Permiso
AcquiredMclean, US · Founded 2020 · 58 employees on LinkedIn · 8 known investors
Permiso provides identity security for AI agents, offering runtime attribution that tracks agent activity after authentication, including tool calls, MCP invocations, and sub-agent spawns. It addresses gaps in identity provider visibility over non-deterministic AI agent behavior.
Also known as Permiso Security
Founders & leadership
Permiso was founded in 2020 by Paul Nguyen.

Investors · 8
Also in the syndicate · 2
Reported raises · per SEC filings
Form D private placements$29.1M disclosed across 1 of 3 rounds · 2022–2024
▶$29.1MraisedMay 2024 · 34 investors · Other TechnologyRule 506(b)
- Jason Lawrence MartinExecutive Officer, Director, Promoter
- Tin Huu NguyenExecutive Officer, Director, Promoter
- Erik KriessmannDirector
- Offering amount
- $29.1M
- Amount sold
- $29.1M
- First sale
- Jan 2024
- Incorporated
- Corporation, Delaware, 2020
- Federal exemptions
- 06b
Source: SEC EDGAR Form D. Amounts as filed; amended filings shown once at their latest values.
Valuation · disclosed
Disclosed eventsSource: SEC prospectus filings, and round valuations the company or its investors disclosed — follow each entry's link for the claim.
Company profile
researched Aug 2026Permiso Security operates an identity security platform that inventories and monitors human, non-human, and AI identities across cloud service providers, SaaS applications, identity providers, CI/CD pipelines, and on-premises environments. The platform is organized into three product areas: Discover, which builds a comprehensive identity inventory; Protect, which continuously evaluates identity risk posture based on usage patterns, exposure, and entitlements to surface high-risk identities, stale or zombie accounts, excessive privileges, and toxic access combinations; and Defend, which monitors for anomalous behavior, lateral movement, and early signs of compromise to support investigation of identity-driven attacks. Capability categories the company markets include identity visibility and intelligence, identity security posture management (ISPM), and identity threat detection and response (ITDR) covering credential compromise, account takeover, and insider threat, with named coverage of AWS, Azure, Okta, and Microsoft 365.
The company's core technical construct is the Universal Identity Graph, which links identities to the credentials they own, the machines they create, the agents they run, and the actions they take, stitching activity across authentication boundaries such as federation, role assumption, access tokens, and direct login. Earlier company materials describe this as creating a composite or "meta" identity that reconstructs user sessions from disparate runtime events, pairing runtime activity with static, posture-based data to generate attributed, high-fidelity alerts rather than single-event detections. In 2026 Permiso extended the approach to AI agents through Identity Runtime Attribution, giving visibility into agent runs, tool calls, MCP invocations, and sub-agent spawns across the agent lifecycle, plus behavioral anomaly detection; the company frames the gap as what happens after authentication, where identity providers lose visibility into non-deterministic agent behavior. In April 2026 it also introduced SandyClaw, a platform for analyzing AI agent skills in a sandboxed environment to identify malicious behavior before deployment.
Research is produced by P0 Labs, the company's cloud and identity threat research group, which includes former Mandiant advanced practices leads and has developed more than 1,500 detection signals fed into the product; its published research covers topics such as prompt injection and phishing surfaces in AI email assistants. Permiso positions itself against SIEM, CNAPP, and cloud workload protection tools, arguing those are siloed to IaaS, event-driven and noisy, and lack identity attribution context.
Founding story
Permiso was co-founded by Jason Martin and Paul Nguyen, both former FireEye executives; Martin was EVP of Products and Engineering at FireEye/Mandiant and Nguyen was SVP of Product Strategy and Product Management, with earlier roles at @stake, Neohapsis, and Invotas. Phani Modali is also listed as a co-founder and SVP of Engineering.
Business model
Permiso sells its identity security platform to enterprises; at the time of its Series A the company reported closing multiple six- and seven-figure license deals with Fortune 500 customers.
Software licensing for the platform, sold to enterprise customers; the company cited significant revenue growth since its seed round and six- and seven-figure license deals.
Traction
Permiso reported closing multiple six- and seven-figure license deals with Fortune 500 customers and increasing revenue significantly after its seed round. Following the 2023 LUCR-3 (Scattered Spider) attacks on MGM and Caesars, multiple casino groups adopted its platform, and it was engaged by other victim organizations to correlate activity that incumbent systems could not. Autodesk was among the first enterprises to deploy its AI agent security capabilities.
Latest developments
In May 2026 Permiso announced Identity Runtime Attribution for AI agents across its Discover, Protect, and Defend products, with Autodesk among the first enterprises to deploy the capabilities; the launch was covered by Security Boulevard. In April 2026 it introduced SandyClaw for sandboxed analysis of AI agent skills. On 30 July 2026, Okta agreed to acquire Permiso, a deal TechCrunch reported at just under $200 million in an almost all-cash structure, expected to close in the third quarter of Okta's fiscal 2027. Okta chief product officer Ely Kahn said Permiso would extend Okta's identity security fabric with identity threat detection and response capabilities and its threat research team.
