While it seemed that generative AI was a sweeping wave of change for businesses, the reality is that even 2.5 years after ChatGPT's debut, we're only at the beginning of this transformation. A striking 96% of IT and data executives intend to expand their use of AI agents this year, as highlighted by a recent survey from Cloudera.
Yet, this surge brings a myriad of challenges for organizations, chief among them: How can they safeguard the security of their software, data, and digital systems, especially as more agents capable of autonomous actions with minimal human intervention come online?
Cyata, a cybersecurity startup based in Tel Aviv, was established to directly address this challenge and is now stepping out of stealth mode to demonstrate its solutions to enterprises.
The company has secured $8.5 million in seed funding, led by TLV Partners, and supported by prominent angel investors and former Cellebrite CEOs Ron Serber and Yossi Carmil. Additionally, former Cellebrite VP of business development Shahar Tal is Cyata’s CEO. You may remember Cellebrite as the well-known security firm that developed techniques to bypass the security of, or "crack," Apple’s highly secure and encrypted iPhone for law enforcement, which attests to the founders' credibility.
“This represents a paradigm shift,” Tal mentioned in an interview with VentureBeat. “Similar to the transition to the cloud, we’re witnessing software evolve before our eyes. Enterprises require new safeguards to manage the speed and autonomy of these systems.”
AI Scaling Hits Its Limits
Power caps, rising token costs, and inference delays are reshaping enterprise AI. Join our exclusive salon to discover how top teams are:
- Turning energy into a strategic advantage
- Architecting efficient inference for real throughput gains
- Unlocking competitive ROI with sustainable AI systems
Secure your spot to stay ahead: https://bit.ly/4mwGngO
A new control dashboard for agentic identities
Cyata’s platform introduces a dedicated solution designed to manage what it calls “agentic identities” — AI systems that carry out tasks independently.
“These agents don’t function like traditional identities — they appear in milliseconds, branch into sub-agents, execute privileged commands, and disappear before identify access management (IAM) or privileged access management (PAM) systems can respond,” Tal explained. “They are faster, possess more privileges, and are more error-prone. The traditional IAM tools are inadequate for this architecture.”
The solution encompasses three integrated features:
- Automated detection of AI agents throughout all enterprise environments
- Real-time forensic observability
- Detailed access control
“We provide the control plane for authentic identities of autonomous digital workers,” Tal explained. “The moment an agent is authenticated, we recognize it, track its activities, and enforce the least privilege in real time.”
Cyata performs automatic scans of cloud and SaaS environments to identify all AI agents in use and associates each with a human owner.
It then observes agent behavior for risky access patterns or anomalies and maintains a comprehensive audit trail of actions, including intent.
“We fingerprint agents by identifying behaviors that diverge from human activity — such as high-speed actions, technical headers, or unusual access patterns,” Tal added.
Real-time justification and AI-to-AI verification
One of Cyata’s most innovative features is its ability to question agents in natural language. When an agent tries to perform a task, Cyata can ask for an explanation and then assess the justification using both rules-based logic and AI.
“A great aspect of AI agents is their ability to communicate in English,” said Tal. “We can inquire why they are using a tool, and they’ll provide contextual justifications that we can evaluate for validity.”
The platform utilizes AI models to evaluate these justifications in real time, adding an extra layer of interpretability and risk assessment.
“It’s AI evaluating AI — assessing context and intent as part of our risk evaluation,” Tal explained.
But what about malicious agents created by hackers or cyber criminals? Cyata is prepared for those as well.
“We aim to ensure that the agent originates from a legitimate source,” said Tal. “For instance, if it originates from the Copilot environment, that’s a positive signal. Or if it has been performing correctly for a while. Conversely, if it’s a new identity we’ve never encountered, that poses more risk. Therefore, we must evaluate the entire risk for each tool call request.”
From discovery to deployment in 48 hrs.
Cyata emphasizes a swift deployment model, delivering immediate value to enterprise security and identity teams.
Integration with widely-used platforms like Microsoft Copilot, Salesforce AgentForce, and other popular identity providers is already supported.
“Our system is designed for rapid integration,” said Tal. “Within 48 hours, we can scan cloud environments, copilots, and other tools to reveal agentic identities and their associated risks.”
Once identified, Cyata links each AI agent to a human stakeholder for accountability, bridging the gap between traditional identity systems and the emerging AI workforce.
Beyond the developers
The increasing use of AI agents extends beyond technical teams. Although developers were initially the primary users, Cyata quickly recognized broader adoption.
“Initially, we assumed developers would be our main audience. However, we’ve observed non-developers deploying agents swiftly — in sales, finance, support — making centralized governance essential,” Tal noted.
Organizations often uncover unexpected usage patterns once Cyata is implemented.
In several instances, tools like Cursor or Copilot were discovered to be operating with elevated permissions, impersonating users, or accessing sensitive data without oversight.
“We’ve encountered scenarios where companies believe they haven’t deployed AI, yet suddenly there’s Cursor or Copilot operating in full impersonation mode, acting on someone’s behalf,” said Tal. “It’s already happening.”
Future-proofing AI agent identity and compliance for enterprises
Cyata’s platform offers multiple modes — from passive monitoring to active enforcement — enabling security teams to adopt it without disrupting workflows.
The system can flag risky activities, suggest mitigations, or enforce human approvals for high-privilege actions. Pricing is based on a SaaS model, determined by the number of managed agentic identities.
The company views its role as not only addressing current gaps but also preparing enterprises for a broader transformation in how work is conducted.
With a team of cybersecurity veterans from Unit 8200, Check Point, and Cellebrite, Cyata is poised to lead in this emerging category. The company will present new research at the upcoming Black Hat conference and is developing a partnership program to enhance integrations with identity vendors and enterprise platforms.
As AI agents become more widespread, Cyata is wagering that enterprises will require advanced tools to comprehend who — or what — is acting on their behalf.
