Hush Security
by Hush Security
Kill standing credentials — discover every AI agent and broker just-in-time access at runtime
Hush Security is an identity-governance and machine-access platform for AI agents and non-human identities. It discovers every agent an enterprise runs, including shadow agents and MCP servers, gives each one a verifiable identity mapped to a human owner, and replaces standing credentials with scoped just-in-time permissions brokered at runtime, backed by a full audit trail and a central kill switch.
Hush Security is a machine-access and identity-governance platform that treats AI agents and non-human identities as a population to be discovered, scoped, and audited in their own right. Its premise, argued publicly by the company at its July 2026 funding announcement, is that the enterprise AI security problem has moved from protecting models to governing what autonomous software is permitted to touch — and the architecture follows from that. Every agent is enrolled into a central registry: desktop assistants, enterprise agents, custom builds, MCP servers and agent-to-agent sprawl, including shadow deployments the security team did not know existed. Each agent gets a verifiable identity of its own rather than a shared credential, and is mapped to an accountable human owner so actions are attributable. Standing credentials are then removed. Hush brokers short-lived, task-scoped just-in-time permissions at runtime, enforcing least-agency and on-behalf-of access so an agent inherits no privilege beyond the task it was asked to perform and cannot escalate through an over-broad service account. Every request, action, approval and resource touch is written to an audit trail for compliance and investigations, with runtime policy enforcement, anomaly detection and a centralised kill switch that revokes an agent's access immediately. The platform integrates with an organisation's existing identity provider rather than replacing it, and is SOC 2 and ISO 27001 certified. Founded in 2024 by four Meta Networks alumni — the Zero Trust company Proofpoint acquired for $120M in 2019 — and running about 31 people across Israel and the US, Hush raised a $30M Series A announced 28 July 2026 with Battery Ventures and YL Ventures returning and Akamai Technologies joining as a strategic investor, taking total funding to $41M. Kyndryl deploys it internally and resells it; Writer, ZoomInfo, Riskified, Swimlane, Shift4, Firefly and K Health appear as named customers.
The CISO or head of identity at an enterprise where developers and business teams have already deployed AI agents and MCP servers faster than IAM can issue and rotate credentials for them.
Every agent gets a scoped, time-limited identity tied to a named human owner — so there are no standing credentials to steal and one switch revokes an agent's access instantly.
At a Glance
- Category
- Governance & Security
- Pricing
- Freemium, Contact for pricing
- Target Market
- CISOs, CIOs, Identity and Access Management Teams, Security Architects, Platform Engineering Teams
- Deployment
- Cloud-first
- Founded
- 2024
- Headquarters
- Tel Aviv, Israel
- Team Size
- 11-50
- Customers
- Not disclosed; publicly named customers include Kyndryl, ZoomInfo, Writer, Riskified, Swimlane, Shift4, Firefly and K Health
Key Features
- ✓Agent discovery and live inventory
Finds desktop assistants, enterprise agents, custom builds, MCP servers and shadow agents, then maintains a live inventory of what is running.
- ✓Per-agent verifiable identity
Issues each agent its own identity instead of a shared credential and maps it to an accountable human owner for attribution.
- ✓Just-in-time, task-scoped permissions
Grants access at runtime for the specific task only, so agents never accumulate standing entitlements or inherit broad privilege.
- ✓Zero credential exposure
Removes standing secrets from agents entirely and brokers short-lived credentials at request time using identity-based access.
- ✓Centralised kill switch
Revokes an agent's access across the whole estate from one control plane when behaviour goes wrong or an investigation opens.
- ✓Attributable audit trail
Logs every request, action, approval and resource access so compliance teams and investigators can reconstruct what an agent did.
- ✓Runtime policy enforcement and anomaly detection
Applies policy and flags abnormal agent behaviour as it happens rather than reporting violations after the fact.
Use Cases
- •Finding the agents nobody registered
Security teams inventory desktop assistants and MCP servers that engineering deployed without review, then bring them under policy.
- •Retiring long-lived API keys from AI agents
Standing credentials embedded in agents and coding assistants are replaced with short-lived tokens brokered at each request.
- •Proving who did what during an incident
Investigators trace an agent action back through its scoped identity to the human owner who is accountable for it.
- •Containing a compromised or misbehaving agent
The central kill switch revokes that agent's access across every connected resource without touching other workloads.
