Terms such as “AI sprawl” have become prevalent in tech social media and thought leadership as organizations begin to deploy AI agents in significant numbers. However, CISOs concerned about securing flocks of agents suddenly functioning across networks are likely discovering a new variety of sprawl: vendors offering assistance.
A brief look at public profiles on Crunchbase and PitchBook reveals at least two dozen companies providing some type of AI agent security. Some vendors evaluate the tools that agents utilize, while others assist firms in controlling the data their agents can access. Others, like CrowdStrike, are developing detection and response measures on the devices where agents operate, and still others aim to identify and rectify unauthorized AI usage.
The offerings vary, naturally, but their claims to detect and regulate agents sound remarkably alike, incorporating knowledge graphs, ongoing monitoring, runtime security, tool accessibility, MCP assessment, and similar features.
Some are even enhancing their products to join the trend. Until last year, AI security startup Reco primarily focused on selling software to map and secure SaaS and AI platforms. Now, it has shifted towards a more comprehensive solution that employs a context graph to link agents to applications, individuals, accounts, and permissions, giving security teams insight into what an agent can access and the ability to restrict unnecessary access.
Reco’s co-founder and CEO Ofer Klein stated that the most significant shift over the past year that encouraged the startup to expand its focus was the rapid pace at which companies are creating and deploying AI agents, outpacing their ability to monitor them. He mentioned that at one of the startup’s Fortune 100 clients, Reco’s platform uncovered 21,000 agents that the company was unaware of. Additionally, at a prominent financial services client, the startup claims it detected an agent established by a former employee that could access Salesforce and transmit that data to a domain the company was blind to.
“The current market demand for agent security is not just related to the agent itself; it encompasses the entirety of the ecosystem from end to end,” Klein told TechCrunch in an exclusive discussion.

Klein is not the only one emphasizing the importance of companies securing this sprawl. Security startup HiddenLayer’s co-founder and CEO, Chris Sestito, mentioned earlier this month that when agents move into production, their costs and risks transition from theoretical to “full scale really quickly,” and that over 50 of his clients have AI agents in production interacting with critical systems and sensitive assets.
Cymphony, another AI startup, reported that at one U.S. public company, it discovered approximately 85,000 files that had become accessible to AI tools and agents.
There is certainly no lack of investors interested in companies that can profit from assisting businesses in locating and securing these agents, and Reco has taken advantage of that demand: The startup announced on Tuesday that it secured $55 million, building on a $30 million Series B funding round in February. AT&T, one of its clients, invested in the extension through its venture arm, along with Forestay and Quadrille Capital.
Klein indicated that the company’s valuation has “more than doubled” since the initial announcement of the Series B in February, vaguely estimating it in the “high hundreds of millions,” although he refrained from providing specific details. Currently, annual recurring revenue is in the “double-digit millions of dollars,” he stated, and he anticipates that it will triple this year. The startup has exceeded 100 clients, with financial services firms making up roughly 40% of the business.
Reco’s strategy appears to be that its current breadth of coverage concerning SaaS applications and the AI agents they increasingly offer will help differentiate it in the market. The company presently integrates with over 280 applications, and Klein asserts that new integrations can be implemented within days. He noted that the platform employs browser and network signals to detect agents outside the applications it connects to directly within organizations, and it possesses controls to examine prompts and tool calls.
The startup intends to utilize the new funding for recruitment, sales, partnerships, and customer support. This latest round of funding elevates Reco’s total capital raised to $140 million.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
