Startup Diligence
Diligence report Cybersecurity / AI workspace security Seed-stage private 2026-06-24

Ent

Intent-aware workspace security startup with elite security founders and a record $100M seed, but thin public proof.

Ent is a high-pedigree, high-ambition workspace security startup with a rare $100M seed and credible product wedge, but the absence of disclosed financials, named customer depth and independent efficacy benchmarks makes it a monitor-now rather than invest-now situation.

Cover facts

Latest financing 01
100 USD M seed (June 2026) [CO002]
Total disclosed funding 02
100 USD M [CO021]
Founded 03
2025 [CO013]
Reported headcount 04
100 employees (~) [CO012]
Disclosed customer verticals 05
3 Global 2000 verticals [CO018]

Company profile

Ent is a seed-stage cybersecurity startup founded in 2025 by RiskIQ veterans Elias Manousos and Brandon Dixon. The company emerged from stealth on 2026-06-16 with a $100M seed round led by Decibel and positioned its product as an intent-aware workspace security layer that observes human and AI-agent activity on the endpoint, infers intent in real time, and intervenes before data exfiltration or insider-risk incidents complete. The public debate is whether exceptional founder pedigree and a large market can outrun thin disclosed customer proof, undisclosed economics and unbenchmarked efficacy.

Website
ent.ai
Founded
2025-01-01
Founders
Elias Manousos, Brandon Dixon
Founding location
San Francisco Bay Area, California, USA
Headquarters
San Francisco, California, USA
Product
Lightweight on-device AI agent for Windows, macOS, Linux and browser environments that infers user and AI-agent intent in real time to support insider-risk detection, AI governance, DLP, last-mile threat prevention and incident investigation.
Customers
Global 2000 enterprises, especially hospitality, financial services, defense and other regulated environments.
Business model
Enterprise security software sold into the CISO budget, likely priced per endpoint or seat, with customer-cloud deployment and attached policy, governance and investigation workflows.
Stage
Seed-stage private
Funding status
$100M seed announced on 2026-06-16 led by Decibel with Sequoia, Craft Ventures, Crosspoint Capital, Shield Capital, Felicis and In-Q-Tel participating; no post-money valuation disclosed.
[CO001, CO002, CO005, CO015, CO018, CO021, CE001, CE005]

Executive summary

Top strengths

  • Elite founder-market fit anchored by RiskIQ and Microsoft security leadership.
  • Large, fast-growing market across endpoint security, DLP, insider risk and AI governance.
  • Lightweight on-device architecture and customer-cloud hosting create a differentiated prevention-first product story.

Top risks

  • No independent public benchmark validates Ent's intent-inference accuracy or false-positive rate.
  • Revenue, ARR, pricing, retention, valuation and customer concentration remain undisclosed.
  • Large incumbents such as Microsoft, CrowdStrike and SentinelOne can bundle adjacent capabilities and compress Ent's wedge.
  • Workplace monitoring, privacy and AI-governance regulation can complicate adoption in regulated geographies.

Open gaps

  • Confirmed post-money valuation, cap table terms and investor governance rights are not public.
  • ARR, burn, runway, gross margin and pricing are undisclosed.
  • Named customer references, renewal behavior, NRR and concentration data are unavailable.
  • Independent efficacy benchmarks and false-positive measurements have not been published.

Contents

Chapter 01

01Company Overview

1.1 Identity, headquarters, founding and business model

Ent is an intent-aware workspace security company that emerged from stealth on June 16, 2026 with a lightweight on-device AI agent for Windows, macOS, Linux and browser extensions. Its core thesis is to bring prevention back to cybersecurity by using specialized AI models to evaluate the intent of both human users and AI agents in real time and intervene before incidents occur, rather than relying on after-the-fact detection. The platform is hosted in the customer's own cloud to preserve data sovereignty, and the company frames its use cases as insider risk detection, AI governance, data loss prevention, last-mile threat prevention and incident investigation. Public records place Ent's headquarters in San Francisco, California, though some coverage uses the broader San Francisco Bay Area, and direct confirmation is advisable. Founding timing is mildly conflicting: BankInfoSecurity reports a May 2025 founding and the Wall Street Journal says Ent launched in 2025, while the company emerged publicly only in mid-2026. The safest canonical description is a 2025-founded, seed-stage private company that operated in stealth for roughly a year before a high-profile 2026 debut. The legal operating entity behind the ent.ai brand has been associated informally with the name Athena Formation Inc., but that is not firmly confirmed in primary disclosures and should be verified against incorporation records. In short, the identity is directionally clear but several basic facts still warrant primary confirmation during diligence.[CO001, CO011, CO013, CO014, CO015, CO016]

Snapshot KPI table
MetricValue / StatusDateConfidenceGap / Notes
Founding2025 (stealth); some sources cite May 20252025mediumWSJ says launched 2025; BankInfoSecurity says founded May 2025.
Emerged from stealthJune 16, 20262026-06-16highBusiness Wire press release and broad syndication.
HeadquartersSan Francisco, California2026mediumSome sources say SF Bay Area; direct confirmation advised.
StageSeed (private)2026-06-16highSingle oversized seed round.
Seed raised$100M2026-06-16highConfirmed by company release and WSJ.
Total raised$100M2026-06-16highOne round to date.
ValuationNo post-money valuation publicly disclosed; unicorn-territory language only.
Headcount~1002026mediumWSJ figure; earlier reports cited fewer pre-hiring.
Revenue / ARRNot disclosed; private seed-stage company.
Customer countNot disclosed; Global 2000 deployments cited without names.
Platform GAWindows, macOS, Linux, browser extensions2026-06-16mediumCompany-stated general availability.

Funding and stealth-exit date are treated as canonical; valuation, revenue, customer count and exact headcount remain private or conflicting and are flagged as gaps.

[CO002, CO011, CO012, CO020, CO021, CO024]
FO003: Snapshot KPIs

Ordinal scorecard converts the chapter's evidence into a fast read on pedigree, capital access, traction signal, disclosure quality and key-person concentration.

[CO005, CO021, CO025, CO031, CO033, CO037]

1.2 Founders, advisory bench and key-person dependence

Ent was co-founded by Elias Manousos and Brandon Dixon, two veterans of RiskIQ. Manousos co-founded and led RiskIQ for roughly fourteen years before Microsoft acquired it in July 2021 in a deal reported at more than $500 million, after which he served as a Microsoft corporate vice president for AI Copilot for Security and threat intelligence. Dixon co-founded PassiveTotal, which RiskIQ acquired, and later worked as a Security AI Strategist at Microsoft where he spearheaded the launch of Microsoft Security Copilot. This is unusually strong founder-market fit for an endpoint and AI-governance security company. That strength carries a corresponding key-person concentration. The two co-founders previously built and sold a company together, and the WSJ-reported headcount of roughly 100 is small relative to incumbents, so execution leans heavily on the founding pair. Ent has bolstered credibility with an advisory bench that it says includes former CISOs of Google, Aetna and MassMutual, a former NSA director, and a former Microsoft corporate vice president for Azure cloud security. Investor leads such as Decibel's Jon Sakoda add governance influence, but the full board composition and which investors hold seats or information rights are not publicly disclosed and remain a diligence item.[CO005, CO006, CO007, CO008, CO009, CO010]

Leadership and founder table
PersonCurrent / recent roleBackgroundFounder-market fit / coverageKey-person dependency
Elias ManousosCo-founder & CEORiskIQ co-founder/CEO ~14 yrs; Microsoft CVP for AI Copilot for SecurityDeep threat-intelligence and security go-to-market pedigreehigh
Brandon DixonCo-founderPassiveTotal co-founder (acquired by RiskIQ); Microsoft Security Copilot leadAI-security product and threat-intelligence depthhigh
Advisory benchStrategic advisorsFormer CISOs of Google, Aetna, MassMutual; former NSA director; former Microsoft CVP Azure cloud securityEnterprise credibility and defense-market accessmedium
Investor leadsBoard / governanceDecibel (Jon Sakoda) led; Sequoia, Crosspoint, Craft, Shield, Felicis, IQT participatedCapital, networks and security-sector expertisemedium

Built from public launch coverage and investor pages; below-founder org structure and exact board composition are not publicly disclosed.

[CO005, CO006, CO009, CO010, CO022, CO023]

1.3 Funding, investors, milestones and disclosure profile

Ent announced $100 million in seed financing on June 16, 2026, led by Decibel with participation from Sequoia, Craft Ventures, Crosspoint Capital Partners, Shield Capital, Felicis and In-Q-Tel. That makes the round one of the largest seed financings in cybersecurity history and brings total capital raised to $100 million across a single round. In-Q-Tel's presence links Ent to U.S. national-security buyers, and Crosspoint adds cybersecurity-specialist private-equity backing. Notably, the company has not disclosed a specific post-money valuation, using only unicorn-territory language, and it has not published revenue, ARR or named customers. The milestone record is compact and concentrated: a 2025 stealth founding, a mid-2026 emergence with simultaneous financing and platform general availability, disclosed Global 2000 deployments in hospitality, financial services and defense, and a planned Black Hat USA 2026 presence in August. Skeptical coverage from The Next Web and DLP Test cautioned that the prevention narrative is no longer contrarian and that intent-detection and low-false-positive claims lack published independent benchmarks. As a result, Ent is best treated as a capital-rich, pedigree-heavy seed company whose narrative currently runs ahead of independently verifiable operating proof.[CO002, CO003, CO004, CO018, CO019, CO020]

Stakeholder or investor map
StakeholderRoleControl / economic importanceDiligence ask
DecibelLead seed investorLargest economic stake; Jon Sakoda board-level influenceConfirm board seat, ownership % and pro-rata rights
SequoiaCo-investorTier-one signaling and follow-on capacityConfirm allocation and any information rights
Crosspoint Capital PartnersCo-investorCybersecurity-specialist PE backing (Greg Clark)Confirm strategic role and governance
Craft VenturesCo-investorEnterprise-software networkConfirm allocation and advisory role
Shield CapitalCo-investorSecurity/national-security focusConfirm defense go-to-market support
FelicisCo-investorGrowth-oriented co-investorConfirm allocation
In-Q-Tel (IQT)Strategic investorLinks Ent to U.S. national-security buyersConfirm strategic agreement scope and any procurement pathway

Investor identities are taken from launch coverage and investor websites; precise ownership percentages and governance terms are private.

[CO003, CO004, CO022, CO029, CO030]
Milestone table
DateEventTypeAmount / Valuation / StatusParticipantsImplication
2025Company founded and operated in stealthfoundingPrivateManousos, DixonTwo-year build before public launch
2025-09Co-founder Brandon Dixon visible as security-AI advisor elsewheregovernancen/aBrandon DixonConfirms founder profile pre-launch
2026-06-16Emerged from stealthproductGA platformEntPublic market entry
2026-06-16Seed financing announcedfinancing$100MDecibel (lead), Sequoia, othersOne of the largest cybersecurity seeds
2026-06-16Platform general availabilityproductWindows/macOS/Linux/browserEntCommercial readiness claimed
2026-06-16Global 2000 deployments disclosedscaleHospitality, finance, defenseEnt customersEarly enterprise traction signal
2026-06Advisory bench unveiledpartnershipn/aEx-CISOs, ex-NSA directorEnterprise and defense credibility
2026-06Skeptical press coverageadversen/aThe Next Web, DLP TestBenchmarks and false-positive claims unproven
2026-08Planned Black Hat USA 2026 presencepartnershipBooth #5341EntGo-to-market visibility step

Single chronology of record for the chapter; 2025 founding day and some 2026 dates are approximate to the reported month.

[CO001, CO002, CO013, CO018, CO024, CO026]
FO001: Company milestone timeline

Ent's public chronology compresses a two-year stealth build into a single high-profile 2026 launch with capital, product GA and early traction announced together.

[CO001, CO002, CO018, CO026, CO035, CO038]
FO002: Company snapshot logic

Ent links a veteran founder pedigree and oversized seed capital to an intent-aware product and early enterprise deployments, with disclosure and key-person dependencies as the main caveats.

[CO005, CO021, CO016, CO018, CO031, CO033]

1.4 Exhibits

Chapter 02

02Market Analysis

2.1 Market boundary, adjacencies and substitutes

Ent sits at the intersection of four security budgets: endpoint security, data loss prevention, insider risk management and the emerging category of AI governance. Drawing the boundary before sizing matters, because Ent is an on-device agent that competes most directly with endpoint protection and EDR for placement on the device, while its differentiated value is in inferring intent for insider risk and governing both human users and AI agents. Gartner's definition of an endpoint protection platform as software deployed on devices to prevent and detect malicious activity anchors the core, and adjacent categories such as UEBA, CASB, EDR and AI governance border the perimeter. On this boundary, the spend Ent can credibly address includes on-device protection, content inspection and exfiltration control, behavioral insider-risk investigation, and controls over AI-agent actions. It excludes network firewalls, pure SIEM, and managed-SOC labor, which are adjacent but not on the endpoint. The status-quo substitutes Ent displaces are legacy DLP suites, EDR alerting workflows and manual insider-risk investigation, all of which the company argues are reactive. XDR and AI-SOC are treated as adjacent rather than core to avoid double counting in the sizing that follows. The practical test for inclusion is whether a budget line is spent on the device or workspace where Ent's agent runs, which keeps the boundary tight and defensible for the diligence reader rather than inflating the headline opportunity with loosely related security spend.[CM001, CM022, CM023, CM025, CM027, CM031]

Market definition table
Segment / categoryIncluded spendExcluded spendBuyer / payerRelevance to Ent
Endpoint security / EPP-EDROn-device protection, detection, responseNetwork firewalls, pure SIEMCISO / security opsCore overlap; Ent is an on-device agent
Data loss preventionContent inspection, exfiltration controlEmail security gateways aloneCISO / complianceDirect use case in Ent's platform
Insider risk managementUser behavior, intent, investigationPhysical securityCISO / insider-risk teamPrimary differentiator for Ent
AI governanceControls over human and AI-agent actionsModel training infrastructureCISO / AI risk ownerEmerging adjacency Ent targets
XDR / AI-SOC (adjacent)Cross-domain correlation, automationManaged SOC laborSecurity operationsBordering category, partial overlap

Boundary is drawn before sizing; XDR/AI-SOC is listed as adjacent rather than core to avoid double counting.

[CM001, CM022, CM023, CM025, CM031]

2.2 TAM, SAM and SOM across multiple lenses

No single TAM number is reliable here, so the chapter triangulates. The global endpoint security market was roughly $18.58 billion in 2025 and about $20.79 billion in 2026, growing near 11.9% toward $32.52 billion by 2030. Within and beside it, EDR is estimated near $6.33 billion in 2026 and growing far faster at about 24% toward $18.68 billion by 2031, while DLP is about $4.67 billion in 2026 growing near 27% toward $12.53 billion by 2030. The broader XDR and AI-SOC opportunity is sized from $33.4 billion in 2025 to $89 billion by 2031, but with the loosest scope. Independent analysts disagree at the margins because they scope these segments differently, and those disagreements are preserved as a diligence item rather than averaged away. Combining endpoint, EDR and DLP gives an order-of-magnitude multi-segment reference above $30 billion before de-duplication, and a defensible 2026 SAM for Ent's combined workspace-security category is roughly $25-30 billion. The obtainable SOM, however, cannot be pinned down: Ent has not disclosed per-endpoint or per-seat pricing, and there is no public Ent-specific SAM or SOM calculation, so the startup-addressable slice remains only partly estimable and rests on category proxies.[CM002, CM003, CM004, CM005, CM006, CM007]

TAM/SAM/SOM or sizing lens table
PublisherSegmentYearValueCAGRConfidenceLimitation
The Business Research CompanyEndpoint security2026$20.79B11.9%highBroad EPP/EDR scope
Research and MarketsEndpoint security2026High-teens to low-$20Bn/amediumRange, not point estimate
Mordor IntelligenceEDR2026$6.33B24.16%mediumSubset of endpoint
The Business Research CompanyDLP2026$4.67B26.9%highExcludes some adjacencies
Fortune Business InsightsDLP2026Growing rapidlyn/amediumQualitative driver framing
HiQual InsightsXDR / AI-SOC2025-2031$33.4B to $89B22.6%lowBroad, adjacent scope
Analyst synthesisCombined workspace SAM2026~$25-30Bn/amediumEstimate; de-duplication required

Multiple lenses are shown rather than one headline TAM; the combined SAM row is an analyst estimate and must be de-duplicated against overlapping segments.

[CM002, CM004, CM006, CM008, CM009, CM010]
FM001: Market sizing lens

Layered view from a multi-segment TAM above $30B down to a combined workspace-security SAM near $25-30B and a presently unquantified startup SOM.

[CM009, CM010, CM032, CM035]
FM002: Market estimate range

Source-backed low/high bounds for four 2026 market quantities, all expressed in USD billions for comparability.

[CM002, CM004, CM006, CM009]

2.3 Buyers, demand drivers and adoption constraints

The economic buyer for Ent is the enterprise CISO, with security operations, IT and compliance as influencers, and budget ownership sitting primarily inside the security organization with overlap into IT and compliance. Ent's disclosed verticals - financial services, hospitality and defense - map to recognizable buying centers and adoption triggers: regulatory and fraud pressure in finance, distributed-workforce risk in hospitality, and national-security mandates in defense. The adoption path typically runs from a targeted pilot through vertical rollout to enterprise-wide deployment, gated by efficacy proof and the consolidation of point tools. On the demand side, AI-accelerated attacks are compressing dwell time and raising the value of prevention, the proliferation of autonomous AI agents is opening a new AI-governance budget line, and tightening data-protection regulation sustains DLP spend; endpoint proliferation and remote work expand the footprint further. The constraints are equally concrete. Microsoft's bundling of Defender into M365 E5 raises switching costs, North America concentrates spend, and skeptical coverage about false positives and unproven benchmarks means trust-based adoption can be slow. The net market read is a large, fast-growing, but incumbent-anchored opportunity where Ent's prevention thesis is most valuable precisely where AI is accelerating attacks.[CM011, CM012, CM013, CM014, CM015, CM016]

Segment / buyer map
SegmentBuyerUserPayerWorkflowAdoption trigger
Financial servicesCISOInsider-risk analystSecurity budgetInsider risk + DLPRegulatory and fraud pressure
HospitalityCISO / ITSOC analystIT/security budgetLast-mile threat preventionDistributed workforce risk
Defense / governmentCISO / security officerThreat hunterProgram budgetAI governance + investigationNational-security mandates
Technology / SaaSCISOSecurity engineerSecurity budgetAI agent governanceAgent proliferation
Regulated enterprise (broad)CISO + complianceCompliance analystCompliance/securityDLP + auditData-protection regulation

Segments are inferred from Ent's disclosed verticals and standard security buying centers; payer lines overlap across IT, security and compliance.

