
Neosec is an American cybersecurity firm that was founded with the mission to revolutionize how businesses secure their most pervasive digital asset: the API. Headquartered in Palo Alto, California, with significant research and development operations in Tel Aviv, Israel, the company quickly rose to prominence by introducing the concept of 'XDR for APIs.' In April 2023, Neosec was acquired by Akamai Technologies in a deal valued at approximately $91.4 million. This acquisition allowed Akamai to integrate Neosec's advanced behavioral analytics with its global Content Delivery Network (CDN) and cloud security portfolio. Today, Neosec functions as a core component of Akamai’s API Security suite, serving global enterprises across financial services, retail, and healthcare sectors. The company is recognized for its ability to handle massive datasets and its unique 'privacy by design' approach using tokenization.
Neosec was founded in 2020 by Giora Engel and Ziv Sivan. Giora Engel, the CEO, is a seasoned cybersecurity entrepreneur who previously co-founded LightCyber, the company that pioneered behavioral attack detection (later acquired by Palo Alto Networks for over $100 million). Ziv Sivan, the CTO, brought deep expertise in big-data engineering and security architecture. The founders' original vision was born from the observation that while network and endpoint security had evolved into sophisticated detection and response (EDR/XDR) models, application security remained stuck in the 'antivirus era' of simple signatures. They sought to build a platform that could treat every API request as a data point in a larger behavioral story, allowing them to detect the subtle 'reconnaissance' and 'logic abuse' phases of an attack that traditional tools miss. The company emerged from stealth in 2021 with a strong team composed of Unit 8200 veterans and former Palo Alto Networks executives.
Before its acquisition by Akamai, Neosec was a well-funded startup that raised a total of $20.7 million. In September 2021, the company announced its $15 million Series A funding round, which was led by True Ventures. Other significant institutional participants included New Era Capital Partners, TLV Partners, and SixThirty. The round also saw participation from notable angel investors and security visionaries such as Mark Anderson (former President of Palo Alto Networks and later CEO of Alteryx), Gary Fish (Founder of Fishtech Group), Mickey Boodaei (CEO of Transmit Security), and Rakesh Loonkar. This capital was primarily used to expand the company's R&D efforts in Israel and to scale its go-to-market operations in North America, eventually positioning the company as an attractive acquisition target for Akamai in early 2023.
The Neosec platform, now Akamai API Security, is structured into four primary functional modules. The 'Discovery' module is the foundation, using out-of-band traffic analysis to build a complete inventory of all APIs, including those not managed by a gateway. The 'Posture Management' module focuses on 'Shielding Right' by auditing the security configuration of discovered APIs against 150+ rules and industry standards like the OWASP API Security Top 10. The 'Runtime Protection' module is the 'brains' of the system, utilizing proprietary ML algorithms to detect anomalies and behavioral deviations in real-time. Finally, 'Active Testing' allows organizations to 'Shift Left' by integrating security testing directly into the CI/CD pipeline. A unique 'ShadowHunt' managed service is also offered, providing human threat hunters who act as an extension of the customer’s security team to investigate alerts and find hidden threats.
Since its acquisition, Neosec’s technology has been integrated into Akamai’s global footprint, which spans over 4,000 locations in 130+ countries. A major focus of expansion has been the Middle East, particularly the GCC region. In 2025, Akamai announced a new localized 'scrubbing center' in Dubai to support regional digital transformation initiatives like Saudi Vision 2030 and UAE's digital economy goals. This expansion ensures that regional customers can utilize Neosec's API security technology with minimal latency while keeping data processing within regional borders to satisfy data residency requirements. The company has also established strong partnerships with regional telecom giants like e& (formerly Etisalat) and Du to distribute these security services to local government and enterprise clients.
In the last 18 months, Neosec (under Akamai) has introduced several major features aimed at enterprise scalability and developer experience. One of the most significant releases is the 'Active Testing' suite, which allows developers to automatically test their APIs for business logic vulnerabilities like BOLA (Broken Object Level Authorization) before code reaches production. Additionally, the platform now features a deeper integration with the Akamai 'App & API Protector,' allowing for 'single-click' blocking of threats identified by Neosec's behavioral engine at the Akamai edge. Other enhancements include advanced support for gRPC and GraphQL protocols, improved tokenization controls for GDPR compliance, and a new integration with ServiceNow and Jira to automate the ticketing and remediation workflow between security and development teams.
Neosec's culture is rooted in a 'data-first' and 'innovation-led' philosophy. Influenced by its Israeli R&D heritage and Silicon Valley leadership, the company emphasizes deep technical excellence and a proactive approach to security. The work environment is characterized by high transparency and a 'team of experts' mentality, particularly evident in the ShadowHunt group, which fosters a culture of collaborative threat research. Following the Akamai acquisition, the team has transitioned into a 'remote-friendly' and 'hybrid' model, benefiting from Akamai’s extensive corporate wellness programs, DEI (Diversity, Equity, and Inclusion) initiatives, and continuous learning opportunities through Akamai University. The culture remains focused on solving the 'impossible' problems of application security through big-data and behavioral science.
Neosec maintains an active presence in the broader cybersecurity and developer communities. The company is a frequent contributor to the OWASP API Security Project, helping to define the industry standards for API threats. Neosec experts regularly present at major conferences such as RSA, Black Hat, and Gartner Security & Risk Management Summit. The company also fosters a developer ecosystem through the 'Akamai TechDocs' and the 'Akamai Blog,' where it shares original research on emerging API vulnerabilities and threat trends. For customers, Akamai hosts 'World Tour' events—including major stops in Dubai and Riyadh—which serve as user group meetups for sharing best practices and networking. Additionally, Neosec offers certification and training paths for security analysts to become proficient in API threat hunting.

Neosec
By Akamai Technologies