Act Security Launches $60M Platform to Fix Cloud Access Sprawl

The News

Act Security just announced a cloud security platform alongside $60 million in total funding, comprising a $20 million seed round led by Team8 and Bessemer Venture Partners and a $40 million Series A led by Notable Capital. Founded in 2025 by the team behind Medigate (acquired by Claroty for $400 million), the Tel Aviv-based company is targeting what it calls “access sprawl” across cloud infrastructure. Rather than surfacing vulnerability findings for teams to triage, Act’s platform enforces deterministic access boundaries for humans, workloads, and AI agents, aiming to structurally remove the conditions that make breaches possible in the first place.

Analyst Take

The cloud security market has spent the better part of a decade building better dashboards. CSPM tools, vulnerability scanners, and posture management platforms have become extraordinarily good at telling organizations what is wrong. What they have not solved is the operational problem that follows: a security team staring at thousands of findings, triaging one by one, while attackers (or increasingly, AI agents) move faster than any human queue can drain. Act Security’s core argument is that the model itself is broken, and the $60 million backing that argument from Team8, Bessemer, and Notable Capital suggests the investment community agrees.

The Access Problem Is Structural, Not Operational

Act’s founding premise is that cloud access sprawl is the root cause most security tooling never actually touches. The company’s CEO cites an internal figure suggesting close to 97% of cloud access sits dormant and unused. That number is consistent with what ECI Research observes in the field: the problem isn’t just that permissions accumulate, it’s that they accumulate invisibly and then get inherited wholesale by AI agents operating at machine speed. This is the architectural gap Act is positioning to close. Instead of patching a vulnerability after it’s been flagged, the platform removes the access path that would make the vulnerability exploitable in the first place. For ITDMs, this reframes security spend from a cost of detection to a cost of prevention, a meaningful shift in how ROI conversations should be structured.

Why AI Agents Change the Threat Calculus

The timing of this launch is not incidental. AI agents are now running inside production environments with real credentials, inherited permissions, and no human judgment filtering their actions. Act’s explicit focus on enforcing boundaries around AI workloads could address an emerging attack surface that most existing cloud security platforms were not designed to handle. The company points to Anthropic’s Claude Mythos as evidence that frontier models can find and exploit access paths faster than any response team can react. That’s a credible argument. For security architects and platform engineers, the implication is clear: least-privilege enforcement can no longer be a periodic audit exercise. It needs to be continuous, automated, and deeply integrated into both identity and network controls simultaneously.

According to ECI Research’s 2026 Application Development: DevSecOps & AppSec survey, 29.1% of respondents selected “AI-generated package risk” as their biggest open-source security concern in 2026. That figure captures only one slice of AI-introduced risk, the dependency layer, but it reflects a broader organizational anxiety about AI expanding the attack surface in ways security tooling hasn’t caught up to. Act is positioning directly into that anxiety, with a product argument that goes beyond scanning to structural remediation.

The Competitive Landscape Is Not Empty

Act will face a well-funded competitive field, but what Act is claiming is architectural differentiation: reasoning across identity, network, and AI access simultaneously, rather than treating them as separate signal streams. That is a harder product to build but a more defensible one if executed well. The CI/CD pipeline integration the company describes, preventing new access violations from ever reaching production, is particularly relevant for developer-centric organizations that have already invested in DevSecOps workflows. ECI Research’s 2026 Application Development: Day 0 survey found that 47.4% of respondents selected “software supply chain security” as one of their top investment priorities for the next 12 months, which places Act’s pipeline enforcement capability squarely in the budget conversations happening right now.

The compliance angle also deserves attention. Act’s platform maps perimeter and data-boundary enforcement to NIST 800-53, PCI DSS, and HIPAA controls. In a regulatory environment where, per ECI Research’s 2026 Application Development: Day 1 survey, 54.7% of respondents cited NIST frameworks as a compliance pressure influencing release engineering, the ability to demonstrate continuous, audit-ready compliance rather than point-in-time attestation has real procurement weight.

Looking Ahead

Act Security’s emergence from stealth with $60 million already deployed signals that this is not a concept company. The founding team’s track record with Medigate, a medical-device security platform that scaled to a $400 million acquisition, suggests operational credibility in converting a novel security category into an enterprise sales motion. The next 12–18 months will test whether Act can translate its architectural argument into measurable outcomes that enterprise security buyers can put in front of a CFO. Customer case studies with quantified reduction in exploitable access paths, not just survey-style satisfaction scores, will be the proof points that determine Series B timing and valuation.

The broader market trajectory favors Act’s thesis. As AI agents proliferate across enterprise cloud environments, the gap between granted permissions and actually-needed permissions will widen, not narrow. Security teams that rely on reactive triage will fall further behind. Vendors that can enforce least privilege continuously and automatically, across the full identity-network-AI stack, are building toward a structural advantage. Act is making a credible bet that access architecture is the next major consolidation point in cloud security. If the AI agent deployment wave accelerates on the timeline most enterprise AI programs are targeting, that bet may pay off faster than the market currently expects.

Authors

  • Paul Nashawaty

    Paul Nashawaty, Practice Leader and Lead Principal Analyst, specializes in application modernization across build, release and operations. With a wealth of expertise in digital transformation initiatives spanning front-end and back-end systems, he also possesses comprehensive knowledge of the underlying infrastructure ecosystem crucial for supporting modernization endeavors. With over 25 years of experience, Paul has a proven track record in implementing effective go-to-market strategies, including the identification of new market channels, the growth and cultivation of partner ecosystems, and the successful execution of strategic plans resulting in positive business outcomes for his clients.

    View all posts
  • With over 15 years of hands-on experience in operations roles across legal, financial, and technology sectors, Sam Weston brings deep expertise in the systems that power modern enterprises such as ERP, CRM, HCM, CX, and beyond. Her career has spanned the full spectrum of enterprise applications, from optimizing business processes and managing platforms to leading digital transformation initiatives.

    Sam has transitioned her expertise into the analyst arena, focusing on enterprise applications and the evolving role they play in business productivity and transformation. She provides independent insights that bridge technology capabilities with business outcomes, helping organizations and vendors alike navigate a changing enterprise software landscape.

    View all posts