Act Security
Tel Aviv startup from the Medigate founders building a platform that stops AI agents from inheriting excessive cloud permissions.
Visit Website ↗ + Add to Compare Claim This CompanyOverview
Act Security builds a cloud security platform aimed at stopping AI agents from inheriting bloated or dangerous cloud permissions as enterprises roll out autonomous agents across their infrastructure. As organizations grant AI agents access to cloud resources, permission sprawl designed for human users creates risk the company says traditional identity tools were not built to handle.
The Tel Aviv-based company was founded by Jonathan Langer (CEO), Itay Kirshenbaum (CTO), Stephen Goldberg (CPO), and Ilai Fallach (Chief R&D Officer). Langer and Kirshenbaum previously co-founded medical-device security company Medigate, which was acquired by Claroty for roughly $400 million in 2021.
Act Security emerged from stealth in July 2026 with $60 million in total funding, comprising a $20 million seed and a $40 million Series A completed just four months apart. The Series A was led by Notable Capital, with participation from Startpoint Capital, Claltech, Bessemer Venture Partners, Team8, Hetz Ventures, and Brightmind.
Innovation Matrix Assessment
Repeat founders with a prior $400M exit (Medigate) closed seed and Series A rounds only four months apart.
Addresses a concrete, fast-emerging problem: AI agents accumulating excessive cloud permissions as enterprises automate infrastructure tasks.
$60M raised within months of launch from well-known institutional investors (Bessemer, Team8) is strong, independently verifiable momentum for a pre-launch company.
Framing permission governance specifically around AI-agent behavior is a meaningful specialization, though it overlaps with the broader CIEM and non-human-identity category.
Still pre-launch commercially; no named customers or independent efficacy evidence yet beyond the founders' track record.
AI agent identity and permission governance is one of the fastest-growing problem areas CISOs are budgeting for in 2026 and beyond.
Why CISOs Should Care
Addresses a risk CISOs are actively worried about today: autonomous AI agents quietly accumulating standing cloud access that no human would be granted.
What Makes It Different
Purpose-built for agent-specific permission lifecycles rather than extending human-identity CIEM tooling to cover agents as an afterthought.
The Matrix Verdict
63/100 — INCREMENTAL INNOVATOR
An Incremental Innovator with unusually strong founder credibility and funding velocity; real-world efficacy evidence is the main gap before it could be called Meaningful.
Editorial Note: Claims vs. Verified Findings
Funding amounts and investor names are independently reported by multiple outlets; product efficacy claims are currently vendor-stated only, as the company has only just exited stealth.
Sources
Alternatives to Act Security
Teleport
An identity-based infrastructure access platform issuing short-lived cryptographic identities for humans, machines, and AI agents in place of…
SpecterOps
Identity attack-path security specialist behind BloodHound, the widely used open-source tool for mapping Active Directory and Entra ID…
Astrix Security
Non-human identity security platform that discovers and governs API keys, OAuth tokens, service accounts, and AI-agent credentials across…
Socure
AI-driven identity verification and fraud platform used by banks, fintechs, and government agencies to validate identities during digital…
Keyfactor
Machine identity and PKI management platform helping enterprises secure certificates, keys, and post-quantum cryptography readiness at scale.
Silverfort
Agentless unified identity protection platform that extends MFA, ITDR, and access policy to legacy and unmanaged systems traditional…