Aug 27, 2026

TVC Analysts: Five Cybersecurity Vendors We’re Looking At

Cybersecurity is not one market. It is a couple of dozen stacked on top of each other, and the lines between them keep moving. Identity, endpoint, detection and response, exposure management and application security each have their own incumbents, their own buying cycles, and their own backlog of problems the last generation of tools chose to leave alone. A security buyer today is rarely shopping for a category. They are trying to close a gap that three products they already own somehow do not cover.

AI is pulling on all of those gaps at once. It is generating new attack surface faster than most teams can inventory it, and it is also the most credible answer to the volume problem that has been breaking security operations for a decade. That tension is where we spend our time. The question we ask about any vendor is whether it solves something that got materially harder in the last eighteen months, and whether it has real product in market rather than a roadmap. The five below clear that bar.

Daylight Security

Daylight calls its model Managed Agentic Security Services, or MASS. The premise is that AI agents and senior security experts should run security operations together, rather than a junior analyst tier triaging alerts and escalating what it cannot resolve. Everything runs on one architecture: managed detection and response, threat hunting, phishing investigation, DLP investigation, and a security data lake that stores the alerts and logs an investigation needs, which removes the requirement for a separate SIEM. The team is built entirely from threat hunters and incident responders operating a follow-the-sun model across four regions, with no night shifts. Daylight recently launched Detection Program Visibility, which gives security leaders a measurable view of how their detection coverage actually performs.

Way Security

Way positions itself as the last mile of identity. Most organizations own an IdP, an IGA platform and PAM tooling, but those controls only reach applications that support modern authentication, which leaves a long tail of apps outside the perimeter of the identity program. Way is a universal integration and enforcement layer that applies the IAM controls a company already owns to every application and identity, including legacy, homegrown, disconnected and non-standard apps, without a rip and replace. That covers MFA and SSO enforcement, automated app onboarding and provisioning, access reviews, joiner-mover-leaver automation, and remediation of orphaned accounts and over-provisioned users. Founded in 2025, Way raised a $20 million seed led by Insight Partners and Glilot Capital, and has paying customers across financial services, healthcare and manufacturing.

Bloom Security

Bloom treats the endpoint as an ecosystem rather than a device. Every laptop now runs AI agents, MCP servers, browser extensions, IDE plugins and open source libraries that nobody put through a security review. Bloom builds a live inventory of everything running across the fleet, assesses risk using marketplace intelligence, static analysis and behavioral sandboxing, then removes risky tools or revokes permissions with a preview of who will be affected. It also blocks malicious packages at the source and applies guardrails to what AI agents can execute and transmit. The company came out of stealth with a $20 million seed, and its research team recently disclosed Extension Resurrection, a weakness on Open VSX and the VS Code Marketplace that let attackers publish malicious extensions under identities that trusted extension packs already referenced. More than 750 affected packs accounted for over 500,000 downloads, and both the Eclipse Foundation and Microsoft have since patched it.

CyCognito

CyCognito works from the outside in. It starts with nothing more than a company name, maps everything that company has exposed to the internet, and traces the handful of paths that actually lead to internal networks and sensitive data. The approach surfaces the assets nobody is tracking, including inherited infrastructure, subsidiary systems and third-party connections, and then validates which weaknesses are genuinely exploitable instead of handing over another scan report. CEO Rob Gurzeev has argued that AI has made the problem sharper, because anyone in finance or HR can now stand up an internet-facing application without touching a security process. The company’s recent work centers on continuous AI pentesting, which runs always-on testing across every exposed asset rather than a sample of high-priority ones.

Reclaim Security

Reclaim describes its platform as an AI security engineer, and the pitch is aimed squarely at the second half of the exposure problem. Most tools find misconfigurations and hand the list to a human. Reclaim discovers exposures across more than 40 security platforms, plans a fix, and executes it. What makes that viable is PIPE, its Productivity Impact Prediction Engine, which simulates the business impact of a change before deployment so that a security fix does not break a workflow or a business-critical application. The company has been named in Gartner’s preemptive security research as a mover in the shift from reactive detection to autonomous remediation, and it recently appointed Stephen Wadsworth as VP of Sales to lead its US growth.

The Through Line

None of these five compete for the same line item, which is part of why they sit on the list together. The movement in security right now is in the spaces between established products. The application the IdP never reached. The browser extension nobody approved. The finding that sat in a queue for a quarter because fixing it might have broken something. Those gaps used to be tolerable. At the rate AI is adding surface area, they are getting harder to justify, and we will be watching how much of what these companies ship holds up at enterprise scale.