Act Security Emerges from Stealth to Fight the Patch Problem
Act Security, a Tel-Aviv based startup founded in 2025, has raised $60 million in funding to address the growing challenge of AI-induced vulnerabilities in cloud environments. The company focuses on reducing access sprawl by enforcing deterministic boundaries that limit what humans, workloads, and AI agents can reach, thereby mitigating the risk of unpatched vulnerabilities being exploited. Act Security's approach aims to make cloud infrastructures structurally secure before attacks unfold, rath
Analysis
TL;DR
- Act Security, a Tel-Aviv based startup founded in 2025, has raised $60 million in funding to address the growing challenge of AI-induced vulnerabilities in cloud environments.
- The company focuses on reducing access sprawl by enforcing deterministic boundaries that limit what humans, workloads, and AI agents can reach, thereby mitigating the risk of unpatched vulnerabilities being exploited.
- Act Security's approach aims to make cloud infrastructures structurally secure before attacks unfold, rather than relying solely on patching vulnerabilities as they are discovered.
- The platform helps enterprises remove exposed paths used by attackers, deploy AI agents safely, and achieve compliance with standards such as NIST 800-53, PCI DSS, and HIPAA.
Why It Matters
The rapid pace at which AI models discover new vulnerabilities is overwhelming traditional patch management strategies, making it crucial for organizations to adopt more proactive security measures. Act Security's approach of reducing access sprawl and enforcing deterministic boundaries offers a strategic solution to this growing problem, potentially setting a new standard for cloud security practices.
Technical Details
- Funding and Team: Act Security secured $60 million in total funding, including a $20 million Seed round and a $40 million Series A round. The founding team includes Jonathan Langer (CEO), Itay Kirshenbaum (CTO), and Pini Pinhasov (CPO), who previously founded Medigate, sold to Claroty for $400 million.
- Core Problem: The article highlights the increasing number of CVEs projected for 2026, with over 161 new vulnerabilities discovered daily. This surge is driven by the capabilities of frontier AI models to identify and exploit vulnerabilities faster than vendors can patch them.
- Solution Approach: Act Security's platform focuses on reducing the attack surface by limiting access permissions to only those necessary for operations. This involves enforcing deterministic boundaries around human users, workloads, and AI agents to prevent unauthorized actions and reduce the risk of exploitation.
- Compliance and Safety: The platform supports compliance with various regulatory frameworks, including NIST 800-53, PCI DSS, and HIPAA, ensuring that enterprises can maintain security while adhering to industry standards.
Industry Insight
- Shift from Reactive to Proactive Security: The rise of AI in vulnerability discovery necessitates a shift from reactive patching to proactive security measures. Companies like Act Security are leading this change by focusing on reducing access sprawl and enforcing strict access controls.
- Importance of Deterministic Boundaries: Enforcing deterministic boundaries is becoming a critical strategy for securing cloud environments. This approach not only mitigates the risk of unpatched vulnerabilities but also ensures that AI agents operate within safe and defined parameters.
- Regulatory Compliance: As regulatory requirements become more stringent, solutions that help enterprises comply with multiple standards simultaneously will be highly valued. Act Security's platform addresses this need, making it an attractive option for organizations looking to enhance their security posture while maintaining compliance.
Disclaimer: The above content is generated by AI and is for reference only.