AI security startup AIR emerged from stealth on Tuesday with $50 million in seed funding to help enterprises monitor the growing software supply chain forming around AI agents — the skills, plugins, and MCP servers that let these agents interact with internal systems and the internet. The company, founded by Yair Saban (CEO) and Niv Hoffman (CTO), both veterans of Israel’s Unit 8200 intelligence corps, said the funding was raised in two tranches: $10 million led by Sequoia, followed by $40 million led by Greenoaks. Other investors include Swish, Netz, Zach Frankel (president of Cognition), Yinon Costica (co-founder of Wiz), Ofir Erlich (co-founder of Eon), Anne Neuberger, and Varun Anand (co-founder of Clay).
The company’s pitch centers on a familiar analogy: just as operating systems require signed drivers before loading code into the kernel, AI agents should require vetted skills and plugins before they can act on a company’s behalf. “In the early 2000s, whenever you installed a driver, the driver didn’t need to be signed. Today, every time you install a driver, you see a signature saying who signed it, because the driver is actually loading code into the kernel,” Saban told TechCrunch. “You don’t have that with skills or plugins or MCPs, and it’s a shame, because it’s the same mechanism, it’s the same lesson, but we haven’t learned it.”
Also read: OpenAI’s ChatGPT Health Now Integrates With Epic EHR for Clinician Access to Patient Data
What AIR’s platform actually does
AIR’s platform is built around three layers: visibility, enforcement, and continuous vetting. The visibility layer discovers AI agents active across a company’s environment, including shadow IT — employees using unapproved AI tools or personal accounts. The enforcement layer hooks into agents to intercept and analyze actions, such as loading a skill or fetching content from the internet. Finally, AIR checks any tool, add-on, or software an agent wants to use against a whitelist the startup maintains.
That whitelist is not static. Saban said AIR continuously evaluates skills and add-ons openly available on the internet for changes and malicious behavior, because a previously approved skill can become risky if a package it downloads changes or its developer’s account is compromised. The company claims its platform currently filters out about 27% of the add-ons and skills it finds online.
Also read: Apple Says Returned MacBook Shows Ex-Employee Used Trade Secrets at OpenAI
Why this matters for enterprises
The risk is not hypothetical. As AI agents gain more autonomy over databases, enterprise systems, and internet access, attackers are shifting tactics — instead of attacking the agent directly, they poison the content the agent consumes. A malicious skill or a compromised MCP server could instruct an agent to exfiltrate data or perform unauthorized actions. For regulated industries like financial services and pharmaceuticals, where AIR says it has seen the strongest demand, the stakes are particularly high.
AIR claims more than 20 customers, with roughly a quarter being large enterprises. The company currently employs about 40 people, and Saban said the new capital will go primarily toward hiring researchers and expanding go-to-market efforts in the U.S. and Europe.
Competition and market context
AIR is entering a crowded and well-funded field. Noma Security offers discovery, access controls, and runtime monitoring for agents, MCP servers, and skills, while Zenity sells security and governance tools that work similarly. Astrix Security’s identity platform also lets companies discover and control agents and MCP servers, and Operant AI offers agent protections as well as an MCP gateway. Venture money is flowing into the category: Zenity raised a $125 million Series C in August, and Noma raised a $100 million Series B last year.
Saban argues that AIR’s moat lies in its continuous vetting of the skills and add-ons ecosystem. “Continuously vetting skills and plugin websites, this is a hard mission to do. Gaining visibility over the endpoint, that is easy. Everybody’s going to do it. It’s hard to create a moat around that,” he said. Sequoia partner Bogomil Balkansky echoed that sentiment in a statement: “This is not a scanning problem, it is a continuous re-verification problem. Inspecting every skill, plugin, MCP server and sub-agent an enterprise’s agents touch, re-inspecting each one every time it changes, in real time and across an entire company’s agent fleet, is an infrastructure problem long before it is a security problem.”
While AI labs and providers will likely build in security checks over time, Saban believes companies will still want an independent product that works across vendors. The coming months will show whether AIR’s continuous vetting approach can differentiate it in a market that is already attracting significant capital and attention.
This article is for informational purposes only and does not constitute financial advice. The AI security market is evolving rapidly, and investment in startups carries inherent risks.