Blog

Three Things That Excite Me About Dawn

3 reasons I believe Dawn Security needed to exist: the problem is real and getting worse, the way we answer it is unlike anything else in the security stack, and the technology that makes that answer possible

3 Things About Dawn Security You Should Know

Today, Dawn steps out of the dark into the light. After more than a year of building quietly alongside design partners, and more than a decade before, building security products at Check Point, Microsoft and Deep Instinct, I finally get to say out loud what we have been working on.

There is a lot I could write about on a day like this: the team we assembled, the customers who trusted us before we had a working product, the investors who backed a thesis before there was a working demo. But I want to write about the product. Specifically, about the three things that excite me most about what Dawn does and why it is special.

Not three features. Three reasons I believe this company needed to exist: the problem is real and getting worse, the way we answer it is unlike anything else in the security stack, and the technology that makes that answer possible only became feasible in the last few years.

1. We are solving a problem every CISO already feels

Most breaches don't break in. They walk in. Attackers operate through valid credentials, trusted identity flows and approved SaaS integrations, moving through authorized pathways while blending into normal activity. Access that was permitted, but never intended.

That activity describes a wall I kept hitting for more than a decade. Identity tools, IAM and IGA, tell you who can reach data. Data tools, DSPM and DLP, tell you what is sensitive. Neither can tell you whether the access that actually happened was intended and legitimate. Authorization is a snapshot of intent taken months or years before the access occurs, and once the grant is made, nobody is watching what those identities actually do or which data they consume. The result is an enterprise that is simultaneously over-permissioned, under-protected and out of compliance, without knowing it.

For years, security teams lived with this gap because the math was still manageable. It no longer is. Three exponential curves now intersect on top of a permission model designed for employees and file shares. Data: IDC projected the global datasphere at roughly 181 zettabytes by 2025, nearly triple the 2020 figure. Identities: CyberArk's Identity Security Landscape puts machine identities at more than 80 for every human employee, up from roughly 45:1 a year earlier. And AI agents: Gartner projects that by 2028 a third of enterprise software will embed agentic AI, up from less than 1% in 2024. Every one of those agents is a new identity that authenticates, inherits permissions and consumes data at machine speed.

In practice, this shows up as four forces the security leaders we work with recognize immediately: entitlement sprawl, where human and machine identities accumulate far more access than their roles require; credential misuse, where valid credentials make illegitimate activity look like normal work; agentic access sprawl, where AI agents multiply access paths across tools, services and data through permissions and MCP connections; and shadow AI, where unmonitored agentic identities reach data outside the organization's visibility.

What excites me here is not the size of the problem. It is that we never have to convince anyone it exists. In our conversations with design partners, the CISO finishes the sentence for us. Ask a security leader today, "Which financial files did your executive team touch last quarter, and which agents touched them too?" and the honest answer is that no tool in their stack can tell them. That is a real pain, felt weekly, with budget and regulatory consequences attached. It is the best kind of problem to build a company around.

2. Dawn answers the one question no other tool is built to answer

Authentication asks who you are. Authorization asks what you are allowed to do. Dawn asks the question that has never been answered at scale: should this access be happening at all? We call that layer post-authorization access legitimacy, and it is the layer missing from every security stack I have ever worked on.

The reason it is missing is structural, not a lack of effort. Identity security understands the "who." Data security understands the "what." They operate in silos, and the intent and legitimacy of the access between them belongs to no one. IGA and IAM govern who can access systems, not which data was actually used or whether the access still reflects a business need. ITDR and UEBA detect unusual behavior, but without data context they create noise and miss illegitimate activity that looks perfectly normal. DSPM classifies sensitive data but has no behavioral profile of the identities using it. DLP reports the problem too late, relying on static policies and content patterns. AI governance tools inventory agents and models, but rarely trace access from the prompt, through MCP, to the specific service and data reached.

Dawn is the Access Intelligence Platform: one platform spanning Identity Security, Data Security, AI Governance and Compliance that unites identity, data and intent to determine whether every access was intended and legitimate, not merely permitted. Identity + Data + Intent = Legitimacy. Within 24 hours of deployment, Dawn delivers four things: Access Discovery, so you know where your data is, what it is in your business context, and every identity that touched it; Post-Authorization Legitimacy, so you know whether that access was intended and legitimate; Agentic Access Intelligence, so you can trace AI access from prompt through MCP to the service and data reached and expose out-of-scope behavior; and Actionability, so every risk arrives decision-ready with a recommended action and an audit-ready evidence trail.

