Breaking: Your SaaS inventory is probably fictionGrip says it protects 125 million users$66 million raisedFrom shadow SaaS to shadow AI

Company profile / Cybersecurity

Grip Security Wants to Find the SaaS Accounts Nobody Approved - Before an Attacker Does

Employees can adopt an app in minutes; security teams may need months to notice. Grip built a business around closing that gap - and around turning an unruly SaaS inventory into actions a small team can actually finish.

The most dangerous software in a company may not be malware. It may be the harmless-looking scheduling tool an employee tried for a week, the personal design account still holding client files, or the AI assistant connected to a drive with an OAuth permission nobody remembers granting. Each one is a small administrative shrug. In aggregate, they become an identity map that attackers can exploit and security teams cannot see.

Grip Security sells a way to draw that map. Founded in 2021 by Lior Yaari, Idan Fast and Alon Shenkler, the Boston-and-Tel Aviv company discovers SaaS applications, accounts, tenants and their relationships to users. It then ranks exposure and pushes cleanup into access reviews, offboarding routines, identity systems and incident-response workflows. The product is aimed at enterprises where buying an app is easy and governing it is not.

That sounds like inventory software until the inventory answers a more expensive question: when someone leaves, where does their access survive? An identity provider can disable the company account it knows. It cannot magically revoke an account created with a password, a social login or an overlooked secondary tenant. Grip’s wedge is the residue between the official directory and the way people actually work.

Grip Security co-founders Lior Yaari, Idan Fast and Alon Shenkler standing together outdoors
Three intelligence veterans, one recurring CISO complaint. From left: Grip’s founding team discovered that the unofficial software catalog was much livelier than the official one.

The joke that became a company

The founders had served together in Israeli military intelligence. Colleagues joked that the trio would start a company after leaving. The useful twist is that Grip’s idea did not begin in a garage full of whiteboards. It sharpened while Yaari was CTO at cybersecurity investor YL Ventures, talking with CISOs and watching technical teams circle the same complaint: existing SaaS security products did not fit the new shape of work.

Cloud access security brokers, or CASBs, were built when companies had a shorter application list and could route activity through a corporate control point. API-based products could see the services they integrated with. Proxies could see traffic that passed through them. Work-from-home, personal devices and employee-led adoption made both assumptions leaky. The first thing to fail was not encryption or authentication. It was the inventory.

“If no one solved this until October, I will.”Lior Yaari, recalling the line that stopped being a joke

Grip’s original technical promise was deliberately non-intrusive: follow the footprints SaaS applications leave rather than install software on every device or sit inside every network path. Its control plane graphs apps, identities, accounts, authentication methods, OAuth grants, tenants and historical use. That graph supports the second half of the product: decide which access matters, find an owner and act.

What buyers are actually buying

The flagship SaaS Security Control Plane covers discovery, identity risk, access control and workflow orchestration. Grip later added SaaS Security Posture Management, which watches supported applications for configuration drift and compliance gaps. Identity threat detection looks for suspicious access and risky authentication. The newest front door is AI security: inventory AI-enabled apps and agents, inspect their OAuth relationships and non-human identities, and govern what they can reach.

This is enterprise subscription software sold through demos, proofs of concept and assessments; Grip does not publish list prices. Its commercial argument therefore leans on outcomes that a CISO or finance chief can count. NFP reported cutting risk-mitigation time by 80 percent and saving $800,000 annually. A streaming customer reported reducing offboarding work by 80 percent. Interpublic Group said Grip exposed ten times more cloud accounts than it knew about.

10×more cloud accounts found for IPG than it knew about
80%less offboarding effort for a streaming customer
$800Kannual savings reported by NFP

A utility company offers the cleanest version of what changed a buyer’s mind. Its third-party risk tools organized vendor assessments but could not reveal shadow IT. Firewall logs were noisy and disconnected from the people using the services. After meeting Grip at the RSA Conference, the team deployed it, uncovered more than 700 applications and used the resulting context to assess roughly 150 suppliers over 18 months. Two-thirds of those suppliers were identified after Grip arrived. The product did not make risk reviews disappear; it made the queue more honest.

