Dossier · Acquired asset · 1 independent source
Fabrix Security
Last updated: Jul 31, 2026
Fabrix Security developed AI-native identity-security software for reasoning about and governing access by human, machine, and AI-agent identities. Silverfort announced its acquisition of Fabrix on April 28, 2026, making Fabrix an acquired technology and team rather than an independent startup.
Visit WebsiteCompany Overview
Fabrix Security built an AI-native identity-security layer around the practical problem of deciding whether an identity should receive access, and what level of access is justified. Its public product materials describe AI agents for access reviews, access requests, identity lifecycle management, and least-privilege enforcement. The system is intended to assemble identity, permission, activity, organizational, and policy context into an identity knowledge graph, then produce explainable recommendations or actions. The target population includes human users as well as non-human identities such as service accounts, API keys, bots, and AI agents, whose volume and speed make periodic manual review increasingly inadequate.
The product thesis is complementary to existing IAM rather than a wholesale replacement for every directory or application. Fabrix describes read-only, agentless connectors for cloud, SaaS, on-premises, and disconnected environments, followed by policy-driven actions through existing IAM workflows. Its named agents cover distinct operational jobs: Auditor for access reviews, Keeper for access requests, Operator for joiner-mover-leaver lifecycle work, and Fixer for reducing privilege creep. The intended differentiation is context-aware, reasoning-based decisioning that can be configured in natural language and kept auditable, with a human-in-the-loop option for higher-consequence actions. In practice, the defensibility of this architecture depends on connector breadth, identity-data quality, latency, false-positive rates, and the quality of its controls around autonomous changes.
The commercial market is identity security, identity governance and administration, non-human identity management, and emerging governance for agentic software. Buyers are likely to be enterprise IAM, security, compliance, and infrastructure teams dealing with fragmented entitlement data and costly access-review processes. The category is attractive because identity misuse and privilege accumulation create risk across cloud, SaaS, legacy, and operational environments, but it is crowded. Microsoft Entra, Okta, CyberArk, SailPoint, Delinea, Saviynt, Silverfort, and specialist identity-security vendors can compete through installed data, enforcement points, workflow integration, or adjacent AI features. Fabrix publicly announced $8 million in seed funding in September 2025, but public evidence in the available materials does not establish revenue, customer count, production scale, or independently verified outcome metrics.
The most important commercialization signal is strategic rather than standalone traction: Silverfort announced on April 28, 2026 that it acquired Fabrix and plans to combine Fabrix's AI-driven authorization and identity knowledge graph with Silverfort's Runtime Access Protection. Silverfort stated that the joint capabilities were expected to become available in the second half of 2026 and that it intended to bring them to its 1,000-plus customers. This provides credible evidence that a larger identity-security platform valued Fabrix's team and technology, but it is not evidence that Fabrix remains an independent strategically relevant company or that the combined products have already achieved the stated deployment outcomes.
Fabrix has credible defensive and national-security adjacency because runtime identity decisioning can reduce privilege escalation, insider-threat exposure, lateral movement, and unauthorized actions by machines or AI agents in critical infrastructure and government environments. The relevance is strongest where hybrid legacy systems, sensitive workloads, and limited security staffing make continuous least-privilege enforcement difficult. It remains a defensive cybersecurity capability, not an offensive military technology, and the record should not imply government contracts or defense deployments that have not been publicly established. Following the acquisition, the strategic question is integration: whether Fabrix's context and AI decisioning can operate safely at Silverfort's enforcement points with explainability, deterministic guardrails, and acceptable latency.
Dual-Use Assessment
Fabrix's identity decisioning and runtime access-control technology has substantive commercial and security-sector applicability. In enterprise environments it can govern human, machine, and AI-agent access, reduce privilege creep, and automate identity workflows; in government, defense, and critical-infrastructure environments the same controls can support least privilege, insider-threat reduction, and resilience across hybrid legacy systems. The capability is defensive and operational rather than an offensive weapons technology, and no public evidence here confirms defense customers or government deployments.
Strategic Fit Assessment
Fabrix had a credible seed-stage identity-security thesis and raised $8 million before Silverfort announced its acquisition in April 2026. The acquisition is a positive validation signal for the technology and team, but it means Fabrix is no longer an independent startup for this database and there is no standalone equity or financing opportunity to assess. Diligence should therefore focus on the integration outcome, production adoption inside Silverfort, technical performance of runtime decisioning, and whether the acquired capabilities create durable product differentiation rather than treating the legacy strategically relevant flag as an investment recommendation.
Strategic Value to U.S.-Israel Alliance
Fabrix is strategically valuable as an acquired identity-security capability that can extend Silverfort's runtime enforcement with AI-based context and authorization decisioning. The combined proposition is relevant to enterprises and to public-sector or critical-infrastructure operators that must govern fast-moving machine and AI identities across legacy and cloud systems. Its value rests on safe integration into existing enforcement paths, reliable identity data, low-latency decisions, human override and auditability, and measurable reduction in excessive access. The acquisition also reduces Fabrix's standalone strategic independence, so future relevance should be evaluated through Silverfort's product delivery and customer adoption.
Key Technologies
- Identity knowledge graph linking identities, entitlements, activity, organizational context, and intent
- AI-driven authorization and reasoning-based access decisions
- Agentic workflows for access reviews, access requests, and joiner-mover-leaver lifecycle operations
- Continuous least-privilege and privilege-creep analysis for human and non-human identities
- Read-only, agentless connectors spanning cloud, SaaS, on-premises, and disconnected systems
- Policy-constrained runtime enforcement with explainable recommendations and audit trails
Use Cases & Applications
- Prioritizing and completing enterprise user access reviews with evidence from permissions and activity
- Evaluating access requests using identity, role, policy, historical, and business context
- Automating joiner, mover, and leaver provisioning and deprovisioning checks
- Finding orphaned accounts, unused entitlements, and excessive privileges across hybrid environments
- Applying just-in-time and just-enough access to service accounts, API keys, and other non-human identities
- Governing AI-agent actions and delegated access through context-aware policy decisions
- Reducing insider-threat and lateral-movement exposure in regulated or critical-infrastructure environments
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.
This record lists 6 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- fabrix.security Public source used for profile verification.
- fabrix.security Public source used for profile verification.
- fabrix.security Public source used for profile verification.
- fabrix.security Public source used for profile verification.
- silverfort.com Public source used for profile verification.
- LinkedIn company page Public source used for profile verification.
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.