The CODEW | Company Deep Dive
The Pitch
Neo emerged from stealth this week with $100 million in
funding across seed and Series A rounds, led by Andreessen Horowitz and Bessemer Venture Partners, with additional participation from Craft Ventures and Merlin Ventures. The Boston-based company, founded in 2025, describes itself as building "Agentic Software Control": a real-time layer that lets security teams inventory, assess, and govern the AI agents, AI-enabled applications, browsers, identities, plugins, extensions, and traditional software increasingly operating inside the enterprise.
 |
| Neo: why AI security startups are attracting mega-rounds — The CODEW. |
It's a crowded thesis with an uncrowded founding team. CEO Nick Warner spent two decades in cybersecurity leadership, including senior roles at Cylance, McAfee, and Forcepoint, before joining SentinelOne, where he designed and built the company's go-to-market organization and, as president and chief operating officer, helped take the company public in 2021. Co-founder and Chief Product Officer Shlomi Salem led SentinelOne's detection engineering function for more than a decade, co-leading its in-house threat research team and building the threat-actor profiles that powered the company's entire security platform. Co-founder and Chief Technology Officer Eran Shirazi previously co-founded the customer-experience software company EasySend. The broader team also includes alumni of Wiz and Palo Alto Networks — two of the most successful cybersecurity exits of the past decade — giving Neo a founding bench with direct experience building, scaling, and selling category-defining security platforms before.
The Problem Neo Says It's Solving
Warner has framed the company's mission around a structural shift in how enterprise software behaves. "Enterprise security was built for a world where software behaved predictably," he said in the company's launch materials. That world, in Neo's telling, is ending: AI agents and agentic capabilities are being embedded into browsers, developer tools, SaaS platforms and traditional applications, giving software the ability to reason, act, invoke tools, and move through multistep workflows using valid — often highly privileged — user permissions, without the predictable, rules-based behavior that traditional application security tooling was designed to monitor.
Neo's platform maintains a live, continuously updated catalog of the active elements running across an enterprise environment — agents, models, browser extensions, and even Model Context Protocol (MCP) servers, the increasingly common integration layer connecting AI models to external tools and data. It then scans those elements for risky permissions and misconfigurations. Critically, the platform includes real-time attribution mechanisms that trace individual software actions directly back to the originating human user, automated agent, or specific application identity — creating what the company describes as an immutable audit trail for agentic activity. On top of that visibility layer, Neo offers native enforcement: security teams can establish granular policies governing tool calls, data movement, API access, and agentic workflows, customized by role or identity group, and the platform can block risky activity or redirect prompts that fall outside approved boundaries directly, without handing off enforcement to a separate security product. In practice, that means Neo is positioning itself not just as a monitoring or observability tool, but as an active control plane sitting between agentic software and the systems it touches.
Why Investors Are Writing Nine-Figure Checks for Category-Defining Bets
Neo's raise is not an isolated data point — it's part of a broader pattern in which "agentic AI security" has become one of the most heavily capitalized sub-markets in venture right now. Earlier this year, in the two weeks surrounding the RSA security conference alone, more than $392 million in new agentic
AI security funding was announced, including Oasis Security's $120 million round for non-human identity and agentic access governance. Separately, market trackers estimate that security-focused agentic AI startups collectively raised well over $260 million in early 2026, with pure-play entrants like Armadin — founded by the creator of Mandiant — pulling in nearly $190 million in combined seed and Series A funding on the strength of founder pedigree alone, even before shipping a mature product.
Several forces are converging to produce this level of investor enthusiasm, and Neo's raise touches on nearly all of them.
1. A genuinely new attack surface. As AI agents gain the ability to take actions, call tools, and move through workflows with limited human oversight, they create a category of risk that didn't meaningfully exist before 2024 — one where a compromised or misconfigured agent can access sensitive data or execute changes at machine speed, using credentials that look, on paper, entirely legitimate. Security researchers increasingly describe agentic AI systems as inevitable high-value targets as adoption scales, precisely because they combine broad system access with behavior that is far less predictable than traditional software.
2. No incumbent has locked up the category yet. Unlike endpoint security or identity management, where established players like CrowdStrike, Okta and Microsoft have dominant positions built over a decade or more, agentic AI governance is still up for grabs. Microsoft's Copilot Studio is often cited as an early leader in the adjacent agent-building space, but the security and governance layer specifically is widely viewed as unsettled — and investors tend to pay a premium for credible teams entering categories before a winner has emerged, betting that early leadership compounds into durable advantage.
3. Founder pedigree substitutes for product maturity. Because the market is so new, few startups have years of enterprise deployment data to point to as proof of product-market fit. Instead, investors are betting heavily on repeat founders with direct experience building and scaling the last generation of security platforms — which is precisely Neo's positioning. Warner's SentinelOne go-to-market and IPO experience, and Salem's decade of detection engineering leadership, function as a credibility shortcut in a market where traditional diligence signals — retention data, annual contract value growth, churn rates — are largely unavailable this early. Andreessen Horowitz general partner Zane Lackey underscored this explicitly in backing the round, noting that Neo's founders "have built category-defining security platforms before" and are "uniquely positioned to build the control layer this new generation of enterprise software requires."
4. The M&A market is validating the thesis in real time. Acquirers are moving just as aggressively as venture investors. Palo Alto Networks closed a roughly $25 billion acquisition of CyberArk in February, ServiceNow spent a combined $14.4 billion acquiring Armis and Moveworks, and Alphabet finalized its $32 billion purchase of Wiz — deals that collectively signal large platform vendors are racing to assemble AI-agent discovery, governance and identity capabilities rather than build them from scratch internally. For venture investors, every large acquisition of an AI-security startup is a data point supporting the thesis that a well-positioned independent company could command a similar premium down the line — and it raises the pressure on incumbents to either build or buy quickly, which in turn sustains the exit environment new entrants like Neo are underwriting against.
