All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Above Security sells an insider threat platform whose AI agents watch employee and AI agent behavior across identity, endpoint, SaaS, and AI tools. The agents turn each finding into a case for security, HR, and legal teams at organizations of 1,000 or more employees. Founded in 2025, it had 10 employees and $50 million in funding by March 2026, led by Ballistic Ventures, Merlin Ventures, and Norwest. Its customer references are security leaders quoted on its site, and it has not disclosed customer or revenue figures. CrowdStrike, AWS, and NVIDIA named it runner-up in their 2026 startup accelerator. Its accumulated data is a behavioral baseline serving each customer alone. The engineering that lets its agents judge intent across those systems is what a rival would take longest to rebuild.
| Description | Above Security builds a managed insider threat platform whose fleet of AI investigative agents analyzes human and AI agent behavior across identity, endpoint, SaaS, and AI environments and delivers investigations that security, legal, and HR teams can act on. | [f1] |
|---|---|---|
| Founded | 2025 | [f2] |
| HQ | San Francisco, California, US and Tel Aviv, Israel | [f1] |
| Funding | $50M total | [f1] |
| Latest funding | Series A, $43M (March 2026) | [f2] |
| Product | What it does |
|---|---|
| Above | Runs specialized investigative AI agents, five named on the site as of July 2026, producing structured investigations with role-scoped views for security, HR, and legal teams. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Above watches user and AI agent behavior across SaaS, endpoint, and identity systems, intervenes in risky actions, and produces investigation narratives for insider threats. The company is mapped to the Cyber Defense Matrix. [f1]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | The pain that DLP fires on movement and UEBA on baselines while agents read in place is qualitative, and CTech is the single non-vendor source describing rising internal risk, so the problem is present but not independently quantified. [s7, s4, s8] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 3/5 | The vendor names five specialized investigative agents on its homepage as of July 2026, an intent-scoring Arbiter engine, and a single investigation case that security, HR, and legal act on together, and the CrowdStrike runner-up citation independently describes the alert-replacement mechanism. No documentation portal, trial, or third-party technical evaluation is public, and the trust center that was live in June no longer resolved when probed in early July 2026. [s1, s2, s7, s13, s14] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | The enabler is the wave of autonomous AI agents reading corporate data under employee OAuth grants, which CTech documented in 2026, but the RSAC accelerator placement, press awareness, and Insider Threat Matrix sponsorship are recognition rather than buyer-side demand, and the agentic-insider urgency is largely vendor-argued. [s13, s8, s11, s7, s4] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 | The Ctrl exit and Trullion are not established as in-domain security builds in the cited coverage, and Boldo's Silverfort role is a senior in-domain post rather than a founder-led security exit, so the bench is strong pedigree at the present bar. [s3, s8, s7] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 | One named customer voice exists, Merlin Entertainments CISO Matt Wilmot inside the vendor’s own release, alongside vendor-stated revenue from six months of selling and Ballistic’s account of customers operational in minutes to hours. Named references in independent coverage are absent, which holds the score at adequate. [s7, s10, s8] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 2/5 | Fifty million dollars raised within eight months by a ten-person company materially outruns one named customer and vendor-stated revenue with no disclosed figure, an outsized raise against verifiable results that the deployment claims do not rescue. [s8, s7] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Insider risk management is an established budget line, and third parties place Above in it without coaching, with CrowdStrike’s release describing the company as managing insider risk and CTech filing it under insider threats. The vendor’s investigation-not-detection framing cites Gartner category guidance in the vendor’s own voice. [s13, s8, s6] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Continuous cross-system intent reasoning that replaces alerts with investigations is more than a quarterly feature for rule-based DLP and UEBA incumbents, and the agentic-insider coverage extends ahead of their current scope. No data flywheel, compliance position, or channel shows in fetched sources, and Microsoft ships bundled insider-risk tooling to the same buyers. [s4, s2, s7] |
Above Security defines insider risk as an investigation problem rather than a detection problem, and it names its buyer precisely. The funding release states that the platform targets organizations with 1,000 or more employees operating in SaaS-forward environments, and the product is built so that security, HR, and legal teams consume the same investigation in role-scoped forms. That three-department framing matches how insider cases actually conclude, in HR action or legal process rather than in a SOC queue.
