Jazz says a quieter DLP dashboard may mean nobody is watching Jazz co-founder and CEO Ido Livneh argued in a September 20th CTech essay that conventional data-loss prevention deployments grow less protective as security teams narrow rules, approve exceptions and stop monitoring noisy workflows, producing quieter dashboards that hide blind spots. Livneh, who founded Jazz in 2024 with Jake Turetsky, Noam Issachar and Yonatan Zohar, said most security leaders cannot tell whether their system got quieter because the data is understood or because it stopped being watched. Jazz is pitching its agentic investigator Melody, which evaluates data activity across four dimensions — the information involved, the systems it moved through, the person performing the action and the surrounding business process — to investigate broadly before filtering. Jazz says a quieter DLP dashboard may mean nobody is watching CEO Ido Livneh argues that years of exceptions let staffing limits become security policy, a failure Jazz built Melody to address. By RuntimeWire Staff https://runtimewire.com/author/runtimewire-staff · Published Primary source: CTech https://www.calcalistech.com/ctechnews/article/zakwq3w87 Why it matters Security teams often tune DLP around available headcount. Jazz is betting that buyers will pay to investigate broadly, escalate selectively and audit what AI dismisses. Jazz https://www.jazz.security/?ref=runtimewire co-founder and CEO Ido Livneh @IdoLivneh https://x.com/IdoLivneh?ref=runtimewire has put a pointed test in front of data-loss prevention buyers: when alerts decline, can the vendor prove that its software kept watching? In a CTech essay published September 20th https://www.calcalistech.com/ctechnews/article/zakwq3w87?ref=runtimewire , Livneh argues that conventional DLP deployments become progressively less protective as security teams narrow rules, approve exceptions and stop monitoring noisy workflows. Each change can be defensible on its own. Accumulated over several years, those decisions create blind spots that the dashboard does not show. "Most security leaders cannot tell you whether their system got quieter because the data is understood or because it stopped being watched," Livneh wrote. That argument is also the founding thesis behind Jazz. Livneh, a Technion alumnus with Israeli military-intelligence experience, founded Jazz in 2024 with Jake Turetsky, Noam Issachar and Yonatan Zohar. The founding group includes veterans of Israel's Unit 81 and alumni of security companies including Axonius and Laminar. Livneh has spent Jazz's first two years making the case that DLP's core failure begins before an analyst ever sees an alert. The dangerous comfort of a smaller queue The problem Livneh describes is familiar across enterprise security: a rule catches legitimate uploads to a vendor, a busy engineering workflow repeatedly triggers the same pattern, or analysts receive more matches than they can examine. Teams respond by narrowing coverage until the workload fits the available headcount. The dashboard improves. The underlying risk may not. A falling alert count has two possible causes. Employees may be handling sensitive data more carefully, or the DLP system may have stopped examining a category of activity months earlier. Both outcomes produce a cleaner graph. Only one represents better security. Exceptions also tend to outlive the reason they were created. A permission approved for one transfer can become a standing exemption for an entire service. An employee can change roles while retaining a workflow exception tied to an old responsibility. The security team eventually inherits a policy assembled from operational compromises whose original context has disappeared. Livneh's sharper point concerns who actually sets policy. When analysts cannot investigate every match, staffing capacity determines which behavior receives scrutiny. Executives may believe they have accepted a defined level of risk, while the practical decision was simply to discard whatever the team could not afford to review. That is a useful distinction for founders selling security automation. Products that make an existing queue faster can reduce analyst labor without restoring the events filtered out upstream. Jazz is betting that customers will pay for software that conducts an initial investigation across a much wider stream of activity before deciding what deserves human attention. Jazz wants Melody to investigate before it filters Jazz's agentic investigator, Melody https://www.jazz.security/product/investigation?ref=runtimewire , evaluates data activity across four dimensions: the information involved, the systems it moved through, the person performing the action and the business process surrounding it. Jazz says that context lets Melody distinguish an expected vendor upload from a sensitive file moving to a personal account. Jazz can then respond with a nudge, request a justification or block the action. Livneh's model leaves the organization's policy in charge while using business context to apply it to an individual event, rather than shutting down a whole workflow because one pattern matched. Jazz claims a typical deployment can reduce roughly 2 million signals to about 80 cases requiring human review. Jazz has used the same figure in materials describing its March accelerator win https://www.jazz.security/blog/news/jazz-wins-the-2026-crowdstrike-and-aws-cybersecurity-startup-accelerator?ref=runtimewire . The ratio is striking, though it measures compression rather than detection quality. Jazz has not published independent comparative testing showing how many risky events Melody catches, how often it reaches the wrong conclusion or how its false-negative rate compares with established DLP products. Livneh acknowledges the central risk created by the approach. An AI investigator can dismiss an event because it misunderstood the file, recipient or employee's purpose. A polished explanation does not repair a faulty assumption. Buyers need access to the evidence and policy behind each decision, including decisions that never reached an analyst. That requirement becomes especially important as DLP vendors reposition AI as an answer to alert fatigue. Adding a summarizer after static rules gives analysts shorter case files. Jazz is proposing a larger architectural change: collect broadly, investigate automatically and escalate selectively. The value of that design depends on whether customers can audit what Melody decided to leave quiet. A product thesis becomes a renewal question Jazz emerged from stealth on March 10th with a $43M Series A and $61M in total funding https://jazz.security/blog/news/jazz-comes-out-of-stealth-with-61m-to-remaster-data-loss-prevention/?ref=runtimewire . Glilot Capital Partners https://glilotcapital.com/?ref=runtimewire and Team8 https://team8.vc/?ref=runtimewire led the Series A, with Ten Eleven Ventures https://www.1011vc.com/?ref=runtimewire , MassMutual Ventures, Merlin Ventures and Encoded Ventures participating. Jazz said at the time that it was running in dozens of organizations and had signed more than a dozen paying customers during its first year. Those customer and deployment figures remain self-reported. Jazz lists AlphaSense, Cass Information Systems, CAVA, Lemonade, Playtika, Rokt, Similarweb and UCLA among organizations using its technology. The public materials establish customer relationships, though they do not disclose contract values, deployment sizes or independently measured security outcomes. The commercial stakes extend beyond replacing an incumbent DLP contract. Newer vendors such as Cyberhaven https://www.cyberhaven.com/press-releases/cyberhaven-raises-100-million-series-d-at-1-billion-valuation?ref=runtimewire and Nightfall AI https://www.nightfall.ai/products/data-exfiltration-prevention?ref=runtimewire are also selling approaches designed for cloud applications, insider risk and data moving into AI tools. Established platforms from Microsoft, Forcepoint and Broadcom already sit inside large enterprise security budgets, as reflected in industry market research https://go.forcepoint.com/sites/default/files/resources/industry analyst reports/report-2024-radicati-dlp-market-quadrant-en 0 0.pdf?ref=runtimewire . Jazz must persuade security leaders that contextual investigation deserves a distinct layer of software and that its judgments remain inspectable at scale. Distribution is part of that effort. RuntimeWire reported in August https://runtimewire.com/article/jazz-melody-crowdstrike-falcon-foundry that Jazz brought Melody's investigations into CrowdStrike's https://runtimewire.com/article/jazz-melody-crowdstrike-falcon-foundry Falcon console after winning the CrowdStrike, AWS and NVIDIA cybersecurity accelerator. The integration puts Jazz's findings inside a workflow security teams already use, reducing the operational cost of adopting another product. Livneh's latest argument gives that sales strategy a simple renewal test. A low alert count should come with evidence of what the system examined and why it stayed silent. Without that record, quiet can describe an effective control or an abandoned patch of coverage. Jazz is betting that CISOs will start demanding proof of the difference.