Grip Security
SaaS identity risk platform that discovers shadow SaaS usage and unmanaged application identities, then extends governance and access control over them.
Visit Website ↗Overview
Grip Security, founded in January 2021 by Lior Yaari, Idan Fast, and Alon Shenkler, addresses SaaS sprawl and shadow IT from an identity angle: discovering the often-large number of SaaS applications employees have signed into using corporate credentials or personal accounts, many of which never went through formal procurement or security review, and then applying identity governance and risk scoring to that unmanaged population.
Its SaaS Security Control Plane platform is designed to sit alongside conventional IAM and CASB tools, filling the gap where business-led SaaS adoption (an employee signing up for a tool with a corporate email, bypassing IT) creates identities and access grants that are invisible to the identity team until an incident or access review surfaces them.
The company has raised $76 million, including a $41 million Series B led by Third Point Ventures, and competes in a growing niche alongside SaaS security posture management (SSPM) vendors, positioning identity risk — rather than pure configuration risk — as its primary lens.
Innovation Matrix Assessment
Has broadened from SaaS discovery into a fuller SaaS Security Control Plane with governance and risk scoring, but the category is still maturing.
Surfacing shadow SaaS identities that bypassed procurement gives security teams visibility they otherwise lack, though remediation still typically requires manual follow-up with business units.
$76M raised across a Series B is respectable but modest relative to leading NHI/identity-security peers in this list, and the company operates in an increasingly crowded SSPM-adjacent space.
Framing shadow SaaS as an identity-risk problem, rather than purely a configuration or data-loss problem, is a genuinely different lens than most CASB or SSPM tools apply.
As a relatively young, privately held company, independent third-party production-scale efficacy evidence is limited beyond funding announcements.
Business-led, unmanaged SaaS adoption is a persistent and likely growing problem as employees and now AI agents adopt new tools independently of IT.
Why CISOs Should Care
Grip gives security teams visibility into the SaaS applications and identities employees have adopted outside formal procurement — a population that traditional IAM and CASB tools typically can't see until it's already a risk.
What Makes It Different
It treats shadow SaaS primarily as an identity governance problem — who has access to what, and how that access was created — rather than purely a data-loss or configuration-posture problem like most SSPM tools.
The Matrix Verdict
58/100 — INCREMENTAL INNOVATOR
A useful, identity-centric take on shadow SaaS discovery in a crowded and still-forming category, with real but moderate funding momentum. An Incremental-to-Meaningful Innovator.
Editorial Note: Claims vs. Verified Findings
Funding figures are corroborated by TechCrunch and BusinessWire coverage of the Series B; the scale of shadow SaaS risk it addresses is a widely discussed industry concern but specific discovery statistics attributed to Grip are vendor-sourced.
Sources
- TechCrunch — Grip Security raises $41M — https://techcrunch.com/2023/08/22/grip-security-raises-41m-to-help-enterprises-manage-their-saas-identity-risk
- BusinessWire — https://www.businesswire.com/news/home/20230822690615/en/Grip-Security-Raising-41-Million-Series-B-Led-by-Third-Point-Ventures
- The SaaS News — https://www.thesaasnews.com/news/grip-security-raises-41-million-in-series-b/
Alternatives to Grip Security
Silverfort
Agentless unified identity protection platform that extends MFA, ITDR, and access policy to legacy and unmanaged systems traditional…
Veza
Identity security platform built around an authorization graph that maps who and what can actually access data and…
Oasis Security
Non-human identity management platform discovering, classifying, and governing service accounts, API keys, and machine credentials, now extending to…
Semperis
Identity resilience platform specializing in Active Directory security posture, attack-path discovery, threat detection, and disaster recovery.
Microsoft Entra ID
Microsoft's cloud identity and access platform (formerly Azure AD) providing SSO, conditional access, MFA, and identity governance across…
CyberArk
The market-leading privileged access management vendor, extending from vaulted human credentials into machine identity and secrets management.