Token Security

Security for AI Identity Access also known as Token

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software.
Founded 2023
Funding $27M
Last updated 2026-08-09

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Token Security's software does two jobs, one easy for a buyer to replace and one costly to unwind. As an inventory it finds and tracks the service accounts, API tokens, and AI agents an enterprise accumulates, and established rivals sell the same discovery. As an enforcement layer it decides what each AI agent may access based on the agent's purpose, and a customer using it that way must rebuild agent permissions to leave. Calcalist reported HPE and HiBob as customers eight months after Token left stealth, while established identity vendors consolidate around it, with Cisco moving to acquire rival Astrix and CyberArk completing its Venafi purchase. Watch whether enterprises route agent permissions through Token or treat it as a list of what they have.

Sourced Details

Description Token Security gives security and IAM teams visibility, control, and governance over the AI agents and non-human identities in their environments across the identity lifecycle. [f1]
Founded 2023 [f2]
HQ Tel Aviv, Israel [f3]
Funding $27M total [f2]
Latest funding $20M Series A led by Notable Capital (January 2025) [f4]
Deployment SaaS [f5]
Compliance ISO 27001, SOC 2 Type 2 [f5]

Products

Product What it does
Token Security Security platform for AI agents and non-human identities that discovers and inventories them, maps their access and risk, and enforces intent-based least-privilege.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

Token Security discovers and inventories AI agents and non-human identities, maps their access and risk, and enforces intent-based least-privilege. It is mapped to the AI Defense Matrix. [f6]

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

Token Security discovers conventional non-human identities such as service accounts and API keys, enforces intent-based least privilege, and detects and remediates identity threats. The company is mapped to the Cyber Defense Matrix. [f7]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 27 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Token names its buyers, the security, IAM, and cloud teams, but the headline 50:1 ratio of non-human to human identities is vendor-stated (s1), and the independent coverage from TechCrunch and Calcalist frames the machine-identity problem qualitatively rather than quantifying it (s9, s10). That is present-but-unproven. [s1, s9, s10]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 Token documents concrete modules, discovery, lifecycle, posture, detection and response, and AI-driven remediation, plus intent-based permissioning, the MCP Server, and a risk-ranked Entitlements Inventory on its own pages (s1, s2, s7), but offers no public docs portal, open-source code, or independent technical evaluation, so the external validation the higher rung needs is absent. [s1, s2, s7]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 4/5 Gartner lists Token Security in a defined Workload Identity Management market (s12), Cisco moved to buy rival Astrix for roughly $400 million while CyberArk completed its Venafi purchase (s11, s15), and RSAC named Token a 2026 finalist (s14), multiple buyer-side and analyst signals within twelve months. The enabler is enterprise agentic-AI adoption since about 2024, which spawns autonomous identities legacy IAM does not govern (s5). [s12, s11, s15, s14, s5]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5 TechCrunch verifies the founders' Unit 8200 backgrounds, with Itamar Apelblat on defense and Ido Shlomo on offensive nation-state work, and Calcalist verifies the Notable Capital and veteran-investor backing (s9, s10). The cited record shows no prior exit or sustained publication record, so the evidence stays at verifiable-experience. [s9, s10]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 4/5 Calcalist and TechCrunch press-name HPE and HiBob as customers (s10, s9), the company adds Bloomreach, BetterHelp, and Dayforce (s5), the trust center names reviewers including Dayforce and ZoomInfo (s6), and Gartner Peer Insights shows a 4.7 average across eight reviews (s12). That is multiple named references, multiply sourced, while revenue stays undisclosed, so strong rather than exceptional. [s9, s10, s5, s6, s12]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 Token raised a modest $27 million total and ships visibly, signing named enterprises within eight months of leaving stealth and maintaining a 2026 release cadence of the Entitlements Inventory and the Claude integration (s10, s7, s8). Revenue and margin stay undisclosed and the triple-digit growth figure is vendor-claimed (s5), so output per dollar is visible but efficiency is unconfirmed, the honest default at 3. [s10, s7, s8, s5]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 4/5 Gartner places Token Security in its Workload Identity Management market alongside Entro and Akeyless (s12), journalists apply the non-human and machine identity labels without vendor coaching (s9, s10), and the consolidation of Cisco-Astrix and CyberArk-Venafi shows buyers treating the category as established (s11, s15). The placement no longer needs vendor explanation, lifting it to a 4. [s12, s9, s10, s11, s15]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 Cisco paid roughly $400 million for Astrix and CyberArk bought Venafi rather than building, which puts the scope beyond a quarterly feature (s11, s15), but those same incumbents sell identity suites to Token's buyers and Token shows no proprietary data flywheel in public evidence (s2). Workflow friction without a structural moat supports a 3. [s11, s15, s2]
Business Risks Identity incumbents could bundle agent-identity governance within a few years and close the standalone window…
  • Identity incumbents could bundle agent-identity governance within a few years and close the standalone window. Cisco is folding Astrix Security into its identity portfolio, and CyberArk and other identity incumbents sell adjacent suites to the same buyers.
  • The triple-digit growth claim is vendor-issued with no disclosed revenue or customer counts, so actual traction could be thinner than the logo wall and the eight Gartner reviews suggest.
  • A non-human identity rival such as Oasis Security or Entro Security could land deeper identity-provider partnerships and relegate Token Security to a niche.
  • Emerging agent-identity standards could let cloud and identity providers issue and govern agent credentials natively, which would shrink the discovery and governance gap Token Security monetizes.
  • An enterprise pullback in agentic-AI deployment would defer the AI-agent identity budget line and return the company to the slower service-account hygiene sale.
Problem & Market Token Security targets the gap between how enterprises govern human identities and how they govern machine ones…