Independent press corroborates the problem in its own voice. CTech reports that enterprises struggle with rising internal risk and that the definition of an insider is expanding beyond human employees as organizations deploy autonomous systems. Dror Nahumi of Norwest, quoted in the funding release, describes insider threats as among the most critical and under-addressed challenges in cybersecurity, an investor voice rather than an independent measure.
The AI-agent expansion is the company’s sharpest problem claim, and it is mechanically specific. Aviv Nahum argues that AI agents are becoming insiders in everything but name, and the vendor’s agentic AI page walks through the failure concretely, since an agent granted OAuth scopes reads corporate data at API speed on its vendor’s servers, where DLP sees no movement and UEBA sees no user-baseline deviation. [s7, s2, s8, s4]
A fleet of named investigative agents is the platform’s core design. As of July 2026 the homepage names five specialized agents, Shadow AI & IT, Data Exfiltration, Flight Risk, Inappropriate Use, and Communications, each described as purpose-built to detect a specific class of threat and together covering SaaS, endpoint, identity, and AI surfaces. The funding release adds the Arbiter engine, which the company says determines intent by correlating behavioral signals the way a human investigator would.
The investigation document is the unit of output, replacing the alert. The platform page presents each finding as one case with a behavioral timeline, contextual analysis, a risk verdict, and recommended actions, built so that security, HR, and legal act together on the same artifact. The about page adds real-time intervention, stating the product politely intervenes and stops risky actions before they happen.
Deployment claims are aggressive and partially corroborated by the lead investor. The funding release describes enterprises deploying in minutes without writing a single policy, rule, or configuration, and Ballistic Ventures writes that most Above customers are operational in minutes to hours with tuning that requires almost no effort.
Public technical depth lags the claims. The site offers no documentation portal or self-service trial, and the trust center that anchored the assurance story in June no longer resolved when probed in early July 2026. The clearest external validation is the CrowdStrike release citing Above for replacing alerts with full investigative narratives. [s1, s2, s7, s3, s10, s13, s14]
Above positions against the rules-and-anomalies generation by name. The homepage contrasts itself with DLP, access management, SIEM and SOAR, UEBA, and CASB, claiming intent understanding where those tools apply static policy, anomaly baselines, or alert orchestration. CTech repeats the core distinction in its own voice, noting the platform does not rely on predefined rules.
The incumbents it must displace are bundled or entrenched. Microsoft sells Purview Insider Risk Management inside Microsoft 365 compliance suites, Proofpoint and DTEX Systems hold dedicated insider-threat budgets, and Teramind serves the monitoring-centric end of the market. Above’s counter is that those tools produce breadcrumbs that still require a human investigation, the labor its agents replace.
The agentic-insider coverage is the differentiated foothold. Above treats an AI agent acting on an employee’s OAuth grant as a class of insider and investigates its behavior alongside the human’s, surface that rule-based incumbents do not yet model. CrowdStrike’s judges singled out exactly this proactive, narrative-producing approach when naming the company accelerator runner-up. [s1, s8, s4, s13]
Traction claims are early and mostly vendor-voiced. The funding release reports substantial revenue across the company’s first six months and quotes one named customer, Merlin Entertainments CISO Matt Wilmot, who credits Above with surfacing critical incidents within five days. The homepage shows a small logo wall under a Trusted by heading including Rogo, and carries titled CISO testimonials, yet no customer speaks in independent coverage.
Investor and program endorsement is the strongest independent signal. Ballistic Ventures, Merlin Ventures, and Norwest led $50 million across seed and Series A within eight months of founding, with Jump Capital and QPV Ventures participating, and CrowdStrike, AWS, and NVIDIA selected the company for their 2026 accelerator and then named it runner-up at the RSAC pitch day.