[CM011, CM012, CM024, CM030, CM033]
Growth drivers and constraints table
Driver / constraintDirectionTimingImplicationDiligence ask
AI-accelerated attacksDriverNowRaises value of preventionQuantify dwell-time reduction
AI agent proliferationDriverNow-2027New AI-governance budget lineConfirm agent-governance demand
Data-protection regulationDriverNowSustains DLP spendMap customer compliance triggers
Remote/distributed workDriverStructuralExpands endpoint footprintConfirm per-seat economics
Incumbent bundling (Defender E5)ConstraintNowRaises switching costTest displacement vs add-on
Unproven efficacy / false positivesConstraintNear-termSlows trust-based adoptionDemand independent benchmarks

Drivers and constraints are tied to budget owner and adoption timing; the efficacy constraint reflects skeptical press coverage.

[CM014, CM015, CM016, CM017, CM018, CM019]
FM003: Buyer / segment map

Mapping of Ent's priority verticals to budget owner, adoption trigger and lead use case.

[CM011, CM012, CM030, CM033, CM014]
FM004: Adoption value-chain map

Adoption flows from a targeted pilot through vertical rollout to enterprise-wide deployment, gated by efficacy proof and budget consolidation.

[CM013, CM018, CM019, CM032]

2.4 Exhibits

Chapter 03

03Competitors

3.1 Competitive landscape: direct, incumbent, adjacent and entrants

The competitive landscape Ent enters is crowded and concentrated. Its most direct competitors are endpoint platforms - CrowdStrike Falcon and SentinelOne Singularity - that pair AI-driven detection with autonomous response. The dominant incumbent is Microsoft Defender for Endpoint, distributed through Microsoft 365 E5 bundling, which gives it near-zero marginal cost to a vast installed base. Platform consolidators such as Palo Alto Cortex XDR, alongside established incumbents Broadcom-owned Symantec, Trend Micro Vision One and Cybereason, round out the endpoint field. Bordering Ent's use cases are the data-loss-prevention and insider-risk specialists - Proofpoint, Varonis and DTEX - whose data-security and behavioral-analytics depth overlap with Ent's insider-risk and DLP claims. The status-quo substitute Ent displaces is reactive detection-and-alerting plus manual investigation, which the company frames as too slow for AI-accelerated attacks. Large enterprises could in principle build internal monitoring, but the intent-inference models are difficult to replicate, limiting build-versus-buy substitution. Finally, a cohort of new AI-agent-security entrants is forming to chase the same emerging AI-governance budget Ent targets, making the entrant frontier as important as the established field. In short, Ent is squeezed between deeply funded public platforms above and nimble specialists beside it, so its landscape position is best understood as a new wedge rather than a head-on replacement for any single incumbent category.[CP001, CP002, CP003, CP004, CP005, CP006]

Competitor profile table
CompetitorCategoryScale / fundingTarget customerProduct scopePricing modelStrategic direction
CrowdStrike FalconDirect (cloud EDR)Public, multi-billion revenueEnterpriseEDR, MDR, threat intel~$100+/endpoint/yrAI-driven platform expansion
SentinelOne SingularityDirect (on-device)Public, ~$17B classEnterprise / mid-marketAutonomous EDR, rollback~$80/endpoint/yrOn-device autonomy + data
Microsoft DefenderIncumbentPart of MicrosoftM365 enterprisesEDR via E5 bundleIncluded in E5Windows-native bundling
Palo Alto Cortex XDRAdjacent platformPublic, large capEnterpriseCross-domain XDRPlatform/credit pricingConsolidation play
Broadcom / SymantecIncumbentPart of BroadcomLarge enterpriseEndpoint suiteEnterprise licenseMature install base
Trend Micro Vision OneIncumbentPublicEnterpriseCross-layer XDRSuite licensingBroad XDR coverage
Varonis / DTEXAdjacent (insider risk)Public / privateRegulated enterpriseData + insider riskPer-user/dataInsider-risk depth
ProofpointAdjacent (DLP)Private (Thoma Bravo)EnterpriseHuman-centric DLPPer-userPeople-centric security

Profiles synthesize vendor and analyst material; figures such as per-endpoint pricing are indicative list references, not negotiated enterprise pricing.

[CP009, CP010, CP011, CP012, CP013, CP003]
FP001: Competitive positioning map

Positioning of Ent and peers on breadth of workspace coverage (x) versus intent-awareness depth (y).

[CP001, CP014, CP015, CP030]

3.2 Capability, pricing and go-to-market comparison

On capability, Ent's differentiation is sharp: it claims real-time intent inference rather than after-the-fact signature or behavior matching, and uniquely says it evaluates the intent of both human users and AI agents - a scope no incumbent yet matches. It hosts in the customer's own cloud for data sovereignty, contrasting with the vendor-cloud model of CrowdStrike, SentinelOne and Defender. Both CrowdStrike and SentinelOne, however, push autonomous AI-driven response as their own core differentiator, and incumbents currently have only limited dedicated AI-agent governance, the precise gap Ent attacks. On pricing, the field is well understood while Ent's is not. CrowdStrike Falcon lists at roughly $100 or more per endpoint per year and SentinelOne near $80 for core tiers, while Microsoft Defender is effectively free to E5 holders - a powerful anchor. Ent has disclosed no pricing, so the comparison preserves that gap explicitly. On go-to-market, Microsoft and CrowdStrike wield outsized distribution through existing enterprise relationships, whereas Ent must sell a new agent into security organizations one vertical at a time. On trust and regulatory posture, Ent's customer-cloud hosting is a credible advantage for regulated buyers wary of vendor-cloud data exposure, and it may also ease procurement in defense and financial-services accounts where data-residency requirements complicate adopting vendor-hosted security telemetry.[CP010, CP012, CP013, CP014, CP015, CP016]

Feature / capability matrix
CapabilityEntCrowdStrikeSentinelOneMS DefenderDLP/insider peers
On-device AI inferenceYesPartial (cloud-first)YesPartialNo
Real-time intent inferenceYes (core)NoLimitedNoLimited
Human + AI-agent coverageYesNoNoNoNo
Prevention-first postureYesDetection-ledDetection + responseDetection-ledPolicy-based
Customer-cloud hostingYesVendor cloudVendor cloudVendor cloudMixed
DLP + insider-risk in one agentYesAdd-onAdd-onVia PurviewSpecialized

Capability claims for Ent are company-stated and not yet independently benchmarked; competitor cells reflect publicly documented positioning.

[CP014, CP015, CP016, CP028, CP025, CP033]
Pricing / packaging comparison
VendorPricing modelIndicative listBundlingNotes
CrowdStrikePer-endpoint subscription~$100+/endpoint/yrModular add-onsTier upsell to platform
SentinelOnePer-endpoint tiered~$80/endpoint/yrCore/Control/CompleteRollback in higher tiers
Microsoft DefenderBundledIncluded in M365 E5E5 suiteMarginal cost near zero for E5 holders
Palo Alto CortexPlatform / creditsCustomXDR platformConsolidation discounts
EntUndisclosed (per-seat/endpoint likely)Not disclosedSingle agentPricing not public at launch

Ent has not disclosed pricing; competitor figures are indicative public references and vary widely by negotiation and volume.

[CP010, CP012, CP013, CP020, CP035]
FP002: Feature breadth / capability map

Capability coverage across Ent and the three leading endpoint incumbents.

[CP014, CP024, CP025, CP035]

3.3 Switching costs, moat durability and displacement risk

Endpoint security carries high switching costs because agents are deployed fleet-wide and wired into SOC workflows, and incumbent bundling - Microsoft's above all - creates lock-in that raises the bar for any displacer. At the same time, enterprises frequently multi-home endpoint, DLP and insider-risk tools, which leaves room for a consolidating entrant that can fold several point capabilities into one agent. Ent's competitive readiness rests on a strong founder pedigree, a $100 million war chest and early Global 2000 deployments across finance, hospitality and defense. The durability of Ent's moat is the central question. Its intent-inference models and human-plus-AI-agent scope are genuinely novel, but they are vulnerable to fast-following incumbents who could embed similar capabilities, and skeptical coverage notes that prevention messaging is no longer contrarian and that Ent has published no independent benchmarks. The weakest moat factor is distribution, where Microsoft and CrowdStrike dominate. The net verdict is that Ent holds a real product wedge that is unproven at scale; it must win on demonstrable efficacy and rapid time-to-value rather than price to overcome incumbent distribution and lock-in. Should it fail to publish convincing efficacy evidence quickly, the most likely outcome is that incumbents absorb the intent-aware concept and Ent is relegated to a niche, which is the core competitive risk a diligence reader must weigh.[CP017, CP018, CP019, CP021, CP022, CP026]

Moat durability / competitive risk register
Moat / risk factorStrength for EntCompetitive threatDurability
Intent-inference modelsHigh (novel)Incumbents fast-followMedium
Human + AI-agent scopeHighPlatform vendors extendMedium
Founder pedigree + capitalHighTalent and capital are broadly availableMedium-high
Customer-cloud sovereigntyMediumIncumbents add sovereign optionsMedium
Distribution / install baseLow (new entrant)Microsoft / CrowdStrike dominanceLow

Durability ratings are analyst judgments; the distribution row is Ent's weakest moat given incumbent bundling and install base.

[CP021, CP022, CP018, CP026, CP032]
FP003: Moat / readiness KPIs

Key competitive-readiness indicators for Ent at launch.

[CP026, CP022, CP036]

3.4 Exhibits

Chapter 04

04Financials

4.1 Revenue model, pricing and go-to-market

Ent runs a SaaS subscription business, most likely priced per endpoint or per seat, though it has disclosed no pricing or list rates at launch. Its revenue mix is presently concentrated in early Global 2000 deployments across financial services, hospitality and defense, with an AI-governance module and professional-services onboarding as emerging and prospective streams. Because the platform is hosted in each customer's own cloud, enterprise onboarding is a real services component rather than a pure self-serve motion. The go-to-market is a direct enterprise motion selling into CISO security organizations. That motion carries the sales-efficiency drag typical of enterprise security, where cycles commonly run six to twelve months or longer. At seed stage these efficiency measures are unobservable externally, so only proxies from comparable cloud and security SaaS apply. Reference pricing from incumbents - roughly $100 or more per endpoint per year for CrowdStrike, near $80 for SentinelOne core tiers, and effectively bundled for Microsoft Defender within E5 - frames Ent's likely per-endpoint monetization, but Ent's own economics remain undisclosed and must be obtained directly in diligence. The practical implication is that, at this stage, revenue modeling for Ent is necessarily a scenario exercise anchored to comparable per-endpoint economics rather than to any figure the company itself has confirmed.[CI001, CI002, CI003, CI004, CI005, CI012]

Revenue streams table
StreamModelStatusBasis of estimateConfidence
Core platform subscriptionSaaS per endpoint/seatLive (undisclosed terms)Company model + analyst normsmedium
AI governance moduleSubscription add-onRoadmap / emergingPress release roadmaplow
Professional services / onboardingServicesLikely at enterprise scaleCustomer-cloud deployment needlow
Expansion (modules, seats)Land-and-expandProspectiveComparable SaaS patternlow

All streams are inferred from the company's stated model and comparable security SaaS; Ent has not published revenue by stream.

[CI001, CI003, CI012, CI027]
Pricing / monetization table
Vendor / modelUnitIndicative rateDisclosure
Ent (likely)Per endpoint or seatNot disclosedNone at launch
CrowdStrike (reference)Per endpoint/yr~$100+Public list references
SentinelOne (reference)Per endpoint/yr~$80Public list references
Microsoft Defender (reference)BundledIncluded in E5Public

Ent's pricing is undisclosed; competitor rates are indicative public references used only to frame Ent's likely monetization.

[CI002, CI027, CI020]
FI001: Revenue model bridge

Qualitative bridge from Ent's deployed agents through subscription and expansion to recurring revenue.

[CI001, CI020, CI027, CI028]

4.2 Cost structure, unit economics and public traction

On cost structure, an on-device SaaS agent can achieve high software gross margins once delivery scales - comparable security SaaS companies report margins commonly in the 70-80%-plus range. Ent's customer-cloud hosting shifts some infrastructure cost to the customer, which can help hosting gross margin, but it adds non-trivial onboarding and support cost for each enterprise deployment. The most capital-intensive element is building proprietary intent-inference AI models, which is talent- and research-intensive and front-loads cost ahead of revenue. On public traction, Ent has disclosed roughly 100 employees and general availability across Windows, macOS, Linux and browser extensions, but no revenue, ARR, burn or margin figures - all of which are private at seed stage. Third-party trackers list it as an early-stage, recently funded company without financial detail. Comparable benchmarks are demanding: category-defining security startups such as Wiz reached $100 million ARR in roughly eighteen months, and CrowdStrike and SentinelOne show subscription endpoint security scaling to billions in high-margin recurring revenue. Ent's potential is real, but its actual unit economics are presently unmeasurable from public evidence, so any contribution-margin or payback estimate carried here should be treated strictly as a comparable-derived placeholder pending management data.[CI006, CI007, CI008, CI009, CI016, CI017]

Unit economics table
MetricEstimate / proxyBasisConfidenceDiligence ask
Gross margin70-80%+ at scaleComparable security SaaSmediumConfirm hosting cost split
Sales cycle~6-12+ monthsEnterprise security normmediumConfirm pipeline velocity
CAC paybackNot estimableNo disclosed CAC/ARRlowRequest CAC and payback
Net revenue retentionNot disclosedSeed stagelowRequest NRR once live
Burn rateHigh (est.)~100 staff + AI R&DlowRequest monthly burn

Unit economics are proxies from comparable SaaS, not Ent disclosures; every row carries an explicit diligence ask.

[CI005, CI006, CI016, CI017, CI032]
FI002: Unit economics bridge

Bridge from list price through delivery and support costs to gross and contribution margin for an on-device SaaS agent.

[CI006, CI007, CI016, CI031]
FI003: Financial estimate range

Estimated ranges for capital, runway and margin, all flagged low-confidence given undisclosed actuals.

[CI010, CI011, CI016, CI005]

4.3 Capital adequacy, runway and financial verdict

Ent has raised $100 million in seed financing - its only disclosed round - led by Decibel with a tier-1 syndicate. At a typical burn for a roughly 100-person security startup investing heavily in AI R&D, that capital implies an estimated eighteen-to-twenty-four-month runway, sensitive to hiring pace, with proceeds most likely directed to engineering, model development, go-to-market and enterprise support. No debt or project-finance obligations have been disclosed. The next financing round will most plausibly be triggered by demonstrated Global 2000 traction and ARR milestones, and the robust cybersecurity funding climate supports Ent's ability to raise follow-on capital. The financial verdict is that Ent is well-capitalized but evidence-thin. Revenue quality is unproven, resting on early deployments rather than disclosed recurring revenue, and a $100 million seed sets a high performance bar with elevated burn expectations - skeptical coverage warns the round compresses the margin for execution error. The principal diligence blockers are undisclosed pricing, revenue, ARR, burn rate, runway and valuation. The financing dependency is therefore high until Ent demonstrates recurring revenue, making ARR milestones the decisive metric for the next round. Taken together, the chapter's financial read is that capital adequacy is a present strength while revenue quality and burn discipline remain unverified, and both must be confirmed before any valuation or return conclusion can be defended.[CI010, CI011, CI013, CI014, CI015, CI018]

Capital adequacy table
ItemValue / estimateBasisNote
Total raised$100M (seed)Press releaseOnly disclosed round
Lead investorDecibelPress releaseTier-1 syndicate
Estimated runway~18-24 monthsBurn proxySensitive to hiring pace
Use of fundsEng, AI, GTM, supportInferredNot itemized publicly
Debt / project financeNone disclosedDisclosure absenceConfirm in diligence

Runway and use of funds are estimates; only the $100M raise and lead investor are firmly disclosed.

[CI010, CI011, CI012, CI014, CI029]
Public financial gaps table
Missing metricWhy it mattersDiligence pathSeverity
Revenue / ARRCore to valuation and tractionRequest audited or management ARRmaterial
Pricing / list ratesDrives revenue model and SOMRequest price bookmaterial
Burn rate / runwayDetermines financing urgencyRequest monthly burn and cashmaterial
Post-money valuationSets dilution and return mathRequest cap table / 409Amaterial
Gross margin actualsValidates SaaS economicsRequest COGS breakdownmoderate

This table enumerates the principal undisclosed financial facts; each is private-evidence-only at seed stage.

[CI009, CI018, CI025, CI030, CI036]
FI004: Capital intensity / cash-flow map

Key capital and cash indicators for Ent at seed stage.

