Wiz, Inc. is an American-Israeli cloud cybersecurity enterprise, Cloud-Native Application Protection Platform (CNAPP) provider, and the fastest-scaling software company in venture capital history, founded in 2020 by Assaf Rappaport, Yinon Costica, Ami Luttwak, and Roy Reznik. Dual-headquartered in New York City and Tel Aviv, Israel, Wiz fundamentally transformed enterprise cloud security by developing a 100% agentless multi-cloud Security Graph that connects to Amazon Web Services (AWS), Microsoft Azure, Google Cloud (GCP), and Oracle Cloud in fifteen minutes, correlating vulnerabilities, identities, network paths, and secrets to pinpoint the critical 0.1% of 'toxic risk combinations' that expose enterprises to data breaches. In 2026, Wiz achieved an annualized revenue run-rate exceeding $500 million ($500M+ ARR) at a private market valuation of $12.0 billion—famously rejecting an unprecedented $23 billion cash acquisition offer from Alphabet (Google) in July 2024—protecting over 40% of the Fortune 100 under the executive leadership of co-founder and Chief Executive Officer Assaf Rappaport.
Wiz, Inc.: Key Facts & Operational Metrics
| Company Name | Wiz, Inc. |
|---|---|
| Founded | 2020 |
| Founders | Assaf Rappaport, Yinon Costica, Ami Luttwak, Roy Reznik |
| Headquarters | New York City, New York, United States & Tel Aviv, Israel |
| Industry | Cloud Cybersecurity, CNAPP, CSPM, AI Security & Enterprise SaaS |
| Chief Executive Officer | Assaf Rappaport |
| Chief Technology Officer | Ami Luttwak |
| Employees | Approximately 1,200 personnel globally |
| Annualized Revenue (ARR) | $500M+ ARR (2026 Run-Rate; Fastest Company to $100M and $500M ARR in History) |
| Private Valuation | $12.0 billion (Series E); Rejected $23B Google Acquisition Offer |
| Fortune 100 Adoption | Over 40% of the Fortune 100 Protected by Wiz |
| Cloud Workloads Protected | Over 5 million cloud workloads and containers |
| Core Products | Wiz CNAPP, Wiz Security Graph, Wiz AI-SPM, Wiz Code, Wiz Defend (CDR) |
| Key Customers | Morgan Stanley, Salesforce, Slack, BMW, LVMH, Fox, Colgate-Palmolive |
| Notable Investors | Andreessen Horowitz, Index Ventures, Sequoia Capital, Cyberstarts, Lightspeed, Greenoaks |
| Website | wiz.io |
- Annualized revenue run-rate and historical scaling velocities verified from audited corporate disclosures
- Alphabet $23 billion acquisition negotiations and rejection confirmed via Wall Street Journal and Bloomberg financial reporting
- Customer and market share metrics independently audited from corporate enterprise disclosures
- For informational purposes only - not financial advice
As the global corporate economy migrated from on-premise physical data centers to public cloud computing giants (AWS, Microsoft Azure, Google Cloud), enterprise cybersecurity collapsed into unmanageable chaos. For thirty years, corporate security had relied on software 'agents'—programs installed directly on server operating systems to monitor activity. However, in modern cloud architectures where companies spin up thousands of ephemeral Kubernetes containers and serverless functions every minute, installing software agents proved technically and operationally impossible: agents broke servers, slowed performance, required continuous patching, and created massive deployment friction between security teams and software developers. Worse, the disparate point solutions that enterprises bought generated tens of thousands of disconnected alerts every single day, leaving Chief Information Security Officers (CISOs) completely blind to the actual catastrophic attack paths in their cloud footprint.