The motion is founder-led enterprise sales on a ten-person team. The founders front all press, the site sells a demo that assembles an investigation on the buyer's own data rather than a trial, and the funding release notes established integrations with CrowdStrike and others across identity, endpoint, and SaaS environments. No marketplace listing, reseller, or MSSP program appears in fetched sources. [s7, s1, s8, s12, s13, s2]
Both founders bring verifiable prior builds, and one maps directly onto the problem domain. CEO Aviv Nahum co-founded Ctrl and served as its CTO until Sana acquired it, with Workday later acquiring Sana, and CPTO Amir Boldo founded Trullion, served as founding SVP of R&D at identity-security vendor Silverfort, and held a VP role at DriveNets. CTech states in its own voice that both are seasoned entrepreneurs with prior exits and veterans of Unit 8200 branches.
Bench depth beyond the founders is invisible. CTech’s headline counts ten employees at the Series A, no other executives are publicly named, and the company carries a production platform, a managed offering, and an enterprise sales motion on that headcount. [s3, s8, s7]
Above stood up a trust center at trust.above.security with substantive collateral for a vendor this young. As captured on June 18, 2026, the center showed a SOC 2 Type 2 compliance badge and gated a SOC 2 report, a Sayfer Security pen-test report, privacy and security whitepapers, and a data flow diagram behind an access request. When probed on July 2, 2026, the subdomain no longer resolved and the served marketing site carried no trust link, so that collateral is a captured record rather than a page buyers can reach.
The genuine gaps sit around the attestation. No standalone ISO 27001 certification of Above's own showed in the captured record, no public vulnerability-disclosure policy appears in fetched sources, and the pen-test evidence was gated behind the access request rather than published.
Privacy resistance is a structural sales risk the company itself anticipates. The homepage frames intervention as coaching rather than consequences, and sentiment analysis across every collaboration channel will draw works-council and privacy-regulator scrutiny in European deployments. A months-old vendor requesting this telemetry should expect long counterparty reviews until references accumulate, and the SOC 2 attestation that answered procurement's initial questions currently has no public home.
Community positioning reinforces the trust collateral. Above is the inaugural sponsor of the Insider Threat Matrix, the open framework maintained by Forscie, a program limited to six annual sponsorships, which aligns the brand with practitioner-owned investigation vocabulary. [s14, s1, s2, s11, s5]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Microsoft | competes with | Purview Insider Risk Management ships inside Microsoft 365 compliance bundles many of Above’s target buyers already license. | N/AMicrosoft is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product. |
| Proofpoint | competes with | Sells dedicated insider threat management tooling to the same enterprise security buyer. | |
| DTEX Systems | competes with | Insider risk management platform built on workforce behavioral telemetry. | |
| Teramind | competes with | Employee monitoring and insider threat detection for the monitoring-centric end of the market. | |
| Cyberhaven | adjacent | Data lineage and data detection and response that overlaps Above’s exfiltration coverage from the data side. |
Add analyzed competitors to compare them side by side with Above Security.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
pivot urgently
Above is defensible where the work is hard and exposed where nothing has accumulated yet. Continuous intent reasoning across SaaS, endpoint, identity, and AI telemetry is years-deep engineering under adversarial pressure, and customers who route security, HR, and legal casework through its investigation documents face real friction if they leave. Against that, SOC 2 is table-stakes rather than blocking, and no proprietary corpus, network effect, or channel blocks a well-funded copycat, while the 1,000-employee threshold targets large buyers without guaranteeing regulated ones. The durable version of this company turns per-tenant behavioral baselines and investigative know-how into an asset an incumbent cannot bundle away, and that asset does not yet show in the public record.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Automated software agents assemble the investigation cases, and the managed framing does not by itself put vendor personnel or liability behind the results: no human judgment layer or liability acceptance appears in the public record, so the customer's team owns the outcomes. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Per-tenant behavioral baselines, integrations across identity, endpoint, and SaaS systems, and investigation workflows shared by security, HR, and legal build meaningful friction over time, while no network effect or residency lock appears in fetched sources. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | Above showed a SOC 2 Type 2 attestation at its trust center as captured in June 2026, table-stakes assurance that eases procurement without blocking substitutes, and no compliance regime mandates this product class. No standalone ISO 27001 certification shows in fetched sources, so the collateral is a feature, not a moat. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Continuous behavioral reasoning across systems and weeks of time, intent scoring that replaces rules and baselines, and real-time intervention at machine pace is specialized ML and real-time engineering under adversarial pressure, not a weekend build. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 | Targets are organizations with 1,000 or more employees, where procurement and legal review gate deals, but no fetched source shows a concentration of regulated-industry or government customers. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Above spans telemetry domains and pushes investigations into the customer's existing stack as a cross-departmental system of record, more than a single-use application but not infrastructure other software depends on. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | Above's only accumulating asset is each tenant's behavioral baseline, which is tenant-specific and rebuildable by a patient rival from the same telemetry. No cross-customer dataset or licensed corpus is claimed, so the data position is replicable rather than a proprietary non-public moat. |
Above names its segment with unusual precision for a stealth-stage vendor. The funding release states the platform targets organizations with 1,000 or more employees operating in SaaS-forward environments, which selects for companies whose collaboration, identity, and AI telemetry already flows through cloud systems the agents can read. The persona design is the distinctive choice, since the same investigation serves the security analyst, the HR partner, and counsel as one shared case, so the product courts three departments rather than one buyer.
The newest public proof of demand dates to the March 2026 stealth exit, and the homepage now carries several named security-leader testimonials, including CISO Oren Gur, whose card carries an unnamed company logo, and Yoni Kaplansky, a head of cyber architecture whose card carries the FICO logo file, alongside the Merlin Entertainments CISO quote the funding release first surfaced. The funding release and Ynet's launch coverage both carry the Merlin Entertainments CISO's described deployment outcome, while deployment coverage beyond that launch-day account remains absent, the freshness gap to watch, but the named-reference base has grown beyond a single customer.
Geography follows the founding story. The release carries a San Francisco and Tel Aviv dateline, CTech and Ynet cover the company as Israeli-founded, and the visible motion is US enterprise sales on Israeli engineering, the standard pattern for this cohort.
The claimed pain is specific and the claimed mechanism is consistent everywhere it appears. Above argues that DLP fires on data movement while agents read files in place, and that UEBA baselines never capture programmatic reads, so both miss the modern insider. Every fetched description, vendor and press alike, gives the same answer, a fleet of specialized investigative agents and an Arbiter engine that scores intent by correlating behavioral signals across systems and time, and as of July 2026 the homepage names five such agents, spanning shadow AI and IT, data exfiltration, flight risk, inappropriate use, and communications sentiment.
The claimed AI advantage is patient cross-system correlation no human team can staff. The platform page pitches the agents as doing everything an analyst would, automatically, with every signal investigated and no detection rules to write, the workload no human team scales to. No proprietary corpus or cross-customer data advantage is claimed in fetched sources, so the accumulating asset is each tenant's behavioral baseline. A latent flywheel sits one step past it, since the sponsorship announcement says the platform speaks the Insider Threat Matrix's behavioral language, a vocabulary alignment that could one day seed cross-tenant intent signatures, and the public record evidences no such shared corpus today.
Public recognition rests on third parties rather than published efficacy evidence. CrowdStrike's release describes the alert-replacement mechanism in its own words when naming Above runner-up, and Ballistic reports customers finding latent issues immediately. The vendor offers a demo that assembles an investigation on the buyer's own data but publishes no documentation, sandbox, or benchmark.
Above runs founder-led enterprise sales with a demo as the entry point. The site offers no trial, no free tier, and no published pricing, and the platform page sells a demonstration that assembles an investigation on the buyer's own data. Both founders are quoted in the launch coverage, which fits a ten-person company that reports substantial revenue without naming its sales organization, and matches the stage where founder-led selling is the healthy signal rather than the warning.
