Capsule Security
by Capsule Security
A runtime trust layer that stops enterprise AI agents from going rogue
Capsule Security is a runtime security platform for enterprise AI agents that monitors agent behavior in real time and blocks unsafe actions before they execute. It is built for security and platform teams adopting agentic AI who need to control agents across coding tools, SaaS, and cloud environments.
Capsule Security, a Tel Aviv-based company founded in 2025 by CEO Naor Paz (ex-F5, Unit 8200) and CTO Lidan Hazout (ex-Transmit Security), is a runtime-first trust layer purpose-built to secure enterprise AI agents. It continuously monitors agent behavior and intervenes during runtime at the first sign of anomalous or unsafe activity — blocking risky commands, unsafe tool usage, sensitive-data exposure, and unexpected action chains before they complete — without proxies, gateways, SDKs, or browser extensions. Its agentless integration automatically discovers AI agents and gives deep real-time visibility into their actions, decisions, and execution paths, while an Agent Security Graph maps relationships between agents, tools, data, and actions to reveal risky paths and control gaps, and white-box red teaming uncovers weaknesses in agent logic and prompts. Capsule works with any framework or environment and supports AI coding agents (Claude Code, Cursor, GitHub Copilot), enterprise platforms (ChatGPT Enterprise, Microsoft Copilot Studio, Salesforce Agentforce, ServiceNow, Atlassian), and cloud providers (AWS Bedrock, Azure AI Foundry, GCP Vertex). The company exited stealth on April 15, 2026 with a $7 million seed round led by Lama Partners and Forgepoint Capital International, and has published the open-source ClawGuard tool plus disclosed the ShareLeak (Microsoft Copilot Studio) and PipeLeak (Salesforce Agentforce) vulnerabilities.
At a Glance
- Category
- Governance & Security
- Pricing
- Contact for pricing
- Target Market
- CISOs, CIOs, Security Engineers, AI Platform Teams
- Founded
- 2025
- Headquarters
- Tel Aviv, Israel
Key Features
- ✓Runtime monitoring & intervention
Continuously monitors agent behavior and interrupts unsafe actions before they are executed.
- ✓Agentless discovery
Automatically discovers AI agents with no need to modify code, agents, or architecture.
- ✓Agent Security Graph
Maps relationships between agents, tools, data, and actions to reveal risky paths and control gaps.
- ✓White-box red teaming
Probes agent logic, prompts, and behaviors to uncover weaknesses before attackers do.
- ✓Identity & least-privilege control
Maintains clear ownership, least privilege, and accountability across autonomous agents.
Use Cases
- •Runtime guardrails
Interrupt risky commands, unsafe tool use, and sensitive-data exposure the moment an agent attempts them.
- •Agent discovery & visibility
Automatically find and monitor AI agents across coding tools, SaaS, and cloud without instrumentation.
- •Agent risk assessment
Use the Agent Security Graph and red teaming to expose control gaps and emerging threats in agent workflows.
Ideal For
Best For
- ✓Securing enterprise AI agents at runtime
- ✓Blocking unsafe agent actions and data exfiltration before execution
- ✓Red-teaming and discovering shadow AI agents across the enterprise
Market Analysis
Pros
- ✓Agentless deployment requires no changes to code or architecture
- ✓Intervenes in real time before unsafe actions complete
- ✓Founders with strong security pedigree (Unit 8200, F5, Transmit Security)
Cons
- ✗Early-stage seed company with a short production track record
- ✗No public pricing and enterprise sales-led only
Pricing
Enterprise
Contact for pricing
- ✓Runtime monitoring and intervention
- ✓Agentless discovery
- ✓Agent Security Graph
- ✓White-box red teaming
Pricing is not publicly disclosed; Capsule sells an enterprise runtime-security layer through a sales-led model.
Sources
This page was written from 2 sources, 1 on domains other than capsulesecurity.io.
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
OpenAI Daybreak
Vetted-access frontier AI for cyber defenders, with a purpose-built offensive-security model
NVIDIA OpenShell
Open-source, kernel-isolated sandbox runtime for autonomous AI agents
Zenity
Runtime AI agent security that blocks a harmful agent action before it executes
Saviynt Zuma
Identity control plane for AI agents and non-human identities, with runtime authorization