All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Willow sells a governed gateway that gives every enterprise AI agent a scoped identity, routes its tool calls through one control point, and logs and can shut down what the agent does. One customer carries most of its public proof. With Willow, Wix built infrastructure supporting nearly 600 tools and over 300,000 weekly tool calls across about 5,000 users. Wix is also the founders' former employer, and two of its executives, co-founder Avishai Abrahami and president Nir Zohar, were early angel backers, so the flagship reference is relationship-linked. Willow does name a non-Wix customer, Innovid, but only Wix is quantified in public. Three former Wix engineers raised a $7 million seed led by Hetz Ventures in June 2026, and the signal to watch is a non-Wix account reaching that depth.
| Description | Identity and access platform for enterprise AI agents. Willow runs as a governed gateway that discovers the agents, tools, and MCP servers in use, issues each agent a scoped credential tied to a real user, and enforces runtime least-privilege with audit and containment. | [f1] |
|---|---|---|
| Founded | 2024 | [f2] |
| HQ | Herzliya, Israel | [f3] |
| Funding | $7M total | [f1] |
| Latest funding | Seed, $7M (June 2026), led by Hetz Ventures | [f4] |
| Product | What it does |
|---|---|
| Willow | Governed access gateway for enterprise AI agents that discovers agents, tools, and MCP servers, issues each a scoped credential tied to a real user, and enforces runtime policy with audit. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Willow discovers every AI agent, tool, and MCP server including unapproved ones, issues each agent a scoped credential tied to a real user with least-privilege, and logs and can contain agent activity. These capabilities are mapped to the AI Defense Matrix. [f5]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Willow names the enterprise security and platform buyer and the gap of agents reaching internal systems faster than governance can follow, and identity incumbents entering the space corroborate the concern, but the scale figures it cites are its own survey data and the pain is generic to the category. [s2, s14, s15] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 3/5 | Willow documents concrete mechanics, per-agent scoped credentials, runtime least-privilege across SaaS, dedicated-cloud, self-hosted, and air-gapped deployments, shadow discovery, and audit, evidenced in the Wix deployment, but no cited open code or independent third-party technical evaluation validates the depth, and the public docs the site links are first-party material rather than independent validation. [s2, s10, s11, s6, s20] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 | The enabler is the 2024 to 2026 rise of the MCP agent-tool standard and enterprise agent adoption, which opened the ungoverned agent-access surface Willow closes. Buyer-side pull appears in surveyed multi-agent adoption, identity incumbents Okta and CyberArk entering agent access, and a production deployment of about 5,000 users at Wix, multiple demand signals within the year. [s14, s15, s6] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 | The three founders, Eyal Ben Ezra, Shalev Shalit, and Idan Chetrit, are former Wix engineers with verifiable in-domain experience, and Wix executives Avishai Abrahami and Nir Zohar backed the seed as angels, but the record shows no prior exit, sustained publication, or independent recognition that would lift the team higher. [s12, s13] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 | Willow's deepest reference is Wix, where with Willow the company built infrastructure supporting nearly 600 tools and 300,000 weekly tool calls, and it also shows a named non-Wix customer, Innovid, and a self-displayed logo wall, but the references sit on Willow's own site, only Wix is corroborated at scale, and Wix is a related party whose executives are angel backers, so the traction holds the score at 3 rather than the independently multi-sourced 4. [s6, s7, s19, s13] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | The 7 million dollar seed is broadly proportional to a seed-stage company shipping a product already in production at Wix, but with no disclosed revenue, margin, or growth-efficiency signal, output per dollar is unconfirmed, the honest default for a funded startup at this stage. [s9, s6] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 | Willow fits the emerging agent-identity and MCP-gateway category that Okta and CyberArk are entering, but the company itself calls the category fast-filling and still explains its placement against basic gateways, so buyers cannot yet place it without vendor coaching. [s5, s14, s3] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | The core, an identity-aware gateway for agent tool access, is what identity incumbents are moving toward and MCP gateways are commoditizing, but Willow's runtime enforcement, connector catalog, and at-scale embedding at Wix add real absorption friction. [s14, s7, s2] |
Willow sells to the enterprise security and platform team that wants employees and agents to use AI tools without losing control of what those agents can reach. The company frames the gap as AI agents connecting to internal systems faster than security can see or govern, including shadow AI that nobody approved, where an agent holds standing access to production data and tools.