Where buyers encounter Above without the vendor selling is recognition programs, not channels. CrowdStrike, AWS, and NVIDIA selected the company for the 2026 accelerator and named it runner-up at the RSAC pitch day, and the Insider Threat Matrix sponsorship puts the brand inside the framework practitioners use for investigations. The site now advertises reseller and technology-alliance programs on a Partners page, though no fetched source documents partner counts or channel-sourced deals, so the demonstrated motion remains direct.
The integration surface hints at the eventual channel story. The funding release notes established integrations with CrowdStrike and others across identity, endpoint, and SaaS environments, proximity that the accelerator relationship reinforces, but none of it yet amounts to a channel an incumbent would have to buy past.
Above publishes no pricing, which signals negotiated enterprise deals and a sales-assisted motion. The unit the company charges by is not disclosed in any fetched source, and for a managed offering that unit will define the business, since per-employee pricing would track how buyers measure their insider population while outcome-based pricing would track the investigation service the marketing promises.
The managed framing invites comparison against the cost of staffing an investigation team rather than a software line item. Ballistic's investment note argues that only highly regulated banks or intelligence-grade organizations could historically afford fully staffed insider risk programs and that Above gives every organization the effect of a highly trained investigation team. That comparison invites buyers to price the product against analysts they will not hire rather than against tooling line items, the more defensible anchor if the claim holds.
Cost behavior at AI scale is the open pricing question. Continuous agentic analysis of communications and behavior carries real inference costs, and no fetched source addresses how consumption translates into the customer's bill or the vendor's margin.
Near-zero-configuration deployment is the operational claim and the lead investor corroborates it. The funding release describes enterprises deploying in minutes without writing a single policy, rule, or configuration, and Ballistic writes that most customers are operational in minutes to hours with tuning that requires almost no effort. The product plugs into the stack the customer already runs, with a published integrations catalog spanning identity, endpoint, cloud, SaaS, AI, and people systems.
Trust and procurement collateral caught up in June 2026, even where operational documentation had not. The trust center captured on June 18 showed a SOC 2 Type 2 attestation and a public risk profile with a four-hour recovery time objective, and it gated a SOC 2 report, a pen-test report, whitepapers, and a data flow diagram behind an access request, though the subdomain no longer resolved when probed on July 2. What still does not appear publicly is an SLA, a status page, an uptime commitment, or self-serve deployment documentation, and enterprises that route insider investigations through a vendor will demand those answers in procurement even when onboarding is genuinely instant.
The telemetry the product handles raises the delivery bar further. Reading communications tone and AI conversations means the data-handling architecture, retention, and residency posture will face scrutiny that ordinary security telemetry does not, and the captured trust collateral answered only part of it, so retention and residency positions still ride on the sales conversation.
Above stood up a trust center at trust.above.security that answered the questions its data access provokes. As captured on June 18, 2026, it carried a SOC 2 Type 2 badge and gated a SOC 2 report, a pen-test report, privacy and security whitepapers, and a data flow diagram behind an access request, and its public risk profile set the data-access level at restricted, impact at moderate, and the recovery time objective at four hours.
The subdomain no longer resolved when probed on July 2, 2026, and the served marketing site carries no trust link, so the collateral is a captured record rather than a live artifact. The other gaps stand as before, since no standalone ISO 27001 certification of Above's own showed in the captured record, no public vulnerability-disclosure policy appears in fetched sources, and the pen-test evidence was gated rather than published.
The company anticipates the surveillance objection rather than avoiding it. The homepage frames intervention as coaching rather than consequences, and the about page states the product politely intervenes and stops risky actions before they happen, positioning that acknowledges where deals will stall. Works councils and privacy regimes in European deployments remain the structural test no fetched source addresses.
The Insider Threat Matrix sponsorship is a further trust investment. Backing Forscie's open, practitioner-built framework as its inaugural sponsor, holding one of the program's six sponsor slots on a twelve-month renewable term, aligns the company with vendor-neutral investigative vocabulary and buys community standing alongside the attestations the trust center carried.