[CI017, CI030, CI035, CI036]

4.4 Exhibits

Chapter 05

05Product & Technology

5.1 Product definition, modules and use cases

In customer-workflow terms, Ent is a lightweight on-device AI agent that watches how people and AI agents act in the workspace and steps in just in time to prevent a security incident before it completes. It observes signals across the browser, applications, workflows and data movement, then evaluates intent rather than waiting for a known-bad signature. Its core modules are a workspace observer, an intent-inference engine built on specialized small AI models, a policy-enforcement layer, an intervention layer and a forensic record that supports later investigation. The platform targets five primary use cases: insider-risk detection, AI governance, data loss prevention, last-mile threat prevention and incident investigation. In each, the agent observes an action - a user exfiltrating data, an AI agent taking a risky step, sensitive data moving, a compromised session acting - infers whether intent is malicious, and intervenes by blocking, warning or permitting, while writing a forensic timeline. Governing the intent of AI agents specifically is a distinguishing capability, aligning with emerging guidance from OWASP's LLM and agent risk work and the Cloud Security Alliance, as autonomous agents introduce new attack surfaces that motivate runtime governance. Read end to end, the product is best understood not as another detector but as a real-time decision layer that sits between a workspace action and its consequence, which is what makes the intent framing more than a marketing label.[CE001, CE002, CE003, CE004, CE011, CE012]

Product module / asset matrix
ModuleFunctionSignals / inputsMaturity
Workspace observerMonitor activityBrowser, apps, workflows, data movementGA
Intent-inference engineEvaluate intentBehavioral signals, small AI modelsGA
Policy enforcementApply controlsOrg policy, risk contextGA
Intervention layerJust-in-time actionReal-time intent verdictGA
Forensic recordInvestigationCaptured activity timelineGA

Module list and inputs are company-stated; maturity is inferred from the general-availability announcement.

[CE002, CE003, CE004, CE011, CE012]
Workflow / use-case table
Use caseCustomer workflowEnt actionOutcome
Insider-risk detectionUser exfiltrates dataInfer malicious intent, intervenePrevent exfiltration
AI governanceAI agent takes risky actionEvaluate agent intent, gate actionGoverned agent behavior
Data loss preventionSensitive data movesDetect at point of actionBlock / warn
Last-mile threat preventionCompromised session actsJust-in-time interventionStop incident early
Incident investigationAnalyst reviews eventProvide forensic recordFaster investigation

Use cases and actions are drawn from Ent's own descriptions; outcomes are the company's stated objectives, not benchmarked results.

[CE013, CE011, CE021, CE023, CE024]
FE002: Customer workflow / operating flow

How a risky workspace action flows through observation, intent scoring and just-in-time intervention to a forensic record.

[CE011, CE013, CE023, CE032]

5.2 Architecture, deployment, dependencies and roadmap

Architecturally, Ent is a hybrid edge-plus-cloud design: AI inference models run on the device for low-latency, real-time intent scoring, while the control plane, storage and forensic record live in the customer's own cloud to preserve data sovereignty. The agent is generally available across Windows, macOS, Linux and browser extensions, and deploys as a lightweight component that integrates into existing enterprise endpoints and security workflows. Its critical dependencies are the endpoint operating systems, browser-extension APIs, local device compute and the customer's cloud environment, and like any EDR-class agent it must balance observability against device resource use. The roadmap, as described at launch, spans AI governance, threat prevention, security integrations - connecting to SIEM, SOAR and identity systems - and multimodal endpoint intelligence that would extend observation to richer signals. Shipping across four endpoint surfaces at general availability indicates meaningful engineering maturity, and the on-device approach reduces cloud round-trips, supporting the company's sub-second intervention claims. Still, the planned integration and multimodal items are directional rather than shipped, so the maturity assessment separates what is generally available today from what remains prospective on the roadmap. Hiring activity across security research, AI engineering and platform roles is a further developer-side signal that build velocity is being sustained after launch rather than tapering.[CE005, CE006, CE007, CE008, CE024, CE025]

Technology / operating architecture table
LayerWhere it runsRoleDependency
On-device agentEndpointObserve + infer intentOS / browser APIs
AI inference modelsOn-deviceReal-time intent scoringLocal compute
Control / management planeCustomer's cloudPolicy, storage, adminCustomer cloud env
Forensic storeCustomer's cloudActivity timelineCustomer storage
Integrations (roadmap)Customer's cloudSIEM/SOAR/identity linksThird-party APIs

Architecture is a hybrid edge-plus-cloud design inferred from company material; integration layer is roadmap rather than fully shipped.

[CE005, CE024, CE025, CE030, CE031]
Roadmap / release / development-stage table
Roadmap itemStageDescriptionSignal
Core platform (4 surfaces)GAWindows, macOS, Linux, browserLaunch announcement
AI governanceActiveGovern human + AI-agent intentPress release
Threat preventionActiveLast-mile preventionPress release
Security integrationsPlannedSIEM/SOAR/identity linksPress release
Multimodal endpoint intelligencePlannedRicher signal observationPress release

Roadmap stages are inferred from the launch announcement; planned items are directional and not yet shipped.

[CE008, CE026, CE029, CE030]
FE001: Product architecture map

Hybrid architecture: an on-device agent observes and infers intent locally, while policy, storage and forensics run in the customer's own cloud.

[CE002, CE004, CE005, CE024]
FE003: Critical dependency map

Ent's runtime depends on endpoint OSes, browser APIs, local compute and the customer's cloud environment.

[CE005, CE025, CE034]

5.3 Differentiation, trust, privacy and compliance

Ent's technical differentiation is inferring intent in real time across both human users and AI agents, rather than matching known-bad signatures after the fact, and it positions this as a complement that can sit alongside existing EDR. The proprietary asset underpinning the approach is its workspace-behavior training data, and intent-based controls map conceptually to behavior-analytics techniques catalogued in MITRE ATT&CK. The clearest risk is efficacy: real-time intent inference can produce false positives that disrupt legitimate activity, and no independent third-party benchmark of Ent's accuracy has been published, leaving real-world efficacy externally unvalidated. On trust and compliance, customer-cloud hosting keeps sensitive telemetry inside the customer's environment, supporting data-residency requirements, while privacy and data-minimization controls are essential for lawful employee monitoring. Recognized control catalogs such as NIST SP 800-53 define the access, audit and monitoring expectations enterprise buyers bring, and aligning to OWASP, CSA AI guidance and MITRE ATT&CK is how Ent can make a novel approach auditable. The net read is a credible, well-architected platform with a genuine wedge whose differentiation is strong but whose efficacy and privacy posture still require independent verification.[CE009, CE010, CE014, CE015, CE016, CE019]

Trust / quality / compliance table
Control areaApproachFramework referenceStatus / gap
Data sovereigntyCustomer-cloud hostingNIST SP 800-53 controlsCompany-stated
Employee privacyData minimization (claimed)Privacy-by-design normsNeeds verification
AI-agent governanceRuntime intent evaluationOWASP LLM / CSA AI guidanceEmerging
Detection efficacyIntent modelsMITRE ATT&CK mappingNo independent benchmark
Audit / forensicsForensic recordAudit-control expectationsCompany-stated

Compliance posture maps Ent's claims to recognized frameworks; the efficacy and privacy rows carry explicit verification gaps.

[CE014, CE016, CE017, CE020, CE022]
FE004: Product maturity / capability map

Maturity and differentiation of Ent's key capabilities at general availability.

[CE009, CE020, CE026, CE036]

5.4 Exhibits

Chapter 06

06Customers

6.1 Customer base segmentation and vertical evidence

Ent disclosed on stealth exit in June 2026 that its platform is deployed across Global 2000 enterprises in three verticals: hospitality, financial services, and defense. These three segments represent Ent's stated early adopter base and define the credible customer scope for diligence. The economic buyer in all three is the enterprise CISO, with security operations and compliance functions as co-stakeholders. The payer sits primarily within the CISO's security budget, with partial overlap into IT and compliance program funds depending on the use case. Financial services is the strongest signal vertical: a public institution's insider-threat lead provided the only named testimonial in public evidence, citing low time-to-value. Financial institutions are also the most active buyers of insider-threat tooling across the industry, driven by regulatory pressure, fraud risk, and the high cost of insider-driven breaches. Hospitality maps to Ent's last-mile threat-prevention use case, where distributed workforces and high data-access density create acute endpoint risk. Defense is the most strategically distinctive vertical: In-Q-Tel's participation in the seed round provides an implicit validator for the national-security applicability of the platform, and CISA guidance confirms that federal agencies actively build insider-threat detection programs across the lifecycle. The global enterprise security market context confirms structural demand across all three verticals. IBM's data breach research shows that organizations using AI-driven security tools achieve substantially lower breach costs and faster containment, while Verizon's DBIR confirms that a meaningful share of breaches involve internal actors through error, misuse, or compromised credentials. These independent data points validate Ent's buyer problem thesis even if they do not directly corroborate Ent's specific deployments. Beyond the three disclosed verticals, technology and SaaS enterprises are a logical next segment given the AI-agent governance use case, but no customer evidence for that vertical exists publicly as of June 2026.[CU001, CU005, CU006, CU007, CU009, CU010]

Customer segmentation table
SegmentBuyer / payerUserUse caseScaleEvidence quality
Financial servicesCISO / security budgetInsider-risk analyst / SOCInsider risk detection, DLPGlobal 2000Customer quote (anonymous)
HospitalityCISO / IT budgetIT security analystLast-mile threat preventionGlobal 2000Company assertion only
Defense / governmentCISO / program budgetThreat hunter / complianceAI governance, investigationGlobal 2000 / national-securityInferred from IQT investor
Technology / SaaS (inferred)CISO / security budgetSecurity engineerAI agent governanceGlobal 2000 (inferred)No direct customer evidence
Regulated enterprise (broad)CISO + complianceCompliance analystDLP + audit trailEnterpriseMarket-level context only

Segments are drawn from Ent's public stealth-exit disclosure plus market-level inference; only hospitality, financial services and defense are company-asserted. Technology/SaaS and broad regulated enterprise are analyst-inferred.

[CU001, CU005, CU006, CU009, CU021, CU032]
FU001: Customer journey map

Illustrative journey from CISO awareness through pilot, production deployment, and expansion to AI agent governance coverage.

Journey stages are inferred from Ent's disclosed deployments and enterprise security market norms; timing is not publicly documented.

[CU022, CU031, CU035, CU038]

6.2 Adoption trajectory and named customer proof

Ent's public adoption evidence is narrow but strategically credible. The company asserted on stealth exit that its platform is in production across Global 2000 enterprises, which implies real deployments existed before the June 2026 announcement. However, no specific customer count, ARR figure, or deployment breadth metric has been disclosed. The stealth period itself signals that Ent had paying customers before public launch — a positive signal versus a pre-revenue launch, but one that cannot be assessed for scale or durability without private data. The named customer proof set is limited to a single anonymous testimonial: an insider-threat lead at a public financial institution who described Ent as the first tool where they felt like an expert on day one. This quote indicates low time-to-value and ease of use, two critical buying criteria in enterprise security, but it is a single data point from an unidentifiable source. No case studies, deployment scale figures, outcome metrics, or reference accounts are publicly available. The three disclosed verticals — hospitality, financial services, and defense — are named in Ent's press release and picked up by multiple independent outlets including TechCrunch, VentureBurn, SiliconANGLE, and CityBiz, confirming the disclosure was intentional and widely covered. However, the verticals are stated as categorical rather than enumerated accounts, leaving the depth of each deployment unknown. TechCrunch characterized Ent as having deployed the platform across Global 2000 enterprises before going public, and VentureBurn noted early enterprise customers in regulated industries. SiliconANGLE similarly reported a base of Global 2000 customers before stealth exit. This convergence across independent outlets on the same company-provided framing increases confidence in the claim's existence, though it does not independently validate its depth or the distinction between production deployments and active evaluations. The evidence freshness is high — all proof dates from the June 2026 launch window — but the volume is thin. Diligence must treat the current proof set as a starting point, not a validation baseline.[CU001, CU002, CU003, CU004, CU015, CU016]

Customer growth and adoption trajectory table
MetricValue / statusDateSourceConfidenceImplication
Named vertical segments3 (hospitality, financial services, defense)Jun 2026Ent press releasehighMulti-vertical early traction confirmed
Customer count (disclosed)Not disclosedJun 2026Ent press releasehighNo public count; gap for diligence
Deployment scopeGlobal 2000 enterprisesJun 2026Ent press releasemediumLarge-enterprise targeting confirmed
Customer testimonials (public)1 anonymous (financial institution)Jun 2026BankInfoSecurity articlehighThin proof set; expansion expected
Stage at stealth exitPaying customers in production (implied)Jun 2026Multiple independent outletsmediumPre-announcement deployments implied
Contract or ARR dataNone disclosedJun 2026No public sourcehighFinancial depth unknown

Adoption metrics reflect only public stealth-exit evidence as of June 2026; customer count, ARR, and NRR are undisclosed.

[CU001, CU002, CU015, CU030, CU037, CU039]
Named customer proof table
CustomerSegmentDeployment / use caseStatusOutcome / quoteLimitation
Public financial institution (anonymous)Financial servicesInsider risk detectionProduction (implied)First tool where I felt like an expert on day oneName undisclosed; depth unknown
Global 2000 hospitality enterprise (anonymous)HospitalityLast-mile threat preventionProduction (claimed)No public outcome statementName and scale undisclosed
Global 2000 defense enterprise (anonymous)Defense / governmentAI governance + investigationProduction (claimed)No public outcome statementName and classification level undisclosed

All named customers are anonymous as of June 2026. Outcomes are limited to one anonymous quote; no case studies, ROI figures, or retention data are public.

[CU001, CU003, CU015, CU016, CU033, CU034]
FU002: Adoption and deployment funnel

Discovery-to-expansion funnel for Ent enterprise accounts, from CISO awareness through full workspace deployment.

Funnel volumes are illustrative only; Ent has not disclosed customer counts. Numbers represent a plausible scale for a seed-stage Global 2000 vendor, not confirmed figures.

[CU001, CU002, CU022, CU029, CU037]

6.3 Retention, durability, satisfaction, and concentration risk

Retention and durability evidence for Ent is entirely absent from the public record. No NRR, GRR, cohort data, or contract-length information has been disclosed. The single positive customer testimonial is insufficient to infer retention — it speaks to ease of initial use, not sustained engagement or renewal behavior. No G2, Capterra, or Gartner Peer Insights review entry exists for Ent as a specific product, which is expected given its June 2026 emergence from stealth and the typical lag before enterprise review platforms accumulate ratings for new products. Buyer satisfaction at the market level is directionally positive for Ent's positioning: CSO Online reports that security buyers favor consolidated insider-risk, DLP, and AI-governance platforms; Help Net Security notes demand for measurable time-to-investigate reductions; and the Gartner Peer Insights EDR review corpus emphasizes efficacy, deployment ease, and false-positive rates as the top buyer criteria. Ent's anonymous customer quote directly addresses deployment ease, suggesting alignment with market-level buyer expectations. However, The Next Web and DLP Test both raised the absence of independent benchmarks for intent-inference accuracy as a credibility concern, and buyer caution around unproven prevention tools is a documented adoption risk in the DLP market. Expansion potential is real but undocumented at the account level. Enterprise DLP consolidation trends in 2026 favor Ent's integrated-platform approach, and the proliferation of AI agents within enterprise workspaces creates a structural upsell opportunity for the AI governance module. Ent's on-device, customer-cloud deployment model reduces data-sovereignty friction for regulated buyers, which is a genuine procurement advantage. However, concentration risk and channel dependence are structurally opaque. With three disclosed verticals and no customer count, it is impossible to assess whether Ent's revenue is evenly distributed or concentrated in one anchor segment. The absence of a disclosed channel or reseller program implies a direct enterprise sales motion, adding sales-cycle risk as the company scales. Procurement friction in regulated industries — including data residency audits, security reviews, and multi-stakeholder approvals — can extend enterprise sales cycles significantly and must be factored into CAC and payback modeling.[CU015, CU017, CU018, CU023, CU024, CU025]

Retention, satisfaction, and durability table
MetricValue / nullSegmentConfidenceDiligence ask
Net revenue retention (NRR)Not disclosedAllhighRequest NRR from Ent under NDA; industry benchmark is 120%+
Gross retention rate (GRR)Not disclosedAllhighRequest GRR; minimum for healthy SaaS is >90%
Customer satisfaction (CSAT)Positive anecdote (1 quote)Financial serviceslowSeek additional testimonials and G2 / Gartner Peer Insights reviews
Contract lengthNot disclosedAllhighConfirm 1- vs 3-year terms; longer = lower churn risk
Known churn or non-renewalNone publicly reportedAllmediumAbsence of public churn is not confirmation of retention

Not-disclosed values indicate metrics withheld or never released as of June 2026. Confidence column reflects evidence quality, not performance expectation. A single positive anecdote does not confirm aggregate satisfaction.

[CU015, CU023, CU027, CU033, CU034]
Expansion and concentration risk table
FactorRisk / driverImpactEvidence basisDiligence path
Vertical concentration3 verticals; possible over-reliance on financial servicesHighCompany-disclosed segment listMap revenue split across verticals under NDA
Customer count concentrationUnknown; if 1–3 anchor accounts, churn is materialHighNo count disclosedRequest ARR by customer cohort
Land-and-expand potentialAgent proliferation creates AI-governance upsellPositiveEnt product roadmap and positioningConfirm expansion unit pricing
Partner / channel dependenceNo public reseller or channel program disclosedMediumNo press or partner announcementsConfirm direct-sales vs channel split
Procurement frictionRegulated buyers require data residency audits and security reviewsMediumCIO Dive and CISA guidanceDocument typical sales cycle length and blockers

Concentration risks are inferred from the narrow set of disclosed customer evidence; no financial data underpins the impact ratings.

[CU028, CU029, CU036, CU038, CU040]
FU003: Customer proof quality matrix

Evidence quality, deployment status, outcome specificity, and retention visibility for each disclosed customer segment.

[CU003, CU016, CU033, CU025, CU023]
FU004: Enterprise security SaaS retention cohort benchmarks

Illustrative retention benchmarks for enterprise security SaaS; Ent-specific retention data is entirely absent from public evidence and must be requested under NDA.

