Startup Diligence
Diligence report cybersecurity Series A 2026-07-28

Neo Security

Neo Security Diligence Report

Neo is an intriguing, well-funded agentic-security startup with a coherent product thesis, but the public record is still too thin on customer proof and price clarity to justify more than a track stance.

Cover facts

Total Funding 01
$100M [CI001]
Launch Date 02
2026-07-20 [CO001]
Core Product 03
Agentic software control [CO003]
Headcount Signal 04
~50 employees [CI009]
Customer Proof 05
No named public references [CU009]
Valuation Visibility 06
Not publicly confirmed [CV004]

Company profile

Neo Security emerged from stealth in July 2026 as a Boston-based cybersecurity company focused on enterprise control for AI agents and AI-enabled software. Founded by Nick Warner, Shlomi Salem, and Eran Shirazi, Neo positions itself as an "agentic software control" platform that inventories agentic software, analyzes capabilities and risk, attributes actions across human and non-human actors, and enforces policy before risky behavior spreads across enterprise workflows. The company launched with a headline $100 million funding announcement and a product narrative tightly aligned to growing enterprise concern about autonomous software embedded in sanctioned tools. Public evidence supports the category urgency and founder quality more strongly than it supports customer depth, commercial metrics, or a precise current valuation.

Website
www.neo.ai
Founded
2024-01-01
Founders
Nick Warner, Shlomi Salem, Eran Shirazi
Founding location
Boston, Massachusetts, United States / Tel Aviv, Israel
Headquarters
Boston, Massachusetts, United States
Product
Neo sells an enterprise platform for discovering agentic software, understanding what those systems can access and do, attributing actions across humans and agents, and applying policy controls that can allow, hold, or block risky actions in real time.
Customers
Large enterprises, especially security-mature and regulated organizations where CISOs, SecOps, governance, identity, and security-architecture teams need visibility and control over AI agents.
Business model
Likely enterprise subscription software sold through a consultative security motion with pilots, demos, and staged production rollout rather than a self-serve product-led model.
Stage
Series A company with large 2026 financing and active commercialization buildout.
Funding status
Public evidence strongly supports a $100 million total funding headline and suggests a large 2026 Series A structure, but the exact post-money valuation and full round terms remain unresolved.
[CO001, CO003, CO005, CI001, CI003, CU001, CV004]

Executive summary

Top strengths

  • Coherent product narrative around a fast-growing enterprise AI-agent security problem.
  • Elite investor sponsorship and large initial capital base.
  • Clear positioning around discovery, attribution, and action-level policy control.

Top risks

  • Public customer proof remains sparse, with no named reference accounts in retained sources.
  • Exact valuation and round economics are not cleanly verified in public evidence.
  • Broader security platforms may bundle overlapping controls before Neo establishes a durable wedge.

Open gaps

  • Exact post-money valuation and round-term detail.
  • Revenue, ARR, retention, and customer-count metrics.
  • Production deployment evidence, benchmarks, and reference architectures.

Contents

Chapter 01

01Company Overview

1.1 Identity, Product Scope, and What the Company Is Actually Selling

Neo launched publicly in July 2026 as a cybersecurity vendor built around what it calls “Agentic Software Control.” Across its launch release, homepage, and platform pages, the company repeatedly frames the core problem not as classic malware prevention or API posture management, but as real-time governance of autonomous software operating inside already approved enterprise tools. That distinction matters. Neo is trying to sit above the operating-system boundary and inside the software layer where agents, browser extensions, MCP servers, embedded models, and AI-enabled applications can act with valid user permissions. The commercial promise is therefore not simply visibility into what binary is running, but visibility into what that software can do, what data it can touch, and what action it is attempting right now. The company’s own copy also emphasizes native enforcement, attribution, and posture analysis, implying a control plane product meant for SecOps buyers rather than a narrow developer plug-in or observability widget.[CO001, CO002, CO003, CO004, CO012, CO014]

Neo snapshot KPI table
MetricValue / statusDate or source vintageConfidenceGap or caveat
Launch date2026-07-20SO001 / SO026highNone
HeadquartersBoston, MASO001 / SO016 / SO029highLegal entity details not disclosed
Public financing headline$100M launch fundingSO001 / SO028 / SO030highOfficial materials do not break out tranches
Alternative round view$25M seed + $75M Series ASO024 / SO025 / SO026mediumConflicts with single-round presentation
Lead investorsa16z and BessemerSO001 / SO008 / SO009highBoard rights undisclosed
Employee count11–50 or ~50SO022 / SO026mediumTracker and news precision differ
Open roles37SO006mediumPoint-in-time only
Named customersNot publicly disclosedSO010mediumPilots mentioned but not named

Mixes direct company statements with third-party tracker and press estimates; round structure and headcount remain partially inconsistent across sources.

[CO001, CO002, CO010, CO017, CO018, CO019]
FO002: How Neo positions its company snapshot logic

Neo’s product narrative links agentic-software discovery to runtime governance and policy enforcement.

[CO004, CO014, CO028, CO029]
FO003: Snapshot KPIs and maturity markers

The public record shows strong launch momentum but thin hard-operating disclosure.

Employee-count precision is inconsistent across third-party sources; the KPI is presented as a range rather than a single audited number.

[CO010, CO012, CO013, CO018, CO022]

1.2 Founders, Leadership, and Operating Footprint

The public leadership story is unusually coherent for a freshly launched company. Nick Warner brings a go-to-market and scaling narrative from SentinelOne, Shlomi Salem brings deep detection-engineering and threat-research credibility, and Eran Shirazi adds enterprise software and vulnerability-research depth. That combination gives Neo a plausible founder-market-fit case because the category it is attacking sits between endpoint, identity, and application control rather than inside one legacy silo. Public evidence also shows an early dual-footprint model: Boston appears to anchor operations and corporate functions, while both Neo’s careers page and Calcalist reporting point to a substantial Israeli engineering presence centered in Tel Aviv. The same careers board showed thirty-seven open roles across R&D, sales, operations, finance, and marketing on the run date, which suggests the company is moving from elite founder-led design into broader organizational buildout. What remains missing is a public board map, succession depth below the founding trio, and any formal disclosure of governance structures.[CO005, CO006, CO007, CO008, CO009, CO010]

Leadership and founder table
PersonRoleRelevant backgroundFounder-market fit / coverageKey-person dependency
Nick WarnerCEO / co-founderFormer SentinelOne President and COO; earlier McAfee, Cylance, ForcepointEnterprise GTM, scaling, public-company operating experienceHigh
Shlomi SalemCPO / co-founderFormer SentinelOne VP of Research and detection leaderThreat research, security product design, attacker mindsetHigh
Eran ShiraziCTO / co-founderFormer EasySend co-founder / CTO; Unit 8200 vulnerability researchArchitecture, enterprise software delivery, technical executionHigh

Covers only publicly named founders; no full executive bench or board committee detail is publicly disclosed.

[CO005, CO006, CO007, CO008]

1.3 Funding Structure, Investors, and Who Matters Economically

The most important diligence finding in the capital stack is that the headline is clear but the structure is not. Neo’s official launch release, echoed by several reprints, says the company “emerged from stealth with $100M in funding” from Andreessen Horowitz and Bessemer Venture Partners with participation from Craft Ventures and Merlin Ventures. Independent reporting from Calcalist, Fundraise Insider, and Seedtable breaks that total into a $25 million seed in 2025 and a $75 million Series A in July 2026. Those statements are directionally compatible on total disclosed capital but not on form, and that difference matters because stage labeling affects dilution expectations, governance rights, and how aggressively investors priced go-to-market maturity. The stakeholder picture is otherwise strong: a16z and BVP supply brand, Craft adds enterprise software pattern recognition, Merlin adds cyber-specific channel leverage, and Calcalist also lists several well-known angel backers from the Israeli cyber ecosystem. No retained public source, however, discloses exact post-money valuation, liquidation preferences, board rights, or secondary liquidity.[CO017, CO018, CO019, CO020, CO021, CO025]

Stakeholder or investor map
StakeholderRole in company storyControl / economic importanceEvidenceDiligence ask
Andreessen HorowitzLead investorSignals conviction and likely board influenceSO001 / SO008Request board seat, pro-rata, and governance rights
Bessemer Venture PartnersLead investorCategory endorsement and cyber-market signalingSO001 / SO007Request board observer or governance role
Craft VenturesParticipating investorEnterprise software GTM networkSO001 / SO009Confirm allocation and support commitments
Merlin VenturesParticipating investorCybersecurity distribution and government networkSO001 / SO026Clarify channel leverage and any strategic terms
Angel syndicateBrand and network supportUseful access but unclear control rightsSO026Request cap-table line items and SAFE/seed conversion details

Public evidence supports the stakeholder list but not ownership percentages, board seats, liquidation stack, or secondary components.

[CO017, CO018, CO025, CO026]

1.4 Scale Signals, Milestones, and What Is Proven So Far

Neo has more launch infrastructure than a typical stealth exit, but still much less proof than a mature category leader. Its site already includes a developed homepage, platform narrative, about page, careers board, and launch newsroom assets, which signals a deliberate enterprise go-to-market wrapper rather than a “coming soon” placeholder. The product message is also more specific than many seed-stage AI-security companies: inventory, risk intelligence, attribution, policy control, and native enforcement appear repeatedly across the retained materials. Independent sources add several directional scale signals: Neo claims first-scan deployment in under fifteen minutes, says the sensor is lightweight, and highlights a knowledge base with over 1.2 million cataloged agentic artifacts. Yet the company still lacks named customer references, revenue or ARR disclosure, customer count, and independent efficacy benchmarks. eWeek’s note that Neo has tested with sensitive-sector organizations without naming them is useful, but it is still pre-proof relative to what later chapters will need for customer and financial conviction.[CO010, CO012, CO013, CO030, CO031, CO037]

Milestone table
DateEventTypeAmount / statusParticipantsImplication
2025-08-01Startup Nation Central tracker dates founding to August 2025foundingTracker-reportedSO022Sets earliest retained public origin point
2025-12-31Calcalist says Neo completed a $25M seed during 2025financing$25M seed (reported)a16z, MerlinExplains stealth build period
2026-03-01Calcalist says Neo published research on an accounting-firm data leak while still in stealthproductResearch outputNeo teamShows pre-launch market signaling
2026-05-01Calcalist reports Neo was raising more than $50M while still in stealthfinancingRound in processKraft / investor syndicate per reportSuggests strong pre-launch demand
2026-07-20Neo emerges from stealth publiclygovernanceLaunch eventFounders and investorsPublic category entry
2026-07-20Official launch release headlines $100M in fundingfinancing$100M headlinea16z, BVP, Craft, MerlinFunds GTM and engineering expansion
2026-07-20Calcalist breaks the financing into $75M Series A plus prior $25M seedfinancingConflicting structurea16z, BVP, Craft, MerlinCreates diligence need on exact round labeling
2026-07-28Careers page shows 37 open roles across Boston, Tel Aviv, and U.S. field positionsscalePost-launch hiring surgeNeo recruitingSignals aggressive buildout

This chronology is limited to events visible in retained public evidence and includes one explicit conflict on financing structure that requires offline confirmation.

[CO001, CO010, CO018, CO019, CO022, CO026]
FO001: Neo milestone timeline

Public milestones show an unusually fast progression from stealth financing to a fully wrapped enterprise launch.

Some dates are month-level proxies because trackers and articles do not always publish exact closing dates.

