top of page

Reco AI Security Funding Reaches $140M, but a Crowded Market Raises the Bar

5 hours ago
14 min read

Reco raised a $55 million Series B extension, taking total funding to $140 million as enterprises struggle to govern AI agents across sprawling SaaS environments. The Reco AI security funding gives the startup more resources to turn its existing application visibility into an agent security platform.

That transition matters more than the financing headline. Reco previously focused on mapping SaaS applications, identities, permissions, and configuration risks. It now wants to connect those records with agents, their owners, the tools they call, and the data they can reach.

The strategy also places Reco inside an increasingly crowded market. HiddenLayer, WitnessAI, CrowdStrike, and other vendors are approaching agent security through runtime monitoring, identity controls, data governance, or application discovery. Reco must prove that its SaaS context gives it a lasting advantage, not simply a timely message.

Reco AI Security Funding Backs a Broader Agent Strategy

The new capital backs Reco’s shift from monitoring SaaS applications to governing autonomous software that acts through them.

The extension follows a $30 million Series B announced in February 2026. AT&T Ventures, Forestay Capital, and Quadrille Capital participated in the latest financing, according to the funding coverage.

AT&T’s involvement carries added significance because the telecommunications company is also a Reco customer. A customer-investor can provide commercial validation, although that relationship does not establish how consistently the product works across other organizations.

Reco plans to spend the capital on hiring, sales, partnerships, and customer support. Those priorities suggest the company believes its immediate constraint is execution and distribution, rather than identifying another market.

CEO Ofer Klein told TechCrunch that Reco’s valuation had more than doubled since February. He placed it in the high hundreds of millions but did not disclose a precise figure.

Klein also said annual recurring revenue had reached the double-digit millions and that he expected it to triple during 2026. These are management statements, not independently audited results. The company has more than 100 customers, with financial services representing about 40% of its business.

Those numbers give Reco a credible enterprise base, especially in a sector where buyers demand lengthy security reviews. They still leave open important questions about contract size, renewal rates, deployment breadth, and how much current revenue comes from agent-specific products.

The financing history shows how quickly Reco’s positioning has evolved. The company raised $25 million in additional capital in 2025, then announced its $30 million Series B in February 2026. That February round brought its reported total to $85 million.

Reco initially described its core problem as the SaaS security gap. The company focused on applications that security teams could not fully inventory, configure, or monitor. Its more recent materials put AI agents, non-human identities, and cross-application connections closer to the center.

The sequence does not mean Reco abandoned SaaS security. Instead, it treats SaaS as the environment through which many enterprise agents receive permissions and perform work.

That distinction is central to the Reco AI security funding thesis. An agent rarely creates value in isolation. It needs access to email, customer records, documents, ticketing systems, collaboration platforms, and internal databases.

Every connection can also expand the damage caused by a compromised instruction, excessive permission, abandoned account, or poorly configured integration. Reco is betting that its existing application graph provides the context needed to find those combinations.

The financing therefore supports both a product expansion and a market repositioning. Reco must sell security leaders on a broader promise without losing the credibility built around SaaS visibility.

Agent Sprawl Turns Inventory Into a Security Problem

Enterprises cannot govern agents they cannot identify, especially when those agents inherit access from people, applications, and service accounts.

Agent sprawl describes the uncontrolled growth of AI agents across an organization. It includes agents built by internal developers, features activated inside commercial software, browser-based assistants, automated workflows, and tools adopted without formal approval.

This is harder to measure than traditional software adoption. One application can host many agent instances, and a single agent can interact with several business systems. Definitions also vary between vendors, making large agent counts difficult to compare.

Klein said Reco found 21,000 previously unknown agents at one Fortune 100 customer. The customer was not named, and neither Reco nor TechCrunch disclosed the counting method.

The number should therefore be treated as a company-reported example, not a general benchmark. Its significance lies in the visibility gap it describes. A large enterprise can approve major AI platforms while still losing track of the individual automations operating inside them.

Reco also claims it found an agent created by a former employee at a financial services customer. That agent reportedly retained Salesforce access and could send information to a domain the organization could not monitor.

This scenario connects several familiar security failures. The employee had left, but a digital actor associated with that person remained active. The agent also had application access and an external communication path.

Conventional offboarding might disable the employee’s account without identifying every delegated token, workflow, or connected agent. Application administrators might see an authorized integration without knowing that its original owner had departed.

The risk comes from the combination. An agent, credential, data source, and external destination might each appear acceptable when reviewed separately. Together, they can create an unapproved route for sensitive information.

Reco calls the data structure behind its approach a context graph. A graph records relationships among agents, applications, accounts, people, permissions, tools, and data resources. Security teams can then examine what an agent can reach, rather than reviewing isolated alerts.