Token Security targets the gap between how enterprises govern human identities and how they govern machine ones. The company says AI agents and non-human identities span on-prem, cloud, and AI platforms while outnumbering human identities by 50 to 1. Service accounts, API tokens, and autonomous agents hold credentials that rarely pass through joiner-mover-leaver review, so over-privileged identities persist.

Independent reporting corroborates the pain without confirming the vendor's ratio. TechCrunch tied machine-identity risk to outdated or over-permissioned credentials and quoted CEO Itamar Apelblat saying hackers log in rather than break in, and Calcalist framed the same problem as the reason enterprises are funding the category. The buyers Token names, the security, IAM, and cloud teams, are the teams that carry the remediation work.

Agentic AI shifts the problem from hygiene to runtime control. Agents act autonomously at machine speed, and a single compromised agent can reach every system it connects to, which moves the buyer's question from inventory to enforcement. [s1, s9, s10, s5]

Product Capabilities The Token Security platform covers the machine-identity lifecycle from discovery to remediation…

The Token Security platform covers the machine-identity lifecycle from discovery to remediation. Documented modules include continuous discovery and visibility, lifecycle management, security posture management, identity threat detection and response, and AI-driven automation and remediation, and the platform applies intent-based permissioning so an agent keeps only the access its purpose requires. The discovery module inventories AI agents and MCP servers alongside conventional service accounts and keys.

Token ships AI-native interfaces on top of the platform. The Token MCP Server and AI Agent give security teams a natural-language way to query inventory and posture from tools such as Claude or Cursor, a June 2026 Entitlements Inventory assigns each entitlement a risk level so teams triage the riskiest access first, and a June 2026 integration brings Anthropic's Claude Compliance API into the same governance model so Claude keys, workspaces, and agents are discovered and governed with other non-human identities.

The verifiable footprint is solid for the category, but external validation is thin. There is no public docs portal or third-party technical evaluation, the open-source footprint is a small Custom-GPT discovery tool rather than an open platform, and the eight reviews on Gartner Peer Insights speak to customer satisfaction rather than to capability depth. The inventory and risk map are built per customer, so the engineering is the differentiator rather than any data asset. [s1, s2, s3, s7, s8, s12]

Competitive Positioning Token Security competes in a non-human identity field that platform vendors are now buying into…

Token Security competes in a non-human identity field that platform vendors are now buying into. Oasis Security and Entro Security are named non-human identity peers, and Gartner groups Token Security with Entro and Akeyless in a Workload Identity Management market. The incumbents arrived through acquisition, with CyberArk buying Venafi for machine-identity management and Cisco moving to acquire Astrix Security for a reported $400 million.

Token positions on AI-agent identity rather than the broader machine-identity catalog alone. The about page frames the company as the identity layer that makes agentic AI possible, and the platform leads with creation-to-runtime control of AI agents to reach the buyer feeling autonomous-agent risk now. That framing trades part of the broader machine-identity market for the faster-moving agent slice.