[CO001, CO010, CO018, CO026, CO037]

1.5 Adverse Signals and the Ground-Truth Gaps That Still Matter

The bear case begins with category durability. Security Boulevard’s skeptical read is not that Neo lacks a real problem, but that real problems in cybersecurity often compress into features once platform vendors react. That risk is especially relevant here because CyberArk, Microsoft, Palo Alto Networks, and other incumbents are already extending identity, cloud, and AI controls toward agentic behavior. A second risk is that public evidence remains thin on hard operating facts: customer names, revenue quality, board structure, and exact valuation are all absent from retained primary sources. Even headcount and round structure vary across trackers and news reports. A third risk is concentration. The public brand is tightly tied to the three founders, and the operating model appears split between Boston leadership and Israeli R&D, which can work very well but also concentrates execution and talent risk. The company is therefore easy to understand strategically, but still under-disclosed operationally.[CO020, CO021, CO022, CO030, CO033, CO034]

1.6 Exhibits

Chapter 02

02Market Analysis

2.1 Market Boundary, Included Spend, and Status-Quo Substitutes

Neo does not operate in the broadest possible “AI security” market; it sits in the narrower but faster-forming layer that governs autonomous software actions. Retained sources consistently point to a category that includes discovery of agents and AI-enabled applications, identity or ownership mapping, least-privilege access, runtime authorization, policy enforcement, audit trails, and behavior-aware protection. The boundary should therefore include agentic software control, non-human identity governance, prompt or tool misuse defense, and evidence-oriented runtime controls. It should exclude generic productivity copilots, ordinary EDR, traditional DLP, and model-hosting infrastructure unless those products explicitly govern agent behavior. The practical reason this boundary is still blurry is that many vendors market adjacent capabilities under one label. Prompt Security stretches from employee AI use to homegrown apps and MCP; Oasis frames agentic access management; Zenity frames decision-path governance; Palo Alto frames an end-to-end platform. Buyers are therefore choosing among overlapping control philosophies, not a single standardized product category.[CM001, CM002, CM003, CM015, CM019, CM021]

Market definition table
Segment / categoryIncluded spendExcluded spendBuyer / payerWhy it matters for Neo
Agentic software controlRuntime visibility, policy, audit, authorizationGeneric AI chat subscriptionsCISO / security architectureCore wedge
Agent identity governanceOwnership, credentials, least privilegeTraditional human IAM onlyIAM / identity securityImportant adjacent spend
Agent runtime protectionPrompt/tool misuse blocking, approvalsStatic source-code scanning aloneSecOps / platform securityCore enterprise need
AI posture & inventoryDiscovery, risk classification, configurationStandalone model hostingSecurity operationsCommon land-and-expand path
AI governance / compliance evidenceLogs, reports, control mappingsPure policy consulting without controlsRisk / governance officeBudget amplifier

Boundary is evidence-constrained and intentionally narrower than the broad “AI security” umbrella.

[CM001, CM002, CM003, CM015, CM019, CM021]
FM003: Adoption funnel or value-chain map

Most enterprises move from discovery to governance before committing to deep runtime enforcement.

[CM002, CM014, CM026, CM027]

2.2 Sizing the Category Without Pretending Precision

The clearest explicit market-size lens in retained evidence comes from MarketsandMarkets, which projects the agentic AI security market at roughly $1.65 billion in 2026 growing to $13.52 billion by 2032 at about 42% CAGR. That is useful directional evidence, but it should not be mistaken for a fully investable SAM for Neo. A second lens is adoption timing: Neo and Bessemer cite Gartner's estimate that agentic capabilities in enterprise applications will expand from 5% in 2025 to 40% by end-2026. A third lens is problem urgency: CyberArk reports that 68% of organizations still lack identity controls for AI systems. Together these lenses support the idea that budget formation is beginning rapidly. They do not, however, resolve how much spend will stay standalone versus migrate into bundled IAM, cloud, or AI-platform suites. Neo's realistic SOM is therefore best framed as large enterprises already operating significant agent fleets, not the entire theoretical AI security TAM.[CM004, CM005, CM006, CM007, CM024, CM034]

TAM/SAM/SOM or sizing lens table
LensYear / geographyValueMethodologyConfidenceLimitation
Explicit analyst TAM2026 global$1.65BMarketsandMarkets forecastmediumSingle publisher estimate
Longer-range TAM2032 global$13.52BMarketsandMarkets forecastmediumIncludes broad vendor set
Adoption lens2026 enterprise apps40% with agentic capability by year-endGartner quote via Neo/BVPmediumNot spend directly
Problem lens2026 enterprise identity controls68% lack AI-system controlsCyberArk researchhighNeed not equal near-term budget
Neo-style SOM2026 large enterprisesNarrow early-adopter subsetInference from buyer maturity and disclosure limitslowNo public customer denominator

Combines explicit published estimates with adoption and problem-intensity proxies because no retained source offers a precise Neo-specific SAM.

[CM004, CM005, CM006, CM007, CM024, CM034]
FM001: Market estimate range

Explicit and proxy lenses all point to fast category formation, but only one retained publisher offers dollar sizing.

The SOM range is an inference for early-adopter spend pools, not a disclosed market statistic.

[CM004, CM005, CM024]
FM004: Adoption funnel

Many enterprises will recognize the problem before they fully budget for runtime enforcement.

Illustrative funnel based on evidence-backed market maturity rather than a disclosed survey dataset.

[CM006, CM007, CM028, CM030, CM035]

2.3 Buyer Segments, Budget Owners, and Adoption Path

The most plausible early buyers are CISOs, identity leaders, security architects, and platform-security teams at large enterprises. Composio's governance materials and several competitive vendors all emphasize authentication, permissions, observability, approval flows, and centralized logging, which are not line-of-business responsibilities. Day-to-day users will likely span SecOps analysts, IAM engineers, appsec teams, and governance functions that need to understand who initiated an action, what tool was called, and whether the action should have been allowed. The adoption path also appears staged. Discovery and shadow-AI control are the easiest opening wedge because they provide visible inventory fast. Runtime authorization, blast-radius analysis, and tool-call governance are the harder but more strategic second phase because they require deeper policy definition and more operational trust. Budget will often be fragmented across security, identity, data, and AI-governance programs, which means sales cycles can be educational and political even when the technical problem is obvious.[CM011, CM012, CM013, CM014, CM016, CM025]

Segment / buyer map
SegmentBuyerUserPayerWorkflow / triggerAdoption trigger
Global 2000 with active AI rolloutCISO / security architectSecOps and IAM teamsSecurity budgetShadow AI, auditability, tool controlAgent sprawl becomes visible
Regulated enterpriseCISO / compliance headGovernance and identity teamsSecurity + complianceApproval gates and evidence trailsRegulatory scrutiny
Developer-heavy enterprisePlatform security leadAppSec / developer platformPlatform engineering + securityCode assistants, MCP, tool callsRapid internal agent creation
Cloud-first enterpriseIdentity or cloud security leadIdentity / cloud operationsShared security budgetLeast-privilege agent accessOver-privileged agents
Midmarket early adopterSecurity leadLean security staffMixed IT/securityDiscovery-first deploymentNeed fast inventory before full controls

Buyer roles are inferred from governance and competitor materials rather than a single disclosed survey.

[CM011, CM012, CM013, CM014, CM025]
FM002: Buyer / segment map

Enterprise demand clusters where security teams already own both AI rollout risk and approval workflows.

[CM011, CM013, CM025, CM030]

2.4 Growth Drivers, Adoption Constraints, and Why the Market Can Still Disappoint

The bullish case is straightforward. AI capabilities are being embedded into already approved enterprise software, creating shadow or semi-approved agentic behavior that legacy controls cannot interpret. Agents can invoke tools, move data, and act autonomously, which makes real-time authorization and post-action auditability far more valuable than static policy documents. NIST, OWASP, and the EU AI Act each reinforce some version of governance, traceability, and risk-managed deployment. But the market has clear constraints. Buyers still need ROI proof, and many will ask whether Microsoft, Palo Alto, CyberArk, or another incumbent can solve “enough” of the problem within an existing contract. The category boundary is also messy: identity, DSPM, DLP, runtime testing, AI gateways, and endpoint controls all touch pieces of the same workflow. Security Boulevard's bear case is therefore important: a real problem can still become a very expensive feature rather than a durable standalone platform market.[CM008, CM009, CM010, CM017, CM018, CM026]

Growth drivers and constraints table
Driver / constraintDirectionTimingImplicationDiligence ask
Agentic features embedded in approved softwarepositivenear-termExpands addressable control problem quicklyMeasure pace of approved-app drift
Need for runtime authorization and audit trailspositivenear-termSupports premium control-plane productsAsk for proof of action-level usage
NIST / OWASP / EU AI Act governance pressurepositivemedium-termImproves buyer urgency and compliance framingAssess which sectors feel pressure first
Bundling by incumbentsnegativenear-termCan shrink standalone budget poolMap overlap against Microsoft/Palo Alto/CyberArk
ROI ambiguity and fragmented budget ownershipnegativenear-termSlows adoption even when risks are obviousRequest conversion and time-to-value data

Rows mix hard external facts with evidence-backed market inferences about buying friction.

[CM009, CM010, CM017, CM018, CM026, CM027]

2.5 What This Structure Means for Neo Specifically

For Neo, the market is attractive because the need is emerging quickly enough that greenfield design wins are still possible. The company does not need to win the whole AI security budget; it needs to win the subset of enterprises that already see a control-plane gap between agent discovery and action-level enforcement. That said, the market is crowded and moving fast. Review lists already contain dozens of vendors, while official competitor pages show that runtime guardrails, identity governance, discovery, and auditability are becoming standard language. Neo's opportunity is therefore not that no one else sees the problem, but that many buyers still lack a product that ties inventory, attribution, and enforcement together cleanly enough to operationalize. The risk is that the same overlap that makes the market large also makes it difficult to defend. Later chapters should therefore emphasize where Neo is genuinely differentiated versus where it is simply participating in a rapidly commoditizing control stack.[CM022, CM032, CM033, CM034, CM035]

2.6 Exhibits

Chapter 03

03Competitors

3.1 Who Actually Competes With Neo

The competitive set is broader than a simple list of AI-security startups. Independent landscape sources, vendor lists, and official competitor pages all show at least three overlapping cohorts today. First are startup specialists such as Prompt Security, Noma, Zenity, Oasis, and Astrix that market directly into AI-agent security or adjacent non-human identity control. Second are large platforms such as Microsoft, Palo Alto Networks, and likely CyberArk and CrowdStrike that can extend existing telemetry and distribution into the same budget conversation. Third are broader AI-security or testing vendors that appear in review lists but may not actually compete head-to-head for every control-plane deal. This means Neo should be compared by function, not just by label. It is most directly in the runtime-governance and control-plane subgroup, not the entire AI-safety universe. That nuance matters because broad vendor counts make the market look more crowded than the actual shortlist a Fortune 500 CISO may use.[CP001, CP011, CP012, CP013, CP030, CP031]

Competitor profile table
CompetitorCategoryScale / funding signalTarget segmentDifferentiationLimitation
NeoStartup control plane$100M launch financing headlineEnterprise SecOpsEndpoint-native inventory + attribution + controlLimited public proof
Prompt SecurityBroad AI security startupEstablished enterprise references on homepageEmployee AI, apps, code, MCPBreadth across multiple AI surfacesBreadth may dilute depth
Noma SecurityAI agent runtime startupStrong launch language around first agentic solutionEnterprise AI agentsBlast radius + runtime guardrailsStill startup-scale
ZenityAI agent governance startupStrong research-led positioningEnterprise AI environmentsDecision-path and intent focusLess obvious distribution
Palo Alto NetworksIncumbent platformGlobal security platformLarge enterpriseUnified control plane and installed baseMay be broad rather than specialized
MicrosoftIncumbent platformEmbedded in E5 / Defender ecosystemMicrosoft-heavy enterpriseBuilt-in agentic automation and distributionBest fit may skew to Microsoft stack

Uses public positioning signals only; funding, customers, and deployment scale are not equally disclosed across vendors.

[CP002, CP003, CP004, CP005, CP006, CP009]
FP001: Competitive positioning map

The field separates most clearly along platform breadth and runtime-control depth.

The quadrant is a directional synthesis of public messaging, not a measured benchmark.

