Ent
Intent-aware workspace security startup with elite security founders and a record $100M seed, but thin public proof.
Ent is a high-pedigree, high-ambition workspace security startup with a rare $100M seed and credible product wedge, but the absence of disclosed financials, named customer depth and independent efficacy benchmarks makes it a monitor-now rather than invest-now situation.
Cover facts
Company profile
Ent is a seed-stage cybersecurity startup founded in 2025 by RiskIQ veterans Elias Manousos and Brandon Dixon. The company emerged from stealth on 2026-06-16 with a $100M seed round led by Decibel and positioned its product as an intent-aware workspace security layer that observes human and AI-agent activity on the endpoint, infers intent in real time, and intervenes before data exfiltration or insider-risk incidents complete. The public debate is whether exceptional founder pedigree and a large market can outrun thin disclosed customer proof, undisclosed economics and unbenchmarked efficacy.
- Website
- ent.ai
- Founded
- 2025-01-01
- Founders
- Elias Manousos, Brandon Dixon
- Founding location
- San Francisco Bay Area, California, USA
- Headquarters
- San Francisco, California, USA
- Product
- Lightweight on-device AI agent for Windows, macOS, Linux and browser environments that infers user and AI-agent intent in real time to support insider-risk detection, AI governance, DLP, last-mile threat prevention and incident investigation.
- Customers
- Global 2000 enterprises, especially hospitality, financial services, defense and other regulated environments.
- Business model
- Enterprise security software sold into the CISO budget, likely priced per endpoint or seat, with customer-cloud deployment and attached policy, governance and investigation workflows.
- Stage
- Seed-stage private
- Funding status
- $100M seed announced on 2026-06-16 led by Decibel with Sequoia, Craft Ventures, Crosspoint Capital, Shield Capital, Felicis and In-Q-Tel participating; no post-money valuation disclosed.
Executive summary
Top strengths
- Elite founder-market fit anchored by RiskIQ and Microsoft security leadership.
- Large, fast-growing market across endpoint security, DLP, insider risk and AI governance.
- Lightweight on-device architecture and customer-cloud hosting create a differentiated prevention-first product story.
Top risks
- No independent public benchmark validates Ent's intent-inference accuracy or false-positive rate.
- Revenue, ARR, pricing, retention, valuation and customer concentration remain undisclosed.
- Large incumbents such as Microsoft, CrowdStrike and SentinelOne can bundle adjacent capabilities and compress Ent's wedge.
- Workplace monitoring, privacy and AI-governance regulation can complicate adoption in regulated geographies.
Open gaps
- Confirmed post-money valuation, cap table terms and investor governance rights are not public.
- ARR, burn, runway, gross margin and pricing are undisclosed.
- Named customer references, renewal behavior, NRR and concentration data are unavailable.
- Independent efficacy benchmarks and false-positive measurements have not been published.
Contents
01Company Overview
1.1 Identity, headquarters, founding and business model
Ent is an intent-aware workspace security company that emerged from stealth on June 16, 2026 with a lightweight on-device AI agent for Windows, macOS, Linux and browser extensions. Its core thesis is to bring prevention back to cybersecurity by using specialized AI models to evaluate the intent of both human users and AI agents in real time and intervene before incidents occur, rather than relying on after-the-fact detection. The platform is hosted in the customer's own cloud to preserve data sovereignty, and the company frames its use cases as insider risk detection, AI governance, data loss prevention, last-mile threat prevention and incident investigation. Public records place Ent's headquarters in San Francisco, California, though some coverage uses the broader San Francisco Bay Area, and direct confirmation is advisable. Founding timing is mildly conflicting: BankInfoSecurity reports a May 2025 founding and the Wall Street Journal says Ent launched in 2025, while the company emerged publicly only in mid-2026. The safest canonical description is a 2025-founded, seed-stage private company that operated in stealth for roughly a year before a high-profile 2026 debut. The legal operating entity behind the ent.ai brand has been associated informally with the name Athena Formation Inc., but that is not firmly confirmed in primary disclosures and should be verified against incorporation records. In short, the identity is directionally clear but several basic facts still warrant primary confirmation during diligence.[CO001, CO011, CO013, CO014, CO015, CO016]
| Metric | Value / Status | Date | Confidence | Gap / Notes |
|---|---|---|---|---|
| Founding | 2025 (stealth); some sources cite May 2025 | 2025 | medium | WSJ says launched 2025; BankInfoSecurity says founded May 2025. |
| Emerged from stealth | June 16, 2026 | 2026-06-16 | high | Business Wire press release and broad syndication. |
| Headquarters | San Francisco, California | 2026 | medium | Some sources say SF Bay Area; direct confirmation advised. |
| Stage | Seed (private) | 2026-06-16 | high | Single oversized seed round. |
| Seed raised | $100M | 2026-06-16 | high | Confirmed by company release and WSJ. |
| Total raised | $100M | 2026-06-16 | high | One round to date. |
| Valuation | No post-money valuation publicly disclosed; unicorn-territory language only. | |||
| Headcount | ~100 | 2026 | medium | WSJ figure; earlier reports cited fewer pre-hiring. |
| Revenue / ARR | Not disclosed; private seed-stage company. | |||
| Customer count | Not disclosed; Global 2000 deployments cited without names. | |||
| Platform GA | Windows, macOS, Linux, browser extensions | 2026-06-16 | medium | Company-stated general availability. |
Funding and stealth-exit date are treated as canonical; valuation, revenue, customer count and exact headcount remain private or conflicting and are flagged as gaps.
[CO002, CO011, CO012, CO020, CO021, CO024]Ordinal scorecard converts the chapter's evidence into a fast read on pedigree, capital access, traction signal, disclosure quality and key-person concentration.
[CO005, CO021, CO025, CO031, CO033, CO037]1.2 Founders, advisory bench and key-person dependence
Ent was co-founded by Elias Manousos and Brandon Dixon, two veterans of RiskIQ. Manousos co-founded and led RiskIQ for roughly fourteen years before Microsoft acquired it in July 2021 in a deal reported at more than $500 million, after which he served as a Microsoft corporate vice president for AI Copilot for Security and threat intelligence. Dixon co-founded PassiveTotal, which RiskIQ acquired, and later worked as a Security AI Strategist at Microsoft where he spearheaded the launch of Microsoft Security Copilot. This is unusually strong founder-market fit for an endpoint and AI-governance security company. That strength carries a corresponding key-person concentration. The two co-founders previously built and sold a company together, and the WSJ-reported headcount of roughly 100 is small relative to incumbents, so execution leans heavily on the founding pair. Ent has bolstered credibility with an advisory bench that it says includes former CISOs of Google, Aetna and MassMutual, a former NSA director, and a former Microsoft corporate vice president for Azure cloud security. Investor leads such as Decibel's Jon Sakoda add governance influence, but the full board composition and which investors hold seats or information rights are not publicly disclosed and remain a diligence item.[CO005, CO006, CO007, CO008, CO009, CO010]
| Person | Current / recent role | Background | Founder-market fit / coverage | Key-person dependency |
|---|---|---|---|---|
| Elias Manousos | Co-founder & CEO | RiskIQ co-founder/CEO ~14 yrs; Microsoft CVP for AI Copilot for Security | Deep threat-intelligence and security go-to-market pedigree | high |
| Brandon Dixon | Co-founder | PassiveTotal co-founder (acquired by RiskIQ); Microsoft Security Copilot lead | AI-security product and threat-intelligence depth | high |
| Advisory bench | Strategic advisors | Former CISOs of Google, Aetna, MassMutual; former NSA director; former Microsoft CVP Azure cloud security | Enterprise credibility and defense-market access | medium |
| Investor leads | Board / governance | Decibel (Jon Sakoda) led; Sequoia, Crosspoint, Craft, Shield, Felicis, IQT participated | Capital, networks and security-sector expertise | medium |
Built from public launch coverage and investor pages; below-founder org structure and exact board composition are not publicly disclosed.
[CO005, CO006, CO009, CO010, CO022, CO023]1.3 Funding, investors, milestones and disclosure profile
Ent announced $100 million in seed financing on June 16, 2026, led by Decibel with participation from Sequoia, Craft Ventures, Crosspoint Capital Partners, Shield Capital, Felicis and In-Q-Tel. That makes the round one of the largest seed financings in cybersecurity history and brings total capital raised to $100 million across a single round. In-Q-Tel's presence links Ent to U.S. national-security buyers, and Crosspoint adds cybersecurity-specialist private-equity backing. Notably, the company has not disclosed a specific post-money valuation, using only unicorn-territory language, and it has not published revenue, ARR or named customers. The milestone record is compact and concentrated: a 2025 stealth founding, a mid-2026 emergence with simultaneous financing and platform general availability, disclosed Global 2000 deployments in hospitality, financial services and defense, and a planned Black Hat USA 2026 presence in August. Skeptical coverage from The Next Web and DLP Test cautioned that the prevention narrative is no longer contrarian and that intent-detection and low-false-positive claims lack published independent benchmarks. As a result, Ent is best treated as a capital-rich, pedigree-heavy seed company whose narrative currently runs ahead of independently verifiable operating proof.[CO002, CO003, CO004, CO018, CO019, CO020]
| Stakeholder | Role | Control / economic importance | Diligence ask |
|---|---|---|---|
| Decibel | Lead seed investor | Largest economic stake; Jon Sakoda board-level influence | Confirm board seat, ownership % and pro-rata rights |
| Sequoia | Co-investor | Tier-one signaling and follow-on capacity | Confirm allocation and any information rights |
| Crosspoint Capital Partners | Co-investor | Cybersecurity-specialist PE backing (Greg Clark) | Confirm strategic role and governance |
| Craft Ventures | Co-investor | Enterprise-software network | Confirm allocation and advisory role |
| Shield Capital | Co-investor | Security/national-security focus | Confirm defense go-to-market support |
| Felicis | Co-investor | Growth-oriented co-investor | Confirm allocation |
| In-Q-Tel (IQT) | Strategic investor | Links Ent to U.S. national-security buyers | Confirm strategic agreement scope and any procurement pathway |
Investor identities are taken from launch coverage and investor websites; precise ownership percentages and governance terms are private.
[CO003, CO004, CO022, CO029, CO030]| Date | Event | Type | Amount / Valuation / Status | Participants | Implication |
|---|---|---|---|---|---|
| 2025 | Company founded and operated in stealth | founding | Private | Manousos, Dixon | Two-year build before public launch |
| 2025-09 | Co-founder Brandon Dixon visible as security-AI advisor elsewhere | governance | n/a | Brandon Dixon | Confirms founder profile pre-launch |
| 2026-06-16 | Emerged from stealth | product | GA platform | Ent | Public market entry |
| 2026-06-16 | Seed financing announced | financing | $100M | Decibel (lead), Sequoia, others | One of the largest cybersecurity seeds |
| 2026-06-16 | Platform general availability | product | Windows/macOS/Linux/browser | Ent | Commercial readiness claimed |
| 2026-06-16 | Global 2000 deployments disclosed | scale | Hospitality, finance, defense | Ent customers | Early enterprise traction signal |
| 2026-06 | Advisory bench unveiled | partnership | n/a | Ex-CISOs, ex-NSA director | Enterprise and defense credibility |
| 2026-06 | Skeptical press coverage | adverse | n/a | The Next Web, DLP Test | Benchmarks and false-positive claims unproven |
| 2026-08 | Planned Black Hat USA 2026 presence | partnership | Booth #5341 | Ent | Go-to-market visibility step |
Single chronology of record for the chapter; 2025 founding day and some 2026 dates are approximate to the reported month.
[CO001, CO002, CO013, CO018, CO024, CO026]Ent's public chronology compresses a two-year stealth build into a single high-profile 2026 launch with capital, product GA and early traction announced together.
[CO001, CO002, CO018, CO026, CO035, CO038]Ent links a veteran founder pedigree and oversized seed capital to an intent-aware product and early enterprise deployments, with disclosure and key-person dependencies as the main caveats.
[CO005, CO021, CO016, CO018, CO031, CO033]1.4 Exhibits
02Market Analysis
2.1 Market boundary, adjacencies and substitutes
Ent sits at the intersection of four security budgets: endpoint security, data loss prevention, insider risk management and the emerging category of AI governance. Drawing the boundary before sizing matters, because Ent is an on-device agent that competes most directly with endpoint protection and EDR for placement on the device, while its differentiated value is in inferring intent for insider risk and governing both human users and AI agents. Gartner's definition of an endpoint protection platform as software deployed on devices to prevent and detect malicious activity anchors the core, and adjacent categories such as UEBA, CASB, EDR and AI governance border the perimeter. On this boundary, the spend Ent can credibly address includes on-device protection, content inspection and exfiltration control, behavioral insider-risk investigation, and controls over AI-agent actions. It excludes network firewalls, pure SIEM, and managed-SOC labor, which are adjacent but not on the endpoint. The status-quo substitutes Ent displaces are legacy DLP suites, EDR alerting workflows and manual insider-risk investigation, all of which the company argues are reactive. XDR and AI-SOC are treated as adjacent rather than core to avoid double counting in the sizing that follows. The practical test for inclusion is whether a budget line is spent on the device or workspace where Ent's agent runs, which keeps the boundary tight and defensible for the diligence reader rather than inflating the headline opportunity with loosely related security spend.[CM001, CM022, CM023, CM025, CM027, CM031]
| Segment / category | Included spend | Excluded spend | Buyer / payer | Relevance to Ent |
|---|---|---|---|---|
| Endpoint security / EPP-EDR | On-device protection, detection, response | Network firewalls, pure SIEM | CISO / security ops | Core overlap; Ent is an on-device agent |
| Data loss prevention | Content inspection, exfiltration control | Email security gateways alone | CISO / compliance | Direct use case in Ent's platform |
| Insider risk management | User behavior, intent, investigation | Physical security | CISO / insider-risk team | Primary differentiator for Ent |
| AI governance | Controls over human and AI-agent actions | Model training infrastructure | CISO / AI risk owner | Emerging adjacency Ent targets |
| XDR / AI-SOC (adjacent) | Cross-domain correlation, automation | Managed SOC labor | Security operations | Bordering category, partial overlap |
Boundary is drawn before sizing; XDR/AI-SOC is listed as adjacent rather than core to avoid double counting.
[CM001, CM022, CM023, CM025, CM031]2.2 TAM, SAM and SOM across multiple lenses
No single TAM number is reliable here, so the chapter triangulates. The global endpoint security market was roughly $18.58 billion in 2025 and about $20.79 billion in 2026, growing near 11.9% toward $32.52 billion by 2030. Within and beside it, EDR is estimated near $6.33 billion in 2026 and growing far faster at about 24% toward $18.68 billion by 2031, while DLP is about $4.67 billion in 2026 growing near 27% toward $12.53 billion by 2030. The broader XDR and AI-SOC opportunity is sized from $33.4 billion in 2025 to $89 billion by 2031, but with the loosest scope. Independent analysts disagree at the margins because they scope these segments differently, and those disagreements are preserved as a diligence item rather than averaged away. Combining endpoint, EDR and DLP gives an order-of-magnitude multi-segment reference above $30 billion before de-duplication, and a defensible 2026 SAM for Ent's combined workspace-security category is roughly $25-30 billion. The obtainable SOM, however, cannot be pinned down: Ent has not disclosed per-endpoint or per-seat pricing, and there is no public Ent-specific SAM or SOM calculation, so the startup-addressable slice remains only partly estimable and rests on category proxies.[CM002, CM003, CM004, CM005, CM006, CM007]
| Publisher | Segment | Year | Value | CAGR | Confidence | Limitation |
|---|---|---|---|---|---|---|
| The Business Research Company | Endpoint security | 2026 | $20.79B | 11.9% | high | Broad EPP/EDR scope |
| Research and Markets | Endpoint security | 2026 | High-teens to low-$20B | n/a | medium | Range, not point estimate |
| Mordor Intelligence | EDR | 2026 | $6.33B | 24.16% | medium | Subset of endpoint |
| The Business Research Company | DLP | 2026 | $4.67B | 26.9% | high | Excludes some adjacencies |
| Fortune Business Insights | DLP | 2026 | Growing rapidly | n/a | medium | Qualitative driver framing |
| HiQual Insights | XDR / AI-SOC | 2025-2031 | $33.4B to $89B | 22.6% | low | Broad, adjacent scope |
| Analyst synthesis | Combined workspace SAM | 2026 | ~$25-30B | n/a | medium | Estimate; de-duplication required |
Multiple lenses are shown rather than one headline TAM; the combined SAM row is an analyst estimate and must be de-duplicated against overlapping segments.
[CM002, CM004, CM006, CM008, CM009, CM010]Layered view from a multi-segment TAM above $30B down to a combined workspace-security SAM near $25-30B and a presently unquantified startup SOM.
[CM009, CM010, CM032, CM035]Source-backed low/high bounds for four 2026 market quantities, all expressed in USD billions for comparability.
[CM002, CM004, CM006, CM009]2.3 Buyers, demand drivers and adoption constraints
The economic buyer for Ent is the enterprise CISO, with security operations, IT and compliance as influencers, and budget ownership sitting primarily inside the security organization with overlap into IT and compliance. Ent's disclosed verticals - financial services, hospitality and defense - map to recognizable buying centers and adoption triggers: regulatory and fraud pressure in finance, distributed-workforce risk in hospitality, and national-security mandates in defense. The adoption path typically runs from a targeted pilot through vertical rollout to enterprise-wide deployment, gated by efficacy proof and the consolidation of point tools. On the demand side, AI-accelerated attacks are compressing dwell time and raising the value of prevention, the proliferation of autonomous AI agents is opening a new AI-governance budget line, and tightening data-protection regulation sustains DLP spend; endpoint proliferation and remote work expand the footprint further. The constraints are equally concrete. Microsoft's bundling of Defender into M365 E5 raises switching costs, North America concentrates spend, and skeptical coverage about false positives and unproven benchmarks means trust-based adoption can be slow. The net market read is a large, fast-growing, but incumbent-anchored opportunity where Ent's prevention thesis is most valuable precisely where AI is accelerating attacks.[CM011, CM012, CM013, CM014, CM015, CM016]
| Segment | Buyer | User | Payer | Workflow | Adoption trigger |
|---|---|---|---|---|---|
| Financial services | CISO | Insider-risk analyst | Security budget | Insider risk + DLP | Regulatory and fraud pressure |
| Hospitality | CISO / IT | SOC analyst | IT/security budget | Last-mile threat prevention | Distributed workforce risk |
| Defense / government | CISO / security officer | Threat hunter | Program budget | AI governance + investigation | National-security mandates |
| Technology / SaaS | CISO | Security engineer | Security budget | AI agent governance | Agent proliferation |
| Regulated enterprise (broad) | CISO + compliance | Compliance analyst | Compliance/security | DLP + audit | Data-protection regulation |
Segments are inferred from Ent's disclosed verticals and standard security buying centers; payer lines overlap across IT, security and compliance.