The concern is echoed beyond Willow's own marketing. Crypto Briefing reports that identity incumbents Okta and CyberArk have signaled interest in agent-related access, because their platforms were built for human identity first, which places the same problem on the incumbents' roadmaps. Calcalist, citing Willow's own data, reports that most companies now run AI agents and that a majority have had an agent-related incident in the past year, so the urgency is real even though the specific figures are the vendor's. [s2, s14, s15]
Willow is a governed gateway that gives each AI agent a scoped credential tied to a real user and brokers its access to enterprise tools. The identity and access page describes provisioning, suspending, and auditing agents individually, with credentials that are scoped and time-bound rather than standing. SecurityWeek describes the platform integrating with Okta and Entra, assigning an identity to every operating agent, controlling which internal endpoints an agent can reach, and enforcing least-privilege at runtime.
The platform pairs that control with discovery, audit, and containment. Willow describes finding the agents, tools, and MCP servers in use, including unapproved ones, and adds rules, guardrails, PII protection, approvals, audit trails, and observability on one control plane. Deployment spans software-as-a-service, dedicated cloud, and self-hosted setups, including fully air-gapped environments, which fits a security buyer that cannot route agent traffic through a shared cloud.
Willow shows its depth through a running deployment rather than an independent test. With Willow, Wix built enterprise infrastructure supporting nearly 600 tools and more than 300,000 weekly tool calls, described in detail by the company's engineers. No cited open code or independent third-party technical evaluation corroborates the capability from outside Willow's own account, and the public docs the site links are first-party material rather than independent validation. [s2, s10, s3, s6, s20]
Willow competes in a fast-filling agent-identity and MCP-gateway category against both startups and the identity incumbents moving to own it. Aembit, Astrix Security, Token Security, Natoma, and Keycard cover overlapping ground in credentialing and governing non-human and agent identities, and Willow itself notes that many rivals are open-source projects, positioning its managed enterprise platform against them.
Its stated edge is enterprise readiness proven early rather than a unique feature. Willow points to CISO sign-off, an audit trail, deployment flexibility, native shadow-AI detection, and runtime policy as the reasons it fits large organizations, and the Wix deployment is the evidence it offers that the approach works at scale.
The structural pressure is the incumbents. Crypto Briefing reports Okta and CyberArk moving toward agent-related access, and those platforms already hold the enterprise's human identity, so they are positioned to fold agent identity into a suite the buyer already licenses. Willow's answer is depth of embedding rather than a barrier the incumbents cannot cross. [s5, s14, s3]
Willow's go-to-market pairs a free entry point with an enterprise motion and leans on a small set of named references. The pricing page invites buyers to start free and scale into skills, approvals, audit trails, and enterprise deployment, and the product routes prospects to a demo. Wix is the one deployment quantified in public. With Willow, Wix built enterprise infrastructure supporting nearly 600 tools and more than 300,000 weekly tool calls, used by about 5,000 weekly users.
That flagship reference is deep but not arms-length. Wix is the founders' former employer, and two Wix executives, co-founder Avishai Abrahami and president Nir Zohar, were early angel backers, so the biggest deployment and the earliest backers are one relationship. Willow does show non-Wix references, a named Innovid testimonial and a self-displayed logo wall, and says deployments are expanding into cyber security, real estate, and fintech, but only the Wix deployment is quantified in public.
Investor conviction reinforces the picture without settling it. Hetz Ventures led the 7 million dollar seed and the Wix founders backed it, a credible signal that experienced buyers value the product. Whether Willow turns these early references into a broad independent base is what the next named customers will show. [s17, s6, s13, s19, s8]
Willow was founded by three former Wix engineers who built the product inside a large public company before spinning it out. Crypto Briefing names Eyal Ben Ezra as CEO, Shalev Shalit as CTO, and Idan Chetrit as VP Platform, all from Wix. That background is directly relevant, because the team built enterprise AI access infrastructure at scale before selling it to others.
