top of page

MIND Series B Funding Puts $72 Million Behind an AI Data Security Bet

6 days ago
13 min read

MIND raised $72 million as its MIND Series B funding pushes an urgent claim: enterprise data controls must operate as quickly as AI moves information. The round gives the Israeli-founded cybersecurity company more resources to pursue that claim. It does not settle whether autonomous protection can outperform established data loss prevention systems.

Crosspoint Capital Partners led the round, while existing investors YL Ventures and Paladin Capital Group also participated. MIND says the financing brings its total funding to $112 million. The announcement arrived just over a year after its $30 million Series A.

The competitive pressure extends beyond other startups. Microsoft, Forcepoint, Netskope, Palo Alto Networks, Proofpoint, and Broadcom already sell data protection across endpoints, cloud applications, email, and corporate networks. MIND must convince buyers that an AI-native platform offers more than a newer interface for familiar controls.

Its timing is favorable. Employees now paste information into AI assistants, connect models with business applications, and delegate multistep work to agents. Those actions create faster, less visible paths for sensitive data to leave approved systems.

The harder question is operational. Enterprises need controls that recognize context, block genuine threats, and avoid interrupting legitimate work. MIND is betting that AI agents can manage that balance better than manually tuned policies.

What the MIND Series B Funding Changes

The new capital moves MIND from an emerging DLP vendor into a better-funded contest for enterprise-wide data control.

MIND announced the Series B on September 17, 2026. According to its funding announcement, the company plans to expand product development, enterprise sales, partnerships, and staffing.

The financing follows a compressed fundraising schedule. MIND emerged from stealth in 2024 and announced a $30 million Series A in June 2025. That earlier round brought its reported funding above $40 million.

The latest investment raises the disclosed total to $112 million. That sum gives MIND room to hire engineers, support larger deployments, and pursue buyers that expect extensive integrations and service capacity.

MIND also says it has built an eight-figure revenue business and serves dozens of customers. The company has not publicly released audited revenue, customer retention, contract duration, or deployment-wide usage data.

Those missing details matter because enterprise security contracts can begin with narrow deployments. A customer logo does not reveal how many endpoints, applications, business units, or data repositories the platform actually covers.

Still, publicly named customers offer some evidence of production use. Children’s Hospital Los Angeles says it uses MIND to stop protected health information from entering AI tools through corporate endpoints. The National Geographic Society says the system helps identify sensitive documents, restrict public sharing, and expose interactions with AI agents.

These examples connect the funding to a concrete problem. Healthcare workers, researchers, engineers, and other employees increasingly use AI tools that can accept files, prompts, database results, and copied text. Security teams often lack a unified view of those movements.

MIND describes its platform as AI-native data loss prevention, or DLP. DLP software identifies sensitive information and applies policies that can warn, quarantine, redact, or block an unsafe action.

Traditional DLP products already perform many of those functions. MIND’s differentiation rests on how much of the investigation, policy adjustment, and response process its software can automate.

Its platform monitors data across endpoints, email, software-as-a-service applications, generative AI tools, and other enterprise environments. MIND says multilayer classification analyzes both content and context before enforcement occurs.

That positioning explains why the round matters beyond its amount. The company is not merely selling another dashboard. It is challenging the assumption that security teams must manually maintain a large collection of static DLP rules.

The financing now lets MIND test that challenge across more customers and more complicated environments. It also raises expectations. Investors will want evidence that deployment speed, classification accuracy, and customer expansion justify another large round so soon after the last one.

Why AI Agents Are Making Data Loss Harder to Control

AI adoption changes data leakage from a series of visible employee actions into a chain of automated decisions.

An employee can accidentally attach the wrong document, paste source code into an unapproved chatbot, or expose a file through a public link. Security teams understand those risks, even when existing controls handle them poorly.

AI agents introduce a different operating pattern. An agent can retrieve data from several systems, combine it, call another service, and produce an external response without separate human approval for every step.

The agent may have valid access to each system. The risk emerges from how it combines permissions, information, and actions across the workflow.

That distinction weakens controls based mainly on file signatures, keywords, or destination lists. A harmless-looking fragment can become sensitive when combined with customer records, product plans, or internal communications.

Prompt injection adds another complication. An agent can encounter malicious instructions inside a document or webpage and then use its authorized tools in unintended ways.

Research from the Singapore and Korea AI Safety Institutes evaluated leakage risks across 12 realistic agent tasks. The agent leakage study examined failures involving data awareness, audience awareness, policy compliance, minimization, and access boundaries.

The significance is practical. An AI system does not need malicious intent to mishandle data. It can expose information because it misunderstood the audience, used more data than necessary, or followed conflicting instructions.

Corporate AI use also crosses several control points. An employee may begin in a browser, retrieve a cloud document, invoke an external model, and send the result through a collaboration platform.

A tool that sees only the initial prompt lacks the full chain. A product focused only on stored data may identify exposure after the information has already moved.

MIND argues that companies need protection for data both at rest and in motion. Its system is designed to discover sensitive material, follow its movement, and enforce policy when an action creates unacceptable risk.

This is the mechanism behind the company’s AI-native label. MIND says its own agents can investigate events, tune controls, and handle parts of the remediation process.

The promise is attractive because policy maintenance remains a major DLP burden. Organizations can accumulate thousands of rules, exceptions, alerts, and classification labels. Each change in software or workflow can create another tuning task.

AI agents increase that burden by creating new paths between systems. A security team cannot realistically write a separate manual rule for every possible sequence of model, application, user, and dataset.

However, automated policy management introduces its own dependency. The defensive agent must correctly understand sensitive content, business context, user authorization, and the destination’s risk.

A mistake can go in either direction. A false negative permits information to escape, while a false positive blocks approved work and encourages employees to evade the control.

MIND’s own terms acknowledge that the platform cannot guarantee detection or prevention of every disclosure, policy violation, or security incident. They also recognize that false positives and false negatives remain possible.

That language is standard for security software, but it identifies the central issue. AI can expand DLP coverage and reduce manual effort. It cannot eliminate the judgment problem at the center of data protection.

MIND Is Challenging the Established DLP Model

MIND’s primary opponent is not one startup. It is the established model of policy-heavy DLP that demands constant human tuning.

Legacy DLP systems developed around relatively predictable channels. They inspected email, web uploads, removable storage, network traffic, and files moving through managed endpoints.

Those channels still matter. Yet enterprise information now travels through cloud collaboration suites, browser applications, personal AI accounts, model APIs, copilots, and autonomous agents.

Established vendors are not ignoring that shift. Microsoft can connect Purview policies with Microsoft 365 identities, labels, endpoints, and applications. Netskope and Zscaler inspect cloud and web traffic through security service edge infrastructure.

Forcepoint emphasizes behavior-aware enforcement. Palo Alto Networks, Proofpoint, Broadcom, and Trellix bring their own endpoint, network, email, and cloud integrations.

These vendors have structural advantages. They already sit inside large technology estates, hold long-term enterprise contracts, and integrate with identity and security operations systems.

Their products can also preserve one policy framework across several channels. That matters to regulated organizations that need consistent enforcement and audit evidence.

MIND counters with a narrower argument. It says the older DLP operating model is too manual, fragmented, and slow for AI-driven workflows.

The company combines data discovery, classification, loss prevention, and insider-risk functions within one platform. It then uses agents to investigate activity and adjust policies.

That approach seeks to reduce the operational gap between finding sensitive data and stopping it from leaving. Data security posture management products often emphasize discovery and exposure. DLP products emphasize controls applied during movement.

MIND wants to connect those functions. The platform must understand what information exists, why it is sensitive, who is using it, and whether a specific movement violates policy.

The contest therefore centers on operating burden rather than feature count. Established vendors can add AI inspection to broad security platforms. MIND must show that rebuilding the workflow around automation produces better daily outcomes.

One measurable outcome is deployment time. Buyers should ask how long MIND takes to discover data, establish usable policies, integrate major channels, and begin enforcing controls.

Another is investigation effort. A product that creates fewer alerts offers limited value if each alert requires extensive manual validation.

The strongest test is policy quality over time. MIND’s agents should reduce repetitive tuning without quietly widening exceptions or blocking more legitimate actions.

Buyers should also compare coverage. A modern DLP product needs visibility across endpoints, browsers, sanctioned applications, unsanctioned services, email, cloud storage, and AI systems.

No vendor has equal depth everywhere. A startup may move faster in AI workflows, while an incumbent may offer stronger coverage inside its own platform.

This is why MIND’s funding does not signal the disappearance of traditional DLP. It signals an attempt to change how DLP is operated.

If MIND proves that automated investigation and tuning lower administrative work, established vendors will face pressure to match that experience. If it cannot, buyers may prefer incremental AI features inside platforms they already use.

The Real Test Is Accuracy Without Workflow Friction

MIND must prove that autonomous enforcement reduces risk without replacing manual policy work with opaque machine decisions.