[CM011, CM012, CM024, CM030, CM033]| Driver / constraint | Direction | Timing | Implication | Diligence ask |
|---|---|---|---|---|
| AI-accelerated attacks | Driver | Now | Raises value of prevention | Quantify dwell-time reduction |
| AI agent proliferation | Driver | Now-2027 | New AI-governance budget line | Confirm agent-governance demand |
| Data-protection regulation | Driver | Now | Sustains DLP spend | Map customer compliance triggers |
| Remote/distributed work | Driver | Structural | Expands endpoint footprint | Confirm per-seat economics |
| Incumbent bundling (Defender E5) | Constraint | Now | Raises switching cost | Test displacement vs add-on |
| Unproven efficacy / false positives | Constraint | Near-term | Slows trust-based adoption | Demand independent benchmarks |
Drivers and constraints are tied to budget owner and adoption timing; the efficacy constraint reflects skeptical press coverage.
[CM014, CM015, CM016, CM017, CM018, CM019]Mapping of Ent's priority verticals to budget owner, adoption trigger and lead use case.
[CM011, CM012, CM030, CM033, CM014]Adoption flows from a targeted pilot through vertical rollout to enterprise-wide deployment, gated by efficacy proof and budget consolidation.
[CM013, CM018, CM019, CM032]2.4 Exhibits
03Competitors
3.1 Competitive landscape: direct, incumbent, adjacent and entrants
The competitive landscape Ent enters is crowded and concentrated. Its most direct competitors are endpoint platforms - CrowdStrike Falcon and SentinelOne Singularity - that pair AI-driven detection with autonomous response. The dominant incumbent is Microsoft Defender for Endpoint, distributed through Microsoft 365 E5 bundling, which gives it near-zero marginal cost to a vast installed base. Platform consolidators such as Palo Alto Cortex XDR, alongside established incumbents Broadcom-owned Symantec, Trend Micro Vision One and Cybereason, round out the endpoint field. Bordering Ent's use cases are the data-loss-prevention and insider-risk specialists - Proofpoint, Varonis and DTEX - whose data-security and behavioral-analytics depth overlap with Ent's insider-risk and DLP claims. The status-quo substitute Ent displaces is reactive detection-and-alerting plus manual investigation, which the company frames as too slow for AI-accelerated attacks. Large enterprises could in principle build internal monitoring, but the intent-inference models are difficult to replicate, limiting build-versus-buy substitution. Finally, a cohort of new AI-agent-security entrants is forming to chase the same emerging AI-governance budget Ent targets, making the entrant frontier as important as the established field. In short, Ent is squeezed between deeply funded public platforms above and nimble specialists beside it, so its landscape position is best understood as a new wedge rather than a head-on replacement for any single incumbent category.[CP001, CP002, CP003, CP004, CP005, CP006]
| Competitor | Category | Scale / funding | Target customer | Product scope | Pricing model | Strategic direction |
|---|---|---|---|---|---|---|
| CrowdStrike Falcon | Direct (cloud EDR) | Public, multi-billion revenue | Enterprise | EDR, MDR, threat intel | ~$100+/endpoint/yr | AI-driven platform expansion |
| SentinelOne Singularity | Direct (on-device) | Public, ~$17B class | Enterprise / mid-market | Autonomous EDR, rollback | ~$80/endpoint/yr | On-device autonomy + data |
| Microsoft Defender | Incumbent | Part of Microsoft | M365 enterprises | EDR via E5 bundle | Included in E5 | Windows-native bundling |
| Palo Alto Cortex XDR | Adjacent platform | Public, large cap | Enterprise | Cross-domain XDR | Platform/credit pricing | Consolidation play |
| Broadcom / Symantec | Incumbent | Part of Broadcom | Large enterprise | Endpoint suite | Enterprise license | Mature install base |
| Trend Micro Vision One | Incumbent | Public | Enterprise | Cross-layer XDR | Suite licensing | Broad XDR coverage |
| Varonis / DTEX | Adjacent (insider risk) | Public / private | Regulated enterprise | Data + insider risk | Per-user/data | Insider-risk depth |
| Proofpoint | Adjacent (DLP) | Private (Thoma Bravo) | Enterprise | Human-centric DLP | Per-user | People-centric security |
Profiles synthesize vendor and analyst material; figures such as per-endpoint pricing are indicative list references, not negotiated enterprise pricing.
[CP009, CP010, CP011, CP012, CP013, CP003]Positioning of Ent and peers on breadth of workspace coverage (x) versus intent-awareness depth (y).
[CP001, CP014, CP015, CP030]3.2 Capability, pricing and go-to-market comparison
On capability, Ent's differentiation is sharp: it claims real-time intent inference rather than after-the-fact signature or behavior matching, and uniquely says it evaluates the intent of both human users and AI agents - a scope no incumbent yet matches. It hosts in the customer's own cloud for data sovereignty, contrasting with the vendor-cloud model of CrowdStrike, SentinelOne and Defender. Both CrowdStrike and SentinelOne, however, push autonomous AI-driven response as their own core differentiator, and incumbents currently have only limited dedicated AI-agent governance, the precise gap Ent attacks. On pricing, the field is well understood while Ent's is not. CrowdStrike Falcon lists at roughly $100 or more per endpoint per year and SentinelOne near $80 for core tiers, while Microsoft Defender is effectively free to E5 holders - a powerful anchor. Ent has disclosed no pricing, so the comparison preserves that gap explicitly. On go-to-market, Microsoft and CrowdStrike wield outsized distribution through existing enterprise relationships, whereas Ent must sell a new agent into security organizations one vertical at a time. On trust and regulatory posture, Ent's customer-cloud hosting is a credible advantage for regulated buyers wary of vendor-cloud data exposure, and it may also ease procurement in defense and financial-services accounts where data-residency requirements complicate adopting vendor-hosted security telemetry.[CP010, CP012, CP013, CP014, CP015, CP016]
| Capability | Ent | CrowdStrike | SentinelOne | MS Defender | DLP/insider peers |
|---|---|---|---|---|---|
| On-device AI inference | Yes | Partial (cloud-first) | Yes | Partial | No |
| Real-time intent inference | Yes (core) | No | Limited | No | Limited |
| Human + AI-agent coverage | Yes | No | No | No | No |
| Prevention-first posture | Yes | Detection-led | Detection + response | Detection-led | Policy-based |
| Customer-cloud hosting | Yes | Vendor cloud | Vendor cloud | Vendor cloud | Mixed |
| DLP + insider-risk in one agent | Yes | Add-on | Add-on | Via Purview | Specialized |
Capability claims for Ent are company-stated and not yet independently benchmarked; competitor cells reflect publicly documented positioning.
[CP014, CP015, CP016, CP028, CP025, CP033]| Vendor | Pricing model | Indicative list | Bundling | Notes |
|---|---|---|---|---|
| CrowdStrike | Per-endpoint subscription | ~$100+/endpoint/yr | Modular add-ons | Tier upsell to platform |
| SentinelOne | Per-endpoint tiered | ~$80/endpoint/yr | Core/Control/Complete | Rollback in higher tiers |
| Microsoft Defender | Bundled | Included in M365 E5 | E5 suite | Marginal cost near zero for E5 holders |
| Palo Alto Cortex | Platform / credits | Custom | XDR platform | Consolidation discounts |
| Ent | Undisclosed (per-seat/endpoint likely) | Not disclosed | Single agent | Pricing not public at launch |
Ent has not disclosed pricing; competitor figures are indicative public references and vary widely by negotiation and volume.
[CP010, CP012, CP013, CP020, CP035]Capability coverage across Ent and the three leading endpoint incumbents.
[CP014, CP024, CP025, CP035]3.3 Switching costs, moat durability and displacement risk
Endpoint security carries high switching costs because agents are deployed fleet-wide and wired into SOC workflows, and incumbent bundling - Microsoft's above all - creates lock-in that raises the bar for any displacer. At the same time, enterprises frequently multi-home endpoint, DLP and insider-risk tools, which leaves room for a consolidating entrant that can fold several point capabilities into one agent. Ent's competitive readiness rests on a strong founder pedigree, a $100 million war chest and early Global 2000 deployments across finance, hospitality and defense. The durability of Ent's moat is the central question. Its intent-inference models and human-plus-AI-agent scope are genuinely novel, but they are vulnerable to fast-following incumbents who could embed similar capabilities, and skeptical coverage notes that prevention messaging is no longer contrarian and that Ent has published no independent benchmarks. The weakest moat factor is distribution, where Microsoft and CrowdStrike dominate. The net verdict is that Ent holds a real product wedge that is unproven at scale; it must win on demonstrable efficacy and rapid time-to-value rather than price to overcome incumbent distribution and lock-in. Should it fail to publish convincing efficacy evidence quickly, the most likely outcome is that incumbents absorb the intent-aware concept and Ent is relegated to a niche, which is the core competitive risk a diligence reader must weigh.[CP017, CP018, CP019, CP021, CP022, CP026]
| Moat / risk factor | Strength for Ent | Competitive threat | Durability |
|---|---|---|---|
| Intent-inference models | High (novel) | Incumbents fast-follow | Medium |
| Human + AI-agent scope | High | Platform vendors extend | Medium |
| Founder pedigree + capital | High | Talent and capital are broadly available | Medium-high |
| Customer-cloud sovereignty | Medium | Incumbents add sovereign options | Medium |
| Distribution / install base | Low (new entrant) | Microsoft / CrowdStrike dominance | Low |
Durability ratings are analyst judgments; the distribution row is Ent's weakest moat given incumbent bundling and install base.
[CP021, CP022, CP018, CP026, CP032]Key competitive-readiness indicators for Ent at launch.
[CP026, CP022, CP036]3.4 Exhibits
04Financials
4.1 Revenue model, pricing and go-to-market
Ent runs a SaaS subscription business, most likely priced per endpoint or per seat, though it has disclosed no pricing or list rates at launch. Its revenue mix is presently concentrated in early Global 2000 deployments across financial services, hospitality and defense, with an AI-governance module and professional-services onboarding as emerging and prospective streams. Because the platform is hosted in each customer's own cloud, enterprise onboarding is a real services component rather than a pure self-serve motion. The go-to-market is a direct enterprise motion selling into CISO security organizations. That motion carries the sales-efficiency drag typical of enterprise security, where cycles commonly run six to twelve months or longer. At seed stage these efficiency measures are unobservable externally, so only proxies from comparable cloud and security SaaS apply. Reference pricing from incumbents - roughly $100 or more per endpoint per year for CrowdStrike, near $80 for SentinelOne core tiers, and effectively bundled for Microsoft Defender within E5 - frames Ent's likely per-endpoint monetization, but Ent's own economics remain undisclosed and must be obtained directly in diligence. The practical implication is that, at this stage, revenue modeling for Ent is necessarily a scenario exercise anchored to comparable per-endpoint economics rather than to any figure the company itself has confirmed.[CI001, CI002, CI003, CI004, CI005, CI012]
| Stream | Model | Status | Basis of estimate | Confidence |
|---|---|---|---|---|
| Core platform subscription | SaaS per endpoint/seat | Live (undisclosed terms) | Company model + analyst norms | medium |
| AI governance module | Subscription add-on | Roadmap / emerging | Press release roadmap | low |
| Professional services / onboarding | Services | Likely at enterprise scale | Customer-cloud deployment need | low |
| Expansion (modules, seats) | Land-and-expand | Prospective | Comparable SaaS pattern | low |
All streams are inferred from the company's stated model and comparable security SaaS; Ent has not published revenue by stream.
[CI001, CI003, CI012, CI027]| Vendor / model | Unit | Indicative rate | Disclosure |
|---|---|---|---|
| Ent (likely) | Per endpoint or seat | Not disclosed | None at launch |
| CrowdStrike (reference) | Per endpoint/yr | ~$100+ | Public list references |
| SentinelOne (reference) | Per endpoint/yr | ~$80 | Public list references |
| Microsoft Defender (reference) | Bundled | Included in E5 | Public |
Ent's pricing is undisclosed; competitor rates are indicative public references used only to frame Ent's likely monetization.
[CI002, CI027, CI020]Qualitative bridge from Ent's deployed agents through subscription and expansion to recurring revenue.
[CI001, CI020, CI027, CI028]4.2 Cost structure, unit economics and public traction
On cost structure, an on-device SaaS agent can achieve high software gross margins once delivery scales - comparable security SaaS companies report margins commonly in the 70-80%-plus range. Ent's customer-cloud hosting shifts some infrastructure cost to the customer, which can help hosting gross margin, but it adds non-trivial onboarding and support cost for each enterprise deployment. The most capital-intensive element is building proprietary intent-inference AI models, which is talent- and research-intensive and front-loads cost ahead of revenue. On public traction, Ent has disclosed roughly 100 employees and general availability across Windows, macOS, Linux and browser extensions, but no revenue, ARR, burn or margin figures - all of which are private at seed stage. Third-party trackers list it as an early-stage, recently funded company without financial detail. Comparable benchmarks are demanding: category-defining security startups such as Wiz reached $100 million ARR in roughly eighteen months, and CrowdStrike and SentinelOne show subscription endpoint security scaling to billions in high-margin recurring revenue. Ent's potential is real, but its actual unit economics are presently unmeasurable from public evidence, so any contribution-margin or payback estimate carried here should be treated strictly as a comparable-derived placeholder pending management data.[CI006, CI007, CI008, CI009, CI016, CI017]
| Metric | Estimate / proxy | Basis | Confidence | Diligence ask |
|---|---|---|---|---|
| Gross margin | 70-80%+ at scale | Comparable security SaaS | medium | Confirm hosting cost split |
| Sales cycle | ~6-12+ months | Enterprise security norm | medium | Confirm pipeline velocity |
| CAC payback | Not estimable | No disclosed CAC/ARR | low | Request CAC and payback |
| Net revenue retention | Not disclosed | Seed stage | low | Request NRR once live |
| Burn rate | High (est.) | ~100 staff + AI R&D | low | Request monthly burn |
Unit economics are proxies from comparable SaaS, not Ent disclosures; every row carries an explicit diligence ask.
[CI005, CI006, CI016, CI017, CI032]Bridge from list price through delivery and support costs to gross and contribution margin for an on-device SaaS agent.
[CI006, CI007, CI016, CI031]Estimated ranges for capital, runway and margin, all flagged low-confidence given undisclosed actuals.
[CI010, CI011, CI016, CI005]4.3 Capital adequacy, runway and financial verdict
Ent has raised $100 million in seed financing - its only disclosed round - led by Decibel with a tier-1 syndicate. At a typical burn for a roughly 100-person security startup investing heavily in AI R&D, that capital implies an estimated eighteen-to-twenty-four-month runway, sensitive to hiring pace, with proceeds most likely directed to engineering, model development, go-to-market and enterprise support. No debt or project-finance obligations have been disclosed. The next financing round will most plausibly be triggered by demonstrated Global 2000 traction and ARR milestones, and the robust cybersecurity funding climate supports Ent's ability to raise follow-on capital. The financial verdict is that Ent is well-capitalized but evidence-thin. Revenue quality is unproven, resting on early deployments rather than disclosed recurring revenue, and a $100 million seed sets a high performance bar with elevated burn expectations - skeptical coverage warns the round compresses the margin for execution error. The principal diligence blockers are undisclosed pricing, revenue, ARR, burn rate, runway and valuation. The financing dependency is therefore high until Ent demonstrates recurring revenue, making ARR milestones the decisive metric for the next round. Taken together, the chapter's financial read is that capital adequacy is a present strength while revenue quality and burn discipline remain unverified, and both must be confirmed before any valuation or return conclusion can be defended.[CI010, CI011, CI013, CI014, CI015, CI018]
| Item | Value / estimate | Basis | Note |
|---|---|---|---|
| Total raised | $100M (seed) | Press release | Only disclosed round |
| Lead investor | Decibel | Press release | Tier-1 syndicate |
| Estimated runway | ~18-24 months | Burn proxy | Sensitive to hiring pace |
| Use of funds | Eng, AI, GTM, support | Inferred | Not itemized publicly |
| Debt / project finance | None disclosed | Disclosure absence | Confirm in diligence |
Runway and use of funds are estimates; only the $100M raise and lead investor are firmly disclosed.
[CI010, CI011, CI012, CI014, CI029]| Missing metric | Why it matters | Diligence path | Severity |
|---|---|---|---|
| Revenue / ARR | Core to valuation and traction | Request audited or management ARR | material |
| Pricing / list rates | Drives revenue model and SOM | Request price book | material |
| Burn rate / runway | Determines financing urgency | Request monthly burn and cash | material |
| Post-money valuation | Sets dilution and return math | Request cap table / 409A | material |
| Gross margin actuals | Validates SaaS economics | Request COGS breakdown | moderate |
This table enumerates the principal undisclosed financial facts; each is private-evidence-only at seed stage.
[CI009, CI018, CI025, CI030, CI036]Key capital and cash indicators for Ent at seed stage.
[CI017, CI030, CI035, CI036]4.4 Exhibits
05Product & Technology
5.1 Product definition, modules and use cases
In customer-workflow terms, Ent is a lightweight on-device AI agent that watches how people and AI agents act in the workspace and steps in just in time to prevent a security incident before it completes. It observes signals across the browser, applications, workflows and data movement, then evaluates intent rather than waiting for a known-bad signature. Its core modules are a workspace observer, an intent-inference engine built on specialized small AI models, a policy-enforcement layer, an intervention layer and a forensic record that supports later investigation. The platform targets five primary use cases: insider-risk detection, AI governance, data loss prevention, last-mile threat prevention and incident investigation. In each, the agent observes an action - a user exfiltrating data, an AI agent taking a risky step, sensitive data moving, a compromised session acting - infers whether intent is malicious, and intervenes by blocking, warning or permitting, while writing a forensic timeline. Governing the intent of AI agents specifically is a distinguishing capability, aligning with emerging guidance from OWASP's LLM and agent risk work and the Cloud Security Alliance, as autonomous agents introduce new attack surfaces that motivate runtime governance. Read end to end, the product is best understood not as another detector but as a real-time decision layer that sits between a workspace action and its consequence, which is what makes the intent framing more than a marketing label.[CE001, CE002, CE003, CE004, CE011, CE012]
| Module | Function | Signals / inputs | Maturity |
|---|---|---|---|
| Workspace observer | Monitor activity | Browser, apps, workflows, data movement | GA |
| Intent-inference engine | Evaluate intent | Behavioral signals, small AI models | GA |
| Policy enforcement | Apply controls | Org policy, risk context | GA |
| Intervention layer | Just-in-time action | Real-time intent verdict | GA |
| Forensic record | Investigation | Captured activity timeline | GA |
Module list and inputs are company-stated; maturity is inferred from the general-availability announcement.