The pedigree is verifiable but not yet decorated. The founders show senior in-domain engineering experience rather than a prior exit, a sustained publication record, or independent industry recognition, which is the evidence the next scoring rung would need. Wix co-founder and CEO Avishai Abrahami and president Nir Zohar backing the seed as angels is a strong external vote of confidence in the team, though it also ties the company closely to a single relationship. [s12, s13]
Willow states enterprise access controls and one attestation. Its rebrand announcement lists SSO with Okta and Azure AD, RBAC, SCIM, and SOC 2, and the platform adds audit trails, approvals, and PII protection as procurement-facing controls. The SOC 2 is company-stated and table-stakes for this buyer rather than a differentiator.
A trust-surface probe found no public self-serve trust portal or downloadable report in the reviewed surfaces, with trust.withwillow.ai, security.withwillow.ai, and the /trust and /security paths all not-found as of July 2026. The pricing page states SOC 2 Type II with documentation available on request, so the attestation is vendor-stated and shared on request rather than open. Because the product sits in the path of agent access to internal systems, an enterprise reviewer still has to request the report rather than self-serve it. [s4, s18, s21, s2]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Aembit | competes with | Brokers scoped credentials for non-human and agent identities across clouds and SaaS, overlapping Willow's per-agent credential and access control. | |
| Natoma | competes with | Governed MCP gateway that gives AI agents identity-aware, per-tool authorization, the same gateway-and-identity motion Willow sells. | |
| Astrix Security | competes with | Secures non-human and agent identities across enterprise systems, contesting Willow's discovery and access-governance layer. | |
| Token Security | competes with | Manages non-human and machine identities for the enterprise, overlapping Willow's agent-identity inventory and governance. | |
| Keycard | competes with | Issues identity and access controls for AI agents, a direct agent-identity competitor at a similar early stage. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Okta | adjacent | Identity incumbent that press reports is signaling interest in agent-related access, positioned to bundle the control layer Willow sells. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| CyberArk | adjacent | Privileged-access incumbent moving toward agent identity, positioned to absorb Willow's layer into a platform enterprises already license. | N/AThese companies operate in different domains, so the scores reflect readiness in different markets. |
Add analyzed competitors to compare them side by side with Willow.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
Willow is sticky because of where it sits between agents and tools. Every tool call runs through its gateway under a scoped, per-agent credential, so replacing Willow means re-plumbing how every agent connects and reabsorbing the policies, credentials, and Okta wiring it handled. At Wix that embedding is real, where Willow supports 300,000 weekly tool calls for about 5,000 users. What Willow accumulates, though, is thin. Its stated SOC 2 is table-stakes, and its connectors and audit logs are engineering a funded rival can rebuild. Natoma shipped the same kind of gateway and is under a pending Snowflake acquisition. Willow's edge is being early and embedded in a customer, a head start rather than a durable lock. The depth of the next enterprise's integration is what to watch.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Willow is software the customer configures and runs, self-service from a free tier into enterprise deployment, with no analyst-staffed managed-service layer that accepts accountability for outcomes, so it is delivered as a software product. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Once Willow sits in the agent access path with accumulated per-agent credentials, policies, connector wiring, and Okta integration, replacing it means re-plumbing how every agent reaches every tool and reabsorbing that integration, but no network effect or data-residency lock appears in the record. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | Willow states SOC 2, SSO, RBAC, and SCIM, common attestations and controls that ease enterprise procurement but do not form a moat absent a regime that mandates a governed agent gateway as a product class. No inspectable third-party report was found by probe as of July 2026. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Building an inline gateway that authenticates and authorizes every agent tool call across SaaS, dedicated-cloud, self-hosted, and air-gapped environments, with least-privilege at runtime plus shadow discovery, is security-critical distributed-systems engineering where a failure would disrupt production agent access. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 | The named buyer is the large enterprise, with Wix on record at about 5,000 users and expansion into regulated sectors stated but unnamed, where procurement and security review slow replacement, but the free tier and self-service entry blend the profile. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 3/3 | Willow is the path agents authenticate and route through to reach tools, a gateway that brokers every connection and enforces policy in-line rather than observing from the side, so agents reach tools through it rather than around it. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | Willow's connector catalog, per-agent policies, and audit logs are tenant-specific configuration and replicable engineering rather than a named non-public corpus, so a funded rival could rebuild the gateway from the same Model Context Protocol standard. |
Willow targets the enterprise security and platform team standing up AI agents at scale. The buyer is the organization where employees and agents already reach for internal tools and where security cannot see or govern that access. Wix is the named instance, an AI Core team whose company-wide rollout now reaches about 5,000 weekly users, with Willow supporting nearly 600 internal tools.
