Skip to content
TECH CEO Daily
StartupsFunding

Reco raises $55 million for AI agent security, says one client had 21,000 unknown agents

Reco's total funding reaches $140 million, and its CEO says a Fortune 100 customer was running 21,000 AI agents it did not know about.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Reco raised $55 million, including a strategic investment from AT&T Ventures, bringing its total funding to $140 million.
  • 2CEO Ofer Klein told TechCrunch the platform found 21,000 agents one Fortune 100 customer did not know about.
  • 3TechCrunch counted at least two dozen companies selling AI agent security, so buyers should weigh vendor staying power.

Video summary · 0:48

Watch: Reco raises $55 million for AI agent security, says one client had 21,000 unknown agents

The story in under a minute, with captions. Tap to play with sound.

Video summary · Voiced with a synthetic voice.

The news

Reco, an AI agent security startup, said on September 29, 2026, that it raised $55 million, including a strategic investment from AT&T Ventures, citing growing demand from Fortune 500 companies that are putting AI agents to work across their software.

New investors Forestay and Quadrille Capital also joined the round. Reco said the money brings its total funding to $140 million and will pay for expansion in sales, partnerships, channels and customer support. The company's release did not name a lead investor; SecurityWeek described AT&T Ventures as the lead.

AI agents are software programs that act on their own, such as pulling records or kicking off workflows, using whatever logins and permissions they are given. Reco says its platform maps which identities those agents use, what data and applications they can reach and what workflows they can start. The company says the product has more than 280 app integrations and 1,000 detection controls, and SecurityWeek reported that it connects with OpenAI, Anthropic, Microsoft Copilot, Salesforce, ServiceNow and Workday.

Co-founder and CEO Ofer Klein told TechCrunch that Reco's valuation has more than doubled since its $30 million Series B in February, placing it in the high hundreds of millions of dollars without giving a figure. He said annual recurring revenue (ARR), the yearly value of subscription contracts, is in the double-digit millions of dollars and that he expects it to triple this year. TechCrunch reported that Reco has more than 100 customers and that financial services firms account for about 40% of its business.

Klein also described what the software has turned up. At one Fortune 100 customer, he told TechCrunch, Reco found 21,000 agents the company did not know about. Reco also claims that at a large financial services client it spotted an agent built by a former employee that could reach Salesforce data and send it to an outside domain the client could not see.

AT&T is both a customer and an investor. In the release, AT&T chief information security officer Rich Baich said the tool gives the company more visibility into agent security risk, access management and third-party integrations, and helps with audit readiness. Klein said in the same release that agents are gaining access to business data "faster than many organizations can map or govern those connections."

The numbers

New funding
$55 million
Total funding to date
$140 million
Prior round
$30 million Series B (February 2026)
Unknown agents found at one Fortune 100 customer (CEO's account)
21,000
App integrations
More than 280
Customers (per TechCrunch)
More than 100

Why CEOs should care

For chief information security officers (CISOs), the 21,000 figure is one customer's result as described by Reco's CEO, not an industry benchmark. It still raises a question every security team can answer internally: how many agents are connected to our business applications, under whose credentials, and who approved them? The former-employee example Reco describes suggests that offboarding checklists written for people may not cover the agents those people created.

For buyers and CFOs, the crowding matters as much as the funding. TechCrunch found at least two dozen companies selling some form of AI agent security, and established vendors such as CrowdStrike (CRWD) are building their own detection and response controls. A field that crowded raises the odds that some vendors will be acquired or shut down, so before signing multi-year contracts, ask about funding runway, customer concentration, and what happens to your integrations and data if the vendor changes hands. Reco's disclosed figures, $140 million raised and ARR in the double-digit millions by the CEO's account, are a starting point for that diligence.

Boards should ask management whether AI agents appear in the company's asset inventory and access reviews at all. AT&T's CISO tied Reco's tool to audit readiness, a framing that moves agent governance from a technical project to a control that auditors and directors can test.

The bigger picture

The round reflects a shift in security spending toward the identities and permissions that software agents inherit. Until last year, Reco mainly sold software to map and secure software-as-a-service (SaaS) applications and AI platforms, TechCrunch reported; it now pitches itself as an agent security company. Rivals are attacking the problem from different angles, with some vetting the tools agents use and others limiting what data agents can reach.

Other vendors report similar exposure. HiddenLayer CEO Chris Sestito told TechCrunch that more than 50 of his customers have AI agents in production touching critical systems, and Cymphony, another startup, said it found about 85,000 files that had become accessible to AI tools and agents at one U.S. public company.

What’s next

Reco said it will spend the new money on sales, partnerships, channels and customer support. The markers to watch are whether Klein's forecast of tripling ARR this year holds, whether the company discloses a formal valuation, and whether more large customers follow AT&T in investing directly in the vendors that police their agents.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

RecoAT&T VenturesAI agentsCybersecurityOfer Klein

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.