Linx Security
AI native identity security and governance platform that maps and governs human, non-human, and AI agent identities in real time, with an autonomous remediation agent, Autopilot.
Linx Security is an AI native identity security and governance platform that continuously maps, monitors and governs every identity in an enterprise: people, non-human identities such as service accounts and API keys, and AI agents. Founded in 2023 by Israel Duanis and Niv Goldenberg, graduates of Israel's Talpiot program with backgrounds at Check Point, Transmit Security and Microsoft, the company emerged from stealth in July 2024 with thirty three million dollars led by Index Ventures and Cyberstarts, then raised a fifty million dollar Series B in 2026 led by Insight Partners.
The platform is built on an identity graph that maps identities, relationships and access paths continuously, so a team can see who has access to what right now.
On top of it, Linx Autopilot is an autonomous agent that watches identity activity, detects meaningful changes the moment they happen, such as newly assigned privileged access or a departmental move, remediates high confidence, policy aligned risks on its own, and escalates ambiguous or high impact changes to a person with the context assembled. Every Autopilot action is logged and auditable.
An Assistant answers identity questions for the team, and joiner, mover and leaver workflows, access requests with approver workflows, just in time access and automated access reviews run across connectors such as GitHub, GitLab, Snowflake, AWS, Salesforce and Datadog.
Linx shows SOC 2 and HIPAA badges and is sold through sales and on the AWS and Azure marketplaces. It does not publish pricing, hosting regions, model providers or a developer API. For a security or identity team with sprawling service accounts and AI agents that wants continuous, automated governance across every identity type, Linx is built for that job; a small organization with a mostly human identity footprint may find a traditional identity provider sufficient.
Vendor details
Canonical URL
https://www.linx.security
Category
Security / SOC agent
Subcategory
Identity security and governance
Funding status
Independent, headquartered in New York with roots in Israel, founded in 2023 by Israel Duanis and Niv Goldenberg. Emerged from stealth in July 2024 with thirty three million dollars led by Index Ventures and Cyberstarts, with angels from Wiz and Transmit Security, then raised a fifty million dollar Series B in 2026 led by Insight Partners, with Cyberstarts and Index Ventures returning, for about eighty three million dollars in total. Reports revenue growing tenfold over a year, roughly one hundred employees, and multimillion dollar contracts with banks, healthcare companies, and Fortune 500 firms governing millions of identities.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Connects across identity providers, SaaS applications, cloud infrastructure, service accounts, and directories to build a unified identity graph of every human, machine, service, and AI agent identity. Ingests activity in real time to map relationships between identities, permissions, and resources, and acts through automated remediation with escalation paths to security teams.
In practice
Your CISO cannot answer who has access to what right now across employees, service accounts, and AI agents, only who had access at last quarter's review. Linx maps every identity and its permissions in real time so the answer is always current.
AI agents are inheriting human permissions and acting across systems at machine speed, and manual access reviews cannot keep up. Linx Autopilot watches identity activity continuously and remediates risky access automatically or escalates it.
Legacy identity governance rollouts drag on for a year and still leave blind spots. Linx builds an identity graph and governs human, machine, and agent identities without a lengthy implementation.