[CE002, CE003, CE004, CE011, CE012]| Use case | Customer workflow | Ent action | Outcome |
|---|---|---|---|
| Insider-risk detection | User exfiltrates data | Infer malicious intent, intervene | Prevent exfiltration |
| AI governance | AI agent takes risky action | Evaluate agent intent, gate action | Governed agent behavior |
| Data loss prevention | Sensitive data moves | Detect at point of action | Block / warn |
| Last-mile threat prevention | Compromised session acts | Just-in-time intervention | Stop incident early |
| Incident investigation | Analyst reviews event | Provide forensic record | Faster investigation |
Use cases and actions are drawn from Ent's own descriptions; outcomes are the company's stated objectives, not benchmarked results.
[CE013, CE011, CE021, CE023, CE024]How a risky workspace action flows through observation, intent scoring and just-in-time intervention to a forensic record.
[CE011, CE013, CE023, CE032]5.2 Architecture, deployment, dependencies and roadmap
Architecturally, Ent is a hybrid edge-plus-cloud design: AI inference models run on the device for low-latency, real-time intent scoring, while the control plane, storage and forensic record live in the customer's own cloud to preserve data sovereignty. The agent is generally available across Windows, macOS, Linux and browser extensions, and deploys as a lightweight component that integrates into existing enterprise endpoints and security workflows. Its critical dependencies are the endpoint operating systems, browser-extension APIs, local device compute and the customer's cloud environment, and like any EDR-class agent it must balance observability against device resource use. The roadmap, as described at launch, spans AI governance, threat prevention, security integrations - connecting to SIEM, SOAR and identity systems - and multimodal endpoint intelligence that would extend observation to richer signals. Shipping across four endpoint surfaces at general availability indicates meaningful engineering maturity, and the on-device approach reduces cloud round-trips, supporting the company's sub-second intervention claims. Still, the planned integration and multimodal items are directional rather than shipped, so the maturity assessment separates what is generally available today from what remains prospective on the roadmap. Hiring activity across security research, AI engineering and platform roles is a further developer-side signal that build velocity is being sustained after launch rather than tapering.[CE005, CE006, CE007, CE008, CE024, CE025]
| Layer | Where it runs | Role | Dependency |
|---|---|---|---|
| On-device agent | Endpoint | Observe + infer intent | OS / browser APIs |
| AI inference models | On-device | Real-time intent scoring | Local compute |
| Control / management plane | Customer's cloud | Policy, storage, admin | Customer cloud env |
| Forensic store | Customer's cloud | Activity timeline | Customer storage |
| Integrations (roadmap) | Customer's cloud | SIEM/SOAR/identity links | Third-party APIs |
Architecture is a hybrid edge-plus-cloud design inferred from company material; integration layer is roadmap rather than fully shipped.
[CE005, CE024, CE025, CE030, CE031]| Roadmap item | Stage | Description | Signal |
|---|---|---|---|
| Core platform (4 surfaces) | GA | Windows, macOS, Linux, browser | Launch announcement |
| AI governance | Active | Govern human + AI-agent intent | Press release |
| Threat prevention | Active | Last-mile prevention | Press release |
| Security integrations | Planned | SIEM/SOAR/identity links | Press release |
| Multimodal endpoint intelligence | Planned | Richer signal observation | Press release |
Roadmap stages are inferred from the launch announcement; planned items are directional and not yet shipped.
[CE008, CE026, CE029, CE030]Hybrid architecture: an on-device agent observes and infers intent locally, while policy, storage and forensics run in the customer's own cloud.
[CE002, CE004, CE005, CE024]Ent's runtime depends on endpoint OSes, browser APIs, local compute and the customer's cloud environment.
[CE005, CE025, CE034]5.3 Differentiation, trust, privacy and compliance
Ent's technical differentiation is inferring intent in real time across both human users and AI agents, rather than matching known-bad signatures after the fact, and it positions this as a complement that can sit alongside existing EDR. The proprietary asset underpinning the approach is its workspace-behavior training data, and intent-based controls map conceptually to behavior-analytics techniques catalogued in MITRE ATT&CK. The clearest risk is efficacy: real-time intent inference can produce false positives that disrupt legitimate activity, and no independent third-party benchmark of Ent's accuracy has been published, leaving real-world efficacy externally unvalidated. On trust and compliance, customer-cloud hosting keeps sensitive telemetry inside the customer's environment, supporting data-residency requirements, while privacy and data-minimization controls are essential for lawful employee monitoring. Recognized control catalogs such as NIST SP 800-53 define the access, audit and monitoring expectations enterprise buyers bring, and aligning to OWASP, CSA AI guidance and MITRE ATT&CK is how Ent can make a novel approach auditable. The net read is a credible, well-architected platform with a genuine wedge whose differentiation is strong but whose efficacy and privacy posture still require independent verification.[CE009, CE010, CE014, CE015, CE016, CE019]
| Control area | Approach | Framework reference | Status / gap |
|---|---|---|---|
| Data sovereignty | Customer-cloud hosting | NIST SP 800-53 controls | Company-stated |
| Employee privacy | Data minimization (claimed) | Privacy-by-design norms | Needs verification |
| AI-agent governance | Runtime intent evaluation | OWASP LLM / CSA AI guidance | Emerging |
| Detection efficacy | Intent models | MITRE ATT&CK mapping | No independent benchmark |
| Audit / forensics | Forensic record | Audit-control expectations | Company-stated |
Compliance posture maps Ent's claims to recognized frameworks; the efficacy and privacy rows carry explicit verification gaps.
[CE014, CE016, CE017, CE020, CE022]Maturity and differentiation of Ent's key capabilities at general availability.
[CE009, CE020, CE026, CE036]5.4 Exhibits
06Customers
6.1 Customer base segmentation and vertical evidence
Ent disclosed on stealth exit in June 2026 that its platform is deployed across Global 2000 enterprises in three verticals: hospitality, financial services, and defense. These three segments represent Ent's stated early adopter base and define the credible customer scope for diligence. The economic buyer in all three is the enterprise CISO, with security operations and compliance functions as co-stakeholders. The payer sits primarily within the CISO's security budget, with partial overlap into IT and compliance program funds depending on the use case. Financial services is the strongest signal vertical: a public institution's insider-threat lead provided the only named testimonial in public evidence, citing low time-to-value. Financial institutions are also the most active buyers of insider-threat tooling across the industry, driven by regulatory pressure, fraud risk, and the high cost of insider-driven breaches. Hospitality maps to Ent's last-mile threat-prevention use case, where distributed workforces and high data-access density create acute endpoint risk. Defense is the most strategically distinctive vertical: In-Q-Tel's participation in the seed round provides an implicit validator for the national-security applicability of the platform, and CISA guidance confirms that federal agencies actively build insider-threat detection programs across the lifecycle. The global enterprise security market context confirms structural demand across all three verticals. IBM's data breach research shows that organizations using AI-driven security tools achieve substantially lower breach costs and faster containment, while Verizon's DBIR confirms that a meaningful share of breaches involve internal actors through error, misuse, or compromised credentials. These independent data points validate Ent's buyer problem thesis even if they do not directly corroborate Ent's specific deployments. Beyond the three disclosed verticals, technology and SaaS enterprises are a logical next segment given the AI-agent governance use case, but no customer evidence for that vertical exists publicly as of June 2026.[CU001, CU005, CU006, CU007, CU009, CU010]
| Segment | Buyer / payer | User | Use case | Scale | Evidence quality |
|---|---|---|---|---|---|
| Financial services | CISO / security budget | Insider-risk analyst / SOC | Insider risk detection, DLP | Global 2000 | Customer quote (anonymous) |
| Hospitality | CISO / IT budget | IT security analyst | Last-mile threat prevention | Global 2000 | Company assertion only |
| Defense / government | CISO / program budget | Threat hunter / compliance | AI governance, investigation | Global 2000 / national-security | Inferred from IQT investor |
| Technology / SaaS (inferred) | CISO / security budget | Security engineer | AI agent governance | Global 2000 (inferred) | No direct customer evidence |
| Regulated enterprise (broad) | CISO + compliance | Compliance analyst | DLP + audit trail | Enterprise | Market-level context only |
Segments are drawn from Ent's public stealth-exit disclosure plus market-level inference; only hospitality, financial services and defense are company-asserted. Technology/SaaS and broad regulated enterprise are analyst-inferred.
[CU001, CU005, CU006, CU009, CU021, CU032]Illustrative journey from CISO awareness through pilot, production deployment, and expansion to AI agent governance coverage.
Journey stages are inferred from Ent's disclosed deployments and enterprise security market norms; timing is not publicly documented.
[CU022, CU031, CU035, CU038]6.2 Adoption trajectory and named customer proof
Ent's public adoption evidence is narrow but strategically credible. The company asserted on stealth exit that its platform is in production across Global 2000 enterprises, which implies real deployments existed before the June 2026 announcement. However, no specific customer count, ARR figure, or deployment breadth metric has been disclosed. The stealth period itself signals that Ent had paying customers before public launch — a positive signal versus a pre-revenue launch, but one that cannot be assessed for scale or durability without private data. The named customer proof set is limited to a single anonymous testimonial: an insider-threat lead at a public financial institution who described Ent as the first tool where they felt like an expert on day one. This quote indicates low time-to-value and ease of use, two critical buying criteria in enterprise security, but it is a single data point from an unidentifiable source. No case studies, deployment scale figures, outcome metrics, or reference accounts are publicly available. The three disclosed verticals — hospitality, financial services, and defense — are named in Ent's press release and picked up by multiple independent outlets including TechCrunch, VentureBurn, SiliconANGLE, and CityBiz, confirming the disclosure was intentional and widely covered. However, the verticals are stated as categorical rather than enumerated accounts, leaving the depth of each deployment unknown. TechCrunch characterized Ent as having deployed the platform across Global 2000 enterprises before going public, and VentureBurn noted early enterprise customers in regulated industries. SiliconANGLE similarly reported a base of Global 2000 customers before stealth exit. This convergence across independent outlets on the same company-provided framing increases confidence in the claim's existence, though it does not independently validate its depth or the distinction between production deployments and active evaluations. The evidence freshness is high — all proof dates from the June 2026 launch window — but the volume is thin. Diligence must treat the current proof set as a starting point, not a validation baseline.[CU001, CU002, CU003, CU004, CU015, CU016]
| Metric | Value / status | Date | Source | Confidence | Implication |
|---|---|---|---|---|---|
| Named vertical segments | 3 (hospitality, financial services, defense) | Jun 2026 | Ent press release | high | Multi-vertical early traction confirmed |
| Customer count (disclosed) | Not disclosed | Jun 2026 | Ent press release | high | No public count; gap for diligence |
| Deployment scope | Global 2000 enterprises | Jun 2026 | Ent press release | medium | Large-enterprise targeting confirmed |
| Customer testimonials (public) | 1 anonymous (financial institution) | Jun 2026 | BankInfoSecurity article | high | Thin proof set; expansion expected |
| Stage at stealth exit | Paying customers in production (implied) | Jun 2026 | Multiple independent outlets | medium | Pre-announcement deployments implied |
| Contract or ARR data | None disclosed | Jun 2026 | No public source | high | Financial depth unknown |
Adoption metrics reflect only public stealth-exit evidence as of June 2026; customer count, ARR, and NRR are undisclosed.
[CU001, CU002, CU015, CU030, CU037, CU039]| Customer | Segment | Deployment / use case | Status | Outcome / quote | Limitation |
|---|---|---|---|---|---|
| Public financial institution (anonymous) | Financial services | Insider risk detection | Production (implied) | First tool where I felt like an expert on day one | Name undisclosed; depth unknown |
| Global 2000 hospitality enterprise (anonymous) | Hospitality | Last-mile threat prevention | Production (claimed) | No public outcome statement | Name and scale undisclosed |
| Global 2000 defense enterprise (anonymous) | Defense / government | AI governance + investigation | Production (claimed) | No public outcome statement | Name and classification level undisclosed |
All named customers are anonymous as of June 2026. Outcomes are limited to one anonymous quote; no case studies, ROI figures, or retention data are public.
[CU001, CU003, CU015, CU016, CU033, CU034]Discovery-to-expansion funnel for Ent enterprise accounts, from CISO awareness through full workspace deployment.
Funnel volumes are illustrative only; Ent has not disclosed customer counts. Numbers represent a plausible scale for a seed-stage Global 2000 vendor, not confirmed figures.
[CU001, CU002, CU022, CU029, CU037]6.3 Retention, durability, satisfaction, and concentration risk
Retention and durability evidence for Ent is entirely absent from the public record. No NRR, GRR, cohort data, or contract-length information has been disclosed. The single positive customer testimonial is insufficient to infer retention — it speaks to ease of initial use, not sustained engagement or renewal behavior. No G2, Capterra, or Gartner Peer Insights review entry exists for Ent as a specific product, which is expected given its June 2026 emergence from stealth and the typical lag before enterprise review platforms accumulate ratings for new products. Buyer satisfaction at the market level is directionally positive for Ent's positioning: CSO Online reports that security buyers favor consolidated insider-risk, DLP, and AI-governance platforms; Help Net Security notes demand for measurable time-to-investigate reductions; and the Gartner Peer Insights EDR review corpus emphasizes efficacy, deployment ease, and false-positive rates as the top buyer criteria. Ent's anonymous customer quote directly addresses deployment ease, suggesting alignment with market-level buyer expectations. However, The Next Web and DLP Test both raised the absence of independent benchmarks for intent-inference accuracy as a credibility concern, and buyer caution around unproven prevention tools is a documented adoption risk in the DLP market. Expansion potential is real but undocumented at the account level. Enterprise DLP consolidation trends in 2026 favor Ent's integrated-platform approach, and the proliferation of AI agents within enterprise workspaces creates a structural upsell opportunity for the AI governance module. Ent's on-device, customer-cloud deployment model reduces data-sovereignty friction for regulated buyers, which is a genuine procurement advantage. However, concentration risk and channel dependence are structurally opaque. With three disclosed verticals and no customer count, it is impossible to assess whether Ent's revenue is evenly distributed or concentrated in one anchor segment. The absence of a disclosed channel or reseller program implies a direct enterprise sales motion, adding sales-cycle risk as the company scales. Procurement friction in regulated industries — including data residency audits, security reviews, and multi-stakeholder approvals — can extend enterprise sales cycles significantly and must be factored into CAC and payback modeling.[CU015, CU017, CU018, CU023, CU024, CU025]
| Metric | Value / null | Segment | Confidence | Diligence ask |
|---|---|---|---|---|
| Net revenue retention (NRR) | Not disclosed | All | high | Request NRR from Ent under NDA; industry benchmark is 120%+ |
| Gross retention rate (GRR) | Not disclosed | All | high | Request GRR; minimum for healthy SaaS is >90% |
| Customer satisfaction (CSAT) | Positive anecdote (1 quote) | Financial services | low | Seek additional testimonials and G2 / Gartner Peer Insights reviews |
| Contract length | Not disclosed | All | high | Confirm 1- vs 3-year terms; longer = lower churn risk |
| Known churn or non-renewal | None publicly reported | All | medium | Absence of public churn is not confirmation of retention |
Not-disclosed values indicate metrics withheld or never released as of June 2026. Confidence column reflects evidence quality, not performance expectation. A single positive anecdote does not confirm aggregate satisfaction.
[CU015, CU023, CU027, CU033, CU034]| Factor | Risk / driver | Impact | Evidence basis | Diligence path |
|---|---|---|---|---|
| Vertical concentration | 3 verticals; possible over-reliance on financial services | High | Company-disclosed segment list | Map revenue split across verticals under NDA |
| Customer count concentration | Unknown; if 1–3 anchor accounts, churn is material | High | No count disclosed | Request ARR by customer cohort |
| Land-and-expand potential | Agent proliferation creates AI-governance upsell | Positive | Ent product roadmap and positioning | Confirm expansion unit pricing |
| Partner / channel dependence | No public reseller or channel program disclosed | Medium | No press or partner announcements | Confirm direct-sales vs channel split |
| Procurement friction | Regulated buyers require data residency audits and security reviews | Medium | CIO Dive and CISA guidance | Document typical sales cycle length and blockers |
Concentration risks are inferred from the narrow set of disclosed customer evidence; no financial data underpins the impact ratings.
[CU028, CU029, CU036, CU038, CU040]Evidence quality, deployment status, outcome specificity, and retention visibility for each disclosed customer segment.
[CU003, CU016, CU033, CU025, CU023]Illustrative retention benchmarks for enterprise security SaaS; Ent-specific retention data is entirely absent from public evidence and must be requested under NDA.
All three rows are illustrative benchmarks derived from publicly available security SaaS retention data; no Ent-specific retention figures exist in public evidence.
[CU015, CU027, CU034]6.4 Exhibits
07Risks
7.1 Regulatory and legal risk
Ent's single largest structural exposure is regulatory. Because the platform monitors how employees and AI agents act on the endpoint, it triggers significant privacy and data-protection obligations across multiple regimes simultaneously. In the EU, GDPR constrains workplace monitoring through purpose-limitation, proportionality and lawful-basis requirements, and the European Data Protection Board has issued guidance restricting intrusive employee monitoring. The EU AI Act adds a second layer: intent-inference systems could be classified as higher-risk, raising documentation and conformity costs. NIST's AI Risk Management Framework signals the governance expectations regulators will increasingly apply. In the United States, state privacy laws such as the CCPA grant data rights over monitoring data, and the FTC has a track record of enforcement against unfair or deceptive data practices. Civil-liberties groups warn that pervasive workplace surveillance carries legal and reputational risk. This regulatory complexity is genuinely global and concurrent, spanning EU GDPR and the AI Act alongside US state and federal regimes, and AI-agent governance is an emerging frontier where rules are still forming, creating compliance uncertainty. Insider-threat programs also face heightened government scrutiny, which is simultaneously a demand driver and a compliance obligation. A documented privacy and AI-governance posture is therefore essential, yet Ent has disclosed none publicly.[CR002, CR003, CR004, CR005, CR006, CR007]
| Regime / area | Risk | Likelihood | Impact | Mitigation |
|---|---|---|---|---|
| EU GDPR | Unlawful employee monitoring | Medium | High | DPIA, lawful basis, minimization |
| EU AI Act | Intent models deemed higher-risk | Medium | High | AI governance, documentation |
| US CCPA / state laws | Data-rights non-compliance | Medium | Medium | Data-subject controls |
| FTC enforcement | Unfair/deceptive data practice | Low | High | Transparency, accuracy |
| Employee-monitoring law | Surveillance overreach claims | Medium | Medium | Consent, governance |
Register enumerates the principal disclosed regulatory exposures for endpoint monitoring; coverage is partial as specific jurisdictional exposure depends on customer geography.
[CR002, CR003, CR005, CR006, CR007, CR008]Ent's external dependencies on customer cloud, endpoint platforms, capital providers and the regulatory environment.
