Identity deskOnion routing co-inventorThree-time cybersecurity founderAembit CEOMachines need identity, too

Person / Cybersecurity / Identity

David Goldschlag Is Giving Machines Their Own ID Check

He helped invent onion routing, built and sold two security companies, and now wants applications and AI agents to stop borrowing human credentials. The through-line is a career spent replacing assumed trust with evidence.

In 2024, David Goldschlag stepped onto the RSA Conference Innovation Sandbox stage with three minutes to explain an invisible problem. His gray jacket was conventional. His black T-shirt was not. Across it, in plain white type, sat Aembit’s entire argument: “Manage Access, Not Secrets.” Somewhere between the slogan and the stopwatch was a problem most people never see. Software spends all day asking other software for things. A service queries a database. A build pipeline pushes code. An AI agent opens a customer record. Much of that traffic still depends on credentials copied into configuration files, passed between systems, and left alive longer than anyone intended.

Goldschlag has made a career of noticing when an old security bargain no longer fits the shape of computing. In the 1990s, he helped devise a way for communication to travel across public networks without exposing who was talking to whom. In the 2010s, he confronted the collision between personal phones and company data, then the collapse of the corporate network as a useful border. At Aembit, which he co-founded with Kevin Sapp in 2021, the unreliable boundary is identity itself. The person has logged in. The program acting for that person may still be a stranger.

3Security companies co-founded
2Founder-led acquisitions before Aembit
$25MAembit Series A announced in 2024

The onion before the agent

Goldschlag’s route into security began in computer science, with a bachelor’s degree from Wayne State University and a Ph.D. from the University of Texas at Austin. His early career included work at the National Security Agency and the U.S. Naval Research Laboratory. At NRL, he worked with Michael Reed and Paul Syverson on onion routing: a system that sends a connection through a sequence of routers while wrapping routing instructions in layers of encryption. Each router peels away only the layer it needs. No single point gets the whole itinerary.

Their 1997 paper, “Anonymous Connections and Onion Routing,” described anonymous, near-real-time connections designed to resist eavesdropping and traffic analysis. The concept later became part of the technical foundation for Tor. In 2020, the IEEE Symposium on Security and Privacy gave the paper its Test of Time Award. Twenty-three years is a long interval in computer security. It is also a useful measure of a durable idea: the network should not learn more than it needs to do its job.

“I firmly believe that we’re in the age of Identity, and it’s creating a significant change in how applications are built and secured.”David Goldschlag, in an Okta Ventures interview

Onion routing and workload identity appear to pull in opposite directions. One conceals relationships from observers; the other establishes a requester’s identity before granting access. Yet both are exercises in disciplined disclosure. What must this participant prove? What can the intermediary know? What should remain hidden? Goldschlag’s work keeps returning to the connection, the policy around it, and the danger of assuming that location equals legitimacy.

One question, four changing boundaries
1990sPublic networks: hide the communication path
2010sPersonal devices: separate work data from private life
Late 2010sCloud access: trust identity, not network location
NowWorkloads and agents: verify every software actor

Three companies and a moving border

After government research, Goldschlag moved through technical and executive roles at USinternetworking, KeySec, Trusted Edge, and Trust Digital. McAfee acquired Trust Digital in 2010, and Goldschlag became its vice president of mobile. The timing mattered. Employees were choosing app-centric smartphones while companies still behaved as if they owned every screen carrying corporate data.

In 2011, he co-founded MobileSpaces with Yoav Weiss. Its software created a governed workspace for business apps and data on personal devices. Goldschlag described the shift at the time as a move from closed, company-owned, email-centric devices toward open devices selected by users. The technical problem had a human constraint: protect the employer’s information without treating the employee’s personal phone as company property. Pulse Secure acquired MobileSpaces in 2014, and Goldschlag became its senior vice president of strategy and CTO.

His next company narrowed in on the network. Goldschlag and Sapp co-founded New Edge Labs in 2017 to give users fine-grained access to private applications based on identity and context rather than a broad tunnel into a corporate network. Netskope acquired the company in 2019 and made its technology part of Netskope Private Access. Goldschlag stayed through 2021 as vice president of Private Access.

