The executive’s laptop had been stolen. Unfortunately, it was already logged into several applications. In an incident described by Reveal Security, someone used that access to browse proprietary material in Confluence and other business systems. The credentials were legitimate. The activity was not. Reveal flagged the unusual behavior, and security analysts revoked the sessions. A stolen machine had inherited the executive’s digital manners, but apparently not quite convincingly enough.
- Reveal monitors what human, machine and AI identities do after login.
- It connects activity across applications to spot unusual behavioral sequences.
- LifeLabs reports detection and response times fell by more than 50%.
The laptop that passed the test
This is the small, consequential distinction around which Reveal has built a company. Authentication answers whether someone possesses the right proof of access. It cannot settle whether the next action serves the business. An administrator may have permission to change a mailbox. A contractor may be entitled to open a document. Those permissions can also furnish an attacker with an entirely respectable-looking route through an organization.
Reveal sells security software for that interval: after admission, before damage. Its customers are security leaders and analysts responsible for SaaS, cloud and custom applications. The practical problems include insider misuse, compromised credentials and risky service-account activity. The product follows identities through their actions, giving investigators context and supporting responses such as account suspension or session revocation. The login is the beginning of the inquiry.
A journey has a grammar
Consider an illustrative sequence: open a customer record, change a setting, export a file. Each action might be ordinary. Their order, combination and relationship to the identity’s previous work can make the sequence interesting. Reveal calls its core approach Identity Journey Analytics. It uses unsupervised machine learning to learn typical action sequences and identify departures, including activity that crosses application boundaries.
The comparison matters as much as the anomaly. In a 2024 discussion hosted by Reveal, veteran CISO Jim Routh emphasized comparing users with similar users. An unfamiliar action for one person may be routine for a colleague with comparable responsibilities. That makes the company’s proposition more precise than “AI finds bad things”: it studies the shape of work and looks for sequences that do not belong.
Founded in January 2021 by Doron Hendler, David Movshovitz and Adi Degani, Reveal originally operated as TrackerDetect. Its 2022 financing announcement presented $23 million, led by SYN Ventures, for expansion and product development. Application detection and response was the early framing. The enduring idea was that business activity, rather than authentication alone, deserved its own security scrutiny.

A hospital lab’s quieter queue
LifeLabs offers a more useful test than an adjective on a product page. Its applications handle sensitive healthcare data. According to the customer case study published by Reveal, home-grown monitoring was expensive to maintain, produced weak signals and struggled to detect insider threats. Strong authentication did not give the security team a sufficiently clear account of what happened inside the applications.
LifeLabs deployed Reveal to learn identity behavior in those systems. The reported result was a reduction of more than 50% in both mean time to detect and mean time to respond. These are customer-reported outcomes in a vendor-published case study, rather than a universal performance guarantee. Their significance is operational: a team could investigate sooner, with less uncertainty about whether an alert deserved attention.
Reported reduction in detection and response times at LifeLabs.Customer case study / results specific to this deployment
“My team doesn’t have to be sold on it. They just love using it.”Mike Melo / CISO, LifeLabs
The audit that arrived a month late
At Silverstein Properties, the difficulty had a different timetable. The property company used Yardi for financial and accounting work, conducted access reviews and stored audit logs. CTO Yael Urman described a process that could uncover anomalies a month or more after they happened. If a user immediately removed their own access, an exception might escape that review altogether.
Reveal monitored user and administrator activity in Yardi, seeking exceptions closer to when they occurred. The case study reports improved detection and response and support for Sarbanes-Oxley controls. The lesson is available even to a reader buying nothing: retaining a log and interpreting it promptly are separate jobs. A beautifully documented surprise is still a surprise.
The insider who never sleeps
Reveal’s August 2025 platform release included human and non-human identities. Its current website places AI agents at the center of the insider-threat story. That is a recognizable extension of the original problem. Software acting with a worker’s credentials may be entitled to enter an application while doing something the worker never intended.
The platform describes a Trust Budget that decreases as anomalous behavior accumulates, with responses ranging from softer containment to higher-impact actions requiring approval. This is a product risk mechanism, not a measurement of someone’s moral character. Connecting activity to its human or machine identity remains essential; otherwise an investigator gets a busy timeline and very little explanation.
Buy the workflow, not the adjective
Reveal is enterprise subscription software, purchased through service orders directly or through authorized resellers. It fits alongside identity-access controls and security operations tools. Broader UEBA products and internal log-based monitoring are alternative routes to parts of the problem. The relevant comparison is whether a team can explain, investigate and contain suspicious application behavior with an acceptable workload.
A sensible evaluation starts with actual audit coverage and identity matching, then checks which response actions the integrations can perform. This is an inference from the architecture: activity absent from the available telemetry cannot provide behavioral evidence. New legitimate workflows also need context. The idea worth copying is modest and demanding: after someone gets access, keep asking whether what they do makes sense.