All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Xage Security sells zero trust access control for operational technology, data centers and cloud, delivered as a software overlay on existing infrastructure. Its buyers include energy, utility and manufacturing operators and federal defense agencies. Founded in 2016, it had raised $80 million by November 2023, after a 2022 Series B led by Piva, and TechCrunch described it then as a company of about 90 employees. A securities filing from March 2026 records a further $14,847,323 sold. Named customers include Kinder Morgan and the Department of the Air Force, under a contract that runs to July 2028. What Xage holds that is hard to copy quickly is a set of credentials and a federal position: a US government cryptographic validation (FIPS 140-3), 14 patent records and the Air Force contract.
| Description | Xage Security sells zero trust access control and protection for operational technology, industrial control systems, data centers and cloud, delivered as a mesh of software nodes overlaid on existing infrastructure. | [f1] |
|---|---|---|
| Founded | 2016 | [f2] |
| HQ | Palo Alto, California, United States | [f3] |
| Funding | $80M total | [f4] |
| Subsidiaries | Xage Security Gov, LLC (Federal contracting entity named as the recipient on the Air Force zero trust software contract recorded at USAspending.gov.) | |
| Latest funding | Regulation D offering, $14,847,323 sold, first sale 2025-12-05 | [f5] |
| Product | What it does |
|---|---|
| Xage Fabric Platform | A distributed mesh of software nodes deployed on premises, in the cloud and at remote sites that enforces access policy across IT, OT and cloud assets. |
| Secure Remote Access | Remote connectivity to critical systems that the company positions as a replacement for VPNs and jump servers, without exposing the network behind them. |
| Xage XPAM | Agentless privileged access management covering human, machine and AI identities across IT, OT, cloud, edge and AI environments from one platform. |
| Critical Asset Protection | Protection for cyber-physical, OT, IoT and infrastructure assets through granular access control, segmentation and virtual patching. |
| Zero Trust Data Exchange | Machine-to-machine and cross-domain data flows carrying authentication, authorization and integrity checks on each exchange. |
| Unified Zero Trust for AI | Runtime visibility and control over what AI agents do, with Agent Sentry watching agent behavior and Resource Gateway governing agent access to systems and data. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Xage XPAM discovers privileged accounts and rotates their passwords, and the Xage Fabric Platform enforces identity-based access to devices, network paths, applications and data exchanges. These capabilities are mapped to the Cyber Defense Matrix. [f6]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | The buyer is specific and the pain is described rather than measured. SecurityWeek's account of the Department of Energy work sets out the case: out-of-state crews restoring a damaged grid hold no account with the utility they are helping, need access for a few weeks, and must lose it when they leave. CSO Online carries an analyst statement that machine-to-machine communication in these environments cannot use conventional multifactor authentication. No cited source puts a cost on an access failure, which holds this at the clear-problem level. [s8, s17, s7] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | Xage publishes mechanism detail and two outside records bear on it. The pages describe a node mesh using Shamir's Secret Sharing and Federated Byzantine Agreement to keep credential and policy data synchronized when sites go offline, plus agentless account discovery through Ansible and Python plugins. NIST's validation list carries an active FIPS 140-3 certificate for the Xage Cryptographic Module for OpenSSL, tested by Acumen Security, and a patent search returns fourteen records assigned to the company describing the enrollment and authentication machinery. [s3, s5, s16, s18] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | The enabler is dated and the recent buyer-side evidence is not. Xage names the change it answers, enterprises connecting AI agents to APIs, databases, cloud services and operational systems where those agents take real-world actions, and it extended the Fabric platform to LLMs and agents in September 2025. On the demand side the newest independently recorded purchase in the cited record is an Air Force contract signed in July 2023 and the newest independent article is from November 2023, so both fall outside the year preceding this snapshot. [s12, s4, s15, s19] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 | The backgrounds are relevant and the exits are carried only by the company's own page. Xage states that Duncan Greatwood ran Topsy before Apple bought it and founded PostPath before Cisco bought it, and that co-founder Susanto Irwan came from Shape Security and Arxan Technologies. SecurityWeek and TechCrunch confirm Irwan and Roman Arutyunov as founders but not the exit history, so the strongest signal in the record is senior in-domain experience rather than an independently evidenced prior build. [s2, s7, s19, s14, s13] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | Named customers sit beside purchase records an outside party keeps. Xage publishes attributed testimony from the chief information officer and chief information security officer of Kinder Morgan and from a Space Systems Command colonel, and USAspending.gov records an Air Force contract for zero trust application development software running to July 2028. Washington Technology reports that SAIC invested and agreed to