axios.com web signal

Act Security exits stealth with $60M to shrink cloud access

TL;DR

  • Act Security emerged from stealth with $60M total: a $20M seed co-led by Team8 and Bessemer, plus a $40M Series A led by Notable Capital.
  • The company was founded in 2025 by the Medigate team, whose prior startup sold to Claroty for $400 million in January 2022.
  • The pitch is to remove access conditions that turn cloud vulnerabilities into breaches, and to enforce boundaries around AI agent workloads.

A quiet detail in the round that just took Tel Aviv's Act Security out of stealth is worth pausing on. The company raised $60 million total across two tranches, a previously undisclosed $20 million seed co-led by Team8 and Bessemer Venture Partners, and a fresh $40 million Series A led by Notable Capital, as Axios reports. That is a lot of money for a company founded in 2025, and it says as much about who is writing the checks as about the pitch itself.

The founders are the Medigate team, Jonathan Langer, Itay Kirshenbaum, Stephan Goldberg and Ilai Fallach, whose previous company sold to Claroty for $400 million in January 2022. Their new bet, as SecurityWeek describes it, is that patching cannot keep up with the rate at which AI is now finding vulnerabilities in cloud environments. So instead of chasing findings, Act tries to remove the access conditions that turn a vulnerability into a breach in the first place. Langer's framing, that the industry cannot patch its way out of everything, is the clean version of a much older CISO complaint.

The specifically-2026 angle is agentic identity. AI agents, Langer told SiliconANGLE, are inheriting the same old human permissions and running around the clock at machine speed with none of the judgment a person would apply. Act says it enforces boundaries around what both people and agents can do in cloud infrastructure, maps to NIST 800-53, PCI DSS and HIPAA, and integrates with CI/CD to block violations before production. Team8 managing partner Liran Grinberg went further, calling it the first platform that actually removes cloud risk rather than mapping it, which is investor talk and worth reading as such.

Take the marketing as marketing. The reporting does not give you customer counts, ARR, pricing, or a clear line on where Act sits against incumbent CIEM, PAM and CNAPP vendors already selling non-human identity governance. Nor does it explain how a boundary-enforcement layer avoids becoming the thing that breaks a CI/CD pipeline the first time it misfires.

For enterprises standing up agent programs this year, the useful move is to press current IAM and cloud security vendors on what boundary enforcement for non-human identities actually means in their roadmap, because a $60 million raise from this syndicate says the smart money believes that category is about to become crowded.