Dossier · Private startup · 4 independent sources
Way Security
Last updated: Aug 31, 2026
Way Security is an Israeli cybersecurity startup building an AI-powered integration and enforcement layer for enterprise identity and access management. Its platform extends existing IAM controls across legacy, homegrown, disconnected, and non-standard applications so organizations can govern more identities without replacing their current identity stack.
Visit WebsiteCompany Overview
**Product and the concrete problem it solves.** Way Security addresses the last mile of enterprise identity and access management, where organizations have already purchased an identity provider or identity-governance platform but cannot make it reach every application and identity in the estate. Modern enterprises routinely operate hundreds of systems, including packaged SaaS, legacy applications, internally developed tools, operational software, and services that were never designed for contemporary SSO, MFA, provisioning, or access-review workflows. The result is a familiar security and operating problem: a CISO may own strong IAM controls on paper, while orphaned accounts, excessive entitlements, shadow applications, and unmanaged identities remain outside those controls because each connection requires custom engineering or consulting work. Way describes its product as a universal integration and enablement layer that makes existing IAM investments complete. The intended outcome is not another standalone directory or a rip-and-replace identity provider, but practical coverage across the applications where access risk actually persists.
**Core technology and how it works.** Public technical disclosure describes the product at the workflow and integration level rather than exposing a proprietary model architecture. Way says AI-driven automation and agentic workflows automate tasks that traditionally require identity engineers, consultants, and system integrators. Its site identifies automated application onboarding, provisioning extensibility, and schema analysis as core capabilities, with a vendor-agnostic approach intended to work across unusual application interfaces and identity stores. Once an application is brought into scope, the platform is designed to extend lifecycle management, joiner-mover-leaver automation, access reviews, MFA, SSO, federation, and other native IdP controls. The company also says it can modernize or federate applications that do not support modern authentication and can surface shadow IT, orphaned accounts, over-provisioned users, and risky entitlements for remediation. The important diligence boundary is that public sources do not specify whether this automation relies on browser agents, connectors, APIs, screen interaction, code generation, or another implementation mix. Way's technical claim is therefore best understood as broad, AI-assisted integration and policy execution, not as independently verified autonomous identity administration.
**Market, customers, and go-to-market.** Way sells into a large, security-sensitive enterprise market where IAM software is only part of total deployment cost. The company and its investors frame implementation and ongoing enablement as a recurring bottleneck: organizations may spend several times the software cost on custom integrations, development, and operational labor, and projects can stall when the remaining applications are legacy or internally built. Way's target buyers are therefore CISOs, identity leaders, IAM program owners, and enterprise security or IT teams that already have an Okta, Microsoft, SailPoint, Saviynt, CyberArk, or similar investment but lack the capacity to extend it across the whole estate. Its go-to-market has two complementary paths. It can sell directly to enterprises as an implementation-acceleration and continuous-operations product, and it can partner with larger identity vendors by helping their customers cross the deployment finish line. Axios reported that Way already partners with some larger identity companies, while the company says it has dozens of paying customers in financial services, healthcare, and manufacturing. Those references are meaningful because they indicate a real budget and buyer problem, but names, contract values, retention, and revenue are not public.
**Traction, funding, and third-party validation.** Way emerged from roughly a year of stealth in July 2026 and announced a $20 million Seed round led by Insight Partners and Glilot Capital. Calcalist reported that the company had approximately 30 employees, active customers in Europe and the United States, and early sales; Axios separately described dozens of paying customers across financial services, healthcare, and manufacturing. The company website presents a generally formed product surface rather than a concept page, including integration coverage, lifecycle management, access reviews, identity-policy enforcement, risk discovery, and remediation workflows. Insight's investment profile provides an unusually concrete account of the founding problem: both founders had seen organizations spend three to five dollars of enablement work for every dollar spent on security software. The funding round is a strong early validation signal because Insight and Glilot are specialist enterprise and Israeli cybersecurity investors, but it is not proof of product-market fit. No public source reviewed here discloses annual recurring revenue, customer names, deployment counts, independent efficacy benchmarks, security certifications, patent grants, or audited evidence that Way's coverage reaches 100% of an enterprise estate.
**Founders and team background.** Way was founded in 2025 by CEO Yossi Barishev and CTO Yonatan Rosenberg. The founders previously worked together at Sygnia, where they advised large enterprises on complex identity and access-management programs and participated in high-severity cyber incident-response work. That provenance gives the product a credible founder-problem fit: they have seen both the strategic importance of identity controls and the operational friction that prevents those controls from being deployed everywhere. Insight Partners reports that Barishev previously ran the security team at Fireblocks, a digital-asset infrastructure company operating under intense adversarial pressure, and uses that experience to emphasize security that enables business rather than blocking it. Calcalist identifies Rosenberg as a veteran of Israel's Unit 8200 as well as a Sygnia cybersecurity expert. The public record does not provide a complete leadership roster, detailed education histories, military-unit chronology, or a full engineering headcount. The approximately 30-person team reported in July 2026 is nevertheless substantial for a company founded the prior year and suggests that Way has invested early in product engineering and enterprise delivery. The same scale creates execution pressure: the company must support heterogeneous integrations while building repeatable software economics.