[CR013, CR028, CR032, CR035]7.2 Operational, dependency and competition risk
Operationally, the dominant risk is efficacy. Real-time intent inference can produce false positives that block legitimate work and erode trust, and Ent's sub-second inference and accuracy claims have not been independently benchmarked - the reason the efficacy risk is rated high-likelihood and high-impact. A fleet-wide on-device agent also carries reliability and performance risk if it degrades devices or fails, and the threat environment of costly breaches and shrinking dwell time validates demand while raising the stakes of getting prevention wrong. Verizon breach data shows human-driven and credential-based incidents remain dominant, and IBM data shows multimillion-dollar average breach costs, both reinforcing the value but also the consequence of failure. On dependencies and competition, Ent relies on each customer's cloud to host its control plane and forensic store, and on endpoint operating-system and browser APIs that could change. The most acute dependency is competitive: Microsoft and CrowdStrike pose concentrated risk through distribution and bundling, and competition risk compounds execution risk because incumbents can out-distribute Ent while it must still prove efficacy. Data-sovereignty obligations in defense and finance could further constrain deployments. Risks also transmit across domains - a privacy enforcement action or efficacy failure could stall sales, raise burn and force a financing event - so these exposures cannot be assessed in isolation.[CR010, CR011, CR012, CR013, CR014, CR022]
| Risk | Description | Likelihood | Impact |
|---|---|---|---|
| False positives | Intent model blocks legitimate work | Medium | High |
| Unproven efficacy | No independent benchmarks | High | High |
| Agent reliability | Fleet-wide performance/failure | Medium | Medium |
| Data security | Sensitive telemetry exposure | Low | High |
| Latency claims | Sub-second inference unverified | Medium | Medium |
Operational risks center on model efficacy and agent reliability; the efficacy row is rated high-likelihood because no external benchmark exists.
[CR010, CR011, CR012, CR023]| Dependency | Risk | Exposure | Mitigation |
|---|---|---|---|
| Customer cloud | Control plane hosted in customer env | Medium | Standardized deployment |
| Endpoint OS / browser APIs | Platform API changes break agent | Medium | Multi-OS engineering |
| Incumbent competition | Microsoft/CrowdStrike bundling | High | Differentiation, time-to-value |
| Capital providers | Follow-on financing needed | Medium | Tier-1 investor syndicate |
Dependency risks span infrastructure, platform APIs, competitive distribution and capital; the incumbent row is the most acute.
[CR013, CR014, CR028, CR035]Likelihood-by-impact placement of Ent's principal risks, surfacing efficacy, regulatory and competition as the highest-priority cells.
[CR001, CR011, CR014, CR015]How a shock in one domain propagates: a privacy action or efficacy failure cascades into stalled sales, higher burn and financing stress.
[CR022, CR029, CR037, CR042]7.3 People, financial risk and mitigations
On people and execution, key-person dependence on co-founders Elias Manousos and Brandon Dixon is acute for a roughly 100-person company, and a $100 million seed sets a high performance bar with elevated burn that is itself an execution risk if traction lags. Expanding beyond three verticals strains a small team, and the single anonymous customer reference leaves execution evidence thin. Financially, model risk is high because revenue, pricing and unit economics are undisclosed, and burn-and-runway risk is material against an estimated eighteen-to-twenty-four-month runway. Reputational risk is elevated by skeptical coverage questioning whether the prevention claims are truly differentiated. These risks have real offsets and mitigations. The founders' Microsoft and RiskIQ pedigree partially mitigates execution and credibility risk, a tier-1 investor syndicate eases financing risk while raising valuation expectations, and customer-cloud hosting plus an advisory board including a former NSA director and former CISOs help navigate regulation and sovereignty. But mitigation ultimately depends on demonstrable efficacy evidence Ent has not yet published. Investors should monitor false-positive rates, deployment renewals, regulatory filings and competitor releases, and treat sustained false-positive complaints, a privacy enforcement action, incumbent feature parity or a failed marquee deployment as explicit thesis-break triggers. Overall, the profile is high-variance: a credible team and capital set against unproven efficacy, heavy regulation and dominant incumbents.[CR015, CR016, CR017, CR018, CR019, CR020]
| Risk | Description | Likelihood | Impact |
|---|---|---|---|
| Key-person dependence | Two founders central | Medium | High |
| High execution bar | $100M seed expectations | Medium | High |
| Vertical expansion | Scaling beyond 3 verticals | Medium | Medium |
| Thin proof | Single anonymous reference | Medium | Medium |
Execution risk is amplified by the outsized seed and thin public proof; founder pedigree is a partial offset.
[CR015, CR016, CR030, CR039]| Risk area | Mitigation | Monitoring indicator | Thesis-break trigger |
|---|---|---|---|
| Efficacy | Publish benchmarks | False-positive rate | Sustained FP complaints |
| Regulatory | DPIA + AI governance | Regulatory filings | Enforcement action |
| Competition | Differentiation + speed | Competitor releases | Incumbent feature parity |
| Execution | Hire + expand verticals | Deployment renewals | Failed marquee deployment |
| Capital | Stage financing to milestones | Burn vs ARR | Down round / stalled raise |
Each mitigation is paired with a concrete monitoring indicator and an explicit thesis-break trigger for ongoing diligence.
[CR019, CR020, CR021, CR033, CR038]7.4 Exhibits
08Valuation
8.1 Investment thesis, anti-thesis and recommendation
The investment thesis for Ent is that intent-aware workspace security could become a default enterprise layer, sold by an elite RiskIQ and Microsoft founding team whose prior RiskIQ exit to Microsoft for $500 million-plus demonstrates value-creation, and validated by a tier-1 syndicate led by Decibel. The anti-thesis is equally clear: detection-first incumbents could embed intent-awareness and commoditize Ent before it scales, leaving its wedge to narrow and its single anonymous customer reference looking thin. These opposing cases are paired across product, team, market, customers and moat to make the central debate explicit. The recommendation is to track Ent rather than invest immediately - a compelling vision and pedigree with real early traction, but execution unproven at scale, undisclosed financials and a crowded, incumbent-anchored market. Confidence is moderate given thin disclosed financials and customer proof, and the high-variance risk profile justifies a track stance rather than immediate conviction. On balance, Ent is a high-quality, high-price, high-uncertainty seed best monitored toward its next round; if efficacy is independently validated and ARR scales, the call would move from track to invest, whereas incumbent feature parity would tip it toward the bear case.[CV001, CV002, CV003, CV004, CV026, CV030]
| Field | Assessment |
|---|---|
| Recommendation | Track (toward next round) |
| Confidence | Moderate |
| Risk rating | High / high-variance |
| Valuation stance | Positive but unconfirmed |
| Decisive milestone | Independent efficacy validation |
Summary reflects a track stance pending efficacy validation and disclosed financials; ratings are analyst judgments.
[CV003, CV004, CV026, CV028, CV041]| Dimension | Thesis (bull) | Anti-thesis (bear) |
|---|---|---|
| Product | Intent-awareness becomes default layer | Detectors add intent, wedge narrows |
| Team | Elite RiskIQ/Microsoft pedigree | Pedigree no guarantee at new scale |
| Market | $20B+ endpoint, fast-growing | Crowded, incumbent-anchored |
| Customers | Global 2000 production traction | Single anonymous reference |
| Moat | Human + AI-agent intent scope | Fast-followed by Microsoft/CrowdStrike |
Thesis and anti-thesis are paired across the diligence dimensions to make the central debate explicit.
[CV001, CV002, CV031, CV016]How evidence flows to a track recommendation: strong team and market, but unproven efficacy and high entry price gate conviction.
[CV001, CV003, CV026, CV041]8.2 Valuation context, comparables and scenarios
The $100 million seed from tier-1 investors implies a valuation widely characterized as in unicorn territory, but no official post-money figure has been disclosed, so the implied number is not directly supported by public evidence, and seed preference and dilution terms remain unknown. With no Ent revenue public, comparables anchor the envelope. CrowdStrike trades as a large-cap platform worth tens of billions, SentinelOne sits in the mid-teens-of-billions class, and Palo Alto Networks exceeds $100 billion as a consolidation comparable; high-growth security software commands elevated EV/revenue multiples. On the private side, Wiz's record ARR ramp before a landmark acquisition frames the path a category-definer must travel, and recent security M&A shows acquirers paying strategic premiums. These inputs produce a scenario envelope rather than a point value. The bull case is an IPO or acquisition at $5 billion-plus if intent-aware security becomes a default layer; the base case is a Series A/B at $500 million to $1 billion-plus if early Global 2000 traction holds; and the bear case is commoditization, a down round or acqui-hire. Valuation is highly sensitive to assumed forward ARR and the multiple applied, and an outsized seed reduces entry discipline while raising the bar for the next round. Probability weighting tilts toward the base case with meaningful bear-case weight given execution risk.[CV005, CV006, CV007, CV008, CV009, CV010]
| Scenario | Assumptions | Valuation range | Probability |
|---|---|---|---|
| Bull | Default layer; efficacy proven | IPO or M&A at $5B+ | Lower |
| Base | Traction holds; Series A/B | $500M-$1B+ | Higher |
| Bear | Commoditized; weak traction | Down round / acqui-hire | Meaningful |
Scenarios carry explicit assumptions and qualitative probabilities; ranges are estimates given undisclosed financials.
[CV008, CV009, CV010, CV027]| Comparable | Type | Valuation / scale | Multiple / note | Relevance |
|---|---|---|---|---|
| CrowdStrike | Public leader | Tens of $B market cap | Elevated EV/revenue | Scaled-success anchor |
| SentinelOne | Public peer | Mid-teens $B class | Growth multiple | On-device peer |
| Palo Alto Networks | Public platform | >$100B market cap | Platform multiple | Consolidation comp |
| Wiz | Private / M&A | Record ARR ramp; landmark deal | Premium private round | Category-definer path |
| Recent security M&A | M&A set | Premium multiples | Strategic premiums | Exit comp |
No named customer logos or Ent revenue exist, so comparables anchor the envelope; coverage is partial and indicative, not a direct multiple on Ent.
[CV011, CV012, CV013, CV014, CV015, CV042]Illustrative implied valuation under different forward-ARR and EV/revenue multiple assumptions (USD billions).
Illustrative scenarios applying public security-software multiples to hypothetical forward ARR; Ent's ARR is undisclosed.
[CV016, CV022, CV032]Scenario valuation ranges for Ent across bear, base and bull outcomes (USD billions).
Scenario ranges are estimates given undisclosed financials and a not-officially-disclosed entry valuation.
[CV008, CV009, CV010, CV017]8.3 Returns, exit readiness and final diligence
A seed investor's return depends on Ent reaching a multi-billion outcome given the large implied entry valuation, with exit paths most plausibly an acquisition by a platform incumbent or, less likely near-term, an IPO. The endpoint and XDR markets' size and growth support a large potential outcome if Ent executes, and a robust cybersecurity funding climate supports a strong next round. CrowdStrike and SentinelOne prove the public-market value of scaled endpoint security, anchoring the upside, while the comparable set spanning public leaders, a marquee private round and recent M&A gives a defensible valuation envelope. The investment KPIs to track are ARR growth, net revenue retention, the conversion of anonymous proof into named references, and the false-positive rate as an efficacy signal, all against a strong $100 million balance sheet. The final diligence asks - ARR and pricing, independent efficacy benchmarks, cap table and preferences, named customer references, and burn and runway - are the gating items required before moving from track to invest. The thesis-break triggers are concrete: incumbent feature parity, sustained false positives, a failed marquee deployment or stalled financing. The single most decisive milestone is published, independent efficacy validation at a named customer; clearing it, with scaling ARR, would flip the recommendation from track to invest.[CV017, CV018, CV019, CV020, CV023, CV024]
| Trigger | Signal | Implication |
|---|---|---|
| Incumbent feature parity | Microsoft/CrowdStrike ship intent | Moat erased |
| Sustained false positives | Customer complaints / churn | Efficacy thesis fails |
| Failed marquee deployment | Public reference collapse | Traction thesis fails |
| Stalled financing | Down round / no Series A | Capital thesis fails |
Each trigger maps a concrete observable signal to the part of the thesis it would break.
[CV020, CV021, CV035, CV040]| Ask | Why | Owner |
|---|---|---|
| ARR and pricing | Validate revenue quality | Company |
| Independent efficacy benchmarks | Validate core product claim | Third party |
| Cap table and preferences | Assess dilution/overhang | Company |
| Named customer references | Verify traction | Company |
| Burn and runway | Assess financing urgency | Company |
These are the gating items required before moving from track to invest.
[CV019, CV007, CV024, CV028, CV039]Key indicators to monitor Ent toward its next round.
[CV024, CV019, CV038, CV039]8.4 Exhibits
Disclaimer
This report is based on public information as of 2026-06-24 and highlights explicit evidence gaps where company-private metrics or independently verified benchmarks are unavailable.
Evidence index
| ID | Statement | Confidence | Sources |
|---|---|---|---|
| CO001 | Ent is an intent-aware workspace security company that emerged from stealth on June 16, 2026. | High | SO001, SO002 |
| CO002 | Ent raised $100 million in seed financing announced on June 16, 2026. | High | SO001, SO016 |
| CO003 | Ent's seed round was led by Decibel. | High | SO003, SO001 |
| CO004 | Sequoia, Craft Ventures, Crosspoint Capital Partners, Shield Capital, Felicis and In-Q-Tel participated in Ent's seed round. | Medium | SO003, SO011 |
| CO005 | Ent was co-founded by Elias Manousos and Brandon Dixon. | High | SO002, SO030 |
| CO006 | Elias Manousos co-founded and led RiskIQ for roughly 14 years before its acquisition by Microsoft. | High | SO002, SO025 |
| CO007 | Microsoft acquired RiskIQ in July 2021 in a deal reported at more than $500 million. | High | SO025, SO026 |
| CO008 | After RiskIQ, Elias Manousos served as a Microsoft corporate vice president for AI Copilot for Security and threat intelligence. | Medium | SO002, SO011 |
| CO009 | Brandon Dixon co-founded PassiveTotal, which was acquired by RiskIQ. | Medium | SO024, SO002 |
| CO010 | Brandon Dixon was a Security AI Strategist at Microsoft who spearheaded the launch of Microsoft Security Copilot. | Medium | SO011, SO024 |
| CO011 | Ent is headquartered in San Francisco, California. | Medium | SO005, SO027 |
| CO012 | The Wall Street Journal reports that Ent was launched in 2025 and has about 100 employees. | Medium | SO016 |
| CO013 | BankInfoSecurity reported that Ent was founded in May 2025 and operated in stealth before its 2026 launch. | Medium | SO005 |
| CO014 | Reported founding timing is mildly conflicting, with sources citing both a 2025 founding and a 2026 emergence from stealth. | Medium | SO005, SO016 |
| CO015 | Ent's platform is a lightweight on-device AI agent that runs across Windows, macOS, Linux and browser extensions. | High | SO014, SO017 |
| CO016 | Ent uses specialized AI models to evaluate the intent of human users and AI agents in real time and intervene before incidents occur. | Medium | SO009, SO017 |
| CO017 | Ent hosts its platform in the customer's own cloud to preserve data sovereignty. | Medium | SO015, SO017 |
| CO018 | Ent's platform is deployed across Global 2000 enterprises in hospitality, financial services and defense. | Medium | SO007, SO001 |
| CO019 | Ent's seed round is described as one of the largest in cybersecurity history. | Medium | SO002, SO011 |
| CO020 | Ent has not publicly disclosed a specific post-money valuation for its seed round. | Medium | SO016, SO001 |
| CO021 | Ent's total capital raised to date is $100 million from a single seed round. | High | SO001, SO003 |
| CO022 | Decibel founding partner Jon Sakoda led the investment in Ent. | Medium | SO003, SO018 |
| CO023 | Ent's advisory bench includes former CISOs of Google, Aetna and MassMutual, a former NSA director, and a former Microsoft CVP for Azure cloud security. | Medium | SO001, SO007 |
| CO024 | Ent's platform reached general availability across Windows, macOS, Linux and browser extensions at its June 2026 launch. | Medium | SO001, SO014 |
| CO025 | Ent positions itself as bringing prevention back to cybersecurity rather than relying on detection after the fact. | High | SO001, SO017 |
| CO026 | The Next Web characterized Ent's prevention messaging as no longer contrarian and flagged the absence of published independent benchmarks. | Medium | SO006 |
| CO027 | DLP Test cautioned that Ent's low-false-positive intent-detection claims remain unproven without independent benchmarks. | Medium | SO012 |
| CO028 | Ent's use cases span insider risk detection, AI governance, data loss prevention, last-mile threat prevention and incident investigation. | Medium | SO017, SO013 |
| CO029 | In-Q-Tel's participation links Ent to U.S. national-security-oriented strategic capital. | Medium | SO022, SO011 |
| CO030 | Crosspoint Capital Partners is a private equity firm focused on cybersecurity, privacy and infrastructure software. | Medium | SO021 |
| CO031 | Ent's two co-founders previously built and sold RiskIQ together, creating concentrated founder-driven execution dependence. | Medium | SO002, SO025 |
| CO032 | Ent's headcount of roughly 100 is small relative to incumbent endpoint-security vendors, increasing key-person and execution risk. | Medium | SO016 |
| CO033 | Ent has not publicly disclosed revenue, ARR or customer count as of its June 2026 launch. | Medium | SO001, SO016 |
| CO034 | An insider-threat lead at a public financial institution described Ent as the first tool where they felt like an expert on day one. | Medium | SO005 |
| CO035 | Ent's emergence from stealth was syndicated widely through a Business Wire press release on June 16, 2026. | High | SO001, SO007 |
| CO036 | Sequoia partner Konstantin Buhler is associated with Sequoia's participation in Ent. | Low | SO003, SO029 |
| CO037 | Ent is a seed-stage, privately held cybersecurity company with an opaque disclosure profile typical of a recently de-stealthed startup. | Medium | SO016, SO001 |
| CO038 | Ent plans market visibility through a Black Hat USA 2026 presence in Las Vegas in August 2026. | Low | SO017, SO031 |
| CO039 | Ent's legal operating entity has been associated in filings discussion with the name Athena Formation Inc., though this is not firmly confirmed in primary disclosures. | Low | |
| CO040 | Ent's funding stage as of 2026 is seed, with capital concentrated in a single oversized round. | High | SO001, SO011 |
