Act: Proactive cloud security

Bessemer Venture Partners backs Act Security from seed to Series A—company emerges from stealth with $60M to eliminate the access paths behind security breaches in the AI era.

Over the last decade, cloud security has revealed where risk lies across organizations, setting off an endless race to fix vulnerabilities. Security teams are handed infinite tables of misconfigurations and vulnerabilities and then spend their days triaging one finding at a time, while the real problem (the access lying underneath) typically expands. 

That gap used to be tolerable when exploiting access required a human moving at human speed. It’s no longer a deterrent when AI agents can now run inside production systems with real autonomy, and frontier models like Mythos can find and exploit access paths faster than any team can respond. Access—not any single vulnerability—has become the primary attack surface in the AI era, exploitable at machine speed.

Act Security exists to close that gap. The company, founded by the team behind Medigate, has emerged from stealth with $60 million in total funding to launch its cloud security platform. At Bessemer, we’ve worked with this team before, making it all the more exciting to support the work they’re doing now.

Act is currently solving one of the biggest problems of this new era, but when we first invested, it was a team bet more than anything else. Even before the first meeting where we learned about Act, we knew this was one of the best cyber teams out there. We’ve followed them closely since their time at Medigate, which was acquired by Bessemer portfolio company Claroty, where they held leadership roles and were instrumental in Claroty's success. This was a group that had already built something together and had the track record to prove it: moving fast, learning even faster, and genuinely obsessed with customer feedback. They were experienced, yet still open to new ideas rather than set in their ways, and they're building an AI-native company in the truest sense: by using AI in everything they do.

A team that's solved this problem before

Act’s founding team consists of CEO Jonathan Langer, CTO Itay Kirshenbaum, CPO Stephan Goldberg, and VP of R&D Ilai Fallach. Langer and Kirshenbaum built Medigate together, took on senior roles at Claroty post-acquisition, and watched the product they built become a major part of Claroty’s growth. That track record is why we’ve backed Act at its $20 million seed round and now in its Series A. Our conviction in the team at their seed was grounded in our thesis that prevention is the biggest gap in cybersecurity today.

Once an attacker gains a foothold in any cloud asset, the lateral movement to the crown jewels is easy because permissions are sprawling and rarely match what an application actually needs. The team’s insight was to treat this as an access architecture problem and secure the cloud at its foundation, before risk becomes exploitable.

What differentiates Act from traditional cloud security

Act's platform is proactive: instead of surfacing more lists of findings, it eliminates the conditions that make those findings exploitable in the first place. The platform enforces deterministic boundaries, grounded in how a business operates across every human, workload, and AI agent that touches cloud infrastructure, using the cloud-native and traditional controls customers already have in place.

In practice, this means organizations can:

  • Eliminate the access paths that attackers, AI-driven or otherwise, would use to move laterally, so a breach in one area doesn't expose everything
  • Deploy AI agents safely, with tightly scoped access boundaries so an agent can reach exactly what each task requires and nothing more
  • Clean up years of accumulated access sprawl and prevent it from reaccumulating, extending enforcement into the CI/CD pipeline so new violations never reach production
  • Map access controls directly to frameworks like NIST 800-53, PCI DSS, and HIPAA, turning compliance into a continuous byproduct of the platform rather than a quarterly scramble

Our cybersecurity strategy at Bessemer has remained consistent: back the strongest teams early, even when the category is still taking shape. We believe the team is what determines whether a company can outperform a hard, ambiguous problem. When we first invested in Act’s seed, the company didn't have a product yet, and the team was validating their thesis for access-based security for cloud environments. Our bet was on Langer, Kirshenbaum, Goldberg, and Fallach as one of the strongest cyber teams to come out of Israel, with a shared history of building and scaling together.

Today, Act has gone from being a validation process run through conversations with CISOs and security practitioners to a live platform addressing what we believe is one of the largest opportunities in cybersecurity today. The assumption that risk moves at human speed is outdated. As AI agents gain more autonomy inside production environments, the organizations that survive will be the ones that remove their access sprawl before it becomes someone else's attack path.

We're proud to have backed Act since its earliest days, and we look forward to continuing the journey with Jonathan and the team as they help the industry move from surfacing risk to eliminating it.