[CP014, CP015, CP016, CP018]

3.2 Startup Specialists: Breadth, Depth, and Where Neo Sits Among Them

Among startup specialists, Neo’s strongest relative claim is depth around endpoint-anchored interception and action control. Prompt Security presents a broader AI-security umbrella spanning employee use, homegrown AI apps, code assistants, MCP, and agentic AI, which may open more doors but can also disperse focus. Noma appears closer to Neo on runtime and guardrail language, especially around blast-radius analysis and production enforcement. Zenity likewise focuses on the decision path of agents, arguing that the security problem cannot be reduced to one legacy category. Oasis and Astrix occupy more identity-centric ground, mapping non-human identities, permissions, and least-privilege access. That makes them meaningful alternatives inside identity-led buying motions but somewhat different from Neo’s stated software-control loop. Overall, Neo is neither alone nor generic: it sits in the subset of startups trying to make runtime governance and attribution operational enough for enterprise deployment.[CP002, CP003, CP004, CP007, CP008, CP009]

Feature / capability matrix
Buying criterionNeoPromptNomaOasisZenityPalo Alto
Discovery / inventoryyesyesyesyesyesyes
Runtime guardrails / action controlyesyesyespartialyesyes
Identity / ownership mappingyespartialyesyesyesyes
Audit trail / attributionyespartialyesyesyesyes
Breadth across employee AI / code / appspartialyespartialpartialpartialpartial

Cells are based on public marketing pages and should be treated as directional rather than lab-verified feature parity.

[CP002, CP003, CP004, CP005, CP007, CP009]
FP002: Feature breadth / capability map

Startups and incumbents cover overlapping nouns but not always with the same operating depth.

Comparative ratings are inferred from public product pages and should be pressure-tested in actual demos.

[CP003, CP004, CP005, CP007, CP022, CP029]

3.3 Incumbents, Bundling, and the Distribution Problem

The biggest competitive threat may come from distribution rather than product elegance alone. Palo Alto Networks already markets a unified control plane covering discovery, supply-chain scanning, identity, and runtime policies, while Microsoft embeds Security Copilot agents directly into Defender, Entra, Intune, and Purview. These incumbents start with installed telemetry, enterprise trust, and contract leverage that a startup cannot match. CyberArk’s identity messaging and CrowdStrike’s AI-security materials show that adjacent platforms are also educating the same buyer set. Cisco’s acquisition of Astrix in 2026 is further evidence that large vendors intend to consolidate the category, not ignore it. For Neo, that means a good product is necessary but not sufficient. The company will need to prove that its control depth or deployment model solves a problem that bundled suites still leave exposed, especially in large regulated accounts where platform rationalization matters.[CP005, CP006, CP010, CP018, CP019, CP021]

Pricing / packaging comparison
VendorPublic price / unitContract modelIncluded capabilitiesUnknownsImplication
NeounknownLikely enterprise subscriptionInventory, attribution, policy controlACV, seats, deployment feeCommercial proof still opaque
Prompt SecurityunknownEnterprise platformEmployee AI + apps + code + MCPUsage pricing unclearBreadth may support larger platform sale
NomaunknownEnterprise platformDiscovery + runtime protectionPackaged modules unclearNeed proof of production depth
Palo AltounknownPlatform / suite motionAgent security within broader suiteIncremental pricing not publicBundling leverage likely strong
MicrosoftUnknown public enterprise pricing beyond Security Copilot capacity constructsBundled + compute-basedAgents inside Microsoft security stackNet-effective cost vs E5 unclearBundling may suppress standalone spend

Public pricing visibility is extremely limited, so this table compares packaging opacity rather than exact commercial terms.

[CP020, CP018, CP024, CP035]
FP003: Moat / readiness KPIs

Competitive risk is driven by crowding, distribution imbalance, and category consolidation speed.

[CP019, CP020, CP021, CP023]

3.4 Pricing Opacity, Moat Logic, and Where the Bear Case Lands

Public-web research is surprisingly weak on the commercial mechanics of the category. Very few retained sources publish prices, and almost none reveal contract models, deployment fees, ACVs, or competitive replacement data. That forces a comparison based on architecture, buyer fit, and likely deployment depth rather than sticker price. Neo’s best moat claim is that endpoint-native interception can provide control that identity-only or API-only products cannot match. But that moat is conditional. If incumbents combine endpoint telemetry, identity graphs, and agent orchestration fast enough, the same features could become part of a broader suite. Security Boulevard’s critique captures the core bear case: a real product can still become a feature. As a result, Neo’s competitive durability should be evaluated through proof of production depth, customer urgency, reference density, and how quickly rivals converge on similar runtime-control narratives. In practice, the most valuable next diligence step is not another web search but actual win-loss evidence from recent enterprise evaluations, especially in Fortune 500 bake-offs where bundled-suite alternatives look superficially good enough.[CP020, CP022, CP023, CP025, CP026, CP027]

Moat durability / competitive risk register
Moat claimThreatSeverityMitigation / diligence ask
Endpoint-native interceptionIncumbents add similar control depthhighDemand production proof of actions actually blocked or governed
Control-plane simplicityPlatforms bundle enough overlapping capabilityhighTrack enterprise willingness to buy separate layer
Founder and investor brandCategory overcrowding blurs credibilitymediumValidate reference wins and pilots
Runtime governance focusIdentity-led buyers choose Oasis/Astrix/CyberArk insteadmediumClarify whether Neo can win identity-led deals
Early category timingMarket consolidates before Neo reaches scalehighMonitor M&A and platform partnerships closely

This risk register translates public positioning into durability questions rather than definitive competitive outcomes.

[CP019, CP026, CP027, CP028, CP033, CP034]

3.5 Exhibits

Chapter 04

04Financials

4.1 Revenue Model: What Can Actually Be Inferred

Public evidence does not disclose revenue, ARR, bookings, or customer count. Even so, Neo’s commercial surface is not random. The company markets to SecOps teams, offers demos, runs an ROI calculator, and speaks in the language of enterprise governance rather than consumer product adoption. That combination strongly suggests an enterprise subscription model sold through high-touch evaluations rather than a self-serve SaaS motion. It is also plausible that the model includes implementation, integration, or policy-tuning services, especially because runtime controls often require customer-specific workflows and approvals. But the public record does not disclose whether services revenue is meaningful or purely supportive. The key takeaway is therefore directional: Neo looks like a security software company with enterprise contract ambition, not a pure usage-based API product. The exact balance between subscription, services, and any consumption element remains a diligence gap that matters for both revenue quality, margin profile, and renewal behavior.[CI004, CI005, CI006, CI014, CI015, CI016]

Revenue streams table
StreamMechanismUnitCurrent value / statusQualityDiligence ask
Core platform subscriptionAnnual enterprise software contractContract / seat / endpoint unknownUndisclosedPotentially high if stickyRequest pricing model and average contract size
Implementation / deployment servicesSetup, policy tuning, integrationsProject fee or bundled unknownUndisclosedCould dilute margins if largeRequest services attach rate
Support / successOngoing enterprise supportSubscription add-on or bundled unknownUndisclosedMay improve retentionRequest support packaging
Training / governance consultingPossible early-stage enablementUnknownUndisclosedLikely non-coreClarify whether material
Consumption componentTool calls / events / agent volumeUnknownNo public evidenceUnclearAsk whether any usage pricing exists

Rows separate plausible monetization mechanisms from disclosed facts; almost all values remain private.

[CI005, CI006, CI016, CI026]
Pricing / monetization table
SignalObserved factList vs realized pricingUnknownsSource
Demo-led motionDemos and contact CTAs are prominentRealized pricing unknownACV, minimums, packagingSI004 / SI005
ROI messagingROI calculator existsNo pricing disclosedAssumptions behind ROI modelSI011
Enterprise contractingLegal pages existNo public commercial schedulesOrder form, security addenda, pilotsSI008 / SI009
Self-serve checkoutNo evidence foundN/AWhether small-team plan existsSI003 / SI004
Bundled usage modelNo public evidenceUnknownEvent / endpoint / seat basisSI003 / SI005

Public materials reveal sales posture but not actual price points or realized discounts.

[CI014, CI015, CI028, CI029]
FI001: Revenue model bridge

Neo’s public sales posture points to enterprise contracts rather than self-serve monetization.

This is an inferred enterprise sales flow based on public GTM assets, not a disclosed sales playbook.

[CI005, CI006, CI015, CI016]

4.2 Unit Economics: Mostly Unknown, and That Matters

Almost every underwriting metric investors would want remains undisclosed. There is no public gross margin, no disclosed net revenue retention, no seat count, no contract value range, and no indication of how much ongoing services work is needed per deployment. There is likewise no revenue denominator that would allow a responsible revenue-per-employee or sales-efficiency estimate. That means the financial story is currently dominated by gaps rather than contradictions. The company may already have attractive subscription economics, or it may still be funding heavy deployment effort to prove out a new category; public sources do not distinguish between those cases. The safest interpretation is therefore that Neo is too early and too private for public-web unit-economics analysis, not that the metrics are weak by default. This chapter should be read as an evidence-constrained framework for follow-up diligence rather than a complete model. Signed customer contracts would change the confidence level immediately.[CI017, CI018, CI024, CI032, CI035]

Unit economics table
MetricValue / nullConfidenceWhy it mattersDiligence ask
Gross marginlowDetermines software quality and services burdenRequest GAAP/non-GAAP margin bridge
Net revenue retentionlowShows expansion and product value densityRequest cohort waterfall
Payback periodlowMeasures sales efficiencyRequest CAC and gross-profit payback
Revenue per employeelowQuick productivity signalNeed revenue denominator first
Services mixlowAffects scalability and marginsRequest services vs subscription split

Nulls are intentional because retained sources do not disclose these values.

[CI017, CI018, CI024, CI035]
Public financial gaps table
Missing metricImpactWhy it mattersExact diligence path
ARR / revenue run ratehighNeeded for valuation and sales-efficiency viewsRequest monthly recurring revenue bridge
Gross marginhighNeeded to judge software qualityRequest cost of revenue detail
Customer count and cohort expansionhighNeeded for retention and pricing-power analysisRequest customer ledger and renewal data
Cash on hand and monthly burnhighNeeded for runway analysisRequest board package or finance summary
Cap table and valuation termshighNeeded for dilution and downside analysisRequest financing documents

This table intentionally highlights what public-web diligence cannot close.

[CI004, CI017, CI018, CI032, CI035]
FI002: Unit economics bridge

The financial model is blocked by missing denominators rather than by one contradictory metric.

[CI017, CI018, CI032, CI035]
FI003: Financial estimate range

Only capital and headcount lend themselves to evidence-backed ranges; most operating metrics do not.

The funding range reflects conflicting public round-structure descriptions rather than different cash balances.

[CI001, CI002, CI009, CI010]

4.3 Capital Adequacy, Hiring Intensity, and Burn Direction

The clearest positive financial fact is the size of announced capital. Whether the launch financing is treated as a single $100 million event or as $25 million seed plus $75 million Series A, Neo is entering the public market with materially more capital than a typical seed-stage cyber startup. That said, announced capital is not the same thing as remaining cash. The same public record shows a company in active buildout mode, with thirty-seven open roles spanning product, GTM, legal, finance, and HR, plus outside evidence of roughly fifty current employees. That combination implies burn is moving up, not down. The company appears to be using capital to accelerate market capture while the category is still forming. That can be rational if product-market fit is real and deployment depth proves defensible. It becomes risky if customer conversion lags hiring pace or if bundled incumbents flatten pricing power faster than expected over time.[CI001, CI002, CI003, CI007, CI008, CI009]

Capital adequacy table
MetricValue / statusConfidenceImplicationDiligence ask
Announced launch capital$100M headlinehighStrong funding baseConfirm tranche breakdown and net proceeds
Alternative round framing$25M seed + $75M Series AmediumPossible earlier cash consumptionConfirm closing dates and uses by tranche
Current employees~50 reportedmediumBurn proxy onlyRequest actual HRIS snapshot
Open roles37mediumBurn likely risingRequest hiring plan by quarter
Cash runway monthslowCannot be derived publiclyRequest cash balance and base / growth burn
Next-round triggerTraction-driven rather than narrative-drivenlowFuture financing likely tied to customer proofRequest board plan and financing memo

Separates disclosed capital facts from unknown cash-on-hand and runway metrics.

