Reco Raises $55M to Scale Enterprise Agent Security
Enterprise security inventories were built for identities and applications that could be reviewed as separate objects. AI agents turn those objects into moving chains of permissions, tools, data, and automated actions, which means an acceptable access decision can change meaning once an agent begins working across systems.
Reco has raised $55M in additional funding to build and sell the control layer around those chains. The September 29 financing includes a strategic investment from AT&T Ventures and support from Forestay and Quadrille Capital, bringing Reco's disclosed total funding to $140M. The company says the money will expand sales, partnerships, channels, and customer support as large enterprises move AI agents into production.
The announcement does not identify a formal round, valuation, security type, or lead investor. That accounting matters because the story is not a newly disclosed Series C. It is additional capital for a company that raised a $30M Series B in February and is now trying to turn early agent-security demand into a broader enterprise operating layer.
What Reco announced
Reco's funding announcement names AT&T Ventures as a strategic participant and identifies Forestay and Quadrille Capital as supporters. Reco describes AT&T as both a customer and investor, placing the financing beside an active enterprise relationship rather than a purely financial endorsement.
The $55M follows a fast funding sequence. Reco announced $25M in additional funding in April 2025, taking its disclosed total to $55M. A $30M Series B in February 2026 lifted that total to $85M, and the latest financing brings it to $140M. Reco has not disclosed a current valuation or how much each investor contributed.
The September release calls Forestay and Quadrille new investors, but Quadrille already participated in the February Series B. The safer reading is that Forestay is newly named in Reco's financing history while Quadrille is continuing its support.
The security problem moves across applications
Reco was founded in 2020 by Ofer Klein, Gal Nakash, and Dr. Tal Shapira. Reco's current leadership page identifies Klein as co-founder and CEO, Nakash as co-founder and CPO, and Shapira as co-founder and CTO.
Their product thesis starts with a limitation in traditional access governance. Security teams can review an employee, service account, or SaaS application and decide that each one looks acceptable. An AI agent can inherit those permissions, connect another application, use a browser session or API, and initiate a workflow that changes the risk of every component around it.
The Reco Graph maps relationships among agents, human and non-human identities, applications, permissions, data, and workflows. Reco says the platform uses that context to discover agents, show what they can reach, prioritize exposure based on business impact, and reduce or revoke unnecessary access. The company reports more than 280 app integrations and 1,000 detection controls, figures that remain company-reported rather than independently audited.
Why AT&T's role matters
AT&T Ventures invests across cybersecurity, data, artificial intelligence, connectivity, and related enterprise technologies. In Reco's announcement, AT&T Ventures head Vikram Taneja frames the investment around the need to understand how agents interact with business applications and data. AT&T CISO Rich Baich also describes Reco as providing visibility into agent risk, access management, and third-party integrations inside AT&T's environment.
That customer-investor relationship is more useful than a generic strategic label because it connects capital to deployment. AT&T is not only evaluating a market thesis from outside. According to the announcement, it is using Reco to strengthen governance across its own enterprise applications and AI ecosystem.
One customer-investor relationship cannot establish broad market leadership. It does show what Reco needs to make repeatable: map a complicated environment, surface risk in language operators can act on, and reduce excessive access without shutting down legitimate automation.
The category is becoming an operating problem
AI security is often discussed at the model or prompt layer, but agents also act through the software companies already run. Reco's September 28 ServiceNow integration announcement makes that distinction concrete. Reco says it maps ServiceNow Otto agents, permissions, connected tools, and potential blast radius while also checking the surrounding ServiceNow environment and routing findings back into existing workflows.
Independent coverage offers a second view of the pressure, though the underlying data still comes from Reco. TechRadar reported that Reco's 2026 study analyzed 500 agent tools and found 62% could read local data and reach the internet. Reco also reported that only 20% of AI tools in the studied enterprise ecosystems were governed by IT.
Those figures should be read as company research, not a universal census. The operational pattern is still clear: agents can arrive through browser extensions, embedded SaaS features, copilots, Model Context Protocol tools, and automated workflows before ownership and review processes catch up.
What the $55M has to change
Reco's February Series B emphasized hiring across engineering, product, and go-to-market. The new financing is aimed more specifically at sales, partnerships, channels, and customer support, which suggests the company is preparing for the harder stage of category formation: turning technical urgency into deployments that survive procurement, implementation, and day-to-day operations.
That work is commercial and organizational as much as technical. A security team needs to know which agent exists, who owns it, what it can reach, and how to remediate access. The business also needs legitimate automation to keep moving, which means a useful platform cannot answer every uncertain connection by blocking it.
Reco now has $140M in disclosed funding and a strategic customer on the cap table. The opportunity is to make the enterprise's agent graph visible before a security incident becomes the first time the organization discovers how many systems were connected.
Frequently Asked Questions
What did Reco announce in September 2026?
Reco announced $55M in additional funding on September 29, 2026. The company said the financing brings its disclosed total funding to $140M and will support expansion across sales, partnerships, channels, and customer support.
Was Reco's $55M financing a Series C?
Reco did not disclose a formal round label for the $55M financing. It should be described as additional funding, not as a Series C, Series B extension, or another named round unless the company releases more detail.
Who participated in Reco's latest funding?
The announcement includes a strategic investment from AT&T Ventures and support from Forestay and Quadrille Capital. Reco also describes AT&T as both a customer and investor, while the amount contributed by each participant was not disclosed.
What does Reco's agent-security platform do?
Reco maps relationships among AI agents, identities, applications, permissions, data, and workflows through the Reco Graph. The company says this context helps security teams discover agents, understand what they can reach, prioritize risk, and reduce unnecessary access.
Why does the AT&T relationship matter?
AT&T's role joins customer deployment and strategic investment in the same relationship. That gives Reco a large-enterprise operating environment in which to prove that its visibility and governance approach can support agent adoption without forcing security teams to block legitimate workflows.
Where the Money Moved
The intelligence briefing of the innovation economy. Funding, M&A, debt and fund closes, read as market signal rather than deal announcements.
Subscribe to Where the Money Moved
