.png)
Aryon: Building the Proactive Cloud Security Policy Enforcement Platform
At Brightmind, we spend a significant time studying the intersection of AI and cybersecurity, and we aim to back deeply technical founders who see the structural shifts of AI on the modern security stack before they occur. Over the past year, one theme has become increasingly obvious to us: policy enforcement is becoming more imperative than ever.
We regularly speak with CISOs, cloud security leaders, and practitioners responsible for securing large-scale cloud environments. The feedback is remarkably consistent. Infrastructure is changing faster than security teams can keep up. AI-generated code, infrastructure automation, and increasingly capable offensive AI systems are accelerating the pace at which vulnerabilities are introduced into production environments. Vulnerability discovery and exploit generation are moving at machine-speed, while patching and remediation still operate at human-speed.
The next generation of cloud security cannot simply detect misconfigurations after deployment, it must prevent misconfigurations before they happen. Historically though, anyone who has worked in cloud infrastructure could tell you that prevention is far easier said than done. Enforcing preventative policies has been a technical challenge because native cloud tools are often hard to configure, risky to enforce, brittle in production, or easily bypassed.In practice, many organizations either disable enforcement or limit it to a narrow subset of policies.
We believe this gap between security policy and actual enforcement is becoming one of the most important problems in modern cloud security to keep up with the Mythos Era.
Aryon recognized this gap earlier than almost anyone we’ve met.
That is why we are leading Aryon’s $29 million Series A. Brightmind is excited to join Ron, Ariel,Yair, and the entire Aryon team’s journey alongside participation from Datadog Ventures and Skinos Ventures. Aryon’s Series A financing will bring their total funding to $38 million, and will bring in support from many prominent angels and serial entrepreneurs close to the Brightmind ecosystem, including George Kurtz, CEO of Crowdstrike; Yevgeny Dibrov, CEO of Armis; and Nadir Izrael, CTO of Armis.
ConvictionThrough a Long Relationship & Hands-On Testing
One nuance that makes our relationship with Aryon so unique is its length and depth. We first met Aryon’s founding team in January 2025, long before the company even had a website, a product launch, or a public presence. Over the past 15 months, we have been incredibly impressed over more than a dozen meetings, significant in-person time, technical testing of Aryon’s product, and watching their company evolve from an ambitious vision into a rapidly growing company, with enterprise customers in highly-regulated industries across healthcare, banking, insurance, and telecom.
However, as technologists-first at Brightmind, it was Aryon’s willingness to allow Brightmind to directly test and deploy its product into Brightmind’s own testing lab and evaluate the product firsthand that got us to an emphatic, “we must invest!”
Over multiple months of hands-on testing, we watched as Aryon’s platform vision expanded from Azure, to AWS, and now GCP coverage. We discussed their long-term vision of expanding from preventative, proactive policy enforcement in the cloud to becoming a fully-fledged Policy Enforcement OS Engine across AI, SaaS, M365,Identity, and Data Security. We saw how the current platform behaved in practice: could it safely enforce policies? Would it decrease operational friction? Could it realistically become part of an enterprise governance workflow?
The answers were all yes.
The result was one of our highest-conviction investments at Brightmind.
Founder-Market Fit Is Exceptional
Additionally, it is hard to imagine a better team to solve this specific problem. CEO Ron Arbel, CTO Ariel Litmanovich, and CPOYair Ladizhensky spent years securing some of the most complex cloud environments in the world as members of Matzov, the IDF’s elite cybersecurity technology unit.
Their experiences working on Project Nimbus gave them a deep understanding of how cloud control planes operate and exposed them to a recurring reality: organizations frequently know what policies they want to enforce but lack reliable mechanisms to enforce them safely. That insight became the foundation for Aryon.
And what impressed usmost over the past 15 months was not simply the founders’ technical expertise.It was their consistency.
Every major product milestone they committed to, they delivered. The team repeatedly demonstrated an ability to execute against ambitious goals while maintaining product quality and customer trust.
Overall, Ron brings unusual clarity and commercial intuition. Ariel possesses rare technical depth around cloud architecture and enforcement. Yair combines deep product instincts with operational rigor. Together, they form one of the strongest founder teams we have encountered in policy enforcement.
We Are Excited
We are incredibly grateful to Ron, Ariel, Yair, and the entire Aryon team for allowing us to be part of this journey. We have spent more than a year getting to know them, learning alongside them, and watching them execute.
We believe policy creation and policy enforcement will emerge as foundational security capabilities across cloud environments, identity systems, SaaS platforms, and enterprise infrastructure broadly.
We could not be more excited to support Aryon.
Let's Secure Tomorrow, Together.
We're always looking for the next generation of cybersecurity innovators. Reach out to our team to start the conversation.
Other Articles
Why We Invested in Empirical: Building Global and Local AI Models for Cybersecurity
Empirical Security is building domain-specific AI models for cybersecurity, founded on the belief that the next generation of security is not a faster scanner or a better dashboard but a security intelligence layer combining global threat intelligence with local, customer-specific environment context. The platform operates through two concentric layers: a Global AI Model, a continuously updating probabilistic scoring model trained on years of curated, globally-pooled data with scores recomputing daily, and per-tenant Local Models, custom enterprise-specific cybersecurity domain models trained on each customer's own telemetry, assets, and controls, which constitute the company's real moat. The first applied use case is exploitation prioritization, answering not just what is vulnerable but what is exploitable in a specific environment right now, extending beyond CVE-based scoring into cloud misconfigurations and application security findings. The founding team invented risk-based vulnerability management and EPSS itself: CTO Michael Roytman is an original EPSS author, Chief Data Scientist Jay Jacobs co-chairs the EPSS Special Interest Group at FIRST, and Ed Bellis co-founded Kenna Security, serving as CTO through Cisco's 2021 acquisition after six years as CISO of Orbitz. EPSS is now integrated into over 120 security platforms and was explicitly endorsed by Anthropic in its April 2026 guidance for AI-accelerated vulnerability discovery, the first time a major LLM provider has backed a purpose-built cybersecurity prioritization model. Brightmind Partners is leading Empirical's $25 million Series A alongside Costanoa Ventures, Hyde Park Angels, and angel investors from across the security ecosystem, bringing total funding to $37 million.
Pi: Building Zero Recurrence Code Security for the AI CodeGen Era
Pi Security is defining a new category, Zero Recurrence Code Security, built on the premise that the industry no longer has a vulnerability discovery problem but a vulnerability recurrence problem. Rather than generating more findings, Pi learns how an organization builds, breaks, fixes, and secures software, then turns that institutional security knowledge into preventative guardrails enforced across the software development lifecycle at design time, IDE time, and pull request time. The platform ingests context from prior incidents, tickets, pull requests, repositories, architecture decisions, and developer workflows to drive root cause analysis, variant discovery, contextual remediation, and ownership mapping, becoming a living security intelligence layer for developers, AI coding agents, and security teams. Founded by Guy Arazi, an offensive security operator and former CISO with roots at Palo Alto Networks and Microsoft, and Yonatan Ramon, who built safety-critical systems at Tesla, Pi raised a $35 million Series A alongside Third Point Ventures and angels including George Kurtz, Yevgeny Dibrov, and Nadir Izrael. Brightmind led Pi's Seed round in early 2025 and is continuing its support through the Series A.