integrate the product into its IT and OT Accelerator line. Scale itself stays vendor-asserted, since the 420 percent revenue growth figure came from the chief executive. [s1, s15, s11, s19] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | The capital is proportional to the motion and the efficiency is unconfirmed. TechCrunch put the total at $80 million in November 2023, and a March 2026 Form D records $14,847,323 more sold from a first sale in December 2025. Shipping is visible over that window through a privileged access line, an AI line and a FIPS validation dated April 2026. No revenue, margin or burn figure appears in the cited record, so output per dollar cannot be confirmed. [s19, s13, s5, s16] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Outside writers place the core business without help from the company. CSO Online calls Xage a zero trust security provider with a decentralized access control platform for OT and ICS, Washington Technology calls it a zero trust software developer, SecurityWeek calls it a zero-trust access provider, and TechCrunch places it among platforms securing IoT and industrial systems. The newer privileged access and AI lines are placed in the cited record only by the company and by republications of its own announcements. [s17, s11, s8, s19, s12] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | There is friction and no structural barrier. The distributed mesh runs without a cloud connection and without a central vault, which is awkward for a cloud-brokered incumbent to match quickly, and the federal footprint brings procurement work a newcomer would have to repeat. Neither is a moat a funded platform vendor could not eventually build, and the cited record shows no accumulating data asset or contractual lock that would make the position compound. [s3, s5, s15] |
The problem is access by people and machines that the asset owner cannot vouch for. SecurityWeek's account of the Department of Energy work puts it in operational terms: when storms damage a grid, utilities bring in crews from out of state who hold no account with the utility they are helping, need access for a few weeks, and must lose it when they leave. Greatwood told SecurityWeek that undetected malware on technicians' laptops has been one of the most common ways individual grid components were hacked over recent years.
The constraint that shapes the market is what the equipment can carry. An Enterprise Strategy Group analyst quoted by CSO Online states that machine-to-machine communication in industrial control systems cannot rely on conventional multifactor authentication, and that many such systems have limited computation, storage and upgrade capability, so controls cannot be added to the device itself. That is why Xage sells an overlay rather than an agent.
Regulation supplied the second push. SecurityWeek tied rising demand to the Colonial Pipeline attack and to the Executive Order and Transportation Security Administration requirements that followed it, and reported that Xage customers in energy, defense, utilities, manufacturing and logistics had more than doubled in the year to May 2022. What the cited record does not carry is a figure for what an access failure costs an operator. [s8, s17, s7]
The Xage Fabric Platform is a mesh of software nodes laid over an existing environment. Xage says the mesh has no single point of failure and no single point to hack, that a distributed password vault removes the central credential store, and that Shamir's Secret Sharing and Federated Byzantine Agreement keep policy and credential data synchronized when some assets drop offline. The company states that the overlay requires no firewall or routing changes and no cloud connection to broker trust, which is the property that matters in air-gapped and intermittently connected sites.
Five product lines sit on that platform. Secure Remote Access handles connectivity to critical systems, Critical Asset Protection covers cyber-physical, OT and IoT assets through granular access control, segmentation and virtual patching, and Zero Trust Data Exchange carries authentication, authorization and integrity checks on machine-to-machine data flows. Xage XPAM adds agentless privileged access management with account discovery and password rotation driven by Ansible and Python plugins.
The newest line is Unified Zero Trust for AI. Xage Agent Sentry watches what AI agents do at runtime and Xage Resource Gateway governs how they reach enterprise systems, data, APIs and infrastructure. The company draws the contrast with prompt filtering explicitly, saying it governs the actions AI systems take rather than their prompts and outputs. NIST's validation list independently records an active FIPS 140-3 certificate for the cryptographic module underneath all of it. [s3, s5, s4, s16]
TechCrunch called Dragos perhaps Xage's biggest rival, at least on the startup front, and noted that Xage is not alone in the market for platforms securing IoT and industrial systems. Xage's own framing is aimed less at any one rival than at the tool estate: its pages argue that VPNs, jump servers, legacy privileged access management, firewalls and network segmentation together are complex, expensive and ineffective at preventing attacks, and offer one platform in their place.
The mechanism Xage puts forward as its difference is architectural. Its pages state that there is no cloud dependency for enforcing zero trust, unlike others that require a cloud connection to broker trust, and that the distributed mesh leaves no central vault to compromise. CSO Online described the same architecture in 2023 as blockchain-based, with nodes interfacing with different directory services at different layers and orchestrating access across them.