[CI001, CI002, CI003, CI007, CI009, CI019]
FI004: Capital intensity / cash-flow map

Public evidence points to strong capital but rising spend intensity and low disclosure.

[CI007, CI011, CI019, CI024, CI030]

4.4 Bull, Bear, and the Financial Questions That Still Matter Most

The bull case is that Neo used exceptional founder pedigree and category timing to raise ahead of demand, giving it enough runway to hire aggressively, land reference accounts, and shape a new market before incumbents fully adapt. On that reading, the lack of public metrics is ordinary private-company opacity rather than a warning sign. The bear case is that the same facts simply show a company with expensive expectations and little public evidence of monetization quality. Security Boulevard’s “product becomes feature” warning matters financially because compressed category durability can hit both pricing power and exit multiple, even if the underlying product is real. For diligence, the most important next documents are not more marketing materials but signed customer contracts, cohort behavior, renewal data, and the actual cap table. Until those exist in evidence, the financial posture remains: strong capital headline, serious buildout, and low confidence on operating efficiency today overall.[CI021, CI022, CI023, CI027, CI033, CI034]

4.5 Exhibits

Chapter 05

05Product & Technology

5.1 Product Modules and the User Jobs Neo Is Trying to Solve

Neo’s product pages are unusually explicit about the jobs the platform is meant to do. The core loop starts with inventory: agents, models, skills, MCP servers, extensions, and other software artifacts are all in scope. It then moves into posture and capability analysis, trying to answer what those artifacts can access and whether they are configured safely. From there Neo emphasizes attribution, which matters because autonomous software may act through valid user sessions and otherwise look legitimate. Finally the system enforces policy by allowing, blocking, or holding actions for approval before data moves. In practical terms, the platform is being built for SecOps and governance teams that want to keep adoption moving without surrendering control. That makes the product less like a prompt firewall and more like an operating control layer for enterprise agent workflows. The consistency of that language across multiple public pages is itself a useful maturity signal.[CE001, CE002, CE003, CE004, CE009, CE010]

Product module / asset matrix
Module / assetPrimary userStatus / maturityDifferentiationDiligence gap
Software inventorySecOpsPublicly describedCovers agents, skills, MCP, extensionsNeed proof of detection depth
Capability and risk intelligenceSecOps / governancePublicly describedMaps what software can access and doNeed scoring methodology
Attribution engineSecurity operationsPublicly describedSeparates human and non-human actionNeed production examples
Policy controlSecurity architecturePublicly describedGroup- and identity-specific controlsNeed rule-authoring detail
Native enforcementSecurity operationsPublicly describedBlock / hold before data movesNeed benchmark data

Maps the modules Neo explicitly names in launch and platform materials.

[CE002, CE003, CE009, CE010]
Workflow / use-case table
User jobCurrent workflow painNeo solutionMeasurable benefitLimitation
Find shadow agentic softwareTraditional tools see binaries, not behaviorArtifact-level discovery and enrichmentBetter visibilityCoverage depth not benchmarked
Understand permissions and configurationAutonomous tools inherit opaque accessCapability and risk intelligenceFaster risk triageScoring evidence not public
Determine who actually actedHuman and agent share one sessionAttribution across human and non-human actorsBetter auditabilityNo public case study
Stop dangerous tool useLogs arrive after the factAllow / block / hold controlsReal-time preventionFalse positives unknown
Scale guardrails across teamsRule writing is tediousLLM-assisted policy authoringFaster policy rolloutNeed proof of policy quality

Use cases are inferred from public copy rather than named customer deployments.

[CE004, CE008, CE009, CE010, CE029]
FE002: Customer workflow / operating flow

The operating loop begins with discovery and ends with governed action.

[CE003, CE009, CE010, CE029]

5.2 Architecture, Workflow, and Why the Endpoint Bet Matters

The most distinctive technical claim is architectural, not merely categorical. Bessemer describes Neo as making the harder bet on an endpoint-resident sensor because API-only visibility cannot intercept what agents actually do inside trusted software. Neo’s own material supports that view with language about native enforcement, real-time action control, and software behavior inside already approved applications. The likely control chain is: endpoint telemetry captures what software and agentic components are present; Neoverse enriches those observations with contextual knowledge; capability and risk analysis surfaces what the software can do; policy logic maps allowed, blocked, or held actions; and attribution plus routing preserve the evidence for downstream SOC workflows. That model is well aligned with agentic risks centered on tool use, privilege inheritance, and hidden actions inside approved applications. Whether it is operationally superior in production remains unproven publicly, but the design thesis is clear.[CE005, CE006, CE007, CE008, CE010, CE011]

Technology / operating architecture table
Layer / componentRoleDependencyRisk
Endpoint sensorObserves software and actionsEndpoint deploymentCoverage or performance trade-offs
Neoverse knowledge baseEnriches artifact understandingContinuously updated dataStaleness or classification gaps
Policy engineMaps decisions to actionsRules, groups, identity contextPolicy noise or drift
Attribution layerLinks actions to actorsReliable identity and telemetryAmbiguous ownership chains
SOC / workflow routingSends evidence and actions outwardExisting enterprise toolingIntegration depth unclear

Architecture is synthesized from public product and investor descriptions, not an official reference diagram.

[CE005, CE007, CE011, CE025, CE027]
FE001: Product architecture map

Neo’s design can be read as a layered control stack from telemetry through enforcement.

Conceptual architecture synthesized from public materials rather than an official technical whitepaper.

[CE005, CE007, CE008, CE027]
FE003: Critical dependency map

The architecture depends on high-quality telemetry, enrichment, policy logic, and enterprise workflow integration.

[CE007, CE011, CE025, CE027]

5.3 Trust, Quality, and Maturity Signals

The public trust story is respectable but incomplete. Neo has legal and privacy surfaces, product copy grounded in governance language, and a narrative that maps well to NIST and OWASP-style frameworks. That means the company understands how enterprise buyers think about AI risk. It does not mean the public record proves quality. Retained sources do not disclose public certifications, benchmark results, false-positive rates, mean time to tune policies, or real production performance data. Nor do they show a public integration catalog, a public API reference, or a reference architecture pack. This asymmetry matters. Early-stage cyber companies often launch with excellent conceptual framing before they have enough field proof to substantiate every operating claim. Neo therefore appears mature enough to sell and demo, but still early from an evidence perspective. The missing proof is not fatal, yet it should temper claims about readiness relative to incumbents and should keep diligence focused on implementation depth.[CE012, CE013, CE014, CE022, CE023, CE024]

Trust / quality / compliance table
Control or quality signalStatusScopeGap
NIST / governance alignmentDirectionalNarrative alignment onlyNo formal attestation
OWASP / agentic-risk relevanceDirectionalThreat model alignmentNo published mapping pack
Legal and privacy pagesVisibleEnterprise readiness baselineNot a proof of security efficacy
Independent benchmark resultsNot publicUnknownNeed false-positive and enforcement data
Public certificationsNot found in retained sourcesUnknownNeed SOC 2 / ISO status

Separates governance-aligned storytelling from independently proven assurance.

[CE012, CE013, CE014, CE030, CE033, CE034]
FE004: Product maturity / capability map

Public evidence is strong on architecture and weaker on measured quality.

Assessment is based on retained public materials only.

[CE022, CE024, CE030, CE034]

5.4 Roadmap Focus, Adjacent Competition, and the Bear Case

Neo launched with a focused story rather than a sprawling platform map, and that is probably the right choice. The Black Hat page, event motion, and launch narrative all imply the current roadmap is centered on proving the enterprise control loop: inventory, attribution, policy, and action-level enforcement. External sources also show, however, that many peers and incumbents now speak similar language. Prompt, Noma, Zenity, Palo Alto, Akto, and others all describe combinations of discovery, guardrails, governance, and runtime protection. The bear case is therefore not that Neo lacks a product, but that the product language becomes crowded faster than Neo can prove production depth. If broader platforms absorb enough of the same capability set, Neo’s differentiation will need to rest on operational outcomes—especially whether customers trust it to actually hold or block risky actions in live environments. That remains the central unresolved product question for investors today, especially before broad public deployment evidence emerges commercially.[CE015, CE016, CE017, CE018, CE019, CE020]

Roadmap / release / development-stage table
Date / stageFeature or milestoneStatusImplicationSource
2026-07 launchFive core platform capabilitiesPublicly announcedCore platform is in market narrativeSE005
2026-07 launchNeoverse knowledge basePublicly announcedDifferentiation story leans on data layerSE004
2026-07 launchEndpoint-native enforcement claimPublicly announcedArchitecture is central to thesisSE006
2026-07 launchDemo-led GTM motionPublicly visibleProduct is entering enterprise evaluation cycleSE022
2026-07 runDatePublic docs still mostly marketing-layerObservedDocumentation maturity may trail ambitionSE003 / SE022

Tracks only milestones visible in retained public sources.

[CE003, CE005, CE007, CE015, CE031, CE032]

5.5 Exhibits

Chapter 06

06Customers

6.1 Who Neo Appears to Sell To, and Who Actually Feels the Pain

Neo’s public materials consistently point to a narrow initial customer profile: large enterprises already deploying or evaluating AI agents across browsers, SaaS platforms, developer tools, and internal workflows. The likely economic buyer is the CISO or a senior security leader, because the product is framed as a control layer for risk, attribution, and policy. Day-to-day operators are probably SecOps, security architecture, identity, and governance teams. End users are the business and engineering groups already experimenting with agentic software. This buyer-user-payer split matters because Neo is not selling generic productivity software; it is trying to convert an emerging governance problem into a line item within enterprise security budgets. That should improve deal size if the pain is real, but it also implies long evaluation cycles and a need for strong executive sponsorship before deployment broadens inside an account. In other words, customer quality and political backing inside the enterprise may matter more than top-of-funnel breadth during the first years of commercialization.[CU001, CU002, CU003, CU004, CU005, CU006]

Customer segmentation table
SegmentBuyer / user / payerPrimary use caseStrategic valuePublic gap
Fortune 1000 security teamsBuyer: CISO; Users: SecOps / security architecture; Payer: security budgetInventory and govern AI agentsLarge budget potential and urgent control needNo named references
Regulated enterprisesBuyer: security + compliance; Users: governance and identity teams; Payer: security / riskAuditability, attribution, policy enforcementHigher need for evidence and accountabilityNo public compliance case studies
Tech-forward software companiesBuyer: platform security leaders; Users: engineering security and ITControl internal and third-party agent usageFast experimentation can create demand earlyUnknown conversion pace
Developer-tool-heavy organizationsBuyer: security leadership; Users: appsec / platform / ITSee and manage agentic activity in browsers and toolsMatches Neo narrative around agentic software sprawlNo public deployment metrics
Board-conscious transformation programsBuyer: CIO/CISO coalition; Users: program governance teamsShow enterprise control without halting adoptionCould support strategic, high-ACV dealsBudget owner may be shared or contested

Segments are inferred from launch, investor, and market materials because Neo has not published a customer roster.

[CU001, CU002, CU003, CU005, CU028]
Buyer / user / payer table
RoleLikely responsibilityWhy Neo mattersOpen question
CISOOwns enterprise AI-agent risk postureNeeds a control story for the board and security programHow quickly does the budget get approved?
SecOps leadOperates detections, approvals, and response workflowsNeeds better attribution and action controlsHow noisy is the product in live use?
Security architect / identity teamDefines policy, permissions, and governance patternsNeeds least-privilege and approval logic for agentsHow deep are integrations with IAM and workflow tools?
Business or engineering team using agentsWants productivity and automation gainsNeeds guardrails without blocking useful automationWill controls be seen as friction or enablement?

The buyer map is synthesized from Neo positioning and investor explanations of the problem owner.

[CU004, CU006, CU007, CU017]
FU001: Customer journey map

Neo’s likely customer path starts with discovery of agentic-software exposure and only later expands into policy standardization and account growth.

