Native raises $42M to enforce cloud security at the architecture level across multi-cloud
What's the deal? Native, a Seattle-based cloud security startup, has emerged from stealth with $42 million in total funding, including a $31 million Series A led by Ballistic VenturesDealroom has a profile for this one. Try Dealroom →. The company has built what it describes as the first cloud security control plane — a platform that translates a security team's intent into enforceable configurations across AWSDealroom has a profile for this one. Try Dealroom →, Microsoft AzureDealroom has a profile for this one. Try Dealroom →,Google Cloud,Dealroom has a profile for this one. Try Dealroom → and Oracle Cloud InfrastructureDealroom has a profile for this one. Try Dealroom →, using each provider's own native controls rather than adding a separate monitoring layer.
The founding team has deep roots in the space: chief executive officer Amit MegiddoDealroom has a profile for this one. Try Dealroom →led Amazon GuardDuty at AWS, chief product officer Gal OrdoDealroom has a profile for this one. Try Dealroom → led AWS Security Hub, and chief technology officer Eyal FaingoldDealroom has a profile for this one. Try Dealroom → was vice-president of cloud security at Check Point. The company already counts Fortune 100 customers across finance, technology, and media.
Why now? AI is compressing the attack timeline. Google's Mandiant unit reported that the average time-to-exploit hit minus one day in 2024 — meaning attackers were exploiting vulnerabilities before patches were even publicly available. That pace makes human-in-the-loop detection and response increasingly inadequate, shifting the security industry toward preventive, architecture-level enforcement.
Multi-cloud complexity is compounding the problem. Each cloud provider has its own identity model, policy mechanisms, and security controls — and most enterprises use only a fraction of what is available. Inconsistency across accounts and clouds creates gaps that are widening as AI workloads are added to the mix.
What could go wrong? Native's approach depends on enterprises trusting a third party to define and enforce security policy across their entire cloud footprint — a significant ask. Deploying controls in production carries real risk; a misconfiguration can disrupt business operations, and Native is positioning itself as the layer that makes those changes. The company includes pre-deployment simulation and approval workflows to mitigate this, but the risk is inherent to the product category.
The cloud security market is also crowded. Palo Alto Networks,CrowdStrike, Wiz (now part of Google), and dozens of others compete for the same enterprise security budget. Native's differentiation — enforcement through native controls rather than detection — is meaningful, but translating that into widespread adoption requires displacing entrenched tools and workflows.
The signal: Native's launch reflects a broader shift in cloud security from detection to prevention. The category has long been defined by tools that identify problems after the fact; the next wave is about embedding security directly into infrastructure so problems do not arise in the first place. Phil VenablesDealroom has a profile for this one. Try Dealroom →, former chief information security officer of Google Cloud and now on Native's board, framed it plainly: the unit of work is no longer finding problems, it is safely enforcing the right architecture at speed. That shift is being accelerated by AI on both sides of the security equation — attackers moving faster, defenders needing to automate more.
Source:
Native
A.M.