Interviews

Micha Rave, CEO and Co-Founder of Hush Security – Interview Series

mm
Add Unite.AI to your preferred sources on Google

Micha Rave, CEO and co-founder of Hush Security, is an experienced cybersecurity and technology executive whose career spans software engineering, product management, enterprise networking, cloud security, and identity. Before co-founding Hush Security in 2024, he spent more than five years at Proofpoint as Senior Director of Product Management for Cloud Security, where he was responsible for its Zero Trust Network Access (ZTNA) and Secure Web Gateway (SWG) product lines. He previously served as VP of Product Management at Meta Networks, focusing on enterprise networking and security, and held product and engineering leadership roles at HARMAN International, Redbend, SanDisk, Hola, Jungo, and Elbit Systems. His background combines hands-on software development with more than two decades of experience building and commercializing security, networking, virtualization, and embedded technology products.

Hush Security is a cybersecurity company focused on securing AI agents and other non-human identities by replacing long-lived credentials and static secrets with identity-based, policy-controlled access. Its platform discovers AI agents, including shadow and internally developed agents, assigns them verifiable identities, and governs their interactions with enterprise systems using scoped, just-in-time permissions, centralized policies, and auditable activity records. The company was founded by security veterans from the team behind Meta Networks, which Proofpoint acquired in 2019. In July 2026, Hush raised a $30 million Series A with Akamai Technologies joining as a strategic investor alongside Battery Ventures and YL Ventures, bringing total funding to $41 million as the company expands its technology for governing enterprise AI agents and non-human infrastructure.

Before founding Hush Security, you spent years building and leading security products, including cloud security at Proofpoint. What did you see in the market that convinced you there was a need to start Hush, and how has that original thesis evolved with the rapid rise of agentic AI?

At Proofpoint we watched enterprises solve human identity while everything non-human still ran on static secrets. Service accounts, workloads, pipelines, all authenticating with keys nobody owned, nobody expired. The industry answered with better vaults. That’s a better safe, not a solution.

The founding thesis was to move non-human access from secrets to identity. Verifiable workload identity, short-lived credentials issued just in time, policy enforced inline. No code rewrites.

Agentic AI made that urgent. An agent is an NHI that reasons and decides at runtime which tools to call. Hand it a static key and you’ve given autonomous software standing access to production, and agents ship outside any change process, a developer wires an MCP server on Tuesday and it’s touching customer data by Friday.

The thesis didn’t change. The scope did. Identity-based access was the right answer for workloads. For agents it’s the only workable one: know every agent that exists, give each one least agency by default, and audit every action. Humans got an IdP. Agents need one too and that’s Hush.

Hush argues that enterprise AI agents should have their own identities and delegated permissions rather than simply inheriting the access rights of the humans using them. Why do traditional Identity and Access Management (IAM) systems struggle with autonomous agents, and what needs to change?

The obvious case is an agent acting for a user. The harder case is an agent with no user at all: a scheduled job, an autonomous SOC responder, a pipeline that reasons and acts on its own. There’s no one to delegate from, so teams fall back on the only tool they have, a static service account with broad permissions and a key that never expires. That’s the same shared-secret model that’s been breaking for a decade, now attached to software that improvises.

The systems on the other end make it worse. Most internal APIs, databases, and MCP servers don’t do real authorization. They check whether you hold a valid token, not what you’re allowed to do with it. Possession equals permission.

What needs to change: every agent gets its own identity, issued cryptographically, whether or not a human is behind it. Access is granted per action, short-lived and scoped, with policy enforced inline rather than trusted to the target system. When there is a user, the agent’s permissions are the intersection of what the user can do and what that agent is allowed to do for that task. When there isn’t, the agent’s own identity and policy are the whole story. Humans got least privilege. Agents need least agency.

You use the concept of “least agency” when discussing AI security. How does least agency differ from the traditional cybersecurity principle of least privilege, and how can organizations determine exactly what an AI agent should be allowed to do for a particular task?

Agents don’t have fixed behavior. Give one read access to a CRM and write access to email and you haven’t granted two permissions, you’ve granted every path between them. Least privilege bounds what an agent can touch. It says nothing about what it should do with it.

Least agency adds the missing dimension: which actions, for which task, right now. An agent triaging tickets needs to read and comment. It doesn’t need to close, delete, or touch billing, even if the token allows it. When the task ends, the access ends.

Deciding what’s allowed starts with observation, not guesswork. Run the agent, watch what it actually calls, and let that define the baseline. Then narrow using three inputs: the task it exists to do, the user it acts for (never more than they could do), and the blast radius of each action, because posting a comment and wiring a payment shouldn’t share an approval path.

Least privilege decided who gets the keys. Least agency decides what they can do once inside.

We often “lend” our identity to our agent, but we do not want the agent to have the same level of permissions we have – this is the definition of least agency.

Hush recently raised a $30 million Series A, bringing total funding to $41 million, with Akamai joining as a strategic investor alongside Battery Ventures and YL Ventures. What does Akamai’s involvement bring beyond capital, and how do you expect the partnership to influence Hush’s expansion into enterprise AI-agent security?

Akamai sits in the traffic path of most of the world’s enterprises, and that’s exactly where agent security has to live. You don’t govern an agent from a dashboard after the fact. You govern it inline, at the moment it calls a tool or API. Akamai built its business on that model.

Beyond capital, they bring three things: Distribution to CISOs already asking how to control agents and MCP traffic; validation that agent identity is a real category, not a feature; and decades of experience securing machine-to-machine traffic at global scale, which is what agent-to-tool traffic is about to become.

Model Context Protocol (MCP) is quickly becoming an important layer for connecting AI agents with tools and enterprise data. From a security perspective, what new risks does MCP introduce, and how should organizations think about identity and authorization between the agent, the MCP server, and the underlying resource?

MCP made connecting an agent to a tool trivial. That’s the risk. A developer adds a server to a config file and the model can now read Jira, query a database, or send email. No review, no inventory, no policy. Security finds out when something breaks.

There are three new problems now:

  1. Shadow MCP – nobody knows how many servers are running or what they touch.
  2. Credential sprawl – most servers authenticate with a static token that grants the whole surface, so the agent gets everything the token can do.
  3. The collapsed chain – the resource only sees the MCP server’s credential, so it can’t tell which agent, acting for which user, made the call. Identity needs to be at the base of every interaction, access should be ephemeral, scoped and based on agent and user permissions.

Hush was originally built around the idea that static secrets and long-lived credentials are a broken foundation for machine access. Since most enterprise infrastructure still relies heavily on API keys, tokens, and other secrets, how can companies realistically move toward identity-based, short-lived access without rebuilding their entire technology stack?

You don’t rebuild. Nobody who says otherwise has met an enterprise. Most of what we protect predates the phrase non-human identity, and it isn’t getting rewritten.

So we don’t ask for it. Hush deploys without code changes and sits in the access path. Step one is discovery: every secret, who’s using it, what it reaches, what it actually does at runtime. Most companies have never seen that picture.

Then it’s a journey, not a migration. Discovery shows which secrets are dead, over-scoped, or highest risk. Fix those first. Then swap static keys for short-lived, identity-issued credentials one system at a time. The app still thinks it’s using a key. The key just stops being long-lived, and the policy moves to us.

The same model covers a fifteen-year-old Java service and an MCP server stood up last week. Start where the risk is, prove it, keep going.

AI agents will increasingly work on behalf of humans and, in many cases, delegate tasks to other agents. As these multi-agent workflows become more complex, how do you maintain a clear chain of identity, authorization, ownership, and accountability for every action that takes place?

The failure mode: a user asks an orchestrator, it delegates to a second agent, which calls a tool through an MCP server, which hits a database with a service account. Four hops later the log shows one thing, a valid token. Who asked, who decided, and who’s responsible are gone.

