BREAKING
Ev Kontsevoy, CEO of Teleport

Ev Kontsevoy / Teleport

CEO & Co-Founder · Teleport · San Francisco

Ev
Kontsevoy

The engineer from Krasnoyarsk who decided the password was civilization's weakest link - and spent a decade building the replacement.

2x YC Founder $175M Raised O'Reilly Author $1.1B Valuation Zero Trust Pioneer

Building the Category,
Round by Round

Mailgun · Y Combinator 2011Exit to Rackspace, 2012
Teleport Seed · Y Combinator 2015Early stage
Series A · Kleiner Perkins 2019Infrastructure security thesis
Series B · 2021Accelerating enterprise adoption
Series C · Bessemer $110M · 2022$175.3M total · $1.1B valuation

Passwords Are
Not a Feature

The argument Kontsevoy has been making for a decade is deceptively simple: the traditional approach to infrastructure security is built on secrets - passwords, SSH keys, private keys, shared credentials - and secrets are, by definition, things that leak. They get copied, forgotten, stolen, reused. Every major breach tells some version of this story.

His answer is cryptographic identity. Short-lived certificates that expire automatically. No stored credentials to steal. Every human, every machine, every service gets a unique cryptographic identity. Access is logged, auditable, revocable. The perimeter isn't a network boundary - it's an identity assertion.

He published this argument formally in an O'Reilly book co-authored with Sakshyam Shah and Peter Conrad: Identity-Native Infrastructure Access Management: Preventing Breaches by Eliminating Secrets and Adopting Zero Trust. It is, in effect, the theoretical backbone of the company he runs.

"Security theater is everywhere. Real zero trust requires eliminating secrets entirely - not just layering on more tools."

Ev Kontsevoy · CyberScoop Op-Ed

The phrase "security theater" appears in a CyberScoop opinion piece he wrote - the careful bureaucratic rituals that make organizations feel protected without actually protecting them. Kontsevoy's hostility toward this isn't academic. It's the frustration of an engineer who watched it up close.

Identity-Native Infrastructure Access Management
O'Reilly Media

The Manifesto, Published

Co-authored by Ev Kontsevoy, Sakshyam Shah, and Peter Conrad. Published by O'Reilly Media. Subtitle: Preventing Breaches by Eliminating Secrets and Adopting Zero Trust.

This is not a product manual. It's the architectural argument for why the industry's current approach to infrastructure access is structurally broken - and what replaces it.

The Zero Trust Stack

  • Cryptographic identity replaces all shared secrets
  • Short-lived certificates - access expires automatically
  • Every session is logged, recorded, and auditable
  • Least-privilege enforcement by default, not by policy
  • Unified identity plane across cloud, on-prem, and hybrid
  • Open-source core - engineers must be able to verify what they trust

AI Agents Don't Have
Passwords Either.
That's the Problem.

In January 2026, Kontsevoy introduced Teleport's Agentic Identity Framework - the company's answer to a question the industry wasn't quite asking yet: who is responsible for securing what AI agents can access?

79% of organizations evaluating or deploying agentic AI systems
13% feel highly prepared for the security implications
70% of AI systems have more access than their human counterparts

"AI agents are definitively not human, but they're not service accounts or scripts either. They are a new identity category - and we need to treat them as such."

Ev Kontsevoy · Teleport Agentic Identity Framework, 2026

The organizations Kontsevoy surveyed that described themselves as "confident" in their AI deployments had a 2.2x higher security incident rate than those who said they were cautious. Confidence, in this space, correlates with blind spots. It's the kind of finding that makes a cybersecurity CEO's argument for you.

His framework proposes that AI agents require the same identity-native approach as humans and machines: short-lived credentials, least-privilege access, complete audit trails, and the same cryptographic identity infrastructure. The same playbook. Extended to a new actor class.

Twenty-Five Years,
Two Unicorns,
One Thesis

From applied mathematics in Siberia to defining the security infrastructure of the AI era - Kontsevoy's career reads like a deliberate narrowing of focus toward a single problem.

