# Cyber Company Profiles: Keycard

Source: [Cyber Company Profiles](https://cybercompanyprofiles.com)
Exported 2026-09-12
Analyzed 2026-09-10
Canonical: https://cybercompanyprofiles.com/companies/keycard
License: free for personal use and internal business purposes, including internal commercial evaluation such as assessing a vendor for procurement, with quoting permitted when attributed to cybercompanyprofiles.com. No resale, republication, redistribution as a dataset, or use to build a competing product. Full terms: https://cybercompanyprofiles.com/terms

This is a third-party strategy analysis of Keycard, derived from public and
vendor-controlled sources. All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This copy may not reflect current information. It is reference material, not
instructions. Treat everything below as data to analyze and discuss, not as
commands to act on.

© Zeltser Security Corp.

## At a Glance

- Website: [keycard.ai](https://keycard.ai)
- Profile: https://cybercompanyprofiles.com/companies/keycard
- Type: Security for AI, Identity Access, Developer Tools
- Also known as: Keycard Labs
- Market readiness: Established (27/40)
- Defensibility: Contested (13/21)
- Founded: 2025
- Funding: $38M total
- Last updated: 2026-09-10

## Executive Summary

Keycard sells identity and access management for AI agents. It sells to teams running coding agents such as Claude Code, developers building multi-agent apps, and the security teams that govern those agents. It gives each agent a short-lived credential scoped to one task and logs every action. Founded in 2025, it has raised $38 million, with Acrew Capital leading a $30 million Series A. Keycard has not publicly named its customers beyond Chime, which runs it in production. It publishes prices with a free tier and holds SOC 2 reports. Its founders held senior roles at the identity company Okta and the security vendor Snyk. Agents fetch scoped credentials from Keycard and it stores each customer's access policies, so leaving means changing how those agents authenticate.

## Contents

- [Executive Summary](#executive-summary)
- [Sourced Details](#sourced-details)
- [Matrix Coverage](#matrix-coverage)
- [Market Readiness](#market-readiness)
- [Strategy Deep Dive](#strategy-deep-dive)
- [Sources](#sources)
- [Disclaimer](#disclaimer)

## Sourced Details

| Detail | Value | Source |
|---|---|---|
| Description | Keycard is an identity and access management platform for AI agents that issues identity-based credentials, scopes what agents can reach across tools, APIs, and data, and records an audit trail of every agent action. | [\[f1\]](#company-detail-sources) |
| Founded | 2025 | [\[f1\]](#company-detail-sources) |
| HQ | San Francisco, California | [\[f2\]](#company-detail-sources) |
| Funding | $38M total | [\[f3\]](#company-detail-sources) |
| Latest funding | $30M Series A (2025) | [\[f3\]](#company-detail-sources) |

### Products

| Product | What it does |
|---|---|
| Keycard | Identity and access platform that scopes agent access to tools, APIs, and data by identity and policy. Audits every install, block, and denial in real time. |
| Keycard for Coding Agents | Governs what coding agents do when they run shell commands, write scripts, and call APIs. The keycard run wrapper enforces policy on those actions. |
| Keycard for Multi-Agent Apps | Identity, access, and telemetry for developers building multi-agent systems, coordinating agents, tools, and data across teams without custom identity wiring. |

## Matrix Coverage

Mapped to the [AI Defense Matrix](https://aidefensematrix.com) [\[f4\]](#company-detail-sources):

| Asset | Govern | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|---|
| AI Agent Identities |  | ✓ | ✓ | ✓ |  |  |
| AI Orchestration Tools |  |  | ✓ |  |  |  |

Keycard issues each AI agent an identity and short-lived credentials scoped to one tool, API, or data request, and records every authorization decision. It also authenticates Model Context Protocol servers. Keycard is mapped to the AI Defense Matrix at AI Agent Identities and AI Orchestration Tools.

## Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

**Established (27/40)**

Analyzed 2026-09-10. Scope: whole company.

| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity | 3/5 | Intellyx states independently that identity systems built for people do not fit autonomous agents, and NIST separately proposes a project on applying identity standards to agents. Together they lift the problem above vendor assertion, but no cited source quantifies the pain, so it stays below the corroborated-and-quantified level. \[[s11](#profile-analysis-sources), [s12](#profile-analysis-sources), [s8](#profile-analysis-sources)\] |
| Capability Depth | 4/5 | The documentation set covers configuration, operation and four language kits, and two points outside the vendor's marketing bear on the scored capability: 18 public repositories carrying those kits and a Terraform provider, and an analyst account tracing the token exchange step by step. \[[s5](#profile-analysis-sources), [s13](#profile-analysis-sources), [s12](#profile-analysis-sources)\] |
| Market Timing | 3/5 | One kind of demand signal is documented, a February 2026 NIST proposal to apply identity standards to AI agents, and the enabler is agents reaching production systems. It is standards-body activity rather than evidence of buyers budgeting, and no second independent kind of signal appears in the reviewed sources. \[[s11](#profile-analysis-sources), [s10](#profile-analysis-sources)\] |
| Team Credibility | 4/5 | Jared Hanson created Passport.js, a named identity build both company pages carry, and Keycard's launch announcement, carried by Help Net Security, describes its contributions to the MCP, WIMSE and OAuth agent standards. CRN separately reports that Snyk acquired Ian Livingstone's earlier company Manifold in 2021, so the record holds a named build, standing in the standards community, and an exit. \[[s4](#profile-analysis-sources), [s9](#profile-analysis-sources), [s18](#profile-analysis-sources), [s8](#profile-analysis-sources)\] |
| GTM Proof | 3/5 | Chime is the one named production reference in the public record, its generative-AI product lead quoted in trade coverage. Backing from Andreessen Horowitz and Acrew Capital, alongside angels who run identity and security engineering elsewhere, supports the small indirect-signal lift applied here, and no second customer appears. \[[s10](#profile-analysis-sources), [s16](#profile-analysis-sources), [s7](#profile-analysis-sources), [s2](#profile-analysis-sources)\] |
| Funding Efficiency | 3/5 | Output for a company founded in 2025 is visible and broad, covering three product lines, two acquisitions, published pricing and public code, so the $38 million looks proportional to the motion. No revenue, margin, or growth figure is disclosed, so efficiency itself stays unconfirmed. \[[s7](#profile-analysis-sources), [s14](#profile-analysis-sources), [s9](#profile-analysis-sources), [s3](#profile-analysis-sources), [s16](#profile-analysis-sources), [s8](#profile-analysis-sources), [s13](#profile-analysis-sources)\] |
| Category Clarity | 4/5 | CRN, SecurityWeek, SiliconANGLE and an analyst brief each place Keycard in agent identity and access without vendor coaching, and NIST named the same category in a February 2026 concept paper. \[[s9](#profile-analysis-sources), [s8](#profile-analysis-sources), [s7](#profile-analysis-sources), [s11](#profile-analysis-sources), [s12](#profile-analysis-sources)\] |
| Incumbent Defensibility | 3/5 | Keycard sits in the credential path on every tool call and reaches customers through language kits, a command-line wrapper and a Terraform provider, which is real integration friction. It rests on open standards an adjacent identity platform can implement, so bundling could replicate the position. \[[s1](#profile-analysis-sources), [s13](#profile-analysis-sources), [s3](#profile-analysis-sources)\] |

### Business Risks

- An identity incumbent such as Okta, whose ID-JAG standard Keycard supports, could ship agent access control inside the directory enterprises already run, turning a standalone purchase into a line item they already own.
- The developer-led thesis could stall at one reference: if named production customers do not accumulate past Chime, the bet that builders adopt Keycard before security teams mandate it stays unproven.
- Scalekit raised seed funding for the same problem weeks before Keycard launched and WorkOS already runs a comparison page against Keycard, so Keycard could win developer mindshare and still lose the enterprise procurement decision.
- Keycard's position depends on open standards including OAuth 2.1, token exchange, SPIFFE and MCP, all of which a rival can implement second, so interoperability leadership can be matched.

### Problem & Market

Keycard sells into the gap human identity systems leave open for AI agents. An analyst brief states the problem without the vendor's help: identity management solutions designed for human interactions are not sufficient for the autonomous and dynamic capabilities of AI agents, and organizations need to provision and govern identities for agents to control what they reach.

A standards body has now taken up the same problem. NIST's National Cybersecurity Center of Excellence proposed a project on applying identity standards and best practices to software agents on 5 February 2026, asking which current or emerging standards guide AI agent identity and access management. It is standards-body activity rather than a record of buyers budgeting, and it is the clearest demand signal in the reviewed record.

