Help shape how security teams validate real attack paths.
Dravian is selecting five organizations to deploy, validate, and help shape Vector through a structured 12-month partnership with our founding product and engineering team.
The program is designed for mature security organizations that already generate large volumes of findings but still depend on manual investigation, fragmented tools, and periodic offensive testing to understand which exposures can become real attacks.
Limited to five organizations. Applications close September 30, 2026, or when the founding cohort is complete.
Applications are reviewed directly by Dravian's founding team. Submission does not guarantee acceptance.
Security teams do not lack findings. They lack continuous validation.
Modern security teams receive findings from application security, cloud security, identity, infrastructure, vulnerability management, and detection tools.
Most of those systems evaluate risks independently.
Determining whether multiple findings can be connected into a credible attack path still frequently depends on manual investigation, internal expertise, scripts, consultants, or periodic offensive testing.
Vector is being built around a specific hypothesis: security teams need a continuous way to validate and prioritize the combinations of exposure that can materially affect the organization.
The Founding Design Partner Program exists to challenge that hypothesis against real environments, operating constraints, security workflows, and measurable outcomes.
An offensive intelligence layer for the existing security stack.
Vector connects and analyzes security findings, infrastructure relationships, identities, application context, and approved operational data to help teams understand credible attack paths.
Vector does not autonomously exploit customer infrastructure. It does not replace penetration testing, red teams, SIEM platforms, CNAPP platforms, vulnerability scanners, or existing security controls.
- Complement existing security products
- Operate inside the customer-controlled environment
- Use read-only access by default
- Support human review and approval
- Connect findings across multiple security domains
- Help prioritize remediation using attack-path context
- Reduce dependence on isolated analysis
- Preserve customer control over sensitive data and deployment
Not everyone is a fit. That is the point.
- A dedicated security leadership function with an executive sponsor
- A technical or operational champion who can drive implementation
- A cloud-native, software-driven, or technically complex environment
- Material regulatory, contractual, or compliance obligations
- A recurring challenge prioritizing or validating security exposures
- Budget and organizational readiness for a paid annual enterprise engagement
- Looking for a free proof of concept or a traditional one-time pentest
- No executive owner or path toward production use
- Cannot allocate technical or operational resources
- Unwilling to participate in structured feedback
- No realistic procurement or budget path
Series B and later-stage technology, fintech, regulated financial services, healthtech, enterprise B2B SaaS, and other highly regulated or technically complex organizations.
United States · United Kingdom · European Union
SOC 2 Type II · ISO 27001 · HIPAA · HITRUST · PCI DSS · GDPR · DORA · sector-specific requirements. Compliance status alone does not determine acceptance.
Twelve months from hypothesis to operational evidence.
Foundation
- · Confirm the operational problem
- · Establish the deployment architecture
- · Define success criteria and baseline measurements
- · Deploy Vector in the agreed environment
- · Executive kickoff
- · Architecture and security review
- · Deployment planning
- · Integration configuration
Co-Design
- · Validate Vector in real workflows
- · Review outputs with the customer team
- · Identify product gaps
- · Improve relevant workflows
- · Weekly structured feedback sessions
- · Product and workflow reviews
- · Roadmap discussions
- · Measurement of agreed outcomes
Operationalization
- · Establish repeatable product use
- · Move from initial validation into recurring workflows
- · Improve adoption across the agreed team
- · Measure sustained operational impact
- · Recurring operational use
- · Adoption monitoring
- · Additional configuration within the agreed scope
- · Executive business review
Prove and Expand
- · Review the full-year results
- · Determine production expansion
- · Define renewal scope
- · Identify additional environments, teams, or workflows
- · Renew the core Vector subscription
- · Expand into additional environments
- · Add business units or product modules
- · Add separately scoped professional services
Foundation Phase Exit Option
At the end of month 3, either party may elect to conclude the engagement if the initial deployment, technical fit, or operational alignment does not meet mutually defined criteria. No additional financial obligation is incurred beyond the Foundation phase.
This exit option is a structural element of the program. It exists so both organizations enter with a clear path to conclude early if the alignment does not materialize.
