Dossier · Private startup · 0 independent sources
Twine Security
Last updated: Jul 31, 2026
Twine Security builds AI digital employees for cybersecurity teams, starting with Alex, an agentic identity and access management specialist that investigates, plans, and executes identity work across existing enterprise tools. The company is positioning governed AI execution as a way to reduce IAM backlog and improve the consistency and auditability of security operations.
Visit WebsiteCompany Overview
Twine Security is building an AI workforce for cybersecurity rather than another standalone identity database or ticketing dashboard. Its first digital employee, Alex, is designed to understand an organization's identity environment, investigate exceptions, plan remediation, and execute IAM work end to end. The company's product materials describe user access reviews, application onboarding, entitlement optimization, least-privilege implementation, SaaS MFA enforcement, identity-lifecycle work, account-ownership integrity, and stale-account cleanup. Alex is intended to operate across existing IAM and IGA investments, with per-action autonomy settings, approval workflows, and audit trails that constrain and record its activity. The important technical proposition is therefore a controlled execution layer combining identity-data analysis, workflow orchestration, language-model reasoning, and enterprise integrations.
The customer problem is substantial and budget-adjacent. Large organizations accumulate disconnected HR sources, directories, applications, groups, entitlements, and privileged identities, while IAM teams must keep access accurate and produce evidence for audits. Manual access reviews and application onboarding are exception-heavy and depend on practitioners who understand policy as well as customer-specific systems. Twine's wedge is aimed at enterprise security, IT, and identity teams that already operate platforms from SailPoint, Saviynt, Microsoft, Okta, CyberArk, or comparable vendors. This lowers the replacement burden, but it also means Twine must prove that it adds measurable execution capacity without becoming another opaque privileged integration layer. The company's website now reports a 41% reduction in ticket load at a Fortune 500 food-and-beverage company, 5,731 hours saved across customers in one quarter, and a 76% entitlement reduction in a Fortune 500 healthcare deployment; these are useful traction signals but remain company-reported and are not a substitute for customer-verified retention or recurring-revenue data.
Twine publicly emerged from stealth in November 2024 with a $12 million seed round led by Ten Eleven Ventures and Dell Technologies Capital. Its official materials identify four founders with a long shared history at Claroty, including CEO Benny Porat and CTO Nadav Erez, and the company has since publicized enterprise references, a Deloitte partnership, accelerator participation, awards, and market recognition. The public record supports a credible early commercialization story, including a 2025 Gartner Cool Vendor mention, RSAC Innovation Sandbox finalist status, and later awards, but it does not establish revenue scale, customer concentration, renewal rates, gross margin, or the proportion of deployments that allow autonomous execution. Twine faces competition from identity-governance incumbents adding native agents, identity-security vendors, and automation platforms that can assemble similar workflows around large language models. Its differentiation will depend on reliable handling of customer-specific exceptions, safe action boundaries, integration depth, and provable ROI rather than the novelty of the digital-employee label.
The national-security relevance is indirect but substantive. Identity assurance, least privilege, account ownership, access review, and traceable remediation are foundational controls in government, defense-industrial, critical-infrastructure, healthcare, and other high-consequence environments. An agent that can reason over entitlements and execute bounded remediation could reduce administrative backlog and improve evidence quality in those settings. Twine's reported participation in Anthropic's Cyber Verification Program is a relevant external signal about the defensive framing of its AI use, but it is not a product endorsement, security certification, or evidence of defense procurement. Twine should therefore be assessed as dual-use identity-security infrastructure, not as a defense mission-system supplier. Critical diligence questions include tenant isolation, model and integration testing, prompt-injection resistance, credential scoping, approval behavior under time pressure, rollback and recovery, independent security evidence, data residency, and measurable production outcomes.
Dual-Use Assessment
Twine's core product automates and governs identity operations, a commercial IAM function with direct applicability to defense, government, critical infrastructure, and other high-consequence environments that require least privilege and reviewable access decisions. The dual-use case is credible at the security-control layer, reinforced by the company's reported Anthropic Cyber Verification Program participation, but public evidence does not show defense contracts, classified deployment, or mission-system integration.
Strategic Fit Assessment
Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.
Twine is a credible strategic-priority signal for a dual-use security thesis because it targets a costly IAM execution bottleneck and places controlled AI action above existing identity systems. The $12M seed led by Ten Eleven Ventures and Dell Technologies Capital, a founding team with Claroty experience, reported enterprise outcomes, and Anthropic Cyber Verification Program participation support early credibility. The case remains diligence-dependent: public sources do not confirm recurring revenue, net retention, customer concentration, deployment repeatability, or whether customers permit enough autonomy to produce durable software-like margins. This is an internal prioritization assessment, not an investment recommendation.
Strategic Value to U.S.-Israel Alliance
Twine could become an execution and governance layer between enterprise identity systems and increasingly autonomous software workers. That role has strategic value in sensitive environments where access must be minimized, decisions must be reviewable, and security teams cannot manually process every exception. Its strategic relevance is strongest if the product improves existing IAM investments, preserves human control, and creates a reliable audit record without adding an uncontrolled privileged system. Current public evidence supports monitoring the company closely, but does not yet establish government adoption, defense procurement, or category leadership.
Key Technologies
- Agentic identity and access management workflow execution
- Identity governance and administration data analysis
- Natural-language investigation of entitlements, exceptions, and attack paths
- Least-privilege and access-policy optimization
- Human approval gates and per-action autonomy controls
- Audit trails, reasoning traces, and remediation evidence
- Integrations with IAM, IGA, HR, directory, SaaS, and ticketing systems
Use Cases & Applications
- User access reviews with business justification and high-privilege analysis
- Application onboarding into existing IGA environments
- Joiner-mover-leaver lifecycle management and stale-account cleanup
- Investigation and reassignment of orphaned account ownership
- Entitlement optimization and least-privilege remediation
- SaaS MFA enforcement and access-policy creation
- IAM ticket backlog resolution with traceable approvals
- Governed identity operations for regulated, government, or defense-industrial IT
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.
This record lists 7 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- twinesecurity.com Public source used for profile verification.
- twinesecurity.com Public source used for profile verification.
- twinesecurity.com Public source used for profile verification.
- twinesecurity.com Public source used for profile verification.
- twinesecurity.com Public source used for profile verification.
- twinesecurity.com Public source used for profile verification.
- LinkedIn company page Public source used for profile verification.
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.