Token Security’s Approach to Agentic Identity
While the industry has spent decades mastering human identity and access management, the explosion of agentic AI has introduced a massive new blind spot for enterprise security. Token Security CEO and co-founder Itamar Apelblat sits down on Techstrong TV ahead of the RSA Innovation Sandbox to discuss how his company is solving the terrifying reality of autonomous agents operating with unchecked privileges. By mapping non-human identities directly to business applications and analyzing their intent, Token is providing the guardrails necessary for organizations to embrace the AI revolution without sacrificing control over their critical data.
Transcript
Hey everyone, welcome back here to Techstrong TV. You know, we're just, what? About two weeks out, maybe even less than two weeks, a week and a half out from our an- annual pilgrimage to San Francisco with the s- where the cybersecurity meets, the cybersecurity industry meets to talk cyber, RSA.
The RSA Conference is something I've been going to for 25 years. We put on every year our DevSecOps event there on Monday, and we'll be doing it this year again. This year it's on securing AI native dev, and it should be a good one.
And, and of course we'll be on Broadcast Alley all week streaming live. One of the other really I can't miss things at RSA every year has become the Innovation Sandbox. I think this is the 20 or 21st year for the Innovation Sandbox, and, you know, if you look at the roster, not just of the ones, the, the one company that wins every year, but if you look at the roster of the 10 finalists that get picked every year, I mean, it's a who's who of the security industry in, in terms of some of these companies.
I mean, just yesterday, Go- you know, Google announced, that the transaction with Wiz closed, and Wiz was one of the Sandbox finalists. I don't think they won. I think they were just a finalist.
Anyway, let me introduce you to one of the finalists from this year. He might, they might win, who knows? But certainly one of the finalists.
I want to introduce you to Itamar Appleblat. Uh, Itamar is the CEO and co-founder of Token Security. Itamar, welcome to Techstrong TV.
It's great to have you on here. My pleasure. So we're gonna talk about Token, but first let's talk about you.
Give us, give us your story, if you don't mind. All right. So, I founded the company together with Ido, my co-founder, and he's the CTO of the company, two and a half years ago.
Uh, we are old, old friends, so I know him from six- for 16 years. So we both joined the military servers, service together. We both served in the 8200 unit, and from the first day he literally taught me how to tie my army boots.
So we are really good friends. Uh, I grew up in Tel Aviv and started my career in cybersecurity when I was 18, so 16 years ago, and, and loved it ever since. So I joined the team that was in charge of securing the infrastructure and the data of the unit, and that was such an exciting thing to do back in the days because back in 2009, we'd seen what we could have done, and then, we understand there's so many threats that this unit, is being targeted by literally nations, right?
So- Sure ... so I learned so, so much during this time. And, and the CISO of the unit, he was my, my commander, so I had to do whatever he told me to do by law, basically.
Uh, and we grew very fast. So from a team of 20, 20 engineers, we became 200. So I grew up with that team and became an R&D group leader, so led few R&D teams, building...
Basically, I had unlimited resources to solve whatever problem I cared about in the cyberspace, and there were some really complex issues, and a lot of them was in the space of identity. So, I have a lot of passion to what we're doing here in Token Security. Um, and yeah, then so I did that for 10 years, then founded my own startup, had some success with it.
It was in the fintech space. Uh, and we founded Token about two and a half years ago, and about a year ago, I moved to New York. So I survived my first winter here.
Congratulations on that. Spring is coming. Well, first you're gonna get through April.
You know what they say in New York, April showers bring May flowers. It rains a lot. It rains a lot in April, but it's all good.
At least it's not snow. Um, good for you. So is your co-founder also in New York, or?
No, so he's in Tel Aviv. So, our entire engineering and product is in, in Tel Aviv, and our go-to market functions are in, in the US spread across the entire state. Excellent.
Very cool. So talk to our... It- Itamar, it's a great story.
You know, I have a lot of friends from Israeli cybersecurity companies. No surprise. And, you know, this is sort of a common path we see, right?
They go into 8200, some are doing offensive work, some are purely defense. I mean, I- You're the first person I've spoken to who actually had to defend the unit, right? Um, but an interesting, an interesting way to really learn, right?
Right? F- I mean, talk about getting thrown into the middle of it. Yeah, exactly.
So we, Ido and I is really the yin and yang of the unit. So he was in the offensive, and he became branch commander, so he was leading hundreds of security researchers. Uh, and he also saw that identity's usually the easiest path in, right?
So, we both came from a different direction, and I think that my experience as someone that building security products from such an early age was understanding that there's so many risk that the organization and the CISO need to, to f- to face, right? And it's all about prioritization and how to become a business enabler, 'cause there's no organization in the world that their job is to protect themselves, right? There's always a bigger outcome than that.
So learned a lot during this time. I'm sure. Uh, there's no doubt.
