American-Israeli cybersecurity startup Neo emerged from stealth on July 20, 2026. It announced $100 million in funding. The money funds security controls for enterprise AI agents and agentic software.
Neo received the investment across seed and Series A rounds from Andreessen Horowitz, Bessemer Venture Partners, Craft Ventures, and Merlin Ventures. Neo plans to use the capital to grow its engineering and go-to-market teams.
Who Built It and Why
Neo was founded by Nick Warner, Shlomi Salem, and Eran Shirazi. Warner is CEO. He previously served as president and COO of SentinelOne. He also held earlier roles at Cylance, McAfee, and Forepoint. Salem is the chief product officer. He led detection engineering at SentinelOne. Shirazi is the CTO. He co-founded customer experience firm EasySend.
Warner described the problem in comments published at launch. AI agents and agentic capabilities are being embedded into browsers, developer tools, SaaS platforms, and traditional applications. That gives software the ability to reason, act, invoke tools, and move through workflows with valid user permissions. Warner's argument is that existing enterprise controls do not address that behavior, and that a dedicated real-time control layer is required.
He described Neo as the answer: a platform that lets enterprises understand what agentic software can do, govern how it behaves, and secure adoption.
Neo's platform covers four core functions: inventory, risk evaluation, attribution, and enforcement.
For inventory, the platform maintains a continuous catalog of agents, models, extensions, and MCP servers. It then evaluates discovered assets for excessive access privileges and configuration vulnerabilities.
Attribution is a key design element. The product traces individual software actions directly back to the originating human user, automated agent, or specific application identity. That traceability matters when an agent's action needs to be audited.
For enforcement, Neo can natively apply granular policies to tool calls, data movement, agentic workflows, and API access. Security teams can restrict unauthorized activities or pause suspicious operations for manual review.
The Control Gap Behind the Investment
Neo has just emerged from stealth. The announcement does not establish broad production adoption, integration complexity, or independent customer outcomes. Those details are unknown at this stage.
What Security and IT Leaders Should Do Now
The decision is not whether your organization needs Neo specifically. It is whether you can answer four questions about agentic capabilities already entering your software stack.
Inventory: Can your existing tools produce a reliable catalog of agents, agentic extensions, and autonomous features in approved applications?
Attribution: Can an API call, data access, or tool invocation be traced to the originating person and the specific agent that executed it?
Policy scope: Do current controls address autonomous behavior? Or do they assume every action begins with a direct human input?
Vendor roadmap: Which approved software providers are adding agents? How will those features change existing permissions and data access?
A failure to answer any of those questions is a control gap. That is true regardless of which product eventually addresses it. Start with the inventory. Map agentic capabilities in approved applications. Document what current security controls can observe, attribute, and block. That baseline will show whether agent-control tooling is a near-term requirement or a category to watch through the next planning cycle.