TLDRocket
Sign in

Tide launched Raziel for AI security. It assumes hackers are inside.

The New Stack Jennifer Riggins

Tide launched Raziel, an AI security tool that acts like hackers are already inside. It tells agents where the blast radius is, not just where the breach starts.

Based on reporting by The New Stack, Jennifer Riggins — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Tide’s pitch starts from a grim premise: most security teams are already losing, even before AI enters the picture. Michael Loewy, who co-founded the Tide Foundation, says the old model expects defenders to be perfect all the time, while an attacker only has to be right once. A typo, a bad line of code, a misconfiguration, a state actor — any of it can be enough.

AI has made that mess worse. Loewy says developers are producing huge amounts of code that hasn’t been reviewed well enough just as advanced models get better at finding and exploiting flaws. At the same time, AI agents are now creating software and carrying out privileged actions. Tide’s worry is not only the break-in. It’s what comes after.

The company’s answer is what it calls “emergent authority.” Instead of leaving authority sitting in one place, Tide says it should be generated only when identity, policy, context and intent line up, then disappear again. In practice, that means getting away from the usual pile-up of admin credentials, root keys, identity providers and service accounts that everyone hopes are secure because they’re buried behind more security.

Tide’s new developer product, TideCloak, sits where identity and access management usually lives and handles authentication, authorization, end-to-end encryption and governance on top of its Cybersecurity Fabric. The implementation is inspectable through the company’s public GitHub repositories. And the white paper behind the whole thing was published with help from a chatbot, which feels exactly on brand for a company trying to teach machines how to guard the door.

The new piece on Monday is Raziel, an MCP server named after the archangel of secrets. Tide says AI assistants can use it to learn its authentication, threshold cryptography, end-to-end encryption and governance setup, then suggest self-hosted or managed hosting and generate verified integration playbooks. There’s even a quickstart for greenfield projects, though the more interesting bit is the company’s approach: instead of asking how an attacker gets in, Raziel assumes they already have. The prompts map out what they can impersonate and what access they can hand themselves.

Tide has also lined up a Lloyd’s of London underwriter so organizations using TideCloak can get preferential cyber insurance terms. The bigger ambition is stranger and more ambitious than a tool rollout. Tide wants to become the sort of invisible infrastructure nobody owns and everybody uses. That’s a very old internet dream, just with far more anxiety about insiders.

My take — AI-written commentary, not fact-checked reporting

The useful idea here is not that hackers are sneaky; everyone already knew that. It’s that modern security still acts surprised when a breach turns into an authority problem, which is a bit rich for an industry built on guarding the keys after leaving them on the table. If AI is going to do more of the work, the default should be less custody, not more trust theatre.

Read more about this at: The New Stack

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.