
AI security startup AIR has emerged from stealth with $50 million in seed funding to help companies monitor the growing ecosystem of skills, plug-ins, MCP servers, and other add-ons that AI agents use to interact with enterprise systems and the internet. The company argues that as agents take on more autonomous work, businesses will need continuous oversight of the software those agents consume, not just the agents themselves.
AIR’s bet on the AI agent supply chain
Founded by CEO Yair Saban and CTO Niv Hoffman, both veterans of Israel’s Unit 8200 intelligence corps, AIR is positioning itself around a problem it says is already taking shape: a software supply chain for AI agents. Its platform is designed to discover agents running inside a company, inspect the tools and components they rely on, and block anything that fails security checks.
The startup also plans to offer a marketplace of vetted add-ons and skills for agents. Saban said the company’s thesis is that AI agents are beginning to resemble operating systems in how they are used inside companies, but the surrounding ecosystem has not yet developed the same kind of oversight that enterprises apply to other software.
How the platform works
AIR says its product has three main pieces. First, it provides visibility into agents active across an environment, including employees who may be using unapproved AI tools or personal accounts. Second, it adds an enforcement layer that hooks into agents and intercepts actions such as loading a skill or fetching web content. Third, it checks requested tools, add-ons, or software against a whitelist maintained by AIR.
That whitelist is continuously updated, according to Saban, because a previously safe skill can become dangerous if its package dependencies change or if a developer account is compromised. AIR said its platform currently filters out about 27% of the add-ons and skills it finds online.
Why AIR says the risk is different
Saban compared the issue to the evolution of software drivers. In the early 2000s, he said, drivers often did not need signatures, but today they are signed because they can load code into the kernel. In his view, skills, plug-ins, and MCPs are similar in that they can introduce code or content into an AI agent’s decision-making flow.
The startup’s concern is not only direct attacks on an agent, but also poisoning the information it consumes. As agents gain more autonomy across databases, enterprise systems, and the open internet, AIR believes attackers may target the content an agent reads or the tools it chooses to trust.
The funding behind AIR
AIR said the two seed rounds closed within weeks of one another. The first raised $10 million and was led by Sequoia, while the second raised $40 million and was led by Greenoaks. The company said the rounds included participation from Swish, Netz, Zach Frankel, president of Cognition, Yinon Costica, co-founder of Wiz, Ofir Ehrlich, co-founder of Eon, Anne Neuberger, Omer Adam, Varun Anand, co-founder of Clay, and other angel investors.
Bogomil Balkansky, a partner at Sequoia, said in an emailed statement that the challenge is “not a scanning problem” but “a continuous re-verification problem.” He said inspecting every skill, plugin, MCP server, and sub-agent in real time across an enterprise’s agent fleet is “an infrastructure problem long before it is a security problem,” and argued that AIR has spent the last year building that pipeline.
Customers and early demand
AIR said it already has more than 20 customers, and Saban said roughly a quarter of them are large enterprises. He said demand has been strongest in highly regulated sectors, especially financial services and pharmaceutical companies.
The company currently has about 40 employees. According to Saban, the fresh capital will mainly be used to hire researchers and expand go-to-market efforts in the U.S. and Europe.
A crowded category is forming
AIR is entering an increasingly busy field. Noma Security offers discovery, access controls, and runtime monitoring for agents, MCP servers, and skills. Zenity provides security and governance tools with similar coverage, while Astrix Security’s identity platform can discover and control agents and MCP servers. Operant AI also sells agent protections and an MCP gateway.
Venture money is flowing into the category as well. Zenity raised a $125 million Series C in August, and Noma raised a $100 million Series B last year. That suggests investors see agent security as a durable market, even as the technical shape of the category is still changing.
AIR’s moat: continuous vetting
Saban argues AIR’s competitive edge is its ability to continuously vet the ecosystem of skills and add-ons around AI agents. He said visibility alone will become a common feature, but monitoring whether a tool has changed, become compromised, or now behaves maliciously is harder to do well.
He also acknowledged that AI labs and platform providers may eventually add more built-in security checks. Even so, AIR believes enterprises will still want an independent layer that works across vendors and can enforce policies consistently across different agent systems.
Source: Original report
Was this helpful?
Explore more: Application Audit & Review More Business & Startups Tech News
Last Modified: September 2, 2026 at 1:52 am
6 views