The product is built for that buyer rather than a single developer experimenting with one agent. Willow offers software-as-a-service, dedicated cloud, and self-hosted deployment, including fully air-gapped environments, which are the options a security review demands before agents touch production systems. The identity and access controls, audit trails, and approvals target the same formal buyer.
A free tier widens the top of the funnel without changing the target. Willow invites teams to start free and grow into skills, approvals, audit trails, and enterprise deployment, and the company says deployments are expanding into cyber security, real estate, and fintech. Beyond Wix it names one reference, Innovid, and shows a Trusted-by logo wall, so the enterprise focus rests on the Wix account plus a thin set of other references and the vendor's roadmap.
Willow's claimed advantage is sitting in the path agents take to reach tools rather than watching from the side. Each agent receives a scoped, time-bound credential tied to a real user, and the platform integrates with Okta and Entra, controls which internal endpoints an agent can reach, and enforces least-privilege at runtime. Policy applies at the moment of access rather than being reconstructed from logs afterward.
Discovery, audit, and containment pair with the enforcement layer. Willow describes finding the agents, tools, and MCP servers in use, including unapproved shadow AI, and adds rules and guardrails, PII protection, approvals, audit trails, and observability on one control plane. Administrators can provision, suspend, and audit agents individually, which is the containment a security team needs when an agent misbehaves.
What holds up is the gateway position and the engineering, not a model advantage or a proprietary dataset. The connector catalog, per-agent policies, and audit logs are software a funded rival could rebuild from the same Model Context Protocol standard, and no proprietary model or named non-public dataset appears in the fetched record. The verifiable strength is a real at-scale deployment rather than an independent technical evaluation.
Willow runs a free-to-enterprise motion led by a handful of named references. The pricing page invites buyers to start free and scale into skills, approvals, audit trails, and enterprise deployment, and the product routes prospects to a demo. Wix is the one deployment quantified in public. With Willow, Wix built enterprise infrastructure supporting nearly 600 tools and more than 300,000 weekly tool calls, used by about 5,000 weekly users.
That flagship reference is deep but relationship-linked. Wix is the founders' former employer, and two Wix executives, co-founder Avishai Abrahami and president Nir Zohar, were early angel backers, so the biggest deployment and the earliest backers are one relationship. Willow does show non-Wix references, a named Innovid testimonial and a self-displayed logo wall, and says deployments are expanding into cyber security, real estate, and fintech, but only the Wix deployment is quantified in public.
Investor conviction reinforces the picture without settling it. Hetz Ventures led the 7 million dollar seed, and the two Wix executives' earlier angel checks add investor validation rather than proof that buyers chose the product. What the record does not yet show is a non-Wix enterprise running Willow at comparable depth, which the next detailed customer story would provide.
Willow publishes tiered pricing, which is uncommon for an enterprise security product and lets a buyer see the entry cost. A free plan carries no cost for up to 5 users, 5 integrations, and unlimited tool calls with proxy support only. A paid plan runs at $15 per seat and adds unlimited members, on-premises integrations, built-in MCPs, and premium support. An enterprise plan is custom and quoted through a contact-us flow, adding flexible on-premises or cloud deployment, SCIM, and guardrails.
The metering shows what Willow charges for. The paid tier bills by the seat rather than by agent or tool call, and every tier keeps tool calls unlimited, so cost scales with the people using the platform rather than the volume of agent activity. That choice prices Willow like a per-user platform, and it leaves the enterprise price, where on-premises deployment and policy controls live, to a negotiated contract.
Willow sells software in several delivery modes rather than an analyst-staffed managed service. It offers software-as-a-service that Willow operates, dedicated cloud, and self-hosted deployment, including fully air-gapped environments, so a buyer can place the gateway where its security posture requires. In every mode the buyer sets the policy, and no analyst-staffed layer takes accountability for outcomes.
