SubImage CEO says attack path mapping can focus AI security agents
SubImage CEO Alex Chantavy says graph databases help AI security agents rank risk across cloud, identity and device data.
By Colin Brandt · Enterprise Reporter
· 3 min read
SubImage Inc. is positioning attack path mapping AI security as a way to give defensive agents the context needed to rank risks across cloud, identity and device systems. Alex Chantavy, the startup’s co-founder and chief executive, told theCUBE at Neo4j’s GraphTalk event that defenders need map-like models of enterprise environments because attackers do not move through infrastructure one alert at a time.
SubImage maps cloud, identity and device data into a single graph for security teams. The company has raised $4.2 million in seed funding after completing Y Combinator’s winter 2025 batch, according to SiliconANGLE’s report on the interview. The company’s valuation, revenue and headcount were not disclosed. Neo4j Inc. is listed among SubImage’s early customers.
The funding detail matters because SubImage is selling into a security market crowded with vendors attaching AI agents to existing alerting, posture management and identity products. A seed-stage company has to prove that its graph model produces better prioritization, rather than another dashboard for security teams to maintain. For context on how expectations shift after an early round, see Venture Post’s guide to Seed vs Series A.
How does attack path mapping help AI security agents?
Attack path mapping models the relationships an attacker could use to move from an exposed asset to sensitive systems or data. For an AI security agent, that graph can show which weakness is part of a plausible route to impact, instead of treating every alert as an isolated item.
Chantavy said the useful property of graphs is their ability to keep related context close together. In his framing, a defender needs to know whether a compute instance is reachable from the internet, which permissions it uses and who last interacted with it. Those are relationship questions, and SubImage’s argument is that they are harder to represent cleanly in traditional relational systems when cloud assets, identities and devices have many overlapping connections.
Chantavy’s background gives the pitch some operator context. He previously worked in government cybersecurity and on Microsoft Corp.’s Azure Red Team. Before SubImage, he helped create Cartography, an open-source tool developed at Lyft Inc. for mapping cloud environments. Cartography was later donated to the Cloud Native Computing Foundation, according to the report.
Why graph databases are showing up in AI security
The renewed interest in graph databases comes as enterprises try to define how AI agents should authenticate, act and be governed. SiliconANGLE reported that security teams are already confronting agents with broad and sometimes unsupervised access. That raises a practical problem: if an agent is supposed to remediate or recommend action, it needs a reliable model of what matters first.
Chantavy compared the current stage of AI agent security to the early cloud-native period, when companies such as Lyft built internal open-source tools before mature vendor categories existed. That comparison is useful, but it is also early-market positioning. SubImage has disclosed seed funding and a named early customer, but it has not disclosed commercial scale, deployment volume or measurable risk-reduction results.
Neo4j hosted the GraphTalk event where the interview took place. SiliconANGLE said theCUBE was a paid media partner for the event and that Neo4j and other sponsors did not have editorial control over the coverage.
This story draws on original reporting from SiliconANGLE.