Above positions as the system of record for insider investigations rather than as infrastructure. The integrations catalog brings telemetry in from identity, endpoint, cloud, SaaS, AI, and people systems, and the single investigation case gives security, HR, and legal a shared artifact, which embeds the product in cross-departmental workflow without making other software depend on it.
The ecosystem play runs through the CrowdStrike orbit and the open framework. The funding release names established integrations with CrowdStrike and others across identity, endpoint, and SaaS environments, the accelerator relationship deepens that proximity, and the Insider Threat Matrix sponsorship ties the product's vocabulary to the framework practitioners are adopting for investigations.
A Partners page advertising reseller and technology alliances now appears on the site, while no API documentation or marketplace listing appears in fetched sources, so platform ambitions currently rest on integration breadth and community positioning rather than on third parties building against Above.
The founding pair brings prior exits and one directly relevant operating run. CEO Aviv Nahum co-founded Ctrl and served as its CTO until Sana acquired it, with Workday later acquiring Sana, and CPTO Amir Boldo founded Trullion and served as founding SVP of R&D at Silverfort, identity-security experience adjacent to the insider problem, plus a VP role at DriveNets. Both are veterans of Unit 8200 branches, Unit 81 and Unit 49, per CTech's own-voice reporting.
Ten people carry the entire mandate. CTech counts ten employees at the Series A, and that team runs a production platform, a managed insider-threat offering, founder-led enterprise sales, and a sponsorship program simultaneously. The $50 million the investors committed against that headcount reads as conviction in the founders specifically, and the next hires will show whether the bench grows toward the managed-service promise or toward product engineering.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Above Security funding press release (PRNewswire, March 23, 2026) | press | 2026-06-11 |
| f2 | CTech on the Above Security Series A (March 23, 2026) | press | 2026-06-11 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Above Security homepage “Insider threat isn’t a single incident, it’s a narrative that unfolds. Oren Gur, CISO: The insider threat is one of the biggest and prioritized risks especially when you deal with international companies and ongoing M&As.” | official | 2026-07-02 |
| s2 | Above AI Investigative Agents platform page (moved from /product, which returned 404 on 2026-07-02) “A fleet of AI investigative agents. Real risk surfaces early, already worked up into a case your team can act on. One case, every team. Security, HR & Legal act together.” | official | 2026-07-02 |
| s3 | About Above Security page “Prev. Co-founder & CTO of Ctrl, acquired by Sana which was acquired by Workday. Politely intervene and stop risky actions before they happen.” | official | 2026-07-02 |
| s4 | Above agentic AI use-case page “The agent now reads at the speed of an API, on the vendor's servers, indefinitely.” | official | 2026-06-12 |
| s5 | Above blog post on the Insider Threat Matrix sponsorship | official | 2026-06-12 |
| s6 | Above blog post citing Gartner insider-risk guidance (May 7, 2026) | official | 2026-06-12 |
| s7 | Above Security funding press release (PRNewswire, March 23, 2026) “Above has established integrations with CrowdStrike, and others across identity, endpoint, and SaaS environments.” | press | 2026-06-12 |
| s8 | CTech on the Above Security Series A (March 23, 2026) “Eight-month-old Israeli cyber startup Above Security raises $43 million Series A with just 10 employees” | press | 2026-06-12 |
| s9 | Ynetnews on the Above Security funding (March 23, 2026) “The funding round was led by Ballistic Ventures, Merlin Ventures and Norwest, with participation from Jump Capital and QPV Ventures, the company said Monday.” | press | 2026-06-12 |
| s10 | Ballistic Ventures on its Above Security investment “Most Above customers are operational in minutes to hours, not months.” | press | 2026-06-12 |
| s11 | Above Security ITM sponsorship press release (PRNewswire, April 27, 2026) “The ITM Sponsorship Program is limited to six positions, each held on an annual basis.” | press | 2026-06-12 |
