Start with Identity
ITDR

Above Security

Founded 2025Tel Aviv, IsraelPrivateScore 2.7/5Evaluated 2026-08-06Website ↗

Capability scores

Methodology →
Authentication
1.5
SSO & Federation
1.0
Authorization
3.5
Lifecycle & Provisioning
1.5
MFA & Passwordless
1.0
Governance & Audit
4.5
Developer Experience
3.5
Deployment Flexibility
2.5
Pricing Transparency
2.0
Support & Ecosystem
2.0

Scored 0–5 against a published rubric. Independent analysis, no vendor sponsorship.

Overview

Above Security is an AI-native insider risk platform founded in 2025 by two veterans of Israeli intelligence Unit 8200, built around what it calls the Arbiter Engine, a fleet of continuously reasoning AI agents that investigate insider risk rather than just flagging anomalies for a human analyst to triage. It raised $50 million in March 2026 (Ballistic Ventures, Merlin Ventures, Norwest) and, in August 2026, took a strategic investment from the CrowdStrike Falcon Fund alongside a Falcon platform integration.

What it is good at

The differentiator is investigation depth over alert volume. Specialized agents, covering shadow IT and SaaS sprawl, data exfiltration intent, flight-risk signals, and communications tone, correlate identity, application, endpoint, HR, and communications data into a single case with a behavioral timeline and stated reasoning behind each risk classification, rather than a stack of disconnected alerts a human has to piece together. Customers reportedly deploy without writing policies, rules, or configuration, a meaningfully lower setup cost than traditional UEBA tooling. The CrowdStrike integration extends this to Falcon Next-Gen SIEM telemetry, letting existing CrowdStrike customers add insider-risk investigation without a separate data pipeline.

Where it falls short

This is a young company: eight months from founding to its first funding round, and its enterprise deployments so far are recent. It has no published pricing, a small support organization by definition of its age, and no track record at the multi-year scale that insider-risk programs in regulated industries typically demand from a vendor. It is also narrowly scoped to insider risk and behavioral investigation, not a broader identity governance or authentication platform.

Pricing

Not published; demo-request, sales-led model typical of an early-stage enterprise security vendor.

Best for, and who should look elsewhere

Worth evaluating for enterprises that already have identity, endpoint, and SaaS telemetry but lack the analyst capacity to investigate insider-risk signals manually, particularly CrowdStrike Falcon customers who can add the integration directly. Look elsewhere if a proven multi-year track record and broad support ecosystem matter more than investigation quality, or if you need identity governance beyond insider-risk detection. See the ITDR vendor directory for established alternatives like Vectra AI and Gurucul.

Bottom line

A genuinely differentiated approach to insider risk, AI-investigated cases instead of raw alerts, backed by serious funding and now a major EDR vendor, but still early enough that buyers should weigh the investigation quality against the company's short operating history.

By SWI Community Team · Last evaluated 2026-08-06

Independent, community-driven analysis. No vendor sponsorship. Compiled from public research and community input and verified on a best-effort basis, so details may be incomplete or out of date. Scores are opinions, not advice. Trademarks belong to their owners; mention does not imply affiliation or endorsement. See the full disclaimer, or send corrections to [email protected].