Hush Security has raised $30 million in Series A funding to expand its identity and access management platform as enterprises introduce AI agents into increasingly sensitive workflows.

Akamai Technologies (AKAM ) joined the round as a strategic investor, while existing backers Battery Ventures and YL Ventures increased their support. The financing brings Hush Security’s total capital raised to $41 million less than a year after the Tel Aviv-based cybersecurity company emerged from stealth.

Hush Security plans to use the capital to expand its engineering and sales teams, particularly in the United States, deepen integrations with enterprise identity and access management systems, and support a broader range of AI platforms and agentic technologies.

The investment reflects growing concern that AI agents are being given access to corporate applications, databases and infrastructure without the identity controls normally applied to employees or conventional software.

AI Agents Create a New Identity Problem

Enterprise AI agents are evolving from conversational tools into software capable of carrying out multistep tasks, calling external tools and taking actions across business systems.

To perform those duties, an agent may need access to source-code repositories, customer records, cloud infrastructure, internal communications or financial applications. In many deployments, that access is still provided through API keys, service accounts and other long-lived credentials.

The problem is not limited to whether an agent is authorised to enter a system. Companies must also determine which agent performed an action, which employee or application initiated it, what information it accessed and whether its permissions should still be active.

Hush Security argues that traditional identity systems were primarily designed around human users and relatively predictable software workloads. Autonomous agents behave differently. They may be created temporarily, operate on behalf of different users and connect to several tools while completing a single assignment.

Recent research has similarly identified identity authentication, dynamic permissions and execution-state verification as unresolved challenges for autonomous agents, particularly when their capabilities and operating context can change at runtime.

“Every company already knows how to manage identity for its people and its applications,” said Micha Rave, CEO and co-founder of Hush Security. “But now software acts autonomously, on its own initiative, inside your most sensitive systems. AI agents need strict identity, not just API keys.”

Replacing Standing Credentials With Runtime Access

Hush Security originally emerged from stealth in September 2025 with an $11 million seed round led by Battery Ventures and YL Ventures. At the time, the company focused on eliminating static credentials used by non-human identities, including automated workloads, service accounts and machine-to-machine connections.

Its platform replaces long-lived secrets with identity-based access that is evaluated when a machine or agent attempts to use a protected resource.

Under this model, an agent does not retain permanent access to every application it might eventually need. Hush Security can instead issue narrowly scoped permissions at runtime based on the agent’s identity, the user behind the request, the resource being accessed and the action being attempted.

This just-in-time approach is intended to reduce the damage that could result from a leaked credential, compromised agent or incorrectly configured permission. Access can expire after the task is completed rather than remaining available indefinitely.

Hush Security says the platform also records agent activity and provides a central mechanism for revoking access. Its broader non-human identity product is designed to cover workloads, automation pipelines, service accounts, AI agents and the secrets those systems traditionally use to communicate.

Discovering Agents and the Tools They Can Reach

The Series A coincides with an expansion of Hush Security’s platform specifically for enterprise AI agents.

The first part of that offering focuses on discovery. Hush Security is designed to identify desktop assistants, enterprise AI products and custom-built agents, including tools deployed without formal approval from security teams.

It then maps the systems each agent can reach, including applications, internal resources and Model Context Protocol servers. MCP provides a standardised way for AI applications to connect with tools and external data, but those connections can also broaden the range of actions an agent is capable of taking.

Once discovered, each agent can be registered and associated with existing corporate permissions. Hush Security combines the authority of the agent with the permissions of the person or application it represents, rather than treating the agent as an unrestricted intermediary.

Security teams can apply just-in-time access policies, review activity logs and use a kill switch to stop an agent’s access when suspicious or unintended behaviour is detected.

The platform is also intended to create an audit trail showing which agent initiated an action, the resources involved and the identity on whose behalf it was operating. That information can support compliance reviews and incident investigations while helping companies distinguish authorised automation from potentially malicious activity.

Akamai Adds a Strategic Security Partner

Akamai’s participation introduces a strategic investor with an extensive presence across internet infrastructure, application delivery and cybersecurity.

Ramanath Iyer, chief strategist at Akamai, described AI agents as another shift requiring companies to reconsider how enterprise systems are protected.

“Every major shift in internet usage and traffic has forced a rethink of how enterprises are secured,” Iyer said. “AI agents are driving the next transformation, and identity is the piece most companies haven’t solved yet.”

Hush Security has also disclosed a commercial relationship with Kyndryl, which has deployed the technology internally and begun offering it to enterprise customers.

Kyndryl’s involvement could give Hush Security another route into large organisations that are modernising complex infrastructure while experimenting with autonomous AI systems.

The platform is being positioned as a shared control layer covering both the agent and the infrastructure it operates within. That differs from AI security products focused primarily on model outputs, prompt filtering or detecting unsafe responses.

Hush Security instead concentrates on what an agent is allowed to do after it generates a response or decides on an action.

Founders Return After Meta Networks Acquisition

Hush Security was founded by members of the team behind Meta Networks, an Israeli zero-trust network access company acquired by Proofpoint in 2019.

Proofpoint agreed to pay approximately $111 million in cash for Meta Networks, with the acquired technology intended to strengthen its cloud access and security portfolio.

That background gives Hush Security’s founders experience building identity-based security controls for distributed enterprise environments. The company is now applying similar principles to a much larger population of non-human actors.

Rather than assigning persistent credentials to every service, workload and agent, Hush Security is betting that access will increasingly be brokered dynamically and tied to a verifiable identity.

The approach will need to integrate with the identity platforms, cloud services and AI development tools that enterprises already use. Hush Security said part of the new funding will therefore be directed towards deeper support for enterprise identity and access management products and agentic ecosystems.

Identity Becomes a Control Layer for Agentic AI

The market for AI agent governance is attracting established identity vendors, cybersecurity companies and a growing group of specialised startups.

Hush Security’s challenge will be demonstrating that its secretless architecture can be adopted without creating new operational friction for developers or slowing down the agents it is intended to control.

Its opportunity comes from the same issue. Enterprises want AI systems that can take meaningful action, but those systems become useful only after they are connected to valuable data and applications.

That makes access management one of the central questions surrounding enterprise agent deployment. An agent that cannot reach corporate systems has limited utility. One with broad, permanent access creates a different kind of risk.

With Akamai joining Battery Ventures and YL Ventures, Hush Security now has additional capital and strategic support to build the identity infrastructure between those two extremes. Its proposed solution is to give agents the access required for a specific task, record what they do and remove that authority when it is no longer needed.