What the positioning leads with has shifted. Through 2023 the distributed ledger was named in the independent record as a core part of the stack, with Greatwood telling TechCrunch it was how the fabric achieves no single point of failure. The current pages lead with identity and, since September 2025, with control over AI agents, while the patent record still carries the earlier machinery in titles on decentralized enrollment and multi-layer ledgers. [s19, s1, s3, s17, s9, s18]
The federal channel is the part an outside party documents. USAspending.gov records contract FA880223C0002 to Xage Security Gov, LLC from the Department of the Air Force for zero trust application development software, signed in July 2023, worth up to $16,726,767 with $5,150,000 obligated and performance running to July 2028. Washington Technology separately reported that Space Force awarded Xage a $17 million contract in late September 2023. That report describes a five-year effort covering terrestrial systems, hybrid satellite architectures and secure data exchanges. TechCrunch noted a $743,000 Air Force contract.
Commercial traction is named but self-published. Xage carries attributed testimony from the chief information officer and the chief information security officer of Kinder Morgan, from the chief information security officer of Ornua and from an information manager at Pacific Canbriam Energy, alongside logos for SAIC, the Navy, the US Marine Corps and ScottsMiracle-Gro. Growth figures come from the company: Mattson told TechCrunch that revenue grew 420 percent and bookings 560 percent over January to June 2023 against a year earlier, at roughly 90 employees.
Partners carry part of the motion. Washington Technology reported that SAIC invested and simultaneously agreed to integrate the product into its IT and OT Accelerator line for operational technology users. The independent press coverage among the cited sources stops in November 2023. Later material in those sources is Xage's own pages, an industry-news republication of its announcements, a March 2026 securities filing and an April 2026 NIST validation. [s15, s11, s19, s1, s12]
The founding pair is corroborated and the reasons for the chief executive changes are not stated in the reviewed sources. SecurityWeek and TechCrunch both name Roman Arutyunov and Susanto Irwan as the founders, though they disagree on the year, with SecurityWeek saying 2017 and TechCrunch saying 2016. The company's 2018 securities filing records the year of incorporation as 2016. Irwan is now co-founder, president and chief technology officer, and Arutyunov is co-founder and chief product officer.
The senior backgrounds sit on the company's own page. Xage states that Duncan Greatwood was chief executive of Topsy before Apple acquired it in 2013 and founder and chief executive of PostPath before Cisco acquired it, that Irwan held senior roles at Shape Security and Arxan Technologies, and that Arutyunov worked at ABB, Tropos Networks and Symantec. The sources reviewed for the 2026-09-04 profile carry no outside confirmation of those exits.
The chief executive seat moved twice inside the cited record. Greatwood signed the company's 2018 securities filing as chief executive, Geoffrey Mattson signed the November 2023 filing as chief executive after TechCrunch reported his appointment that September, and Greatwood signed again as chief executive in March 2026. The sources reviewed for the 2026-09-04 profile document who held the office on each of those dates. They do not state the reasons for either change. The federal business runs under a separate name, Xage Security Gov, LLC, which is the recipient on the Air Force contract. [s7, s19, s2, s20, s13, s14, s15]
The strongest attestation is one anyone can check. NIST's cryptographic module validation list carries certificate 5229 for the Xage Cryptographic Module for OpenSSL, active under FIPS 140-3 with an overall level of 1, a life-cycle assurance exception at level 3, a sunset date of July 2029 and an initial validation dated April 2026 by the laboratory Acumen Security. The listing names Xage Security, Inc. at the Palo Alto address as the vendor.
The rest of the compliance record points at outside registries. The certifications page carries an ISO certificate numbered ICI-IS-2312025 linked to the IAF CertSearch database. It lists IEC 62443-4-1 certificate FR_Cyber10093 and IEC 62443-4-2 certificate FR_Cyber10120 at security level 3, each linked to the IECEE certificate database. The FIPS entry links to the NIST record above. Only the NIST record sits among the reviewed sources, so the ISO and IEC entries rest on registries those sources do not include. The same page also states that Xage signed CISA's Secure by Design pledge, and CSO Online reported in 2023 that the company joined the Joint Cyber Defense Collaborative to advise on critical infrastructure protection.
