Surf AI
by Surf AI
Agentic security operations that close the exposure and hygiene backlog instead of ticketing it
Surf AI is an agentic security operations platform that builds a context graph across identity, cloud, security, SaaS, HR and IT systems, then uses AI agents to prioritise exposures by real business impact, trace each one to its actual owner, and drive remediation through to closure. It targets the security hygiene backlog teams know about but never have capacity to clear.
Surf AI is an agentic security operations platform aimed at the unglamorous half of enterprise security: the exposure and hygiene backlog that teams know about but never have the capacity to close. It ingests signals from identity providers, cloud services, security monitoring tools, SaaS applications, HR systems and IT service management, and builds a context graph that connects assets, users, roles, permissions, owners and dependencies. Specialised AI agents then work that graph, identifying exposure conditions, correlating them with operational and business context so prioritisation reflects real impact rather than a raw severity score, tracing each issue to the person or team who actually owns the affected system, and driving goal-oriented remediation workflows through to closure rather than opening a ticket that bounces between queues. Representative work includes disabling dormant and orphaned accounts, reclaiming unused software licences, resolving certificate management gaps, correcting configuration drift, adjusting over-broad access, and cleaning up CMDB and network hardware inventory records. Humans are explicitly kept in the loop: agents propose and execute against defined policies while approvals and oversight remain with the security team, and every action is auditable. The company was founded in 2024 by a team of Israeli cybersecurity veterans, Yair Grindlinger as CEO with Elad Horn, Roie Cohen Duwek, Avner Gideoni and Brenton Gumucio, and is headquartered in New York. It launched publicly in March 2026 with $57 million in combined seed and Series A funding led by Accel, with participation from Cyberstarts and Boldstart Ventures, and says it is already deployed at global and Fortune 500 organisations, with Cushman & Wakefield CISO Erik Hart quoted on its site.
The CISO or head of security operations at a large enterprise with a years-old exposure backlog, dormant accounts and CMDB drift that every audit flags and no team has ever had the headcount to actually clear.
Exposures get prioritised by real business impact, routed to the human who actually owns the system, and remediated to closure by agents rather than added to a ticket queue.
At a Glance
- Category
- Governance & Security
- Pricing
- Contact for pricing
- Target Market
- CISOs, CIOs, Heads of Security Operations, IT Operations Leaders, GRC Teams, Enterprise Architects
- Deployment
- Cloud-first
- Founded
- 2024
- Headquarters
- New York, United States
- Customers
- No public customer count; the vendor cites global and Fortune 500 deployments and quotes Cushman & Wakefield CISO Erik Hart
Key Features
- ✓Cross-system context graph
Connects assets, users, roles, permissions, owners and dependencies from identity, cloud, security, SaaS, HR and IT sources.
- ✓Business-impact prioritisation
Ranks exposures by what they actually threaten in context rather than by raw severity score, so remediation effort follows real risk.
- ✓Ownership tracing
Resolves each exposure to the person or team that genuinely owns the system, which is usually the bottleneck in hygiene work.
- ✓Goal-oriented remediation agents
Specialised AI agents pursue a remediation outcome to completion, preserving context as work progresses instead of handing off a ticket.
- ✓Zero-ticket resolution model
Closes exposures through automated workflows rather than routing them into a service desk queue where they age indefinitely.
- ✓Policy-bound human oversight
Agents act only within defined policies, with approvals retained by the security team and every action logged and auditable.
- ✓Continuous exposure discovery
Monitors the estate continuously as assets, accounts and permissions change, rather than producing a point-in-time assessment.
Capabilities
Use Cases
- •Clearing dormant and orphaned accounts
Correlate identity, HR and SaaS data to find accounts belonging to departed staff or defunct services, then disable them safely at scale.
- •Zero-day exposure response
Query the context graph to determine which assets are genuinely affected, who owns them, and drive patching or mitigation to closure.
- •CMDB and inventory hygiene
Reconcile network hardware and configuration records against observed reality so downstream audits and incident response stop working from stale data.
- •Reclaiming unused software licences
Identify assigned but unused SaaS seats across the estate and drive reclamation, turning a hygiene programme into a measurable cost saving.
- •Continuous identity governance enforcement
Detect over-broad or drifted access as roles change and adjust permissions against policy without waiting for a quarterly access review.
