Dawnguard
by Dawnguard
AI-native security architecture automation that builds secure cloud systems from day zero
Dawnguard is an AI-native security architecture automation platform that shifts cloud security into the design phase. Teams generate and review a cloud architecture on a collaborative canvas, export production-ready Infrastructure as Code from the approved design, then continuously validate that the running environment has not drifted away from it. It targets cloud architects, platform engineers and security teams who currently review finished infrastructure retroactively.
Dawnguard is an AI-native security architecture automation platform that moves cloud security from post-deployment detection into the design phase. In its Design stage, engineering and security teams generate a cloud architecture on a collaborative canvas from a text prompt or an uploaded reference image, then refine it with AI-driven insights scored across the Well-Architected pillars. A Discover stage connects live cloud environments to inventory resources and visualise their relationships, dependencies and improvement opportunities; the plan tiers meter this by connected Azure subscriptions or AWS accounts and by total resource count. The Deploy stage generates production-ready Infrastructure as Code from the approved design and then continuously validates that what is actually running still matches it, closing what the company calls the security drift between architectural intent and operational reality — CTO Kim van Lavieren frames the product as turning architecture into enforceable code rather than leaving it in documents, spreadsheets and diagrams. A hosted Dawnguard MCP server surfaces the same cloud security insights, guardrail guidance and compliance checking inside MCP-capable coding assistants including Claude Code, Visual Studio Code and Cursor, so engineers can query findings without opening a separate dashboard. Three plans — Essential, Advanced and Elite — scale from 5 to 100 connected subscriptions or accounts and 2.5k to 60k resources, with SSO, SCIM, full tenant isolation and a 50M-token architecture-generation allowance included from the entry tier. Founded in 2025 and headquartered in Amsterdam by CEO Mahdi Abdulrazak and CTO Kim van Lavieren, whose roughly 45-person team includes security engineers from IBM, Amazon and the Royal Netherlands Navy, Dawnguard left design-partner status for general availability in July 2026 alongside a $3.3M pre-seed extension from BNVT Capital, Curiosity VC and eCAPITAL that brought total funding above $6.3M, and opened a New York office to target US financial services.
The cloud architect or security architect at a regulated enterprise who is asked to approve cloud designs that already exist only as diagrams, and cannot prove the deployed estate still matches them.
One approved architecture that produces the Infrastructure as Code and then keeps proving the running environment has not drifted from it.
At a Glance
- Category
- Governance & Security
- Pricing
- Subscription, Contact for pricing
- Target Market
- CISOs, Cloud Architects, Platform Engineers, Security Engineers
- Deployment
- Cloud-only, Multi-cloud
- Founded
- 2025
- Headquarters
- Amsterdam, Netherlands
- Team Size
- 11-50
Key Features
- ✓AI architecture design canvas
Generates a cloud architecture from a text prompt or reference image and refines it collaboratively in minutes.
- ✓Well-Architected insights
Scores designs across the Well-Architected pillars and surfaces improvement opportunities before anything is deployed.
- ✓Live environment discovery
Connects existing cloud accounts to inventory resources and visualise their relationships and dependencies automatically.
- ✓Infrastructure as Code generation
Emits production-ready IaC from an approved design instead of hand-translating a diagram into Terraform.
- ✓Continuous drift validation
Checks deployed environments against the approved architecture so intent and reality cannot silently diverge.
- ✓Dawnguard MCP server
Delivers cloud security insights and guardrail guidance inside Claude Code, Visual Studio Code and Cursor.
- ✓Enterprise access controls
SSO, SCIM provisioning and full tenant isolation are included on every plan tier, not gated behind an upsell.
Capabilities
Use Cases
- •Pre-deployment security review
Security signs off an architecture on the canvas before engineers write any infrastructure code at all.
- •Landing zone design
Stand up a compliant landing zone from a prompt rather than copying the last project's diagram.
- •Post-deployment drift detection
Catch configuration that has wandered from the approved design before an auditor or an attacker finds it.
- •Inherited estate discovery
Map an inherited AWS or Azure estate to see what exists and how the resources actually relate.
- •Security context inside the IDE
Ask about live cloud findings from a coding assistant instead of switching to a separate console.
