The commercial story a cloud-security company tells is usually about coverage: one platform that sees more of the environment, so a customer consolidates spend onto it instead of buying a separate tool for each layer. Wiz built that story on a specific technical bet, agentless scanning, reading a cloud environment from the outside without asking customers to deploy software inside every workload. It is a fast-to-adopt approach that made the company one of the most-watched names in security, and the subject of a widely reported agreement for Google to acquire it. A patent application speaks to where that platform is heading in a particular way. It is not a roadmap slide; it is a roughly 18-month-delayed snapshot of where the research budget actually went, surfaced only when the application publishes. Two Wiz records that just published do not describe more of the same agentless scanning. They describe the company reaching into the two categories on either side of it.
The first is runtime. US20260189464A1, "Endpoint Detection and Response Based on Aggregated Runtime Execution Data," describes a sensor placed on a cloud resource that detects an event, matches it to a rule specifying a mitigation action, carries that action out, and records the event into a software bill of materials so that separate signals can later be joined into a dangerous combination. That is a control-and-act footprint, not the read-only snapshot posture that agentless scanning provides. Runtime detection and response is a distinct product category, and a distinct competitive field, from the configuration scanning Wiz is known for; a filing that puts a sensor on the workload and lets it act is a filing pointed at that field.
The second is data. US20260189596A1, "Techniques for Agentless Detection of Sensitive Data on Managed Databases," works the other adjacent market: knowing not just whether a cloud resource is misconfigured but whether it holds data that matters.
The system and method for agentless detection of sensitive data in a cloud computing environment are presented. The method includes extracting a data schema of a data file from the data file; deploying the data file in a cloud computing environment; storing the data schema in a security database, the security database including a representation of the cloud computing environment; generating a data file node in the security database, the data file node corresponding to the data file; classifying a type of sensitive data in the data file; updating a value in metadata of the data file node, the value indicating the classified type of sensitive data; and performing a mitigation action based on the classified type of sensitive data and a location of the data file.— Techniques for Agentless Detection of Sensitive Data on Managed Databases, US20260189596A1
As the dependent claims describe it, the classification can sort a file as personal identifiable information, personal health information, payment-card data, or not sensitive, and the mitigation can range from an alert that a sensitive file is somewhere it should not be, to removing or deleting the file. That is the shape of what the industry calls data security posture management, and notably it is done the agentless way, extracting schemas and building nodes in a security graph rather than installing collectors. The company applied its founding technique to a neighboring problem.
One filing is a project. Two, pointed at different edges, is a direction.
The two records are more informative together than apart because they point at different adjacencies. Runtime detection extends the platform down into execution; data discovery extends it across into the contents of storage. Both share the graph-of-the-environment substrate that agentless scanning already produces, the runtime record writes events into a software bill of materials keyed to component identities, and the data record builds file nodes into a security database that holds a representation of the cloud environment. The engineering signal is a platform being widened at two edges from the same core data model, rather than two unrelated bets.
Set against the broader July 2 drop, the direction is where a good deal of the field's disclosed effort is going. US20260189600A1 describes automated response coordinated across a collective of client networks; US20260189576A1 describes edge-native detection that scores risk from an identity graph and pushes policy to enforcement nodes; and US20260189589A1 describes using a large language model to keep a vulnerability-and-risk-assessment framework current. Access-side work shows up too, in US20260189570A1, directed at curbing privilege overreach through group-based access. These are separate filings from separate parties, but the market context they establish is consistent: buyers are consolidating onto platforms that both detect and act, and that reason over the whole environment rather than one control at a time. Wiz's two filings read as an entry into exactly that consolidation, from the posture-scanning side of it.
The business read: platform expansion, disclosed as engineering.
Here is why the pairing matters more than either record alone. The commercial argument for a security platform is that each new capability it absorbs is a tool a customer no longer buys separately, and the categories most valuable to absorb are the ones nearest the platform's existing footprint, because they reuse the same data and the same deployment relationship. Runtime detection and data security posture management are precisely those near-in categories for an agentless posture vendor. Applications that push R&D into both suggest a company treating platform breadth, not a single better scanner, as the research objective, the same coverage-and-consolidation logic that underwrites the pitch to customers and, by extension, the valuation a strategic acquirer would put on it.
The standard caveat applies and is load-bearing for a business reader. These are published applications, not granted patents. They establish where research money was spent roughly 18 months ago, not what Wiz can yet enforce against a competitor, and the claims that ultimately issue may be narrower than the abstracts read today. For reading direction rather than litigation exposure, that is precisely the value: a grant tells you what a company locked down, while an application tells you what it was reaching for. On the evidence of US20260189464A1 and US20260189596A1, what it was reaching for was the runtime and the data, the two markets flanking the agentless scanning it already owns.
Comments
Loading comments…