Twine Security
Twine Security builds autonomous 'AI digital employees' — starting with Alex, an IAM specialist — that execute identity and access management work end-to-end.
Visit Website ↗ + Add to Compare Claim This CompanyOverview
Twine Security (twinesecurity.com) is a Tel Aviv-Yafo, Israel-based startup founded in May 2024 by Benny Porat (CEO), Nadav Erez, and Omri Green — former core team members of OT-security unicorn Claroty. The company raised a $12 million seed round in November 2024, co-led by Ten Eleven Ventures and Dell Technologies Capital, with Wiz co-founder/CEO Assaf Rappaport among the angel investors.
Twine’s product is a line of autonomous ‘AI digital employees’ designed to execute full security workflows rather than just surface alerts; its first, Alex, is scoped to identity and access management — detecting issues, analyzing identity/access data, planning remediation, and then executing the remediation itself. In its own case-study materials, Twine cites named or identified enterprise customers (Qualtrics, Nestlé, Siemens, ICTS Europe, Telit Cinterion) and a Deloitte partnership, along with reported results such as a 41% reduction in ticket load for a Fortune 500 food-and-beverage customer within 180 days, a 76% entitlement reduction at a Fortune 500 healthcare customer, and 5,731 hours saved across customers in a recent quarter.
In October/November 2025, Twine was named a Gartner ‘Cool Vendor’ in Identity-First Security — independent analyst recognition rather than a vendor claim — and was also named a Forbes Cloud 100 Rising Star, an RSAC 2025 Innovation Sandbox finalist, and a Black Hat USA 2025 Startup Spotlight finalist.
Innovation Matrix Assessment
Within ~18 months of founding, shipped a working IAM-focused agent (Alex), landed named enterprise deployments, and collected multiple industry recognitions (Gartner, RSAC, Black Hat finalist) — fast, substantiated progress for a seed-stage company.
Directly targets chronic IAM operational toil (access reviews, entitlement cleanup, ticket backlog) with reported before/after metrics (ticket-load and entitlement reductions) tied to named or identified Fortune 500 customers — concrete, if vendor-reported, operational relevance.
A $12M seed plus multiple named enterprise customers (Qualtrics, Nestlé, Siemens, ICTS Europe, Telit Cinterion), a Deloitte partnership, and a genuine Gartner Cool Vendor placement is unusually strong independent momentum evidence for a company this young.
The 'autonomous digital employee' framing for full-lifecycle IAM task execution (not just detection) is a genuinely distinct category framing, though it sits within a broader, fast-growing wave of agentic security-operations tooling rather than standing alone.
Reported metrics (41% ticket reduction, 76% entitlement reduction, hours saved) come from Twine's own case studies with named or Fortune-500-anonymized customers, not independent audits; Gartner's Cool Vendor nod is analyst recognition, not an efficacy test.
IAM automation via agentic AI directly addresses the identity team talent gap and growing entitlement sprawl — a problem highly likely to remain central over the next 3-5 years.
Why CISOs Should Care
Offers CISOs a way to apply continuous, always-on execution capacity to chronic IAM backlog (access reviews, entitlement cleanup, remediation) without proportionally growing headcount, directly addressing the identity-team talent gap.
What Makes It Different
Rather than another IAM dashboard or detection tool, Twine frames its product as an autonomous 'digital employee' performing the full analyze-plan-execute-remediate loop for IAM tasks, backed by named enterprise deployments and reported before/after metrics.
The Matrix Verdict
62/100 — INCREMENTAL INNOVATOR
The most substantiated of comparable early-stage agent-security vendors: independent analyst recognition (Gartner Cool Vendor), named Fortune 500 and recognizable customers, and reported operational metrics give it more real-world grounding than typical seed-stage peers, though efficacy metrics remain vendor-reported rather than independently audited.
Editorial Note: Claims vs. Verified Findings
Customer-impact metrics (41% ticket-load reduction, 76% entitlement reduction, 5,731 hours saved) are reported by Twine in its own press/case-study materials with named or Fortune-500-anonymized customers, not independently audited or third-party tested. Gartner's 'Cool Vendor' designation is independent analyst recognition but is explicitly not a ranking or endorsement of efficacy.
Sources
Alternatives to Twine Security
Teleport
An identity-based infrastructure access platform issuing short-lived cryptographic identities for humans, machines, and AI agents in place of…
SpecterOps
Identity attack-path security specialist behind BloodHound, the widely used open-source tool for mapping Active Directory and Entra ID…
Astrix Security
Non-human identity security platform that discovers and governs API keys, OAuth tokens, service accounts, and AI-agent credentials across…
Socure
AI-driven identity verification and fraud platform used by banks, fintechs, and government agencies to validate identities during digital…
Keyfactor
Machine identity and PKI management platform helping enterprises secure certificates, keys, and post-quantum cryptography readiness at scale.
Silverfort
Agentless unified identity protection platform that extends MFA, ITDR, and access policy to legacy and unmanaged systems traditional…