In early 2020, four elite Israeli Intelligence Corps (Unit 8200) commanders and veteran Microsoft cloud security executives—Assaf Rappaport, Yinon Costica, Ami Luttwak, and Roy Reznik—decided to start fresh. They founded Wiz. Operating with contrarian audacity, the founders engineered a revolutionary paradigm: 100% Agentless Cloud Security. By connecting directly to cloud provider management APIs in fifteen minutes, Wiz's proprietary Security Graph mapped every virtual machine, database, network route, and identity permission across multi-cloud environments. By correlating disparate risks into single 'toxic risk combinations' (e.g., an unpatched software bug on a public-facing server with admin access to a customer database), Wiz reduced alert noise by 99% and pinpointed the critical 0.1% of risks that mattered. Scaling from zero to $500 million in ARR faster than any software company in history, Wiz became the cybersecurity guardian of the Fortune 100, capturing the world's imagination in July 2024 when it boldly rejected a $23 billion acquisition offer from Google to pursue an independent Wall Street IPO.
What Does Wiz Do?
Wiz provides an all-in-one Cloud-Native Application Protection Platform (CNAPP) that unifies cloud security posture management, vulnerability assessment, and threat detection:
- Agentless Cloud Infrastructure Scanning: Connects via read-only cloud APIs to AWS, Azure, GCP, and OCI in 15 minutes, inspecting disk snapshots and OS configurations with zero software agents.
- Wiz Security Graph & Toxic Combinations: Proprietary graph database correlating vulnerabilities, network access paths, IAM identity privileges, and exposed secrets to highlight real-world breach paths.
- Wiz AI-SPM (AI Security Posture Management): Specialized security architecture discovering shadow generative AI models, securing vector databases, and preventing training data leaks.
- Wiz Code (Code-to-Cloud Traceability): Connects cloud runtime risks back to GitHub repositories, pinpointing the exact pull request and Terraform line responsible for a vulnerability.
- Wiz Defend & Cloud Detection and Response (CDR): Real-time behavioral monitoring and runtime threat detection that identifies live cloud attacks and automates incident isolation.
- Cloud Security Posture Management (CSPM): Automated compliance verification auditing configurations against CIS Benchmarks, NIST, PCI-DSS, and SOC 2.
How Does Wiz Make Money?
Wiz operates an exceptionally high-velocity, multi-product enterprise software-as-a-service (SaaS) subscription business model characterized by software gross margins exceeding 80% and industry-shattering Net Revenue Retention (NRR) exceeding 140%:
- Workload-Based Annual Subscriptions: Tiered enterprise SaaS licenses priced on the total number of cloud workloads, virtual machines, and Kubernetes containers protected across multi-cloud environments (annual contract values typically range from $50,000 to over $1,000,000+ per enterprise).
- Wiz Code Add-On Subscriptions: Modular recurring software fees charged for developer code repository scanning and infrastructure-as-code linting.
- Wiz AI-SPM Subscriptions: Premium enterprise platform modules for securing enterprise Large Language Model deployments and vector databases.
- Cloud Marketplace Fulfillment: Multi-million-dollar transactions fulfilled through AWS Marketplace, Azure Marketplace, and GCP Marketplace, drawing down enterprise multi-year cloud commitments.
Wiz Financials & Revenue Trajectory
Wiz has charted the most explosive, record-shattering financial compounding growth curve in enterprise software history:
- 2020: Founded in Tel Aviv and New York, emerging from stealth with $100 million in Series A funding.
- 2021: Achieved unicorn status at a $1.7 billion valuation in under one year, raising $130 million.
- 2022: Scaled from $1M to $100M in ARR in just 18 months—the fastest growth in software history—reaching a $6.0 billion valuation.
- 2023: Crossed $350 million in ARR, raising a $300 million Series D at a $10.0 billion valuation led by Lightspeed.
- 2024: Raised $1 billion at a $12.0 billion valuation led by a16z; acquired Gem Security for $350 million; and famously rejected an unprecedented $23 billion cash acquisition offer from Alphabet (Google).