The certifications page lists Gartner, Forrester, Omdia, Frost and Sullivan and ESG reports naming the company. Named entries include a privileged access management Magic Quadrant dated October 2025 and an Omdia On the Radar note dated June 2025. None of those documents sits among the sources reviewed for the 2026-09-04 profile, so their content is unverified here. [s16, s6, s22, s3, s17]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Dragos | competes with | A TechCrunch article calls it perhaps Xage's biggest rival, at least on the startup front, among platforms securing IoT and industrial systems. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Claroty | adjacent | Adjacent because it competes for the same industrial security budget as Xage. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| CyberArk | competes with | Competes for the privileged access budget Xage XPAM targets, and Xage's privileged access page sets XPAM against it in a comparison table. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Cyolo | competes with | Competes for the same OT secure remote access buyer. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Xona Systems | competes with | Competes for the same OT secure remote access buyer. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| BeyondTrust | adjacent | Adjacent in the enterprise privileged access budget Xage XPAM enters, and Xage's privileged access page sets XPAM against it in a comparison table. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
Add analyzed competitors to compare them side by side with Xage Security.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
press the advantage
Xage's credentials and its federal position are what it holds that is hard to copy quickly. NIST's public list carries an active FIPS 140-3 validation for the cryptographic module inside the platform. An Air Force contract for zero trust software runs to July 2028 through a separate entity, Xage Security Gov, LLC. A patent search returns fourteen records assigned to the company, with titles covering decentralized enrollment and revocation of devices and multi-layer ledgers. Xage does not disclose any telemetry or content that accumulates to it across customers. The platform overlays the existing environment, and Xage says deployment needs no network change.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Xage sells software the customer runs. It also sells a services practice, and its own page describes that practice as assessment and design work against IEC 62443, C2M2, NIST 800 and NERC, implementation work across OT and IT, and maintenance with service-level support, delivered together with global service delivery partners. The cited pages do not show that practice carrying responsibility for the customer's security outcome, so the offering reads as customer-run software with project work beside it. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | A mechanism is documented and the exit is not sized. Credentials and policy split across mesh nodes under Shamir's Secret Sharing, discovered privileged accounts get rotated passwords under Xage-defined policies, and account checkout governs who holds a credential and when. The cited record does not state what leaving would cost in duration, parties or complexity, so the migration stays unsized. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 2/3 | The credential is real and it is not a mandate. NIST's validation list carries an active FIPS 140-3 certificate for the Xage Cryptographic Module for OpenSSL at overall level 1, validated in April 2026 by Acumen Security and running to a 2029 sunset, which is a regulator-mediated validation carried out by an accredited laboratory rather than by ordinary enterprise paperwork. It validates a module rather than authorizing a service, and the IEC 62443 entries point at a certificate registry the reviewed sources do not include, so the barrier is time and audit work rather than exclusion. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | The mechanism needs distributed-systems engineering rather than integration work. Xage describes a node mesh using Shamir's Secret Sharing and Federated Byzantine Agreement so policy and credential data stay synchronized when sites drop offline, with authentication against site-level directories preserved during a network loss. CSO Online described nodes interfacing with separate directory services at different layers and orchestrating access across them. Fourteen patent records cover the enrollment and authentication machinery. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | The buyers are regulated operators and government. USAspending.gov records an Air Force contract to Xage Security Gov, LLC, Washington Technology reports a Space Force award covering information networks and satellite ground stations, and Xage publishes attributed testimony from a Space Systems Command colonel and from the chief information officer and chief information security officer of the pipeline operator Kinder Morgan. The verticals it sells into are energy, utilities, manufacturing, healthcare, transportation and defense. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Xage is a platform beside the assets rather than infrastructure they call at runtime. The mesh brokers human-to-machine and machine-to-machine interactions, extends to MCP servers and proxies for AI agents, and deploys at every layer of an environment, which is more than one end-user application. It still overlays an environment that keeps running its own directories, firewalls and routing, and Xage sells the absence of required network change as a feature. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 2/3 | The evidenced asset is patents, not data. A patent search returns fourteen records assigned to Xage Security, Inc., the earliest granted in October 2018 and two granted in September 2025, with titles covering decentralized enrollment and revocation of devices, a single authentication portal for industrial network protocols, multi-layer ledgers and zero-trust enforcement in operational technology systems. Nothing in the cited record describes telemetry or content accumulating to Xage across customers. |
Xage sells to organizations whose production equipment cannot host security software. Its own pages name oil and gas, clean and renewable energy, manufacturing, electric utilities, healthcare, federal government, space, the defense industrial base and transportation as the industries it addresses, and the platform is pitched across IT, OT and cloud rather than at one of them.