**Competitive dynamics.** Way sits between identity platforms, identity-governance suites, integration tooling, and security services, so its competition is both direct and indirect. Okta and Microsoft Entra ID can improve their own connectors, lifecycle features, and professional-services ecosystems while using installed distribution to defend the account. SailPoint and Saviynt own large identity-governance programs and can deepen coverage of non-standard applications, while CyberArk competes for privileged and machine-identity budgets. Specialist implementation firms and system integrators remain a powerful substitute because they can write one-off connectors and absorb the messy work Way is trying to productize. Identity-integration specialists such as Strata Identity and hybrid-access vendors can also overlap on federation and legacy modernization. Way's proposed edge is a neutral execution layer that works with the buyer's existing tools, brings unsupported applications under governance, automates schema and provisioning work, and avoids forcing a multi-year identity-platform replacement. That is commercially attractive but technically contestable. The moat will depend on integration coverage, reusable automation, deployment telemetry, safe handling of privileged credentials, low failure rates, and a data or workflow advantage that makes each new application cheaper to onboard than the last.
**Defense, security, and resilience dual-use relevance.** Way's core technology is directly relevant to cyber resilience because identity is the authorization boundary through which employees, contractors, service accounts, applications, and increasingly autonomous software reach sensitive systems. In a defense-industrial supplier, hospital network, manufacturer, utility, or government agency, an unmanaged legacy application can remain a durable path around otherwise strong MFA and access-governance controls. Extending lifecycle policy, access reviews, joiner-mover-leaver actions, and least-privilege remediation to those systems could reduce orphaned access, slow lateral movement, and improve the ability to revoke compromised identities during an incident. The same integration layer could help defense contractors govern mixed commercial and mission-support systems without rewriting every legacy application, subject to deployment and accreditation requirements. This is genuine dual-use cyber infrastructure, not a defense weapon or a demonstrated military capability. Way has not publicly disclosed government or defense customers, classified deployment, FedRAMP or equivalent authorization, air-gapped operation, or a contract with a military organization. Its strategic relevance should therefore be scored as credible resilience adjacency grounded in the product's control-plane function, with diligence focused on data residency, privileged-access architecture, offline or disconnected operation, cryptographic controls, auditability, and whether the company can meet public-sector procurement standards.
**Growth stage, trajectory, and key diligence risks.** Way is early stage but has advanced faster than a typical Seed company: it was founded in 2025, emerged from stealth in July 2026, raised $20 million, built a roughly 30-person team, and reported paying customers and sales in the United States and Europe. The next phase is to turn founder-led identity expertise and bespoke enterprise work into a repeatable platform. The trajectory is attractive if Way can convert each difficult integration into reusable product capability, expand from initial application onboarding into continuous identity operations, and become a partner that increases rather than threatens the value of incumbent IAM vendors. Key risks are material. First, integrations may remain services-heavy, limiting gross margins and making customer deployments difficult to scale. Second, an automation error that grants or revokes access incorrectly can cause a security incident or business outage, so precision, approval controls, and rollback must be tested. Third, Okta, Microsoft, SailPoint, Saviynt, CyberArk, and large integrators can respond through connectors, bundling, or professional services. Fourth, customers may resist giving a young vendor privileged access to identity infrastructure. Fifth, public traction is promising but opaque because revenue, retention, customer names, and independent benchmarks are undisclosed. Finally, the defense and critical-infrastructure thesis remains prospective. The strongest validation milestones are repeatable deployment-time reductions, audited security controls, independently referenceable customers, expansion revenue, and evidence that Way can operate safely in constrained environments.
Dual-Use Assessment
Way Security's core integration and enforcement layer has credible dual-use relevance because identity controls protect both commercial enterprises and the defense-industrial, government, healthcare, manufacturing, energy, and other critical systems on which resilience depends. (1) It extends MFA, SSO, lifecycle management, access reviews, and remediation into legacy or homegrown applications that often remain outside modern security policy. (2) It can help operators discover orphaned accounts, over-provisioned users, shadow applications, and risky entitlements, then shorten the path from identity compromise to containment. (3) The same vendor-agnostic approach could support defense contractors and public-sector estates that cannot replace mission-support software quickly. The boundary is important: Way is a commercial cybersecurity startup, not a defense prime, and public sources do not establish government customers, classified deployment, military contracts, FedRAMP-equivalent authorization, or operation in air-gapped environments. Its dual-use score therefore reflects direct cyber-resilience applicability and Israeli security expertise, tempered by the absence of demonstrated defense adoption and the need to validate privileged-access safety, auditability, data residency, and disconnected-environment operation.
Strategic Fit Assessment
Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.
