Oak
Last updated: Jul 20, 2026
Oak is an Israeli-founded cybersecurity company building an AI-native 'Identity Operating System' — a unified control plane that governs every human, machine, and AI-agent identity across an enterprise, replacing the fragmented stack of legacy identity governance and access tools.
Visit WebsiteCompany Overview
**Product and the concrete problem it solves.** Oak attacks one of the most persistent and consequential failure modes in enterprise security: no organization can reliably answer, at any given moment, the question "who — and what — has access to which systems, and are they actually using it?" Identity has quietly become the dominant attack surface. Compromised credentials, over-provisioned permissions, orphaned accounts, and stale entitlements are among the most common root causes of breaches, and the legacy identity-governance-and-administration (IGA) and identity-and-access-management (IAM) stack was architected for a slower, human-centric, on-premises world. Oak's answer is what it markets as an **AI-native "Identity Operating System"** — a single control plane that consolidates the fragmented tangle of legacy identity tools and continuously governs the full lifecycle of every identity. Crucially, Oak scopes "identity" to include not just employees and contractors but the exploding population of *non-human* identities: service accounts, machines, workloads, and — increasingly — autonomous AI agents that now act inside enterprise systems alongside people. The company's leadership frames the category shift explicitly, drawing the analogy to how CNAPP consolidated the fragmented cloud-security stack a few years earlier.
**Core technology and how it actually works.** Oak's technical thesis is that identity governance should be evidence-based and continuous rather than record-based and periodic. Instead of trusting static entitlement records or waiting for quarterly access-review campaigns, Oak's platform ingests raw operational data across an environment and builds a **live identity graph** that maps each identity's granted permissions against its *actual* usage. An **AI connector framework** is used to reach across on-premises systems, cloud infrastructure, SaaS applications, and custom/home-grown apps, and Oak claims this AI-driven approach lets it build integrations far faster than traditional connector engineering allows — a meaningful practical advantage in the notoriously integration-heavy identity market. On top of the graph, the system makes **real-time, risk-based decisions and remediations**: it can flag and strip unnecessary or unused permissions as they drift, and it reacts to anomalous signals (for example, logins from unusual locations) as risk events rather than waiting for a scheduled review. The design goal is a shift from operations-based governance (tickets, campaigns, manual certifications) to risk-based, always-on governance — and explicitly to extend that governance model to AI agents, which Oak's founders argue legacy tooling was never built to handle.
**Market, customers, and go-to-market.** Oak sells into the large and structurally growing identity-security market, competing for budget with entrenched IGA suites, IAM/identity providers, and the newer wave of machine- and non-human-identity specialists. The timing thesis is that AI agents are about to multiply the number of identities inside every enterprise by an order of magnitude while simultaneously making credential-based attacks easier to execute, forcing a re-platforming of identity governance that incumbents built for the cloud era are poorly positioned to serve. Oak's go-to-market is enterprise-direct and, notably, launched with the product **already generally available and deployed with paying enterprise customers** — it did not emerge from stealth as a concept but as a shipping platform. Management spent the stealth period consulting with more than 100 CISOs and IAM leaders to shape the product, and the company is orienting much of its commercial motion toward the U.S. market, where most of its staff will soon be based; a Black Hat USA 2026 showcase (Booth 4203) signals an aggressive enterprise-security-buyer launch. Specific customer names have not been disclosed, which is normal at this stage but limits independent verification of traction.
**Traction, funding, and third-party validation.** Oak emerged from stealth on **July 15, 2026** with **$60 million in seed funding** — one of the largest seed rounds ever raised by an Israeli cybersecurity company, and an outlier for a "seed" label. The round was **co-led by Accel, CRV, and Greylock Partners**, with participation from **Hetz Ventures, AlphaDrive Ventures, and strategic angel investors**. The investor roster is itself a strong validation signal: three top-tier funds co-leading a first institutional round is unusual and reflects conviction in the founder and category. There is also a relationship history — Accel previously led the Series A of Morag's prior company, Ermetic, and reportedly held a standing informal commitment to back his next venture. The combination of a large round, tier-one multi-lead syndicate, a generally-available product at launch, and prior-relationship investor conviction constitutes meaningful third-party diligence, even though revenue, customer counts, and unit economics remain undisclosed.
