Back to vendors
T

Token Security

Visit site
Entry priceNot public; quoted through enterprise engagement with no self serve tierFull pricing detail

Non human identity security platform that discovers and governs machine identities and AI agents across cloud, SaaS and on premises systems, with posture management, threat detection, least privilege, a conversational Token AI Agent and MCP Server, and Enzo for building identity workflows in natural language.

Token Security is a non human identity security company, headquartered in Tel Aviv with a New York presence, that secures the machine identities and AI agents spreading across enterprises. Founded in 2023 by Itamar Apelblat and Ido Shlomo, it has raised about twenty seven million dollars across a seven million dollar seed round led by TLV Partners and a twenty million dollar Series A in January 2025, backed by Notable Capital and SNR, and was named to The Information's list of the fifty most promising startups of 2025.

Non human identities such as service accounts, API keys, OAuth tokens, secrets and AI agents often run with broad, permanent access and no clear owner. Token discovers them across cloud, SaaS, on premises and CI/CD systems, maps ownership and access paths, and enforces least privilege, with posture management, identity threat detection and response, access reviews, and policies for how the customer's own AI agents are created and what they may reach.

On the agent side, the Token AI Agent and the Token MCP Server, launched in May 2025, let teams query inventory, risk and blast radius in plain language, and the MCP Server works with Claude, ChatGPT, Gemini and Cursor and can generate remediation scripts and initiate actions. Enzo, launched in June 2026, lets security and identity teams build their own live applications, workflows and automations in natural language, including Slack and email notifications, ticketing, lifecycle management and remediation actions, with the platform also triggering remediation on dynamic risk thresholds.

Token's trust center lists ISO/IEC 27001:2022 and SOC 2 Type 2. Enzo recommends remediation and offers one click actions, and its actions are logged. Token's public pages do not document an approval step before an automated action runs, a run trace of Token's own agent, the MCP Server's endpoint and tools, or where the service is hosted. Token does not name the model behind its agent. It fits a security team that needs to inventory and govern the machine identities and AI agents across a mixed estate and wants to build its own identity workflows on that inventory; a team looking for a general purpose agent builder or a secrets only vault will find it focused on identity governance.

Vendor details

Canonical URL

https://token.security

Category

Security / SOC agent

Subcategory

Non human identity and AI agent security

Funding status

Independent, headquartered in Tel Aviv with a New York presence, founded in 2023 by Itamar Apelblat and Ido Shlomo. Token Security has raised about twenty seven million dollars across a seven million dollar seed round led by TLV Partners and a twenty million dollar Series A in January 2025, backed by Notable Capital and SNR with angel investors including Kevin Mahaffey, founder of Lookout, and Shlomo Kramer, co-founder of Cato Networks. It was named to The Information's list of the fifty most promising startups of 2025.

Company status

independent

Use cases & customers

Primary use cases

non human identity discovery and governanceAI agent identity securityidentity posture managementidentity threat detection and response

Target customers

security teamsenterprise CISOscloud and hybrid enterprises

Deployment options

SaaScloudhybridon-premise

Integrations

Token Security's integrations catalog covers AWS, Azure and GCP, identity providers such as Okta and Microsoft Entra ID, source control and CI/CD, secrets vaults such as HashiCorp Vault and CyberArk, ticketing such as Jira and ServiceNow, Slack and Microsoft Teams, SIEM and log tools, and AI platforms whose agents it discovers. Enzo applications act through notifications, ticketing, lifecycle and remediation workflows, and the Token MCP Server exposes the identity inventory to Claude, ChatGPT, Gemini and Cursor.

In practice

AI agents and service accounts are multiplying across your cloud and on premise systems with broad permissions and no owner, and human style controls do not catch them. Token Security discovers every non human identity in seconds and enforces least privilege before one is abused.

A leaked API key or over privileged token is the entry point for a growing share of cloud breaches, but your team cannot even inventory them. Token Security maps ownership, scores risk, and triggers remediation on dynamic thresholds.

Security teams drown in fragmented identity data and cannot answer which inactive machine identities are riskiest. The Token AI Agent lets them ask in plain language across inventory, posture, secrets, and threats and get guided remediation.

Agentic Index coverage score

6.5 / 14 capabilities · 46%

Integrations & Tool Calling Full

Enzo applications send Slack notifications, run email workflows, open tickets, handle lifecycle management and run remediation actions against connected systems, and the Token MCP Server can "generate remediation scripts, and even initiate actions". The integrations catalog covers ticketing (Jira, ServiceNow), chat (Slack, Microsoft Teams), the major clouds, identity providers and secrets vaults.

Sourcetoken.security/blog/introducing-enzo-by-token-security-the-ai-native-identity-security-application-builderread 2026-09-28

Workflow Orchestration Full

Enzo, launched 3 June 2026, lets security teams describe and build their own live applications, workflows and automations in natural language, with workflow triggers and recurring identity operations. The platform also triggers remediation workflows on dynamic risk thresholds.

Sourcetoken.security/blog/introducing-enzo-by-token-security-the-ai-native-identity-security-application-builderread 2026-09-28

Knowledge Grounding & RAG Full

The Token AI Agent, the MCP Server and Enzo all draw on the same live identity context, which Token keeps current across the customer's own estate. It maps human and non human identities, AI agents, cloud and SaaS accounts, secrets and credentials, each with its owner and blast radius.

Sourcetoken.security/blog/introducing-the-first-nhi-mcp-server-ai-powered-smarter-driving-fast-remediationread 2026-09-28

Human Oversight & Guardrails Partial

Remediation in Enzo comes as a recommendation with one click actions, so the decision stays with the team, and approvals appear among the workflows Enzo can support. No public page documents an approval step that holds an agent action until a person signs off. The policy controls on the product page govern the customer's own AI agents, not Token's.

