Act Security
Action-centric cloud security platform that eliminates excessive access paths at the infrastructure layer instead of just flagging vulnerabilities after the fact.
Visit Website ↗ + Add to CompareOverview
Act Security is built on the premise that cloud security has focused too long on identifying vulnerabilities without addressing the excessive access permissions that make those vulnerabilities exploitable in the first place. Rather than reporting a finding for a human to patch, Act’s platform places contextual boundaries across a customer’s cloud environment and continuously removes unnecessary access paths as the environment changes — targeting the access sprawl that sits behind most cloud breaches, whether the attacker is human or an AI agent.
Act was founded in 2025 by Jonathan Langer, Itay Kirshenbaum, Stephan Goldberg, and Ilai Fallach — the team behind Medigate, the medical-device cybersecurity company acquired by Claroty for roughly $400 million. The Tel Aviv-based company emerged from stealth in July 2026 with $60 million in total funding: a $20 million seed round led by Team8 and Bessemer Venture Partners, followed by a $40 million Series A led by Notable Capital.
The founding team’s prior successful exit and the scale of funding secured before any public product launch reflect strong investor conviction in the “action-centric” thesis, even though the platform’s real-world impact on breach rates has not yet been independently measured.
Innovation Matrix Assessment
A repeat founding team raised $60M across seed and Series A and launched a full platform within roughly a year of founding.
Eliminating excessive access paths rather than just flagging vulnerabilities gives security teams a way to reduce risk proactively, ahead of the next disclosed CVE.
A $60M raise from Team8, Bessemer, and Notable Capital, backing a founding team with a proven $400M prior exit (Medigate), is a strong and independently verifiable momentum signal.
Reframing cloud security around eliminating access paths rather than patching vulnerabilities is a genuine shift in operating model, not merely a new dashboard on familiar CSPM findings.
The platform is newly launched with no independently published breach-prevention results yet; efficacy claims currently rest on the company's own description of its approach.
Excessive cloud access and permission sprawl are consistently cited root causes in breach reports, and this problem grows as AI agents add another class of identities needing access.
Why CISOs Should Care
It shrinks the pool of exploitable access paths across the cloud estate before an attacker — human or AI — ever needs a specific vulnerability to exploit.
What Makes It Different
It removes excessive access permissions proactively rather than reporting vulnerabilities and waiting on a patch or manual fix.
The Matrix Verdict
70/100 — MEANINGFUL INNOVATOR
Act Security is a Meaningful Innovator: a proven founding team, substantial and credible funding, and a genuine reframing of the cloud security problem, tempered by the fact that its real-world efficacy is not yet independently proven.
Editorial Note: Claims vs. Verified Findings
Funding amounts, investors, and the founders' prior Medigate exit are independently corroborated (Bessemer, Calcalist, PR Newswire). Specific claims about access-path reduction outcomes are vendor-sourced and not yet independently benchmarked.
Sources
- Bessemer Venture Partners — https://www.bvp.com/news/act-proactive-cloud-security
- Calcalist — https://www.calcalistech.com/ctechnews/article/u1pvtdzh3
- PR Newswire — https://www.prnewswire.com/news-releases/act-security-launches-action-centric-cloud-security-platform-with-60-million-in-funding-302836148.html
Alternatives to Act Security
Wiz
Agentless, graph-based cloud security platform that maps multi-cloud risk end-to-end, now owned by Google after a record $32B…
Chainguard
Provides hardened, minimal, continuously-rebuilt container images and software packages to eliminate vulnerabilities before they reach production.
Microsoft Defender for Cloud
Microsoft's built-in cloud-native application protection platform, unifying CSPM, workload protection, and DevOps security natively across Azure, AWS, and…
Sysdig
The company behind Falco, the CNCF's runtime security standard, offering an eBPF/kernel-level CNAPP built on live syscall-based threat…
Obsidian Security
Obsidian Security provides a SaaS security posture management (SSPM) platform that detects identity-centric threats and misconfigurations across enterprise…
Upwind Security
Fast-growing, venture-backed CNAPP startup combining agentless scanning with eBPF runtime sensors for real-time cloud and AI workload risk…