Reco Raises $55 Million to Map and Secure Enterprise AI Agents

Reco has raised $55 million in new financing to expand its work on AI agent security. The company announced the round on September 29, 2026. TechCrunch
The financing builds on a $30 million Series B raised in February. The extension drew investment from AT&T, a Reco customer investing through its venture arm, alongside Forestay and Quadrille.
Reco is led by co-founder and CEO Ofer Klein. Under Klein, the company shifted from software to map and secure SaaS and AI platforms to a broader architecture centered on a context graph. The graph connects agents to applications, people, accounts and permissions. Like a live map of keys and doors, it treats each agent as a first-class identity with inheritance, delegation and scope, not as an isolated API client.
Reco points to discovery as the hard part. It said its platform found 21,000 agents that a Fortune 100 customer did not know about. Most enterprises already struggle with SaaS sprawl, OAuth grants that let one app access another, service accounts for automated work, and over-permissioned integrations. Autonomous agents multiply the problem because they can be created by business users, developers and other agents, often outside centralized IT provisioning.
The February Series B was led by Zeev Ventures, with participation from Insight Partners and boldstart ventures. That syndicate was disclosed in April. The September extension adds strategic and cross-stage capital without replacing the earlier lead.
The current round has history. In April 2025, Reco described an additional $25 million raise and said it intended to use the funding to scale its AI-native SaaS offering and to close what it called the SaaS Security Gap with Dynamic SaaS Security. Reco Redseed participated as a new investor in that $25 million round at the time. Calcalistech
Operational signals since then include recognition as a CRN 2025 Stellar Startup and a doubling of headcount across multiple regions. The company has also been named an OpenAI Select Partner, lists a catalog of more than 270 agents and apps, and says its Factory provides more than 260 app integrations.
In my view, two details deserve attention. AT&T investing as a customer points to production deployment rather than pilot interest. The 21,000 unknown agents and the catalog and integration counts also carry weight, because in SaaS security results depend on seeing what IT misses and parsing permissions across enough connections.
The broader context here is a crowded field. Startups are racing to define agent security, with approaches ranging from runtime guardrails and prompt filtering to identity governance and posture management. Reco is betting that the control point is the relationship map. If you can continuously resolve which agent can act on which data, on whose behalf, and through which app authorization, you can enforce policy before execution and audit after it.
In my view, that emphasis is sound for an enterprise buyer. Inference controls and content filters have a role, but enterprise risk from agents will concentrate in authorization logic. Stale OAuth tokens, excessive scopes, shared service accounts and transitive access through connected apps are already known failure modes. Agents make them dynamic. A context graph is one plausible way to keep the permission model current as agents spawn, share credentials and chain tools. The open questions are operational. How fresh is the graph, how noisy are the findings, and how cleanly can remediation plug into existing identity and ticketing workflows without creating a parallel console that security teams ignore.