Ideal For
Best For
- ✓Cloud architects who need a design reviewed and turned into Infrastructure as Code in the same tool
- ✓Security teams that keep being handed finished infrastructure and asked to approve it retroactively
- ✓Platform engineering teams standardising landing zones across many AWS accounts or Azure subscriptions
- ✓Regulated organisations that must evidence the running estate still matches an approved architecture
- ✓Teams already using MCP-capable assistants such as Claude Code, Cursor or VS Code who want cloud security findings in the editor
Not Ideal For
- ✗Google Cloud-first estates — the published plan metering and scan coverage are expressed in Azure subscriptions and AWS accounts, with no GCP support stated anywhere public
- ✗Buyers who need a vendor compliance pack up front; no SOC 2 or ISO certification is published, which is a real gap for a product granted read access to production cloud estates
- ✗Small teams wanting self-serve signup and transparent pricing — every tier routes through a booked demo
- ✗Organisations looking for runtime threat detection or incident response; this is design-time and posture tooling, not a SIEM or full CNAPP replacement
Deployment
Market Analysis
Pros
- ✓Attacks a genuine gap — architecture review is normally documents and diagrams disconnected from what actually ships
- ✓Generates the Infrastructure as Code and then continuously conformance-checks against the same approved design, so the loop closes
- ✓The MCP server puts cloud security findings where engineers already work instead of behind yet another dashboard
- ✓SSO, SCIM and full tenant isolation are included on the entry tier rather than held back as an enterprise upsell
- ✓Founding team carries relevant security engineering backgrounds from IBM, Amazon and the Royal Netherlands Navy
Cons
- ✗There is no independent practitioner signal at all as of September 2026 — no Hacker News discussion, no G2, Capterra or TrustRadius listing, and no public user reviews — so every capability claim rests on the vendor's own material and launch coverage
- ✗Pre-seed stage with roughly $6.3M raised and about 45 staff, and generally available only since July 2026, which is thin backing for a control point that reads production cloud estates
- ✗No pricing is published on any tier; the plans page lists quotas but no prices, and the only route forward is booking a demo
- ✗Architecture generation is metered by a token allowance, so a team that iterates heavily on designs can hit a limit it cannot cost in advance
- ✗No SOC 2 or ISO certification is published, which is a conspicuous omission for a security vendor selling into regulated financial services
- ✗Public material names only AWS and Azure; there is no stated Google Cloud coverage, so multi-cloud estates are only partly served
Pricing
Essential
Contact for pricing
- ✓5 subscriptions or accounts
- ✓2.5k resources
- ✓Generate architectures (50M tokens)
- ✓Live architecture canvas
- ✓Insights across Well-Architected pillars
- ✓Full isolation, SSO and SCIM
Advanced
Contact for pricing
- ✓50 subscriptions or accounts
- ✓30k resources
- ✓Advanced customer support
- ✓Early access to WebGPU canvas
- ✓All Essential features
Elite
Contact for pricing
- ✓100 subscriptions or accounts
- ✓60k resources
- ✓Newest models
- ✓Preview new features
- ✓Elite customer support
- ✓All Essential features
No prices are published on any tier. The three plans are differentiated by connected Azure subscriptions or AWS accounts (5 / 50 / 100), resource count (2.5k / 30k / 60k) and support level, with a 50M-token allowance for architecture generation on the entry tier; SSO, SCIM and full isolation are included from Essential rather than gated behind Elite. Every tier routes through a booked demo, so cost cannot be benchmarked before a sales conversation, and heavy design iteration may hit the token allowance.
Security & Compliance
Connect
Sources
This page was written from 8 sources, 6 on domains other than dawnguard.ai.
- 1.dawnguard.ai — dawnguard.aivendor
- 2.dawnguard.ai — plansvendor
- 3.engtechnica.com — dawnguard launches cloud security architecture platform
- 4.helpnetsecurity.com — dawnguard security architecture automation platform
- 5.thesaasnews.com — dawnguard raises 3 4m pre seed
- 6.mcpservers.org — dawnguard mcp
- 7.startuphub.ai — dawnguard automates secure cloud design
- 8.linkedin.com — dawnguard
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
DeepKeep
AI security platform covering red teaming, an AI firewall, agent attack-surface scanning and runtime controls for coding agents
Armadin
Autonomous offensive security: AI agent swarms that chain your weak spots into proven attack paths before an attacker does
WitnessAI
Network-layer AI security and governance for employee AI use, models, apps and agents
Ascerta
Enterprise AI management: measure the ROI, cost and adoption of every AI initiative, agent and coding tool