Canaan Management Inc

07/27/2026 | Press release | Distributed by Public on 07/28/2026 08:20

Mate: Continuous Detection, Continuous Response at Machine Speed.

Why We Backed Mate

I am pleased to announce that Canaan is leading Mate Security's $35 million Series A, alongside Insight Partners, Team8, and M12, Microsoft's Venture Fund. This comes less than a year after Mate emerged from stealth with an oversubscribed $15.5 million seed round, and brings the company's total funding to over $50 million. It's also, for me, the culmination of a search that started more than two years ago.

Why We Waited

I've been looking at the AI SOC space for over two years. We didn't make a bet in that time, and it wasn't for lack of trying. Four things held us back.

First, the models weren't there. Early LLMs simply weren't effective or trustworthy enough to sit inside a security workflow where a wrong call has real consequences.

Second, nobody had rebuilt the architecture to be AI-native from the ground up - we saw plenty of AI features bolted onto legacy SOC tooling, but not a platform designed around how AI agents actually need to reason and act.

Third, we hadn't found a team with the right combination of AI depth and security expertise. Plenty of founders had one or the other: brilliant AI researchers with no feel for how a real SOC actually operates under pressure, or seasoned security operators who treated AI as a feature to bolt on rather than a foundation to build from. Very few had genuinely lived both worlds.

And fourth, and maybe most importantly: point solutions weren't going to be enough. A company that only does AI triage on top of someone else's SIEM is easily replaced the moment a competitor - or the SIEM vendor itself - ships the same feature. The solution has to be holistic, spanning detection and response as one system, not a wrapper around one piece of it.

Mate is that holistic solution.

A Threat Environment That's Fundamentally Different

To understand why this matters now, it helps to look at how attacks are actually being carried out.

Attackers are no longer manually hunting for footholds one system at a time. They're using AI to read a vulnerability disclosure, reason about the underlying code, and generate a working exploit automatically, often within hours of that vulnerability becoming public. Anthropic disclosed in September 2025 that a state-aligned threat actor had hijacked Claude Code instances to run autonomous cyber operations against roughly 30 targets, with the model handling an estimated 80 to 90 percent of the tactical steps without a human in the loop. This isn't a one-off: the Picus Red Report 2026 found that roughly 80 percent of the top observed adversary techniques now show signs of AI-generated tooling, and HackerOne's 2025 disclosure data shows AI-related vulnerability reports surged more than 200 percent year over year, with prompt injection reports up 540 percent. Once inside, attackers move immediately: CrowdStrike's 2026 Global Threat Report puts average eCrime breakout time - compromise to lateral movement- at 29 minutes, with the fastest observed case under a minute and data exfiltration beginning within four minutes of initial access in one documented intrusion.

The old model of security assumed a gap between when a flaw became known and when someone would exploit it - weeks, sometimes months, enough time for a human team to write a signature, patch, or detection rule and get ahead of it. That window has effectively collapsed to about 24 hours in 2026, down from roughly 53 days just two years ago, and Mandiant and Google's Threat Intelligence Group describe the shift bluntly: what once unfolded over weeks now materializes in days, and in some cases, minutes.

As attackers are running automated pipelines from vulnerability to exploit to breach, defenders need an equivalent pipeline running just as fast, from the moment a vulnerability surfaces, to a detection rule being written for it, to an alert being triaged and confirmed as a real attack, all without waiting on a human to manually connect each step. Any AI layered into the SOC has to actually reduce noise and be verifiable, not just add another dashboard analysts have to double-check. This is precisely the gap Mate is built to close: a single, continuous system spanning detection through response, built on a context layer specific to each organization, so what the AI concludes is something a human analyst can trust and act on immediately.

The Team

The team is what makes Mate special. Co-founder and CTO Guy Pergal massively accelerated product velocity at Axonius, quickly rising to lead a 40-person engineering team. CEO Asaf Wiener was one of the top performers at Wiz during its breakout growth years, and before that built security operations tooling at Microsoft alongside co-founder and CPO Oren Saban; the two of them have effectively already built a SOC together once. Wiener also came up through one of the most elite units of the IDF. This is a team with real operating scar tissue, not just AI research pedigree, and it shows in the product: it's a crack team that takes no prisoners.

What stood out to us wasn't simply that Mate uses AI, every vendor in this space says that now. It was the team's conviction that trustworthy AI in security requires a genuine, structured understanding of how a specific organization operates: its systems, its people, its history of past alerts and decisions. Mate builds that understanding into a persistent context layer that its detection, investigation, response, and hunting agents all draw from and contribute to, so the system gets sharper with every incident instead of starting from zero each time.

What's Next

Mate has grown more than 500 percent since Q3 of last year, expanding the platform's reach across the Fortune 500 as more security teams move away from static playbooks toward systems that learn continuously. With this new round, Mate will take their technology to more customers worldwide.

Congratulations to Asaf, Oren, Guy, and the entire Mate team.

Canaan Management Inc published this content on July 27, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on July 28, 2026 at 14:20 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]