NewCore
by NewCore
Workforce identity rebuilt for humans, machines and AI agents
NewCore is a workforce identity security platform that authenticates, discovers and governs human employees and AI agents in one identity core. It targets enterprises whose legacy identity provider was built for people only, offering split-key token signing, phishing-resistant VisualMFA and first-class lifecycle management for AI agents.
NewCore is an identity security company founded in 2025 and based in Tel Aviv and San Francisco that emerged from stealth on June 15, 2026 with $66M raised at a reported $300M valuation. It was co-founded by Zohar Alon (CEO), who founded cloud-security company Dome9 (acquired by Check Point); Amihai Neiderman (CTO), a former Unit 8200 researcher and founder of Nym Health; and Erez Yarkoni (CCO), former CIO of T-Mobile USA and Telstra. NewCore argues that incumbent identity providers bolt agent management onto platforms designed for humans, so it built a single identity core for humans, machines and AI agents. Its Secure Split Key technology divides SAML/OIDC token-signing credentials between the customer and the platform to remove a single point of compromise. VisualMFA replaces phishable factors with an out-of-band, visually verified exchange backed by hardware-bound credentials in TPM and Secure Enclave, designed to resist relay, replay and social engineering. Agentic identity management treats AI agents as first-class identities with lifecycle and revocation, and an Agentic Skill lets Claude Code, Codex and Cursor access enterprise systems as managed identities. Identity Discovery continuously maps human and agent identities, including shadow accounts, orphaned credentials and unmanaged agents, and an agent-driven migration tool targets zero-downtime moves off an existing provider. At launch TechCrunch reported fewer than 10 customers, 10+ design partners and 50+ employees, with pricing expected in summer 2026. It competes directly with Okta and Microsoft Entra.
The CISO or identity/IAM lead at an enterprise rolling out AI agents and coding assistants who needs agents governed as identities alongside employees.
One identity graph and policy layer for humans and AI agents, with phishing-resistant sign-in and no single signing key to steal.
At a Glance
- Category
- Governance & Security
- Pricing
- Contact for pricing
- Target Market
- CISOs, CIOs, Identity and Access Management Teams, Security Architects
- Deployment
- Cloud-first
- Founded
- 2025
- Headquarters
- Tel Aviv, Israel and San Francisco, USA
- Team Size
- 51-200
- Customers
- Fewer than 10 (TechCrunch, June 2026)
Key Features
- ✓VisualMFA
Out-of-band, visually verified authentication with hardware-bound credentials in TPM and Secure Enclave, resisting relay, replay and social-engineering attacks.
- ✓Secure Split Key
Splits SAML/OIDC token-signing credentials between customer and platform, removing a single point of compromise in the identity provider.
- ✓Agentic identity management
Treats AI agents as first-class identities with lifecycle management and revocation, instead of shared service accounts or API keys.
- ✓Agentic Skill
Lets coding agents such as Claude Code, Codex and Cursor reach enterprise systems as managed, governed identities.
- ✓Identity Discovery
Continuously maps human and agent identities, surfacing shadow accounts, orphaned credentials and unmanaged agents across the estate.
- ✓Agent-driven migration
Uses agents to move organisations off an existing identity platform with the stated goal of zero downtime.
Use Cases
- •Governing AI coding agents
An engineering organisation gives Claude Code, Codex and Cursor managed identities so agent access to internal systems is scoped, audited and revocable.
- •Phishing-resistant workforce sign-in
A security team replaces push and OTP factors with VisualMFA's hardware-bound verification to blunt relay and social-engineering attacks.
- •Identity estate discovery
Continuous discovery finds shadow accounts, orphaned credentials and unmanaged agents so the team can remove standing access before attackers use it.
- •Hardening token signing
Split-key signing ensures a compromise of the identity provider alone cannot forge SAML or OIDC tokens for downstream applications.
Ideal For
Best For
- ✓Enterprises deploying AI agents that need lifecycle, access and revocation managed like employee identities
- ✓Governing coding agents such as Claude Code, Codex and Cursor as managed identities
- ✓Security teams hunting shadow accounts, orphaned credentials and unmanaged agents
- ✓Organisations that want phishing-resistant, hardware-bound MFA across the workforce
Not Ideal For
- ✗Risk-averse buyers who need a proven vendor — NewCore emerged from stealth in June 2026 with fewer than 10 customers
- ✗Teams wanting published pricing, compliance attestations or independent reviews before a pilot; none were public at research time
- ✗Organisations satisfied with the agent features Okta or Microsoft Entra are adding, since a core identity-provider migration is a heavy project
Deployment
Market & Ratings
Fewer than 10 (TechCrunch, June 2026)
Market Analysis
Pros
- ✓Founders with a prior security exit (Dome9 to Check Point) and enterprise CIO experience
- ✓Agent identities, discovery and governance in the same core as human sign-in
- ✓Architectural answers to known identity-provider failure modes: split-key signing and hardware-bound MFA
- ✓Well funded for its stage at $66M
Cons
- ✗Very early: out of stealth in June 2026 with fewer than 10 customers and 10+ design partners (TechCrunch)
- ✗No published pricing, compliance certifications or named customers at research time
- ✗Replacing a core identity provider is a high-risk migration, and Okta and Microsoft Entra are already adding agent-identity features
- ✗No independent user reviews on G2 or practitioner discussion on Hacker News yet
Pricing
Enterprise
Contact for pricing
- ✓Identity Security
- ✓Identity Discovery
- ✓Agentic Governance
NewCore publishes no pricing; TechCrunch reported at the June 2026 launch that pricing was expected in summer 2026, and nothing was listed on newcore.com at research time, so every deal is sales-led.
Security & Compliance
Sources
This page was written from 6 sources, 4 on domains other than newcore.com.
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
Rein Security
Runtime security for enterprise AI agents, deployed as a sidecar inside your own cloud
SAS AI Navigator
SaaS AI governance inventory for models, agents and use cases, sold through Microsoft Marketplace
Armadin
Autonomous offensive security: AI agent swarms that chain your weak spots into proven attack paths before an attacker does
DeepKeep
AI security platform covering red teaming, an AI firewall, agent attack-surface scanning and runtime controls for coding agents