· investment-strategies  · 2 min read

Bessemer-Backed Act Security Emerges With $60M to Kill Cloud Access Paths

Act Security, founded by the Medigate team and backed by Bessemer from seed through Series A, emerged from stealth with $60M to eliminate the access sprawl that makes cloud vulnerabilities exploitable — including by AI agents.

Act Security emerged from stealth on July 28, 2026 with $60 million in disclosed funding — including seed capital from Bessemer Venture Partners — to stop selling more vulnerability lists and start removing the paths attackers (and agents) use.

Key facts

  • Company: Act Security (action-centric cloud security)
  • Total funding: $60M
  • Seed ($20M): Team8 + Bessemer Venture Partners (Hetz, Claltech)
  • Series A ($40M): Notable Capital (Startpoint Capital, SVCI)
  • Public launch: July 28, 2026 (rounds previously private)
  • Founders: Jonathan Langer (CEO), Itay Kirshenbaum (CTO), Stephan Goldberg (CPO), Ilai Fallach (VP R&D) — Medigate / Claroty veterans
  • HQ: Tel Aviv

Who uses Act — and why

Customers are cloud security, IAM, and platform teams that already own CSPM/CNAPP tools and still cannot patch fast enough.

They hire Act when:

  • ~Most cloud permissions are unused (Act cites ~97% unused/unneeded in customer environments).
  • AI agents inherit broad human-era access and run 24/7 without human judgment.
  • Compliance (NIST 800-53, PCI DSS, HIPAA) needs continuous control mapping, not quarterly scramble.

Job to be done: shrink blast radius so a missed patch or a misdirected agent cannot walk the network.

Why this matters now

AI sped up offense (finding and chaining exposures) faster than vendors can ship patches. Findings dashboards got denser; exploitable access paths did not shrink. Act’s bet: prevention via deterministic boundaries across humans, workloads, and agents — using cloud-native controls customers already have.

Why raise from Bessemer (portfolio fit)

Bessemer backed the team at seed and stayed through Series A. That is relationship capital:

  • Prior Medigate outcome credibility with BVP.
  • Explicit firm thesis that prevention beats more alert volume.
  • Same cyber franchise that just led Onyx — Bessemer is stacking an agentic-era security book (endpoint control, agent control plane, cloud access prevention).

Founders likely wanted a lead that already knew their operating style and could help recruit enterprise design partners quickly after stealth.

Act vs Onyx vs Neo (same week, different layer)

CompanyLayerPrimary buyer pain
ActCloud access paths / boundariesUnused permissions make vulns and agents dangerous
OnyxAgent control plane (steer/block)Agents acting across SaaS/cloud/endpoints
NeoEndpoint agentic software controlWhat agents are running on devices and how to govern them

Useful for founders: you can raise into the same mega-theme without competing on the same SKU.

Practical takeaway

  • Founders: If your cyber deck only shows “more detections,” expect pushback. Act’s narrative — and Bessemer’s — is remove conditions of exploitability.
  • Investors: Diligence should ask what % of permissions Act actually removes and whether CI/CD enforcement sticks when eng velocity is the KPI.

Sources

  1. PR Newswire — Act Security $60M launch (Jul 28, 2026): https://www.prnewswire.com/il/news-releases/act-security-launches-action-centric-cloud-security-platform-with-60-million-in-funding-302836148.html
  2. Bessemer — Act investment note: https://www.bvp.com/news/act-proactive-cloud-security
  3. Bessemer fund profile: /fund/bessemer-venture-partners

Frequently Asked Questions

Common questions about this topic

Back to Blog

Related Posts

View All Posts »