All three rows are illustrative benchmarks derived from publicly available security SaaS retention data; no Ent-specific retention figures exist in public evidence.

[CU015, CU027, CU034]

6.4 Exhibits

Chapter 07

07Risks

7.1 Regulatory and legal risk

Ent's single largest structural exposure is regulatory. Because the platform monitors how employees and AI agents act on the endpoint, it triggers significant privacy and data-protection obligations across multiple regimes simultaneously. In the EU, GDPR constrains workplace monitoring through purpose-limitation, proportionality and lawful-basis requirements, and the European Data Protection Board has issued guidance restricting intrusive employee monitoring. The EU AI Act adds a second layer: intent-inference systems could be classified as higher-risk, raising documentation and conformity costs. NIST's AI Risk Management Framework signals the governance expectations regulators will increasingly apply. In the United States, state privacy laws such as the CCPA grant data rights over monitoring data, and the FTC has a track record of enforcement against unfair or deceptive data practices. Civil-liberties groups warn that pervasive workplace surveillance carries legal and reputational risk. This regulatory complexity is genuinely global and concurrent, spanning EU GDPR and the AI Act alongside US state and federal regimes, and AI-agent governance is an emerging frontier where rules are still forming, creating compliance uncertainty. Insider-threat programs also face heightened government scrutiny, which is simultaneously a demand driver and a compliance obligation. A documented privacy and AI-governance posture is therefore essential, yet Ent has disclosed none publicly.[CR002, CR003, CR004, CR005, CR006, CR007]

Regulatory / legal risk register
Regime / areaRiskLikelihoodImpactMitigation
EU GDPRUnlawful employee monitoringMediumHighDPIA, lawful basis, minimization
EU AI ActIntent models deemed higher-riskMediumHighAI governance, documentation
US CCPA / state lawsData-rights non-complianceMediumMediumData-subject controls
FTC enforcementUnfair/deceptive data practiceLowHighTransparency, accuracy
Employee-monitoring lawSurveillance overreach claimsMediumMediumConsent, governance

Register enumerates the principal disclosed regulatory exposures for endpoint monitoring; coverage is partial as specific jurisdictional exposure depends on customer geography.

[CR002, CR003, CR005, CR006, CR007, CR008]
FR003: Dependency map

Ent's external dependencies on customer cloud, endpoint platforms, capital providers and the regulatory environment.

[CR013, CR028, CR032, CR035]

7.2 Operational, dependency and competition risk

Operationally, the dominant risk is efficacy. Real-time intent inference can produce false positives that block legitimate work and erode trust, and Ent's sub-second inference and accuracy claims have not been independently benchmarked - the reason the efficacy risk is rated high-likelihood and high-impact. A fleet-wide on-device agent also carries reliability and performance risk if it degrades devices or fails, and the threat environment of costly breaches and shrinking dwell time validates demand while raising the stakes of getting prevention wrong. Verizon breach data shows human-driven and credential-based incidents remain dominant, and IBM data shows multimillion-dollar average breach costs, both reinforcing the value but also the consequence of failure. On dependencies and competition, Ent relies on each customer's cloud to host its control plane and forensic store, and on endpoint operating-system and browser APIs that could change. The most acute dependency is competitive: Microsoft and CrowdStrike pose concentrated risk through distribution and bundling, and competition risk compounds execution risk because incumbents can out-distribute Ent while it must still prove efficacy. Data-sovereignty obligations in defense and finance could further constrain deployments. Risks also transmit across domains - a privacy enforcement action or efficacy failure could stall sales, raise burn and force a financing event - so these exposures cannot be assessed in isolation.[CR010, CR011, CR012, CR013, CR014, CR022]

Operational / quality / security risk register
RiskDescriptionLikelihoodImpact
False positivesIntent model blocks legitimate workMediumHigh
Unproven efficacyNo independent benchmarksHighHigh
Agent reliabilityFleet-wide performance/failureMediumMedium
Data securitySensitive telemetry exposureLowHigh
Latency claimsSub-second inference unverifiedMediumMedium

Operational risks center on model efficacy and agent reliability; the efficacy row is rated high-likelihood because no external benchmark exists.

[CR010, CR011, CR012, CR023]
Partner / dependency risk register
DependencyRiskExposureMitigation
Customer cloudControl plane hosted in customer envMediumStandardized deployment
Endpoint OS / browser APIsPlatform API changes break agentMediumMulti-OS engineering
Incumbent competitionMicrosoft/CrowdStrike bundlingHighDifferentiation, time-to-value
Capital providersFollow-on financing neededMediumTier-1 investor syndicate

Dependency risks span infrastructure, platform APIs, competitive distribution and capital; the incumbent row is the most acute.

[CR013, CR014, CR028, CR035]
FR001: Risk heatmap

Likelihood-by-impact placement of Ent's principal risks, surfacing efficacy, regulatory and competition as the highest-priority cells.

[CR001, CR011, CR014, CR015]
FR002: Risk transmission map

How a shock in one domain propagates: a privacy action or efficacy failure cascades into stalled sales, higher burn and financing stress.

[CR022, CR029, CR037, CR042]

7.3 People, financial risk and mitigations

On people and execution, key-person dependence on co-founders Elias Manousos and Brandon Dixon is acute for a roughly 100-person company, and a $100 million seed sets a high performance bar with elevated burn that is itself an execution risk if traction lags. Expanding beyond three verticals strains a small team, and the single anonymous customer reference leaves execution evidence thin. Financially, model risk is high because revenue, pricing and unit economics are undisclosed, and burn-and-runway risk is material against an estimated eighteen-to-twenty-four-month runway. Reputational risk is elevated by skeptical coverage questioning whether the prevention claims are truly differentiated. These risks have real offsets and mitigations. The founders' Microsoft and RiskIQ pedigree partially mitigates execution and credibility risk, a tier-1 investor syndicate eases financing risk while raising valuation expectations, and customer-cloud hosting plus an advisory board including a former NSA director and former CISOs help navigate regulation and sovereignty. But mitigation ultimately depends on demonstrable efficacy evidence Ent has not yet published. Investors should monitor false-positive rates, deployment renewals, regulatory filings and competitor releases, and treat sustained false-positive complaints, a privacy enforcement action, incumbent feature parity or a failed marquee deployment as explicit thesis-break triggers. Overall, the profile is high-variance: a credible team and capital set against unproven efficacy, heavy regulation and dominant incumbents.[CR015, CR016, CR017, CR018, CR019, CR020]

People / execution risk register
RiskDescriptionLikelihoodImpact
Key-person dependenceTwo founders centralMediumHigh
High execution bar$100M seed expectationsMediumHigh
Vertical expansionScaling beyond 3 verticalsMediumMedium
Thin proofSingle anonymous referenceMediumMedium

Execution risk is amplified by the outsized seed and thin public proof; founder pedigree is a partial offset.

[CR015, CR016, CR030, CR039]
Mitigation and kill criteria table
Risk areaMitigationMonitoring indicatorThesis-break trigger
EfficacyPublish benchmarksFalse-positive rateSustained FP complaints
RegulatoryDPIA + AI governanceRegulatory filingsEnforcement action
CompetitionDifferentiation + speedCompetitor releasesIncumbent feature parity
ExecutionHire + expand verticalsDeployment renewalsFailed marquee deployment
CapitalStage financing to milestonesBurn vs ARRDown round / stalled raise

Each mitigation is paired with a concrete monitoring indicator and an explicit thesis-break trigger for ongoing diligence.

[CR019, CR020, CR021, CR033, CR038]

7.4 Exhibits

Chapter 08

08Valuation

8.1 Investment thesis, anti-thesis and recommendation

The investment thesis for Ent is that intent-aware workspace security could become a default enterprise layer, sold by an elite RiskIQ and Microsoft founding team whose prior RiskIQ exit to Microsoft for $500 million-plus demonstrates value-creation, and validated by a tier-1 syndicate led by Decibel. The anti-thesis is equally clear: detection-first incumbents could embed intent-awareness and commoditize Ent before it scales, leaving its wedge to narrow and its single anonymous customer reference looking thin. These opposing cases are paired across product, team, market, customers and moat to make the central debate explicit. The recommendation is to track Ent rather than invest immediately - a compelling vision and pedigree with real early traction, but execution unproven at scale, undisclosed financials and a crowded, incumbent-anchored market. Confidence is moderate given thin disclosed financials and customer proof, and the high-variance risk profile justifies a track stance rather than immediate conviction. On balance, Ent is a high-quality, high-price, high-uncertainty seed best monitored toward its next round; if efficacy is independently validated and ARR scales, the call would move from track to invest, whereas incumbent feature parity would tip it toward the bear case.[CV001, CV002, CV003, CV004, CV026, CV030]

Recommendation summary table
FieldAssessment
RecommendationTrack (toward next round)
ConfidenceModerate
Risk ratingHigh / high-variance
Valuation stancePositive but unconfirmed
Decisive milestoneIndependent efficacy validation

Summary reflects a track stance pending efficacy validation and disclosed financials; ratings are analyst judgments.

[CV003, CV004, CV026, CV028, CV041]
Thesis / anti-thesis table
DimensionThesis (bull)Anti-thesis (bear)
ProductIntent-awareness becomes default layerDetectors add intent, wedge narrows
TeamElite RiskIQ/Microsoft pedigreePedigree no guarantee at new scale
Market$20B+ endpoint, fast-growingCrowded, incumbent-anchored
CustomersGlobal 2000 production tractionSingle anonymous reference
MoatHuman + AI-agent intent scopeFast-followed by Microsoft/CrowdStrike

Thesis and anti-thesis are paired across the diligence dimensions to make the central debate explicit.

[CV001, CV002, CV031, CV016]
FV001: Recommendation logic

How evidence flows to a track recommendation: strong team and market, but unproven efficacy and high entry price gate conviction.

[CV001, CV003, CV026, CV041]

8.2 Valuation context, comparables and scenarios

The $100 million seed from tier-1 investors implies a valuation widely characterized as in unicorn territory, but no official post-money figure has been disclosed, so the implied number is not directly supported by public evidence, and seed preference and dilution terms remain unknown. With no Ent revenue public, comparables anchor the envelope. CrowdStrike trades as a large-cap platform worth tens of billions, SentinelOne sits in the mid-teens-of-billions class, and Palo Alto Networks exceeds $100 billion as a consolidation comparable; high-growth security software commands elevated EV/revenue multiples. On the private side, Wiz's record ARR ramp before a landmark acquisition frames the path a category-definer must travel, and recent security M&A shows acquirers paying strategic premiums. These inputs produce a scenario envelope rather than a point value. The bull case is an IPO or acquisition at $5 billion-plus if intent-aware security becomes a default layer; the base case is a Series A/B at $500 million to $1 billion-plus if early Global 2000 traction holds; and the bear case is commoditization, a down round or acqui-hire. Valuation is highly sensitive to assumed forward ARR and the multiple applied, and an outsized seed reduces entry discipline while raising the bar for the next round. Probability weighting tilts toward the base case with meaningful bear-case weight given execution risk.[CV005, CV006, CV007, CV008, CV009, CV010]

Bull / base / bear scenario table
ScenarioAssumptionsValuation rangeProbability
BullDefault layer; efficacy provenIPO or M&A at $5B+Lower
BaseTraction holds; Series A/B$500M-$1B+Higher
BearCommoditized; weak tractionDown round / acqui-hireMeaningful

Scenarios carry explicit assumptions and qualitative probabilities; ranges are estimates given undisclosed financials.

[CV008, CV009, CV010, CV027]
Comparable valuation table
ComparableTypeValuation / scaleMultiple / noteRelevance
CrowdStrikePublic leaderTens of $B market capElevated EV/revenueScaled-success anchor
SentinelOnePublic peerMid-teens $B classGrowth multipleOn-device peer
Palo Alto NetworksPublic platform>$100B market capPlatform multipleConsolidation comp
WizPrivate / M&ARecord ARR ramp; landmark dealPremium private roundCategory-definer path
Recent security M&AM&A setPremium multiplesStrategic premiumsExit comp

No named customer logos or Ent revenue exist, so comparables anchor the envelope; coverage is partial and indicative, not a direct multiple on Ent.

[CV011, CV012, CV013, CV014, CV015, CV042]
FV002: Valuation sensitivity

Illustrative implied valuation under different forward-ARR and EV/revenue multiple assumptions (USD billions).

Illustrative scenarios applying public security-software multiples to hypothetical forward ARR; Ent's ARR is undisclosed.

[CV016, CV022, CV032]
FV003: Valuation / return range

Scenario valuation ranges for Ent across bear, base and bull outcomes (USD billions).

Scenario ranges are estimates given undisclosed financials and a not-officially-disclosed entry valuation.

[CV008, CV009, CV010, CV017]

8.3 Returns, exit readiness and final diligence

A seed investor's return depends on Ent reaching a multi-billion outcome given the large implied entry valuation, with exit paths most plausibly an acquisition by a platform incumbent or, less likely near-term, an IPO. The endpoint and XDR markets' size and growth support a large potential outcome if Ent executes, and a robust cybersecurity funding climate supports a strong next round. CrowdStrike and SentinelOne prove the public-market value of scaled endpoint security, anchoring the upside, while the comparable set spanning public leaders, a marquee private round and recent M&A gives a defensible valuation envelope. The investment KPIs to track are ARR growth, net revenue retention, the conversion of anonymous proof into named references, and the false-positive rate as an efficacy signal, all against a strong $100 million balance sheet. The final diligence asks - ARR and pricing, independent efficacy benchmarks, cap table and preferences, named customer references, and burn and runway - are the gating items required before moving from track to invest. The thesis-break triggers are concrete: incumbent feature parity, sustained false positives, a failed marquee deployment or stalled financing. The single most decisive milestone is published, independent efficacy validation at a named customer; clearing it, with scaling ARR, would flip the recommendation from track to invest.[CV017, CV018, CV019, CV020, CV023, CV024]

Thesis-break and kill triggers table
TriggerSignalImplication
Incumbent feature parityMicrosoft/CrowdStrike ship intentMoat erased
Sustained false positivesCustomer complaints / churnEfficacy thesis fails
Failed marquee deploymentPublic reference collapseTraction thesis fails
Stalled financingDown round / no Series ACapital thesis fails

Each trigger maps a concrete observable signal to the part of the thesis it would break.

[CV020, CV021, CV035, CV040]
Final diligence asks table
AskWhyOwner
ARR and pricingValidate revenue qualityCompany
Independent efficacy benchmarksValidate core product claimThird party
Cap table and preferencesAssess dilution/overhangCompany
Named customer referencesVerify tractionCompany
Burn and runwayAssess financing urgencyCompany

These are the gating items required before moving from track to invest.

[CV019, CV007, CV024, CV028, CV039]
FV004: Investment KPIs

Key indicators to monitor Ent toward its next round.

[CV024, CV019, CV038, CV039]

8.4 Exhibits

Disclaimer

This report is based on public information as of 2026-06-24 and highlights explicit evidence gaps where company-private metrics or independently verified benchmarks are unavailable.

