Dossier · Private startup · 0 independent sources
Linx Security
Last updated: Jul 31, 2026
Linx Security is a New York-based identity security and governance startup building an AI-native platform for mapping, monitoring, governing, and remediating access risk across human, non-human, and agentic identities.
Visit WebsiteCompany Overview
Linx Security builds an identity security and governance platform around an identity graph that connects people, accounts, entitlements, applications, infrastructure, machines, and AI agents. Its public product materials describe agentless data ingestion from applications, directories, and other systems; graph-based modeling of identity relationships; risk analysis across identities and access; lifecycle automation; and policy-controlled remediation. The company has also launched Autopilot, an autonomous identity-security agent that is intended to continuously monitor changes, evaluate risk in context, remediate high-confidence issues, and escalate ambiguous or high-impact actions to a human. That architecture addresses a specific weakness in legacy identity governance: periodic reviews and ticket queues can leave privilege drift in place long after it appears.
The immediate commercial buyer is likely a combination of identity and access management, security, and IT operations teams at organizations with complex SaaS, cloud, directory, and application estates. Linx positions the platform as a way to unify security, governance, and access management rather than forcing those teams to reconcile separate views of the same identity lifecycle. The scope includes joiner-mover-leaver workflows, access reviews, excessive or dormant privileges, just-in-time access, and governance of service accounts, API keys, bots, and AI agents. Its website emphasizes rapid deployment and day-one value, while the product pages emphasize continuous monitoring and auditable action. These are useful commercial differentiators if they translate into shorter implementations and measurable reductions in manual identity work.
There are credible public traction signals, but they remain mostly company-reported and should be diligenced rather than treated as independently verified operating metrics. Linx announced a $50 million Series B led by Insight Partners on March 31, 2026, with continued participation from Cyberstarts and Index Ventures, and said total funding reached $83 million. The same announcement described a 100-person company, multimillion-dollar contracts with banks, healthcare companies, and Fortune 500 firms, and governance of millions of identities. The company also reports an emerging product cycle around its AI assistant, MCP server, and Autopilot agent. Those signals suggest enterprise demand and meaningful capital support, but the database does not have public evidence for ARR, retention, gross margin, deployment counts, or the proportion of revenue attributable to autonomous features.
Competition is substantial. SailPoint and Saviynt bring established identity governance suites; Microsoft Entra ID Governance and One Identity benefit from broader platform relationships; and Veza, ConductorOne, Silverfort, and other identity-security specialists compete for visibility, posture management, and least-privilege budgets. Linx’s proposed edge is workflow integration: an identity graph and AI agents that can move from discovery and contextual risk analysis to governed action. The core question is whether this produces safer and faster outcomes than incumbent governance workflows, or whether larger vendors can bundle comparable capabilities before Linx achieves durable distribution. Integrations, policy modeling, permissions accuracy, and customer trust will matter more than the AI label alone.
The defense and national-security adjacency is substantive but indirect. Identity compromise is a recurring route into enterprises, suppliers, cloud estates, and critical infrastructure, so continuous privilege analysis and rapid, auditable containment can support cyber resilience in defense-adjacent environments. The same product could help reduce blast radius for contractors, administrators, service identities, and automated workloads in sensitive networks. There is no public evidence in the reviewed sources of defense contracts, classified deployment, or a government-specific product, so the dual-use case should be understood as security infrastructure relevance rather than claimed defense adoption. Strategically, Linx is worth tracking as a control-plane candidate in the expanding identity-security market, with diligence centered on autonomy safety, integration depth, reference customers, and repeatable enterprise economics.
Dual-Use Assessment
Identity governance, access-risk analysis, and controlled remediation have direct commercial and security-infrastructure uses. The same capabilities can reduce privilege abuse and improve auditability in defense suppliers, critical infrastructure, and other sensitive environments, but public sources reviewed do not establish defense contracts or government deployment; the thesis is adjacency and resilience value, not demonstrated military adoption.
Strategic Fit Assessment
Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.
Linx is a credible strategic-priority signal for a dual-use technology database because identity is a foundational security control, the company has disclosed a substantial Series B and enterprise traction, and its platform targets the growing problem of non-human and agentic access. The case is not an investment recommendation: public evidence is still thin on recurring revenue, retention, margins, deployment scale, and independent customer validation. Diligence should test whether autonomous remediation is safe and explainable, whether integrations create durable switching costs, and whether the company can defend its position as identity incumbents add AI and posture features.
Strategic Value to U.S.-Israel Alliance
Linx could become strategically important as an identity control layer for enterprises whose attack surface spans employees, contractors, workloads, service accounts, and AI agents. Continuous visibility and policy-bounded action can improve resilience by shortening the time between privilege change and correction while preserving an audit trail. The value is highest in regulated or interconnected environments, but it depends on accurate identity correlation, reliable connectors, conservative automation, and the ability to operate across legacy systems without creating access outages.
Key Technologies
- Graph-based identity fabric linking identities, entitlements, and resources
- Agentless identity-data ingestion across directories, SaaS, cloud, and enterprise systems
- Identity security posture management and contextual access-risk analytics
- AI agents for identity investigation, governance, and remediation
- Policy-scoped autonomous remediation with human escalation and audit logs
- Lifecycle automation, access reviews, and just-in-time access
- Governance for machine, service, API, and AI-agent identities
Use Cases & Applications
- Mapping hidden relationships between people, accounts, applications, resources, and entitlements
- Detecting privilege drift, dormant accounts, toxic combinations, and excessive access
- Automating joiner-mover-leaver and role-change workflows across heterogeneous systems
- Running continuous access reviews and producing auditable governance evidence
- Enforcing just-in-time or least-privilege access for sensitive applications and infrastructure
- Monitoring and governing service accounts, API keys, bots, and AI agents
- Reducing identity attack surface and containing access risk in regulated enterprises and critical suppliers
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.
This record lists 6 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- linx.security Public source used for profile verification.
- linx.security Public source used for profile verification.
- linx.security Public source used for profile verification.
- linx.security Public source used for profile verification.
- linx.security Public source used for profile verification.
- LinkedIn company page Public source used for profile verification.
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.