Token Security
Token Security provides an identity-first security platform that discovers, governs, and remediates AI agent and non-human identity risks across enterprise cloud, SaaS, and AI environments, selling via direct field sales to CISOs and IAM teams at mid-market and enterprise customers.
- Company typePrivate
- Founded2023
- HeadquartersTel Aviv, Israel
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Token Security does
Token Security is a Tel Aviv-based cybersecurity company founded in 2023 by two former Israel Defense Forces Unit 8200 veterans (CEO Itamar Apelblat and CTO Ido Shlomo) that provides an identity-first security platform purpose-built for AI agents and non-human identities (NHIs). The platform is structured around three operational pillars — Discover, Understand, and Enforce — and uses an agentless architecture to correlate AI agents, human users, secrets, permissions, and data into a unified identity graph across IaaS, PaaS, SaaS, workloads, on-premises systems, and databases. Core technical components include the Token MCP Server (a Model Context Protocol interface for natural language queries from Claude, ChatGPT, Gemini, and Cursor), the Token AI Agent (a native conversational assistant embedded in the platform UI), the Enzo AI-native application builder (enabling customers to build operational apps from natural language), and an intent-based permissioning engine that shifts governance from static role-based scopes to dynamic least-privilege controls aligned with each agent's stated and observed purpose. The platform integrates with AWS, Azure, and GCP plus more than 1,000 enterprise systems spanning identity providers, EDRs, SIEMs, vaults, CI/CD pipelines, and AI platforms (OpenAI, Anthropic, Bedrock, Microsoft Copilot, Google Gemini).
Token Security monetizes through quote-based enterprise SaaS subscriptions sold via a direct field-sales motion ("Book a Demo" CTAs sitewide), supplemented by free open-source tooling (AI Privilege Guardian, GPTs Compliance Insights on GitHub) that functions as a top-of-funnel acquisition layer. Its primary buyers are CISOs and identity/IAM teams at mid-market and enterprise organizations that have deployed or are deploying agentic AI at scale, with named customers spanning SaaS, HR technology, EdTech, observability, healthcare, insurance, market intelligence, and infrastructure — including HPE, HiBob, Udemy, Elastic, Klaviyo, BetterHelp, Lemonade, GitLab, GEHA, AlphaSense, and Dayforce. As of early 2026, the company has raised approximately $32 million in disclosed funding across a $7M seed (May 2024, TLV Partners and SNR), a $20M Series A (January 2025, Notable Capital), a $5M uncapped SAFE from the RSAC 2026 Innovation Sandbox contest, and a strategic investment from SVCI; it has also announced a planned relocation of corporate headquarters to the United States.
Token Security firmographics
Firmographics- Name
- Token Security
- Legal name
- Token Security Co., Ltd.
- Website
- https://token.security
- Company type
- Private
- Founded year
- 2023
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Token Security provides an identity-first security platform that discovers, governs, and remediates AI agent and non-human identity risks across enterprise cloud, SaaS, and AI environments, selling via direct field sales to CISOs and IAM teams at mid-market and enterprise customers.
- Ownership category
- akta.pro rank
Token Security industry classification
Industry- Product category
- Cybersecurity Identity Governance
- akta.pro primary industry
- Identity, Access & Secrets Management for AI Systems (IAM for agents/models) (HDAAAKAJ)
- akta.pro secondary industry
- Secrets Management & Machine Identity (API keys, certificates, workload identity) (HDAEAJAJ)
Keywords
Where Token Security is headquartered
LocationHeadquarters
- HQ city
- Tel Aviv
- HQ country
- Israel
- HQ region
- Middle East
Offices2 records
Markets served
Token Security business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Enterprise SaaS Subscription: Recurring subscription revenue from enterprises licensing the AI Agent & Non-Human Identity Security Platform. Sold via 'Book a Demo' enterprise sales motion with custom contracts; pricing is quote-based and not publicly disclosed. Customers include HPE, HiBob, Udemy, Elastic, GEHA, Klaviyo, BetterHelp, and Lemonade.
- Professional Services & Open-Source Tooling (Auxiliary): Adjacent offerings include free open-source tools (AI Privilege Guardian, GPTs Compliance Insights) used as top-of-funnel demand generation, plus likely professional services for deployment, integration, and custom remediation across complex enterprise environments.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Annual | Quote-based enterprise subscription; specific tiers/pricing not publicly listed |
Go-to-market motion1 record
Distribution channels3 records
Marketing channels10 records
Token Security product offering
Product offeringCore offering
Token Security sells an AI Agent & Non-Human Identity (NHI) Security Platform that continuously discovers machine identities and AI agents across enterprise cloud, SaaS, and on-prem environments, maps them into a unified identity graph, and enforces intent-based least-privilege policies with automated remediation. The platform is sold as a quote-based annual subscription to mid-market and enterprise security and identity teams via a direct field-sales motion (Book a Demo).
