Why We Invested in Bonfy.AI

I don’t typically invest in cybersecurity. But every once in a while, a founding team walks in with so much depth, experience, and clarity — it changes the conversation entirely.

That was the case with Gidi Cohen and Danny Kibel.

They didn’t come in to impress. They came in to build with conviction born from experience. Gidi, who founded Skybox Security, helped shape the way enterprises visualize risk and reduce exposure across complex networks. Danny, as CEO of Idaptive, led the company through a successful acquisition by CyberArk after spinning out from Centrify. He then led Cyberark’s 700 person R&D team. Both have built and scaled security companies. Both have navigated regulation-heavy environments, technology shifts, long enterprise sales cycles, and complex organizational risk. And both knew, long before most, that GenAI would bring a new kind of security problem to the forefront.

Bonfy doesn’t focus on securing the GenAI tools themselves. It focuses on what actually matters: the content those tools create and the risks that come with it.

As GenAI becomes embedded in everything from email to code to customer communication, the line between human- and AI-generated content blurs. Sensitive information flows faster, gets repurposed endlessly, and often bypasses the traditional security stack entirely. Legacy DLP systems weren’t designed for this. Most GenAI security tools aren’t either.

Bonfy’s Adaptive Content Security (ACS™) platform tackles the problem head-on. It continuously learns an organization’s context — policies, ecosystem, sensitivities — and detects content-level risks, whether created by AI or humans. It’s fast, accurate, and adaptive to how work really happens: across platforms, with overlapping tools, and constant iteration.

In our recent Cybersecurity Blueprint: GenAI Revolution report, we highlighted Bonfy’s approach as one of the clearest examples of how GenAI-era risks should be handled. As we wrote:

“Bonfy tackles data risk directly with an adaptive content analysis platform that self-learns an organization’s business content and its user-defined business logic. Rather than focusing on the security of the GenAI tools themselves, Bonfy’s solution focuses on the content generated by either AI engines and/or humans.”

There’s no shortage of GenAI security startups in the market. Many are focused on valuable edge cases — prompt injection, browser extensions, LLM firewalls. But when we asked CISOs what keeps them up at night, the answer was almost always the same: “We don’t know where the sensitive content is going, or what it looks like after GenAI touches it.”

Bonfy is solving that exact pain point.

We backed this team because of who they are. Experienced, clear-headed, and built for the kind of challenge most wouldn’t dare take on. They move with intent, cut through the noise, and stay focused on what matters. 

 

Related Content