Skip to content

Push Security

Push Security detects and blocks identity attacks — phishing, credential stuffing, account takeover, malicious OAuth grants — directly inside the browser, where they actually happen.

Visit Website ↗ + Add to Compare
67/100Incremental Innovator

Overview

Push Security builds browser-based identity threat detection and prevention, placing a detection point directly in the browser to catch phishing, credential stuffing, account takeover, and malicious OAuth integrations as they occur — closer to the actual point of compromise than network- or identity-provider-level tools typically reach. The platform also extends into visibility and policy enforcement for shadow AI tool usage inside the browser.

Founded in 2022 by Adam Bateman (CEO), Tyrone Erasmus (CTO), and Jacques Louw (CPO) — a team with roots in offensive security firm MWR InfoSecurity and identity vendor Duo Security, including advisors Jon Oberheide and Dug Song (Duo’s co-founders) — Push Security is backed by investors including Google Ventures, Decibel Partners, Redpoint, B3 Capital, and Datadog.

Push’s differentiator is the browser itself as the enforcement point: rather than relying on network logs or identity-provider signals that arrive after an attack has already progressed, it observes and intervenes at the moment a user interacts with a phishing page or grants a risky OAuth permission.

Innovation Matrix Assessment

Innovation Velocity 8/10

A genuinely novel browser-native detection point, built by a team with deep offensive-security and identity-industry (Duo Security) pedigree.

Operational Value 7/10

Catches phishing, credential stuffing, account takeover, and malicious OAuth grants at the moment of user interaction, directly addressing top identity-based breach vectors.

Market Momentum 6/10

Backing from Google Ventures, Datadog, and Redpoint, alongside advisors who co-founded Duo Security, reflects strong strategic investor confidence.

Category Disruption 6/10

Using the browser as a real-time identity-attack detection and enforcement point is a genuinely different approach from traditional IAM, EDR, or SASE-based identity protection.

Real-World Efficacy 5/10

Still an emerging company; independent, large-scale efficacy validation beyond investor and advisor endorsement was not found publicly.

Enduring Relevance 8/10

Identity-based attacks (phishing, credential theft, OAuth abuse) and browser-delivered AI tools are top current and near-future threat vectors, keeping this approach highly relevant.

Why CISOs Should Care

Stops identity attacks — phishing, credential stuffing, account takeover, risky OAuth grants — at the moment they happen in the browser, before they reach the network or identity provider.

What Makes It Different

Uses the browser itself as a real-time detection and enforcement point rather than relying on network logs or identity-provider signals that arrive after the fact.

The Matrix Verdict

67/100 — INCREMENTAL INNOVATOR

A technically differentiated, well-backed identity security approach with strong founder pedigree; independent large-scale validation is still building.

Editorial Note: Claims vs. Verified Findings

Investor and founder-background details are independently reported; efficacy claims specific to attack-prevention rates were not independently verified.

Sources