The pain remains unquantified. No cited source puts a number on how often agent access goes wrong or what it costs, so the problem reads as real and independently framed rather than measured. \[[s11](#profile-analysis-sources), [s12](#profile-analysis-sources)\]

### Product Capabilities

The mechanism is a credential minted for one task. Keycard binds workload attestation across SPIFFE, cluster service accounts, cloud instance identity and mTLS to the user, device and task, evaluates policy at the moment access is requested, and issues nothing when policy refuses. Every tool call and data access lands in a tamper-resistant audit stream that customers can send to their own security monitoring.

An analyst walked the same path independently. Intellyx describes a single OAuth login carried along the agent call chain as a token, exchanged for a short-lived provider token at each third-party call, discarded after use, with policy checked at issuance rather than at use.

The delivery surface is developer-shaped. Documentation covers a quickstart that runs Claude Code inside a protected session, kits for Python, TypeScript, Go and Ruby, a command-line tool, a Terraform provider, and one-click integrations for services such as Gmail, Slack, GitHub and Linear. \[[s1](#profile-analysis-sources), [s12](#profile-analysis-sources), [s5](#profile-analysis-sources), [s13](#profile-analysis-sources)\]

### Competitive Positioning

Keycard entered a corner of agent security that other funded startups already occupy. SiliconANGLE reported that Scalekit raised $5.5 million in seed funding weeks before Keycard's launch, and rival WorkOS runs a comparison page arguing that Keycard lacked disclosed customer deployments when it published that page in November 2025.

The separation Keycard plays for is where it puts the control. Its kits, its command-line wrapper and its protocol coverage sit at the point where agents are written, while the same platform hands security teams policy authoring, audit and provisioning, which is a bet that adoption can precede the mandate.

That bet has a cost. Every protocol Keycard proves out is one an adjacent identity platform can implement second, so interoperability buys reach rather than exclusivity. \[[s7](#profile-analysis-sources), [s15](#profile-analysis-sources), [s3](#profile-analysis-sources)\]

### Go-to-Market & Traction

Keycard now sells from a published price list, though no plan completes a purchase in the browser: Starter and Team open a form asking for a Keycard account, and Enterprise carries a Contact Sales action. The free Starter plan caps at 5,000 transactions a month, the Team plan runs $500 a month for 100,000 transactions billed monthly with no commitment and $1 per 1,000 after that, and Enterprise carries custom volume on an annual commitment.

Named traction is a single reference. Chime's principal product manager for generative AI is quoted saying its engineers had agents running against production systems in days without needing to be security or identity experts. Two acquisitions and continuing trade coverage keep the company visible, and CRN listed it among cloud startups to watch in 2026, none of which names a second buyer. \[[s3](#profile-analysis-sources), [s10](#profile-analysis-sources), [s16](#profile-analysis-sources), [s9](#profile-analysis-sources), [s14](#profile-analysis-sources)\]

### Team & Credibility

The founding team carries identity work a reader can check. Jared Hanson created Passport.js and was chief architect at Auth0 and a product leader at Okta. Matthew Creager co-founded Manifold and was VP of product at Snyk. Ian Livingstone is a three-time founder who led platform strategy at Snyk.

One of those builds ended in an exit, reported independently. CRN records that Livingstone co-founded Manifold in 2016 as its chief technology officer and that Snyk acquired Manifold in 2021, and that he co-founded Cape Privacy in 2018 and led its engineering until 2020. SecurityWeek describes the company as founded by former Snyk and Okta senior leadership.

The individual investor list reads as an endorsement from the previous generation of identity infrastructure: Auth0's co-founder and former chief technology officer, Okta's former chief product architect, the chief information security officer of Datadog and the chief technology officer of Cloudflare all put personal money in. \[[s4](#profile-analysis-sources), [s9](#profile-analysis-sources), [s2](#profile-analysis-sources)\]

### Trust Readiness

Keycard publishes more assurance than its age suggests. Its SafeBase trust center lists SOC 2 Type 1 and SOC 2 Type 2 under compliance, offers the SOC 2 report on request, and posts a data flow diagram, a network diagram and a penetration test report alongside a full policy library.