**Founders and team background.** Oak is co-founded by **Shai Morag (CEO)** and **Tal Marom (Chief Product Officer)**, and the founder pedigree is the single strongest asset in the story. Morag is a serial cybersecurity entrepreneur with more than two decades in the field and **three prior exits reportedly totaling roughly $500 million**: Integrity-Project (acquired by Mellanox, now part of NVIDIA, in 2014), Secdo (acquired by Palo Alto Networks in 2018), and Ermetic — a cloud-identity/CIEM company — acquired by Tenable in 2023 for a reported ~$265 million, after which Morag served as Tenable's Chief Product Officer. That last data point matters: Oak is Morag returning to the identity problem with direct, recent operating experience at the scale of a public security vendor. Marom previously led product teams at Tenable and Salesforce and brings Israeli military technical background. The company built a **~50-person team** during stealth, split across Israel and San Francisco, and is hiring aggressively in the U.S. The principal team question is not capability but focus and durability — Morag has publicly framed Oak as his "last company," which is motivating but also raises normal key-person considerations.
**Competitive dynamics.** Oak enters a crowded, well-capitalized field and its differentiation rests on the AI-native, consolidation, and non-human-identity angles rather than on inventing a new category from scratch. (1) Against legacy **IGA incumbents** (SailPoint, Saviynt) it competes on continuous, usage-based governance versus periodic certification campaigns, and on AI-accelerated integration. (2) Against **IAM/identity providers** (Okta, Microsoft Entra ID, Ping) it is complementary in places but competes for the "single control plane" narrative. (3) Against **privileged-access and identity-security** players (CyberArk, and detection-oriented ITDR vendors like Silverfort) it overlaps on risk and least-privilege enforcement. (4) The most strategically important battleground is **machine and AI-agent identity**, where a fast-growing cohort of specialists — Astrix Security, Oasis Security, Token Security, Aembit — is racing for the same "identity for the AI era" position; Oak's own investor acknowledged it will face "plenty of competitors" leveraging AI, making speed-to-scale decisive. Oak's plausible edges are: (i) a genuinely consolidated control plane rather than a point tool; (ii) AI-native connector-building that compresses the integration bottleneck that historically slows identity deployments; (iii) a live, usage-aware identity graph enabling real-time remediation; and (iv) an exceptionally credible founder who has sold into and operated this exact market. The countervailing risk is structural: identity is a sticky, lock-in-heavy market where displacing incumbents is slow, and "AI-native" is a claim many competitors are making simultaneously.
**Defense, security, and resilience dual-use relevance.** Oak's dual-use relevance should be read as a strong *adjacency*, not a fielded defense capability. Identity governance is foundational cyber-resilience infrastructure: government agencies, defense primes, and critical-infrastructure operators are precisely the organizations under the most acute pressure to implement zero-trust architectures, where the animating principle — "never trust, always verify," enforced per-identity and per-access — is exactly the problem Oak automates. Continuous, usage-based least-privilege enforcement, real-time revocation of drifted permissions, and a live map of who and what can touch which systems map directly onto zero-trust mandates (for example, the kind embodied in U.S. federal and defense zero-trust strategies) and onto the security of operational-technology and critical-infrastructure environments. The frontier element — governing **AI-agent and machine identities** — is directly relevant to the secure deployment of autonomous and AI-enabled systems in defense and national-security contexts, where non-human actors increasingly hold privileged access. The honest calibration: Oak is a commercial enterprise-cyber company whose technology is highly relevant to government/defense/critical-infrastructure resilience, but it is not marketed with disclosed defense contracts, certifications (e.g., FedRAMP), or fielded national-security deployments. Its dual-use weight is real and will scale with any public-sector, defense, or critical-infrastructure adoption and accreditation it converts.
**Growth stage, trajectory, and key diligence risks.** Oak reads as an **early-stage but unusually well-capitalized** company: a just-emerged (July 2026) seed-labeled round of extraordinary size, a shipping GA product, a tier-one syndicate, and a proven founder — a profile that behaves more like a Series A than a typical seed. The trajectory bet is that identity re-platforming driven by AI agents creates a large, urgent budget line that a consolidated, AI-native control plane can capture faster than incumbents can retrofit. The key diligence risks are: (1) **intense, well-funded competition** across legacy IGA, IAM, and the AI-agent-identity cohort, in a market where "AI-native" is a widely shared claim; (2) **structural stickiness and lock-in** in identity that make incumbent displacement slow and reference-driven; (3) **undisclosed traction** — no public customer names, revenue, retention, or unit economics, so real adoption depth is unverified; (4) **execution and scaling risk** as the company builds out a U.S.-centric enterprise sales motion at speed; (5) **key-person dependence** on Morag; and (6) on the strategic axis, the **absence of documented public-sector/defense adoption or accreditation** that would convert dual-use adjacency into fielded strategic value. Progression from here would be evidenced by named enterprise (and ideally government/critical-infrastructure) customers, disclosed ARR/retention, credible AI-agent-identity deployments at scale, and any zero-trust/FedRAMP-style accreditation.
Dual-Use Assessment
Oak's dual-use relevance is a strong adjacency rather than a fielded defense capability. (1) Identity governance is foundational cyber-resilience infrastructure: government agencies, defense primes, and critical-infrastructure operators face the most acute pressure to implement zero-trust architectures, whose per-identity 'never trust, always verify' principle is exactly what Oak automates via continuous, usage-based least-privilege enforcement and real-time revocation of drifted permissions. (2) A live, usage-aware map of who and what can access which systems maps directly onto U.S. federal/defense zero-trust mandates and onto securing operational-technology and critical-infrastructure environments. (3) The frontier capability — governing machine and AI-agent identities — is directly relevant to the secure deployment of autonomous and AI-enabled systems in defense and national-security contexts, where non-human actors increasingly hold privileged access. Calibration: Oak is a commercial enterprise-cyber company with no publicly disclosed defense contracts, government accreditations (e.g., FedRAMP), or fielded national-security deployments; its dual-use weight is real but will materialize only as public-sector, defense, or critical-infrastructure adoption and accreditation are converted.
Strategic Fit Assessment
Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.
Oak is an early-stage but unusually well-capitalized Israeli cyber company whose appeal rests on an exceptional founder, a large re-platforming market, and a timely AI-agent-identity thesis — tempered by crowded competition and undisclosed traction. (1) Founder quality: Shai Morag has three prior cybersecurity exits reportedly totaling ~$500 million (Integrity-Project/Mellanox-NVIDIA 2014, Secdo/Palo Alto 2018, Ermetic/Tenable ~$265M 2023) and returns to the identity problem with recent public-vendor operating experience as Tenable's CPO. (2) Validation: a $60M seed co-led by Accel, CRV, and Greylock — a rare three-way tier-one lead — with a product already generally available and deployed at enterprises, is meaningful third-party diligence; Accel had a prior relationship from backing Ermetic. (3) Market timing: AI agents are poised to multiply enterprise identities while making credential attacks easier, forcing a governance re-platforming that cloud-era incumbents are poorly positioned to serve, and Oak's consolidation-plus-non-human-identity angle targets that shift directly. Counterweights that should dominate assessment: (a) intense, well-funded competition across legacy IGA (SailPoint, Saviynt), IAM (Okta, Microsoft Entra), and the AI-agent-identity cohort (Astrix, Oasis, Token, Aembit), where 'AI-native' is a widely shared claim; (b) identity is a sticky, lock-in-heavy market where incumbent displacement is slow; (c) no disclosed customer names, revenue, or retention, leaving real traction unverified; and (d) the strongest strategic uplift (public-sector/defense adoption and accreditation) is not yet documented. This is a priority-signal assessment of strategic and technical fit, not an investment recommendation.
Strategic Value to U.S.-Israel Alliance
Oak's strategic value sits in the cyber-resilience and identity-security layer rather than in a fielded product. (1) Foundational infrastructure: identity governance is the connective tissue of zero-trust security, and a consolidated, continuously-verifying control plane is high-leverage across commercial, government, defense, and critical-infrastructure environments simultaneously. (2) Zero-trust alignment: continuous, usage-based least-privilege enforcement and real-time permission revocation map directly onto federal and defense zero-trust mandates and onto securing OT/critical-infrastructure access. (3) AI-agent frontier: governing machine and AI-agent identities is directly relevant to the secure deployment of autonomous and AI-enabled systems in national-security contexts, an emerging and under-served problem. (4) Sovereign/allied ecosystem relevance: an Israeli-founded identity-security platform with a tier-one investor base strengthens the allied cyber-tooling landscape. The realized strategic weight depends on Oak converting commercial traction into public-sector, defense, or critical-infrastructure deployments and accreditations; absent those, its strategic value is strong on the commercial cyber axis but remains an adjacency on the defense axis rather than a fielded capability.
Key Technologies
- AI-native 'Identity Operating System' — a unified control plane consolidating fragmented legacy IGA/IAM tooling
- Live identity graph continuously built from raw operational data, mapping granted permissions against actual usage
- AI connector framework spanning on-premises, cloud, SaaS, and custom applications for rapid integration
- Real-time, risk-based access decisions and automated remediation (stripping unused/over-provisioned permissions as they drift)
- Governance of non-human identities — service accounts, machines, workloads, and autonomous AI agents — across their lifecycle
- Anomaly-driven risk triggers (e.g., unusual login locations) replacing periodic certification campaigns with always-on governance
- Full-lifecycle identity governance model shifting from operations-based to risk-based enforcement
Use Cases & Applications
- Continuous least-privilege enforcement across enterprise cloud, SaaS, on-prem, and custom systems
- Governing and securing AI-agent and machine identities that hold privileged access in modern enterprises
- Replacing periodic access-review/certification campaigns with real-time, usage-based governance
- Detecting and remediating over-provisioned, orphaned, or drifted permissions before they are exploited
- Consolidating a fragmented identity-tool stack into a single control plane for CISOs and IAM teams
- Supporting zero-trust architecture programs in government, defense, and critical-infrastructure organizations
- Compliance and audit readiness (demonstrable, continuous identity governance for regulated environments)
- Reducing credential-based attack surface as AI increases the ease and scale of identity-driven attacks
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.
This record lists 7 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- Oak Raises $60M in Seed Funding to Build the AI-Native Identity Operating System (PR Newswire, official press release, 15 Jul 2026) Primary source confirming the $60M seed, co-leads Accel/CRV/Greylock plus Hetz Ventures and AlphaDrive Ventures, the AI-native 'Identity Operating System' governing human/machine/AI-agent identities, general availability with enterprise customers, founders Shai Morag (CEO) and Tal Marom (CPO), dual Tel Aviv/San Francisco base, official website (oak.id), and Black Hat USA 2026 showcase.
- Backed by $60M in funding, Oak steps out of stealth to fix the identity mess that AI agents are making worse (TechCrunch, 15 Jul 2026) Verifies the AI-agent identity problem, the live identity graph and usage-based real-time remediation approach, ~50-person team split Israel/San Francisco with U.S. hiring focus, Morag's exits (Secdo/Palo Alto 2018; Ermetic/Tenable ~$265M 2023, then Tenable CPO), Accel's prior Ermetic relationship, 100+ CISO consultations during stealth, and investor caution that Oak faces 'plenty of competitors.'
- Oak Emerges From Stealth Mode With $60 Million in Funding (SecurityWeek, Jul 2026) Independent security-trade corroboration of the AI-powered 'Identity Operating System,' the single control plane consolidating IGA/IAM, coverage of 'all human, AI, and machine identities,' the CNAPP-consolidation analogy, AI-driven real-time risk decisions/remediation, the investor syndicate, and the Tel Aviv/San Francisco base.
- After three cyber exits, Shai Morag raises $60 million to reinvent enterprise identity (Calcalist/CTech, Jul 2026) Israeli-ecosystem source confirming Oak as an Israeli-founded company, Morag's three prior exits (Integrity-Project/Mellanox 2014, Secdo/Palo Alto 2018, Ermetic/Tenable 2023) reportedly totaling ~$500M, the $60M raise, and the enterprise-identity reinvention thesis.
- Oak raises $60 million for AI-native identity platform (Ynet / Ynetnews, Jul 2026) Corroborates the $60M seed, the co-lead syndicate (Accel, Greylock, CRV) plus Hetz Ventures and AlphaDrive Ventures, ~50 employees across Israel and San Francisco, the live identity graph analyzing raw operational data, and coverage of employees, contractors, applications, machines, and AI agents.
- Oak raises $60M for an AI-native identity platform (The Next Web, Jul 2026) Independent European tech-media corroboration of the $60M seed round, the AI-native identity platform positioning across human, machine, and AI-agent identities, the founder background, and the emergence from stealth in July 2026.
- Oak — Official Company Website Canonical company website confirming Oak's branding as an AI-native Identity Security / Identity Operating System company.
- Profile update timestamp Last updated in the Claw & Talon database on Jul 20, 2026.
Investor Lens
What this entry is
Private startup
Why it may matter
Oak may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.
How an independent investor should read this
Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.
Evidence to verify
- Verify current status
- Verify traction
- Verify cap table/funding
- Verify technical claims
- Verify regulatory/export-control issues
- Verify customer concentration
Main investor questions
- Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
- What customer, revenue, product, and technical evidence supports the company story?
- What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
- Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
- What evidence would change the thesis or show that the profile is stale?
What not to infer
- Inclusion does not imply endorsement.
- Inclusion does not imply allocation availability or current fundraising.
- Scores do not indicate investment suitability or expected returns.
- Strategic importance does not automatically imply venture return potential.
Diligence questions
- What evidence verifies Oak's current customer traction, deployment status, and revenue concentration?
- Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
- Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
- How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
- What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.
Related companies
Need a diligence readout?
Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.