Your personal memory, across sessions, agents, and devices.

Surf AI Raises $57M for Agentic Security Operations — But a Living Context Graph Without Persistent Memory Resets Between Incident Cycles

MemU Team MemU Team
Surf AI agentic security operations platform with living context graph

Surf AI launched on March 17, 2026, with 57 million dollars in funding led by Accel alongside Cyberstarts and Boldstart Ventures, introducing an agentic security operations platform that rethinks how enterprises detect, prioritize, and remediate security exposures. Founded in 2024 by Israeli cybersecurity leaders, Surf ingests data from identity providers, cloud services, security tools, HR platforms, and IT management systems to build a living context graph — a dynamic representation connecting assets, users, roles, permissions, ownership, and dependencies. Specialized AI agents traverse this graph to identify exposures, correlate them with operational context, prioritize by asset criticality and business ownership, and recommend or execute remediation actions with human oversight and full audit trails.

But context that resets between incident cycles is context that cannot compound. The living context graph captures current security posture with impressive fidelity. Yet agentic security operations that reconstruct their understanding from scratch after each remediation cycle cannot carry forward the intelligence previous cycles generated — which exposures recur, which remediation strategies produce lasting results, and which organizational patterns predict future vulnerabilities.

Agentic Security Operations: What Surf AI Gets Right (And What It Misses)

Surf AI's decision to build a living context graph rather than relying on static vulnerability databases represents a genuine advance. Traditional security platforms enumerate exposures in isolation — an unpatched server here, excessive permissions there — without understanding relationships. Surf's graph connects these dots: a misconfigured service account is more critical when it has admin permissions on a production database owned by finance and accessible through a public-facing API. This contextual prioritization eliminates alert fatigue plaguing teams drowning in decontextualized findings.

The use of specialized AI agents rather than monolithic analysis engines is architecturally sound for agentic security operations. Different security domains require different expertise: identity exposure analysis differs from cloud misconfiguration detection or certificate lifecycle management. By deploying domain-specific agents sharing the same context graph, Surf enables each to apply specialized reasoning while benefiting from unified context. An identity agent discovering an orphaned account can correlate with a cloud agent's finding about that account's API access patterns.

The remediation capability moves beyond advisory. Rather than generating reports for operators, Surf's agents execute remediation directly — disabling accounts, rotating credentials, adjusting permissions — while maintaining human oversight through approval workflows and comprehensive audit trails.

The limitation is the graph's temporality. It reflects current state. When agents remediate an exposure, the graph updates, but historical context of why that exposure existed, how it was discovered, and what resolved it fades. The next time a similar exposure appears from the same root cause, agents rediscover the remediation strategy rather than applying learned knowledge. Agentic security operations without persistent cross-cycle memory cannot distinguish genuinely novel threats from recurring patterns with known solutions.

Surf AI living context graph with MemU persistent security intelligence layer

The MemU Agentic Memory Framework: Persistent Memory for Security Operations

The MemU Agentic Memory Framework transforms the living context graph from a snapshot of current posture into a continuously accumulating body of security intelligence. Where Surf's graph captures what is true now, MemU captures what has been true over time — creating temporal depth enabling pattern recognition, trend analysis, and predictive security that reactive analysis alone cannot deliver.

Consider a large enterprise where an identity agent discovers that a departing employee's service accounts were not deprovisioned, granting continued access to production systems. Surf's agents remediate by disabling the accounts. Three months later, the same pattern recurs with a different employee from the same department. With MemU, agents recognize this as a recurring pattern rooted in that department's offboarding process, escalating from tactical remediation to a systemic process fix. Without persistent memory, each incident is treated as novel — the same root cause is remediated at the symptom level indefinitely.

The MemU Agentic Memory Framework provides capabilities directly enhancing agentic security operations:

  • Incident pattern persistence: Every detection, investigation, and remediation cycle generates intelligence about exposure patterns, root causes, and resolution effectiveness. MemU captures this as structured security memory agents query when evaluating new findings — enabling immediate classification of recurring patterns versus novel threats and recommending proven strategies based on historical effectiveness.
  • Remediation outcome tracking: Not all fixes are equally durable. Some resolve exposures permanently while others address symptoms reappearing within weeks. MemU tracks durability across cycles, building evidence guiding agents toward lasting solutions and flagging approaches with poor track records.
  • Cross-domain threat correlation: Surf's agents operate across identity, cloud, and certificate domains; the MemU Agentic Memory Framework provides the temporal correlation layer connecting findings across domains and time — identifying attack chains unfolding gradually across weeks that are invisible to any single snapshot.

A living context graph shows current security posture. The MemU Agentic Memory Framework remembers every state your posture has been in — enabling agents to detect patterns visible only through temporal analysis across many incident cycles.

Head-to-Head: Surf AI vs. Other Security Operations Platforms

Surf AI alone: The living context graph provides rich contextual awareness, specialized agents identify and remediate exposures, and human oversight ensures accountability. But each remediation cycle starts with a fresh graph containing no memory of previous cycles. Agents cannot distinguish recurring patterns from novel threats, and strategies cannot leverage historical effectiveness data.

Surf AI + MemU Agentic Memory Framework: Every remediation cycle deposits intelligence future cycles build upon. Agents recognize recurring patterns immediately, apply proven strategies first, and escalate systemic root causes rather than repeatedly treating symptoms. The living context graph gains temporal depth, transforming agentic security operations from reactive response into predictive intelligence anticipating exposures before they materialize.

Compared to other agentic security operations approaches — CrowdStrike Charlotte AI, Microsoft Security Copilot, Palo Alto XSIAM — Surf offers the most sophisticated context graph with direct remediation. But all share the same temporal limitation: current-state awareness without historical intelligence. MemU uniquely provides the persistent memory layer any security platform needs to evolve from reactive detection to predictive prevention.

Securing the Enterprise: Better Together

MemU does not replace Surf's context graph — it ensures security intelligence compounds across every incident cycle:

  • Graph enrichment: Surf maps current relationships; MemU adds historical data — how permissions evolved, which access patterns preceded incidents, which organizational changes correlated with exposure spikes — enriching analysis with temporal context revealing trends invisible in any single snapshot.
  • Agent specialization: Surf deploys domain-specific agents; MemU's persistent memory ensures each carries forward expertise across cycles — an identity agent that has resolved hundreds of deprovisioning incidents applies accumulated expertise to every new finding rather than starting with a blank slate.
  • Audit intelligence: Audit trails record what happened; MemU captures why specific decisions were made, what alternatives were considered, and what outcomes resulted — transforming compliance artifacts into operational intelligence informing future agentic security operations decisions.

Get Started with MemU

Give your security agents persistent memory to transform agentic security operations from reactive incident response into predictive intelligence compounding with every remediation cycle. The MemU Agentic Memory Framework integrates with any security platform — one API, instant persistence, zero changes to existing infrastructure. Visit memu.pro to explore the Agentic Memory Framework API, or check out the GitHub repository to start building agents that remember.

Tags: Surf AI, agentic security operations, living context graph, AI security agents, exposure remediation, persistent security intelligence, cybersecurity automation, MemU AI