1stProtect Emerges from Stealth with New Approach to Endpoint Security
Veterans of enterprise cybersecurity unveil a platform that verifies user intent and blocks unauthorized data access and exfiltration in microseconds — even without internet connectivity.
SAN FRANCISCO, March 19, 2026 — 1stProtect, a Silicon Valley-based cybersecurity startup founded by veterans of global enterprise cybersecurity programs, today emerged from stealth with an industry-changing new endpoint security platform designed to stop modern cyberattacks before sensitive data can be stolen by monitoring system behavior and verifying user intent in real time.
The company will formally launch the platform during the RSAC 2026 Conference.
Why Existing Cybersecurity Tools Fail
For decades, enterprise security has relied on perimeter defenses and cloud-based analytics to detect threats. As AI expands workload autonomy, organizations also need direct policy controls over what software actors are allowed to do during execution.
Modern attacks increasingly operate inside trusted systems — using legitimate processes or stolen credentials — making them difficult for traditional detection systems to identify until long after sensitive data is accessed.
"We built this company around a simple idea: autonomous systems need explicit runtime boundaries," said Kervin Pillay, Chief Executive Officer of 1stProtect. "Instead of relying on intent assumptions, we verify each critical action in context and block unauthorized activity in real time."
A New Model for Endpoint Protection
Rather than relying only on cloud analytics after an event starts, 1stProtect adds an endpoint runtime authorization layer. The platform evaluates attempted actions and enforces explicit policy boundaries before high-risk operations complete.
This model complements existing detection and response tooling by adding deterministic allow-or-block decisions at execution time.
One Engine Instead of Many
Most modern security stacks rely on multiple independent engines — separate systems for endpoint protection, identity security, data loss prevention, and threat detection.
1stProtect provides a user-space runtime authorization layer that can be applied consistently across those categories:
- Credential and Session Theft
- Ransomware and Destructive Attacks
- Data and Exfiltration
- Application and Browser Security
- Runtime Behavioral Attacks
- Identity and Active Directory Attacks
On-Device AI Investigation
The platform includes an AI-driven investigator that runs directly on the endpoint. The system performs forensic analysis locally using an on-device MCP server, allowing threat investigations and remediation to occur without sending sensitive data to the cloud.
Built by Security Industry Veterans
The company is led by Kervin Pillay, former Chief Technology Officer of Automation at a global technology company, and Chief Technology Officer Rafel Ivgi, a highly decorated cybersecurity veteran with nearly three decades of experience across enterprise security platforms.
"What makes 1stProtect different is not just the architecture, but the team behind it," said Mr. Ivgi. "We've seen firsthand where traditional approaches break down — whether that's cloud latency, tool sprawl, or blind spots around credentials and data access. That collective expertise has allowed us to rethink endpoint protection from the ground up."
Contact
Investor and Customer Contact: info@1stProtect.ai
Media Contacts: Scott Deveau / Nate Johnson, August Strategic Communications — 1stProtect@augustco.com
Source: RSAC Media Center