All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Aembit gives software workloads and AI agents a managed identity that brokers short-lived credentials and enforces policy on every request. Its proof points are unusually concrete for a company on more than 40 million dollars of funding: public documentation, a free self-service tier, a published price sheet, and founders who sold two prior security companies to Netskope and McAfee. The customer evidence is softer. Snowflake and a managed service provider appear by name only on Aembit's own pages, while the independently confirmable signals are strategic backing from Okta and CrowdStrike and a KuppingerCole analyst placement. The policies customers embed into the broker, which sits in the authentication path, are what make Aembit costly to replace.
| Description | Aembit gives AI agents access to MCP servers and the resources behind them through policy, issuing OAuth 2.1 tokens and brokering credentials at request time so agents never hold the secrets. | [f1] |
|---|---|---|
| Founded | 2021 | [f2] |
| HQ | Silver Spring, Maryland, US | [f3] |
| Latest funding | Series A, $25M (September 2024) | [f2] |
| Deployment | SaaS, Self-hosted | [f4] |
| Compliance | ISO 27001, SOC 2 Type 2 | [f4] |
| Product | What it does |
|---|---|
| Aembit | Identity and access management for AI agents that issues OAuth 2.1 tokens, enforces policy on every MCP request, and brokers credentials so agents reach MCP servers and resources without secrets. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Aembit is identity and access management for AI agents that issues OAuth 2.1 tokens, enforces policy on every MCP request, and brokers credentials so agents reach MCP servers and resources without secrets. It is mapped to the AI Defense Matrix. [f5]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Aembit names a specific buyer in security, identity, and DevSecOps teams and a concrete problem in long-lived secrets and ungoverned agent access, and SiliconANGLE ties the pain to non-human identity attacks on Cloudflare. The quantified pain rests on Aembit's own survey carried by that press, so the scale is vendor-produced rather than independently measured. [s1, s8, s11] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | Aembit publishes a detailed documentation portal covering trust providers, credential providers, access policies, and the MCP components, and anyone can exercise the product through a free self-service tier, two validation points beyond marketing pages, while GitGuardian independently describes the workload-attested token model. The open docs plus a directly testable free tier put the capability evidence above the category default. [s3, s5, s6, s11] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | The enabler is the non-human identity attacks SiliconANGLE identified as a market driver, including the one on Cloudflare, and the move of AI agents into production, which created an authorization gap Aembit answered with its April 2026 IAM for Agentic AI release. Independent demand evidence is thin, reducing to category recognition, a vendor-authored GitGuardian roundup and a KuppingerCole Rising Star placement, rather than named buyer RFP or budget data. [s3, s8, s9, s11] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | Founders David Goldschlag and Kevin Sapp are a repeat team whose prior security companies New Edge Labs and Trust Digital were acquired by Netskope and McAfee, a verified in-domain exit record TechCrunch reported at the seed, and David co-invented onion routing at the NSA. A verified prior-exit record distinguishes the founders from typical first-time security founders and lifts the score above the category default. [s4, s7] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 | Snowflake and a managed service provider appear as named customers on Aembit's pages and a 300 billion dollar firm details a Claude deployment, but all are first-party accounts without independent corroboration of scale, which fits the one-or-two-named-customer rung. The Okta Ventures and CrowdStrike Falcon Fund investments that SiliconANGLE confirms are ecosystem credibility rather than evidence of customer traction. [s1, s8, s14] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | Aembit raised 41.6 million dollars across a 16.6 million dollar seed and a 25 million dollar Series A and ships visibly on it, including the agentic GA, SPIFFE support, and certifications, but revenue, margin, and growth efficiency are undisclosed, so the raise is proportional to the enterprise motion without confirmed output per dollar. The raise is modest rather than outsized. [s7, s8, s3, s17, s16] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Non-human identity is an analyst-tracked and practitioner-tracked category, and third parties place Aembit in it without vendor coaching, including a KuppingerCole Rising Star designation in non-human identity and GitGuardian categorizing Aembit under workload identity security. It is placed as a participant rather than the named category leader, so it sits below the top rung. [s9, s11, s15] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Inline credential brokering across clouds, SaaS, and on-prem is more than a quarterly feature, and once Aembit sits in the access path with deployed policies it is embedded in customer workflows, but Okta and Microsoft are adjacent to the same buyer, cloud providers offer native workload identity federation that Aembit itself integrates with, and no proprietary data advantage is claimed. [s3, s6, s11] |
Aembit targets the gap between mature human identity management and the unmanaged identities of software, meaning the applications, scripts, CI/CD pipelines, and now AI agents that authenticate to sensitive systems with long-lived API keys and secrets. The company frames the problem as credentials stored in code, shared over chat, and rarely rotated, with AI agents compounding it because their access cannot be governed the way a human's is.
