Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversFall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
Blog

Zafran Emerges From Stealth With Risk and Mitigation Platform, Raising More Than $30 Million

By TheFinanceBase Team7 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Zafran publicly emerged from stealth on March 28, 2024, announcing more than $30 million in funding led by Sequoia Capital and Cyberstarts. The Israeli cybersecurity company introduced a platform designed to identify which vulnerabilities are genuinely exploitable in a specific environment and reduce that exposure with existing security controls while organizations work toward permanent fixes.

The $30 million figure is historical, not Zafran’s latest disclosed funding total. In December 2025, the company announced a $60 million Series C and said its total disclosed funding had reached $130 million. Strategic investments from Amex Ventures and Cisco Investments followed in 2026.

What Zafran announced in 2024

Founded in 2022, Zafran was created by CEO Sanaz Yashar, CTO Ben Seri and CPO Snir Havdala. The company has Israeli cybersecurity roots, while its stealth-exit announcement was issued from New York.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Zafran said it had raised more than $30 million, with Sequoia Capital and Cyberstarts as lead investors and participation from Cerca Partners and Penny Jar. Contemporary coverage often rounded the amount to $30 million, but the company’s wording was “over $30 million.” The announcement did not clearly identify the financing stage, so it should not automatically be described as a Series A or another specific round.

In its launch announcement, Zafran described itself as a risk-and-mitigation platform focused on fighting threat exploitation. Its central idea was that organizations need to understand not only whether a vulnerability exists, but whether attackers can realistically exploit it in that particular environment.

Read Zafran’s original announcement.

The vulnerability-management problem Zafran targets

Traditional vulnerability programs commonly follow a discover, rank and patch workflow. That model remains necessary, but it can produce an enormous queue of findings. A scanner may identify thousands of vulnerabilities without showing which ones are reachable, exploitable and important to the business.

Patching also takes time. Security teams may need to test updates, coordinate with application owners, schedule maintenance windows, manage dependencies and avoid interrupting critical services. In some environments, a patch can take weeks or months to deploy safely.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That delay creates an exploitation window: the period between discovering a vulnerability and permanently fixing it. During that period, the affected system may already have some protection. Endpoint detection and response, firewalls, web-application firewalls, segmentation or cloud-policy controls may reduce the likelihood or impact of exploitation. But the effectiveness of those controls depends on their configuration, coverage and position in the attack path.

Zafran’s thesis is that vulnerability risk should therefore reflect the surrounding environment rather than rely mainly on a generic severity score. An internet-facing vulnerability on a business-critical asset may deserve immediate attention even if its standalone score is moderate. A severe vulnerability may be less urgent if the vulnerable software is not running or relevant attack paths are blocked—although that conclusion still depends on accurate telemetry.

How the risk-and-mitigation model works

Zafran said its platform combines vulnerability findings with runtime information, internet exposure, threat intelligence, exploitability analysis, asset context and security-control configuration. The company called the resulting assessment Zafran Applicable Risk.

In practical terms, the workflow is intended to look like this:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Gather findings: Ingest vulnerability data from scanners and other security tools.
  2. Confirm environmental context: Determine whether the affected software is present, running and associated with a particular asset.
  3. Assess exposure: Establish whether the asset is internet-facing or reachable through another relevant route.
  4. Consider exploitation: Add threat intelligence and evidence about exploitability or exploitation in the wild.
  5. Evaluate controls: Examine asset criticality and the configuration and apparent coverage of existing defensive controls.
  6. Mitigate: Recommend or potentially mobilize a compensating control to reduce exposure before patching.
  7. Remediate: Track the permanent fix, such as patching, upgrading, removing software or changing architecture.

Zafran’s current platform description groups the process into four stages: Unify Findings, Assess Risk, Mitigate and Remediate. It also describes proactive exposure hunting for new CVEs, zero-days, threat actors, internet-exposed assets and control gaps.

Mitigation is not the same as remediation

This distinction is essential for evaluating Zafran’s approach.

  • Mitigation reduces the chance or impact of exploitation, often by changing a control or configuration.
  • Remediation removes the underlying vulnerable condition, commonly through patching, upgrading, uninstalling software or redesigning the affected system.
  • Risk acceptance is a documented decision to tolerate remaining risk, usually with an owner and review date.

A firewall rule, endpoint policy or segmentation change may shrink an exploitation window, but it does not necessarily remove vulnerable code. Controls can also drift, fail to cover lateral movement or protect only part of an attack path. Zafran’s model is therefore better understood as a way to reduce exposure before or alongside patching—not as a universal replacement for patch management.

