
Cylake Raises $245M for On-Prem AI Security Platform
Palo Alto Networks founder Nir Zuk's new startup Cylake raised $245 million, taking its total to $290 million six months after leaving stealth.
A $245 Million Round Six Months Out of Stealth
Cylake announced a $245 million convertible note on September 8, bringing total funding to $290 million roughly six months after the company emerged from stealth with a $45 million seed led by Greylock Partners in March. Lightspeed Venture Partners, Picture Capital and Redpoint Ventures took part in the new round.
- $245 million raised via convertible note; $290 million total since March 2026
- Lightspeed's Ravi Mhatre joins the board; Picture Capital's Rakesh Loonkar becomes a board observer
- Founders: CEO Nir Zuk (Palo Alto Networks founder and former CTO), CDO Wilson Xu and chief architect Ehud "Udi" Shamir, a SentinelOne co-founder
- Timeline: beta by the end of 2026, general availability in 2027
What the Platform Is Built to Do
Cylake is building an AI-native security platform that runs entirely on-premises or in a private cloud. The target customer is the organisation that cannot put its security telemetry in a public cloud — government agencies and heavily regulated enterprises — and has therefore been left assembling coverage from fragmented point products.
The architectural pitch is unification: pull data and context from across an organisation's infrastructure into a single foundation, then run AI-driven analysis on top of it. Zuk's framing is that the architecture needs rebuilding around complete data, sovereignty and control for an AI-native world. Mhatre's version from the investor side is that the gap between what AI security tooling assumes and what regulated firms can actually deploy was identified early.
Both are fair descriptions of a real constraint. Most of the interesting defensive AI tooling shipped in the past two years assumes a SaaS control plane, and that assumption quietly disqualifies a large set of buyers.
Why Does Sovereign Deployment Matter for AI Security?
The honest answer is data gravity. AI-driven detection works best with breadth — endpoint, identity, network and application telemetry in one place — and breadth is exactly what data residency rules restrict. An organisation that must keep telemetry inside its own boundary has historically had to choose between compliance and correlation.
Building for on-premises from the start is a harder engineering path than adding a private option later. You lose centralised model updates, shared threat intelligence flows and elastic compute, and you have to replace each of those with something that works inside a customer's walls. That is a big part of what $290 million and eighteen months of runway are for.
It is worth keeping expectations calibrated: this is a funding round, not a product. Beta is still months away and general availability is a 2027 target. The evidence available today is a strong founding team, real investor conviction, and a clearly identified gap — not shipped capability.
The Wider Pattern in Defensive AI Funding
Money continues to flow toward defence rather than only toward the offensive-capability conversation. That is the encouraging read on a busy year: OpenAI put $1 billion behind frontline cyber defenders earlier this month, and coordinated migration work like the G7 and CISA post-quantum priorities is moving on a parallel track.
Cylake's specific contribution, if it lands, is making the sovereign deployment case competitive rather than a compromise. Organisations that cannot use public cloud security tooling have spent years accepting weaker coverage as the price of compliance. A well-funded team with this pedigree taking that constraint seriously is good news for defenders on the wrong side of it. More in our AI security coverage.
Sources: SecurityWeek — September 8, 2026; GlobeNewswire — September 8, 2026.
More Ai Security Stories

Invisible Unicode Phishing: How to Spot and Block It
Microsoft tracked 2.37 million daily messages hiding invisible Unicode inside words. Normalizing tag characters before filtering stops the trick.

G7 and CISA Set 5 Post-Quantum Migration Priorities
A joint G7 and CISA call to action lays out five post-quantum priorities and a phased, risk-based migration plan organizations can start today.

PostgreSQL Fixes a 12-Year-Old Logical Decoding Flaw
CVE-2026-6471 let a REPLICATION-privileged user load arbitrary code. Patches shipped in PostgreSQL 18.6, 17.11, 16.15, 15.19 and 14.24 in August.