| CO041 | Ent's lightweight agent and customer-cloud hosting differentiate it from cloud-first detection platforms. | Medium | SO017, SO002 |
| CO042 | LinkedIn lists Ent as an intent-aware workspace security company based in San Francisco. | Low | SO028 |
| CM001 | Ent's addressable market spans endpoint security, data loss prevention, insider risk and AI governance. | Medium | SM018, SM019 |
| CM002 | The global endpoint security market was about $18.58 billion in 2025 and roughly $20.79 billion in 2026. | Medium | SM012, SM017 |
| CM003 | The endpoint security market is projected to grow at roughly an 11.9% CAGR toward about $32.52 billion by 2030. | Medium | SM012 |
| CM004 | The endpoint detection and response market is estimated near $6.33 billion in 2026. | Medium | SM013 |
| CM005 | The EDR market is projected to reach about $18.68 billion by 2031 at a 24.16% CAGR. | Medium | SM013 |
| CM006 | The data loss prevention market was about $3.68 billion in 2025 and roughly $4.67 billion in 2026. | Medium | SM014, SM015 |
| CM007 | The DLP market is projected to grow at about a 26.9% CAGR toward $12.53 billion by 2030. | Medium | SM014 |
| CM008 | The XDR and AI-SOC market is projected to grow from about $33.4 billion in 2025 to $89 billion by 2031 at a 22.6% CAGR. | Low | SM016 |
| CM009 | A defensible 2026 SAM for Ent's combined endpoint, DLP and AI-governance workspace category is roughly $25-30 billion. | Medium | SM012, SM014 |
| CM010 | Summing endpoint security (~$20.79B), EDR (~$6.33B) and DLP (~$4.67B) gives an order-of-magnitude 2026 reference near $32 billion before de-duplication. | Medium | SM012, SM013, SM014 |
| CM011 | The primary economic buyer for Ent is the enterprise CISO, with security operations, IT and compliance as influencers. | Medium | SM021, SM019 |
| CM012 | Budget ownership for workspace security typically sits within the CISO's security budget, with overlap into IT and compliance. | Medium | SM021 |
| CM013 | The adoption path for an intent-aware agent runs from targeted pilot to vertical rollout to enterprise-wide deployment. | Medium | SM018, SM019 |
| CM014 | AI-driven attacks are compressing dwell time and raising the value of prevention over detection. | Medium | SM021, SM022 |
| CM015 | The proliferation of autonomous AI agents in the workspace is creating new demand for AI governance controls. | Medium | SM024, SM023 |
| CM016 | Tightening data-protection and AI regulation is a structural demand driver for DLP and AI governance. | Medium | SM015, SM011 |
| CM017 | Endpoint security demand is driven by endpoint proliferation, remote work and rising attack sophistication. | High | SM001, SM002 |
| CM018 | Incumbent bundling, such as Defender within Microsoft 365 E5, raises switching costs for new endpoint entrants. | Medium | SM002, SM025 |
| CM019 | Buyer caution about false positives and unproven benchmarks is an adoption constraint for new prevention tools. | Medium | SM025 |
| CM020 | Independent analysts broadly agree that endpoint security is a high-teens-to-low-$20-billion market in 2026 despite methodology differences. | Medium | SM012, SM001, SM017 |
| CM021 | EDR and DLP are growing materially faster than the overall endpoint security market. | Medium | SM013, SM014 |
| CM022 | Status-quo substitutes for Ent include legacy DLP, EDR alerting and manual insider-risk investigation. | Medium | SM019, SM017 |
| CM023 | Adjacent categories bordering Ent include UEBA, CASB, EDR and emerging AI-governance tooling. | Medium | SM008, SM007 |
| CM024 | North America concentrates the largest share of endpoint security spend. | Medium | SM003, SM009 |
| CM025 | Gartner defines an endpoint protection platform as a solution deployed on devices to prevent and detect malicious activity. | Medium | SM005, SM008 |
| CM026 | Worldwide cybersecurity revenue is projected to grow at double digits annually through 2030. | Medium | SM010, SM009 |
| CM027 | Cloud-based endpoint deployments are growing faster than on-premise alternatives. | Medium | SM006 |
| CM028 | Regulatory compliance requirements are boosting endpoint and data-protection investment. | Medium | SM009, SM004 |
| CM029 | No public Ent-specific SAM or SOM calculation has been disclosed, so sizing relies on category proxies. | Medium | SM018, SM019 |
| CM030 | Financial services, hospitality and defense are credible early demand pools given Ent's disclosed deployments. | Medium | SM018, SM021 |
| CM031 | Market estimates conflict at the margin because vendors scope endpoint, EDR, DLP and XDR differently, which must be preserved in diligence. | Medium | SM016, SM013, SM012 |
| CM032 | The startup-addressable slice depends on per-endpoint or per-seat pricing that Ent has not disclosed, leaving SOM only partly estimable. | Low | SM019, SM002 |
| CM033 | DLP demand is rising specifically because of insider risk and AI-driven data exfiltration. | Medium | SM011, SM015 |
| CM034 | The 2026 figures used here are current-year analyst estimates published in 2026. | Medium | SM012, SM014 |
| CM035 | Endpoint, EDR and DLP together establish a multi-segment TAM well above $30 billion that Ent's platform straddles. | Medium | SM012, SM013, SM014 |
| CM036 | Ent's prevention-first thesis is most valuable where AI accelerates attacks and shrinks response windows. | Medium | SM021, SM024 |
| CP001 | Ent's most direct competitors are cloud and on-device endpoint platforms led by CrowdStrike Falcon and SentinelOne Singularity. | Medium | SP016, SP025 |
| CP002 | Microsoft Defender for Endpoint is a primary competitor distributed through Microsoft 365 E5 bundling. | Medium | SP005, SP018 |
| CP003 | Palo Alto Networks Cortex XDR competes through platform consolidation across endpoint, network and cloud. | Medium | SP006 |
| CP004 | Broadcom-owned Symantec and Trend Micro Vision One are established enterprise endpoint incumbents. | Medium | SP007, SP008 |
| CP005 | DLP and insider-risk vendors such as Proofpoint, Varonis and DTEX overlap with Ent's use cases. | Medium | SP009, SP010, SP011 |
| CP006 | Cybereason is a further EDR competitor in the detection-and-response segment. | Low | SP013 |
| CP007 | The status-quo substitute Ent displaces is reactive detection-and-alerting EDR plus manual investigation. | Medium | SP015, SP014 |
| CP008 | Large enterprises can attempt to build internal monitoring, but intent-inference models are hard to replicate, limiting build-versus-buy substitution. | Low | SP015, SP023 |
| CP009 | CrowdStrike is a publicly traded, multi-billion-dollar-revenue platform with broad EDR, MDR and threat-intelligence scope. | High | SP001, SP012 |
| CP010 | CrowdStrike Falcon is priced on a per-endpoint subscription basis, commonly around or above roughly $100 per endpoint per year. | Medium | SP002 |
| CP011 | SentinelOne Singularity emphasizes on-device autonomous response and one-click rollback. | Medium | SP003 |
| CP012 | SentinelOne packaging is tiered, with per-endpoint pricing commonly cited near roughly $80 per endpoint per year for core tiers. | Medium | SP004 |
| CP013 | Microsoft Defender benefits from deep Windows integration and is included in M365 E5, lowering its marginal cost to bundled buyers. | Medium | SP005 |
| CP014 | Ent differentiates by inferring intent in real time rather than matching known-bad signatures or behaviors after the fact. | Medium | SP014, SP015 |
| CP015 | Ent uniquely claims to evaluate the intent of both human users and AI agents, a scope incumbents do not yet match. | Medium | SP023, SP020 |
| CP016 | Ent hosts its platform in the customer's own cloud for data sovereignty, contrasting with cloud-first incumbents. | Medium | SP015, SP014 |
| CP017 | Endpoint security switching costs are high because agents are deployed fleet-wide and integrated with SOC workflows. | Medium | SP012, SP025 |
| CP018 | Incumbent bundling, especially Microsoft's, creates lock-in that raises the bar for displacement. | Medium | SP005, SP018 |
| CP019 | Enterprises frequently multi-home endpoint, DLP and insider-risk tools, leaving room for a consolidating entrant. | Medium | SP009, SP010 |
| CP020 | Microsoft and CrowdStrike hold outsized distribution power through existing enterprise relationships. | Medium | SP001, SP005 |
| CP021 | Ent's intent-aware moat is vulnerable to fast-following incumbents embedding similar capabilities. | Medium | SP018, SP022 |
| CP022 | Skeptical coverage notes that prevention messaging is no longer contrarian and that Ent lacks published independent benchmarks. | Medium | SP018, SP022 |
| CP023 | New AI-agent-security entrants are emerging to compete for the same AI-governance budget Ent targets. | Low | SP020, SP027 |
| CP024 | Independent analyst reviews consistently rank CrowdStrike, Microsoft and SentinelOne among endpoint leaders. | Medium | SP012 |
| CP025 | Incumbents currently have limited dedicated AI-agent governance, a gap Ent targets. | Low | SP015, SP006 |
| CP026 | Ent's competitive readiness rests on founder pedigree, a $100M war chest and early Global 2000 deployments. | Medium | SP016, SP024 |
| CP027 | Endpoint security is a concentrated market where a few platforms capture most enterprise spend. | Medium | SP025, SP026 |
| CP028 | CrowdStrike and SentinelOne both push autonomous, AI-driven response as a core differentiator. | Medium | SP001, SP003 |
| CP029 | Trend Micro Vision One positions as a broad cross-layer detection and response platform. | Low | SP008 |
| CP030 | Varonis and DTEX anchor the insider-risk and data-security adjacency Ent overlaps. | Medium | SP010, SP011 |
| CP031 | Proofpoint anchors the human-centric DLP and data-protection adjacency. | Low | SP009 |
| CP032 | Ent's prevention-and-intent framing is a genuine product wedge but unproven against incumbents at scale. | Medium | SP017, SP018 |
| CP033 | Customer-cloud hosting is a credible differentiator for regulated buyers wary of vendor-cloud data exposure. | Medium | SP015, SP017 |
| CP034 | The competitive intelligence here reflects vendor and analyst material current as of mid-2026. | Medium | SP012, SP001 |
| CP035 | Palo Alto's consolidation strategy intensifies pricing and bundling pressure on point solutions. | Medium | SP006, SP007 |
| CP036 | Ent must win on demonstrable efficacy and time-to-value to overcome incumbent distribution and lock-in. Should it fail to publish convincing efficacy evidence quickly, the most likely outcome is that incumbents absorb the intent-aware concept and Ent is relegated to a niche, which is the core competitive risk a diligence reader must weigh. | Medium | SP019, SP021 |
| CI001 | Ent operates a SaaS subscription model, most likely priced per endpoint or per seat. | Medium | SI013, SI012 |
| CI002 | Ent has not publicly disclosed its pricing or list rates as of launch. | Medium | SI013, SI017 |
| CI003 | Ent's revenue mix is presently concentrated in early Global 2000 deployments across finance, hospitality and defense. | Low | SI021, SI012 |
| CI004 | Ent's go-to-market is a direct enterprise motion selling into CISO security organizations. | Medium | SI016, SI013 |
| CI005 | Enterprise security sales cycles typically run several months to over a year, a sales-efficiency drag at seed stage. | Medium | SI005, SI006 |
| CI006 | On-device SaaS agents can achieve high software gross margins once delivery scales. | Medium | SI006, SI011 |
| CI007 | Customer-cloud hosting shifts some infrastructure cost to the customer, potentially improving Ent's hosting gross margin but adding deployment-support cost. | Low | SI013, SI005 |
| CI008 | Ent has disclosed headcount of roughly 100 employees and platform general availability, but no revenue figures. | Medium | SI017, SI012 |
| CI009 | No public revenue or ARR figure exists for Ent given its seed-stage, private status. | Medium | SI017, SI004 |
| CI010 | Ent raised $100 million in seed financing, its only disclosed round to date. | High | SI012, SI014 |
| CI011 | At a typical burn for a roughly 100-person security startup, $100M implies an estimated 18-24 month runway. | Low | SI005, SI006 |
| CI012 | The seed proceeds are most likely directed to engineering, AI-model development, go-to-market and enterprise support. | Medium | SI022, SI013 |
| CI013 | Ent's next round will likely be triggered by demonstrated Global 2000 traction and ARR milestones. | Low | SI020, SI016 |
| CI014 | No debt or project-finance obligations have been disclosed for Ent. | Low | SI012, SI004 |
| CI015 | At seed stage, Ent's revenue quality is unproven and rests on early deployments rather than disclosed recurring revenue. | Medium | SI017, SI018 |
| CI016 | Comparable security SaaS companies report gross margins commonly in the 70-80%+ range at scale. | High | SI007, SI008 |
| CI017 | Building proprietary intent-inference AI models is research-and-talent intensive, front-loading cost ahead of revenue. | Medium | SI006, SI022 |
| CI018 | The principal diligence blockers are undisclosed pricing, revenue, ARR, burn rate and exact runway. | Medium | SI004, SI017 |
| CI019 | A $100M seed sets a high performance bar and elevated burn expectations, a financial risk if traction lags. | Medium | SI018, SI019 |
| CI020 | CrowdStrike and SentinelOne demonstrate that subscription endpoint security can scale to billions in high-margin recurring revenue. | High | SI007, SI008 |
| CI021 | Category-defining security startups such as Wiz reached $100M ARR in roughly 18 months, a demanding benchmark. | Medium | SI002, SI006 |
| CI022 | Cybersecurity venture funding remains robust, supporting Ent's ability to raise follow-on capital. | Medium | SI003, SI001 |
| CI023 | Third-party trackers list Ent as an early-stage, recently funded company without disclosed financials. | Low | SI009, SI010 |
| CI024 | The financial data points used here reflect disclosures and comparables current as of mid-2026. | Medium | SI012, SI007 |
| CI025 | Ent's seed valuation is implied to be large but is not officially disclosed, limiting dilution analysis. | Medium | SI017, SI014 |
| CI026 | An outsized seed compresses the margin for execution error before the next priced round. | Medium | SI019, SI018 |
| CI027 | Per-endpoint or per-seat pricing would tie Ent's revenue directly to deployed device or user counts. | Medium | SI013, SI025 |
| CI028 | The endpoint security market's double-digit growth supports a long revenue runway if Ent converts deployments. | Medium | SI026, SI025 |
| CI029 | Decibel's lead and a tier-1 syndicate signal investor confidence in Ent's financing trajectory. | Medium | SI020, SI015 |
| CI030 | Financing dependency is high until Ent demonstrates recurring revenue, given pre-revenue-disclosure status. | Medium | SI017, SI018 |
| CI031 | Service-delivery costs include enterprise onboarding into each customer's own cloud, a non-trivial deployment effort. | Low | SI013, SI005 |
| CI032 | Sales efficiency at seed stage is unmeasurable externally; only proxies from comparable SaaS apply. | Low | SI006, SI011 |
| CI033 | Pulse2 and other outlets corroborate the $100M seed and stealth emergence without adding financial detail. | Low | SI024, SI023 |
| CI034 | Ent's margin path should track comparable security SaaS if it reaches scale, but is unproven today. | Medium | SI011, SI007 |
| CI035 | The seed capital is sufficient to fund 2024-style multi-year product and GTM build before a Series A. | Low | SI012, SI006 |
| CI036 | Overall, Ent's financial profile is high-potential but evidence-thin, with valuation, revenue and burn all undisclosed. | Medium | SI017, SI004 |
| CE001 | Ent is a lightweight on-device AI agent that monitors workspace activity to prevent security incidents before they occur. | Medium | SE011, SE012 |
| CE002 | The platform observes workspace signals across browser, applications, workflows and data movement. | Medium | SE008, SE014 |
| CE003 | Ent's core modules include a workspace observer, an intent-inference engine, a policy-enforcement layer, an intervention layer and a forensic record. | Medium | SE008, SE011 |
| CE004 | The intent-inference engine uses specialized, small AI models to evaluate the intent of human users and AI agents in real time. | Medium | SE014, SE015 |
| CE005 | Ent runs AI models on the device and hosts the platform in the customer's own cloud for data sovereignty. | Medium | SE012, SE011 |
| CE006 | The platform is generally available on Windows, macOS, Linux and browser extensions. | High | SE011, SE009 |
| CE007 | Ent deploys as a lightweight agent that integrates into existing enterprise endpoints and security workflows. | Medium | SE009, SE021 |
| CE008 | Ent's roadmap spans AI governance, threat prevention, security integrations and multimodal endpoint intelligence. | Medium | SE011, SE008 |
| CE009 | Ent differentiates technically by inferring intent in real time rather than matching known-bad signatures after the fact. | Medium | SE012, SE017 |
| CE010 | Ent's models are trained on workspace-behavior data, the proprietary asset underpinning its intent inference. | Low | SE015, SE007 |
| CE011 | Ent provides just-in-time interventions that act before an incident is completed. | Medium | SE012, SE011 |
| CE012 | The platform maintains a forensic record to support incident investigation. | Medium | SE008, SE014 |
| CE013 | Ent's primary use cases are insider-risk detection, AI governance, DLP, last-mile threat prevention and incident investigation. | High | SE011, SE012 |
| CE014 | Customer-cloud hosting keeps sensitive telemetry within the customer's environment, supporting data-residency requirements. | Medium | SE012, SE003 |
| CE015 | Endpoint agents must be lightweight to avoid degrading device performance, a key reliability constraint. | Medium | SE010, SE024 |
| CE016 | Intent-based controls map conceptually to behavior-analytics techniques catalogued in MITRE ATT&CK. | Medium | SE002, SE005 |
| CE017 | Governing AI-agent actions aligns with emerging guidance such as OWASP's LLM and agent risk work and CSA AI guidance. | Medium | SE001, SE004 |
| CE018 | Autonomous AI agents introduce new attack surfaces that motivate runtime governance of agent intent. | Medium | SE007, SE004 |
| CE019 | Real-time intent inference risks false positives that could disrupt legitimate user activity. | Medium | SE018, SE019 |
| CE020 | No independent third-party benchmarks of Ent's intent-inference accuracy have been published. | Medium | SE018, SE019 |
| CE021 | Privacy and data-minimization controls are essential for lawful endpoint monitoring of employees. | Medium | SE003, SE010 |
| CE022 | Security controls catalogs such as NIST SP 800-53 define the access, audit and monitoring controls enterprise buyers expect. | Medium | SE003, SE005 |
| CE023 | DLP and last-mile threat prevention require observing data movement at the point of action on the endpoint. | Medium | SE010, SE006 |
| CE024 | Ent's architecture combines on-device inference with customer-cloud control, a hybrid edge-plus-cloud design. | Medium | SE008, SE009 |
| CE025 | Critical dependencies include the customer's cloud environment, endpoint operating systems and browser extension APIs. | Medium | SE009, SE010 |
| CE026 | At general availability the platform spans four endpoint surfaces, indicating meaningful engineering maturity. | Medium | SE009, SE011 |
| CE027 | AI-driven endpoint attacks are accelerating, raising the value of prevention-oriented design. | Medium | SE006, SE016 |
| CE028 | Ent positions intent inference as a complement that can sit alongside existing EDR rather than fully replace it. | Low | SE017, SE012 |
| CE029 | Multimodal endpoint intelligence on the roadmap implies extending observation beyond text to richer signals. | Low | SE008, SE022 |
| CE030 | Security integrations on the roadmap would connect Ent to SIEM, SOAR and identity systems. | Low | SE011, SE010 |
| CE031 | The on-device approach reduces reliance on cloud round-trips, supporting sub-second intervention claims. | Low | SE008, SE014 |