That design resembles the relationship mapping already used in identity, cloud, and SaaS security products. The agent-specific challenge is that permissions and actions can change during a workflow.

An employee typically follows a recognizable login and application pattern. An agent can process an instruction, call several tools, retrieve documents, update a record, and send a response within one automated sequence.

The agent may also act through a human identity, a service account, or its own credential. That variety complicates ownership and accountability.

Reco says its platform integrates with more than 280 applications. Klein also said the company can add integrations within days and use browser or network signals to find agents beyond directly connected applications.

Those claims matter because discovery coverage determines the quality of every later control. A graph with incomplete application or identity data can present a confident but misleading view.

Security teams should ask what Reco counts as an agent, which signals identify one, and how duplicate instances are handled. They should also ask whether discovery continues after deployment and how quickly the graph reflects revoked permissions.

The broader agent governance challenge is already affecting adoption. Google Cloud reported that 79% of surveyed technology leaders viewed security, governance, or operations as their largest obstacle to scaling inference.

The same report found that 35% of senior IT decision-makers cited inadequate security for multi-system access as a primary barrier to agent deployment. These vendor-sponsored figures require context, but they support the central issue: agents become useful by crossing system boundaries.

Reco is positioning inventory as the first control point. The company’s harder task is showing that discovery leads to reliable policy enforcement when agents change tools, permissions, and behavior.

Reco’s SaaS Graph Faces Runtime Security Rivals

Reco is competing against a different security route, one that prioritizes what an agent does during execution instead of starting with application relationships.

The AI agent security market does not have one settled product boundary. Vendors use similar language while protecting different parts of the technology stack.

Reco begins with enterprise applications and the identities connecting them. Its platform aims to identify agents, associate them with owners, map permissions, inspect tool calls, and restrict unnecessary access.

HiddenLayer approaches the problem from AI workload and runtime security. Runtime security means observing and responding to behavior while a model or agent is operating.

HiddenLayer raised a $100 million Series B in September 2026. The company said it would expand protections for agents in production and for autonomous coding tools that write, review, or ship code.

Its runtime security strategy focuses on detecting prompt manipulation, tool misuse, and unauthorized actions as they occur. HiddenLayer also covers model discovery, attack simulation, and AI supply-chain risks.

CrowdStrike brings an endpoint and detection-response heritage. Its agent security products connect prompts and agent activity with downstream execution on devices and infrastructure.

The company’s agent lifecycle controls include discovery, identity, software supply-chain protection, and runtime containment. CrowdStrike says agents require continuous authorization because they can execute code, access files, and move sensitive information.

These approaches overlap, but their starting points differ.

Reco asks which agents exist, who owns them, and which SaaS resources they can reach. Runtime-focused vendors ask what happens while an agent processes instructions and executes actions. Endpoint vendors examine the device and workload activity generated by those actions.

An enterprise will probably need elements of all three. A complete control path might discover an agent through SaaS telemetry, verify its identity, limit its permissions, inspect its tool calls, and stop dangerous behavior at runtime.

The commercial question is which vendor becomes the main control plane. Security teams generally resist adding separate consoles for every new risk category. Established platforms can bundle agent protections into existing contracts and operational workflows.

Reco’s advantage is context across cloud applications. If its graph already maps people, accounts, permissions, and SaaS connections, adding agents can give customers a faster route to usable governance.

Its disadvantage is that mapping access does not automatically reveal every harmful action. An agent may have legitimate permission to read a document and send an email. The security problem appears when malicious or misleading content causes it to combine those capabilities.

This is where prompt injection becomes relevant. Prompt injection occurs when untrusted content alters an agent’s instructions, potentially redirecting its tools or exposing data.

A malicious instruction might be hidden in a web page, document, message, or tool response. The agent can encounter it during an otherwise approved task.

Application context helps estimate the possible damage, but runtime inspection helps identify the dangerous sequence. Reco says it can inspect prompts and tool calls, bringing it closer to that runtime territory.

The market will test how deeply that inspection works across different models and applications. It will also test whether Reco can respond quickly enough without blocking legitimate automation.

Security buyers should resist broad claims that one graph, gateway, or endpoint sensor solves agent risk by itself. Each sees a different portion of the workflow.

A practical evaluation should follow one agent from creation through authentication, tool selection, data access, execution, and retirement. Buyers can then identify which stages remain invisible or depend on another product.

Reco’s product will be strongest when its application relationships lead directly to enforceable decisions. A security team should be able to identify an abandoned agent, understand its access, revoke a risky connection, and confirm that the action took effect.

The funding gives Reco time to build that proof. It does not remove the pressure from larger platforms or well-capitalized AI security specialists.

