All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Permiso's platform is agentless and API-based, attributing every agent run and tool call to an identity at runtime and enforcing through approval gates and kill switches, and the reviewed record does not evidence it as the credential issuer workloads log in with. That lets it deploy in days, and Autodesk expanded its Permiso use to agent identities without a new deployment. What Permiso's durability rests on in the record is a research reputation and detection breadth a funded rival could rebuild, not a named non-public asset.
| Description | Permiso gives security teams identity security for AI agents, tying every run, event, and tool call to the identity behind it in real time across cloud, SaaS, and on-prem so teams can discover agents and catch anomalous behavior. | [f1] |
|---|---|---|
| Founded | 2020 | [f2] |
| HQ | Palo Alto, California, US | [f3] |
| Funding | $28.5M total | [f2] |
| Latest funding | Series A, $18.5M, led by Altimeter Capital (2024) | [f4] |
| Deployment | SaaS | [f5] |
| Product | What it does |
|---|---|
| Permiso AI Security | Permiso AI Security: Capability of the Permiso identity platform that discovers AI agents, attributes runs and tool calls to identities, and detects anomalous agent behavior in real time. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Permiso AI Security discovers AI agents, attributes runs and tool calls to identities, and detects anomalous agent behavior in real time. It is mapped to the AI Defense Matrix. [f6]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score |
|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs, demos, and third-party validation. | 4/5 |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
pivot urgently
| Dimension | Score |
|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Permiso: Secure Every AI Agent, Skill, and Action | official | 2026-07-09 |
| f2 | SiliconANGLE on Permiso Series A | press | 2026-06-14 |
| f3 | Permiso Series A announcement | official | 2026-06-14 |
| f4 | SecurityWeek on Permiso Series A | press | 2026-06-14 |
| f5 | AI Defense Matrix Catalog entry | other | 2026-06-10 |
| f6 | AI Defense Matrix Catalog mapping | other | 2026-06-23 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Permiso Security homepage “Autodesk is among the first enterprises to deploy the capabilities, securing AI agents across its products, workforce, and cloud infrastructure.” | official | 2026-07-01 |
| s2 | Permiso AI Security product page “Discover agents, attribute identity at runtime, detect anomalies, sandbox skills, and enforce controls, including kill switches at machine speed.” | official | 2026-06-18 |
| s3 | Permiso about page with founder bios and named customers “Sebastian Goodwin, CISO at Nutanix, a Permiso customer ... Erik Bataller, VP of Security at ACV Auctions, a Permiso customer” | official | 2026-06-18 |
| s4 | Permiso AI agent runtime security launch blog “Permiso Brings Identity Runtime Attribution to AI Agents with Discover, Protect, and Defend” | official | 2026-06-13 |
| s5 | Security Boulevard on Permiso AI agent security launch “The Permiso platform addresses that issue by surfacing non-deterministic behavior, dynamic tool usage, inherited credential chains, and runtime activity that legacy security tools don’t monitor.” | press | 2026-07-01 |
| s6 | SiliconANGLE on Permiso Series A funding total “Permiso has raised $18.5 million in new funding... Including the new funding, Permiso has raised $28.5 million to date.” | press | 2026-06-13 |
| s7 | Permiso Series A announcement with traction detail “Permiso has raised a $18.5m Series A led by Altimeter Capital with participation from Point72 Ventures.” | official | 2026-06-13 |
| s8 | FinSMEs on Permiso seed and Series A investors “Prior to this, they raised a $10M seed funding round from Point72 Ventures, Foundation Capital, 11.2 Capital, WorkBench Capital, and prominent angel investors.” | press | 2026-06-13 |
| s9 | SC Media on Permiso 2026 SC Award for Best Threat Detection Technology “Permiso Security is the winner of the 2026 SC Award for Best Threat Detection Technology for its Permiso Identity Threat Detection and Response (ITDR) platform, which detects identity-based attacks across cloud and hybrid environments.” | press | 2026-07-01 |
| s10 | Cloud Security Alliance research note on LLMjacking “When Sysdig's Threat Research Team published the original LLMjacking research in May 2024, the threat category was genuinely novel.” | research | 2026-06-18 |
| s11 | Equilar executive bio for Permiso co-CEO Jason Martin “Co-Founder, Co-Chief Executive Officer at Permiso Security” | other | 2026-06-13 |
| s12 | Permiso Series A announcement with deal-size detail “closing multiple six and seven figure license deals with Fortune 500 customers, Permiso has raised a $18.5m Series A led by Altimeter Capital” | official | 2026-06-13 |
| s13 | Permiso Series A announcement on casino-group engagements “After MGM and Caesars were targeted by LUCR-3 (Scattered Spider) last September, multiple casino groups turned to Permiso's platform to help defend all layers of their cloud attack surface.” | official | 2026-06-13 |