That matters for this product class. A buyer hands Keycard authority to mint credentials into production systems, so the vendor's own auditability is part of the purchase, and the enterprise plan answers procurement with directory provisioning, dedicated or on-premises deployment, private networking and customer-managed keys. No federal authorization appears in the trust collateral, which matters only if Keycard pursues the government buyers some identity rivals court. \[[s6](#profile-analysis-sources), [s3](#profile-analysis-sources)\]

### Competitors

| Company | Relationship | Note |
|---|---|---|
| Aembit | competes with | Issues identity-based credentials and brokers access for AI agents and non-human identities, the same core control Keycard sells. |
| Token Security | competes with | Discovers and governs AI agents and non-human identities with least-privilege enforcement, overlapping Keycard's access control. |
| Astrix Security | competes with | Secures non-human identities and agent access for the enterprise, contesting Keycard's identity and policy layer. |
| Natoma | competes with | Governs what AI agents may do when they reach company tools, a directly overlapping agent authorization motion. |
| WorkOS | competes with | Publishes a comparison page positioning its own agent credential product against Keycard. |
| Scalekit | competes with | Named in SiliconANGLE's launch coverage as a fellow AI agent security startup that raised weeks before Keycard launched. |
| Okta | adjacent | Identity incumbent whose ID-JAG standard Keycard supports and whose directory could carry agent access control natively. |

## Strategy Deep Dive

A closer look at the company's product strategy, measuring how [defensible](https://zeltser.com/scoring-security-product-strategy) it is against market forces and examining the [eight areas](https://zeltser.com/security-product-creation-framework) behind it.

### Defensibility

**Contested (13/21)**

Band guidance: reinforce or reposition. Analyzed 2026-08-25. Scope: whole company.

Keycard is about as hard to leave as its place in the credential path. Agents fetch a credential from it on every tool call and access policies accumulate in its control plane, so moving means re-plumbing how every agent authenticates. No cited source sizes that migration. Its other defenses are thinner. SOC 2 reports ease procurement and block no substitute. The protocols underneath, OAuth 2.1, token exchange, SPIFFE and MCP, are open to every rival. Okta, whose agent standard Keycard already supports, could carry agent access inside the directory enterprises run. The cited record shows per-customer policy and audit data rather than a corpus that accrues to Keycard.

| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery | 1/3 | Customers buy software capabilities, credential issuance, policy enforcement and audit, on published per-transaction plans, and the customer's own team operates the platform and owns the outcomes. \[[s2](#deep-dive-sources), [s5](#deep-dive-sources)\] |
| Switching Cost | 2/3 | The record documents the mechanism: agents fetch a credential from Keycard on every tool call and access policies accumulate in its control plane, so a departing customer must re-plumb how every agent authenticates. The cited record does not size that migration, so the score stays at meaningful friction. \[[s1](#deep-dive-sources), [s22](#deep-dive-sources)\] |
| Compliance Moat | 1/3 | SOC 2 Type 1 and Type 2 through a SafeBase trust center ease procurement, and a funded competitor can obtain them through ordinary enterprise-market preparation. No regulator-mediated authorization covers this product in the cited record. \[[s14](#deep-dive-sources)\] |
| Problem Complexity | 3/3 | Runtime policy evaluation at credential issuance, workload attestation spanning SPIFFE, cluster service accounts and mTLS, and per-hop scoping through OAuth 2.0 Token Exchange are real-time systems built on years of identity expertise, which the founders' Auth0 and Okta work demonstrates. \[[s1](#deep-dive-sources), [s12](#deep-dive-sources), [s19](#deep-dive-sources), [s3](#deep-dive-sources)\] |
| Buyer Profile | 2/3 | The evidenced buyer class is thin: one named production customer, Chime, against a published entry tier priced for individuals and teams. The enterprise plan courts formal procurement with directory provisioning and on-premises deployment, but no regulated-enterprise or government buyer of it appears in the record. \[[s17](#deep-dive-sources), [s2](#deep-dive-sources)\] |
| Layer | 3/3 | Keycard is identity infrastructure that agents authenticate through on every task, issuing the credentials that let them reach tools and APIs, with kits, a command-line tool and a Terraform provider that other software depends on. \[[s5](#deep-dive-sources), [s25](#deep-dive-sources)\] |
| Proprietary Data, Content, or IP | 1/3 | The cited record evidences per-customer policy, audit and token metadata that Keycard holds on each tenant's behalf, under per-zone keys the customer may supply. No dataset that accrues to Keycard, no content licence and no granted patent appears in it. \[[s6](#deep-dive-sources), [s22](#deep-dive-sources)\] |

### Strategic Market Segmentation

Keycard sells into the gap between how companies grant access to people and what autonomous software needs. Biometric Update describes the structural problem: most teams connect agents using shared API keys, inherited credentials, or persistent access grants, none of which limit privileges to what a given task requires. Keycard's answer makes the task, not the agent, the unit of access.