The acquirers that validate the market also become the competition. Cisco plans to fold Astrix into its identity portfolio, and CyberArk and other identity incumbents sell identity suites to the same buyers, so Token needs depth a bundled feature cannot match. [s12, s15, s11, s4, s2]

Go-to-Market & Traction Token Security backs its traction with named enterprise customers…

Token Security backs its traction with named enterprise customers. Calcalist and TechCrunch name HPE and HiBob in independent reporting, the 2025 growth release adds Bloomreach, BetterHelp, and Dayforce, and the trust center lists reviewers including Dayforce, AlphaSense, and ZoomInfo.

Third-party signals reinforce the logo wall. RSAC named Token Security a 2026 Innovation Sandbox finalist, and Gartner Peer Insights shows a 4.7 average across eight customer reviews in the Workload Identity Management market. The company claims triple-digit growth for 2025 in its own release, though revenue and customer counts stay undisclosed.

A hired go-to-market team now fronts part of the selling. The 2025 growth release is datelined New York, which signals a United States enterprise motion layered on top of the Tel Aviv engineering base. [s10, s9, s5, s6, s4, s14, s12]

Team & Credibility Token Security's credibility comes from a founding team with verifiable Unit 8200 depth…

Token Security's credibility comes from a founding team with verifiable Unit 8200 depth. TechCrunch reports that CEO Itamar Apelblat worked on defensive security at Israel's Unit 8200 while CTO Ido Shlomo led offensive work against nation-state targets, and the company is registered as a private limited entity, Token Security Ltd, in Tel Aviv. Public sources show no prior company built and exited by either founder and no sustained publication record.

Veteran investors back the team where the public track record is thin. Calcalist reports a $20 million Series A led by Notable Capital, with participation from TLV Partners and executives from Palo Alto Networks, CrowdStrike, Check Point, and Venafi. Those checks vouch for the founders ahead of disclosed revenue. [s9, s13, s10]

Trust Readiness Token Security publishes the trust collateral enterprise buyers expect before granting broad identity access…

Token Security publishes the trust collateral enterprise buyers expect before granting broad identity access. The SafeBase-hosted trust center lists ISO/IEC 27001:2022 and SOC 2 Type 2 certifications, a pentest report and network diagram behind access gates, and named reviewers including HiBob, PROS, Dayforce, AlphaSense, BetterHelp, and ZoomInfo.

The collateral matters because the product needs privileged reach to do its job. Token discovers and governs identities across cloud, SaaS, CI/CD, source control, and AI platforms, so a buyer is granting visibility into its credential estate, and audit evidence is the precondition for that grant. The certifications ease procurement but do not block a substitute, since every same-stage rival can obtain the same audits and no regulation mandates this product class. [s6, s8]

Competitors Oasis Security, Entro Security, Astrix Security, Aembit, Cisco, CyberArk…
Company Relationship Note Compare
Oasis Security competes with Non-human identity security platform with a broader NHI focus and less emphasis on AI agents.
Entro Security competes with Non-human identity discovery and detection vendor with deep software-pipeline integration. N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable.
Astrix Security competes with Direct non-human identity rival that Cisco moved to acquire in 2026 for a reported $400 million.
Aembit competes with Non-human and workload identity vendor that brokers short-lived credentials for workloads and AI agents.
Cisco adjacent Platform vendor folding Astrix Security into its identity portfolio, turning a rival startup into an incumbent threat. N/AWe scored these companies at different scopes, so the totals measure different things.
CyberArk adjacent Identity security incumbent that bought machine-identity vendor Venafi and sells privileged access to the same buyers.

Add analyzed competitors to compare them side by side with Token Security.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Exposed 12 /21 Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software. pivot urgently