The inline role raises the operational stakes. Because every agent tool call routes through Willow, its availability and latency directly affect whether agents can act, so Willow becomes a dependency in the agent's access path. That is the same exposure a network gateway carries, and it makes reliability a first-order concern for a buyer putting agents into production.
Operational commitments are not spelled out in the fetched record. Willow describes audit trails and observability, but the public pages do not publish an uptime SLA or incident-response terms, so the operational assurance an enterprise change-management review looks for rests for now on the Wix deployment rather than stated guarantees.
Willow states enterprise access controls and one attestation. Its rebrand announcement lists SSO with Okta and Azure AD, RBAC, SCIM, and SOC 2, and the platform adds audit trails, approvals, and PII protection as procurement-facing controls. The SOC 2 is company-stated and eases procurement without setting Willow apart.
A trust-surface probe found no public self-serve trust portal or downloadable report in the reviewed surfaces, with trust.withwillow.ai, security.withwillow.ai, and the /trust and /security paths all not-found as of July 2026. The pricing page states SOC 2 Type II with documentation available on request, so the attestation is vendor-stated and shared on request rather than open.
That posture matters more than usual because the product sits in the path of agent access to sensitive systems. A gateway that authorizes and brokers every tool call handles credentials, policy, and a record of every action, so a security buyer weighs the attestation alongside the audit trail and identity controls. For now an enterprise reviewer has to request the report rather than self-serve it.
Willow positions itself as the control plane between AI agents and enterprise tools rather than a point control. It standardizes how agents connect through one governed gateway, maintains a catalog of connectors, skills, and plugins, and works across agents such as Claude, ChatGPT, and Cursor. The claim rests on owning the access path agents traverse to reach company systems.
That position is what platform owners are moving to control. Crypto Briefing reports Okta and CyberArk signaling interest in agent-related access, and those vendors already hold the enterprise's human identity, so they are the natural owners of agent identity too. An independent gateway is exposed to an incumbent folding the same control into a suite the buyer already licenses.
A pending deal points the same direction. Snowflake signed a definitive agreement to acquire Natoma, a comparable enterprise Model Context Protocol gateway, a sign that a major data platform wants this layer integrated; the deal had not closed as of the cited release. Willow's counter is depth of embedding at a customer, which slows absorption without removing the incumbents' structural advantage.
Willow's founders come from engineering roles at Wix. Crypto Briefing names Eyal Ben Ezra as CEO, Shalev Shalit as CTO, and Idan Chetrit as VP Platform, all former Wix engineers. After founding Willow, the team deployed it at scale at their former employer, which is where its flagship proof lives.
The pedigree is verifiable but not yet decorated. The cited sources document Wix engineering experience but do not document a prior exit, a sustained publication record, or independent recognition. Wix co-founder Avishai Abrahami and president Nir Zohar backing the seed as angels is a strong external vote for the team, though it also concentrates the company's early validation in a single relationship with its former employer and first customer.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | SecurityWeek on Willow identity and access platform for AI agents | press | 2026-07-06 |
| f2 | webrix.ai domain registration record (RDAP), registered 2024-05-04, earliest verifiable Willow (formerly Webrix) footprint | regulatory | 2026-07-06 |
| f3 | Willow launch announcement dateline | official | 2026-07-06 |
| f4 | Crypto Briefing on Willow seed round and investors | press | 2026-07-06 |
| f5 | AI Defense Matrix Catalog mapping | other | 2026-07-06 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Willow homepage “One governed connection to any tool.” | official | 2026-07-06 |
| s2 | Willow identity and access page “Each agent receives a governed credential, scoped, time-bound, tied to a real user. Provision, suspend, and audit agents individually.” | official | 2026-07-06 |