| s14 | Permiso 2026 SC Award win noting back-to-back recognition “This marks the second consecutive year Permiso has been recognized at the SC Awards. In 2025, the company won Most Promising Early-Stage Startup.” | official | 2026-06-13 |
| s15 | Permiso SOC 2 Type I blog post (Type II being pursued with Vanta and auditor Johanson Group LLP) “We're excited to announce that Permiso is now SOC 2 Type I certified. This certification signifies that an independent third-party auditor has validated the design of our security program controls” | official | 2026-06-16 |
| s16 | Aembit homepage on IAM for agentic AI and workload identities “Apply policy, context, and audit to all agent interactions based on their unique identities.” | official | 2026-07-01 |
| s17 | Token Security homepage on agentic AI and non-human identity security “The Token Security Agentic AI and Non-Human Identity Security Platform” | official | 2026-07-01 |
| s18 | Clutch Security homepage on securing non-human identities and agents “Every Identity. Every Agent. Every Secret. Discover, Govern, and Secure Your Entire Non-Human Attack Surface.” | official | 2026-07-01 |
| s19 | SecurityWeek on the FireEye acquisition of Invotas (February 2016) “FireEye announced that it has acquired Invotas International, a privately held provider of security automation and orchestration software.” | press | 2026-07-01 |
| s20 | Microsoft: Defender for Identity, identity threat detection and response for the SOC “Use Defender for Identity to deliver enriched identity insights and help your security operations teams better prevent, detect, and respond to identity-based cyberthreats.” | official | 2026-07-01 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Permiso Security homepage (Discover, Protect, Defend across human, non-human, and agentic identity) “Autodesk is among the first enterprises to deploy the capabilities, securing AI agents across its products, workforce, and cloud infrastructure.” | official | 2026-06-15 |
| s2 | Permiso AI Security product page (identity security for the agentic era) “Discover agents, attribute identity at runtime, detect anomalies, sandbox skills, and enforce controls, including kill switches at machine speed.” | official | 2026-06-15 |
| s3 | Permiso about page with founder bios and named customers “Nathan Norton, Senior Staff Security Engineer at Modern Health, a Permiso customer” | official | 2026-06-18 |
| s4 | Permiso AI agent runtime security launch blog “These detections are powered by P0 Labs threat intelligence, which now includes agent-specific behavioral patterns built from the same team's research into LLMjacking, cross-prompt injection vulnerabilities in AI copilots, and analysis of 341+ malicious AI agent skills.” | official | 2026-06-18 |
| s5 | Security Boulevard on Permiso AI agent security launch “The extension to the Permiso Security platform makes it possible to maintain continuous visibility into agent runs, events, tool calls, data access, Model Context Protocol (MCP) servers and the underlying infrastructure those agents operate on.” | press | 2026-06-15 |
| s6 | SiliconANGLE on the Permiso Series A and CloudGrappler open-source tool “Founded in 2020, Permiso offers an identity-based cloud detection and response solution for cloud infrastructures.” | press | 2026-06-15 |
| s7 | Permiso Series A announcement with deal-size and casino-group detail “closing multiple six and seven figure license deals with Fortune 500 customers, Permiso has raised a $18.5m Series A led by Altimeter Capital with participation from Point72 Ventures.” | official | 2026-06-15 |
| s8 | SC Media on Permiso winning the 2026 SC Award for Best Threat Detection Technology “Permiso has developed more than 1,500 detection signals tied to known attacker TTPs ... The platform's agentless architecture integrates with AWS, Azure, Google Cloud and Kubernetes, allowing organizations to deploy quickly” | press | 2026-06-15 |
| s9 | Permiso SOC 2 Type I blog post (Type II being pursued with Vanta and auditor Johanson Group LLP) “We're excited to announce that Permiso is now SOC 2 Type I certified. This certification signifies that an independent third-party auditor has validated the design of our security program controls” | official | 2026-06-16 |
| s10 | Permiso homepage and security page AICPA SOC attestation seal (SOC 2) “21972-312_SOC_NonCPA.png, the AICPA SOC for Service Organizations seal (aicpa.org/soc4so), shown on the homepage and the security page, image only with alt text set to the filename” | official | 2026-06-17 |
| s11 | Permiso pricing path (returns HTTP 404 not found, no published pricing page) | official | 2026-07-01 |
| s12 | SecurityWeek on the FireEye acquisition of Invotas (February 2016) “FireEye announced that it has acquired Invotas International, a privately held provider of security automation and orchestration software.” | press | 2026-07-01 |
| s13 | Permiso Master Subscription Agreement (SOC 2 Type II report on request, Monitored Identities as the subscription unit) “will make its most recent SOC 2 Type II report available for Customer's review upon request” | official | 2026-07-14 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Do not republish its content or share access without the operator's permission.