[ Funding
](https://www.unite.ai/series/funding/)
[Add Unite.AI to your preferred sources on Google](https://www.google.com/preferences/source?q=unite.ai)
Zenity has raised $125 million in Series C funding as businesses move artificial intelligence agents from controlled experiments into systems capable of accessing data, invoking software tools and completing operational tasks.
Norwest led the round, with Qumra Capital, SoftBank Vision Fund 2, Hitachi Ventures and LG Technology Ventures joining as new investors. Existing backers Vertex Ventures, Third Point Ventures, DTCP and Intel (INTC ) Capital also participated. The company did not disclose its valuation.
The financing follows Zenity’s $38 million Series B in October 2024 and brings the company’s disclosed funding to at least $180 million.
From AI Experiments to Autonomous Systems #
The size of the round reflects a broader change in how enterprises are adopting AI. The initial wave of generative AI primarily involved employees interacting with chatbots to produce text, summarize documents or retrieve information.
AI agents introduce a different level of risk because they can take action. Depending on their permissions, agents may access internal databases, call application programming interfaces, update records, execute code, send messages or initiate workflows spanning multiple enterprise systems.
This shifts the security problem beyond whether a model produces an inappropriate response. Organizations must also understand which agents have been deployed, who controls them, what information they can reach and what actions they are authorized to perform.
An agent can behave exactly as designed while still creating a security incident if it has excessive permissions, encounters manipulated information or interprets an attacker’s instructions as part of a legitimate task.
Zenity describes this as an “agent-layer” problem. Its platform is designed to examine an agent’s configuration, permissions, connected tools, memory and runtime actions rather than looking only at the prompts entering a model or the responses it generates.
How Zenity Secures AI Agents #
Zenity divides its platform into three principal areas: observability, security posture management, and detection and response.
The observability component discovers and inventories agents operating across an organization. This includes agents embedded in software-as-a-service platforms, internally developed agents running in cloud environments and local tools installed on employee devices.
The objective is to give security teams a continuously updated picture of each agent’s owner, configuration, permissions, integrations and runtime behavior. This is becoming increasingly important as individual departments and employees gain the ability to create agents without going through a conventional software development or security review process.
Zenity’s governance layer evaluates configurations and permissions before an agent enters production. Policies can be used to identify excessive access, unsecured integrations or tools that could allow an agent to operate beyond its intended role. The platform can continue checking those controls as agents are modified over time.
At runtime, Zenity analyzes an agent’s execution path, including its tool calls, memory access, data usage and interactions with other systems. The company says it can use this context to allow, modify or block an action before it occurs.
That approach is intended to distinguish between a normal request and an apparently normal request that has been influenced by malicious content. It also addresses an important limitation of prompt filtering: a dangerous outcome can emerge from a sequence of individually harmless actions.
Covering SaaS, Cloud and Employee Devices #
Zenity is attempting to provide a common security layer across a fragmented agent ecosystem.
For software-as-a-service environments, it supports agents associated with platforms such as Microsoft 365 Copilot, Microsoft Copilot Studio, ChatGPT Enterprise and Salesforce (CRM ) Agentforce. These systems can provide agents with access to business documents, customer records, communications and workflows that the enterprise does not fully host or control. The platform also covers custom agents built with services including AWS Bedrock, Azure AI Foundry and Google Vertex AI. Zenity monitors which tools and cloud services these agents invoke while applying policies during development and execution.
A third area involves device-based agents such as coding assistants, desktop applications and agentic browsers. These tools can operate inside an employee’s authenticated environment, potentially inheriting access to files, browser sessions and connected services.
Bringing these environments into one system could simplify governance, but it also creates a considerable technical challenge. The architecture, permissions and telemetry available from a software-as-a-service copilot can differ substantially from those of a custom cloud agent or locally installed coding tool.
Security Research Highlights the Emerging Threat Model #
Zenity has supported its product development with research conducted through Zenity Labs, which investigates how autonomous systems can be manipulated through untrusted content.
Its AgentFlayer research examined zero-click and one-click attack chains involving widely used enterprise AI platforms. The demonstrations included scenarios in which malicious instructions delivered through emails, documents, support cases or collaboration tools caused agents to expose information, misuse connected tools or alter their responses.
More recent research examined Perplexity’s Comet agentic browser. Zenity researchers demonstrated how hidden instructions inside a calendar invitation could influence the browser while it was performing a routine task. In one scenario, the compromised agent navigated an unlocked 1Password web vault and transmitted credentials through ordinary web requests.
The research attributed the issue to insufficient separation between the user’s intentions and third-party content encountered by the agent. Because the agent was already operating within an authenticated browser session, it could potentially use access that the user had legitimately granted.
These demonstrations illustrate why agent security cannot rely entirely on detecting obviously malicious prompts. The instructions may be buried inside data that an agent is expected to read, while the resulting actions may resemble normal browsing, document retrieval or application activity.
They also underscore the importance of boundaries that remain enforceable even when an agent’s reasoning has been manipulated.
Funding Global Expansion and Product Development #
Zenity says its revenue has tripled in each of the past two years and is on pace to triple again this year. The company reports that many of its customers are Fortune 500 and Global 2000 organizations operating in regulated industries such as financial services, healthcare, pharmaceuticals, manufacturing and energy.
It now has more than 230 employees, with research and development centered in Tel Aviv and its go-to-market and operational functions led from New York.
The Series C funding will be used to accelerate product development, expand Zenity Labs and strengthen the company’s presence in Europe and the Asia-Pacific region. It will also give Zenity additional resources to support a growing number of agent frameworks as enterprise AI infrastructure becomes more diverse.
That expansion comes less than two years after the company’s previous institutional round, when Zenity was still emphasizing its origins in low-code and no-code application security. Its current positioning reflects how those earlier concerns have evolved: employees who could once build simple business applications can now create agents capable of making decisions and operating connected systems.
AI Agent Security Is Becoming Its Own Category #
Zenity’s fundraise signals investor confidence that AI agent security could develop into a substantial cybersecurity category rather than remain a feature within existing cloud, identity or endpoint products.
The argument for a dedicated category is that conventional tools generally see only part of an agent’s activity. Cloud security platforms can inspect infrastructure, identity systems can manage permissions and endpoint products can detect operating-system-level threats. They do not necessarily understand an agent’s intended role or how a chain of tool calls relates to the user’s original objective.
Zenity will still need to prove that its intent-based controls can operate across rapidly changing frameworks without creating excessive alerts, blocking legitimate work or adding unacceptable latency. It must also demonstrate that enterprises will purchase a separate agent-security platform rather than rely on controls added by major cloud and software providers.
The immediate market opportunity is nevertheless becoming clearer. As agents gain access to sensitive data and begin controlling consequential business processes, organizations will need more than a record of what happened after an incident. They will need mechanisms capable of identifying which agents exist, constraining what they can do and intervening before an unintended action becomes a breach.
Zenity’s $125 million Series C gives the company significant resources to pursue that role as security teams prepare for an enterprise environment increasingly populated by autonomous software.