Evidence index

Claims
IDStatementConfidenceSources
CO001 Ent is an intent-aware workspace security company that emerged from stealth on June 16, 2026. High SO001, SO002
CO002 Ent raised $100 million in seed financing announced on June 16, 2026. High SO001, SO016
CO003 Ent's seed round was led by Decibel. High SO003, SO001
CO004 Sequoia, Craft Ventures, Crosspoint Capital Partners, Shield Capital, Felicis and In-Q-Tel participated in Ent's seed round. Medium SO003, SO011
CO005 Ent was co-founded by Elias Manousos and Brandon Dixon. High SO002, SO030
CO006 Elias Manousos co-founded and led RiskIQ for roughly 14 years before its acquisition by Microsoft. High SO002, SO025
CO007 Microsoft acquired RiskIQ in July 2021 in a deal reported at more than $500 million. High SO025, SO026
CO008 After RiskIQ, Elias Manousos served as a Microsoft corporate vice president for AI Copilot for Security and threat intelligence. Medium SO002, SO011
CO009 Brandon Dixon co-founded PassiveTotal, which was acquired by RiskIQ. Medium SO024, SO002
CO010 Brandon Dixon was a Security AI Strategist at Microsoft who spearheaded the launch of Microsoft Security Copilot. Medium SO011, SO024
CO011 Ent is headquartered in San Francisco, California. Medium SO005, SO027
CO012 The Wall Street Journal reports that Ent was launched in 2025 and has about 100 employees. Medium SO016
CO013 BankInfoSecurity reported that Ent was founded in May 2025 and operated in stealth before its 2026 launch. Medium SO005
CO014 Reported founding timing is mildly conflicting, with sources citing both a 2025 founding and a 2026 emergence from stealth. Medium SO005, SO016
CO015 Ent's platform is a lightweight on-device AI agent that runs across Windows, macOS, Linux and browser extensions. High SO014, SO017
CO016 Ent uses specialized AI models to evaluate the intent of human users and AI agents in real time and intervene before incidents occur. Medium SO009, SO017
CO017 Ent hosts its platform in the customer's own cloud to preserve data sovereignty. Medium SO015, SO017
CO018 Ent's platform is deployed across Global 2000 enterprises in hospitality, financial services and defense. Medium SO007, SO001
CO019 Ent's seed round is described as one of the largest in cybersecurity history. Medium SO002, SO011
CO020 Ent has not publicly disclosed a specific post-money valuation for its seed round. Medium SO016, SO001
CO021 Ent's total capital raised to date is $100 million from a single seed round. High SO001, SO003
CO022 Decibel founding partner Jon Sakoda led the investment in Ent. Medium SO003, SO018
CO023 Ent's advisory bench includes former CISOs of Google, Aetna and MassMutual, a former NSA director, and a former Microsoft CVP for Azure cloud security. Medium SO001, SO007
CO024 Ent's platform reached general availability across Windows, macOS, Linux and browser extensions at its June 2026 launch. Medium SO001, SO014
CO025 Ent positions itself as bringing prevention back to cybersecurity rather than relying on detection after the fact. High SO001, SO017
CO026 The Next Web characterized Ent's prevention messaging as no longer contrarian and flagged the absence of published independent benchmarks. Medium SO006
CO027 DLP Test cautioned that Ent's low-false-positive intent-detection claims remain unproven without independent benchmarks. Medium SO012
CO028 Ent's use cases span insider risk detection, AI governance, data loss prevention, last-mile threat prevention and incident investigation. Medium SO017, SO013
CO029 In-Q-Tel's participation links Ent to U.S. national-security-oriented strategic capital. Medium SO022, SO011
CO030 Crosspoint Capital Partners is a private equity firm focused on cybersecurity, privacy and infrastructure software. Medium SO021
CO031 Ent's two co-founders previously built and sold RiskIQ together, creating concentrated founder-driven execution dependence. Medium SO002, SO025
CO032 Ent's headcount of roughly 100 is small relative to incumbent endpoint-security vendors, increasing key-person and execution risk. Medium SO016
CO033 Ent has not publicly disclosed revenue, ARR or customer count as of its June 2026 launch. Medium SO001, SO016
CO034 An insider-threat lead at a public financial institution described Ent as the first tool where they felt like an expert on day one. Medium SO005
CO035 Ent's emergence from stealth was syndicated widely through a Business Wire press release on June 16, 2026. High SO001, SO007
CO036 Sequoia partner Konstantin Buhler is associated with Sequoia's participation in Ent. Low SO003, SO029
CO037 Ent is a seed-stage, privately held cybersecurity company with an opaque disclosure profile typical of a recently de-stealthed startup. Medium SO016, SO001
CO038 Ent plans market visibility through a Black Hat USA 2026 presence in Las Vegas in August 2026. Low SO017, SO031
CO039 Ent's legal operating entity has been associated in filings discussion with the name Athena Formation Inc., though this is not firmly confirmed in primary disclosures. Low
CO040 Ent's funding stage as of 2026 is seed, with capital concentrated in a single oversized round. High SO001, SO011
CO041 Ent's lightweight agent and customer-cloud hosting differentiate it from cloud-first detection platforms. Medium SO017, SO002
CO042 LinkedIn lists Ent as an intent-aware workspace security company based in San Francisco. Low SO028
CM001 Ent's addressable market spans endpoint security, data loss prevention, insider risk and AI governance. Medium SM018, SM019
CM002 The global endpoint security market was about $18.58 billion in 2025 and roughly $20.79 billion in 2026. Medium SM012, SM017
CM003 The endpoint security market is projected to grow at roughly an 11.9% CAGR toward about $32.52 billion by 2030. Medium SM012
CM004 The endpoint detection and response market is estimated near $6.33 billion in 2026. Medium SM013
CM005 The EDR market is projected to reach about $18.68 billion by 2031 at a 24.16% CAGR. Medium SM013
CM006 The data loss prevention market was about $3.68 billion in 2025 and roughly $4.67 billion in 2026. Medium SM014, SM015
CM007 The DLP market is projected to grow at about a 26.9% CAGR toward $12.53 billion by 2030. Medium SM014
CM008 The XDR and AI-SOC market is projected to grow from about $33.4 billion in 2025 to $89 billion by 2031 at a 22.6% CAGR. Low SM016
CM009 A defensible 2026 SAM for Ent's combined endpoint, DLP and AI-governance workspace category is roughly $25-30 billion. Medium SM012, SM014
CM010 Summing endpoint security (~$20.79B), EDR (~$6.33B) and DLP (~$4.67B) gives an order-of-magnitude 2026 reference near $32 billion before de-duplication. Medium SM012, SM013, SM014
CM011 The primary economic buyer for Ent is the enterprise CISO, with security operations, IT and compliance as influencers. Medium SM021, SM019
CM012 Budget ownership for workspace security typically sits within the CISO's security budget, with overlap into IT and compliance. Medium SM021
CM013 The adoption path for an intent-aware agent runs from targeted pilot to vertical rollout to enterprise-wide deployment. Medium SM018, SM019
CM014 AI-driven attacks are compressing dwell time and raising the value of prevention over detection. Medium SM021, SM022
CM015 The proliferation of autonomous AI agents in the workspace is creating new demand for AI governance controls. Medium SM024, SM023
CM016 Tightening data-protection and AI regulation is a structural demand driver for DLP and AI governance. Medium SM015, SM011
CM017 Endpoint security demand is driven by endpoint proliferation, remote work and rising attack sophistication. High SM001, SM002
CM018 Incumbent bundling, such as Defender within Microsoft 365 E5, raises switching costs for new endpoint entrants. Medium SM002, SM025
CM019 Buyer caution about false positives and unproven benchmarks is an adoption constraint for new prevention tools. Medium SM025
CM020 Independent analysts broadly agree that endpoint security is a high-teens-to-low-$20-billion market in 2026 despite methodology differences. Medium SM012, SM001, SM017
CM021 EDR and DLP are growing materially faster than the overall endpoint security market. Medium SM013, SM014
CM022 Status-quo substitutes for Ent include legacy DLP, EDR alerting and manual insider-risk investigation. Medium SM019, SM017
CM023 Adjacent categories bordering Ent include UEBA, CASB, EDR and emerging AI-governance tooling. Medium SM008, SM007
CM024 North America concentrates the largest share of endpoint security spend. Medium SM003, SM009
CM025 Gartner defines an endpoint protection platform as a solution deployed on devices to prevent and detect malicious activity. Medium SM005, SM008
CM026 Worldwide cybersecurity revenue is projected to grow at double digits annually through 2030. Medium SM010, SM009
CM027 Cloud-based endpoint deployments are growing faster than on-premise alternatives. Medium SM006
CM028 Regulatory compliance requirements are boosting endpoint and data-protection investment. Medium SM009, SM004
CM029 No public Ent-specific SAM or SOM calculation has been disclosed, so sizing relies on category proxies. Medium SM018, SM019
CM030 Financial services, hospitality and defense are credible early demand pools given Ent's disclosed deployments. Medium SM018, SM021
CM031 Market estimates conflict at the margin because vendors scope endpoint, EDR, DLP and XDR differently, which must be preserved in diligence. Medium SM016, SM013, SM012
CM032 The startup-addressable slice depends on per-endpoint or per-seat pricing that Ent has not disclosed, leaving SOM only partly estimable. Low SM019, SM002
CM033 DLP demand is rising specifically because of insider risk and AI-driven data exfiltration. Medium SM011, SM015
CM034 The 2026 figures used here are current-year analyst estimates published in 2026. Medium SM012, SM014
CM035 Endpoint, EDR and DLP together establish a multi-segment TAM well above $30 billion that Ent's platform straddles. Medium SM012, SM013, SM014
CM036 Ent's prevention-first thesis is most valuable where AI accelerates attacks and shrinks response windows. Medium SM021, SM024
CP001 Ent's most direct competitors are cloud and on-device endpoint platforms led by CrowdStrike Falcon and SentinelOne Singularity. Medium SP016, SP025
CP002 Microsoft Defender for Endpoint is a primary competitor distributed through Microsoft 365 E5 bundling. Medium SP005, SP018
CP003 Palo Alto Networks Cortex XDR competes through platform consolidation across endpoint, network and cloud. Medium SP006
CP004 Broadcom-owned Symantec and Trend Micro Vision One are established enterprise endpoint incumbents. Medium SP007, SP008
CP005 DLP and insider-risk vendors such as Proofpoint, Varonis and DTEX overlap with Ent's use cases. Medium SP009, SP010, SP011
CP006 Cybereason is a further EDR competitor in the detection-and-response segment. Low SP013
CP007 The status-quo substitute Ent displaces is reactive detection-and-alerting EDR plus manual investigation. Medium SP015, SP014
CP008 Large enterprises can attempt to build internal monitoring, but intent-inference models are hard to replicate, limiting build-versus-buy substitution. Low SP015, SP023
CP009 CrowdStrike is a publicly traded, multi-billion-dollar-revenue platform with broad EDR, MDR and threat-intelligence scope. High SP001, SP012
CP010 CrowdStrike Falcon is priced on a per-endpoint subscription basis, commonly around or above roughly $100 per endpoint per year. Medium SP002
CP011 SentinelOne Singularity emphasizes on-device autonomous response and one-click rollback. Medium SP003
CP012 SentinelOne packaging is tiered, with per-endpoint pricing commonly cited near roughly $80 per endpoint per year for core tiers. Medium SP004
CP013 Microsoft Defender benefits from deep Windows integration and is included in M365 E5, lowering its marginal cost to bundled buyers. Medium SP005
CP014 Ent differentiates by inferring intent in real time rather than matching known-bad signatures or behaviors after the fact. Medium SP014, SP015
CP015 Ent uniquely claims to evaluate the intent of both human users and AI agents, a scope incumbents do not yet match. Medium SP023, SP020
CP016 Ent hosts its platform in the customer's own cloud for data sovereignty, contrasting with cloud-first incumbents. Medium SP015, SP014
CP017 Endpoint security switching costs are high because agents are deployed fleet-wide and integrated with SOC workflows. Medium SP012, SP025
CP018 Incumbent bundling, especially Microsoft's, creates lock-in that raises the bar for displacement. Medium SP005, SP018
CP019 Enterprises frequently multi-home endpoint, DLP and insider-risk tools, leaving room for a consolidating entrant. Medium SP009, SP010
CP020 Microsoft and CrowdStrike hold outsized distribution power through existing enterprise relationships. Medium SP001, SP005
CP021 Ent's intent-aware moat is vulnerable to fast-following incumbents embedding similar capabilities. Medium SP018, SP022
CP022 Skeptical coverage notes that prevention messaging is no longer contrarian and that Ent lacks published independent benchmarks. Medium SP018, SP022
CP023 New AI-agent-security entrants are emerging to compete for the same AI-governance budget Ent targets. Low SP020, SP027
CP024 Independent analyst reviews consistently rank CrowdStrike, Microsoft and SentinelOne among endpoint leaders. Medium SP012
CP025 Incumbents currently have limited dedicated AI-agent governance, a gap Ent targets. Low SP015, SP006
CP026 Ent's competitive readiness rests on founder pedigree, a $100M war chest and early Global 2000 deployments. Medium SP016, SP024
CP027 Endpoint security is a concentrated market where a few platforms capture most enterprise spend. Medium SP025, SP026
CP028 CrowdStrike and SentinelOne both push autonomous, AI-driven response as a core differentiator. Medium SP001, SP003
CP029 Trend Micro Vision One positions as a broad cross-layer detection and response platform. Low SP008
CP030 Varonis and DTEX anchor the insider-risk and data-security adjacency Ent overlaps. Medium SP010, SP011
CP031 Proofpoint anchors the human-centric DLP and data-protection adjacency. Low SP009
CP032 Ent's prevention-and-intent framing is a genuine product wedge but unproven against incumbents at scale. Medium SP017, SP018
CP033 Customer-cloud hosting is a credible differentiator for regulated buyers wary of vendor-cloud data exposure. Medium SP015, SP017
CP034 The competitive intelligence here reflects vendor and analyst material current as of mid-2026. Medium SP012, SP001
CP035 Palo Alto's consolidation strategy intensifies pricing and bundling pressure on point solutions. Medium SP006, SP007
CP036 Ent must win on demonstrable efficacy and time-to-value to overcome incumbent distribution and lock-in. Should it fail to publish convincing efficacy evidence quickly, the most likely outcome is that incumbents absorb the intent-aware concept and Ent is relegated to a niche, which is the core competitive risk a diligence reader must weigh. Medium SP019, SP021
CI001 Ent operates a SaaS subscription model, most likely priced per endpoint or per seat. Medium SI013, SI012
CI002 Ent has not publicly disclosed its pricing or list rates as of launch. Medium SI013, SI017
CI003 Ent's revenue mix is presently concentrated in early Global 2000 deployments across finance, hospitality and defense. Low SI021, SI012
CI004 Ent's go-to-market is a direct enterprise motion selling into CISO security organizations. Medium SI016, SI013
CI005 Enterprise security sales cycles typically run several months to over a year, a sales-efficiency drag at seed stage. Medium SI005, SI006
CI006 On-device SaaS agents can achieve high software gross margins once delivery scales. Medium SI006, SI011
CI007 Customer-cloud hosting shifts some infrastructure cost to the customer, potentially improving Ent's hosting gross margin but adding deployment-support cost. Low SI013, SI005
CI008 Ent has disclosed headcount of roughly 100 employees and platform general availability, but no revenue figures. Medium SI017, SI012
CI009 No public revenue or ARR figure exists for Ent given its seed-stage, private status. Medium SI017, SI004
CI010 Ent raised $100 million in seed financing, its only disclosed round to date. High SI012, SI014
CI011 At a typical burn for a roughly 100-person security startup, $100M implies an estimated 18-24 month runway. Low SI005, SI006
CI012 The seed proceeds are most likely directed to engineering, AI-model development, go-to-market and enterprise support. Medium SI022, SI013
CI013 Ent's next round will likely be triggered by demonstrated Global 2000 traction and ARR milestones. Low SI020, SI016
CI014 No debt or project-finance obligations have been disclosed for Ent. Low SI012, SI004
CI015 At seed stage, Ent's revenue quality is unproven and rests on early deployments rather than disclosed recurring revenue. Medium SI017, SI018
CI016 Comparable security SaaS companies report gross margins commonly in the 70-80%+ range at scale. High SI007, SI008
CI017 Building proprietary intent-inference AI models is research-and-talent intensive, front-loading cost ahead of revenue. Medium SI006, SI022
CI018 The principal diligence blockers are undisclosed pricing, revenue, ARR, burn rate and exact runway. Medium SI004, SI017
CI019 A $100M seed sets a high performance bar and elevated burn expectations, a financial risk if traction lags. Medium SI018, SI019
CI020 CrowdStrike and SentinelOne demonstrate that subscription endpoint security can scale to billions in high-margin recurring revenue. High SI007, SI008
CI021 Category-defining security startups such as Wiz reached $100M ARR in roughly 18 months, a demanding benchmark. Medium SI002, SI006
CI022 Cybersecurity venture funding remains robust, supporting Ent's ability to raise follow-on capital. Medium SI003, SI001
CI023 Third-party trackers list Ent as an early-stage, recently funded company without disclosed financials. Low SI009, SI010
CI024 The financial data points used here reflect disclosures and comparables current as of mid-2026. Medium SI012, SI007
CI025 Ent's seed valuation is implied to be large but is not officially disclosed, limiting dilution analysis. Medium SI017, SI014
CI026 An outsized seed compresses the margin for execution error before the next priced round. Medium SI019, SI018
CI027 Per-endpoint or per-seat pricing would tie Ent's revenue directly to deployed device or user counts. Medium SI013, SI025
CI028 The endpoint security market's double-digit growth supports a long revenue runway if Ent converts deployments. Medium SI026, SI025
CI029 Decibel's lead and a tier-1 syndicate signal investor confidence in Ent's financing trajectory. Medium SI020, SI015
CI030 Financing dependency is high until Ent demonstrates recurring revenue, given pre-revenue-disclosure status. Medium SI017, SI018
CI031 Service-delivery costs include enterprise onboarding into each customer's own cloud, a non-trivial deployment effort. Low SI013, SI005
CI032 Sales efficiency at seed stage is unmeasurable externally; only proxies from comparable SaaS apply. Low SI006, SI011
CI033 Pulse2 and other outlets corroborate the $100M seed and stealth emergence without adding financial detail. Low SI024, SI023
CI034 Ent's margin path should track comparable security SaaS if it reaches scale, but is unproven today. Medium SI011, SI007
CI035 The seed capital is sufficient to fund 2024-style multi-year product and GTM build before a Series A. Low SI012, SI006
CI036 Overall, Ent's financial profile is high-potential but evidence-thin, with valuation, revenue and burn all undisclosed. Medium SI017, SI004
CE001 Ent is a lightweight on-device AI agent that monitors workspace activity to prevent security incidents before they occur. Medium SE011, SE012
CE002 The platform observes workspace signals across browser, applications, workflows and data movement. Medium SE008, SE014
CE003 Ent's core modules include a workspace observer, an intent-inference engine, a policy-enforcement layer, an intervention layer and a forensic record. Medium SE008, SE011