Corroboration exists outside Aembit's own marketing. SiliconANGLE's Series A coverage described non-human identity attacks on Cloudflare and similar companies as the market driver, and a 2026 GitGuardian roundup treats non-human identity security as an established tool category. Aembit's own survey statistic on credentials stored in code is vendor-produced, so it grounds the messaging rather than the independent scale of the pain.
The buyer is specific. Aembit sells to security, identity, and DevSecOps teams in cloud-heavy organizations, and the agentic expansion targets the same buyer at the moment enterprises are wiring agents into MCP servers and internal data. [s8, s11, s1, s3]
Aembit authenticates workloads by their native identity, evaluates policy including posture signals, and injects short-lived credentials so applications never hold secrets. Native identity sources span cloud workload identity and SPIFFE, and the November 2025 SPIFFE JWT-SVID credential provider extends that model to SPIFFE-compliant services. The architectural bet is enforcement in the access path, which goes beyond discovery and visibility.
The April 2026 IAM for Agentic AI release added two documented components. The MCP Authorization Server runs as a managed Aembit Cloud capability that implements the OAuth 2.1 authorization-code flow from the MCP specification and federates to identity providers such as Okta, Azure AD, and Google. The MCP Identity Gateway validates tokens, enforces policy on every MCP request, and exchanges credentials so agents never hold them, with Blended Identity evaluating the agent and the human operating it in one decision.
The capabilities can be verified beyond marketing pages. The public documentation portal is detailed and carries a dedicated AI guide for the MCP components, a free self-service tier makes the product directly testable, and GitGuardian's independent roundup describes Aembit as replacing long-lived static credentials with short-lived, workload-attested tokens. [s3, s6, s11, s17]
Aembit positions itself as an independent identity broker for non-human and agentic access, leading with runtime enforcement where most non-human identity peers are known for discovery and governance. Rivals such as Astrix, Oasis, and Entro compete for the same budget line, and as the category converges the enforcement distinction is narrowing rather than absolute. GitGuardian's 2026 roundup captures both the strength and the limit of Aembit's stance, crediting a workload identity model aligned with cloud-native architectures while noting that Aembit does not scan repositories for credentials already leaked.
Against incumbents, Aembit positions itself as complementary. It describes its product as a policy layer over the bootstrap secrets that secrets managers store, and it federates with human identity providers instead of replacing them. Okta is at once an integration target and, through Okta Ventures, a strategic investor.
With IAM for Agentic AI, Aembit opened a second competitive front against emerging MCP gateway and agent-identity products. Its claim there is that the same policy engine and identity plane now span workloads and agents. [s11, s3, s8]
Aembit runs a two-sided motion. It offers a transparent self-service tier, free for a small number of workloads or AI agents with sign-up and no sales call, and converts that entry into a sales-assisted enterprise motion with custom pricing, conditional access, and 24x7 support.