Data security products operate in an unforgiving part of the enterprise stack. A system that misses sensitive transfers fails its security purpose. A system that blocks ordinary work loses user support.

False positives are especially damaging in DLP. An employee who repeatedly encounters incorrect warnings may seek an unmonitored channel, use a personal account, or request broad exceptions.

Broad exceptions weaken protection. They can also make performance statistics look better by removing difficult traffic from enforcement.

AI classification can improve on simple pattern matching. It can distinguish a public product brochure from a confidential roadmap, even when both contain similar terminology.

Yet contextual classification is not automatically dependable. Models can behave differently after updates, struggle with unfamiliar document formats, or misunderstand specialized language.

Global enterprises add further complexity. Policies must account for regional privacy rules, data residency obligations, languages, business roles, and contractual restrictions.

An autonomous agent tuning those policies needs strict boundaries. Security teams must know which changes it can make, what evidence supports each change, and how to reverse an incorrect decision.

Auditability becomes as important as classification. A blocked action should produce a clear explanation that a security analyst, employee, regulator, or customer can understand.

MIND says its platform provides automated investigation and remediation. The company has not publicly disclosed enough independent benchmark data to compare its false-positive rate, detection accuracy, or processing latency with major competitors.

The named customer accounts are useful, but they remain selected testimonials. They do not replace controlled testing across a buyer’s own applications and data.

Children’s Hospital Los Angeles offers a meaningful use case because protected health information carries strict handling requirements. The organization says MIND blocks such information from entering AI tools without affecting endpoint performance.

That statement supports the product’s practical relevance. It should still be evaluated as a customer claim presented by MIND, not as an independent performance audit.

National Geographic’s account highlights a different requirement. It describes visibility into interactions between organizational data and AI agents, alongside document labeling and sharing restrictions.

Together, the examples show why enterprises are interested. They do not establish how the product behaves across every data type, application, or adversarial scenario.

Prospective buyers should run representative trials. Tests should include ordinary uploads, copied text, generated summaries, source code, screenshots, multilingual content, and agent-initiated transfers.

They should also test evasive behavior. Sensitive information can be reformatted, split across prompts, encoded, paraphrased, or embedded inside larger documents.

A credible evaluation needs both security and productivity metrics. Detection rates matter, but so do user interruptions, analyst review time, exception volume, and the time required to explain a decision.

Enterprises should examine failure handling as well. When the platform loses connectivity or confidence, buyers need to know whether it blocks activity, permits it, or routes it for review.

The $72 million round gives MIND resources to improve these areas. Capital itself provides no proof that the underlying tradeoff has been solved.

Private financing can reflect market timing, investor conviction, revenue growth, or competitive positioning. It does not independently verify product accuracy.

This distinction matters because AI security attracts urgent spending. Companies fear data exposure, but urgency can shorten evaluations and reward ambitious claims.

MIND’s best path is transparent evidence. Published methodology, deployment metrics, customer expansion, and third-party assessments would help buyers separate automation from marketing.

What MIND’s Funding Means for Enterprise Buyers

The round gives buyers another serious option, but purchasing decisions should turn on control coverage and measurable workload reduction.

The immediate benefit is competitive pressure. More investment in AI-aware DLP gives enterprises leverage to demand better integrations, clearer policies, and faster deployment from every vendor.

MIND can use the funding to deepen channel coverage. That work is essential because data movement rarely stays inside one vendor’s environment.

An employee might retrieve a document from Microsoft 365, process it through a third-party model, and publish the output in another cloud service. An agent might perform the same sequence through APIs.

Security teams need continuity across that chain. A product that controls only the browser or endpoint may miss server-side agent activity. A cloud-only product may miss information copied from local applications.

Buyers should begin with data flows rather than vendor labels. They need to identify where sensitive information originates, which identities can access it, and where AI systems can send it.

The next question concerns enforcement. Some organizations need warnings for low-risk behavior and hard blocks for regulated data. Others need redaction, quarantine, approval, or detailed audit records.

MIND’s platform aims to automate these decisions. Buyers should verify whether its policy model matches their tolerance for autonomous action.

Integration depth deserves equal attention. A DLP product must exchange context with identity platforms, endpoint tools, cloud services, security operations systems, and incident-response workflows.

A technically accurate alert can still fail operationally if it lacks an owner or cannot trigger a useful response.

Security leaders should also examine administrative control. They need role separation, policy versioning, approval workflows, and records showing why automated changes occurred.

