AIR: A Firewall for AI Agents, Six Months Old

A critical assessment of the $50M that AIR raised across two seed rounds weeks apart — ~$10M led by Sequoia, then ~$40M led by Greenoaks — to build a “context firewall” for AI agents, entering a category the platform vendors have already begun buying out.

ProofStory Research September 1, 2026

$50M Across Two Seed Rounds — September 1, 2026

AIR emerged from stealth positioning itself as “The Context Firewall for AI Agents” — software that discovers the agents running inside a company and vets the skills, plugins, MCPs, and add-ons those agents pull from unreviewed sources. Founded February 2026 by two Unit 8200 veterans.

$50M
Total Seed Funding
2
Seed Rounds, Weeks Apart
~6mo
Age at Stealth Exit
20+
Customers (Claimed)

Three Core Questions

01

“Is the Problem Real?”

Yes. Agents now load skills, plugins, and MCP servers from sources no security team reviewed — a genuine, expanding attack surface. Sequoia and Greenoaks are underwriting a consensus thesis the whole category is funding, not a contrarian one.

02

“Is the Category Still Open?”

Barely. This is a shakeout, not greenfield: Prompt Security sold to SentinelOne (~$250M), Protect AI to Palo Alto (~$700M), and Zenity just raised $125M. AIR enters at seed, six months old, behind rivals one to two rounds ahead.

03

“What Backs the Claims?”

The funding is confirmed by five outlets. Everything else — 20+ customers, a 27% filter rate, 17,800 malicious add-ons, 6.7M installs — traces back to AIR itself. No named customer, no ARR, no third-party audit, no certifications.

Key Finding: AIR has a strong syndicate, an elite offensive-cyber founding team, and a real problem. But it is a six-month-old seed-stage entrant in a market where the platform vendors have already bought their agent-security capability — and its own CEO concedes the approach “was very easy to copy.” The most likely path is acquihire into a platform, and a $50M seed sets a high bar for a soft landing.

The Numbers

Founded
February 2026 — ~6 months old at launch
HQ
Unresolved — Israeli press says Israel (R&D, ~40 staff); US press says New York
Founders
Yair Saban (CEO), Niv Hoffman (CTO) — both Unit 8200 offensive-cyber veterans; Ryan Knisley (CSO), ex-CISO Disney & Costco
Funding
$50M total across two seed rounds: ~$10M (Sequoia), ~$40M (Greenoaks). Valuation undisclosed.
Angels
Yinon Costica (Wiz), Varun Anand (Clay), Ofir Ehrlich (Eon), Zach Frankel (Cognition), Anne Neuberger (ex-US cyber advisor)
Product
“Context Firewall for AI Agents” — discovers agents, vets skills/plugins/MCPs/sub-agents, filters inputs into agent context in real time
Integrations
Slack, ServiceNow, Salesforce, GitHub, Cursor, Copilot, ChatGPT, Claude; model layer names OpenAI, Anthropic, Azure AI Foundry, Bedrock, Vertex AI
Certifications
None visible — no SOC 2 / ISO 27001 listed; no named subprocessors disclosed
Pricing
None public. “Book a Demo” enterprise sales; free add-on scanner at scan.air.security

The Unsigned-Driver Pitch

CEO Yair Saban’s analogy: agent add-ons today are like unsigned drivers in the early 2000s — unvetted code running with privilege. AIR positions itself as the signing authority. Here is the lifecycle it claims to cover.

The Vetting Lifecycle AIR Claims

01

Discover

Find the AI agents — sanctioned and shadow — running inside the enterprise.

02

Inventory Add-ons

Enumerate the skills, plugins, MCP servers, and sub-agents each agent pulls in.

03

Vet Pre-Deploy

Analyze each add-on for hidden behavior, prompt injection, and supply-chain takeover.

04

Filter at Runtime

Sit inline and filter every input into the agent’s context as it operates.

05

Re-check on Update

Re-vet after every add-on update — the point where trusted tools turn malicious.

The website and the press describe two different products. Coverage sells a discovery-and-posture tool (“find your agents, vet their add-ons”); the site leads with an inline “context firewall” that filters every input at runtime. Those have different architectures and different moats. The story has not converged — a tell for a company that raised on narrative before the product did.

17,800 Add-ons, One Source

AIR’s launch centers on internal “MCPJacking” research: 17,800+ public AI add-ons tied to untrusted external sources across ~6.7M installations, with ~27% of what it scans filtered out. These are striking numbers — and every one of them is generated by the vendor selling the fix, unaudited and unreproduced. Compelling marketing; not yet evidence.

Sequoia (Bogomil Balkansky)

Led the first ~$10M. Thesis: founders “saw early that AI agents would create a completely new security problem.”

Greenoaks (Patrick Backhouse)

Led the ~$40M. Thesis: agents use “skills, plugins, add-ons, and MCPs from sources no security team has reviewed.”

Unit 8200 Pedigree

Offensive-cyber provenance is the hook — but the same alumni network produced NSO Group. A dual-use question for regulated buyers.

“Context Firewall”

AIR sits between agents and the outside world, filtering every input into an agent’s context. Maximum value — and maximum access.

Two “Seed” Rounds

Calling a $40M round “seed” conveniently sidesteps Series-A valuation optics. The two-step structure is unexplained.

