Dossier · Private startup · 5 independent sources
Rig Security
Last updated: Sep 8, 2026
Rig Security is a Tel Aviv cybersecurity startup building an AI-native identity-protection platform that maps human, machine, and AI identities, exposes cross-system privilege paths, detects identity threats, and automates safer remediation. Its core thesis is that fragmented identity data and over-privileged access have become a primary enterprise attack surface as cloud workloads and autonomous agents multiply.
Visit WebsiteCompany Overview
**Product and the problem it solves.** Rig Security addresses a specific failure in modern enterprise defense: organizations have many identity systems, cloud accounts, HR records, SaaS applications, endpoint tools, and security logs, but no continuously reconciled view of what each person, machine, service account, or AI agent can actually reach. The result is identity sprawl, orphaned accounts, excessive permissions, toxic combinations of access, and attack paths that cross boundaries owned by different teams. Rig presents itself as an end-to-end identity-protection platform rather than a single access-management feature. Its public product materials describe one living map for human, non-human, and AI identities, with the ability to correlate ownership, attributes, behavior, permissions, and cross-platform lateral movement. The concrete buyer problem is not simply discovering another account; it is helping a security team decide which identity path creates material risk, who owns it, what the blast radius is, and how to reduce that risk without accidentally breaking production operations.
**Core technology and how it works.** Rig says it connects through APIs to cloud, HR, IT, business, and security systems, including GitHub and Snowflake, while ingesting SIEM events and telemetry from tools such as Wiz and CrowdStrike. That architecture is important because it aims to enrich identity data with actual usage and threat context instead of treating a directory record or permission list as sufficient evidence. The platform's four publicly described functions are unified identity visibility and inventory, agentic identity-posture risk mitigation, AI-driven threat detection and response, and compliance or least-privilege enforcement. Its product blog describes an identity graph that can show every identity and dangerous access path, attribute ownership, model the impact of proposed fixes, and provide AI-assisted remediation. The company also describes near-real-time threat detection and runtime AI enforcement, but the public material does not disclose model architecture, training data, detection benchmarks, or whether remediation is deterministic policy automation, a human-approved workflow, or autonomous action in each deployment. Those implementation details are central diligence questions rather than assumptions.
**Market, customers, and go-to-market.** Rig sells into the enterprise identity-security and cloud-security market, where the buyer is likely a CISO, identity team, cloud-security team, or security-operations leader responsible for reducing access risk across a heterogeneous estate. The category spans identity governance and administration, identity-threat detection and response, cloud infrastructure entitlement management, privileged access, non-human identity security, and the newer problem of AI-agent governance. Rig's API-only positioning is a practical go-to-market choice: a customer can connect existing systems and create a unified view without replacing its identity provider or deploying a new inline network appliance. The official site includes an anonymous customer-style outcome statement about reducing manual investigation and safely adopting AI, but it does not identify that organization, disclose contract size, or publish a case study with independently measurable results. A public Information Security Media Group discussion placed CEO Guy Kozliner alongside a Delta Dental Plans Association CISO to discuss human and non-human identities, which demonstrates category engagement but should not be treated as proof that Delta Dental is a Rig customer. Public sources reviewed do not establish a named production customer list, pricing model, renewal rate, or sales cycle.
**Traction, funding, and third-party validation.** Rig was incorporated in Israel as RIG SECURITY LTD on October 13, 2024, according to a public company-registry record, and Dealroom lists an October 2024 launch date, Tel Aviv headquarters, and a 2-10 employee band. The company appears to be early and actively building its commercial footprint. It was listed among the startups selected for the 2025 AWS and CrowdStrike Cybersecurity Startup Accelerator, a program described by CrowdStrike as providing mentorship, technical support, and go-to-market guidance, with NVIDIA support. Crunchbase identifies True Ventures and the AWS/CrowdStrike accelerator among Rig's investors or backers, but public sources reviewed do not disclose an equity round amount, valuation, or cap table that can be treated as confirmed. Rig's official site shows investor or ecosystem marks without a detailed financing announcement. The Cybertech Global Tel Aviv 2026 catalog independently describes Rig as an AI-native identity-security company that unifies fragmented identity data into a living, actionable view. These are useful validation signals, but they are not substitutes for security efficacy benchmarks, named reference deployments, revenue evidence, or independently audited operating metrics.
