Fundraising Fox

Mallory

Founded 2025 · 10 employees on LinkedIn · 3 known investors

Mallory is a threat intelligence platform that continuously ingests open, commercial, and underground sources into a structured threat graph, then correlates active adversary activity against an organization's actual assets to determine exposure. It prioritizes and routes remediation work into a security team's existing tools (code repos, cloud, EDR, identity, SaaS, ticketing, SOAR), serving corporate security teams.

Also known as Mallory AI · malloryai

Investors · 3

Also in the syndicate · 1

Live Oak Venture Partners

Company profile

researched Aug 2026

Mallory is an Austin, Texas company founded in 2024 that develops what it calls an AI-native threat and exposure management platform. The system continuously ingests thousands of open, commercial, and underground sources — vendor advisories, dark web forums, research blogs, GitHub disclosures, government feeds, and vulnerability/CVE data — and resolves them into a single structured threat graph of actors, campaigns, vulnerabilities, and observables, with each claim linked to its supporting evidence.

The platform then connects to tools a customer already runs, including code repositories, cloud, EDR, identity, SaaS, ticketing, and asset inventory systems, and reads each incoming threat against the customer's actual assets to determine whether the organization is in scope. Exposures are ranked by observed adversary behavior rather than by static severity scores, and the resulting work is routed into tickets, detections, and remediation workflows under customer-defined policy guardrails, with human review and override at each step and verification that an exposure has been closed. Scheduled agents run recurring exposure checks across repositories, supply chain, and CI/CD.

Mallory positions itself as an upstream reasoning layer that feeds downstream systems such as CTEM and exposure management, SOAR and ticketing, AI SOC, vulnerability management, SIEM, and EDR. Connectivity options include native support for Claude Code, the Model Context Protocol, an open REST API, and webhooks, alongside more than 40 other integrations. The company also publishes open-source tooling on GitHub, including an MCP server (archived), a Python API client, and a Go CLI exporter for the Mallory API.

Founding story

Founder and CEO Jonathan Cran spent roughly two decades in security, beginning as a network administrator and working as a penetration tester at Rapid7, then founding Intrigue, an open-source attack surface project that was integrated into Mandiant and became part of Google Threat Intelligence. He describes repeatedly encountering security teams working across narrow tools and assembling context manually, and left Google in 2024 to start Mallory.

Business model

Mallory sells a SaaS platform to enterprise security teams, offered with a free trial (14 days per the company site; a 30-day trial was cited at launch) that provides full platform access without a credit card, with usage described as opt-in.

Subscription software delivered as a SaaS platform with integrations across existing security tooling.

Traction

The company cites early adopters including Texas Mutual Insurance and a Fortune 500 healthcare threat intelligence team, plus an endorsement from HD Moore, creator of Metasploit and CEO of runZero. Its public GitHub organization hosts four repositories updated through mid-2026.

Latest developments

In April 2026 Mallory launched its platform for general availability as SaaS and announced a seed round led by Decibel Partners with participation from Live Oak Venture Partners and angel investors from Google, Robinhood, Cisco, Fastly, and GreyNoise. The company states that adversary-weighted prioritization ships today, while routing into ticketing and detections is live where supported and expanding, and pre-computed exposure on ingest remains on the roadmap.

Full profile — market position, technology, go-to-market, geography, history, risks & controversies

Market position

Mallory describes its category as unified cyber risk intelligence, positioning between external threat intelligence feeds and internal exposure tooling, and presents itself as a reasoning layer upstream of CTEM, SOAR, AI SOC, and vulnerability management products rather than a replacement scanner or inventory system.

The company emphasizes provenance — every claim in the graph citing its evidence — combined with prioritization driven by current adversary activity rather than publication-date CVSS scores, and integration with tools customers already own instead of deploying an additional scanner or maintaining a separate asset inventory. It also notes verification that an exposure has actually been eliminated rather than merely ticketed.

Technology

A structured threat graph built from continuously processed, deduplicated, and entity-resolved sources sits at the core of the product, with frontier language models reasoning across both external adversary activity and the customer's environment. Agents perform prioritization, routing, and remediation assistance under policy guardrails, and scheduled agent routines run recurring exposure questions. Interfaces include Claude Code support, MCP, a REST API, webhooks, and a web UI; personalized feeds are scoped to a customer's tracked entities, tech stack, and industry.

Go-to-market

Self-service free trial with full platform access from the website, supported by developer-facing distribution through open-source repositories, an MCP server, an API client, and a marketplace of agent skills for CTI and security operations; the April 2026 launch was accompanied by industry press coverage and customer testimonials.

Corporate and enterprise security teams, including CISOs, SOC and cyber threat intelligence teams, and vulnerability/exposure management functions. Named or described early users include Texas Mutual Insurance, a Fortune 500 healthcare CTI team, and OWASP is listed among organizations whose security teams use the product.

Geography

Headquartered in Austin, Texas, United States.

History

Founded in 2024 and headquartered in Austin, Texas. In April 2026 the company publicly launched its platform and disclosed a seed investment led by Decibel Partners with participation from Live Oak Venture Partners and individual senior leaders from Google, Robinhood, Cisco, Fastly, and GreyNoise.

Risks & controversies

Product capabilities are at differing stages of maturity: the company states that routing into ticketing and detections is only live for supported integrations and still expanding, and that pre-computing exposure on ingest is on the roadmap. Public trial terms are stated inconsistently across the company site (14 days) and launch coverage (30 days).

Compiled by commissioned research from 8 cited public sources — announcements, filings, and press listed under research sources below.

Key figures

latest reported
Free trial lengthApr 202630 days
Public GitHub repositoriesJun 20264 repositories

Company-reported or press-reported figures, each dated to when it was claimed — not independently audited.

Timeline · 2

launches, deals, and filings
Apr 2026
Seed investment led by Decibel Partners

Mallory announced a seed investment led by Decibel Partners, with participation from Live Oak Venture Partners and individual industry leaders from organizations including Google, Robinhood, Cisco, Fastly, and GreyNoise. No amount was disclosed.

source ↗

Apr 2026
Mallory launches AI-native threat intelligence platform

Mallory announced the launch of an AI-native threat intelligence platform that monitors thousands of threat sources, contextualizes them against a customer's attack surface, and supports hunt, detection, and exposure management use cases. Available immediately as SaaS with integrations into existing security tools and native support for Claude Code, MCP, and an API.

source ↗

Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.

In the news

Research sources · 8

primary sources listed

8 public sources were cited for this profile; the first-party ones are listed here.

Frequently asked questions

What does Mallory do?
Austin-based Mallory builds an AI-native threat and exposure management platform that maps live adversary activity to a company's assets.
Who are Mallory's investors?
Mallory's investors include Aviso Ventures, Decibel Partners.