Three aspects of that value proposition make me proudest as a product leader.

First, there are no rules. No policies to author, tune or let rot. Anyone who has run a DLP or IGA program knows that the policy is where good intentions go to die: months spent writing rules and labeling files, and the result is static and blind to meaning the day it ships. Dawn learns an organization-specific taxonomy from the content itself.

Second, Dawn is deliberately agnostic to what kind of identity it is looking at. A human user, a service account and an AI agent are all identities with a profile and a purpose. That is why the same platform that right-sizes an employee's entitlements can also follow an agent from the prompt it received to the data it actually consumed, and flag the moment it steps outside its intended scope.

Third, time to value. Years of access history, answers in 24 hours. The service account still reading the M&A folder, the agent running on a departed employee's credentials, the quiet oversharing that leaks data every day: surfaced in hours and ruled on in seconds, with the evidence your auditors will ask for already attached. For the buyer, the outcome is simple. Move fast with AI without losing control of access. Authorized is not the same as legitimate, and Dawn is the first platform built around that distinction.

3. The technology is a different model, not a better baseline

The security industry's answer to complexity has been behavioral analytics: learn a baseline of normal, then flag deviations. It sounds reasonable, and I have shipped products built on it. In practice it fails in two structural ways. It is reactive, because the system waits for an identity to consume data before scoring it, and by the time the anomaly is scored the data is already gone. And it drowns defenders in false positives, because in a modern enterprise almost everything is unusual. New agents, new integrations and new datasets appear daily, so legitimate work constantly looks anomalous, while sophisticated attackers deliberately look normal. The deepest flaw is philosophical: unusual is not the same as illegitimate, and usual is not the same as safe. An adversary using valid credentials inside an approved SaaS integration is, by definition, behaving normally.

Dawn reasons from necessity instead of from baselines. Rather than asking "does this look like the past?", it asks "does this access make sense at all?" That question can be asked ahead of consumption, so when the nature of a data asset changes, whether new content, new sensitivity or a new business purpose, the system reasons about whether access should be happening, by whom, and why. Protection moves upstream of the breach instead of trailing behind it.

The mechanics are what get me out of bed. Every access event is contextualized as an interaction between two things. On one side is an identity, defined by an access profile: its function, its purpose, the nature of its work. On the other is a data asset, defined by a data profile: what the data is, what it is for, and who genuinely needs it. Legitimacy becomes a question of alignment. Access is legitimate only if the attributes of the access profile align with the attributes of the targeted data. A mismatch is not merely an anomaly; it is a strong, explainable signal of a potential data breach, and every finding carries that explanation with it.

Under the hood, Dawn deploys across a customer's SaaS, identity and AI stack within 24 hours and immediately reconstructs up to a year of access history, at the scale of tens of terabytes and thousands of identities. From that history, together with the content itself, our engine continuously classifies data, clusters identities and data into a living graph, and produces legitimacy judgments. The taxonomy is organization-specific and learned from the content, so there is no labeling project to run first and no rule set to maintain later.

I am careful with the phrase "AI-driven," because in security it has become a decoration. So let me be specific about the job the AI does at Dawn. Building rich access and data profiles is a hard problem. Reliably assessing whether they align is harder still. Recent advances in AI have made that reasoning tractable for the first time, at enterprise scale, without a human writing the rules. That is the unlock Dawn is built on, and it is why this company could not have existed five years ago. A team of twelve, drawing on experience from Microsoft, AWS, Snowflake, Citi, Intuit, Bloomberg, Zscaler, Salesforce and Unit 8200, has built something that a much larger team could not have built with the previous generation of tools.

The first light

The perimeter dissolved years ago. Trust is the new attack surface, and the identities crossing it now include agents that no human reviews. Dawn exists to defend that surface, not by memorizing yesterday's behavior, but by reasoning about today's necessity.

We are coming to light with enterprise customers and design partners already running the platform, and  investments from some of the strongest names in the industry, including Brightmind Partners, The CrowdStrike Falcon Fund, Disruptive AI,  and Silver Tech. What excites me most is that the three things I have described here are not a roadmap. They are what the product does today, within 24 hours of deployment.

If you cannot answer the question "which identities and agents touched my most sensitive data last quarter, and should they have?", I would like to show you what the answer looks like.

They say it is always darkest before the dawn.
We are proud to shed the first light on how identities really use your data.

Learn more at dawnsecurity.io.

‍

Authorized ≠ Legitimate.

See the difference in your own environment, in 24 hours.