UpShaqo
Intelligence desk
Agent Trust & Security Source-backed analysis

Reco's $55M Raise Turns Agent Sprawl Into a Sales Pitch

Reco's fresh $55M round, backed partly by customer AT&T, arrives as at least two dozen startups chase the same CISO budget line. The real story is what buyers are discovering inside their own networks.

UpShaqo Editorial IntelligenceSeptember 29, 20266 min read
Intelligence standard

Independent UpShaqo analysis built from fresh, attributed sources. We explain the impact instead of repeating the announcement.

Read for leverage: focus on the workflow change, the customer problem, and the next action—not only the product announcement.

The number that should make any CISO pause isn't the $55 million. It's 21,000 — the count of agents Reco says it found running inside a single Fortune 100 customer's environment that the company itself didn't know existed. That gap between what enterprises think they're running and what's actually operating on their networks is the entire market opportunity right now, and it's why investors keep writing checks into a category that already looks crowded.

Reco announced Tuesday that it raised $55 million, layering onto the $30 million Series B it closed in February. Total capital raised now stands at $140 million. AT&T, which is also a Reco customer, invested through its venture arm alongside Forestay and Quadrille Capital. Co-founder and CEO Ofer Klein told TechCrunch the company's valuation has "more than doubled" since February and now sits in the "high hundreds of millions," with annual recurring revenue in the double-digit millions and a projected tripling this year.

Those are strong numbers for a fourteen-month-old pivot. They're also a useful proxy for how fast the underlying problem is compounding — and how much room competitors think is left to fight over.

Why Buyers Are Suddenly Paying Attention

Until last year, Reco mostly sold software to map and secure SaaS and AI platforms, a narrower, more contained job. The shift toward a full "context graph" — connecting agents to the apps, people, accounts, and permissions they touch — happened because, in Klein's telling, companies started building and deploying agents faster than anyone could inventory them.

That's not an abstract worry. Reco says it found an agent set up by a former employee at a large financial services customer that still had access to Salesforce and was quietly sharing that data with a domain the company couldn't see. Separately, AI startup Cymphony reported finding roughly 85,000 files that had become accessible to AI tools and agents at one U.S. public company. HiddenLayer's CEO, Chris Sestito, put the stakes in blunter terms: once agents reach production, cost and risk go from theoretical to "full scale really quickly," and he says more than 50 of his customers already have agents touching critical systems and sensitive assets.

Analysis: These aren't edge cases dressed up for a sales deck — they describe a governance failure that predates any specific vendor's product. Enterprises adopted agent tooling through dozens of business units simultaneously, without a central inventory process built for it. That's the actual thing being sold here: not "AI security" in the abstract, but an answer to the very concrete question, what do we have running, and what can it reach?

A Crowded Field With Overlapping Pitches

A quick scan of Crunchbase and PitchBook turns up at least two dozen companies selling some form of AI agent security, and their approaches split roughly into a few camps: vendors vetting the tools agents use, vendors controlling what data agents can reach, device-level detection and response players like CrowdStrike, and startups focused purely on surfacing unapproved or "shadow" AI usage. Reco is trying to sit across several of those lanes at once, using its context graph plus browser and network signals to catch agents operating outside the apps it connects to directly.

The language across the category has converged hard — knowledge graphs, continuous monitoring, runtime security, MCP vetting — to the point that pitch decks are becoming difficult to distinguish from a distance. That convergence is itself a signal worth reading: when a dozen-plus vendors describe the same problem with nearly identical vocabulary, it usually means either the market is genuinely early and everyone is racing toward the same obvious shape of the solution, or it means undifferentiated positioning is about to collide with buyer fatigue.

Distribution Is Doing the Differentiating Work

Reco's bet, as Klein frames it, is that its prior life as a SaaS-security platform gives it an edge competitors built purely for agents don't have: existing integrations with more than 280 apps, with new ones addable within days. Financial services makes up about 40% of Reco's more than 100 customers, a concentration that tracks with an industry already saturated in compliance obligations and audit requirements — a natural first buyer for anything promising visibility into ungoverned access.

Analysis: In a market this crowded, the deciding factor for enterprise buyers is rarely which vendor has the cleverest detection logic. It's who can plug into the stack that's already there without a six-month integration project. A security team evaluating five nearly identical pitches will gravitate toward whoever already talks to Salesforce, Workday, and the internal SSO layer — which is exactly the lane Reco is trying to occupy by leaning on its SaaS-security legacy rather than starting from a blank agent-monitoring slate.

AT&T's investment alongside its status as a customer also matters for distribution, functioning less as passive capital and more as a credibility signal other enterprise buyers can point to during procurement conversations.

The Pricing Question Nobody's Answering Yet

Reco's ARR sits in the double-digit millions with a tripling projected this year — real growth, but modest relative to the $140 million now raised across two rounds. Analysis: That gap between capital raised and revenue booked is normal for an early-stage security category, but it also hints at where pricing power actually sits. With two dozen vendors chasing the same CISO budget line using near-identical language, buyers are likely to demand proof-of-value pilots, multi-vendor bake-offs, and usage-based pricing rather than accepting flat platform fees. Vendors that can point to a specific, quantified catch — like the ex-employee agent leaking Salesforce data — will have an easier time justifying premium pricing than those still selling on the promise of visibility alone.

The Wedge Nobody's Fully Claimed

Most of the current pitches focus on discovery and access control at the point an agent is already running. What's noticeably thinner across the category, based on the public positioning of Reco and its peers, is lifecycle governance for agents that get decommissioned, forked, or handed off between teams — the exact scenario that produced Reco's ex-employee example. An agent doesn't need to be malicious to become a liability; it just needs to outlive the employee, project, or vendor relationship that created it. A startup that owns that offboarding moment — treating agent decommissioning with the same rigor enterprises apply to employee offboarding — would be solving a problem adjacent to, but distinct from, the discovery race everyone else is currently running.

What Buyers Should Do Before the Next Pitch

For CISOs fielding calls from this expanding vendor list, the practical filter is simple: ask for a live inventory count, not a demo. Any vendor claiming context-graph visibility should be able to show, in a sales call, roughly how many agents it expects to surface in an environment of a given size — and what happens to access when the agent's owner leaves the company. That question alone will separate genuine coverage from repackaged SaaS-security dashboards riding the same wave of enterprise anxiety that just helped Reco raise $55 million.

Sources

#AI agent security#Reco#shadow AI#enterprise fundraising#CISO buyers#agent governance#SaaS security

Two doors. Pick one.

Hire the team.
Or become it.