Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Sweet Security Raises $75 Million for Cloud and AI Security

Sweet Security raised $75 million in a Series B led by Evolution Equity Partners to expand its runtime cloud platform and AI-security offering. Its reported cumulative funding varies between $120 million and $125 million.
From TheFinanceBase Team7 min to read

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sweet Security announced a $75 million Series B on November 12, 2025, led by Evolution Equity Partners, with Munich Re Ventures, Glilot Capital Partners and Key1 Capital participating. The Tel Aviv-based company says it will use the financing to expand internationally and develop its runtime security platform for cloud environments and AI systems. The round also highlights a funding figure that remains unsettled: Sweet’s blog puts its total funding at $125 million, while its press release and independent coverage report $120 million.

What Sweet Security announced

The financing is a $75 million Series B equity round. Evolution Equity Partners led it; Munich Re Ventures, Glilot Capital Partners and Key1 Capital also participated. Sweet says the proceeds will support international expansion and product development, including more cloud-runtime capabilities and its growing focus on AI security. The announcement introduced or emphasized the company’s AI Security Platform alongside its runtime-focused cloud offering. (Sweet’s announcement; Business Wire release)

Calcalist Tech reported that about $15 million of the round involved secondary transactions—purchases of existing shares—rather than all of the money going to the company as new capital. That figure is a media report, not a line-item allocation confirmed in Sweet’s announcement. (Calcalist Tech)

The cumulative funding figure is inconsistent

Sweet’s funding blog says the Series B brings total funding to $125 million. Its contemporaneous press release and several independent reports give $120 million. Previously reported rounds include a $12 million launch or seed financing and a $33 million Series A in March 2024, which, added to this $75 million round, totals $120 million. The public materials do not explain the $5 million difference, so neither cumulative figure should be treated as fully reconciled. (Sweet; Business Wire; SecurityWeek)

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What Sweet Security sells

Sweet describes its product as a runtime-powered cloud-native application protection platform, or CNAPP. A CNAPP brings together security functions for cloud infrastructure and the applications running on it. Sweet’s product materials describe coverage spanning workloads, applications, identities, vulnerabilities, APIs, data, Kubernetes and containers, CI/CD pipelines, and cloud configuration. The company lists capabilities including cloud detection and response, workload protection, identity threat detection, vulnerability management, cloud security posture management, entitlement management, API and data security, and dynamic application security testing. These are vendor-described product capabilities, not independent evaluations of how well each performs. (Sweet Runtime CNAPP)

What “runtime-first” means

Posture and vulnerability tools commonly flag risks based on configuration, code, or software inventory: they identify what might be exposed or exploitable. Runtime security instead observes activity while workloads, applications, identities, and cloud resources are operating. The aim is to add evidence about what is actually happening, helping a team distinguish an active or reachable risk from a theoretical finding and prioritize its response.

Sweet says its sensor uses eBPF, a Linux kernel technology used to collect low-level system telemetry. The company says it correlates cloud, workload, and application activity. eBPF does not by itself establish zero performance overhead, nor does runtime telemetry replace code review, identity governance, model evaluation, or supply-chain controls. Buyers should request deployment-specific overhead and efficacy evidence. (Runtime CNAPP; Detection and response)

What Sweet’s AI-security platform is designed to do

Sweet calls the offering its AI Security Platform, or AISP, and also uses the term AI Detection and Response (AIDR). Its product materials describe a set of capabilities across AI discovery, posture, data flows, and runtime monitoring—not simply one standalone AI gateway or one prompt filter. (Sweet AI Security Platform; AI security solution)

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Discover and inventory: Find models, agents, LLM servers, AI-enabled services, and potentially unapproved “shadow AI”; build an inventory or AI bill of materials.
  • Map exposure and access: Map model, agent, API, and data interactions; identify exposed endpoints, misconfigurations, and excessive permissions.
  • Monitor runtime activity: Observe prompts and interactions, sensitive data moving through AI workflows, and deviations from established agent behavior.
  • Detect and respond: Look for prompt injection and other adversarial behavior, apply policy guardrails, and, in some deployment modes, block actions inline.

These are product claims about intended functionality. Detecting suspicious prompts or agent behavior is not a guarantee that every attack will be detected, that an AI system is safe, or that every production action can be blocked without disrupting legitimate work.

Why cloud security vendors are moving toward AI workloads

Production AI systems often connect models and agents to APIs, databases, tools, cloud workloads, and business processes. An agent may be able to read sensitive records, call services, execute code, or trigger actions. If those permissions are broader than necessary—or if the organization does not know which agents and models are in use—the risks touch cloud security, application security, identity, and data protection at once.

