Get listed

NewCore vs Hush: Agentic SSO vs Runtime Kill Switch

Identity tickets moved from workforce SSO to machines and NHIs. The next buy asks who the agent is, who authorized it, and where access dies.

Workforce SSO was the closed ticket for a decade. Machine and non-human identity access became the next seat when service accounts and API keys outgrew the IdP story. Coding agents and autonomous workers push a third conversation into the same IAM room: who is this agent, who authorized the grant, and where is the kill switch when it goes sideways?

Between these two, NewCore productizes agentic SSO and a human-approved agent identity lifecycle inside a security-first IdP rebuilt for humans, machines, and agents. Hush Security productizes the runtime access path: enroll agents in a registry, strip standing credentials, issue scoped just-in-time permissions, log every action, and cut access from a centralized kill switch.

Shared "agent identity" language does not make them one interchangeable buy. Related NHI coverage lives under non-human identity tools; the compare index is at Compare.

NewCore NewCore Hush Security Hush
JobAgentic SSO and first-class agent identity lifecycle for humans and AI agentsAgent and NHI registry with JIT permissions, secretless access, and kill switch
How risk closesAuthenticate, govern, and revoke agents as identities; human grant, review, and revoke pathsEnroll the agent, remove standing secrets, grant scoped JIT at runtime, log actions, kill switch
CI failNot a classic PR SAST gate; identity and authz control plane before agents act as principalsNot a classic PR SAST gate; runtime access and credential path while agents call tools
DeployEnterprise identity platform / IdP path; demo-gatedAccess management control plane across infra and AI platforms; demo-gated
License/pricingSales quote / Request a Demo; no public dollar SKU (checked 5 Sep 2026)Sales quote / Book a Demo; no public dollar SKU (checked 5 Sep 2026)
Who operates itIdentity and IAM owning agentic SSO and lifecycleIdentity and SecOps owning registry, JIT, and kill switch at runtime

Funding marks stage and category heat rather than erase the job split. On 15 June 2026 NewCore emerged from stealth with a 66M USD seed led by Cyberstarts with Index Ventures and Evolution Equity Partners (TechCrunch coverage of that launch cited about a 300M USD valuation). On 28 July 2026 Hush announced a 30M USD Series A with Akamai joining Battery Ventures and YL Ventures, bringing total capital raised to about 41M USD.

That authorization question is why both vendors land on the same shortlist after the IAM โ†’ machine โ†’ agent ticket opens. The buyer still has to pick the operating surface: agentic SSO and lifecycle, or runtime JIT and kill switch.

We reviewed first-party documentation, funding notices, product pages, and live community threads. We did not test the products in paid production environments, so this is not a hands-on benchmark.

NewCore

NewCore

Hush Security

Hush Security

Editions and pricing

Neither publishes a self-serve dollar table. Both route buyers to demo or quote. NewCore is a 2026 seed-stage identity platform with a large reported seed and a cited ~300M USD valuation at launch. Hush is a Series A access-management company at about 41M USD total after the July 2026 round with Akamai as a strategic investor. Funding is a durability signal, not proof the products compete for the same seat.

NewCore NewCoreHush Security Hush
Owner (2026)Independent. Founded by Zohar Alon, Amihai Neiderman, and Erez YarkoniIndependent. Founded by the Meta Networks team; Akamai as Series A strategic
How you buy it nowRequest a Demo / Get in Touch (checked 5 Sep 2026)Book a Demo / Contact (checked 5 Sep 2026)
Public unitsNo public self-serve dollar SKUNo public self-serve dollar SKU
Funding signal66M USD seed Jun 2026; Cyberstarts, Index, Evolution; ~300M USD valuation cited at launch30M USD Series A Jul 2026; Akamai + Battery + YL; about 41M USD total

If procurement needs a published monthly number before a call, neither page ships one today. POC design should start from the job: agentic SSO and lifecycle versus runtime JIT and kill switch.

Agentic SSO and identity lifecycle

NewCore NewCoreHush Security Hush
Primary surfaceNext-gen IdP: humans and AI agents as first-class identities with lifecycle, trust scoring, and revocationAgents enroll in a central registry and map to existing permissions; not an IdP-first SSO story
Human approvalMobile grant, review, and revoke for agents; Agentic Skill packages for Claude Code, Codex, and CursorPolicies and approvals sit on the access path; human oversight is runtime governance, not SSO onboarding
Identity architectureSecure Split Key for SAML/OIDC signing; VisualMFA; continuous discovery of shadow and orphaned identitiesIdentity-based JIT access replacing standing credentials across NHIs and agents
What teams argue aboutWhether rebuilding the IdP for agents is required when runtime access controls already existWhether a registry and JIT path without agentic SSO covers coding-agent fleets that need first-class principals

Between these two, do not buy a shared "agent identity" checkbox. Buy the operating surface: NewCore when agents must authenticate and live as governed principals inside the identity platform; Hush when the urgent gap is how agents reach systems after they exist.

Runtime JIT, secretless access, and kill switch

NewCore NewCoreHush Security Hush
Standing credentialsAgents authenticate into the enterprise trust map rather than living as disguised service accountsStanding credentials are stripped; scoped JIT permissions are issued at runtime
MCP and toolsAgentic Skill integrations for coding agents; governance is identity-lifecycle firstDiscovers and maps MCPs, tools, and resources agents can reach and actually use
Kill / revokeRevocation path is part of first-class agent identity lifecycle and human oversightCentralized kill switch for agent actions beside continuous logging and audit
What teams argue aboutWhether IdP revocation alone stops a live agent mid-tool-call without a runtime fenceWhether JIT and kill switch are enough without treating agents as SSO principals

Between these two, Hush owns the standing-secret and mid-action stop story. NewCore owns making the agent a principal you can authenticate, score, and revoke inside identity.

Where they overlap

Both sell agent identity and governance language. Both talk revocation, permissions, and AI agents that are not just another service account. Both are demo-quoted vendors riding 2025-2026 agent adoption. Overlap is category timing and shared vocabulary, not identical product breadth. Treating them as interchangeable duplicates spend without covering both jobs.

When to use both

Running both can be honest when jobs stay separate: NewCore for agentic SSO and human-approved identity lifecycle, Hush for runtime JIT, credential elimination, and kill switch across agents and NHIs. Keep ownership clear so two agent-access lanes do not fight the same ticket.

Skip Hush for this pair if the urgent buy is rebuilding workforce and agent identity in one IdP and runtime secretless access already has an owner. Skip NewCore for this pair if the buying committee standardized on runtime agent access controls and first-class agentic SSO is only a later roadmap item.

Decide the job first. If the product must deepen agentic SSO and human-approved identity lifecycle, that is NewCore. If the product must deepen runtime JIT, secretless access, and kill switch for agents and NHIs, that is Hush. Only then book the demos.

FAQs

Are NewCore and Hush the same agent identity product?

No. Both talk agent identity, but between these two NewCore leads with agentic SSO and identity lifecycle, and Hush leads with registry, JIT permissions, secretless access, and a centralized kill switch.

Do either publish list prices?

No public self-serve dollar SKUs on either first-party site as of 5 Sep 2026. Both route to demo or sales quote.

What funding should buyers note?

NewCore emerged Jun 2026 with a 66M USD seed (Cyberstarts, Index, Evolution; ~300M USD valuation cited at launch). Hush raised a 30M USD Series A in Jul 2026 with Akamai as a strategic investor, about 41M USD total. Funding is relevant for roadmap durability; it does not make the jobs identical.

Is this a scored bake-off?

No. Order is editorial.