Hagai Shapira doesn't remember the exact moment Craft Ventures decided to write him a check. But he knows it happened fast—uncomfortably fast, by venture capital standards.
On September 15, 2025, Daylight emerged from stealth mode. Shapira and his co-founder Eldad Rudich had spent barely three months talking to potential customers, testing a premise that felt audacious even by cybersecurity's inflated standards: that AI agents could actually replace much of the human labor in managed security services. Not assist. Not augment. Replace.
By November 4—less than 50 days after launch—Craft Ventures sent over a preemptive term sheet. $33 million. Series A.
In an industry where funding cycles typically lumber across quarters and due diligence stretches into what feels like geological time, Daylight's trajectory stands out. The Tel Aviv-based startup went from founding to $40 million in total capital before most companies finish their first pilot program. Perhaps more striking: they did it during a period when venture investors, burned by the 2021-2022 funding frenzy, have grown considerably more cautious.
That speed wasn't luck, and it wasn't hype. It was built on a specific, testable bet about how enterprises will buy security services in an age when AI agents are becoming capable of genuine autonomy.
The Unit 8200 Veterans Make Their Move
Both Shapira and Rudich came from Torq, the security automation company, where they held director-level roles in product and engineering. Before that, they'd done their time in Unit 8200, Israel's elite intelligence unit that's become something of a farm system for cybersecurity founders.
From those perches, they'd watched the managed detection and response market evolve—or, more accurately, fail to evolve. MDR had grown into a crowded, increasingly commoditized space. The problem wasn't a lack of vendors; it was that most MDR services still operated like glorified help desks. Customers sent in alerts. Analysts somewhere triaged them. Then they sent recommendations back. The ping-pong never stopped, and neither did the escalations.
"The traditional MDR model is broken," Shapira wrote in a September blog post announcing Daylight's launch—a piece that doubled as both manifesto and product pitch.
The question they set out to answer: Could autonomous AI genuinely handle the investigation and response work that typically required human escalation? Not just flag threats in some probabilistic way, but actually contain them.
Their technical approach pairs what's being called "agentic AI" with human security experts who operate more like strategic supervisors than frontline analysts. The AI agents actively investigate incidents by pulling context from identity systems, HR databases, and business applications—the messier, more contextual data sources that traditional security tools often ignore. Then they collaborate with analysts through ChatOps interfaces embedded in Slack or Microsoft Teams.
Daylight claims this results in near-zero false positives and a tenfold improvement in response speed compared to traditional MDR. Bold numbers. The kind that make seasoned security buyers raise an eyebrow.
When VCs Move at Startup Speed
The $7 million seed round from Bain Capital Ventures closed the same day Daylight launched publicly. Maple VC joined, along with a roster of security founder-operators that reads like an Israeli cybersecurity hall of fame: the Torq co-founders, the Cyera co-founders, Ofir Ehrlich from EON. These weren't passive check-writers. They were operators who'd built and scaled security companies through similar inflection points.
By the time Craft came calling in November, Daylight had signed dozens of enterprise customers across the U.S. and Europe—a customer roster that provided unusual validation for such an early-stage company. The Motley Fool. Cresta. McKinsey Investment Office. Burberry. SIXT. One customer, Cresta, reported a five-fold reduction in mean time to respond.
What caught Craft's attention, according to partners Kevin Gabura and Michael Robinson, wasn't just the customer traction, impressive as it was. It was the signal that enterprises were willing to fundamentally rethink managed security—not just optimize around the edges.
Gabura and Robinson have been developing an investment thesis they call "agent-native" companies: startups built from day one to leverage autonomous AI rather than retrofitting it into legacy workflows. They pegged the managed security services market at more than $50 billion annually—a figure that helps explain why even a preemptive term sheet made sense at such an early stage.
The Series A announcement brought additional heavyweight validation: Assaf Rappaport from Wiz and the Armis founders joined the cap table. When investors with those track records write checks three months after seed, it tends to validate the underlying hypothesis. Or at least suggest the hypothesis is worth a very large bet.
The MASS Category Gambit

