Clover Security is a design-led product security platform that puts AI agents into the tools where software is designed and built. Rather than scanning finished code, its agents work at design time — a different shape from the scanner-aggregation ASPM tools it sits alongside.
The company launched in November 2025 with $36M co-led by Notable Capital and Team8, with SVCI, the Wiz founders, and Shlomo Kramer participating, and later a strategic investment from ServiceNow. It was founded by CEO Alon Kollmann and CPO Or Chen.
What is Clover Security?
Clover’s argument is that reactive scanning cannot keep pace with AI-assisted development. When AI agents generate whole features in seconds, finding issues after implementation lands too late.
So Clover moves upstream. Its agents understand architecture, intent, and system behavior before code exists, bringing security into the design conversation instead of the post-mortem.
The agents start like a new team member: learning the organization’s context from existing documents and codebases, then extending manual work like design reviews, architecture reviews, and threat modeling.
Key capabilities
Clover packages its platform as a set of context-aware agents. Each one takes over a slice of product security work that used to be manual.
| Agent | What it does |
|---|---|
| Discovery | Surfaces critical changes and blind spots, and prioritizes risky features |
| Design review | Automates security review of designs and architecture |
| Security policy | Applies organizational policies inside developer workflows |
| Threat modeling | Generates continuous application- and code-level threat models |
| Developer guidance | Guides builders on secure decisions in their workflow |
| Governance | Tracks secure-design posture, standards adherence, and maturity |
| MCP | Gives visibility into AI-generated code and secures MCPs |
| Vibe coding | Checks vibe-coding and shadow AI for misconfigurations and missing controls |
Design-time threat modeling
The threat modeling agent auto-generates application- and code-level threat models from your existing codebase, diagrams, and documents. That reframes threat modeling from a one-off workshop into something continuous.
Design-to-implementation drift
Clover also watches for drift between the intended design and what actually ships. A secure design only holds if the code matches it, and the drift check is where design-time review meets the codebase.
Securing AI-assisted development
Two agents target the AI-native SDLC directly. The MCP agent enforces policies on coding agents and secures MCPs, while the vibe coding agent flags excessive permissions and missing controls in AI-assisted work.
Where it fits and how it compares
Clover sits in the ASPM neighborhood as an application security program platform, but it works differently by design. It does not deduplicate scanner findings; it works before those findings would exist.
That makes the comparison less about feature parity and more about philosophy. Phoenix Security and Jit route and remediate findings after scanners run, while Clover tries to eliminate whole classes of issues in the design phase.
The team’s background sits behind that bet. Clover’s founders and staff previously built security products at Microsoft, Checkmarx, and Dazz (acquired by Wiz), and cite that decade of reactive-tooling experience as the reason for the design-first approach.
Clover does not publish pricing and routes prospects through a demo request. For scanner-aggregation and remediation platforms in the same category, browse the full ASPM tools landscape on AppSec Santa.