Token Security keeps customers mainly through one mechanism: a buyer that uses it to define and enforce what its AI agents may access must rebuild those permissions to replace it. The engineering underneath, continuous discovery and governance of machine identities across cloud, SaaS, and AI platforms, takes years of specialized work, but rival Astrix holds the same position. Everything else is a credibility floor rather than a moat. The customer runs the software instead of buying judgment Token stands behind. The SOC 2 and ISO 27001 audits ease procurement without blocking a substitute, and the reviewed record shows no product-specific mandate behind them. Token assembles the identity inventory per customer, and the cited record shows no cross-customer dataset or exclusive data right.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Token sells a software platform for discovery, lifecycle, posture, detection, and remediation that the customer configures and runs, with AI-driven remediation and a natural-language interface as software output rather than a managed service or an accountability layer.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Discovery baselines, lifecycle and remediation workflows, and intent-based least-privilege that the product defines and enforces create meaningful friction once embedded, while no network effect or data-residency lock raises it further.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 The trust center publishes SOC 2 Type 2 and ISO/IEC 27001:2022 with access-gated reports. Neither certification establishes a Token-specific mandate, retained liability, or a replacement-blocking authorization, so the assurance eases procurement rather than protecting the position.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Continuous discovery of non-human identities, agents, and MCP servers across on-prem, cloud, SaaS, and AI platforms, plus identity threat detection and an intent-based permissioning engine, is security-critical distributed-systems engineering that takes years of specialized expertise.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3 Named references skew enterprise, with HPE and HiBob press-named and the trust center listing Dayforce, AlphaSense, BetterHelp, and ZoomInfo as reviewers, where procurement slows replacement, but the demo-led motion shows no regulated-only roster.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 Token defines and enforces policies for agent creation, intent, access, and operation, and it integrates with identity providers and privileged access management, which is a platform with application features rather than infrastructure other applications depend on. The cited record shows no agent request passing through Token and names no application that stops working without it, and the platform note in this snapshot treats access-path infrastructure as a prospect rather than a current state.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 The inventory and risk map are built per customer, and the cited record identifies no proprietary cross-customer dataset and no exclusive data right, so the reviewed evidence points to a replicable asset rather than a flywheel.
Strategic Market Segmentation Token Security sells to enterprises whose machine identities have outgrown the controls built for people…

Token Security sells to enterprises whose machine identities have outgrown the controls built for people. The company frames service accounts, API tokens, and autonomous agents as the population legacy joiner-mover-leaver governance never covered, and it names security, identity and access management, and cloud teams as the buyers who carry that work. The about page positions the company as the identity layer that makes agentic AI possible.

Token now leads with agentic-AI messaging while still serving the broader non-human identity estate. It secures every non-human identity from service accounts to AI agents, but the messaging leads with creation-to-runtime control of agents, which targets the buyer feeling autonomous-agent risk now rather than the buyer doing routine service-account hygiene. That emphasis may concentrate demand among buyers with urgent agent-governance needs rather than the broader machine-identity base.

Named demand spans recognizable enterprises rather than design partners alone. Calcalist reports HPE and HiBob as customers, and the trust center names HiBob, PROS, Dayforce, AlphaSense, BetterHelp, and ZoomInfo among its reviewers. The open question is whether the agent-identity pitch pulls a budget line distinct from service-account spend or sells into the identity budget rivals already contest.

Product Capabilities & AI Advantages Token Security covers the machine-identity lifecycle from discovery through automated remediation…

Token Security covers the machine-identity lifecycle from discovery through automated remediation. The platform runs continuous discovery and visibility, lifecycle management, security posture management, identity threat detection and response, and automation and remediation, and the product page describes intent-based permissioning that aligns an agent's access with what it is meant to do rather than the credentials it holds. That intent model replaces long-lived, over-scoped credentials with purpose-bound access and right-sizes permissions as agent behavior evolves.

The AI-native interfaces sit on top of that platform rather than replacing it. The Token MCP Server and AI Agent let teams query inventory and posture in natural language from tools such as Claude or Cursor, a June 2026 Entitlements Inventory ranks every entitlement by risk so teams triage the riskiest access first, and a June 2026 integration brings Anthropic's Claude Compliance API into the same model so Claude keys, workspaces, and agents are governed alongside other non-human identities. The cadence shows a team extending coverage toward the AI platforms its buyers adopt.

The public footprint is credible, and it is engineering depth rather than a data moat. The inventory and risk map are built per customer from the identity logs and telemetry Token says it analyzes, and the natural-language layer is an interface over the same platform data, reachable from common chat applications. A metadata flywheel across customers is conceivable for an inventory product of this kind, but the cited sources identify no proprietary cross-customer dataset or exclusive data right.

Sales Engagement & Go-to-Market Token Security runs a demo-led enterprise motion with a public proof-of-demand record for its stage…

Token Security runs a demo-led enterprise motion with a public proof-of-demand record for its stage. Every product and platform page routes to a book-a-demo call rather than self-serve signup, which signals a sales-assisted enterprise purchase. The company reached named enterprises within months of leaving stealth, and Calcalist reported HPE and HiBob as customers eight months after it emerged from stealth.