The journey is inferred from Neo positioning, investor commentary, and enterprise-security buying patterns rather than a published GTM diagram.

[CU003, CU015, CU016, CU018, CU020, CU031]

6.2 What the Public Record Does and Does Not Prove About Adoption

Neo’s demand narrative is credible, but the proof surface is thin. The company, investors, and launch coverage repeatedly describe agentic software as a rapidly escalating enterprise problem, and investor write-ups suggest repeated conversations with CISOs influenced the company thesis. That is useful directional evidence that the category resonates with buyers. What it does not provide is named-customer validation. Retained public sources do not list reference accounts, published case studies, deployment counts, contract values, or renewal metrics. Even the Black Hat motion reads more like executive briefing and pipeline-building than public proof of production scale. The practical conclusion is not that Neo lacks customers; it is that the current evidence base supports early enterprise interest and likely pilots better than it supports claims of broad, durable adoption. That distinction is central to customer diligence because category heat can mask how early the underlying commercial evidence still is.[CU008, CU009, CU010, CU011, CU012, CU013]

Customer growth / adoption trajectory table
SignalWhat is publicDateConfidenceImplication
Stealth exit with large financingCompany launched with $100M headline funding and immediate enterprise-control message2026-07mediumCapital likely funds rapid enterprise selling
Investor CISO feedback loopInvestors describe strong CISO concern around AI-agent risk2026-07mediumCategory pain appears real even if customer names are absent
Executive briefing motionBlack Hat page advertises private meetings and demos2026-07mediumPipeline building and pilot creation are active priorities
Named customer case studiesNone found in retained sources2026-07-28highAdoption depth remains unverified publicly
Renewal / retention dataNone found in retained sources2026-07-28highCustomer durability cannot yet be underwritten

Trajectory uses public go-to-market signals rather than disclosed counts of customers, contracts, or seats.

[CU008, CU010, CU011, CU013, CU014]
Named customer proof table
Proof dimensionObserved statusEvidence qualityWhy it matters
Named customer logosNot foundLowWithout logos, buyer validation is weaker
Published case studiesNot foundLowNo outcome evidence on deployment or ROI
Investor-channel customer signalsPresentMediumShows buyer conversations but not contractual proof
Event / demo activityPresentMediumIndicates active selling motion
Public retention or expansion metricsNot foundLowDurability and upsell quality remain unknown

Separates directional demand signals from hard customer proof.

[CU009, CU010, CU012, CU024, CU033]
FU003: Public adoption proof matrix

Public evidence is strongest on problem urgency and weakest on named customer outcomes.

Assessment reflects retained public sources only.

[CU009, CU012, CU013, CU024, CU033]

6.3 How Adoption Likely Moves from Discovery to Controlled Expansion

The likely customer motion begins with discovery and risk framing rather than with a self-serve trial. Enterprises first need to understand where agentic software already exists, which identities and permissions those systems inherit, and which actions require approval or blocking. That makes Neo’s initial use case diagnostic and governance-heavy. If the platform can quickly surface shadow agentic software or risky actions, the next stage is limited policy deployment on a constrained set of users, business groups, or workflows. Expansion would then depend on whether the product can reduce noise while preserving business velocity. This is a classic land-and-expand cyber motion, but it depends on strong deployment discipline. Because the product touches policy and workflow enforcement, expansion will probably require security, IT, and business stakeholders to trust the same control model rather than only a single champion. It also means time-to-value in the pilot phase will disproportionately shape whether early accounts ever become durable references.[CU015, CU016, CU017, CU018, CU019, CU020]

Concentration / expansion risk table
RiskWhy it could happenEvidenceImpactMitigant
Design-partner concentrationEarly stage likely means a small number of influential accountsNo customer-count disclosureHighBroaden vertical mix and publish references
Pilot-to-production drop-offMany enterprises test agents before full rolloutMarket sources show production adoption lags experimentationHighProve fast time-to-value and low-friction deployment
Bundling pressureIncumbents may add adjacent controls into larger suitesCompetitor chapter shows fast feature convergenceMediumWin on action-level control quality
Shared-budget ambiguitySecurity, IT, and business teams may all touch the spend decisionBuyer map is cross-functionalMediumTie value to risk ownership and audit outcomes
Referenceability bottleneckSensitive early customers may resist public disclosureNo named references foundMediumDevelop anonymized proof packs and metrics

Risk table focuses on customer-quality and scaling constraints rather than pure market size.

[CU021, CU023, CU025, CU026, CU035]
FU002: Adoption / deployment funnel

Public evidence suggests a consultative enterprise motion from urgency creation to controlled rollout rather than a pure self-serve funnel.

The flow abstracts likely steps visible in launch and event materials.

[CU008, CU011, CU017, CU019, CU022]

6.4 Durability, Concentration, and Why Customer Quality Matters More Than Logo Count

For Neo, customer quality is more important than raw logo count in the near term. A handful of deeply engaged design partners in regulated enterprises could matter more than many shallow pilots, because the product category is still being defined. The downside is concentration risk. If early adoption is limited to a small set of sophisticated customers, roadmap influence, pricing leverage, and referenceability may all become concentrated. Durability is also unproven. Public sources do not reveal contract structure, time to deploy, usage frequency, policy hit rates, or net retention. In addition, incumbent vendors may bundle adjacent AI-governance features into larger platforms, raising the bar Neo must clear to keep expansion inside each account. Until Neo publishes stronger customer evidence, investors should assume adoption exists but remains early, selective, and vulnerable to proof gaps. Until those proof points appear, any bullish customer narrative should be treated as directional rather than conclusive.[CU023, CU024, CU025, CU026, CU027, CU032]

FU004: Customer durability and concentration risk

The biggest near-term customer risks are proof gaps and early-account concentration rather than lack of theoretical demand.

Scores are directional and not quantitative operating metrics.

[CU023, CU025, CU026, CU035]

6.5 Exhibits

Chapter 07

07Risks

7.1 Regulatory, Legal, and Accountability Risks

Neo’s category sits directly inside a tightening policy environment. Enterprises using autonomous software increasingly need inventories, oversight, logging, accountability, and least-privilege controls, which makes Neo directionally well aligned with the EU AI Act, NIST-style governance, and joint government guidance on agentic AI adoption. Alignment, however, is not immunity. If the company overstates what its controls can prove, or if customers rely on the platform as a substitute for broader compliance programs, responsibility disputes could emerge quickly after an incident. Neo also publishes standard privacy and terms surfaces, but those are baseline legal hygiene rather than evidence that the company has solved complex questions about agency, liability, or regulated-sector deployment. Because agentic AI remains legally fluid, Neo faces a double risk: buyers want help precisely because the rules are evolving, yet evolving rules can also widen diligence burdens, lengthen procurement, and raise the standard for product claims and documentation.[CR001, CR002, CR003, CR004, CR005, CR006]

Regulatory / legal risk register
Rule / issueJurisdictionStatusLikelihoodSeverityMitigationResidual exposureDiligence path
AI accountability and documentation burdenEU / multinationalLive and tighteningMediumHighInventory, logging, oversight, and careful product scopingCustomers may still expect broader compliance coverage than Neo providesAsk for compliance mappings, audit trails, and customer deployment playbooks
Privacy and monitoring sensitivityUS / EU / globalPersistentMediumHighPrivacy policy, clear data handling, scoped telemetryEndpoint and workflow visibility can still trigger reviewRequest data-flow diagrams and retention controls
Liability after autonomous-software incidentsMulti-jurisdictionEmergingMediumHighCareful product claims and approval workflowsResponsibility can still be disputed after harmReview contracts, indemnities, and incident-response assumptions
Sector-specific procurement scrutinyFinance / healthcare / public sectorPersistentHighMediumTarget security-mature customers firstLonger cycles and more documentation needsAsk for regulated-customer readiness evidence

The register ranks risks visible from public materials and current AI-governance guidance rather than from Neo contractual disclosures.

[CR001, CR002, CR003, CR004, CR005, CR031]
FR001: Risk heatmap

Residual risk is highest where public proof is limited and customer reliance could still be significant.

Heat levels are analytical ratings derived from retained public sources.

[CR001, CR009, CR018, CR026]

7.2 Operational, Product, and Security Failure Risks

The most important product risk is not whether Neo has a coherent story; it does. The risk is whether a control plane for agentic software can work accurately enough in live enterprise environments to be trusted with approval and blocking decisions. False positives could slow business workflows, while false negatives could create a dangerous illusion of control. Endpoint-resident or telemetry-heavy architectures may also create deployment friction, performance concerns, or integration complexity that become visible only after pilot stages. Public evidence does not yet disclose benchmarks, tuning effort, detection coverage, or large-scale reference architectures, so investors cannot independently verify how the product behaves under stress. Prompt injection, policy bypass, and overprivileged-agent patterns also mean the threat surface moves as fast as customer adoption. In practice, Neo must prove that it can keep coverage current, decisions understandable, and operator overhead manageable even as the underlying software ecosystem changes rapidly.[CR009, CR010, CR011, CR012, CR013, CR014]

Operational / quality / security risk register
Failure modeLikelihoodSeverityMitigation maturityResidual exposureUnresolved gap
False positives block legitimate workflowsMediumHighUnknown from public sourcesHighNo published operator-noise metrics
False negatives create a false sense of controlMediumHighUnknown from public sourcesHighNo benchmarked efficacy disclosures
Endpoint or telemetry friction slows rolloutMediumMediumConceptually addressed but not provenMediumNo deployment-time evidence
Prompt injection or policy bypass outruns controlsHighHighCategory guidance exists; product proof limitedHighNo public red-team outcome data
Knowledge-base freshness degrades detection qualityMediumMediumCompany claims continuous updatesMediumNo independent validation of update quality

Operational risks are ranked using category threat models and Neo’s currently disclosed product surfaces.

[CR009, CR010, CR011, CR012, CR013, CR014]
FR002: Risk transmission map

Several operational and legal risks transmit directly into adoption, revenue quality, and valuation.

The map shows directional causality rather than measured probabilities.

[CR010, CR012, CR020, CR025]
FR003: Relative risk ranking

Customer proof and operational efficacy are the two most consequential near-term risks.

Scores are directional rankings, not probabilities.

[CR011, CR018, CR020, CR027]

7.3 Commercial, Adoption, and Go-to-Market Risks

Commercially, Neo is exposed to the classic problems of a hot but immature category. Buyer urgency appears real, yet public customer proof remains sparse, which means the company may need to win long enterprise cycles before the market fully accepts a new budget line. If early customers are mostly sophisticated design partners, concentration and roadmap capture risk increase. Procurement could also be slowed by shared ownership across security, IT, engineering, and compliance teams. Meanwhile, broader cybersecurity vendors can frame many adjacent capabilities as extensions of identity, SaaS governance, app security, or AI-runtime security. That does not erase Neo’s differentiation, but it compresses the window in which a specialist can define the category. Strong financing buys time; it does not guarantee that Neo can convert attention into durable, referenceable accounts. Until customer evidence deepens, the commercial risk is less that demand does not exist and more that proof, deployment friction, and bundling pressure keep revenue scale below investor expectations today materially overall.[CR018, CR019, CR020, CR021, CR022, CR023]

Commercial / adoption risk register
RiskLikelihoodSeverityEvidenceMitigation
Sparse public customer proofHighHighNo named references in retained sourcesPublish proof packs and deployment outcomes
Long enterprise evaluation cyclesHighMediumCross-functional buying and new-category educationNarrow initial use cases with rapid time-to-value
Bundling by incumbentsHighHighMultiple broader vendors now market adjacent AI-agent controlsWin on precision and action-level enforcement
Design-partner concentrationMediumMediumCustomer-count opacityBroaden logo base and vertical mix
Budget ownership ambiguityMediumMediumSecurity, IT, and business teams all benefitTie value to explicit risk-owner KPIs

Commercial risks reflect the mismatch between strong market narrative and still-limited customer evidence.