CE004 The intent-inference engine uses specialized, small AI models to evaluate the intent of human users and AI agents in real time. Medium SE014, SE015
CE005 Ent runs AI models on the device and hosts the platform in the customer's own cloud for data sovereignty. Medium SE012, SE011
CE006 The platform is generally available on Windows, macOS, Linux and browser extensions. High SE011, SE009
CE007 Ent deploys as a lightweight agent that integrates into existing enterprise endpoints and security workflows. Medium SE009, SE021
CE008 Ent's roadmap spans AI governance, threat prevention, security integrations and multimodal endpoint intelligence. Medium SE011, SE008
CE009 Ent differentiates technically by inferring intent in real time rather than matching known-bad signatures after the fact. Medium SE012, SE017
CE010 Ent's models are trained on workspace-behavior data, the proprietary asset underpinning its intent inference. Low SE015, SE007
CE011 Ent provides just-in-time interventions that act before an incident is completed. Medium SE012, SE011
CE012 The platform maintains a forensic record to support incident investigation. Medium SE008, SE014
CE013 Ent's primary use cases are insider-risk detection, AI governance, DLP, last-mile threat prevention and incident investigation. High SE011, SE012
CE014 Customer-cloud hosting keeps sensitive telemetry within the customer's environment, supporting data-residency requirements. Medium SE012, SE003
CE015 Endpoint agents must be lightweight to avoid degrading device performance, a key reliability constraint. Medium SE010, SE024
CE016 Intent-based controls map conceptually to behavior-analytics techniques catalogued in MITRE ATT&CK. Medium SE002, SE005
CE017 Governing AI-agent actions aligns with emerging guidance such as OWASP's LLM and agent risk work and CSA AI guidance. Medium SE001, SE004
CE018 Autonomous AI agents introduce new attack surfaces that motivate runtime governance of agent intent. Medium SE007, SE004
CE019 Real-time intent inference risks false positives that could disrupt legitimate user activity. Medium SE018, SE019
CE020 No independent third-party benchmarks of Ent's intent-inference accuracy have been published. Medium SE018, SE019
CE021 Privacy and data-minimization controls are essential for lawful endpoint monitoring of employees. Medium SE003, SE010
CE022 Security controls catalogs such as NIST SP 800-53 define the access, audit and monitoring controls enterprise buyers expect. Medium SE003, SE005
CE023 DLP and last-mile threat prevention require observing data movement at the point of action on the endpoint. Medium SE010, SE006
CE024 Ent's architecture combines on-device inference with customer-cloud control, a hybrid edge-plus-cloud design. Medium SE008, SE009
CE025 Critical dependencies include the customer's cloud environment, endpoint operating systems and browser extension APIs. Medium SE009, SE010
CE026 At general availability the platform spans four endpoint surfaces, indicating meaningful engineering maturity. Medium SE009, SE011
CE027 AI-driven endpoint attacks are accelerating, raising the value of prevention-oriented design. Medium SE006, SE016
CE028 Ent positions intent inference as a complement that can sit alongside existing EDR rather than fully replace it. Low SE017, SE012
CE029 Multimodal endpoint intelligence on the roadmap implies extending observation beyond text to richer signals. Low SE008, SE022
CE030 Security integrations on the roadmap would connect Ent to SIEM, SOAR and identity systems. Low SE011, SE010
CE031 The on-device approach reduces reliance on cloud round-trips, supporting sub-second intervention claims. Low SE008, SE014
CE032 SANS and industry guidance stress that effective insider-risk programs require behavioral context, not just access logs. Medium SE005, SE002
CE033 The technical claims here derive from company material and framework references current as of mid-2026. Medium SE008, SE003
CE034 Ent's agent must balance observability against device resource use, an engineering trade-off common to EDR. Medium SE010, SE024
CE035 Pulse2 and other outlets corroborate the platform's GA across desktop and browser surfaces. Low SE020, SE013
CE036 The platform's differentiation and maturity are credible but its real-world efficacy remains externally unvalidated. Medium SE019, SE018
CE037 Ent is actively hiring across security research, AI engineering and platform teams, a developer-side signal of build momentum. Medium SE017, SE015
CU001 Ent has disclosed deployment across Global 2000 enterprises in three verticals: hospitality, financial services, and defense. High SU013, SU014
CU002 Ent emerged from stealth in June 2026 without disclosing a specific customer count. High SU013, SU009
CU003 A named anonymous customer — an insider-threat lead at a public financial institution — provided a positive testimonial for Ent. Medium SU015, SU013
CU004 The financial institution customer stated Ent was 'the first tool where I felt like an expert on day one', indicating low time-to-value. Medium SU015, SU009
CU005 Ent targets the Global 2000, indicating its primary segment is large enterprises with complex security needs. Medium SU011, SU013
CU006 The economic buyer for Ent is the enterprise CISO, with security operations and compliance as co-stakeholders. Medium SU003, SU002
CU007 Security buyers in 2026 favor platforms that consolidate insider risk, DLP, and AI governance into a single agent. Medium SU003, SU012
CU008 CISOs prioritize tools that reduce alert fatigue and surface intent rather than generating more events. Medium SU002, SU006
CU009 Enterprises in regulated verticals — financial services, defense, healthcare — are the earliest adopters of AI-governance controls. Medium SU004, SU007
CU010 Financial institutions are among the most active buyers of insider-threat tooling in the enterprise market. Medium SU007, SU022
CU011 Insider-driven incidents rank among the costliest enterprise security failures, sustaining buyer urgency for insider-risk platforms. Medium SU005, SU023
CU012 CISA guidance affirms that insider threats — malicious, negligent, or unwitting — require lifecycle detection controls. Medium SU008, SU007
CU013 A meaningful share of data breaches involve internal actors through error, misuse, or compromised credentials. Medium SU023, SU022
CU014 Organizations using security AI and automation see significantly lower breach costs and faster containment. Medium SU022, SU023
CU015 No public customer count, ARR, or NRR figure has been disclosed by Ent as of June 2026. Medium SU013, SU018
CU016 Ent's Global 2000 deployment claim is company-asserted and unverified by independent third parties as of June 2026. Medium SU017, SU025
CU017 The Next Web noted that Ent has not published independent benchmarks for its intent-inference claims. Medium SU017
CU018 Enterprise DLP buying in 2026 is shifting toward integrated platforms that address insider risk and AI governance. Medium SU012, SU003
CU019 Ent's on-device agent supports insider risk detection, AI governance, DLP, last-mile prevention, and incident investigation use cases. Medium SU020, SU019
CU020 Defense and government customers represent a high-value strategic segment given IQT's participation in Ent's seed round. Medium SU013, SU009
CU021 Hospitality enterprises face distributed-workforce risk that maps to Ent's last-mile threat-prevention use case. Medium SU021, SU019
CU022 Ent's typical adoption path begins with a targeted pilot in a single vertical before expanding enterprise-wide. Medium SU009, SU016
CU023 No public churn, failed pilot, or contract non-renewal evidence exists for Ent as of June 2026. Medium SU013, SU018
CU024 Buyer caution about unproven intent-inference accuracy is a potential adoption constraint in the DLP incumbent market. Medium SU025, SU017
CU025 Gartner Peer Insights EDR reviewers weight efficacy, ease of deployment, and false-positive rates most heavily. Medium SU001, SU003
CU026 Ent's platform is hosted in the customer's own cloud, reducing data-sovereignty friction for regulated-industry buyers. Medium SU019, SU020
CU027 No retention cohort, GRR, or NRR data is publicly available for Ent, as the company has not disclosed financial metrics. Medium SU015, SU013
CU028 Customer concentration risk is undisclosed; if three verticals represent the full base, any single-vertical dependency could be material. Medium SU016, SU021
CU029 Ent's design for enterprise-scale agentic AI governance positions it for expansion as AI agents proliferate in customer workspaces. Medium SU020, SU018
CU030 All customer evidence for Ent post-launch dates from June 2026, reflecting only the stealth-exit announcement window. Medium SU013, SU009
CU031 Buyers want measurable reductions in time-to-investigate and clearer attribution of risky behavior. Medium SU006, SU003
CU032 Defense-sector deployments carry national-security mandate tailwinds driven in part by IQT as a strategic investor. Medium SU008, SU013
CU033 No G2, Capterra, or Gartner Peer Insights review entry for Ent as a specific product exists as of June 2026. Medium SU001, SU015
CU034 The anonymous financial-institution testimonial represents the only direct customer voice in publicly available evidence. Medium SU015, SU013
CU035 Ent's platform targets the workspace layer across Windows, macOS, Linux, and browser environments, broadening deployment surface. Medium SU018, SU019
CU036 Enterprise DLP consolidation trends in 2026 favor unified platforms over point products, supporting Ent's land-and-expand potential. Medium SU012, SU007
CU037 Ent's stealth period with paying Global 2000 customers indicates pre-announcement product-market validation, though depth is unknown. Medium SU016, SU010
CU038 Procurement friction in regulated industries includes data residency audits, security reviews, and multi-stakeholder approvals. Medium SU004, SU008
CU039 Ent has not disclosed whether its stealth customer base includes signed enterprise contracts or proof-of-concept evaluations. Medium SU013, SU018
CU040 The combination of IQT participation and defense-vertical deployment signals potential for government/defense procurement channels. Medium SU013, SU020
CR001 Ent's most severe risks cluster around regulatory/privacy exposure, unproven efficacy, incumbent competition and key-person dependence. Medium SR016, SR017
CR002 Endpoint monitoring of employees triggers significant privacy and data-protection obligations. High SR006, SR001
CR003 The EU GDPR constrains workplace monitoring through purpose-limitation, proportionality and lawful-basis requirements. High SR001, SR008
CR004 The European Data Protection Board has issued guidance restricting intrusive employee monitoring. Medium SR008
CR005 The EU AI Act imposes obligations on AI systems that could classify intent-inference as higher-risk, raising compliance cost. Medium SR002
CR006 US state privacy laws such as the CCPA grant employees and consumers data rights relevant to monitoring data. Medium SR004
CR007 The FTC has pursued enforcement against unfair or deceptive data practices, a US enforcement risk. Medium SR003
CR008 Civil-liberties groups warn that pervasive workplace surveillance carries legal and reputational risk. High SR007, SR006
CR009 NIST's AI Risk Management Framework signals the governance expectations regulators will apply to AI systems. Medium SR005
CR010 Real-time intent inference risks false positives that could block legitimate work and erode trust. Medium SR017, SR016
CR011 Ent's sub-second inference and efficacy claims have not been independently benchmarked. Medium SR017, SR016
CR012 A fleet-wide on-device agent introduces reliability and performance risk if it degrades devices or fails. Medium SR023, SR026
CR013 Ent depends on each customer's cloud infrastructure to host its control plane and forensic store. Medium SR012, SR011
CR014 Microsoft and CrowdStrike pose concentrated competitive risk through distribution and bundling. Medium SR025, SR026
CR015 Key-person dependence on co-founders Elias Manousos and Brandon Dixon is acute for a roughly 100-person company. Medium SR013, SR021
CR016 A $100M seed sets a high performance bar and elevated burn, an execution risk if traction lags. Medium SR016, SR017
CR017 Burn-and-runway risk is material given undisclosed burn and an estimated 18-24 month runway. Low SR021, SR014
CR018 Financial-model risk is high because revenue, pricing and unit economics are undisclosed. Medium SR021, SR011
CR019 Mitigations include an advisory board with a former NSA director and former CISOs to navigate regulation. Medium SR011, SR018
CR020 Customer-cloud hosting is itself a mitigation that supports data-sovereignty compliance. Medium SR012, SR027
CR021 Thesis-break triggers include sustained false-positive complaints, a failed marquee deployment or incumbent feature parity. Medium SR016, SR025
CR022 Risks transmit across domains: a privacy enforcement action could stall sales and worsen burn. Medium SR001, SR014
CR023 The threat environment - costly breaches and shrinking dwell time - validates demand but raises the stakes of failure. High SR010, SR009
CR024 Verizon breach data shows human-driven and credential-based incidents remain dominant, supporting insider focus. Medium SR009
CR025 IBM breach-cost data shows multimillion-dollar average breach costs, underscoring prevention value. Medium SR010
CR026 AI-agent governance is an emerging regulatory frontier where rules are still forming, creating compliance uncertainty. Medium SR029, SR028
CR027 Insider-threat programs face heightened government scrutiny, both a demand driver and a compliance obligation. Medium SR030, SR027
CR028 Data-sovereignty obligations in defense and finance could constrain or complicate deployments. Medium SR012, SR008
CR029 Competition risk and execution risk compound: incumbents can out-distribute Ent while it must prove efficacy. Medium SR026, SR016
CR030 Expansion beyond three verticals is an execution risk given limited team scale. Medium SR021, SR014
CR031 Reputational risk is elevated by skeptical coverage questioning whether prevention claims are differentiated. Medium SR016, SR022
CR032 Regulatory complexity is global, spanning EU GDPR/AI Act and US state and federal regimes simultaneously. Medium SR001, SR002, SR004
CR033 Mitigation depends on demonstrable efficacy evidence Ent has not yet published. Medium SR017, SR012
CR034 The founders' Microsoft and RiskIQ pedigree partially mitigates execution and credibility risk. Medium SR013, SR019
CR035 Tier-1 investor backing partially mitigates financing risk but raises valuation-expectation risk. Medium SR011, SR014
CR036 Endpoint-market concentration means Ent must win share from entrenched incumbents, a structural risk. Medium SR023, SR024
CR037 A successful red-team or privacy regulator action against intent inference would be a severe adverse event. Medium SR007, SR003
CR038 Monitoring indicators include false-positive rates, deployment renewals, regulatory filings and competitor releases. Medium SR005, SR017
CR039 The single anonymous customer reference leaves execution evidence thin and concentration risk high. Medium SR015, SR021
CR040 Diligence asks include efficacy benchmarks, privacy DPIA, burn data and a key-person retention plan. Medium SR017, SR012
CR041 DataM and other coverage frame AI as reshaping both attack and defense, raising the cost of getting prevention wrong. Low SR020, SR010
CR042 Overall, Ent's risk profile is high-variance: a credible team and capital against unproven efficacy, heavy regulation and dominant incumbents. Medium SR016, SR013
CV001 The investment thesis is that intent-aware workspace security could become a default enterprise layer, led by an elite team. Medium SV011, SV013
CV002 The anti-thesis is that incumbents embed intent-awareness and commoditize Ent before it scales. Medium SV016, SV029
CV003 The recommendation is to track Ent: compelling vision and pedigree, but execution unproven at scale. Medium SV014, SV017
CV004 Confidence in the recommendation is moderate given thin disclosed financials and customer proof. Medium SV021, SV017
CV005 The $100M seed from tier-1 investors implies a valuation widely characterized as in unicorn territory, though not officially disclosed. Medium SV013, SV011
CV006 No official post-money valuation has been disclosed, so the implied figure is not directly supported by public evidence. Medium SV021, SV011
CV007 Seed preference and dilution terms are undisclosed, leaving overhang analysis incomplete. Low SV021, SV010
CV008 The bull case is acquisition by a major platform or an IPO at $5B+ if intent-aware security becomes a default layer. Low SV006, SV001
CV009 The base case is growth to a Series A/B at a $500M-$1B+ valuation if early Global 2000 traction holds. Low SV010, SV008
CV010 The bear case is commoditization by incumbents, a down round or acqui-hire if efficacy and traction disappoint. Low SV016, SV017
CV011 CrowdStrike trades as a large-cap security platform with a market capitalization in the tens of billions of dollars. High SV001, SV004
CV012 SentinelOne is a public security company valued in the mid-teens-of-billions range. High SV002, SV030
CV013 Palo Alto Networks is a platform-consolidation comparable with a market cap above $100 billion. Medium SV003, SV004
CV014 Wiz demonstrated a record revenue ramp before a landmark acquisition agreement, a benchmark for category-defining security startups. Medium SV005, SV009
CV015 Strategic acquirers continue to pay premiums for differentiated security platforms with enterprise traction. Medium SV006, SV007
CV016 High-growth security software trades at elevated enterprise-value-to-revenue multiples relative to broader SaaS. High SV008, SV001
CV017 A seed investor's return depends on Ent reaching a multi-billion outcome, given the large implied entry valuation. Low SV010, SV008
CV018 Exit paths are acquisition by a platform incumbent or, less likely near-term, an IPO. Low SV006, SV003
CV019 Final diligence asks include ARR, pricing, efficacy benchmarks, cap table and customer references. Medium SV021, SV017
CV020 Thesis-break triggers include incumbent feature parity, sustained false positives or a failed marquee deployment. Medium SV016, SV029
CV021 An outsized seed valuation reduces entry discipline and compresses the margin for execution error. Medium SV010, SV017
CV022 Valuation is highly sensitive to assumed forward ARR and the revenue multiple applied. Medium SV008, SV009
CV023 A robust cybersecurity funding climate supports Ent's ability to raise a strong next round. Medium SV007, SV020
CV024 Investment KPIs to track include ARR growth, net revenue retention, named references and false-positive rate. Medium SV014, SV015
CV025 Comparables and valuation inputs used here are current as of mid-2026. Medium SV001, SV008
CV026 Ent's high-variance risk profile justifies a track stance rather than immediate conviction investment. Medium SV016, SV014
CV027 Probability weighting tilts toward the base case, with meaningful bear-case weight given execution risk. Low SV017, SV010
CV028 The single most decisive milestone is published, independent efficacy validation at a named customer. Medium SV017, SV012
CV029 The endpoint and XDR markets' size and growth support a large potential outcome if Ent executes. Medium SV026, SV028, SV027
CV030 Decibel's lead and a tier-1 syndicate signal strong external validation of the opportunity. Medium SV023, SV024
CV031 The founders' RiskIQ exit to Microsoft for $500M+ demonstrates prior value-creation, supporting the bull case. Medium SV013, SV019
CV032 CrowdStrike and SentinelOne prove the public-market value of scaled endpoint security, anchoring the upside. High SV001, SV002
CV033 Macrotrends data corroborates CrowdStrike's multi-billion revenue scale used as a north-star comparable. Medium SV004, SV029
CV034 Pulse2 and BusinessOutstanders corroborate the $100M raise underpinning the entry valuation. Low SV025, SV022
