All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Silverfort sells identity security to large enterprises. Its technology sits inside the authentication flow across on-premises Active Directory and cloud identity providers. Working from inside that flow lets Silverfort push multi-factor authentication onto legacy applications, command-line tools and operational technology systems that cannot support it natively. Two acquisitions were made to extend it: Rezonate in November 2024 for cloud identity, and Fabrix Security in April 2026 for an engine intended to decide access at the moment of the request. The April announcement targeted the second half of 2026 for most of the capabilities that purchase is meant to bring. A buyer comparing the platform against that announcement is comparing it against a schedule.
| Description | Silverfort sells an identity security platform that sits inline with authentication across on-premises and cloud identity providers, extending multi-factor authentication to legacy applications and command-line tools and adding discovery and access policies for service accounts. | [f1] |
|---|---|---|
| Founded | 2016 | [f2] |
| Funding | $222M total | [f3] |
| Latest funding | Series D, $116M, January 2024 | [f2] |
| Product | What it does |
|---|---|
| Silverfort Identity Security Platform | Inline identity security platform sold in four packages, each including the Runtime Access Protection engine and an identity graph and inventory. |
| Universal MFA | Extends multi-factor authentication to legacy applications, homegrown systems, command-line tools, OT infrastructure and local Windows logins. |
| Non-Human Identity Security | Discovers non-human identities, baselines how they are used, and enforces access policies that fence their activity. |
| AI Agent Security | Discovers AI agents, ties each to an accountable human owner, and controls agent actions at runtime before they execute. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Silverfort Universal MFA extends authentication controls to resources that cannot support them natively, Non-Human Identity Security fences service-account activity, and the detection module answers identity attacks with inline response. These capabilities are mapped to the Cyber Defense Matrix. [f4]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | The buyer and the gap are stated plainly, and an analyst report attributes over 80% of breaches to identity misuse, but that pain is the whole category's rather than specific to what Silverfort covers. [s6, s7, s18] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 3/5 | Capability pages describe the inline mechanism and its coverage of legacy systems in concrete terms, and the reviewed sources carry no independent technical evaluation of that architecture. [s1, s6, s7] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | KuppingerCole projects 19-23% annual growth for identity threat detection over five years, which is one independently documented demand signal. The reviewed record adds no second kind. [s18] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 | Independent press names the three founders of 2016, two of whom hold operating titles today. Silverfort's own leadership page adds that the president hired in 2025 was CRO at SailPoint and at Centrify, now Delinea. It credits him with positioning SailPoint for its 2017 IPO. That is verifiable senior in-domain revenue leadership. The reviewed record names no in-domain product build these executives led, and the IPO credit rests on Silverfort's own page rather than an independent source. The next rung asks for prior builds or exits, multiply evidenced. [s3, s15] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | Named enterprise customers appear on the trust portal and in customer quotes, and press reporting carries customer and revenue growth figures, though those figures came from the company and date to January 2024. [s1, s9, s12, s13] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | The $222 million raised is proportional to a platform sold to global enterprises, and the efficiency evidence on record is company-stated growth, most recently published in November 2024, with no margin disclosure. [s3, s12, s13] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | KuppingerCole evaluates Silverfort ITDR alongside Microsoft, Okta and CyberArk in a named and established market, which places the product in a budget line buyers already recognize. [s18, s5] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Silverfort enforces on top of identity infrastructure from several vendors, and the cited record evidences no moat beyond that placement. Microsoft, whose directory products it enforces on top of, is rated a leader in the same detection market. [s1, s11, s18] |
Enterprises run authentication through several systems at once, and the controls each system offers stop at its own edge. Active Directory authenticates domain logins, a cloud identity provider handles modern applications, and between them sit legacy applications, homegrown systems, command-line tools and OT infrastructure that ordinary multi-factor authentication cannot reach.
The gap is well documented by parties other than Silverfort. KuppingerCole reports that identity misuse has become the predominant mode of intrusion, with over 80% of data breaches linked to it, and that non-human identities such as service accounts and API keys widen the problem further.
What the analyst record does not establish is that this particular coverage gap, rather than identity security generally, is what enterprises are budgeting against. The pain Silverfort names is real and widely attested; its specificity to Silverfort's slice of it rests on the company's own framing. [s6, s7, s18]
Silverfort's mechanism is placement. Its Runtime Access Protection technology sits in the authentication path alongside existing identity infrastructure rather than replacing it, which is how a control can reach a system the vendor never integrated with. Universal MFA extends multi-factor authentication to legacy applications, homegrown systems, command-line tools, OT infrastructure and local Windows logins without modifying them.
