Invest1 distinct publisher3 min readPublished
Sequoia and Greenoaks led the round for a 40-person company founded in February, which makes the priced asset a research library showing 6.7 million installs of add-ons that fetch their instructions from sources nobody vetted.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
The asset being priced is the research. It is not the product, which the report describes only as an inline firewall filtering what enters an agent's context rather than fencing what the agent is permitted to do [7]. And it is not revenue, since Calcalist's account carries no valuation, no revenue figure and no customer count [15]. Two studies do the work of a pipeline: more than 17,800 public AI add-ons, across roughly 6.7 million installations, taking instructions from untrusted external sources [8], and AI Skills wearing Anthropic and OpenAI branding specifically to get past platform security review, one of which could execute arbitrary code on enterprise systems [9].
Divide those two numbers and the average flagged add-on carries about 376 installations [17]. That ratio describes a broad, thin problem: thousands of small artifacts rather than three big ones, so there is no single takedown that resolves it and no inventory a CISO can produce on a Friday afternoon. That is a good shape to sell a filtering layer against. It is also a shape in which most individual items are too obscure to have hurt anyone yet.
Fifty million dollars across 40 employees is $1.25 million a head [16], which is a hiring authorisation more than a burn rate, and the report says the focus of that headcount is a research laboratory on AI and agent behaviour [5]. The named senior hire is Ryan Knisley, formerly chief information security officer at Disney and at Costco [6]. So the money is going into evidence production and into somebody who has sat on the buying side of the table twice, which is a bet that the constraint is the procurement conversation rather than the code.
This reads differently depending on what happens next. Anthropic and OpenAI could make Skills and MCP servers signed and verifiable at install, at which point provenance is settled upstream and runtime filtering is a thinner business than $50 million implies; AIR's own finding that impersonators were built to bypass platform review is evidence that such review already exists and is being iterated on [9]. Or the incumbent proxy and data-loss vendors ship context filtering as a feature and AIR is bought rather than built into a category. Or the load-bearing claim holds: co-founder and CEO Yair Saban argues the danger is malicious information reaching the agent, not excessive permissions, and names installed extensions and tools, fraudulent websites and internal organisational data as the three sources [11], while granting that organisations are extending trust and permissions as they come to rely on agents [12].
This is probably wrong, but the research library looks like the more durable half of the company, because a number travels into a board deck faster than a product travels into a network path, and Saban's framing of a firewall for what enters an agent's context [10] is a category name attached to a citation rather than to a deployment. The thesis breaks the day installed agent tooling ships signed by default, since filtering at runtime is worth less once provenance is fixed at install. Until then, 17,800 is a question that arrives before anyone has the inventory to answer it.
Ranked by verification strength, evidence, and original report placement.
AIR describes its product as an inline firewall for AI agents, a system designed to protect what enters an agent's context rather than simply restricting what the agent is allowed to do.
Saban told Calcalist: "Every enterprise has a firewall protecting its network. Now they need one protecting their AI agents... AI agents need a new kind of firewall, one that protects what enters their context."
Saban says the risk comes from exposure to malicious information rather than unnecessary permissions, and names three main sources: extensions and tools installed on an agent, websites it encounters online including fraudulent or fake sites, and internal organizational information.
Saban says AI agents are "a hedged risk" and that organizations are gaining trust in agents, counting on them to deliver products, and granting increased permissions.
Calcalist's report of the round states no valuation, no revenue figure and no customer count for AIR.
Cybersecurity company AIR Security raised $50 million in funding led by Sequoia Capital and Greenoaks.
Distinct publishers with included, body-backed reporting in this cluster.
Follow any of these and your For You feed starts watching them — no settings page required.
build
The $559M-versus-$12.3B quarter matters more than the $65B run rate4 distinct publishers
invest
The first AI IPO writes the comp sheet, and Anthropic is holding the pen1 distinct publisher
product
A 2x LLM bill is not a bug report: token spend is an observability problem1 distinct publisher
security
Air Security hijacked live Official MCP Registry entries by buying their expired domains1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One outlet, launch-day numbers, one interested source
Everything here rests on a single Calcalist story published the day AIR left stealth, and inside it on the company's own research and its CEO's quotes. The round facts are the kind that get corrected fast if wrong; the 17,800 add-ons and the Anthropic- and OpenAI-branded Skills are not, and no methodology, sample or platform response accompanies them.
Selling, allegedly; nothing you can count
The only commercial signal is Saban saying there are big customers, followed by no name, no number and no contract detail. Forty employees and a senior CISO hire show intent to sell into large enterprises, not that large enterprises have bought. The 6.7 million installs measure the problem's spread, not AIR's footprint.
Firewall-for-agents framing runs ahead of the receipts
"Every enterprise has a firewall protecting its network. Now they need one protecting their AI agents" is a category claim, and $50 million six months in prices it as if the category already exists. What is actually demonstrated is a research census and a product description. The gap is between the size of the analogy and the absence of a single named deployment.
The research and the remedy have the same author
AIR published the studies that define the danger and sells the filter for it, and the studies surfaced on the day it needed attention and a valuation. The angel list — Wiz, Cognition, Clay, Eon founders — is a network with reason to see this category grow, and the co-leads had already committed before any of these numbers were checked.
Solid on the money, thin on everything after it
We would defend the round, the founders, the headcount and the Knisley hire — those are checkable, publicly contradictable facts. Confidence drops sharply on the threat numbers and the commercial story, where a single interested source is all our coverage has.