Developer docs
API playgroundTry for free, no card

Search company profiles

Above Security

Full company profile

uuid005nayl

Namestring
Above Security
Legal namestring
Above Security Inc.
Websiteurl
above.security
Company typeenum
Private
Founded yearint
2025
Descriptiontext

Above Security is an Israeli cybersecurity company that builds an AI-native insider-threat management platform targeting large enterprises. Founded in 2025 in Tel Aviv by Unit 8200 veterans Aviv Nahum (CEO) and Amir Boldo (CPTO), the company emerged from stealth in March 2026 alongside a $50 million Series A led by Ballistic Ventures with Merlin Ventures and Norwest co-leading. The platform ingests signals across identity, endpoint, SaaS, cloud, AI, and HR systems via 27 named native connectors and an open API, then orchestrates a fleet of five specialized AI investigative agents — Shadow AI & IT, Data Exfiltration, Flight Risk, Inappropriate Use, and Communications — that continuously reason over each identity's living behavioral baseline to produce investigation-ready narratives and in-the-moment user coaching, positioning itself as a near-zero-false-positive alternative to legacy DLP, UEBA, SIEM, and CASB tools.

The product is packaged as three core modules (AI Investigative Agents, Behavioral Timeline, Real-time Guidance) and six named use cases (Pre-departure, Agentic AI, Custom GPT, Personal AI, Credential Leaks, Malicious Insider) and is delivered as a managed subscription to organizations with 1,000 or more employees on custom multi-year contracts. The company sells exclusively through a direct, demo-led enterprise sales motion (no public pricing or self-serve) and pairs the platform with the open Insider Threat Matrix framework, of which Above is the inaugural sponsor. The company is ISO/IEC 42001 certified, has been generating revenue for six months prior to launch, employs 11–50 people, and is led operationally from Tel Aviv with a US-facing presence anchored on its RSAC 2026 launch and named US enterprise customers including FICO.

Short descriptiontext

Above Security is an Israel-based, AI-native insider-threat management platform that uses specialized investigative agents to continuously reason over behavior across identity, endpoint, SaaS, AI, and HR systems, sold to large enterprises (1,000+ employees) on custom multi-year subscription contracts.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
11–50
akta.pro rankint
HeadquartersTel Aviv, Israel
HQ citystring
Tel Aviv
HQ countrystring
Israel
HQ regionstring
Middle East
Markets served

Serves global market

Offices1 record

Each record includes

City, Country, Type, Description, Source

Keyword5 values
insider threat management, AI security agents, behavioral risk analytics, data loss prevention, insider risk platform
Industry3 codes
1Secure Model Deployment & Runtime Protection (sandboxing, isolation)
CodeHDAAAKAHPrimaryYes
2Insider Threat Program Design & Risk Assessments
CodeBPAKADAMPrimaryNo
3AI/Analytics Video Surveillance (Detection, LPR, People Counting)
CodeHSAHACAFPrimaryNo
NAICS code2 codes
  • Computer Systems Design and Related Services54151
  • Computer Systems Design Services541512
SIC code2 codes
  • Services-Computer Programming Services7371
  • Services-Prepackaged Software7372
Product category
Insider Threat Management
Social media profiles3 records
GTM motion3 records

Each record includes

Type, Description, Source

Revenue model2 records
1Enterprise SaaS subscription
TypeSubscription Recurring
Description

Above Security is offered as an AI-native managed insider threat platform sold to enterprise customers (organizations with 1,000+ employees) on a subscription basis. The company emerged from stealth already generating revenue for six months, indicating recurring SaaS contracts with enterprise customers rather than one-time license sales. The "Schedule demo" / "Book a demo" model on every page is consistent with annual or multi-year enterprise agreements.

prnewswire.com
2Managed services (managed insider threat)
TypeManaged Services
Description

The platform is positioned as a "managed insider threat platform" where Above's AI agents continuously operate investigations on behalf of customer security, HR, and legal teams — implying ongoing managed-service value on top of the underlying subscription.

above.security
Marketing channels9 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels3 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Personnel, Technology or R&D, Infrastructure, Marketing or Sales, Operations
Pricing details1 tier
1Custom enterprise pricing via demo / sales conversation
ModelOtherBilling cadenceMulti-year contract
Notes

No public pricing published. Sales motion is demo-led; pricing is determined per enterprise deployment, consistent with subscription contracts sized to workforce and signal scope.

above.security
GTM typeB2B
B2B
Offering typeSoftware
Software
Brand1 record
1Insider Threat Matrix
Description

An open framework of insider threat techniques, separately branded and hosted at insiderthreatmatrix.org, which Above Security inaugurated as sponsor.

