Agentic AI
,
Application Security
,
Artificial Intelligence & Machine Learning
Agentic Security Startup Identifies AI Capabilities Embedded Across Enterprise Apps

An agentic software control startup led by SentinelOne’s former president emerged from stealth with $100 million to map the rapidly expanding ecosystem of artificial intelligence-enabled software.
See Also: Snyk Reportedly Cuts 90 Jobs to Accelerate AI Strategy
The Andreessen Horowitz and Bessemer Venture Partners-led funding will help Neo analyze both conventional binary software and newer non-binary components such as AI skills, plug-ins, browser extensions and tools, said co-founder and CEO Nick Warner. He said this will power Neo’s security platform by providing the context needed for discovery, visibility and policy enforcement.
“The adoption cycle for AI software has moved faster than I think anybody really anticipated,” Warner told ISMG. “Almost 50% of enterprise software is going to be agentic by the end of this year, and so I think that’s led to faster velocity and greater interest in our technology than we had anticipated.”
Boston-based Neo, founded in August 2025, has been led since its inception by Warner, who most recently spent five-and-a-half years as SentinelOne’s president, chief operating officer and chief revenue officer. Prior to that, Warner spent more than three years as Cylance’s worldwide sales leader and nearly two years leading advanced technology sales at McAfee (see: How XDR Is Fulfilling the Promise That SIEM Never Did).
Why Enterprise Apps Create Such a Big Security Challenge
Apps for HR systems, finance tools, CRM platforms and productivity software are adding autonomous AI capabilities, but he said organizations often have little understanding of what AI functions have been introduced, what models they rely upon or how they interact with sensitive corporate data. This long tail of enterprise applications will ultimately create a larger security challenge than the frontier AI models.
“Most companies are flying blind, and they need illumination,” Warner said. “They need to better understand the software that’s in their environment, the software that’s being downloaded in their environment and how that software is currently running in this agentic world.”
As AI agents begin automating workflows, interacting with business systems and accessing sensitive data, they gain the same privileges as the human user. This creates questions for security teams about what information an app can access, whether it can train on corporate data, what third-party AI models power its capabilities and whether those capabilities have been properly evaluated before deployment.
“The identity is inherited from the human user,” Warner said. “The permissions are inherited from the human user. If you combine that with the ability to automate and to have agentic control over different systems, processes and data, this is a brave new world for all of security, and a lot of companies have tried to scramble and define and try to limit some of the core AI provider capabilities.”
Neo’s AI agents automatically discover software, analyze skills, summarize intended functionality and compare those findings with actual behavior to identify malicious or deceptive software, Warner said. The platform also reviews terms of service, requested permissions and data usage policies to determine whether applications train on enterprise information or request excessive privileges, he said.
“Our platform does discovery, context, visibility, policy and control – all in one easy-to-deploy product,” Warner said. “That fundamentally is very different, and that actually contains a lot of the core IP that our folks brought, both with deep experience in threat research, but also deep experience in building enterprise world-class endpoint sensor solutions.”
Why Analyzing AI Sessions on the Endpoint Is Best
Many first-generation AI security vendors built gateway or proxy architectures based on the assumption that AI interactions would occur primarily through browser sessions with cloud-hosted models, but AI is rapidly moving onto endpoints through desktop applications, coding assistants and locally running models. Neo designed a full endpoint agent capable of discovering AI software and monitoring activity.
“A lot of old detection tools – whether it was EDR or IPS/IDS – a lot of that was trying to look at software code,” Warner said. “But now, what you actually need to look at are a lot of plain English instructions. The good news is agentic agents themselves are extremely good at analyzing language.”
Neo analyzes AI sessions directly on the endpoint rather than forwarding prompts, conversations or user activity to external cloud services, which he said reduces privacy concerns because sensitive information remains on the device. Local analysis also enables Neo to observe activities that never traverse enterprise networks, including direct API calls, local model execution and other AI interactions, he said.
“We’re not having to rely on sending something out to a cloud, analyzing it, sending it back,” Warner said. “We do all of our detection and protection locally in the system.”
Clients need to know what software exists in their environment, which apps contain agentic capabilities, what models they rely on, what permissions they request, whether they can train on corporate data and how they interact with other systems. Neo’s strategy is built around providing this visibility first and then enabling organizations to apply policy and enforcement based on that intelligence, Warner said.
“I believe that this market is going to be at least as big as the endpoint security market was,” Warner said. “What we’re not doing is selling a niche solution just to say developer machines. This is something that all enterprises will need to better understand this new software layer.”
