Koi Pitch Deck: All 9 Slides + Teardown

See all 9 slides of the Koi pitch deck — a 2024 Series A deck — with a slide-by-slide teardown of what the deck does well and where it falls short.

Koi’s 9-slide Series A deck is a masterclass in establishing urgency and credibility within a crowded cybersecurity market. By framing the problem as an 'evolution of endpoints' that traditional tools cannot handle—specifically targeting non-binary assets like AI models, extensions, and packages—Koi carves out a niche in a $17B market (Slide 1). The deck leans heavily on qualitative validation, dedicating entire slides to raw inbound Slack/form submissions (Slide 6) and testimonials from CISOs managing up to 130,000 endpoints (Slide 7). While it lacks a formal business model or financial proj…

Key takeaways

The $38M Narrative: Security for the Modern Endpoint

Koi’s 2024 Series A deck is a concise 9-slide presentation that successfully raised $38 million in a challenging venture environment. The deck’s primary strength lies in its ability to redefine a mature category—endpoint security—by focusing on a new, unmanaged attack surface: non-binary software assets. By moving away from traditional antivirus and toward the governance of AI models, browser extensions, and developer packages, Koi positions itself as a necessary evolution rather than a redundant tool.

Slide 1: The $17B Hook

The title slide is minimalist, featuring the logo and a clear value proposition: 'Koi Endpoint Security Platform.' The sub-headline immediately establishes the scale of the ambition, stating they are 'Going after the $17b endpoint protection market.' This sets a high-stakes tone for the rest of the presentation, signaling to investors that this is a venture-scale opportunity in a proven spending category.

Slide 2: Team Pedigree

Slide 2 focuses on the human capital behind the technology. The headline, 'We have built the best team to go after a $17B market opportunity,' reinforces the market size from the previous slide. The slide displays 22 team members, with the leadership row highlighting roles such as Head of GTM, Head of Customers, CPO, CEO, CTO, VP R&D, Head of Product, and Head of Finance. Crucially, it includes logos of former employers: Microsoft, Zscaler, Sygnia, Akamai, and what appears to be an Israeli intelligence unit crest. This creates immediate institutional trust.

Slide 3: Defining the 'Non-Binary' Problem

Slide 3 provides the 'Why Now?' for the investment. It argues that 'Organizations can't handle the evolution of their endpoints.' The slide categorizes the new threat landscape as 'Non-Binaries,' listing Apps, Packages, Models, MCPs, Extensions, and Containers. It features a wall of logos representing the modern developer and employee ecosystem, including Maven, NPM, DockerHub, Chrome, VS Code, Hugging Face, and Jupyter Notebooks. The implication is clear: traditional security tools protect the OS, but they don't protect the tools employees actually use to work.

Slide 4: The Three-Step Solution

Slide 4 introduces the product interface and the core workflow: Discover ('Any piece of software in your IT ecosystem'), Assess ('Every single software item's risk'), and Enforce ('Through policy-based enforcement and remediation'). The screenshot shows a dashboard inventorying items like 'Adblocker for Chrome' and 'Prettify JSON,' flagging them with severity levels like 'Critical' or 'High' based on findings like 'Malicious Activity Detected' or 'Vulnerable to Remote Code Execution.'

Slide 5: The Risk Engine and 2025 Campaigns

Slide 5 highlights the 'Risk Engine.' It features a counter showing '048923564' items scanned. A notable claim in the top right box is that the engine 'Detected the biggest campaigns in 2025.' This suggests the deck was used for a late 2024 or early 2025 fundraise, emphasizing the real-time efficacy of the platform against modern threats like Malware, Infostealers, Vulnerable code, Ransomware, and Spyware.

Slide 6: Proving Inbound Demand

Perhaps the most persuasive slide in the deck, Slide 6 is a collage of 'Enterprise Inbound Demand.' Instead of a bar chart showing growth, Koi shows raw evidence: screenshots of Retool form submissions and Slack messages. One message from a 'National Security Engineer' asks for an API key for 500 users; another from a 'Senior SOC Analyst' mentions dealing with a specific 'Cyberhaven Chrome extension info stealer issue.' This slide proves that the market is actively seeking Koi's specific solution.

Slide 7: CISO Validation

Slide 7, titled 'Don't take our word for it,' provides qualitative social proof. The testimonials are categorized by the size of the deployment, ranging from 3K to 130K endpoints. One InfoSec Director claims the product 'eliminates the workload of 20 full-time employees,' while a CISO states they have 'instructed our legal team that complete this deal is the top priority for our entire organization.' These quotes address the 'pain' and 'ROI' questions that investors typically ask.

Slide 8: The Funding Roadmap

Slide 8, 'Funding Round,' is a simple timeline showing how the capital will be deployed. It identifies two primary milestones: 'Building up the GTM team' and 'Pipeline support, pre-sale, post-sale, R&D.' While it lacks a specific dollar amount or valuation (common in decks shared post-raise), it indicates a transition from product-market fit to scaling the organization.