| s3 | Willow platform overview “One control plane for every AI agent, tool, and skill in your enterprise.” | official | 2026-07-06 |
| s4 | Willow rebrand announcement, security controls “SSO with Okta and Azure AD. RBAC. SCIM. SOC 2.” | official | 2026-07-06 |
| s5 | Willow rebrand announcement, enterprise positioning “Many competitors are open-source projects wearing enterprise badges. Willow is a managed enterprise platform from day one.” | official | 2026-07-06 |
| s6 | Willow launch post, Wix production deployment “The platform is already running in production at Wix, powering ~5,000 weekly active users across engineering, product, design, HR, finance, and legal.” | official | 2026-07-06 |
| s7 | Willow Wix case study, tools and tool-call volume “the AI Core team built the enterprise MCP infrastructure that now supports nearly 600 tools and 300,000+ weekly tool calls” | official | 2026-07-06 |
| s8 | Willow launch post, sector expansion “Deployments are now expanding across cyber security, real estate, fintech, and adtech.” | official | 2026-07-06 |
| s9 | SecurityWeek on Willow seed and stealth exit “Willow (formerly Webrix) emerged from stealth mode on Thursday with an identity and access platform for enterprise AI agents and $7 million in seed funding.” | press | 2026-07-06 |
| s10 | SecurityWeek on Willow runtime access control “The platform integrates directly with established identity providers, such as Okta and Entra, assigning a verifiable identity to every operating AI agent. The platform controls exactly which internal endpoints an agent can reach and enforces least-privilege access rules at runtime.” | press | 2026-07-06 |
| s11 | SecurityWeek on Willow deployment options “Organizations can deploy the infrastructure through a software-as-a-service model, a dedicated cloud, or self-hosted setups, including fully air-gapped environments.” | press | 2026-07-06 |
| s12 | Crypto Briefing on Willow founders “The founding team, Eyal Ben Ezra (CEO), Shalev Shalit (CTO), and Idan Chetrit (VP Platform), all came from Wix.” | press | 2026-07-06 |
| s13 | Crypto Briefing on Willow seed round and investors “The round, announced June 4, was led by Hetz Ventures, with prior angel contributions from Wix Co-Founder Avishai Abrahami and Wix President Nir Zohar.” | press | 2026-07-06 |
| s14 | Crypto Briefing on identity incumbents entering agent access “Larger identity management players like Okta and CyberArk have signaled interest in agent-related use cases, but their platforms were built for human identity first.” | press | 2026-07-06 |
| s15 | Calcalist on enterprise agent adoption and incident data “Today, 79% of companies already implement AI agents within their organizations, and 73% operate multi-agent systems... According to a survey published this year, 65% of companies reported incidents involving AI agents over the past 12 months.” | press | 2026-07-06 |
| s16 | AI Defense Matrix Catalog listing for Willow “Identity and access layer for AI agents that discovers every agent, tool, and MCP server, issues each a governed scoped credential tied to a real user, and logs and contains their activity.” | other | 2026-07-06 |
| s17 | Willow pricing page “Simple pricing for governed AI agent work. Start free, connect your tools in minutes, and scale when you're ready with skills, approvals, audit trails, and enterprise deployment options” | official | 2026-07-06 |
| s18 | Trust-surface probe: trust.withwillow.ai, security.withwillow.ai, and the /trust and /security paths all returned HTTP 404 (ctx fetch, 2026-07-06) | other | 2026-07-06 |
| s19 | Willow homepage: Innovid customer testimonial (Assaf Grimberg, SVP Software Engineering) and a Trusted-by customer logo wall “Willow gave us a single platform to govern and secure our developers' local machines, especially around exposure to MCP servers and external skills. It improved our ability to control access and reduce risk.” | official | 2026-07-06 |
| s20 | Willow homepage links public product documentation at docs.webrix.ai “Documentation Get up and running fast. Read the docs” | official | 2026-07-06 |
| s21 | Willow pricing FAQ on the SOC 2 Type II attestation “Is Willow SOC 2 certified? Yes. SOC 2 Type II. Documentation available on request.” | official | 2026-07-06 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Willow homepage “One governed connection to any tool.” | official | 2026-07-06 |
| s2 | Willow identity and access page “Each agent receives a governed credential, scoped, time-bound, tied to a real user. Provision, suspend, and audit agents individually.” | official | 2026-07-06 |