CV035 Carta data shows outsized seeds raise the bar for subsequent rounds, a valuation risk. Medium SV010, SV008
CV036 Morningstar syndication confirms the Global 2000 deployment claims that underpin the base case. Medium SV018, SV011
CV037 Sacra's Wiz analysis frames the ARR ramp a category-defining startup must achieve to justify a unicorn entry. Medium SV009, SV005
CV038 On balance, Ent is a high-quality, high-price, high-uncertainty seed best monitored toward its next round. Medium SV014, SV016
CV039 If efficacy is independently validated and ARR scales, the recommendation would move from track to invest. Medium SV015, SV008
CV040 If incumbents reach feature parity first, the bear case dominates and the case breaks. Medium SV029, SV016
CV041 Ent's valuation stance is positive-but-unconfirmed: attractive optionality at a price that demands proof. Medium SV010, SV014
CV042 The comparable set spans public leaders, a marquee private round and recent M&A, giving a defensible valuation envelope. Medium SV001, SV005, SV006
Sources
IDPublisherTitleQuote
SO001 Business Wire Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity Ent today emerged from stealth with $100 million in seed financing to bring prevention back to cybersecurity with an intent-aware workspace security platform.
SO002 SiliconANGLE RiskIQ founders launch Ent with $100M to rethink endpoint defense The company was founded by Elias Manousos and Brandon Dixon, who previously built RiskIQ before its $500 million-plus acquisition by Microsoft.
SO003 The SaaS News Ent Raises $100M in Seed Funding The round was led by Decibel, with participation from Sequoia, Craft Ventures, Crosspoint Capital and others.
SO004 FinTech Global Ent's $100m seed signals a shift in cybersecurity thinking Ent's intent-aware approach reflects a broader shift from detection toward prevention in enterprise security.
SO005 BankInfoSecurity (ISMG) Ent Raises $100M to Reinvent Endpoint Security for AI Era An insider-threat lead at a public financial institution said Ent was the first tool where I felt like an expert on day one.
SO006 The Next Web Ent's $100M seed bets on intent-aware workspace prevention Prevention is back is hardly a contrarian rallying cry anymore, and Ent has yet to publish independent benchmarks for its intent-inference claims.
SO007 Morningstar (Business Wire) Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity Ent's platform is deployed across Global 2000 enterprises in hospitality, financial services and defense.
SO008 Pulse 2.0 Ent Raises $100 Million Seed Round And Emerges From Stealth Ent emerged from stealth with an AI-powered workspace security platform and $100 million in seed funding.
SO009 Business Outstanders Ent's $100M Seed Funding for AI Endpoint Security Ent uses specialized AI models to evaluate the intent of users and AI agents in real time.
SO010 DataM Intelligence Ent Raises $100 Million Seed Funding for AI Endpoint Security Platform The endpoint security market is positioned for double-digit growth as AI reshapes both attack and defense.
SO011 Tech Funding News Ent: ex-Microsoft Security Copilot founders raise $100M for AI threats Brandon Dixon spearheaded the launch of Microsoft Security Copilot before co-founding Ent.
SO012 DLP Test Ent Emerges from Stealth with $100 Million Seed Round Without independent benchmarks, claims about low false-positive intent detection remain unproven, and DLP buyers have heard prevention promises before.
SO013 AIExpert.news Ent Emerges From Stealth With $100M Seed for AI-Aware Endpoint Security Ent positions itself to govern both human users and autonomous AI agents in the workspace.
SO014 Yahoo Finance (Business Wire) Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity Ent's lightweight on-device agent runs across Windows, macOS, Linux and browser extensions.
SO015 FinancialContent / WRAL Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity The platform is hosted in the customer's own cloud to preserve data sovereignty.
SO016 The Wall Street Journal Cyber Startup Ent Raises $100 Million in Seed Funding Launched in 2025, Ent has about 100 workers and is led by RiskIQ co-founder Elias Manousos.
SO017 Ent Ent - Intent-Aware Workspace Security Ent brings prevention back to cybersecurity by understanding the intent behind every action in the workspace.
SO018 Decibel Decibel - Venture capital for technical founders Decibel partners with founders building foundational enterprise and security companies.
SO019 Shield Capital Shield Capital - Investing in security and resilience Shield Capital backs founders at the intersection of commercial technology and national security.
SO020 Felicis Felicis - Venture capital firm Felicis invests in iconic companies reinventing the world for the better.
SO021 Crosspoint Capital Partners Crosspoint Capital Partners - Cybersecurity and privacy investing Crosspoint Capital is a private equity firm focused on the cybersecurity, privacy and infrastructure software markets.
SO022 In-Q-Tel In-Q-Tel - Strategic investor for national security IQT identifies and adapts cutting-edge technologies to support the missions of the U.S. national security community.
SO023 Craft Ventures Craft Ventures - Venture capital for founders Craft Ventures invests in founders building the defining companies of their categories.
SO024 FinancialContent (Business Wire) Pillar Security Appoints Former Microsoft AI Security Leader Brandon Dixon as Strategic Advisor Brandon Dixon co-founded PassiveTotal, which was acquired by RiskIQ, and later served as a Security AI Strategist at Microsoft.
SO025 Microsoft News Microsoft acquires RiskIQ to strengthen cybersecurity of digital transformation and hybrid work Microsoft has acquired RiskIQ, a leader in global threat intelligence and attack surface management.
SO026 TechCrunch Microsoft confirms it has acquired RiskIQ Reports valued the RiskIQ acquisition at more than $500 million.
SO027 Crunchbase Ent - Company Profile Ent is a cybersecurity company founded in 2025 and headquartered in San Francisco.
SO028 LinkedIn Ent - Company Page Ent is an intent-aware workspace security company based in San Francisco.
SO029 Sequoia Capital Sequoia Capital - Partnering with founders Sequoia partners early and stays for the long arc of company building.
SO030 Ent About Ent Ent was founded by Elias Manousos and Brandon Dixon to bring prevention back to cybersecurity.
SO031 Ent Ent Blog Our mission is to understand intent so security teams can intervene before incidents occur.
SM001 Grand View Research Endpoint Security Market Size, Share & Trends Analysis Report Growing endpoint proliferation and remote work are key drivers of endpoint security demand.
SM002 MarketsandMarkets Endpoint Security Market - Global Forecast The endpoint security market is driven by the rising sophistication and frequency of cyberattacks.
SM003 Precedence Research Endpoint Security Market Size and Growth North America dominates endpoint security spending led by enterprise and government buyers.
SM004 Fortune Business Insights Endpoint Security Market Size, Share & Growth The shift to AI-driven detection and response is reshaping endpoint security budgets.
SM005 Gartner Definition of Endpoint Protection Platform (EPP) - Glossary An endpoint protection platform is a solution deployed on endpoint devices to prevent file-based malware and detect malicious activity.
SM006 Allied Market Research Endpoint Security Market Statistics, Forecast Cloud-based endpoint security deployments are growing faster than on-premise alternatives.
SM007 Market Research Future Endpoint Security Market Research Report - Forecast Endpoint security adoption is accelerating across BFSI, healthcare and government verticals.
SM008 Verified Market Research Endpoint Security Market Size And Forecast Endpoint security is converging with EDR, DLP and identity into unified platforms.
SM009 Global Market Insights Endpoint Security Market Size & Share, Growth Forecast Increasing regulatory compliance requirements are boosting endpoint security investments.
SM010 Statista Cybersecurity - Worldwide Market Outlook Worldwide cybersecurity revenue is projected to show steady double-digit annual growth through 2030.
SM011 Precedence Research Data Loss Prevention Market Size and Forecast DLP demand is rising as enterprises confront insider risk and AI-driven data exfiltration.
SM012 The Business Research Company Endpoint Security Global Market Report 2026 The endpoint security market will grow from $18.58 billion in 2025 to $20.79 billion in 2026 at a CAGR of 11.9%.
SM013 Mordor Intelligence Endpoint Detection and Response (EDR) Market Size & Share Analysis The EDR market is estimated at $6.33 billion in 2026 and is projected to reach $18.68 billion by 2031 at a CAGR of 24.16%.
SM014 The Business Research Company Data Loss Prevention Global Market Report 2026 The data loss prevention market will grow from $3.68 billion in 2025 to $4.67 billion in 2026 at a CAGR of 26.9%.
SM015 Fortune Business Insights Data Loss Prevention Market Size, Share & Growth Report Rising insider threats and stringent data-protection regulations are driving rapid DLP market expansion.
SM016 HiQual Insights Cybersecurity XDR / AI-SOC Market 2026-2031 The XDR and AI-SOC market is projected to grow from $33.4 billion in 2025 to $89 billion by 2031 at a CAGR of 22.6%.
SM017 Research and Markets Endpoint Security Market Report Endpoint security remains one of the largest and fastest-consolidating segments of enterprise cybersecurity spend.
SM018 Business Wire Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity Ent today emerged from stealth with $100 million in seed financing to bring prevention back to cybersecurity with an intent-aware workspace security platform.
SM019 Ent Ent - Intent-Aware Workspace Security Ent brings prevention back to cybersecurity by understanding the intent behind every action in the workspace.
SM020 SiliconANGLE RiskIQ founders launch Ent with $100M to rethink endpoint defense The company was founded by Elias Manousos and Brandon Dixon, who previously built RiskIQ before its $500 million-plus acquisition by Microsoft.
SM021 FinTech Global Ent's $100m seed signals a shift in cybersecurity thinking Ent's intent-aware approach reflects a broader shift from detection toward prevention in enterprise security.
SM022 DataM Intelligence Ent Raises $100 Million Seed Funding for AI Endpoint Security Platform The endpoint security market is positioned for double-digit growth as AI reshapes both attack and defense.
SM023 Tech Funding News Ent: ex-Microsoft Security Copilot founders raise $100M for AI threats Brandon Dixon spearheaded the launch of Microsoft Security Copilot before co-founding Ent.
SM024 Business Outstanders Ent's $100M Seed Funding for AI Endpoint Security Ent uses specialized AI models to evaluate the intent of users and AI agents in real time.
SM025 The Next Web Ent's $100M seed bets on intent-aware workspace prevention Prevention is back is hardly a contrarian rallying cry anymore, and Ent has yet to publish independent benchmarks for its intent-inference claims.
SP001 CrowdStrike CrowdStrike Falcon Platform The CrowdStrike Falcon platform delivers cloud-native, AI-powered endpoint and workload protection.
SP002 CrowdStrike CrowdStrike Falcon Pricing & Bundles Falcon Go starts at $59.99 per endpoint per year, with higher tiers for Enterprise and Complete MDR.
SP003 SentinelOne SentinelOne Singularity Platform Singularity delivers autonomous, on-device AI that detects and remediates threats in real time with one-click rollback.
SP004 SentinelOne Singularity Platform Packages Singularity is offered in Core, Control and Complete tiers priced per endpoint.
SP005 Microsoft Microsoft Defender for Endpoint Defender for Endpoint is included with Microsoft 365 E5 and provides industry-leading endpoint protection.
SP006 Palo Alto Networks Cortex XDR - Extended Detection and Response Cortex XDR unifies endpoint, network and cloud data to stop sophisticated attacks.
SP007 Broadcom Symantec Endpoint Security Symantec Endpoint Security delivers protection for traditional and mobile endpoints at enterprise scale.
SP008 Trend Micro Endpoint Security - Trend Vision One Trend Vision One brings endpoint protection into a unified cybersecurity platform.
SP009 Proofpoint Information Protection and DLP Proofpoint combines content inspection with user behavior to prevent data loss across channels.
SP010 Varonis Varonis Data Security Platform Varonis automatically discovers and protects sensitive data and detects insider threats.
SP011 DTEX Systems DTEX InTERCEPT Insider Risk Platform DTEX uses behavioral indicators to detect insider risk while preserving employee privacy.
SP012 Gartner Peer Insights Endpoint Protection Platforms Reviews and Ratings CrowdStrike, Microsoft and SentinelOne lead the endpoint protection platform market by review volume.
SP013 Cybereason Cybereason Defense Platform Cybereason correlates endpoint telemetry into operation-centric attack stories.
SP014 Business Wire Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity Ent today emerged from stealth with $100 million in seed financing to bring prevention back to cybersecurity with an intent-aware workspace security platform.
SP015 Ent Ent - Intent-Aware Workspace Security Ent brings prevention back to cybersecurity by understanding the intent behind every action in the workspace.
SP016 SiliconANGLE RiskIQ founders launch Ent with $100M to rethink endpoint defense The company was founded by Elias Manousos and Brandon Dixon, who previously built RiskIQ before its $500 million-plus acquisition by Microsoft.
SP017 FinTech Global Ent's $100m seed signals a shift in cybersecurity thinking Ent's intent-aware approach reflects a broader shift from detection toward prevention in enterprise security.
SP018 The Next Web Ent's $100M seed bets on intent-aware workspace prevention Prevention is back is hardly a contrarian rallying cry anymore, and Ent has yet to publish independent benchmarks for its intent-inference claims.
SP019 BankInfoSecurity (ISMG) Ent Raises $100M to Reinvent Endpoint Security for AI Era An insider-threat lead at a public financial institution said Ent was the first tool where I felt like an expert on day one.
SP020 Tech Funding News Ent: ex-Microsoft Security Copilot founders raise $100M for AI threats Brandon Dixon spearheaded the launch of Microsoft Security Copilot before co-founding Ent.
SP021 DataM Intelligence Ent Raises $100 Million Seed Funding for AI Endpoint Security Platform The endpoint security market is positioned for double-digit growth as AI reshapes both attack and defense.
SP022 DLP Test Ent Emerges from Stealth with $100 Million Seed Round Without independent benchmarks, claims about low false-positive intent detection remain unproven, and DLP buyers have heard prevention promises before.
SP023 Business Outstanders Ent's $100M Seed Funding for AI Endpoint Security Ent uses specialized AI models to evaluate the intent of users and AI agents in real time.
SP024 Morningstar (Business Wire) Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity Ent's platform is deployed across Global 2000 enterprises in hospitality, financial services and defense.
SP025 Mordor Intelligence Endpoint Detection and Response (EDR) Market Size & Share Analysis The EDR market is estimated at $6.33 billion in 2026 and is projected to reach $18.68 billion by 2031 at a CAGR of 24.16%.
SP026 The Business Research Company Endpoint Security Global Market Report 2026 The endpoint security market will grow from $18.58 billion in 2025 to $20.79 billion in 2026 at a CAGR of 11.9%.
SP027 AIExpert.news Ent Emerges From Stealth With $100M Seed for AI-Aware Endpoint Security Ent positions itself to govern both human users and autonomous AI agents in the workspace.
SI001 Crunchbase News Cybersecurity Funding Coverage Cybersecurity remained one of the most heavily funded enterprise software categories into 2026.
SI002 Sacra Sacra Research - Private market intelligence Leading security SaaS companies sustain gross margins above 75% at scale.
SI003 CB Insights State of Cybersecurity Startup Funding Mega-rounds at the seed stage have become a hallmark of repeat security founders with proven exits.
SI004 Crunchbase Ent - Financials Ent has raised a total of $100M across one funding round, a seed round announced in June 2026.
SI005 SaaStr The SaaS Metrics That Matter Best-in-class SaaS companies target CAC payback under 12 months and net revenue retention above 120%.
SI006 Bessemer Venture Partners State of the Cloud Top-decile cloud companies combine durable growth with improving free-cash-flow margins.
SI007 CrowdStrike Investor Relations CrowdStrike Investor Relations CrowdStrike reports subscription gross margins near 80% and a Rule-of-40 profile.
SI008 SentinelOne Investor Relations SentinelOne Investor Relations SentinelOne has prioritized revenue growth while progressing toward positive operating margins.
SI009 Tracxn Ent - Company Financials and Funding Tracxn lists Ent as a seed-stage cybersecurity company funded in 2026.
SI010 Growjo Ent - Revenue and Employee Estimates Growjo estimates place Ent's headcount near 100 employees following its 2026 emergence from stealth.
SI011 Aventis Advisors SaaS Valuation Multiples SaaS revenue multiples compressed from 2021 peaks but premium security assets still command double-digit forward multiples.
SI012 Business Wire Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity Ent today emerged from stealth with $100 million in seed financing to bring prevention back to cybersecurity with an intent-aware workspace security platform.
SI013 Ent Ent - Intent-Aware Workspace Security Ent brings prevention back to cybersecurity by understanding the intent behind every action in the workspace.
SI014 SiliconANGLE RiskIQ founders launch Ent with $100M to rethink endpoint defense The company was founded by Elias Manousos and Brandon Dixon, who previously built RiskIQ before its $500 million-plus acquisition by Microsoft.
SI015 The SaaS News Ent Raises $100M in Seed Funding The round was led by Decibel, with participation from Sequoia, Craft Ventures, Crosspoint Capital and others.
SI016 FinTech Global Ent's $100m seed signals a shift in cybersecurity thinking Ent's intent-aware approach reflects a broader shift from detection toward prevention in enterprise security.
SI017 The Wall Street Journal Cyber Startup Ent Raises $100 Million in Seed Funding Launched in 2025, Ent has about 100 workers and is led by RiskIQ co-founder Elias Manousos.
SI018 The Next Web Ent's $100M seed bets on intent-aware workspace prevention Prevention is back is hardly a contrarian rallying cry anymore, and Ent has yet to publish independent benchmarks for its intent-inference claims.
SI019 DLP Test Ent Emerges from Stealth with $100 Million Seed Round Without independent benchmarks, claims about low false-positive intent detection remain unproven, and DLP buyers have heard prevention promises before.
SI020 Decibel Decibel - Venture capital for technical founders Decibel partners with founders building foundational enterprise and security companies.
SI021 Morningstar (Business Wire) Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity Ent's platform is deployed across Global 2000 enterprises in hospitality, financial services and defense.
SI022 Tech Funding News Ent: ex-Microsoft Security Copilot founders raise $100M for AI threats Brandon Dixon spearheaded the launch of Microsoft Security Copilot before co-founding Ent.
SI023 DataM Intelligence Ent Raises $100 Million Seed Funding for AI Endpoint Security Platform The endpoint security market is positioned for double-digit growth as AI reshapes both attack and defense.
SI024 Pulse 2.0 Ent Raises $100 Million Seed Round And Emerges From Stealth Ent emerged from stealth with an AI-powered workspace security platform and $100 million in seed funding.
