The Zynap Manifesto

zynap why we built V3

A letter from the founders · Dani Solís & Oriol Agustí

We’ve spent years in the trenches of cybersecurity, watching up close how cybercrime evolves, organizes, industrializes and monetizes, and how fast it adapts the moment money, talent and incentives line up.

Cybercrime is accelerating again. Right now.

AI is already making attackers faster, cheaper, more scalable and more adaptive. More automation. Better personalization. Continuous improvement. What used to take a skilled attacker weeks now takes hours. And that gap keeps closing.

The uncomfortable part is realizing it’s not a fair fight. Defenders are playing by the rules, everything from regulation and compliance to process, budget and the obligation to be precise. The bad guys just don’t. They move faster. They have fewer limits. They reinvest their profits. They attract talent. They buy access, infrastructure, capabilities. And now they have AI too.

That should worry all of us. Because if the attacker is evolving this fast, defense can’t stay where it is.

And today, if we’re honest, too much of cybersecurity is still reactive. Too many tools. Too many alerts. Too much noise. Too many handoffs. Too many decisions made without context. Too much manual work between systems that were supposed to help. We’ve watched great security teams burn their best hours fighting their own stack while the attacker just kept moving.

It’s a workflow problem, not a tooling one: intelligence sits in one place, exposure management in another, automation in a third. Every handoff costs time. And time is the new risk.

The industry gave us tools. What defenders need now is different: to stop watching and start acting. To defend actively, and close the window the attacker is counting on before it can be used against them.

Active defense used to mean deception and hacking back. We mean something more useful: reducing exploitable risk before impact, with people in control of every decision that matters. That’s why we built Zynap.

Part of this conviction was born at Blueliv. Back then the idea was simple. Defenders were fighting blind, and they needed to see the attacker: the infrastructure, the stolen credentials, the campaigns, the intent. We built one of Europe’s threat-intelligence pioneers around that belief, and Outpost24 (then backed by Monterro, and later acquired by Vitruvian Partners) went on to acquire us.

But Blueliv taught us something we’ve never forgotten. Over and over, the same pattern: intelligence about the attacker in one place, and the reality of the business, its environment, its exposure, its priorities, somewhere else entirely. Different teams. Different tools. Different heads. The data was there. The products were there. But the two contexts never met. And the action was missing.

Customers had three, four intelligence feeds, and still didn’t know what to do with them beyond pasting reports and IOCs. Everything hinged on what the analyst already happened to know. A report that sits in a drawer protects no one. And intelligence you don’t act on fast is just a record of what you failed to prevent. 

For years the industry kept stacking layers on the same broken model. More dashboards. More alerts. More interfaces. TIPs, SOARs, feeds: all designed to optimize an operational reality that no longer exists. And now, more AI on top of the same disconnect. A copilot on top of chaos isn’t real transformation. It’s automation without intelligence, and that just automates the noise. 

We don’t believe in agentic noise. Copilots sell you tools; we’re here to deliver outcomes: defense that actually acts, not one more assistant telling you what you already know. AI on its own isn’t the product. Better security outcomes are. 

Real AI-native cybersecurity isn’t a model wrapped around an old workflow. It’s redesigning operations so defenders get more context, speed, precision and control, and the power to act before the damage is done.

That’s the heart of Zynap.

Security runs on two contexts. The attacker’s: who’s targeting you, what they’ve stolen, what they can exploit. That one we know first-hand: we’ve spent years building our own intelligence, reading signals most companies never get to see, from the side of the enemy that worries you most. And yours: your environment, your own exposure, your unique dependencies, the priorities of your business. Today the two live apart, in separate tools, separate teams, separate heads. And every decision loses time and precision crossing that gap.

What we’re building

We’re not building one more tool for the pile. We’re building the operational brain of active defense: the place where both contexts finally meet and become action, in the same motion, in one solution. From a signal nobody else caught, to what it means for your exposure, to a business decision (what to stop now, what can wait, which assets matter most), to the preemptive move that closes the window before anyone gets to use it. That end-to-end path is exactly where the market breaks. We built Zynap to walk it. All of it before impact. That’s the hard part. It’s also the whole point.

It takes weight off good people. It lets teams validate risk faster, prioritize what actually matters to their business, and act earlier, on top of the tools they already run. We won’t ask you to rip anything out. And it’s built not just to inform, but to act, always with humans in control.

Because the future of cybersecurity won’t be won by whoever owns the most dashboards. It’ll be won by whoever turns intelligence into action faster than the attacker turns opportunity into impact.

Security won’t be won from the alert queue. It’ll be won by acting on intelligence, in context, before impact. Get there before they do.

That’s the shift we’re building for.

From reactive to preemptive.

From isolated tools to active defense.

From noise to context.

From context to action.

From knowing to doing.

This is personal. We didn’t build Zynap to follow the market. We built it because we’ve seen, up close, exactly where it breaks. We’ve felt the noise good teams carry. We’ve watched brilliant people lose hours stitching context together by hand. And we’ve seen the bad guys get faster every single year.

We’re not interested in building one more cybersecurity company that makes the stack look modern while the problem stays exactly the same.

Great security companies are built by people who share a mission, not by technology alone. People who use technology to protect and to build, never to abuse it, and who want to do their best work and keep raising the bar. People with values. People who share what they know, who have each other’s backs, who understand that building something that matters is always bigger than individual credit.

Without that, none of the rest holds up. And if the good guys don’t work together, the bad guys win.

So this is where we stand: with the defenders. Because cybercrime isn’t slowing down. It’s scaling. And with AI, it’ll scale faster.

Defense can’t stay reactive. That’s why we built Zynap. And this is our mission: to help defenders outsmart cybercrime before impact.

Dani Solís & Oriol Agustí
Cofounders, Zynap