Every AI-agent security pitch this year starts with the same slide: agents have credentials, agents take actions, nobody is watching. Rein Security’s Series A is interesting because of where the company started, not what it says.
The round. Rein raised a $25M Series A co-led by Glilot Capital and Sienna Venture Capital, with Corner Ventures, Atlacle and RNP Capital Advisors participating. Total raised is now $35M (SecurityWeek, Oct 8). Valuation: Undisclosed. Matan Bar-Efrat and Netanel Rubin founded the company in 2024. It has 31 employees and offices in Tel Aviv and New York (Calcalist).
The traction claim. Rein says revenue is up 8x and customers 5x since it launched the product in January 2026, and that it now secures thousands of agents executing millions of actions. Those are company figures. Revenue and customer counts are Undisclosed, and 8x on a nine-month-old product can mean a small number got bigger. Read it as direction, not scale.
Why the origin matters. SecurityWeek describes Rein as built in 2024 to protect applications at runtime and give real-time context inside production, then extended to AI agents. That’s the part we’d underline. Most agent-security startups have to win a new deployment slot: a gateway, a proxy, an SDK someone has to wire in. A vendor already watching production code has a shorter path. Agents are mostly code running in production with a model in the loop. If your sensor is already there, the agent is the next thing it sees.
Same day, same instinct. Rein wasn’t alone on Thursday. Arcjet, which sells runtime security through SDKs developers drop into their apps, extended the same policies to coding agents such as Claude Code, OpenAI Codex, Cursor and GitHub Copilot, with an endpoint agent to find the unmanaged ones. PRE Security announced AgentGuard, which sits between agents and their tools and decides whether an action proceeds, gets watched, needs a human or gets blocked. Three vendors, three entry points: production runtime, the developer laptop and the tool call.
And one counterexample. Teleskope made its data-security co-pilot Kosmo generally available the same morning, and its headline design choice is that Kosmo has no tool that executes a change. It proposes, and a person approves. That’s the honest split in this market right now. Some vendors want to sit inline and veto actions. Others are betting buyers won’t let anyone sit inline yet.
Our POV. Inline wins eventually, because advisory controls don’t stop anything at machine speed. But inline is also where a false positive breaks a revenue workflow, and that’s where deals stall. Rein’s advantage is that it can start in observe mode on code it already instruments and earn the right to block. Its risk is the platforms. SailPoint pitched runtime governance for agents two days ago, and every large endpoint and cloud vendor has an agent story. A $35M company has to be clearly better at the runtime layer, or it becomes a feature in someone else’s console.
Who buys it? This is the question we’d want answered before the valuation. Runtime application security has mostly been an AppSec budget. Agent misuse lands with SecOps and identity. If Rein sells to both, the deal cycle gets longer. If it sells to one, it has to beat that team’s incumbent.
What we’d ask in the pilot. How is the sensor deployed, and what does it add in latency on a hot path? Can it tell an agent’s action from the human or service account it runs under? What share of customers run it in blocking mode, not just alerting? How does it handle agents you didn’t build, like a vendor’s copilot calling your API? And after 90 days, who wrote the policies: a security engineer, or the tool?
For investors. The 8x number will get the headlines. The better signal is whether those thousands of agents sit in a few big accounts or many, and how many of Rein’s original runtime customers turned on the agent product. Attach rate tells you whether the distribution thesis is real.
