Act Security
by Act Security
Action-centric cloud security that removes standing access from humans, workloads and AI agents
Act Security is a cloud security platform that removes excessive access instead of reporting it. It models what every human, workload and AI agent can actually reach across identity and network together, then strips unused access paths through native cloud controls and infrastructure-as-code. It is aimed at security teams putting production AI agents into cloud environments where those agents inherit years of accumulated human permissions.
Act Security is a cloud security platform that tries to remove attack paths rather than score them. Instead of ranking misconfigurations, it maps a customer's cloud into boundaries that mirror how the business actually operates, then cross-analyses identity, network and AI access together to model what each human, workload and AI agent can genuinely reach — the company's stated premise being that close to 97% of granted cloud access sits dormant and unused while remaining fully exploitable. Enforcement is organised around six boundaries: external, to block inbound attack and data exfiltration; human identity, to remove standing privileged access; environment, to isolate production from sandbox; application, to prevent lateral movement; AI, to constrain what endpoint and cloud AI agents can reach; and data, for tenant isolation and regulatory scope covering GDPR, NIST 800-53, PCI DSS and HIPAA. The platform is agentless — it writes through existing cloud-native controls and infrastructure-as-code pipelines such as Terraform and CloudFormation — and every proposed policy change is first simulated against historical access patterns so legitimate operations do not break, a design inherited from the founders' previous company, Medigate, which secured hospital devices that could not tolerate downtime. Continuous validation then runs from CI/CD through runtime to stop access sprawl from returning. Founded in 2025 in Tel Aviv by CEO Jonathan Langer and the team that sold Medigate to Claroty for roughly $400 million, Act left stealth on 28 July 2026 with $60 million in funding, is SOC 2 Type II and ISO 27001 certified, and is available through the AWS and Azure marketplaces.
CISOs and cloud security architects who are about to put autonomous AI agents into production on AWS or Azure and have realised those agents will inherit the same over-broad IAM roles their human predecessors accumulated.
Dormant and excessive cloud access is actually removed — simulated first against real historical usage so nothing breaks — instead of appearing as one more finding on a posture dashboard nobody has time to remediate.
At a Glance
- Category
- Governance & Security
- Pricing
- Contact for pricing, Subscription
- Target Market
- CISOs, CIOs, Cloud Security Architects, Platform Engineering Teams
- Deployment
- Cloud-only, Multi-cloud
- Founded
- 2025
- Headquarters
- Tel Aviv, Israel
Key Features
- ✓Boundary mapping
Maps cloud constructs into boundaries reflecting real business operations, comparing configured, observed and intended access side by side.
- ✓Reachability modelling
Cross-analyses identity, network and AI access together rather than separately, exposing paths that single-dimension CIEM or CSPM tools miss.
- ✓Hardening campaigns
Structured, staged policy changes that eliminate access paths in bulk instead of leaving thousands of individual findings for engineers to triage.
- ✓Policy simulation
Every proposed change is tested against historical access patterns before enforcement, so removing permissions does not break legitimate production workflows.
- ✓AI agent boundaries
Enforces tightly scoped access around every AI workload so production agents reach only what their task actually requires.
- ✓Agentless native enforcement
Writes policy through existing cloud-native controls and infrastructure-as-code such as Terraform and CloudFormation, with no sensor to deploy.
- ✓Continuous validation from CI/CD to runtime
Catches new over-permissive configuration in the pipeline so access sprawl does not silently rebuild after the initial cleanup.
Capabilities
Use Cases
- •Safe production rollout of AI agents
Security defines a hard access boundary around each AI workload so an autonomous agent cannot inherit a human's accumulated admin permissions.
- •Eliminating standing privileged access
Dormant admin and break-glass permissions are removed across the estate after simulation confirms no legitimate workflow depends on them.
- •Blast-radius reduction ahead of an audit
Environment and application boundaries isolate production from sandbox and stop lateral movement between apps, evidencing least privilege for NIST 800-53 or PCI DSS.
- •Stopping access sprawl at the source
Boundary policies are enforced inside Terraform and CloudFormation pipelines so over-permissive infrastructure never reaches production in the first place.
- •Multi-tenant data isolation
Data boundaries enforce tenant separation and regulatory scope for SaaS providers handling customer data under GDPR or HIPAA obligations.
