The RSAC Innovation Sandbox contest is back at the RSAC Conference, and all of the finalists are using AI in their products. The "Shark Tank" style competition shows off new businesses that use cutting-edge technologies to solve tough cybersecurity problems. Finalists give a three-minute pitch and then answer questions in front of a panel of expert judges and a live audience at the RSAC Conference.

The winner is called the "Most Innovative Startup." The finalists, in alphabetical order, are Charm Security, Clearly AI, Inc., Crash Override, Fig Security, Geordie AI, Glide Identity, Humanix, Realm Labs, Token Security, and ZeroPath. The rules say that companies that want to compete must have a product that came out between December and

  • Geordie AI is a platform for security and governance that lets organizations find AI agents in real time, keep an eye on their behavior, and manage their risks. Security teams can see what AI agents are running, what systems they are accessing, and if anything strange is happening. The platform connects to code environments, cloud platforms, and endpoint devices through APIs, endpoint agents, and single sign-on. This lets you see all AI agents working in different environments in real time and get risk intelligence analysis.
  • Glide Identity is a digital identity security company that offers authentication that is safe for AI and ready for agents. The company says that its SIM-anchored cryptographic authentication platform is hard to hack and resistant to phishing.

The platform uses both internal company knowledge (like internal security policies, compliance systems, operating specifications, and other documents) and industry-wide standards and regulatory compliance frameworks (like GDPR, EU, CRA, etc.) to come up with review suggestions, compliance documents, and risk plans. With its Engineering Relationship Management (ERM) platform, Crash Override deals with shadow engineering, AI infiltration, and losing control over the software supply chain.

Instead of trying to fix the DevSecOps problems by adding more vulnerability scanners, the platform collects build execution data that APIs can't access, shows what's deployed with automated SLSA Level-2 compliance, tracks provenance, and manages certificates before they affect production.

Fig Security has a technology for managing the reliability of security observability and detection that automatically looks at how security data flows, detection rules, and response processes depend on each other. The platform keeps an eye on how well current security systems are working, automatically finds changes in each module and how they affect the whole system, and fixes system problems. Development teams can directly look at the risks and take action to fix them by combining application security analysis, vulnerability verification, and repair suggestions into a single platform.

Related: Businesses Get Ready for the IT Transformation Shift in 2026 ## More Than Just a Title Related: Microsoft Will Bundle Security Copilot With M365 Enterprise Licenses Making it to the finalist round is more than just a name.

The RSAC Conference said in a statement that the Top 10 Finalists have made more than 100 acquisitions and invested more than $50.1 billion since the contest began. Veeam bought Security AI, the winner of the 2020 contest, for $1.725 billion. Google just bought Wiz, a finalist in 2021, for $32 billion.