The traditional concept of corporate identity—once defined by a physical photo ID card clipped to a lanyard—has been rendered obsolete by the digital transformation of the modern workplace. Today, the perimeter of a company is no longer a physical office door; it is a sprawling, ephemeral network of cloud applications, AI agents, and remote endpoints. As humans and machines increasingly collaborate in these complex digital environments, the legacy identity and access management (IAM) tools designed for the previous era are failing.
Enter Oak, an Israeli cybersecurity startup emerging from stealth with a mission to redefine how organizations govern access. Backed by a massive $60 million seed round and led by a veteran team of security experts, Oak is positioning itself as the "unified control plane" for the identity era.
The Problem: Legacy Systems in a High-Velocity World
For decades, IAM systems have functioned like digital bouncers, granting or denying entry based on static rules. However, the modern enterprise environment is far more fluid. Employees, contractors, and an ever-increasing number of AI agents constantly interact with data across disparate SaaS platforms.
Current IAM solutions are largely manual, reactive, and disconnected. They rely on periodic, infrequent access reviews that fail to keep pace with the speed of business. If an employee changes roles, leaves a department, or logs in from an anomalous location, legacy systems often remain oblivious, leaving "zombie permissions" behind—orphaned access rights that serve as prime targets for cyberattackers.
As Shai Morag, co-founder of Oak and a seasoned security entrepreneur, explains: "Right now, the whole process is too manual, and it’s operations-based, not risk-based. There is no automated trigger when a user exhibits abnormal behavior or when an access right is no longer required for their daily workflow."
A Chronology of Innovation and Exit
The genesis of Oak is rooted in the deep industry expertise of its founders, Shai Morag and Tal Marom. Their journey is one of consecutive success and an unwavering commitment to solving the most stubborn problems in cloud security.
The Foundation of Expertise
Shai Morag’s resume reads like a map of modern cybersecurity evolution. A former major in the Israeli military, Morag transitioned to the private sector and became a serial entrepreneur. He founded Secdo, an endpoint detection and response startup, which he successfully exited to Palo Alto Networks in 2018.
Following that success, Morag co-founded Ermetic, a cloud infrastructure entitlement management platform. Ermetic gained significant market traction, eventually being acquired by Tenable in 2023 for $265 million. Morag stayed on as Chief Product Officer at Tenable, working closely with the company’s leadership. It was here that he met Tal Marom, a product team lead who had honed his skills at Salesforce and within the Israeli defense establishment.
The Turning Point
The trajectory shifted following the untimely passing of Tenable CEO Amit Yoran in early 2025. Morag, initially intending to retire and step away from the rigors of startup life, found himself compelled by the persistent gaps he saw in the IAM landscape. Together with Marom, he decided to channel his experience into a new, more ambitious project.
While in stealth, the duo spent months consulting with over 100 Chief Information Security Officers (CISOs) and IAM leaders. This period of intense research allowed them to identify the specific pain points that plague modern security teams: the lack of visibility into app usage and the inability to automate permission revocation in real-time.
The Oak Solution: An AI-Native Approach
Oak’s product is not merely a patch for existing systems; it is a fundamental reimagining of access governance. By leveraging an AI connector framework, the platform maps identity access directly to actual application usage.
How It Works
The platform continuously monitors how identities—both human and non-human (AI agents)—interact with the organization’s data ecosystem. Instead of relying on manual, periodic audits, Oak’s system identifies unused or excessive permissions and revokes them in real-time.
By shifting from an operations-based model to a risk-based model, Oak enables security teams to automate the lifecycle of access. If an AI agent requires access to a database for a specific project, Oak grants it; once the project concludes or the usage pattern shifts, the access is automatically rescinded. This creates a "just-in-time" security posture that minimizes the attack surface significantly.
Supporting Data and Investment Landscape
The scale of Oak’s seed funding is an anomaly in the current venture capital market, signaling strong institutional confidence in both the product and the founders. The $60 million seed round was co-led by Accel, CRV, and Greylock Partners, with significant participation from AlphaDrive Ventures, Hetz Ventures, and a suite of prominent angel investors.
The Investor Perspective
Andrei Brasoveanu, a partner at Accel, has a long history with Morag, having led the Series A round for Ermetic when it was still pre-revenue. "I knew he had it in him to build another company, but this time even bigger and even better," Brasoveanu noted.
For Accel, the investment was a strategic bet on both the technology and the leadership. Brasoveanu emphasized that while AI is often seen as a democratizing force for younger, inexperienced founders, the IAM space requires a level of institutional navigation and product maturity that only seasoned veterans possess. "There’s complexity in the product, and there’s also complexity in the organizations you have to navigate to figure out how to sell something like this," he added.
Implications for the Cybersecurity Industry
The emergence of Oak highlights several critical shifts in the broader cybersecurity landscape.
1. The Rise of Non-Human Identities
As companies integrate more AI agents and automated workflows into their operations, the number of non-human identities is skyrocketing. These entities often have broad access, making them an attractive target for hackers. Oak’s ability to manage these identities as easily as human ones positions it at the forefront of the "Identity-First" security trend.
2. The End of Vendor Lock-in?
The IAM market has historically been dominated by legacy players, leading to deep-seated vendor lock-in. Companies have been reluctant to switch tools due to the immense technical debt involved in re-configuring identity governance. By positioning itself as a "unified control plane" that can integrate across existing systems, Oak aims to act as an abstraction layer, potentially easing the transition for enterprises looking to modernize without a complete "rip-and-replace" cycle.
3. The "Born as a Giant" Philosophy
Morag’s stated vision is to "be born as a giant." By building a team of 50 people during the stealth phase and planning an aggressive expansion, particularly in the United States, Oak is signaling that it is not looking for a quick exit. Instead, it is building the infrastructure of a long-term, enterprise-grade powerhouse.
Future Outlook
As Oak transitions from stealth to general availability, the company faces the challenge of scaling its operations while maintaining the rigorous security standards its product promises. Competition in the identity space is fierce, with established incumbents and agile startups all vying to capitalize on the AI security wave.
However, the team at Oak is undeterred. Morag, who has committed to making this his final professional endeavor, is focused on the long-term impact of the company. "I will go big or go home," he told TechCrunch.
For the modern CISO, the promise of Oak is one of reclaimed control. In a world where every digital interaction carries risk, the ability to dynamically manage access is no longer a luxury—it is the bedrock of corporate survival. As Oak scales, the industry will be watching to see if this "unified control plane" can truly bridge the gap between legacy security and the autonomous, AI-driven future.
The company’s ability to execute on its vision, backed by its massive war chest and the collective experience of its founders, sets the stage for a significant shift in how the world’s largest organizations manage their most precious digital asset: their identity.

