>samit_hota
Back to security news
SN-2026-211InformationalOpen

Hush Security Secures $30 Million Series A for AI Agent Governance

Samit Hota·
CVE ID
N/A
Affected Products / Orgs
Enterprise AI Architectures, Model Context Protocol (MCP) Implementations
#news#data-breach#hush

Tel Aviv-based cybersecurity startup Hush Security announced a $30 million Series A funding round, bringing its total funding to $41 million. The round was backed by Akamai Technologies alongside existing investors Battery Ventures and YL Ventures. Founded in 2024, the company emerged from stealth in September 2025 with a specialized Hush Security AI agent governance and machine access platform designed to bring strict identity verification, privilege scoping, and runtime monitoring to enterprise AI agents.

Hush Security plans to use the new capital to scale its engineering and sales operations, broaden integrations across Identity and Access Management (IAM) platforms and agentic ecosystems, and expand enterprise corporate partnerships.

The Blind Spot in Enterprise Non-Human Identity

Enterprise security programs have historically focused on two primary identity classes: human users authenticated through SSO and MFA, and static service accounts or workload identities authenticated via API keys, tokens, or digital certificates.

The rapid proliferation of autonomous AI agents breaks both paradigms. Modern agentic workflows rely on dynamic reasoning loops where software independently decides which tasks to run, which APIs to invoke, and which downstream databases to query. Traditionally, security teams have granted these agents broad service account credentials or static API keys. When an agent possesses long-lived credentials, any compromise—whether through indirect prompt injection, tool poisoning, or unsafe model context handling—exposes the enterprise to significant risk. An attacker manipulating an agent can execute unvetted operations across sensitive back-end microservices, cloud infrastructure, or corporate data stores with the full authority of that agent’s underlying API keys.

Furthermore, the adoption of standardized integration frameworks like the Model Context Protocol (MCP) allows agents to dynamically discovery and connect to external tools, databases, and third-party APIs. Without central visibility and fine-grained runtime authorization, security teams lack visibility into which agents exist, what tools they access, and what privileges they exercise at any given moment.

Machine Access and JIT Governance Architecture

Hush Security’s machine access platform targets this architectural gap by replacing persistent static credentials with centralized control and dynamic runtime enforcement. Key capabilities of the platform include:

  • Centralized Agent Registry: Enrolls all enterprise AI agents into a single inventory, allowing security teams to discover unauthorized shadow agents running across internal environments and map their connections to MCPs, third-party tools, and internal infrastructure.
  • Just-in-Time (JIT) Dynamic Scoping: Eliminates permanent hardcoded API keys and service tokens. The platform injects scoped, ephemeral permissions at runtime, restricting an agent’s access explicitly to the specific action approved for its immediate task execution.
  • Runtime Policy Enforcement: Provides a centralized control panel to map permissions, enforce granular policies per action, and immediately sever compromised or malfunctioning agents via a global kill switch.
  • Comprehensive Audit Trail: Logs every interaction, tool call, and resource request initiated by an agent, delivering detailed audit trails necessary for incident response, forensic investigations, and regulatory compliance.

As organizations scale their deployment of autonomous agents to process core business logic, managing non-human identity (NHI) policies at the agent layer is becoming a foundational component of enterprise zero-trust architectures.

What Security Teams Should Do

Organizations deploying autonomous AI agents or Model Context Protocol server integrations should take immediate steps to audit their machine identity posture:

  1. Inventory Non-Human Credentials: Conduct an audit of all static API keys, service principals, and long-lived tokens assigned to internal LLMs, orchestration pipelines, and agent frameworks.
  2. Implement Ephemeral Authorization: Transition away from static high-privilege credentials in favor of dynamic secret injection or short-lived tokens scoped to specific tool calls.
  3. Enforce Boundary Control on MCP Servers: Treat Model Context Protocol tool endpoints as untrusted trust boundaries. Apply strict input validation, action confirmation prompts for high-impact operations, and centralized access logging across all agent-to-tool communications.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call