The Funding Validates Demand, Not Reco’s Category Lead

Investor interest confirms that enterprises will spend on agent security, but it does not determine which technical architecture will win.

At least two dozen companies now sell some form of AI agent security, according to TechCrunch’s review of public company profiles. Their products cover tool vetting, data access, identity, runtime monitoring, prompt security, and shadow AI discovery.

That density creates a difficult buying environment. CISOs must evaluate products before common definitions, benchmarks, and deployment patterns have stabilized.

Vendors can describe the same feature using different language. One company’s agent inventory can resemble another company’s shadow AI discovery. Context graphs, knowledge graphs, identity graphs, and asset graphs may overlap substantially.

The reverse problem also exists. Similar phrases can conceal important technical differences. “Agent security” can refer to monitoring prompts, protecting models, governing permissions, screening Model Context Protocol servers, or containing endpoint activity.

Model Context Protocol, commonly called MCP, is a standard for connecting AI systems with tools and external data. MCP expands what agents can do, but it also creates another integration layer that defenders must review.

Reco needs to demonstrate where its platform controls behavior and where it only reports risk. Visibility has value, but security teams eventually need to approve, restrict, isolate, or remove an agent.

The company must also substantiate its customer examples. The reported discovery of 21,000 unknown agents is striking, yet readers cannot evaluate the result without a definition or methodology.

The count might include embedded assistants, agent instances, workflows, tools, service accounts, or repeated observations. Each interpretation has different security implications.

A smaller number of agents with broad access could present more risk than thousands of narrow automations. Raw inventory size should not become a substitute for exposure analysis.

Reco says financial services customers represent about 40% of its business. That concentration provides access to demanding buyers with strict audit, identity, and data controls.

It can also raise expectations. Banks and other regulated institutions need clear evidence trails, consistent enforcement, regional controls, and predictable integration behavior.

Agent governance must extend into offboarding and change management. When an employee changes roles, every delegated permission and associated agent should be reviewed. When an application modifies its AI features, the organization needs to detect new identities and connections.

The same requirement applies to knowledge systems. An agent’s output is only as controlled as the documents, messages, and databases it can retrieve. Teams building internal AI workflows need clear access boundaries around their knowledge base, not simply a record of which model generated an answer.

Another uncertainty concerns false positives. Browser and network signals can broaden discovery, but broad detection can also classify ordinary automation as an agent.

Security teams will ignore alerts if the platform cannot rank them by credible impact. Reco’s graph must distinguish a low-risk assistant from an abandoned workflow with write access to customer systems.

False negatives carry the opposite cost. An agent that avoids known browser, network, or application signals can remain absent from the graph. Organizations should test how Reco handles custom agents, internal APIs, local models, and automation platforms.

Data access is another practical concern. A platform that maps enterprise applications and identities may process highly sensitive metadata. Customers will need to examine retention, regional hosting, administrative access, and the scope of collected prompts.

Inspecting prompts can improve detection, but it may also expose confidential content to another security system. Reco must make collection boundaries and redaction controls clear.

These questions do not negate the funding case. They define the work that follows it.

The strongest evidence will come from deployments that show lower exposure, faster investigation, and dependable policy enforcement. Revenue growth and customer counts matter, but security outcomes will determine whether Reco becomes durable infrastructure.

Why Existing Security Tools Cannot Simply Absorb the Problem

Agent security combines familiar controls in unfamiliar sequences, making integration more important than adding another isolated product.

Identity and access management already determines who can enter enterprise systems. Data loss prevention already watches for sensitive information leaving approved boundaries. Endpoint detection already observes processes, files, and network activity.

SaaS security tools already inventory applications and configuration risks. Model security products test prompts, training data, and inference behavior.

Agents cross these categories because they translate language into actions. They can authenticate like identities, communicate like users, call software like applications, and change their behavior based on retrieved content.

Traditional controls can still help. The challenge is connecting their observations into one decision before an automated workflow completes.

Consider a sales agent preparing a customer update. It might retrieve account details from Salesforce, search meeting notes, read support tickets, create a document, and send an email.

Each action can be authorized. The combined workflow can still expose information to the wrong recipient if the instruction, identity, or destination changes.

An application-level graph can show the agent’s potential reach. Runtime telemetry can show the sequence it actually executed. Identity controls can verify the account and narrow its permissions.

Data controls can identify protected content. Endpoint or cloud monitoring can contain downstream activity when the workflow moves beyond SaaS APIs.

No single layer replaces the others. The emerging contest is therefore about coordination.

Reco’s integration footprint gives it one path toward coordination. It says its platform covers more than 280 applications and can add new integrations within days.

That breadth can help buyers avoid separate discovery projects for each application. However, integration counts reveal little about depth.