The defining segment characteristic is a constraint rather than an industry. An Enterprise Strategy Group analyst quoted by CSO Online states that industrial control systems commonly have limited computation, storage and upgrade capability, which prevents adding or upgrading controls on the device, and that machine-to-machine communication cannot use conventional multifactor authentication. A vendor that overlays those assets addresses a population that agent-based tools cannot reach.
Federal work is a segment in its own right. USAspending.gov names Xage Security Gov, LLC, not Xage Security, Inc., as the recipient of an Air Force contract for zero trust application development software, and the company staffs a federal sales function under the Xage Government name covering defense, civilian and systems integrator customers.
The architecture is the capability claim. Xage describes the Fabric platform as a mesh of software nodes with no single point of failure and no single point to hack, a distributed password vault in place of a central credential store, and Shamir's Secret Sharing plus Federated Byzantine Agreement holding policy and credential data in sync when some assets go offline. The company states there is no cloud dependency for enforcing zero trust, in contrast to designs that need a cloud connection to broker trust.
Privileged access management is where that architecture is applied most concretely. Xage XPAM discovers privileged accounts and onboards them, manages passwords, and keeps a distributed secrets vault without a cloud dependency, using plugins packaged as Ansible or Python scripts so support for new device types ships without a full product upgrade. Account checkout rotates a password and reserves the account for one user for a set period.
The AI line applies the same enforcement point to agents. Xage Agent Sentry provides runtime visibility and control over what agents do, and Xage Resource Gateway governs how they reach systems, data, APIs and infrastructure, including hardened identity-aware MCP servers and proxies. The company draws the contrast plainly, saying it governs the actions AI systems take where other tools focus on prompts and outputs. This line launched in September 2025, so the cited record carries the design rather than deployment evidence.
Selling runs through a hired organization and through partners. Xage lists a chief revenue officer, a vice president of enterprise sales for the Americas and Europe, a regional vice president for the Middle East, Turkey and Africa, and a vice president of federal sales, alongside a partner program and a technology integrations page.
The clearest partner motion is with SAIC. Washington Technology reported that SAIC invested in the company and at the same time agreed to integrate the product into its IT and OT Accelerator line so operational technology users could adopt zero trust inside their networks. That gives Xage a route into federal accounts through an incumbent integrator rather than through direct competition with one.
Demand generation leans on regulation and on analyst reports. The services pages offer to help buyers meet Transportation Security Administration pipeline directives and to design programs against IEC 62443, C2M2, NIST 800 and NERC, and a certifications page lists Gartner, Forrester, Omdia, Frost and Sullivan and ESG documents that name the company. None of those documents appears in the cited record, so their content stays unverified here even though the citations themselves are ordinary.
No price appears anywhere in the reviewed pages. Each commercial path on those pages ends at a demo request, a datasheet download or a conversation with an expert. That is the pattern of negotiated enterprise deals.
What the pages do argue is cost displacement rather than a price point. Xage says its platform lets a buyer eliminate a patchwork of VPNs, jump servers, legacy privileged access management, firewalls and network segmentation, and claims better total cost of ownership than legacy privileged access management by protecting more assets and account types without agent overhead or a multi-year deployment. The company also states that deployment can take as little as one day.
The billing unit is stated even where the price is not. A comparison table on the privileged access page gives the Xage licensing model as user-based, with unlimited assets and one tier. The pages reviewed for this profile do not define what counts as a user.
Delivery is software the customer deploys, and Xage names the changes it says a buyer can skip: agents, firewall rules, network routing and rip-and-replace. The company states that Fabric nodes run on premises, in the cloud and at remote sites. Nodes can take over for each other, so an upgrade needs no downtime. Xage XPAM is agentless, which is the property that lets it reach assets that cannot run endpoint software.
Operating under degraded conditions is treated as a design requirement rather than an option. The company says credential and policy information is distributed across nodes so authentication and policy enforcement continue when a site goes offline, and CSO Online reported that local users can authenticate against the site-level directory when the site loses network connectivity.
A services organization sits beside the product. Xage Cybersecurity Services covers assessment and design against IEC 62443, C2M2, NIST 800 and NERC, implementation across OT and IT environments, and ongoing maintenance with service-level operational support, delivered with what the company calls its global service delivery partners.