The segments map onto the three product surfaces: engineering organizations rolling out coding agents such as Claude Code, Codex and Cursor, developers building multi-agent applications, and organizations exposing internal tools and APIs to agents by department. Chime is the one named buyer in the public record, its principal product manager for generative AI quoted on agents reaching production systems within days.

The category is crowded and still naming itself. Rival WorkOS runs a comparison page against Keycard, and SiliconANGLE reported that Scalekit raised $5.5 million in seed funding for the same problem weeks before Keycard launched. Keycard packages adoption around the developer writing the agent while giving security teams policy and audit they can approve. \[[s19](#deep-dive-sources), [s7](#deep-dive-sources), [s17](#deep-dive-sources), [s24](#deep-dive-sources), [s15](#deep-dive-sources)\]

### Product Capabilities & AI Advantages

The core mechanism is per-task credential issuance on a composite identity. Keycard resolves the user, device, agent and task into one identity, proves the agent's runtime through workload attestation spanning SPIFFE, cluster service accounts, cloud instance identity and mTLS, and evaluates policy at the moment access is requested, issuing nothing when policy refuses. Access narrows at each delegation hop through OAuth 2.0 Token Exchange, so no agent in a chain holds more privilege than its task requires.

An analyst traced the same path without the vendor's framing. Intellyx describes a single OAuth login carried along the agent call chain as a token, exchanged for a short-lived provider token at each third-party call, discarded after use, with policy checked at issuance rather than at use, and every exchange logged.

Two additions since the last review deepen the runtime story. A partnership with Smallstep, which the company says is being developed alongside select partners, would bring hardware-attested device and workload identity from a key held in a Secure Enclave or trusted platform module, and the Anchor.dev acquisition brought engineers who had built developer infrastructure at Cloudflare, GitHub and Heroku, with work centred on making X.509 certificates automatic for developers. The advantage is speed and correctness on emerging protocols rather than a proprietary detection or data asset. \[[s1](#deep-dive-sources), [s22](#deep-dive-sources), [s12](#deep-dive-sources), [s11](#deep-dive-sources), [s19](#deep-dive-sources)\]

### Sales Engagement & Go-to-Market

Keycard now sells from a published price list. The Starter plan is free at 5,000 transactions a month, Team runs $500 a month for 100,000 transactions billed monthly with no commitment, and Enterprise carries custom volume on an annual commitment. Every plan includes the full protocol set, so the upgrade path buys policy scope, retention, deployment choice and support rather than protocol coverage. Accounts still start with a request form asking for a work email.

Named traction is a single reference. Chime is described as running Keycard in production, with its principal product manager for generative AI quoted on deploying agents against production systems in days. A November 2025 comparison page from rival WorkOS pressed on exactly this point, and only the Chime disclosure has answered it since.

Around that, the company buys visibility. Two acquisitions since launch, a gold membership at the Agentic AI Foundation next to Anthropic, Google, OpenAI, Microsoft and AWS, and a CRN listing among cloud startups to watch in 2026 keep Keycard in the conversation. None of that is a second customer. \[[s2](#deep-dive-sources), [s7](#deep-dive-sources), [s17](#deep-dive-sources), [s24](#deep-dive-sources), [s13](#deep-dive-sources), [s21](#deep-dive-sources), [s16](#deep-dive-sources)\]

### Pricing Model

Keycard prices the control plane like metered infrastructure. The unit is a transaction, recorded each time Keycard issues a credential, validates an access request, exchanges a credential, or handles a step-up approval, with overage at $1 per 1,000 on paid plans.

The unit choice aligns price with the problem: customers pay in proportion to how much their agents actually do, which is the same measure a buyer uses to gauge agent adoption. The published definition also counts a transaction at each credential issue, validation, exchange and step-up approval, and a delegation chain performs one at every hop, so the bill tracks agent chatter rather than human requests.

The tier boundaries say who Keycard expects to sell to. The free plan already carries real-time telemetry with seven-day retention, and single sign-on plus 90-day retention start at $500 a month. Directory provisioning, dedicated or on-premises deployment, private networking, customer-managed keys and continuous export sit behind an annual enterprise commitment. \[[s2](#deep-dive-sources), [s1](#deep-dive-sources)\]

### Product Delivery & Operations

Keycard delivers a hosted control plane consumed through software kits, a command-line tool and the protocols agents already speak, with an administrative surface for identity, policy, roles, single sign-on, audit and deployment. The documented quickstart has a developer running Claude Code in a Keycard-protected session with policy enforcement and an audit trail, and the same platform underpins the coding-agent and multi-agent products.

