Product1 publisher3 min readPublished
Reco takes $55 million into an agent security market where two dozen vendors sound alike
Reco, whose software maps what AI agents can reach and cuts unneeded access, added $55 million in a field of at least two dozen rivals. Their pitches share one vocabulary, so a buyer has to compare what each product does once it finds an agent.
The Product Desk · Product desk

What happened
- Until last year Reco mostly sold software to map and secure SaaS and AI platforms, before repositioning its product around AI agents.
- AT&T, a Reco customer, invested in the extension through its venture arm, as did Forestay and Quadrille Capital.
- CEO Ofer Klein said the valuation has more than doubled since the February Series B and put it in the high hundreds of millions, without giving specifics.
- Annual recurring revenue is in the double-digit millions of dollars, Klein said, and he expects it to triple this year.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- decision Feature grids that repeat the same terms tell a buyer little about these vendors, so the comparison has to be a test against agents running in the buyer's own systems.
- exposure Closing a departing employee's accounts can leave the agents they built with their access intact, so the agent inventory belongs in the offboarding process.
- precedent Reco's move from SaaS security into agents makes it likely that tools a company already pays for will also start pitching agent coverage, adding to the shortlist.
Reco says that at a large financial services customer it found an agent a former employee had set up. The agent could still reach Salesforce and share that data with a domain the company could not see [7]. The example is Reco's own, and the customer is unnamed. For the security team, finding that agent is the first task. Removing its access is the second.
TechCrunch based its count of vendors on public Crunchbase and PitchBook profiles [1]. The products do different jobs. Some vet the tools agents use, some control which data agents can reach, some look for unapproved AI use, and CrowdStrike is among those building detection and response on the devices agents run on [2]. The products differ, but the promises share a word list: knowledge graphs, continuous monitoring, runtime security, tool access, MCP vetting [3].
Here's what teams tell themselves users do: ask before they build an agent. Here's what users actually do, going by the vendors' own counts. Klein said companies are building and deploying agents faster than they can keep track of [6]. He also said Reco's platform found 21,000 agents at one Fortune 100 customer that the company did not know about [8]. Cymphony said it found about 85,000 files open to AI tools and agents at one U.S. public company [11]. HiddenLayer CEO Chris Sestito said more than 50 of his customers have agents in production touching critical systems and sensitive assets [10]. All of these figures come from companies that sell the remedy.
Reco's graph ties each agent to the apps, people, accounts and permissions around it [5]. It builds that picture from direct integrations with more than 280 apps, and Klein says new ones can be added within days [17]. For agents outside those apps it uses browser and network signals, and it has controls to inspect prompts and tool calls [18]. "The market demand right now for agent security is not only about the agent itself; it's about the entire ecosystem end-to-end," Klein told TechCrunch [9].
Reco's buyers so far skew toward banks and insurers. It has more than 100 customers, and financial services accounts for about 40% of the business [16]. Investors have moved fast too. Of the $140 million Reco has raised in total [19], $85 million came from the February Series B and this extension [12][1], about 61% [2].
A shortlist can be sorted on two axes. The first is where a tool sees agents: inside apps through integrations, or from signals on the device, browser and network. The second is what the tool does after a find: report the agent, or cut its access. Reco says it uses both integrations and outside signals, and that it can cut access [5][18]. The forcing test is the ex-employee case, run in the buyer's own environment, counting the agents that lost access and the hours from discovery to cutoff. A discovery total only measures the scan. In my view the better pick is the tool that can cut access in the apps a company already runs. The tradeoff is that an integration-first product's direct view ends at its integration list, and anything beyond that depends on browser and network signals [17][18].
What to watch
- Whether Reco's annual recurring revenue triples this year, as Klein expects.
- A named Reco customer reporting how many discovered agents lost access after a scan, and how quickly.
- Whether device-focused vendors such as CrowdStrike add controls that cut agent permissions inside SaaS apps.