One attestation is independently checkable. NIST's cryptographic module validation list carries certificate 5229 for the Xage Cryptographic Module for OpenSSL, active under FIPS 140-3 at an overall level of 1 with a life-cycle assurance exception at level 3, a July 2029 sunset and an initial validation dated April 2026 performed by the laboratory Acumen Security. The record names Xage Security, Inc. at the Palo Alto address as the vendor and points at the Fabric platform page.
The remaining compliance claims point at outside registries. The certifications page carries an ISO certificate numbered ICI-IS-2312025 linked to the IAF CertSearch database. It lists IEC 62443-4-1 certificate FR_Cyber10093 and IEC 62443-4-2 certificate FR_Cyber10120 at security level 3, each linked to the IECEE certificate database. Neither registry entry is among the reviewed sources, so the FIPS validation is the one certificate those sources confirm at its issuing record.
Public-sector alignment is documented on both sides in one case. Xage states that it signed CISA's Secure by Design pledge, and CSO Online reported in 2023 that the company joined the Joint Cyber Defense Collaborative to advise on critical infrastructure protection.
The platform is designed to sit on top of other vendors' identity systems rather than replace them. CSO Online described Xage Fabric mapping multiple identity providers and Active Directory services onto different network layers of an OT environment, with nodes interfacing with separate directory services at separate levels and working together to apply one policy. The article names Microsoft Active Directory, Active Directory Federation Services and providers supporting LDAP or SAML 2.0 as the integration targets.
Extension is packaged rather than bespoke. Xage says plugins are packaged sets of scripts, written with tools such as Ansible or Python, that let the system talk to a device for account discovery or password rotation, and that plugins ship independently so customers gain device support without a full product upgrade. That is how a platform aimed at heterogeneous industrial estates keeps adding coverage.
The newest extension surface is the model context protocol. Xage describes hardened, identity-aware and entitlement-aware MCP servers, MCP proxies and agent access shields, which places the product in the path between an AI agent and the systems it calls rather than beside the model.
The founders are corroborated and still in place. SecurityWeek and TechCrunch both name Roman Arutyunov and Susanto Irwan as founders, and the company lists Irwan as co-founder, president and chief technology officer and Arutyunov as co-founder and chief product officer. The two press accounts disagree on the founding year, with SecurityWeek saying 2017 and TechCrunch saying 2016, and the company's own 2018 securities filing records 2016.
Senior pedigree rests on the company's own account of it. Xage states that Duncan Greatwood was chief executive of Topsy before Apple acquired it in 2013 and founder and chief executive of PostPath before Cisco acquired it, that Irwan held senior engineering and product roles at Shape Security and Arxan Technologies, and that Arutyunov worked at ABB, Tropos Networks and Symantec. The sources reviewed for the 2026-09-04 profile carry no outside confirmation of those exits.
Leadership changed twice inside the cited record. Greatwood signed the 2018 securities filing as chief executive, Geoffrey Mattson signed the November 2023 filing as chief executive after TechCrunch reported his appointment that September, and Greatwood signed the March 2026 filing as chief executive again. The sources reviewed for the 2026-09-04 profile document who held the office on each of those dates. They do not state the reasons for either change.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Xage Security: Xage Fabric Platform product page | official | 2026-09-04 |
| f2 | SEC EDGAR: Xage Security, Inc. Form D rendered filing | regulatory | 2026-09-04 |
| f3 | Xage Security: About Us page | official | 2026-09-04 |
| f4 | TechCrunch: report on the November 2023 Xage Security B2 round | press | 2026-09-04 |
| f5 | SEC EDGAR: Xage Security, Inc. Form D rendered filing signed 2026-03-18 | regulatory | 2026-09-04 |
| f6 | Xage Security: Privileged Access Management product page | official | 2026-09-04 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Xage Security: homepage “Xage delivers access and protection that’s easy to deploy, easy to manage, and easy to use, while stopping cyberattacks at every stage.” | official | 2026-09-04 |