| CE032 | SANS and industry guidance stress that effective insider-risk programs require behavioral context, not just access logs. | Medium | SE005, SE002 |
| CE033 | The technical claims here derive from company material and framework references current as of mid-2026. | Medium | SE008, SE003 |
| CE034 | Ent's agent must balance observability against device resource use, an engineering trade-off common to EDR. | Medium | SE010, SE024 |
| CE035 | Pulse2 and other outlets corroborate the platform's GA across desktop and browser surfaces. | Low | SE020, SE013 |
| CE036 | The platform's differentiation and maturity are credible but its real-world efficacy remains externally unvalidated. | Medium | SE019, SE018 |
| CE037 | Ent is actively hiring across security research, AI engineering and platform teams, a developer-side signal of build momentum. | Medium | SE017, SE015 |
| CU001 | Ent has disclosed deployment across Global 2000 enterprises in three verticals: hospitality, financial services, and defense. | High | SU013, SU014 |
| CU002 | Ent emerged from stealth in June 2026 without disclosing a specific customer count. | High | SU013, SU009 |
| CU003 | A named anonymous customer — an insider-threat lead at a public financial institution — provided a positive testimonial for Ent. | Medium | SU015, SU013 |
| CU004 | The financial institution customer stated Ent was 'the first tool where I felt like an expert on day one', indicating low time-to-value. | Medium | SU015, SU009 |
| CU005 | Ent targets the Global 2000, indicating its primary segment is large enterprises with complex security needs. | Medium | SU011, SU013 |
| CU006 | The economic buyer for Ent is the enterprise CISO, with security operations and compliance as co-stakeholders. | Medium | SU003, SU002 |
| CU007 | Security buyers in 2026 favor platforms that consolidate insider risk, DLP, and AI governance into a single agent. | Medium | SU003, SU012 |
| CU008 | CISOs prioritize tools that reduce alert fatigue and surface intent rather than generating more events. | Medium | SU002, SU006 |
| CU009 | Enterprises in regulated verticals — financial services, defense, healthcare — are the earliest adopters of AI-governance controls. | Medium | SU004, SU007 |
| CU010 | Financial institutions are among the most active buyers of insider-threat tooling in the enterprise market. | Medium | SU007, SU022 |
| CU011 | Insider-driven incidents rank among the costliest enterprise security failures, sustaining buyer urgency for insider-risk platforms. | Medium | SU005, SU023 |
| CU012 | CISA guidance affirms that insider threats — malicious, negligent, or unwitting — require lifecycle detection controls. | Medium | SU008, SU007 |
| CU013 | A meaningful share of data breaches involve internal actors through error, misuse, or compromised credentials. | Medium | SU023, SU022 |
| CU014 | Organizations using security AI and automation see significantly lower breach costs and faster containment. | Medium | SU022, SU023 |
| CU015 | No public customer count, ARR, or NRR figure has been disclosed by Ent as of June 2026. | Medium | SU013, SU018 |
| CU016 | Ent's Global 2000 deployment claim is company-asserted and unverified by independent third parties as of June 2026. | Medium | SU017, SU025 |
| CU017 | The Next Web noted that Ent has not published independent benchmarks for its intent-inference claims. | Medium | SU017 |
| CU018 | Enterprise DLP buying in 2026 is shifting toward integrated platforms that address insider risk and AI governance. | Medium | SU012, SU003 |
| CU019 | Ent's on-device agent supports insider risk detection, AI governance, DLP, last-mile prevention, and incident investigation use cases. | Medium | SU020, SU019 |
| CU020 | Defense and government customers represent a high-value strategic segment given IQT's participation in Ent's seed round. | Medium | SU013, SU009 |
| CU021 | Hospitality enterprises face distributed-workforce risk that maps to Ent's last-mile threat-prevention use case. | Medium | SU021, SU019 |
| CU022 | Ent's typical adoption path begins with a targeted pilot in a single vertical before expanding enterprise-wide. | Medium | SU009, SU016 |
| CU023 | No public churn, failed pilot, or contract non-renewal evidence exists for Ent as of June 2026. | Medium | SU013, SU018 |
| CU024 | Buyer caution about unproven intent-inference accuracy is a potential adoption constraint in the DLP incumbent market. | Medium | SU025, SU017 |
| CU025 | Gartner Peer Insights EDR reviewers weight efficacy, ease of deployment, and false-positive rates most heavily. | Medium | SU001, SU003 |
| CU026 | Ent's platform is hosted in the customer's own cloud, reducing data-sovereignty friction for regulated-industry buyers. | Medium | SU019, SU020 |
| CU027 | No retention cohort, GRR, or NRR data is publicly available for Ent, as the company has not disclosed financial metrics. | Medium | SU015, SU013 |
| CU028 | Customer concentration risk is undisclosed; if three verticals represent the full base, any single-vertical dependency could be material. | Medium | SU016, SU021 |
| CU029 | Ent's design for enterprise-scale agentic AI governance positions it for expansion as AI agents proliferate in customer workspaces. | Medium | SU020, SU018 |
| CU030 | All customer evidence for Ent post-launch dates from June 2026, reflecting only the stealth-exit announcement window. | Medium | SU013, SU009 |
| CU031 | Buyers want measurable reductions in time-to-investigate and clearer attribution of risky behavior. | Medium | SU006, SU003 |
| CU032 | Defense-sector deployments carry national-security mandate tailwinds driven in part by IQT as a strategic investor. | Medium | SU008, SU013 |
| CU033 | No G2, Capterra, or Gartner Peer Insights review entry for Ent as a specific product exists as of June 2026. | Medium | SU001, SU015 |
| CU034 | The anonymous financial-institution testimonial represents the only direct customer voice in publicly available evidence. | Medium | SU015, SU013 |
| CU035 | Ent's platform targets the workspace layer across Windows, macOS, Linux, and browser environments, broadening deployment surface. | Medium | SU018, SU019 |
| CU036 | Enterprise DLP consolidation trends in 2026 favor unified platforms over point products, supporting Ent's land-and-expand potential. | Medium | SU012, SU007 |
| CU037 | Ent's stealth period with paying Global 2000 customers indicates pre-announcement product-market validation, though depth is unknown. | Medium | SU016, SU010 |
| CU038 | Procurement friction in regulated industries includes data residency audits, security reviews, and multi-stakeholder approvals. | Medium | SU004, SU008 |
| CU039 | Ent has not disclosed whether its stealth customer base includes signed enterprise contracts or proof-of-concept evaluations. | Medium | SU013, SU018 |
| CU040 | The combination of IQT participation and defense-vertical deployment signals potential for government/defense procurement channels. | Medium | SU013, SU020 |
| CR001 | Ent's most severe risks cluster around regulatory/privacy exposure, unproven efficacy, incumbent competition and key-person dependence. | Medium | SR016, SR017 |
| CR002 | Endpoint monitoring of employees triggers significant privacy and data-protection obligations. | High | SR006, SR001 |
| CR003 | The EU GDPR constrains workplace monitoring through purpose-limitation, proportionality and lawful-basis requirements. | High | SR001, SR008 |
| CR004 | The European Data Protection Board has issued guidance restricting intrusive employee monitoring. | Medium | SR008 |
| CR005 | The EU AI Act imposes obligations on AI systems that could classify intent-inference as higher-risk, raising compliance cost. | Medium | SR002 |
| CR006 | US state privacy laws such as the CCPA grant employees and consumers data rights relevant to monitoring data. | Medium | SR004 |
| CR007 | The FTC has pursued enforcement against unfair or deceptive data practices, a US enforcement risk. | Medium | SR003 |
| CR008 | Civil-liberties groups warn that pervasive workplace surveillance carries legal and reputational risk. | High | SR007, SR006 |
| CR009 | NIST's AI Risk Management Framework signals the governance expectations regulators will apply to AI systems. | Medium | SR005 |
| CR010 | Real-time intent inference risks false positives that could block legitimate work and erode trust. | Medium | SR017, SR016 |
| CR011 | Ent's sub-second inference and efficacy claims have not been independently benchmarked. | Medium | SR017, SR016 |
| CR012 | A fleet-wide on-device agent introduces reliability and performance risk if it degrades devices or fails. | Medium | SR023, SR026 |
| CR013 | Ent depends on each customer's cloud infrastructure to host its control plane and forensic store. | Medium | SR012, SR011 |
| CR014 | Microsoft and CrowdStrike pose concentrated competitive risk through distribution and bundling. | Medium | SR025, SR026 |
| CR015 | Key-person dependence on co-founders Elias Manousos and Brandon Dixon is acute for a roughly 100-person company. | Medium | SR013, SR021 |
| CR016 | A $100M seed sets a high performance bar and elevated burn, an execution risk if traction lags. | Medium | SR016, SR017 |
| CR017 | Burn-and-runway risk is material given undisclosed burn and an estimated 18-24 month runway. | Low | SR021, SR014 |
| CR018 | Financial-model risk is high because revenue, pricing and unit economics are undisclosed. | Medium | SR021, SR011 |
| CR019 | Mitigations include an advisory board with a former NSA director and former CISOs to navigate regulation. | Medium | SR011, SR018 |
| CR020 | Customer-cloud hosting is itself a mitigation that supports data-sovereignty compliance. | Medium | SR012, SR027 |
| CR021 | Thesis-break triggers include sustained false-positive complaints, a failed marquee deployment or incumbent feature parity. | Medium | SR016, SR025 |
| CR022 | Risks transmit across domains: a privacy enforcement action could stall sales and worsen burn. | Medium | SR001, SR014 |
| CR023 | The threat environment - costly breaches and shrinking dwell time - validates demand but raises the stakes of failure. | High | SR010, SR009 |
| CR024 | Verizon breach data shows human-driven and credential-based incidents remain dominant, supporting insider focus. | Medium | SR009 |
| CR025 | IBM breach-cost data shows multimillion-dollar average breach costs, underscoring prevention value. | Medium | SR010 |
| CR026 | AI-agent governance is an emerging regulatory frontier where rules are still forming, creating compliance uncertainty. | Medium | SR029, SR028 |
| CR027 | Insider-threat programs face heightened government scrutiny, both a demand driver and a compliance obligation. | Medium | SR030, SR027 |
| CR028 | Data-sovereignty obligations in defense and finance could constrain or complicate deployments. | Medium | SR012, SR008 |
| CR029 | Competition risk and execution risk compound: incumbents can out-distribute Ent while it must prove efficacy. | Medium | SR026, SR016 |
| CR030 | Expansion beyond three verticals is an execution risk given limited team scale. | Medium | SR021, SR014 |
| CR031 | Reputational risk is elevated by skeptical coverage questioning whether prevention claims are differentiated. | Medium | SR016, SR022 |
| CR032 | Regulatory complexity is global, spanning EU GDPR/AI Act and US state and federal regimes simultaneously. | Medium | SR001, SR002, SR004 |
| CR033 | Mitigation depends on demonstrable efficacy evidence Ent has not yet published. | Medium | SR017, SR012 |
| CR034 | The founders' Microsoft and RiskIQ pedigree partially mitigates execution and credibility risk. | Medium | SR013, SR019 |
| CR035 | Tier-1 investor backing partially mitigates financing risk but raises valuation-expectation risk. | Medium | SR011, SR014 |
| CR036 | Endpoint-market concentration means Ent must win share from entrenched incumbents, a structural risk. | Medium | SR023, SR024 |
| CR037 | A successful red-team or privacy regulator action against intent inference would be a severe adverse event. | Medium | SR007, SR003 |
| CR038 | Monitoring indicators include false-positive rates, deployment renewals, regulatory filings and competitor releases. | Medium | SR005, SR017 |
| CR039 | The single anonymous customer reference leaves execution evidence thin and concentration risk high. | Medium | SR015, SR021 |
| CR040 | Diligence asks include efficacy benchmarks, privacy DPIA, burn data and a key-person retention plan. | Medium | SR017, SR012 |
| CR041 | DataM and other coverage frame AI as reshaping both attack and defense, raising the cost of getting prevention wrong. | Low | SR020, SR010 |
| CR042 | Overall, Ent's risk profile is high-variance: a credible team and capital against unproven efficacy, heavy regulation and dominant incumbents. | Medium | SR016, SR013 |
| CV001 | The investment thesis is that intent-aware workspace security could become a default enterprise layer, led by an elite team. | Medium | SV011, SV013 |
| CV002 | The anti-thesis is that incumbents embed intent-awareness and commoditize Ent before it scales. | Medium | SV016, SV029 |
| CV003 | The recommendation is to track Ent: compelling vision and pedigree, but execution unproven at scale. | Medium | SV014, SV017 |
| CV004 | Confidence in the recommendation is moderate given thin disclosed financials and customer proof. | Medium | SV021, SV017 |
| CV005 | The $100M seed from tier-1 investors implies a valuation widely characterized as in unicorn territory, though not officially disclosed. | Medium | SV013, SV011 |
| CV006 | No official post-money valuation has been disclosed, so the implied figure is not directly supported by public evidence. | Medium | SV021, SV011 |
| CV007 | Seed preference and dilution terms are undisclosed, leaving overhang analysis incomplete. | Low | SV021, SV010 |
| CV008 | The bull case is acquisition by a major platform or an IPO at $5B+ if intent-aware security becomes a default layer. | Low | SV006, SV001 |
| CV009 | The base case is growth to a Series A/B at a $500M-$1B+ valuation if early Global 2000 traction holds. | Low | SV010, SV008 |
| CV010 | The bear case is commoditization by incumbents, a down round or acqui-hire if efficacy and traction disappoint. | Low | SV016, SV017 |
| CV011 | CrowdStrike trades as a large-cap security platform with a market capitalization in the tens of billions of dollars. | High | SV001, SV004 |
| CV012 | SentinelOne is a public security company valued in the mid-teens-of-billions range. | High | SV002, SV030 |
| CV013 | Palo Alto Networks is a platform-consolidation comparable with a market cap above $100 billion. | Medium | SV003, SV004 |
| CV014 | Wiz demonstrated a record revenue ramp before a landmark acquisition agreement, a benchmark for category-defining security startups. | Medium | SV005, SV009 |
| CV015 | Strategic acquirers continue to pay premiums for differentiated security platforms with enterprise traction. | Medium | SV006, SV007 |
| CV016 | High-growth security software trades at elevated enterprise-value-to-revenue multiples relative to broader SaaS. | High | SV008, SV001 |
| CV017 | A seed investor's return depends on Ent reaching a multi-billion outcome, given the large implied entry valuation. | Low | SV010, SV008 |
| CV018 | Exit paths are acquisition by a platform incumbent or, less likely near-term, an IPO. | Low | SV006, SV003 |
| CV019 | Final diligence asks include ARR, pricing, efficacy benchmarks, cap table and customer references. | Medium | SV021, SV017 |
| CV020 | Thesis-break triggers include incumbent feature parity, sustained false positives or a failed marquee deployment. | Medium | SV016, SV029 |
| CV021 | An outsized seed valuation reduces entry discipline and compresses the margin for execution error. | Medium | SV010, SV017 |
| CV022 | Valuation is highly sensitive to assumed forward ARR and the revenue multiple applied. | Medium | SV008, SV009 |
| CV023 | A robust cybersecurity funding climate supports Ent's ability to raise a strong next round. | Medium | SV007, SV020 |
| CV024 | Investment KPIs to track include ARR growth, net revenue retention, named references and false-positive rate. | Medium | SV014, SV015 |
| CV025 | Comparables and valuation inputs used here are current as of mid-2026. | Medium | SV001, SV008 |
| CV026 | Ent's high-variance risk profile justifies a track stance rather than immediate conviction investment. | Medium | SV016, SV014 |
| CV027 | Probability weighting tilts toward the base case, with meaningful bear-case weight given execution risk. | Low | SV017, SV010 |
| CV028 | The single most decisive milestone is published, independent efficacy validation at a named customer. | Medium | SV017, SV012 |
| CV029 | The endpoint and XDR markets' size and growth support a large potential outcome if Ent executes. | Medium | SV026, SV028, SV027 |
| CV030 | Decibel's lead and a tier-1 syndicate signal strong external validation of the opportunity. | Medium | SV023, SV024 |
| CV031 | The founders' RiskIQ exit to Microsoft for $500M+ demonstrates prior value-creation, supporting the bull case. | Medium | SV013, SV019 |
| CV032 | CrowdStrike and SentinelOne prove the public-market value of scaled endpoint security, anchoring the upside. | High | SV001, SV002 |
| CV033 | Macrotrends data corroborates CrowdStrike's multi-billion revenue scale used as a north-star comparable. | Medium | SV004, SV029 |
| CV034 | Pulse2 and BusinessOutstanders corroborate the $100M raise underpinning the entry valuation. | Low | SV025, SV022 |
| CV035 | Carta data shows outsized seeds raise the bar for subsequent rounds, a valuation risk. | Medium | SV010, SV008 |
| CV036 | Morningstar syndication confirms the Global 2000 deployment claims that underpin the base case. | Medium | SV018, SV011 |
| CV037 | Sacra's Wiz analysis frames the ARR ramp a category-defining startup must achieve to justify a unicorn entry. | Medium | SV009, SV005 |
| CV038 | On balance, Ent is a high-quality, high-price, high-uncertainty seed best monitored toward its next round. | Medium | SV014, SV016 |
| CV039 | If efficacy is independently validated and ARR scales, the recommendation would move from track to invest. | Medium | SV015, SV008 |
| CV040 | If incumbents reach feature parity first, the bear case dominates and the case breaks. | Medium | SV029, SV016 |
| CV041 | Ent's valuation stance is positive-but-unconfirmed: attractive optionality at a price that demands proof. | Medium | SV010, SV014 |
| CV042 | The comparable set spans public leaders, a marquee private round and recent M&A, giving a defensible valuation envelope. | Medium | SV001, SV005, SV006 |
| ID | Publisher | Title | Quote |
|---|---|---|---|
| SO001 | Business Wire | Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity | Ent today emerged from stealth with $100 million in seed financing to bring prevention back to cybersecurity with an intent-aware workspace security platform. |
| SO002 | SiliconANGLE | RiskIQ founders launch Ent with $100M to rethink endpoint defense | The company was founded by Elias Manousos and Brandon Dixon, who previously built RiskIQ before its $500 million-plus acquisition by Microsoft. |
| SO003 | The SaaS News | Ent Raises $100M in Seed Funding | The round was led by Decibel, with participation from Sequoia, Craft Ventures, Crosspoint Capital and others. |
| SO004 | FinTech Global | Ent's $100m seed signals a shift in cybersecurity thinking | Ent's intent-aware approach reflects a broader shift from detection toward prevention in enterprise security. |
| SO005 | BankInfoSecurity (ISMG) | Ent Raises $100M to Reinvent Endpoint Security for AI Era | An insider-threat lead at a public financial institution said Ent was the first tool where I felt like an expert on day one. |
| SO006 | The Next Web | Ent's $100M seed bets on intent-aware workspace prevention | Prevention is back is hardly a contrarian rallying cry anymore, and Ent has yet to publish independent benchmarks for its intent-inference claims. |
