Nokod Security's pitch deck is a textbook example of how to sell a solution for an emerging technical gap. By focusing on the 'democratization of app creation,' the founders highlight a massive security blind spot in modern enterprises. The deck leans heavily on the founders' impressive pedigree, featuring exits to Ping Identity and Thoma Bravo. While the version available publicly redacts specific financial projections and competitive positioning, the structural flow is logical: it establishes the LCNC trend, showcases real-world breaches, and presents a modular architecture for mitigation.…
Key takeaways
- The founding team features two former founders with exits to Ping Identity and Thoma Bravo, establishing immediate credibility (Slide 2).
- The deck leverages Gartner data to project that 65% of applications will be based on low-code by 2024 (Slide 5).
- Problem validation is supported by news headlines of 38 million records exposed via Microsoft Power Apps (Slide 6).
- The solution is presented as a modular 'NCLC Analyzer' that detects malicious, vulnerable, and non-compliant apps (Slide 12).
- Market sizing uses three distinct methodologies, including a top-down Appsec approach valuing the 2023 opportunity at $6.07B (Slide 14).
- The Go-To-Market strategy targets CISOs and Directors of Appsec in mid-market organizations and above (Slide 17).
- Direct quotes from CISOs at global banks and Fortune 50 healthcare companies provide social proof for the 'process validation' (Slide 19).
- The funding roadmap explicitly links the $8M Seed round to headcount growth, targeting 25 FTEs by Month 24 (Slide 20).
Executive Summary and Team Pedigree
Slide 1: Title Slide
The deck opens with a clean, dark-themed title slide. The logo is a 3D cube with green accents, and the tagline is functional: "Securing your Low-code \ No-code Applications." It immediately identifies the niche without using buzzwords.
Slide 2: Founding Team
This is a high-signal slide. Yair Finzi (CEO) is noted as a former founder of SecuredTouch, which was acquired by Ping Identity. Amichai Shulman (CTO) is a former founder of Imperva, acquired by Thoma Bravo, with 25 years of experience. Yuval Peled (VP Engineering) brings backend expertise from Ping Identity. For a Seed round, this level of exit history significantly de-risks the investment.
The Market Opportunity: The LCNC Explosion
Slide 3: Real-world Examples
To ground the abstract concept of "no-code," the deck shows three specific examples: a Western Union banking app, a B2B employee benefits app, and PepsiCo's vending machine web app. This proves that LCNC is not just for internal prototypes but for mission-critical, customer-facing applications .
Slide 4: Enterprise Adoption
A logo cloud featuring HSBC, T-Mobile, Coca-Cola, and Goldman Sachs demonstrates that the world's largest, most regulated companies are already using these platforms. This sets the stage for why a security solution is necessary for the enterprise segment.
Slide 5: The LCNC Trend
Nokod cites Gartner, stating that 65% of applications will be based on low-code by 2024 . They also note that platforms like Office365 and Salesforce offer LCNC out-of-the-box, meaning the attack surface is growing automatically without IT intervention.
The Problem: Security Blind Spots
Slide 6: Threats and Attacks
The deck uses "fear, uncertainty, and doubt" (FUD) effectively by citing a real headline: "Microsoft Power Apps Data Leak Fallout: 38 Million Records Exposed." This transforms a theoretical risk into a documented financial and reputational liability.
Slide 7: Security Challenges
This slide lists six specific pain points. Key among them are the "democratization and decentralization of apps creation" and the fact that "Apps can go directly to the production environment" without traditional security gates. This defines the "why now" for the product.
Slides 8-9: Attack Vectors
These slides detail how breaches happen, citing Forrester's prediction of major breaches in 2023. They categorize risks into Malicious Apps (account takeover), Vulnerable Apps (injection attacks), and Non-compliant Apps (PII collection). This shows a deep understanding of the threat landscape.
The Solution and Architecture
Slide 10: Mission Statement
A simple transition slide stating the goal: "Empower organizations with tools and intelligence for preventing cyber attacks and data breaches through low-code \ no-code applications."
Slide 11: The Solution Visualization
The 3D cube from the logo is used here as a metaphor for the Nokod NCLC Analyzer . It sits between the LCNC platforms and the Appsec Portal, feeding SOC (Security Operations Center) alerts to the team. It visualizes the product as a "security layer" rather than a replacement for existing tools.
Slide 12: Architecture
This slide provides a technical breakdown of the stack. It shows integrations with ServiceNow, Salesforce, Microsoft PowerApps, and OutSystems . The five-layer stack (Data Lake, Analysis, Model, Engine, Portal) suggests a sophisticated backend capable of handling high-volume logs and complex app logic.
Market Size and Business Strategy
Slides 13-15: TAM Analysis
Nokod provides a robust market sizing section using three different lenses:
Top-down #1: Based on the Appsec market, projected at $6.07B in 2023 . · Top-down #2: Based on the LCNC platform market, projected at $4B in 2023 . · Bottom-up: Based on 350,000 large companies. The final TAM figure and deal size are redacted in this version, but the methodology is sound.