How Zafran differs from conventional security tools

Tool or approach Primary role How Zafran positions its difference
Vulnerability scanner Finds and reports vulnerabilities Adds environmental, exploitability and control context to prioritization.
Patch-management system Deploys software updates Addresses the period before a patch is safe or available by coordinating compensating controls.
EDR Detects or responds to endpoint activity Uses endpoint protection as one part of a broader exposure assessment rather than treating it as the whole program.
Firewall or segmentation platform Controls network access and movement May serve as a mitigation mechanism within a wider risk workflow.
Exposure-management platform Unifies assets, vulnerabilities and attack-surface context Zafran emphasizes control-aware mitigation and remediation operations.

This does not mean Zafran automatically replaces these products. Its value depends on whether it adds useful orchestration and decision context to the tools an organization already owns. Zafran’s current materials describe a hybrid, agentless approach that can ingest information across existing tools, but agentless does not mean integration-free: connectors, credentials, permissions, APIs and reliable data pipelines are still required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What happened after the stealth launch

  • March 28, 2024: Zafran emerged from stealth with more than $30 million in funding.
  • April 28, 2025: The company introduced “Remediation Operations,” or RemOps, according to its resource archive.
  • December 2, 2025: Zafran announced a $60 million Series C led by Menlo Ventures and said total disclosed funding had reached $130 million.
  • February 24, 2026: Amex Ventures announced a strategic investment in Zafran.
  • July 22, 2026: Cisco Investments announced a strategic investment. The announcement described the investment as extending Zafran’s previously announced $130 million total; it did not establish a new total funding figure.

The company’s positioning has also broadened. Zafran now describes its product as an AI-native Threat Exposure Management or Agentic Exposure Management platform, with an Exposure Graph linking assets, vulnerabilities, attack paths and security controls. Those labels and capability claims come from Zafran and should not be treated as independent proof of performance.

Its current product language covers discovery, prioritization, mitigation, remediation operations and proactive exposure hunting. The company says RemOps consolidates remediation work and routes tasks through ticketing systems.

See Zafran’s Series C announcement and its Cisco Investments announcement.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Who might benefit from Zafran?

Zafran appears most relevant to large enterprises with substantial vulnerability backlogs, complex hybrid environments and multiple existing security controls. It may be especially useful where patching is constrained by uptime, application compatibility, regulatory requirements or operational risk.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A smaller organization with a manageable asset inventory and straightforward patch queue may not need an additional exposure-management layer. The product may also be a poor fit for buyers seeking a basic scanner, transparent self-service pricing or a platform that requires few integrations.

Buyers should ask:

  • Which scanners, endpoint tools, firewalls, cloud platforms and ticketing systems are supported?
  • Which mitigation actions can be automated, and which require approval?
  • How are staged rollout, rollback and audit trails handled?
  • How does the platform verify that a mitigation remains effective after configuration drift?
  • What data and permissions are required, and where is telemetry processed and retained?
  • How is success measured—reduced exploitable exposure, faster remediation, fewer emergency patches or another metric?
  • Does the product complement existing CNAPP, attack-surface-management, EDR or vulnerability-management capabilities, or substantially duplicate them?

Important limitations and risks

Data quality matters. If asset, runtime, exposure or control data is incomplete or stale, a risk assessment can be wrong. A system could be marked mitigated even though a control is disabled, misconfigured or absent on part of the environment.

“Mitigated” needs a precise definition. A perimeter rule may block one external route but do nothing against lateral movement. EDR may detect exploitation without preventing it. Segmentation may limit blast radius without stopping initial compromise.

Automation can cause disruption. Changing firewall rules, endpoint behavior, access policies or cloud controls can block legitimate traffic or interrupt production. Approval gates, testing, staged deployment, rollback and change records are critical.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Lower risk is not zero risk. Threat intelligence can lag newly developed attacks, attackers can chain multiple weaknesses, and a compensating control can fail. Permanent remediation and documented ownership remain necessary.

Pricing is not fully transparent. An AWS Marketplace listing displayed a Zafran Platform subscription at $300,000, but the available listing did not establish the billing term, asset quantity, included modules or whether the figure is typical for all customers. It should be treated only as a pricing signal, not a universal quote.

Bottom line

Zafran’s 2024 launch was built around a practical problem: organizations often cannot patch every vulnerability immediately, yet scanner severity alone does not explain which systems are truly exposed. Its proposed answer was to combine vulnerability and threat data with asset context and existing security controls, then use that information to prioritize and mitigate risk while permanent remediation proceeds.

The original announcement involved more than $30 million in funding from Sequoia Capital, Cyberstarts, Cerca Partners and Penny Jar. That figure is now part of Zafran’s history: the company later announced a $60 million Series C and $130 million in total disclosed funding, followed by strategic investments in 2026. The broader product has evolved into an AI-native exposure-management platform, but the core evaluation question remains the same—whether its control-aware context and mitigation workflows produce measurable risk reduction beyond what a buyer’s existing security stack already provides.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.