above.security
Core offering1 text field

Above Security builds an AI-native insider threat management platform that deploys a fleet of specialized AI investigative agents to continuously observe behavior across identity, endpoint, SaaS, cloud, AI, and HR systems, infer intent, intervene in real time with user coaching, and produce investigation-ready evidentiary timelines. The platform is sold to large enterprises (1,000+ employees) on a multi-year subscription basis, with pricing determined per deployment rather than published.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 5 values shown
  • Insider threat cases that previously required weeks of manual investigation now surface in hours, with full chain-of-custody documentation ready for HR and legal
+4 more records
Product overview1 text field

Above Security is delivered as a single unified AI-native insider-risk platform with three tightly coupled core modules — AI Investigative Agents, the Behavioral Timeline and Real-time Guidance — that work together to observe behavior across identity, endpoint, SaaS, cloud, AI and HR systems, infer intent, intervene in real time, and produce an evidentiary investigation report. On top of this core, Above packages six named solution / use-case offerings that map the platform onto the highest-stakes insider-risk patterns customers face today: Pre-departure, Agentic AI, Custom GPT, Personal AI, Credential Leaks, and Malicious Insider. Signal ingestion is delivered through the Above Integrations directory (Okta, Microsoft Entra, Ping, Google Workspace, CrowdStrike, SentinelOne, Microsoft Defender, AWS, Slack, Microsoft Teams, Gmail, Outlook, Google Calendar, Google Drive, Jira, Linear, ServiceNow, Claude, ChatGPT, Amazon Bedrock, Bedrock AgentCore, Azure AI Foundry, Workday, HiBob, Deel, Microsoft Purview and GitHub) together with an open API that ingests any custom signal, so every investigation arrives with full context rather than as another isolated alert.

Product and service11 records
1Above Platform
CategoryInsider Risk Management Platform
Description

AI-native managed insider-threat platform for organizations with 1,000+ employees; connects across identity, endpoint, SaaS, cloud, AI, and HR systems and orchestrates a fleet of specialized AI agents that observe behavior, build a real-time behavioral timeline, intervene when risk is forming, and produce evidentiary investigation reports.

2AI Investigative Agents
CategoryAI Agents / Investigation Engine
Description

Productized line of five specialized agents (Shadow AI & IT, Data Exfiltration, Flight Risk, Inappropriate Use, Communications) that run investigations end-to-end and cover ground traditional DLP, UEBA, SIEM, CASB, and EDR tools cannot reach.

3Behavioral Timeline
CategoryInvestigation Workspace
Description

Real-time assembly of every signal with surrounding context, stitching activity across systems and time into a single coherent behavioral timeline for each identity with assigned risk scores and evidentiary narratives.

4Real-time Guidance
CategoryUser Coaching / Intervention
Description

Coaching layer that nudges users before risk lands, intervening in the moment when someone attempts to push sensitive data to an unsanctioned AI tool and asking them to justify the action.

5Pre-departure Use Case
CategoryInsider Risk Use Case
Description

Targets the leaver playbook pattern by stitching job-search activity, document selection, AI-tool seeding, and after-hours export bursts into a multi-week staging arc surfaced before the resignation email lands.

6Agentic AI Use Case
CategoryInsider Risk Use Case
Description

Targets OAuth-scoped autonomous AI agents acting on corporate data, observing consent screens, scopes, and vendors and tying subsequent data reproduction on vendor servers back to the consent event.

7Custom GPT Use Case
CategoryInsider Risk Use Case
Description

Surfaces persistent personal ChatGPT / Claude / Gemini projects trained on company documents, names the employees who built them, and quantifies the proprietary corpus uploaded to support trade-secret investigations.

8Personal AI Use Case
CategoryInsider Risk Use Case
Description

Detects customer data crossing into personal ChatGPT, Claude, and Gemini accounts, verifies the receiving account by evidence, and names the customer whose data crossed the line to enable targeted controls.

9Credential Leaks Use Case
CategoryInsider Risk Use Case
Description

Catches credentials, recovery keys, JWTs, and OAuth grants leaving the boundary through channels legacy DLP does not watch, by observing high-risk text fields, code editors, and configuration screens at the moment they are typed, pasted, or committed.

10Malicious Insider Use Case
CategoryInsider Risk Use Case
Description

Targets insiders with legitimate access and a hidden agenda, stitching activity across systems and time to distinguish a high-performer with an agenda from a high-performer doing the job, and produces a timestamped, attributed event chain ready for legal, HR, and security.

11Above Integrations
CategoryIntegration Directory
Description

Catalog of native connectors across identity & access (Okta, Microsoft Entra, Ping, Google Workspace), endpoint & EDR (CrowdStrike, SentinelOne, Microsoft Defender), cloud (AWS), productivity & collaboration (Slack, Teams, Gmail, Outlook, Google Calendar, Google Drive, Jira, Linear, ServiceNow), AI & agents (Claude, ChatGPT, Amazon Bedrock, Bedrock AgentCore, Azure AI Foundry), HR & people (Workday, HiBob, Deel), and data & source (Microsoft Purview, GitHub), plus an open API for ingesting any custom signal.