Let's, let's talk a little bit about identity, right? So I've always felt if cloud security had a killer app, it was IAD, right? Identity and, you know, access control.
IAC, excuse me. IAC. Um, but identity, you, you know, as things get more complicated or sophisticated, so do our i- our identity issues become more complicated and sophisticated.
So, you know, when we first started with cloud security, it was, identity was about human identity, people's identity. Cloud native, containerization, kube, all of these things, and all of a sudden we started worrying about the identity of virtual machines, the ide- identity of containers, the identity of non-human assets. Then we had APIs, right?
All of a sudden now API security became, you know, the hot, hot thing. We gotta kind of... we gotta understand what APIs we have out there.
Are they locked down? What's their configuration? We, we almost needed to have sort of an identity of API sort of thing.
Now, of course, the, the rage is AI, agents, agentic AI. They also need to have identities. We, we see it here at TekStrong with my own people experimenting.
Talk to us about how that kind of progression of identity has manifested into token security. Yeah. So actually a funny story.
When we, when we started the company, we saw that identity is, is pretty much broken 'cause we saw so many identity solutions that are focused, that are human-centric, right? Right. And there are some amazing leaders that are solving this problem and haven't really changed in the past 20, 30 years.
Um, but then as you shared, there's so many new innovations, and we see that the robust, the largest amount of identities are tho- those non-human. And the funny story was that I was actually called back for reserve duty in the unit that I was serving at, and they gave me this, you know, third-party contractor account, and I was starting to do my job, and then I tried to log into a system, and I couldn't. So I asked for permissions, right?
It's, it's super bureaucratic. I, I waited and waited, literally, you know, sitting in my chair, getting paid from the taxpayers to do nothing. So I was super frustrated.
And then I tried to log in through a service account that I created back in the day, six years before. Um, 'cause I remember the password. It, it was a funny password.
You know, we were young, young, soldiers back then. So tried to log in, and all of a sudden I was an admin in one of the most secure networks in the entire world, right? Oh my God.
Oh, oh my God. Then I asked my friends, "Why they didn't change the password? " Why didn't they just kill your account?
Yeah. Yeah. And they, and then they said they were scared.
They didn't know who's using that, that service, who, who's using this user, which applications are depend on that. " Then there was a new transition that happened in the world, and that's that right now every organization is racing to adopt AI, right? And very early on, we understand that adopting AI, the promise of it is not just a chatbot that answering questions, right?
It's, it's agentic AI. It's agents that take actions, that, that, that, write software, that, solve problems, right? So we were, we were trying to understand, okay, what's the risk over there?
And very early on, you understand that the agent risk is based on the level of access that they have into your business application and the level of autonomy. And I think this is a new class of identity we have to secure because it's a- it's all about the identity. So about two years ago, we, we, started to tackle this agent identity space that, that grew very fast, and we're seeing our organization having so many challenges on even knowing about those identities and then understanding the owners and which applications are connected.
So yeah, I'm very excited about it, and what I love about it is that adoption of AI is, is a must now, and AI agents is, is such an exciting technology, and we live in such an exciting time, and it's, it's great to be part of, a solution that helps organization to actually adopt it in a secure way, right? So I- Mm-hmm ... I, I have a lot of passion about that.
As you should, right? I've never met a successful founder, co-founder who doesn't have passion about what they do. They don't have passion.
So, you know, I was talking to a friend of mine, called me this morning. He's, he's a, a money manager, financial, you know, planner, asking me a question about AI and, and how real it is and whether I'm using it, he... whatsoever.
And I told him, you know, I live in a world where I don't m- I, what I used to measure in months and years, I measure in hours and days. Right? It's just crazy.
I, I thought what we went through in November and December was earth-shattering. Like, stuff got real in around November, December, the latest iterations that came out of AI that... But then the whole OpenClaw thing and the agentics, the last month, f- I feel like we did five years in the last month.
Um, it's gotta be... I am imagine from where you sit, it's a very similar thing, right? You, okay, I mean, the mission hasn't changed.
You still want to lock down identities, right? You still wanna make identity control, you know, feasible, doable, simple as possible. But it's just, you know, what, what's going on in the world is, it's gotta be, I don't know if it's terrifying, exhilarating, a little of both.
I think it, it, it is a, a little of both. Every CISO that I'm, I'm speaking with is sharing that their board, their CIO, CTOs are really right now pushing AI 'cause they see how fast you can innovate, you can, you can excel, solve problems. But many don't understand exactly what does that mean and how does it look in a good end in a, in an enterprise in a secure way.
So, I'm, I, I completely agree with that. And when you think about agent and agent identity, it's, it's a new class of identities, right? It, you, we cannot treat it as our human employees or even our, as our machines because it's a mix of both.
It has, the flexibility of being unpredictable, it's non-deterministic, it, right? It doesn't follow, follow any script, but it's taking it in a much greater action and scale, li- just like service accounts and machines i- identities. So it's, it's, it's an interesting mesh.
