Palantir's FedStart: the fast lane into the US government cloud
6 min read
On 18 June 2026, a company almost nobody outside cybersecurity circles has heard of announced it had joined a Palantir Technologies programme called FedStart. This is not a contract with a federal agency, and it is not a sale: it is entry into a mechanism that promises to shrink, from years to months, the time a small technology company needs to earn the right to sell to the US government. The case of Oligo Security — an Israeli cybersecurity start-up — shows clearly how this new gateway works today, and why it is worth watching closely even from outside the United States.
Who Oligo Security is
Founded in 2022 in Tel Aviv by three co-founders with backgrounds in Israeli cyber intelligence — Nadav Czerninski (CEO), Gal Elbaz (CTO, previously at Check Point) and Avshalom Hilu (Chief Product Officer) — Oligo emerged from stealth in February 2023 with $28 million raised across seed and Series A, led by Lightspeed Venture Partners, Ballistic Ventures and TLV Partners. In January 2025 it closed a $50 million Series B led by Greenfield Partners, with participation from Red Dot Capital Partners and Strait Capital: close to $80 million raised in under two years. Disclosed customers include Databricks, Salesforce, ServiceNow, Instacart and Cresta.
The technology: watching what actually runs, not what might
The product is known in the trade as ADR — Application Detection and Response (CADR for cloud). Classic software security tools analyse code at rest — libraries, dependencies, known vulnerabilities (CVEs) — and produce very long alert lists, most of them about functions that never actually execute in the real application. Oligo instead observes code at runtime, while it is actually running in production, using the Linux kernel’s eBPF technology: a mechanism that lets the operating system observe execution with minimal overhead, without rewriting the application. It builds a behavioural profile of each service, distinguishes theoretical vulnerabilities from ones an attacker can actually reach, and blocks exploitation attempts in real time. One customer, Cresta, states it cut the vulnerabilities needing a fix by 99% by focusing only on those with an actually-executed vulnerable function. The limit is just as real: runtime observation only kicks in once the code is already executing, it does not replace upstream checks earlier in development, and it still has to be integrated into every customer’s stack — it is not a switch that flips itself on.
The known terms of the deal: what the announcement says, and what it does not
Here the announcement needs separating from the substance. FedStart is a programme Palantir describes as “accreditation as a service”: it gives partner companies access to its own already-authorised cloud infrastructure and its own compliance apparatus — Authority to Operate (ATO) processes, audit artefacts, continuous monitoring, control assessments. The stated goal for Oligo is to accelerate the path to FedRAMP High and DoD Impact Level 5 authorisation, the level covering the Pentagon’s most sensitive unclassified information — controlled data and National Security System-related workloads. The announcement does not say Oligo already holds those authorisations: it says it is pursuing them inside Palantir’s infrastructure. Neither the deal’s financial terms (percentages, fees, any equity stake for Palantir) nor the name of an already-signed federal agency customer have been made public. Oligo’s CEO, Nadav Czerninski, said: “Security teams can no longer afford to detect attacks after an attacker has a foothold. Modern attacks are AI-assisted, move at high velocity, and exploit gaps where most tools have no visibility: at runtime.” Ali Monfre, head of FedStart at Palantir, added that the programme lets Oligo Security “accelerate its path to achieving FedRAMP High and DoD IL5 authorization and bring their unique technology to government customers.”
What it means
For Oligo, the deal cuts years of red tape — but it ties its entry into the federal market, the richest in the world for cybersecurity, to a single intermediary. For Palantir, every company that joins FedStart strengthens its role as more than an analytics and AI supplier: it becomes trusted infrastructure through which other suppliers — even ones competing with each other — must pass to reach government customers, a position that extends well beyond its own Foundry or AIP products, and one that also touches on dual-use and compliance questions when the stated goal is a level like IL5. For procurement, the advantage is speed: agencies get access to specialised tools without years of parallel authorisations. The mirror-image risk is concentration: if a single intermediary’s compliance assessment has a gap, every company that passes through the same channel inherits it, and the diversity of independent scrutiny shrinks. For anyone buying in this space — including in defence — the same lesson applies that the GAO report on US government AI procurement has been documenting for months: trust is verified, not inherited from a supplier’s brand. Europe and Italy have no direct equivalent today: Italy’s ACN cloud qualification under the National Cybersecurity Perimeter and the EU’s EUCS certification scheme remain national processes, or are still being finalised at EU level — slower and more fragmented than a fast lane run by a single large private supplier. A structural difference worth keeping in mind before comparing the speed of US and European procurement.
The operational lesson
- Separate the announcement from the milestone: “having joined an accreditation programme” is not the same as “holding the authorisation” — check the actual certification (a FedRAMP Marketplace listing, an ATO letter), not the press release.
- If you are a supplier weighing a similar deal, write down today what happens if the intermediary changes terms, price or the relationship: without a reversibility clause, your only route to an entire market depends on another supplier’s goodwill.
- If you are a buying agency or company, ask who actually carried out the security assessment and whether you can review the compliance artefacts directly, rather than relying on the intermediary’s brand.
- Check noise-reduction percentages (“99% fewer false positives”) against your own real workload, not the customer quoted in the press release: these are marketing numbers before they are yours.
- In Europe, look at the real equivalents — ACN qualification, EUCS — before choosing a supplier on the promise of a shortcut.
Anyone watching these deals from a procurement office — public or private — should apply the same principle we use when assessing a supplier for our own clients: verify what is already proven, what is still a promise, and what happens if the supplier changes course. It is the standard behind every architecture we build to remain replaceable, not just installable.
Assessing a security or AI supplier presenting a certification “in progress” or a deal with a major partner? Let’s talk for thirty minutes: together we will separate what is already guaranteed from what still needs proving.
Sources
- Business Wire (via Yahoo Finance) — Oligo Security Joins Palantir’s FedStart Program to Accelerate Runtime Security for Federal Agencies (18 June 2026)
- CIO Influence — Oligo Security Joins Palantir’s FedStart Program to Accelerate Runtime Security for Federal Agencies (19 June 2026)
- SecurityWeek — Oligo Raises $50M to Tackle Application Detection and Response