The company’s platform governs what AI agents are allowed to do inside corporate systems, and investors are betting that’s where the real security risk lies
Zenity, the Tel Aviv and Boston-based AI agent security and governance startup, has closed a $125 million Series C funding round led by Norwest Venture Partners. The raise, announced this week, pushes Zenity’s total disclosed funding to roughly $185 million and marks one of the largest bets yet on a fast-emerging category: securing what AI agents do inside the enterprise, not just what goes into the model.
New investors Qumra Capital, SoftBank Vision Fund 2, Hitachi Ventures, and LG Technology Ventures joined the round, alongside returning backers Vertex Ventures, Third Point Ventures, DTCP, and Intel Capital. Zenity has not disclosed its post-money valuation, its profitability, or whether an IPO is on the roadmap. The company said the capital is primarily primary funding, with a modest secondary component that let some early employees and founders sell a portion of their shares.
The size and speed of the round says as much about the market as it does about Zenity. Over the past two years, enterprises have moved from experimenting with generative AI chatbots to deploying autonomous AI agents that can log into systems, pull data, trigger workflows, and complete multi-step tasks without a human clicking “approve” at every turn. That shift changes the risk profile entirely.
Most cybersecurity spending directed at AI so far has gone toward two things: hardening the underlying models and monitoring the prompts users type into them. Zenity’s pitch to investors is that neither layer addresses the real exposure. Once an agent has standing access to a CRM, an inbox, a code repository, or a financial system, the danger isn’t a poorly worded prompt, it’s the agent itself acting outside its intended scope, whether because of a bug, a compromised integration, or a deliberate manipulation by an outside attacker.
Zenity CEO Ben Kliger has described this moment as an inflection point for the industry, arguing that security teams need to focus on the actions and autonomy agents are granted, not simply on what a user or the model outputs. He’s noted that unlike a search-style chatbot that answers a question and stops, modern agents stay connected to core business systems on an ongoing basis, meaning a single misbehaving agent can touch far more of a company’s infrastructure than a single bad prompt ever could. Norwest partner Assaf Harel echoed that view in the funding announcement, pointing to Zenity’s early-mover position and its track record of successful deployments across Fortune 1000 customers as a key reason the firm backed the round.
At its core, Zenity’s product is built to sit between AI agents and the enterprise systems they’re allowed to touch. Rather than only reviewing prompts or scanning model outputs after the fact, the platform evaluates an agent’s intent before an action executes and can approve, modify, or block that action in real time. That real-time control is what Zenity positions as its key differentiator from tools that audit AI behavior only retroactively.
The platform is built to work across the major agent ecosystems enterprises are already using, including Microsoft Copilot, ChatGPT Enterprise, Google Gemini, Anthropic’s Claude, OpenAI’s Codex, and Cursor, as well as custom agents built on infrastructure like AWS Bedrock and AgentCore, Microsoft Foundry, and Google Vertex AI. That breadth matters because most large organizations aren’t standardizing on a single AI vendor they’re running a patchwork of agents from different providers, often built by different teams, with no unified way to govern what any of them are allowed to do.
Zenity says its customer base skews heavily toward large, regulated organizations: Fortune 500 and Global 2000 companies in financial services, healthcare, pharmaceuticals, energy, manufacturing, and technology. SoftBank Corp. is among the named customers. According to the company, revenue has tripled in each of the last two years, and it’s on pace to triple again this year, a growth rate that helps explain why a roster of strategic investors, several of whom are themselves deploying agents internally, wanted into this round.
Zenity was founded in 2021 by Ben Kliger, who serves as CEO, and Michael Bargury, the company’s CTO. Both are veterans of Unit 8200, the Israeli intelligence corps’ elite cyber unit that has produced a long list of security-industry founders, and both previously worked together at Microsoft, where they helped build cloud and operational-technology security products before striking out on their own. This Series C follows a $38 million Series B the company raised in October 2024, meaning Zenity has more than tripled its total funding in under two years, a trajectory that tracks closely with the broader acceleration of enterprise AI agent adoption over the same period.
One element that sets Zenity apart from newer entrants in the AI security space is its research division, Zenity Labs. The team has built a reputation for surfacing serious vulnerabilities in widely used AI systems and has contributed findings to established industry security frameworks, including OWASP’s guidance and MITRE ATLAS, the adversarial threat matrix built specifically for AI systems. Among its more notable disclosures, Zenity Labs identified a class of attack it dubbed “AgentFlayer” a zero-click exploit capable of compromising enterprise AI agents without requiring any action from the user being targeted. The research team has also flagged vulnerabilities in Microsoft Copilot Studio and in Perplexity’s Comet browser, along with weaknesses in connected enterprise services that could otherwise have exposed sensitive company data.
Kliger has pointed to this research pipeline as a genuine competitive edge, noting that vulnerabilities and misbehavior the lab uncovers inside real enterprise environments feed directly back into product development giving Zenity a view into emerging attack patterns before they show up in the broader threat landscape.
Zenity’s raise lands amid a broader surge of investor interest in AI agent security specifically, as distinct from the older category of “AI security” focused on model safety and content filtering. As enterprises across North America, Europe, and Asia-Pacific race to put agents into production connecting them to email, code repositories, customer data, and financial systems boards and security chiefs are increasingly asking a harder question than “is the model safe?” They’re asking what happens if an agent with legitimate access starts doing something it shouldn’t.
That question is exactly what’s fueling checks like this one. The new investors joining Zenity’s round aren’t just financial backers; several, including SoftBank, Hitachi, and LG, are themselves large enterprises actively deploying AI agents in their own operations, giving the round a strategic dimension beyond pure venture return.
Zenity says the new capital will go toward three main priorities: accelerating product development, expanding Zenity Labs’ research capacity, and deepening its footprint in Europe and Asia-Pacific to meet enterprise demand in regions where AI agent adoption is accelerating fastest.
