such as running Ocean against two leading email security platforms, are purchase evaluations against incumbent tools. SourceOcean, ocean.securityread 2026-10-06 |
|
| Browser & Computer Use | Not documented |
|
No page documents an agent driving a browser, desktop or remote computer. Ocean works through the Microsoft 365 and Google Workspace APIs. SourceOcean, ocean.security/platformread 2026-10-06 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Ocean has opened direct customer access to Ray, its central autonomous AI investigation engine. While Ray previously operated strictly in the background to automatically triage and remediate emails, security teams can now query the AI directly to run on-demand investigations, reconstruct attacks, and trace threat actors.
Bears on: Security / enterprise
View sourcePricing
Not public; quoted through sales after a demo
not published
What is public
No list prices, rates or entry point are published.
Billing mechanics
Sold through sales after a demo; the billing unit is not published.
Cost watchouts
Migrating off an existing email security vendor may carry overlap or transition cost during the switch.
Variable cost rationale
No billing unit is published; as an inference, email security is commonly priced per protected mailbox, which would make cost predictable per seat.
Additional watchouts
Positioned as a replacement rather than an add on, so evaluate against the cost of the incumbent it displaces.
Sales call required
Yes, required for paid access
Free / trial
Proof of value deployments; no public free tier
Key ambiguities
No price anchor, billing unit or minimum commitment is disclosed.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Ocean
The closest documented capability profiles to Ocean among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Equixly4.5 / 14Adds documented Security, Identity & Governance
- Token Security6.5 / 14Adds documented Security, Identity & Governance
- Dux3.0 / 14A lighter documented profile than Ocean
- Intezer7.0 / 14Adds documented Security, Identity & Governance and Memory & State Persistence
- Radiant Security6.0 / 14Adds documented Security, Identity & Governance
- Enclave6.5 / 14Adds documented Model Flexibility & Routing
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded