Sweet Security

Runtime CNAPP unifying cloud and AI-workload defense

Security & Safety Paid
Researched · Published · Reviewed
RECATOOLS Score
7 / 10
Capability
7.5
Value for money
6.5
Ease of use
6
ASEAN readiness
5
API quality
6
Founded
HQ
Users
Launched
Developer

Overview

A runtime-first cloud-native application protection platform that folds CDR, posture, identity and API security into one sensor, now extended to securing AI models and agents. Built for cloud-native engineering and security teams.

Advertisement

What you can produce with Sweet Security

  • Runtime cloud detection and response (CDR)
  • Vulnerability and posture management (CSPM)
  • Identity threat detection and response (ITDR)
  • API security
  • AI Security Platform: model and agent discovery/mapping
  • Prompt-injection and adversarial-behavior detection for AI
  • Patented LLM-driven detection engine (claims 0.04% alert noise)
  • Runtime sensor for cloud and Kubernetes workloads
Advertisement

ASEAN Perspective

Sweet Security in Southeast Asia

ASEAN-region availability and pricing notes coming soon. Drop the editorial team a note via /contact/ if you can supply local context (Singapore/Malaysia/Indonesia/Thailand/Vietnam).

RECATOOLS Verdict

Sweet's bet is that cloud security should start at runtime, not in a static scan, and it packages CNAPP capabilities around a live sensor that watches workloads as they actually behave. It claims to cut alert noise to 0.04% via a patented LLM-driven detection engine, and it has extended the same runtime lens to AI, discovering models and agents, mapping how they interact and flagging prompt-injection and over-permissioned access. The team is ex-IDF cyber leadership, and a $75M Series B in late 2025 plus reported sixfold ARR growth signal real momentum against Wiz and Sysdig. This is an install-a-sensor, enterprise-sales product: onboarding means instrumenting your cloud and Kubernetes, and pricing is quote-only. Good fit for mid-to-large teams running cloud-native and AI workloads that need runtime visibility, not a static posture snapshot. Not relevant to individuals or small teams, and there's no documented SEA presence, so confirm support and data handling directly.

Independent AI-assisted assessment by RECATOOLS.

What people say

Sweet Security was founded in 2023 by a trio of Israeli cyber veterans, including former IDF CISO Dror Kashti alongside Eyal Fisher and Orel Ben Ishay. It moved fast from the start, raising $33M within six months of leaving stealth, and in November 2025 announced a $75M Series B led by Evolution Equity Partners, with Munich Re Ventures, Glilot Capital and Key1 Capital joining. That brought total funding to roughly $120M. The company reported a sixfold jump in ARR and a tenfold rise in enterprise customers over the preceding year, including multiple Fortune 1000 names.

Alongside the raise, Sweet positioned itself as a unified runtime CNAPP: one platform delivering real-time detection and response, vulnerability and posture management, identity threat protection and API security, all fed by runtime context rather than static configuration data. The detection engine is patented and LLM-driven, and Sweet claims it reduces alert noise to just 0.04% by grounding alerts in what workloads are actually doing.

The newer angle is AI security. Sweet's AI Security Platform (AISP) lets teams discover every model and agent in their environment, map how they interact with each other and with LLM servers, and catch misconfigurations or over-permissioned access before they turn into incidents. It also watches for adversarial behavior such as prompt injection and analyzes agent activity in real time, which is where the "cloud and AI at runtime" tagline comes from.

Public, independent user reviews are still thin, which is typical for a company this young and this enterprise-focused, so buyers should weigh the funding-and-growth signals and analyst framing more than crowd ratings for now. Competitively it's lined up against Wiz and Sysdig in the runtime and CNAPP space.

Because deployment involves instrumenting live cloud and Kubernetes workloads with Sweet's sensor, this is not a self-serve trial; pricing is quote-based and onboarding is hands-on. There's no published ASEAN presence, so regional teams should validate support coverage and data-residency options with the vendor.

Summary of public user & expert reviews, compiled by RECATOOLS.

About this listing

Researched on
Published on
Last reviewed

This entry was compiled from publicly available data including Sweet Security's official website, press releases, documentation, and reputable third-party publications. RECATOOLS is not affiliated with Sweet Security unless explicitly stated.

Data accuracy

Third-party AI tools update their pricing, features, availability, and policies frequently. Information here may be outdated by the time you read this — we make reasonable efforts to keep listings current, but cannot guarantee absolute accuracy.

For the latest details, please refer to Sweet Security directly →

Spotted something out of date? Suggest an update →

Advertisement