And what we understand is that in order to secure this new, new type of identity, you really need to understand the purpose, the intent of the agent, right? Mm-hmm. Uh, once you understand what this agent meant to do, what those actions are actually, what's the reason for those actions, then you can start to restrict their access, manage their life cycle, enforce your policies.
Um, today, it, it's, it's a bit tough to even, to organization to understand what, how organization adopting AI, but that will be the next, step, is understanding also the actual use case of those agents, and then create a much more tailor-made experience and security processes for that. Got it. Got it.
Um, let, let's get, if you don't mind, Itamar, I, I want to dig a little deeper into Token itself, into Token Security itself. And what a great name, right? For, for a company that's working on AI, agent, identity risk, Token's a good name.
It's a good choice there. Um, how are you doing this? Like, let's, you know, our audience is a technical audience.
How are you doing this? Yeah. So we basically, because we understand that agents are, the risk of an agent is based on the level of access they have and to which business applications.
So basically, our philosophy was, first of all, we don't want to create latency or stop the organization from adopting AI or create friction. So we are creating a seamless experience by just integrating to both sides. So we have integrations into your business critical applications, over hundreds of different integrations, where we map all the identities that can interact with those resources.
And on the other hand, we have integration to all of those AI applications where the agencies are running from, whether it's locally in your, in your own computer or through different SaaS applications or different engines. And then we connect the two. We look at the agents and their activity configurations, skills, ownership, and also look at what the actions are they doing and where.
Once you connect those two, 'cause this is a data problem, then you can start to analyze the intent of the agent and enforce your policy. So, for example, if you want using Token, you can say, "Hey, I wanted OpenClaw will only run in this department. Any other installation, I don't want it to, to, I don't want it to have it.
" Today, you can, you can't do that. You don't know which OpenClaw instances you have. You don't know what they're connected to, what's their mission.
So with Token, you can do that by us connecting to those two sides of the interactions. Mm-hmm. Excellent.
Excellent. Um, you know, I wish we could show people, but we, this isn't set up for that kind of demo. Itamar, we're almo- we're probably over time already, and I, I, I, I don't want to ignore the whole sandbox thing.
We got to mention it, right? Token is one of the 10 finalists this year for the Innovation Sandbox. Uh, you know, the last couple years things have changed, right?
Now you've got basically they put aside about $50 million in venture capital, 5 million per finalist, you know, available to you for being chosen one of the 10. Talk about what it was like applying and then making it to the finals. Yeah.
Yeah. Um-The, the application wasn't easy. Uh, we were ...
We, we got ready, we, we, we worked really well on the presentation, created videos, and when, when we heard the news, I remember, Christian and Ross from... Who were leading our marketing team, were like, you know, like trying to look again, try to understand if it's us or not, 'cause this is probably one of the most iconic, events- Events ... in, in cybersecurity and in, probably in- in the entire startup, ecosystem.
So we were so honored to be part of it. And I remember me going to RSA, my first RSA, and looking on people in the stage, and this is a, a great, a great group to be a part of. Yeah.
It is. You're in, you're in, uh... What's the word I'm looking for?
You're in, like, very high, high, company, right? Very distinguished company. Yeah.
Good for you. And then, of course, the Innovation Sandbox, on Monday of RSA Week, I, I wanna say it's the 22nd, May, March 22nd, I think is that Monday, on the second floor there, they'll... You'll be presenting to a panel of, of VCs and, and dignitaries, and then of course the winner will be announced.
Um, you know what we didn't mention, Itamar? What's the website for Token Security? security.
Excellent. Yeah. Excellent.
Hey, I wish you the best of luck going into, into the Sandbox, but you know what they say, like, in the Miss America Pageant, "You're all winners already. You made the finalists. You already won.
" So congratulations on what you've built and what you're doing. Continued success. We will be, we'll be live all week there.
Well, Monday we put on our event, actually right in the room above you, on the third floor. And, but the rest of the week we're there on Broadcast Alley doing videos. Come by and say hello.
Awesome. Looking forward to it. And also come to our booth and, check it out.
I'll be honest, I, I do one quick pass of that floor and get the hell out of there. It's so overwhelming. I- I know.
You know what? I, I camp out by my, my Broadcast Alley booth there and people come talk to me. It's too much.
And the other thing is, it, it takes me... I mean, like, I'm going to RSA 25 years. It takes me a long time- Yeah ...
to say hello to everyone and get around that floor. But, anyway, again, congratulations. Best of luck with Token.
Thank you so much. This sounds like something we need, so good, good, good job there, man. All righty.
Appreciate it. Thank you. It- Thank you.
Itamar Appleblat, CEO, co-founder of Token Security, one of this year's Innovation Sandbox finalists here on Techstrong TV. We're gonna take a break. We'll be back.