SURF SECURITY
SURF Security provides a Chromium-based Zero Trust enterprise browser and extension that enforces endpoint security, DLP, and Shadow AI controls directly on the device, targeting enterprise CISOs, CIOs, and IT security teams globally. Founded 2022.
- Company typePrivate
- Founded2022
- HeadquartersNew York, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What SURF SECURITY does
SURF Security is an enterprise cybersecurity vendor founded in 2022 in London with US headquarters in New York. The company sells a Chromium-based Zero Trust enterprise browser and a lightweight browser extension that enforce security policy directly on the endpoint, eliminating the need for proxy, VDI, or traffic backhauling. The platform targets enterprise CISOs, CIOs, IT/Security teams, and compliance officers, with named customers spanning telecommunications (Ericsson, Vodafone), security (Tanium, Check Point), professional services (PIB Group), HR/staffing (Jobandtalent), and healthcare (Alivi, Numan). It is positioned to consolidate the VPN, VDI, CASB, SWG, and RBI tool stack into a single browser-based control point that also covers managed and unmanaged BYOD devices and third-party contractor access.
The core technology is a Chromium browser with an on-device policy engine plus an extension that wraps Chrome and Edge. Product portfolio spans the Zero Trust Browser, Zero Trust Extension, a Secure Access module for scoped remote access, an Agentic AI runtime (a sandboxed, human-verified execution loop for autonomous agents with an air-gap between planning and live access), a Shadow AI Extension for governing GenAI tools, and an AI Deepfake Detection browser feature launched in November 2024. Integrations include native SSO and group-sync with Okta (Okta Ventures is an investor), Microsoft Entra ID, Splunk SIEM, and MDM push providers; the platform is SOC 2 Type II certified and maps controls to GDPR, ISO 27001, PCI-DSS, and DORA.
The business model is per-identity annual subscription sold primarily via enterprise field sales, led by a free proof-of-concept period that converts into paid contracts. Distribution is augmented by a formal partner program targeting system integrators and MSSPs and by Okta co-sell motion. The company is privately held, venture-backed by 11.2 Capital, Okta Ventures, and Mango Capital (seed, November 2022), led by CEO Moty Jacob and CTO Ziv Yankovitz, and operates with 11-50 employees.
SURF SECURITY firmographics
Firmographics- Name
- SURF SECURITY
- Legal name
- Surf Security Inc.
- Website
- https://surf.security
- Company type
- Private
- Founded year
- 2022
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- SURF Security provides a Chromium-based Zero Trust enterprise browser and extension that enforces endpoint security, DLP, and Shadow AI controls directly on the device, targeting enterprise CISOs, CIOs, and IT security teams globally. Founded 2022.
- Ownership category
- akta.pro rank
SURF SECURITY industry classification
Industry- Product category
- Enterprise Browser Security
- NAICS
- Software Publishers (5132), Software Publishers (51321)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Browser & Web Isolation Security (HDADAEAK)
- akta.pro secondary industries
- Access Management & Policy Enforcement (Zero Trust) (BPAMAEAH), Identity & Access Security Services (IAM, PAM, Zero Trust) (BPAKAHAI)
Keywords
Where SURF SECURITY is headquartered
LocationHeadquarters
- HQ city
- New York
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
SURF SECURITY business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Enterprise Browser Subscription: Subscription-based access to the full Zero Trust Browser platform, priced per user/identity with an annual billing cycle. The platform is offered initially as a free POC (proof of concept), then transitions to a paid enterprise subscription plan.
- Zero Trust Extension Subscription: Revenue generated from the lightweight Zero Trust browser extension, offered as part of the same enterprise subscription tier or potentially as a separate per-seat subscription.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Pay-as-you-go | Free POC tier for initial evaluation |
| Subscription | Annual | Enterprise paid subscription |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels7 records
SURF SECURITY product offering
Product offeringCore offering
SURF Security builds a Chromium-based Zero Trust Enterprise Browser delivered as both a full standalone browser and a lightweight extension for Chrome and Edge. The platform enforces security policy directly on the endpoint, providing on-device DLP, Shadow AI discovery and control, a sandboxed Agentic AI runtime, AI deepfake detection, scoped Zero Trust access, and compliance audit trails that replace VPN, VDI, CASB, SWG, and RBI infrastructure. The product is sold per user/identity on an annual subscription basis to enterprise security, IT, compliance, and contractor-access use cases.
