Analysis
AIR, an AI security startup, came out of stealth with $50 million raised across two seed rounds closed within weeks of each other, TechCrunch reported Sept. 1. Sequoia led the first, $10 million round; Greenoaks led the second, $40 million round.
AIR was founded by Yair Saban, chief executive, and Niv Hoffman, chief technology officer, both veterans of Israel's Unit 8200 intelligence corps -- a pipeline that has produced a large share of this cycle's Israeli AI-security founders, including teams behind Wiz and multiple other cybersecurity companies now valued in the billions. AIR's product addresses a problem specific to the agentic-AI era: as AI agents increasingly pull in third-party "skills," plugins and tool integrations from open marketplaces to extend what they can do, most companies have no visibility into which of those add-ons are running inside their environment, let alone whether any of them are safe.
The platform discovers which agents are active inside a company, continuously vets the skills, tools and components those agents rely on, and blocks any that fail AIR's security criteria from interacting with company software or external systems. Pebblous reported that AIR's filtering currently rejects roughly 27% of the add-ons and skills it scans across the open internet -- meaning more than a quarter of what agents might otherwise pull in automatically fails a basic security check. AIR also runs a marketplace of pre-vetted add-ons, giving customers a safer default path rather than just a blocklist.
“AIR also runs a marketplace of pre-vetted add-ons, giving customers a safer default path rather than just a blocklist.”
AIR sits adjacent to, but distinct from, the guardrail and red-teaming companies also raising this month -- Lasso Security screens model inputs and outputs at inference time, and Alice builds adversarial test data to red-team models before deployment, while AIR is narrower and more supply-chain-specific: it governs which third-party components an agent is allowed to load in the first place, closer to a software bill-of-materials tool than a content filter. That distinction matters because this week's GitSpawn disclosure showed exactly the kind of attack surface AIR is built to catch -- a malicious component silently triggering code execution the moment an agent interacts with it.
AIR says it already has more than 20 customers, with roughly a quarter of them large enterprises and the strongest demand from financial services and pharmaceutical companies -- regulated industries where an agent quietly pulling in an unvetted skill isn't just a security incident, it's a compliance failure with its own reporting obligations.
A $50 million seed across two rounds closed within weeks, before any public product benchmark or third-party security audit exists, is priced almost entirely on founder pedigree and investor conviction rather than demonstrated defensibility -- Sequoia and Greenoaks are underwriting two Unit 8200 veterans and a live problem, not yet a proven moat, and the 27% rejection rate AIR cites is a self-reported metric from its own scanning methodology rather than an independently verified figure.