EN
返回档案库

档案库 · 开发与企业工具 · 战略决策 · 2024–2026

SubImage 押注开放核心安全图谱,挑战 Wiz

SubImage(YC W25)押注安全团队想要一个可扩展的开放核心替代 Wiz 的方案:Cartography 的创始人在 2025 年 11 月筹集了 420 万美元的种子资金。

SubImage

它在赌什么企业会选择一个开放、可扩展的安全图谱,而不是封闭的平台,因此保持核心开放并让团队丰富它,可以赢得 Wiz 定义的市场。已上线

做的是什么生意

SubImage sells a hosted security platform that maps AWS, SaaS and internal infrastructure into a queryable graph, exposes attack paths and misconfigurations, and generates fixes such as AWS CLI commands or automated infrastructure-as-code pull requests.

启动资金$4.2M seed (announced 2025-11-17) from FundersClub, Y Combinator, Phosphor Capital and Transpose Platform.

起因

Alex Chantavy, who started in security at the NSA and later led penetration tests on Microsoft's Red Team, joined Lyft in 2019 and helped build Cartography to map cloud infrastructure as an attacker would. Kunaal Sikka, a Lyft staff engineer, co-created the project; the two kept working together and founded SubImage in 2024, joining Y Combinator's Winter 2025 batch and launching on Hacker News on 2025-02-24.

经过

The launch pitch was direct: Cartography was a CNCF project used by more than 70 companies, and SubImage would 'pick up where Cartography leaves off' with a fully hosted offering, fix suggestions, a natural-language query interface and custom data enrichment. The founders positioned the product as an open-core alternative to Wiz, raised a $4.2M seed before YC Demo Day, and announced it publicly on 2025-11-17 with plans to grow the engineering team and expand customer pilots.

结果

As of 2026-09-05 the company is still active: Y Combinator's directory lists SubImage as an active Winter 2025 company with a four-person team in San Francisco, still maintaining Cartography as open source while building the managed offering on top.

背景

SubImage 由 Alex Chantavy 和 Kunaal Sikka 于 2024 年创立,销售基于 Cartography 的托管安全图谱平台,Cartography 是两人于 2019 年在 Lyft 创建的开源工具。它将云、SaaS 和内部基础设施映射到图谱中,使安全团队能够看到通往敏感数据的攻击路径,并获得具体的修复建议,而不是又一个警报流。

战略赌注是开放性:虽然 Wiz 普及了云原生安全平台,但 SubImage 作为开放核心替代品推出,让客户用自己的数据扩展图谱、编写 Python 插件并检查底层模式,而不是被锁定在专有生态系统中。

Cartography 的历史提供了切入点。该项目为 Lyft 红队创建,于 2019 年开源,后来被 CNCF 采用,为 SubImage 提供了一个由 70 多家公司组成的社区,创始人可以向其销售托管层。公司经历了 Y Combinator 的 Winter 2025 批次,并于 2025 年 2 月 24 日在 Hacker News 上公开发布,获得了 135 分。

SubImage 于 2025 年 11 月 17 日宣布了 420 万美元的种子轮融资,来自 FundersClub、Y Combinator、Phosphor Capital 和 Transpose Platform。截至 2026 年 9 月 5 日,它仍然是旧金山一家活跃的四人的公司,在维护 Cartography 的同时,构建修复、变更跟踪和访问管理功能。

这件事要成立,得有什么

  • 安全团队已经信任 Cartography,因此 SubImage 的托管产品以参考社区亮相,而不是冷启动。
  • 保持图谱开放,让客户能够验证发现结果的生成方式,并将覆盖范围扩展到专有的内部系统,这是封闭竞争对手难以匹敌的信任优势。
  • 基于图谱的攻击路径建模来自创始人的红队经验,这为产品提供了竞争对手无法复制的可信起源故事。
  • 自动化修复,从为小团队提供 CLI 命令到为大型团队提供 IaC 拉取请求,目标是可见性工具通常止步的“最后一英里”。

可借鉴之处

开源项目可以成为护城河和分发渠道:将 CNCF 工具的托管层货币化给了 SubImage 信任和用户群,而这些通常是种子阶段的供应商需要花钱购买的。

后续进展

截至 2026 年 9 月 5 日,SubImage 是 Y Combinator Winter 2025 的一家公司,在旧金山有四人的团队。它于 2025 年 11 月 17 日从 FundersClub、Y Combinator、Phosphor Capital 和 Transpose Platform 筹集了 420 万美元的种子资金,用于工程招聘、客户试点和缩短修复时间的功能。Cartography 仍然是 CNCF 下的开源项目,公司宣布的路线图包括修剪过度权限、强制执行安全不变量、检测有风险的基础设施变更以及扩展跨云和 SaaS 的错误配置覆盖。

资料来源

发现哪里写错了?告诉我们。

轮到你了

你刚读完一家。说说你在做什么,看看谁在赌同一件事。

免费账号 · 3 次免费提问 · 不用绑卡

相关案例