AI Agent Security Startup Raises $30 Million as Enterprise Risks Grow

A new funding round is strengthening the push to secure AI agents before their access expands across enterprise systems. The startup says machine identities are creating security gaps that conventional tools were not built to manage.

EcoEco4 min read
AI Agent Security Startup Raises $30 Million as Enterprise Risks Grow

A new wager on machine workers

A New York–Tel Aviv startup focused on securing AI agents has raised $30 million in a financing round that includes a $25 million Series A. The deal places its post-investment value above $100 million and follows an earlier seed investment from the same venture firm. The startup is two years old and employs roughly 30 people.

The capital arrives as organizations begin assigning AI systems access to internal applications, databases and operational tools. Unlike a conventional application account, an autonomous agent may move across several services, gather context from multiple sources and act far faster than a person. Security teams therefore need to understand not only what a system can reach, but also what it is doing and why.

Early traction supports the bet

The company reports a customer base in the tens and generated seven figures in annual recurring sales during its first year of selling. Most clients are currently located in North America, although demand is beginning to emerge in Europe, the Middle East and Africa. The venture investor also used the product internally and saw existing customers broaden their deployments, factors that supported its decision to invest again.

Why people-first identity controls are straining

The startup’s central idea is to place people, AI agents and machine accounts in one access map. That map connects credentials, permission records, data relationships and activity traces, giving defenders a clearer picture of which actor can reach which corporate asset.

That model responds to a gap in traditional identity management. Employees usually have stable job descriptions and relatively fixed permissions. Agents can choose different paths to complete a task, pick up new tools and, in some designs, generate subordinate agents. Their behavior may shift while a workflow is running, making static approval lists an incomplete control.

The stakes are no longer theoretical. In one engagement with a large listed company, the startup discovered that roughly 85,000 files had become available to AI tools and agents. It removed the exposure and later confirmed that the files had not been read through those AI systems. That outcome is important: the finding demonstrated unsafe reach, not a proven data breach.

Another case involved an outside partner who placed an unauthorized copy of a popular AI model on infrastructure it could already use. Existing credentials then allowed the tool to review several thousand sensitive files. The episode shows how a separate AI deployment can turn ordinary access rights into a much broader attack surface.

Automating investigations and repairs

The platform combines AI with security operations. It can investigate alerts, rank likely incidents, recommend what teams should address first and, in some cases, repair permission settings itself. Organizations that prefer human oversight can route difficult cases to the company’s specialists. That hybrid approach may be valuable in regulated environments where automated changes require clear audit trails.

A crowded market with room to grow

AI security is becoming a competitive field as established vendors bundle identity, data protection and agent-management capabilities into their offerings. The startup says some customers have consolidated security products, while its investor currently views the platform as an additional layer rather than a wholesale replacement.

The startup’s differentiator is its insistence that identity and data exposure cannot be evaluated separately. A permission may look reasonable in an identity system but become dangerous when attached to an agent capable of querying a sensitive dataset. Conversely, knowing the sensitivity of data without understanding which autonomous actor can reach it leaves defenders blind.

If that approach succeeds, spending could expand as agents spread beyond experimental projects into everyday business operations. The company must nevertheless prove that the need is large enough to support a standalone category rather than become a feature inside suites sold by much larger security companies. It may also need to displace narrower tools in areas such as data-loss prevention over time.

What enterprise buyers should examine

  • Can the platform map every human, service account and AI agent to the data it can access?
  • Can it detect unauthorized models and flag permissions that are unsafe for automation?
  • Can it provide an auditable record of automated security changes?
  • Can it integrate with existing identity infrastructure without forcing a full rebuild?

Recent public episodes in which autonomous systems bypassed safeguards, modified external systems or left large volumes of changes behind reinforce the urgency. The immediate lesson for buyers is not to block every agent. It is to inventory them, restrict their permissions and monitor their activity before productivity gains create an access problem that is difficult to reverse.

Eco

About the author

Eco

This article is provided for informational purposes only and does not constitute investment advice. Past performance is not indicative of future results.