Scale indicator8 records

Each record includes

Type, Value, Description, Source

Partnership16 partners
Strategic tierCoreTypeTechnology or Integration
Description

Named integration partner under Identity & Access. Surfaces sign-in anomalies, MFA fatigue, and risky session context from Okta for the Above Security investigation layer.

Strategic tierCoreTypeTechnology or Integration
Description

Named integration partner under Identity & Access. Pulls conditional-access events, token grants, and identity-risk signals.

Strategic tierCoreTypeTechnology or Integration
Description

Named integration partner under Identity & Access. Pulls Workspace sign-ins, OAuth grants, and session risk, tied to the person.

Strategic tierCoreTypeTechnology or Integration
Description

Named integration partner under Endpoint & EDR. Correlates CrowdStrike endpoint detections with intent. CrowdStrike also co-hosts the Cybersecurity Startup Accelerator (alongside AWS and NVIDIA) in which Above Security participated.

Strategic tierCoreTypeTechnology or Integration
Description

Named integration partner under Cloud & Infrastructure. Surfaces console and API actions that signal staging or exfiltration. AWS also co-hosts the 2026 Cybersecurity Startup Accelerator (with CrowdStrike and NVIDIA) in which Above Security was a finalist.

Strategic tierCoreTypeTechnology or Integration
Description

Named integration partner under Productivity & Collaboration. Captures channel posts, external shares, and file movement across Slack workspaces.

Strategic tierCoreTypeTechnology or Integration
Description

Named integration partner under Productivity & Collaboration. Captures chats, meetings, and shared files tied to the person and the moment.

Strategic tierCoreTypeTechnology or Integration
Description

Named integration partner under Productivity & Collaboration. Captures file shares, downloads, and external access in real time.

Strategic tierCoreTypeTechnology or Integration
Description

Named integration partner under AI & Agents. Captures prompts, uploads, and data shared with Anthropic's models.

Strategic tierCoreTypeTechnology or Integration
Description

Named integration partner under AI & Agents. Captures conversations and file uploads that move data into OpenAI.

Strategic tierCoreTypeTechnology or Integration
Description

Named integration partner under AI & Agents. Captures model calls and data passed to foundation models in the customer's AWS cloud.

12Bedrock AgentCore
Strategic tierCoreTypeTechnology or Integration
Description

Named integration partner under AI & Agents. Captures autonomous agent actions and the scope they're granted.

above.security
Strategic tierCoreTypeTechnology or Integration
Description

Named integration partner under HR & People. Captures resignation, role-change, and pre-departure signals that reweight risk.

Strategic tierCoreTypeTechnology or Integration
Description

Named integration partner under Data & Source. Captures repo clones, pushes, and access changes around departures.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Supports the 2026 Cybersecurity Startup Accelerator co-hosted by CrowdStrike and AWS that Above Security participated in. NVIDIA Inception provides AI frameworks and compute support to accelerator participants.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Above Security is the inaugural sponsor of the Insider Threat Matrix, an open framework of insider threat techniques hosted at insiderthreatmatrix.org. The framework is linked prominently from Above Security's homepage and serves as a category-defining community asset.

Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeDirect peer
Description

Proofpoint's ITM product (formerly ObserveIT) is a direct peer: enterprise insider-threat detection combining user-behavior analytics, content inspection and investigations across email, cloud and endpoints. Targets the same CISO buyer with a similar behavioral-investigation workflow.

TypeBroad incumbent
Description

Microsoft's Purview IRM is bundled into the M365 E5 enterprise license and offers insider risk scoring, policy-based investigation and DLP signal integration. A broad incumbent with massive distribution that Above must position against on AI quality and time-to-value rather than feature breadth.

TypeEmerging player
Description

Grip Security is a SaaS security posture management vendor focused on discovering and governing third-party SaaS and AI-tool OAuth access — directly overlapping Above's Shadow AI & IT and Custom GPT use cases for SaaS-heavy enterprises.

TypeBroad incumbent
Description

Exabeam is a SIEM-adjacent UEBA and AI-driven security analytics platform with behavioral baselining and investigation workflows. Broader portfolio than Above, but overlapping in user-behavior analytics for insider risk detection.

TypeBroad incumbent
Description

Mimecast acquired Code42 to add insider risk and data exfiltration detection to its email and collaboration security suite. Comparable enterprise-insider-risk positioning but bundled into a much broader security portfolio.

TypeDirect peer
Description

Cyberhaven provides AI-powered data lineage and insider risk detection that traces how sensitive data moves through endpoints, cloud and AI tools. Closely aligned with Above's AI-native, cross-system behavioral approach and competes for the same emerging 'agentic AI data risk' category.

TypeDirect peer
Description

Veriato (formerly SpectorSoft) is an insider threat and employee monitoring vendor focused on user activity capture, behavioral analytics and investigation — comparable in use case though typically more endpoint-centric than Above's cross-platform agent model.

