Free tools Windows power users keep installed
One-click scans. No signup required.
Push Security announced a $30 million Series B on April 24, 2025, led by Redpoint Ventures. Datadog Ventures and B3 Capital joined as new investors, while existing backers Decibel and GV also participated. Push said it will use the financing for security research, product development, strategic hiring and international expansion.
The round is historical rather than a new 2026 funding event. It matters because Push is betting that the browser—where employees authenticate to cloud applications and active sessions can be hijacked—needs its own identity-security layer.
What Push Security raised
| Detail | Confirmed information |
|---|---|
| Announcement | April 24, 2025, from Boston, Massachusetts |
| Round | $30 million Series B |
| Lead investor | Redpoint Ventures |
| New investors | Datadog Ventures and B3 Capital |
| Existing investors participating | Decibel and GV, formerly Google Ventures |
| Stated use of proceeds | Research, platform and product development, hiring and global expansion |
The announcement does not disclose valuation, the percentage of the company sold, revenue, individual check sizes, the allocation among those uses, or whether any portion was secondary capital. Redpoint led the syndicate; the release does not establish that it supplied the entire $30 million. Push’s announcement and the Business Wire version provide the financing details.
Why the browser is an identity-security battleground
Cloud applications are commonly accessed in a browser, so a compromise may happen after a user has passed an identity provider. Attackers can steal credentials through cloned login pages, use adversary-in-the-middle or reverse-proxy phishing, capture session tokens, abuse OAuth consent, or exploit weak and reused passwords. Credential stuffing, malicious extensions, ClickFix copy-and-paste attacks and account takeover can likewise unfold in the live browser session.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
An identity provider can record an authentication decision, an endpoint agent can see processes on a device, and a secure web gateway can inspect network traffic. None necessarily has the same view of the page a user sees, the form being filled, a suspicious redirect, or behavior inside an authenticated SaaS session. Push’s thesis is that the browser is both a source of security telemetry and an enforcement point.
What Push Security’s browser agent does
Detection inside existing browsers
Push describes a browser extension or agent that operates in users’ existing browsers. It looks for signals such as cloned login pages, suspicious scripts, credential misuse, stolen-token behavior and other identity-risk patterns. The company also markets identity-posture checks, SaaS discovery, browser-extension security, AI-application visibility and controls for uploads, downloads and clipboard activity. Capabilities can change as the product develops; its product overview and interactive demonstrations show the current positioning.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Response and integrations
Depending on policy, the agent can monitor, warn or block. Security-relevant events can be sent to SIEM and SOAR tools and connected with Slack, Microsoft Teams, Tines, REST APIs and identity-provider workflows, according to Push’s public materials. A useful deployment therefore depends on what the security team does after an alert: revoke sessions, reset credentials, remove malicious OAuth grants, disable accounts and communicate with affected users.
Data handling claims
Push says routine browsing activity is normally kept local, while detection-triggered events are encrypted in transit and at rest and platform data is stored in the European Union. Those are vendor statements, not an independent audit finding. Buyers should verify what leaves the browser, retention, regional processing, analyst access and treatment of page content, screenshots, keystrokes, form fields and clipboard data in contractual and technical documentation. See the company’s pricing and security information.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsRank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Traction disclosed with the round
Push said its customer base grew 380% year over year in January 2025, that its platform was deployed on more than 1.5 million endpoints globally, and that headcount had more than doubled during the preceding year. It cited customers in technology, finance and healthcare and announced Kevin Arsenault as chief revenue officer, formerly a sales leader at CrowdStrike and Proofpoint. The Business Wire release also identifies Chris Tilton as chief marketing officer, with prior associations with Cobalt.io and Bugcrowd.
These are company-reported figures. Push did not publish the absolute customer count, retention, recurring revenue, endpoint definition or geographic breakdown, so the growth percentage and deployment total cannot be independently sized from the announcement.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What investors are betting on
Redpoint managing director Erica Brescia described the browser as a critical security perimeter. Datadog executive Bharat Sajnani highlighted Push’s research-led browser approach. Those comments explain the investors’ thesis; they are endorsements, not comparative efficacy tests.
The broader market case is that identity attacks increasingly use valid credentials, active sessions, OAuth permissions and user behavior rather than only malware. Browser telemetry may expose activity that an identity provider or network control misses, while an extension can be deployed without replacing the browser or re-architecting network traffic. That convenience must still be weighed against extension governance, privacy and coverage limits.
