Above Security
Above Security is an Israel-based, AI-native insider-threat management platform that uses specialized investigative agents to continuously reason over behavior across identity, endpoint, SaaS, AI, and HR systems, sold to large enterprises (1,000+ employees) on custom multi-year subscription contracts.
- Company typePrivate
- Founded2025
- HeadquartersTel Aviv, Israel
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Above Security does
Above Security is an Israeli cybersecurity company that builds an AI-native insider-threat management platform targeting large enterprises. Founded in 2025 in Tel Aviv by Unit 8200 veterans Aviv Nahum (CEO) and Amir Boldo (CPTO), the company emerged from stealth in March 2026 alongside a $50 million Series A led by Ballistic Ventures with Merlin Ventures and Norwest co-leading. The platform ingests signals across identity, endpoint, SaaS, cloud, AI, and HR systems via 27 named native connectors and an open API, then orchestrates a fleet of five specialized AI investigative agents — Shadow AI & IT, Data Exfiltration, Flight Risk, Inappropriate Use, and Communications — that continuously reason over each identity's living behavioral baseline to produce investigation-ready narratives and in-the-moment user coaching, positioning itself as a near-zero-false-positive alternative to legacy DLP, UEBA, SIEM, and CASB tools.
The product is packaged as three core modules (AI Investigative Agents, Behavioral Timeline, Real-time Guidance) and six named use cases (Pre-departure, Agentic AI, Custom GPT, Personal AI, Credential Leaks, Malicious Insider) and is delivered as a managed subscription to organizations with 1,000 or more employees on custom multi-year contracts. The company sells exclusively through a direct, demo-led enterprise sales motion (no public pricing or self-serve) and pairs the platform with the open Insider Threat Matrix framework, of which Above is the inaugural sponsor. The company is ISO/IEC 42001 certified, has been generating revenue for six months prior to launch, employs 11–50 people, and is led operationally from Tel Aviv with a US-facing presence anchored on its RSAC 2026 launch and named US enterprise customers including FICO.
Above Security firmographics
Firmographics- Name
- Above Security
- Legal name
- Above Security Inc.
- Website
- https://above.security
- Company type
- Private
- Founded year
- 2025
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Above Security is an Israel-based, AI-native insider-threat management platform that uses specialized investigative agents to continuously reason over behavior across identity, endpoint, SaaS, AI, and HR systems, sold to large enterprises (1,000+ employees) on custom multi-year subscription contracts.
- Ownership category
- akta.pro rank
Above Security industry classification
Industry- Product category
- Insider Threat Management
- NAICS
- Computer Systems Design and Related Services (54151), Computer Systems Design Services (541512)
- SIC
- Services-Computer Programming Services (7371), Services-Prepackaged Software (7372)
- akta.pro primary industry
- Secure Model Deployment & Runtime Protection (sandboxing, isolation) (HDAAAKAH)
- akta.pro secondary industries
- Insider Threat Program Design & Risk Assessments (BPAKADAM), AI/Analytics Video Surveillance (Detection, LPR, People Counting) (HSAHACAF)
Keywords
Where Above Security is headquartered
LocationHeadquarters
- HQ city
- Tel Aviv
- HQ country
- Israel
- HQ region
- Middle East
Offices1 record
Markets served
Above Security business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Infrastructure, Marketing or Sales, Operations
Revenue model
- Enterprise SaaS subscription: Above Security is offered as an AI-native managed insider threat platform sold to enterprise customers (organizations with 1,000+ employees) on a subscription basis. The company emerged from stealth already generating revenue for six months, indicating recurring SaaS contracts with enterprise customers rather than one-time license sales. The "Schedule demo" / "Book a demo" model on every page is consistent with annual or multi-year enterprise agreements.
- Managed services (managed insider threat): The platform is positioned as a "managed insider threat platform" where Above's AI agents continuously operate investigations on behalf of customer security, HR, and legal teams — implying ongoing managed-service value on top of the underlying subscription.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom enterprise pricing via demo / sales conversation |
Go-to-market motion3 records
Distribution channels3 records
Marketing channels9 records
Above Security product offering
Product offeringCore offering
Above Security builds an AI-native insider threat management platform that deploys a fleet of specialized AI investigative agents to continuously observe behavior across identity, endpoint, SaaS, cloud, AI, and HR systems, infer intent, intervene in real time with user coaching, and produce investigation-ready evidentiary timelines. The platform is sold to large enterprises (1,000+ employees) on a multi-year subscription basis, with pricing determined per deployment rather than published.