The platform sells as four packages, each carrying the runtime engine and an identity inventory, with detection, privileged access and access analytics added at higher tiers. Non-Human Identity Security discovers service accounts, baselines how they behave and fences their activity. AI Agent Security discovers agents, ties each to a human owner and controls agent actions before they execute.
Silverfort bought capabilities as well as building them. It announced the Rezonate acquisition in November 2024 and scheduled the combined cloud identity offering for mid-2025, and the reviewed sources do not record whether that date held. Fabrix Security followed in April 2026, bringing an authorization engine whose joint capabilities the announcement targeted for the second half of 2026. [s1, s5, s6, s7, s8, s10, s11]
KuppingerCole's 2025 evaluation of the identity threat detection market rates Silverfort a Product/Innovation Leader and names seven others Overall Leaders: BeyondTrust, CrowdStrike, CyberArk, Delinea, Microsoft, Okta and Saviynt. That is a placement to read closely, because Microsoft makes the directory products Silverfort's own announcement says it enforces on top of.
The architectural argument cuts both ways. Silverfort enforces controls on top of identity infrastructure from several vendors at once, so it sells into a budget its own dependencies also compete for. In April 2026 it announced a strategic alliance with SentinelOne. [s4, s11, s18]
The named-customer evidence is solid. Silverfort's trust portal names Agoda, Payoneer, Kayak, UPS, Singtel and Airbus among the organizations that trust it, and IT and security leaders at Kayak, Singtel and Womble Bond Dickinson are quoted by name on the company's site.
The scale figures are weaker than they look, because Silverfort is the source of all of them. TechCrunch reported in January 2024 that the company was signing customers at 100 per quarter with revenue growing 100% annually and recurring revenue in the tens of millions, and SecurityWeek reported hundreds of new enterprise customers the same week, both attributing the numbers to the company. Silverfort restated the same quarterly and revenue figures in its November 2024 acquisition announcement, and the 1,000-plus customer count it cites today appears only on its own pages.
An independent record of a different kind exists: a Coller secondaries fund's SEC filing lists Silverfort, Inc. among its equity holdings, at 159,276 shares. That records a holding under the Silverfort name and nothing about commercial scale. [s1, s9, s10, s11, s12, s13, s17]
The founding team is identifiable and two of the three still hold operating titles. Globes names Hed Kovetz, Yaron Kassner and Matan Fattal as the 2016 founders, all previously in the Israel Defense Forces' 8200 unit, and the company page lists Kovetz as chief executive, Kassner as chief technology officer and Fattal as a co-founder. Kovetz came from product leadership at Verint and Fattal from Intucell, which Cisco acquired.
The commercial bench was hired for scale. Howard Greenfield joined as president in June 2025 from the venture firm Canaan, after earlier revenue leadership at Centrify, now Delinea, and at SailPoint, both of them identity vendors.
What the record does not show is a prior identity-security exit among the founders. Their claim to domain standing is this company: a decade of building it, and an analyst evaluation that rates the product against the biggest vendors in the market. [s3, s15, s18]
Silverfort publishes a SafeBase trust center listing SOC 2, ISO/IEC 27001:2022, GDPR, CCPA, CPRA, the EU-US Data Privacy Framework, Microsoft SSPA and NIST Cybersecurity Framework alignment, with a document library covering penetration test reports, architecture diagrams and a shared responsibility model behind an access request.
The security posture of the product itself gets unusual attention on that portal, which matters for a product that sits in the authentication path. Silverfort states that its platform does not extract passwords, hashes, session keys or other secrets from Active Directory, and that the core can run on-premises as a hardened virtual appliance.