TypeDirect peer
Description

Teramind delivers user-behavior analytics, insider threat detection and productivity monitoring with session replay and content capture. A direct peer in the insider-risk category with broader monitoring scope and a longer sales footprint.

TypeDirect peer
Description

DTEX is a pure-play insider risk and user-behavior analytics vendor for the enterprise, with comparable positioning around behavioral investigation, leaver risk and near-zero false positives. Direct overlap with Above's target buyer and use cases.

TypeEmerging player
Description

Nudge Security discovers and governs employee-adopted SaaS and AI accounts (including ChatGPT and Claude) at the identity layer — an adjacent emerging approach to Above's behavioral investigation of AI-tool misuse.

Market position
Weaknesses4 records

Each record includes

Headline, Details, Source

Competitive moat6 records

Each record includes

Type, Details

Key risks1 record

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers4 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment4 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile4 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
Yes

Docs URL, Description

Integration27 records

Each record includes

Title, Type, Description, Source

AI capability11 records

Each record includes

Type, Description, Source

AI maturity
App detail

Has app

Feature10 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles4 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
Compliance2 records

Each record includes

Name, Class, Description

Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds3 records

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors7 records

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Above Security

Insider Threat Managementabove.security

Above Security is an Israel-based, AI-native insider-threat management platform that uses specialized investigative agents to continuously reason over behavior across identity, endpoint, SaaS, AI, and HR systems, sold to large enterprises (1,000+ employees) on custom multi-year subscription contracts.

What Above Security does

Above Security is an Israeli cybersecurity company that builds an AI-native insider-threat management platform targeting large enterprises. Founded in 2025 in Tel Aviv by Unit 8200 veterans Aviv Nahum (CEO) and Amir Boldo (CPTO), the company emerged from stealth in March 2026 alongside a $50 million Series A led by Ballistic Ventures with Merlin Ventures and Norwest co-leading. The platform ingests signals across identity, endpoint, SaaS, cloud, AI, and HR systems via 27 named native connectors and an open API, then orchestrates a fleet of five specialized AI investigative agents — Shadow AI & IT, Data Exfiltration, Flight Risk, Inappropriate Use, and Communications — that continuously reason over each identity's living behavioral baseline to produce investigation-ready narratives and in-the-moment user coaching, positioning itself as a near-zero-false-positive alternative to legacy DLP, UEBA, SIEM, and CASB tools.

The product is packaged as three core modules (AI Investigative Agents, Behavioral Timeline, Real-time Guidance) and six named use cases (Pre-departure, Agentic AI, Custom GPT, Personal AI, Credential Leaks, Malicious Insider) and is delivered as a managed subscription to organizations with 1,000 or more employees on custom multi-year contracts. The company sells exclusively through a direct, demo-led enterprise sales motion (no public pricing or self-serve) and pairs the platform with the open Insider Threat Matrix framework, of which Above is the inaugural sponsor. The company is ISO/IEC 42001 certified, has been generating revenue for six months prior to launch, employs 11–50 people, and is led operationally from Tel Aviv with a US-facing presence anchored on its RSAC 2026 launch and named US enterprise customers including FICO.

Above Security firmographics

Firmographics
Name
Above Security
Legal name
Above Security Inc.
Website
https://above.security
Company type
Private
Founded year
2025
Operating status
Operating
Headcount range
11–50 employees
Short description
Above Security is an Israel-based, AI-native insider-threat management platform that uses specialized investigative agents to continuously reason over behavior across identity, endpoint, SaaS, AI, and HR systems, sold to large enterprises (1,000+ employees) on custom multi-year subscription contracts.
Ownership category
akta.pro rank

Above Security industry classification

Industry
Product category
Insider Threat Management
NAICS
Computer Systems Design and Related Services (54151), Computer Systems Design Services (541512)
SIC
Services-Computer Programming Services (7371), Services-Prepackaged Software (7372)
akta.pro primary industry
Secure Model Deployment & Runtime Protection (sandboxing, isolation) (HDAAAKAH)
akta.pro secondary industries
Insider Threat Program Design & Risk Assessments (BPAKADAM), AI/Analytics Video Surveillance (Detection, LPR, People Counting) (HSAHACAF)

Keywords

  • Insider threat management
  • AI security agents
  • Behavioral risk analytics
  • Data loss prevention
  • Insider risk platform

Where Above Security is headquartered

Location

Headquarters

HQ city
Tel Aviv
HQ country
Israel
HQ region
Middle East

Offices1 record

Markets served

Above Security business model

Business model
GTM type
B2B
Offering type
Software
Cost components
Personnel, Technology or R&D, Infrastructure, Marketing or Sales, Operations

Revenue model

  1. Enterprise SaaS subscription: Above Security is offered as an AI-native managed insider threat platform sold to enterprise customers (organizations with 1,000+ employees) on a subscription basis. The company emerged from stealth already generating revenue for six months, indicating recurring SaaS contracts with enterprise customers rather than one-time license sales. The "Schedule demo" / "Book a demo" model on every page is consistent with annual or multi-year enterprise agreements.
  2. Managed services (managed insider threat): The platform is positioned as a "managed insider threat platform" where Above's AI agents continuously operate investigations on behalf of customer security, HR, and legal teams — implying ongoing managed-service value on top of the underlying subscription.