The useful clue arrived as a question. Customers understood identity-based access for people, but they kept asking about software talking to software. Modern applications had stopped being tidy stacks under one roof. They were collections of services spread across cloud providers, databases, partner systems, and software-as-a-service APIs. A secret could open the door, but possession of a secret did not explain what stood outside it.

The founder clue

The next company was hiding inside an edge case from the previous one: if zero trust worked for users, who would provide it for workloads?

A badge for software

Goldschlag and Sapp had known each other for nearly two decades by the time they started Aembit. Their proposal was to bring the machinery of modern human identity to applications. Identify the workload from observable evidence. Evaluate its posture and context. Check a central policy. Give it a short-lived credential for a specific resource. Record what happened. The developer does not have to become an authentication specialist, and the security team gets a comprehensible trail.

David Goldschlag presenting Aembit’s workload identity platform at the 2024 RSA Conference Innovation Sandbox
THREE MINUTES, ONE T-SHIRT, MANY MACHINES - Goldschlag pitches Aembit at the 2024 RSA Conference Innovation Sandbox. The company finished as runner-up. Video frame: RSA Conference.

Aembit emerged from stealth in March 2023 with a generally available service, recognition in a Gartner report on identity-first security, and $16.6 million in seed financing. The company became one of ten RSA Innovation Sandbox finalists in 2024 and finished as runner-up. That September, it announced a $25 million Series A led by Acrew Capital, with participation from Ballistic Ventures, Ten Eleven Ventures, Okta Ventures, and CrowdStrike Falcon Fund. The round brought the company’s reported funding at the time to nearly $45 million.

Disclosed Aembit financing milestones

Seed 2023
$16.6M
Series A
$25M

The category has acquired several names: workload identity, machine identity, non-human identity. The nouns cover applications, scripts, bots, service accounts, automated pipelines, and now AI agents. Their shared oddity is scale. A company may employ thousands of people but operate far more software identities, many created and retired automatically. Password habits that were merely untidy for humans become absurd when multiplied across ephemeral cloud infrastructure.

“More importantly, you really don’t want to manage secrets; you want to manage access.”David Goldschlag

That distinction is the practical center of Aembit. A secret is an object: a token, key, or password that can be copied. Access is a decision: this workload may call this service, under these conditions, for this period. The former tends to linger. The latter can expire. It also turns security policy into something closer to a living system than a cabinet full of spare keys.

When the software speaks for you

AI agents have made Goldschlag’s subject less abstract. An agent does not simply generate text. In an enterprise, it may read a file, update a customer record, query a warehouse, call a payment service, or coordinate other agents. If it uses the employee’s standing permissions, accountability blurs. The agent is not the employee, but it is acting for the employee. Aembit’s current argument is that systems need both identities: who the agent is and on whose behalf it is operating.

Goldschlag has described the desired sequence plainly. Authenticate the agent. Establish the person or system it represents. Determine access rights just in time. Issue an ephemeral credential for the requested service. Log the steps. It is less cinematic than an autonomous assistant racing through a workflow. That is partly the point. Useful infrastructure turns spectacle into procedure.

In 2026, Goldschlag continued pressing that case in articles and industry discussions about agentic identity. He warned that giving every employee an AI assistant can quietly give every assistant the employee’s access. The old shortcut returns in a clever new interface. Shared credentials, oversized permissions, and missing audit trails do not become modern because a language model is holding them.

There is a neat reversal in the full career. Onion routing helped computers communicate without exposing the people at either end. Aembit asks computers to present enough trustworthy evidence to act. Privacy and authorization are not twins, but they are relatives. Both depend on refusing the network’s lazy assumptions. Both ask identity to appear only where it belongs.

Goldschlag’s biography can be read as a tour through cybersecurity eras, but the more personal thread is collaboration. He has said that working with people you like and trust makes the founder’s journey more fun. Sapp has been beside him across two companies. Aembit’s own account emphasizes a remote team and the input of design partners. For a founder preoccupied with formal proofs of trust, he has also built repeatedly on the informal kind earned over years.

The stakes keep changing costumes: an anonymous web session, a personal phone, a cloud application, an AI agent. The question underneath is still stubbornly recognizable. What does this connection deserve, and what evidence earns it? Goldschlag has spent three decades making computers answer more carefully. The machines have become talkative. He would like them to show their papers.