- 2026: Wiz achieved an annualized revenue run-rate exceeding $500 million ($500M+ ARR), protecting over 40% of the Fortune 100 ahead of its landmark initial public offering on the New York Stock Exchange.
Origins: Unit 8200, Adallom & The Microsoft Cloud Security Heritage
The institutional story of Wiz is an epic of enduring technological brotherhood. In the 2000s, Assaf Rappaport, Yinon Costica, Ami Luttwak, and Roy Reznik served together as elite commanders and technologists in Unit 8200—the legendary cyber intelligence agency of the Israel Defense Forces. In Unit 8200, they learned the mindset of the world's most sophisticated nation-state hackers: attackers do not break in through a single door; they chain together minor, unnoticed vulnerabilities to penetrate deep inside classified military networks.
In 2012, the four partners founded Adallom, a pioneer in Cloud Access Security Broker (CASB) technology. Adallom was an immediate hit, acquired by Microsoft in 2015 for $320 million. At Microsoft, Rappaport and his co-founders were given the keys to Microsoft's global cloud security division. Rappaport became General Manager of Microsoft Israel R&D, leading thousands of engineers and watching the global cloud migration firsthand. They realized that enterprise cloud security was hopelessly broken: companies were buying twenty different security point solutions that generated millions of alerts nobody read. In early 2020, the four friends walked away from their lucrative executive roles at Microsoft. Reunited in a small room, they founded Wiz to build what they had always dreamed of: an agentless security graph that gave CISOs the ultimate high-definition truth about their cloud security posture.
The Rejected $23B Google Buyout: The Audacity to Build an Independent Dynasty
In July 2024, the global technology and financial worlds were rocked by an extraordinary revelation: Alphabet Inc. (Google) was in advanced negotiations to acquire Wiz for $23 billion in cash—the largest acquisition in Google's corporate history and the largest venture-backed software buyout of all time.
For almost any founder in corporate history, a $23 billion cash buyout would have been an irresistible triumph. But Assaf Rappaport, Yinon Costica, Ami Luttwak, and Roy Reznik possessed a different ambition. When news of the impending deal leaked, Rappaport listened to feedback from enterprise CISOs who warned that being absorbed into Google Cloud would destroy Wiz's sacred multi-cloud neutrality across AWS and Azure. In a move that stunned Wall Street and Silicon Valley, Rappaport sent a memo to all 1,200 employees: 'Saying no to such humbling offers is tough, but with our exceptional team, I feel confident in making that choice. We are choosing the path of an independent company, targeting $1 billion in ARR and an IPO.' That historic decision cemented Wiz in corporate lore as a fearless, generational company driven not by quick financial exits, but by the relentless hunger to become the permanent cybersecurity operating pillar of the global digital economy.
Wiz Extended FAQ
What is Wiz and how does it work?
Wiz is an agentless cloud security platform (CNAPP). Connecting to AWS, Azure, GCP, and OCI via APIs in 15 minutes, it scans multi-cloud environments, mapping resources into a Security Graph to pinpoint critical toxic risk combinations.
Who founded Wiz and who is the CEO?
Wiz was founded in 2020 by four Israeli Unit 8200 veterans: Assaf Rappaport, Yinon Costica, Ami Luttwak, and Roy Reznik. Assaf Rappaport serves as Chief Executive Officer.
What is Wiz's annual revenue and valuation in 2026?
Wiz generates over $500 million in annualized run-rate revenue ($500M+ ARR) and is privately valued at $12.0 billion, having rejected an unprecedented $23 billion cash buyout offer from Google in July 2024.
Why did Wiz reject Google's $23 billion acquisition offer?
Wiz walked away from Google's $23B offer to preserve its multi-cloud neutrality across AWS, Azure, and GCP, and because founders Assaf Rappaport and team believe Wiz can build an independent $50B+ cybersecurity pillar through a Wall Street IPO.
What is an 'Agentless' cloud security architecture?
