· investment-strategies · 2 min read
Bessemer-Backed Act Security Emerges With $60M to Kill Cloud Access Paths
Act Security, founded by the Medigate team and backed by Bessemer from seed through Series A, emerged from stealth with $60M to eliminate the access sprawl that makes cloud vulnerabilities exploitable — including by AI agents.
Act Security emerged from stealth on July 28, 2026 with $60 million in disclosed funding — including seed capital from Bessemer Venture Partners — to stop selling more vulnerability lists and start removing the paths attackers (and agents) use.
Key facts
- Company: Act Security (action-centric cloud security)
- Total funding: $60M
- Seed ($20M): Team8 + Bessemer Venture Partners (Hetz, Claltech)
- Series A ($40M): Notable Capital (Startpoint Capital, SVCI)
- Public launch: July 28, 2026 (rounds previously private)
- Founders: Jonathan Langer (CEO), Itay Kirshenbaum (CTO), Stephan Goldberg (CPO), Ilai Fallach (VP R&D) — Medigate / Claroty veterans
- HQ: Tel Aviv
Who uses Act — and why
Customers are cloud security, IAM, and platform teams that already own CSPM/CNAPP tools and still cannot patch fast enough.
They hire Act when:
- ~Most cloud permissions are unused (Act cites ~97% unused/unneeded in customer environments).
- AI agents inherit broad human-era access and run 24/7 without human judgment.
- Compliance (NIST 800-53, PCI DSS, HIPAA) needs continuous control mapping, not quarterly scramble.
Job to be done: shrink blast radius so a missed patch or a misdirected agent cannot walk the network.
Why this matters now
AI sped up offense (finding and chaining exposures) faster than vendors can ship patches. Findings dashboards got denser; exploitable access paths did not shrink. Act’s bet: prevention via deterministic boundaries across humans, workloads, and agents — using cloud-native controls customers already have.
Why raise from Bessemer (portfolio fit)
Bessemer backed the team at seed and stayed through Series A. That is relationship capital:
- Prior Medigate outcome credibility with BVP.
- Explicit firm thesis that prevention beats more alert volume.
- Same cyber franchise that just led Onyx — Bessemer is stacking an agentic-era security book (endpoint control, agent control plane, cloud access prevention).
Founders likely wanted a lead that already knew their operating style and could help recruit enterprise design partners quickly after stealth.
Act vs Onyx vs Neo (same week, different layer)
| Company | Layer | Primary buyer pain |
|---|---|---|
| Act | Cloud access paths / boundaries | Unused permissions make vulns and agents dangerous |
| Onyx | Agent control plane (steer/block) | Agents acting across SaaS/cloud/endpoints |
| Neo | Endpoint agentic software control | What agents are running on devices and how to govern them |
Useful for founders: you can raise into the same mega-theme without competing on the same SKU.
Practical takeaway
- Founders: If your cyber deck only shows “more detections,” expect pushback. Act’s narrative — and Bessemer’s — is remove conditions of exploitability.
- Investors: Diligence should ask what % of permissions Act actually removes and whether CI/CD enforcement sticks when eng velocity is the KPI.
Sources
- PR Newswire — Act Security $60M launch (Jul 28, 2026): https://www.prnewswire.com/il/news-releases/act-security-launches-action-centric-cloud-security-platform-with-60-million-in-funding-302836148.html
- Bessemer — Act investment note: https://www.bvp.com/news/act-proactive-cloud-security
- Bessemer fund profile: /fund/bessemer-venture-partners