Company profile
Daylight AI
Hybrid MDR combining AI agents and human analysts for security operations.
- Category
- Security AI
- Headquarters
- Israel
- Sells to
- Enterprise
- Business model
- Services & consulting
- Deployment
- Cloud / SaaS
- Pricing
- Not published
- Builds own models
- Yes
- Modalities
- Text
What Daylight AI does
Daylight AI offers a hybrid Managed Detection and Response (MDR) model, combining AI agents and human analysts to provide advanced security services. Their approach, called Managed Agentic Security Services (MASS), leverages AI for investigation, reasoning, and execution across complex workflows, while human experts provide judgment, accountability, and outcomes. This model aims to address the shortcomings of traditional security services that are often reactive, labor-intensive, and overly reliant on internal knowledge. Daylight provides continuous monitoring, detection, and response with context-aware investigations, threat hunting, phishing investigation and response, and agentic DLP investigation and response. They also offer an Agentic Security Data Lake service for long-term data retention, searchable storage, and self-service investigation, utilizing an AI agent as an interface for querying data. The company focuses on modern enterprise defense, emphasizing business context, agentic investigations, and elite human expertise for fast, precise, end-to-end threat resolution. They also provide solutions for AI security, addressing new attack surfaces and threats specific to AI agents and large language models.
Products
- Managed Detection and Response (MDR)Continuous monitoring, detection, and response with context-aware investigations, offering a different operating model than traditional MDRs.
- Threat HuntingCoordinated, autonomous agents continuously hunt using IOC-based and hypothesis-based methods, guided by threat intelligence and environmental knowledge.
- Phishing Investigation and ResponseEnriches phishing alerts from email and identity platforms with identity and activity context to rapidly assess and contain malicious messages, compromised accounts, and user interactions.
- Agentic DLP Investigation and ResponseInvestigates DLP alerts indicating exposure or exfiltration of sensitive data, using user behavior, data movement, and access activity for quick risk assessment and containment.
- Agentic Security Data LakeProvides long-term data retention, searchable storage, and self-service investigation capabilities. It stores raw telemetry, allows querying with an AI agent or directly via KQL, and is fully managed by Daylight.
- AI SecurityOffers detection and response for AI-specific threats like prompt injection, shadow AI tooling, credential/data exfiltration, identity/permission behavior anomalies, and runaway AI sessions.
Key capabilities
- Hybrid MDR model combining AI agents and human analysts
- Managed Agentic Security Services (MASS) foundation
- Agentic investigation
- Expert operators (threat hunters and incident responders)
- Follow-the-sun global team of senior experts
- New integrations in days
- Long-term data retention (Security Data Lake)
- Searchable storage for recent data (90 days hot storage)
- Cold storage for archival data with on-demand rehydration
- Conversational AI interface for data lake investigation
- Direct KQL access for advanced users
- No normalization required for raw telemetry in data lake
- Zero operational overhead for data lake management
- Purpose-built data lake for MDR
- Prompt Injection Detection
- MCP & Tool Governance
- Credential & Data Exfiltration detection
- Identity & Permission Behavior tracking
- Runaway & Cost Anomalies detection
- Data & Context Exposure detection
- Detection rules on AI telemetry (Claude Enterprise's OTel runtime stream and Compliance API)
- Investigation correlated with full context (identity, endpoint, cloud, SaaS, business context)
- Verdict with complete evidence chain
- Automated response actions
Use cases
- Continuous monitoring, detection, and response for security incidents
- Proactive threat hunting using IOC-based and hypothesis-based methods
- Investigation and containment of phishing attacks
- Investigation and containment of DLP alerts
- Historical security data investigation without SIEM or tickets
- Self-service security intelligence from telemetry
- Detecting and responding to AI-specific threats in agentic systems
- Governing shadow AI tooling and MCPs
- Preventing credential and data exfiltration by AI agents
- Tracking and managing AI identity and permission behavior
- Identifying and mitigating runaway AI sessions and cost anomalies
- Detecting sensitive data exposure through AI prompt context
AI approach
Daylight AI offers Managed Detection and Response (MDR) services that combine AI agents with human analysts. Their 'Managed Agentic Security Services (MASS)' model uses AI to investigate, reason, and execute complex workflows, while human experts provide judgment, accountability, and outcomes. They utilize AI for continuous monitoring, detection, threat hunting, phishing investigation, and DLP investigation. The AI also acts as an interface for their Security Data Lake Service, allowing users to query data in plain English, with the agent writing and refining KQL queries. They also provide AI security features like prompt injection detection, MCP & tool governance, credential & data exfiltration detection, identity & permission behavior tracking, and runaway & cost anomaly detection, by analyzing AI telemetry from sources like Claude Enterprise's OTel runtime stream and Compliance API.
Tech named: AI agents, LLM, KQL, OTel runtime stream, Compliance API, Claude Enterprise
Industries served
- Computer and Network Security
- Finance (non-banking)
- Software
- Health Tech
What it says sets it apart
- Hybrid MDR model combining AI agents and human analysts
- Agentic AI replicates top IR people skills for deeper investigations at scale
- LLM communication through Slack enhances efficiency and event investigation
- AI and human triage enhances security operations
- Built on MASS (Managed Agentic Security Services) foundation
- Goes beyond traditional MDR with a new operating model
- Powered by threat hunters and incident responders, not junior analysts
- Experts customize detections, build integrations, and inform AI context
- AI is the interface, not just the product, for data lake access
- Raw telemetry stored exactly as it arrives, no parsers or schemas needed
- Fully managed data lake with zero operational overhead
- Purpose-built data lake for MDR, not a general-purpose tool
- Addresses new attack surfaces and threats specific to AI runtime behavior
- Provides programmatic visibility into AI agent actions
- Detection layer built specifically for AI threats
- Focus on security operations for AI, not just governance
Funding rounds we track
Bain Capital Ventures, Maple VC
From the AI funding tracker — rounds as reported by the linked publications.
This profile was compiled from Daylight AI's own public pages in July 2026 and reflects what the company states about itself — not an endorsement or an independent audit of those claims. Facts are extracted with AI and filtered by an automated check that drops any named product, customer or certification missing from the source pages. Full method. Something out of date? Tell us.