Neo Raised $100 Million to Put a Bouncer on Your AI Agents
Boston cybersecurity startup Neo raised $100 million to secure AI agents with endpoint controls, software inventory, and real-time policy enforcement.
Somewhere in Boston, an AI agent is currently asking for permission to access a customer database, invoke a browser extension, and send an email that begins, “Just circling back.” This is how the future arrives: not with a robot uprising, but with a workflow automation tool holding valid credentials and an unsettling amount of initiative.
That is the problem Boston-based cybersecurity startup Neo says it is tackling. On July 20, Neo emerged from stealth with $100 million in funding from Andreessen Horowitz and Bessemer Venture Partners, with participation from Craft Ventures and Merlin Ventures. The company was founded in 2025 by former SentinelOne leaders Nick Warner and Shlomi Salem, alongside CTO Eran Shirazi, according to the launch announcement and local reporting from the Boston Business Journal.
Neo calls its product an “agentic software control” platform, which is startup language for “we would like to know what the software is doing before it does something expensive.” The pitch includes an inventory of AI agents, applications, plugins, extensions, MCP servers, and ordinary enterprise software that has quietly acquired agentic features. It also promises posture intelligence, attribution, policy controls, and native enforcement.
My verdict: this is a serious technical bet and a meaningful Boston cybersecurity story. The money is enormous for a company that just left the shadows, but the underlying problem is not imaginary. Enterprise software is becoming less like a filing cabinet and more like a junior employee with API access. Someone has to become the security team’s hall monitor.
The enterprise agent has a badge, a password, and too much confidence
Traditional endpoint security is good at answering familiar questions: Which process is running? Which file changed? Which user logged in? What known malware signature just wandered past the perimeter wearing a fake mustache?
AI agents make the questions stranger. An agent may act through a browser, a developer tool, a SaaS platform, or a plugin. It may inherit a person’s permissions, chain several tools together, and perform actions that look legitimate because the identity behind them is legitimate. The threat is not necessarily a rogue hacker breaking in. It may be approved software doing an unapproved thing at machine speed.
Neo’s product is designed to connect each action to the human, agent, application, or identity responsible. That sounds like basic accounting until you reconstruct an automated workflow after it has touched six systems. An audit trail is not glamorous, but neither is incident response at 2 a.m.
Bessemer’s investment memo says Neo is taking an endpoint-first approach, placing a sensor on the device where the agent actually operates instead of relying only on API-based visibility. The distinction matters. An API log can tell you what happened after the fact. An endpoint control can, at least in theory, intercept a tool call or data movement while it is happening.
That is also the difficult part. Endpoint software has to coexist with operating systems, browsers, developer environments, performance budgets, and users who become philosophical the moment a security tool slows down their laptop by three percent. The sensor that survives thousands of real machines and weird legacy applications is the hard part.
Neo wants to turn AI inventory into something less haunted
The company says its platform continuously catalogs what software can do, what it can access, and whether it is configured safely. It calls the knowledge base behind that inventory Neoverse, which is either a useful security graph or the name of a starship about to ask for your single sign-on.
The practical idea is solid. A security team cannot govern software it cannot see, and “AI agent” is not a single application category. It can mean a coding assistant, customer-service workflow, enterprise search tool, browser extension, or a normal product that added a button labeled “autonomous” during an enthusiastic planning meeting.
Neo says its system can observe traffic and propose policies, with plain-language tools for creating and applying controls. That could reduce policy-authoring work, although “allow the agent to update the customer record but not export personal data” still needs a precise authorization model underneath.
This is where Neo’s Boston flavor shows. The region has a long habit of turning difficult systems problems into enterprise infrastructure: identity, networking, health data, robotics, payments, and security. The local culture is not always excellent at pretending a problem is easy. It is quite good at building a control plane and then scheduling three meetings about who owns it.
The $100 million is a bet on the leash, not the puppy
The financing is a substantial signal. Bessemer describes the transaction as a $100 million Series A, while the launch release frames it as $100 million in total funding. Either way, investors are placing a very large early bet on the idea that agent security becomes a category of its own.
The timing makes sense. As we have noted before, the useful agent economy is supervised automation inside workflows where businesses already spend money. The closer agents get to code repositories, customer records, payments, and internal documents, the more valuable visibility and rollback become.
There is a nice contradiction here. The industry sells autonomy as the product, while enterprises ask for controls around it. The less an agent behaves like a software feature, the more it needs an employee’s machinery: identity, scope, logging, approvals, and an off switch.
Neo is not alone. Akamai’s agent-security work approaches the problem from the edge and the public internet, while other vendors focus on identity, model gateways, runtime monitoring, or application security. Neo’s wager is that the endpoint is where enforcement has to happen if companies want to stop risky behavior in real time.
That position is plausible, but it is not automatically dominant. Customers may not want another agent-specific console. Existing endpoint, identity, network, and cloud-security vendors will all claim that their platforms already cover most of this. Neo could define a market, or become another feature in a menu labeled “Advanced.”
Boston gets another security company with homework
Neo plans to expand engineering and go-to-market teams, with the Boston Business Journal reporting plans to hire more than 20 people by year’s end. A hundred million dollars can buy time, talent, and an impressive office espresso machine. It cannot buy trust by default.
The Boston connection matters beyond the mailing address. Warner brings SentinelOne scaling experience, Salem brings deep detection-engineering experience, and Shirazi combines cybersecurity research with enterprise software. That mix fits a problem spanning AI, operating systems, identity, policy, and sales.
It fits Boston’s more durable pattern: building unpleasantly necessary layers for seeing networks, measuring exposure, managing access, and proving what happened. The control-plane instinct is strong here. Sometimes the city builds the bouncer. Sometimes it builds the clipboard.
Verdict: a promising experiment with a very expensive clipboard
Neo’s emergence is a meaningful win for Boston tech, not because $100 million makes a market real, but because it targets the part of agentic AI after the demo: permissions, attribution, interception, governance, and what happens when software acts correctly on the wrong instruction.
The risk is category inflation. “Agentic software control” could become a useful product or a branded layer of overlap between endpoint security and identity management. Neo must prove its sensor sees what customers cannot already see, and stops risky behavior without turning automation into a help-desk ticket.
Still, this is the right problem to be tackling. AI agents are moving into enterprise systems whether security teams feel spiritually prepared or not. If Boston’s newest large-funded cybersecurity company can give those teams a live map, a policy engine, and a reliable off switch, that is not hype. It is infrastructure with a sense of humor.
If the agent objects to the bouncer, Neo can show the audit trail.