The named-customer evidence is real but first-party. Snowflake appears on the homepage with a security leader quoted, Aembit publishes a managed-service-provider story, and a case study describes a 300 billion dollar investment firm running Claude agents across MCP servers, all on Aembit's own pages. The independently confirmable pull is investor based: SiliconANGLE reports Okta Ventures and CrowdStrike Falcon Fund among the Series A backers.
Category-building is deliberate for the stage. Aembit was selected as a 2024 RSAC Innovation Sandbox finalist. Revenue and customer counts are not public, so the named accounts and investor relationships are the traction case. [s1, s8, s14, s15]
Aembit's founders are a repeat team with domain-relevant exits. CEO David Goldschlag and CTO Kevin Sapp have worked together for roughly two decades, and TechCrunch reported at the seed that they co-founded New Edge Labs, acquired by Netskope, and Trust Digital, acquired by McAfee. David also worked at the NSA and co-invented onion routing, the foundation of Tor, an unusually deep identity-and-trust pedigree.
Investor and leadership signals are verifiable. TechCrunch covered the 2023 seed from Ballistic Ventures and Ten Eleven Ventures, and SiliconANGLE reports Acrew Capital leading the Series A. Senior bench strength is visible in the October 2024 hire of Mario Duarte, formerly Snowflake's security leader, as CISO.
Current team size and engineering depth are not publicly disclosed, which limits visibility into the organization behind the products. Aembit nonetheless shipped from a 2023 launch to a second generally available product line in April 2026, a pace that is hard to sustain without a functioning product organization. [s4, s7, s8, s13]
Aembit's trust posture is ahead of typical Series A stage. The company reports a SOC 2 Type II attestation with recertification and an ISO 27001 certification, and it runs a public trust center at trust.aembit.io, powered by SafeBase, where buyers can review the program and request SOC 2 and ISO 27001 documentation. These are first-party claims, but they are specific, dated, and the kind of evidence enterprise procurement expects.
The trust bar is higher for Aembit than for most vendors at this stage. Aembit brokers customer credentials in the authentication path, so a compromise or outage at Aembit directly affects customer access to production systems.
Public materials cover most of what procurement reviews ask for. With published compliance status and requestable audit reports, a transparent pricing page, and detailed documentation, Aembit lowers third-party-risk friction for the regulated buyers its case studies suggest. A public vulnerability disclosure policy and any federal authorization did not appear in the reviewed pages. [s12, s16, s1, s5]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Astrix Security | competes with | Non-human identity rival centered on SaaS and OAuth discovery and governance, listed alongside Aembit in third-party NHI tool roundups. | |
| Oasis Security | competes with | Non-human identity discovery, inventory, and lifecycle platform competing for the same emerging machine-identity budget line. | |
| Entro Security | competes with | Machine identity discovery and lifecycle governance vendor listed in the same NHI category roundups. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Okta | adjacent | Human identity incumbent and strategic investor through Okta Ventures. Aembit federates with it today, but it could extend into workload and agent access. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Akeyless | adjacent | Secrets management platform. Aembit positions its policy layer over secrets managers rather than replacing vault storage. |
Add analyzed competitors to compare them side by side with Aembit.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
Aembit keeps its customers through the cost of leaving. Workloads and AI agents get their short-lived credentials from Aembit's broker on every request. Customers write access policies into that broker and connect identity providers, clouds, and clusters to it. A customer that leaves must rewire how each workload authenticates, by reverting to static credentials or by substituting another broker. That friction is the whole of Aembit's staying power. Aembit sells customer-configured software rather than judgment and gathers no proprietary dataset. Its SOC 2 and ISO 27001 attestations are commercial table stakes a funded rival could also earn. Aembit's hold on an account is no deeper than the policies the account has written into the broker.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Customers buy software capabilities such as policy enforcement, credential brokering, and audit through self-service signup or licensed plans. No judgment, managed service, or accountability layer is part of the offer. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Once Aembit sits in the authentication path with deployed edge components, accumulated access policies, and identity-provider and cloud integrations, a departing customer must re-plumb how every workload authenticates, and pipeline and cluster anchor points add to that. The friction is meaningful, though it brings no network effects or residency lock. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | SOC 2 Type II and ISO 27001 ease procurement, and the product provides audit trails over every access attempt that can support compliance reviews, but these are commercial, table-stakes attestations, the cited record names no regime mandating this product class, and the same bars are open to any vendor that pursues them, so this is procurement assurance rather than a moat. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Real-time inline credential exchange, workload attestation across clouds, Kubernetes, and SPIFFE, and OAuth 2.1 MCP flows are security-critical distributed-systems engineering where failure breaks customer production access, work that takes years of specialized identity expertise. Constant attacker pressure on credentials modestly reinforces the score. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 | Visible customers such as a 300 billion dollar investment firm, a Snowflake security team, and a managed service provider skew enterprise, where procurement and legal slow replacement, but Aembit also courts small teams through the self-service free plan, which blends the buyer profile. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 3/3 | Aembit is identity infrastructure that workloads, pipelines, and AI agents depend on to reach data and services. Applications and agents authenticate through it rather than around it, so removing it breaks production access. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | No proprietary dataset, threat-intelligence corpus, or cross-customer telemetry flywheel is claimed in public materials. Policies and access graphs are tenant-specific configuration a rival could not buy but a customer could recreate. |
Aembit serves two stacked segments with one platform. The original segment is security and DevSecOps teams in cloud-heavy mid-market and enterprise organizations that need workload-to-workload access control across clouds, SaaS, and data centers, the positioning a GitGuardian roundup echoed at capture time when it called Aembit well suited for cloud-native, Kubernetes-heavy organizations, wording that no longer appears on the live page. The second segment is enterprises adopting AI agents and MCP servers, where the buyer is often the same identity or security leader now accountable for agent access, and the agentic line reached general availability in April 2026.
The newest public proof comes from the agentic side. Aembit leads its site with a case study of a 300 billion dollar investment firm that deployed Claude agents across connected MCP servers, alongside a managed-service-provider story and a Snowflake testimonial. The set skews enterprise, with a finance customer and a service-provider customer suggesting regulated and outsourced niches where credential handling is a procurement concern.
Stated personas match the personas the product serves. The pricing page addresses an individual team running services or agents in production, enterprise plans add conditional access and 24x7 support for organization-wide deployments, and the free Starter plan reaches platform teams below the enterprise threshold.
Geographic and vertical segmentation remain implicit. Aembit is headquartered in Maryland per the SEC filing record, and no vertical-specific packaging is visible.
The claimed pain points are concrete, and public documentation demonstrates the capabilities that address them. Aembit names secrets sprawl, long-lived credentials, fragmented cloud IAM, and ungoverned AI-agent access as the problems. Docs cover workload attestation through trust providers for cloud roles and Kubernetes, GCP and Azure workload identity federation, and SPIFFE, plus policy evaluation with posture conditions and credential providers that inject short-lived tokens.
The agentic release is documented to the same depth. The MCP Authorization Server implements the OAuth 2.1 authorization-code flow from the MCP specification and federates to Okta, Azure AD, and Google. The MCP Identity Gateway validates tokens and exchanges credentials on every MCP request, and Blended Identity evaluates the agent and the human operating it in one policy decision so each user gets per-user credential isolation.
Aembit claims no proprietary detection model or data advantage in its AI story. The product secures AI agents as the asset under management rather than running AI as its engine. The durable technical depth is protocol and infrastructure engineering, real-time inline credential exchange across heterogeneous environments rather than accumulated data.
Aembit has repositioned around the current agent stack. The homepage leads with IAM for agentic AI, the docs carry a dedicated AI guide for the MCP components, and the November 2025 SPIFFE credential provider extends the same identity model to SPIFFE-compliant services.
