C2A Security is a privately held cybersecurity vendor founded in 2016 and headquartered in Jerusalem, Israel, focused on risk-driven DevSecOps for regulated, software-defined products—especially in automotive and mobility. Operating with long-term enterprise licensing and targeting North America, Europe, and Asia-Pacific, the company has raised $18.7 million to date (including $6.5 million in 2019) and is aiming for a Series B round. With around 40 employees and an experienced leadership team, it is investing heavily in R&D and has gained traction with multiple Tier 1 automotive OEMs.
Its flagship platform, EVSec, provides end-to-end product security, compliance, and automation across the full lifecycle: design, development, operations, and post-market surveillance. The platform’s differentiation is a holistic, risk-based automation approach that unifies security and compliance workflows rather than treating them as separate, manual processes. Core capabilities include multi-level SBOM and HBOM management, contextual vulnerability assessment, automated compliance reporting, and collaborative task orchestration to coordinate remediation across teams and stakeholders.
A key innovation is EVSec AutoSynth, which layers generative AI on top of a proprietary cyber model to consolidate threat intelligence, binary scanning outputs, and risk metrics into a unified governance dashboard. EVSec supports out-of-the-box alignment with major frameworks and regulations such as UN R155/156, the EU Cyber Resilience Act, and IEC 62443, enabling faster releases without sacrificing assurance. While the company’s specialization and regulatory alignment are strengths, challenges include a market still driven more by compliance mandates than organic demand, a heavy automotive focus with only early expansion beyond it, and lower visibility versus larger general-purpose DevSecOps vendors.
See All Locations
See All Locations