Aim Security

Researched 2026-06-28; re-verified 2026-07-27. Primary category: ai-runtime-security. Acquired by cato-networks — deal closed 2025-09-03. Brand retired: aim.security now 301-redirects to catonetworks.com. The shopping unit is Cato AI Security, not Aim.

One-liner — An enterprise AI-security pure-play (AI firewall + shadow-AI control + AI-SPM) bought by SASE vendor cato-networks in its first-ever acquisition, now fully absorbed and sold as Cato AI Security.

What it does

Aim secures enterprise AI across three jobs: (1) securing employee use of public AI apps — shadow-AI discovery and policy (CASB-for-AI / ai-access-governance); (2) protecting private AI apps and agents via an inline AI Firewall that screens prompts/responses for prompt injection, data leakage and abuse (ai-runtime-security); and (3) securing the AI development lifecycle via AI Security Posture Management — discovering and governing the AI assets an org builds (ai-spm). It targeted Fortune 500 / Global 2000 buyers. Aim’s research team is also known publicly for AI vulnerability discovery (e.g., “EchoLeak”-class agent/Copilot exploits).

Where it sits in the stack

Primary ai-runtime-security (the AI firewall) with a secondary ai-spm tag (posture management); also overlaps ai-access-governance (shadow AI). Layer: model-prompt. Lethal-trifecta role: covers all three legs — untrusted input (prompt-injection defense), sensitive data (DLP on AI traffic), egress (governing what leaves to public AI). Sits at the green↔red boundary.

Deployment & architecture

SaaS with API and inline deployment in front of AI apps/agents. As of 2026-03-17 the integration is done: Aim’s inspection runs natively inside the cato-networks SASE Platform on Cato Neural Edge, a GPU-accelerated (NVIDIA) inspection layer deployed across Cato’s private backbone, so AI controls ride the same inline path as SD-WAN/SSE rather than as a standalone proxy. Standalone-Aim deployments were offered a migration path. Integrations: IdP, SIEM, the enterprise’s AI gateways and SaaS estate.

Positioning & differentiators

Aim covered the full enterprise-AI-security span (shadow AI + runtime firewall + AI-SPM) in one product rather than picking a single slice — that breadth is part of why a SASE vendor bought it to instantly fill its AI-security line. Founded by Unit 8200 veterans, backed by YL Ventures and Canaan Partners.

Post-acquisition (verified 2026-07-27): the three-leg product structure survived the absorption but the name did not. Cato sells it as Cato AI Security (AISEC) with the legs renamed: AI Security for End Users (shadow-AI discovery and policy on public GenAI), AI Security for Applications (Aim’s AI Firewall — prompt injection, data leakage, runtime attacks against private AI apps/agents), Agentic AI Security (visibility and logging of agent↔model↔MCP-server interactions, tool calls, APIs), and AI-SPM (posture, tested against EU AI Act and ISO 42001). The differentiator is no longer “best-of-breed AI-security pure-play” but “AI security you don’t deploy separately because it’s already in the SASE path you bought” — which is a platform argument, and only compelling if you are already buying Cato.

Nearest neighbors: witnessai, prompt-security, lakera, calypsoai, prisma-airs, harmonic-security, zenity.

Ownership, funding & M&A

Founded 2022 (HQ Tel Aviv, US presence in New York) by Unit 8200 veterans (Matan Getz, CEO; Adir Gruss, CTO). VC-backed by YL Ventures and Canaan Partners (~$28M raised across seed + Series A pre-acquisition; exact total not itemized in sources — noted as unknown-precise). Acquired by cato-networks — announced and closed 2025-09-03; value not officially disclosed, press reports ~$350M (some reports $350–400M). This is Cato’s first acquisition. Confidence: high.

Why closed, not pending (re-checked 2026-07-27): Cato’s press release is written entirely in the past tense with no “definitive agreement,” no expected-close window and no regulatory condition, and it told existing Aim customers they could deploy “today” — a post-close integration plan. Same-day independent coverage (SecurityWeek, CyberScoop, SiliconANGLE, Help Net Security) reported it as done. There is no separate completion announcement, which is normal for a private cash-and-stock deal of this size. Corroborating behavioural evidence: the entire aim.security domain 301-redirects to Cato’s homepage, and Cato’s AI-security product pages carry no Aim branding at all.

CTO / hedge-fund lens

Day-1 control type (AI firewall + shadow-AI), but you cannot buy Aim — as of 2026-07-27 the only way to get this technology is as Cato AI Security on the cato-networks SASE Platform. That makes it a SASE-platform decision, not an AI-security decision: relevant if you are already on Cato or actively choosing a SASE vendor, and a competitive comparison point otherwise. Do not shortlist “Aim Security” — the name is retired and any vendor list still carrying it is stale. Indirect SR 11-7 relevance (control point, plus AI-asset inventory from AI-SPM has mild model-governance value; the AI-SPM leg now advertises EU AI Act / ISO 42001 testing, which is compliance-adjacent but not model-risk management).

Competitors / alternatives

witnessai, prompt-security, lakera, calypsoai, prisma-airs, cisco-ai-defense, harmonic-security, zenity.

Open questions / to verify

  • Precise total funding (sources cite YL Ventures/Canaan backing; figure ~$28M approximate).
  • Official deal value — still not disclosed by Cato as of 2026-07-27; press estimates range ~$350M (Calcalist) to $350–400M. Left null in frontmatter rather than guessed.
  • Whether the Aim brand survives inside Cato or is fully absorbed. Resolved 2026-07-27: fully absorbed, brand retired.
  • Whether Cato AI Security is separately licensable/priced or bundled into SASE tiers — Cato does not publish pricing; unverified.
  • Whether Aim’s founders (Matan Getz, Adir Gruss) are still at Cato — not confirmed either way.

Sources

History

  • [2026-06-28] Stub created from seed registry.
  • [2026-06-28] Researched; confirmed acquired by cato-networks (announced 2025-09-03, ~$350M reported, Cato’s first acquisition). Seed flag verified. Filled founding (2022), Tel Aviv HQ, YL/Canaan backing, three-part product. Confidence raised to high.
  • [2026-07-27] URL audit found www.aim.security 301-redirects to catonetworks.com with zero Aim branding. Re-researched: the acquisition closed 2025-09-03 (same day as announced — Cato’s PR is past-tense with no definitive-agreement or pending-close language; same-day independent coverage reports it as done; no separate completion announcement exists). ownership_state acquired-pending → acquired-closed; verify_after cleared; acquisition.closed set to 2025-09-03. Aim brand retired — the site folded wholesale into Cato Networks and the technology is now GA as Cato AI Security (launched 2026-03-17, running on the GPU-accelerated Cato Neural Edge inspection layer). website repointed from aim.security to Cato’s AI Security (AISEC) product hub; aka gained “Cato AI Security”. Price remains officially undisclosed → null.