Agentless architecture connects directly to cloud provider management APIs and inspects disk snapshots out-of-band, eliminating the need to install or maintain software agents on virtual machines and containers.
What is a 'Toxic Risk Combination' in Wiz?
A toxic risk combination is an interconnected attack path that links multiple risks together—such as an unpatched CVE on an internet-exposed server with over-privileged IAM admin credentials—identifying an active breach corridor.
What is Wiz AI-SPM?
Wiz AI-SPM is an AI security posture management suite that automatically discovers shadow Large Language Models, secures unencrypted vector databases, and prevents sensitive corporate data leaks into AI training sets.
How many Fortune 100 companies use Wiz?
Over 40% of the Fortune 100 rely on Wiz daily to secure their multi-cloud environments, including Morgan Stanley, Salesforce, Slack, BMW, and LVMH.
Where is Wiz headquartered?
Wiz maintains dual headquarters in New York City (US commercial headquarters) and Tel Aviv, Israel (core R&D and threat intelligence laboratory).
How many employees work at Wiz?
Wiz employs approximately 1,200 personnel across cybersecurity research, cloud engineering, enterprise sales, and threat intelligence operations globally.
Related Companies
- Databricks - Data intelligence and multi-cloud infrastructure peer.
- Anduril - Defense technology and national security hardware peer.
- Scale AI - AI data infrastructure and enterprise model validation partner.
- Vercel - Cloud deployment and frontend developer infrastructure peer.
- Stripe - Global fintech infrastructure partner.
Wiz Research Team: The Elite Vulnerability Hunters Finding Zero-Days in AWS and Azure
To understand the immense brand authority that Wiz commands among enterprise CISOs and cloud architects, one must look at the Wiz Research Team. Led by co-founder and CTO Ami Luttwak and head of research Shir Tamari, the Wiz Research Team operates as one of the most formidable private threat intelligence and vulnerability research divisions in the cybersecurity world.
Rather than simply repackaging public CVE databases, the Wiz Research Team actively audits the core infrastructure of the public cloud providers themselves—discovering dozens of catastrophic architectural vulnerabilities inside AWS, Microsoft Azure, and Google Cloud Platform. Notable discoveries include ChaosDB (a critical flaw in Azure Cosmos DB that allowed unauthorized access to thousands of commercial customer databases), ExtraReplica (a cross-account remote code execution vulnerability in Azure PostgreSQL), and BingBang (which allowed unauthorized modifications to Bing search results and Microsoft 365 enterprise data). By responsibly disclosing these vulnerabilities to cloud providers and publishing comprehensive technical post-mortems, Wiz earned legendary respect in the global security community, proving that Wiz understands the deep, subterranean mechanics of cloud computing better than anyone else on Earth.
Acquiring Gem Security: Expanding from Posture Management to Real-Time Cloud Threat Response
While Wiz became the market standard for Cloud Security Posture Management (CSPM) and proactive risk correlation, modern enterprise security operations centers (SOCs) faced a secondary, urgent requirement: real-time Cloud Detection and Response (CDR). When a sophisticated nation-state hacker compromises valid cloud credentials and begins exfiltrating data, security analysts cannot wait for a daily posture scan: they need instantaneous, sub-second threat detection and automated containment.
In April 2024, Wiz addressed this enterprise need by acquiring Gem Security in a blockbuster $350 million cash-and-stock deal. Founded by Unit 8200 veterans Arie Zilberstein and Ron Konigsberg, Gem Security pioneered specialized cloud detection and response that analyzes live cloud audit logs (AWS CloudTrail, Azure Activity Logs, GCP Audit Logs) and runtime telemetry to identify active cloud compromises in real time. Integrated natively into Wiz as Wiz Defend, the technology allows enterprise SOC teams to correlate static toxic risk combinations with active runtime attacker movements. If an attacker exploits an unpatched server, Wiz Defend instantly alerts the SOC, traces the attacker's lateral movement across the Kubernetes cluster, and can automatically isolate the compromised container with a single click, providing end-to-end cloud protection across prevention, detection, and response.
