Rein Security has closed a $25m Series A to sell runtime controls for enterprise AI agents, taking its total funding to $35m. It is the latest in a run of raises that has turned agent security into one of the most crowded corners of the market, and UK buyers should shop accordingly.
What happened
On 8 October 2026, Rein Security announced a $25m Series A round. Glilot Capital and Sienna Venture Capital jointly led it, with Corner Ventures, Atlacle and RNP Capital Advisors also taking part. The company was founded in 2024, has headquarters in both New York and Tel Aviv, and has now raised $35m in total.
Rein started out protecting applications at runtime and has since pointed that technology at AI agents, the software that takes actions inside business systems on a user’s behalf. It says the new money will pay for product development, agent-focused research and hiring around the world. According to the company, revenue is up eightfold and its customer count fivefold since it launched commercially in January 2026. It names Dun & Bradstreet, Lemonade, Flex and Swimlane as customers, and says it protects thousands of agents that between them carry out millions of actions.
Investors are pitching the deal as an early bet on a new category. Glilot Capital’s Arik Kleinstein called agent security “a fast-moving and underserved area of security”. Rein’s chief executive, Matan Bar-Efrat, said that security has not kept up with the autonomy these systems now have.
The detail
Rein’s product uses what it calls a patented sidecar design. Instead of forcing agent traffic through a central gateway or proxy, a component runs next to each agent at the point where it executes. The aim is to show security teams what code an agent runs and which resources it reaches, to apply policy, and to block harmful actions as they happen. The company also offers controls over the agent supply chain: the models, tools and connectors an agent depends on.
The release gives one production example. An onboarding agent at a large organisation opened a PDF containing a hidden prompt injection that tried to push the agent outside its role, and Rein says it caught and stopped the resulting action. The company’s research team, Agent Breakers, also presented work at Black Hat USA 2026 on compromising an AI shopping agent belonging to a large US retailer. Neither claim has been independently verified.
The bigger story is the money moving into this space. SecurityWeek’s funding coverage for the past four weeks lists a cluster of agent-focused raises: Reco ($55m), doxx.net ($38m), AIUC ($40m), Outerlimit ($16m), Rig Security ($12m) and Kontext Security ($4m). Armadin’s $255m round at a $2.5bn valuation sits at the far end of the same theme. When TechCrunch covered Reco’s raise, it counted at least two dozen vendors selling AI agent security, many with overlapping promises. In its release, Rein quotes Gartner figures that put the market for securing AI at nearly $4.8bn in 2027, up 68.7% on 2026, and close to $7.7bn by 2028.

Why it matters for UK organisations
Rein and Reco are not UK companies, but UK buyers are likely to see them soon. A Series A this size usually pays for sales teams, and London is often an early stop for Israeli and US security start-ups expanding into Europe. CISOs at UK banks, insurers and retailers should expect a stream of near-identical pitches for agent visibility, identity and runtime guardrails.
UK policy is heading the same way. In August, the NCSC’s chief technology officer, Ollie Whitehouse, publicly raised concerns about “unsanctioned actions” by frontier AI models. He argued that AI needs strong safeguards and real-time oversight, because spotting problems after the event is not enough. The AI Security Institute has also warned that capable agents in privileged settings may act beyond their authorised scope. That is exactly the problem runtime tools claim to solve, so expect boards and auditors to start asking how agent activity is monitored and contained.
A crowded market helps buyers on price but brings consolidation risk: many of today’s start-ups will be bought or fold, forcing customers built around their proprietary designs into awkward migrations.
Expert view
When we test environments that have deployed AI agents, the findings are rarely exotic. In my experience, the agent itself is seldom the weak point. The trouble lies in what it has been allowed to reach: service accounts with broad rights, API tokens that never expire, connectors to finance or HR systems that nobody reviewed. An agent that can be steered by a poisoned document is dangerous mainly because of the privileges sitting behind it.
So I would treat runtime agent security as a useful extra layer, not a replacement for basics. Tools like Rein’s can give visibility that is currently missing, and the ability to stop an action mid-flight is valuable. However, a vendor’s claimed revenue multiple and Fortune 500 logos tell you nothing about how the product will cope with your own estate. Ask for proof in your environment, with your agents, before signing.
The sidecar-versus-gateway question deserves thought. A gateway gives one control point but becomes a bottleneck and a target. Sidecars avoid moving data through a third party, which may help with UK GDPR and data residency discussions, but they add components to every deployment that must themselves be patched and monitored. Neither approach is automatically better.
What to do now
- Inventory your agents first. Before you buy anything, list every AI agent, copilot integration and automation with write access to business systems, including those set up by individual staff. TechCrunch reports that Reco found 21,000 unknown agents at a single large customer.
- Apply least privilege to agent identities. Treat each agent as a user account under the Cyber Essentials user access control requirement: dedicated credentials, minimal rights, no shared admin tokens, and regular reviews.
- Log agent actions centrally. Make sure tool calls and data access by agents land in your existing SIEM so the SOC can investigate them. Visibility you cannot query is of little use during an incident.
- Run a structured vendor evaluation. If you go to market, ask suppliers for a proof of concept on your own workloads, detail on how their components are secured and updated, where data is processed, and what happens to your policies if they are acquired.
- Include agents in testing scope. Ask your penetration testers to cover prompt injection through documents, email and web content, and to check what a hijacked agent could actually do with the permissions it holds.
- Keep secure configuration and patching current. Agent frameworks and connectors are software like any other and belong within the Cyber Essentials patch management and secure configuration controls.
Bottom line
Rein’s $25m round is modest by this autumn’s standards, but it confirms that investors see securing AI agents as a category in its own right. UK organisations will soon have plenty of products to choose from. The sensible order of work is to find your agents, cut their permissions and log what they do, and only then to evaluate which, if any, runtime product adds enough to justify its cost.
Sources
- PR Newswire: Rein Security Raises $25 Million to Secure the AI Agents Enterprises Build and Stop the Ones That Attack Them
- SecurityWeek: Rein Security Raises $25 Million to Guard AI Agents at Runtime
- Pulse 2.0: Rein Security Raises $25 Million Series A To Secure Enterprise AI Agents
- The AI Insider: Rein Security Raises $25M to Secure the AI Agents Enterprises Build
- TechCrunch: Reco raises $55M as AI agent security startups crowd the market
- SecurityWeek: Cybersecurity Funding News
- UKTN: NCSC concerned over ‘unsanctioned actions’ of frontier AI models