Lineaje began with a small heresy: finding vulnerable code is the easy part. Its larger bet is to trace every ingredient, judge the real risk, and send back a repair that does not wreck the build.

The internet taught machines to behave like people. Arkose Labs built a business by making the badly behaved ones pay for the privilege.
TruU set out to kill the office password. Then it discovered that the more interesting question begins after login: who - or what - is really acting inside the system?
A badge tap looks trivial. Across 19 hospitals, it helped give clinicians back 49,057 hours a year - and turned a login utility into the wedge for a much larger identity business.
Most security software watches the real network for suspicious behavior. Acalvio takes the stranger route: it fills the attacker’s map with convincing fiction - then waits for the lie to be touched.
The Mountain View security startup began by watching third-party APIs. Then AI agents arrived, inherited the credentials, and made the overlooked space between apps the main event.
Most security tools check the badge at the door. WideField followed the badge through every room - a post-login bet that carried the three-year-old startup into Cisco and Splunk.
Companies taught employees to prove who they are. Aembit is betting the next security market belongs to doing the same for software - issuing short-lived access to workloads and AI agents only when policy says yes.
PlainID is an Israeli cybersecurity company and the recognized pioneer of Policy-Based Access Control (PBAC). Its authorization platform lets enterprises define, manage, and enforce who can access what across applications, data, APIs, microservices, and - increasingly - AI agents, replacing the tangle of hard-coded access rules scattered across systems with centralized, dynamic, real-time policy decisions. Founded in 2014 and headquartered in Tel Aviv with a strong New York presence, PlainID has raised roughly $99-100M and serves Fortune 500 organizations across financial services, healthcare, telecom, and government.
Veza is an identity security company that helps enterprises understand and control who can take what action on what data. Its patented Access Graph maps permissions across cloud platforms, SaaS apps, data systems, and infrastructure for human, machine, and AI identities, letting organizations enforce least privilege, automate access reviews, and govern non-human and AI-agent identities. Founded in 2020 and headquartered in the California Bay Area, Veza agreed to be acquired by ServiceNow in a deal announced December 2025.
Straiker is a Sunnyvale-based agentic AI security company that helps enterprises deploy AI agents without handing attackers the keys. Its platform spans three jobs - Discover AI maps the agents, MCP servers, and workflows running across a company; Ascend AI red-teams them before deployment to surface prompt injection, goal hijacking, and tool misuse; and Defend AI blocks identity abuse, memory poisoning, and data exfiltration at runtime. Founded by former Palo Alto Networks and Akamai security leaders, Straiker raised a $64M Series A in June 2026, bringing total funding to $85M.
Virtue AI is a San Francisco-based enterprise AI security company that helps organizations deploy generative AI and AI agents safely. Founded in 2024 by AI-safety researchers from Berkeley, Stanford, and Chicago, its platform combines automated red-teaming (VirtueRed), real-time multimodal guardrails (VirtueGuard), and an end-to-end agent security suite (AgentSuite) to catch prompt injections, jailbreaks, data poisoning, and policy violations before they reach production. The company raised $30 million in seed and Series A funding and counts frontier AI labs and enterprises in finance, healthcare, and IT among its customers.
Opsin is a San Jose-based enterprise AI security company that helps organizations adopt generative AI tools like Microsoft Copilot, ChatGPT Enterprise, Claude, and Google Gemini without leaking sensitive data. Its platform continuously maps AI agents across the enterprise, assesses what data those agents can surface, detects oversharing and policy violations in real time, and remediates misconfigurations - giving security, GRC, and legal teams visibility and control within about 24 hours of a one-click API integration.
Opal Security is an AI-native identity and access governance platform that gives enterprises real-time visibility and direct control over every identity - employees, service accounts, and AI agents alike. Founded in 2020 in San Francisco, Opal replaces stale, checkbox-style access reviews with policy-as-code and just-in-time access so organizations can enforce least privilege at scale instead of merely auditing it after the fact.