5. Enterprises are moving faster than their security teams can track. Employees are adopting AI agents and copilots organically, and software vendors are embedding agentic features into products enterprises already use — often without formal procurement review or security sign-off. Gartner has projected that the share of enterprise applications with agentic capabilities could jump from roughly 5% in 2025 to as much as 40% by the end of 2026, a rate of change that has historically produced exactly the kind of security gap that spawns large, durable franchises. That combination of fast, decentralized adoption and thin oversight mirrors the setup that made cloud security posture management and CASB (cloud access security broker) tools into billion-dollar categories a decade earlier, once enterprise SaaS adoption outran the security team's ability to track it.
How Neo Positions Itself Against the Field
Neo enters a market that already includes several well-funded and credible competitors, each attacking a slightly different slice of the same underlying problem. Oasis Security has focused specifically on non-human identity governance — securing the credentials and access tokens that agents and service accounts use, rather than the agents' behavior itself. WitnessAI has positioned itself around AI usage governance and policy enforcement for generative AI tools broadly, with an emphasis on data loss prevention and compliance. Armadin, founded by Mandiant's creator, is leaning heavily on incident-response and threat-intelligence pedigree to build trust with security operations teams evaluating agentic risk.
Neo's differentiation, based on its public positioning, is breadth combined with enforcement: rather than focusing narrowly on identity, or narrowly on usage policy, Neo is attempting to unify inventory, posture assessment, attribution and real-time enforcement into a single control layer spanning agents, applications, browsers and traditional software alike. That's an ambitious scope for a company just emerging from stealth, and it puts Neo in more direct competition with platform-scale incumbents — not just other well-funded startups — as CrowdStrike, Microsoft, Okta and others inevitably extend their existing platforms toward agentic governance rather than cede the category to new entrants.
The Risks
Neo's bet is not without real uncertainty. The agentic
AI governance market remains conceptually undefined — there's no industry consensus yet on what "securing an AI agent" fully entails in practice, which means Neo, its competitors, and its prospective customers are all still negotiating what a complete product in this category should look like. Consolidation is already reshaping the competitive landscape faster than most startups can establish independent footholds; CISOs who sign with a standalone vendor today may find that vendor absorbed into a larger platform's roadmap within a year or two, as has already happened following several of 2026's biggest security acquisitions. That dynamic cuts both ways for Neo: it validates the category and creates acquisition upside, but it also means Neo is racing against a shrinking window in which independent, best-of-breed vendors remain the default choice for enterprise buyers.
There's also a more fundamental product question underlying the whole category: does a platform like Neo's actually reduce risk in live production environments, or does it primarily provide visibility and after-the-fact reporting — valuable, but a meaningfully lower bar than genuine, real-time control? Neo's own positioning suggests it intends to enforce policy and block risky activity outright, not merely observe and alert on it, which is a substantially harder technical and organizational trust problem than inventory and monitoring alone. Enterprises tend to be far more cautious about granting a new vendor the authority to autonomously block or redirect production workflows than they are about granting read-only visibility — meaning Neo's path to broad enforcement-level deployment, as opposed to observability-level deployment, may be slower than its funding round and messaging suggest.
Finally, Neo faces a talent and execution question common to well-funded but young
security startups: the company said it plans to use its $100 million to rapidly scale both its engineering and go-to-market teams, which means much of its actual product depth and market validation still lies ahead rather than behind it. A strong founding team and a large round buy credibility and runway, but they don't yet constitute proof that Neo's specific architectural approach to attribution and enforcement will hold up against adversarial, fast-moving agentic threats in production at scale.
The Bigger Picture
Neo's $100 million round is best read less as a bet on one company and more as a bet on a category. Investors across the market — from Andreessen Horowitz and Bessemer backing Neo, to the syndicates behind Oasis Security, Armadin and WitnessAI — are converging on the same conviction: as enterprise software becomes agentic, governance and security for that software will become as foundational, and as valuable, as identity and access management became in the cloud era. The M&A backdrop — Alphabet's $32 billion Wiz deal, Palo Alto Networks' $25 billion CyberArk acquisition, ServiceNow's $14.4 billion in combined AI-security-adjacent purchases — suggests the platform vendors agree, and are already paying up to avoid being caught flat-footed.
Whether Neo becomes the category's defining platform or one of several credible contenders will depend less on its founding pedigree, which is already well established, and more on whether it can convert inventory and visibility into genuinely trusted, production-grade enforcement before a platform incumbent extends its existing footprint into the same territory — or before a faster-moving, more narrowly focused startup gets there first. At $100 million and roughly a year old, Neo has bought itself the runway to make that case. It hasn't yet proven it.
Sources
This analysis is based on official company announcements, investor commentary, and independent reporting, including:
Advertisement
Building instead of buying? Start with a company that actually exists.
Every "build vs. buy" decision starts with a more basic one: is your company legally formed yet? Firstbase handles US incorporation end-to-end — LLC or C-Corp setup, EIN registration, a business bank account, and ongoing compliance — all from one dashboard, no lawyer required.
Start Your Business with Firstbase →
Company Deep Dive is a flagship editorial series from The CODEW that examines the pivotal events, strategic decisions, products, funding rounds, acquisitions, and leadership moves shaping technology companies. Each article goes beyond the headlines to explain what happened, why it matters, and how it could influence the broader technology industry.
No comments: