Security
Neo Raises $100 Million To Secure Enterprise Software As AI Agents Spread
Neo emerged from stealth with $100 million for a control layer that catalogs AI agents, governs tool calls, and attributes autonomous software actions inside enterprise environments.
By Leo W ·

Neo has emerged from stealth with $100 million in seed and Series A funding to tackle a problem that is quickly becoming unavoidable for enterprise security teams: ordinary business software is gaining agentic capabilities faster than security tooling can explain who did what. The American-Israeli startup, based in Boston, says its platform gives companies visibility and control over AI agents, AI-enabled applications, models, extensions, MCP servers, and traditional software across enterprise environments. SecurityWeek reported that the funding came from Andreessen Horowitz, Bessemer Venture Partners, Craft Ventures, and Merlin Ventures, and will be used to expand engineering and go-to-market teams.
The company is entering a market created by a subtle but important shift. Endpoint and SaaS security products were built around a world where human users clicked, typed, opened files, and ran applications. AI agents change that pattern. They can read documents, invoke tools, call APIs, move data, execute code, and act inside workflows using valid user permissions. A security system that sees only the resulting process or API call may not know whether the action came from the person, a sanctioned assistant, a browser extension, an embedded SaaS agent, or a compromised workflow.
Neo's pitch is therefore about attribution and policy. SecurityWeek reported that the platform maintains a continuous catalog of active agents and AI-enabled components, evaluates excessive privileges and configuration vulnerabilities, and traces software actions back to the originating human user, automated agent, or application identity. It can enforce granular policies for tool calls, data movement, agentic workflows, and API access, including pausing suspicious activity for manual review. That is exactly the control plane enterprises will need if AI capabilities keep appearing inside products they already use.

The founding team gives the funding round credibility. Chief executive Nick Warner previously served as president and chief operating officer of SentinelOne and held leadership roles at Cylance, McAfee, and Forepoint. Co-founder Shlomi Salem led detection engineering at SentinelOne, and co-founder Eran Shirazi previously co-founded EasySend. Investors are backing a group that understands endpoint detection and response, but the thesis is that EDR is no longer enough when the endpoint itself becomes a workspace for autonomous software.
Andreessen Horowitz framed the investment as a response to a third generation of endpoint security. The first generation relied on static antivirus signatures. The second watched behavior through EDR and XDR platforms. The third has to govern agents running with user-level privileges. That argument is not marketing abstraction. If Microsoft, Google, Salesforce, ServiceNow, Atlassian, and hundreds of SaaS vendors embed agents into daily workflows, every enterprise will inherit a changing population of semi-autonomous actors. Some will be approved. Some will be shadow IT. Some will arrive through software updates rather than procurement.
The control problem is hard because agents blur identity. A human may ask an assistant to summarize files. The assistant may call a retrieval tool, query a database, send content to a model, write a draft, and update a ticket. If sensitive data moves, who is accountable? The user who made the request, the model provider, the SaaS platform, the extension, or the internal workflow owner? Neo is betting that enterprises will need systems that can answer those questions in real time and block actions when the chain of authority is unclear.

The timing is favorable because AI adoption has outpaced governance. Companies that eagerly adopted coding assistants, meeting bots, document copilots, and customer-service agents are now asking what those tools can see, what they retain, how they make tool calls, and whether security logs can distinguish approved automation from misuse. Traditional data-loss prevention tools can catch some movement after the fact. They are less suited to deciding whether an agent should be allowed to combine a spreadsheet, a customer record, an internal prompt, and an external API call in the first place.
That difference is why agent security is not just another feature inside endpoint protection. An endpoint tool may see a process writing a file or a browser connecting to a service. An agent-governance layer has to understand intent, delegated authority, tool context, and the sequence of intermediate steps. It needs to know that a request began in a customer-support workflow, touched a CRM record, invoked a model, called a ticketing API, and attempted to send a summary outside the organization. Without that chain, security teams may see only isolated events and miss the policy violation created by their combination.