SI025 Mordor Intelligence Endpoint Detection and Response (EDR) Market Size & Share Analysis The EDR market is estimated at $6.33 billion in 2026 and is projected to reach $18.68 billion by 2031 at a CAGR of 24.16%.
SI026 The Business Research Company Endpoint Security Global Market Report 2026 The endpoint security market will grow from $18.58 billion in 2025 to $20.79 billion in 2026 at a CAGR of 11.9%.
SE001 OWASP OWASP Top 10 for Large Language Model Applications Excessive agency and prompt injection are leading risks for LLM-based applications and autonomous agents.
SE002 MITRE MITRE ATT&CK Knowledge Base ATT&CK documents adversary tactics and techniques across the attack lifecycle, including exfiltration and insider abuse.
SE003 NIST SP 800-53 Rev. 5 Security and Privacy Controls SP 800-53 provides a catalog of security and privacy controls for information systems and organizations.
SE004 Cloud Security Alliance Artificial Intelligence Research Securing AI agents requires controls over their permissions, actions and data access in real time.
SE005 SANS Institute SANS Reading Room - Security White Papers Effective insider threat programs combine behavioral analytics with user activity monitoring and clear policy.
SE006 Dark Reading Endpoint Security News and Analysis On-device AI inference is becoming central to next-generation endpoint defense.
SE007 arXiv Identifying the Risks of LM Agents with an LM-Emulated Sandbox Language-model agents can take unintended high-impact actions, motivating guardrails that evaluate intent before execution.
SE008 Ent Ent Platform Overview Ent's lightweight on-device agent observes workspace activity and infers intent using specialized AI models.
SE009 Ent Ent Product Ent supports insider risk detection, AI governance, data loss prevention, last-mile threat prevention and incident investigation.
SE010 TechTarget SearchSecurity - Enterprise Security Technology Data sovereignty requirements increasingly push security vendors to deploy within the customer's own cloud tenant.
SE011 Business Wire Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity Ent today emerged from stealth with $100 million in seed financing to bring prevention back to cybersecurity with an intent-aware workspace security platform.
SE012 Ent Ent - Intent-Aware Workspace Security Ent brings prevention back to cybersecurity by understanding the intent behind every action in the workspace.
SE013 SiliconANGLE RiskIQ founders launch Ent with $100M to rethink endpoint defense The company was founded by Elias Manousos and Brandon Dixon, who previously built RiskIQ before its $500 million-plus acquisition by Microsoft.
SE014 Business Outstanders Ent's $100M Seed Funding for AI Endpoint Security Ent uses specialized AI models to evaluate the intent of users and AI agents in real time.
SE015 Tech Funding News Ent: ex-Microsoft Security Copilot founders raise $100M for AI threats Brandon Dixon spearheaded the launch of Microsoft Security Copilot before co-founding Ent.
SE016 DataM Intelligence Ent Raises $100 Million Seed Funding for AI Endpoint Security Platform The endpoint security market is positioned for double-digit growth as AI reshapes both attack and defense.
SE017 FinTech Global Ent's $100m seed signals a shift in cybersecurity thinking Ent's intent-aware approach reflects a broader shift from detection toward prevention in enterprise security.
SE018 DLP Test Ent Emerges from Stealth with $100 Million Seed Round Without independent benchmarks, claims about low false-positive intent detection remain unproven, and DLP buyers have heard prevention promises before.
SE019 The Next Web Ent's $100M seed bets on intent-aware workspace prevention Prevention is back is hardly a contrarian rallying cry anymore, and Ent has yet to publish independent benchmarks for its intent-inference claims.
SE020 Pulse 2.0 Ent Raises $100 Million Seed Round And Emerges From Stealth Ent emerged from stealth with an AI-powered workspace security platform and $100 million in seed funding.
SE021 Morningstar (Business Wire) Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity Ent's platform is deployed across Global 2000 enterprises in hospitality, financial services and defense.
SE022 AIExpert.news Ent Emerges From Stealth With $100M Seed for AI-Aware Endpoint Security Ent positions itself to govern both human users and autonomous AI agents in the workspace.
SE023 BankInfoSecurity (ISMG) Ent Raises $100M to Reinvent Endpoint Security for AI Era An insider-threat lead at a public financial institution said Ent was the first tool where I felt like an expert on day one.
SE024 Mordor Intelligence Endpoint Detection and Response (EDR) Market Size & Share Analysis The EDR market is estimated at $6.33 billion in 2026 and is projected to reach $18.68 billion by 2031 at a CAGR of 24.16%.
SE025 The Business Research Company Endpoint Security Global Market Report 2026 The endpoint security market will grow from $18.58 billion in 2025 to $20.79 billion in 2026 at a CAGR of 11.9%.
SU001 Gartner Peer Insights Endpoint Detection and Response Solutions Reviews Enterprise buyers weight efficacy, ease of deployment and false-positive rates most heavily in endpoint reviews.
SU002 Security Magazine Security Magazine – Enterprise Security News CISOs increasingly prioritize tools that reduce alert fatigue and surface intent, not just events.
SU003 CSO Online CSO Online – Security Leadership Security buyers favor platforms that consolidate insider risk, DLP and AI governance into one agent.
SU004 CIO Dive CIO Dive – Enterprise IT News Enterprises in regulated verticals are early adopters of AI-governance controls for the workforce.
SU005 SC Media SC Media – Cybersecurity News and Analysis Insider-driven incidents continue to rank among the costliest and hardest to detect for enterprises.
SU006 Help Net Security Help Net Security – Industry News Buyers want measurable reductions in time-to-investigate and clearer attribution of risky behavior.
SU007 BankInfoSecurity (ISMG) Insider Threat – News and Resources Financial institutions remain among the most active buyers of insider-threat tooling.
SU008 CISA Insider Threat Mitigation Insider threats can be malicious, negligent, or unwitting, and require detection across the activity lifecycle.
SU009 TechCrunch Ent Raises $100M Seed Round to Combat AI-Driven Cyber Threats Ent said it has already deployed its platform across Global 2000 enterprises spanning hospitality, financial services and defense.
SU010 VentureBurn Ent Raises $100M Seed for Workspace Security The workspace security startup has secured early enterprise customers across regulated industries before emerging from stealth.
SU011 CityBiz Cybersecurity Startup Ent Emerges from Stealth with $100M in Seed Funding Ent's platform is designed for Global 2000 enterprises with the most sensitive and complex security requirements.
SU012 DLP Report Data Loss Prevention Trends 2026 Enterprise DLP buying is shifting from point products toward integrated platforms that also address insider risk and AI governance.
SU013 Business Wire Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity Ent's platform is deployed across Global 2000 enterprises in hospitality, financial services and defense.
SU014 Morningstar (Business Wire) Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity Ent's platform is deployed across Global 2000 enterprises in hospitality, financial services and defense.
SU015 BankInfoSecurity (ISMG) Ent Raises $100M to Reinvent Endpoint Security for AI Era An insider-threat lead at a public financial institution said Ent was the first tool where I felt like an expert on day one.
SU016 SiliconANGLE RiskIQ founders launch Ent with $100M to rethink endpoint defense Ent has already built out a base of Global 2000 customers before coming out of stealth.
SU017 The Next Web Ent's $100M seed bets on intent-aware workspace prevention Prevention is back is hardly a contrarian rallying cry anymore, and Ent has yet to publish independent benchmarks for its intent-inference claims.
SU018 Ent Ent – Intent-Aware Workspace Security Ent brings prevention back to cybersecurity by understanding the intent behind every action in the workspace.
SU019 Ent Ent Platform Overview Ent's lightweight on-device agent observes workspace activity and infers intent using specialized AI models.
SU020 Ent Ent Product Ent supports insider risk detection, AI governance, data loss prevention, last-mile threat prevention and incident investigation.
SU021 FinTech Global Ent's $100m seed signals a shift in cybersecurity thinking Ent's intent-aware approach reflects a broader shift from detection toward prevention in enterprise security.
SU022 IBM Cost of a Data Breach Report Organizations extensively using security AI and automation see significantly lower breach costs and faster containment.
SU023 Verizon Data Breach Investigations Report (DBIR) A meaningful share of breaches involve internal actors through error, misuse or compromised credentials.
SU024 Pulse 2.0 Ent Raises $100 Million Seed Round And Emerges From Stealth Ent emerged from stealth with an AI-powered workspace security platform and $100 million in seed funding.
SU025 DLP Test Ent Emerges from Stealth with $100 Million Seed Round Without independent benchmarks, claims about low false-positive intent detection remain unproven, and DLP buyers have heard prevention promises before.
SR001 GDPR.eu General Data Protection Regulation (GDPR) The GDPR imposes strict obligations on the processing of personal data, including workplace monitoring.
SR002 EUR-Lex Regulation (EU) 2024/1689 (Artificial Intelligence Act) The AI Act sets harmonised rules and obligations for AI systems based on their level of risk.
SR003 U.S. Federal Trade Commission Privacy and Security Business Guidance The FTC enforces against unfair or deceptive practices involving consumer data and security.
SR004 California Attorney General California Consumer Privacy Act (CCPA) The CCPA grants California consumers rights over personal information collected by businesses.
SR005 NIST AI Risk Management Framework The AI RMF helps organizations manage risks to individuals, organizations and society from AI systems.
SR006 IAPP Employee Monitoring and Privacy Employee monitoring sits in a legal gray zone where transparency and proportionality requirements vary sharply by jurisdiction.
SR007 Electronic Frontier Foundation Workplace Privacy Pervasive workplace surveillance raises serious privacy and civil-liberties concerns for employees.
SR008 European Data Protection Board European Data Protection Board The EDPB issues guidance on the processing of employee data and monitoring under EU law.
SR009 Verizon Data Breach Investigations Report (DBIR) A meaningful share of breaches involve internal actors through error, misuse or compromised credentials.
SR010 IBM Cost of a Data Breach Report Organizations extensively using security AI and automation see significantly lower breach costs and faster containment.
SR011 Business Wire Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity Ent today emerged from stealth with $100 million in seed financing to bring prevention back to cybersecurity with an intent-aware workspace security platform.
SR012 Ent Ent - Intent-Aware Workspace Security Ent brings prevention back to cybersecurity by understanding the intent behind every action in the workspace.
SR013 SiliconANGLE RiskIQ founders launch Ent with $100M to rethink endpoint defense The company was founded by Elias Manousos and Brandon Dixon, who previously built RiskIQ before its $500 million-plus acquisition by Microsoft.
SR014 FinTech Global Ent's $100m seed signals a shift in cybersecurity thinking Ent's intent-aware approach reflects a broader shift from detection toward prevention in enterprise security.
SR015 BankInfoSecurity (ISMG) Ent Raises $100M to Reinvent Endpoint Security for AI Era An insider-threat lead at a public financial institution said Ent was the first tool where I felt like an expert on day one.
SR016 The Next Web Ent's $100M seed bets on intent-aware workspace prevention Prevention is back is hardly a contrarian rallying cry anymore, and Ent has yet to publish independent benchmarks for its intent-inference claims.
SR017 DLP Test Ent Emerges from Stealth with $100 Million Seed Round Without independent benchmarks, claims about low false-positive intent detection remain unproven, and DLP buyers have heard prevention promises before.
SR018 Morningstar (Business Wire) Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity Ent's platform is deployed across Global 2000 enterprises in hospitality, financial services and defense.
SR019 Tech Funding News Ent: ex-Microsoft Security Copilot founders raise $100M for AI threats Brandon Dixon spearheaded the launch of Microsoft Security Copilot before co-founding Ent.
SR020 DataM Intelligence Ent Raises $100 Million Seed Funding for AI Endpoint Security Platform The endpoint security market is positioned for double-digit growth as AI reshapes both attack and defense.
SR021 The Wall Street Journal Cyber Startup Ent Raises $100 Million in Seed Funding Launched in 2025, Ent has about 100 workers and is led by RiskIQ co-founder Elias Manousos.
SR022 Business Outstanders Ent's $100M Seed Funding for AI Endpoint Security Ent uses specialized AI models to evaluate the intent of users and AI agents in real time.
SR023 Mordor Intelligence Endpoint Detection and Response (EDR) Market Size & Share Analysis The EDR market is estimated at $6.33 billion in 2026 and is projected to reach $18.68 billion by 2031 at a CAGR of 24.16%.
SR024 The Business Research Company Endpoint Security Global Market Report 2026 The endpoint security market will grow from $18.58 billion in 2025 to $20.79 billion in 2026 at a CAGR of 11.9%.
SR025 Microsoft Microsoft Defender for Endpoint Defender for Endpoint is included with Microsoft 365 E5 and provides industry-leading endpoint protection.
SR026 CrowdStrike CrowdStrike Falcon Platform The CrowdStrike Falcon platform delivers cloud-native, AI-powered endpoint and workload protection.
SR027 NIST SP 800-53 Rev. 5 Security and Privacy Controls SP 800-53 provides a catalog of security and privacy controls for information systems and organizations.
SR028 OWASP OWASP Top 10 for Large Language Model Applications Excessive agency and prompt injection are leading risks for LLM-based applications and autonomous agents.
SR029 Cloud Security Alliance Artificial Intelligence Research Securing AI agents requires controls over their permissions, actions and data access in real time.
SR030 CISA Insider Threat Mitigation Insider threats can be malicious, negligent, or unwitting, and require detection across the activity lifecycle.
SV001 StockAnalysis.com CrowdStrike Holdings (CRWD) Stock Overview CrowdStrike trades at a premium revenue multiple reflecting durable growth and high retention.
SV002 StockAnalysis.com SentinelOne (S) Stock Overview SentinelOne's market value reflects strong growth tempered by ongoing operating losses.
SV003 StockAnalysis.com Palo Alto Networks (PANW) Stock Overview Palo Alto Networks is among the largest pure-play cybersecurity companies by market capitalization.
SV004 Macrotrends CrowdStrike Market Cap History CrowdStrike's market capitalization has compounded substantially since its 2019 IPO.
SV005 Wiz Wiz Newsroom Wiz scaled to one of the fastest revenue ramps in software history before its landmark acquisition agreement.
SV006 Aventis Advisors Cybersecurity M&A Report Strategic acquirers continue to pay premiums for differentiated security platforms with enterprise traction.
SV007 CB Insights Cybersecurity Trends Report AI-native security and agentic-AI governance are among the most-funded emerging cybersecurity themes.
SV008 Meritech Capital Comparables Table High-growth security software trades at elevated enterprise-value-to-revenue multiples relative to the broader SaaS index.
SV009 Sacra Wiz - Revenue, Growth and Valuation Wiz reached $100M ARR in roughly 18 months, a benchmark for category-defining security startups.
SV010 Carta Startup Valuations and Round Data Outsized seed rounds raise the bar for subsequent rounds, compressing the margin for execution error.
SV011 Business Wire Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity Ent today emerged from stealth with $100 million in seed financing to bring prevention back to cybersecurity with an intent-aware workspace security platform.
SV012 Ent Ent - Intent-Aware Workspace Security Ent brings prevention back to cybersecurity by understanding the intent behind every action in the workspace.
SV013 SiliconANGLE RiskIQ founders launch Ent with $100M to rethink endpoint defense The company was founded by Elias Manousos and Brandon Dixon, who previously built RiskIQ before its $500 million-plus acquisition by Microsoft.
SV014 FinTech Global Ent's $100m seed signals a shift in cybersecurity thinking Ent's intent-aware approach reflects a broader shift from detection toward prevention in enterprise security.
SV015 BankInfoSecurity (ISMG) Ent Raises $100M to Reinvent Endpoint Security for AI Era An insider-threat lead at a public financial institution said Ent was the first tool where I felt like an expert on day one.
SV016 The Next Web Ent's $100M seed bets on intent-aware workspace prevention Prevention is back is hardly a contrarian rallying cry anymore, and Ent has yet to publish independent benchmarks for its intent-inference claims.
SV017 DLP Test Ent Emerges from Stealth with $100 Million Seed Round Without independent benchmarks, claims about low false-positive intent detection remain unproven, and DLP buyers have heard prevention promises before.
SV018 Morningstar (Business Wire) Ent Emerges from Stealth to Bring Prevention Back to Cybersecurity Ent's platform is deployed across Global 2000 enterprises in hospitality, financial services and defense.
SV019 Tech Funding News Ent: ex-Microsoft Security Copilot founders raise $100M for AI threats Brandon Dixon spearheaded the launch of Microsoft Security Copilot before co-founding Ent.
SV020 DataM Intelligence Ent Raises $100 Million Seed Funding for AI Endpoint Security Platform The endpoint security market is positioned for double-digit growth as AI reshapes both attack and defense.
SV021 The Wall Street Journal Cyber Startup Ent Raises $100 Million in Seed Funding Launched in 2025, Ent has about 100 workers and is led by RiskIQ co-founder Elias Manousos.
SV022 Business Outstanders Ent's $100M Seed Funding for AI Endpoint Security Ent uses specialized AI models to evaluate the intent of users and AI agents in real time.
SV023 Decibel Decibel - Venture capital for technical founders Decibel partners with founders building foundational enterprise and security companies.
SV024 The SaaS News Ent Raises $100M in Seed Funding The round was led by Decibel, with participation from Sequoia, Craft Ventures, Crosspoint Capital and others.
SV025 Pulse 2.0 Ent Raises $100 Million Seed Round And Emerges From Stealth Ent emerged from stealth with an AI-powered workspace security platform and $100 million in seed funding.
SV026 Mordor Intelligence Endpoint Detection and Response (EDR) Market Size & Share Analysis The EDR market is estimated at $6.33 billion in 2026 and is projected to reach $18.68 billion by 2031 at a CAGR of 24.16%.
SV027 The Business Research Company Endpoint Security Global Market Report 2026 The endpoint security market will grow from $18.58 billion in 2025 to $20.79 billion in 2026 at a CAGR of 11.9%.
SV028 HiQual Insights Cybersecurity XDR / AI-SOC Market 2026-2031 The XDR and AI-SOC market is projected to grow from $33.4 billion in 2025 to $89 billion by 2031 at a CAGR of 22.6%.
SV029 CrowdStrike CrowdStrike Falcon Platform The CrowdStrike Falcon platform delivers cloud-native, AI-powered endpoint and workload protection.
SV030 SentinelOne SentinelOne Singularity Platform Singularity delivers autonomous, on-device AI that detects and remediates threats in real time with one-click rollback.