AI security startup Reco closed a $55 million Series B extension, bringing total funding to $140 million. AT&T's venture arm Forestay and Quadrille Capital participated in the round, which follows a $30 million Series B in February.
The capital influx reflects a straightforward market problem: enterprises are deploying AI agents at scale without visibility into what data those agents can access or what permissions they hold. Security teams lack baseline inventory, let alone governance.
At least two dozen companies on Crunchbase and PitchBook now market AI agent security solutions. Reco's differentiation hinges on its context graph—a data model that maps agents to applications, user accounts, and permissions. The platform lets security teams visualize agent access and revoke unnecessary privileges as deployments expand.
The company repositioned from SaaS and AI platform security to focus on agent governance after customer deployments accelerated last year. Reco co-founder and CEO Ofer Klein said market demand extends beyond securing individual agents to encompassing the entire ecosystem.
Reco's platform identified 21,000 agents unknown to one Fortune 100 customer. At a large financial services firm, it discovered an agent created by a former employee that retained access to Salesforce data and could share it with an untracked external domain.
Chris Sestito, co-founder and CEO of rival HiddenLayer, said the calculus shifts once agents reach production. HiddenLayer's customer base includes over 50 companies running AI agents in production environments that touch critical systems and sensitive assets.
Cymphony, another competitor in the space, reported finding approximately 85,000 files at a U.S. public company that had become accessible to AI tools and agents.
These numbers explain the investor appetite. Agent sprawl is not theoretical risk—it is operational exposure at scale with no clear ownership or remediation path.


