$51.5M Out of Stealth: The AI Hacker Changing Cybersecurity
Ida Geffen, CEO & Co-Founder of Novee, joins us to discuss emerging from stealth with $51.5M in funding and how Novee’s proprietary AI hacker is redefining offensive security. A continuously running AI pentesting agent that thinks like real attackers and exposes what traditional tools miss.
Transcript
Hey everyone, welcome back here to another Tech Trunk TV interview. I'm happy to be joined. Well, first timer on our show, new company coming outta stealth.
All exciting, exciting stuff. Say hello to Ido Geffen. Ido was with a company called Novi.
Ido. Welcome, welcome to Text Trunk tv. Thank you.
Very excited to be here, Ellen. So Ido, we're gonna talk about Novi, we're gonna talk about the stealth coming outta stealth announcement, but let's first talk about ido, tell our, tell our audience a little bit about you. Yeah, sure.
So, uh, my name is Ido. Uh, I'm the CEO and co-founder here at Novi. Uh, 20 years of experience in cyber.
Uh, for the last decade I've been in executive roles in three different cybersecurity startups, and before that I served for 10 years in the Israeli security agency, which is pretty much equivalent to the NSA, uh, mostly leading strategic cyber initiatives. Um, yeah, so this is a briefly about my background in cyber over the last 20 years. So were you in 8,200 or in the, uh, different agency?
Uh, different agency, but pretty much, uh, equivalent. Yeah, we work a lot with a 200. Got it, got it.
No, we've, well, you know, when you cover the cyber market, when 40% of all the cyber VC money is being poured into Israeli cyber startups, you get to know all the different, all the different players and places where, where they're coming from. Um, but you know that, that's a great thing. So this is your first startup that you founded though?
Yeah, it is. Yeah. I always like to ask this question of first time founders especially.
Yeah. 'cause you know, it, you don't wake up one day and say, yeah, I feel like starting a company today. You know, you, it's, you gotta kind of feel it in your, in your gut to, you gotta have that fire, that passion that you, this has to be done.
It, it needs to be done. It's gonna make the world better for you. What, what was that passion?
Eddo? Yeah. And what question?
So how many years? Uh, gone and er, my two other co-founders gone, by the way, was in eight 200, uh, and er is a program graduate. It was, uh, a team leader in my group in the Israeli security agency.
So the three of us are very good friends for a very long time, for more than 15 years. And we always played with this idea that we will, in the end, we will initiate a company together. And September last year, it was the first time that the Open AI released oh one, the first reasoning model.
And we are as a three geek guys, like just read all of the specification card of it and was pretty blown away about the capabilities and, and what we think that could be done with this type of, uh, new type of technology. And we started to connect to, to oh one, the, the, the model, uh, techni, uh, tools that are specifically in, uh, um, tools that we used in the past in order to hack into specific applications, adding our knowledge and techniques into prompts way and, and added in, uh, good. So that's, uh, like a knowledge base that we've added to it.
And we've witnessed that we are very, very quickly being able to do, uh, and find novel issues, novel vulnerabilities in applications, something that couldn't be done before in automatic way. And this is, was like our aha moment that non something fundamentally changed in the ability of, uh, on how to conduct the penetration testing. And this, the way we felt that this is our moment is there is a very unique technological shift that we have a very unique expertise and a very big pain that is just going to grow on the, the customer side.
The, because the, the, you know, there is much more code now that is generating by ai, much more applications and much more vulnerabilities that you cannot continue and just do it like, like penetration testing is being done today, only point in time in the manual way. Got it. You know, you know, I've been in security 25, 30 years.
When I first started, one of the companies I co-founded, we, we were, one of our products was Van Vulnerability assessment of management. And back then, look, it was, uh, it was difficult to get people to at least scan their networks once a year, let alone quarterly, monthly, weekly, continuously. You know, it to the idea of being able to do that or that you should do it even, you know, it was foreign, was foreign to most people.
Now, I remember when, uh, meta Exploit first came out, right? In HD war, I'm sure you've probably have heard of HD and, and everything. I know HD for a long time, and now we had the ability to do AppSec scanning, penetration testing.
But again, it was, it was a tool used by consultants. You would call in maybe a red team or, or something, right? Again, but once a year to pay, if you were a big PCI, you know, merchant maybe a little or more often, when do you think we, we cross the Rubicon from once a year or once a quarter to continuous testing?
To continuous security scanning? Yeah, so I, I think that, you know, what, what would happen until today is that you have a real technical barrier that you couldn't do this type of testing in continuous way. Um, and o one of the reasons that you asked also before, you know, when we started to initiate the company, so we spoke with different, uh, CISOs and, and security practitioners, and we got a lot of people that are saying to us, especially in organizations that store sensitive data, and they have, you know, that the, the, the product applications that they are developing is the core revenue making of, of the, of the company that they're telling us we want to, to do much faster, deeper, wider test.
And they told us, for example, that, um, that they want us to do it in, in a daily basis because the, the, the way that Code ships today is in continuous way, right? You have the CICD. So I think this is the right time for us to, that, to eliminate this pain currently, that really security practitioners need to choose between two bad options, continuous tools that works in continuous way, which is great, but provides very shallow insights and tons of false positives or manual penetration testing that provide novel insights.
Sometimes that is really just point in time. So at least from what we are feeling today from the market, there is a need and a lot of requests that even not doing the test only once in a month, but can you please connect to our CICD and then we will be able to test the Delta and every new release you will be able to do full blown penetration testing. So I think the, the time is now and, and, and the urgency is just getting bigger because today a developers, you know, utilizing more and more AI tools for developers and you ev even have vibe coding.
So it's just exploding the, the amount of application that, uh, enterprise today are generating. So I think that this is the right time for it. Agreed.
So I think it was just yesterday, YL Ventures, one of the first Israeli cyber venture funds pioneered that model, um, released their annual, uh, venture report on the state of Israeli Israeli cyber. You know, it was pretty eye-opening, right? The amount of money, the amount of companies, the amount of exits, serial founders, everything else.
But even in light of that, right? You guys are launching from stealth with a a really, I mean, a seed round. That's pretty remarkable.
Not the biggest ever. I I saw it. You know, they've, lately we've seen some crazy seed rounds, but tell us a little bit about, uh, your seed round here, Novi seed round.
Yeah, so first of all, we were lucky, um, because Ventures is one of our, it's, uh, the seed investor and also Cannan partner, uh, which is also invested in a lot of early stage, in early stage, either early cybersecurity startups like, uh, Snyk and others. Um, and the fact that we had such a great VC that have a very good experience on, you know, are we in product market fit and the fact that they've seen that how quickly we were able to generate revenue and dozens of customers and how quickly we're getting those, this is what, so the, the, it came from them, the, the fact that you should hire, you should raise now much more money in order to, you know, to, to take the advantage that you currently have and the, and the pain that is really, uh, vivid today in the market. So you raised the money and congratulations like a $51 million plus seed round, um, beyond it's a lot of money.
What does it mean in terms of accelerating product plans, accelerating go to market for Novi? Yeah, great question. So we understand that in order for us to be one or two, three steps before the bad guys, we need to build something unique with a real mode that it's hard to, for, for, you know, just, uh, you know, for any other attacking group to be in our level.
So the fact that we raised so much money gave us the ability to raise, uh, to, to attract the best talent in the world in cyber, but also in ai, we have PhDs in our team. We have the guy, the head of AI in our team. Dan Padnos was a VP of platform in AI 21.
So he literally built a model that tried to compete with JGPT for seven years. So this is what gave us the, the confidence that we don't just another wrapper on top of chair GPT, we are building our own po uh, model that is specialized in Bel. And we already, uh, seen some tremendous results even comparing to Gemini and Claude that for specific types of vulnerability, we already have 55% better results.
And so this type of money and, and the ability to move very fast and to really attract a very unique talent, uh, this is what we think, what give us a good confidence that we will be able to build something that is much, much better than all of the bad guys, uh, and their ability. So we will be faster, deeper, and wider on protecting, uh, our customer. You know, uh, this week actually the 15th, we have our Predict 2026 virtual event.
And, uh, we've got all of the FU analysts talking, but this is something we spoke about in the cyber session there, which is for 2026 and beyond, just using the frontier models by themselves is not enough to really do security. Right? Right.
Because you gotta remember that those front, those frontier models are as good as the, the information, the data they're trained on and they're trained on. They don't call 'em large language models for nothing, right? They're large models, but they're not that specialized, right?
Remember that 90% they estimate of all of the data that's digitized is behind firewalls, was not used by these large models to train. And so the future is, you want to call 'em small models, you wanna call 'em, uh, you know, vector databases that are in front, or we're Calling it purpose, purpose trained AI model. Okay.
Purpose trained AI models, right? That's, that's where the actions gonna be. No one's going to do highly specialized work just on a generic frontier model.
Agreed. Agreed. I, I definitely agree that a lot of the, the challenge also when you're building this type of model is exactly like you described, is ability to create a lot of synthetic data and simulate those type of attacks.
Um, and this is exactly what we are doing. And also those large language models as you described, there are good and in, in everything, right? On how to cook a, a dinner and, and how to answer early generic questions, but they're not specialized in taking forry knowledge on finding issues at, at, at, uh, at applications, or even more importantly, on how should one fix, mitigate or remediate security issues.
Sure. Um, yeah. So the, of the external context that they're missing, Agreed.
Um, let's talk about go to market a little bit. So how, how do people sign up for Novi? How do they get started?
What does the cost, you know, what, what's that all look like beyond, beyond the technology? Yeah, so starting us with us is, uh, I'm calling it, we have a pretty no-brainer, uh, proposal, meaning that you can just come to our website, Novi security, uh, book for a demo. And, and basically that's it.
I mean, after that signing an MDA and we can start a POV and out of the unique proposal that we're saying to people, at least now that we are in the early stages, is you are already paying for penetration testing. You already have budget for it. We are the best penetration testing company in the world.
Um, so we can do it. We, you can replace this budget with us. And by the way, we also can replace your dynamic application security testing, the DAF tools, the vulnerability scanners, um, and we are coming from the outside.
So some organizations have external exposure tools, so we can replace the traditional scanners and the manual penetration testing, uh, in one bundle that gives you the best from, from both words. Um, but really the deployment is just signing an NDA, giving us an access to the application that you liked us to test. And that's it.
So this is what makes us move that fast, is the ability to very quick deployment. And in a matter of less than a week, you're getting an access to the user interface, seeing all of the unique issue that we were able to detect. Um, and most of the time that this is pretty enough for Okay, let's, let's now work together in collaboration.
Who, Who would you say the, the average the target customer is? So we are targeting at least medium size and above organizations. Uh, we're not customers that, or, uh, organizations that are doing penetration testing just for compliance.
Those are not our, uh, ideal customer profile. We really look for organizations that sees themselves as a target, and they really care from the security, uh, of their applications, and they, and they want a prime, uh, results. This is what we are providing.
So, Got it. We're about outta time, but I wanna make sure we hit this NOV security, N-O-V-E-E Security. Yeah.
People Go sign up and start, you know, as you said, sign VA and get a, uh, a, uh, a, an instant going and see how it goes. Yeah, definitely. Excellent.
Uh, congratulations. You know, mazel tough on the, on the raises. Good luck going to market now.
Right now it gets fun. Yeah. Yeah, it is.
Now, now they game me Done. Definitely. All right.
Ada Geffen, CEO co-founder at Novi at Novi Security, continuous AI powered, uh, pen testing and more all your security testing right in one place. We're, we're gonna take a break here on text on tv. We'll be right back.