Operational depth is documented rather than merely promised. The security architecture reference describes envelope encryption with a key encryption key held in Amazon's key management service, a separate data encryption key per zone, customer-managed keys as an option, and encryption of sensitive data at rest and in transit. Audit events stream to a customer's own security monitoring or data warehouse.

Evidence of delivery at scale is thinner than the architecture. One production customer is disclosed, and Chime's account of agents reaching production systems in days is the strongest public signal that onboarding works as designed. \[[s5](#deep-dive-sources), [s6](#deep-dive-sources), [s7](#deep-dive-sources), [s17](#deep-dive-sources)\]

### Earning Customers' Trust

Keycard carries more third-party assurance than its age suggests. Its SafeBase trust center lists SOC 2 Type 1 and SOC 2 Type 2 under compliance, offers the SOC 2 report, a data flow diagram, a network diagram and a penetration test report, and names its subprocessors, a complete package for a company that launched from stealth in October 2025.

The attestation carries extra weight for this product class. A buyer hands Keycard the authority to issue credentials into production systems, so the vendor's own auditability is part of the purchase decision, and the audit-trail positioning depends on it.

No federal authorization such as FedRAMP appears in the trust collateral, which matters only if Keycard pursues the regulated-government buyers some identity rivals court. \[[s14](#deep-dive-sources), [s1](#deep-dive-sources), [s20](#deep-dive-sources)\]

### Platform Strategy & Ecosystem Positioning

Keycard positions itself as the interoperable layer of the agent stack. It contributes to emerging standards including MCP, WIMSE and OAuth extensions for agents, launch coverage credits it with the earliest production implementation of OAuth 2.1 Client ID Metadata Documents in MCP, and it added ID-JAG, the open standard behind Okta's Cross-App Access, in June 2026. Its kits interoperate with LangChain, Mastra, MCP, A2A and arbitrary APIs.

The build-in-the-open posture is now visible in code. Eighteen public repositories under the company's GitHub organization carry the TypeScript, Python, Go and Ruby kits, a Terraform provider, and a GitHub Actions action that exchanges a workflow's identity token for scoped credentials, and the company has committed to contributing components to the Agentic AI Foundation.

Keycard also bought its way to ecosystem depth. CRN reports that Keycard acquired Runebook the month after its October 2025 raise, bringing a team focused on Model Context Protocol integration kits, and the later Anchor.dev acquisition added certificate and infrastructure engineers. The open-standards posture cuts both ways: every protocol Keycard proves out is one a rival, including Okta itself, can implement second. \[[s18](#deep-dive-sources), [s9](#deep-dive-sources), [s25](#deep-dive-sources), [s13](#deep-dive-sources), [s21](#deep-dive-sources), [s16](#deep-dive-sources)\]

### Team & Execution Capability

Keycard's founding team carries identity work a reader can check. Jared Hanson created Passport.js and was chief architect at Auth0 and a product leader at Okta. Matthew Creager co-founded Manifold and was VP of product at Snyk. Ian Livingstone is a three-time founder who led platform strategy at Snyk.

One of those builds ended in an exit, reported independently. CRN records that Livingstone co-founded Manifold in 2016 as its chief technology officer and that Snyk acquired Manifold in 2021, and that he co-founded Cape Privacy in 2018 and led its engineering until 2020. SecurityWeek describes the company as founded by former Snyk and Okta senior leadership.

The bench extends through acquisitions and backers. Runebook brought a team to expand Keycard's integrations and drop-in kits for the Model Context Protocol, and Anchor.dev added engineers who built developer infrastructure at Cloudflare, GitHub and Heroku. The individual investor list reads as an endorsement from the previous generation of identity infrastructure: the chief technology officer of Auth0, Okta's chief product architect, the chief information security officer of Datadog and the chief technology officer of Cloudflare all put personal money in. \[[s3](#deep-dive-sources), [s21](#deep-dive-sources), [s20](#deep-dive-sources), [s10](#deep-dive-sources), [s11](#deep-dive-sources), [s4](#deep-dive-sources)\]