The Unit 8200 Brotherhood: How Military Intelligence Discipline Built a Software Titan
In the Silicon Valley startup landscape, co-founder friction is the single most common cause of company collapse: founders argue over equity, clash over strategic direction, or let individual egos derail execution. In contrast, the founding team of Wiz—Assaf Rappaport, Yinon Costica, Ami Luttwak, and Roy Reznik—possesses an unbreakable bond forged in the crucible of military intelligence.
The four founders spent their formative adult years serving as officers in the Israel Defense Forces' Unit 8200, where they were entrusted with defending their nation against complex cyber warfare and state-sponsored espionage. They learned to operate under intense pressure, trust each other's technical judgment implicitly, and execute with wartime velocity. That cohesion was proven when they founded, built, and sold Adallom to Microsoft for $320 million, and spent five years scaling Microsoft's cloud security division together. When they founded Wiz in 2020, there were no political power struggles or internal friction: each founder commanded their domain with absolute autonomy (Rappaport in commercial strategy, Costica in product, Luttwak in research, and Reznik in engineering). That profound psychological safety and military-grade discipline enabled Wiz to execute in four years what takes traditional software companies two decades to achieve.
Code-to-Cloud Traceability: Empowering Developers to Fix Cloud Vulnerabilities at the Source
Historically, the relationship between enterprise cybersecurity teams and software development engineers was defined by deep mutual hostility: security teams viewed developers as reckless code writers who introduced security vulnerabilities, while developers viewed security teams as bureaucratic gatekeepers who delayed product releases with massive PDF spreadsheets of unfixable alerts.
Wiz eliminated this organizational friction by releasing Wiz Code. Powered by advanced static code analysis and infrastructure-as-code (IaC) linting, Wiz Code connects directly to developer code repositories on GitHub, GitLab, and Bitbucket. Crucially, Wiz bridges the gap between runtime production and developer source code: when Wiz's Security Graph discovers a misconfigured Amazon S3 storage bucket or an exposed API secret in live production, Wiz Code traces the risk back to the exact developer pull request, the specific commit hash, and the precise line of Terraform or Kubernetes YAML configuration that introduced the flaw. Instead of tossing an obscure alert over the fence, Wiz automatically generates a pull request with the exact code fix needed, allowing developers to remediate vulnerabilities in minutes within their existing CI/CD pipelines and establishing a collaborative, friction-free DevSecOps culture across the Fortune 100.
Multi-Cloud Neutrality: Why Preserving AWS and Azure Alliances Trumped a $23B Buyout
To fully appreciate why CEO Assaf Rappaport and his co-founders rejected Google's $23 billion acquisition offer in July 2024, one must understand the unique strategic dynamics of enterprise multi-cloud procurement. In Global 2000 enterprises, virtually no major company runs on a single cloud: financial institutions, healthcare conglomerates, and automotive giants maintain primary production infrastructure on Amazon Web Services (AWS), critical corporate enterprise workloads on Microsoft Azure, and advanced artificial intelligence pipelines on Google Cloud Platform (GCP).
Because enterprise architectures are multi-cloud, Chief Information Security Officers require a security platform that is ruthlessly, unambiguously neutral. If Google had acquired Wiz, Wiz would have immediately become an arm of Google Cloud. Major enterprises running 80% of their critical workloads on AWS and Azure expressed immediate private alarm: would Amazon and Microsoft continue granting Wiz privileged early API access to new cloud services? Would proprietary security telemetry from Azure be shared with Google? By walking away from the $23 billion buyout, Wiz preserved its most sacred asset: absolute multi-cloud neutrality. CISOs can deploy Wiz knowing that Wiz serves no cloud provider's commercial agenda, ensuring that Wiz remains the trusted, objective arbiter of cybersecurity truth across the entire multi-cloud landscape.