Product overview
Above Security is delivered as a single unified AI-native insider-risk platform with three tightly coupled core modules — AI Investigative Agents, the Behavioral Timeline and Real-time Guidance — that work together to observe behavior across identity, endpoint, SaaS, cloud, AI and HR systems, infer intent, intervene in real time, and produce an evidentiary investigation report. On top of this core, Above packages six named solution / use-case offerings that map the platform onto the highest-stakes insider-risk patterns customers face today: Pre-departure, Agentic AI, Custom GPT, Personal AI, Credential Leaks, and Malicious Insider. Signal ingestion is delivered through the Above Integrations directory (Okta, Microsoft Entra, Ping, Google Workspace, CrowdStrike, SentinelOne, Microsoft Defender, AWS, Slack, Microsoft Teams, Gmail, Outlook, Google Calendar, Google Drive, Jira, Linear, ServiceNow, Claude, ChatGPT, Amazon Bedrock, Bedrock AgentCore, Azure AI Foundry, Workday, HiBob, Deel, Microsoft Purview and GitHub) together with an open API that ingests any custom signal, so every investigation arrives with full context rather than as another isolated alert.
Differentiator
Problem solved
Functional benefit
Brands
- Insider Threat Matrix: An open framework of insider threat techniques, separately branded and hosted at insiderthreatmatrix.org, which Above Security inaugurated as sponsor.
Products and services
- Above Platform AI-native managed insider-threat platform for organizations with 1,000+ employees; connects across identity, endpoint, SaaS, cloud, AI, and HR systems and orchestrates a fleet of specialized AI agents that observe behavior, build a real-time behavioral timeline, intervene when risk is forming, and produce evidentiary investigation reports.
- AI Investigative Agents Productized line of five specialized agents (Shadow AI & IT, Data Exfiltration, Flight Risk, Inappropriate Use, Communications) that run investigations end-to-end and cover ground traditional DLP, UEBA, SIEM, CASB, and EDR tools cannot reach.
- Behavioral Timeline Real-time assembly of every signal with surrounding context, stitching activity across systems and time into a single coherent behavioral timeline for each identity with assigned risk scores and evidentiary narratives.
- Real-time Guidance Coaching layer that nudges users before risk lands, intervening in the moment when someone attempts to push sensitive data to an unsanctioned AI tool and asking them to justify the action.
- Pre-departure Use Case Targets the leaver playbook pattern by stitching job-search activity, document selection, AI-tool seeding, and after-hours export bursts into a multi-week staging arc surfaced before the resignation email lands.
- Agentic AI Use Case Targets OAuth-scoped autonomous AI agents acting on corporate data, observing consent screens, scopes, and vendors and tying subsequent data reproduction on vendor servers back to the consent event.
- Custom GPT Use Case Surfaces persistent personal ChatGPT / Claude / Gemini projects trained on company documents, names the employees who built them, and quantifies the proprietary corpus uploaded to support trade-secret investigations.
- Personal AI Use Case Detects customer data crossing into personal ChatGPT, Claude, and Gemini accounts, verifies the receiving account by evidence, and names the customer whose data crossed the line to enable targeted controls.
- Credential Leaks Use Case Catches credentials, recovery keys, JWTs, and OAuth grants leaving the boundary through channels legacy DLP does not watch, by observing high-risk text fields, code editors, and configuration screens at the moment they are typed, pasted, or committed.
- Malicious Insider Use Case Targets insiders with legitimate access and a hidden agenda, stitching activity across systems and time to distinguish a high-performer with an agenda from a high-performer doing the job, and produces a timestamped, attributed event chain ready for legal, HR, and security.