No federal authorization appears in the reviewed sources. For a vendor selling to global enterprises across finance, manufacturing and retail that is an ordinary posture, and what it does hold, a SOC 2 report, an ISO 27001 certification and privacy-framework alignments, is the baseline set enterprise buyers expect. [s9, s12]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| CyberArk | competes with | Rated an Overall Leader in the same analyst evaluation of identity threat detection. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Okta | competes with | Rated an Overall Leader in the same analyst evaluation of identity threat detection. | |
| Microsoft | competes with | Rated an Overall Leader in the same analyst evaluation, and the maker of Active Directory and Entra ID, which Silverfort enforces on top of. | N/AMicrosoft is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product. |
| Semperis | competes with | Evaluated in the same analyst report for Active Directory threat detection and response. | |
| Delinea | competes with | Rated an Overall Leader in the same analyst evaluation. Silverfort's president was earlier chief revenue officer at Centrify, now known as Delinea. | |
| SentinelOne | competes with | Evaluated in the same analyst report for identity threat detection, and named in Silverfort's April 2026 strategic alliance announcement. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
Add analyzed competitors to compare them side by side with Silverfort.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
What makes Silverfort hard to displace is mostly where its software sits, because the cited record does not evidence an asset it retains that a rival could not assemble. The controls run inside the authentication path alongside Active Directory and other identity infrastructure. Replacing the product therefore means putting a different one into a live login path across every system it covers, and the reviewed sources do not size that work. The SOC 2 report and ISO 27001 certification on its trust portal are the baseline assurances enterprise buyers expect, and no government authorization appears in the record. The organizations its trust portal names are multinational firms. What the company holds is a hard engineering position, won one deployment at a time.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Customers buy packaged software, sold in four tiers for on-premises, cloud or hybrid environments with an option to assemble capabilities individually, and support above the standard level is priced as a percentage of the license. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | The product decides and enforces inside a live authentication exchange before it completes, so a replacement has to take that position over, and the cited record does not size that migration. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | The trust portal lists SOC 2, ISO/IEC 27001:2022 and privacy-framework alignment, which a funded competitor obtains through ordinary enterprise preparation, and the record shows no government authorization. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Deciding and enforcing access inside a live authentication exchange across Kerberos, NTLM and LDAP flows and command-line access is real-time systems work, and Silverfort's Series C coverage describes years spent building the platform. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | Silverfort's trust portal names UPS, Airbus, Singtel and Payoneer among the organizations that trust it, and Silverfort, quoted by SecurityWeek, places its customer base in global financial services, manufacturing and retail. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 3/3 | The platform sits in the authentication path that other applications depend on to admit users, machines and agents, rather than presenting an interface an end user works in. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | Silverfort and its press coverage describe the technology as patented, and the reviewed record identifies no granted patent, retained corpus or cross-customer dataset that a competitor could not assemble. |
Silverfort's coverage argument addresses enterprises that run more than one identity system and still depend on older ones. Its trust portal names UPS, Airbus, Singtel, Agoda, Payoneer and Kayak among the organizations that trust it, and Silverfort told SecurityWeek at the Series D that its customer additions came from global financial services, manufacturing and retail.
The segment is defined by a constraint rather than an industry. KuppingerCole describes organizations facing fragmented identity management ecosystems built from separate tools for privileged access, governance and monitoring, which is the shape of estate Silverfort's coverage argument addresses. The coverage half of that argument speaks loudest to buyers who still run the older systems.
The packaging lets a buyer enter at a smaller commitment. The Core package carries posture management and multi-factor authentication, while enforcement capabilities such as the authentication firewall and threat detection sit in higher tiers.
The core mechanism is inline placement rather than an agent. Silverfort describes Runtime Access Protection as integrating with existing identity infrastructure and enforcing before the authentication completes, and Help Net Security in 2022 described the same approach as requiring no modification to endpoints, servers or applications. That is what lets Universal MFA reach legacy applications, command-line tools, OT systems and local Windows logins.
The newer capabilities extend the same placement to non-human and agent access. Non-Human Identity Security discovers service accounts, establishes behavioral baselines and fences their activity, and AI Agent Security discovers agents, binds each to a human owner and controls agent actions before they execute.
The artificial-intelligence claims deserve separating into what ships and what is announced. AI Agent Security is a capability inside the Plus package on the pricing page. The runtime authorization engine, in which each request is evaluated against a knowledge graph with artificial intelligence in the loop when needed, comes from the Fabrix purchase, and Silverfort dated most of those joint capabilities to the second half of 2026, a window the reviewed sources do not report against.
The motion is quote-led enterprise selling, with a channel the company set out to expand. SecurityWeek reported in January 2024 that the Series D capital would go toward product modules and channel go-to-market partnerships, and the company today runs a partner network with a portal, channel partners and a cyber-insurance partner program.
A hired executive now leads the go-to-market organization. Howard Greenfield joined as president in June 2025 from the venture firm Canaan, after earlier revenue leadership at Centrify, now Delinea, and at SailPoint, and the company page says he leads its go-to-market strategy and execution and oversees sales and marketing.