Product overview
SURF Security is a browser-SASE cybersecurity company that has created a unified Zero Trust Enterprise Browser platform built around a Chromium-based browser, a lightweight browser extension, and a dedicated Agentic AI security module. The portfolio consists of the core Zero Trust Browser (full Chromium-based browser replacing or augmenting consumer browsers), the Zero Trust Extension (add-on for existing browsers), SURF Agentic AI (secure runtime for autonomous AI agents), and the Shadow AI Extension (for discovering and governing AI tool usage). Together, these products secure generative AI, web threats, and remote access from a single browser-based control point, eliminating the need for separate VPN, VDI, CASB, or proxy infrastructure.
Differentiator
Problem solved
Functional benefit
Products and services
- Zero Trust Browser A full Chromium-based Zero Trust enterprise browser that provides endpoint security controls directly in the browser. Replaces or augments consumer browsers (Chrome, Edge) with security features including in-browser DLP for GenAI, Zero Trust access controls, and data monitoring without requiring VDI, proxy, or backhaul infrastructure. Designed for enterprise IT and security teams.
- Zero Trust Extension A lightweight browser extension that adds enterprise Zero Trust controls to existing Chrome, Edge, and other Chromium browsers. Users do not need to switch browsers to be protected, enabling frictionless deployment across managed and unmanaged devices for BYOD and contractor scenarios.
- SURF Agentic AI The first secure runtime for autonomous agent workflows. A sandboxed, human-verified environment that isolates AI agents from live systems, enforcing an air-gap between planning and execution to prevent prompt injection attacks and rogue autonomous actions. Includes full video, logs, and transcripts for auditability.
- Shadow AI Extension A specialized extension for discovering and governing AI tool usage across the organization. Discovers sanctioned and shadow AI on managed and unmanaged devices, masks PII and secrets in prompts, and blocks risky uploads in real time. Governs AI browser extensions and their permission scope.
- AI Deepfake Detection Tool An AI-powered deepfake detection capability integrated into the SURF enterprise browser that identifies manipulated images and video content in real time, addressing AI-generated fraud and social engineering threats.
- Secure Access Zero Trust remote access capability that replaces VPN, VDI, and CASB stack. Provides scoped access to corporate applications for contractors, BYOD staff, and acquired teams without requiring laptops to ship or virtual desktops to run. Supports third-party contractors with specific app access and full audit trails.
Quantifiable outcome
- Organizations report 0 minutes from install to org-wide protection (as marketed on the platform)
- +3 more outcomes
Companies that use SURF SECURITY
Customer profileNamed customers8 records
Segments9 records
Ideal customer profiles4 records
SURF SECURITY technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration4 records
AI capability8 records
Feature9 records
SURF SECURITY partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core and secondary.
- OktacoreSURF has a deep native integration with Okta for identity-first access control. Organizations can authenticate users through Okta into the SURF secure work environment, apply policies to existing Okta users and groups, implement transactional MFA, and integrate SSO directly from Okta into SURF. Group changes within Okta are automatically implemented within SURF.
- Microsoft Entra IDsecondarySURF integrates with Microsoft Entra ID (formerly Azure AD) as part of its identity integration stack, allowing organizations using Microsoft's identity platform to enforce Zero Trust access through the SURF browser.
- SplunksecondarySURF integrates with Splunk SIEM as part of its stack integration capabilities, allowing organizations to send SURF policy decisions and audit logs into their existing Splunk security information and event management infrastructure.
- MDM (Mobile Device Management) ProviderssecondarySURF can be pushed via existing MDM infrastructure, allowing organizations to deploy the Zero Trust browser or extension to managed devices through their existing MDM tooling. This integration enables IT teams to deploy SURF at scale without additional deployment infrastructure.
Scale indicators1 record
Recent moves6 records
Expansion highlights6 records
SURF SECURITY competitors and assessment
Company assessmentBroad incumbents
- Netskope: SSE/SASE incumbent offering CASB, SWG, and ZTNA. Competes for the same secure-access and SaaS-governance budget SURF targets; SURF's narrative is that Netskope cannot see into encrypted browser traffic without backhauling.
- Cloudflare: Cloud-delivered SASE/ZTNA/network-services incumbent with Cloudflare Access; increasingly overlapping with SURF's secure-remote-access narrative for distributed workforces and contractor access.