- Above Integrations Catalog of native connectors across identity & access (Okta, Microsoft Entra, Ping, Google Workspace), endpoint & EDR (CrowdStrike, SentinelOne, Microsoft Defender), cloud (AWS), productivity & collaboration (Slack, Teams, Gmail, Outlook, Google Calendar, Google Drive, Jira, Linear, ServiceNow), AI & agents (Claude, ChatGPT, Amazon Bedrock, Bedrock AgentCore, Azure AI Foundry), HR & people (Workday, HiBob, Deel), and data & source (Microsoft Purview, GitHub), plus an open API for ingesting any custom signal.
Quantifiable outcome
- Insider threat cases that previously required weeks of manual investigation now surface in hours, with full chain-of-custody documentation ready for HR and legal
- +4 more outcomes
Companies that use Above Security
Customer profileNamed customers4 records
Segments4 records
Ideal customer profiles4 records
Above Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration27 records
AI capability11 records
Feature10 records
Above Security partnerships and signals
Strategic signalPartnerships
16 partnerships are on record, tiered core.
- OktacoreNamed integration partner under Identity & Access. Surfaces sign-in anomalies, MFA fatigue, and risky session context from Okta for the Above Security investigation layer.
- Microsoft EntracoreNamed integration partner under Identity & Access. Pulls conditional-access events, token grants, and identity-risk signals.
- Google WorkspacecoreNamed integration partner under Identity & Access. Pulls Workspace sign-ins, OAuth grants, and session risk, tied to the person.
- CrowdStrikecoreNamed integration partner under Endpoint & EDR. Correlates CrowdStrike endpoint detections with intent. CrowdStrike also co-hosts the Cybersecurity Startup Accelerator (alongside AWS and NVIDIA) in which Above Security participated.
- Amazon Web Services (AWS)coreNamed integration partner under Cloud & Infrastructure. Surfaces console and API actions that signal staging or exfiltration. AWS also co-hosts the 2026 Cybersecurity Startup Accelerator (with CrowdStrike and NVIDIA) in which Above Security was a finalist.
- SlackcoreNamed integration partner under Productivity & Collaboration. Captures channel posts, external shares, and file movement across Slack workspaces.
- Microsoft TeamscoreNamed integration partner under Productivity & Collaboration. Captures chats, meetings, and shared files tied to the person and the moment.
- Google DrivecoreNamed integration partner under Productivity & Collaboration. Captures file shares, downloads, and external access in real time.
- Claude (Anthropic)coreNamed integration partner under AI & Agents. Captures prompts, uploads, and data shared with Anthropic's models.
- ChatGPT (OpenAI)coreNamed integration partner under AI & Agents. Captures conversations and file uploads that move data into OpenAI.
- Amazon BedrockcoreNamed integration partner under AI & Agents. Captures model calls and data passed to foundation models in the customer's AWS cloud.
- Bedrock AgentCorecoreNamed integration partner under AI & Agents. Captures autonomous agent actions and the scope they're granted.
- WorkdaycoreNamed integration partner under HR & People. Captures resignation, role-change, and pre-departure signals that reweight risk.
- GitHubcoreNamed integration partner under Data & Source. Captures repo clones, pushes, and access changes around departures.
- NVIDIA (via NVIDIA Inception)coreSupports the 2026 Cybersecurity Startup Accelerator co-hosted by CrowdStrike and AWS that Above Security participated in. NVIDIA Inception provides AI frameworks and compute support to accelerator participants.
- Insider Threat MatrixcoreAbove Security is the inaugural sponsor of the Insider Threat Matrix, an open framework of insider threat techniques hosted at insiderthreatmatrix.org. The framework is linked prominently from Above Security's homepage and serves as a category-defining community asset.
Scale indicators8 records
Recent moves6 records
Expansion highlights6 records
Above Security competitors and assessment
Company assessmentDirect peers
- Proofpoint Insider Threat Management: Proofpoint's ITM product (formerly ObserveIT) is a direct peer: enterprise insider-threat detection combining user-behavior analytics, content inspection and investigations across email, cloud and endpoints. Targets the same CISO buyer with a similar behavioral-investigation workflow.
- Cyberhaven: Cyberhaven provides AI-powered data lineage and insider risk detection that traces how sensitive data moves through endpoints, cloud and AI tools. Closely aligned with Above's AI-native, cross-system behavioral approach and competes for the same emerging 'agentic AI data risk' category.
