SentinelOne founders launch Neo with $100M to build the control layer for agentic software
Former SentinelOne executives Nick Warner, Shlomi Salem, and Eran Shirazi launched Neo out of stealth with $100 million from Andreessen Horowitz, Bessemer Venture Partners, Craft Ventures, and Merlin Ventures. Neo is building a real-time control layer for agentic software that gives SecOps teams inventory, intelligence, attribution, and policy enforcement over the autonomous applications spreading through their organizations. The thesis: security was built for deterministic software. Agentic software breaks every assumption that architecture was built on.
Context from: Globenewswire | Citybiz | Neo
The decision it puts on your desk
Map your agentic software surface by end of week. List every AI agent, agentic browser, MCP-connected plugin, and AI-enabled SaaS tool your team uses. For each one, answer three questions: what can it access, what credentials does it use, and what changed in the last 90 days that nobody reviewed. If you cannot answer all three, audit the most permissive agent by Friday. The decision is whether to build the controls now or wait until an incident forces the conversation.
Nick Warner took SentinelOne public at $10 billion. On July 20, he and two co-founders launched Neo out of stealth with $100 million from Andreessen Horowitz, Bessemer Venture Partners, Craft Ventures, and Merlin Ventures.
Neo calls itself the Agentic Software Control company. The name is precise. It is not building another endpoint security tool. It is building a real-time control layer that sits between SecOps teams and the agentic software spreading through their organizations. The company had been operating quietly since early 2026 and tested its platform with organizations in financial services, transportation, and energy before the public launch.

The problem: software stopped behaving predictably
Enterprise security was architected around a specific model. Applications are deterministic. Users are human. Data moves through known paths. Security tools monitor those paths.
That model is breaking on two fronts simultaneously.
Employees are adopting AI tools from the bottom up: agents, agentic browsers, AI-enabled SaaS, MCP-connected plugins. And established software vendors are embedding agentic capabilities into products already approved for enterprise use. The application you vetted six months ago now has autonomous capabilities you never reviewed.
Gartner's numbers capture the speed. Only 5% of enterprise applications featured agentic capabilities in 2025. That number is projected to hit 40% by the end of 2026. The shift is not coming. It is already in your stack, and your security tools cannot see it.
The core problem is not that agents are malicious. It is that they are autonomous. They reason, act, invoke tools, chain APIs, and move through workflows with valid user permissions. They leave a trail that looks legitimate to every existing security tool. The controls built for deterministic software do not know the difference between a human moving a file and an agent moving a file with that human's credentials. They were not designed to.
Neo's framing is direct: "Enterprise security was built for a world where software behaved predictably. That world is changing fast."
What Neo actually ships
The Neo platform delivers five capabilities, and the order matters.
Neoverse-Powered Software Inventory gives SecOps a full catalog of AI agents, AI-enabled applications, browsers, plugins, extensions, MCP servers, and traditional software adding agentic capabilities. Neoverse is Neo's continuously updated knowledge base. It is the substrate the rest of the platform runs on.
Capability and Risk Intelligence helps teams understand what agentic software can do, what it can access, and whether it is configured safely. An HR platform with a new agentic summarization feature now has access to every personnel record. A browser with an embedded AI agent can navigate internal systems with your credentials. Neo surfaces what changed and what it means.
Real-Time Attribution produces an audit trail tying every action back to the human, agent, application, or identity responsible. When an agent moves data between systems at 3 a.m. using a VP's credentials, the security team needs to know it was the agent, not the VP. Most tools today report the credential. Neo reports the actor behind it.
Granular Software Control lets organizations enforce group-specific or identity-specific policies for tool calls, API access, data movement, and agentic workflows. Engineering gets different agent permissions than marketing. Contractors get different permissions than employees. The policy layer is scoped to identity, not just application.
Native Enforcement is the architectural differentiator. Neo enforces controls natively inside the software layer where agentic activity occurs. It blocks risky activity, redirects out-of-bound prompts, and stops malicious models without handing enforcement off to another tool. The platform does not detect and alert. It detects and intervenes.
The founding team is not new to this
The three founders have a combined track record that explains the $100 million raise before a public product.
