Dune Security website screenshot

Dune Security

Dune Security is a cybersecurity company whose User Adaptive Risk Management platform uses AI-driven behavioral analysis to quantify and reduce user-layer cyber risk. It runs omni-channel attack simulations (email/spear phishing, smishing, vishing, deepfakes, and encrypted-app lures) tailored to each employee's role and behavior, generates a live User Risk Score from five inputs (business impact, simulations, training activity, external security integrations, and historical data), and automatically adapts micro-training and security controls in real time. The platform integrates with IAM, EDR, SEG, DLP, and HRIS systems to escalate or restrict access for high-risk users, and ships an in-house training library (Security Awareness, Compliance, and Functional-Specific Training) covering NIST 800-53, NIST CSF, HIPAA, PCI DSS, SOX, ISO 27001, FFIEC, GLBA, and GDPR. Dune Security is backed by Craft Ventures.

Dune Security is profiled on the APIs.io network. Tagged areas include Company, Security, Cybersecurity, Human Risk Management, and Insider Threat.

Dune Security’s developer surface includes engineering blog and 9 more developer resources.

15.1/100 emerging ▬ flat Agent 4/100 human only Full breakdown ↓
scored 2026-07-27 · rubric v0.5
0 APIs
CompanySecurityCybersecurityHuman Risk ManagementInsider ThreatPhishing DefenseSocial EngineeringSecurity Awareness TrainingBehavioral AnalyticsUser Risk Scoring

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 15.1/100 · emerging
Contract Quality 0.0 / 25
Developer Ergonomics 0.4 / 20
Commercial Clarity 7.9 / 20
Operational Transparency 0.0 / 13
Governance 0.0 / 12
Discoverability 6.8 / 10
Agent readiness — 4/100 · human only
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 15
MCP Server 0 / 12
Machine-Readable Auth 0 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 4 / 4
Consent & Bot Identity 0 / 3
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/dune-security: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Dune Security Domain Security

TLSv1.3 · HSTS · DNSSEC · DMARC

SECURITY

Dune Security Trust Center

SOC 2 Type II, ISO 27001, HIPAA, GDPR, CCPA, NIST CSF v2.0

SECURITY

Resources

Get Started 1

Portal, sign-up, and the first successful call

Agent Surfaces 2

MCP servers, agent skills, and machine-readable catalogs

Access & Security 3

Authentication, authorization, and security posture

Commercial 1

Pricing, plans, and the legal terms of use

Company 3

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: dune-security
name: Dune Security
description: Dune Security is a cybersecurity company whose User Adaptive Risk Management platform uses AI-driven behavioral
  analysis to quantify and reduce user-layer cyber risk. It runs omni-channel attack simulations (email/spear phishing, smishing,
  vishing, deepfakes, and encrypted-app lures) tailored to each employee's role and behavior, generates a live User Risk Score
  from five inputs (business impact, simulations, training activity, external security integrations, and historical data),
  and automatically adapts micro-training and security controls in real time. The platform integrates with IAM, EDR, SEG,
  DLP, and HRIS systems to escalate or restrict access for high-risk users, and ships an in-house training library (Security
  Awareness, Compliance, and Functional-Specific Training) covering NIST 800-53, NIST CSF, HIPAA, PCI DSS, SOX, ISO 27001,
  FFIEC, GLBA, and GDPR. Dune Security is backed by Craft Ventures.
url: https://raw.githubusercontent.com/api-evangelist/dune-security/refs/heads/main/apis.yml
accessModel:
  pricing: unknown
  onboarding: unknown
  trial: false
  try_now: false
  public: false
  label: Unknown
  confidence: low
  source: []
  generated: '2026-07-22'
  method: derived
image: https://cdn.prod.website-files.com/67f91a416272c7432bc1ac28/6808deaf18e9d80105f7198c_Open%20Graph.png
x-type: company
x-source: vc-portfolio
x-backed-by:
- craft-ventures
x-tier: stub
x-tier-reason: portfolio-lead
specificationVersion: '0.20'
created: '2026-07-17'
modified: '2026-07-18'
tags:
- Company
- Security
- Cybersecurity
- Human Risk Management
- Insider Threat
- Phishing Defense
- Social Engineering
- Security Awareness Training
- Behavioral Analytics
- User Risk Scoring
apis: []
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
common:
- type: Website
  url: https://dune.security
- type: About
  url: https://dune.security/about-us
- type: Blog
  url: https://dune.security/blog
- type: Login
  url: https://app.dune.security/
- type: PrivacyPolicy
  url: https://dune.security/legal/privacy-policy
- type: TrustCenter
  url: https://app.vanta.com/dune.security/trust
- type: Compliance
  url: https://app.vanta.com/dune.security/trust
- type: DomainSecurity
  url: security/dune-security-domain-security.yml
- type: LLMsTxt
  url: llms/dune-security-llms.txt
- type: WellKnown
  url: well-known/dune-security-well-known.yml
x-enrichment:
  date: '2026-07-19'
  status: backfilled
  pass: local-v1
  note: backfilled from .gitignore signal + verified work evidence