# NewCore's $66M Bet: A Security-First Identity Platform for Humans, Machines, and AI Agents


NewCore, a newly emerged identity and access management startup, has secured $66 million in Series A funding as it exits stealth mode, announcing an ambitious mission to build a unified security framework that protects not only human users but also machine identities and artificial intelligence agents operating within enterprise environments.


The funding round underscores growing investor confidence in a critical gap in the cybersecurity market: traditional identity infrastructure was designed for humans managing machines. Today's enterprises face a fundamentally different challenge—orchestrating trust and access control across an expanding ecosystem of humans, automated systems, microservices, cloud workloads, and increasingly, AI agents that operate with increasing autonomy and decision-making authority.


## The Market Opportunity


The identity and access management (IAM) market has long focused on authenticating and authorizing human users. However, the operational reality of modern enterprises has shifted dramatically:


  • Machine identity explosion: Cloud-native architectures, Kubernetes deployments, and microservices have spawned thousands of non-human identities that lack proper management frameworks
  • AI agent proliferation: Organizations are deploying autonomous AI agents for everything from customer support to financial analysis, raising questions about how to enforce access boundaries and audit their actions
  • Supply chain complexity: Third-party integrations, API partnerships, and cloud dependencies require granular access policies that adapt in real-time

  • NewCore enters a market that includes established players like Okta, Microsoft Entra ID, and Auth0, alongside specialized vendors focused on machine identity (like HashiCorp Vault) and emerging platforms addressing AI governance. The startup's approach appears to unify these concerns under a single architectural vision.


    ## Security-First Architecture


    While specific technical details remain limited in the initial announcement, NewCore's positioning suggests a fundamental departure from legacy IAM assumptions. A security-first approach in identity platforms typically means:


    Zero-trust principles: Rather than trusting access once verified, the system continuously evaluates context—device posture, location, behavioral anomalies, and real-time risk factors—before granting or maintaining access.


    Multi-stakeholder verification: For AI agents, this could mean requiring not just authentication but attestation that the model hasn't been tampered with, that its outputs are being monitored, and that it operates within defined behavioral boundaries.


    Unified audit trails: Tracking who did what, when machines acted on whose behalf, and what decisions AI agents made requires a forensic layer that modern IAM platforms often treat as an afterthought.


    Cross-identity federation: Humans, machines, and AI agents often operate in collaboration—a developer's code deployment might trigger a machine identity to request resources, which then passes data to an AI model for processing. NewCore's architecture likely treats these orchestrated workflows as first-class authentication and authorization events.


    ## The Funding Landscape


    The $66 million Series A represents substantial institutional confidence. In an era of tightened venture capital spending on cybersecurity, particularly for infrastructure plays, this signals investor belief that identity will be a central battleground as organizations digitally transform.


    NewCore's funding follows similar large rounds in adjacent categories:

  • Snyk (software composition analysis) raised $530M across all rounds
  • HashiCorp (infrastructure automation and secrets management) has raised $300M+
  • Teleport (privileged access management) closed a $150M Series C in 2022

  • The identity platform category remains attractive because it touches every application, every cloud workload, and every user—making it a foundational layer that enterprises cannot avoid.


    ## Implications for Enterprise Security


    Access Control Complexity: Organizations moving to adopt NewCore or similar platforms face a significant operational shift. Defining access policies for AI agents requires first defining what those agents are permitted to do, which mandates detailed threat modeling and policy frameworks that many enterprises currently lack.


    Organizational Alignment: Security teams and AI teams have historically operated in silos. NewCore's unified approach may force organizational structure changes to establish shared identity governance committees that span both functions.


    Migration and Integration: Enterprises with existing identity infrastructure built on legacy systems (Okta, Active Directory) must evaluate whether to rip-and-replace or adopt NewCore as an overlay. Partial deployments could introduce new compliance and audit gaps.


    Compliance and Attestation: Regulators increasingly scrutinize AI deployments. An identity platform that can definitively audit which AI agent took which action, authorized by which human, and based on what input data becomes a regulatory necessity rather than a nice-to-have.


    ## Competitive Positioning


    NewCore enters a fragmented market rather than a concentrated one. No single vendor has definitively solved the "humans + machines + AI agents" identity problem at scale. This fragmentation works in NewCore's favor—incumbent IAM vendors have legacy code and customer bases tied to human-centric models, while specialized machine identity vendors haven't tackled human access or AI governance.


    However, large incumbents like Microsoft and Google could quickly extend their cloud identity platforms to address machine and AI identity concerns, leveraging their installed bases and integration advantages.


    ## HackWire Analysis


    Why This Matters Now: Identity infrastructure has become the central control point for enterprise security, precisely because it's the only system that observes *all* access requests—human, machine, and increasingly, AI-initiated. As organizations deploy AI agents with genuine decision-making authority (approving expenses, accessing customer data, initiating transactions), the ability to enforce trust boundaries and audit outcomes shifts from "compliance requirement" to "existential operational necessity."


    A platform purpose-built around this reality arrives at exactly the moment enterprises are beginning to ask "who authorized this AI to do that?" For the first time, the answer isn't always a human.


    The deeper trend NewCore exploits is the convergence of three identity problems that vendors had previously solved separately. Legacy IAM solved human access. Secrets management (Vault, AWS Secrets Manager) solved machine identity. And AI governance is currently unsolved. NewCore's $66M bet is that these will merge into a single architectural problem—one system must answer "is this entity trustworthy right now?"—and enterprises will pay premium margins for a platform that handles all three elegantly rather than stitching together incompatible point solutions.


    Watch for how quickly NewCore addresses AI explainability. An identity platform isn't just for gating access; it's also for reconstructing why an action was taken. That forensic capability—showing exactly what context and rules caused an AI agent to be granted a sensitive permission—could become the most valuable feature as regulatory pressure mounts.


    — HackWire Editorial


    ## Recommendations for Organizations


    1. Audit current identity infrastructure: Evaluate whether your existing IAM platform has any concept of machine identity or AI governance, or whether you're patching these with separate tools

    2. Define AI agent access policies: Before deploying autonomous agents in production, establish what data and systems they should access, and design identity policies that enforce these boundaries

    3. Centralize audit logging: Ensure that identity decisions for humans, machines, and AI agents flow to a single monitoring system where security teams can correlate and investigate


    ---


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)