Slide 9: Closing

The deck concludes with a 'Thank You' slide featuring a whimsical illustration of a red airship, maintaining the consistent visual theme of clouds and flight used throughout the presentation.

What Koi Does Well

Koi excels at category reframing . By focusing on 'non-binaries' like AI models and browser extensions, they make the $17B endpoint market feel underserved. They also leverage raw social proof exceptionally well. Slide 6’s collage of inbound requests is more convincing than a polished growth chart because it shows the specific, technical language of customers who are currently 'drowning' (as Slide 7 puts it) in manual vetting processes. Finally, the team slide is positioned early to establish that this is an 'expert-led' venture, which is critical in the cybersecurity sector where trust is the primary currency.

What is Missing from the Koi Deck

The most glaring omission is quantitative financial data . There are no mentions of Annual Recurring Revenue (ARR), Net Revenue Retention (NRR), or Customer Acquisition Cost (CAC). While the inbound demand is shown, the conversion rate and deal size are left to the imagination. Additionally, there is no competitive landscape slide. While one testimonial claims they are the 'only player,' the cybersecurity market is notoriously crowded with 'shadow IT' and 'SaaS security' startups that overlap with Koi’s mission. A founder using this deck as a template should be prepared to provide a detailed data room to back up these qualitative claims.

Founder Takeaways: Copy the Proof, Not the Omissions

Founders should emulate Koi’s use of specific customer pain points . The quotes on Slide 7 aren't generic 'great product' blurbs; they mention specific endpoint counts and headcount savings. Copy the visual consistency and the problem-first approach that identifies a specific shift in the market (the 'evolution of endpoints'). However, unless you have a team with a similar pedigree and a massive influx of inbound enterprise leads, you should not omit the business model or competitive analysis. Koi likely raised on the strength of their team and early enterprise traction, but most startups will need to show the math behind the momentum.

Frequently asked questions

How much did Koi raise with this deck?
According to publisher-reported facts from Business Insider, Koi raised $38 million in a Series A round in 2024. The deck itself does not state the specific dollar amount requested, only the intended use of funds for GTM and R&D.
What specific problem does Koi solve in cybersecurity?
Koi addresses the security risks associated with 'non-binaries' that traditional endpoint protection often misses. As shown on Slide 3, this includes software add-ons, browser extensions, AI models, MCPs, and packages from repositories like NPM, PyPi, and Hugging Face.
Does the deck include a competitive landscape or matrix?
No. The deck does not feature a traditional competitor grid. Instead, it uses customer testimonials on Slide 7 to claim they are the 'only player in this space' and that organizations were 'drowning in vetting' before using the platform.
What are the primary use of funds for the Series A?
Slide 8 outlines two main areas for investment: building up the Go-To-Market (GTM) team and providing pipeline support across pre-sale, post-sale, and R&D functions. It uses a minimalist timeline graphic to illustrate these priorities.
How does Koi demonstrate product-market fit?
Koi uses Slide 6 to show 'Enterprise Inbound Demand' through a series of screenshots of form submissions and Slack messages. These messages show security professionals from various firms requesting POCs, pricing, and API access.
Cover slide of the Koi pitch deck — Series A 2024
Koi pitch deck, slide 1 (2024)

Koi pitch deck: the facts

Company
Koi
Year
2024
Stage
Series A
Slides
9
Sector
Cybersecurity
Deck type
Fundraising Pitch Deck
Outcome
$38M Raised
Headquarters
N. America

Koi pitch deck PDF

The full Koi deck is embedded on this page and can be read slide by slide in the browser — no download or account required. Each slide is covered in the breakdown above.

What the Koi pitch deck was used for

This deck is for **Koi**, an Israeli cybersecurity startup focused on endpoint protection for the modern software stack, including software add-ons, extensions, containers, and AI-related components. In 2025, Business Insider published Koi’s pitch deck associated with its combined $48M seed and Series A funding, highlighting a $38M Series A to address an estimated $17B endpoint security market and a strategy that emphasizes inbound enterprise demand and social proof. The deck relates to a 2024–2025 fundraising period in which Koi raised a $10M seed and a $38M Series A led by top-tier cybersecurity and venture investors. The company was later acquired by Palo Alto Networks for a reported ~$400M, but this outcome occurred after the deck’s use.

Business model: Enterprise cybersecurity platform providing endpoint security for the modern software stack, focusing on software add-ons and non-traditional endpoint components such as extensions, containers, packages, AI models, and AI agents.

Round
Series A
Lead investor
Battery Ventures and Team8 (co-leads)
Investors
Battery Ventures, Team8, Picture Capital, NFX, Cerca Partners
Founded
2024
Headquarters
Tel Aviv, Israel
Industry
Cybersecurity (Endpoint security / agentic endpoint security)
Total funding
$48M

Year: 2024–2025 (seed completed around late 2024/early 2025, Series A closed in August/September 2025)

Raised: $38M Series A as part of $48M total funding (including a $10M seed round)

Use of funds as presented: To scale Koi’s endpoint security platform for the modern software stack, expand coverage across extensions, containers, packages, AI models and agents, and build out go-to-market and product teams to serve enterprise customers.

