Act Security

Cybersecurity Dual-Use Technology Priority Signal Founded 2025

Last updated: Jul 31, 2026

Act Security is a Tel Aviv cloud-security startup building an action-centric platform that reduces excessive access and attack paths across cloud infrastructure. Its product combines contextual access analysis, guided hardening campaigns, simulation, and cloud-native enforcement for human, workload, network, data, and AI-agent access.

Visit Website

Company Overview

Act Security is positioning its product as a shift from finding cloud-security problems to eliminating the access conditions that make them exploitable. The platform maps cloud boundaries, models reachability, and compares intended, observed, and configured access. It brings identity, network, and AI access into a unified model, then uses that model to identify excessive permissions, unintended paths, cross-environment movement, and other forms of access sprawl. The public product description emphasizes six boundary types: external, human identity, environment, application, AI, and data. This is a more specific proposition than generic AI-assisted alert triage: the intended control point is the infrastructure access layer where a policy change can remove a class of reachable attack paths.

The operational workflow is also concrete. Act describes guided hardening campaigns built around guardrails and ring-fencing, simulation of proposed changes against historical access data, human review, and delivery through existing cloud-native controls and Infrastructure-as-Code such as Terraform or CloudFormation. The no-agent, native-enforcement posture could reduce deployment and maintenance friction for organizations that already manage cloud policy through code. It also creates a useful diligence test: the product must accurately distinguish necessary access from dormant or dangerous access, preserve legitimate business flows, and produce changes that security and platform teams can review and roll back. A platform that merely generates another risk list would not earn durable differentiation; a platform that safely reduces blast radius at scale could become a control plane for cloud least privilege.

The initial customer context is enterprise security, cloud infrastructure, and organizations adopting AI workloads. The company’s public site displays named CISO testimonials from organizations including AlphaSense, Armis, Benchling, Hibob, Klaviyo, Papaya, and WestCap, which are useful commercial traction signals but are not, by themselves, proof of paid deployments, retention, or quantified risk reduction. Act also states that its controls can support NIST 800-53, PCI DSS, HIPAA, and related boundary requirements, and its site links to AWS and Azure Marketplace listings. These claims should be validated through customer references, product documentation, marketplace status, and independent assurance evidence. The market remains highly competitive: CNAPP, cloud security posture management, identity governance, attack-path management, and cloud infrastructure entitlement management vendors increasingly overlap. Act will need to show that its unified access model and policy-enforcement workflow produce better outcomes than buying adjacent features from a broad platform.

The company has a potentially strong team signal. Its founders previously built Medigate, a healthcare-security company acquired by Claroty, and the current leadership page identifies Jonathan Langer, Stephan Goldberg, Itay Kirshenbaum, and Ilai Fallach as co-founders. Public reporting says Act raised a $20M seed and a $40M Series A, bringing disclosed funding to $60M, only months after formation. That financing and prior operating history support an early but well-capitalized commercialization profile; they do not establish product-market fit. The next milestones to test are repeatable enterprise sales, expansion beyond founder-led references, deployment time, policy-change acceptance rates, measurable reduction in reachable paths, renewal and expansion behavior, and the ability to support large multi-cloud environments without creating operational outages.

The dual-use case is credible but bounded. The same reduction of standing privilege, lateral movement, data exfiltration routes, and AI-agent reachability can improve resilience for commercial enterprises, critical infrastructure operators, public-sector systems, and defense contractors. In national-security settings, the strongest relevance would be as a hardening and blast-radius-reduction layer for cloud-hosted mission support, logistics, intelligence, or enterprise systems, subject to authorization, sovereignty, disconnected-environment, and procurement requirements. There is no sufficient public evidence here to claim defense deployment or government contracts. Strategic value therefore rests on whether Act can make preventive access control auditable, interoperable, and safe in high-consequence environments while competing against large security-platform incumbents.

Dual-Use Assessment

Military & Commercial Applications

Act's core capability is substantive dual-use infrastructure security: reducing excessive permissions and reachable attack paths can protect commercial clouds as well as government, critical-infrastructure, and defense-contractor environments. The national-security case is conditional because public materials do not establish defense customers, classified deployment, or government contracts; diligence should test cloud sovereignty, auditability, disconnected-operation options, and procurement readiness.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

Act Security is a credible strategic-priority signal for a dual-use cybersecurity database because it targets a persistent cloud problem at the access and blast-radius layer, with a specific workflow for modeling, simulating, and enforcing changes. The founders' prior Medigate experience and the disclosed $20M seed plus $40M Series A improve the team and financing case. This is not an investment recommendation: the key unresolved questions are paid-customer depth, renewal, measurable attack-path reduction, false-positive and outage rates, deployment friction, and differentiation against CNAPP and identity-security platforms that can bundle adjacent controls.

Strategic Value to U.S.-Israel Alliance

Act could improve the resilience of allied cloud environments by converting least-privilege intent into continuously tested, enforceable boundaries for people, workloads, data, and AI agents. Its use of existing cloud-native controls and Infrastructure-as-Code may be relevant where operators require reviewable changes and an auditable chain from risk discovery to enforcement. The value is strongest for critical infrastructure, defense suppliers, and public-sector systems with complex permissions and high blast-radius sensitivity, but remains conditional on sovereignty, compliance evidence, operational safety, and deployment in the environments those buyers actually use.

Key Technologies

  • Contextual cloud access graphing
  • Intended, observed, and configured access analysis
  • Identity, network, workload, and AI-agent reachability modeling
  • Least-privilege guardrails and application ring-fencing
  • Historical-access policy simulation
  • Infrastructure-as-Code and cloud-native policy enforcement
  • Continuous access-drift and boundary validation

Use Cases & Applications

  • Removing excessive human and workload permissions
  • Blocking unintended inbound access and cross-environment lateral movement
  • Ring-fencing crown-jewel applications and sensitive data
  • Constraining cloud AI agents to defined infrastructure and data boundaries
  • Simulating and shipping Terraform or CloudFormation hardening changes
  • Reducing access sprawl and cloud blast radius in regulated enterprises
  • Hardening cloud systems operated by public-sector and defense contractors
  • Supporting continuous evidence for least-privilege and boundary controls

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.

This record lists 6 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Investor Lens

What this entry is

Private startup

Why it may matter

Act Security may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.

How an independent investor should read this

Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.

Evidence to verify

  • Verify current status
  • Verify traction
  • Verify cap table/funding
  • Verify technical claims
  • Verify regulatory/export-control issues
  • Verify customer concentration

Main investor questions

  • Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
  • What customer, revenue, product, and technical evidence supports the company story?
  • What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
  • Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
  • What evidence would change the thesis or show that the profile is stale?

What not to infer

  • Inclusion does not imply endorsement.
  • Inclusion does not imply allocation availability or current fundraising.
  • Scores do not indicate investment suitability or expected returns.
  • Strategic importance does not automatically imply venture return potential.

Diligence questions

  • What evidence verifies Act Security's current customer traction, deployment status, and revenue concentration?
  • Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
  • Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
  • How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
  • What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.

Need a diligence readout?

Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.