Way Security has raised $20 million in a seed funding round co-led by Insight Partners and Glilot Capital, backing the cybersecurity startup’s effort to automate one of the most expensive and labour-intensive parts of enterprise identity and access management.
Founded in 2025 by CEO Yossi Barishev and CTO Yonatan Rosenberg, Way Security is developing an AI-powered platform that helps organizations deploy and operate the identity infrastructure they already own. The company is not trying to replace established identity providers. Instead, it is targeting the implementation work, custom integrations and ongoing operational processes that frequently cause identity projects to run over budget and remain incomplete.
The company currently employs approximately 30 people and plans to use the funding to expand its presence in the United States while continuing to develop its identity operations platform.
Addressing the Work That Begins After IAM Software Is Purchased
Identity and access management, commonly known as IAM, governs who or what can access an organization’s applications, systems and data. The category includes technologies such as single sign-on, multi-factor authentication, identity governance, access reviews and employee lifecycle management.
Purchasing those systems, however, is only the beginning.
Large organizations may have thousands of applications accumulated through acquisitions, internal development and years of technology upgrades. Some support modern identity standards, while others rely on older authentication methods or custom access controls. Connecting all of them to a central identity system can require extensive engineering, consulting and coordination with application owners.
Way Security estimates that implementation, customization and continuing operational work can cost enterprises three to five times more than the underlying IAM software. These projects can also extend over several years while delivering less coverage than originally planned.
The company is positioning its software as an alternative to handling this work through large consulting engagements and highly manual internal projects.
“The issue isn’t that enterprises lack the right tools,” Barishev said. “It’s that those tools are incredibly expensive and complex to operationalize. We built Way Security to remove that friction.”
An Agentic Execution Layer for Identity Operations
Way Security uses AI-driven automation and agentic workflows to handle identity operations that would otherwise require consultants, system integrators or internal engineering teams. The platform works alongside an organization’s existing identity governance, identity provider and authentication systems, extending controls such as single sign-on, multi-factor authentication, lifecycle management and access reviews to legacy, internally developed and custom applications that may not support standard federation protocols.
The software is also designed to identify risks hidden inside individual applications, including orphaned accounts, excessive privileges, unmanaged access and outdated entitlements. Rather than simply recommending changes, its agents can execute defined workflows for account cleanup, policy enforcement and access governance, helping organizations expand IAM coverage without replacing their existing identity infrastructure.
Extending Identity Controls to Difficult Applications
One of the recurring challenges in enterprise IAM is achieving consistent coverage.
Modern cloud applications often integrate readily with identity providers through standards such as Security Assertion Markup Language or OpenID Connect. Older and proprietary applications may not. As a result, employees can receive a streamlined authentication experience for newer software while continuing to use separate credentials and manual access processes elsewhere.
These gaps create operational work for IT teams and make it harder for security departments to enforce uniform policies.
Way Security’s approach is to create an integration layer capable of applying identity controls regardless of how an application was originally built. According to the company, this can allow organizations to extend authentication, lifecycle management and access governance across a broader portion of their environment without modifying each application individually.
The model could be particularly relevant for large financial institutions, healthcare organizations and other enterprises that operate a mixture of cloud services, on-premises infrastructure and internally developed software.
Way Security says it is already working with enterprise customers in several industries, including Fortune 500 companies, financial institutions and global healthcare organizations.
What Automated Identity Operations Could Change
Way Security plans to use the new capital to expand its presence in the United States and continue developing its platform.
The broader significance of this type of software lies in its potential to change how identity programmes are implemented and maintained. Rather than treating every application connection, access review or account-cleanup process as a separate consulting project, enterprises could increasingly use software agents to perform defined operational tasks across their existing identity infrastructure.
This would not eliminate the need for security teams or specialist oversight. Identity policies still require human judgement, particularly when access decisions involve sensitive data, regulatory requirements or unusual business processes. However, automating repetitive implementation and maintenance work could allow those teams to concentrate on higher-risk decisions instead of routine configuration.
As enterprise environments continue to grow more fragmented, the effectiveness of this model will depend on whether automated systems can work consistently across modern cloud platforms, legacy applications and internally developed software. Way Security’s progress will offer an early indication of whether agentic automation can make identity operations more scalable without introducing new layers of complexity.