Aembit runs a hybrid motion of product-led entry and sales-assisted enterprise expansion. Self-service is real, with signup that requires no sales call, a free Starter plan the pricing page describes as suited to smaller projects, and documentation deep enough for independent deployment. Aembit closes enterprise deals through contact-sales plans that add conditional access and 24x7 support.
Founder-led selling remains visible at a stage where that is a healthy signal. CEO David Goldschlag opened NHIcon 2026 with remarks setting the agenda on agentic AI security, and he is the quoted voice in the funding coverage. A hired go-to-market layer sits under the founders, including a CISO who led security at Snowflake and senior sales and marketing leaders, while the founders still front the public selling.
Distribution beyond the direct motion remains thin, and the strongest independent signal is strategic investor validation rather than reported customer traction. SiliconANGLE reports Okta Ventures and CrowdStrike Falcon Fund among the Series A backers, and CrowdStrike and Wiz feed posture signals into Aembit policies. No reseller program or cloud marketplace listing appeared in the reviewed pages.
Category-building is deliberate for the stage. Aembit runs NHIcon, a recurring virtual conference its CEO opened in 2026 with remarks on agentic AI security, and was selected as a 2024 RSAC Innovation Sandbox finalist.
Aembit publishes its pricing. Its published price sheet lets a buyer estimate cost before any sales contact, a buyer-transparency signal in a category where evaluation is otherwise sales-gated.
The pricing unit matches how buyers count the problem. Aembit charges per workload and per agent, with the agentic Teams tier running 20 dollars per agent per month and scaling from 10 to 500 agents, the same unit a security team uses to measure its non-human estate. The free Starter plan covers 10 workloads with 10 access policies, and Enterprise plans add unlimited workloads or AI agents, conditional access, custom log retention, and 24x7 support.
The open question is whether the model fits agent economics. Per-agent flat pricing fits predictable fleets but may misprice highly elastic agent swarms. The free plan retains event logs for only 24 hours, so retaining logs longer than a day requires a paid plan.
What the sheet supports is a calculable entry point rather than a deal size: the Teams tier's ten-agent floor at twenty dollars per agent per month works out to about 2,400 dollars a year. Typical contract values and revenue mix are undisclosed.
Aembit pairs a managed control plane with customer-deployed data-plane components. Aembit Cloud hosts the control plane, including the managed MCP Authorization Server with nothing for the customer to deploy. Inside the customer environment, Aembit Edge performs workload credential injection and the MCP Identity Gateway enforces policy locally, so network boundaries and data locality stay under customer control.
The deployment story is documentation-first and friendly to infrastructure-as-code. An engineer can implement the product without sales engagement, working from a public quickstart and per-platform install guides covering cloud roles, Kubernetes, and SPIFFE.
Aembit must clear a high operational bar because it operates in the authentication path. A slow or unavailable broker directly blocks customer workloads from authenticating, and public materials do not yet document SLAs, regional redundancy, or failure modes. Aembit answers data residency only partially, since the gateway deploys in the customer’s environment with control over network boundaries and data locality while the managed control plane is centrally hosted.
Aembit front-loads its public trust posture, a fit for a company whose product holds the keys to customer infrastructure. The company reports a SOC 2 Type II attestation with recertification and an ISO 27001 certification, and it operates a public trust center at trust.aembit.io, powered by SafeBase, that lists SOC 2 and ISO/IEC 27001 and offers document requests. These are first-party claims, but they are dated and verifiable during procurement.
The deeper trust argument is architectural. Aembit positions the product so customers never hand it standing secrets, since credentials are short-lived and minted just in time, and the MCP gateway deploys in the customer’s own environment, giving the customer control over network boundaries and data locality.
Security leadership adds credibility. Mario Duarte led security at Snowflake before joining as CISO in October 2024, a background that matters to the data-platform-heavy customer base.
Gaps remain visible in public materials. No public vulnerability disclosure policy or bug-bounty program appeared in the reviewed pages, and the reviewed pages show no federal authorization, consistent with the current commercial-enterprise focus but a ceiling on regulated-government expansion.