Way Security is a strong internal priority signal for cyber-resilience diligence, but this flag is not an investment recommendation. (1) The problem is concrete and budgeted: enterprise IAM programs frequently stall at the integration boundary, where manual development and consulting can cost several times the software purchase. (2) The wedge is differentiated enough to test: Way complements existing identity platforms and seeks to productize the difficult work of reaching legacy and homegrown applications instead of asking buyers to rip and replace. (3) Early proof is stronger than a stealth thesis alone: the company raised $20 million from Insight Partners and Glilot Capital, employs about 30 people, and has reported paying customers and sales in the United States and Europe. (4) Founder-market fit is unusually direct because Yossi Barishev and Yonatan Rosenberg previously led IAM and incident-response work at Sygnia, with Barishev also having run security at Fireblocks and Rosenberg bringing Unit 8200 experience. Counterweights are equally important: no public revenue, retention, named customers, independent benchmark, or disclosed certification; a young platform is being trusted with privileged identity infrastructure; and the category is exposed to incumbents, system integrators, and services-heavy deployments. The diligence case turns on repeatability, gross-margin potential, integration safety, and whether Way becomes a scalable product rather than an AI-assisted consultancy.
Strategic Value to U.S.-Israel Alliance
Way's strategic value is concentrated in the identity-control layer that determines who can access sensitive systems and how quickly that access can be changed. (1) Resilience leverage: bringing legacy and homegrown applications under the same MFA, SSO, lifecycle, access-review, and remediation policies can close gaps that attackers exploit after a credential compromise. (2) Deployment leverage: a vendor-neutral enablement layer may help organizations obtain value from existing IAM investments without waiting years to rewrite or replace every application. (3) Critical-sector relevance: financial services, healthcare, manufacturing, defense suppliers, utilities, and government agencies all operate heterogeneous estates where unsupported systems can remain outside governance. (4) Ecosystem leverage: partnering with established identity vendors could let Way reach large installed bases while preserving a complementary position. Strategic confidence remains conditional because no defense or government deployment is public, and a control-plane product must prove secure privileged access, rollback, audit quality, disconnected-operation support, and accreditation readiness before it can be treated as a national-security asset.
Key Technologies
- AI-assisted application onboarding, schema analysis, and provisioning extensibility for heterogeneous enterprise systems
- Vendor-agnostic IAM integration layer spanning legacy, homegrown, disconnected, and non-standard applications
- Identity-policy enforcement for MFA, SSO, federation, and other native identity-provider controls on applications without modern authentication
- Lifecycle management and joiner-mover-leaver automation across broad application portfolios
- Identity-risk discovery for shadow IT, orphaned accounts, over-provisioned users, and risky entitlements
- Access-review and entitlement-remediation workflows designed to reduce manual identity operations
- Agentic workflow automation for identity integration and enterprise IAM operations
Use Cases & Applications
- Extending an existing Okta or Microsoft Entra IAM program to legacy and internally developed applications
- Automating joiner-mover-leaver provisioning and deprovisioning across a large enterprise application estate
- Applying MFA, SSO, or federation to applications that lack native modern-authentication support
- Discovering and remediating orphaned accounts and excessive entitlements in financial-services environments
- Completing identity-governance and access-review programs across healthcare and manufacturing systems
- Reducing custom connector and consulting work for enterprise IAM deployments in the United States and Europe
- Extending identity controls across defense-contractor and critical-infrastructure legacy estates, subject to accreditation and deployment validation
- Providing identity vendors and system integrators with an enablement layer for difficult customer environments
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.
This record lists 6 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- Way Security — The Integration Layer That Enforces Identity Everywhere Official company website verifying the product positioning, no-rip-and-replace model, legacy and homegrown application coverage, application onboarding, provisioning extensibility, schema analysis, lifecycle management, access reviews, MFA, SSO, identity-risk discovery, and entitlement remediation capabilities.
- Way Security wants to rebuild the foundation of enterprise identity Insight Partners' investor profile verifying the founders' problem framing, year of stealth, funding relationship, Yossi Barishev's prior Fireblocks security leadership, the founders' enterprise-security experience, identity and AI-agent context, and the company's complementary approach to existing identity infrastructure.
- Way Security raises $20 million Seed to tackle enterprise identity headaches Independent Israeli technology coverage verifying the $20M Seed round led by Insight Partners and Glilot Capital, 2025 founding, founders Yossi Barishev and Yonatan Rosenberg, approximately 30 employees, active customers in Europe and the United States, Sygnia backgrounds, and the legacy-IAM integration problem.
- חברת הסייבר Way Security גייסה 20 מיליון דולר מאינסייט וגלילות Calcalist's Hebrew report corroborating the funding, 2025 founding, approximately 30-person team, AI-based IAM operations, vendor-agnostic enforcement across legacy and internal applications, reported active customers, and the company's claim that it already has sales.
- Exclusive: Identity startup Way Security raises $20M Axios reporting verifying the $20M Seed, AI-driven automation and agentic workflows, partnerships with larger identity companies, and the report of dozens of paying customers in financial services, healthcare, and manufacturing.
- Way Security founders' public company and professional profiles Public company-profile source for corroborating Way Security's company identity and launch presence; used cautiously because LinkedIn does not independently verify customer, funding, or technical-performance claims.
- Profile update timestamp Last updated in the Claw & Talon database on Aug 31, 2026.
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.