Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

Cyata Emerged From Stealth With $8.5 Million—Then Was Acquired by Check Point

By TheFinanceBase Team8 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Cyata announced its emergence from stealth on July 30, 2025, with an $8.5 million seed round led by TLV Partners. The Tel Aviv startup was building an identity and security-control layer for autonomous enterprise AI agents—software that can use tools, access systems, and take actions on a company’s behalf.

Current status: Cyata is no longer an independent startup. Check Point announced its agreement to acquire the company on February 12, 2026, and reported that the acquisition was completed during the first quarter of 2026.

What Cyata announced

Cyata combined three announcements on July 30, 2025:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. It emerged from stealth.
  2. It introduced a platform for governing what it called “agentic identities.”
  3. It disclosed an $8.5 million seed funding round led by TLV Partners.

The company said the round also included angel investment from former Cellebrite CEOs Ron Serber and Yossi Carmil. The launch announcement did not provide a complete list of institutional investors, so other database-listed participants should not be treated as confirmed investors without separate attribution. Cyata’s launch announcement

What problem was Cyata trying to solve?

Cyata’s premise was that AI agents create a different identity-governance problem from both human employees and conventional service accounts.

  • Human identities are usually connected to HR records, managers, onboarding, training, and employment status.
  • Service accounts are typically long-lived machine identities with relatively predictable uses.
  • AI agents can be created dynamically, execute multi-step tasks, use tools, access sensitive data, trigger transactions, and potentially create or coordinate additional workflows.

An identity system may successfully authenticate the account behind an agent without answering more important operational questions: Which agent is acting? Who owns it? What tools can it invoke? What data can it reach? Is its behavior within policy? When should a human approve the action?

That is the gap Cyata was targeting. Its focus was identity governance for AI agents, not comprehensive protection for every part of an AI system.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Agent identity is not the same as model security

Cyata’s stated product focus should not be confused with security for foundation models or AI applications generally. Agent-identity governance deals primarily with the agent as an actor: its permissions, ownership, activity, and access to enterprise systems.

Other AI-security concerns include prompt injection, model poisoning, adversarial machine learning, data leakage, vulnerable plugins and tools, compromised software supply chains, unsafe retrieval pipelines, and harmful model outputs. A platform can help control an agent’s access while leaving some of those other risks to separate application-security, data-security, cloud, endpoint, or identity controls.

How Cyata described its platform

1. Agent discovery

Cyata said its platform continuously scans desktop and SaaS environments to find AI identities and agents that might otherwise become “shadow” infrastructure. The proposed inventory would connect agents to:

  • their permissions and effective privileges;
  • a human or organizational owner;
  • the systems and data they can reach; and
  • the risks associated with those identities.

For enterprise buyers, the difficult question is coverage. A useful discovery system would need to find not only officially approved agents, but also custom scripts, browser automations, embedded copilots, agents in IDEs and cloud environments, and agents using ordinary service accounts or personal credentials.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Forensic observability

The company said it would create audit trails showing what agents accessed and which actions they took. Relevant activity could include tool calls, API activity, data access, configuration changes, code deployments, financial operations, and interactions between agents.

Cyata also said its system could capture an agent’s intent by requiring it to justify its reasoning in real time. That should be understood as a product capability claimed at launch—not as proof that a security system can reliably inspect an AI model’s private chain-of-thought or establish that a natural-language explanation is truthful. Observable actions and tool calls remain more defensible evidence than an agent’s stated rationale alone.

3. Access control and governance

Cyata positioned the platform as a way to apply identity-style controls to AI copilots, chatbots, and task-driven agents. The controls described at launch included:

  • granular permissions;
  • least-privilege access;
  • just-in-time authorization;
  • human approval for sensitive operations; and
  • risk assessment and governance.

The goal was to let an agent perform routine work while requiring approval before high-impact actions, such as moving money, changing production configurations, accessing restricted records, or deploying code.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who founded Cyata?

The disclosed founding team consisted of:

  • Shahar Tal, co-founder and chief executive officer;
  • Dror Roth, vice president of research and development; and
  • Baruch Weizman, chief technology officer.

Cyata said the founders had backgrounds involving Unit 8200, Cellebrite, and Check Point. Its announcement described Tal as a cybersecurity veteran who led malware and vulnerability research at Check Point and later led research labs at Cellebrite. CTech provided additional Israeli startup and founder context.

At launch, Cyata said it had assembled a team of 12 cybersecurity professionals in Tel Aviv, with 60% of management coming from Cellebrite. Those figures describe the company at launch and should not be read as its current headcount.

Why the $8.5 million seed round mattered

The significance of the funding was not simply its dollar amount. It signaled investor interest in a security category built around autonomous software actors as enterprises moved from experimenting with text-generation tools toward deploying systems that could act across business applications.

TLV Partners led the round. The disclosed angel investors were Ron Serber and Yossi Carmil, both former Cellebrite CEOs. The financing gave Cyata capital to develop its product, build its team, and pursue enterprise adoption of the “agentic identity” concept.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cyata described itself as the first control plane for agentic identities. That is a company positioning claim, not an independently established fact about the entire market. Similarly, statements that AI agents represent a transformation comparable to earlier technology shifts should be attributed to company executives or investors rather than presented as objective findings.

