AIR Raises $50M for Continuous Checks on AI-Agent Add-Ons
The startup aims to stop enterprise agents from consuming risky tools and external content after approval—not only before it. Its early commercial metrics are company-reported.
Listen to this story
The audio brief
Story brief
3 key pointsAIR Security is entering the AI-agent security market with $50 million raised in two seed financings, backed by Sequoia Capital and Greenoaks. Its platform continuously evaluates plugins, skills, tools and external sources as agents use them, rather than treating approval as a one-time decision. AIR reports more than 20 customers and a 27% rejection rate for scanned add-ons, but both figures are company-supplied....
- 01
The financings closed within weeks: Sequoia led a $10 million round, followed by Greenoaks’ $40 million investment.
- 02
AIR reports roughly 25% of its 20-plus customers are large enterprises; customer and rejection figures are self-reported.
- 03
Air Filter scans add-ons before use; Air Defend monitors runtime activity; Air Control manages agent posture and policies.
AIR Security has emerged from stealth with $50 million across two seed rounds to police the add-ons and external sources used by enterprise AI agents. The company is betting that a one-time approval is insufficient when a previously acceptable skill or plugin can change after deployment.
The financings closed within weeks of each other. Sequoia Capital led the first, $10 million seed round; Greenoaks led the second, worth $40 million. AIR was founded by Yair Saban and Niv Hoffman, veterans of Israel’s Unit 8200 intelligence corps.
Securing what an agent takes in
AIR says its platform discovers agents running within a company, evaluates the skills, tools and components they use, and can block interactions that fail its security criteria. That puts the product at the point where an agent tries to load a skill, invoke a tool or visit an external source.
A case for re-verification
Saban’s central argument is that an add-on can become risky after it passes review—for example, if a package it downloads changes or its developer account is compromised. AIR maintains a whitelist and checks requested components against it, positioning ongoing evaluation rather than a single scan as its core control.
Three layers in AIR’s product pitch
- Air Filter vets add-ons before use. Sequoia says it uses static analysis, dependency checks and sandbox detonation—running software in an isolated environment—to assess them.
- Air Defend is intended for runtime monitoring, while Air Control handles agent posture and policy management, according to Sequoia.
The differentiation test
AIR enters a category that already includes Noma Security, Zenity, Astrix Security and Operant AI, whose offerings overlap across discovery, controls, governance and runtime protection. AIR and Sequoia contend that continuously evaluating a changing pool of skills, plugins and related components is harder to replicate than agent discovery alone.
The company has about 40 employees and plans to spend the capital on research hiring and go-to-market expansion in the U.S. and Europe. Saban said demand has been strongest in financial services and pharmaceuticals; the commercial test is whether those buyers adopt an independent layer if AI providers eventually add more of their own security checks and policies.
Sources
- techcrunch.comAIR raises $50M to help companies vet the skills and add-ons AI agents use | TechCrunch
- sequoiacap.comsequoiacap.com