- •Governing MCP tool access at scale
Enterprises control which Model Context Protocol servers, tools and resources each agent may reach rather than trusting the agent.
Ideal For
Best For
- ✓Discovering shadow AI agents, MCP servers and agent-to-agent traffic that never went through a security review
- ✓Eliminating long-lived API keys and service-account credentials embedded in agents and coding assistants
- ✓Producing an attributable audit trail of agent actions for compliance, incident investigation and EU AI Act-style accountability
- ✓Enforcing least-agency, on-behalf-of access so an agent cannot inherit a human's full entitlements
- ✓Enterprises that need an emergency kill switch to revoke a misbehaving agent's access across the estate at once
Not Ideal For
- ✗Organisations that require an established vendor with a deep support bench — Hush was founded in 2024, employs roughly 31 people, and emerged from stealth less than a year before its Series A
- ✗Buyers who need published enterprise pricing to budget, since only a free tier is advertised and everything above it requires a sales conversation
- ✗Teams unwilling to place a vendor in the runtime credential path; brokering short-lived credentials at request time makes Hush an availability dependency for agent access
- ✗Companies without an existing identity provider to integrate against, since Hush layers on IdP infrastructure rather than replacing it
- ✗Buyers who want to validate claims against independent user reviews before purchase — there is effectively no practitioner discussion of Hush on Hacker News and no readable public review score
Deployment
Market & Ratings
Not disclosed; publicly named customers include Kyndryl, ZoomInfo, Writer, Riskified, Swimlane, Shift4, Firefly and K Health
Market Analysis
Pros
- ✓Removes standing credentials rather than managing them, which eliminates the class of attack that secret rotation only shortens
- ✓Agent-to-human-owner mapping makes the audit trail genuinely attributable, which secret-scanning tools cannot provide
- ✓SOC 2 and ISO 27001 certified already, unusual for a company two years old and roughly 31 people
- ✓Kyndryl deploying internally and reselling gives independent operational validation plus enterprise distribution
- ✓Founding team previously built and exited Meta Networks, a Zero Trust platform Proofpoint acquired for $120M in 2019
- ✓Akamai's strategic participation in the Series A points to an edge/identity integration path rather than pure financial backing
Cons
- ✗No independent practitioner signal exists — a Hacker News search for 'Hush Security' returns a single unrelated 2008 comment, and no readable public review score was available, so vendor claims are unverified by users
- ✗Very small vendor: founded 2024, roughly 31 employees, out of stealth under a year, which is a real support and roadmap risk for a control that sits in the access path
- ✗No published pricing above a free tier, and the metering unit is undisclosed, making cost impossible to model before a sales cycle
- ✗Runtime credential brokering makes Hush a hard dependency for agent access — an outage in the broker is an outage in every governed agent
- ✗The non-human identity category is crowded with overlapping discover-and-scope pitches from Astrix, Entro, Token Security, Oasis Security, Britive and GitGuardian, so differentiation is hard to assess from marketing alone
- ✗No public data-residency or SLA documentation was found, which matters for EU and regulated buyers
Pricing
Free Forever
$0
- ✓No secrets required to start
- ✓Get up and running in minutes
Enterprise
Contact for pricing
- ✓Full agent discovery and inventory
- ✓Just-in-time access brokering
- ✓Centralised governance and audit
- ✓IdP integration
Hush advertises a Free Forever tier that requires no secrets to get started, but publishes no list pricing above it — enterprise deployments are a sales conversation, and neither the metering unit (per agent, per identity, per seat) nor any tier boundaries are disclosed publicly. Budget for a negotiated annual contract and ask directly how the free tier's limits are defined, since that boundary is the single most important commercial unknown. No public SLA or data-residency documentation was found either, so both should be raised in procurement.
Security & Compliance
Connect
Sources
This page was written from 5 sources, 4 on domains other than hush.security.
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
Drata AI Agent Governance
Discover every AI agent, block policy violations inline, and prove it to an auditor
Astelia
AI-native exposure management that proves which vulnerabilities an attacker can actually reach, then drives the fix
Microsoft Project Perception
An agentic security system of red, blue and green AI agents that expose, investigate and remediate risk inside Microsoft Defender
Actualyze AI
Enterprise AI control plane that governs, secures and cost-optimises every model request