Skip to main content
A

Atalya

Atalya provides a behavioral identity security platform that detects and contains account takeover attacks by learning each user's normal patterns across identity, mailbox, content, graph, and tenant signals. The platform revokes compromised sessions in under ten seconds and removes attacker persistence, all while processing data exclusively within the EU. It offers shadow-mode deployment, a 99.5% precision SLA on autonomous actions, and Spanish, Italian, German, French, and Portuguese payment-fraud detection.

HQ unknown
Updated yesterday

Funding

Funding not disclosed

Funding rounds are not available yet.

Founders

Founder details are not available yet.

Product

Problem

Standard security controls are designed to decide whether someone can log in, not to notice that the person who logged in this morning is not the usual user. Session tokens captured by phishing kits bypass multi-factor authentication entirely, and dangerous emails sent from a compromised internal account do not cross the perimeter gateway, making them invisible to traditional inspection. Incident response is further slowed by manually reconstructing forensic evidence, which delays NIS2 notifications and burdens security teams.

Solution

Atalya builds a per-identity behavioral model for every user in an organization, learning over a 21-day baseline how each person logs in, which devices and hours they use, who they correspond with, and what threads and counterparts belong to them. The Mirador engine correlates signals across five families—identity, mailbox, content, graph, and tenant—scoring deviations and using a language model to judge suspicious sequences against that identity's own history. When a case reaches sufficient confidence, Atalya autonomously contains the threat in under ten seconds by revoking sessions, blocking access, forcing password resets, removing hiding rules, and quarantining internally-sent phishing emails. All processing and storage remain within the EU, and the platform operates in shadow mode by default, giving administrators granular authority over which actions are automated. The platform also generates a complete behavioral chronology that serves as ready-made evidence for NIS2, DORA, ENS, and ISO 27001 reporting.

Target Audience

Primary customers are regulated organizations in the EU—including financial entities, critical infrastructure operators, and mid-to-large enterprises—whose security teams need behavioral account-takeover defense, NIS2/DORA reporting automation, and EU data residency guarantees.

Features

  • Continuous per-identity behavioral modeling with a 21-day baseline and ongoing updates across five signal families: identity, mailbox, content, graph, and tenant
  • Autonomous containment in under ten seconds: session revocation, access blocking, forced password resets, hidden-rule removal, and retroactive quarantine of phishing emails already sent from a compromised mailbox
  • Attacker persistence sweep that removes fraudulent authenticators, OAuth consents, mailbox delegations, and forwarding rules
  • Semantic payment-fraud detection tuned for Spanish, Italian, German, French, and Portuguese business correspondence, capturing fraudulent payment-instruction language that English-first models miss
  • Contractual SLA targets: ≥99.5% precision on autonomous actions, ≥92% recall on validated takeovers, ≤1 erroneous containment per 10,000 identities per month, <60-second detection time, <10-second containment time, and 100% of detections accompanied by an explainable behavioral chronology
  • Shadow-mode default with per-action authorization controls, one-click reversal for all automated actions, and mandatory human confirmation for irreversible actions during the first 60 days of deployment
  • Deployment via API with no MX change, no on-premise agent, and all data processed and stored on EU infrastructure with zero third-country transfers
  • FHIR-compatible export of behavioral timelines for use as pre-filled NIS2 24-hour, 72-hour, and final reports, plus DORA incident classification and ENS/ISO 27001 control mapping
This profile is AI-generated and may contain inaccuracies.