[CR018, CR019, CR020, CR021, CR022, CR023]
Mitigation and kill-criteria table
ThemeBest-case mitigantKill criterionWhat would change the view
Customer proofReferenceable deployments and clearer ROI evidenceNo credible references after heavy spending periodNamed or anonymized production proof
Product efficacyBenchmarks, low-friction rollout, manageable tuningControls cannot be trusted for live approvals or blockingThird-party validation and operator metrics
DifferentiationDemonstrate better action-level control than platformsIncumbents absorb enough capability to flatten Neo’s wedgeSustained evidence of superior enforcement quality
Regulatory positioningClear role boundaries and compliance mappingsCustomers treat Neo claims as insufficient for auditsPublished mappings and sector-ready documentation

This table converts raw risks into investment decision thresholds.

[CR026, CR027, CR028, CR029, CR030, CR036]
FR004: Mitigation logic

The thesis improves only if Neo converts concept leadership into referenceable operational evidence.

Flow summarizes diligence logic rather than a company-published process.

[CR028, CR029, CR036, CR040]

7.4 Strategic Risk Ranking, Mitigations, and Kill Criteria

For diligence purposes, Neo’s risk profile is manageable only if the company converts conceptual leadership into operational evidence quickly. The best mitigants are straightforward in principle: publish stronger reference architectures, add named or anonymized customer proof, show measurable deployment outcomes, and clarify where the platform stops relative to customer compliance obligations. Investors should also define kill criteria in advance. The thesis should weaken materially if the company cannot produce credible customer references, if incumbent suites replicate enough functionality to flatten Neo’s differentiation, or if regulatory and liability burdens make enterprise deployments too cumbersome. Conversely, the thesis strengthens if Neo demonstrates low-friction deployment, meaningful control efficacy, and durable adoption in regulated or security-mature organizations. The company’s capital base provides room to execute, but that room should be treated as an opportunity to validate the thesis rather than as proof that the thesis is already validated.[CR026, CR027, CR028, CR029, CR030, CR036]

7.5 Exhibits

Chapter 08

08Valuation

8.1 Recommendation Frame: Strong Category, Incomplete Price Discovery

Neo checks many boxes that typically support premium private-market pricing: strong founders, top-tier investors, large announced funding, and a category that maps directly to urgent enterprise anxiety around AI agents. If all of those inputs were paired with visible customer proof and a clearly verified mark, the company could plausibly sit near the top end of early-stage cyber valuations. The problem is price discovery. Retained public sources support the $100 million aggregate funding headline far more clearly than they support any exact current valuation. Some third-party trackers and reports imply a large Series A structure, but they do not converge on fully verifiable terms or a confirmed post-money mark. That creates a practical investment issue: Neo may still be an attractive company, yet the precision of any valuation conclusion must be lower than the precision of the category and team story. Recommendation therefore depends on whether investors can validate commercial proof and entry price privately, not on public narrative alone.[CV001, CV002, CV003, CV004, CV005, CV006]

Recommendation summary table
RecommendationConfidenceRisk ratingValuation stanceDecision implication
watchmediumhighunverifiableTrack closely and require private proof on customers, efficacy, and round terms before investing

Recommendation is based on public evidence only and should not substitute for access to private company materials.

[CV001, CV025, CV026, CV027, CV040]
Funding / valuation evidence table
Evidence pointWhat is publicConfidenceImplication
Aggregate fundingMultiple retained sources support a $100M total funding headlineHighCapital strength is real
Series A sizeSeveral third-party sources point to a large 2026 Series A structureMediumRound size likely premium for stage
Exact post-money valuationNot cleanly confirmed in retained public evidenceLowPrecise valuation stance must stay cautious
Revenue baseNo ARR or revenue disclosure foundHighTraditional multiple analysis is speculative
Term detailsNo reliable public term-sheet detail foundHighPrice discipline depends on private diligence

Separates what the public record supports from what it still cannot verify.

[CV002, CV003, CV004, CV005, CV017, CV018]
FV001: Recommendation logic

The recommendation depends on price verification and customer proof more than on category excitement alone.

Flow summarizes investment logic rather than a company-published process.

[CV001, CV006, CV025, CV026, CV027]

8.2 What Could Support a Premium Valuation Anyway

There are real reasons the market could award Neo a premium multiple or strategic premium despite limited public operating data. In 2026, cyber capital remains concentrated in perceived outliers, and agentic AI security is attracting disproportionate attention from investors and acquirers. Neo also benefits from timing: it launched as enterprises are only beginning to understand the risks of autonomous software embedded in sanctioned tools. If the company owns a differentiated control point and can become the standard for attribution and policy enforcement, it could support a premium well above a conventional seed or early Series A benchmark. Comparable market commentary further suggests that investors are willing to pay up for companies positioned at the intersection of AI and cybersecurity, especially when the addressable pain spans identity, application control, and governance. Those are serious valuation supports. They simply do not erase the need to verify product efficacy, customer depth, and the actual terms of the current round.[CV009, CV010, CV011, CV012, CV013, CV014]

Thesis / anti-thesis table
ArgumentWhat would change the view
Neo may own a critical control point for enterprise AI agentsClear proof that customers trust the platform for live controls would strengthen the thesis
Elite investors and timing support premium interestA verified top-decile price without proof would weaken upside
Agentic AI security could become a large standalone budget areaIf adjacent suites absorb the wedge, the anti-thesis strengthens
Execution proof can convert narrative into defensible valueSlow pilot conversion or weak references would worsen the anti-thesis

Pairs the core bullish case with the evidence that would most change conviction.

[CV009, CV013, CV021, CV028, CV033, CV037]
Comparable valuation table
MarkerWhat it suggestsCaution
2026 cyber funding concentrationOutlier companies can command large roundsLarge rounds do not prove durable value
Agentic AI security market mapsThe category is strategically hotMaps often mix stages and business models
Cyber valuation reportsPremium segments can trade above market averagesPublic and private marks are not interchangeable
AI-native security M&A commentaryScarcity can create strategic premiumsM&A premiums cannot be assumed for a startup without proof
Investor-brand signalTop-tier sponsors can support ambitious pricingBrand does not replace customer evidence

Uses market context as a framing tool rather than as a direct pricing formula.

[CV010, CV011, CV012, CV014, CV019, CV020]
FV004: Market context indicators

Market conditions remain favorable for AI-native security funding, but selectivity is high.

Indicators summarize retained market commentary and should be read directionally.

[CV010, CV011, CV013, CV014]

8.3 What Limits Valuation Confidence and Raises Overpayment Risk

The clearest limitation is that Neo’s public evidence is still stronger on category heat than on company-specific outcomes. There are no retained public disclosures of ARR, customer count, net retention, gross margin, or usage depth. That means any revenue-multiple logic has to be hypothetical. The second limitation is comparability. Many 2026 market maps and valuation commentaries blend different types of AI security companies, maturity stages, and commercialization profiles. A premium paid for a later-stage company with proven scale does not automatically transfer to a newly publicized startup, even in the same broad theme. The third limitation is competitive compression. If large platforms absorb enough of Neo’s differentiation before the company establishes referenceable proof, today’s premium narrative could age badly. Together these factors argue against treating an unverified valuation rumor or aspirational mark as investable truth. At minimum, investors should require private diligence that reconciles customer proof, commercial momentum, and round terms before accepting a top-decile price.[CV017, CV018, CV019, CV020, CV021, CV022]

Diligence checkpoints / what changes view table
CheckpointIf positiveIf negative
Named or anonymized production referencesSupports premium confidenceKeeps stance cautious
Evidence of low-friction deploymentImproves probability of expansionRaises GTM and valuation risk
Verified commercial momentumSupports paying for category leadershipMakes a premium mark harder to justify
Clearer round terms and priceAllows disciplined underwritingLeaves entry economics opaque
Durable differentiation versus bundlesImproves upside asymmetryIncreases risk of multiple compression

These checkpoints define what must improve before a public watch stance should upgrade.

[CV023, CV024, CV028, CV029, CV030, CV038]
FV003: Valuation / return range

Public evidence supports only a broad scenario range, not a precise current mark.

Ranges are analytical scenario bands in $M equity value, not observed market marks.

[CV004, CV017, CV018, CV029]
FV005: Risk / reward decision matrix

Upside is high only if proof and price discipline improve together.

Matrix is a decision aid derived from public evidence.

[CV021, CV025, CV027, CV030]

8.4 Decision Logic, Sensitivity, and Price Discipline

The most defensible public conclusion is not a hard target valuation but a disciplined posture. If a prospective investor can privately confirm strong pilot conversion, real production controls, and a cap table that does not already bake in near-perfect execution, Neo remains worth tracking closely and could merit participation. If the ask assumes category leadership before customer validation is visible, the right stance is caution. In simple terms, the investment can work from several paths: exceptional product proof, fast adoption in regulated enterprises, or strategic scarcity in agentic security. It can fail from several as well: slow conversion, weak referenceability, aggressive bundling, or an entry price that leaves little room for execution risk. Given that the exact valuation is not well evidenced publicly, the rational recommendation is watch rather than pass or invest outright. Investors should lean in only if private diligence improves confidence on proof and price simultaneously.[CV025, CV026, CV027, CV028, CV029, CV030]

FV002: Valuation sensitivity

The underwriting case is most sensitive to proof, price, and differentiation durability.

Values are directional sensitivity scores rather than modeled returns.

[CV023, CV024, CV028, CV038]

8.5 Exhibits

Disclaimer

This recommendation is based on public evidence only. Any investment decision should rely on private diligence covering customer references, deployment quality, security efficacy, legal scope, and actual round terms.

