Push Security
Push Security is an AI-native browser security platform deployed as a lightweight extension that combines telemetry, real-time controls, and autonomous agents to stop credential phishing, account takeover, shadow SaaS exposure, and AI-tool data loss for enterprise customers.
- Company typePrivate
- Founded2022
- HeadquartersBoston, United States
- Headcount101–250
- GTM typeB2B
- OfferingSoftware
What Push Security does
Push Security is an AI-native browser security company founded in July 2022 that deploys its platform as a lightweight browser extension rather than requiring infrastructure replacement. The platform combines privacy-preserving browser telemetry, real-time in-browser controls, and autonomous AI agents to detect and stop browser-based attacks — including AiTM phishing, ClickFix, ConsentFix, device code phishing, session hijacking, malicious OAuth integrations, and credential stuffing — across Chrome, Edge, Firefox, Brave, Arc, Safari, Opera, and AI/enterprise browsers. Beyond attack prevention, the platform secures employee AI tool usage (including shadow AI and agentic sessions), discovers shadow SaaS, hardens unmanaged identities with in-browser guardrails, and provides browser-based data loss prevention.\n\nPush Security originally launched as a London-based SaaS security company and has since relocated its headquarters to Boston following its April 2025 Series B. The company is backed by approximately $49M in total funding across seed ($4M, July 2022, Decibel-led), Series A ($15M, April 2023, GV-led), and Series B ($30M, April 2025, Redpoint Ventures-led) rounds, with strategic participation from Datadog Ventures, B3 Capital, and angel investors including Dug Song and Rich Waldron. The company holds SOC 2 Type II, GDPR, and UK Cyber Essentials certifications and operates from Boston with a London heritage.\n\nThe company operates a per-employee subscription model: $5 per employee per month on annual billing (or $6 monthly) for a standard tier covering up to 500 employees, with custom volume-based enterprise pricing above 500 employees. In mid-2025 Push transitioned to a 'partner-first, partner-only' go-to-market via the Push Security Advisor Network (PSAN) with Pro and Elite tiers, complementing continued enterprise field sales and a self-serve PLG tier. The platform serves security-conscious enterprises across software development, fintech, financial services, cybersecurity, insurance, and industrial automation verticals, with named customers including GitLab, Cribl, Ramp, Sophos, GreyNoise, Thinkst, PortSwigger, Flex, Inductive Automation, Upvest, and Convex Insurance.
Push Security firmographics
Firmographics- Name
- Push Security
- Legal name
- Push Security, Inc.
- Website
- https://pushsecurity.com
- Company type
- Private
- Founded year
- 2022
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Short description
- Push Security is an AI-native browser security platform deployed as a lightweight extension that combines telemetry, real-time controls, and autonomous agents to stop credential phishing, account takeover, shadow SaaS exposure, and AI-tool data loss for enterprise customers.
- Ownership category
- akta.pro rank
Push Security industry classification
Industry- Product category
- Browser Security
- NAICS
- Computer Systems Design and Related Services (54151), Security Systems Services (56162)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Browser & Web Isolation Security (HDADAEAK)
- akta.pro secondary industries
- Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII) (HDAEANAG), Credential Stuffing & Password Attack Protection (HDADALAC)
Keywords
Where Push Security is headquartered
LocationHeadquarters
- HQ city
- Boston
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
Push Security business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Operations
Revenue model
- Browser Security Platform Subscription: Annual and monthly subscription-based pricing model with per-employee licensing. Push costs $6 per employee license/month when billed monthly, discounted to $5 per employee license/month on a 12-month contract. Volume discounts available for organizations with more than 500 employees.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Per seat | Annual | Standard tier for organizations up to 500 employees |
| Subscription | Monthly | Enterprise tier for organizations with 500+ employees |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels6 records
Push Security product offering
Product offeringCore offering
Push Security provides an AI-native browser security platform deployed as a lightweight browser extension that combines rich browser telemetry, real-time control, and autonomous agents to detect and stop browser-based attacks (credential phishing, AiTM, ClickFix, device code phishing, session hijacking), secure AI tool usage, discover shadow SaaS and shadow AI, harden unmanaged identities, and prevent data loss across every browser in an organization without requiring infrastructure replacement.
Product overview
Push Security offers an AI-native browser security platform delivered as a lightweight browser extension (supporting Chrome, Edge, Firefox, Brave, Arc, Safari, Opera, Island, Prisma, Comet, Atlas, and AI/enterprise browsers) that requires no infrastructure replacement. The platform is architected around four core outcomes: detecting and stopping advanced browser-based attacks, achieving security outcomes (hardening identities, securing AI, investigating incidents, preventing data loss), and replacing legacy security tools (remote browser isolation, SWG, CASB, security awareness training). Key detection modules include Account Takeover Prevention, Unmanaged Identity Hardening, Shadow SaaS Discovery & Control, AI Security & Governance, Browser Data Loss Prevention, ClickFix Detection, Malicious Browser Extension Detection, Malicious Copy-Paste Detection, ConsentFix Detection, Device Code Phishing Detection, and InstallFix Detection. The company also publishes the Browser & Identity Attacks Matrix (51 techniques across 10 phases, open-source on GitHub) and the annual 2026 Browser Attack Techniques Report as threat intelligence resources.
Differentiator
Problem solved
Functional benefit
Products and services
- Push Security Platform AI-native browser security platform deployed as a lightweight browser extension (no infrastructure replacement) supporting Chrome, Edge, Firefox, Brave, Arc, Safari, Opera, Island, Prisma, Dia, Comet, Atlas, and other AI/enterprise browsers. Combines browser telemetry, real-time control, and autonomous agents to stop browser-based attacks, secure AI tool usage, harden identities, and prevent data loss.
