Push Security
Push Security detects and blocks identity attacks — phishing, credential stuffing, account takeover, malicious OAuth grants — directly inside the browser, where they actually happen.
Visit Website ↗ + Add to CompareOverview
Push Security builds browser-based identity threat detection and prevention, placing a detection point directly in the browser to catch phishing, credential stuffing, account takeover, and malicious OAuth integrations as they occur — closer to the actual point of compromise than network- or identity-provider-level tools typically reach. The platform also extends into visibility and policy enforcement for shadow AI tool usage inside the browser.
Founded in 2022 by Adam Bateman (CEO), Tyrone Erasmus (CTO), and Jacques Louw (CPO) — a team with roots in offensive security firm MWR InfoSecurity and identity vendor Duo Security, including advisors Jon Oberheide and Dug Song (Duo’s co-founders) — Push Security is backed by investors including Google Ventures, Decibel Partners, Redpoint, B3 Capital, and Datadog.
Push’s differentiator is the browser itself as the enforcement point: rather than relying on network logs or identity-provider signals that arrive after an attack has already progressed, it observes and intervenes at the moment a user interacts with a phishing page or grants a risky OAuth permission.
Innovation Matrix Assessment
A genuinely novel browser-native detection point, built by a team with deep offensive-security and identity-industry (Duo Security) pedigree.
Catches phishing, credential stuffing, account takeover, and malicious OAuth grants at the moment of user interaction, directly addressing top identity-based breach vectors.
Backing from Google Ventures, Datadog, and Redpoint, alongside advisors who co-founded Duo Security, reflects strong strategic investor confidence.
Using the browser as a real-time identity-attack detection and enforcement point is a genuinely different approach from traditional IAM, EDR, or SASE-based identity protection.
Still an emerging company; independent, large-scale efficacy validation beyond investor and advisor endorsement was not found publicly.
Identity-based attacks (phishing, credential theft, OAuth abuse) and browser-delivered AI tools are top current and near-future threat vectors, keeping this approach highly relevant.
Why CISOs Should Care
Stops identity attacks — phishing, credential stuffing, account takeover, risky OAuth grants — at the moment they happen in the browser, before they reach the network or identity provider.
What Makes It Different
Uses the browser itself as a real-time detection and enforcement point rather than relying on network logs or identity-provider signals that arrive after the fact.
The Matrix Verdict
67/100 — INCREMENTAL INNOVATOR
A technically differentiated, well-backed identity security approach with strong founder pedigree; independent large-scale validation is still building.
Editorial Note: Claims vs. Verified Findings
Investor and founder-background details are independently reported; efficacy claims specific to attack-prevention rates were not independently verified.
Sources
Alternatives to Push Security
Teleport
An identity-based infrastructure access platform issuing short-lived cryptographic identities for humans, machines, and AI agents in place of…
SpecterOps
Identity attack-path security specialist behind BloodHound, the widely used open-source tool for mapping Active Directory and Entra ID…
Socure
AI-driven identity verification and fraud platform used by banks, fintechs, and government agencies to validate identities during digital…
Keyfactor
Machine identity and PKI management platform helping enterprises secure certificates, keys, and post-quantum cryptography readiness at scale.
Astrix Security
Non-human identity security platform that discovers and governs API keys, OAuth tokens, service accounts, and AI-agent credentials across…
CyberArk
The market-leading privileged access management vendor, extending from vaulted human credentials into machine identity and secrets management.