THE SECURITY BRIEF
PLATFORM RELEASE / AUG 2025 · HUMAN + NON-HUMAN IDENTITIESCUSTOMER REPORT / LIFELABS: DETECTION & RESPONSE TIMES DOWN >50%
Company / Identity security

Reveal Security watches what happens after “Welcome back”

A valid login can conceal a stolen session, an impatient insider or an AI agent with too much freedom. Reveal Security follows the behavior that comes next.

The executive’s laptop had been stolen. Unfortunately, it was already logged into several applications. In an incident described by Reveal Security, someone used that access to browse proprietary material in Confluence and other business systems. The credentials were legitimate. The activity was not. Reveal flagged the unusual behavior, and security analysts revoked the sessions. A stolen machine had inherited the executive’s digital manners, but apparently not quite convincingly enough.

The useful bits
  • Reveal monitors what human, machine and AI identities do after login.
  • It connects activity across applications to spot unusual behavioral sequences.
  • LifeLabs reports detection and response times fell by more than 50%.

The laptop that passed the test

This is the small, consequential distinction around which Reveal has built a company. Authentication answers whether someone possesses the right proof of access. It cannot settle whether the next action serves the business. An administrator may have permission to change a mailbox. A contractor may be entitled to open a document. Those permissions can also furnish an attacker with an entirely respectable-looking route through an organization.

Reveal sells security software for that interval: after admission, before damage. Its customers are security leaders and analysts responsible for SaaS, cloud and custom applications. The practical problems include insider misuse, compromised credentials and risky service-account activity. The product follows identities through their actions, giving investigators context and supporting responses such as account suspension or session revocation. The login is the beginning of the inquiry.

A journey has a grammar

Consider an illustrative sequence: open a customer record, change a setting, export a file. Each action might be ordinary. Their order, combination and relationship to the identity’s previous work can make the sequence interesting. Reveal calls its core approach Identity Journey Analytics. It uses unsupervised machine learning to learn typical action sequences and identify departures, including activity that crosses application boundaries.

Illustration / three valid actions, one question
01Open recordAccess permitted
02Change settingAccess permitted
03Export fileAccess permitted
Does this sequence fit this identity’s usual work?
Every step has its papers in order. The itinerary deserves a second look. This is an illustration, not a recorded incident.

The comparison matters as much as the anomaly. In a 2024 discussion hosted by Reveal, veteran CISO Jim Routh emphasized comparing users with similar users. An unfamiliar action for one person may be routine for a colleague with comparable responsibilities. That makes the company’s proposition more precise than “AI finds bad things”: it studies the shape of work and looks for sequences that do not belong.

Founded in January 2021 by Doron Hendler, David Movshovitz and Adi Degani, Reveal originally operated as TrackerDetect. Its 2022 financing announcement presented $23 million, led by SYN Ventures, for expansion and product development. Application detection and response was the early framing. The enduring idea was that business activity, rather than authentication alone, deserved its own security scrutiny.

Reveal Security co-founders David Movshovitz, Doron Hendler and Adi Degani, standing outdoors
Three founders, one awkward question: what did the trusted user do next? David Movshovitz, Doron Hendler and Adi Degani, from left.

A hospital lab’s quieter queue

LifeLabs offers a more useful test than an adjective on a product page. Its applications handle sensitive healthcare data. According to the customer case study published by Reveal, home-grown monitoring was expensive to maintain, produced weak signals and struggled to detect insider threats. Strong authentication did not give the security team a sufficiently clear account of what happened inside the applications.

LifeLabs deployed Reveal to learn identity behavior in those systems. The reported result was a reduction of more than 50% in both mean time to detect and mean time to respond. These are customer-reported outcomes in a vendor-published case study, rather than a universal performance guarantee. Their significance is operational: a team could investigate sooner, with less uncertainty about whether an alert deserved attention.

>50%

Reported reduction in detection and response times at LifeLabs.Customer case study / results specific to this deployment

“My team doesn’t have to be sold on it. They just love using it.”Mike Melo / CISO, LifeLabs

The audit that arrived a month late

At Silverstein Properties, the difficulty had a different timetable. The property company used Yardi for financial and accounting work, conducted access reviews and stored audit logs. CTO Yael Urman described a process that could uncover anomalies a month or more after they happened. If a user immediately removed their own access, an exception might escape that review altogether.

Reveal monitored user and administrator activity in Yardi, seeking exceptions closer to when they occurred. The case study reports improved detection and response and support for Sarbanes-Oxley controls. The lesson is available even to a reader buying nothing: retaining a log and interpreting it promptly are separate jobs. A beautifully documented surprise is still a surprise.

The insider who never sleeps

Reveal’s August 2025 platform release included human and non-human identities. Its current website places AI agents at the center of the insider-threat story. That is a recognizable extension of the original problem. Software acting with a worker’s credentials may be entitled to enter an application while doing something the worker never intended.

The platform describes a Trust Budget that decreases as anomalous behavior accumulates, with responses ranging from softer containment to higher-impact actions requiring approval. This is a product risk mechanism, not a measurement of someone’s moral character. Connecting activity to its human or machine identity remains essential; otherwise an investigator gets a busy timeline and very little explanation.

Buy the workflow, not the adjective

Reveal is enterprise subscription software, purchased through service orders directly or through authorized resellers. It fits alongside identity-access controls and security operations tools. Broader UEBA products and internal log-based monitoring are alternative routes to parts of the problem. The relevant comparison is whether a team can explain, investigate and contain suspicious application behavior with an acceptable workload.

A sensible evaluation starts with actual audit coverage and identity matching, then checks which response actions the integrations can perform. This is an inference from the architecture: activity absent from the available telemetry cannot provide behavioral evidence. New legitimate workflows also need context. The idea worth copying is modest and demanding: after someone gets access, keep asking whether what they do makes sense.