No Certifications

A security vendor with inline access to all agent traffic launched with no visible SOC 2 or ISO 27001 — a procurement blocker.

A Shakeout, Not a Greenfield

The structural risk AIR’s launch never addresses: the platform vendors have already started acquiring their way into agent security, and the strongest independents are one to two rounds ahead.

$250M

Prompt Security → SentinelOne

Acquired August 2025 having raised only ~$23M. The platform players are buying, not building — and paying premiums for teams that got in earlier than AIR.

$700M

Protect AI → Palo Alto

Folded into Prisma AIRS. Palo Alto, CrowdStrike, Check Point, and SentinelOne now each have an agent-security answer already in the portfolio.

$125M

Zenity (Series C)

Raised August 2026, led by Norwest. Among independents still standing, Zenity and Noma (~$100M+ Series B) out-resource a $50M seed-stage entrant chasing the same finance and pharma buyers.

20+

AIR’s Customers

Company-claimed, none named, no ARR. The verifiable core of this story is the funding event; the traction is entirely self-reported six months in.

The moat rests on a claim you cannot check. Saban concedes the approach “was very easy to copy in the past” and that “many companies are emerging today,” then asserts the detection engine is “very difficult to develop.” That is a moat argument built on unverifiable internal difficulty — not on data, distribution, or switching costs.

Weaknesses & Threat Vectors

Six structural risks the $50M does not resolve.

High

Category Consolidation

Platform vendors have already acquired agent-security capability (Prompt, Protect AI, Apex). AIR’s window to remain independent may be closing before it scales — a risk its launch messaging never names.

High

Traction Is 100% Self-Reported

No named customer, no ARR, no third-party validation of the 20+ customers, 27% filter rate, or 17,800-add-on research. The only independently confirmed fact is that the money moved.

High

Better-Funded Independents Ahead

Zenity (~$125M) and Noma (~$100M+) are one to two rounds ahead in the same finance and pharma accounts AIR is targeting from a standing start.

Medium

“Who Watches the Watcher”

Inline visibility into all agent context, built by offensive-cyber operators, with no visible SOC 2 / ISO 27001 and no named subprocessors — the product’s value and its risk are the same surface.

Medium

Positioning Incoherence

“Context firewall” (runtime filter) and “discover-and-vet add-ons” (posture) are different products. The identity hasn’t settled — risky when rivals ship both.

Medium

The Two-“Seed” Structure

~$10M then ~$40M weeks apart, both labeled seed, unexplained. Benign read: Greenoaks pre-empted at a markup. Skeptical read: round health or valuation optics.

Assessment Matrix

Product Differentiation
Low-Medium
Competent taxonomy and framing, but overlapping discovery/runtime features ship across the category
Traction Quality
Low
Every metric self-reported; no named references, ARR, or audits six months in
Competitive Moat
Low
Founder concedes copyability; better-funded rivals and platform incumbents occupy the space
Security / Access Risk
High
Inline access to all agent context with no visible certifications or subprocessor disclosure
Team
Medium-High
Elite Unit 8200 pedigree and a marquee CISO hire; offensive dual-use provenance is a regulated-buyer question
Investor Signal
High
Sequoia + Greenoaks leading, plus Wiz/Clay/Cognition founders and Anne Neuberger — the most defensible positive
Investor Thesis
Medium
“Agent supply chain is unreviewed” is sound and timely — but a consensus thesis the whole category funds, not an edge

AIR is a strong team with a strong syndicate solving a real problem — late. The agent-security attack surface is genuine, and Sequoia plus Greenoaks is a serious signal. But this is a consolidating market, not a greenfield: the platform vendors have already bought in, the leading independents are rounds ahead, and AIR’s traction is entirely self-reported at six months old. The most honest read is that the $50M buys a seat at an acquihire table — a high price for a soft landing, and a high bar to clear if it wants anything more.

Research Sources

Based entirely on publicly available information, including the TechCrunch announcement of September 1, 2026. Every operating metric in this report is company-sourced unless otherwise attributed; only the funding event is independently corroborated.

  1. TechCrunch — “AIR raises $50M to help companies vet the skills and add-ons AI agents use” (September 1, 2026)
  2. SiliconANGLE — “AIR Security launches with $50M to build a firewall for AI agents” (September 1, 2026)
  3. PYMNTS — “AI Agent Security Startup AIR Raises $50 Million to Guard Enterprise Supply Chains” (2026)
  4. Calcalist (Ctech) — “Six-month-old AIR Security raises $50 million to build a firewall for AI agents” (note: describes the raise as a single round, conflicting with US coverage)
  5. AIR company website (air.security) and add-on scanner (scan.air.security) — accessed September 2026
  6. Tech Startups — “AI security startup Zenity raises $125M” (August 3, 2026)
  7. Dark Reading / Dealroom — “SentinelOne Acquires Prompt Security (~$250M)” (August 2025)
  8. Calcalist — “M&A spotlight shifts to Lasso, Aim, and Pillar after SentinelOne’s Prompt deal”
  9. Apono — “Top AI Agent Security Solutions” (competitor funding cross-check)
  10. Sequoia Capital (Bogomil Balkansky) & Greenoaks (Patrick Backhouse) — attributed investor thesis quotes in launch coverage