**Founders and team background.** Rig's founder profile is a meaningful part of its thesis. Guy Kozliner is identified by the company as co-founder and CEO; his public biography describes prior work on the CTO team at Wiz, software-engineering experience at Cybereason, operating experience at FrontLife, and service as a commander in the Israeli Defense Force's Special Forces intelligence corps. Nissim Bitan is identified in Rig's founding article as co-founder and CTO, with prior engineering and cloud roles at Rookout, Firefly, Aqua Security, and Taboola, plus earlier service in the IDF Mamram technology unit. This pairing combines enterprise-security exposure, cloud architecture, and Israeli military technology experience relevant to identity and access problems. There is a small but important public-record discrepancy: Rig's current About page lists Nokky Goren as CTO, while the company's January 2026 founding article names Bitan as CTO. The most defensible record is therefore that Kozliner and Bitan are public co-founders, while current executive responsibilities and the broader engineering headcount require confirmation. Rig's team pedigree is credible, but the small disclosed employee band creates key-person and execution concentration risk.
**Competitive dynamics.** Rig competes in a crowded field where the product boundary is still moving. Okta and Microsoft Entra ID own major parts of the workforce-identity control plane and can extend native governance, risk, and AI-agent features to installed customers. CyberArk, SailPoint, and Saviynt compete from privileged-access and identity-governance positions, while Israeli specialists such as Astrix Security and Hush Security focus on non-human identities, machine credentials, and secretless access. NewCore is pursuing a security-first identity architecture for humans, machines, and AI agents; Offroad uses agentic investigation and remediation for identity risk; and Oak markets a unified identity operating system for the agentic enterprise. Rig's plausible edge is the combination of a living identity graph, cross-platform attack-path context, AI-assisted remediation, and threat detection in one agentless integration layer. That edge is not yet proven as a durable moat: competitors make overlapping AI-native claims, incumbents have distribution and proprietary telemetry, and identity teams may prefer incremental controls over a new system of record. Rig will need to show lower time-to-value, better risk prioritization, safer remediation, and stronger visibility than point tools and bundled incumbent features.
**Defense, security, and resilience dual-use relevance.** Rig's core technology has credible dual-use relevance because identity compromise is a common pathway into enterprises, defense suppliers, government systems, and critical infrastructure, while machine and AI identities are increasingly embedded in the automation that operates those environments. A continuously reconciled identity graph can help defenders identify over-privileged service accounts, lateral-movement paths, stale contractor access, and autonomous agents with permissions that exceed their mission. Near-real-time detection and policy-based least-privilege enforcement are relevant to zero-trust programs, secure software factories, cloud-hosted mission support, and industrial or public-sector environments where access attribution and rapid revocation matter. The Israeli military and cloud-security backgrounds of the founders reinforce the team's potential fit for high-consequence security problems. The limitation is equally important: public sources reviewed do not document a military contract, classified deployment, government customer, security accreditation, or disconnected or sovereign operating mode. Rig is therefore dual-use through transferable defensive cyber capability and resilience value, not through a verified fielded defense product.
**Growth stage, trajectory, and key diligence risks.** Rig should be classified as early stage. Its incorporation and launch dates are recent, public employee data indicates a small team, and no disclosed financing amount, revenue, named customer, or independently measured product outcome was found in the sources reviewed. The accelerator selection and founder pedigree give it a credible starting position, while the identity-security market is large and strategically urgent as AI agents create more non-human principals and permissions. The trajectory will depend on converting a compelling map-and-remediate narrative into repeatable enterprise deployments. Priority diligence points are: (1) verify current leadership and the Bitan/Goren CTO discrepancy; (2) obtain customer references and quantify time-to-remediation, false-positive rates, and unsafe-change prevention; (3) understand how the identity graph handles incomplete ownership data, shadow identities, and rapidly changing agent permissions; (4) test whether API-only access is sufficient for response or whether customers need enforcement at runtime; (5) confirm security architecture, tenant isolation, data residency, and on-premises or sovereign options; (6) establish funding runway, hiring plan, and unit economics; and (7) assess whether Okta, Microsoft, CyberArk, NewCore, Hush, Offroad, and Oak can compress the product's differentiation. Rig is strategically interesting, but the evidence supports a monitored early-stage company rather than a proven category leader.
Dual-Use Assessment
Rig's core identity-security technology has credible commercial and defense/security-resilience applicability. In commercial environments, it unifies human, machine, and AI-agent identity data, detects access risk, maps lateral movement, and supports least-privilege remediation. In defense, government, and critical-infrastructure environments, the same controls could reduce contractor and service-account exposure, improve attribution for privileged actions, govern autonomous workflows, and shorten response to identity compromise. The connection is capability-based rather than contract-based: public sources reviewed do not establish a military customer, classified deployment, government accreditation, or sovereign/offline operating mode. Rig should therefore be treated as a genuine dual-use defensive-cyber platform with adjacency-grade national-security relevance, not as a fielded defense supplier.
Strategic Fit Assessment
Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.