What happened after the Koi deck

Following its seed and Series A rounds totaling $48M, Koi continued to scale its endpoint security platform for modern software and AI agents. Within roughly two years of founding, it was acquired by Palo Alto Networks in a deal reported at around $400M, validating its technology and market thesis beyond the fundraising deck.

What the Koi deck got right

What could have been stronger

How an investor would read this deck

What draws attention

Risks that stand out

Questions this deck invites

What founders can take from the Koi deck

Koi pitch deck: common questions

What does Koi do?

Koi is a cybersecurity startup that provides endpoint security for the modern software stack, focusing on blind spots traditional EDR and MDM tools do not cover, such as extensions, containers, packages, AI models, and autonomous AI agents.

How much funding did Koi raise and when?

Koi raised a total of $48M across a $10M seed round and a $38M Series A. The seed was closed in December (around late 2024 or early 2025), and the Series A was closed in August 2025, according to Business Insider and investor communications.

Who invested in Koi’s seed and Series A rounds?

The $10M seed round was led by Picture Capital and NFX with participation from Cerca Partners, while the $38M Series A was led by Battery Ventures and Team8, with the same early investors participating, according to Business Insider and public investor posts.

Where can I read about Koi’s pitch deck and the story behind it?

Business Insider obtained and published Koi’s pitch deck in September 2025, describing how the founders used a white-hat hacking demonstration on the Microsoft Visual Studio Code Marketplace to illustrate a major security gap and support their fundraising narrative.

What happened to Koi after its Series A?

Koi was acquired by Palo Alto Networks in 2026 in a transaction widely reported at around $400M in value. This acquisition happened after the seed and Series A rounds and after the pitch deck was used to raise the $48M.

Sources

Funding and outcome facts on this page were researched on 2026-08-30 from the pages below.

What investors wrote about this round

Investor-side writing matched to this company through dated, cited funding evidence.

Battery Ventures · Barak Schoster, Danel Dayan, Lior Mallul

Related funding context

This investor wrote about a closely related funding event for this company, not verified as the same round.

September 11, 2025

  • Traditional endpoint security tools struggle to monitor non-executable software artifacts like VS Code extensions or browser plugins, creating security blind spots.
    “They excel at catching malware in binaries, but they struggle with non-executable artifacts like VS Code extensions or browser plugins. In practice, these tools lack visibility into what happens inside trusted apps, leaving a blind spot for attackers to exploit.”
    Written at the time of the investment · Source
  • Koi's founders Amit Assaraf, Idan Dardikman, and Itay Kruk have extensive backgrounds in offensive cybersecurity research, military cybersecurity units, and developer software.
    “Founders Amit Assaraf (CEO), Idan Dardikman (CTO) and Itay Kruk (CPO) each bring a rare combination of deep cybersecurity, devtools and research pedigree. Prior to starting Koi, the three collectively spent decades in offensive security research and building developer-focused sof”
    Written at the time of the investment · Source
  • Koi enables low-friction deployment without heavy agents, allowing enterprises to roll out protection within hours.
    “No heavy agents; enterprises can roll out protection in hours.”
    Written at the time of the investment · Source
  • Koi complements existing EDR, UEM, and App Control tools by providing real-time artifact governance and supply-chain firewall protection at the endpoint.
    “By positioning itself between UEM, EDR, and app control, Koi is not replacing these categories but complementing them, acting as a real-time, supply-chain firewall for the endpoint.”
    Written at the time of the investment · Source

Team8

Related funding context

This investor wrote about a closely related funding event for this company, not verified as the same round.

September 11, 2025

  • Koi combines continuous visibility, an AI-driven risk engine, and automated enforcement to give enterprises control over software running on their endpoints.
    “By combining continuous visibility, an AI-driven risk engine, and automated enforcement, Koi gives enterprises control over every piece of software running on their endpoints.”
    Publication date not verified · Source
  • Multiple CISOs requested follow-ups with Koi following their pitch and demo at the 2025 CISO Village Summit.
    “Multiple CISOs requested follow ups and mentioned the challenges they are facing with the rise of non-binary components in their organization.”
    Publication date not verified · Source
  • Koi is building the first endpoint security platform purpose-built for the non-binary software layer.
    “Koi is building the first endpoint security platform purpose-built for the non-binary software layer.”
    Publication date not verified · Source
  • Team8 expects Koi to define the reference architecture for securing modern endpoints.
    “We believe Koi will define the reference architecture for securing modern endpoints.”
    Publication date not verified · Source
  • CEO Amit Assaraf combines strong technical capability with business and marketing leadership.
    “Alongside them is CEO Amit Assaraf, a founder with both strong business instincts and deep technical capability.”
    Publication date not verified · Source

Related fundraising guides (24)

This deck's categories (1)

Decks from the same year (1)

Decks with a similar raise (1)

Browse companies alphabetically (1)

Decks in the same category (12)

More pitch deck teardowns (16)

Recently published pitch deck teardowns (12)

Fundraising library · Pitch deck examples · Investor directory · Founder database