Aembit positions itself as an independent identity broker, a neutral control plane spanning clouds, SaaS, and on-prem rather than a feature inside any one cloud's IAM. The agentic launch is a platform proof point, because the MCP components draw on the same access-policy engine, attestation infrastructure, and credential-provider machinery as the workload product, so the second product line did not start from scratch.
The integration surface is broad for the stage. Identity providers Okta, Azure AD, and Google federate in through OIDC and SAML, cloud-native identity systems and SPIFFE act as trust anchors, and CrowdStrike and Wiz contribute posture signals the policy engine consumes.
Aembit positions cooperatively against the rest of the stack. Secrets managers operate under Aembit policy as a credential source rather than something applications call directly, and human identity providers supply the user context the MCP Authorization Server blends into agent identities.
Third parties building on Aembit are not yet visible. No public API marketplace or partner-built integrations beyond Aembit-authored connectors appeared in the reviewed pages, so the platform claim rests on shared internal foundations and integration breadth rather than external network effects.
The founding team is the most verifiable asset the company has. CEO David Goldschlag and CTO Kevin Sapp are repeat co-founders, and TechCrunch reported at the seed that they built New Edge Labs, acquired by Netskope, and Trust Digital, acquired by McAfee. The about page adds that David worked at the NSA and co-invented onion routing, the foundation of Tor, directly relevant pedigree for an identity-and-trust infrastructure company.
Domain fit is exact. The founders describe Aembit as arising from conversations with previous ZTNA-era customers whose secrets vaults and cloud IAM tooling were not solving workload access, and the about page says they have known each other for nearly 20 years.
The execution record is observable and was delivered on seed and Series A capital totaling 41.6 million dollars. Aembit launched publicly in 2023, reached the RSAC Innovation Sandbox finals in 2024, earned SOC 2 and ISO certifications, shipped a SPIFFE credential provider in November 2025, and took a second product line to general availability in April 2026.
Bench depth beyond the founders has filled in. Mario Duarte joined as CISO from Snowflake's security leadership in October 2024, and the current team adds senior sales and marketing leaders. Press reporting put Aembit at 11 full-time employees, most in engineering, and the cited pages give no later figure, which limits assessment of whether the organization can sustain two product lines and an enterprise sales motion at once.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Aembit: IAM for Agentic AI | official | 2026-07-09 |
| f2 | Aembit raises $25M to tackle nonhuman identity security challenges | press | 2026-06-28 |
| f3 | SEC EDGAR submissions record: Aembit, Inc. (CIK 0001918754) | regulatory | 2026-06-28 |
| f4 | AI Defense Matrix Catalog entry | other | 2026-06-13 |
| f5 | AI Defense Matrix Catalog mapping | other | 2026-06-23 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Aembit homepage (Snowflake customer testimonial) “Aembit is a game changer! Along with making us more secure, Aembit also helps automate existing processes. We estimate that Aembit can save us five to 10 hours a day.” | official | 2026-06-28 |
| s2 | Aembit IAM for Agentic AI product page “Create and enforce policies that control when AI agents can access MCP servers and the sensitive resources behind them, with complete visibility into every access attempt.” | official | 2026-06-28 |
| s3 | Aembit IAM for Agentic AI is generally available “It implements the OAuth 2.1 authorization code flow defined in the MCP specification, so AI agents and MCP clients can authenticate and receive access tokens minted by Aembit access policies.” | official | 2026-06-28 |
