Invest1 publisher3 min readPublished
Prevalent AI takes $22m after nine years of self-funding, and points it at financial crime
The UK graph vendor's first outside round backs a bet that enterprises have stopped shopping for smarter models and started paying to fix their own data.
The Investor · Invest desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- AI company Prevalent has raised $22 million from Integrity Growth Partners, its first external investment in nine years.
- This month the company secured a $22 million investment from Integrity Growth Partners, a growth equity firm headquartered in Los Angeles; the investment marks the company's first major funding round.
- Paul Stokes and Arun Raj set up Prevalent AI in 2017 after they had sold their earlier cybersecurity company, and Stokes refused any external financing for nine years.
- The team of 200 people is currently extending its knowledge graph technology from cybersecurity to address financial crime.
- Stokes told Tech Funding News: "We believed it was possible that, if we raised money too early, we might have been raising it at the wrong time, since the market had not yet recognised what was required."
Compiled by The InvestorSomething wrong?How this is made
Why it matters
Prevalent AI, the UK company set up in 2017 by Paul Stokes and Arun Raj after they sold an earlier cybersecurity business, has taken $22 million from Integrity Growth Partners, a Los Angeles growth equity firm [3][1][2][7]. It is the first external investment in nine years, and the 200-person team is using it to extend its knowledge graph technology from cybersecurity into financial crime [1][4].
The refusal to raise is the more interesting part of the record. Stokes turned down outside financing for nine years, telling Tech Funding News that raising too early would have meant "raising it at the wrong time, since the market had not yet recognised what was required" [3][5]. The one prior transaction, a minority stake bought in 2021 by Istari, part of Singapore's Temasek, was secondary and put no new capital into the business [6]. Stokes says the company was built for large enterprise customers rather than for investor funding cycles, with products co-developed alongside loyal enterprise accounts from the start [9].
The provenance is unusually heavy for a firm this size. Stokes, a New Zealander, spent more than 20 years in UK security data science, first with intelligence and defence agencies and later in commercial cybersecurity [8]. The founding group had GCHQ connections: board member Sir Iain Lobban ran GCHQ from 2008 to 2014, and co-founder Andrew France left GCHQ's Cyber Defence Operations to become chief executive of Darktrace, which listed in London in 2021 and was taken private by Thoma Bravo for $5.3 billion in 2024 [10][11].
What the company sells is a reconciliation layer. It pulls from hundreds of internal tools, security platforms, cloud logs and identity systems into what it calls a sovereign knowledge graph, continuously updated and deduplicated, built and hosted under the customer's control rather than on a shared third-party cloud, and queryable by both human analysts and AI agents [13][14]. Notably, the graph itself is not built with large language models; Stokes argues that would introduce "assumptions and deviations in the graph that aren't accurate" [15]. The company positions itself alongside rather than against general-purpose graph databases such as Neo4j and TigerGraph, which customers often already run, and sells the reconciliation work as a managed product [16]. Its answer to the copyability question is time served: nine years of deterministic reconciliation, against rivals who say it is easy to replicate [22].
Customers are banks, telecoms operators and insurers with more than 5,000 staff and sometimes more than 100,000, spread across regions [12]. Stokes says revenue has doubled each year and concedes that pace gets harder with scale [17]. A doubling rate without a disclosed base is a weak number, and the concession is the honest part.
The timing thesis is that foundation models are, in Stokes's phrase, "already plenty smart enough", and that fragmented internal data is the binding constraint [18]. Gartner forecasts $240 billion of enterprise information security spending in 2026 and expects more than 40% of agentic AI projects to be cancelled, implying fewer than 60% survive [19][20][21].
Watch whether financial crime buyers, who sit in a different budget and a different regulator's line of sight than security teams, buy the same graph. Watch the growth rate as the comparison base rises, and watch whether taking institutional money changes a nine-year habit of building slowly to enterprise specification.