1994 - 1998
BS in Applied Mathematics, Siberian Federal University (Krasnoyarsk State University), Krasnoyarsk, Russia
1999 - 2003
Software Engineer at National Instruments - first exposure to engineering culture at scale
2006 - 2008
Lead Engineer at GE Security - building the pattern recognition for security infrastructure
2010
Co-founds Mailgun with Taylor Wakefield - email APIs for developers, built in the "scratch your own itch" tradition
2011
Mailgun accepted into Y Combinator W2011. First YC batch. CEO building for Slack, Lyft, GitHub, Reddit.
2012
Rackspace acquires Mailgun. Joins as Director of Product and Strategy, builds the OnMetal product line.
2015
Co-founds Teleport (Gravitational) with Wakefield and Alexander Klizhentas. Second Y Combinator batch: S2015.
2016
Teleport launches publicly as open-source infrastructure access platform under Apache 2.0
2022
Series C: $110M at $1.1B valuation. Bessemer Venture Partners leads. Total raised: $175.3M.
2023
O'Reilly publishes "Identity-Native Infrastructure Access Management." License changes to AGPLv3.
2026
Launches Agentic Identity Framework. Teleport ranked #9 in Security on Fast Company's Most Innovative Companies.

Open Source as
Distribution Strategy

Teleport started with an Apache 2.0 license. It was free, it spread, and engineers adopted it because it solved a real problem. The commercial product built on top of that adoption.

In December 2023, Kontsevoy changed the license to AGPLv3 - a shift that caused discussion in open-source circles. The reason wasn't philosophical. It was competitive. Hyperscalers can take Apache-licensed software, run it as a managed service, and never contribute back. AGPLv3 changes that equation.

The move is a window into how he thinks: pragmatic over principled, but with the principles visible in the structure. The open-source core is still available. Engineers can still verify what they trust. The business model just became more defensible.

"A unified identity layer is a prerequisite to deploying AI within enterprise infrastructure environments."

Ev Kontsevoy · Teleport Blog, 2026

2025-2026 Awards

  • Fast Company Most Innovative in Security, #9 (2026)
  • Cyber Defense Magazine Global InfoSec Awards, 4 categories (2026)
  • AWS Rising Star Partner of the Year (2025)
  • TAG Top Five Leader, Data Access Governance (2025)
  • SC Awards Finalist, Best Identity Management Solution (2026)
  • Citizens Securities Cyber 66 List - hottest privately held cybersecurity companies
  • Futuriom 50 (second consecutive year)

The Specific and
Strange Facts

The details that didn't make the official bio but explain who he is.

✈️

Grew up in Krasnoyarsk fascinated by "the mystery and miracle of flight" - the kind of childhood observation that tends to turn into a career in systems engineering.

🤝

Has co-founded two companies with the same partner, Taylor Wakefield. Mailgun (2010). Teleport (2015). Rare in startups - usually the lesson from the first one is to work with someone different.

🎓

His degree is in Applied Mathematics, not Computer Science. Teleport is written 73.4% in Go - a language built for systems engineering by mathematically-minded programmers.

🏆

Two Y Combinator batches, a decade apart. W2011 as Mailgun CEO. S2015 as Teleport co-founder. YC describes this as a "rare double-founder" pattern.

📖

The O'Reilly book subtitle is "Preventing Breaches by Eliminating Secrets." Teleport's product does exactly that. The book is the thesis; the company is the evidence.

🔑

Changed Teleport's license from Apache 2.0 to AGPLv3 in December 2023 - a rare public acknowledgment that open-source businesses need protection from the very hyperscalers that use their work.

What He Actually Says

On AI Agents

"AI agents are definitively not human, but they're not service accounts or scripts either. They are a new identity category - and we need to treat them as such."

On Security Theater

"Genuine zero trust requires eliminating secrets entirely - not just layering on more tools. Most of what companies call 'zero trust' is performance, not security."

On Engineering Culture

"Engineers shouldn't have to worry about security and compliance issues every time they access computing resources. That friction is where breaches happen."

On Infrastructure Identity

"A unified identity layer is a prerequisite to deploying AI within enterprise infrastructure environments. Without it, you're building on sand."

On the Security Gap

"79% of organizations are evaluating or deploying agentic AI. Only 13% feel highly prepared. That gap is the next major security crisis - and it's already here."

Ev Kontsevoy On Record

Conference talks, podcast interviews, and conversations about the future of infrastructure security.

The EnterpriseReady Podcast

Episode 53 - Kontsevoy in conversation with Replicated CEO Grant Miller on the evolution from competition to collaboration in the enterprise software world. June 2025.

Watch on YouTube ↗

Teleport Connect 2024

Closing remarks from Teleport's annual conference. Kontsevoy on identity attacks as the predominant infrastructure threat - and where the platform goes next. December 2024.

Watch at Teleport.com ↗

Software Defined Talk #346

Kontsevoy's early career, the origin of Teleport's opinionated approach to secure access, and why open-source is still the right foundation for security software. March 2022.

Listen to Episode ↗

Links & Profiles