| s4 | Aembit about page (founders) “Best known for pioneering zero trust user network access (ZTNA) at New Edge Labs, which was acquired by Netskope in 2019, they are now focusing on non-human identity security at Aembit.” | official | 2026-06-28 |
| s5 | Aembit pricing page “Starter Free: 10 Workloads (clients and services), 10 Access Policies, 24 Hours of Event Log Retention, Community Support.” | official | 2026-06-28 |
| s6 | Aembit documentation portal “Aembit now provides documentation for securing AI agent communications using the Model Context Protocol (MCP). Covers the MCP Authorization Server, MCP Identity Gateway, and MCP Server.” | official | 2026-06-28 |
| s7 | TechCrunch: Aembit raises $16.6M to bring identity management to workloads “they co-founded the zero trust platform New Edge Labs, which was acquired by Netskope, and the mobile device management platform Trust Digital, which was acquired by McAfee.” | press | 2026-06-28 |
| s8 | SiliconANGLE: Aembit raises $25M to tackle nonhuman identity security challenges “Acrew Capital led the Series A round, with previous investors Ballistic Ventures, Ten Eleven Ventures, Okta Ventures Inc. and CrowdStrike Falcon Fund also participating.” | press | 2026-06-28 |
| s9 | KuppingerCole Rising Star: Aembit (Paul Fisher) “Aembit leverages secretless authentication to secure non-human identities (NHIs) across cloud and on-premises environments. Eliminating static credentials, Aembit's dynamic, policy-driven model enforces Zero Trust principles, reducing credential-based risks.” | research | 2026-06-28 |
| s10 | SEC EDGAR submissions record: Aembit, Inc. (CIK 0001918754) “name: Aembit, Inc., stateOfIncorporation: DE, business address SILVER SPRING MD, Form D filings 2022-03-25, 2023-02-16, 2023-06-23, and 2024-07-29.” | regulatory | 2026-06-28 |
| s11 | GitGuardian: Top 10 Non-Human Identity Security Tools for 2026 “It helps eliminate long-lived static credentials by replacing them with short-lived, workload-attested tokens. A strong workload identity security model that aligns with cloud-native architectures. Cons: Aembit doesn't scan code repositories for existing leaked credentials.” | research | 2026-06-28 |
| s12 | Aembit Trust Center (SafeBase) “Compliance: ISO/IEC 27001, SOC 2.” | official | 2026-06-28 |
| s13 | Aembit appoints Mario Duarte, former Snowflake security leader, as CISO “Mario Duarte, Former Snowflake Cybersecurity Leader, Joins Aembit as CISO to Tackle Non-Human Identities. Veteran security executive brings 20+ years of experience to the non-human IAM company.” | official | 2026-06-28 |
| s14 | Aembit case study: a $300B investment firm secures Claude access “Aembit is the identity control plane securing this firm's Claude deployment across all connected MCP servers, full identity, access control, and audit logging in place for every employee.” | official | 2026-06-28 |
| s15 | RSAC Innovation Sandbox Contest 2024 finalists “RSA Conference, the world's leading cybersecurity conferences and expositions, today announced the Top 10 Finalists for its 19th annual RSAC Innovation Sandbox contest.” | press | 2026-06-28 |
| s16 | Aembit earns SOC 2 Type II recertification “Aembit Earns SOC 2 Type II Recertification for Ongoing Security and Compliance.” | official | 2026-06-28 |
| s17 | Aembit introduces a SPIFFE credential provider at KubeCon (Nov 2025) “Nov. 11, 2025, Aembit, the identity and access management platform for agentic AI, today announced at KubeCon + CloudNativeCon North America 2025 support for the SPIFFE JWT-SVID specification.” | official | 2026-06-28 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Aembit homepage (customer testimonials) “Aembit is a game changer! Along with making us more secure, Aembit also helps automate existing processes. We estimate that Aembit can save us five to 10 hours a day.” | official | 2026-06-28 |
| s2 | Aembit IAM for Agentic AI product page “Create and enforce policies that control when AI agents can access MCP servers and the sensitive resources behind them, with complete visibility into every access attempt.” | official | 2026-06-28 |