Neo's timing also reflects the spread of MCP servers and tool ecosystems around AI assistants. Developers are connecting models to databases, file systems, calendars, browsers, code repositories, cloud consoles, and internal applications. Those connectors make agents useful because they let models act. They also create a new supply chain. A poorly configured connector can expose sensitive data. A malicious extension can route information to an outside service. A trusted agent can be manipulated through prompt injection embedded in a document or website. Enterprise security teams need visibility into those connections before they can decide which ones are acceptable.
The identity layer is likely to become the hardest part. Many organizations give AI tools access by piggybacking on a user's existing permissions. That is easy to deploy but difficult to govern. A finance employee may be allowed to view payroll data, but an assistant summarizing a meeting may not need the same access. A developer may be allowed to read a source repository, but a code agent should not automatically be allowed to open production secrets or modify deployment settings. Least privilege has to be redesigned for delegated software actors, not only human employees.
Auditing will also have to change. After a security incident, investigators need to reconstruct what happened. In an agentic workflow, the answer may involve prompts, retrieved documents, tool calls, model outputs, approval steps, API responses, and human edits. If those logs are scattered across SaaS products and model providers, attribution becomes slow or impossible. Neo is betting that companies will pay for a consolidated timeline that shows not only which user account was involved, but also which agent, extension, model, and policy decision participated in the action.
The startup's challenge is scope. Enterprise software environments are messy. Companies run old endpoint agents, identity providers, browser extensions, custom internal apps, sanctioned SaaS tools, shadow SaaS tools, developer scripts, automation platforms, and now model-based assistants. Cataloging all of that continuously is difficult even before agent behavior is added. Neo will have to integrate broadly enough to matter without becoming another partial dashboard that security teams must reconcile with existing SIEM, SOAR, EDR, CASB, and identity systems.
The funding size signals that investors believe the category will form quickly. A $100 million early-stage raise gives Neo room to hire, build integrations, and educate buyers before the market vocabulary is settled. But it also raises expectations. Security buyers are skeptical of new acronyms and crowded control planes. To win, Neo will have to show concrete risk reduction: blocked data exfiltration, prevented over-permissioned agents, cleaner audits, fewer blind spots, and policies that business teams can understand without waiting for security engineers to review every workflow.
One reason the category may form quickly is that AI agents create risk in places security teams do not normally inspect closely. A spreadsheet add-on, a browser assistant, a workflow automation, or a customer-support bot may not look like privileged infrastructure at first. Once it can call tools, read documents, and make decisions, it can become a path for sensitive data movement or unauthorized action. The security team needs to discover those agents before it can classify them. That discovery problem alone could justify a new layer of tooling.
Policy enforcement will have to be granular. A company may allow an AI assistant to summarize public documentation but block it from reading source code. It may allow a sales agent to draft emails but not send them without approval. It may allow a coding agent to open pull requests but not merge or deploy. It may allow a support bot to read customer records but not export bulk data. Those distinctions are too specific for broad allow-or-block rules. Neo's value proposition depends on whether it can express those policies in ways that map to real business workflows.
The category also intersects with insurance. Cyber insurers increasingly ask companies to document controls around identity, access, logging, data loss, and third-party software. AI agents add a new set of questions: which agents exist, what permissions do they have, how are tool calls logged, and how can the company prove that a sensitive action was approved? If agentic software becomes common, insurers may start treating agent governance as part of cyber hygiene. That would turn a technical control into a financial requirement.
There is a developer-relations challenge as well. Security controls that block every agent action will be ignored or bypassed. Controls that are too loose will fail. The product has to give developers and business teams a path to register agents, request permissions, test workflows, and see why actions are blocked. That means agent security cannot live only in the security operations center. It has to be usable by the teams building or adopting automation, otherwise shadow AI will grow around it.
Neo's American-Israeli positioning may help it recruit from two strong security labor markets, but the company will still compete for scarce talent. Agent security requires people who understand endpoint telemetry, cloud identity, SaaS APIs, model behavior, prompt injection, and enterprise procurement. That hybrid expertise is still rare. The funding round gives Neo the ability to hire aggressively, yet scaling expertise into a product that works across many environments will be harder than telling a convincing market story.
