Q&A with Red Access CEO DorZvi On The Growing Need of Endpoint Security

0
Red Access is a cybersecurity company securing the modern enterprise session. Its platform secures how employees actually work today — across browsers, desktop AI apps like ChatGPT and Claude, and the embedded browsers and AI inside hundreds of enterprise tools like Slack, Outlook, and more — all from a single agentless session layer configuration, with no browser replacement, no extension rollout, and no additional endpoint agent. Red Access delivers SWG, CASB, DLP, phishing protection, web and AI security visibility and control alongside the security stack organizations already run.

Can you share the most interesting story that happened to you since you started your career, especially one that shaped your leadership approach at your current company?

One of the experiences that shaped me most was actually the journey I took with my co-founder, Tal. We’ve known each other since we were kids. We went to school together, served in the military together, and later worked together at both Solebit and Mimecast.
Even before Red Access, we had this idea that one day we wanted to build something of our own. So when we joined a small cybersecurity startup earlier in our careers, part of the motivation was to learn. Not only technology, but how a company is built, how decisions are made, how you deal with customers, and how you respond when things don’t go according to plan.
That experience shaped how I lead today. I try to create an environment where people can give very direct feedback, including to me. Especially as a first-time founder, you quickly realize you don’t have all the answers. The important thing is to surround yourself with people who will tell you what you need to hear, not only what you want to hear. That was true when it was five of us in a room, and it’s true now.

What initially brought you to this specific career path, and how did it lead to your role in this company?

Cybersecurity has really been the common thread through my entire professional life. I started working on both offensive and defensive security during my military service, and afterward moved into security research and development at Solebit. When Solebit was acquired by Mimecast, I continued there.
Throughout those roles I was working very close to the actual mechanics of attacks: malware, threat detection, how users and applications interact, and where existing security layers do or don’t have visibility.
Tal and I eventually started Red Access because we saw a change happening in the way people worked. More and more activity was moving into browsers, SaaS applications, GenAI tools, and distributed environments, but much of the security architecture around it had been designed for a different world.
We didn’t start with, “let’s build a browser-security company.” We started with a problem we kept seeing, validated it with customers and design partners, and then tried to find a fundamentally simpler way to solve it. That’s still how we operate.

What makes your company stand out from competitors in the market? Can you share an example that highlights this?

The principle we started with is that security shouldn’t force a trade-off between protection, user experience, and operational simplicity. In practice, most organizations have been asked to make exactly that trade-off: replace the browser, roll out an extension to every endpoint, or add another agent, in exchange for visibility and control.
We took a different path. Red Access secures the session itself, the layer where the user actually works, whether that’s a browser, a SaaS app, a GenAI tool, or an AI-powered desktop app built on Electron or WebView2. That means we can extend security across all of those surfaces without replacing the browser, without rolling out an extension, and without adding another endpoint agent. It’s why our line has become “Secure the desktop. Not just the browser.”
One of the first “aha” moments in almost every prospect conversation is the same. People understand the capabilities, and then we explain there’s no agent and no browser to swap. That’s usually the point where the conversation shifts from evaluation to deployment.
One of our earliest customers was a financial institution with around 16,000 employees. They had leaned heavily on VPN infrastructure as work went remote, and the model was becoming difficult to manage as hybrid became permanent. Red Access gave them centralized protection without asking employees to install anything on their personal devices. That deployment was one of the first real signals for us that the architecture was solving an operational problem, not just a technical one.

Are you working on any exciting new products or projects? How do you think this innovation will positively impact your customers?

One area we’ve been spending a lot of time on is what happens when employees stop just using AI tools and start building with them.
Earlier this year we published a piece of research we called Shadow Builders. We looked at thousands of applications employees had built using no-code and AI-assisted platforms, and the picture was striking: the overwhelming majority were built using corporate email addresses, a large share exposed sensitive data, and thousands had no authentication or access controls at all. These aren’t rogue projects, either. They’re marketing teammates building dashboards, ops people building internal tools, analysts spinning up something to move faster. It’s real work. It’s just invisible to security.
That research became the basis for a new capability we recently launched called Shadow Builders Discovery, which gives security teams visibility into what’s actually being built inside their organization through these channels, without slowing anyone down.
The reason this matters for customers is that most of the tooling built for AI security today looks at prompts and models. That’s important, but it misses a whole other category of exposure that happens one layer up, at the session, where the building actually takes place. Being able to see that, govern it, and give employees room to keep working is where I think a lot of the next few years of enterprise security is going to be spent.

What was the tipping point for your company’s recent success? Was there a change in strategy or approach that others might learn from?

I don’t think there was one dramatic pivot. It was more a series of validations.
One of the first was getting our first paying customer. Until that point you can have design partners, great conversations, and people telling you the idea makes sense. But there is a huge difference between someone saying “this is interesting” and someone deploying the product in a real environment, depending on it, and paying for it. That moment changed the company. We were no longer only building software — we were responsible for delivering a service that a customer relied on.
As we grew, the lesson was to stay very close to the repeatable problem. I’ve always believed the founder should do the first sales, hear the objections directly, and understand where you win and where you lose before trying to scale the process. You can’t hand a playbook to a sales team if the playbook doesn’t exist yet.
More recently, that same discipline has helped us expand the architecture from browser security into a much broader session-security problem, covering GenAI, SaaS, and AI-powered desktop apps. It’s also part of what gave investors confidence in our $17 million Series A in 2025, which brought our total funding to $23 million and is helping us accelerate in the U.S. market.

Can you share a significant challenge your company faced and how you overcame it? What key lesson did that experience provide?

One of the biggest challenges with building something new in cybersecurity is that being technically right isn’t enough.
When you introduce a different architecture, customers naturally test every assumption. The early stage of Red Access involved a constant cycle of deploying, finding issues we hadn’t seen before, fixing them, going back to the customer, and testing again. That process can be uncomfortable, but it’s also where the company gets built.
The lesson for me was not to separate product development from customer learning. Especially early on, they’re really the same process. You need customers who are willing to challenge you, and internally you need a culture where people are comfortable saying, “this isn’t working yet.”
That approach also changes how you think about leadership. The CEO’s job isn’t to protect the original idea. It’s to make sure the company keeps learning faster than the problem changes.

In just a few words, what differentiates your leadership role from others in the company? What impact does this have on company culture or product success?

I think my role is to keep the company connected to reality. Reality in the market, reality for our customers, and reality inside the company.
As CEO, I spend a lot of time connecting those perspectives and making sure what we’re building solves a real problem, that we’re hearing uncomfortable feedback early enough, and that everyone understands why we’re making the choices we make.
Tal and I also have a long history together, which helps. We can disagree very directly and still trust the intent behind the disagreement. I think that has influenced the broader culture as well: debate is healthy, feedback is expected, and the best idea should win regardless of where it comes from.
Learn more about Red Access by visiting: https://redaccess.io/
Related News:
Share.

About Author

Dor Zvi is the Co-founder and CEO of Red Access, a cybersecurity company that secures how employees actually work today -- across browsers, desktop AI apps. AI tools, and a growing set of embedded browsers and AI inside enterprise tools -- without replacing the browser, deploying extensions, or adding another endpoint agent. A cybersecurity entrepreneur and executive, Dor works closely with security leaders to address the growing gap between traditional endpoint and network security and the way employees actually work today -- across browsers, AI tools, and desktop applications.