Dawnguard's pitch: In a world where AI speeds up both coding and hacking, detecting threats is already too late
The pitch from Dawnguard's founders sounds almost heretical in an industry built on detection. What if, they ask, cybersecurity teams have been fighting the wrong battle all along?
While the rest of the sector races to spot threats milliseconds faster—a competitive arms race that has minted several unicorns—the Amsterdam-based startup wants to reframe the problem entirely. Don't just catch vulnerabilities early, they argue. Stop them from being deployed at all. The company emerged from stealth recently with what it calls a "security architecture automation platform," alongside $3.3 million in fresh funding and a new Manhattan office. That brings total capital to north of $6.3 million, a modest war chest for what amounts to a direct challenge to the industry's prevailing logic.
The timing isn't arbitrary. AI-assisted development has compressed deployment cycles to the point where traditional security models—scan the code, flag the problem, patch it later—are beginning to buckle. By the time a vulnerability surfaces in runtime protection or a code scanner, the flawed architecture is already live and serving traffic. CEO Mahdi Abdulrazak and CTO Kim van Lavieren, both of whom cut their teeth at IBM, Microsoft, Amazon, and in military cyber operations, have taken to calling this the "Mythos Era." It's a somewhat grandiose term for a straightforward observation: software now evolves and gets exploited faster than conventional security processes were designed to handle.
"Cybersecurity has become trapped in an endless cycle of detection, response, and patching," Abdulrazak said when the company launched its general availability. "In the Mythos Era, where AI accelerates both development and exploitation, reactive security is indefensible against adversaries operating at machine speed."
His co-founder was blunter. "That gap [between what was designed and what ultimately gets deployed] is where risk lives," van Lavieren said. The implication: if attackers can weaponize flaws faster than defenders can fix them, the only viable strategy is to design systems that never contain those flaws in the first place.
It's a compelling theory. Whether enterprises will buy into it—and add yet another layer to already-sprawling security stacks—remains an open question.
How It Works
Dawnguard's platform revolves around three core workflows, which the company labels Design, Discover, and Deploy. The Design layer is perhaps the most ambitious: it generates cloud architectures from natural language prompts, existing code, documentation, or even rough sketches. Teams define what the company calls "non-functional requirements"—security policies, compliance standards, performance targets—on a collaborative canvas. The platform then structures those into enforceable architectural decisions.
It supports the big three cloud providers: AWS, Azure, and Google Cloud. Policies tied to frameworks like ISO 27001 translate into guardrails during the design phase. (ISO 42001 and SOC 2 support are listed as coming soon.) The idea is to embed security constraints before anyone writes infrastructure code, not after that code is running in production and generating alerts.
The Discover workflow is more straightforward—it maps existing cloud resources and their relationships across all three major providers, giving teams a read-only snapshot of what's actually deployed. Deploy, meanwhile, converts approved designs directly into production-ready Terraform code, with security guardrails baked in from the start. The platform also runs continuous validation to ensure what's deployed stays aligned with what was approved, a safeguard against what Dawnguard calls "security drift."
In essence, the company is positioning itself upstream of the rest of the cybersecurity stack. It generates the infrastructure that other tools will later scan. It enforces the guardrails that runtime tools will later check for violations. Traditional shift-left tools—code scanners, infrastructure-as-code validators—still operate too late in the lifecycle, Dawnguard argues. They catch mistakes, but they don't prevent the underlying architectural flaws that make those mistakes possible.
The Money and the Expansion

The latest $3.3 million came from existing investor BNVT Capital, with new participation from Curiosity VC and eCAPITAL. Dawnguard first surfaced with a $3 million pre-seed round led by 9900 Capital and several angel investors. (BNVT now describes itself as an existing investor, though it wasn't named in the earlier announcement—the timeline of its initial involvement is somewhat opaque.)
The funding accompanies a push into the U.S. market. The company recently opened an office at 228 East 45th Street in Manhattan, a clear signal it's targeting enterprise customers in North America alongside its European base. The team had grown to around thirty employees by the time of the launch, according to industry coverage.
Dawnguard has also pursued partnerships to extend its reach. Earlier this year, it announced a tie-up with Invictus Incident Response, integrating incident readiness and response controls into its workflows. More recently, it's collaborated with external security partners like Hadrian to complement detection capabilities within customer environments—an acknowledgment, perhaps, that even if you prevent vulnerabilities architecturally, you still need layers of defense once systems are live.
A Crowded, Complicated Market

The competitive landscape is tricky to parse. Dawnguard isn't a traditional cloud security posture management tool like Wiz, Orca, or Palo Alto Networks' Prisma Cloud, which focus on scanning infrastructure and runtime environments for misconfigurations and active threats. It's not quite a threat modeling platform like IriusRisk or ThreatModeler, either—those help teams identify risks and controls but don't generate deployable infrastructure.
Instead, Dawnguard occupies a space that's still being defined: an architecture control layer that sits upstream of both categories. It's attempting to turn security and compliance requirements into actual infrastructure before deployment happens. Call it preventative rather than reactive.
Whether enterprises will embrace a new category of tooling for this purpose is far from certain. Security teams already manage stacks that sprawl across detection, response, identity, compliance, and data protection. Adding another layer—especially one that requires buy-in from architects, developers, and security teams simultaneously—demands proof that design-time automation delivers measurably better outcomes than hardening at later stages.
There's some external validation for the thesis, though. A research note from the Cloud Security Alliance earlier this year described "AI vulnerability discovery velocity" outpacing organizations' ability to patch, with shrinking time-to-exploit windows and overwhelmed disclosure processes. If attackers can move faster than defenders can respond, the logic goes, maybe the only defensible position is to design systems that don't contain exploitable flaws to begin with.
But logic and adoption are different things. The cybersecurity market is littered with companies that had sound theories and struggled to change entrenched workflows.
Dawnguard's platform is now generally available. Enterprises looking to shift security further left—not just left of production, but left of deployment—have a new option to evaluate. Whether that option becomes a foundational piece of the stack or another niche tool will depend on how well the company can prove its central claim: that in a world where both development and exploitation happen at machine speed, prevention beats detection.
For now, the founders are betting that the industry's endless cycle of scanning and patching is running out of road. And they're not alone in thinking that way—though they may be among the first to build a business around the alternative.
