Security News

Cybersecurity news aggregator

🤝
INFO News SecurityWeek

Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance

  • What: Kiteworks acquires Bonfy.AI to enhance AI-driven data security
  • Impact: Enhances real-time policy enforcement for sensitive data across human and AI workflows
Read Full Article →

Data Protection Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance Financials have not been disclosed, but the estimated cost is in the tens of millions of dollars. By Kevin Townsend | September 11, 2026 (6:56 AM ET) Flipboard Reddit Whatsapp Whatsapp Email Kiteworks has announced the acquisition of AI data security company Bonfy.AI, a move aimed at extending real-time policy enforcement over sensitive data exchanged by both human users and AI agents. Kiteworks delivers a content-sharing platform to safeguard sensitive data as it moves across enterprise networks, external organizations, and internal systems. It includes regulatory compliance, governance, and audit tracking. Bonfy.ai is an AI‑native content‑security platform protecting sensitive data across human workflows and AI‑agent reasoning. It offers real‑time classification, contextual enforcement, and cross‑SaaS governance. The cost of the acquisition has not been disclosed but is estimated by CTech at ‘tens of millions of dollars’. The Bonfy technology will be used to extend Kiteworks’ policy enforcement across agent and human data exchange and usage in real time and inline across email, file sharing, SaaS applications, data repositories, Internet-facing AI assistants, and autonomous agents. It fills, says Kiteworks, a structural gap in how enterprises protect sensitive data. Enterprises have detailed inventories of their sensitive data, but the inventories do not necessarily control what happens to that sensitive data when it is used or transferred. Bonfy technology fills this gap by classifying the data at the moment it is exchanged, and applying security policies before the transfer is completed – including when the exchange involves an AI assistant or autonomous agent. Advertisement. Scroll to continue reading. Combining this technology with the Kiteworks control plane for secure data exchange, says Kiteworks, governs data in motion and in use through a single policy model that applies equally to people, machines, and systems across the enterprise. “Bonfy.AI’s cutting-edge technology expands our coverage and capability to deliver the control our customers need in the AI era, and its excellent team will further accelerate the development of our unified Data Control Plane,” suggests Amit Toren, chief business officer at Kiteworks. This is the eighth Kiteworks acquisition in five years, with each one designed to expand the firm’s data security and compliance platform. The value of this acquisition includes a governed decision inline at runtime rather than a report after the fact; decisions based on genuine context rather than simple pattern matching; a single policy model for both human and AI workflows; enterprise-wide data exchange control; and provable compliance at the moment of decision. It becomes an extension of Kiteworks rather than a parallel product. “Everything we build comes back to a single promise to our customers: you stay in control of your private data, everywhere it moves and everywhere it is used,” comments Tim Freestone, chief strategy officer at Kiteworks. “Inline at runtime classification is what makes that promise complete. Knowing where sensitive data lives is part of the equation, but deciding, in the instant data leaves, whether it should leave, and being able to prove that decision to a regulator months later is a big gap we’re closing.” Bonfy was founded in early 2024 by Gidi Cohen and Danny Kibel. It emerged from stealth in June 2025 with $9.5 million in seed funding. “We built Bonfy.AI around a single idea: risk is created when data moves, not when it sits, and controlling it means reading the full context of an exchange at runtime, before it completes,” said CEO Cohen. “Kiteworks gives that technology a control plane and a reach we could not have built on our own. I’m excited to see it governing data for both people and AI agents at global scale.” Related : Palo Alto Networks Acquires AI Agent Platform Console Related : Fortinet Acquires AI Security Company Virtue AI Related : Watch on Demand: Cloud & Data Security Summit Related : Data Security Firm Evervault Raises $25 Million in Series B Funding Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Kevin Townsend AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser The Hidden Instructions That Can Hijack AI Agents OpenAI Agents Hijack Another Victim Website OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders Catch Raises $5 Million for AI Executive Assistant With Guardrails Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents Latest News Surfshark Systems Targeted by Hackers Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion PaperCut Flaws Exploited in AI-Powered Attacks Mandiant Founder Kevin Mandia Joins Amazon Board Cybersecurity M&A Roundup: 33 Deals Announced in August 2026 Anthropic Researcher Resigns With Warning About the Dangers of AI Development Hacker Conversations: Vinnie Liu, Performer Turned Ringmaster Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the Move Proofpoint has announced the appointment of Brian Levey as Chief Legal Officer and Puja Jaspal as Chief People Officer. Levey previously served as Chief Business Affairs & Chief Legal Officer at Upwork and played a key role in eBay’s growth and strategic transactions. Amazon has elected Kevin Mandia to its Board of Directors. Gigamon has named Grant Yacomeni as Chief Information Security Officer. More People On The Move Expert Insights This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email

Share this article