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Where Push fits beside existing controls
| Control | Primary strength | How it differs from Push |
|---|---|---|
| Phishing-resistant MFA | Prevents many fraudulent authentications through hardware-backed or device-bound methods | Push focuses on browser-session behavior and post-authentication activity; it does not replace MFA |
| Identity provider and ITDR | Authentication policy, access decisions and identity-risk response | Push adds page, session and SaaS context that may not appear in identity logs |
| EDR | Processes, files and device activity | Push observes browser activity rather than acting as a general endpoint agent |
| Secure web gateway or SSE | Network, URL, access and data controls | Push emphasizes what happens within the browser tab and authenticated session |
| Enterprise browser or remote browser isolation | Managed browsing environment or isolated execution | Push seeks to work with existing browsers through an agent |
| DLP and CASB | Data movement and SaaS governance | Push markets browser-level data and SaaS signals, but organizations should map overlapping policies |
Practical buyer checks and limitations
Coverage and deployment
- Confirm support for the organization’s browsers, including Chrome, Edge, Firefox, Safari, Brave, Opera and Arc where applicable.
- Test installation through MDM, browser management, direct installation, email enrollment and self-enrollment.
- Clarify whether BYOD and unmanaged-device coverage has the same enforcement and telemetry as managed endpoints.
- Determine what happens when a user disables, removes or evades the extension: alert, block or loss of telemetry.
- Test interactions with password managers, accessibility tools, privacy extensions and enterprise browser controls.
Detection quality and user impact
- Run a proof of concept against legitimate SaaS redirects, development tools and unusual administrative login flows.
- Measure false positives, warning and blocking friction, exception handling and custom-rule workflows.
- Ask what investigation data is available—application, user, timestamp, referrer, click path and session or token indicators—without collecting excessive content.
- Do not treat behavioral detection as a guarantee against every novel phishing kit or zero-day technique.
Coverage gaps
A browser agent does not automatically protect native desktop or mobile applications, command-line access, non-browser APIs, service accounts, infrastructure identities or embedded web views outside its deployment model. Those paths require separate controls.
Public pricing and alternatives
Push’s pricing page, reviewed August 18, 2026, listed standard pricing of $6 per employee per month with monthly billing or $5 per employee per month with an annual contract, for plans covering up to 500 employees. Larger organizations are directed to sales for enterprise pricing and volume discounts. The figures are current public pricing signals, not terms of the 2025 financing.
| Product | Best fit | Published pricing signal |
|---|---|---|
| Okta FastPass | Passwordless, phishing-resistant authentication and device trust | The reviewed page promotes trials and contacting sales; no directly comparable public per-user price was stated |
| Microsoft Defender Suite / Entra Suite | Organizations standardized on Microsoft 365, Entra, Defender, Intune, Purview and Sentinel | $12 per user/month paid yearly for each suite on the pricing overview reviewed August 18, 2026; eligibility and included components must be checked |
| Cloudflare Zero Trust | Secure access, web security, browser isolation and SASE consolidation | Free, pay-as-you-go and contract options; components may be per-user or usage-based |
Push may be attractive where the specific gap is browser-stage phishing, session theft, shadow SaaS, malicious extensions or browser-based AI and data risk. Okta FastPass is more focused on authentication, Microsoft offers broader identity, endpoint, data and SIEM coverage, and Cloudflare is broader across access and network security. Combinations can make sense when Push supplies browser visibility while another platform supplies authentication, endpoint or network enforcement.
What the funding may enable
Push explicitly tied the capital to research, product development, hiring and global expansion. Its newsroom lists later product, research and partnership activity through 2026, but the available announcements do not prove that any particular later launch was financed by this round. The newsroom also lists a $15 million fundraising announcement dated April 2, 2023; that does not by itself establish cumulative total funding of $45 million because the company’s complete prior financing history is not confirmed.
Bottom line for security and technology buyers
The Series B validates investor interest in browser-centric identity defense, not a claim that Push replaces MFA, identity providers, EDR, email security, secure web gateways or DLP. The decision question is whether its browser telemetry and response workflows add measurable value beyond existing controls. A proof of concept should test unmanaged devices, extension failure, privacy boundaries, false positives, investigation depth and the response actions available after a session or credential compromise.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