Differentiator
Problem solved
Functional benefit
Brands
- Token Research: A dedicated research division of Token Security focused on AI and non-human identity security threat research, publishing technical research, threat intelligence, and expert-led insight.
- Enzo
Products and services
- Token Security AI Agent & Non-Human Identity Security Platform The flagship agentless SaaS platform that continuously discovers AI agents and machine identities across IaaS, PaaS, SaaS, workloads, on-prem, and databases; correlates them into a unified identity graph; enforces intent-based least-privilege policies; and provides real-time threat detection with automated IaC-aware remediation. Sold as a quote-based annual enterprise subscription.
- Token MCP Server and AI Agent A conversational AI layer built into the Token Security platform that lets security, IAM, and development teams query their NHI environment, retrieve findings, generate remediation scripts, and initiate actions via natural language — available as a native UI agent and as an MCP Server consumable from external chat and AI agent apps.
- Enzo (AI-Native Application Builder) An AI-native application builder that enables Token Security customers to describe an identity security workflow in natural language and have Enzo generate an application that operationalizes identity data into actionable controls, addressing the gap where platforms could visualize risk but could not make remediation actionable.
- AI Privilege Guardian (Free Open-Source Tool) A free, open-source interactive tool that enables enterprises to define agent intent, generate granular permission policies, and detect privilege drift by comparing actual behavior against declared purpose for AI agents across cloud environments. Distributed as a top-of-funnel demand-generation offering.
- GPTs Compliance Insights (GCI) — Open-Source Tool A free, open-source tool published on GitHub that discovers Custom GPTs, identifies their owners, and surfaces access scope — used by security and IAM teams to inventory shadow AI usage and as a top-of-funnel acquisition mechanism into the enterprise platform.
Companies that use Token Security
Customer profileNamed customers13 records
Segments5 records
Ideal customer profiles4 records
Token Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration76 records
AI capability12 records
Feature10 records
Token Security partnerships and signals
Strategic signalPartnerships
Twelve partnerships are on record, tiered core and flagship.
- CrowdStrikecoreEcosystem partner offering endpoint forensic analysis for AI agent and NHI security; integrated with Token Security's platform and listed on the integrations page under EDR category.
- OpenAIcoreEcosystem partner providing GPT compliance auditing capabilities within Token Security's NHI security solution; integrated as an AI Platform connector on the integrations page.
- DescopecoreCo-published the AI Security Guide alongside Token Security as a partner during the 2025 momentum period, indicating joint thought leadership and likely co-marketing activity.
- Amazon Web Services (AWS)flagshipFirst-class integration covering AWS cloud resources, IAM roles, EKS, AWS Secrets Manager, AWS Redshift, and Bedrock AI platform; foundational to Token Security's discovery and posture management capabilities.
- Microsoft AzureflagshipFirst-class integration covering Azure cloud services, Microsoft Entra ID, AKS, Azure DevOps, Microsoft Defender, Microsoft Sentinel, and Microsoft Copilot/Foundry; central to Token Security's NHI discovery.
- Google Cloud Platform (GCP)flagshipFirst-class integration covering GCP cloud services, GKE, Google Workspace, Google Gemini AI platform, and GCP Secret Manager.
- OktacoreIdentity provider integration enabling Token Security to discover and govern NHIs managed by Okta and align with enterprise SSO.
- AnthropiccoreAI platform integration enabling Token Security to discover and govern Anthropic Claude usage and related AI agent identities.
- HashiCorp Vault / CyberArk / AWS Secrets Manager / GCP Secret ManagercoreVault integrations enabling Token Security to discover vault-managed secrets and migrate unvaulted secrets to secured secret stores as part of lifecycle management.
- Cloud Security Alliance (CSA)flagshipCommissioned and co-published the 'Autonomous but Not Controlled: AI Agent Incidents Now Common in Enterprises' survey (April 2026), validating Token Security's research-driven market positioning around AI agent governance.
- Splunk / Datadog / Microsoft Sentinel / ExabeamcoreSIEM and log analytics integrations enabling Token Security's NHI threat detection to feed alerts and telemetry into enterprise security operations platforms.
- GitHub / GitLab / Bitbucket / Azure DevOps / CircleCI / GitHub Actions / JenkinscoreCI/CD and source manager integrations enabling Token Security to discover NHIs provisioned through DevOps pipelines and link identities back to Infrastructure-as-Code (IaC) artifacts.