| s12 | CrowdStrike accelerator selection press release (January 5, 2026) “CrowdStrike (NASDAQ: CRWD) today announced the 35 startups selected for its third annual Cybersecurity Startup Accelerator with Amazon Web Services (AWS) and NVIDIA” | press | 2026-06-12 |
| s13 | CrowdStrike accelerator winner press release (March 25, 2026) “Above Security was named runner-up for using AI agents to proactively manage insider risk and replace alerts with full investigative narratives.” | press | 2026-06-12 |
| s14 | Above Security trust center (captured 2026-06-18, trust probe 2026-07-02 found NXDOMAIN on public resolvers and no trust link on the served site) “(12) Certifications - SOC 2 Type II, pen test by Sayfer Security.” | official | 2026-06-18 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Above Security homepage “Most tools surface anomalies. Above surfaces context. Oren Gur, CISO: The insider threat is one of the biggest and prioritized risks especially when you deal with international companies and ongoing M&As.” | official | 2026-07-02 |
| s2 | Above AI Investigative Agents platform page (moved from /product, which returned 404 on 2026-07-02) “A fleet of AI investigative agents. Real risk surfaces early, already worked up into a case your team can act on. See an investigation on your own data.” | official | 2026-07-02 |
| s3 | About Above Security page “Prev. Founder Trullion, First SVP R&D at Silverfort, VP at DriveNets. Politely intervene and stop risky actions before they happen.” | official | 2026-07-02 |
| s4 | Above agentic AI use-case page “an AI agent acting on behalf of an employee is itself a class of insider” | official | 2026-06-11 |
| s5 | Above blog post on the Insider Threat Matrix sponsorship | official | 2026-06-11 |
| s6 | Above blog post citing Gartner insider-risk guidance (May 7, 2026) | official | 2026-06-11 |
| s7 | Above Security funding press release (PRNewswire, March 23, 2026) “The platform targets organizations with 1,000 or more employees operating in SaaS-forward environments.” | press | 2026-06-11 |
| s8 | CTech on the Above Security Series A (March 23, 2026) “Within just six months of its founding, the company completed both a $7 million Seed round, led by Merlin Ventures and Norwest, and this latest Series A.” | press | 2026-06-11 |
| s9 | Ynetnews on the Above Security funding (March 23, 2026) “Above Security, an Israeli-founded cybersecurity startup, has emerged from stealth with $50 million in funding” | press | 2026-06-11 |
| s10 | Ballistic Ventures on its Above Security investment “every organization can now have the effect of a highly trained insider risk investigation team, continuously learning, adapting, and evolving” | press | 2026-06-11 |
| s11 | Above Security ITM sponsorship press release (PRNewswire, April 27, 2026) “the open-source framework maintained by Forscie that catalogs the human behaviors and discrete events defining insider threat investigations” | press | 2026-06-11 |
| s12 | CrowdStrike accelerator selection press release (January 5, 2026) “Thirty-five startups were selected for the eight-week, equity-free program” | press | 2026-06-11 |
| s13 | CrowdStrike accelerator winner press release (March 25, 2026) “Above Security was named runner-up for using AI agents to proactively manage insider risk and replace alerts with full investigative narratives.” | press | 2026-06-11 |
| s14 | CTech on the Above Security Series A and headcount (March 23, 2026) “Eight-month-old Israeli cyber startup Above Security raises $43 million Series A with just 10 employees” | press | 2026-06-13 |
| s15 | Above Security trust center (captured 2026-06-18, trust probe 2026-07-02 found NXDOMAIN on public resolvers and no trust link on the served site) “Compliance: SOC 2 Type 2. Documents: SOC 2 Report, Pentest Report, Privacy Whitepaper, Security Whitepaper, Data Flow Diagram. Risk Profile: Data Access Level Restricted, Impact Level Moderate, RTO 4 hours.” | official | 2026-06-18 |
| s16 | Above integrations page “Plug Above into the stack you already run. Above connects to your identity, SaaS, endpoint, cloud and AI tools” | official | 2026-07-02 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.