# Dune Security

**Canonical:** https://apis.io/providers/dune-security/  
**Website:** https://dune.security  
**APIs profiled:** 0

Dune Security is a cybersecurity company whose User Adaptive Risk Management platform uses AI-driven behavioral analysis to quantify and reduce user-layer cyber risk. It runs omni-channel attack simulations (email/spear phishing, smishing, vishing, deepfakes, and encrypted-app lures) tailored to each employee's role and behavior, generates a live User Risk Score from five inputs (business impact, simulations, training activity, external security integrations, and historical data), and automatically adapts micro-training and security controls in real time. The platform integrates with IAM, EDR, SEG, DLP, and HRIS systems to escalate or restrict access for high-risk users, and ships an in-house training library (Security Awareness, Compliance, and Functional-Specific Training) covering NIST 800-53, NIST CSF, HIPAA, PCI DSS, SOX, ISO 27001, FFIEC, GLBA, and GDPR. Dune Security is backed by Craft Ventures.

## Kin Score — 9.6 / 100 (minimal)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 9.6).

| Facet | Score |
|---|---|
| Discoverability | 57.4 |
| Contract Quality | 0.0 |
| Governance | 0.0 |
| Contract Governance | 0.0 |
| Operational Transparency | 0.0 |
| Developer Ergonomics | 2.4 |
| Commercial Clarity | 17.1 |
| Access Clarity | 17.1 |

## Agent readiness — 0.0 (human-only)

| Dimension | Value |
|---|---|
| Spec Presence | no |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | no |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Unknown — onboarding: unknown, pricing: unknown, trial: no (confidence: low).

## Security (2)

- **Dune Security Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC
- **Dune Security Trust Center** — SOC 2 Type II, ISO 27001, HIPAA, GDPR, CCPA, NIST CSF v2.0

## Tags

Company, Security, Cybersecurity, Human Risk Management, Insider Threat, Phishing Defense, Social Engineering, Security Awareness Training, Behavioral Analytics, User Risk Scoring

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/dune-security/). Scores are computed from the provider's own public artifacts under a published rubric.
