Act Security has emerged from stealth with $60 million in funding and a cloud security platform designed to reduce the access paths that allow attackers to move through corporate infrastructure. The company raised a $20 million seed round led by Team8 and Bessemer Venture Partners, with participation from Hetz Ventures and Claltech. It subsequently raised a $40 million Series A led by Notable Capital, with participation from Startpoint Capital and SVCI.
Act was founded in 2025 by members of the team behind medical-device security company Medigate, which Claroty acquired for approximately $400 million. The new company is focused on access architecture across cloud environments rather than primarily identifying individual vulnerabilities or configuration problems.
Cloud systems frequently accumulate permissions as employees, applications and workloads change. Accounts may retain access that is no longer necessary, creating potential pathways that an attacker could exploit after compromising one identity or workload.
Act analyzes identity, network and AI access together and establishes deterministic boundaries controlling what people, workloads and autonomous agents can reach. The platform uses cloud-native and conventional security controls already available within a customer’s environment.
Its capabilities are designed to eliminate exposed pathways, limit AI agents to specifically approved resources and continuously remove unused permissions. Act also integrates with continuous integration and deployment pipelines to identify access violations before new applications or infrastructure enter production.
The platform maps its controls to compliance requirements including NIST 800-53, the Payment Card Industry Data Security Standard and the Health Insurance Portability and Accountability Act. This is intended to provide an ongoing record showing how access boundaries are enforced.
Act is positioning its system as an alternative to security products that present teams with large lists of vulnerabilities without addressing whether those weaknesses are actually reachable through an available access path.
KEY QUOTES:
“Based on what we are seeing from our customers, close to 97% of cloud access sits dormant and unused, and now AI agents are inheriting those same old human permissions, running around the clock, at machine speed, with none of the judgment a person would apply.”
“In parallel, Mythos confirmed what much of the cyber world had started to realize, that we can’t patch our way out of everything, no matter how hard we try. Visibility tools surface thousands of findings and leave teams triaging symptoms one by one, while the root cause, the access architecture, goes unaddressed.”
“Instead of chasing findings, we remove the conditions that turn risk into a breach, making the cloud structurally secure before attacks unfold.”
Jonathan Langer, Co-Founder and CEO of Act Security
“We backed Act because of the caliber of the founding team who saw the access problem before the rest of the market did. Cloud security has spent a decade telling organizations where their risk is.”
“Act is the first platform that actually removes it, and in an era where AI exploits exposure in minutes rather than months, that’s the new baseline. We believe this is one of the largest opportunities in cybersecurity today.”
Liran Grinberg, Co-Founder and Managing Partner at Team8