Act Raises $60M to Remove the Cloud Paths AI Can Exploit
Act Security launched with $60 million to reduce cloud risk by removing unnecessary permissions and access routes.

AI can find cloud vulnerabilities faster than many teams can patch them. Act Security thinks the answer is to remove the unnecessary paths attackers could use in the first place.
What happened
Act emerged from stealth with $60 million in total funding: a $20 million seed round led by Team8 and Bessemer Venture Partners, followed by a $40 million Series A led by Notable Capital.
The founders previously built Medigate, a healthcare-cybersecurity company.
Why it matters
Cloud environments accumulate permissions, connections and services over time. Many are no longer needed, but they remain available to human users, workloads and increasingly AI agents.
Security teams commonly receive long lists of vulnerabilities and alerts, then struggle to decide what to fix first. Act’s action-centric approach focuses on the routes an attacker or compromised agent could actually use. It then attempts to remove unnecessary access and reduce the number of possible actions.
This matters because AI changes both sides of security. Attackers can automate discovery, while companies are giving their own agents broader access to get useful work done.
The bigger picture
The cloud-security market is shifting from finding more problems to shrinking the environment’s usable attack surface. The winning tools may be those that help teams make safe changes, not simply produce longer alert queues.