Daylight isn't positioning itself as just another MDR vendor trying to execute a little better than CrowdStrike or Red Canary. Instead, the company introduced a new term—"Managed Agentic Security Services," or MASS—to describe its vision for the category.
The framing is deliberate. It suggests managed security will expand well beyond detection and response to include identity threat response and cloud workload protection, all powered by the same agentic intelligence backbone.
Those modules are coming, according to the Series A press release. The architecture makes intuitive sense: if you've built AI agents capable of investigating and responding to endpoint threats, extending them to identity or cloud workloads becomes a natural expansion, not a pivot. Whether enterprises will actually buy these bundled MASS offerings or continue to prefer best-of-breed point solutions remains an open, and commercially critical, question.
For now, Daylight's differentiation lives in operational claims that sound almost too good to be true. The company says it deploys in under an hour. It promises 100 percent environment coverage. It claims the lowest mean time to detect and respond in the industry.
Those are benchmarks that matter in a market where the incumbents have already set punishingly high bars.
What Three Months Actually Proves
The compressed timeline between seed and Series A raises an obvious question: What does it take to convince venture capitalists to move that fast in cybersecurity, a sector where proof of concept and compliance validation typically slow everything down to bureaucratic crawl?
Part of the answer lies in market timing. Enterprises are being squeezed from multiple directions: AI-driven attacks that evolve faster than traditional defenses can adapt, and shrinking security budgets that make expensive human-heavy services harder to justify. Traditional MDR requires significant analyst labor, which makes it expensive to scale. If agentic AI can genuinely reduce analyst workload while improving outcomes—a big if—the unit economics shift dramatically.
The other part is founder credibility and network effects. Shapira and Rudich built products at Torq during its rapid growth phase, which means they've seen what scaling a cybersecurity company actually looks like. Their investor syndicate includes operators who've scaled similar businesses from zero to billions. That network provided both customer introductions and technical validation far faster than most startups could achieve organically.
Still. The real test isn't landing early adopters who are willing to take risks on unproven technology. It's whether Daylight can scale beyond those initial believers without compromising the service quality that won them those accounts in the first place.
The company now operates across North America, Asia, and Europe, with recent expansion into Singapore and appearances at FS-ISAC APAC. The geographic footprint suggests ambitions beyond niche adoption—but also introduces operational complexities that have tripped up plenty of well-funded security startups before.
The Incumbent Problem (And It's a Big One)
Daylight enters a market where the leaders aren't exactly standing still. CrowdStrike, which has come to dominate the MDR conversation, continues to collect analyst recognitions and expand its platform capabilities. Smaller but formidable players like Expel and ReliaQuest have carved out defensible positions by focusing on outcomes and unusual transparency around their processes.
The competitive landscape isn't forgiving, and it's not getting easier.
What Daylight has that most challengers lack is a thesis that goes beyond incremental improvement. The MASS framing positions managed security as a fundamentally different service category rather than a faster, cheaper version of the same thing. Whether that resonates with enterprise buyers—who often, maddeningly from a startup perspective, prefer proven vendors over novel approaches—will define the company's trajectory over the next 18 months.
The $40 million in capital buys time and flexibility to find out. The founders say they'll use the funding to expand the team and build out the identity and cloud modules. They're also investing heavily in the agentic AI platform itself, which needs to stay ahead of both increasingly sophisticated threat actors and competing automation approaches from better-funded incumbents.
The Gaps That Remain

For all the momentum and institutional validation, notable gaps remain.
Daylight's performance metrics—that tenfold improvement in response speed, the near-zero false positives—come from company claims rather than third-party validation. Customer testimonials highlight speed improvements, certainly, but there's limited visibility into how the service performs under sustained, sophisticated attacks or complex compliance requirements that often reveal hidden operational weaknesses.
The aggressive geographic expansion also introduces the kind of operational complexity that tests even mature security providers. Delivering consistent service quality across time zones and regulatory environments is difficult. Attempting to do it while simultaneously building new product modules and scaling the underlying AI platform? That's a recipe for operational strain.
The company's approach to human-AI collaboration, while compelling in theory, faces inevitable scrutiny from security teams who are, by training and temperament, skeptical of automation that operates without meaningful human oversight. Daylight's ChatOps model keeps analysts in the loop, but the balance between autonomy and control will need to evolve—probably awkwardly at times—as the AI agents handle more responsibility.
Perhaps the biggest question mark is sustainability of technical advantage. Will the agentic AI architecture maintain its edge as competitors inevitably adopt similar approaches? The cybersecurity market moves with brutal speed. Technical differentiation that seems genuinely novel in late 2025 could be table stakes by mid-2026.
The Real Work Ahead

Three months from seed to Series A doesn't happen often, but it's not entirely unprecedented in genuinely hot categories. What makes Daylight's trajectory notable is the confluence of factors: founder pedigree, market timing, customer traction, and a clear category vision all aligning during a period when VCs have been notably cautious about deployment speed.
Craft's bet is that agent-native companies will capture disproportionate value in managed services markets as AI capabilities mature. If that thesis holds—and it's a thesis, not yet a proven fact—Daylight's early momentum matters less than its ability to execute on the MASS vision over the next 18 to 24 months. The company has capital. It has customers. It has a technical foundation.
Now it needs to prove the category it's defining actually exists.
For Shapira and Rudich, the rapid follow-on round validates their decision to focus on managed services rather than building yet another security tool that would compete in an already oversaturated market. But validation from venture capitalists isn't the same as validation from enterprises replacing their existing MDR providers—often expensive, politically fraught decisions that involve multiple stakeholders and long evaluation cycles.
That's the work ahead: showing that agentic AI paired with human expertise isn't just faster than traditional MDR, but different enough, better enough, to justify the switching costs and implementation risk.
The cybersecurity market has seen plenty of companies raise significant capital quickly on promising technology and compelling founder stories. The ones that last—that build durable businesses rather than just impressive fundraising narratives—are the ones that turn technical innovation into operational reality at scale.
Daylight has clearly nailed the first part. The second part, considerably harder and less glamorous, is just beginning.
