Six months into retirement, Nir Zuk apparently got bored.
The founder of Palo Alto Networks—a company that redefined enterprise firewalls and grew into one of cybersecurity's giants—stepped away last August after more than two decades at the helm. But on March 5, 2026, he resurfaced with Cylake, a startup armed with $45 million in seed funding from Greylock Partners and a thesis that cuts against the grain of nearly everything happening in modern security software.
The pitch? Most AI-powered cybersecurity tools assume you can send your data to the cloud. For a sizable chunk of the world's most sensitive organizations, that assumption is a non-starter.
Cylake is building what it calls an "AI-native" security platform designed to operate entirely inside a customer's own environment—no telemetry shipped to public clouds, no reliance on third-party AI services. It's a bet on sovereign infrastructure at a moment when the rest of the industry is racing toward cloud-delivered everything. Which makes it either deeply prescient or profoundly out of step, depending on whom you ask.
The Problem Zuk Sees
Here's the tension: generative AI has unlocked powerful new ways to detect threats, automate responses, and make sense of overwhelming volumes of security data. But those capabilities typically require massive compute resources and centralized data processing—hallmarks of public cloud platforms like AWS, Azure, or Google Cloud.
For government agencies, critical infrastructure operators, and heavily regulated enterprises, that's where the equation breaks down. Data residency laws, compliance mandates, and operational security concerns often prohibit sending sensitive telemetry outside controlled environments. You can't pipe Defense Department network traffic through OpenAI's API, no matter how good the threat detection might be.
Zuk laid out the argument in an open letter timed to Cylake's launch. Generative AI, he wrote, doesn't reduce the need for dedicated security platforms—it amplifies it. But only if those platforms can access complete security data without the architectural compromises that come with cloud economics.
It's a nuanced position. And it runs headlong into the conventional wisdom that cloud-native, SaaS-delivered security is simply the future.
What Cylake Is Actually Building
The technical details remain sparse—deliberately so, according to the company's blog. But the broad strokes are these: Cylake combines hardware and software to create what it describes as a "sovereign data foundation." The system ingests telemetry from network traffic, endpoints, cloud workloads, and existing security tools, then consolidates everything into a local data layer that lives on-premises or in a private cloud.
Machine learning models and automated workflows—what the company calls "agentic workflows"—run directly inside that environment. No data exits the perimeter.
It's an architecture designed around constraints rather than conveniences. Most security startups today optimize for speed to deployment and ease of integration, which generally means building on top of hyperscaler infrastructure. Cylake is doing the opposite: building for customers who need AI-powered security but can't—or won't—use public cloud services to get it.
Whether that represents a meaningful market or a niche curiosity is the central question.
Who's Building It

Zuk isn't doing this alone. He recruited Wilson Xu, previously SVP of Engineering at Palo Alto Networks, as Chief Development Officer. Ehud "Udi" Shamir, who co-founded SentinelOne back in 2013, signed on as Chief Architect. The executive roster also includes Maya Marcus as Chief Product Officer, Jesse Ralston as CTO, and Jony Hartono as CFO.
It's a team with serious pedigree. Between them, they've built billion-dollar security companies and navigated the complexities of selling into the most demanding enterprise environments. That matters when you're attempting something as architecturally ambitious—and operationally complex—as combining on-premises hardware, local AI processing, and enterprise-grade security automation.
The company describes itself as a "small, highly experienced team" spanning hardware, software, data infrastructure, and applied AI. Headcount hasn't been disclosed, nor have specific product features or hardware specifications. Cylake is being careful about what it reveals and when.
The Market Cylake Is Chasing
The target audience is what the company calls "the world's largest and most regulated institutions." Think government agencies with classified networks, financial services firms navigating a thicket of compliance requirements, critical infrastructure operators managing power grids or water systems, and multinational corporations operating in jurisdictions with strict data sovereignty laws.
It's not a small market, though it's arguably a slower-moving one than the venture-backed startup world typically pursues. These customers don't move fast and break things. They move deliberately and demand proof.
Other vendors have begun addressing pieces of this problem. Nutanix expanded sovereign cloud support for fully disconnected environments late last year. Acronis launched on-premises deployment capabilities designed to mimic cloud-grade features. SentinelOne has enabled regionalized deployments to satisfy data residency requirements in markets like Saudi Arabia.
What differentiates Cylake—at least in theory—is that it's architected from the ground up around local data processing and AI, rather than adapting cloud-native tools for on-premises use. Whether that architectural purity translates into a better product or just different trade-offs won't be clear until customers can actually kick the tires.
General availability is targeted for early 2027. The company is currently working with an undisclosed group of design partners. No pricing or business model details have been shared.
What $45 Million Says
A seed round that size is unusual, particularly for a hardware-software hybrid in a market dominated by cloud-delivered SaaS. It signals a few things.
First, investor appetite for contrarian infrastructure plays appears alive and well, especially as data sovereignty concerns accelerate across government and regulated sectors. Greylock's investment thesis, published alongside the announcement, frames the opportunity around "AI-native, agentic" security built on "holistic data and context" for customers who demand full operational control.
Second, it reflects confidence in the founding team. Zuk's track record at Palo Alto Networks speaks for itself—he didn't just build a successful company, he built one that defined a product category. That buys credibility with investors willing to bet on a long development cycle and a sales process measured in years, not quarters.
But the round also underscores the risk. Delivering on the promise of combining hardware, on-premises deployment, and AI-native architecture at enterprise scale is ferociously complex. The technical challenges are substantial. The go-to-market motion will be slow. And if the market isn't as large or as eager as Cylake believes, even $45 million won't stretch forever.
The Bigger Question

Zuk's bet hinges on a belief that data sovereignty isn't a passing concern—it's a structural constraint that will reshape how security software gets built and deployed. If he's right, Cylake is early to a wave that will eventually force the entire industry to rethink cloud-centricity. If he's wrong, the company is building an expensive solution for a market that may not materialize at the scale required to justify the investment.
For now, Cylake remains in what one might generously call "careful disclosure mode." The positioning is clear: sovereign, AI-native, built for the most demanding environments. But the details of how it all works—and whether customers will pay for it—won't arrive until closer to that 2027 launch window.
In the meantime, the cybersecurity world will be watching to see whether Zuk's contrarian instincts prove as accurate this time as they did when he bet on next-generation firewalls two decades ago. Sometimes the market rewards those who zig when everyone else zags.
Sometimes it doesn't.