Ideal For
Best For
- ✓Clearing a long-standing security hygiene backlog that repeatedly fails audit but never gets staffed
- ✓Identity governance work such as disabling dormant, orphaned and over-privileged accounts across cloud and SaaS
- ✓Establishing ownership for exposures in environments where the CMDB is stale and nobody knows who runs a given system
- ✓Zero-day response, where the question is which assets are actually affected and who can act on them right now
- ✓Reclaiming unused SaaS licences and idle cloud resources as a measurable cost outcome alongside the risk reduction
Not Ideal For
- ✗Small or mid-sized organisations with a simple, well-inventoried estate, where the context graph has little fragmentation to resolve and a spreadsheet already answers the ownership question
- ✗Teams looking for detection and response. This is exposure management and hygiene, not an EDR, SIEM or SOC alerting replacement
- ✗Buyers who want fully autonomous remediation. The vendor is explicit that humans remain responsible for oversight and approvals, so the headcount saving is bounded
- ✗Organisations that cannot grant broad read access across identity, cloud, HR and IT systems, since the context graph depends on exactly that breadth of integration
Deployment
Market & Ratings
No public customer count; the vendor cites global and Fortune 500 deployments and quotes Cushman & Wakefield CISO Erik Hart
Market Analysis
Pros
- ✓Targets a genuinely unsolved problem: exposure and hygiene backlogs are universally acknowledged, chronically unstaffed, and rarely addressed by tools that only produce more findings
- ✓Ownership tracing across HR, IT service management and identity data attacks the actual bottleneck, which is not knowing who can fix a given system
- ✓Human oversight and auditability are designed in rather than promised later, which is what security leadership will demand before letting agents touch production access
- ✓Well capitalised for its stage at $57 million led by Accel with Cyberstarts and Boldstart, reducing the near-term vendor-viability risk
Cons
- ✗No independent buyer evidence exists: no G2, Capterra, TrustRadius or PeerSpot listing was found, and no substantive Hacker News or Reddit discussion of the platform surfaced
- ✗The single public reference is one quoted CISO. There is no published customer count, no case study with measured outcomes and no disclosed deployment size
- ✗Human approval remains required by design, so the promised capacity relief is real but bounded, and buyers modelling headcount savings should discount accordingly
- ✗No published pricing, no metering unit and no disclosed SOC 2, ISO 27001 or other compliance certifications, all of which a security buyer will require in procurement
- ✗Value depends on granting broad read access across identity, cloud, HR and IT systems, which is itself a significant risk-review and integration burden before any benefit is realised
- ✗Exposure management is a crowded and consolidating category where Wiz, Tenable, Axonius and identity-governance vendors are all adding agentic remediation to products customers already own
Pricing
Enterprise
Contact for pricing
- ✓Cross-system context graph
- ✓Continuous exposure discovery and prioritisation
- ✓Ownership tracing
- ✓Goal-oriented remediation agents
- ✓Policy-bound approvals and audit trail
No pricing is published anywhere on the site, which routes all enquiries through a demo request, and no metering unit such as per-asset, per-identity or per-integration has been disclosed publicly. Treat this as an enterprise sales motion with negotiated terms and expect the evaluation to include integration scoping across identity, cloud, HR and IT systems, since the platform's value depends entirely on how much of the estate it can read.
Security & Compliance
Sources
This page was written from 6 sources, 5 on domains other than surf.ai.
- 1.securityweek.com — surf ai raises 57 million for agentic security operations pl
- 2.siliconangle.com — surf ai launches agentic security operations platform 57m fu
- 3.businesswire.com — Surf AI Launches with $57 Million in Funding to Help Enterpr
- 4.fintech.global — surf ai raises 57m to tackle enterprise security ops
- 5.thesaasnews.com — surf ai raises 57 million in funding
- 6.surf.ai — surf.aivendor
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
Actualyze AI
Enterprise AI control plane that governs, secures and cost-optimises every model request
Onyx Security
The secure AI control plane — inspect, govern and block what your agents do
Torq SOC Brain
A self-learning layer that trains your SOC's own AI on your analysts' past verdicts
Norm Ai
Regulatory AI agents that turn written rules into executable compliance checks