When NeuraLegion launched in 2018, its product was an AI-powered fuzzer to help developers find and mitigate security exploits in their code. The problem, as CEO Gadi Bashvitz explained, was that it was almost too good: it hunts zero-days and finds them, 'creates havoc', and 'crashes any target that it runs against' — so running it near production required the facility to recreate that target again and again, coordination most enterprises couldn't manage.

By the time the team raised its $4.7 million seed round in 2020, it had already shifted to dynamic application security testing — finding vulnerabilities in web applications and APIs by simulating outside attacks. That remained the focus: the tools integrate with CI/CD pipelines, scan web apps and REST, SOAP and GraphQL APIs, and pride themselves on avoiding the false positives that send developers into time-wasting rabbit holes. Bashvitz said the company had no intention of branching into static application security testing.

In March 2022 the company capped the evolution with a rename to Bright Security and a $20 million Series A led by Evolution Equity Partners, with previous investors DNX Ventures, J-Ventures, Fusion Fund and Incubate Fund participating. Bashvitz said many companies had similar names, and 'Bright' better represents the mission — 'provide illumination for all these teams', both visibility into vulnerabilities and a guiding light on doing DAST correctly.

The company said more than 4,000 organizations now used its products. Evolution Equity partner Karthik Subramanian, joining the board, framed the thesis: tools built exclusively for the AppSec team 'are already antiquated if they aren't usable by developers and the DevOps team' — security had to become a joint mission with shared responsibilities.

A $20M Series A led by Evolution Equity Partners, and more than 4,000 organizations using its dynamic application security testing products.

The original product failed not on capability but on operability — a fuzzer that destroys its target demands infrastructure customers didn't have.

The pivot traded a spectacular demo for a product teams could actually run, and the 4,000-organization base followed.

The rename closed out a name that no longer matched the company — and a crowded namespace of 'Neura' startups.

A product can be too good to use: if customers can't safely operationalize it, pivoting to the version they can run isn't a retreat.

As of the March 2022 announcement, Bright Security was live with 4,000+ organizations, freshly capitalized with $20M, and deliberately staying focused on DAST rather than expanding into adjacent testing categories.

FOLLOW THE EVIDENCE

The sources

  1. NeuraLegion becomes Bright Security and raises $20M Series A techcrunch.com