Nick Warner, CEO, designed and built SentinelOne's go-to-market organization and, as COO, took the company public in 2021 at a $10 billion market cap. Before SentinelOne, he held senior roles at Cylance, McAfee, and Forcepoint. He has been selling enterprise security for over two decades.
Shlomi Salem led detection engineering at SentinelOne for more than a decade and co-led the in-house threat research team. He built the threat actor profiles that powered the company's entire security platform.
Eran Shirazi previously co-founded EasySend, a customer experience company later acquired, and spent years leading the IDF's Unit 8200 vulnerability research group. His background spans enterprise cybersecurity, threat intelligence, and large-scale software development.
The venture backing is structured as a bet on category creation, not feature competition. a16z's Zane Lackey said it directly: "Nick, Shlomi, Eran, and the Neo team have built category-defining security platforms before, and we believe they are uniquely positioned to build the control layer this new generation of enterprise software requires."
Bessemer's Elliott Robinson framed the same bet: "Vision is important, but execution will determine the companies that define this next era of security, and Neo is tackling one of agentic security's hardest problems."
The structural gap Neo is targeting
The existing security stack has a blind spot the size of the agentic transformation.
SIEMs monitor logs. EDRs monitor endpoints. CASBs monitor cloud applications. Identity tools monitor logins. None of them were built to track an agent that chains five API calls across three platforms using legitimate credentials, leaves no suspicious log pattern, and completes its task in under a second.
Agentic software does not need to exploit a vulnerability to be dangerous. It needs to be over-permissioned, under-monitored, and treated like a human user it is not. That describes the default state of agentic adoption in most enterprises today.
The Gartner projection that 40% of enterprise apps will be agentic by end of 2026 means the window to build the control layer is measured in months, not years. Every enterprise that deploys agentic tools without an agentic control layer is building technical debt in a category that does not forgive it. The bill comes due the first time an agent automates a process nobody realized it had access to.
The enterprise pattern
Neo tested its platform with organizations in financial services, transportation, and energy. The sector choice is deliberate. These are industries where regulatory obligations are non-negotiable and audit trails are mandatory. The consequences of an uncontrolled agent are measured in compliance violations, not just operational friction.
A bank cannot have an agent moving customer data between systems without knowing which agent, on whose behalf, with what permissions. An energy company cannot have an agent modifying operational parameters without an attributable audit trail. A transportation company cannot have an agent accessing safety-critical systems without policy enforcement. These are the use cases Neo is targeting first.
The catch
Three things this launch does not settle.
First, the platform has been tested but not broadly deployed. The organizations that tested it are early design partners. The gap between tested and scaled is the entire enterprise sales cycle, and agentic security is a new enough category that every buyer needs to be educated before they buy. The go-to-market motion is part product, part category creation.
Second, the addressable problem is real but the compliance case is still forming. Gartner's 40% projection is directionally right, but regulatory frameworks for agentic software control do not exist yet. Enterprises are buying protection against a risk their auditors have not written rules for. That makes the sale harder. Neo has to sell the problem before it can sell the solution.
Third, the incumbents are not standing still. CrowdStrike, Palo Alto Networks, and Wiz all have agentic security initiatives. SentinelOne itself, the company Warner and Salem helped build, has announced agentic security features. Neo's advantage is focus: it is not dragging a legacy platform into a new category, it is building the category from scratch. But the window to establish that lead is the same window the incumbents are using to adapt.
What we are doing this week
We are mapping our own agentic software surface: every AI agent, agentic browser, MCP-connected plugin, and AI-enabled SaaS tool our team uses. The exercise is one part inventory, one part risk assessment. Which agent has access to which system with which credentials? What changed in the last 90 days that we did not review? If the answer is "we do not know," we are Neo's target customer, and so is every other team running agentic workflows without an agentic control layer.
Source
← Previous
White House commits $5 billion to AI science, expanding Genesis Mission to 15 agencies
Next →
Glow emerges from stealth with $180M at $1.2B valuation to rebuild endpoint security for the AI era
The Morning Recap
We sift the day. You make the calls.
The decision on every story, in your inbox before your first call.