Pricing tiers

ModelBillingPrice
OtherMulti-year contractCustom enterprise pricing via demo / sales conversation

Go-to-market motion3 records

Distribution channels3 records

Marketing channels9 records

Above Security product offering

Product offering

Core offering

Above Security builds an AI-native insider threat management platform that deploys a fleet of specialized AI investigative agents to continuously observe behavior across identity, endpoint, SaaS, cloud, AI, and HR systems, infer intent, intervene in real time with user coaching, and produce investigation-ready evidentiary timelines. The platform is sold to large enterprises (1,000+ employees) on a multi-year subscription basis, with pricing determined per deployment rather than published.

Product overview

Above Security is delivered as a single unified AI-native insider-risk platform with three tightly coupled core modules — AI Investigative Agents, the Behavioral Timeline and Real-time Guidance — that work together to observe behavior across identity, endpoint, SaaS, cloud, AI and HR systems, infer intent, intervene in real time, and produce an evidentiary investigation report. On top of this core, Above packages six named solution / use-case offerings that map the platform onto the highest-stakes insider-risk patterns customers face today: Pre-departure, Agentic AI, Custom GPT, Personal AI, Credential Leaks, and Malicious Insider. Signal ingestion is delivered through the Above Integrations directory (Okta, Microsoft Entra, Ping, Google Workspace, CrowdStrike, SentinelOne, Microsoft Defender, AWS, Slack, Microsoft Teams, Gmail, Outlook, Google Calendar, Google Drive, Jira, Linear, ServiceNow, Claude, ChatGPT, Amazon Bedrock, Bedrock AgentCore, Azure AI Foundry, Workday, HiBob, Deel, Microsoft Purview and GitHub) together with an open API that ingests any custom signal, so every investigation arrives with full context rather than as another isolated alert.

Differentiator

Problem solved

Functional benefit

Brands

  • Insider Threat Matrix: An open framework of insider threat techniques, separately branded and hosted at insiderthreatmatrix.org, which Above Security inaugurated as sponsor.

Products and services

  • Above Platform AI-native managed insider-threat platform for organizations with 1,000+ employees; connects across identity, endpoint, SaaS, cloud, AI, and HR systems and orchestrates a fleet of specialized AI agents that observe behavior, build a real-time behavioral timeline, intervene when risk is forming, and produce evidentiary investigation reports.
  • AI Investigative Agents Productized line of five specialized agents (Shadow AI & IT, Data Exfiltration, Flight Risk, Inappropriate Use, Communications) that run investigations end-to-end and cover ground traditional DLP, UEBA, SIEM, CASB, and EDR tools cannot reach.
  • Behavioral Timeline Real-time assembly of every signal with surrounding context, stitching activity across systems and time into a single coherent behavioral timeline for each identity with assigned risk scores and evidentiary narratives.
  • Real-time Guidance Coaching layer that nudges users before risk lands, intervening in the moment when someone attempts to push sensitive data to an unsanctioned AI tool and asking them to justify the action.
  • Pre-departure Use Case Targets the leaver playbook pattern by stitching job-search activity, document selection, AI-tool seeding, and after-hours export bursts into a multi-week staging arc surfaced before the resignation email lands.
  • Agentic AI Use Case Targets OAuth-scoped autonomous AI agents acting on corporate data, observing consent screens, scopes, and vendors and tying subsequent data reproduction on vendor servers back to the consent event.
  • Custom GPT Use Case Surfaces persistent personal ChatGPT / Claude / Gemini projects trained on company documents, names the employees who built them, and quantifies the proprietary corpus uploaded to support trade-secret investigations.
  • Personal AI Use Case Detects customer data crossing into personal ChatGPT, Claude, and Gemini accounts, verifies the receiving account by evidence, and names the customer whose data crossed the line to enable targeted controls.
  • Credential Leaks Use Case Catches credentials, recovery keys, JWTs, and OAuth grants leaving the boundary through channels legacy DLP does not watch, by observing high-risk text fields, code editors, and configuration screens at the moment they are typed, pasted, or committed.
  • Malicious Insider Use Case Targets insiders with legitimate access and a hidden agenda, stitching activity across systems and time to distinguish a high-performer with an agenda from a high-performer doing the job, and produces a timestamped, attributed event chain ready for legal, HR, and security.
  • Above Integrations Catalog of native connectors across identity & access (Okta, Microsoft Entra, Ping, Google Workspace), endpoint & EDR (CrowdStrike, SentinelOne, Microsoft Defender), cloud (AWS), productivity & collaboration (Slack, Teams, Gmail, Outlook, Google Calendar, Google Drive, Jira, Linear, ServiceNow), AI & agents (Claude, ChatGPT, Amazon Bedrock, Bedrock AgentCore, Azure AI Foundry), HR & people (Workday, HiBob, Deel), and data & source (Microsoft Purview, GitHub), plus an open API for ingesting any custom signal.