Another software company had a CASB that could detect traffic, yet could not reliably tie activity to identities or support clean offboarding. After adopting Grip, it reported that 91 to 95 percent of apps were running through single sign-on and that 300 applications had been archived. Its small security team traded manual reviews for automated workflows. The decisive feature was not a prettier alert. It was the ability to connect the alert to an accountable person and a repeatable action.

The market moved toward Grip

Grip entered a crowded neighborhood. AppOmni, Adaptive Shield, Obsidian Security, Wing Security, Reco, Valence and Suridata approach SaaS posture, threat detection or governance from different angles. Microsoft, Cisco, Netskope and Skyhigh sell CASB capabilities inside larger security platforms. Identity-governance suites and SaaS-management tools overlap from either side. Grip’s distinction is its attempt to combine broad discovery, identity context and enforcement across both sanctioned and shadow services.

That positioning attracted $6 million in seed funding in April 2021, a $19 million Series A led by Intel Capital that December, and a $41 million Series B led by Third Point Ventures in August 2023. Total disclosed funding reached $66 million. The company says it now protects 125 million users. Its own 2025 report analyzed 29 million SaaS accounts tied to 1.7 million identities across 23,987 applications - a useful demonstration of scale, though the findings come from its customer base rather than a random sample of all companies.

Then AI arrived inside practically every software pitch deck and a great many existing SaaS products. For Grip, shadow AI was less a pivot than a costume change. An employee connecting an AI assistant to Google Drive creates the same family of questions as any shadow app: who authorized it, what identity does it use, which data can it reach, how long does the token live, and who turns it off? Grip’s 2026 expansion added agents and non-human identities to the graph. A Cyera integration adds data sensitivity, linking who has access with what the accessible data is worth.

“It’s easier to sign up for SaaS than it is to track activity.”A utility customer on the problem Grip changed

What an operator can copy

The transferable lesson is a sequence, not a tool recommendation. First, create a continuous inventory from observed behavior, not purchase records alone. Second, attach every account, token and integration to a human or machine identity. Third, rank work by exposure and business importance, because a thousand unowned alerts are merely a new kind of shadow IT. Fourth, send remediation into the systems people already use: identity providers, ticketing, chat, security operations and procurement. Finally, verify closure. A ticket marked done is not proof that an OAuth token died.

There is also a product lesson in Yaari’s path. He listened for a complaint sophisticated buyers repeated while incumbents explained why their architecture was sufficient. He found a wedge with a short reveal: deploy quickly, observe for several days, then show the buyer an inventory that contradicts the spreadsheet. Grip says its proof of concept can surface the app footprint within five days. Surprise is doing part of the selling.

Where the playbook breaksDiscovery is not governance by itself. Grip is a weaker fit for a small organization with a short, tightly controlled app list, or for a company that cannot provide useful identity and activity signals. Automation also fails when nobody owns the policy, application or exception process. In a heavily locked-down environment, an existing identity suite or CASB may cover enough of the estate. And if a team cannot act on findings, broader visibility simply produces a more accurate backlog.

The harder limit is organizational. Grip can identify a forgotten account, calculate a risk score and prepare a workflow. It cannot decide whether the sales team’s oddball tool is essential, whether legal accepts the vendor, or whether the departing executive needs a 30-day exception. Those judgments require owners. The product works best where security, identity, procurement and application teams agree on rules before the dashboard starts blinking.

The useful kind of control

Grip’s company page lists four principles: do not compromise on coverage, make it simple, make it cost-effective, and use “no marketing fluff.” The last line is funny because cybersecurity has never met a dramatic noun it could not capitalize. But the better interpretation is operational. Security teams do not need theatrical visibility. They need the name of the app, the identity behind it, the access it carries and the next defensible action.

That is where Grip fits. It is not antivirus for ChatGPT, nor a magic shield around every SaaS vendor. It is a control layer for the messy middle between a person choosing a tool and an organization deciding what that choice means. The company’s bet is that enterprise software will keep becoming easier to adopt and harder to inventory. So far, AI agents are making that bet look less eccentric by the week.

Go deeper