- Zscaler: Incumbent cloud-security platform spanning ZTNA, SWG, CASB, and DLP — the legacy stack SURF argues it can replace. Surface competition in remote-access and SaaS-security RFPs, but does not deliver browser-native on-device policy.
- Palo Alto Networks (Prisma SASE / Prisma Access Browser): Broader enterprise-security incumbent that acquired Talon to add an enterprise-browser offering to Prisma; competes with SURF across the full ZTNA/SASE/enterprise-browser stack with a much larger channel.
- Google Chrome Enterprise / Microsoft Edge for Business: Browser-vendor native enterprise offerings that increasingly bundle in-browser DLP, URL filtering, and AI controls; represent the largest long-term incumbency risk to independent enterprise browser vendors like SURF.
Direct peers
- Seraphic Security: Emerging enterprise-browser security vendor offering browser-based Zero Trust controls delivered via extension. Overlaps directly with SURF's extension product and competes for similar CISO buyers focused on BYOD and unmanaged-device security.
- Menlo Security: Browser-isolation and web-security vendor whose isolation-based approach (cloud-rendered browsing) competes with SURF's endpoint-native browser strategy for the same enterprise secure-access and web-protection budget.
- Authentic8 (Silo): Pioneer in cloud-based browser isolation for high-assurance use cases; serves government, financial services, and enterprises with similar scoped-access use cases to SURF, particularly for third-party contractors and BYOD.
- Talon Cyber Security (Palo Alto Networks): Enterprise browser vendor acquired by Palo Alto Networks for ~$625M in late 2023 and integrated into Prisma; competes head-to-head with SURF in enterprise-browser RFPs and brings PANW's massive sales channel into every deal SURF enters.
- Island: The leading dedicated enterprise-browser vendor and SURF's most direct competitor; offers a Chromium-based secure enterprise browser with similar ZTNA, DLP, and AI-governance capabilities to SURF. Closely comparable in product, target buyer (CISO/CIO), and GTM motion.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
SURF SECURITY social profiles
Digital presenceSURF SECURITY compliance and trust
Trust signalCompliance5 records
SURF SECURITY financial estimates
Financial estimateRevenue estimate
Valuation estimate
SURF SECURITY leadership team
Management profileNumber of profiles
Profiles4 records
SURF SECURITY funding detail
Funding detailFunding overview
Funding rounds1 record
Investors4 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
SURF SECURITY M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about SURF SECURITY
What does SURF SECURITY do?
SURF Security builds a Chromium-based Zero Trust Enterprise Browser delivered as both a full standalone browser and a lightweight extension for Chrome and Edge. The platform enforces security policy directly on the endpoint, providing on-device DLP, Shadow AI discovery and control, a sandboxed Agentic AI runtime, AI deepfake detection, scoped Zero Trust access, and compliance audit trails that replace VPN, VDI, CASB, SWG, and RBI infrastructure. The product is sold per user/identity on an annual subscription basis to enterprise security, IT, compliance, and contractor-access use cases.
Is SURF SECURITY a public or private company?
SURF SECURITY is a private company. It is classified as venture growth investor backed and is currently operating.
When was SURF SECURITY founded?
SURF SECURITY was founded in 2022. It employs 11 to 50 people.
Where is SURF SECURITY based?
SURF SECURITY is headquartered in New York, United States, in the North America region.
How does SURF SECURITY make money?
Two revenue lines are on record. Enterprise Browser Subscription is the primary driver. The others are zero Trust Extension Subscription.
Who are SURF SECURITY's main competitors?
Broad incumbents on record are Netskope, Cloudflare, Zscaler, Palo Alto Networks (Prisma SASE / Prisma Access Browser) and Google Chrome Enterprise / Microsoft Edge for Business. Direct peers are Seraphic Security, Menlo Security, Authentic8 (Silo), Talon Cyber Security (Palo Alto Networks) and Island.
Does SURF SECURITY have an API?
No public API is recorded for SURF SECURITY.
What industry is SURF SECURITY in?
SURF SECURITY's product category is Enterprise Browser Security. Its primary akta.pro industry code is HDADAEAK, Browser & Web Isolation Security, with a secondary code of BPAMAEAH, Access Management & Policy Enforcement (Zero Trust). Its NAICS code is 5132 and its SIC code is 7372.