The fix is refusing to let identity collapse at any hop. Every agent has its own cryptographic identity. When it delegates, it doesn’t hand over its token. It issues a scoped delegation: this sub-agent, this task, these actions, on behalf of this user. Each hop carries the full chain, and its own permissions.

Accountability comes from enforcing and logging inline, at the point of action. The gateway’s record of what it was allowed to do, what it called, and the chain behind it.

Multi-agent systems will get harder to reason about. The chain of custody for each action doesn’t have to.

Prompt injection and other attacks can potentially manipulate an otherwise legitimate AI agent into taking actions its operator never intended. To what extent can identity-based access controls limit the damage from a compromised or manipulated agent, even when the underlying AI model behaves incorrectly?

You won’t stop prompt injection at the model. Models read untrusted content by design. Assume the agent will eventually be talked into something wrong. The question is what it can do when that happens.

Identity-based access bounds the blast radius. A manipulated agent with least agency can only misuse the actions it was granted for that task. If it can read tickets and post comments, no injection makes it exfiltrate the customer database. The token doesn’t have the reach.

User attribution keeps the chain intact: which user, which agent, which task, on every call. The agent never exceeds what the user could do, and every action traces back.

Anomaly detection catches what policy allows but intent didn’t. An agent that normally reads five records and suddenly pulls five thousand is out of character even if each call is authorized. Because the gateway sits inline and knows the baseline, it can flag or block that in real time.

The model will be wrong sometimes. Scoped identity, attribution, and behavioral baselines make wrong survivable.

Hush is primarily focused on securing AI, but how are you using AI within Hush itself? Are there areas such as discovering non-human identities, analyzing access patterns, prioritizing risk, or enforcing policies where AI can materially improve the security platform?

We use it wherever it earns its place.

In the product, the hard part isn’t finding secrets, it’s understanding them. A key shows up in traffic. Workload identity, vendor integration, dev test token, dead credential? An LLM reads the runtime context and owner signals and proposes an answer with a confidence score. It summarizes what an identity actually does in plain human language, so the policy is one a human will approve. It ranks risk by real reach and blast radius, not static severity. Enforcement stays deterministic. AI helps write the policy – it doesn’t get a vote at runtime.

Inside Hush, agentic programming changed our clock. Features that took a sprint take days, and we ship integrations at a pace a Series A team couldn’t otherwise afford. LLMs triage support tickets, cluster root causes, and surface customer requests for roadmap discussions. Our own MCP gateway sits in front of all of it, helping our customers reason and consume NHI and agentic risk.

Hush says multiple Fortune 500 companies are now using its technology, while Kyndryl has deployed Hush internally and begun reselling it to enterprise clients. What are you learning from these large-scale deployments about the real-world governance problems companies encounter once AI agents move from experimentation into production? 

Nobody knows what they have. Every large deployment starts the same way: security thinks there are a dozen agents in production, discovery finds hundreds, already touching customer data. The governance problem isn’t policy, it’s inventory first.

The credentials are worse than the agents. Almost every production agent runs on a static service account that predates it, with permissions accumulated over years for something else. It didn’t get scoped access.

Ownership is missing. Ask who’s accountable for an agent, or a NHI and you get a team name at best, a departed contractor, or silence.

And the buyer changed. This was a platform team problem. Now the CISO owns it because the board is asking. That moved us from pilots to enterprise rollouts, and it’s why Kyndryl deployed internally before reselling.

Agents didn’t create new governance problems. They took the ones enterprises ignored for a decade with service accounts and made them much worse.

Thank you for the great interview, readers who wish to learn more should visit Hush Security.

Antoine is a visionary leader and founding partner of Unite.AI, driven by an unwavering passion for shaping and promoting the future of AI and robotics. A serial entrepreneur, he believes that AI will be as disruptive to society as electricity, and is often caught raving about the potential of disruptive technologies and AGI.

As a futurist, he is dedicated to exploring how these innovations will shape our world. In addition, he is the founder of Securities.io, a platform focused on investing in cutting-edge technologies that are redefining the future and reshaping entire sectors.