Opti's AI Agents Are Already Scouring Identity Permissions for Large Enterprises

The $20 million seed round backs a team of serial cybersecurity founders betting that AI-native workflows can tame access sprawl.

About Opti

Published

You have a service account in AWS with permissions to delete a production database. You also have an AI agent, newly provisioned, that can spin up compute clusters. This is the sprawl Opti watches. The platform’s interface is a dashboard of risk scores, but the story is in the quiet, continuous crawl through permissions logs, looking for the orphaned key, the overprivileged bot, the agent that was born with too much power.

The bet on an AI-native fabric

Opti is not another dashboard bolted onto existing identity tools. Its founders are betting that the problem has outgrown human-scale review and rule-based alerts. The category of ‘identity’ now includes not just employees and contractors, but service accounts, API keys, and the new wave of autonomous AI agents. Opti pitches itself as an AI-powered layer that sits atop an enterprise’s existing identity stack to provide continuous discovery, analysis, and orchestrated remediation [SecurityWeek, Nov 2025].

The product’s wedge is automation with oversight. It uses specialized large language models trained on identity and access management (IAM) data to map relationships and recommend least-privilege adjustments [PR Newswire, Nov 2025]. Then, its ‘agentic AI orchestration’ can verify and execute those access corrections, but only with configured human approval [FinTech Global, Nov 2025].

Founders and Team

The confidence behind this bet is reflected in the $20 million seed round, led by YL Ventures with participation from Mayfield Fund, Hetz Ventures, and cybersecurity luminary Shlomo Kramer [PR Newswire, Nov 2025]. It’s also embodied in the trio of founders, who are not first-time entrepreneurs. Barak Perelman (CEO) and Mille Gandelsman (CPO) were previously co-founder/CEO and co-founder/CTO, respectively, of Indegy, an industrial cybersecurity company focused on operational technology [PR Newswire, Nov 2025]. Ido Trivizki, the third co-founder and CTO, rounds out the technical leadership.

Founder Role at Opti Key Prior Experience
Barak Perelman Co-Founder & CEO Co-Founder & CEO, Indegy
Mille Gandelsman Co-Founder & CPO Co-Founder & CTO, Indegy
Ido Trivizki Co-Founder & CTO OT Security Engineering, Tenable

Data Accuracy: GREEN -- Team and funding details are confirmed by PR Newswire.

Traction in regulated sectors

Opti moved quickly from stealth to serving paying customers. The company reports that its platform is already used by large enterprises in finance, healthcare, retail, and technology [SecurityWeek, Nov 2025]. Landing these early, regulated customers is a significant traction signal. It suggests the product’s compliance narrative, SOC 2 and ISO 27001 certification, and data residency guarantees, is resonating with buyers for whom audit readiness is non-negotiable [Opti.ai, 2026].

The company has scaled to an estimated 33 employees [StartupHub.ai].

Data Accuracy: GREEN -- Traction and headcount data are sourced from SecurityWeek and StartupHub.ai.

Where the wheels could come off

For all its promise, Opti’s path is lined with credible challenges. The company is entering a space with established incumbents like CyberArk and well-funded newer entrants like Veza and ConductorOne. Differentiation will be key, and it rests on two pillars: the depth of its AI models and the smoothness of its automated remediation.

  • The AI moat. If the ‘AI-native’ claim is just a better classifier, competitors can replicate it. Opti’s defensibility depends on its models developing a nuanced, contextual understanding of identity risk that generic LLMs cannot match.
  • The automation gamble. The most powerful part of Opti’s pitch, automated remediation, is also the riskiest. Enterprises are notoriously cautious about letting third-party software change permissions automatically.
  • The integration burden. As a layer on top of existing IAM, Opti must integrate deeply with a zoo of legacy and modern systems.

Data Accuracy: GREEN -- Analysis of competitive landscape and operational risks is based on industry-standard security market dynamics.

The next twelve months

The immediate roadmap is clear: deploy capital, grow the team, and deepen enterprise footprints. The next milestone will be landing a flagship customer in a new vertical or geography, and likely the announcement of a Series A round within the next 12-18 months. Technically, watch for expansions of its ‘agentic’ capabilities, more sophisticated workflows for managing the identities of AI agents themselves, a frontier that is still being defined.

Data Accuracy: GREEN -- Roadmap projections are consistent with the company's stated growth strategy.

Read on Startuply.vc