| s3 | Willow platform overview, control plane surfaces “One control plane for every AI agent, tool, and skill in your enterprise.” | official | 2026-07-06 |
| s4 | Willow rebrand announcement, security controls “SSO with Okta and Azure AD. RBAC. SCIM. SOC 2.” | official | 2026-07-06 |
| s5 | Willow rebrand announcement, enterprise positioning “Many competitors are open-source projects wearing enterprise badges. Willow is a managed enterprise platform from day one.” | official | 2026-07-06 |
| s6 | Willow launch post, Wix production deployment “The platform is already running in production at Wix, powering ~5,000 weekly active users across engineering, product, design, HR, finance, and legal.” | official | 2026-07-06 |
| s7 | Willow Wix case study, tools and tool-call volume “the AI Core team built the enterprise MCP infrastructure that now supports nearly 600 tools and 300,000+ weekly tool calls” | official | 2026-07-06 |
| s8 | Willow launch post, sector expansion “Deployments are now expanding across cyber security, real estate, fintech, and adtech.” | official | 2026-07-06 |
| s9 | SecurityWeek on Willow seed and stealth exit “Willow (formerly Webrix) emerged from stealth mode on Thursday with an identity and access platform for enterprise AI agents and $7 million in seed funding.” | press | 2026-07-06 |
| s10 | SecurityWeek on Willow runtime access control “The platform integrates directly with established identity providers, such as Okta and Entra, assigning a verifiable identity to every operating AI agent. The platform controls exactly which internal endpoints an agent can reach and enforces least-privilege access rules at runtime.” | press | 2026-07-06 |
| s11 | SecurityWeek on Willow deployment options “Organizations can deploy the infrastructure through a software-as-a-service model, a dedicated cloud, or self-hosted setups, including fully air-gapped environments.” | press | 2026-07-06 |
| s12 | Crypto Briefing on Willow founders “The founding team, Eyal Ben Ezra (CEO), Shalev Shalit (CTO), and Idan Chetrit (VP Platform), all came from Wix.” | press | 2026-07-06 |
| s13 | Crypto Briefing on Willow seed round and investors “The round, announced June 4, was led by Hetz Ventures, with prior angel contributions from Wix Co-Founder Avishai Abrahami and Wix President Nir Zohar.” | press | 2026-07-06 |
| s14 | Crypto Briefing on identity incumbents entering agent access “Larger identity management players like Okta and CyberArk have signaled interest in agent-related use cases, but their platforms were built for human identity first.” | press | 2026-07-06 |
| s15 | Calcalist on enterprise agent adoption and incident data “Today, 79% of companies already implement AI agents within their organizations, and 73% operate multi-agent systems... According to a survey published this year, 65% of companies reported incidents involving AI agents over the past 12 months.” | press | 2026-07-06 |
| s16 | Willow pricing page, tiered plans “$0/month Up to 5 users Connect up to 5 integrations Unlimited tool calls Proxy MCP support only ... $15/seat For teams with advanced needs All free plan features included Unlimited team members ... Contact Us Custom solutions for large orgs” | official | 2026-07-06 |
| s17 | Trust-surface probe: trust.withwillow.ai, security.withwillow.ai, and the /trust and /security paths all returned HTTP 404 (ctx fetch, 2026-07-06) | other | 2026-07-06 |
| s18 | AI Defense Matrix Catalog listing for Willow “Identity and access layer for AI agents that discovers every agent, tool, and MCP server, issues each a governed scoped credential tied to a real user, and logs and contains their activity.” | other | 2026-07-06 |
| s19 | Snowflake announces intent to acquire Natoma, a comparable MCP gateway “today announced it has signed a definitive agreement to acquire Natoma, an enterprise Model Context Protocol (MCP) platform for AI agents” | official | 2026-07-06 |
| s20 | Willow homepage: Innovid customer testimonial (Assaf Grimberg, SVP Software Engineering) and a Trusted-by customer logo wall “Willow gave us a single platform to govern and secure our developers' local machines, especially around exposure to MCP servers and external skills. It improved our ability to control access and reduce risk.” | official | 2026-07-06 |
| s21 | Willow pricing FAQ on the SOC 2 Type II attestation “Is Willow SOC 2 certified? Yes. SOC 2 Type II. Documentation available on request.” | official | 2026-07-06 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.