- Veriato: Veriato (formerly SpectorSoft) is an insider threat and employee monitoring vendor focused on user activity capture, behavioral analytics and investigation — comparable in use case though typically more endpoint-centric than Above's cross-platform agent model.
- Teramind: Teramind delivers user-behavior analytics, insider threat detection and productivity monitoring with session replay and content capture. A direct peer in the insider-risk category with broader monitoring scope and a longer sales footprint.
- DTEX Systems: DTEX is a pure-play insider risk and user-behavior analytics vendor for the enterprise, with comparable positioning around behavioral investigation, leaver risk and near-zero false positives. Direct overlap with Above's target buyer and use cases.
Broad incumbents
- Microsoft Purview Insider Risk Management: Microsoft's Purview IRM is bundled into the M365 E5 enterprise license and offers insider risk scoring, policy-based investigation and DLP signal integration. A broad incumbent with massive distribution that Above must position against on AI quality and time-to-value rather than feature breadth.
- Exabeam: Exabeam is a SIEM-adjacent UEBA and AI-driven security analytics platform with behavioral baselining and investigation workflows. Broader portfolio than Above, but overlapping in user-behavior analytics for insider risk detection.
- Mimecast (Code42): Mimecast acquired Code42 to add insider risk and data exfiltration detection to its email and collaboration security suite. Comparable enterprise-insider-risk positioning but bundled into a much broader security portfolio.
Emerging players
- Grip Security: Grip Security is a SaaS security posture management vendor focused on discovering and governing third-party SaaS and AI-tool OAuth access — directly overlapping Above's Shadow AI & IT and Custom GPT use cases for SaaS-heavy enterprises.
- Nudge Security: Nudge Security discovers and governs employee-adopted SaaS and AI accounts (including ChatGPT and Claude) at the identity layer — an adjacent emerging approach to Above's behavioral investigation of AI-tool misuse.
Market position
Weaknesses4 records
Competitive moat6 records
Key risks1 record
Key highlights7 records
Customer concentration
Above Security social profiles
Digital presenceAbove Security compliance and trust
Trust signalCompliance2 records
Above Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Above Security leadership team
Management profileNumber of profiles
Profiles4 records
Above Security funding detail
Funding detailFunding overview
Funding rounds3 records
Investors7 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Above Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Above Security
What does Above Security do?
Above Security builds an AI-native insider threat management platform that deploys a fleet of specialized AI investigative agents to continuously observe behavior across identity, endpoint, SaaS, cloud, AI, and HR systems, infer intent, intervene in real time with user coaching, and produce investigation-ready evidentiary timelines. The platform is sold to large enterprises (1,000+ employees) on a multi-year subscription basis, with pricing determined per deployment rather than published.
Is Above Security a public or private company?
Above Security is a private company. It is classified as venture growth investor backed and is currently operating.
When was Above Security founded?
Above Security was founded in 2025. It employs 11 to 50 people.
Where is Above Security based?
Above Security is headquartered in Tel Aviv, Israel, in the Middle East region.
How does Above Security make money?
Two revenue lines are on record. Enterprise SaaS subscription is the primary driver. The others are managed services (managed insider threat).
Who are Above Security's main competitors?
Direct peers on record are Proofpoint Insider Threat Management, Cyberhaven, Veriato, Teramind and DTEX Systems. Broad incumbents are Microsoft Purview Insider Risk Management, Exabeam and Mimecast (Code42). Emerging players are Grip Security and Nudge Security.
Does Above Security have an API?
Yes. Above Security's API ingests any signal a customer can send to it, allowing customers to feed custom telemetry into the platform so Above's AI investigators can incorporate it into continuous behavioral investigations. The integrations page states "Above ships new integrations every month, and our API ingests any signal you can send." Specific endpoints, auth method, rate limits, versioning, or sandbox availability are not specified in the source material.
What industry is Above Security in?
Above Security's product category is Insider Threat Management. Its primary akta.pro industry code is HDAAAKAH, Secure Model Deployment & Runtime Protection (sandboxing, isolation), with a secondary code of BPAKADAM, Insider Threat Program Design & Risk Assessments. Its NAICS code is 54151 and its SIC code is 7371.