▸Full profile — market position, technology, go-to-market, geography, history, risks & controversies
Market position
Permiso competes in identity threat detection and response and identity security posture management, adjacent to SIEM, CNAPP, and CSPM vendors. Altimeter partner Erik Kriessmann said customers described Permiso as a pillar of their cloud security stack alongside Wiz, CrowdStrike, and Palo Alto Networks. TechCrunch framed the Okta acquisition as part of identity vendors expanding from login verification to continuous monitoring of what users, applications, and AI agents do after authentication.
Permiso describes its distinguishing element as combining runtime and static identity enrichment in the Universal Identity Graph so identities can be tracked across authentication boundaries, producing attribution and context that it says SIEM, CNAPP, and CSPM tooling does not provide; detection content is built by an in-house research group from observed threat actor behavior rather than from product categories.
Technology
The Universal Identity Graph correlates runtime and static identity data to connect identities to credentials, machines, agents, and actions across identity providers, IaaS, PaaS, SaaS, CI/CD, and on-premises environments, reconstructing sessions across authentication boundaries. Detection content includes more than 1,500 signals developed by P0 Labs. AI-specific capabilities include Identity Runtime Attribution for agent runs, tool calls, and MCP invocations, behavioral anomaly detection, and SandyClaw sandbox analysis of agent skills.
Go-to-market
The company markets directly to enterprise security teams through demo requests, published threat research and hunting campaigns from P0 Labs, threat briefings for prospective customers, and customer references from organizations including Autodesk, Modern Health, ACV Auctions, and Nutanix.
Enterprise security operations and cloud security teams, including large organizations in technology, healthcare, and gaming/casino sectors; named customers and references include Autodesk, Modern Health, ACV Auctions, and Nutanix.
Geography
Company announcements identify Palo Alto, California as its location, and TechCrunch refers to it as Palo Alto-based. It also has operations in India, with a Director of Operations for India on the leadership team.
History
Permiso emerged from stealth in 2022 and was named a SINET16 Innovator. It had previously raised a $10 million seed round, and in April 2024 announced an $18.5 million Series A led by Altimeter Capital with participation from Point72 Ventures, which it said would fund faster integration work and new product capabilities. It won the 2025 SC Award for Most Promising Early-Stage Startup and the 2026 SC Award for Best Threat Detection Technology. In May 2026 it launched AI agent runtime security capabilities, and in July 2026 Okta agreed to acquire the company.
Risks & controversies
Company materials note that AI agents can circumvent intended permission constraints, citing an observed case in which a coding agent bypassed GitHub repository permissions by finding an alternate path to clone and merge code.
Compiled by commissioned research from 8 cited public sources — announcements, filings, and press listed under research sources below.
Key figures
latest reportedCompany-reported or press-reported figures, each dated to when it was claimed — not independently audited.
Timeline · 8
launches, deals, and filingsOkta agreed to acquire Permiso Security to extend its identity security fabric with identity threat detection and response and threat research capabilities. Terms were not disclosed publicly; a source told TechCrunch the deal was valued at just under $200 million and structured as an almost all-cash transaction. Closing is expected in the third quarter of Okta's fiscal 2027.
$200M source ↗
Permiso announced AI agent runtime security capabilities delivering agent runtime identity attribution and behavioral anomaly detection across the agent lifecycle, including visibility into agent runs, tool calls, and MCP invocations. Autodesk was among the first enterprises to deploy the capabilities.
Platform designed to analyze AI agent skills in a sandboxed environment to identify malicious behavior before deployment.
Second consecutive year of recognition at the SC Awards, for the identity security platform covering human, non-human, and AI identities across cloud, SaaS, CI/CD, and on-premises environments.
Series A round led by Altimeter Capital with participation from Point72 Ventures, to expand integrations and product capabilities. TechCrunch later reported the round valued the company at about $80 million post-money.
$18.5M source ↗
Recognition given to 16 cybersecurity companies; noted alongside the company's emergence from stealth mode in 2022.
Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.
In the news
▸Research sources · 8
primary sources listed
- Permisopermiso.io · web
8 public sources were cited for this profile; the first-party ones are listed here.
Frequently asked questions
- What does Permiso do?
- Permiso is an identity security company that detects threats from human, non-human, and AI agent identities across cloud and SaaS.
- Who founded Permiso?
- Permiso was founded by Paul Nguyen in 2020.
- Who are Permiso's investors?
- Permiso's investors include 11.2 Capital, aVenture, Point72 Ventures, Vertex Ventures, Work-Bench, Altimeter Capital.
- How much funding has Permiso raised?
- Permiso has disclosed $29.1M raised across 1 of its 3 known rounds.
- Where is Permiso headquartered?
- Permiso is headquartered in Mclean, US.