| SO007 | Morningstar (Business Wire) | Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity | Ent's platform is deployed across Global 2000 enterprises in hospitality, financial services and defense. |
| SO008 | Pulse 2.0 | Ent Raises $100 Million Seed Round And Emerges From Stealth | Ent emerged from stealth with an AI-powered workspace security platform and $100 million in seed funding. |
| SO009 | Business Outstanders | Ent's $100M Seed Funding for AI Endpoint Security | Ent uses specialized AI models to evaluate the intent of users and AI agents in real time. |
| SO010 | DataM Intelligence | Ent Raises $100 Million Seed Funding for AI Endpoint Security Platform | The endpoint security market is positioned for double-digit growth as AI reshapes both attack and defense. |
| SO011 | Tech Funding News | Ent: ex-Microsoft Security Copilot founders raise $100M for AI threats | Brandon Dixon spearheaded the launch of Microsoft Security Copilot before co-founding Ent. |
| SO012 | DLP Test | Ent Emerges from Stealth with $100 Million Seed Round | Without independent benchmarks, claims about low false-positive intent detection remain unproven, and DLP buyers have heard prevention promises before. |
| SO013 | AIExpert.news | Ent Emerges From Stealth With $100M Seed for AI-Aware Endpoint Security | Ent positions itself to govern both human users and autonomous AI agents in the workspace. |
| SO014 | Yahoo Finance (Business Wire) | Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity | Ent's lightweight on-device agent runs across Windows, macOS, Linux and browser extensions. |
| SO015 | FinancialContent / WRAL | Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity | The platform is hosted in the customer's own cloud to preserve data sovereignty. |
| SO016 | The Wall Street Journal | Cyber Startup Ent Raises $100 Million in Seed Funding | Launched in 2025, Ent has about 100 workers and is led by RiskIQ co-founder Elias Manousos. |
| SO017 | Ent | Ent - Intent-Aware Workspace Security | Ent brings prevention back to cybersecurity by understanding the intent behind every action in the workspace. |
| SO018 | Decibel | Decibel - Venture capital for technical founders | Decibel partners with founders building foundational enterprise and security companies. |
| SO019 | Shield Capital | Shield Capital - Investing in security and resilience | Shield Capital backs founders at the intersection of commercial technology and national security. |
| SO020 | Felicis | Felicis - Venture capital firm | Felicis invests in iconic companies reinventing the world for the better. |
| SO021 | Crosspoint Capital Partners | Crosspoint Capital Partners - Cybersecurity and privacy investing | Crosspoint Capital is a private equity firm focused on the cybersecurity, privacy and infrastructure software markets. |
| SO022 | In-Q-Tel | In-Q-Tel - Strategic investor for national security | IQT identifies and adapts cutting-edge technologies to support the missions of the U.S. national security community. |
| SO023 | Craft Ventures | Craft Ventures - Venture capital for founders | Craft Ventures invests in founders building the defining companies of their categories. |
| SO024 | FinancialContent (Business Wire) | Pillar Security Appoints Former Microsoft AI Security Leader Brandon Dixon as Strategic Advisor | Brandon Dixon co-founded PassiveTotal, which was acquired by RiskIQ, and later served as a Security AI Strategist at Microsoft. |
| SO025 | Microsoft News | Microsoft acquires RiskIQ to strengthen cybersecurity of digital transformation and hybrid work | Microsoft has acquired RiskIQ, a leader in global threat intelligence and attack surface management. |
| SO026 | TechCrunch | Microsoft confirms it has acquired RiskIQ | Reports valued the RiskIQ acquisition at more than $500 million. |
| SO027 | Crunchbase | Ent - Company Profile | Ent is a cybersecurity company founded in 2025 and headquartered in San Francisco. |
| SO028 | Ent - Company Page | Ent is an intent-aware workspace security company based in San Francisco. | |
| SO029 | Sequoia Capital | Sequoia Capital - Partnering with founders | Sequoia partners early and stays for the long arc of company building. |
| SO030 | Ent | About Ent | Ent was founded by Elias Manousos and Brandon Dixon to bring prevention back to cybersecurity. |
| SO031 | Ent | Ent Blog | Our mission is to understand intent so security teams can intervene before incidents occur. |
| SM001 | Grand View Research | Endpoint Security Market Size, Share & Trends Analysis Report | Growing endpoint proliferation and remote work are key drivers of endpoint security demand. |
| SM002 | MarketsandMarkets | Endpoint Security Market - Global Forecast | The endpoint security market is driven by the rising sophistication and frequency of cyberattacks. |
| SM003 | Precedence Research | Endpoint Security Market Size and Growth | North America dominates endpoint security spending led by enterprise and government buyers. |
| SM004 | Fortune Business Insights | Endpoint Security Market Size, Share & Growth | The shift to AI-driven detection and response is reshaping endpoint security budgets. |
| SM005 | Gartner | Definition of Endpoint Protection Platform (EPP) - Glossary | An endpoint protection platform is a solution deployed on endpoint devices to prevent file-based malware and detect malicious activity. |
| SM006 | Allied Market Research | Endpoint Security Market Statistics, Forecast | Cloud-based endpoint security deployments are growing faster than on-premise alternatives. |
| SM007 | Market Research Future | Endpoint Security Market Research Report - Forecast | Endpoint security adoption is accelerating across BFSI, healthcare and government verticals. |
| SM008 | Verified Market Research | Endpoint Security Market Size And Forecast | Endpoint security is converging with EDR, DLP and identity into unified platforms. |
| SM009 | Global Market Insights | Endpoint Security Market Size & Share, Growth Forecast | Increasing regulatory compliance requirements are boosting endpoint security investments. |
| SM010 | Statista | Cybersecurity - Worldwide Market Outlook | Worldwide cybersecurity revenue is projected to show steady double-digit annual growth through 2030. |
| SM011 | Precedence Research | Data Loss Prevention Market Size and Forecast | DLP demand is rising as enterprises confront insider risk and AI-driven data exfiltration. |
| SM012 | The Business Research Company | Endpoint Security Global Market Report 2026 | The endpoint security market will grow from $18.58 billion in 2025 to $20.79 billion in 2026 at a CAGR of 11.9%. |
| SM013 | Mordor Intelligence | Endpoint Detection and Response (EDR) Market Size & Share Analysis | The EDR market is estimated at $6.33 billion in 2026 and is projected to reach $18.68 billion by 2031 at a CAGR of 24.16%. |
| SM014 | The Business Research Company | Data Loss Prevention Global Market Report 2026 | The data loss prevention market will grow from $3.68 billion in 2025 to $4.67 billion in 2026 at a CAGR of 26.9%. |
| SM015 | Fortune Business Insights | Data Loss Prevention Market Size, Share & Growth Report | Rising insider threats and stringent data-protection regulations are driving rapid DLP market expansion. |
| SM016 | HiQual Insights | Cybersecurity XDR / AI-SOC Market 2026-2031 | The XDR and AI-SOC market is projected to grow from $33.4 billion in 2025 to $89 billion by 2031 at a CAGR of 22.6%. |
| SM017 | Research and Markets | Endpoint Security Market Report | Endpoint security remains one of the largest and fastest-consolidating segments of enterprise cybersecurity spend. |
| SM018 | Business Wire | Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity | Ent today emerged from stealth with $100 million in seed financing to bring prevention back to cybersecurity with an intent-aware workspace security platform. |
| SM019 | Ent | Ent - Intent-Aware Workspace Security | Ent brings prevention back to cybersecurity by understanding the intent behind every action in the workspace. |
| SM020 | SiliconANGLE | RiskIQ founders launch Ent with $100M to rethink endpoint defense | The company was founded by Elias Manousos and Brandon Dixon, who previously built RiskIQ before its $500 million-plus acquisition by Microsoft. |
| SM021 | FinTech Global | Ent's $100m seed signals a shift in cybersecurity thinking | Ent's intent-aware approach reflects a broader shift from detection toward prevention in enterprise security. |
| SM022 | DataM Intelligence | Ent Raises $100 Million Seed Funding for AI Endpoint Security Platform | The endpoint security market is positioned for double-digit growth as AI reshapes both attack and defense. |
| SM023 | Tech Funding News | Ent: ex-Microsoft Security Copilot founders raise $100M for AI threats | Brandon Dixon spearheaded the launch of Microsoft Security Copilot before co-founding Ent. |
| SM024 | Business Outstanders | Ent's $100M Seed Funding for AI Endpoint Security | Ent uses specialized AI models to evaluate the intent of users and AI agents in real time. |
| SM025 | The Next Web | Ent's $100M seed bets on intent-aware workspace prevention | Prevention is back is hardly a contrarian rallying cry anymore, and Ent has yet to publish independent benchmarks for its intent-inference claims. |
| SP001 | CrowdStrike | CrowdStrike Falcon Platform | The CrowdStrike Falcon platform delivers cloud-native, AI-powered endpoint and workload protection. |
| SP002 | CrowdStrike | CrowdStrike Falcon Pricing & Bundles | Falcon Go starts at $59.99 per endpoint per year, with higher tiers for Enterprise and Complete MDR. |
| SP003 | SentinelOne | SentinelOne Singularity Platform | Singularity delivers autonomous, on-device AI that detects and remediates threats in real time with one-click rollback. |
| SP004 | SentinelOne | Singularity Platform Packages | Singularity is offered in Core, Control and Complete tiers priced per endpoint. |
| SP005 | Microsoft | Microsoft Defender for Endpoint | Defender for Endpoint is included with Microsoft 365 E5 and provides industry-leading endpoint protection. |
| SP006 | Palo Alto Networks | Cortex XDR - Extended Detection and Response | Cortex XDR unifies endpoint, network and cloud data to stop sophisticated attacks. |
| SP007 | Broadcom | Symantec Endpoint Security | Symantec Endpoint Security delivers protection for traditional and mobile endpoints at enterprise scale. |
| SP008 | Trend Micro | Endpoint Security - Trend Vision One | Trend Vision One brings endpoint protection into a unified cybersecurity platform. |
| SP009 | Proofpoint | Information Protection and DLP | Proofpoint combines content inspection with user behavior to prevent data loss across channels. |
| SP010 | Varonis | Varonis Data Security Platform | Varonis automatically discovers and protects sensitive data and detects insider threats. |
| SP011 | DTEX Systems | DTEX InTERCEPT Insider Risk Platform | DTEX uses behavioral indicators to detect insider risk while preserving employee privacy. |
| SP012 | Gartner Peer Insights | Endpoint Protection Platforms Reviews and Ratings | CrowdStrike, Microsoft and SentinelOne lead the endpoint protection platform market by review volume. |
| SP013 | Cybereason | Cybereason Defense Platform | Cybereason correlates endpoint telemetry into operation-centric attack stories. |
| SP014 | Business Wire | Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity | Ent today emerged from stealth with $100 million in seed financing to bring prevention back to cybersecurity with an intent-aware workspace security platform. |
| SP015 | Ent | Ent - Intent-Aware Workspace Security | Ent brings prevention back to cybersecurity by understanding the intent behind every action in the workspace. |
| SP016 | SiliconANGLE | RiskIQ founders launch Ent with $100M to rethink endpoint defense | The company was founded by Elias Manousos and Brandon Dixon, who previously built RiskIQ before its $500 million-plus acquisition by Microsoft. |
| SP017 | FinTech Global | Ent's $100m seed signals a shift in cybersecurity thinking | Ent's intent-aware approach reflects a broader shift from detection toward prevention in enterprise security. |
| SP018 | The Next Web | Ent's $100M seed bets on intent-aware workspace prevention | Prevention is back is hardly a contrarian rallying cry anymore, and Ent has yet to publish independent benchmarks for its intent-inference claims. |
| SP019 | BankInfoSecurity (ISMG) | Ent Raises $100M to Reinvent Endpoint Security for AI Era | An insider-threat lead at a public financial institution said Ent was the first tool where I felt like an expert on day one. |
| SP020 | Tech Funding News | Ent: ex-Microsoft Security Copilot founders raise $100M for AI threats | Brandon Dixon spearheaded the launch of Microsoft Security Copilot before co-founding Ent. |
| SP021 | DataM Intelligence | Ent Raises $100 Million Seed Funding for AI Endpoint Security Platform | The endpoint security market is positioned for double-digit growth as AI reshapes both attack and defense. |
| SP022 | DLP Test | Ent Emerges from Stealth with $100 Million Seed Round | Without independent benchmarks, claims about low false-positive intent detection remain unproven, and DLP buyers have heard prevention promises before. |
| SP023 | Business Outstanders | Ent's $100M Seed Funding for AI Endpoint Security | Ent uses specialized AI models to evaluate the intent of users and AI agents in real time. |
| SP024 | Morningstar (Business Wire) | Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity | Ent's platform is deployed across Global 2000 enterprises in hospitality, financial services and defense. |
| SP025 | Mordor Intelligence | Endpoint Detection and Response (EDR) Market Size & Share Analysis | The EDR market is estimated at $6.33 billion in 2026 and is projected to reach $18.68 billion by 2031 at a CAGR of 24.16%. |
| SP026 | The Business Research Company | Endpoint Security Global Market Report 2026 | The endpoint security market will grow from $18.58 billion in 2025 to $20.79 billion in 2026 at a CAGR of 11.9%. |
| SP027 | AIExpert.news | Ent Emerges From Stealth With $100M Seed for AI-Aware Endpoint Security | Ent positions itself to govern both human users and autonomous AI agents in the workspace. |
| SI001 | Crunchbase News | Cybersecurity Funding Coverage | Cybersecurity remained one of the most heavily funded enterprise software categories into 2026. |
| SI002 | Sacra | Sacra Research - Private market intelligence | Leading security SaaS companies sustain gross margins above 75% at scale. |
| SI003 | CB Insights | State of Cybersecurity Startup Funding | Mega-rounds at the seed stage have become a hallmark of repeat security founders with proven exits. |
| SI004 | Crunchbase | Ent - Financials | Ent has raised a total of $100M across one funding round, a seed round announced in June 2026. |
| SI005 | SaaStr | The SaaS Metrics That Matter | Best-in-class SaaS companies target CAC payback under 12 months and net revenue retention above 120%. |
| SI006 | Bessemer Venture Partners | State of the Cloud | Top-decile cloud companies combine durable growth with improving free-cash-flow margins. |
| SI007 | CrowdStrike Investor Relations | CrowdStrike Investor Relations | CrowdStrike reports subscription gross margins near 80% and a Rule-of-40 profile. |
| SI008 | SentinelOne Investor Relations | SentinelOne Investor Relations | SentinelOne has prioritized revenue growth while progressing toward positive operating margins. |
| SI009 | Tracxn | Ent - Company Financials and Funding | Tracxn lists Ent as a seed-stage cybersecurity company funded in 2026. |
| SI010 | Growjo | Ent - Revenue and Employee Estimates | Growjo estimates place Ent's headcount near 100 employees following its 2026 emergence from stealth. |
| SI011 | Aventis Advisors | SaaS Valuation Multiples | SaaS revenue multiples compressed from 2021 peaks but premium security assets still command double-digit forward multiples. |
| SI012 | Business Wire | Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity | Ent today emerged from stealth with $100 million in seed financing to bring prevention back to cybersecurity with an intent-aware workspace security platform. |
| SI013 | Ent | Ent - Intent-Aware Workspace Security | Ent brings prevention back to cybersecurity by understanding the intent behind every action in the workspace. |
| SI014 | SiliconANGLE | RiskIQ founders launch Ent with $100M to rethink endpoint defense | The company was founded by Elias Manousos and Brandon Dixon, who previously built RiskIQ before its $500 million-plus acquisition by Microsoft. |
| SI015 | The SaaS News | Ent Raises $100M in Seed Funding | The round was led by Decibel, with participation from Sequoia, Craft Ventures, Crosspoint Capital and others. |
| SI016 | FinTech Global | Ent's $100m seed signals a shift in cybersecurity thinking | Ent's intent-aware approach reflects a broader shift from detection toward prevention in enterprise security. |
| SI017 | The Wall Street Journal | Cyber Startup Ent Raises $100 Million in Seed Funding | Launched in 2025, Ent has about 100 workers and is led by RiskIQ co-founder Elias Manousos. |
| SI018 | The Next Web | Ent's $100M seed bets on intent-aware workspace prevention | Prevention is back is hardly a contrarian rallying cry anymore, and Ent has yet to publish independent benchmarks for its intent-inference claims. |
| SI019 | DLP Test | Ent Emerges from Stealth with $100 Million Seed Round | Without independent benchmarks, claims about low false-positive intent detection remain unproven, and DLP buyers have heard prevention promises before. |
| SI020 | Decibel | Decibel - Venture capital for technical founders | Decibel partners with founders building foundational enterprise and security companies. |
| SI021 | Morningstar (Business Wire) | Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity | Ent's platform is deployed across Global 2000 enterprises in hospitality, financial services and defense. |
| SI022 | Tech Funding News | Ent: ex-Microsoft Security Copilot founders raise $100M for AI threats | Brandon Dixon spearheaded the launch of Microsoft Security Copilot before co-founding Ent. |
| SI023 | DataM Intelligence | Ent Raises $100 Million Seed Funding for AI Endpoint Security Platform | The endpoint security market is positioned for double-digit growth as AI reshapes both attack and defense. |
| SI024 | Pulse 2.0 | Ent Raises $100 Million Seed Round And Emerges From Stealth | Ent emerged from stealth with an AI-powered workspace security platform and $100 million in seed funding. |
| SI025 | Mordor Intelligence | Endpoint Detection and Response (EDR) Market Size & Share Analysis | The EDR market is estimated at $6.33 billion in 2026 and is projected to reach $18.68 billion by 2031 at a CAGR of 24.16%. |
| SI026 | The Business Research Company | Endpoint Security Global Market Report 2026 | The endpoint security market will grow from $18.58 billion in 2025 to $20.79 billion in 2026 at a CAGR of 11.9%. |
| SE001 | OWASP | OWASP Top 10 for Large Language Model Applications | Excessive agency and prompt injection are leading risks for LLM-based applications and autonomous agents. |
| SE002 | MITRE | MITRE ATT&CK Knowledge Base | ATT&CK documents adversary tactics and techniques across the attack lifecycle, including exfiltration and insider abuse. |
| SE003 | NIST | SP 800-53 Rev. 5 Security and Privacy Controls | SP 800-53 provides a catalog of security and privacy controls for information systems and organizations. |
| SE004 | Cloud Security Alliance | Artificial Intelligence Research | Securing AI agents requires controls over their permissions, actions and data access in real time. |