Scale indicators13 records
Recent moves7 records
Expansion highlights7 records
Token Security competitors and assessment
Company assessmentDirect peers
- Astrix Security: Astrix Security is the closest direct competitor to Token Security, focused specifically on securing non-human identities (service accounts, API keys, OAuth tokens, AI agents) and detecting third-party/connected-app risk. Highly comparable in product scope, customer profile (mid-market to enterprise CISOs), and stage.
- Entro Security: Entro Security provides a holistic Non-Human Identity security platform covering secrets lifecycle, posture management, and threat detection across cloud and SaaS. Direct NHI overlap with Token Security, with a similar early-to-growth-stage profile and enterprise SaaS GTM motion.
Broad incumbents
- CyberArk: CyberArk is the leader in Privileged Access Management and has expanded into secrets management and machine identity security. It is a broad incumbent in the same buyer and overlapping technology area, with much greater scale and a wider portfolio than Token Security's focused NHI/AI-agent platform.
- HashiCorp (Vault): HashiCorp Vault is a leading secrets management and identity-based secrets platform (now part of IBM), used by many of the same enterprises Token Security targets. It overlaps on secrets, workload identity, and machine credentials but does not natively offer AI-agent intent-based governance.
- Okta: Okta is a leading identity and access management platform serving the same enterprise CISO buyers as Token Security. Its acquisition of Spera Security added NHI discovery capability, making it a credible incumbent competitor that could bundle NHI/AI-agent governance into its existing identity platform.
- Wiz: Wiz is a leading cloud security platform (CNAPP) that has been expanding into identity- and entitlement-related capabilities. It targets the same enterprise security buyers and overlaps with Token Security on cloud identity and posture management, with much broader scale.
- BeyondTrust: BeyondTrust is a broad privileged access management and identity security vendor with deep enterprise penetration. It overlaps with Token Security on privileged/machine identity governance and serves a similar enterprise buyer base.
Emerging players
- Silverfort: Silverfort provides unified identity protection across on-prem and cloud environments, including for service accounts and machine identities. It addresses a partially overlapping buyer problem and competes with Token Security in identity threat detection and post-breach prevention.
- Akeyless: Akeyless provides a unified secrets management and zero-trust application access platform. It overlaps with Token Security on secrets lifecycle and machine identity credential management for cloud-native environments, with a similar emerging-vendor profile.
- AuthMind: AuthMind is an identity-focused security platform that inventories and secures non-human identities and service accounts across cloud, SaaS, and on-prem. It is a partial-overlap emerging competitor in the same NHI category Token Security is building.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks1 record
Key highlights7 records
Customer concentration
Token Security social profiles
Digital presenceToken Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Token Security leadership team
Management profileNumber of profiles
Profiles8 records
Token Security funding detail
Funding detailFunding overview
Funding rounds5 records
Investors6 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Token Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Token Security
What does Token Security do?
Token Security sells an AI Agent & Non-Human Identity (NHI) Security Platform that continuously discovers machine identities and AI agents across enterprise cloud, SaaS, and on-prem environments, maps them into a unified identity graph, and enforces intent-based least-privilege policies with automated remediation. The platform is sold as a quote-based annual subscription to mid-market and enterprise security and identity teams via a direct field-sales motion (Book a Demo).
Is Token Security a public or private company?
Token Security is a private company. It is classified as venture growth investor backed and is currently operating.
When was Token Security founded?
Token Security was founded in 2023. It employs 11 to 50 people.
Where is Token Security based?
Token Security is headquartered in Tel Aviv, Israel, in the Middle East region.
How does Token Security make money?
Two revenue lines are on record. Enterprise SaaS Subscription is the primary driver. The others are professional Services & Open-Source Tooling (Auxiliary).
Who are Token Security's main competitors?
Direct peers on record are Astrix Security and Entro Security. Broad incumbents are CyberArk, HashiCorp (Vault), Okta, Wiz and BeyondTrust. Emerging players are Silverfort, Akeyless and AuthMind.
Does Token Security have an API?
Yes. Token Security offers an MCP Server (Model Context Protocol) and AI Agent that deliver a real-time natural language interface enabling security, IAM, and development teams to query their environment using natural language. The MCP Server can be consumed from chat applications such as Claude, ChatGPT, Gemini, or AI agent-based applications like Cursor. Token AI supports dynamic querying across the NHI Inventory, NHI Security Posture Management, Lifecycle Management, Secrets, and Threat Detection and Response, providing instant insights, explanations, and guided remediation recommendations including scripts, CLI commands, and fix recommendations. Webhooks are supported for custom integrations.
What industry is Token Security in?
Token Security's product category is Cybersecurity Identity Governance. Its primary akta.pro industry code is HDAAAKAJ, Identity, Access & Secrets Management for AI Systems (IAM for agents/models), with a secondary code of HDAEAJAJ, Secrets Management & Machine Identity (API keys, certificates, workload identity).