Terms like “AI sprawl” have become common fare on tech social media and in thought leadership as enterprises start deploying AI agents en masse. But CISOs worried about securing swarms of agents suddenly operating across networks are likely finding themselves dealing with a new kind of sprawl: vendors offering to help.
Just a quick glance at public Crunchbase and PitchBook profiles turns up at least two dozen companies selling some form of AI agent security. Some vendors vet the tools agents use, while others try to help companies control what data their agents can reach. Some others, like CrowdStrike, are building detection and response controls on the devices agents run, and still others are focused on finding and resolving unapproved AI usage.
The products differ, of course, but their promises to discover and govern agents sound quite similar, involving knowledge graphs, continuous monitoring, runtime security, tool access, MCP vetting, and the like.
Some are even updating their products to join the bandwagon. Until last year, AI security startup Reco was mostly selling software to map and secure SaaS and AI platforms. Now, it’s repositioned around a broader solution that uses a context graph to connect agents to apps, people, accounts, and permissions, giving security teams a way to see what an agent can reach and cut off access it doesn’t need.
According to Reco’s co-founder and CEO Ofer Klein, the biggest change over the past year that spurred the startup to broaden its scope was that companies are building and deploying AI agents faster than they can keep track of. At one of the startup’s Fortune 100 customers, he said, Reco’s platform found 21,000 agents the company didn’t know about. And at a large financial services customer, the startup claims it identified an agent set up by an ex-employee that could access Salesforce and share that data with a domain the company couldn’t see.
“The market demand right now for agent security is not only about the agent itself; it’s about the entire ecosystem end-to-end,” Klein told TechCrunch in an exclusive interview.

Klein’s not alone in stressing the urgency for companies to secure this sprawl. Security startup HiddenLayer‘s co-founder and CEO, Chris Sestito, earlier this month told me that when agents reach production, the scale of their costs and risk goes from theoretical to “full scale really quickly,” and that over 50 of his customers have AI agents in production touching critical systems and sensitive assets.
Cymphony, another AI startup, said at one U.S. public company, it found about 85,000 files that had become accessible to AI tools and agents.
There’s no doubt a ton of investors are interested in companies that can make a mint out of helping companies find and secure all these agents, and Reco has capitalized on that demand: The startup on Tuesday said it raised $55 million, building on a $30 million Series B in February. AT&T, a customer, invested in the extension via its venture arm, as did Forestay and Quadrille Capital.
Klein said the company’s valuation has “more than doubled” since the Series B was first announced in February, and vaguely estimated it in the “high hundreds of millions” though he wouldn’t share specifics. Annual recurring revenue right now is in the “double-digit millions of dollars,” he said, and he expects it to triple this year. The startup has more than 100 customers, and financial services companies account for about 40% of the business.
Reco’s bet, it appears, is that its existing coverage of SaaS apps, and the AI agents they are increasingly offering, will help it stand out from the crowd. The company currently integrates with more than 280 apps, and Klein says new integrations can be added within days. Klein said the platform uses browser and network signals to find agents outside apps it connects to directly within companies, and it has controls to inspect prompts and tool calls.
The startup will use the new funding for hiring, sales, partnerships, and customer support. The new funding brings Reco’s total capital raised to $140 million.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.