Procurement teams may find the MIND Series B funding reassuring because it extends the company’s financial capacity. Large customers want confidence that a security vendor can support multiyear deployments.

However, total funding should not substitute for business continuity review. Buyers still need to assess contractual protections, support coverage, product dependencies, and export options for policies and evidence.

The competitive comparison should include incumbents and newer data-security companies. Microsoft Purview may suit organizations centered on Microsoft services. Netskope or Zscaler may fit companies already routing traffic through their security infrastructure.

Data-focused vendors such as Cyera and Varonis approach the problem through discovery, posture, identity, and access context. Cyberhaven emphasizes tracing data movement and lineage.

MIND’s proposition sits between these approaches. It wants to discover information, understand its context, and stop dangerous movement while automating much of the operational work.

That combination is appealing, but broad platforms can become complicated. Each additional channel creates integration, latency, policy, and support demands.

Enterprises should therefore compare complete workflows. A useful trial follows sensitive data from discovery through attempted movement, enforcement, investigation, remediation, and reporting.

Teams also need a durable record of policy decisions and exceptions. A searchable technical knowledge base can help preserve why controls changed and which evidence supported each decision.

That documentation cannot replace security telemetry. It can prevent institutional knowledge from disappearing when analysts, application owners, or compliance staff change roles.

Ultimately, the funding broadens the buyer’s choice. It does not simplify the buying decision.

The winning platform will not be the one that mentions AI most often. It will be the one that reduces unauthorized data movement while making fewer demands on users and security teams.

Three Signals Will Show Whether MIND’s Bet Is Working

MIND’s next phase should be judged through deployment evidence, customer expansion, and independent validation rather than another funding headline.

The first signal is broader production deployment. MIND has identified dozens of customers and two concrete use cases, but the market needs more detail about coverage.

Useful evidence would include the number of protected endpoints, applications, AI services, and agent workflows. It should also show whether customers expanded after an initial rollout.

Expansion would strengthen MIND’s argument because security buyers rarely broaden a deployment that creates excessive friction. Narrow pilots that remain narrow would weaken it.

The second signal is measurable automation performance. MIND says its agents investigate incidents, tune policies, and reduce manual DLP work.

The company can support that claim with metrics such as analyst time saved, policy changes accepted, false-positive reductions, investigation duration, and exception volume.

Independent testing would carry more weight than selected case studies. Security teams need evaluations based on realistic data, adversarial inputs, and complicated application chains.

A strong result would show that automation improves outcomes without hiding uncertainty. A weak result would reveal that analysts still perform most of the difficult judgment.

The third signal is the response from established vendors. Microsoft, Netskope, Forcepoint, Palo Alto Networks, Proofpoint, and Broadcom have access to large enterprise estates.

If they simplify DLP operations and extend policy enforcement across AI agents, MIND will face a tougher distribution battle. Existing customers often prefer an integrated upgrade over another security console.

However, an aggressive incumbent response would also validate MIND’s thesis. It would show that AI-driven workflows have forced the DLP market to reconsider manual policy administration.

Buyers should watch acquisitions and partnerships as well. Large security platforms may seek specialized technology for agent visibility, data lineage, or autonomous policy management.

MIND says the new financing will deepen technology and channel partnerships. The value of those relationships will depend on whether they create complete enforcement paths, not merely reseller announcements.

The company’s reported eight-figure revenue base provides a starting point. The next question is whether it can preserve rapid growth while supporting more complex customers.

That transition often exposes operational strain. Enterprise deals require implementation staff, integrations, regional support, compliance documentation, and dependable response during incidents.

MIND now has more capital to build those capabilities. It also has less room to present itself as an untested newcomer.

The MIND Series B funding is significant because it finances a direct challenge to conventional DLP operations. AI agents are accelerating data movement, while security teams remain accountable for every disclosure.

MIND believes defensive agents can monitor that movement and manage controls at comparable speed. Enterprises should test the claim with their hardest workflows, not their cleanest demonstrations.

Over the next several months, look for expanded deployments, transparent accuracy metrics, and concrete incumbent responses. Those signals will reveal whether MIND is redefining DLP operations or joining a crowded market with a timely message.

For security leaders, the next action is straightforward. Map one sensitive workflow that includes an AI tool or agent, then test whether existing controls can follow the data from access through final destination. If they cannot, compare vendors using the same workflow, policy, and failure conditions. Demand evidence for detection quality, blocked legitimate work, analyst effort, and decision auditability. MIND’s financing makes it a credible participant in that evaluation. Only production results will determine whether its autonomous model delivers safer AI adoption.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page