Evidence index

Claims
IDStatementConfidenceSources
CO001 Neo emerged from stealth on 2026-07-20 and publicly launched as a cybersecurity company focused on agentic software control. High SO001, SO026, SO028
CO002 Neo is headquartered in Boston, Massachusetts in its public launch materials and later coverage. High SO001, SO016, SO029
CO003 Neo describes itself as the Agentic Software Control company for modern AI-driven enterprises. High SO001, SO002, SO029
CO004 Neo says its platform governs AI agents, AI-enabled applications, browsers, digital identities, and traditional software that is becoming agentic. High SO001, SO002, SO004
CO005 Neo's public founder roster consists of Nick Warner, Shlomi Salem, and Eran Shirazi. High SO001, SO003, SO026
CO006 Nick Warner is CEO and co-founder and previously served as SentinelOne's President and COO through its 2021 IPO. High SO001, SO003, SO026
CO007 Shlomi Salem is CPO and co-founder and previously led detection engineering and threat research at SentinelOne. High SO001, SO003, SO026
CO008 Eran Shirazi is CTO and co-founder and previously co-founded EasySend after earlier Unit 8200 vulnerability-research work. High SO001, SO003, SO026
CO009 Neo's public material shows a dual geography of Boston-based operations plus a large Tel Aviv engineering footprint. Medium SO003, SO006, SO026
CO010 Neo's careers page listed 37 open roles on 2026-07-28. Medium SO006
CO011 The posted roles cluster around Boston operations, U.S. field go-to-market roles, and Tel Aviv R&D functions. Medium SO006
CO012 Neo says customers can deploy its sensor in under 15 minutes for first scan, under one hour for full deployment, and with a 25MB agent footprint. High SO002, SO005
CO013 Neo says Neoverse catalogs more than 1.2 million agentic artifacts and risk profiles. Medium SO005
CO014 Neo's core control loop combines software inventory, posture or risk intelligence, real-time attribution, policy control, and native enforcement. High SO001, SO004, SO028
CO015 Investor and company materials repeat Gartner's estimate that enterprise applications with agentic capabilities will rise from 5% in 2025 to 40% by end-2026. Medium SO001, SO007, SO029
CO016 CyberArk reported that 68% of organizations do not yet have identity-security controls for AI systems, supporting Neo's category urgency. High SO017, SO007
CO017 Andreessen Horowitz and Bessemer Venture Partners are the lead investors named across the launch materials, with Craft Ventures and Merlin Ventures also participating. High SO001, SO008, SO009
CO018 Neo's official launch announcement describes the financing as $100 million without publicly breaking out round tranches. High SO001, SO028, SO030
CO019 Calcalist, Fundraise Insider, and Seedtable each describe the financing as a $75 million Series A following a previously undisclosed $25 million seed round. Medium SO024, SO025, SO026
CO020 Third-party datasets therefore disagree on whether Neo should be underwritten as a single $100 million launch round or as $25 million seed plus $75 million Series A. Medium SO001, SO024, SO025, SO026
CO021 Public sources reviewed do not disclose Neo's exact post-money valuation, making unicorn status directionally plausible but not directly verifiable from retained evidence. Low
CO022 Startup Nation Central describes Neo as founded in August 2025 with 11–50 employees, while Calcalist reports 50 employees with 40 in Israel by July 2026. Medium SO022, SO026
CO023 Calcalist reports that Neo currently employs 50 people, including roughly 40 in Israel. Medium SO026
CO024 Startup Nation Central describes Neo as operating with 11–50 employees and raising $75 million across two rounds, which is directionally consistent on scale but not on total disclosed capital. Medium SO022
CO025 Named angel backers disclosed by Calcalist include Assaf Rappaport, Merav Bahat, Ofir Ehrlich, Ofer Ben-Noon, Omar Adam, and Zaza Pachulia. Medium SO026
CO026 Calcalist's May 2026 pre-launch coverage said Neo had already raised a $25 million seed led by a16z and Merlin and was then raising more than $50 million in a new round. Medium SO027
CO027 Both the launch press release and later coverage say Neo will use the new capital mainly to expand engineering and go-to-market capacity. High SO001, SO024, SO029
CO028 Neo frames the main threat as autonomous software acting with valid user permissions, chaining tools and workflows in ways legacy controls treat as legitimate. High SO001, SO005, SO026
CO029 BVP argues Neo chose an endpoint sensor architecture because API-only visibility cannot intercept or govern agent actions in real time. Medium SO007
CO030 eWeek says Neo is still early and has not yet disclosed independent performance data or detailed customer results. Medium SO010
CO031 eWeek says Neo has tested its approach with organizations in sensitive sectors such as finance and energy but has not named reference customers. Medium SO010
CO032 The careers page and launch copy together imply Neo is in a rapid post-launch buildout rather than a mature scaling phase with fully stabilized functions. Medium SO001, SO006
CO033 Security Boulevard argues the biggest strategic risk is that agentic-security controls could compress into features inside larger endpoint, identity, or cloud suites rather than persist as a standalone platform category. Medium SO013
CO034 BARC frames Neo's governance pitch as increasingly relevant to enterprises preparing for AI-governance obligations such as the EU AI Act. Medium SO012, SO021
CO035 NIST's AI Risk Management Framework reinforces the need for traceability, governance, and controls around AI behavior, aligning with Neo's audit-trail and policy narrative. Medium SO020, SO001
CO036 MarketsandMarkets forecasts the agentic AI security market to expand from about $1.65 billion in 2026 to $13.52 billion by 2032, which supports investor interest but also raises competition risk. Medium SO018, SO019
CO037 Neo's public web presence was broad enough by late July 2026 to include a homepage, platform explainer, about page, careers board, and launch news, indicating it launched with a full enterprise go-to-market wrapper rather than only a stealth landing page. High SO001, SO002, SO003, SO006
CO038 No public board composition, customer count, or revenue run-rate was disclosed in retained evidence, so later diligence chapters must treat those as unresolved. Medium SO001, SO003, SO010
CM001 The agentic-software security market spans visibility, policy, identity, runtime protection, and audit controls for AI agents and AI-enabled applications rather than only model safety or content filtering. High SM004, SM010, SM023
CM002 Composio argues that enterprises increasingly need a management layer, not just a proxy, to handle authentication, permissions, observability, and kill-switches for agents. Medium SM004, SM005
CM003 Agent Security segments the category around identity and access, posture, runtime protection, runtime authorization, and compliance. Medium SM010, SM011
CM004 MarketsandMarkets sizes the agentic AI security market at about $1.65 billion in 2026 and $13.52 billion by 2032. Medium SM001, SM002
CM005 The same MarketsandMarkets forecast implies roughly 42% CAGR through 2032, making the category one of the faster-growing adjacent security segments. Medium SM001, SM002
CM006 Neo and BVP both cite Gartner's estimate that agentic capabilities will appear in 40% of enterprise applications by end-2026 versus 5% in 2025. High SM023, SM024
CM007 CyberArk reports that 68% of organizations still lack identity-security controls for AI systems, supporting a real control gap rather than a purely aspirational market. High SM003, SM024
CM008 OWASP's 2026 agentic applications material formalizes distinct risks such as goal hijacking, tool misuse, identity abuse, and memory poisoning. High SM008, SM009
CM009 NIST's AI Risk Management Framework emphasizes governance, traceability, and ongoing monitoring, which map directly to enterprise demand for agent controls. High SM006, SM004
CM010 The EU AI Act increases buyer interest in auditability and governance for high-impact AI deployments, even when a vendor is not selling directly into Europe. Medium SM007, SM012
CM011 Primary buyers are typically CISOs, security architecture leaders, and identity or platform security teams rather than line-of-business AI teams. Medium SM004, SM010, SM024
CM012 Day-to-day users include SecOps analysts, identity engineers, application-security teams, and governance personnel who need visibility into tool calls and approvals. Medium SM004, SM005, SM011
CM013 Budget ownership is likely fragmented across security operations, identity, data security, and emerging AI governance programs, which slows category scaling. Medium SM004, SM010, SM025
CM014 Adoption commonly starts with discovery or shadow-AI control before expanding into runtime enforcement and least-privilege policy. Medium SM016, SM018, SM020
CM015 Prompt Security positions the market as covering employee AI use, homegrown AI apps, code assistants, MCP, and agentic AI, implying broad adjacencies but also product sprawl. Medium SM016
CM016 Noma emphasizes deep discovery, contextual risk analysis, blast-radius visualization, and runtime guardrails, showing that runtime governance is a core buying criterion. Medium SM017, SM011
CM017 Palo Alto Networks markets a unified control plane for agent identity, supply-chain scanning, behavior testing, and runtime policies, signaling rapid incumbent entry. Medium SM018, SM015
CM018 Microsoft Security Copilot embeds agents and agentic automation inside existing Microsoft security workflows, raising the risk that some buyer demand is satisfied by bundled platforms. Medium SM019
CM019 Oasis frames a distinct subsegment around agentic access management and non-human identity governance. Medium SM020, SM010
CM020 Astrix frames AI agent security through the lens of non-human identities, least-privileged access, and audit trails, but its June 2026 Cisco acquisition also signals early consolidation. Medium SM021
CM021 Zenity argues that agent security requires simultaneous discovery, policy, identity, and runtime defense because no legacy category captures the full decision path of an agent. Medium SM022
CM022 General Analysis, Mindgard, and Akto all publish long vendor lists in 2026, indicating the category is crowded and still searching for a durable leaderboard. Medium SM013, SM014, SM015
CM023 Because many review and benchmark lists mix AI testing, posture management, runtime protection, and governance tools, the practical market boundary remains fluid. Medium SM013, SM014, SM015
CM024 The near-term SOM for a company like Neo is narrower than the headline TAM because the first buyers are mostly large enterprises with active agent deployments and security teams able to sponsor a new control layer. Medium SM004, SM024, SM025
CM025 Regulated sectors such as finance, healthcare, and critical infrastructure are likely early adopters because auditability and action-level approvals matter more there. Medium SM004, SM007, SM023
CM026 One major growth driver is that AI capabilities are being embedded inside already approved SaaS and security tools, making shadow or semi-approved agentic behavior harder to govern. High SM023, SM024, SM016
CM027 A second driver is the shift from passive copilots to agents that can invoke tools, move data, and act autonomously, which increases the need for real-time authorization. High SM004, SM008, SM018
CM028 A major adoption constraint is proof-of-ROI: buyers can understand the risk narrative yet still struggle to justify a standalone spend before incidents or compliance pressure force action. Medium SM025, SM013
CM029 Another constraint is overlap with existing IAM, DSPM, DLP, EDR, and cloud-security programs, which can turn evaluations into platform rationalization debates. Medium SM022, SM025
CM030 A third constraint is that runtime governance is operationally harder than discovery or dashboarding, so buyers may pilot broadly but deploy narrowly. Medium SM017, SM018, SM022
CM031 Security Boulevard's critique that today's product can become tomorrow's feature is a direct adverse argument against rich standalone market assumptions. Medium SM025
CM032 For Neo specifically, the market is attractive because the problem is real, timing is strong, and the category is early enough that a new control-plane vendor can still earn design wins. Medium SM004, SM023, SM024
CM033 For Neo specifically, the market is also risky because incumbents and adjacent startups are already covering most of the same nouns: identity, runtime, posture, audit, and policy. Medium SM017, SM018, SM019, SM020, SM021, SM022
CM034 Public evidence is strong enough to support a bullish market-growth narrative but not precise enough to calculate a company-specific SAM or SOM from disclosed customer counts. Medium SM001, SM023
CM035 The cleanest diligence posture is to treat 2026 as category-creation year for agentic-security budgets, not as proof that long-term spend pools are already stable. Medium SM012, SM025
CP001 The relevant competitive set spans startup specialists and large incumbents rather than a single homogeneous peer group. Medium SP011, SP014, SP015
CP002 Neo positions around endpoint or software-layer control, inventory, attribution, and native enforcement for agentic applications. High SP001, SP002
CP003 Prompt Security positions around employee AI use, homegrown AI apps, code assistants, MCP, and agentic AI, giving it a broad AI-security footprint. Medium SP003
CP004 Noma emphasizes deep discovery, blast-radius analysis, and runtime guardrails tailored to AI agents. High SP004, SP018, SP019
CP005 Palo Alto Networks markets Prisma AIRS as a unified control plane spanning discovery, supply-chain scanning, behavior testing, identity, and runtime policies. Medium SP005
CP006 Microsoft embeds Security Copilot agents into its existing Defender, Entra, Intune, and Purview workflows, making distribution a key advantage. High SP006, SP024
CP007 Oasis frames a distinct identity-centric wedge around agentic access management and non-human identities. Medium SP007
CP008 Astrix frames AI agent security through non-human identities, least-privileged access, and audit trails. Medium SP008
CP009 Zenity positions around discovery, policy, identity, and runtime defense focused on the decision path of agents. Medium SP009
CP010 CyberArk research and messaging reinforce identity-security urgency, making it a likely adjacent incumbent rather than a direct point-solution peer. Medium SP010, SP011
CP011 Agent Security benchmarks the market around identity, posture, runtime protection, runtime authorization, and compliance. Medium SP011, SP013
CP012 MarketsandMarkets includes Microsoft, Palo Alto, CrowdStrike, Noma, Mindgard, Zenity, Astrix, and many others, confirming a crowded field. Medium SP014, SP016, SP017