| s2 | Xage Security: About Us page “Xage’s security solutions attracted leading venture investors to the company’s $80M in fundraising to date.” | official | 2026-09-04 |
| s3 | Xage Security: Xage Fabric Platform product page “The Xage Fabric Platform provides unified Zero Trust security anywhere—across data centers, cloud, digital assets, cyber-physical systems (CPS), OT, LLMs, and AI agents.” | official | 2026-09-04 |
| s4 | Xage Security: Unified Zero Trust for AI product page “Secure autonomous AI with comprehensive visibility and deterministic control over LLMs, agents, data, tools, and APIs.” | official | 2026-09-04 |
| s5 | Xage Security: Privileged Access Management product page “Xage XPAM replaces legacy PAM with agentless, zero trust privileged access management, built for IT, OT, and cloud across the whole enterprise and every asset.” | official | 2026-09-04 |
| s6 | Xage Security: Certifications and Recognition page, the probe of the company's published trust surface “Compliance Certifications ISO Certificate ICI-IS-2312025 FIPS 140-3 validation Certificate 5229 IEC IEC 62443-4-1: FR_Cyber10093 IEC 62443-4-2: FR_Cyber10120 (SL3)” | official | 2026-09-04 |
| s7 | SecurityWeek: report on the 2022 Xage Series B top-up “Palo Alto, Calif-based firm Xage has raised a $6 million top-up to the $30 million Series B funding it secured in January 2022.” | press | 2026-09-04 |
| s8 | SecurityWeek: report on the Xage Department of Energy contract “Recognizing these issues, the Department of Energy has contracted with Xage, a zero-trust access provider, to expand its existing Xage Fabric application to provide secure and controlled access to emergency responders.” | press | 2026-09-04 |
| s9 | TechCrunch: report on the January 2022 Xage Series B “Piva led the round with participation from Momenta, Valor Equity Partners and OurCrowd, along with existing investors March Capital, City Light Capital, Saints Capital and Saudi Aramco Energy Ventures. The startup said it has raised $54 million to date.” | press | 2026-09-04 |
| s11 | Washington Technology: report on the SAIC investment in Xage Security “Xage Security, a startup zero trust software developer, has completed a $20 million funding round that included Science Applications International Corp. as an investor alongside six other venture capital firms.” | press | 2026-09-04 |
| s12 | Help Net Security: industry-news item on the Xage Fabric Platform AI release “Industry News September 10, 2025” | press | 2026-09-04 |
| s13 | SEC EDGAR: Xage Security, Inc. Form D rendered filing signed 2026-03-18 “Total Offering Amount $ 15,072,520 USD” | regulatory | 2026-09-04 |
| s14 | SEC EDGAR: Xage Security, Inc. Form D rendered filing signed 2023-11-08 “/s/ Geoffrey Mattson Geoffrey Mattson Chief Executive Officer 2023-11-08” | regulatory | 2026-09-04 |
| s15 | USAspending.gov: award record for contract FA880223C0002 “"piid": "FA880223C0002",” | regulatory | 2026-09-04 |
| s16 | NIST CMVP: cryptographic module validation certificate 5229 “Certificate #5229 Details Module Name Xage Cryptographic Module for OpenSSL Standard FIPS 140-3 Status Active Sunset Date 7/10/2029 Overall Level 1” | regulatory | 2026-09-04 |
| s17 | CSO Online: article on the Xage multilayer identity and access management offering “Shweta Sharma Senior Writer Xage’s new IAM offering provides multilayer authentication for ICS/OT News Apr 20, 2023” | press | 2026-09-04 |
| s18 | Google Patents: query result for patents assigned to Xage Security “"total_num_results": 14,” | research | 2026-09-04 |
| s20 | SEC EDGAR: Xage Security, Inc. Form D rendered filing signed 2018-07-30 “Year of Incorporation/Organization Over Five Years Ago X Within Last Five Years (Specify Year) 2016” | regulatory | 2026-09-04 |
| s19 | TechCrunch: report on the November 2023 Xage Security B2 round “today announced that it raised $20 million in a B2 funding round that brings the company’s total raised to $80 million.” | press | 2026-09-04 |
| s22 | Xage Security: Certifications and Recognition page captured with outbound links preserved “Certificate ICI-IS-2312025 (https://www.iafcertsearch.org/certification/tnzT3i0mtvd7kggfmpO09da4)” | official | 2026-09-04 |
| s21 | Xage Security: Cybersecurity Services page “Assess & Design Strategize and architect a modern industrial cybersecurity program based on identity and asset-centric Zero Trust, IEC 62443, C2M2, NIST 800, NERC, and related industry standards.” | official | 2026-09-04 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Xage Security: homepage “Xage delivers access and protection that’s easy to deploy, easy to manage, and easy to use, while stopping cyberattacks at every stage.” | official | 2026-09-04 |