Static cloud controls can identify configuration weaknesses but may not show what an agent is doing during a particular execution. Sweet’s strategic thesis is that runtime context can help teams monitor both conventional cloud workloads and AI systems within one platform. That is a rationale for consolidation, not proof that a unified product outperforms specialized tools. AI inventory and runtime monitoring also do not, on their own, prove model robustness or eliminate prompt injection, data leakage, unsafe tool use, or compromised dependencies.

Who founded Sweet Security

Sweet lists Dror Kashti as co-founder and CEO, Eyal Fisher as co-founder and chief product officer, and Orel Ben Ishay as co-founder and VP of R&D. The company describes Kashti as a former CISO of the Israel Defense Forces; Bloomberg also reported that the startup was founded by the former Israeli army CISO. References disagree on the company’s founding year: SecurityWeek says 2023, while SiliconANGLE and Globes say 2022. Sweet’s current About page does not resolve that discrepancy. (Sweet About page; Bloomberg; SecurityWeek; SiliconANGLE; Globes)

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the financing signals—and what it does not prove

A $75 million Series B gives Sweet capital to pursue enterprise expansion and broaden a product that spans cloud runtime security and AI use cases. The company says its goals include global expansion and product innovation; likely areas of investment include sales, engineering, integrations, and enterprise operations, but no public line-item budget establishes how the round will be allocated. Investors’ participation signals interest in the company and its market thesis, not independent validation of product performance.

Sweet’s press release reports sixfold ARR growth and tenfold growth in enterprise customers. Those are company-reported metrics; the announcement does not provide the baselines or enough detail to independently assess them. The release also uses positioning such as “first” and “leading” for the unified platform. Those are promotional claims, not established market rankings. (Business Wire)

What an enterprise buyer should evaluate

Sweet’s public product pages direct prospective buyers to request a demo rather than publish a price list or self-service plan. A platform spanning runtime cloud security and AI may suit an organization with substantial cloud-native workloads, production AI agents, and the staff to investigate behavioral alerts. It may be less appropriate for a team seeking only basic cloud posture checks, transparent self-service pricing, a standalone AI gateway, or a narrow point solution. (Sweet demo page)

Questions to ask in a technical evaluation

  • Which cloud providers, Kubernetes distributions, operating systems, serverless platforms, and workload types are supported in the intended deployment?
  • What does the eBPF sensor collect, where is data processed, and how are sensitive data, retention, residency, and tenant isolation handled?
  • What performance overhead does the sensor introduce under workloads like yours?
  • Which model providers, AI frameworks, agent runtimes, MCP implementations, gateways, and orchestration systems are supported?
  • Can the product block actions inline in your deployment, or does it only alert? What is the rollback path if a guardrail interrupts a valid workflow?
  • How are prompt-injection detections validated, and what evidence is available for false positives and false negatives?
  • How does the system distinguish suspicious agent behavior from legitimate automation with broad permissions?
  • Can findings integrate with your SIEM, SOAR, ticketing, and incident-response processes?
  • What exactly is included in licensing, and what are the minimum commitments, usage meters, deployment fees, and professional-services costs?

Operational and platform trade-offs

  • Inventory is not omniscience: AI components that do not produce observable traffic, or that operate through unmanaged channels, may not appear in an inventory.
  • Behavior can be ambiguous: An agent performing its intended task can resemble an attacker when it has broad access.
  • Enforcement can disrupt production: Inline controls can stop harmful actions, but immature policies can block legitimate workflows.
  • Telemetry needs an operating process: Runtime visibility is useful only if findings are prioritized, investigated, and connected to response workflows.
  • Consolidation has a cost: Replacing several tools with one platform may reduce tool sprawl, but it can increase vendor concentration and migration costs if specialist needs remain unmet.
  • Metrics need definitions: Claims about noise reduction, detection speed, accuracy, or response time require clear baselines, workload context, and independent validation before buyers rely on them.

Sweet competes in a market that also includes broad CNAPP and cloud-security platforms such as Wiz, Orca Security, Palo Alto Networks Prisma Cloud, and Microsoft Defender for Cloud. Their scope and deployment models differ, and the available financing announcement does not establish a head-to-head product result. An evaluation should compare coverage against the buyer’s own environments and existing tools rather than assume that a broad platform necessarily replaces every specialist control.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.