# Oak Emerges From Stealth With $60M to Consolidate Fragmented Identity Security
New AI-powered Identity Operating System aims to unify governance across human, machine, and AI identities in enterprise environments
Israeli cybersecurity startup Oak has officially launched from stealth mode with $60 million in seed funding, backed by prominent venture firms including Accel, Greylock Partners, and CRV. The investment signals growing market confidence in a new category of identity-centric security platforms designed to consolidate fragmented tooling across enterprise identity governance.
Founded in late 2025, Oak has built an AI-powered Identity Operating System that unifies identity governance across all users, services, and emerging AI agents within an organization's infrastructure. The platform is already generally available and targets a pain point that resonates across enterprise security teams: the sprawl of disconnected identity and access management tools that provide incomplete visibility and control.
## The Problem: Identity Governance Fragmentation
Today's enterprises struggle with a fundamental challenge: identity and access management (IAM) has become increasingly fragmented. Organizations deploy multiple tools across cloud, on-premises, SaaS, and homegrown systems—each managing identities in isolation, each with its own data model, and none providing a cohesive view of who can access what and whether that access is being used appropriately.
Oak's co-founder and Chief Product Officer Tal Marom articulated the scope of the problem during stakeholder interviews:
> "We spent months speaking with more than 100 CISOs and IAM leaders, and they all share the same problems: running too many disconnected tools, being unable to see how access is used, and having no way to govern AI agents."
This fragmentation creates several operational risks:
## How Oak's Identity Operating System Works
Oak's platform takes a different architectural approach from traditional IAM suites. Rather than attempting to replace legacy systems directly, the platform acts as a unified control plane that maps identities across an organization's entire environment.
### Core Capabilities
Universal Connector Architecture: Oak connects to applications across cloud platforms, on-premises infrastructure, SaaS services, and custom applications. According to the company, connectors can be established within hours—a significant advantage over traditional IAM deployments that typically require months of implementation.
Raw Evidence-Based Identity Mapping: Instead of relying on static provisioning records, Oak builds identity profiles from raw evidence of what each identity actually does. This means the platform observes:
AI-Driven Risk Assessment: The platform uses machine learning to evaluate identity risk in real time. Oak assigns risk scores based on observed behavior, making continuous recommendations for access remediation. This moves security teams from periodic access reviews to continuous governance.
Multi-Identity Scope: Critically, Oak is designed to govern three identity types simultaneously:
As organizations deploy more AI systems internally, the lack of AI identity governance in legacy IAM tools has become a significant gap. Oak positions itself to address this emerging security boundary.
## Background and Market Context
### The Founders' Track Record
Oak's founding team brings substantial cybersecurity pedigree. Shai Morag (CEO) is a serial founder and investor with three prior acquisition exits:
Tal Marom (Chief Product Officer) led product teams at both Tenable (after Ermetic's acquisition) and Salesforce, providing both security and enterprise SaaS product expertise.
This founding profile suggests Oak is not a first-time venture—the team understands how to build, scale, and integrate security platforms into enterprise environments.
### The "CNAPP Moment" for Identity
Marom drew a strategic comparison during the announcement:
> "Just as CNAPP consolidated the fragmented cloud security stack, identity is now at that same inflection point, and Oak is designed to be the platform that brings it all together."
Cloud-Native Application Protection Platforms (CNAPP) emerged in 2021-2022 to consolidate container security, vulnerability management, and configuration assessment. The category exploded because it solved a real integration problem—enterprises no longer needed separate tools for each container security dimension.
Oak is positioning itself as the identity equivalent: a single platform replacing multiple fragmented identity governance, access management, and risk assessment tools.
## Funding and Strategic Positioning
The $60 million seed round is substantial—most seed rounds range from $5M to $20M. The lead investors represent tier-one venture capital focused on enterprise infrastructure:
Additional support from Hetz Ventures and AlphaDrive Ventures indicates Israeli venture backing, reflecting the country's strong cybersecurity ecosystem.
