15 / Insider risk security
Above Security
One unusual action is a clue. The surrounding story is what gives it meaning.

Met with
- Jonathan Nativ · Global Head of Alliances
Connecting the events
Above Security focuses on insider risk. Its public product describes connecting activity across people, applications and data to build an investigation, rather than treating each event in isolation.
It also describes guidance inside everyday tools, helping employees choose a company-approved action while work is happening. The scope includes human activity and AI agents with access to company systems.
The technical question is context
Downloading a document can be ordinary work. The same download, followed by an unusual transfer, may deserve attention. I would test whether the product can connect those events without assuming the worst about the person.
Identity matching and time ordering matter. An investigation can become misleading if two accounts are joined incorrectly or an event appears in the wrong sequence. I would want the underlying evidence beside the explanation.
I would also test an innocent explanation. Can the system revise its assessment when new context appears? An AI-generated narrative should remain a hypothesis supported by evidence, rather than become a verdict about an employee’s intent.
The business model and moat
The buyer needs to understand meaningful risk without creating an unmanageable pile of alerts. I would measure time to a defensible decision, the quality of evidence and how often an investigation requires unnecessary follow-up.
The potential moat is a reliable way to connect events across systems, combined with useful investigation workflows. More data alone does not guarantee a better explanation. The product needs the right context and a way to handle uncertainty.
Privacy and access controls belong inside that moat. Security teams need enough information to act responsibly, with limits on who can inspect sensitive records and a record of their own access. Trust can be lost on either side of the investigation.
My take
I like the shift towards helping a team understand what happened and what to do next. The strongest direction would combine good evidence with proportionate action. That can make the product useful to security teams while respecting the people whose activity it examines.
Public financing
Above Security announced $50 million in funding on 23 March 2026, led by Ballistic Ventures, Merlin Ventures and Norwest, with participation from Jump Capital and QPV Ventures.
- Ballistic Ventures
- Merlin Ventures
- Norwest
- Jump Capital
- QPV Ventures
Gold marks my selection of established, tier-one VC backers. It is a personal classification.
There’s more to talk about.
Contact me to discuss Above Security and explore these ideas in more depth.
Talk to Matthias