L

Lema

by Lema (Lema Labs)

Governance & SecurityAI Agents & OrchestrationEnterprise Platform

Agentic third-party risk management — treat vendor risk as a security problem, not a checklist

Contact for pricing·Added Sep 3, 2026·Updated Sep 3, 2026
Share:
THE DAILY BRIEF
Lema

by Lema (Lema Labs)

Governance & SecurityAI Agents & OrchestrationEnterprise Platform

Agentic third-party risk management — treat vendor risk as a security problem, not a checklist

Contact for pricing

Lema is an agentic third-party risk management platform for enterprise security and vendor-risk teams that have outgrown annual questionnaires and spreadsheets. It runs an AI agent that behaves like a vulnerability researcher against each vendor, continuously tracking what that vendor can reach inside your environment and modelling how a compromise there would actually reach your business.

At a Glance

Category
Governance & Security
Pricing
Contact for pricing
Target Market
CISOs, CIOs, Third-Party Risk Managers, Security Operations Teams, GRC Teams, Procurement Leaders
Deployment
Cloud-first
Founded
2023
Headquarters
Tel Aviv, Israel
Team Size
11-50

Key Features

  • Forensic AI assessment
  • Open-source reconnaissance
  • Blast radius monitoring
  • Exposure path analysis
  • Sub-five-minute vendor assessment
  • Continuous rather than point-in-time review

Capabilities

text generation
image generation
video generation
code generation
workflow automation
api access
audio generation
fine tuning
agent orchestration

Use Cases

  • Fast-track vendor onboarding
  • Detecting permission scope drift
  • Prioritising a vendor breach notification
  • Replacing spreadsheet-based TPRM at scale
  • Validating vendor security claims

Ideal For

Best For

  • Replacing annual security questionnaires with continuous, evidence-backed monitoring of what vendors can actually access
  • Onboarding new vendors quickly under a security review rather than a compliance checklist — Lema claims assessment in under five minutes
  • Detecting scope drift when an existing vendor's permissions or data access quietly expand beyond what was originally approved
  • Modelling concrete exposure paths so a vendor finding can be prioritised by business impact instead of a generic risk score
  • Scaling a small TPRM function across a large vendor estate in regulated sectors such as financial services and healthcare

Not Ideal For

  • Organisations whose real requirement is audit evidence for a specific framework — Lema is explicitly positioned against the checklist model, so a compliance-attestation workflow is not the point of the product
  • Companies with a small, stable vendor list where a security team already reviews each supplier directly and continuous monitoring adds cost without adding signal
  • Buyers who need published pricing or a self-serve evaluation: the vendor has no pricing page and no trial, so every engagement starts with sales
  • Teams that cannot grant deep visibility into identity, permissions and data flows, which the blast-radius and exposure-path features depend on to produce anything better than a scorecard

Market Analysis

Enterprise-gradeSecurity-firstVenture-backed

Pros

  • Named enterprise logos published on the vendor's own site — Klaviyo, AlphaSense, Cresta, Well Health, OPENLANE, SCI and Delta Dental — rather than an anonymous Fortune 500 claim
  • Strong domain pedigree: three Unit 8200 alumni, two of whom built and exited Noname Security to Akamai, applied to a problem that is genuinely a security problem
  • Attacks a well-evidenced gap — Team8's investment note cites roughly 60% of companies depending on 1,000+ third parties while McKinsey attributes nearly a third of recent breaches to them
  • Continuous monitoring plus onboarding assessment in one product addresses the specific failure mode of annual questionnaire-based TPRM, where a profile is stale the day it is filed

Cons

  • No independent user reviews anywhere — no G2, Capterra, TrustRadius or PeerSpot listing was found, and a Hacker News Algolia query for the company returns zero results, so nobody has publicly described the deployment experience
  • The 'assess a vendor in under five minutes' figure is entirely vendor-reported and has not been independently tested; press coverage repeats it without validation
  • No published pricing, no trial and no disclosed compliance certifications (SOC 2, ISO 27001) — a notable gap for a security vendor asking for deep visibility into identity and data flows at regulated buyers
  • Displacing an incumbent TPRM or GRC suite is a rip-and-replace decision at most enterprises; run alongside an existing platform it becomes an additional line item rather than a saving
  • Small and young — roughly 35 employees, out of stealth only since February 2026 — so support depth and roadmap durability are unproven at Fortune 500 scale
  • Public sources disagree on the founding year (SecurityWeek reports 2023, the vendor's own site says 2024), a small but real signal that published details are not tightly controlled

Pricing

Enterprise

Contact for pricing

  • Forensic AI vendor assessment and open-source reconnaissance
  • Continuous blast radius monitoring of vendor access
  • Exposure path analysis with remediation recommendations
  • Continuous monitoring across the full vendor portfolio

No pricing is published — the vendor's /pricing path returns a 404 and no plan tiers, per-vendor rate or platform fee appears anywhere in the launch coverage, so cost cannot be estimated before a sales conversation. Given the positioning at Fortune 500 financial services and healthcare buyers with very large vendor portfolios, expect enterprise-scale annual contracts most likely metered on the number of monitored third parties. Budget separately for the integration work: the blast-radius and exposure-path features need visibility into identity, permissions and data flows, which is a heavier lift than the questionnaire tools this replaces.

Security & Compliance

soc2
gdpr
hipaa
iso27001
sso
data residency

THE DAILY BRIEF

Enterprise AI insights for technology and business leaders, twice weekly.

beri.net

Subscribe at beri.net/subscribe for twice-weekly AI insights delivered to your inbox.

LinkedIn: linkedin.com/in/rberi  |  X: x.com/rajeshberi

© 2026 Rajesh Beri. All rights reserved.

Lema is an agentic third-party risk management platform for enterprise security and vendor-risk teams that have outgrown annual questionnaires and spreadsheets. It runs an AI agent that behaves like a vulnerability researcher against each vendor, continuously tracking what that vendor can reach inside your environment and modelling how a compromise there would actually reach your business.

Lema is an agentic third-party risk management platform that treats vendor risk as a security problem rather than a compliance exercise. The company emerged from stealth in February 2026 with $24 million in total funding — a $17.5 million Series A led by Team8 on top of a roughly $6.5 million seed led by F2 Venture Capital with Salesforce Ventures participating. Its three founders, Eddie Dovzhik (chief executive), Omer Yehudai (chief product officer) and Tomer Roizman (chief technology officer), served together in Israel's Unit 8200, and Dovzhik and Roizman previously worked at Noname Security before Akamai acquired it. Instead of mailing annual questionnaires and scoring the returned answers, Lema runs an AI agent trained to behave like a vulnerability researcher against each vendor. Forensic AI assessment reads vendor-supplied documents and artefacts to surface misclassified vulnerabilities and undisclosed capabilities; open-source reconnaissance sweeps publicly available information the vendor would rather not volunteer; blast radius monitoring tracks in real time what each vendor can actually reach inside the customer's environment, flagging scope drift, permission changes and unauthorised access; and exposure path analysis models how a compromise at that vendor would propagate into the business, with specific remediation recommendations attached. The company says a new vendor can be assessed in under five minutes, against hours of questionnaire review. It sits in a market where, per Team8's investment note, roughly 60% of companies depend on more than 1,000 third parties and McKinsey attributes nearly a third of recent breaches to them. Customers listed on Lema's own site include Klaviyo, AlphaSense, Cresta, OPENLANE and Delta Dental.

Ideal Buyer

The CISO or head of third-party risk at a regulated enterprise — financial services, healthcare, or a company with 1,000+ vendors — whose TPRM analysts spend their week chasing questionnaire responses that are stale the day they arrive.

Key Benefit

Vendor risk becomes evidence-backed and continuous: you see what each vendor can actually reach in your environment today, and the specific path by which a breach there would reach you.

At a Glance

Category
Governance & Security
Pricing
Contact for pricing
Target Market
CISOs, CIOs, Third-Party Risk Managers, Security Operations Teams, GRC Teams, Procurement Leaders
Deployment
Cloud-first
Founded
2023
Headquarters
Tel Aviv, Israel
Team Size
11-50

Key Features

  • Forensic AI assessment

    Reads vendor-supplied documents and artefacts to surface misclassified vulnerabilities and undisclosed capabilities the vendor did not volunteer in its questionnaire.

  • Open-source reconnaissance

    Sweeps publicly available information about each vendor to surface security issues the vendor would prefer to keep out of its own disclosures.

  • Blast radius monitoring

    Tracks in real time which of your critical assets each vendor can reach, flagging scope drift, permission changes and unauthorised access as they happen.

  • Exposure path analysis

    Models how a compromise at a given vendor would actually propagate into your business, then recommends the specific remediation that breaks the path.

  • Sub-five-minute vendor assessment

    Produces an initial risk profile for a new vendor in under five minutes, replacing the hours normally spent reviewing a returned questionnaire.

  • Continuous rather than point-in-time review

    Combines the one-time onboarding assessment with ongoing monitoring, so a vendor's risk profile does not go stale between annual review cycles.

Capabilities

text generation
image generation
video generation
code generation
workflow automation
api access
audio generation
fine tuning
agent orchestration

Use Cases

  • Fast-track vendor onboarding

    Procurement needs a new SaaS supplier approved this week; the platform produces an evidence-backed risk profile in minutes rather than a multi-week questionnaire round trip.