External validation arrived faster than disclosed revenue. RSAC named Token a 2026 Innovation Sandbox finalist, Gartner Peer Insights lists it in the Workload Identity Management market with a 4.7 average across eight customer reviews, and the company claims triple-digit 2025 growth in its own release. Peer Insights ratings are end-user opinions rather than analyst-authored placement, so these are program and buyer-side signals on top of named-customer adoption.

Investor and acquirer behavior frames the commercial context. TechCrunch reported a $20 million Series A bringing total funding to $27 million, and the same identity vendors that validate the category are buying into it, with Cisco moving to acquire Astrix and CyberArk completing its Venafi purchase. Disclosed revenue or a customer count beyond the named logos does not appear in fetched sources.

Pricing Model Token Security publishes no pricing in fetched sources, so the charged unit and list price stay private…

Token Security publishes no pricing in fetched sources, so the charged unit and list price stay private. Every conversion path on the product and platform pages is a book-a-demo call rather than a published plan, which usually signals negotiated enterprise deals. The absence withholds any budget-anchoring signal, so a buyer cannot size the spend before entering a sales conversation.

The charged unit is not stated, though the product shape suggests what buyers pay for. Token meters a population it discovers, the non-human identities and agents across cloud, SaaS, CI/CD, source control, and AI platforms, so the natural unit is identities or agents under management rather than human seats. Confirming whether the meter is identities, integrations, or a platform subscription would require a sales conversation.

The model reads as capacity for governing a growing identity estate rather than a per-feature license. The agent-first framing and the intent-based control plane point at a buyer paying to bring an expanding machine-identity population under one policy, but the specific consumption terms stay behind the demo gate.

Product Delivery & Operations Token Security delivers as software the customer configures and operates, not as a managed service…

Token Security delivers as software the customer configures and operates, not as a managed service. The platform discovers, inventories, and governs non-human identities across on-prem, hybrid, and cloud environments, and the buyer runs it against its own estate rather than handing the function to Token analysts. Nothing in fetched sources describes a managed-detection or analyst-staffed operating model alongside the platform.

The AI-native layer changes how operators interact with the platform rather than who runs it. The Token MCP Server and AI Agent let teams query inventory and posture and request guided remediation in natural language, and automation and remediation modules act on findings the platform surfaces. Operators meet the platform inside the tools they already use.

Operational maturity collateral is partial. The trust center lists a network diagram and a penetration-test report in its document library, with sensitive information available through a request-access flow, which is more operational evidence than many same-stage rivals show, but published uptime commitments or support service-level agreements do not surface in fetched pages.

Earning Customers' Trust Token Security publishes the trust collateral an enterprise buyer expects before granting broad identity access…

Token Security publishes the trust collateral an enterprise buyer expects before granting broad identity access. The SafeBase-hosted trust center lists ISO/IEC 27001:2022 and SOC 2 Type 2 certifications and a documents library that lists a pentest report and a network diagram, with sensitive information available through a request-access flow. The certifications and request-gated reports are stronger procurement evidence than a footer badge alone.

The collateral matters because the product needs privileged reach to do its job. Token discovers and governs identities across cloud, SaaS, CI/CD, source control, and AI platforms, so a buyer is granting visibility into its credential estate, and audit evidence is the precondition for that grant. The trust center displays HiBob, Dayforce, and ZoomInfo under the heading "reviewed and trusted by", which is the vendor's own framing rather than published evidence that each completed the review.

The attestations are enterprise-grade but table stakes rather than a moat. The two certifications ease procurement, and neither one establishes a Token-specific mandate, retained liability, or an authorization a replacement would have to reproduce, so they do not block a substitute. A buyer should still resolve data-handling and retention terms in a formal review beyond the published certifications.

Platform Strategy & Ecosystem Positioning Token Security positions as the identity control plane for non-human and agent identities rather than a point scanner…

Token Security positions as the identity control plane for non-human and agent identities rather than a point scanner. The Claude integration blog calls the product a unified control plane that brings AI-platform identities into the same governance model as other non-human identities, and the about page frames the company as the identity layer that makes agentic AI possible. The platform claim rests on becoming the place agent access is defined and enforced.

