Defakto Funding Highlights the Growing Market for Non-Human Identity Security

Defakto’s reported $30.75 million funding round reflects growing investor attention on non-human identity security. The market is responding to a basic operational reality: enterprises now depend on vast numbers of service accounts, API credentials, workload identities and autonomous agents, while governance processes remain heavily oriented around people.

The funding itself matters less than the problem it represents. Machine identities often outnumber human identities, have broad access and lack consistent ownership. As AI agents increase the number of identities that can make decisions, the cost of leaving that gap unresolved will rise.

Why the category is gaining urgency

Secrets sprawl is one visible symptom. Credentials are embedded in code, copied between environments or left active after a project ends. Other identities are created automatically by cloud platforms and never added to an access review. These principals can be difficult to identify because they do not always have a clean HR record, directory profile or obvious business owner.

AI agents add a behavioural dimension. A service account may perform a predictable task, but an agent can select a tool, change the sequence of operations and initiate downstream activity. Security teams need to govern both the identity and the authority it exercises at each moment.

A mature NHI security programme starts with discovery across infrastructure, cloud platforms, CI/CD pipelines, applications and data services. It then assigns ownership, classifies risk and maps each identity to the permissions and relationships that matter. That inventory must remain current as workloads are created and retired.

From inventory to enforcement

Visibility alone will not reduce exposure. Organisations need controls that rotate or replace long-lived secrets, issue credentials just in time and remove access when a workload no longer requires it. Policies should distinguish between read, write, administrative and data-export actions, then apply stronger checks to the highest-impact operations.

Governance also needs meaningful evidence. Reviews should show what a machine identity accessed, whether the activity matched its purpose and which person or process authorised the relationship. For Agentic Identity, that chain of accountability is essential to investigate misuse and demonstrate responsible deployment.

The funding trend suggests buyers will see more platforms promising to unify discovery, posture management and runtime enforcement. They should test whether those claims work across heterogeneous environments, whether ownership can be operationalised and whether controls support existing IAM workflows. The winners will make machine identity understandable to security teams without treating it as merely another secrets vault.