| s2 | Xage Security: About Us page “Xage’s security solutions attracted leading venture investors to the company’s $80M in fundraising to date.” | official | 2026-09-04 |
| s3 | Xage Security: Xage Fabric Platform product page “The Xage Fabric Platform provides unified Zero Trust security anywhere—across data centers, cloud, digital assets, cyber-physical systems (CPS), OT, LLMs, and AI agents.” | official | 2026-09-04 |
| s4 | Xage Security: Unified Zero Trust for AI product page “Secure autonomous AI with comprehensive visibility and deterministic control over LLMs, agents, data, tools, and APIs.” | official | 2026-09-04 |
| s5 | Xage Security: Privileged Access Management product page “Xage XPAM replaces legacy PAM with agentless, zero trust privileged access management, built for IT, OT, and cloud across the whole enterprise and every asset.” | official | 2026-09-04 |
| s6 | Xage Security: Certifications and Recognition page, the probe of the company's published trust surface “Compliance Certifications ISO Certificate ICI-IS-2312025 FIPS 140-3 validation Certificate 5229 IEC IEC 62443-4-1: FR_Cyber10093 IEC 62443-4-2: FR_Cyber10120 (SL3)” | official | 2026-09-04 |
| s7 | SecurityWeek: report on the 2022 Xage Series B top-up “Palo Alto, Calif-based firm Xage has raised a $6 million top-up to the $30 million Series B funding it secured in January 2022.” | press | 2026-09-04 |
| s8 | SecurityWeek: report on the Xage Department of Energy contract “Recognizing these issues, the Department of Energy has contracted with Xage, a zero-trust access provider, to expand its existing Xage Fabric application to provide secure and controlled access to emergency responders.” | press | 2026-09-04 |
| s9 | TechCrunch: report on the January 2022 Xage Series B “Piva led the round with participation from Momenta, Valor Equity Partners and OurCrowd, along with existing investors March Capital, City Light Capital, Saints Capital and Saudi Aramco Energy Ventures. The startup said it has raised $54 million to date.” | press | 2026-09-04 |
| s11 | Washington Technology: report on the SAIC investment in Xage Security “Xage Security, a startup zero trust software developer, has completed a $20 million funding round that included Science Applications International Corp. as an investor alongside six other venture capital firms.” | press | 2026-09-04 |
| s12 | Help Net Security: industry-news item on the Xage Fabric Platform AI release “Industry News September 10, 2025” | press | 2026-09-04 |
| s13 | SEC EDGAR: Xage Security, Inc. Form D rendered filing signed 2026-03-18 “Total Offering Amount $ 15,072,520 USD” | regulatory | 2026-09-04 |
| s14 | SEC EDGAR: Xage Security, Inc. Form D rendered filing signed 2023-11-08 “/s/ Geoffrey Mattson Geoffrey Mattson Chief Executive Officer 2023-11-08” | regulatory | 2026-09-04 |
| s15 | USAspending.gov: award record for contract FA880223C0002 “"piid": "FA880223C0002",” | regulatory | 2026-09-04 |
| s16 | NIST CMVP: cryptographic module validation certificate 5229 “Certificate #5229 Details Module Name Xage Cryptographic Module for OpenSSL Standard FIPS 140-3 Status Active Sunset Date 7/10/2029 Overall Level 1” | regulatory | 2026-09-04 |
| s17 | CSO Online: article on the Xage multilayer identity and access management offering “Shweta Sharma Senior Writer Xage’s new IAM offering provides multilayer authentication for ICS/OT News Apr 20, 2023” | press | 2026-09-04 |
| s18 | Google Patents: query result for patents assigned to Xage Security “"total_num_results": 14,” | research | 2026-09-04 |
| s20 | SEC EDGAR: Xage Security, Inc. Form D rendered filing signed 2018-07-30 “Year of Incorporation/Organization Over Five Years Ago X Within Last Five Years (Specify Year) 2016” | regulatory | 2026-09-04 |
| s19 | TechCrunch: report on the November 2023 Xage Security B2 round “today announced that it raised $20 million in a B2 funding round that brings the company’s total raised to $80 million.” | press | 2026-09-04 |
| s22 | Xage Security: Certifications and Recognition page captured with outbound links preserved “Certificate ICI-IS-2312025 (https://www.iafcertsearch.org/certification/tnzT3i0mtvd7kggfmpO09da4)” | official | 2026-09-04 |
| s21 | Xage Security: Cybersecurity Services page “Assess & Design Strategize and architect a modern industrial cybersecurity program based on identity and asset-centric Zero Trust, IEC 62443, C2M2, NIST 800, NERC, and related industry standards.” | official | 2026-09-04 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.