Blast Security's $10 Million Seed Funds a Compiler for Cloud Guardrails

The Israeli startup, founded by Solebit veterans, aims to shift enterprise security from alert triage to continuous prevention.

About Blast Security

Published

In the crowded landscape of cloud security, the most common patient symptom is not a breach, but fatigue. Security teams are inundated with thousands of alerts, a reactive workflow that treats symptoms after the environment is already sick. The bet from Tel Aviv-based Blast Security is that the entire model is backwards. Instead of detecting misconfigurations and vulnerabilities, its platform attempts to write a prescription of preventive guardrails before a single line of code is deployed [Blast Security].

Founded in 2024 and emerging from stealth this year with a $10 million seed round, the company is pitching a preemptive defense fabric that integrates directly with cloud controls [PR Newswire, Feb 2025]. The founding team, veterans of the acquired cybersecurity firm Solebit, are translating their experience in threat prevention into a new architectural approach for global enterprises.

The Preventive Compiler

At the core of Blast's platform is what it calls an "innovative compiler" [Startup Nation Finder]. The system is designed to ingest an organization's security policies and compliance requirements, then translate them into environment-specific guardrails that are enforced across cloud accounts, subscriptions, and projects. The platform integrates with major infrastructure like AWS, Azure, Google Cloud, and Kubernetes, as well as CI/CD pipelines, aiming to model and test every change before it reaches production [Perplexity Sonar Pro Brief].

The claimed outcome is a shift from noise to prevention. Early customer engagements, according to the company, have resulted in "preventing cloud risk by over 90% and significantly shrinking the blast radius" [PR Newswire, Feb 2025]. The platform's continuous environment learning component is meant to validate that these guardrails remain effective as the business evolves [Startup Nation Finder].

A Team Built on a Prior Exit

The credibility of this technical bet leans heavily on the founders' track record. The trio of Boris Vaynberg (CEO), Ido Bukra, and Roi Panai previously built Solebit, a machine learning-based threat prevention company acquired by Mimecast in 2018 for approximately $88 million in cash [PR Newswire, Feb 2025]. Their backgrounds also include service in elite Israeli Defense Force units [Pulse 2.0].

Founder Role Key Background
Boris Vaynberg CEO Co-founded Solebit (acquired by Mimecast), former CTO at Venus Concept Inc.
Ido Bukra Co-Founder Cybersecurity expert with 10+ years in research and product; Solebit veteran.
Roi Panai Co-Founder & CTO Cybersecurity expert with 15 years in R&D leadership, specializing in preventative security.

The Crowded Clinic

Blast Security is not entering an empty waiting room. The cloud security and posture management market is densely populated with well-funded and established players.

  • Established CSPM Leaders. Companies like Wiz and Orca Security have defined the cloud-native application security platform (CNAPP) category.
  • Integrated Suite Players. Microsoft Defender for Cloud and CrowdStrike Falcon Cloud Security offer cloud security as part of broader, integrated platform suites.
  • Focused Challengers. Startups like Sweet Security and Lacework represent focused competitors attacking specific parts of the cloud security lifecycle.

Blast's answer to this crowd is its foundational premise: that prevention, not detection, is the necessary paradigm shift. The company is betting that enterprises, weary of alert fatigue, will prioritize a system designed to stop issues before they generate alerts [Morningstar, Nov 2025].

The Road to an A Round

The $10 million seed, co-led by investors 10D and MizMaa Ventures, provides runway to refine the product and pursue those early enterprise logos [PR Newswire, Feb 2025]. The next twelve months will be critical for Blast to convert its initial engagements into referenceable, named customer case studies.

For the security teams at global enterprises, the standard of care today is largely reactive. It involves deploying multiple scanning tools, managing a constant stream of alerts, and conducting manual remediation. Blast Security's intervention proposes a different clinical pathway: encoding security into the infrastructure itself, aiming for a state of continuous compliance where the blast radius of any potential incident is minimized by design.

Read on Startuply.vc