That control-plane position is a sharper bet than discovery alone, because intent-based least-privilege defines and enforces what agents may do. The Claude blog casts agent workflows as identity-driven access paths and Token as the control plane that secures them, so the product could become access-path infrastructure if customers adopt it for enforcement rather than only inventory. How deep that runs turns on whether buyers route agent governance through Token or query it occasionally.

The exposure is that adjacent identity vendors already own the control plane for humans. The incumbents arrived in non-human identity through acquisition, with Cisco moving to buy Astrix and CyberArk completing its Venafi purchase, so the agent-identity layer Token is building is ground established identity platforms are positioned to extend into.

Team & Execution Capability Token Security's credibility comes from a founding team with verifiable national-security depth…

Token Security's credibility comes from a founding team with verifiable national-security depth. TechCrunch reports the company was founded in 2023 and ties the founders to Israeli signals-intelligence backgrounds, with Apelblat on defense and Shlomo on offensive nation-state work. The cited sources describe entrepreneurial ventures and startup experience without identifying a prior company the founders built and exited.

The investor bench reinforces the founder signal where the public track record is thin. Calcalist reports the $20 million Series A was led by Notable Capital with total funding reaching $27 million, drawing participation from TLV Partners and executives from Palo Alto Networks, CrowdStrike, Check Point, and Venafi. That backing across an early round is itself a signal about the founders.

The depth below the founders is the open question. Fetched sources establish the founding team and the lead investor but do not surface individual prior builds across the broader leadership bench, so the verifiable strength is the founders' domain background and the investor confidence it has drawn.

