BLST Security
BLST Security is an Israel-based API security company that uses AI/ML to detect business logic vulnerabilities in APIs for AppSec and DevOps teams, offering the open-source Cherrybomb CLI tool and a tiered SaaS platform (Free, $20/month Standard, custom Enterprise).
- Company typePrivate
- Founded2022
- HeadquartersTel Aviv, Israel
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What BLST Security does
BLST Security is an Israel-based, privately held API security company founded in 2022 and headquartered in Tel Aviv. The company targets business logic vulnerabilities in APIs — application-specific logic flaws such as broken authentication flows, fraud scenarios, and privilege escalation paths that legacy security tools like WAFs and SAST scanners are not designed to detect. Its product surface comprises two offerings: Cherrybomb, an open-source Rust-based CLI tool for OpenAPI Specification validation and HTTP log mapping that has accumulated over 487 GitHub stars and functions as a developer acquisition channel; and the BLST Security Platform, a cloud-based SaaS product layered with AI/ML modules called Attacker (which simulates business logic attack flows during integration) and Decider (which learns normal API behavior and flags anomalies), along with a Runtime Validation feature that compares production HTTP logs against OpenAPI specifications to detect drift. The platform is offered in three tiers — Free (basic OAS scanning), Standard at $20 per month, and Enterprise (custom pricing) — and is sold through a hybrid go-to-market combining self-serve signup, online purchase for the Standard tier, and direct sales engagement (Book a Demo, Contact form) for Enterprise deals, including CI/CD pipeline and ticketing integrations.
BLST Security is led by four co-founders — Chaim Peer (CEO), Guy Levinger (CTO), Omer Elbaz (CDO), and Roy Barnea (Chief Architect) — with the full team reported at 1-10 employees. The company appears to be bootstrapped or self-funded, with no disclosed venture capital or institutional investment, and no subsidiaries, acquisitions, or mergers in its operating history. Its addressable market is horizontal, targeting AppSec and DevOps teams globally, with commercial availability extending beyond Israel into the United States, Canada, and the European Union.
The go-to-market motion is product-led growth centered on Cherrybomb, complemented by a Discord developer community, a weekly newsletter, a blog, LinkedIn presence, and a documentation portal. The company has no named enterprise customers, no disclosed revenue, no announced funding rounds, and no published AI benchmarks or research output. Its core value proposition is the claim that its AI/ML approach reduces cloud risks by over 90% when integrated into security workflows, supported by the technical premise that its algorithm is application-agnostic and learns per-customer traffic patterns.
BLST Security firmographics
Firmographics- Name
- BLST Security
- Legal name
- BLST Security Ltd.
- Website
- https://blstsecurity.com
- Company type
- Private
- Founded year
- 2022
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- BLST Security is an Israel-based API security company that uses AI/ML to detect business logic vulnerabilities in APIs for AppSec and DevOps teams, offering the open-source Cherrybomb CLI tool and a tiered SaaS platform (Free, $20/month Standard, custom Enterprise).
- Ownership category
- akta.pro rank
BLST Security industry classification
Industry- Product category
- API Security Software
- NAICS
- Security Systems Services (except Locksmiths) (561621), Security Systems Services (56162)
- SIC
- Services-Computer Programming Services (7371), Services-Prepackaged Software (7372)
- akta.pro primary industry
- API Security & Service-to-Service Security (mTLS, Service Mesh Security) (HDABAHAN)
- akta.pro secondary industry
- Software Supply Chain & Dependency Security (SBOM, Signing) (HDADACAD)
Keywords
Where BLST Security is headquartered
LocationHeadquarters
- HQ city
- Tel Aviv
- HQ country
- Israel
- HQ region
- Middle East
Offices1 record
Markets served
BLST Security business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D
Revenue model
- Platform Subscriptions: Tiered SaaS subscription model with three levels: Free tier for basic OAS scanning, Standard tier at $20/month for endpoint management and subdomain handling, and Enterprise tier with unlimited resources and advanced features including business logic problem detection and runtime validation. Enterprise pricing is custom/quote-based.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Monthly | Free tier for basic API security scanning with complete OAS scan, params table, and email support |
| Subscription | Monthly | $20/month for developers needing API understanding and improvement tools |
| Subscription | Annual | Custom enterprise pricing for complete API security solution |
Go-to-market motion1 record
Distribution channels3 records
Marketing channels6 records
BLST Security product offering
Product offeringCore offering
BLST Security provides an AI/ML-based API security platform that detects business logic vulnerabilities through behavioral analysis and attack simulation. The platform integrates into SDLC pipelines and is delivered via a cloud SaaS product (Basic, Standard, and Enterprise tiers) plus an open-source CLI tool called Cherrybomb for offline OpenAPI Specification validation and HTTP log analysis.
Product overview
BLST Security offers a unified API security platform consisting of two main products: (1) the BLST Security Platform — a cloud SaaS product with tiers (Basic/Free, Standard $20/mo, Enterprise/custom) that integrates into CI/CD pipelines to detect business logic vulnerabilities, map API endpoints, and perform runtime validation; and (2) Cherrybomb — an open-source CLI tool that validates OpenAPI Specifications and HTTP logs offline. The platform layers AI/ML capabilities (Attacker and Decider modules) on top of the CLI to simulate and detect business logic attacks, with the platform designed for AppSec and DevOps teams and Cherrybomb serving as the free, open-source entry point for developers.
Differentiator
Problem solved
Functional benefit
Brands
- Cherrybomb: Open-source API Security CLI tool that validates API specifications through OpenAPI Specification (OAS) scans, parameter tables, endpoint mapping, and visualization.
Quantifiable outcome
- Reduces cloud risks by over 90% when integrated into security workflows
Companies that use BLST Security
Customer profileSegments1 record
Ideal customer profiles2 records
BLST Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration3 records
AI capability5 records
Feature6 records
BLST Security partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- BLST Security Ltd.primaryBLST Security Ltd. is the legal entity registered in Israel that operates the BLST Security platform and services. Governed by Israeli law with jurisdiction in Tel Aviv courts.
Scale indicators2 records
Recent moves6 records
Expansion highlights5 records
BLST Security competitors and assessment
Company assessmentMarket position
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
BLST Security social profiles
Digital presenceBLST Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
BLST Security leadership team
Management profileNumber of profiles
Profiles4 records
BLST Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
BLST Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about BLST Security
What does BLST Security do?
BLST Security provides an AI/ML-based API security platform that detects business logic vulnerabilities through behavioral analysis and attack simulation. The platform integrates into SDLC pipelines and is delivered via a cloud SaaS product (Basic, Standard, and Enterprise tiers) plus an open-source CLI tool called Cherrybomb for offline OpenAPI Specification validation and HTTP log analysis.
Is BLST Security a public or private company?
BLST Security is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was BLST Security founded?
BLST Security was founded in 2022. It employs 1 to 10 people.
Where is BLST Security based?
BLST Security is headquartered in Tel Aviv, Israel, in the Middle East region.
How does BLST Security make money?
One revenue line is on record: platform Subscriptions.
Does BLST Security have an API?
No public API is recorded for BLST Security.
What industry is BLST Security in?
BLST Security's product category is API Security Software. Its primary akta.pro industry code is HDABAHAN, API Security & Service-to-Service Security (mTLS, Service Mesh Security), with a secondary code of HDADACAD, Software Supply Chain & Dependency Security (SBOM, Signing). Its NAICS code is 561621 and its SIC code is 7371.