« Back to News

Surf AI 🏄: The New Agentic Operating Model for Security | Welcome to boldstart

  • 03.17.2026

From L to R: Ed Sim (boldstart), Yair Grindlinger and Brenton Gumucio (Surf AI, 2 of co-founders)

Security is breaking.

The world needs a new model.

AI-powered attackers move faster, exposure compounds instantly, and the traditional stack can’t keep up. Alerts flood across identity, cloud, data, and infrastructure, yet tools remain siloed. Even when teams see the risk, they can’t act fast enough – remediation is fragmented across different teams.

In the age of AI, security hygiene is non-negotiable. Enterprises must eliminate exposure and reduce blast radius, which requires continuous visibility, instant drift detection, and remediation that actually executes.

That’s Surf AI. It moves security from a series of alerts to a functional operating model. Every asset watched, every gap closed, every day – connecting context and ownership to action at scale.

That’s why we’re fired 🔥 up to welcome Surf AI to the boldstart family. Today the company is launching with $57M in total funding, with Accel leading the Series A and inception co-leads boldstart and Cyberstarts doubling down.

Our partnership always starts with the founders, and this team is exceptional. Together they bring decades of cybersecurity experience, having seen the security operations problem from every angle: repeat founders who’ve successfully exited, opinionated product leaders, deep research and engineering DNA, and real-world front-line experience with enterprise customers.

I’ve known Yair Grindlinger for years – a seasoned, repeat cybersecurity founder, built FireLayers, acquired by Proofpoint, where he ran cloud as SVP. Brenton Gumucio helped scale BigID where we worked closely together. Elad Horn was CPO at Cohesity after leading product for cloud security at Proofpoint. Roie Cohen-Duwek ran security research at Proofpoint and before that led enterprise security research at IBM Trusteer. And Avner Gideoni was CTO of IBM Trusteer, where he and Roie first built together. Five founders. Decades of scars. They’ve lived every side of this problem. Now they’re on a mission to end it.

They saw it clearly: security teams don’t struggle because they lack visibility. They struggle because their visibility is fragmented across identity, cloud, SaaS, and infrastructure.

When you can’t see how systems connect, you can’t see the real risk.

Connected context changes that. But once you see the risk, someone still has to fix it. Identity drift accumulates. Orphaned accounts linger. Permissions become toxic. Misconfigurations creep in. Security teams open tickets, coordinate across teams, and wait for approvals while the long tail of risk keeps growing.

Surf AI closes that gap.

This isn’t another security dashboard.

It’s a new operating model for security.

The platform builds a context graph of the enterprise, connecting identity systems, infrastructure, security tools, HR platforms, and data environments into a unified model before mapping them to business context such aas asset ownership, permissions, and dependencies. This connected view surfaces risks no siloed tool could detect. Once Surf understands how everything connects, specialized AI agents continuously execute the remediation work security teams have struggled to keep up with for years: revoking stale access, cleaning up orphaned accounts, fixing misconfigurations, and enforcing policy in real time. All of this happens with human oversight and full auditability.

In short, Surf AI operationalizes your entire security program with AI.

Surf is a new layer of enterprise software. Not just intelligence, but execution intelligence: systems that understand context, connect the dots across the enterprise, and continuously and safely act on what they find.

These systems are foundational to what we call the Autonomous Enterprise, where AI systems don’t just surface insights but increasingly take action across the enterprise safely and continuously.

From our earliest conversations with Yair, Brenton, Elad, Avner and Roie it was clear this team had both the experience and the ambition to rethink how security operations should work in an agent-native world.

That’s exactly the kind of founding team we love partnering with at inception.

We couldn’t be more excited to be on this journey together with our friends at Cyberstarts and Accel.

Welcome to the boldstart family.