Rig is a credible early-stage cyber priority signal, but the public evidence supports disciplined diligence rather than a conclusion about commercial success. (1) The problem is structurally important: identity sprawl, machine credentials, and AI-agent permissions are expanding faster than directory-centric governance can handle. (2) The product thesis is coherent: API-first aggregation, a living identity graph, attack-path context, and remediation in one layer can reduce the fragmentation between IAM, cloud security, and SOC teams. (3) Founder-market fit is strong, combining Wiz and Cybereason experience with cloud-platform engineering and Israeli military technology backgrounds. (4) The AWS/CrowdStrike/NVIDIA accelerator selection and public company registration provide external validation beyond the company's own website. The offsets are material: funding amount, named customers, revenue, efficacy benchmarks, and current executive structure are not fully public; the category is crowded; and incumbents can bundle adjacent capabilities. strategically relevant is a legacy internal priority-signal flag only, not an investment recommendation.
Strategic Value to U.S.-Israel Alliance
Rig's strategic value is concentrated in identity as a control plane for resilient digital operations. A continuously updated view of who or what can reach sensitive systems can help organizations reduce persistent privilege, investigate compromise faster, and govern the non-human and AI identities that are becoming part of critical workflows. That matters to defense suppliers, public agencies, and infrastructure operators even when the product is sold commercially, because a compromised service account or autonomous agent can create the same lateral-movement and attribution problem across sectors. The strategic case remains conditional on proof that Rig can operate safely at enterprise scale, preserve data sovereignty, support constrained deployments, and produce measurable risk reduction rather than another dashboard.
Key Technologies
- API-based identity graph unifying human, non-human, and AI-agent identities across cloud, HR, IT, business, and security systems
- Identity posture management that surfaces toxic access combinations, ownership gaps, and cross-platform privilege paths
- AI-assisted remediation with what-if impact analysis and permission right-sizing
- Near-real-time identity threat detection and response enriched by SIEM, cloud, EDR, and security-stack telemetry
- Runtime AI enforcement and policy-based least-privilege controls for autonomous agents and machine identities
- Continuous compliance and access-risk visualization for heterogeneous enterprise environments
Use Cases & Applications
- Inventorying human, service-account, workload, contractor, and AI-agent identities across multi-cloud and SaaS estates
- Finding toxic combinations and lateral-movement paths that span identity providers, cloud permissions, code repositories, and data platforms
- Prioritizing and safely right-sizing over-privileged or orphaned identities without breaking production access
- Detecting compromised credentials and anomalous identity behavior through combined access, ownership, and threat telemetry
- Governing AI agents and automated workflows with attributable identities, scoped permissions, and revocation paths
- Supporting zero-trust, least-privilege, and continuous-compliance programs for regulated enterprises
- Hardening defense-industrial suppliers, public-sector systems, and critical-infrastructure operators against identity-based intrusion
- Providing security teams with an operational identity map for incident investigation and blast-radius analysis
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.
This record lists 8 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- Identity Protection Platform for the AI Era - Rig Security official website Verifies Rig's canonical product positioning around human, non-human, and AI identities, identity correlation, lateral-movement analysis, agentic posture management, AI-driven threat detection and response, and runtime AI enforcement.
- About RIG Security - Protecting Enterprise Identities Verifies the company mission, Guy Kozliner as founder and CEO, the public leadership listing including Nokky Goren, Tel Aviv operating context, and the identity-security product thesis.
- Why We Started Rig - Rig Security Verifies the four-function product model, API connections to cloud, HR, IT, business, SIEM, and security tools, identity-map and remediation workflow, and the published biographies of co-founders Guy Kozliner and Nissim Bitan.
- RIG SECURITY LTD - Israeli company registry record Verifies the legal name RIG SECURITY LTD, Israeli private-company status, active status, incorporation date of 2024-10-13, and Tel Aviv address.
- Rig Security - Dealroom company profile Verifies the Tel Aviv-Yafo headquarters, October 2024 launch date, 2-10 employee estimate, rig.security domain, and identity-security category description.
- CrowdStrike and AWS Select 36 Startups for 2025 Cybersecurity Accelerator Verifies Rig Security's selection for the 2025 AWS and CrowdStrike Cybersecurity Startup Accelerator and the program's technical, mentorship, and go-to-market support with NVIDIA involvement.
- Rig Security - Israeli companies at RSA 2025 Verifies the public ecosystem description of Rig Security as founded by Guy Kozliner and Nissim Bitan and its unified AI-focused identity-risk and access-remediation positioning.
- AI Didn't Break Identity Security. It Exposed What Was Already Broken Verifies Guy Kozliner's public role as Rig co-founder and CEO and provides independent context for the identity-centric threat model and non-human identity risks addressed by the company.
- Profile update timestamp Last updated in the Claw & Talon database on Sep 8, 2026.
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.