| SE005 | SANS Institute | SANS Reading Room - Security White Papers | Effective insider threat programs combine behavioral analytics with user activity monitoring and clear policy. |
| SE006 | Dark Reading | Endpoint Security News and Analysis | On-device AI inference is becoming central to next-generation endpoint defense. |
| SE007 | arXiv | Identifying the Risks of LM Agents with an LM-Emulated Sandbox | Language-model agents can take unintended high-impact actions, motivating guardrails that evaluate intent before execution. |
| SE008 | Ent | Ent Platform Overview | Ent's lightweight on-device agent observes workspace activity and infers intent using specialized AI models. |
| SE009 | Ent | Ent Product | Ent supports insider risk detection, AI governance, data loss prevention, last-mile threat prevention and incident investigation. |
| SE010 | TechTarget | SearchSecurity - Enterprise Security Technology | Data sovereignty requirements increasingly push security vendors to deploy within the customer's own cloud tenant. |
| SE011 | Business Wire | Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity | Ent today emerged from stealth with $100 million in seed financing to bring prevention back to cybersecurity with an intent-aware workspace security platform. |
| SE012 | Ent | Ent - Intent-Aware Workspace Security | Ent brings prevention back to cybersecurity by understanding the intent behind every action in the workspace. |
| SE013 | SiliconANGLE | RiskIQ founders launch Ent with $100M to rethink endpoint defense | The company was founded by Elias Manousos and Brandon Dixon, who previously built RiskIQ before its $500 million-plus acquisition by Microsoft. |
| SE014 | Business Outstanders | Ent's $100M Seed Funding for AI Endpoint Security | Ent uses specialized AI models to evaluate the intent of users and AI agents in real time. |
| SE015 | Tech Funding News | Ent: ex-Microsoft Security Copilot founders raise $100M for AI threats | Brandon Dixon spearheaded the launch of Microsoft Security Copilot before co-founding Ent. |
| SE016 | DataM Intelligence | Ent Raises $100 Million Seed Funding for AI Endpoint Security Platform | The endpoint security market is positioned for double-digit growth as AI reshapes both attack and defense. |
| SE017 | FinTech Global | Ent's $100m seed signals a shift in cybersecurity thinking | Ent's intent-aware approach reflects a broader shift from detection toward prevention in enterprise security. |
| SE018 | DLP Test | Ent Emerges from Stealth with $100 Million Seed Round | Without independent benchmarks, claims about low false-positive intent detection remain unproven, and DLP buyers have heard prevention promises before. |
| SE019 | The Next Web | Ent's $100M seed bets on intent-aware workspace prevention | Prevention is back is hardly a contrarian rallying cry anymore, and Ent has yet to publish independent benchmarks for its intent-inference claims. |
| SE020 | Pulse 2.0 | Ent Raises $100 Million Seed Round And Emerges From Stealth | Ent emerged from stealth with an AI-powered workspace security platform and $100 million in seed funding. |
| SE021 | Morningstar (Business Wire) | Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity | Ent's platform is deployed across Global 2000 enterprises in hospitality, financial services and defense. |
| SE022 | AIExpert.news | Ent Emerges From Stealth With $100M Seed for AI-Aware Endpoint Security | Ent positions itself to govern both human users and autonomous AI agents in the workspace. |
| SE023 | BankInfoSecurity (ISMG) | Ent Raises $100M to Reinvent Endpoint Security for AI Era | An insider-threat lead at a public financial institution said Ent was the first tool where I felt like an expert on day one. |
| SE024 | Mordor Intelligence | Endpoint Detection and Response (EDR) Market Size & Share Analysis | The EDR market is estimated at $6.33 billion in 2026 and is projected to reach $18.68 billion by 2031 at a CAGR of 24.16%. |
| SE025 | The Business Research Company | Endpoint Security Global Market Report 2026 | The endpoint security market will grow from $18.58 billion in 2025 to $20.79 billion in 2026 at a CAGR of 11.9%. |
| SU001 | Gartner Peer Insights | Endpoint Detection and Response Solutions Reviews | Enterprise buyers weight efficacy, ease of deployment and false-positive rates most heavily in endpoint reviews. |
| SU002 | Security Magazine | Security Magazine – Enterprise Security News | CISOs increasingly prioritize tools that reduce alert fatigue and surface intent, not just events. |
| SU003 | CSO Online | CSO Online – Security Leadership | Security buyers favor platforms that consolidate insider risk, DLP and AI governance into one agent. |
| SU004 | CIO Dive | CIO Dive – Enterprise IT News | Enterprises in regulated verticals are early adopters of AI-governance controls for the workforce. |
| SU005 | SC Media | SC Media – Cybersecurity News and Analysis | Insider-driven incidents continue to rank among the costliest and hardest to detect for enterprises. |
| SU006 | Help Net Security | Help Net Security – Industry News | Buyers want measurable reductions in time-to-investigate and clearer attribution of risky behavior. |
| SU007 | BankInfoSecurity (ISMG) | Insider Threat – News and Resources | Financial institutions remain among the most active buyers of insider-threat tooling. |
| SU008 | CISA | Insider Threat Mitigation | Insider threats can be malicious, negligent, or unwitting, and require detection across the activity lifecycle. |
| SU009 | TechCrunch | Ent Raises $100M Seed Round to Combat AI-Driven Cyber Threats | Ent said it has already deployed its platform across Global 2000 enterprises spanning hospitality, financial services and defense. |
| SU010 | VentureBurn | Ent Raises $100M Seed for Workspace Security | The workspace security startup has secured early enterprise customers across regulated industries before emerging from stealth. |
| SU011 | CityBiz | Cybersecurity Startup Ent Emerges from Stealth with $100M in Seed Funding | Ent's platform is designed for Global 2000 enterprises with the most sensitive and complex security requirements. |
| SU012 | DLP Report | Data Loss Prevention Trends 2026 | Enterprise DLP buying is shifting from point products toward integrated platforms that also address insider risk and AI governance. |
| SU013 | Business Wire | Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity | Ent's platform is deployed across Global 2000 enterprises in hospitality, financial services and defense. |
| SU014 | Morningstar (Business Wire) | Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity | Ent's platform is deployed across Global 2000 enterprises in hospitality, financial services and defense. |
| SU015 | BankInfoSecurity (ISMG) | Ent Raises $100M to Reinvent Endpoint Security for AI Era | An insider-threat lead at a public financial institution said Ent was the first tool where I felt like an expert on day one. |
| SU016 | SiliconANGLE | RiskIQ founders launch Ent with $100M to rethink endpoint defense | Ent has already built out a base of Global 2000 customers before coming out of stealth. |
| SU017 | The Next Web | Ent's $100M seed bets on intent-aware workspace prevention | Prevention is back is hardly a contrarian rallying cry anymore, and Ent has yet to publish independent benchmarks for its intent-inference claims. |
| SU018 | Ent | Ent – Intent-Aware Workspace Security | Ent brings prevention back to cybersecurity by understanding the intent behind every action in the workspace. |
| SU019 | Ent | Ent Platform Overview | Ent's lightweight on-device agent observes workspace activity and infers intent using specialized AI models. |
| SU020 | Ent | Ent Product | Ent supports insider risk detection, AI governance, data loss prevention, last-mile threat prevention and incident investigation. |
| SU021 | FinTech Global | Ent's $100m seed signals a shift in cybersecurity thinking | Ent's intent-aware approach reflects a broader shift from detection toward prevention in enterprise security. |
| SU022 | IBM | Cost of a Data Breach Report | Organizations extensively using security AI and automation see significantly lower breach costs and faster containment. |
| SU023 | Verizon | Data Breach Investigations Report (DBIR) | A meaningful share of breaches involve internal actors through error, misuse or compromised credentials. |
| SU024 | Pulse 2.0 | Ent Raises $100 Million Seed Round And Emerges From Stealth | Ent emerged from stealth with an AI-powered workspace security platform and $100 million in seed funding. |
| SU025 | DLP Test | Ent Emerges from Stealth with $100 Million Seed Round | Without independent benchmarks, claims about low false-positive intent detection remain unproven, and DLP buyers have heard prevention promises before. |
| SR001 | GDPR.eu | General Data Protection Regulation (GDPR) | The GDPR imposes strict obligations on the processing of personal data, including workplace monitoring. |
| SR002 | EUR-Lex | Regulation (EU) 2024/1689 (Artificial Intelligence Act) | The AI Act sets harmonised rules and obligations for AI systems based on their level of risk. |
| SR003 | U.S. Federal Trade Commission | Privacy and Security Business Guidance | The FTC enforces against unfair or deceptive practices involving consumer data and security. |
| SR004 | California Attorney General | California Consumer Privacy Act (CCPA) | The CCPA grants California consumers rights over personal information collected by businesses. |
| SR005 | NIST | AI Risk Management Framework | The AI RMF helps organizations manage risks to individuals, organizations and society from AI systems. |
| SR006 | IAPP | Employee Monitoring and Privacy | Employee monitoring sits in a legal gray zone where transparency and proportionality requirements vary sharply by jurisdiction. |
| SR007 | Electronic Frontier Foundation | Workplace Privacy | Pervasive workplace surveillance raises serious privacy and civil-liberties concerns for employees. |
| SR008 | European Data Protection Board | European Data Protection Board | The EDPB issues guidance on the processing of employee data and monitoring under EU law. |
| SR009 | Verizon | Data Breach Investigations Report (DBIR) | A meaningful share of breaches involve internal actors through error, misuse or compromised credentials. |
| SR010 | IBM | Cost of a Data Breach Report | Organizations extensively using security AI and automation see significantly lower breach costs and faster containment. |
| SR011 | Business Wire | Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity | Ent today emerged from stealth with $100 million in seed financing to bring prevention back to cybersecurity with an intent-aware workspace security platform. |
| SR012 | Ent | Ent - Intent-Aware Workspace Security | Ent brings prevention back to cybersecurity by understanding the intent behind every action in the workspace. |
| SR013 | SiliconANGLE | RiskIQ founders launch Ent with $100M to rethink endpoint defense | The company was founded by Elias Manousos and Brandon Dixon, who previously built RiskIQ before its $500 million-plus acquisition by Microsoft. |
| SR014 | FinTech Global | Ent's $100m seed signals a shift in cybersecurity thinking | Ent's intent-aware approach reflects a broader shift from detection toward prevention in enterprise security. |
| SR015 | BankInfoSecurity (ISMG) | Ent Raises $100M to Reinvent Endpoint Security for AI Era | An insider-threat lead at a public financial institution said Ent was the first tool where I felt like an expert on day one. |
| SR016 | The Next Web | Ent's $100M seed bets on intent-aware workspace prevention | Prevention is back is hardly a contrarian rallying cry anymore, and Ent has yet to publish independent benchmarks for its intent-inference claims. |
| SR017 | DLP Test | Ent Emerges from Stealth with $100 Million Seed Round | Without independent benchmarks, claims about low false-positive intent detection remain unproven, and DLP buyers have heard prevention promises before. |
| SR018 | Morningstar (Business Wire) | Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity | Ent's platform is deployed across Global 2000 enterprises in hospitality, financial services and defense. |
| SR019 | Tech Funding News | Ent: ex-Microsoft Security Copilot founders raise $100M for AI threats | Brandon Dixon spearheaded the launch of Microsoft Security Copilot before co-founding Ent. |
| SR020 | DataM Intelligence | Ent Raises $100 Million Seed Funding for AI Endpoint Security Platform | The endpoint security market is positioned for double-digit growth as AI reshapes both attack and defense. |
| SR021 | The Wall Street Journal | Cyber Startup Ent Raises $100 Million in Seed Funding | Launched in 2025, Ent has about 100 workers and is led by RiskIQ co-founder Elias Manousos. |
| SR022 | Business Outstanders | Ent's $100M Seed Funding for AI Endpoint Security | Ent uses specialized AI models to evaluate the intent of users and AI agents in real time. |
| SR023 | Mordor Intelligence | Endpoint Detection and Response (EDR) Market Size & Share Analysis | The EDR market is estimated at $6.33 billion in 2026 and is projected to reach $18.68 billion by 2031 at a CAGR of 24.16%. |
| SR024 | The Business Research Company | Endpoint Security Global Market Report 2026 | The endpoint security market will grow from $18.58 billion in 2025 to $20.79 billion in 2026 at a CAGR of 11.9%. |
| SR025 | Microsoft | Microsoft Defender for Endpoint | Defender for Endpoint is included with Microsoft 365 E5 and provides industry-leading endpoint protection. |
| SR026 | CrowdStrike | CrowdStrike Falcon Platform | The CrowdStrike Falcon platform delivers cloud-native, AI-powered endpoint and workload protection. |
| SR027 | NIST | SP 800-53 Rev. 5 Security and Privacy Controls | SP 800-53 provides a catalog of security and privacy controls for information systems and organizations. |
| SR028 | OWASP | OWASP Top 10 for Large Language Model Applications | Excessive agency and prompt injection are leading risks for LLM-based applications and autonomous agents. |
| SR029 | Cloud Security Alliance | Artificial Intelligence Research | Securing AI agents requires controls over their permissions, actions and data access in real time. |
| SR030 | CISA | Insider Threat Mitigation | Insider threats can be malicious, negligent, or unwitting, and require detection across the activity lifecycle. |
| SV001 | StockAnalysis.com | CrowdStrike Holdings (CRWD) Stock Overview | CrowdStrike trades at a premium revenue multiple reflecting durable growth and high retention. |
| SV002 | StockAnalysis.com | SentinelOne (S) Stock Overview | SentinelOne's market value reflects strong growth tempered by ongoing operating losses. |
| SV003 | StockAnalysis.com | Palo Alto Networks (PANW) Stock Overview | Palo Alto Networks is among the largest pure-play cybersecurity companies by market capitalization. |
| SV004 | Macrotrends | CrowdStrike Market Cap History | CrowdStrike's market capitalization has compounded substantially since its 2019 IPO. |
| SV005 | Wiz | Wiz Newsroom | Wiz scaled to one of the fastest revenue ramps in software history before its landmark acquisition agreement. |
| SV006 | Aventis Advisors | Cybersecurity M&A Report | Strategic acquirers continue to pay premiums for differentiated security platforms with enterprise traction. |
| SV007 | CB Insights | Cybersecurity Trends Report | AI-native security and agentic-AI governance are among the most-funded emerging cybersecurity themes. |
| SV008 | Meritech Capital | Comparables Table | High-growth security software trades at elevated enterprise-value-to-revenue multiples relative to the broader SaaS index. |
| SV009 | Sacra | Wiz - Revenue, Growth and Valuation | Wiz reached $100M ARR in roughly 18 months, a benchmark for category-defining security startups. |
| SV010 | Carta | Startup Valuations and Round Data | Outsized seed rounds raise the bar for subsequent rounds, compressing the margin for execution error. |
| SV011 | Business Wire | Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity | Ent today emerged from stealth with $100 million in seed financing to bring prevention back to cybersecurity with an intent-aware workspace security platform. |
| SV012 | Ent | Ent - Intent-Aware Workspace Security | Ent brings prevention back to cybersecurity by understanding the intent behind every action in the workspace. |
| SV013 | SiliconANGLE | RiskIQ founders launch Ent with $100M to rethink endpoint defense | The company was founded by Elias Manousos and Brandon Dixon, who previously built RiskIQ before its $500 million-plus acquisition by Microsoft. |
| SV014 | FinTech Global | Ent's $100m seed signals a shift in cybersecurity thinking | Ent's intent-aware approach reflects a broader shift from detection toward prevention in enterprise security. |
| SV015 | BankInfoSecurity (ISMG) | Ent Raises $100M to Reinvent Endpoint Security for AI Era | An insider-threat lead at a public financial institution said Ent was the first tool where I felt like an expert on day one. |
| SV016 | The Next Web | Ent's $100M seed bets on intent-aware workspace prevention | Prevention is back is hardly a contrarian rallying cry anymore, and Ent has yet to publish independent benchmarks for its intent-inference claims. |
| SV017 | DLP Test | Ent Emerges from Stealth with $100 Million Seed Round | Without independent benchmarks, claims about low false-positive intent detection remain unproven, and DLP buyers have heard prevention promises before. |
| SV018 | Morningstar (Business Wire) | Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity | Ent's platform is deployed across Global 2000 enterprises in hospitality, financial services and defense. |
| SV019 | Tech Funding News | Ent: ex-Microsoft Security Copilot founders raise $100M for AI threats | Brandon Dixon spearheaded the launch of Microsoft Security Copilot before co-founding Ent. |
| SV020 | DataM Intelligence | Ent Raises $100 Million Seed Funding for AI Endpoint Security Platform | The endpoint security market is positioned for double-digit growth as AI reshapes both attack and defense. |
| SV021 | The Wall Street Journal | Cyber Startup Ent Raises $100 Million in Seed Funding | Launched in 2025, Ent has about 100 workers and is led by RiskIQ co-founder Elias Manousos. |
| SV022 | Business Outstanders | Ent's $100M Seed Funding for AI Endpoint Security | Ent uses specialized AI models to evaluate the intent of users and AI agents in real time. |
| SV023 | Decibel | Decibel - Venture capital for technical founders | Decibel partners with founders building foundational enterprise and security companies. |
| SV024 | The SaaS News | Ent Raises $100M in Seed Funding | The round was led by Decibel, with participation from Sequoia, Craft Ventures, Crosspoint Capital and others. |
| SV025 | Pulse 2.0 | Ent Raises $100 Million Seed Round And Emerges From Stealth | Ent emerged from stealth with an AI-powered workspace security platform and $100 million in seed funding. |
| SV026 | Mordor Intelligence | Endpoint Detection and Response (EDR) Market Size & Share Analysis | The EDR market is estimated at $6.33 billion in 2026 and is projected to reach $18.68 billion by 2031 at a CAGR of 24.16%. |
| SV027 | The Business Research Company | Endpoint Security Global Market Report 2026 | The endpoint security market will grow from $18.58 billion in 2025 to $20.79 billion in 2026 at a CAGR of 11.9%. |
| SV028 | HiQual Insights | Cybersecurity XDR / AI-SOC Market 2026-2031 | The XDR and AI-SOC market is projected to grow from $33.4 billion in 2025 to $89 billion by 2031 at a CAGR of 22.6%. |
| SV029 | CrowdStrike | CrowdStrike Falcon Platform | The CrowdStrike Falcon platform delivers cloud-native, AI-powered endpoint and workload protection. |
| SV030 | SentinelOne | SentinelOne Singularity Platform | Singularity delivers autonomous, on-device AI that detects and remediates threats in real time with one-click rollback. |