Agent security also has to deal with prompt injection, the attack class that makes ordinary documents and web pages part of the security surface. An agent may read an email, a ticket, a webpage, or a PDF that contains hidden instructions telling it to ignore policy, reveal data, or call a tool. Traditional security products are not built to interpret natural-language instructions as executable risk. A platform that governs agents will need to understand when content is being treated as instruction, when a tool call is being requested, and whether the request conflicts with policy.
The category may eventually require shared standards. If every vendor describes agents, tool calls, permissions, and approvals differently, enterprises will struggle to compare products or audit behavior across platforms. Security teams will need common event schemas that distinguish human actions from model-generated actions, tool-mediated actions, and automated workflow actions. Neo can help define that language if it moves early, but standards are also an opportunity for incumbents and industry groups. The company is not only building software; it is competing to name the problem.
There is a cultural challenge inside companies as well. Business teams adopt AI agents because they want speed. Security teams introduce controls because they see risk. If those groups talk past each other, employees will route work through unsanctioned tools. The winning agent-security products will let business owners see policies as guardrails that make automation deployable, not as a blanket veto. That requires reporting that connects controls to business outcomes: workflows approved, risks reduced, incidents prevented, and tasks completed within policy.
The urgency will increase as agents move from recommendation to execution. A meeting assistant that summarizes notes is useful but low-risk. An agent that updates CRM records, changes cloud permissions, opens pull requests, files expenses, or contacts customers carries operational authority. Enterprises adopted many SaaS tools before fully understanding their data exposure. Neo is betting that they will not get the same grace period with autonomous agents, because the actions are faster, harder to attribute, and more likely to cross systems.
The first customers for this category will probably be organizations that already feel the pain: financial institutions, healthcare companies, large software firms, defense contractors, and global enterprises with strict audit requirements. Those buyers will not adopt agent controls because the concept is fashionable. They will adopt them if auditors, security incidents, or internal AI rollouts create a concrete need to prove control. Neo's challenge is to convert a broad anxiety about AI agents into specific buying events with measurable outcomes.
If Neo can show those outcomes, it may define a category before larger vendors converge on the same language.
Incumbents will not ignore the space. Identity vendors can extend conditional access to agents. Endpoint vendors can add agent process attribution. Browser-security companies can monitor web-based AI tools. Cloud providers can govern model calls and tool permissions inside their own platforms. SaaS vendors can add native controls for their embedded copilots. Neo's opportunity is to sit above those layers and correlate across them. Its risk is that customers may prefer controls built into the platforms they already buy, especially if budgets tighten or agent adoption consolidates around a few large ecosystems.
There is also a compliance angle. Regulated companies will need to show auditors that AI tools do not bypass data-handling rules, segregation of duties, retention policies, or approval chains. An agent that drafts a contract, changes a customer record, approves an expense, or queries a medical file can create regulated activity even if no human touched the final API call. The enterprise question is no longer whether an AI assistant is allowed in the company. It is which actions the assistant can take, under whose authority, with what evidence trail, and with what ability to stop the action before harm occurs.
Neo will still have to prove it can survive the platform response. Microsoft, Google, CrowdStrike, Palo Alto Networks, Wiz, Okta, Zscaler, and other security and identity vendors all have reasons to build their own agent governance layers. A startup can win if it moves faster, integrates across more surfaces, and defines a category before incumbents standardize it. It can lose if the largest platforms make agent attribution a native feature and customers prefer fewer security consoles. The $100 million round gives Neo time, but not a moat by itself.
The broader signal is that agent security is no longer a niche research problem. It is becoming an enterprise budget line. The same capabilities that make AI agents useful make them hard to supervise: they operate across tools, make intermediate decisions, and act with credentials borrowed from people and applications. Companies that want the productivity upside will need an answer to a basic question after every automated action: what acted, under whose authority, with what data, and within which policy? Neo is one of the first well-funded bets that this question becomes a category.
Topics: Neo, AI agents, cybersecurity, enterprise software