
RAND, 8200, StarkWare and SSI alumni raise $20 million to secure AI
Attestable is betting that zero-knowledge cryptography can provide a new way for companies and governments to verify what happens inside increasingly powerful AI systems.
Attestable, an Israeli cybersecurity startup developing technology to verify the behavior of artificial intelligence systems, has raised $20 million in Seed funding led by TLV Partners and Altimeter Capital, with participation from Netz Capital, Cerca Partners and private investors including Assaf Rappaport, Yevgeny Dibrov, Nadir Izrael, Sharin Fisher Dibrov and Charlie Songhurst, a board member at Meta.
The company was founded in 2025 by three mathematicians: CEO Yogev Bar-On, CTO Shahar Papini and VP of R&D Shahar Samocha. Pepini previously worked at StarkWare and later at Ilya Sutskever’s AI company Safe Superintelligence (SSI).
Attestable is developing technology that allows organizations to verify which calculations an AI system is performing and what information it is using, without exposing the model itself or the sensitive data involved. The technology is aimed at organizations using AI for critical processes where security, resilience and reliability are essential.
The need for such capabilities is growing as AI systems move beyond experimentation and into decision-making and information processing in fields such as finance and defense. Organizations need confidence that AI systems are behaving as intended, but the models themselves are complex, and the systems around them can involve a large number of components, making them difficult to monitor and verify.
Attestable's technology is based on zero-knowledge proofs, a field of cryptography that allows one party to prove that a statement is true without revealing the underlying information used to prove it. The company says it has achieved a mathematical breakthrough that makes it possible to apply the technology to AI systems and generate rapidly verifiable proofs of how a model operates while keeping both the model and sensitive information confidential.
The company's longer-term ambition is to develop a technology that can be used by major AI labs to protect their systems from hostile actors, including foreign governments, while also allowing governments and large organizations to prove to one another that AI systems are being operated according to agreed security requirements.
Bar-On's path to founding Attestable began with work in information security before he moved to California about four years ago to focus on AI. He subsequently joined the RAND Corporation, a nonprofit organization that advises the U.S. government, where he became involved in the intersection between AI and national security.
"I worked in information security companies. I moved to California about four years ago to work on AI. There I joined the RAND Corporation, a nonprofit organization that advises the American government. There I became involved in the connection between AI and national security," Bar-On told Calcalist.
He said his co-founders brought complementary expertise. Pepini worked with him at Unit 8200 before moving to StarkWare and later SSI, while Samocha worked with Pepini at StarkWare.
"Pepini worked with me at 8200 and worked at StarkWare and then at Ilya Sutskever's SSI," Bar-On said. "He was a suitable figure for me because of the combination of his knowledge from StarkWare and SSI, a combination of AI and cryptography. It took me a long time to convince him to move from SSI, and Samocha worked with him at StarkWare."
Bar-On describes the company's initial objective in stark terms: protecting AI laboratories from sophisticated attacks aimed at stealing their models.
"We are developing a way to secure AI labs from attacks by foreign attackers, companies like Anthropic and OpenAI," he said.
He distinguishes Attestable from companies that focus on simulating attacks against AI systems.
"We are doing something different from Irregular. They do attack simulations. We are making a system that allows labs to maintain security and prove to a third party that they maintain security," he said. "This allows several parties to coordinate what is happening in their organization and also to prove to a second party what they are doing for security."
The problem, he said, is fundamentally difficult because it requires proving what an AI system is doing without requiring the parties involved to simply trust one another.
"This is a very difficult technology to solve. We are a group of mathematicians who think we can solve the problem, and we have managed to reach a significant breakthrough in the world of zero-knowledge proofs and practical technology for AI labs. Most were skeptical of our ability to achieve this."
Attestable currently employs 15 people, most of them at its development center in Israel, with the remainder based in California. Bar-On said the company has deliberately kept the team small and has relatively low infrastructure costs because its work is primarily mathematical rather than dependent on large amounts of computing power.
"We raised $20 million in November 2025 and we do not have many expenses, much beyond salaries," he said. "We only develop technologies at a mathematical level and do not need a lot of computing power. Our approach is a small team, but the best there is."
The company plans to use the funding to expand its team and continue developing its technology.
Bar-On believes that the technology could eventually become part of the infrastructure surrounding advanced AI systems, particularly as increasingly capable models begin to operate with greater autonomy.
"In the next stage, my vision is that whoever runs AI in the world will use our technology, which is a necessary technology," he said. "In our world of superintelligence, it is important to have control and accountability mechanisms."
His argument is that traditional cybersecurity tools may not be sufficient as AI systems become more capable and increasingly central to organizations.
"AI can be good and cure cancer, but it can do very bad things, and we must make sure that it only does good," Bar-On said. "With the help of our technology, we can make sure that we only do good."
He envisions Attestable's technology eventually becoming part of regulation and agreements between organizations that use increasingly powerful AI systems.
"We do not require the parties to trust each other. We mathematically prove what everyone does," he said.
The threat that Attestable is targeting is not limited to conventional cyberattacks. Bar-On argues that the AI models themselves are becoming increasingly valuable targets, as the cost of attacking sophisticated AI systems falls while the potential rewards from obtaining proprietary models rise.
"It is difficult to say if we see attacks, but the biggest concern of the laboratories is to defend themselves at the business level. Everything is based on the AI file they built, and protecting it is of the utmost importance," he said.
"Attackers will spend a lot of money on it, but stealing GPT-5 is a huge reward, and it will be easier to be an attacker today thanks to AI."
Yonatan Mandelbaum of TLV Partners said the firm was drawn to Attestable because it views AI security as a problem that will require more than adaptations of existing cybersecurity products.
"We understood that security for AI is interesting and important, and there are many good companies, but they are looking at what needs to be dealt with in the short term," Mandelbaum said. "What will come requires a new paradigm in a world where AI will do everything."
"In the new world, it will not be enough to have a new firewall or new intrusion-prevention software," he added. "The new world is not far away. We saw the recently published attacks of the different models."
Mandelbaum said he was struck by the founders' approach to the problem.
"When I met Yogev and Shahar, I saw a new way of thinking about AI security," he said. "The possibility of doing something like this is going to be one of the newest layers that allows AI to go out into the real world."
He said there may be setbacks as the industry works through the security challenges surrounding increasingly capable AI systems, but argued that the technology will continue to advance.
"This is not a security company, but a special company that has one of the strongest teams in the world in this field," Mandelbaum said.
The investment itself came together unusually quickly. "In my opinion, this is the first investment in Israel that came out of a baseball game," he said. "We sat at the game and five days later an agreement was reached."














