Act Security exits stealth with $60M to shrink what compromised agents can reach
The Medigate alumni raised a seed and a Series A before anyone knew the company existed. Their thesis: AI finds holes faster than humans can patch, so shrink the blast radius instead.
Act Security emerged from stealth on Tuesday, July 28, with 60 million dollars already raised across two rounds: a 20 million dollar seed led by Team8 and Bessemer Venture Partners, with Hetz Ventures and Claltech participating, and a 40 million dollar Series A led by Notable Capital with Startpoint Capital and the Silicon Valley CISO Investments syndicate. Raising a Series A before a launch press release is a statement in itself, and the CISO syndicate on the cap table suggests the buyers were in the room early.
Action-centric, not alert-centric
The company, founded in 2025 by members of the team behind healthcare-security firm Medigate, describes its product as 'action-centric' cloud security, per its launch announcement. Instead of generating another queue of vulnerability alerts, the platform reduces the permissions, network connections and infrastructure relationships that a compromised identity can actually reach. The underlying claim is that organizations carry enormous access sprawl; the vast majority of granted cloud permissions go unneeded and unused, the company says. That figure is Act's own framing rather than an independent audit, but the direction of the claim matches what most cloud security practitioners will privately concede about their own environments.
The agentic thesis
What separates this launch from a generic cloud security pitch is that its stated reason for existing is agentic. As SecurityWeek reported, the founding thesis is that AI's ability to discover vulnerabilities is spiraling the patch problem beyond human remediation capacity. If automated systems can find holes faster than security teams can close them, then racing to patch is a losing game, and the rational move is to limit what any single compromised identity, human or machine, can do. That logic applies with particular force to AI agents, which are identities that hold credentials, call APIs and act at machine speed. An over-permissioned agent is the same problem as an over-permissioned employee, multiplied by throughput.
The industry has been converging on this from several directions. Identity vendors are building agent-specific controls, as we covered in Okta's agent identity rollout, and the cost of getting it wrong was on display when Hugging Face demanded 100 million dollars from OpenAI after an agent-linked breach. Act is betting that the durable layer is not agent authentication but the map of what each identity can touch once authenticated.
A crowded day for security money
Act did not launch into a quiet news cycle. July 28's funding announcements were dominated by AI-security and control-plane rounds, and the pattern across them is consistent: investors are funding the layer that makes autonomous systems safe to deploy, on the theory that enterprise agent adoption stalls without it. Sixty million dollars for a company that spent its first year in stealth is a bet that CISOs will treat blast-radius reduction as a prerequisite for agent rollouts, not an add-on.
For the agentic AI as a service market, that is the takeaway. Every GaaS vendor selling operated agents into an enterprise is implicitly selling the customer a new population of privileged identities, and security review is already the longest gate in agent procurement. Platforms that can show tight, provably minimal permission footprints will clear those reviews faster than platforms that ask for broad access and promise good behavior. Companies like Act are building the tooling that will make that difference measurable. If the action-centric framing catches on, expect agent permission audits to become a standard line in enterprise GaaS contracts within a few quarters.