| s3 | Aembit IAM for Agentic AI is generally available “Blended Identity is Aembit's access model that evaluates the identity of the AI agent and the human operating it together in a single policy decision, at request time.” | official | 2026-06-28 |
| s4 | Aembit about page (founders) “Our founders, Kevin Sapp and David Goldschlag, have known each other for nearly 20 years. Best known for pioneering zero trust user network access (ZTNA) at New Edge Labs, which was acquired by Netskope in 2019.” | official | 2026-06-28 |
| s5 | Aembit pricing page “Starter Free: 10 Workloads (clients and services), 10 Access Policies, 24 Hours of Event Log Retention, Community Support.” | official | 2026-06-28 |
| s6 | Aembit documentation portal “Aembit now provides documentation for securing AI agent communications using the Model Context Protocol (MCP). Covers the MCP Authorization Server, MCP Identity Gateway, and MCP Server.” | official | 2026-06-28 |
| s7 | Aembit agentic pricing tiers “The 'AI' Teams tier, running $20 per agent per month, is for teams moving agents into production, scaling from 10 to 500 agents with live support.” | official | 2026-06-28 |
| s8 | Aembit case study: a $300B investment firm secures Claude access “Aembit is the identity control plane securing this firm's Claude deployment across all connected MCP servers, full identity, access control, and audit logging in place for every employee.” | official | 2026-06-28 |
| s9 | Aembit introduces a SPIFFE credential provider at KubeCon (Nov 2025) “Nov. 11, 2025, Aembit, the identity and access management platform for agentic AI, today announced at KubeCon + CloudNativeCon North America 2025 support for the SPIFFE JWT-SVID specification.” | official | 2026-06-28 |
| s10 | NHIcon 2026 (Aembit virtual conference) “Welcome to NHIcon! David will set the stage for a day of exploring the importance of agentic ai security and how it's essential to protect the workloads that power modern infrastructure.” | official | 2026-06-28 |
| s11 | Aembit Trust Center (SafeBase) “Compliance: ISO/IEC 27001, SOC 2.” | official | 2026-06-28 |
| s12 | Aembit appoints Mario Duarte, former Snowflake security leader, as CISO “Mario Duarte, Former Snowflake Cybersecurity Leader, Joins Aembit as CISO to Tackle Non-Human Identities. Veteran security executive brings 20+ years of experience to the non-human IAM company.” | official | 2026-06-28 |
| s13 | TechCrunch: Aembit raises $16.6M to bring identity management to workloads “they co-founded the zero trust platform New Edge Labs, which was acquired by Netskope, and the mobile device management platform Trust Digital, which was acquired by McAfee.” | press | 2026-06-28 |
| s14 | SiliconANGLE: Aembit raises $25M to tackle nonhuman identity security challenges “Acrew Capital led the Series A round, with previous investors Ballistic Ventures, Ten Eleven Ventures, Okta Ventures Inc. and CrowdStrike Falcon Fund also participating.” | press | 2026-06-28 |
| s15 | KuppingerCole Rising Star: Aembit (Paul Fisher) “Aembit leverages secretless authentication to secure non-human identities (NHIs) across cloud and on-premises environments. Eliminating static credentials, Aembit's dynamic, policy-driven model enforces Zero Trust principles, reducing credential-based risks.” | research | 2026-06-28 |
| s16 | SEC EDGAR submissions record: Aembit, Inc. (CIK 0001918754) “name: Aembit, Inc., stateOfIncorporation: DE, business address SILVER SPRING MD, Form D filings 2022-03-25, 2023-02-16, 2023-06-23, and 2024-07-29.” | regulatory | 2026-06-28 |
| s17 | GitGuardian: Top 10 Non-Human Identity Security Tools for 2026 “A strong workload identity security model that aligns with cloud-native architectures. Well-suited for cloud-native and Kubernetes-heavy organizations. Cons: Aembit doesn't scan code repositories for existing leaked credentials.” | research | 2026-06-28 |
| s18 | Aembit earns SOC 2 Type II recertification “Aembit Earns SOC 2 Type II Recertification for Ongoing Security and Compliance.” | official | 2026-06-28 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.