- Browser & Identity Attacks Matrix Open-source knowledge base documenting 51 browser and identity attack techniques across 10 tactical phases, inspired by MITRE ATT&CK and adapted for cloud-first environments. Published publicly on GitHub for the security community.
- 2026 Browser Attack Techniques Report Annual threat intelligence report analyzing browser-based attack techniques behind major breaches, covering AiTM phishing, malicious OAuth apps, malicious browser extensions, credential stuffing, ClickFix variants, and session hijacking.
Companies that use Push Security
Customer profileNamed customers11 records
Segments3 records
Ideal customer profiles3 records
Push Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability9 records
Feature17 records
Push Security partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core and influential.
- GuidePoint SecuritycoreStrategic partnership announced to enhance browser-based threat detection and response for mutual customers. The partnership aims to provide real-time protection against modern threats like phishing and session hijacking through the browser, which is increasingly recognized as a critical security perimeter.
- John Hammond (Huntress)influentialSenior Principal Security Researcher at Huntress who collaborated with Push Security on ConsentFix v2/v3 research, improving the attack technique and demonstrating its effectiveness. Contributed to webinars and research publications with Push VP R&D Luke Jennings on browser-based attack techniques.
- Troy Hunt (Have I Been Pwned)influentialCreator of Have I Been Pwned collaborated with Push Security on the 'Yes, You've Been Pwned' webinar discussing compromised credential attacks. Provided insights on how identity attacks have evolved over the last decade and the current credential theft landscape.
- Matt Johansen (Vulnerable U)influentialFounder of Vulnerable U collaborated with Push Security Field CTO Mark Orlando on the 'Security Theater vs. Security That Works' webinar examining where enterprise security is falling short and what actually works against browser-based attacks.
Scale indicators7 records
Recent moves6 records
Expansion highlights6 records
Push Security competitors and assessment
Company assessmentDirect peers
- Nudge Security: Browser extension-based SaaS security platform focused on shadow IT discovery, SaaS spend management, and identity governance. Overlaps with Push Security in browser-native SaaS discovery and identity hardening.
- LayerX Security: Browser security platform delivered as a lightweight extension that provides in-browser threat detection, shadow SaaS discovery, and GenAI/data governance. Direct competitor to Push Security in browser-layer security for the enterprise.
- SlashID: Identity and authentication security company with browser-based detection capabilities. Overlaps with Push Security in browser-native identity attack detection and credential protection.
- Seraphic Security: Enterprise browser security platform that protects against phishing, data loss, and shadow IT at the browser layer without replacing the browser. Closely comparable architecture and go-to-market to Push Security.
- SquareX: Browser security company focused on detecting and mitigating browser-based attacks, malicious extensions, and identity threats. Competes with Push Security in the browser-detection surface.
Broad incumbents
- CrowdStrike: Endpoint security leader whose Falcon platform is extending into browser security and identity threat detection. Represents a major incumbent competitor with bundled offerings and substantial channel reach.
- Zscaler: Cloud security platform providing ZIA/ZPA with browser isolation capabilities through partnerships. Competes with Push Security in web/identity threat protection as part of a broader SASE portfolio.
- Netskope: SSE/SASE leader with CASB, SWG, and browser-based DLP capabilities. Overlaps with Push Security in shadow SaaS discovery and browser-layer data protection as part of an integrated platform.
- Menlo Security: Established browser isolation and web security vendor offering Secure Cloud Browser and Anti-Phishing solutions. Competes with Push Security in browser-layer threat prevention for enterprises.
Emerging players
- Island: Enterprise browser startup pursuing an alternative 'replace the browser' architecture rather than extension-based approach. Competes for the same browser security budget but with a fundamentally different deployment model.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
Push Security social profiles
Digital presencePush Security compliance and trust
Trust signalCompliance3 records
Push Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Push Security leadership team
Management profileNumber of profiles
Profiles9 records
Push Security funding detail
Funding detailFunding overview
Funding rounds3 records
Investors5 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Push Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Push Security
What does Push Security do?
Push Security provides an AI-native browser security platform deployed as a lightweight browser extension that combines rich browser telemetry, real-time control, and autonomous agents to detect and stop browser-based attacks (credential phishing, AiTM, ClickFix, device code phishing, session hijacking), secure AI tool usage, discover shadow SaaS and shadow AI, harden unmanaged identities, and prevent data loss across every browser in an organization without requiring infrastructure replacement.
Is Push Security a public or private company?
Push Security is a private company. It is classified as venture growth investor backed and is currently operating.
When was Push Security founded?
Push Security was founded in 2022. It employs 101 to 250 people.
Where is Push Security based?
Push Security is headquartered in Boston, United States, in the North America region.
How does Push Security make money?
One revenue line is on record: browser Security Platform Subscription.
Who are Push Security's main competitors?
Direct peers on record are Nudge Security, LayerX Security, SlashID, Seraphic Security and SquareX. Broad incumbents are CrowdStrike, Zscaler, Netskope and Menlo Security. Island is listed as an emerging player.
Does Push Security have an API?
No public API is recorded for Push Security.
What industry is Push Security in?
Push Security's product category is Browser Security. Its primary akta.pro industry code is HDADAEAK, Browser & Web Isolation Security, with a secondary code of HDAEANAG, Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII). Its NAICS code is 54151 and its SIC code is 7372.