Ideal For
Best For
- ✓Constraining what production AI agents can reach before they are granted cloud credentials
- ✓Removing dormant and standing privileged access across AWS and Azure at scale
- ✓Reducing lateral movement between applications and isolating production from sandbox environments
- ✓Preventing new access sprawl by enforcing boundaries in Terraform and CloudFormation pipelines
- ✓Evidencing continuous compliance against NIST 800-53, PCI DSS, HIPAA and GDPR access requirements
Not Ideal For
- ✗Google Cloud-first organisations — the platform is listed and documented for AWS and Azure, and GCP coverage is not stated, so multi-cloud shops with meaningful GCP estate still need a second tool
- ✗Buyers who require third-party validation before purchase: the company left stealth in July 2026 with no G2, PeerSpot or Gartner Peer Insights reviews and no public production write-ups
- ✗Teams that only want visibility and reporting — Act's value is in enforcement, which means change-management work and simulation cycles before anything is removed
- ✗Small cloud estates where a handful of IAM roles can be audited by hand; the platform is priced and positioned for enterprise environments
Deployment
Market Analysis
Pros
- ✓Enforcement-first design addresses the actual failure of a decade of cloud security tooling — findings that are produced faster than anyone can remediate them
- ✓Pre-enforcement simulation against historical access is the credible answer to the usual objection that least privilege breaks production
- ✓Founding team has done this before in an environment with zero tolerance for downtime: Medigate secured hospital medical devices and sold to Claroty for about $400 million
- ✓SOC 2 Type II and ISO 27001 certified at launch, with named CISO references at Klaviyo, Benchling, Armis, AlphaSense, Omada Health and Monolithic Power Systems
Cons
- ✗Publicly launched 28 July 2026 with no independent user reviews on G2, PeerSpot or Gartner Peer Insights and no Hacker News discussion, so production behaviour at scale is unverified by anyone outside the vendor's reference list
- ✗The Next Web's coverage is explicit about the execution risk: prove it in production and action-centric security becomes a category, fail and it is 'one more dashboard in a market that already has too many'
- ✗The category is crowded — established CSPM, CIEM and attack-path vendors already sell adjacent capability, and concurrent Israeli entrants Way Security and Mate Security launched into the same space
- ✗AWS and Azure are the documented clouds; Google Cloud support is not stated, which is a real gap for genuinely multi-cloud estates
- ✗No published pricing, no free tier and no trial, so evaluation requires a sales cycle and a scoping engagement before any technical validation
- ✗Sources disagree on the Series A syndicate — the company's own release names Notable Capital, Startpoint Capital and SVCI while The Next Web reports Lux Capital — which is a small reminder that launch-week reporting is not yet settled
Pricing
Enterprise
Contact for pricing
- ✓Boundary mapping and reachability modelling across AWS and Azure
- ✓Hardening campaigns with pre-enforcement simulation
- ✓AI workload access boundaries
- ✓CI/CD and infrastructure-as-code enforcement
- ✓Compliance mapping to NIST 800-53, PCI DSS, HIPAA and GDPR
No pricing is published on the website or in any launch coverage, and there is no self-service tier or advertised free trial — every deal goes through sales. The company maintains an AWS Marketplace seller profile and an Azure Marketplace presence, which in practice means procurement via private offer against committed cloud spend rather than a public price list. Budget accordingly: this is an enterprise security purchase with a scoping and simulation phase before enforcement begins.
Security & Compliance
Sources
This page was written from 7 sources, 5 on domains other than act.security.
- 1.act.security — act.securityvendor
- 2.act.security — platformvendor
- 3.prnewswire.com — act security launches action centric cloud security platform
- 4.thenextweb.com — act security stealth 60m cloud access ai agents
- 5.cybersecuritytribe.com — act security launches with 60 million in funding
- 6.cioinfluence.com — act security launches action centric cloud security platform
- 7.aws.amazon.com — seller profile
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
Ambient.ai
Agentic physical security: vision-language models that watch every camera continuously
Obsidian Security
Governs what AI agents and non-human identities can access and do inside your SaaS apps
Ceros
Bind every AI agent session to a real person on a verified device — and block what policy forbids
Noma Security
Discover, govern and defend every AI agent and MCP server in the enterprise — from inventory to runtime enforcement