Startupspublished

AIR Raises $50M for Continuous Checks on AI-Agent Add-Ons

The startup aims to stop enterprise agents from consuming risky tools and external content after approval—not only before it. Its early commercial metrics are company-reported.

By 2 min read
AIR Raises $50M for Continuous Checks on AI-Agent Add-Ons
AIR Raises $50M for Continuous Checks on AI-Agent Add-Ons

Listen to this story

The audio brief

About 1:32
0:001:32
Read transcript
AIR Security has raised 50 million dollars across two seed financings, closing just weeks apart, to continuously check the tools and outside content used by enterprise AI agents. Sequoia Capital led a 10-million-dollar round, followed by Greenoaks with 40 million. The startup was founded by Yair Saban and Niv Hoffman, who previously served in Israel’s Unit 8200 intelligence corps. AIR’s pitch is that approving an add-on once is not enough. A skill or plugin can change later, pull in a different package, or become dangerous if its developer account is compromised. The company says its platform discovers agents inside a business, checks what they are trying to load or invoke, and can block interactions that fail its security criteria. Its product is split into three layers: Air Filter scans add-ons before use; Air Defend monitors activity while an agent is running; and Air Control manages policies and the agent’s overall security posture. Sequoia says the checks include static analysis, dependency reviews, and sandbox detonation—running software in an isolated environment. AIR reports more than 20 customers, with about a quarter classified as large enterprises, and says its scanner rejects roughly 27 percent of the add-ons it finds online. Those figures are company-reported. It is entering a field that includes Noma Security, Zenity, Astrix Security, and Operant AI. The key test is whether finance and pharmaceutical companies will pay for continuous, independent checks as AI providers add more built-in security controls.

Story brief

3 key points

AIR Security is entering the AI-agent security market with $50 million raised in two seed financings, backed by Sequoia Capital and Greenoaks. Its platform continuously evaluates plugins, skills, tools and external sources as agents use them, rather than treating approval as a one-time decision. AIR reports more than 20 customers and a 27% rejection rate for scanned add-ons, but both figures are company-supplied....

  1. 01

    The financings closed within weeks: Sequoia led a $10 million round, followed by Greenoaks’ $40 million investment.

  2. 02

    AIR reports roughly 25% of its 20-plus customers are large enterprises; customer and rejection figures are self-reported.

  3. 03

    Air Filter scans add-ons before use; Air Defend monitors runtime activity; Air Control manages agent posture and policies.

AIR Security has emerged from stealth with $50 million across two seed rounds to police the add-ons and external sources used by enterprise AI agents. The company is betting that a one-time approval is insufficient when a previously acceptable skill or plugin can change after deployment.

The financings closed within weeks of each other. Sequoia Capital led the first, $10 million seed round; Greenoaks led the second, worth $40 million. AIR was founded by Yair Saban and Niv Hoffman, veterans of Israel’s Unit 8200 intelligence corps.

Securing what an agent takes in

AIR says its platform discovers agents running within a company, evaluates the skills, tools and components they use, and can block interactions that fail its security criteria. That puts the product at the point where an agent tries to load a skill, invoke a tool or visit an external source.

A case for re-verification

Saban’s central argument is that an add-on can become risky after it passes review—for example, if a package it downloads changes or its developer account is compromised. AIR maintains a whitelist and checks requested components against it, positioning ongoing evaluation rather than a single scan as its core control.

Three layers in AIR’s product pitch

  • Air Filter vets add-ons before use. Sequoia says it uses static analysis, dependency checks and sandbox detonation—running software in an isolated environment—to assess them.
  • Air Defend is intended for runtime monitoring, while Air Control handles agent posture and policy management, according to Sequoia.

The differentiation test

AIR enters a category that already includes Noma Security, Zenity, Astrix Security and Operant AI, whose offerings overlap across discovery, controls, governance and runtime protection. AIR and Sequoia contend that continuously evaluating a changing pool of skills, plugins and related components is harder to replicate than agent discovery alone.

The company has about 40 employees and plans to spend the capital on research hiring and go-to-market expansion in the U.S. and Europe. Saban said demand has been strongest in financial services and pharmaceuticals; the commercial test is whether those buyers adopt an independent layer if AI providers eventually add more of their own security checks and policies.

Sources

  1. techcrunch.comAIR raises $50M to help companies vet the skills and add-ons AI agents use | TechCrunch
  2. sequoiacap.comsequoiacap.com