Capsule Security
by Capsule Security
Runtime security that stops AI agents from going rogue before an action executes.
Capsule Security monitors what enterprise and coding AI agents actually do at runtime and blocks unsafe tool calls, data exposure and prompt-injection-driven actions before they execute. It is built for security teams that must let employees use Claude Code, Cursor, Copilot Studio or Agentforce without losing control of what those agents touch.
Capsule Security is a Tel Aviv-based agentic-AI security company founded in 2025 by CEO Naor Paz, formerly of F5 and Unit 8200, and Lidan Hazout, formerly VP of R&D at SecuredTouch and Transmit Security. It emerged from stealth in April 2026 with a $7 million seed round led by Lama Partners and Forgepoint Capital International. The platform targets the runtime gap: the window between an agent receiving a prompt and executing an action, where it can be manipulated or can silently exfiltrate data. Capsule discovers agents across the estate without code changes, maps agents, tools, data and actions in an Agent Security Graph, observes execution paths in real time, and allows, flags or blocks each action against policy before it completes, producing auditable telemetry for governance and investigations. It connects agentlessly (no proxies, gateways, SDKs or browser extensions) to coding agents (Claude Code, Cursor, GitHub Copilot), enterprise agents (ChatGPT Enterprise, Microsoft Copilot Studio, Salesforce Agentforce, ServiceNow, Atlassian) and builder platforms (AWS Bedrock, Azure Foundry, GCP Vertex). At launch it disclosed ShareLeak (CVE-2026-21520), an indirect prompt injection in Copilot Studio, and PipeLeak in Agentforce, both since patched, and released ClawGuard, an open-source pre-invocation checkpoint for OpenClaw-style frameworks. In September 2026 it shipped an 'AI circuit breaker' built on two fine-tuned Nvidia Nemotron models, reporting 98% accuracy on the StepShield benchmark and decisions in as little as 71 milliseconds. H&R Block's CISO is a named reference.
A CISO or AppSec lead whose organisation is rolling out coding agents and SaaS agents (Copilot Studio, Agentforce) faster than security can review each one.
Per-action allow, flag or block decisions on agent behaviour before execution, across many agent platforms, without deploying proxies or SDKs.
At a Glance
- Category
- Governance & Security
- Pricing
- Contact for pricing
- Target Market
- CISOs, Security Engineers, AppSec Teams, CIOs
- Deployment
- Cloud-first
- Founded
- 2025
- Headquarters
- Tel Aviv, Israel
Key Features
- ✓Runtime intervention
Evaluates each agent action in context and blocks unsafe commands, tool calls or data exposure before the action executes.
- ✓Agentless agent discovery
Finds agents across coding tools, SaaS platforms and cloud builders without modifying code, agents or architecture.
- ✓Agent Security Graph
Maps relationships between agents, tools, data and actions so security teams can see blast radius and risky access paths.
- ✓AI circuit breaker (Nemotron-based)
Two fine-tuned Nvidia Nemotron models judge whether an intended action fits the task, reporting 98% on StepShield at around 71 ms.
- ✓Whitebox red teaming
Proactively tests agent logic and prompts for vulnerabilities such as indirect prompt injection before agents reach production.
- ✓Auditable telemetry
Records agent decisions and execution paths for governance, compliance evidence and security investigations after an incident.
Use Cases
- •Securing coding agents
Security teams watch Claude Code, Cursor and Copilot sessions and stop destructive commands or secret exfiltration before execution.
- •Stopping prompt injection in SaaS agents
Blocks agent actions triggered by untrusted inputs, such as the PipeLeak lead-form injection Capsule found in Salesforce Agentforce.
- •Agent inventory and posture
Discovers every agent across Bedrock, Foundry, Vertex and enterprise SaaS and maps which tools and data each can reach.
- •Compliance and investigation evidence
Provides an auditable record of what each agent did and why it was allowed or blocked, supporting regulators and incident response.
- •Pre-deployment agent testing
Red-teams new agent workflows and prompts to surface exploitable logic before business units put them into production.
Ideal For
Best For
- ✓Governing developer use of Claude Code, Cursor and GitHub Copilot on endpoints
- ✓Blocking prompt-injection-driven actions in Microsoft Copilot Studio and Salesforce Agentforce
- ✓Building an inventory of agents, tools and data access across SaaS and cloud agent builders
- ✓Producing audit telemetry of agent actions for compliance and incident investigation
- ✓Red-teaming agent logic and prompts before rollout
Not Ideal For
- ✗Organisations that want an established vendor with public pricing and peer reviews; Capsule is a seed-stage company founded in 2025
- ✗Teams whose main risk is model-level content safety (toxic output, jailbreak text) rather than agent actions, where an LLM guardrail or AI firewall is a closer fit
- ✗Environments using agent platforms outside Capsule's published integration list, which would need confirming with the vendor
Deployment
Market Analysis
Pros
- ✓Covers coding agents, SaaS agents and cloud agent builders from one agentless platform
- ✓Credible research track record: disclosed ShareLeak (CVE-2026-21520) and PipeLeak at launch
- ✓Published detection figures: 98% on StepShield with decisions in as little as 71 ms
- ✓Named enterprise reference in H&R Block's CISO; finalist in CrowdStrike's startup accelerator
Cons
- ✗Very young vendor (founded 2025, $7M seed), so long-term viability and support depth are unproven
- ✗No public pricing, and no G2, Capterra or Hacker News practitioner reviews to validate claims
- ✗Benchmark comparisons are vendor-run, and the third-party baseline model it beat was not disclosed
- ✗Customer list is largely undisclosed beyond one named reference
Pricing
Enterprise
Contact for pricing
- ✓Runtime monitoring and intervention
- ✓Agent discovery and Security Graph
- ✓Whitebox red teaming
- ✓Policy enforcement
Capsule publishes no pricing on its website, and none of the launch or funding coverage disclosed a metering model; buying is sales-led via a demo request, so budget and scope must be negotiated directly.
Security & Compliance
Sources
This page was written from 5 sources, 4 on domains other than capsulesecurity.io.
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
WitnessAI
Network-layer AI security and governance for employee AI use, models, apps and agents
Ascerta
Enterprise AI management: measure the ROI, cost and adoption of every AI initiative, agent and coding tool
Reco
AI agent security and SaaS security platform that discovers, governs and secures every agent, app and identity
Arcjet
Runtime security for AI agents: observe, enforce and audit agent tool calls, with prompt-injection, PII and abuse controls in code