security
May 13, 2026
By Teun
JupiterOne adds AI attack surface and vulnerability tools
JupiterOne has launched two new products, AI Attack Surface Management and Unified Vulnerability Management, to help security teams track AI sprawl and prioritize vulnerabilities. The company says the tools map assets, identities and AI agents together so teams can see what matters to business risk.
JupiterOne Inc. said today it is launching two new products aimed at helping security teams manage the growing risk from AI systems spread across enterprise environments.
The company is introducing AI Attack Surface Management, or AI ASM, and Unified Vulnerability Management, or UVM. JupiterOne says both tools are meant to connect assets, vulnerabilities and AI agents to business risk in a single view.
JupiterOne’s pitch is that enterprises are deploying AI tools, software-as-a-service applications and cloud resources faster than security teams can keep track of them. At the same time, the company says AI agents are now touching nearly every system, while vulnerabilities are accumulating faster than teams can review and prioritize them.
AI ASM is designed to close that visibility gap. According to JupiterOne, the product provides a continually updated, relationship-aware view of the enterprise through automated discovery across hundreds of integrations.
The company says AI ASM maps how AI agents, systems, cloud resources and identities interact in one place. Security teams can query that data in plain English or through JupiterOne’s native query language to understand what exists, how assets connect, how they might be exploited and what business impact could follow.
Chief Executive Paul Forte said AI has changed the attack surface and that new models are increasing the number of possible weaknesses every day. He said most teams are dealing with fragmented tooling and do not have a clear view of how their systems interact.
“This launch gives defenders a streamlined approach to assessing risk without stitching together separate tools, programs, or teams,” Forte said.
The second product, UVM, is aimed at vulnerability prioritization. JupiterOne said traditional scanners can show what may be vulnerable, while severity scores often reflect theoretical risk rather than the reality of a specific environment.
UVM evaluates vulnerabilities in the context of each customer deployment. The company said it analyzes the flaw alongside the full attack chain to show what is vulnerable, what it is linked to and how an attacker could move through those paths to reach business-critical assets.
JupiterOne also said the tool deduplicates findings across products and identifies asset ownership. The company says that can shorten remediation cycles by routing fixes to the people responsible for them.
Both offerings are built on JupiterOne’s graph-native data platform, which already underpins its broader AI risk management message. The company markets itself to security teams in highly regulated industries and says the graph model helps users query how risk flows across assets, identities and controls rather than relying on static lists.
Chief Product Officer Kevin Tonkin said security teams are dealing with too many vulnerabilities and too little context. He said connecting vulnerabilities to the assets and attack paths around them, and showing who owns what needs to be fixed, helps teams remediate more efficiently.
JupiterOne said it has raised $119 million across four rounds. Investors include Bain Capital Ventures, Sapphire Ventures, LifeOmic Security, Cisco Investments, Splunk Ventures, Rain Capital Fund LP, Tribe Capital Management, Heavybit Industries Inc. and Sands Capital Ventures.