Israeli cybersecurity startup Neo emerged from stealth Monday with $100 million in funding to build what it calls a “real-time control layer” for AI agents and AI-enabled software operating inside enterprise systems. The company is betting that autonomous software creates a security category distinct from traditional endpoint, identity, and cloud security.

The financing breaks down into a $75 million Series A led by Andreessen Horowitz and Bessemer Venture Partners, with participation from Craft Ventures and Merlin Ventures, plus a previously undisclosed $25 million seed round completed in 2025, according to Calcalist.

The Founding Team

Neo was founded by three executives who built significant parts of the existing cybersecurity stack. Nick Warner built SentinelOne’s go-to-market organization and served as COO through the company’s 2021 IPO, after holding senior roles at Cylance, McAfee, and Forcepoint. Shlomi Salem spent over a decade leading SentinelOne’s detection engineering organization and co-led its internal threat research team, developing threat actor profiles that became a core component of the security platform. Eran Shirazi previously co-founded customer experience software company EasySend and led a vulnerability research group in the IDF’s Unit 8200.

The angel investor list reads like a who’s who of Israeli cybersecurity: Wiz co-founder and CEO Assaf Rappaport, former Wiz executive Merav Bahat, Talon and Argus founder Ofer Ben-Noon, and former NBA player Zaza Pachulia, Calcalist reported.

The Problem Neo Is Solving

Traditional endpoint security (EDR) and identity security tools were designed for software that behaved predictably and relied on human users. AI agents introduce a different model: they reason, invoke external tools, chain together workflows, and make decisions while appearing to operate as legitimate users.

“The challenge with AI agents is that they operate with legitimate user permissions,” Salem told Calcalist. “Organizations don’t always know what information those agents can access, what actions they’re authorized to perform, or how they learn about the organization. Those are entirely new security questions.”

According to Gartner, only 5% of enterprise applications incorporated agentic capabilities in 2025, but that figure is expected to reach 40% by the end of 2026, Calcalist reported. That velocity creates a window where autonomous software proliferates faster than security teams can track it.

How the Platform Works

Neo’s platform automatically maps AI agents, AI-powered applications, browser extensions, plugins, Model Context Protocol (MCP) servers, and traditional software that has acquired agentic capabilities across an enterprise environment. A continuously updated knowledge base catalogs the capabilities, risks, and behavioral patterns of each component.

The platform records every action performed by users, AI agents, applications, or digital identities, creating an audit trail. Organizations define policies governing tool activation, API access, data transfers, and AI workflows. Neo enforces those policies directly within the software layer, blocking risky activity, malicious AI models, and prompts that exceed predefined security boundaries.

Salem described the focus as securing the “AI agent endpoint,” a term that frames autonomous software as the next surface area CISOs need to monitor, comparable to the laptop and server endpoints that built SentinelOne’s business.

An Increasingly Crowded Market

Neo enters a market that is filling quickly. Brex open-sourced CrabTrap, an HTTP proxy that intercepts agent network requests, earlier this month. PromptArmor published security analysis finding that 39% of Claude connectors likely call additional AI subprocessors. Google is building agentic defense capabilities into Chronicle. The common thread: existing security tools have blind spots for autonomous software.

Neo is betting that enterprises will require dedicated controls rather than relying on traditional products extended with AI features. “Every major technological revolution gives rise to an entirely new security category, and agentic AI will be no different,” said Shay Michel, Managing Partner at Merlin Ventures, in a statement to Calcalist.

The company currently employs 50 people, including 40 in Israel, and said it will use the funding to expand engineering and go-to-market teams.