We agree on a focused set of operational outcomes before implementation begins. Examples include:
- · Validate credible attack paths that previously required manual investigation
- · Reduce the time required to investigate a potential attack path
- · Improve remediation prioritization across categories of findings
- · Change or confirm a material security decision
- · Establish repeatable use by the designated customer team
Dravian does not guarantee a predetermined finding, vulnerability, or security outcome. The program is designed to determine whether Vector creates measurable operational value.
Organizations that successfully complete the program and continue using Vector retain preferred Founding Design Partner terms for the qualifying subscription.
- · Preferred renewal pricing while the subscription remains active
- · Applies to the agreed core Vector subscription
- · Requires continuous subscription and timely payment
- · Additional environments, business units, or services may require a separate agreement
Specific pricing and discount details are handled during the commercial phase of the selection process, not published on this page.
A design partnership is reciprocal. Both sides show up.
- Direct communication with the Dravian product and engineering team
- Weekly feedback sessions during the initial six-month co-design period
- Quarterly executive reviews and documented roadmap visibility
- Meaningful influence over applicable product decisions
- Early access to selected product capabilities
- Preferred Founding Design Partner commercial and renewal terms
- Access to the closed founding cohort peer network
- An engaged executive sponsor and a technical or operational champion
- Access to a production or production-representative environment
- Weekly participation during the first six months
- Honest product, implementation, and workflow feedback
- Collaboration on success criteria and outcome measurement
- Participation in a mutually approved case-study or reference process
Participation does not guarantee that every requested feature will be built. Custom development, additional environments, professional services, and premium support outside the agreed scope may require a separate commercial agreement.
Reference and case-study formats — named, anonymized, private, or executive quotation — are mutually approved. Named public disclosure is never automatically required.
Designed for controlled environments. Built with matching rigor.
- Customer-controlled, self-hosted or private-cloud deployment
- Customer-controlled keys and model configuration
- Read-only access by default and least-privilege permissions
- Human review for sensitive actions
- No sale of customer data. No egress by design.
- Security and architecture review before production use
- · Customer-controlled deployment as default architecture
- · Security review conducted before any production deployment
- · Confidentiality governed through NDA, MSA, and data-processing terms
- · Documented internal security practices and access controls
- · SOC 2 Type II readiness program
- · Formal information security policies and controls documentation
- · Third-party security review of Dravian's product and infrastructure
We will not claim certifications, controls, or capabilities we have not formally achieved. Partners have full visibility into current controls, roadmap items, and any documented gaps during the architecture and security review, before any production deployment.
You work directly with the people building Vector.
This is not a channel sale, a partner delivery model, or a services engagement fronted by an account manager. Direct communication with the founder throughout the program. Executive-to-executive engagement during quarterly reviews. No layer of sales representatives between the customer and the people writing the code.
- Prior product leadership in regulated healthcare technology environments, including HIPAA-regulated platforms.
- Enterprise sales experience with large technology, financial services, and consumer platform organizations.
- Prior founder experience in artificial intelligence product development, including partnerships with major cloud providers.
- Ongoing engagement with the offensive security and CISO community.
Five positions. Selected for fit, not volume.
- · Severity and frequency of the problem
- · Executive commitment
- · Technical fit
- · Production readiness
- · Ability to participate
- · Procurement and budget readiness
- · Strategic relevance
- · Reference and case-study feasibility
- · Ability to create measurable evidence
The initial cohort is designed to include organizations from multiple regulated verticals to enable meaningful cross-industry learning. Expected representation includes:
- · Financial services and fintech
- · Healthcare technology and healthtech
- · Enterprise B2B SaaS with material regulatory obligations
The final composition depends on application quality, technical fit, and organizational readiness rather than a strict vertical allocation.
The program is not first come, first served.
Dravian may close applications before September 30, 2026 once the five-partner cohort is complete.
Answers to what applicants ask most.
01Is this a free beta?
02How many organizations will be accepted?
03When do applications close?
04Does applying guarantee acceptance?
05Can we exit the program early if the fit is not right?
06Do we need to deploy Vector in production?
07Will Dravian build every feature we request?
08Can the engagement remain confidential?
09Is a public case study required?
10What does the Founding Cohort peer network include?
11What certifications does Dravian currently hold?
12What happens after the first year?
Bring us a real security problem.
We are selecting five organizations willing to deploy Vector, test our assumptions, contribute operational expertise, and help establish a new standard for continuous offensive security.
Applications are reviewed directly by Dravian's founding team.