
Wiz veteran raises $12 million Seed to secure AI agents at Rig Security
Guy Kozliner, who worked on Wiz co-founder Ami Luttwak's CTO team, is building a platform to distinguish AI agents from the humans whose identities they use.
Cybersecurity company Rig Security has raised a $12 million Seed round led by Ten Eleven Ventures and Brightmind Partners. The CrowdStrike Falcon Fund also participated through a strategic investment, alongside cybersecurity founders and executives including Ami Luttwak, co-founder and CTO of Wiz. The company closed the round in late 2025 and is now emerging from stealth.
Rig Security was founded in early 2025 by CEO Guy Kozliner, a Wiz alumnus who served on the CTO team under Ami Luttwak. The leadership team also includes CTO Nokky Goren, formerly the first engineer at Axis Security, which was acquired by HPE, and Head of Product Michal Haikov, a veteran of Unit 8200 and Flow Security, which was acquired by CrowdStrike. Rig Security currently employs 20 people and plans to expand its team in both Israel and the US over the coming year.
Rig Security has developed a platform designed to create a real-time security layer for identities in the era of AI agents. The platform identifies AI agents at endpoints, distinguishes their activity from that of the human or machine identity through which they operate, and enforces policies on their actions in real time. It maps identities, permissions, sessions and actions onto a single graph connecting cloud environments, on-premises systems, identity providers and endpoints.
The company argues that AI agents are creating a new identity security problem because they typically operate through existing human or machine identities rather than separate accounts. An AI coding assistant or autonomous agent, for example, can use the permissions of the employee or service account that launched it. As a result, an action carried out by an agent can appear in identity providers, audit logs and security information and event management systems as if it had been performed by the person whose identity it is using.
Rig's product operates through two complementary engines. The first, RICE, or Rig Identity Correlation Engine, connects identities scattered across organizational systems and builds a unified view of users, their permissions, access rights and relationships with more than 96% accuracy. The company says the engine was developed with a research team of Harvard alumni and is currently in the patent process. The underlying research has produced five inventions.
RICE provides the foundation for what Rig calls its Identity Dependencies Graph, a live map of how human, machine and AI identities are connected through accounts, permissions, sessions and trust relationships. The second component, Bifrost, is a lightweight endpoint sensor that detects identity activity where it originates on the device. It can identify when an AI agent is operating through an employee's session, distinguish that activity from the user's own activity and enforce policies inline, allowing the company to block a risky action before it reaches the cloud without necessarily blocking the employee.
Together, the technologies are designed to provide identity security posture management and identity threat detection and response across human, machine and AI identities from a single platform. Rig says it can deploy without agents in minutes and then roll out its sensors to add runtime attribution and policy enforcement.
Rig says it is already being used in production by Fortune 200 organizations across financial services, insurance, healthcare and technology. The platform is available through the AWS Marketplace and CrowdStrike Marketplace. The company was also named one of the top three startups among hundreds of participants in a cybersecurity accelerator run by AWS, CrowdStrike and NVIDIA. Rig says it analyzes and protects hundreds of millions of identity events and access signals each month.
"Identity used to mean people's credentials. Today the most active identities in an enterprise are AI agents, and they are acting under human names," said Guy Kozliner, founder and CEO of Rig Security. "Security teams can see that an account did something dangerous. What they cannot see is whether a person did it or an agent did, and they cannot stop the agent without blocking the person. The problem is access that is broader than intended, ungoverned, and hiding behind human activity. We built Rig so organizations can unleash AI securely: know exactly which agents exist, what access they have borrowed right now, what they are doing with it, and enforce policy on it at runtime."
Before founding Rig, Kozliner was a member of Luttwak's team at Wiz, where the company developed a graph-based approach to cloud security. Luttwak is now an investor in Rig. CrowdStrike, whose Falcon platform is focused on endpoint protection, also joined the round as a strategic investor.