One connector might expose users and permissions. Another might provide configuration events, agent inventories, prompt records, and real-time enforcement. Buyers should evaluate accessible objects and supported actions for every critical system.

CrowdStrike argues that effective protection needs visibility, identity, and runtime response. HiddenLayer emphasizes continuous testing because design-time reviews cannot predict every production interaction.

Reco’s model is compatible with those arguments if it becomes the relationship layer connecting their signals. It competes with them if it claims to replace controls that operate closer to execution.

Partnerships will therefore matter as much as product features. Reco announced a ServiceNow partnership around the same period as the financing, pointing toward integration with existing security and workflow processes.

The company has also worked with data security vendors. These connections can help security teams understand not only which resource an agent accessed, but also whether that resource contained regulated or confidential information.

A coordinated system should answer several questions after an incident. Which agent acted, who owned it, what instruction initiated the workflow, which tools ran, what data moved, and which policy stopped it?

It should also preserve evidence without requiring analysts to reconstruct the event across several consoles. That requirement gives graph-based products an opportunity, but only if their records remain complete and current.

The operational model matters for employees too. Knowledge workers will continue adopting assistants that reduce repetitive tasks. Blocking every unapproved tool can push usage further outside monitored systems.

Organizations need a path for reviewing, approving, and narrowing access without making every experiment wait through a long procurement cycle. A searchable record of approved workflows can support that process.

Teams can apply the same discipline to their own AI workflows. They should identify data sources, intended outputs, human approval points, and the credentials used at each step.

Reco’s opportunity is to make that discipline enforceable across enterprise SaaS. Its risk is becoming another dashboard that describes agent sprawl without reducing it.

Three Signals Will Show Whether Reco’s Bet Is Working

The next test is whether Reco converts its funding into measurable control, defensible integrations, and durable enterprise adoption.

The first signal is evidence from production deployments. Reco should provide clearer definitions for agents, identities, and risky connections, alongside repeatable measurement methods.

Customer case studies should explain the starting environment, the discovery process, the controls applied, and the resulting reduction in exposure. Large inventory numbers attract attention, but remediation outcomes help buyers evaluate value.

Useful evidence would include how quickly organizations identify unowned agents, revoke abandoned credentials, or reduce excessive permissions. It should also describe false-positive rates and the applications covered.

If Reco publishes consistent methodology and independent customer validation, its context graph argument becomes stronger. If future disclosures rely mainly on dramatic anonymous counts, buyers may struggle to compare the product.

The second signal is competitive convergence. CrowdStrike, HiddenLayer, WitnessAI, major cloud platforms, and identity vendors are adding overlapping controls.

Reco needs to show that its SaaS foundation produces information competitors cannot easily reproduce. Faster integration development could help, especially as software companies embed agents into existing applications.

Depth will remain decisive. Reco should prove that its connectors can observe agent ownership, permissions, tool calls, and policy changes across critical enterprise platforms.

The company must also decide when to partner and when to compete. Integrating with runtime and endpoint providers can make Reco more useful. Trying to replace every security layer would stretch product scope and place it against larger platforms.

If Reco becomes a trusted source for agent-to-application relationships, it can occupy a clear place in the stack. If established vendors deliver comparable discovery through tools customers already own, Reco’s differentiation will narrow.

The third signal is commercial quality after the financing. Management expects annual recurring revenue to triple during 2026, but the more important questions concern retention and product adoption.

Buyers should watch whether existing SaaS security customers expand into agent controls. Expansion would support Reco’s claim that its installed base provides an efficient route into the new market.

New customer composition will also matter. Continued strength in financial services could demonstrate that Reco meets demanding governance requirements. Broader adoption would reduce dependence on one industry.

The $55 million extension gives Reco a longer runway for engineering, support, partnerships, and sales. It also raises expectations because the company has now reported $140 million in total capital.

The Reco AI security funding is best understood as a bet on control across relationships. Agents obtain their usefulness from the applications, identities, tools, and data surrounding them. Reco wants its graph to make those relationships visible and governable.

That thesis is credible, but the market remains unsettled. Runtime specialists can argue that access maps do not capture behavior. Endpoint platforms can argue that containment must occur where actions execute. Identity vendors can argue that continuous authorization belongs within their control plane.

Enterprise buyers should ask which product can follow an agent across the entire sequence, from creation and authentication to action and retirement. They should also demand evidence that policies work across both commercial applications and internally developed agents.

Reco has secured the capital to make its case. Now it must show that an expanding graph can do more than reveal agent sprawl after it happens.

The next few months should clarify whether customers treat Reco as their central agent governance layer or as one component within a larger security stack. Which outcome would make the most sense for your organization’s agents, identities, and application estate?

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page