Agentic AI
,
Artificial Intelligence & Machine Learning
,
Endpoint Security
Nir Zuk’s Startup Targets Firms Unable to Send Sensitive Security Data to the Cloud
A startup led by the founder of Palo Alto Networks raised $245 million to build an autonomous, vertically integrated cybersecurity system that operates on premises.
See Also: Why Traditional DLP Can’t Keep Up With AI Data Growth
The convertible note from Lightspeed Venture Partners, Picture Capital and Redpoint Ventures will help Cylake build the hardware, storage, software, data infrastructure, cybersecurity capabilities and artificial intelligence capabilities needed to operate locally, said Chief Marketing Officer René Bonvanie. Cylake will serve organizations that can’t allow their security infrastructure or sensitive data to depend on an external cloud provider.
“We raised $45 million in March to demonstrate that we are serious about this to candidates, to the market, to our design partners,” Bonvanie told ISMG. “We are raising $245 million dollars now to show how serious we are on getting this product in the hands of our beta testers in December and of our customers mid next year. So, that’s why we need the money, and that’s why we need it now.”
Cylake, founded in 2026, employs 31 people and has raised $290 million, having previously completed a seed round led by Greylock Partners. The company has been led since its inception by Nir Zuk, who founded Palo Alto Networks in 2005 and served as its chief technology officer and a board member until August 2025 (see: Nir Zuk: Google’s Multi-Cloud Security Strategy Won’t Work).
Why Highly Regulated Firms Need On-Premises Security Systems
Highly regulated and security-sensitive enterprises may be unable or unwilling to send information outside their own infrastructure, but Bonvanie said modern cybersecurity vendors have largely stopped building for those customers. As a result, they’ve had to continue operating older on-premises products from Splunk, McAfee and Symantec or assemble their own systems from open-source components.
“Think of critical infrastructure, financial services companies, government agencies, where there’s just not an option to have components of their cybersecurity infrastructure be hosted in the cloud or be delivered from the cloud,” Bonvanie said. “These systems are oftentimes air gapped or completely isolated, and for those organizations, there really isn’t anything modern in the market.”
Regulations can prohibit organizations from moving particular information outside a jurisdiction, such as banking regulations that require data associated with Swiss operations to remain in Switzerland. He said such requirements complicate the use of security products that depend on cloud storage, cloud analytics or public AI models. For CISOs, the question therefore extends beyond security architecture, Bonvanie said.
“I’m not interested in companies that are perfectly fine with shipping their data to Anthropic or to Google,” Bonvanie said. “I am going to focus on organizations that do not want that, that cannot do that, but are in a type of business or in a type of mindset where they will not allow that to happen.”
Hardware became necessary once Cylake determined that its system had to operate independently of cloud infrastructure while handling enormous volumes of security data, Bonvanie said. Owning the hardware also gives Cylake greater control over cost and capacity. Customers can run AI models and store security data locally without incurring separate cloud storage charges or token-based AI costs.
“We didn’t come from the perspective that we wanted to build hardware and find a purpose for it,” Bonvanie said. “We wanted to build a system that could work on all of an organization’s data, a system that was not dependent on the cloud and it turns out the only way you can do that is when you also build the hardware.”
What Cylake Plans to Include in Its Security Portfolio
Cylake plans to create a common ingestion pipeline feeding a locally operated data lake, with the infrastructure collecting, storing, managing and archiving information from endpoints, servers, internet of things devices and third-party security products. The objective is to let operators analyze security activity across the organization’s complete dataset rather than repeatedly moving between isolated tools.
“Our motivation was to build an amazing cybersecurity system that was working on all of a customer’s data, not 30 puddles of data across 30 different tools for which you pay with 30 different bills,” Bonvanie said. “We wanted one system with one ingestion pipeline where I can look at all data from anything in the infrastructure, and it turns out that this can only be done on hardware.”
Cylake intends to provide endpoint, data, IoT, identity and browser security itself and replace many of the point products customers use today, Bonvanie said. Third-party telemetry will therefore remain available to the system while an increasing proportion of the information becomes what Bonvanie described as “firsthand” telemetry generated by Cylake’s own technologies.
“We will ingest all the telemetry at first- and third-hand, as we call it, and over time, more and more of that is becoming firsthand because we will provide those capabilities,” Bonvanie said. “Our customers can put anything in our data lake that they desire.”
AI can help security operators probe an incident, but Cylake can’t simply send customer information to public AI providers since doing so would undermine the sovereign and autonomous model at the center of its product. The company therefore needs AI capabilities that run inside its own system, potentially combining open-source models with technology Cylake develops or adapts for enterprise use, he said.
“I cannot rely on Anthropic or OpenAI models because that would mean I would have to rent from those guys,” Bonvanie said. “So, we need to build those capabilities into the system, and we need to make choices on what kind of models we are going to incorporate.”