  • Detecting permission scope drift

    An integrated vendor's OAuth scope quietly widens after a product update; blast radius monitoring flags the change against what was originally approved.

  • Prioritising a vendor breach notification

    When a supplier discloses an incident, exposure path analysis shows whether that vendor could actually reach your sensitive assets and what to remediate first.

  • Replacing spreadsheet-based TPRM at scale

    A security team responsible for over a thousand suppliers moves off spreadsheets and annual questionnaires onto continuous monitoring without adding analyst headcount.

  • Validating vendor security claims

    Forensic assessment and open-source recon cross-check what a vendor asserted in its documentation against what is externally observable about its actual posture.

Ideal For

Best For

  • Replacing annual security questionnaires with continuous, evidence-backed monitoring of what vendors can actually access
  • Onboarding new vendors quickly under a security review rather than a compliance checklist — Lema claims assessment in under five minutes
  • Detecting scope drift when an existing vendor's permissions or data access quietly expand beyond what was originally approved
  • Modelling concrete exposure paths so a vendor finding can be prioritised by business impact instead of a generic risk score
  • Scaling a small TPRM function across a large vendor estate in regulated sectors such as financial services and healthcare

Not Ideal For

  • Organisations whose real requirement is audit evidence for a specific framework — Lema is explicitly positioned against the checklist model, so a compliance-attestation workflow is not the point of the product
  • Companies with a small, stable vendor list where a security team already reviews each supplier directly and continuous monitoring adds cost without adding signal
  • Buyers who need published pricing or a self-serve evaluation: the vendor has no pricing page and no trial, so every engagement starts with sales
  • Teams that cannot grant deep visibility into identity, permissions and data flows, which the blast-radius and exposure-path features depend on to produce anything better than a scorecard

Deployment

On-Premise

Market Analysis

Enterprise-gradeSecurity-firstVenture-backed

Pros

  • Named enterprise logos published on the vendor's own site — Klaviyo, AlphaSense, Cresta, Well Health, OPENLANE, SCI and Delta Dental — rather than an anonymous Fortune 500 claim
  • Strong domain pedigree: three Unit 8200 alumni, two of whom built and exited Noname Security to Akamai, applied to a problem that is genuinely a security problem
  • Attacks a well-evidenced gap — Team8's investment note cites roughly 60% of companies depending on 1,000+ third parties while McKinsey attributes nearly a third of recent breaches to them
  • Continuous monitoring plus onboarding assessment in one product addresses the specific failure mode of annual questionnaire-based TPRM, where a profile is stale the day it is filed

Cons

  • No independent user reviews anywhere — no G2, Capterra, TrustRadius or PeerSpot listing was found, and a Hacker News Algolia query for the company returns zero results, so nobody has publicly described the deployment experience
  • The 'assess a vendor in under five minutes' figure is entirely vendor-reported and has not been independently tested; press coverage repeats it without validation
  • No published pricing, no trial and no disclosed compliance certifications (SOC 2, ISO 27001) — a notable gap for a security vendor asking for deep visibility into identity and data flows at regulated buyers
  • Displacing an incumbent TPRM or GRC suite is a rip-and-replace decision at most enterprises; run alongside an existing platform it becomes an additional line item rather than a saving
  • Small and young — roughly 35 employees, out of stealth only since February 2026 — so support depth and roadmap durability are unproven at Fortune 500 scale
  • Public sources disagree on the founding year (SecurityWeek reports 2023, the vendor's own site says 2024), a small but real signal that published details are not tightly controlled

Pricing

Enterprise

Contact for pricing

  • Forensic AI vendor assessment and open-source reconnaissance
  • Continuous blast radius monitoring of vendor access
  • Exposure path analysis with remediation recommendations
  • Continuous monitoring across the full vendor portfolio

No pricing is published — the vendor's /pricing path returns a 404 and no plan tiers, per-vendor rate or platform fee appears anywhere in the launch coverage, so cost cannot be estimated before a sales conversation. Given the positioning at Fortune 500 financial services and healthcare buyers with very large vendor portfolios, expect enterprise-scale annual contracts most likely metered on the number of monitored third parties. Budget separately for the integration work: the blast-radius and exposure-path features need visibility into identity, permissions and data flows, which is a heavier lift than the questionnaire tools this replaces.

Security & Compliance

soc2
gdpr
hipaa
iso27001
sso
data residency

Sources

This page was written from 5 sources, 4 on domains other than lema.ai.

  1. 1.lema.ailema.aivendor
  2. 2.securityweek.comlema ai emerges from stealth with 24 million to tackle third
  3. 3.calcalistech.comsyk3dddpzx
  4. 4.team8.vcfrom checklists to continuous assurance why we invested in l
  5. 5.fintech.globalsupply chain security start up lema ai bags 24m
Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe