Offroad

Cybersecurity Dual-Use Technology Priority Signal Founded 2025

Last updated: Jul 20, 2026

Offroad is a New York- and Tel Aviv-based cybersecurity startup building an 'agentic' identity security platform that uses autonomous AI agents to discover, investigate, and remediate identity risks across human users, non-human identities, and AI agents. It emerged from stealth in June 2026 with a $7 million seed round led by Ibex Investors and Skywell Capital.

Visit Website

Company Overview

**Product and the concrete problem it solves.** Offroad attacks a problem that has quietly become one of the hardest in enterprise security: identity has stopped being a human-scale problem. A modern organization no longer manages a bounded set of employee logins governed by an identity provider; it manages a sprawling, fast-changing mesh of human users, machine identities (service accounts, API keys, tokens, workload identities), and — increasingly — autonomous AI agents that authenticate, hold permissions, and act on their own. Offroad's framing, in co-founder and CEO Dan Bendler's words, is that "enterprises now operate across a constantly changing mix of human users, machine identities, and AI agents," and that the volume of identity-security work this creates has outrun what human teams can triage manually. The company positions its platform as an "agentic identity security team" — software that does the investigative and remediation labor a human identity/security team would do, but continuously and at machine scale. Concretely, it aims to move an organization "from identity visibility to full risk resolution": not just surfacing that a dormant service account has excessive privileges or that an AI agent's permissions drifted, but investigating the context, deciding whether it is a real risk, and either fixing it automatically where policy allows or escalating it to the right owner.

**Core technology and how it actually works.** Offroad's platform is organized around three functions — discovery, investigation, and remediation — executed by AI agents rather than static rules. On discovery, it "ingests data from 250+ sources across your cloud, SaaS and on-prem," pulling from major identity providers (Okta, Microsoft Entra ID, Ping Identity), the three hyperscalers (AWS, Google Cloud, Azure), and a long tail of SaaS systems (Salesforce, Slack, ServiceNow, Workday, GitHub, Datadog, Snowflake, and others) to assemble a unified picture of who and what can access what. For the AI-agent and non-human-identity (NHI) case specifically, the product claims to analyze "the intent, permissions, and ownership of AI agents and non-human identities to proactively identify and prevent access abuse" — i.e., not merely enumerating credentials but reasoning about what a given machine or agent identity is *for*, who controls it, and whether its observed permission usage matches its purpose. Investigation is where the "agentic" claim is most load-bearing: rather than dumping alerts on an analyst, Offroad's agents are meant to gather context across those fragmented systems, correlate posture issues with runtime signals, and produce a reasoned judgment. Remediation is then automated where policies permit — dynamically auditing permission usage, revoking or right-sizing access — or routed to the appropriate human owner. The technical bet is that large-model-driven agents can absorb the context-gathering and correlation toil that makes identity governance so labor-intensive, thereby collapsing alert fatigue and shrinking the window between detection and fix.

**Market, customers, and go-to-market.** Offroad sells into the enterprise identity-security market, one of the largest and most contested categories in cybersecurity, and it is riding two powerful sub-trends: the explosion of non-human identities (which now vastly outnumber human ones in most cloud estates) and the arrival of autonomous AI agents as first-class actors that need to be identified, permissioned, and policed. Its go-to-market is classic enterprise B2B SaaS — a platform sold to CISOs, identity/IAM teams, and security operations groups — and its integration-heavy architecture (250+ connectors, deep hooks into Okta/Entra/Ping and the hyperscalers) is designed to slot into existing identity stacks rather than replace them. The dual New York and Tel Aviv footprint reflects a common Israeli-cyber pattern: Israeli engineering and threat-research depth paired with a U.S. commercial and sales presence aimed at the American enterprise buyer where the largest security budgets sit. Named production customers, design partners, pricing, and pipeline are not disclosed in the public record and should be treated as unverified; at this stage the company is best understood as a funded, product-defined entrant rather than one with proven enterprise traction.

**Traction, funding, and third-party validation.** The verifiable facts are the funding event and the investors behind it. Offroad emerged from stealth on June 4, 2026 with a **$7 million seed round led by Ibex Investors and Skywell Capital (Skywell Capital Partners)**, announced via BusinessWire and covered by Calcalist, SecurityWeek, SiliconANGLE, Ynet, and multiple trade outlets. That is a modest seed by 2026 Israeli-cyber standards — peers in the adjacent AI-agent/identity space raised far larger rounds in the same window (for example Oak at ~$60M, NewCore at ~$66M total, and Onyx Security at ~$40M) — which is a useful calibration point: Offroad is early and lightly capitalized relative to the cohort competing for the same problem. The strongest third-party validation is therefore not scale but the founders' pedigree and the investors' willingness to back them pre-revenue; the round's stated use of proceeds is to build out the platform and the "agentic identity security team." Revenue, headcount, valuation, and customer counts are not publicly disclosed.

**Founders and team background.** Offroad was founded in 2025 by **Dan Bendler** (co-founder and CEO) and **Philip Shteyn** (co-founder and CTO). Bendler is a repeat founder who, per multiple reports, previously founded two AI startups that collectively raised more than $45 million — relevant because Offroad's thesis is fundamentally an applied-AI bet, and prior experience shipping AI products and raising capital is directly on-point. Shteyn is described as a former **Unit 8200 captain** who "helped build Palo Alto Networks' Cortex platform" — a combination that matters: Unit 8200 is Israel's signals-intelligence unit and the single most prolific incubator of Israeli cyber founders, and Cortex is a widely deployed enterprise/government SecOps and XDR platform, so Shteyn brings both offensive/defensive security depth and hands-on experience building a large-scale security product used in real SOCs. The principal open questions are ordinary for a 2025-vintage seed company: total headcount, the depth of the engineering and go-to-market bench beyond the two founders, and whether the team can convert a strong pedigree into enterprise-grade reliability in a category where false remediation actions carry real operational risk.

**Competitive dynamics.** Offroad competes in an unusually crowded lane where three markets are colliding — identity governance (IGA), non-human-identity security, and the brand-new category of AI-agent security. (1) Against **incumbent identity platforms** — Okta, Microsoft Entra, CyberArk, SailPoint — Offroad is a specialist layer betting that agentic investigation/remediation is a capability the incumbents are slower to build; but those incumbents own the data and the buyer relationship. (2) Against the **NHI-security wave** — Oak (AI 'Identity Operating System'), NewCore (identity/permission infrastructure for employees, systems, and AI agents), and others — it competes directly on the machine-identity problem, often with less capital. (3) Against the **AI-agent-security cohort** — Onyx Security, Melian Security (runtime security for enterprise AI agents), and a fast-growing field of 2025–2026 entrants — it overlaps on securing autonomous agents. Offroad's plausible differentiators are: (i) an end-to-end discover→investigate→remediate loop rather than visibility-only tooling; (ii) breadth of ingestion (250+ sources) for unified context; and (iii) a founder-market fit combining repeat AI-building experience with 8200/Cortex security depth. The countervailing reality is that nearly every competitor makes similar "agentic," "context," and "autonomous remediation" claims, so the moat will be proven only in deployed reliability and enterprise references, neither of which is yet public.

**Defense, security, and resilience dual-use relevance.** Offroad's dual-use relevance should be read as a defensive-cyber and resilience adjacency, not a fielded defense capability. Its core technology — governing the identities, permissions, and behavior of machine and AI-agent actors — sits squarely in the defensive-security domain that is core to Claw & Talon's cyber thesis, and it addresses a resilience problem that governments and critical-infrastructure operators face as directly as commercial enterprises: as agentic AI is adopted inside defense, intelligence, and national-infrastructure environments, controlling what autonomous agents and non-human identities can do — and catching compromise or drift at runtime — becomes a hard security requirement. The founder signal reinforces the adjacency: a Unit 8200 background and hands-on work on Palo Alto's Cortex (a platform deployed in government and defense SOCs) indicate the team understands the operational-security context that public-sector and defense buyers require. The honest calibration is that Offroad has disclosed no government, defense, or critical-infrastructure customers, no clearances, and no sovereign/air-gapped deployment posture; its dual-use weight is therefore category-level and pedigree-based, and would only become concrete if it wins public-sector references or hardens the product for classified/on-prem environments.

**Growth stage, trajectory, and key diligence risks.** Offroad reads as an **early-stage** company: founded 2025, out of stealth in mid-2026 on a $7M seed, product-defined but pre-scale, with a strong founder duo and a hot but savagely competitive market. The trajectory to watch is whether it can convert pedigree into paying enterprise deployments before better-capitalized peers (Oak, NewCore, Onyx, and identity incumbents) crowd the category. The key diligence risks are, first, **capitalization and competitive intensity** — a $7M seed is small against rivals raising 6–10x more for the same problem, compressing runway to prove differentiation; second, **product-reliability risk** — autonomous remediation of identity/permissions is high-stakes, where an over-eager agent revoking legitimate access can cause outages, so trust and precision are existential; third, **category commoditization** — "agentic identity security" is a crowded, buzzword-dense space where the technical claims are hard to distinguish from the outside; fourth, **traction opacity** — no disclosed customers, revenue, headcount, or valuation, so all commercial claims are unverified; and fifth, **dual-use thinness** — its strategic weight on the defense/resilience axis is adjacency and founder-pedigree, not fielded capability. Progression from here would be evidenced by named enterprise (and ideally public-sector) customers, demonstrated safe autonomous remediation at scale, a larger Series A, and clarity on how it defends its niche against both incumbents and the well-funded NHI/AI-agent cohort.

Dual-Use Assessment

Military & Commercial Applications

Offroad's dual-use relevance is a defensive-cyber and resilience adjacency rather than a fielded defense capability, and should be read with calibration. (1) Core-domain fit: governing the identities, permissions, and runtime behavior of machine identities and autonomous AI agents is a defensive-security function that maps directly onto Claw & Talon's cyber thesis. (2) Resilience relevance: as agentic AI enters defense, intelligence, and critical-infrastructure operations, constraining what non-human and AI-agent identities can do — and detecting compromise, drift, or abuse at runtime — becomes a genuine national-resilience requirement, not merely an enterprise convenience. (3) Founder signal: CTO Philip Shteyn is a former Unit 8200 captain who helped build Palo Alto Networks' Cortex, a SecOps/XDR platform deployed in government and defense SOCs, indicating the team understands operational-security contexts that public-sector buyers demand. (4) Honest limits: Offroad has disclosed no government, defense, or critical-infrastructure customers, no clearances, and no air-gapped/sovereign deployment posture; its dual-use weight is category-level and pedigree-based, and would become concrete only with public-sector references or a hardened classified/on-prem offering. Dual-use is credible as defensive-cyber for the agentic-AI era, but remains an adjacency at this stage.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

Offroad is an early-stage, founder-strong bet on the agentic-AI security wave, appealing on team and category timing but heavily caveated by capitalization and competitive intensity. (1) Founder-market fit: repeat AI founder Dan Bendler (prior startups raised >$45M combined) paired with CTO Philip Shteyn (ex-Unit 8200 captain who helped build Palo Alto Networks' Cortex) is a credible team for an applied-AI security product. (2) Category timing: non-human-identity and AI-agent security is one of the fastest-growing problems in cybersecurity as machine identities dwarf human ones and autonomous agents become first-class actors. (3) Differentiated posture: an end-to-end discover→investigate→remediate loop with 250+ integrations, if it works reliably, is more valuable than the visibility-only tools that dominate the space. Counterweights that should dominate the assessment: (a) a $7M seed is small versus peers raising 6–10x more for the same problem (Oak ~$60M, NewCore ~$66M, Onyx ~$40M), compressing runway; (b) autonomous remediation of identity/permissions is operationally high-risk — a wrong action causes outages — so trust and precision are existential and unproven; (c) the category is crowded and buzzword-dense, making differentiation hard to verify externally; and (d) no customers, revenue, headcount, or valuation are disclosed. This is a priority-signal assessment of strategic and technical fit, not an investment recommendation.

Strategic Value to U.S.-Israel Alliance

Offroad's strategic value sits in the defensive-cyber resilience layer for the agentic-AI era, with weight that is category-level today rather than fielded. (1) Enabling security capability: governing machine and AI-agent identities is a horizontal defensive-security function relevant to enterprises, governments, and critical-infrastructure operators alike as they adopt autonomous AI. (2) Resilience thesis: constraining and monitoring non-human/agent actors at runtime addresses a genuine attack surface — compromised or drifting agents — that will grow as agentic AI proliferates in sensitive environments. (3) Israeli-cyber pedigree and talent: a Unit 8200 / Palo Alto Cortex founder lineage and a Tel Aviv engineering base connect it to the ecosystem that repeatedly produces globally relevant defensive-security technology. (4) Calibration: with no disclosed government/defense/critical-infrastructure customers, no clearances, and no sovereign deployment posture, its strategic weight on the defense axis is an adjacency that would only become concrete with public-sector references or a hardened on-prem/air-gapped offering. Its realized strategic value depends on converting a strong team and hot category into deployed, reliable, referenceable enterprise (and ideally public-sector) usage.

Key Technologies

  • Agentic identity security: autonomous AI agents that discover, investigate, and remediate identity risks (discover → investigate → remediate loop) rather than visibility-only tooling
  • Non-human-identity (NHI) governance across service accounts, API keys, tokens, and machine/workload identities
  • AI-agent security: analysis of the intent, permissions, and ownership of autonomous AI agents to detect and prevent access abuse
  • Broad data ingestion — 250+ connectors across cloud, SaaS, and on-prem — for unified identity context
  • Deep integration with identity providers (Okta, Microsoft Entra ID, Ping Identity) and hyperscalers (AWS, Google Cloud, Azure)
  • Dynamic permission-usage auditing with policy-gated automated remediation and escalation to identity owners
  • Context correlation across fragmented systems to reduce alert fatigue and shorten detection-to-fix time

Use Cases & Applications

  • Continuously discovering and right-sizing over-privileged non-human identities (service accounts, tokens, API keys) across cloud and SaaS estates
  • Securing autonomous AI agents by policing their permissions, intent, and ownership to prevent access abuse or exfiltration
  • Automated investigation and remediation of identity posture risks to relieve overloaded IAM and SecOps teams
  • Unifying identity context across Okta/Entra/Ping, AWS/GCP/Azure, and SaaS apps for a single risk picture
  • Detecting and responding to runtime identity threats (credential misuse, privilege drift) as they occur
  • Reducing standing privilege and enforcing least-privilege across human and machine identities at scale
  • Providing an 'agentic identity security team' for enterprises that cannot staff the manual triage load
  • Governing agent and machine identities in defense/government/critical-infrastructure environments adopting agentic AI (prospective adjacency)

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.

This record lists 6 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Investor Lens

What this entry is

Private startup

Why it may matter

Offroad may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.

How an independent investor should read this

Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.

Evidence to verify

  • Verify current status
  • Verify traction
  • Verify cap table/funding
  • Verify technical claims
  • Verify regulatory/export-control issues
  • Verify customer concentration

Main investor questions

  • Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
  • What customer, revenue, product, and technical evidence supports the company story?
  • What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
  • Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
  • What evidence would change the thesis or show that the profile is stale?

What not to infer

  • Inclusion does not imply endorsement.
  • Inclusion does not imply allocation availability or current fundraising.
  • Scores do not indicate investment suitability or expected returns.
  • Strategic importance does not automatically imply venture return potential.

Diligence questions

  • What evidence verifies Offroad's current customer traction, deployment status, and revenue concentration?
  • Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
  • Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
  • How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
  • What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.

Need a diligence readout?

Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.