At a $60M seed, Oak is likely valued in the $200-$300 million range—putting it in the category of well-capitalized startups competing directly with established players like Okta, CyberArk, and Ping Identity, while positioning against emerging competitors like 8Layers (which raised $2.9M for identity security) and others in the consolidation wave.
## Implications for Organizations
### Who Should Pay Attention
Organizations with the following characteristics should evaluate Oak's offering:
| Scenario | Why It Matters |
|----------|----------------|
| Large enterprises with 500+ employees | Fragmented IAM across multiple cloud and on-prem systems creates governance gaps |
| Rapid cloud migration underway | Cloud identity sprawl outpaces traditional IAM deployment speed |
| Deploying internal AI systems | Need governance for AI agents, vector databases, and autonomous systems |
| Recent M&A activity | Identity consolidation across acquired companies is a persistent pain point |
| Regulated industries | Financial services, healthcare, and government require comprehensive access audits |
### Strategic Considerations
RFP Timing: Organizations evaluating identity consolidation over the next 12-24 months should include Oak in competitive evaluations. The startup's willingness to build connectors rapidly makes it suitable for time-sensitive deployments.
Displacement Strategy: Oak's value proposition assumes organizations will maintain multiple identity sources during transition. Rather than requiring a "rip and replace" migration, Oak's approach allows parallel operations—a lower-risk path for established enterprises.
AI Governance Readiness: As enterprises move from proof-of-concept to production AI deployments, AI identity governance will move from "nice-to-have" to "compliance requirement." Organizations thinking ahead on this transition should factor AI identity handling into their identity platform selection.
## HackWire Analysis
Why This Matters Now — And What It Says About Enterprise Security's Direction
Oak's $60M funding round represents more than a single startup launch; it signals a fundamental shift in how enterprises will govern access and identity in the coming years.
The timing is critical. We are at an inflection point where three forces collide: (1) enterprises have embraced multi-cloud and hybrid infrastructure, leaving legacy IAM tools unable to keep pace; (2) AI agents and large language models are moving from experimentation to production deployment, creating entirely new identity governance challenges that traditional IAM was never designed to handle; and (3) breach aftermath data consistently shows that privilege abuse and excessive access are root causes, not vulnerabilities. Identity governance, done right, is fundamentally defensive.
The investor backing here is notable—Accel and Greylock don't deploy capital in overcrowded categories. Their participation suggests they see identity consolidation as a multi-billion-dollar market category with staying power. The comparison to CNAPP is apt: just as cloud security fragmentation created space for a new category, identity fragmentation is doing the same.
The hidden risk most enterprises miss: Many organizations will attempt to "fix" their identity mess by buying another tool rather than fixing the underlying architecture. Oak's value lies not in being yet another identity tool, but in becoming the unifying layer. However, organizations that deploy Oak without simultaneously simplifying their underlying identity infrastructure will end up with just one more tool to manage. The real win comes from consolidation—tearing out redundant systems—not layering on top of them.
For defenders: identity governance must move from annual reviews to continuous assessment. Static access reviews are security theater at this point. If your identity program doesn't include continuous monitoring of who has what access and whether it's being used, you're not defending; you're hoping not to be noticed.
— HackWire Editorial
## Recommendations for Defenders
For Enterprise Security Teams:
1. Audit your identity tool inventory — document every tool your organization uses for IAM, access governance, and identity risk. You will likely find 5-8 disconnected systems.
2. Define your AI identity strategy — before evaluating identity platforms, establish requirements for governing AI agents, model access, and automated systems.
3. Prioritize continuous over periodic — shift identity governance from annual reviews to real-time visibility and remediation.
For Chief Information Security Officers:
1. Include identity consolidation in strategic planning — identity governance is no longer a back-office function; it's foundational to breach defense.
2. Evaluate Oak alongside incumbents — competitive pressure from new entrants often accelerates innovation in established vendors.
3. Demand AI governance maturity — vendors claiming to support AI identity governance should have concrete, auditable proof—not just roadmap promises.
---
## Related Coverage