Company intelligence
Mimic
Kernel-level known-good enforcement. Unauthorized change is blocked before it executes.
About Mimic
Mimic is an enterprise security company built on known-good enforcement at the kernel. Detection-based security asks whether an activity matches a known threat, which requires knowing the attack in advance. Mimic asks a different question: was this change authorized? A novel exploit with no signature, a signed binary performing unauthorized actions, an AI agent holding valid credentials, and a misconfigured administrative script all fail the same enforcement test if their changes fall outside the authorized baseline. Mimic profiles a system in its authorized operational state, then evaluates every change against that baseline at Ring 0, the layer every file write, registry change, driver load, and process action must pass through. Enforcement runs through a file system mini-filter driver on Windows and eBPF on Linux, with the enforcement logic itself running in a WebAssembly sandbox implemented in Rust. Four capabilities run on that foundation: Ransomware Defense. Blocks the unauthorized changes ransomware depends on, rather than recognizing the ransomware. AI Shield. Governs what AI agents can do. Enforces declared scope at the kernel regardless of credential validity. Virtual Patching. Covers the window between vulnerability disclosure and patch deployment, and covers end-of-life systems that will never receive another fix. Change Control. Evaluates the change itself, where identity and workflow tools govern only the request. Founded in 2023 and headquartered in Palo Alto, Mimic has raised $77M. The Series A was led by GV and Menlo Ventures, with Ballistic Ventures, Team8, Wing Ventures and Shield Capital participating. Kevin Mandia and Ted Schlein serve on the board.
Verified activity
Signals from Mimic
1 published signal