What the launch did—and did not—prove

The announcement established that Cyata had raised a publicly disclosed $8.5 million seed round and had launched a product focused on AI-agent discovery, monitoring, and control. It did not, by itself, establish:

  • how many customers were using the product;
  • how comprehensively it could discover custom or short-lived agents;
  • its false-positive or false-negative rates;
  • how much telemetry or privileged access a deployment required;
  • how it handled dynamically spawned sub-agents;
  • how it controlled agents from multiple vendors; or
  • that it could prevent every AI-related breach or unsafe action.

Those are important distinctions for investors, security leaders, and founders evaluating the market. A product launch demonstrates a thesis and a proposed capability—not independently validated performance or durable market traction.

Key questions for enterprise buyers

An organization assessing an agent-security platform should ask vendors to demonstrate the following in its own environment:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Comprehensive discovery: Can it find sanctioned and unsanctioned agents across endpoints, browsers, IDEs, SaaS, cloud services, and internal applications?
  2. Responsibility mapping: Can it identify the human owner, application owner, business process, data owner, and downstream dependencies?
  3. Effective privilege: Does it show actual reachable systems and data, including inherited, delegated, temporary, and token-based access—not merely assigned permissions?
  4. Behavioral visibility: Can it record tool calls, API requests, data access, configuration changes, agent-to-agent activity, and high-risk actions?
  5. Policy enforcement: Does it support least privilege, just-in-time access, approval workflows, separation of duties, revocation, and emergency shutdown?
  6. Integration: Can it work with IAM, identity governance, PAM, SIEM, SOAR, EDR/XDR, SaaS-security, cloud, and data-security systems?
  7. Audit evidence: Are logs durable, attributable, tamper-resistant, exportable, and governed by appropriate retention policies?
  8. Privacy controls: What prompts, code, customer data, and business-process details are collected, and how are they protected?
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Trade-offs and failure modes

Agent governance introduces several practical tensions:

  • Visibility versus privacy: Detailed telemetry can expose confidential prompts, source code, customer information, or internal workflows.
  • Control versus productivity: Human approvals can reduce risk but may undermine the speed and autonomy that make agents useful.
  • Detection versus coverage: Known frameworks may be easier to identify than custom scripts, embedded copilots, browser automations, or agents hidden behind normal credentials.
  • Attribution versus ambiguity: Shared credentials, automatically generated workflows, and sub-agents can make it difficult to assign responsibility.
  • Explanation versus trust: An agent’s rationale may be incomplete, post hoc, or misleading. Natural-language explanations should not replace records of actual actions.
  • New platform versus existing IAM: Some organizations may prefer extending their current identity stack instead of buying a separate control plane.

There are also concrete failure scenarios. A platform may see an agent but not the full data flow behind its action. A valid credential may be used in an unsafe sequence. A periodic scan may miss a short-lived agent. An approver may authorize an action without understanding its downstream effects. Logs may record an API call without proving which agent initiated it. Overly broad policies create excessive privilege, while overly restrictive policies can encourage teams to bypass controls.

Agent identity controls also do not automatically protect against prompt injection, malicious tools, vulnerable plugins, compromised upstream systems, or model abuse. Buyers should treat them as one layer in a broader security architecture.

Current status: Check Point acquired Cyata

Check Point announced an agreement to acquire Cyata on February 12, 2026. Check Point later reported that the transaction was completed during the first quarter of 2026. Cyata’s current website identifies it as a Check Point company. Check Point’s fiscal 2025 filing supports the acquisition announcement, while its first-quarter 2026 results support the completion timing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check Point disclosed approximately $92 million in net cash consideration for the Cyata and Cyclops acquisitions combined. That figure should not be reported as Cyata’s standalone purchase price. It also should not be confused with Cyata’s $8.5 million seed financing or a company valuation.

The acquisition places Cyata’s agent-identity capabilities within Check Point’s broader security portfolio. For current buyers, the relevant commercial action is an enterprise demo or security-architecture assessment through Cyata or Check Point; no public self-serve pricing was disclosed in the supplied sources.

Where Cyata fits in the security market

Cyata’s original thesis sits at the intersection of several established categories:

  • IAM and identity governance: authentication, authorization, lifecycle management, and ownership;
  • PAM and secrets management: control of privileged credentials and high-risk access;
  • Endpoint, cloud, and SaaS security: visibility into where agents run and what applications they use;
  • SIEM, SOAR, and XDR: detection, investigation, and response; and
  • AI application security: protection for models, prompts, tools, retrieval systems, and data flows.

Adjacent platforms may be appropriate depending on the environment. Microsoft Entra is a natural starting point for organizations standardized on Microsoft 365 and Azure, but buyers should verify the depth of autonomous-agent discovery and behavioral controls required. Okta and Auth0 provide identity infrastructure, while CyberArk emphasizes privileged access, secrets, and machine identities. CrowdStrike offers broader endpoint, identity, cloud, and threat-detection capabilities. These products are not automatically equivalent to a specialist platform centered on agentic identity governance.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The practical comparison is not simply “which vendor secures AI?” It is whether a platform can discover the organization’s actual agents, map responsibility, understand effective privilege, observe downstream actions, enforce proportionate controls, and provide evidence that security and compliance teams can defend.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.