Sources & related URLs
Research sources
Agentic Index coverage score
6.5 / 14 capabilities · 46%
| Integrations & Tool Calling | Full |
|---|---|
|
Connectors to GitHub, GitLab, Snowflake, AWS, Salesforce, Datadog and identity providers, and the platform acts in them. Provisioning, access changes, joiner, mover and leaver workflows and remediation run without other teams doing the work. Sourcelinx.security/platform/automation-remediationread 2026-09-28 |
|
| Workflow Orchestration | Partial |
|
Joiner, mover and leaver workflows run automatically on events and Autopilot moves from detection to remediation or escalation, but these are the product's own flows. No workflow builder, branching the buyer designs or multi agent handoff is documented. Sourcelinx.security/platform/automation-remediationread 2026-09-28 |
|
| Knowledge Grounding & RAG | Full |
|
An identity graph continuously maps the customer's human, non-human and AI agent identities, their relationships and access paths, and Autopilot and the Assistant reason over it. Sourcelinx.securityread 2026-09-28 |
|
| Human Oversight & Guardrails | Full |
|
Autopilot acts on its own only on high confidence, policy aligned risks and escalates ambiguous or high impact changes to a person with full context assembled, who decides. Access requests go through approver workflows. Sourcelinx.security/platform/autopilotread 2026-09-28 |
|
| Security, Identity & Governance | Partial |
|
SOC 2 and HIPAA badges appear on the homepage, and Linx runs a trust center at trust.linx.security, but no page documents SSO, SCIM or roles for its own console. Governing customers' identities is the product's function, not its own access surface. Sourcelinx.securityread 2026-09-28 |
|
| Observability & Auditability | Full |
|
Every Autopilot action is logged, policy scoped and auditable, and every remediation decision is logged and traceable for incident response and regulators. Sourcelinx.security/platform/autopilotread 2026-09-28 |
|
| Memory & State Persistence | Not documented |
|
No agent memory store with a scope or lifetime is documented. The identity graph's history is the product's data model and grounds its reasoning rather than serving as agent memory. Sourcelinx.security/platform/autopilotread 2026-09-28 |
|
| Deployment & Data Residency | Not documented |
|
Hosting is not documented. Linx names AWS and Azure Marketplace listings, which are purchase channels, and publishes no hosting region, no choice of region and no customer environment option. Sourcetrust.linx.securityread 2026-09-28 |
|
| Prebuilt Agents, Templates & Packs | Partial |
|
Two named agents, Autopilot for autonomous remediation and the Assistant for identity intelligence, plus built in joiner, mover and leaver workflows. No catalog of templates or wider agent set is documented. Sourcelinx.securityread 2026-09-28 |
|
| Triggers & Channel Coverage | Full |
|
Autopilot detects identity changes the moment they happen, not on a schedule, and joiner, mover and leaver workflows execute automatically when events trigger them. Sourcelinx.security/platform/autopilotread 2026-09-28 |
|
| Model Flexibility & Routing | Not documented |
|
No page names the models or providers behind Autopilot or the Assistant, and no model choice is offered. Sourcelinx.security/platform/autopilotread 2026-09-28 |
|
| APIs, SDKs & MCP Extensibility | Not documented |
|
No API, SDK or MCP server for the Linx platform is documented. Connectors pull from other systems, which is not an interface for calling Linx. Sourcelinx.securityread 2026-09-28 |
|
| Testing, Debugging & Optimization | Not documented |
|
No evaluation harness, scored test cases, simulation or gate for Autopilot's decisions is documented. Risk analysis of access is the product's function, not a test of the agent. Sourcelinx.security/platform/autopilotread 2026-09-28 |
|
| Browser & Computer Use | Not documented |
|
No page documents an agent driving a browser, desktop or remote computer. Remediation runs through connectors. Sourcelinx.securityread 2026-09-28 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Linx Security launched a new secure third-party agent access integration within the Snowflake security ecosystem. This integration enables enterprises to connect, govern, and audit the activity of autonomous AI agents by applying the same identity discipline used for human and system accounts.
Bears on: Integrations
View sourcePricing
Not public; quoted through sales, also listed on AWS and Azure Marketplace
not published
What is public
No list pricing. Linx quotes through sales and lists the product on AWS Marketplace and Azure Marketplace, with no self serve tier.
Billing mechanics
Sold through sales or cloud marketplaces; the billing unit is not published.
Cost watchouts
Because non-human and agent identities can outnumber humans many times over, identity based pricing can scale faster than headcount.
Variable cost rationale
Sold as an enterprise subscription scoped to the size of the identity environment, so cost tends to grow as the number of human, machine, and agent identities governed expands.
Additional watchouts
With no public rate and pricing likely tied to identity volume, confirm how the explosion of non-human and agent identities affects cost over time.
Sales call required
Yes, required for paid access
Free / trial
Demo on request; no public free tier
Key ambiguities
No public rate is published, and whether pricing is per identity, per module, or flat enterprise is not disclosed.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Linx Security
The closest documented capability profiles to Linx Security among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Portal265.5 / 14A lighter documented profile than Linx Security
- AirMDR6.0 / 14Fuller documented coverage on Security, Identity & Governance
- Astelia8.0 / 14Adds documented APIs, SDKs & MCP Extensibility
- Exaforce8.0 / 14Adds documented Memory & State Persistence
- Pi6.0 / 14Adds documented Memory & State Persistence
- Quantro Security7.0 / 14Fuller documented coverage on Workflow Orchestration and Prebuilt Agents, Templates & Packs
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded