Reco AI Agent Security Funding Adds $55M, but a Crowded Market Raises the Bar
Reco AI agent security funding has added $55 million as the startup races to secure enterprise agents that companies cannot always find or control. The financing brings Reco’s total capital raised to $140 million. It also arrives only months after the company announced a $30 million Series B.
The speed of that follow-on investment is the real story. Reco is no longer pitching only better visibility into software-as-a-service applications. It is trying to become the security map for agents, identities, applications, permissions, data, and workflows across an enterprise.
That shift puts Reco into a crowded contest with WitnessAI, Noma Security, established cybersecurity vendors, and controls built into major software platforms. Reco must now show that its context-based approach can produce measurable protection, not just another inventory of AI activity.
Reco AI Agent Security Funding Backs a Broader Expansion
The new capital backs Reco’s transformation from a SaaS security vendor into a broader agent security platform.
Reco announced the additional financing on September 29, 2026. The round includes a strategic investment from AT&T Ventures, with support from new investors Forestay and Quadrille Capital.
According to the company’s funding announcement, the money will support sales, partnerships, channel development, and customer support. Reco says it plans to expand its presence across North America and Europe.
The round follows a $30 million financing announced in February. That earlier investment included Zeev Ventures, Insight Partners, Boldstart Ventures, Workday Ventures, TIAA Ventures, S Ventures, and Quadrille Capital.
Reco says its total funding now stands at $140 million. CEO and co-founder Ofer Klein told TechCrunch that the company’s valuation had more than doubled since February. He described it only as being in the high hundreds of millions.
Klein also said annual recurring revenue had reached the double-digit millions. He expects it to triple during 2026, although that forecast has not been independently verified.
The company has more than 100 customers, according to Klein. Financial services organizations represent about 40 percent of its business, making regulated enterprises an important part of its growth plan.
Those customers are buying more than a conventional AI gateway. Reco’s central product is a context graph, which connects agents with the applications, identities, permissions, and data around them.
A context graph is a continuously updated map of relationships inside a technology environment. It helps a security team understand not only that an agent exists, but also what that agent can reach.
That distinction matters because an agent can inherit access from a user, service account, application, or connected tool. A seemingly low-risk assistant can become dangerous when those inherited privileges cross multiple systems.
Reco says its platform can find agents through direct application integrations, browser signals, and network activity. The company also claims it can inspect prompts and tool calls, then help administrators remove unnecessary access.
In June, Reco formally introduced its expanded agent security platform. At that time, it reported more than 230 application integrations and 1,000 detection controls.
The company now advertises more than 280 integrations. That expanding coverage supports Reco’s argument that application context gives it an advantage over products focused only on model traffic.
AT&T’s involvement adds strategic weight because the telecommunications company is both an investor and a customer. A customer investment can signal confidence in a product’s value, but it is not independent proof of wider demand.
The round therefore finances a specific expansion rather than a simple continuation. Reco is betting that its history in SaaS security gives it the right foundation for governing agents across connected enterprise systems.
The capital also raises expectations. Reco must expand integrations, customer support, and distribution while keeping its technical claims credible across many different agent platforms.
Why Enterprise Agent Sprawl Became an Urgent Security Problem
The problem is not simply that enterprises are deploying more agents, but that agents can act through permissions assembled across several systems.
An AI agent is software that can plan or perform actions toward a goal. Unlike a chatbot that only produces text, an agent can call tools, retrieve records, update applications, or trigger workflows.
That ability changes the security equation. Traditional application inventories usually track software, users, devices, and service accounts as separate objects. Agents can connect those categories while operating under delegated authority.
An employee might authorize an agent to read email, search cloud storage, update customer records, and send messages. Each permission may appear reasonable alone, while the combined path creates a much larger exposure.
The risk grows when ownership is unclear. Agents may be purchased as standalone products, built internally, or activated within software that an enterprise already uses.
A Salesforce assistant, Microsoft 365 copilot, Slack application, or browser extension can introduce agent-like behavior without a separate procurement event. Security teams may discover the capability only after employees begin using it.
This is the condition often described as agent sprawl. The term covers uncontrolled growth in the number of agents, their connections, and the permissions they accumulate.
Reco says one Fortune 100 customer had 21,000 agents that the organization did not know about. That number comes from the company and has not received independent technical validation.
Klein also described a financial services customer where Reco reportedly found an agent created by a former employee. The agent could access Salesforce and share information with a domain outside the company’s visibility.
That scenario illustrates why inventory alone is insufficient. A security team needs to know who created an agent, which credentials it uses, and what happens when its owner leaves.
It also needs to understand indirect access. An agent may lack direct permission to open a sensitive database but gain equivalent access through another application or workflow.
Reco’s premise is that relationships reveal these risks. Its graph connects people, accounts, agents, applications, permissions, data, and observed activity so defenders can evaluate a complete path.
That model resembles identity governance applied to autonomous software. Instead of asking only whether a person should hold a permission, the system asks whether an agent should exercise it.
The difference becomes important when agents operate continuously. A human might open a customer record several times during a workday. An agent can examine thousands of records or execute repeated actions within minutes.
Speed compresses the time available for a security team to respond. It also increases the potential impact of an incorrect instruction, compromised credential, or malicious prompt.
Prompt injection adds another layer. This attack places hostile instructions inside content that an AI system reads, attempting to redirect the system’s behavior or expose information.
Agents are particularly exposed because they consume external data and possess tools. An injected instruction becomes more consequential when the receiving system can send email, modify files, or call an application programming interface.
Researchers studying agent deployment have documented persistent weaknesses under adversarial testing. One large-scale security study analyzed 1.8 million prompt-injection attempts submitted through a public competition.
The researchers reported more than 60,000 successful attacks that induced policy violations. Those outcomes included unauthorized data access, prohibited financial actions, and regulatory compliance failures.
A commercial security product cannot eliminate every failure inside an underlying model. It can, however, restrict what the model can access and monitor the actions that follow.
That creates demand for tools spanning discovery, permission management, runtime monitoring, and response. It also explains why buyers face overlapping claims from a growing list of vendors.
For teams building AI systems around internal documents, access design matters as much as retrieval quality. A searchable knowledge base remains safe only when its automation respects ownership and permission boundaries.
The immediate pressure falls on chief information security officers. They must support rapid AI adoption without allowing every department to create an independent access structure.
Developers also feel that pressure. Security requirements added after deployment can force them to redesign tool calls, identity flows, approval checkpoints, and audit records.
Enterprise buyers therefore need evidence that an agent security platform can discover real deployments without blocking legitimate experimentation. Reco’s new financing gives it more resources to pursue that balance.
Reco’s Context Graph Faces a Crowded Security Market
Reco’s main opponent is not one company, but a crowded market offering similar promises through different technical routes.
Some vendors monitor the traffic flowing between users, models, and applications. Others emphasize runtime protection, non-human identity controls, model testing, data security, or application posture management.
Reco approaches the problem through relationships. Its graph is designed to reveal how an agent connects with identities, software, permissions, and information across an enterprise.
The company says this existing SaaS coverage lets it add context that a narrower AI gateway might miss. A gateway typically observes requests crossing a particular control point, but activity can occur outside that route.
Browser extensions, embedded assistants, and direct application integrations complicate the gateway model. An organization may need several discovery methods to see agents introduced through different channels.
Reco says it supplements its direct integrations with browser and network signals. That combination aims to find activity beyond supported applications while preserving the richer context of connected systems.
The approach sounds differentiated, but competitors are pursuing adjacent forms of visibility. WitnessAI monitors enterprise AI interactions and has expanded its controls to cover agents, tools, and Model Context Protocol servers.
Model Context Protocol, commonly called MCP, is a standard for connecting AI systems to data sources and tools. It simplifies integration, but each connection can introduce another permission and trust boundary.
WitnessAI raised $58 million in strategic funding in January 2026. Its enterprise AI controls focus on observing what data enters AI systems and what agents do on a user’s behalf.
Noma Security represents another route. It positions its product across AI development, application use, and agent security, with controls covering models, data, infrastructure, and runtime behavior.
Noma announced a $100 million Series B in July 2025. Its security expansion showed that substantial investor interest reached this category before Reco’s latest round.
Established vendors also matter. CrowdStrike and other endpoint security providers can observe processes and behavior on devices where agents operate.
Identity companies can extend non-human identity products to agent credentials. Cloud providers can enforce permissions inside their platforms, while major SaaS vendors can add controls around their own assistants.
These incumbents possess distribution, installed telemetry, and existing security budgets. Startups must prove that their cross-platform visibility provides enough value to justify another management layer.
Reco’s strongest argument is that no single application vendor sees the entire enterprise ecosystem. An embedded Salesforce control cannot fully map what happens when an agent reaches Microsoft 365, Slack, or an external tool.
The same argument applies to cloud boundaries. Enterprises often use several infrastructure platforms alongside hundreds of SaaS products, creating fragmented oversight.
A graph can connect those fragments if its integrations capture enough reliable information. That condition introduces the central technical challenge for Reco.
The graph is only as useful as its data. Missing applications, stale permissions, ambiguous ownership, or incomplete activity logs can produce a misleading risk picture.
Reco says it can add new integrations within days. Fast integration work supports coverage, but buyers must examine the depth of each connector.
A connector that lists accounts provides less security value than one that identifies delegated permissions, agent actions, and unusual behavior. Integration counts do not describe those differences.
The market’s shared language further complicates evaluation. Many companies now promise agent discovery, continuous monitoring, least-privilege access, runtime controls, and MCP security.
Least privilege means granting only the access required for a specific task. The idea is familiar, but applying it to adaptive agents remains difficult because their actions can change with context.
Vendors must translate common principles into enforceable controls. They need to show which risky action they detect, which permission they remove, and how quickly they contain a threat.
Reco’s context graph offers a plausible mechanism for answering those questions. The funding does not establish that it answers them better than competing systems.
That gap between a coherent architecture and verified outcomes will shape the company’s next stage. Reco has enough capital to pursue scale, but the category’s crowded field prevents financing from serving as a durable moat.
What Reco’s Numbers Do Not Yet Prove
Reco has presented strong growth signals, but its most striking deployment and performance claims still come from the company itself.
The reported customer count, recurring revenue range, expected revenue growth, and undisclosed valuation all help explain investor interest. None provides a complete measure of security effectiveness.
Revenue growth can show that companies will pay for a product. It does not reveal whether the product identifies every agent, prevents misuse, or reduces incident costs.
The 21,000-agent discovery is similarly compelling but difficult to interpret without methodology. The figure could include embedded assistants, automations, workflows, integrations, or other software objects with different risk levels.
A useful assessment would explain how Reco defines an agent. It would also distinguish active production agents from test systems, abandoned configurations, and low-risk application features.
False positives deserve equal attention. If a product labels too many ordinary workflows as dangerous agents, security teams can lose time investigating low-value alerts.
False negatives present the opposite problem. An incomplete connector or encrypted activity path can leave the most sensitive agent invisible while creating a reassuring dashboard.
Buyers should ask how Reco validates discovery across applications that expose different logs and permission models. They should also examine how the product handles internally built agents with custom tools.
Remediation introduces another uncertainty. Discovering excessive access is valuable, but reducing it without disrupting work requires accurate ownership and business context.
An agent used for month-end reporting may need broad read access during a defined period. Removing that access automatically could break a critical process.
Reco says its context graph helps prioritize risk and enable precise remediation. Enterprises should test that claim against complex workflows rather than treating the graph as a complete policy engine.
The same caution applies to prompt and tool-call inspection. Monitoring a prompt can reveal obvious policy violations, but intent can remain ambiguous.
An agent may assemble a harmful sequence from several individually acceptable actions. A security layer must correlate behavior across time, tools, accounts, and applications.
Encrypted content and data residency rules can also constrain inspection. Regulated organizations may prohibit a security vendor from retaining sensitive prompts or document contents.
Reco’s concentration in financial services could become an advantage because those customers impose demanding control requirements. It could also increase implementation complexity and sales scrutiny.
Strategic investors present another tradeoff. AT&T can help validate enterprise requirements and support distribution, yet one prominent customer does not guarantee repeatable adoption across industries.
The crowded market raises commercial risk as well. Enterprises may delay purchases while they compare specialized products with new capabilities from existing vendors.
They may also consolidate controls under a larger security provider. A startup must then demonstrate either superior coverage or a clear integration role within an established security stack.
Platform vendors could narrow the opportunity by improving native governance. Microsoft, Salesforce, ServiceNow, Google, and other software companies already control important agent deployment surfaces.
Native controls often lack cross-platform context, but they can meet basic customer needs without adding a separate vendor. Reco’s value must remain visible after those baseline features improve.
There is also a question of category boundaries. Agent security overlaps with identity security, data security, SaaS posture management, application security, and AI governance.
Overlap helps Reco address several budgets, but it creates more competition. Buyers may struggle to decide which team owns procurement and which existing product should be replaced.
Reco must avoid becoming another dashboard that identifies risk but sends remediation elsewhere. Its platform will need to connect findings with practical access changes and incident workflows.
Independent case studies would strengthen the company’s claims. Useful evidence would include deployment coverage, time to detect unknown agents, false-positive rates, and completed permission reductions.
Security buyers should also demand adversarial testing. A controlled evaluation can measure whether Reco detects prompt injection, tool misuse, credential abuse, and cross-application data movement.
The financing gives the company time to build that evidence. It does not remove the need for it.
Reco’s latest round should therefore be read as a bet on market timing and architecture. The verdict on operational effectiveness remains open.
Enterprise Buyers Need Outcomes, Not Another Agent Inventory
The winning agent security platform will connect discovery with enforceable controls and measurable reductions in access risk.
An inventory is the starting point because an enterprise cannot govern agents it cannot see. Yet discovery becomes valuable only when it changes a security decision.
A useful platform should identify an agent’s owner, purpose, credentials, tools, accessible data, and recent actions. It should also show how those elements combine into a risky path.
That path matters more than an isolated vulnerability. An agent with a weak prompt boundary presents one level of risk, while the same agent with financial permissions presents another.
Buyers should begin evaluations with concrete scenarios. One scenario might involve an employee leaving while an agent retains access through that person’s delegated credentials.
Another might test whether a support agent can retrieve restricted customer records through a connected knowledge system. A third could measure behavior after a malicious document injects new instructions.
The product should explain both detection and response for each case. A vague risk score offers less value than a trace showing the affected identity, resource, permission, and recommended action.
Security teams should also inspect how a platform separates observation from enforcement. Immediate automated containment is appropriate for some events, while others require human approval.
An agent attempting to send sensitive data to an unknown domain may justify an automatic block. A new internal workflow requesting broader read access might require review instead.
Developers need useful feedback from the same system. A control that only reports to security after deployment encourages repeated mistakes and slower remediation.
Earlier checks can flag excessive tool scopes, unsafe credential storage, or missing approval gates before an agent reaches production. Runtime monitoring can then catch behavior that design-time tests missed.
This combination pressures vendors to cover the full lifecycle without claiming total protection. No platform can guarantee that an adaptive system will always behave safely.
Reco’s graph could support that lifecycle by maintaining context across development and operation. The company still needs to demonstrate how consistently that model works outside its strongest integrations.
Buyers should compare Reco’s approach with gateway, identity, endpoint, and data-security products already in their environment. The relevant question is not which vendor uses the broadest terminology.
The question is which combination closes a documented control gap. In some environments, Reco could become the coordinating layer across applications.
In others, native controls and an existing identity platform may cover the highest-priority risks. A specialized runtime product might be more appropriate when the main exposure sits inside custom agents.
Procurement should therefore follow an internal agent inventory, not precede it. Organizations need to identify which systems can act, whose authority they use, and what information they can reach.
That exercise can also reveal ownership gaps. Security, engineering, data governance, legal, and application administrators often manage different parts of the same agent workflow.
A platform can connect technical objects, but it cannot resolve an unclear accountability model by itself. Enterprises still need policies for approval, monitoring, incident response, and decommissioning.
Decommissioning deserves particular attention. Agents can survive their original projects through unattended service accounts, tokens, scripts, and application connections.
Reco’s reported former-employee example captures that risk. An enterprise should be able to revoke or transfer every agent-related permission when an owner changes roles.
Vendors can distinguish themselves by making those lifecycle controls easy to verify. Evidence should be exportable for auditors and understandable to application owners.
The market will likely reward products that produce clear operational results. Examples include fewer unknown agents, fewer excessive permissions, faster investigations, and shorter containment times.
Funding announcements cannot substitute for those results. Reco’s $55 million expansion creates an opportunity to publish them and compete on more than feature breadth.
Three Signals Will Test Reco’s Agent Security Bet
Reco’s next phase will be judged by integration depth, independently verifiable customer outcomes, and its response to platform competition.
The first signal is whether Reco turns its expanding integration count into deeper controls. New connectors should expose agent ownership, delegated permissions, tool use, and cross-application activity.
A higher integration total will strengthen Reco’s argument only if customers gain useful context from those connections. Shallow inventory coverage would weaken the company’s differentiation.
The second signal is evidence from enterprise deployments. Reco should document how customers reduced unknown agents, dangerous access paths, investigation time, or exposed data.
Customer stories need enough methodology to separate measurable outcomes from promotional claims. Independent validation would carry more weight than anonymous examples or aggregate figures.
The third signal is how competitors and platform vendors respond. WitnessAI, Noma Security, identity providers, endpoint vendors, and major software companies are all moving into adjacent territory.
If buyers adopt Reco alongside those products, its graph may establish a distinct coordinating role. If native features absorb the same use cases, Reco will face pressure to prove greater depth.
Partnerships will offer an early clue. Reco’s work with ServiceNow and its backing from AT&T suggest a strategy built around enterprise distribution and workflow integration.
Execution now matters more than category creation. The agent security market already contains several heavily funded vendors with overlapping messages.
Reco has built a credible case that SaaS relationships and inherited permissions deserve more attention. Its financing gives the company resources to carry that thesis into large, regulated environments.
The unresolved question is whether context mapping can become an enforcement advantage. A graph that only visualizes agent sprawl will struggle in a market full of dashboards.
A graph that consistently finds hidden authority, explains exposure, and enables safe remediation would be more defensible. That is the standard Reco’s customers and competitors will now test.
For developers and enterprise buyers, the practical step is to track evidence rather than funding momentum. Ask vendors to demonstrate discovery, permission analysis, containment, and lifecycle controls against your real applications. Compare those results with the protections already available in your identity, cloud, and endpoint systems. Reco AI agent security funding makes the company a better-resourced contender, but it does not settle the market. Over the next quarter, watch its connector depth, published customer outcomes, and competitive partnerships. Those signals will show whether Reco is building a lasting control layer or joining an increasingly crowded inventory market.



