Act Security has emerged from stealth with $60 million in funding and a cloud security platform designed to reduce the access paths that allow attackers to move through enterprise infrastructure.
Founded in 2025 by members of the team behind healthcare cybersecurity company Medigate, Act Security is entering the market with a $20 million seed round and a $40 million Series A. Team8 and Bessemer Venture Partners led the seed round, with participation from Hetz Ventures and Claltech. Notable Capital led the Series A, joined by Startpoint Capital and the Silicon Valley CISO Investments syndicate.
Rather than adding another layer of vulnerability alerts, the company is concentrating on the permissions, network connections, and infrastructure relationships that determine what a compromised identity can actually reach.
Moving Beyond Cloud Security Alerts
Cloud security platforms have become increasingly effective at finding exposed services, vulnerable software, excessive permissions, and configuration mistakes. The difficulty is that security teams can receive thousands of findings without a practical way to address all of them.
Act Security is approaching the problem from a different direction. Instead of treating every vulnerability as an isolated remediation task, the platform attempts to remove the access paths that would make those vulnerabilities useful to an attacker.
This involves analyzing identity permissions and network reachability together. An identity may technically have permission to access a resource, for example, but an attacker also needs a viable network path to reach it. Conversely, a reachable workload may remain protected when authorization controls prevent meaningful access.
Act Security combines these layers to establish cloud perimeters around users, applications, workloads, and AI agents. Its Microsoft Azure offering can model effective permissions across Microsoft Entra ID, Network Security Groups, and virtual network policies, simulate proposed changes before enforcement, and apply least-privilege controls through existing Azure infrastructure.
Why AI Agents Make Excessive Access More Dangerous
Excessive cloud permissions are not a new problem, but AI agents could make the consequences more immediate.
Act Security says its analysis of customer environments indicates that close to 97% of granted cloud access is dormant or unused. These permissions may have accumulated as employees changed roles, applications evolved, temporary projects became permanent, and service accounts received broader access than necessary.
The introduction of AI agents adds another class of identity to this environment. Agents may inherit the permissions of human users or existing service accounts while operating continuously and executing actions much faster than a person could.
This creates risks even when an agent is functioning as intended. An incorrectly configured agent could access sensitive systems outside its intended role, while a compromised agent could give an attacker a fast-moving route through connected cloud resources.
Act Security’s platform is intended to place defined access boundaries around each agent, limiting it to the data, services, and infrastructure required for its assigned task. The broader objective is to prevent an agent from using inherited permissions to move laterally across an organization.
Enforcing Boundaries Through Existing Cloud Controls
The platform does not rely solely on producing recommendations for security teams to review. It is designed to continuously enforce access boundaries through cloud-native controls and other security systems that customers already operate.
Before applying a policy, organizations can simulate its impact to determine whether the change could interrupt a legitimate application or business process. This step is important because overly aggressive access restrictions can cause outages just as easily as weak controls can create security gaps.
Act Security can also extend these policies into continuous integration and continuous deployment pipelines. New infrastructure configurations can therefore be evaluated before they reach production, reducing the likelihood that access sprawl will immediately return after an initial cleanup.
The company is also positioning the platform as a preventative layer that complements existing detection and response products. Its AWS Marketplace profile describes the technology as infrastructure-level threat prevention rather than a replacement for tools that monitor active attacks.
The Medigate Team Returns to Cybersecurity
Act Security is led by co-founder and CEO Jonathan Langer, who previously co-founded Medigate, a security company focused on connected medical devices and healthcare infrastructure.
Medigate developed technology for discovering and securing clinical assets operating across hospital networks. Claroty completed its acquisition of the company in January 2022, combining Medigate’s healthcare expertise with a broader platform for securing industrial, enterprise, and healthcare cyber-physical systems.
That experience is relevant to Act Security’s current strategy. Medical environments contain large numbers of connected devices, specialized protocols, legacy systems, and operational processes that cannot tolerate disruption. Cloud infrastructure presents a different technical environment, but it creates a similar requirement to improve security without interfering with critical systems.
The founders are now applying that experience to a wider cloud access problem, including the growing number of non-human identities created by applications, automated workloads, and AI agents.
Turning Prevention Into an Operational Product
The $60 million in funding gives Act Security substantial early backing, but the company is entering a crowded cloud security market. Major cybersecurity platforms already provide combinations of cloud security posture management, identity security, entitlement management, workload protection, and attack-path analysis.
Act Security’s differentiation will depend on whether it can move reliably from identifying risky access to enforcing safer infrastructure without introducing operational friction.
That will require accurate modeling of legitimate business activity, support for rapidly changing cloud environments, and close integration with the controls used across different cloud providers. Organizations will also need confidence that automated policy changes will not block developers, applications, or emergency access procedures.
Policy simulation and gradual enforcement could help address those concerns, but the platform’s long-term value will ultimately depend on measurable reductions in exploitable access rather than the number of findings it can generate.
Securing the Infrastructure Behind AI Adoption
As enterprises deploy more autonomous software, cloud security is likely to become increasingly tied to identity and authorization. AI agents may act like applications, employees, and automated administrators at the same time, making conventional distinctions between human and machine access less useful.
Act Security’s launch reflects a broader shift toward controlling what every identity can reach before an intrusion occurs. Instead of assuming security teams can patch every weakness or investigate every alert, the platform is built around limiting the potential impact of a compromised account, workload, or agent.
The approach will now be tested in production environments where access requirements change constantly. Should it prove capable of enforcing those boundaries without disrupting legitimate activity, action-centric security could become an important component of how organizations manage cloud infrastructure in the AI era.