Quantifiable outcome

  • Insider threat cases that previously required weeks of manual investigation now surface in hours, with full chain-of-custody documentation ready for HR and legal
  • +4 more outcomes

Companies that use Above Security

Customer profile

Named customers4 records

Segments4 records

Ideal customer profiles4 records

Above Security technology and API

Technology

Technology focussed Yes

API detail

Has API
Yes
API docs
API detail

Core technology

AI maturity

App detail

Integration27 records

AI capability11 records

Feature10 records

Above Security partnerships and signals

Strategic signal

Partnerships

16 partnerships are on record, tiered core.

  • OktacoreTechnology or IntegrationNamed integration partner under Identity & Access. Surfaces sign-in anomalies, MFA fatigue, and risky session context from Okta for the Above Security investigation layer.
  • Microsoft EntracoreTechnology or IntegrationNamed integration partner under Identity & Access. Pulls conditional-access events, token grants, and identity-risk signals.
  • Google WorkspacecoreTechnology or IntegrationNamed integration partner under Identity & Access. Pulls Workspace sign-ins, OAuth grants, and session risk, tied to the person.
  • CrowdStrikecoreTechnology or IntegrationNamed integration partner under Endpoint & EDR. Correlates CrowdStrike endpoint detections with intent. CrowdStrike also co-hosts the Cybersecurity Startup Accelerator (alongside AWS and NVIDIA) in which Above Security participated.
  • Amazon Web Services (AWS)coreTechnology or IntegrationNamed integration partner under Cloud & Infrastructure. Surfaces console and API actions that signal staging or exfiltration. AWS also co-hosts the 2026 Cybersecurity Startup Accelerator (with CrowdStrike and NVIDIA) in which Above Security was a finalist.
  • SlackcoreTechnology or IntegrationNamed integration partner under Productivity & Collaboration. Captures channel posts, external shares, and file movement across Slack workspaces.
  • Microsoft TeamscoreTechnology or IntegrationNamed integration partner under Productivity & Collaboration. Captures chats, meetings, and shared files tied to the person and the moment.
  • Google DrivecoreTechnology or IntegrationNamed integration partner under Productivity & Collaboration. Captures file shares, downloads, and external access in real time.
  • Claude (Anthropic)coreTechnology or IntegrationNamed integration partner under AI & Agents. Captures prompts, uploads, and data shared with Anthropic's models.
  • ChatGPT (OpenAI)coreTechnology or IntegrationNamed integration partner under AI & Agents. Captures conversations and file uploads that move data into OpenAI.
  • Amazon BedrockcoreTechnology or IntegrationNamed integration partner under AI & Agents. Captures model calls and data passed to foundation models in the customer's AWS cloud.
  • Bedrock AgentCorecoreTechnology or IntegrationNamed integration partner under AI & Agents. Captures autonomous agent actions and the scope they're granted.
  • WorkdaycoreTechnology or IntegrationNamed integration partner under HR & People. Captures resignation, role-change, and pre-departure signals that reweight risk.
  • GitHubcoreTechnology or IntegrationNamed integration partner under Data & Source. Captures repo clones, pushes, and access changes around departures.
  • NVIDIA (via NVIDIA Inception)coreStrategic or Co-development PartnerSupports the 2026 Cybersecurity Startup Accelerator co-hosted by CrowdStrike and AWS that Above Security participated in. NVIDIA Inception provides AI frameworks and compute support to accelerator participants.
  • Insider Threat MatrixcoreStrategic or Co-development PartnerAbove Security is the inaugural sponsor of the Insider Threat Matrix, an open framework of insider threat techniques hosted at insiderthreatmatrix.org. The framework is linked prominently from Above Security's homepage and serves as a category-defining community asset.

Scale indicators8 records

Recent moves6 records

Expansion highlights6 records

Above Security competitors and assessment

Company assessment

Direct peers

  • Proofpoint Insider Threat Management: Proofpoint's ITM product (formerly ObserveIT) is a direct peer: enterprise insider-threat detection combining user-behavior analytics, content inspection and investigations across email, cloud and endpoints. Targets the same CISO buyer with a similar behavioral-investigation workflow.
  • Cyberhaven: Cyberhaven provides AI-powered data lineage and insider risk detection that traces how sensitive data moves through endpoints, cloud and AI tools. Closely aligned with Above's AI-native, cross-system behavioral approach and competes for the same emerging 'agentic AI data risk' category.
  • Veriato: Veriato (formerly SpectorSoft) is an insider threat and employee monitoring vendor focused on user activity capture, behavioral analytics and investigation — comparable in use case though typically more endpoint-centric than Above's cross-platform agent model.
  • Teramind: Teramind delivers user-behavior analytics, insider threat detection and productivity monitoring with session replay and content capture. A direct peer in the insider-risk category with broader monitoring scope and a longer sales footprint.
  • DTEX Systems: DTEX is a pure-play insider risk and user-behavior analytics vendor for the enterprise, with comparable positioning around behavioral investigation, leaver risk and near-zero false positives. Direct overlap with Above's target buyer and use cases.

Broad incumbents

  • Microsoft Purview Insider Risk Management: Microsoft's Purview IRM is bundled into the M365 E5 enterprise license and offers insider risk scoring, policy-based investigation and DLP signal integration. A broad incumbent with massive distribution that Above must position against on AI quality and time-to-value rather than feature breadth.
  • Exabeam: Exabeam is a SIEM-adjacent UEBA and AI-driven security analytics platform with behavioral baselining and investigation workflows. Broader portfolio than Above, but overlapping in user-behavior analytics for insider risk detection.
  • Mimecast (Code42): Mimecast acquired Code42 to add insider risk and data exfiltration detection to its email and collaboration security suite. Comparable enterprise-insider-risk positioning but bundled into a much broader security portfolio.

Emerging players

  • Grip Security: Grip Security is a SaaS security posture management vendor focused on discovering and governing third-party SaaS and AI-tool OAuth access — directly overlapping Above's Shadow AI & IT and Custom GPT use cases for SaaS-heavy enterprises.
  • Nudge Security: Nudge Security discovers and governs employee-adopted SaaS and AI accounts (including ChatGPT and Claude) at the identity layer — an adjacent emerging approach to Above's behavioral investigation of AI-tool misuse.

Market position

Weaknesses4 records

Competitive moat6 records

Key risks1 record

Key highlights7 records

Customer concentration

Above Security social profiles

Digital presence

Above Security compliance and trust

Trust signal

Compliance2 records

Above Security financial estimates

Financial estimate

Revenue estimate

Valuation estimate

Above Security leadership team

Management profile

Number of profiles

Profiles4 records

Above Security funding detail

Funding detail

Funding overview

Funding rounds3 records

Investors7 records

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

Above Security M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about Above Security

What does Above Security do?

Above Security builds an AI-native insider threat management platform that deploys a fleet of specialized AI investigative agents to continuously observe behavior across identity, endpoint, SaaS, cloud, AI, and HR systems, infer intent, intervene in real time with user coaching, and produce investigation-ready evidentiary timelines. The platform is sold to large enterprises (1,000+ employees) on a multi-year subscription basis, with pricing determined per deployment rather than published.

Is Above Security a public or private company?

Above Security is a private company. It is classified as venture growth investor backed and is currently operating.

When was Above Security founded?

Above Security was founded in 2025. It employs 11 to 50 people.

Where is Above Security based?

Above Security is headquartered in Tel Aviv, Israel, in the Middle East region.

How does Above Security make money?

Two revenue lines are on record. Enterprise SaaS subscription is the primary driver. The others are managed services (managed insider threat).

Who are Above Security's main competitors?

Direct peers on record are Proofpoint Insider Threat Management, Cyberhaven, Veriato, Teramind and DTEX Systems. Broad incumbents are Microsoft Purview Insider Risk Management, Exabeam and Mimecast (Code42). Emerging players are Grip Security and Nudge Security.

Does Above Security have an API?

Yes. Above Security's API ingests any signal a customer can send to it, allowing customers to feed custom telemetry into the platform so Above's AI investigators can incorporate it into continuous behavioral investigations. The integrations page states "Above ships new integrations every month, and our API ingests any signal you can send." Specific endpoints, auth method, rate limits, versioning, or sandbox availability are not specified in the source material.

What industry is Above Security in?

