DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
The Finance Base
Akamai

Noname Security Raised $135 Million to Secure APIs. Akamai Bought It in 2024

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Noname Security announced a $135 million Series C round on December 15, 2021, at a $1 billion post-money valuation. The funding was meant to expand sales, marketing and research and development. The company is no longer independent: Akamai completed its acquisition in June 2024 for approximately $450 million, with a later SEC filing reporting $452.3 million in cash consideration.

That history puts the headline in perspective: the round marked Noname’s rise as an API-security startup, not its final outcome. Its “proactive” pitch combined several different security functions rather than one guarantee against API attacks.

What Noname announced in 2021

Georgian and Lightspeed Venture Partners led the $135 million round. Insight Partners, Cyberstarts, Next47, Forgepoint Capital and The Syndicate Group also participated. Noname said the Series C brought its total financing to $220 million and planned to use the money to expand its global go-to-market operation and research and development. Noname’s funding announcement called it the first API-security unicorn, a company characterization tied to the round’s valuation.

Noname had launched from stealth in December 2020 with $25 million in initial funding. At the time of the Series C, VentureBeat reported that the company had about 200 employees. The launch announcement and VentureBeat’s account of the round provide the contemporaneous details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Noname was founded by Oz Golan and Shay Levi, described by VentureBeat as former members of Israel’s Unit 8200. The company’s early pitch landed as businesses were relying on APIs to connect applications, data and services—and often had incomplete visibility into what they had exposed.

Why APIs create security risks

An API is a defined way for software systems to exchange data or trigger actions. Businesses use APIs to connect mobile and web applications, internal services, data stores, partners and cloud platforms. That makes API security more than a question of whether an endpoint is reachable. A flaw in authentication, authorization, input handling or configuration can expose data or let a user perform an action they should not be able to perform.

For example, an API may return another customer’s records because it fails to check whether the requester is entitled to them. A compromised API can also enable changes to business processes, not just data theft. In its 2021 account, VentureBeat quoted Noname executives describing APIs that could trigger actions such as starting a broadcast stream or controlling electricity service. These examples illustrate potential impact; they do not mean every API flaw has the same consequences.

The underlying enterprise problem is often visibility and ownership: a company may not know every API in use, who maintains it, what information it returns, or whether its permissions still match its intended purpose. Finding an endpoint is a useful first step, but it does not establish that the endpoint is secure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What “proactively” meant in Noname’s pitch

Noname used “proactive” as an umbrella for controls at different points in an API’s life. The capabilities below were described by the company and in contemporaneous coverage; they should not be read as independently validated performance results.

  • Discovery: Identify APIs, including undocumented or “shadow” endpoints that may not appear in a formal inventory.
  • Posture and configuration review: Find exposed or misconfigured endpoints that could create unnecessary risk.
  • Runtime monitoring: Observe API behavior after deployment and look for suspicious activity or changes.
  • Behavioral baselining: Learn patterns considered normal and flag deviations. Noname described using AI in this context, but that is not the same as detecting every vulnerability or business-logic flaw.
  • Response: Alert on suspicious behavior and, according to the company, take automated action. Detection and blocking are distinct: enforcement can interrupt legitimate traffic if rules are wrong.
  • Pre-production testing: Noname described plans to test code, vulnerabilities and configurations earlier in development, before APIs reached production.
  • Deployment approach: The company positioned its agentless or cloud-native deployment as a way to get started without installing agents or inserting proxies. Faster deployment does not by itself prove complete traffic visibility.

These functions address different problems. A declared API specification can be accurate while its authorization logic is flawed; runtime monitoring may spot unusual behavior without fixing the underlying code. No single discovery or monitoring product removes the need for secure design, testing, access controls and accountable remediation.

Rank #4
API Security in Action
  • API Security in Action
  • Manning Publications
  • ABIS BOOK

What traction Noname reported—and what those figures establish

VentureBeat reported that Noname said it had customer engagements with 20% of Fortune 500 companies within its first year on the market, along with customers in pharmaceuticals, retail and telecommunications. “Engagements” does not necessarily mean paying customers or production deployments, and the account did not name those organizations.

In its December 2021 announcement, Noname also said its platform had discovered and remediated misconfigurations that could have exposed billions of sensitive records and was blocking more than 1,000 attacks per day across customers. Those are company-reported claims, not independently audited measures of confirmed breach prevention or attack volume. The announcement did not provide enough methodology to assess how the figures were calculated. The company’s announcement and VentureBeat’s coverage are the sources for these claims.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How the story ended: Akamai’s acquisition

Akamai announced its intent to acquire Noname in May 2024, saying the deal would strengthen its API-security capabilities and broaden deployment options across cloud, edge, on-premises and other environments. It completed the acquisition in June 2024. Akamai described the purchase price as approximately $450 million; its SEC filing later reported cash consideration of $452.3 million.

The acquisition price is useful context beside Noname’s $1 billion 2021 post-money valuation, but the figures are not directly interchangeable. A private financing valuation and a later acquisition price can differ in timing, transaction structure, dilution and investor rights; the comparison alone does not establish what any particular investor received. Akamai’s acquisition announcement, completion announcement and SEC filing document the transaction.

Akamai later described the combined offering as Akamai API Security, integrating Noname technology with its existing capabilities. Akamai also said Noname customers discovered, on average, 40% more APIs than they initially expected; this is an Akamai-reported figure, not an independently established industry-wide result. Akamai’s integration explanation describes the product direction. Its 2025 annual report says the acquisition added approximately 200 employees and was intended to add flexible deployment options, integrations and enhanced attack analysis. Akamai’s annual report provides that corporate context.

What enterprise buyers should evaluate

For a buyer, the 2021 pitch is less important than whether a product fits the organization’s API estate and operating model. Discovery, testing, monitoring and enforcement are not interchangeable features. Evaluate the coverage and the work required to turn findings into fixes.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Inventory coverage: Ask whether discovery includes internal, external, dormant, partner and third-party APIs, and how encrypted or infrequently used traffic is handled.
  • Authorization and business logic: Determine whether testing can identify broken object-level authorization, privilege escalation and flaws that are not visible from a schema comparison alone.
  • Pre-production fit: Check support for API specifications, source code, CI/CD pipelines and developer workflows if the goal is to catch issues before release.
  • Runtime enforcement: Separate alerting from blocking. Ask about inline deployment, latency, false-positive handling, rollback and how legitimate traffic is protected.
  • Ownership and integrations: Confirm that findings can be assigned to service owners and connected to ticketing, SIEM, SOAR, identity, cloud, gateway, WAF and developer tools used by the organization.
  • Data handling: Establish whether request or response content is copied to a vendor-controlled environment, what is retained, and how sensitive data is protected.
  • Operational limits: Ask how the product handles incomplete visibility, unsupported gateways and baseline learning periods. Malicious activity during learning can be mistaken for normal behavior, while anomaly alerts can create noise.
  • Commercial continuity: Because Noname is part of Akamai, confirm the current product name, roadmap, licensing, support and migration terms directly with Akamai. A broader platform may offer integration advantages but can also change packaging or increase vendor dependence.

The Series C showed how strongly investors valued the prospect of securing a growing API footprint in 2021. The acquisition is the more consequential update: Noname’s technology continued as part of Akamai rather than as an independent startup, and the financing valuation should not be mistaken for the eventual sale price.

Quick Recap

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.