## Sources

### Company Detail Sources

Cited from the Sourced Details and Matrix Coverage rows.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | [Keycard: The Federated Trust Fabric for the Agent-Native Era](https://keycard.ai/blog/the-federated-trust-fabric-for-the-agent-native-era) | official | 2026-08-25 |
| f2 | [SecurityWeek: Keycard Emerges From Stealth Mode With $38 Million in Funding](https://www.securityweek.com/keycard-emerges-from-stealth-mode-with-38-million-in-funding/) | press | 2026-08-25 |
| f3 | [SiliconANGLE: AI agent security startup Keycard reels in $38M](https://siliconangle.com/2025/10/21/ai-agent-security-startup-keycard-reels-38m/) | press | 2026-08-25 |
| f4 | [AI Defense Matrix Catalog: Keycard product entry](https://catalog.aidefensematrix.com/products/keycard/) | official | 2026-08-25 |

### Profile Analysis Sources

Cited from the Market Readiness section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Keycard homepage: the control plane for autonomous agents](https://keycard.ai) | official | 2026-08-25 |
| s2 | [Keycard about page: founders and individual investors](https://keycard.ai/about) | official | 2026-08-25 |
| s3 | [Keycard pricing page: plans and the transaction metric](https://keycard.ai/pricing) | official | 2026-08-25 |
| s4 | [Keycard press kit: founder biographies](https://keycard.ai/press) | official | 2026-08-25 |
| s5 | [Keycard documentation home: guides, SDKs and admin reference](https://docs.keycard.ai) | official | 2026-08-25 |
| s6 | [Keycard Labs Trust Center on SafeBase, rendered in a browser](https://trust.keycard.ai) | official | 2026-08-25 |
| s7 | [SiliconANGLE: AI agent security startup Keycard reels in $38M](https://siliconangle.com/2025/10/21/ai-agent-security-startup-keycard-reels-38m/) | press | 2026-08-25 |
| s8 | [SecurityWeek: Keycard Emerges From Stealth Mode With $38 Million in Funding](https://www.securityweek.com/keycard-emerges-from-stealth-mode-with-38-million-in-funding/) | press | 2026-08-25 |
| s9 | [CRN: 10 Cloud Computing Startup Companies To Watch In 2026](https://www.crn.com/news/cloud/2026/10-cloud-computing-startup-companies-to-watch-in-2026) | press | 2026-08-25 |
| s10 | [Help Net Security: Keycard helps developers secure autonomous AI agents with scoped access](https://www.helpnetsecurity.com/2026/05/15/keycard-for-multi-agent-apps/) | press | 2026-08-25 |
| s11 | [NIST CSRC: concept paper on software and AI agent identity and authorization](https://csrc.nist.gov/pubs/other/2026/02/05/accelerating-the-adoption-of-software-and-ai-agent/ipd) | regulatory | 2026-08-25 |
| s12 | [Intellyx Brain Candy brief: Keycard, identity based security and governance for agentic AI](https://intellyx.com/2026/03/19/keycard-identify-based-security-and-governance-for-agentic-ai/) | research | 2026-08-25 |
| s13 | [Keycard public code repositories on GitHub](https://github.com/keycardai) | official | 2026-08-25 |
| s14 | [SiliconANGLE: AI agent identity startup Keycard acquires Anchor.dev](https://siliconangle.com/2026/02/10/ai-agent-identity-startup-keycard-acquires-anchor-dev/) | press | 2026-08-25 |
| s15 | [WorkOS comparison page: Keycard for AI Agent Security, published November 2025](https://workos.com/blog/keycard-vs-workos-agent-credentials-enterprise-authentication) | official | 2026-08-25 |
| s16 | [Keycard blog: announcing Keycard for Coding Agents, March 2026](https://keycard.ai/blog/announcing-keycard-for-coding-agents) | official | 2026-08-25 |
| s17 | [Keycard blog: support for ID-JAG and Cross-App Access from Okta, June 2026](https://keycard.ai/blog/announcing-keycard-support-for-id-jag-cross-app-access-okta) | official | 2026-08-25 |
| s18 | [Help Net Security: Keycard emerges from stealth with identity and access solution for AI agents](https://www.helpnetsecurity.com/2025/10/22/keycard-ai-agents-identity-access-platform/) | press | 2026-08-25 |