Sourcetoken.security/blog/introducing-enzo-by-token-security-the-ai-native-identity-security-application-builderread 2026-09-28

Security, Identity & Governance Partial

The trust center lists ISO/IEC 27001:2022 and SOC 2 Type 2. No public page documents customer facing SSO, roles or an admin audit log for the Token console. Identity governance is the product Token sells, not a control described for its own console.

Sourcetrust.token.securityread 2026-09-28

Observability & Auditability Partial

Actions taken by Enzo applications are audited and carry full audit logging, so Token's own automation leaves an action log. No run trace of the Token AI Agent or of Enzo's steps is documented. The immutable logs and audit trails on the product page record what the customer's AI agents do, not Token's own agent.

Sourcetoken.security/blog/introducing-enzo-by-token-security-the-ai-native-identity-security-application-builderread 2026-09-28

Memory & State Persistence Not documented

Neither the Token AI Agent nor Enzo has documented memory with a stated scope and lifetime. The identity inventory and behavioral baselines are Token's data model of the customer's estate rather than agent memory.

Sourcetoken.security/productread 2026-09-28

Deployment & Data Residency Not documented

Where Token itself runs is not stated. Its coverage across on premises, hybrid and cloud environments describes where it discovers identities, and the homepage, product page and trust center name no hosting region or option to run in the customer's environment.

Sourcedocs.token.securityread 2026-09-28

Prebuilt Agents, Templates & Packs Partial

Token ships one conversational agent, the Token AI Agent, and the MCP Server. The Enzo posts describe example applications such as a Clean Exit Checklist and access review workflows, but no named library of prebuilt agents or templates that a customer installs is documented.

Sourcetoken.security/blog/introducing-enzo-by-token-security-the-ai-native-identity-security-application-builderread 2026-09-28

Triggers & Channel Coverage Full

The platform triggers "intelligent remediation workflows based on dynamic risk thresholds and contextual awareness", so detected risk starts the work without a person. Enzo adds workflow triggers and recurring identity operations.

Sourcetoken.securityread 2026-09-28

Model Flexibility & Routing Not documented

The model behind the Token AI Agent and Enzo is not named, and no choice of provider is offered. Customers can point their own assistant, such as Claude, ChatGPT, Gemini or Cursor, at the Token MCP Server, but that is their own model using Token's tools. The AI platforms in the integrations catalog are estates Token discovers.

Sourcetoken.security/integrationsread 2026-09-28

APIs, SDKs & MCP Extensibility Partial

The Token MCP Server, launched 22 May 2025, lets Claude, ChatGPT, Gemini and Cursor query inventory, risk and blast radius, and initiate actions. No public page gives its endpoint, authentication scheme or tool list, and no public REST API or SDK is named. Product documentation lives at docs.token.security.

Sourcetoken.security/blog/introducing-the-first-nhi-mcp-server-ai-powered-smarter-driving-fast-remediationread 2026-09-28

Testing, Debugging & Optimization Not documented

No test harness with scored cases, preview or quality gate is documented for the Token AI Agent or Enzo applications. Attack path analysis and compliance validation test the customer's estate, not Token's agent.

Sourcetoken.security/productread 2026-09-28

Browser & Computer Use Not documented

Token works through API integrations with clouds, identity providers and vaults. No agent operating a browser or desktop is documented.

Sourcetoken.security/integrationsread 2026-09-28

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Recent platform changes

2026-08-26·Workflow orchestrationVerified

Token Security introduced Enzo, an AI-native identity security application builder that allows users to create live applications, workflows, dashboards, and automations using natural language. The solution is built directly into the Token Security platform and requires no additional infrastructure or coding.

Bears on: Workflow orchestration

View source
View all 1 change for Token Security →Tracked since Aug 2026 · Verified from public vendor sources

Pricing

Not public; quoted through enterprise engagement with no self serve tier

enterprise subscription; basis not disclosed

What is public

No list pricing. Token Security sells through enterprise engagement, with no public rates and no self serve tier.

Billing mechanics

Rates and billing basis are not disclosed. Inference, not stated by the vendor: an enterprise subscription scoped to the identity estate, the environments covered and the modules enabled.

Cost watchouts

Inference, not stated by the vendor: broad coverage across cloud, on premises and CI/CD and larger identity estates may raise cost.

Variable cost rationale

Inference, not stated by the vendor: likely scoped to the number of non human identities, the environments covered and the modules enabled, so cost would grow with the size of the identity estate.

Additional watchouts

Confirm how pricing scales with the number of identities discovered and the environments in scope, and whether modules like threat detection and response are priced separately.

Sales call required

Yes, required for paid access

Free / trial

Demo on request; no public free tier

Key ambiguities

No public rate is disclosed, and the pricing basis, whether per identity, per environment, or platform tier, is not clear.

Agentic Index verified 2026-09-28

Alternatives to Token Security

The closest documented capability profiles to Token Security among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Astelia8.0 / 14Fuller documented coverage on Human Oversight & Guardrails and Security, Identity & Governance
  • Clutch Security6.0 / 14Adds documented Deployment & Data ResidencyToken Security vs Clutch Security →
  • Intezer7.0 / 14Adds documented Memory & State Persistence
  • Ocean5.0 / 14A lighter documented profile than Token Security
  • Pi6.0 / 14Adds documented Memory & State Persistence
  • Quantro Security7.0 / 14Fuller documented coverage on Human Oversight & Guardrails and Prebuilt Agents, Templates & Packs

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.