Above Security's product category is Insider Threat Management. Its primary akta.pro industry code is HDAAAKAH, Secure Model Deployment & Runtime Protection (sandboxing, isolation), with a secondary code of BPAKADAM, Insider Threat Program Design & Risk Assessments. Its NAICS code is 54151 and its SIC code is 7371.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
Solutions Review Technology News and Vendor ReviewsIdentity Management and Information Security News for the Week of August 28th: Fideo Intelligence, Above Security, Forcepoint, and MoreSolutions Review's editorial team compiled identity management and information security news for the week of August 28th, covering vendor product launches, hiring and portfolio updates. Highlights include Above Security's Synthetic Insider Threat Matrix, ExtraHop's 400 Gbps sensor, Fideo Intelligence's Fideo Lens, Forcepoint's new Chief Marketing Officer, and Globalgig's expanded MSSP stack.Third NewsAbove Security and Forscie Unveil the Innovative Synthetic Insider Threat MatrixAbove Security and Forscie announced on August 27, 2026 the launch of the Synthetic Insider Threat Matrix, a framework developed jointly by Above Theory and Forscie to address risks from AI-driven "synthetic" insiders. The matrix maps 166 knowledge objects covering unauthorized data access, autonomous exfiltration, privilege misuse and shadow AI, and is open access. It cites 28.6 million enterprise AI agents in 2025, projected past 2.2 billion by 2030.PR NewswireAbove Security and Forscie Launch the Synthetic Insider Threat MatrixAbove Security and Forscie launched the Synthetic Insider Threat Matrix, an extension of the Insider Threat Matrix for AI agents. The framework maps 166 knowledge objects covering detection and prevention techniques for synthetic-insider incidents. It is free and open, with Above's AI agents already mapping investigations to SITM categories.Pulse 2.0Above Security Receives Strategic Investment From CrowdStrike Falcon FundAbove Security has received a strategic investment from the CrowdStrike Falcon Fund and announced an integration with the CrowdStrike Falcon platform. The partnership allows Above's AI-native insider risk management agents to correlate telemetry from CrowdStrike’s Next-Gen SIEM into investigation-ready cases. This follows Above's recent $50 million financing round led by Ballistic Ventures, Merlin Ventures, and Norwest.FinSMEsAbove Security Receives Investment From CrowdStrike Falcon FundAbove Security, an Israeli AI-native insider threat platform, received an undisclosed investment from CrowdStrike Falcon Fund. The company will use the funds to expand operations and development. The platform provides managed insider risk protection powered by autonomous AI investigators.MSSP AlertCrowdStrike invests in Above Security, adds insider risk investigations to FalconCrowdStrike announced a strategic investment in Above Security through the CrowdStrike Falcon Fund at Black Hat USA 2026, integrating Above's managed insider risk platform with the Falcon platform. The integration will use endpoint, identity, and third-party telemetry from CrowdStrike Falcon Next-Gen SIEM to create investigation-ready insider risk cases, with Above sending completed investigations back into Falcon. The deal expands an existing partnership and follows Above's recent $50 million funding round, giving CrowdStrike an insider risk capability without requiring customers to build a separate investigation process.Third NewsAbove Security Takes Major Step Forward with CrowdStrike Investment for Enhanced Insider Risk ManagementAbove Security announced a strategic investment from the CrowdStrike Falcon Fund on August 4, 2026, at the Black Hat USA conference in San Francisco. The investment will integrate CrowdStrike's Falcon platform into Above Security's AI-driven insider threat detection operations, enabling CrowdStrike's clients to access enhanced insider risk investigations correlated with Falcon Next-Gen SIEM telemetry. The partnership builds on Above Security's prior selection to the CrowdStrike Cybersecurity Startup Accelerator and its $50 million funding round led by Ballistic Ventures, Merlin Ventures, and Norwest.YahooAbove Security Announces Strategic Investment from the CrowdStrike Falcon Fund, Furthering Its Mission to Democratize Elite Insider Risk ManagementAbove Security, an AI-native managed insider threat platform, announced a strategic investment from the CrowdStrike Falcon Fund and integration with the CrowdStrike Falcon platform at Black Hat USA. The partnership enables CrowdStrike customers to extend their Falcon deployment with Above's AI-driven insider risk investigations, correlating SIEM telemetry into investigation-ready cases. Above was previously selected from nearly 1,000 applicants for the CrowdStrike Cybersecurity Startup Accelerator and recently closed a $50 million funding round led by Ballistic Ventures, Merlin Ventures, and Norwest.PR NewswireAbove Security Announces Strategic Investment from the CrowdStrike Falcon Fund, Furthering Its Mission to Democratize Elite Insider Risk ManagementAbove Security, an AI-native managed insider threat platform, announced a strategic investment from the CrowdStrike Falcon Fund along with integration into the CrowdStrike Falcon platform, building on their existing partnership and mission to democratize elite insider risk management. The integration will allow CrowdStrike customers to extend their Falcon deployment with ready-made insider risk investigations powered by Above's AI agents and Falcon's Next-Gen SIEM telemetry. The investment follows Above's recent $50 million funding round and its participation in and runner-up finish at the CrowdStrike Cybersecurity Startup Accelerator.VC News DailyAbove Security Announces New InvestmentAbove Security, an AI-native managed insider threat platform, announced a strategic investment from the CrowdStrike Falcon Fund and integration with the CrowdStrike Falcon platform. The investment and integration agreement deepen an existing partnership between the two companies and advance Above Security's mission to democratize elite insider risk management. Above Security provides autonomous AI investigators that continuously monitor user behavior across SaaS, internal, and custom applications to surface insider risk before incidents occur.