Slide 16: Go-To-Market
The strategy is clear: Direct Sales at the start, targeting North America and EMEA. They identify the buyer as the CISO or Director of Appsec , but note that the entry point is often the Digital Transformation Manager. The business model is a subscription correlated with the number of protected apps .
Slide 17: Competition
The slide claims the space is a "blue ocean." While the specific competitor names are redacted, the positioning chart shows Nokod in the top-right quadrant, implying they offer higher specialized value than existing generalist tools.
Validation and Roadmap
Slide 18: Process Validation
This is a powerful social proof slide. It includes quotes from a CISO at a Top 50 global bank and a Platform Director at a Fortune 50 healthcare company . These quotes confirm that Appsec teams currently "just can't follow the high pace" of LCNC development.
Slide 19: Validation Takeaways
The specific operational plan is redacted , but the slide structure suggests they have a 5-point plan for how they will iterate based on the feedback received in Slide 18.
Slide 20: Timeline 2023-2025
The final content slide ties the $8M Seed round to specific milestones. They plan to grow from 4 FTEs to 25 FTEs over 24 months. The product roadmap moves from an MVP with 1-2 covered platforms to a full-scale solution. Revenue and customer targets are redacted, but the headcount transparency shows a clear plan for capital allocation.
Slide 21: Contact
What Works in This Deck
1. Founder-Market Fit: The team slide is positioned early and is incredibly strong. Investors in cybersecurity prioritize founders who have "been there, done that," and two exits to major players (Ping Identity and Thoma Bravo) is a rare pedigree for a Seed round.
2. Problem Specificity: Instead of saying "security is hard," the deck identifies a very specific, growing gap: the citizen developer. By using Gartner stats and real-world breach headlines, they make the problem feel urgent and inevitable.
3. Multi-Lens TAM: Providing three different ways to calculate the market size shows that the founders are thinking like business owners, not just engineers. It gives investors confidence that the $8M ask is backed by a massive opportunity.
What Is Missing or Redacted
1. Competitive Landscape: The competitive analysis is entirely redacted. While they claim a "blue ocean," investors would want to know how they stack up against legacy CASB (Cloud Access Security Broker) or SSPM (SaaS Security Posture Management) players who might try to move into this niche.
2. Unit Economics: There is no mention of Customer Acquisition Cost (CAC) or Lifetime Value (LTV). While this is common in early Seed decks, the redacted "Average annual deal size" on Slide 15 is a critical piece of the puzzle for understanding the scalability of the direct sales model.
3. Product Deep Dive: While the architecture is shown, there are no screenshots of the actual Appsec Portal or examples of what a "SOC Alert" looks like. Seeing the UI would help prove the product is "design partner-ready" as claimed on Slide 20.
Founder Takeaways
Focus on the 'Why Now': Nokod does this perfectly by linking their solution to the 65% LCNC adoption rate projected by Gartner. If you are building in a niche, you must prove that the niche is about to become the mainstream.
Use Social Proof Early: Even if you don't have paying customers, quotes from potential buyers (CISOs) that validate the pain point are invaluable. It proves you have done the discovery work and aren't building in a vacuum.
Tie Funding to Headcount: Don't just ask for $8M; show exactly how many people that money buys and what those people will build. The Month #1 to Month #24 hiring roadmap is a great way to visualize the company's evolution.
Frequently asked questions
- What is the core problem Nokod Security is solving?
- Nokod addresses the security gap created by Low-Code/No-Code (LCNC) platforms. As business users ('citizen developers') build apps without traditional engineering oversight, they often bypass security testing, leading to data exposure, authorization bypasses, and non-compliance. Slide 7 explicitly lists six challenges, including the 'inflation of LCNC apps' and the lack of proper security code testing.
- How does the team's background influence the pitch?
- The team is the deck's strongest asset. CEO Yair Finzi previously founded SecuredTouch (acquired by Ping Identity), and CTO Amichai Shulman founded Imperva (acquired by Thoma Bravo). This 40+ years of combined experience in cybersecurity makes the technical claims on Slide 13 regarding the 'Appsec engine' and 'Appsec model' highly believable to investors.
- What is the proposed business model?
- According to Slide 17, Nokod utilizes a subscription-based business model. The pricing is correlated with the number of protected applications. Their initial go-to-market strategy focuses on direct sales in North America and EMEA, targeting organizations that already have a dedicated Appsec team but lack visibility into their LCNC ecosystem.
- How does Nokod calculate its Total Addressable Market (TAM)?
- The deck uses three approaches. Method #1 takes the $9.35B Appsec market and applies Gartner's 65% LCNC projection to reach $6.07B. Method #2 takes the $26.72B LCNC platform market and assumes 15% is spent on security, totaling $4B. Method #3 is a bottom-up calculation based on 350,000 large companies, though the final figure is redacted (Slides 14-16).
- What are the primary technical components of the Nokod platform?
- The architecture (Slide 13) consists of five layers: a Data Lake for platform logs, an App Analysis layer, a proprietary Appsec Model, an Appsec Engine, and a user-facing Appsec Portal. It integrates directly with major platforms like ServiceNow, Salesforce, Microsoft PowerApps, and OutSystems to provide centralized monitoring and SOC alerts.