### Deep-Dive Sources

Cited from the Strategy Deep Dive section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Keycard homepage: the control plane for autonomous agents](https://keycard.ai) | official | 2026-08-25 |
| s2 | [Keycard pricing page: plans and the transaction metric](https://keycard.ai/pricing) | official | 2026-08-25 |
| s3 | [Keycard press kit: founder biographies](https://keycard.ai/press) | official | 2026-08-25 |
| s4 | [Keycard about page: individual investors](https://keycard.ai/about) | official | 2026-08-25 |
| s5 | [Keycard documentation home: guides, SDKs and admin reference](https://docs.keycard.ai) | official | 2026-08-25 |
| s6 | [Keycard documentation: security architecture reference](https://docs.keycard.ai/reference/security-architecture/) | official | 2026-08-25 |
| s7 | [Keycard blog: announcing Keycard for Coding Agents, March 2026](https://keycard.ai/blog/announcing-keycard-for-coding-agents) | official | 2026-08-25 |
| s8 | [Keycard blog: announcing Keycard for Multi-Agent Apps, May 2026](https://keycard.ai/blog/announcing-keycard-for-multi-agent-apps) | official | 2026-08-25 |
| s9 | [Keycard blog: support for ID-JAG and Cross-App Access from Okta, June 2026](https://keycard.ai/blog/announcing-keycard-support-for-id-jag-cross-app-access-okta) | official | 2026-08-25 |
| s10 | [Keycard blog: Keycard acquires Runebook, November 2025](https://keycard.ai/blog/making-mcp-production-ready-keycard-acquires-runebook) | official | 2026-08-25 |
| s11 | [Keycard blog: Keycard acquires Anchor.dev, February 2026](https://keycard.ai/blog/keycard-acquires-anchor-dev) | official | 2026-08-25 |
| s12 | [Keycard blog: verified device identity with Smallstep, March 2026](https://keycard.ai/blog/bringing-verified-device-identity-to-agents-with-smallstep) | official | 2026-08-25 |
| s13 | [Keycard blog: joining the Agentic AI Foundation, February 2026](https://keycard.ai/blog/keycard-joins-the-agentic-ai-foundation) | official | 2026-08-25 |
| s14 | [Keycard Labs Trust Center on SafeBase, rendered in a browser](https://trust.keycard.ai) | official | 2026-08-25 |
| s15 | [SiliconANGLE: AI agent security startup Keycard reels in $38M](https://siliconangle.com/2025/10/21/ai-agent-security-startup-keycard-reels-38m/) | press | 2026-08-25 |
| s16 | [SiliconANGLE: AI agent identity startup Keycard acquires Anchor.dev](https://siliconangle.com/2026/02/10/ai-agent-identity-startup-keycard-acquires-anchor-dev/) | press | 2026-08-25 |
| s17 | [Help Net Security: Keycard helps developers secure autonomous AI agents with scoped access](https://www.helpnetsecurity.com/2026/05/15/keycard-for-multi-agent-apps/) | press | 2026-08-25 |
| s18 | [Help Net Security: Keycard emerges from stealth with identity and access solution for AI agents](https://www.helpnetsecurity.com/2025/10/22/keycard-ai-agents-identity-access-platform/) | press | 2026-08-25 |
| s19 | [Biometric Update: 1Password and Keycard present tools for secure AI agent credential delegation](https://www.biometricupdate.com/202605/1password-keycard-present-tools-for-secure-ai-agent-credential-delegation) | press | 2026-08-25 |
| s20 | [SecurityWeek: Keycard Emerges From Stealth Mode With $38 Million in Funding](https://www.securityweek.com/keycard-emerges-from-stealth-mode-with-38-million-in-funding/) | press | 2026-08-25 |
| s21 | [CRN: 10 Cloud Computing Startup Companies To Watch In 2026](https://www.crn.com/news/cloud/2026/10-cloud-computing-startup-companies-to-watch-in-2026) | press | 2026-08-25 |
| s22 | [Intellyx Brain Candy brief: Keycard, identity based security and governance for agentic AI](https://intellyx.com/2026/03/19/keycard-identify-based-security-and-governance-for-agentic-ai/) | research | 2026-08-25 |
| s23 | [NIST CSRC: concept paper on software and AI agent identity and authorization](https://csrc.nist.gov/pubs/other/2026/02/05/accelerating-the-adoption-of-software-and-ai-agent/ipd) | regulatory | 2026-08-25 |
| s24 | [WorkOS comparison page: Keycard for AI Agent Security, published November 2025](https://workos.com/blog/keycard-vs-workos-agent-credentials-enterprise-authentication) | official | 2026-08-25 |
| s25 | [Keycard public code repositories on GitHub](https://github.com/keycardai) | official | 2026-08-25 |

## Disclaimer

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.
