Rein Security has raised $25 million in Series A financing to expand software that monitors and controls AI agents while they carry out work inside business systems. The round brings its total funding to $35 million.
Glilot Capital and Sienna Venture Capital co-led the financing, announced on October 8. Other participants included Corner Ventures, Atlacle and RNP Capital Advisors.
The New York and Tel Aviv company says the money will fund product development, research and hiring. Series A is an early-stage investment round intended to finance a company’s expansion; the amount raised is not revenue from customers.
Security follows what the agent does
An AI agent can use software tools to carry out tasks, such as retrieving records or updating a business system. Its access makes the consequences of a wrong instruction different from those of a chatbot producing an incorrect answer.
Rein describes its technology as runtime protection, meaning it operates while software is executing. The company says its platform observes agents’ actions and applies controls before harmful activity proceeds.
It says the platform already protects thousands of agents executing millions of actions. Customers named in the announcement include Dun & Bradstreet and Lemonade. These are company-reported deployment claims, rather than an independent assessment of how many incidents the product prevents.
Rein also reported that revenue had increased eightfold and its customer base fivefold since its January 2026 launch. It did not disclose the underlying revenue figure or customer count, limiting comparisons with other security businesses.
Permissions create risks beyond the prompt
The security organization OWASP identifies excessive agency as a risk when AI applications have more functionality, permissions or autonomy than their intended task requires.
A system that only needs to read a database, for example, should not automatically receive permission to change or delete its records. An unexpected model response becomes more damaging when the connected tools can perform unnecessary actions.
OWASP recommends limiting tools and permissions, requiring human approval for consequential actions, and enforcing authorization in the systems receiving requests. Monitoring and activity logs can help identify unwanted behavior, but do not replace those access controls.
For buyers, a security product therefore needs to be assessed against the tasks agents perform and the systems they can reach. Our earlier coverage of research into cybersecurity budgeting examines how expected losses and the protection an investment buys can guide that spending decision.
In its funding update, Rein said it would expand work by its Agent Breakers research team and hire in New York and Tel Aviv. The company is directing capital toward both developing protections and examining how agents can be manipulated.
Cover: Representative server equipment with a separately drawn security symbol. The photograph does not show a Rein installation, customer system or security incident. Photograph: Brett Sayles (Pexels License). Cropped and arranged by Market Business News.