Sources

Company Detail Sources (7)
Id Source Tier Accessed
f1 Token Security: Identity-First AI Agent Security official 2026-07-09
f2 TechCrunch on the Token Security Series A press 2026-06-29
f3 RSAC 2026 Innovation Sandbox finalist analysis research 2026-06-12
f4 CTech on the Token Security Series A press 2026-06-29
f5 AI Defense Matrix Catalog entry other 2026-06-13
f6 AI Defense Matrix Catalog mapping other 2026-06-23
f7 Token Security platform official 2026-06-12
Profile Analysis Sources (15)
Id Source Tier Accessed
s1 Token Security homepage
“AI Agent and non-human identitites span across on-prem, cloud and AI platforms, while outnumbering human identities by 50:1.”
official 2026-06-29
s2 Token Security platform overview
“Token Security understands AI agent intent to align access with what an AI agent is meant to do.”
official 2026-06-29
s3 Token MCP Server and AI Agent page
“The Token MCP Server and AI Agent deliver a real-time natural language interface that lets security teams interact directly with their environment.”
official 2026-06-29
s4 Token Security about page
“We are on a mission to secure the autonomous enterprise. As AI agents evolve from simple assistants to independent actors, Token Security provides the identity lifecycle and intent-based access management required.”
official 2026-06-29
s5 Token Security 2025 growth release
“The company achieved triple-digit growth as cybersecurity, IAM, and cloud teams raced to gain visibility, control, and governance over the fastest-growing attack surface in their enterprise: Agentic AI.”
official 2026-06-29
s6 Token Security trust center
“Compliance ISO/IEC 27001:2022 SOC 2 Type 2. Token Security is reviewed and trusted by HiBob PROS Dayforce AlphaSense BetterHelp ZoomInfo.”
official 2026-06-29
s7 Token Security Entitlements Inventory launch blog
“Every entitlement is assigned a risk level, allowing teams to triage the riskiest access first. The Entitlements Inventory feature now gives them that view.”
official 2026-06-29
s8 Token Security Claude Compliance API integration blog
“Token Security's integration with Claude's Compliance API brings Claude into the same security and governance model as other non-human and AI agent identities across cloud, SaaS, CI/CD, source control, and AI platforms.”
official 2026-06-29
s9 TechCrunch on the Token Security Series A
“Token Security, which emerged from stealth earlier this year and was founded in 2023, has now raised $20 million in Series A funding”
press 2026-06-29
s10 CTech on the Token Security Series A
“raised $20 million in Series A funding led by Notable Capital. The round comes just eight months after the company emerged from stealth, bringing total funding to $27 million. Token customers include HPE and Hibob.”
press 2026-06-29
s11 SecurityWeek on Cisco moving to acquire Astrix Security
“Cisco on Monday announced its intent to acquire Astrix Security... While Cisco did not disclose financial terms, Calcalist reports the deal to be valued at roughly $400 million.”
press 2026-06-29
s12 Gartner Workload Identity Management market listing for Token Security (4.7, 8 reviews)
“Token Security 4.7 (8 Ratings). Token Security provides a comprehensive solution for managing and securing non-human identities.”
research 2026-06-29
s13 OpenCorporates: Token Security Ltd (Israeli registry)
“Status Active. Company Type Private Limited Company. Jurisdiction Israel. Alternative Names TOKEN SECURITY.”
regulatory 2026-06-29
s14 RSAC 2026 Innovation Sandbox finalists announcement
“Token Security accelerates secure enterprise Agentic AI adoption by discovering, managing, and governing every AI agent and non-human identity.”
press 2026-06-29
s15 CyberArk completes its acquisition of Venafi
“today announced the successful completion of its acquisition of Venafi, a leader in machine identity management, from Thoma Bravo”
press 2026-06-29
Deep-Dive Sources (14)
Id Source Tier Accessed
s1 Token Security homepage: machine-first AI-native identity security
“Token Security secures every non-human identity, from service accounts and API tokens to AI agents, with continuous discovery, control, and automated response. Discovery & Visibility Lifecycle Management Security Posture Detection & Response Automation & Remediation”
official 2026-06-29
s2 Token Security platform: secure every AI agent from creation to runtime
“Token Security understands AI agent intent to align access with what an AI agent is meant to do. Replace over-scoped credentials with intent-based access. Automatically enforce least privilege as agent behavior and intent evolve.”
official 2026-06-29
s3 Token Security MCP Server and AI Agent natural-language interface
“The Token MCP Server and AI Agent deliver a real-time natural language interface that lets security teams interact directly with their environment.”
official 2026-06-29
s4 Token Security about page: identity layer for agentic AI
“We are on a mission to secure the autonomous enterprise. As AI agents evolve from simple assistants to independent actors, Token Security provides the identity lifecycle and intent-based access management required.”
official 2026-06-29
s5 Token Security Trust Center (SafeBase): certifications, documents, reviewers
“Compliance ISO/IEC 27001:2022 SOC 2 Type 2. Token Security is reviewed and trusted by HiBob PROS Dayforce AlphaSense BetterHelp ZoomInfo.”
official 2026-06-29
s6 Token Security Claude Compliance API integration into the identity control plane
“Token Security's integration with Claude's Compliance API brings Claude into the same security and governance model as other non-human and AI agent identities across cloud, SaaS, CI/CD, source control, and AI platforms.”
official 2026-06-29
s7 Token Security Entitlements Inventory launch blog
“Every entitlement is assigned a risk level, allowing teams to triage the riskiest access first. The Entitlements Inventory feature now gives them that view.”
official 2026-06-29
s8 Token Security 2025 growth release
“The company achieved triple-digit growth as cybersecurity, IAM, and cloud teams raced to gain visibility, control, and governance over the fastest-growing attack surface in their enterprise: Agentic AI.”
official 2026-06-29
s9 TechCrunch on the Token Security Series A (funding, founders, problem)
“Token Security, which emerged from stealth earlier this year and was founded in 2023, has now raised $20 million in Series A funding.”
press 2026-06-29
s10 CTech on the Token Security Series A (backers, named customers)
“raised $20 million in Series A funding led by Notable Capital. The round comes just eight months after the company emerged from stealth, bringing total funding to $27 million. Token customers include HPE and Hibob.”
press 2026-06-29
s11 SecurityWeek on Cisco moving to acquire Astrix Security
“Cisco on Monday announced its intent to acquire Astrix Security... While Cisco did not disclose financial terms, Calcalist reports the deal to be valued at roughly $400 million.”
press 2026-06-29
s12 CyberArk completes its acquisition of Venafi
“today announced the successful completion of its acquisition of Venafi, a leader in machine identity management, from Thoma Bravo”
press 2026-06-29
s13 Gartner Peer Insights Workload Identity Management listing for Token Security (4.7, 8 customer ratings)
“Token Security 4.7 (8 Ratings). Token Security provides a comprehensive solution for managing and securing non-human identities.”
research 2026-06-29
s14 RSAC 2026 Innovation Sandbox finalists announcement
“Token Security accelerates secure enterprise Agentic AI adoption by discovering, managing, and governing every AI agent and non-human identity.”
press 2026-06-29

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.