Astrix Security

Cybersecurity Acquired asset Dual-Use Technology Founded 2021

Last updated: Jul 31, 2026

Astrix Security built a platform for discovering, governing, and protecting non-human identities and AI-agent access, including API keys, service accounts, OAuth applications, secrets, and MCP servers. Cisco completed its acquisition of Astrix in June 2026 and is integrating the technology into Cisco Security.

Visit Website

Company Overview

Astrix Security addressed the identity layer created by software rather than people. Its platform correlated API keys, service accounts, OAuth grants, secrets, IAM roles, SSH keys, webhooks, and other machine-to-machine credentials across SaaS, cloud, on-premises, databases, vaults, CI/CD systems, and AI platforms. The product's central value proposition was continuous discovery with ownership and business context: security teams could see what an application or agent could reach, which permissions and tokens enabled that access, who created it, and whether the path was stale, excessive, anomalous, or hidden from normal identity-governance review. Astrix later framed this as a Discover-Secure-Deploy model for AI agents, MCP servers, and other non-human identities.

The technology matters because automation has outgrown traditional human-centric IAM processes. A service account or OAuth integration can remain active after its owner changes jobs, inherit broad permissions, or become a transitive path into sensitive systems. AI agents intensify the problem: an agent can combine a model, tools, credentials, and delegated authority, creating an access subject whose behavior and scope may change faster than a periodic access review. Astrix's identity graph, risk prioritization, remediation workflows, short-lived credentials, just-in-time access, and policy-at-provisioning approach are relevant controls for reducing privilege, improving accountability, and limiting blast radius. The company also described agentic threat detection and response for compromised credentials or out-of-scope actions, although the depth and operational performance of those capabilities require buyer-side validation.

The commercial market sits between identity governance, privileged access management, secrets management, SaaS security, cloud security, and emerging AI-agent security. Astrix's purpose-built focus gave it a clear problem narrative, but it also exposed the company to well-capitalized substitutes. CyberArk and Akeyless can control or broker secrets and privileged access; SailPoint and Microsoft Entra can extend governance and identity context; Wiz and other cloud-security platforms can identify cloud entitlement risk; and SSPM or integration-security products can cover subsets of SaaS connections. Astrix therefore needed to demonstrate that its cross-environment inventory, entitlement graph, connector coverage, and safe remediation were materially more useful than the combination of tools customers already owned. Public company material cited Fortune 1,000 adoption and named enterprise customer examples, but those statements are company-reported and should not be treated as independently verified revenue, retention, or deployment-scale evidence.

The company raised a reported $45 million Series B in 2024 and was founded in 2021. Cisco announced its intent to acquire Astrix on May 4, 2026 and later stated that the acquisition completed on June 29, 2026. Cisco plans to integrate Astrix capabilities into Cisco Identity Intelligence and extend them through Secure Access, Duo, and Splunk-related security workflows. That gives the technology a stronger distribution and telemetry context than Astrix had as a standalone vendor, while changing the diligence question from venture-scale independence to integration quality, customer continuity, product roadmap ownership, and team retention. The public record confirms the acquisition, but not the purchase price or the full commercial terms.

The dual-use case is credible but indirect. Defense, intelligence, critical-infrastructure, and defense-industrial environments depend on automated workflows, APIs, privileged service accounts, partner integrations, and increasingly AI-assisted systems. Discovery and least-privilege controls for those identities can reduce credential abuse, lateral movement, and supply-chain exposure. However, no public evidence reviewed here establishes a specific defense contract, deployment, accreditation, or classified-environment operation by Astrix. Its strategic relevance should therefore be based on the transferability of the technology and Cisco's enterprise security distribution, with deployment in restricted or disconnected environments treated as an open diligence question rather than an established capability.

Dual-Use Assessment

Military & Commercial Applications

Astrix's core controls for API keys, service accounts, OAuth tokens, secrets, AI agents, and machine-to-machine access have substantive applicability in defense, intelligence, critical-infrastructure, and defense-industrial environments that depend on automated workflows. The strategic case is technology transferability rather than documented defense contracting: public sources reviewed do not establish a specific military customer, accreditation, or deployment in a restricted environment.

Strategic Fit Assessment

Astrix addressed a significant and expanding security problem and its reported Series B, product scope, and Cisco acquisition provide meaningful validation of strategic relevance. It is no longer an independent startup opportunity: Cisco completed the acquisition in June 2026, so the record should not function as a current standalone investment signal. Relevant diligence now concerns technology integration, customer retention, roadmap preservation, and whether Cisco can convert Astrix's specialist NHI capabilities into durable platform value.

Strategic Value to U.S.-Israel Alliance

Astrix is strategically valuable as an acquired technology asset that gives Cisco a focused control plane for AI-agent and non-human identity risk. Its discovery and entitlement context can strengthen Cisco Identity Intelligence and connect identity, access, network, application, and behavioral telemetry. The capability is relevant to secure automation in commercial, critical-infrastructure, and defense-adjacent settings, but public evidence does not prove deployment in restricted or classified environments.

Key Technologies

  • Continuous discovery of non-human identities across SaaS, cloud, on-premises, CI/CD, vault, and AI environments
  • Identity and entitlement graphing for permissions, owners, tokens, resources, and transitive access
  • OAuth application and third-party integration governance
  • Risk prioritization and behavioral detection for anomalous machine or agent activity
  • Credential lifecycle, secret-management, revocation, and remediation workflows
  • Short-lived, just-in-time, precisely scoped access for AI agents and automation
  • MCP-server and agent discovery with policy and audit controls

Use Cases & Applications

  • Inventory and governance of service accounts, API keys, OAuth apps, IAM roles, and other machine credentials
  • Detection and remediation of stale, orphaned, over-privileged, or shadow integrations
  • Identity-first security for AI agents and MCP servers accessing enterprise data and tools
  • Incident response through token blast-radius analysis and rapid credential revocation
  • Least-privilege enforcement across cloud, SaaS, internal systems, and CI/CD pipelines
  • Third-party and defense-industrial supply-chain access hygiene
  • Auditability and policy control for automated workflows in regulated environments

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.

This record lists 8 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Investor Lens

What this entry is

Acquired asset

Why it may matter

Astrix Security may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.

How an independent investor should read this

Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.

Evidence to verify

  • Verify current status
  • Verify technical claims
  • Verify regulatory/export-control issues

Main investor questions

  • Is this entry a benchmark, buyer, ecosystem node, acquired asset, or strategic reference rather than a live startup opportunity?
  • What does this reference clarify about buyers, sector structure, public-market context, or strategic demand?
  • Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
  • What evidence would change the thesis or show that the profile is stale?

What not to infer

  • Inclusion does not imply endorsement.
  • Inclusion does not imply allocation availability or current fundraising.
  • Scores do not indicate investment suitability or expected returns.
  • Strategic importance does not automatically imply venture return potential.

Diligence questions

  • What evidence verifies Astrix Security's current customer traction, deployment status, and revenue concentration?
  • Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
  • Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
  • How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
  • Is the company a live venture opportunity, a mature strategic reference, an acquired asset, or primarily a market-mapping entry?

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.

Need a diligence readout?

Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.