Skip to content
TECH CEO Daily
StartupsFunding

Rig Security launches with $12 million to catch AI agents acting under employees' logins

The Tel Aviv startup says AI agents borrow the identities of the people who launch them, so their actions look like the employee's own in the audit log.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Rig Security emerged from stealth on September 29 with a $12 million seed round led by Ten Eleven Ventures and Brightmind.
  • 2Rig says AI agents borrow the identity of whoever launched them, so their actions are logged as that person's.
  • 3Its platform aims to block a risky agent action without locking out the employee whose account it uses.

The news

Rig Security, a Tel Aviv startup, came out of stealth on September 29 with $12 million in seed funding led by Ten Eleven Ventures and Brightmind Partners for software that spots AI agents running under employees' accounts and stops risky actions without locking employees out.

The problem Rig describes is simple. Coding assistants, autonomous agents and automation tools usually do not log in as themselves, the company said; they borrow the identity of the person or service account that launched them. As SiliconANGLE put it, whatever an agent does is then logged against that developer or service account, so an agent that wiped a production database would look, in the audit log, like the engineer's own work.

"What they cannot see is whether a person did it or an agent did," chief executive Guy Kozliner said of security teams. SecurityWeek noted that the usual fix for a misbehaving account, disabling it, blocks the legitimate employee along with the agent. Rig says its platform can block a rogue or misused agent's risky action before it reaches the cloud, without disrupting the person whose identity the agent borrowed.

The product has three main parts, according to the company and press reports. RICE, the Rig Identity Correlation Engine, matches identities across systems with what Rig says is 96% accuracy. An identity dependencies graph keeps a live map of how accounts connect, and a lightweight endpoint sensor, which SecurityWeek identified as Bifrost, separates agent sessions from user sessions and enforces policy. Rig combines identity security posture management, which finds risky permissions, with identity threat detection and response.

The CrowdStrike Falcon Fund also invested, along with angel investors including Ami Luttwak, co-founder and chief technology officer of Wiz. Kozliner previously worked on Wiz's CTO team. Chief technology officer Nokky Goren was the first engineer at Axis Security, which HPE bought in 2023, according to SiliconANGLE, and head of product Michal Haikov is a veteran of Israel's Unit 8200 and of Flow Security, now part of CrowdStrike. Israeli outlet Calcalist reported the company was founded in early 2025, has 20 employees and closed the round in late 2025.

Rig says it is in production at Fortune 200 organizations in financial services, insurance, healthcare and technology, and is sold through the AWS Marketplace and CrowdStrike Marketplace. One named customer, mortgage lender New American Funding, said through its assistant vice president of digital identity, Bill Harper, that Rig shows which agents are running and whose access they are using.

The numbers

Seed round
$12 million
Identity-matching accuracy (company claim)
96%
Employees (Calcalist)
20
Breaches involving compromised identities (Google Cloud report, cited by Rig)
Roughly 3 in 4

Why CEOs should care

For CISOs, the first task is an inventory. Ask which AI agents and coding assistants run under which employee and service accounts, and whether your identity provider or endpoint tools can tell an agent's session from a person's. Then check your kill switch: can you stop one agent without disabling the employee's account and halting their work? Rig cites Google Cloud's Cloud Threat Horizons Report for the first half of 2026 as finding that roughly three in four breaches involve compromised identities, a reminder of how much rides on the accounts agents borrow.

For general counsel, HR leaders and boards, the issue is accountability. If audit logs record an agent's actions as the employee's, internal investigations, compliance records and even disciplinary decisions could rest on the wrong facts. Update incident response playbooks so that when an account does something harmful, teams check for agent activity before drawing conclusions, and set rules for which agents may act with an employee's credentials and with how much access.

For buyers, Rig is a 20-person, seed-stage company, so weigh vendor risk alongside the feature list. Its listing on AWS and CrowdStrike marketplaces can simplify purchasing, and CrowdStrike's venture arm is an investor. Ask for evidence behind the 96% accuracy claim and how it performs on your own mix of identity systems.

The bigger picture

Identity security already covers people and "non-human" identities such as service accounts and API keys. Agents blur that line because they are software acting with a human's credentials. Rig's backers, including CrowdStrike's fund and Wiz's co-founder, are betting that telling the two apart becomes its own security category as companies let agents write code and change systems on employees' behalf.

What’s next

SecurityWeek reported that Rig will spend the money on research and engineering, expanding its U.S. sales and building partner channels, and Calcalist said it plans to grow in Israel and the U.S. Watch whether large identity and endpoint vendors add agent-session detection of their own, which would test how long a stand-alone product can stay ahead.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Rig SecurityCrowdStrikeTen Eleven VenturesAI agents

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.