Public proof of demand is a mix of strong names and old numbers. The names on the trust portal are current and checkable, while the growth figures reported by TechCrunch and SecurityWeek in January 2024 came from the company, which restated the same quarterly and revenue figures in its November 2024 acquisition announcement. The reviewed sources carry no newer growth rate, though Silverfort's own pages now count more than a thousand organizations.
Silverfort publishes its packaging but not its prices. Four packages named Core, Plus, Advanced and Enterprise stack capabilities, each including the runtime engine and an identity inventory, and the route forward on the page is a quote request. A la carte purchase of individual capabilities is offered as an alternative.
The stated unit is organization size rather than seats, assets or events. That choice fits a control meant to cover everything, since a per-resource price would penalize the coverage the product is sold on, and it also means a buyer cannot estimate cost from the site.
Support is tiered on top, with a standard level included, a premier level at ten percent of license cost and a diamond level at twenty percent. Silverfort publishes no license figure at all, so a buyer reaches a number only through a sales conversation.
Deployment is designed to avoid touching protected systems. Silverfort states that the core of its platform can be delivered on-premises as a hardened virtual appliance and that it integrates with Active Directory by installing an adapter, and its MFA capability page repeats that no agents or application changes are required.
The company makes a speed claim about rollout, saying customers achieve identity security across the organization within days, which appears in its own acquisition announcement and is not independently corroborated in the reviewed sources.
The operational risk of the design is the flip side of its reach. A control that decides inside authentication has to be available whenever logins happen, and the reviewed sources do not describe what the product does when it cannot reach its own decision path.
The trust surface is real and reasonably complete. A SafeBase portal at trust.silverfort.com lists SOC 2, ISO/IEC 27001:2022, GDPR, CCPA, CPRA, the EU-US Data Privacy Framework, Microsoft SSPA and NIST Cybersecurity Framework alignment, with penetration test reports, architecture diagrams, a shared responsibility model and CISO attestations behind an access request.
For a product inside the authentication path, the more interesting disclosure is architectural. Silverfort states that it does not extract passwords, hashes, session keys or other secrets from Active Directory, so, by the company's own account, a compromise of the appliance would not hand over directory secrets. The sub-processor list names Amazon Web Services, Microsoft Azure, Snowflake, Coralogix and Firebase.
No federal authorization appears in the reviewed sources, which leaves United States government buyers outside what the record shows the company can serve.
Silverfort's platform strategy is to attach to identity systems rather than replace them, and the Rezonate announcement lists Active Directory, Entra ID and other identity and access management products as the infrastructure it enforces on top of. Microsoft is therefore both a dependency and a rival.
The partner answer to that tension is visible in the newsroom. April 2026 brought a strategic alliance with SentinelOne, and June 2026 an integration placing agent identity controls into Microsoft Copilot Studio, both of which extend reach without asking the buyer to leave an existing stack.
The dependency is genuine and worth naming plainly. Silverfort's controls work by enforcing on top of identity infrastructure that Microsoft makes, and Microsoft holds an Overall Leader placement in the same analyst evaluation that rates Silverfort a Product and Innovation Leader.
Two of the three founders hold operating titles a decade in. Globes names Hed Kovetz, Yaron Kassner and Matan Fattal as the 2016 founders, all alumni of the Israel Defense Forces' 8200 unit, and the company page lists Kovetz as chief executive, Kassner as chief technology officer and Fattal as a co-founder. Kovetz came from product leadership at Verint, Kassner worked on machine learning at Microsoft and Cisco, and Fattal built real-time systems at Intucell before Cisco acquired it.
Hiring has been aimed at scale, and one purchase added a team as well as technology. The president joined in 2025 with earlier revenue leadership at two identity vendors, and Calcalist reported that fourteen Fabrix employees would join Silverfort, a group whose leaders came from Run:ai, Orca Security and Microsoft Entra.
The gap in the record is a prior exit in this domain among the founders. They can point to this company and to an analyst evaluation that rates its product in the same market as Microsoft, CrowdStrike and CyberArk.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Silverfort: Identity Security Platform homepage | official | 2026-09-04 |
| f2 | Globes: Israeli identity protection co Silverfort raises $116m | press | 2026-09-04 |
| f3 | SecurityWeek: Identity Security Firm Silverfort Lands $116 Million Investment | press | 2026-09-04 |
| f4 | Silverfort: pricing and package comparison | official | 2026-09-04 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.