Astelia joins GuidePoint Security to cut vulnerability backlog with AI
Astelia, an AI-native exposure management platform, has agreed a distribution partnership with GuidePoint Security, giving the latter's enterprise client base access to Astelia's reachability analysis and agentic remediation capabilities. The announcement comes shortly after Astelia closed a $35 million funding round and reported several large enterprise renewals, though neither deal values nor customer names were disclosed.
The core proposition is selectivity. Astelia argues that conventional vulnerability scanners produce more noise than signal: severity-based triage made sense when the gap between a published CVE and a working exploit was measured in weeks, but frontier AI models are compressing that window to hours. The company says that once real network topology, privilege requirements, and dependency chains are factored in, roughly 1% of scanner findings represent genuine, reachable exposure. Its platform targets that fraction and then applies agentic remediation to generate fixes that extend beyond patching to configuration changes and network segmentation.
The deal
Astelia integrates with customers' existing scanners via read-only connections, rather than deploying endpoint agents or running active scans of its own. That approach reduces deployment friction and addresses a common objection from security teams wary of adding active tooling to already complex environments. The platform also independently surfaces newly disclosed and zero-day vulnerabilities, supplementing what legacy scanners catch.
Alon Noy, co-founder and chief executive of Astelia, made the case plainly: "Reachability analysis is how teams get their footing back. Only about 1% of what a scanner flags is genuinely reachable and exploitable once you account for the real network topology, and the fastest fix often isn't a patch at all but a configuration or segmentation change that cuts the attack path in minutes."
Mark Thornberry, SVP of Partnerships at GuidePoint, framed the partnership as a response to a specific gap in how enterprises consume vulnerability data. "Enterprises don't have a shortage of vulnerability data. They have a shortage of certainty about which findings actually put them at risk," he said.
Market context
The exposure management category is crowded and evolving quickly. Legacy vulnerability management vendors such as Tenable and Qualys are broadening their platforms toward continuous threat exposure management, a framework articulated by Gartner that emphasises exploitability and business context over raw CVSS scores. Newer entrants, including Pentera, XM Cyber and Cymulate, compete on attack-surface simulation and prioritisation. Astelia's differentiator, it claims, is combining topology-aware reachability analysis with agentic, automated remediation rather than stopping at ranked lists.
The timing is commercially sensitive. The EU's NIS2 Directive, which came into force across member states in late 2024, and the UK Cyber Security and Resilience Bill currently moving through Parliament both impose tighter obligations on organisations to demonstrate active vulnerability management, not merely detection. That regulatory pressure is nudging buyers toward tools that produce auditable evidence of risk reduction, not just dashboards of open findings.
GuidePoint is a well-established value-added reseller and managed security services provider with a broad enterprise install base, making it a meaningful distribution partner for a vendor at Astelia's stage. Channel partnerships of this kind are a standard go-to-market motion for cybersecurity startups looking to reach procurement-ready enterprise accounts without building a large direct sales team.
Astelia said the $35 million raise and multiple enterprise renewals are the foundation for accelerating channel expansion, though no further partnership names or geographic expansion targets were disclosed in this announcement.