CP013 Review lists from General Analysis, Mindgard, Akto, and Agent Security all show different vendor orderings, suggesting the leaderboard is not settled. Medium SP012, SP015, SP016, SP017
CP014 Neo’s strongest apparent differentiation is its endpoint-anchored control narrative rather than a pure API, governance, or identity-only stance. Medium SP002, SP003, SP007, SP009
CP015 Noma and Palo Alto are closest to Neo on runtime-governance language because both emphasize action-level controls and guardrails. Medium SP004, SP005, SP018
CP016 Oasis and Astrix skew more identity-centric than Neo, focusing on permissions and non-human identities rather than full software control loops. Medium SP007, SP008, SP020
CP017 Prompt Security is broader than Neo across employee AI, application AI, and code assistants, which can be an advantage in platform breadth but a dilution risk in depth. Medium SP003, SP002
CP018 Microsoft and Palo Alto benefit from pre-existing distribution, adjacent telemetry, and bundling leverage that startups cannot match. Medium SP005, SP006, SP024
CP019 Astrix’s acquisition by Cisco in June 2026 is direct evidence that incumbents are buying their way into the category. High SP020, SP021
CP020 No retained source provides clean public pricing for Neo or most direct competitors, so packaging comparisons are more about architecture than sticker price. Medium SP003, SP004, SP005, SP006
CP021 CrowdStrike’s AI-security material underscores that broader security platforms are also educating the same budget holders Neo wants to reach. Medium SP023
CP022 Buying criteria consistently center on visibility, runtime control, identity or ownership, compliance evidence, and safe production deployment. Medium SP011, SP013, SP018
CP023 The field is crowded enough that distribution and trust may matter as much as any one feature checklist. Medium SP014, SP015, SP019
CP024 Neo has a credible founder and investor brand but less public proof than incumbents on customer scale and ecosystem breadth. Medium SP001, SP006, SP005
CP025 Prompt Security, Noma, and Zenity each market themselves as enterprise AI security leaders, indicating category claims are easy to make and hard to verify comparatively. Medium SP003, SP004, SP009
CP026 Neo’s moat claim is strongest if endpoint-native interception really yields enforcement depth that API-only or identity-only products cannot replicate. Medium SP002, SP009, SP011
CP027 That moat weakens if incumbents can combine endpoint telemetry, identity, and agent orchestration quickly enough to offer “good enough” controls inside larger suites. Medium SP005, SP006, SP025
CP028 The most plausible near-term competitive wedge for Neo is fast, enterprise-grade runtime control for approved software already becoming agentic. Medium SP001, SP002, SP011
CP029 The least differentiated part of the market is inventory or visibility alone, because many vendors now claim some form of discovery. Medium SP004, SP005, SP008, SP009
CP030 A serious competitor matrix must separate platform breadth from deployment depth, because the vendors are not all solving the same problem at the same layer. Medium SP011, SP013, SP015
CP031 MarketsandMarkets and third-party lists include many more companies than a realistic enterprise shortlist, so shortlists will likely be narrowed by existing stack fit and trust. Medium SP014, SP017, SP023
CP032 The category is early enough that acquisitions, partnership announcements, and platform integrations may matter more than published win rates in 2026. Medium SP019, SP020, SP024
CP033 Neo should expect its hardest competition in Fortune 500 accounts to come from incumbents and well-funded control-plane startups, not from generic security software vendors. Medium SP005, SP006, SP018, SP021
CP034 The strongest adverse case is that the market converges on suites where agent controls are one module among many, compressing standalone valuations. Medium SP019, SP020, SP025
CP035 Public-web competitor research still cannot reveal actual pricing, retention, displacement rates, or side-by-side win-loss data, leaving major underwriting gaps. Medium SP003, SP004, SP005, SP006
CI001 Neo's public financing headline is $100 million as of its July 2026 launch. High SI001, SI018, SI020
CI002 Calcalist, Fundraise Insider, and Seedtable describe the financing as a $75 million Series A after a $25 million seed round. Medium SI012, SI014, SI015
CI003 The discrepancy between a single $100 million launch round and a $25M seed plus $75M Series A remains unresolved in retained public evidence. Medium SI001, SI012, SI014, SI015
CI004 Public sources reviewed do not disclose revenue, ARR, gross margin, NRR, or cash balance. Medium SI001, SI003, SI012
CI005 Neo presents itself as an enterprise software platform for SecOps teams, implying a subscription-driven software model rather than a consumer or ad-supported model. Medium SI001, SI003, SI004
CI006 The product narrative around demos, ROI tooling, and sales engineering suggests revenue is expected to come through enterprise contracts with evaluation and rollout phases. Medium SI004, SI005, SI011
CI007 The careers page shows 37 open roles, supporting the view that Neo is in an investment-heavy buildout phase. Medium SI002
CI008 Open roles span GTM, finance, legal, product, and engineering, implying rapid opex expansion across both revenue and corporate functions. Medium SI002
CI009 Calcalist reports Neo has about 50 employees, with roughly 40 in Israel, providing the clearest headcount-based burn proxy in retained evidence. Medium SI012
CI010 Startup Nation Central lists Neo at 11–50 employees, which is directionally consistent but less precise than Calcalist. Medium SI016
CI011 The combination of 50 employees and 37 open roles implies Neo is planning a substantial step-up in payroll and hiring spend after launch. Medium SI002, SI012
CI012 Both company and third-party sources say the new capital will be used mainly to expand engineering and go-to-market teams. High SI001, SI014, SI019
CI013 The presence of finance controller, sales operations manager, human resources, and corporate attorney roles indicates infrastructure spending beyond pure product build. Medium SI002
CI014 No retained source discloses list pricing or minimum contract value for Neo. Medium SI003, SI004, SI005
CI015 Neo’s public site markets demos and ROI messaging rather than self-serve checkout, implying high-touch enterprise sales motion. Medium SI004, SI011
CI016 Because Neo sells into security operations and governance workflows, its revenue quality is more likely to depend on annual or multi-year enterprise subscriptions than usage-only spend. Medium SI001, SI003, SI022
CI017 Public evidence is insufficient to estimate gross margin with confidence because there is no disclosed mix of software, services, support, or cloud inference cost. Medium SI001, SI003, SI004
CI018 Public evidence is insufficient to estimate net revenue retention because there is no disclosed customer cohort or expansion data. Medium SI001, SI003, SI006
CI019 A $100 million launch capital base materially reduces near-term financing pressure even without public revenue disclosure. Medium SI001, SI018, SI024
CI020 If the round truly comprised $25 million seed plus $75 million Series A, Neo may already have consumed substantial stealth build capital before public launch. Medium SI012, SI013, SI014
CI021 The next financing trigger is more likely to be customer traction and production deployments than mere category narrative, because the narrative was already priced into the launch round. Medium SI021, SI022, SI023
CI022 Security Boulevard’s critique implies that if the category becomes a feature, Neo’s pricing power and exit multiple could compress before IPO readiness. Medium SI021
CI023 Craft and BVP both emphasize the speed of agentic adoption, which supports aggressive GTM hiring but does not prove monetization quality. Medium SI022, SI023
CI024 Neo’s financial disclosure profile remains private-undisclosed based on retained public evidence. Medium SI001, SI006, SI007
CI025 The news, blog, and event pages show marketing investment around launch but do not reveal monetization metrics. Medium SI006, SI007, SI010
CI026 A reasonable revenue-stream hypothesis is core platform subscription plus services for deployment, policy tuning, and integrations, but the services share is not disclosed. Low SI003, SI004, SI005
CI027 Because Neo is targeting regulated, high-stakes workflows, successful deals could carry higher ACVs than commodity AI-assistant governance tools, but no public contract data confirms that yet. Low SI003, SI022, SI025
CI028 The ROI calculator implies Neo is trying to articulate quantified value before the company has publicly disclosed its own operating metrics. Medium SI011
CI029 The legal pages suggest Neo is already standing up enterprise contracting infrastructure rather than operating only as a research project. Medium SI008, SI009
CI030 The financial model is currently easiest to underwrite as capital-backed product build with uncertain revenue timing rather than as an already efficient growth machine. Medium SI001, SI002, SI012
CI031 The strongest public balance-sheet fact is the size of announced capital, not the size of current cash on hand. Medium SI001, SI018, SI019
CI032 Without customer count or ARR, it is impossible to derive revenue per employee responsibly from retained sources. Medium SI001, SI012, SI016
CI033 If Neo closes large reference accounts quickly, the same headcount base could become a sign of ahead-of-demand investment rather than overspending. Low SI002, SI021
CI034 If Neo fails to convert the current hiring and marketing push into production customers, the large launch round could turn from strength into an expectation burden. Medium SI002, SI021, SI023
CI035 Public-web financial diligence remains dominated by evidence gaps rather than contradictions on operating results, because the company has disclosed almost none of those results. Medium SI001, SI006, SI007
CE001 Neo’s public product narrative centers on real-time protection for the “agentic enterprise.” High SE001, SE005
CE002 The platform claims to reveal, understand, and control human and non-human activity across devices, browsers, identities, and applications. High SE001, SE003, SE005
CE003 Neo presents five core product capabilities: software inventory, capability and risk intelligence, attribution, granular software control, and native enforcement. High SE005, SE003
CE004 Neo inventories agents, models, skills, MCP servers, extensions, and other software artifacts rather than only top-level application binaries. High SE001, SE003, SE004
CE005 Neo says Neoverse is a continuously updated knowledge base covering more than 1.2 million agentic artifacts and risks. Medium SE004
CE006 Neo claims its sensor can deliver first scan in under 15 minutes, full deployment in under one hour, and a 25MB endpoint footprint. High SE001, SE004
CE007 BVP’s writeup says Neo made a deliberate architectural bet on an endpoint sensor because API-only visibility cannot intercept and govern agent actions in real time. Medium SE006
CE008 Neo’s policy engine is described as LLM-assisted and able to propose or refine policy after observing traffic. Medium SE006, SE003
CE009 Neo emphasizes attribution that ties actions back to the human, agent, application, or identity responsible. High SE005, SE003
CE010 The product is meant to allow, block, or hold actions for approval before sensitive data or systems are touched. High SE001, SE003
CE011 Composio’s MCP governance material highlights centralized identity, policy, and audit control as key enterprise requirements around tool-calling agents. Medium SE012
CE012 OWASP’s 2026 agentic applications material reinforces the need to defend against tool misuse, identity abuse, memory poisoning, and cascading failures. High SE011, SE017
CE013 NIST AI RMF reinforces requirements around governance, traceability, and monitoring that match Neo’s attribution and policy story. High SE010, SE005
CE014 Neo’s privacy policy and terms of service show that the company is already presenting enterprise legal surfaces beyond marketing pages. Medium SE023, SE024
CE015 The Black Hat 2026 event page indicates Neo is already packaging demos and field education around the product. Medium SE022
CE016 Prompt Security, Noma, and Zenity each emphasize overlapping discovery, runtime, and governance capabilities, confirming Neo is not alone in product direction. Medium SE007, SE008, SE009
CE017 Palo Alto’s AIRS 3.0 press and docs show incumbents are moving toward full lifecycle agent security including discovery, identity, behavior testing, and runtime control. High SE013, SE014, SE015
CE018 Akto’s guidance treats runtime guardrails, posture management, discovery, and governance as standard parts of an enterprise AI agent security program. Medium SE016, SE017, SE018
CE019 CrowdStrike’s Charlotte AI page shows that adjacent security vendors increasingly mix AI assistants, investigation workflows, and broader security automation into the same conversation. Medium SE019
CE020 IBM’s 2026 control-gap study supports Neo’s premise that enterprise deployment is outpacing governance readiness. Medium SE020
CE021 Microsoft’s 2026 Work Trend narrative suggests enterprises are redesigning work around agents, which increases demand for operational guardrails rather than one-time code reviews. Medium SE021
CE022 Neo does not publicly disclose independent benchmark results, false-positive rates, or production-scale performance metrics. Medium SE001, SE003, SE005
CE023 Neo also does not publicly disclose named integrations with SIEMs, IdPs, or ticketing platforms in retained sources, though the product messaging implies those workflows. Medium SE001, SE003
CE024 The product looks broad enough to cover discovery, control, and attribution, but not yet documented enough publicly to prove deployment depth versus peers. Medium SE001, SE003, SE025
CE025 Neo’s most distinctive architectural claim remains endpoint-native interception for agentic software already running inside trusted applications. Medium SE004, SE006
CE026 If the category shifts toward control planes embedded inside broader suites, Neo’s product differentiation will need to come from operational depth rather than vocabulary. Medium SE013, SE025
CE027 The likely operating architecture includes endpoint telemetry, knowledge-base enrichment, policy evaluation, attribution, and response routing to existing SOC processes. Medium SE001, SE003, SE006
CE028 The product is built for enterprise operators rather than end users, as shown by its language around SecOps, group-specific policy, and governed approvals. High SE001, SE003, SE005
CE029 Neo’s public materials imply a workflow in which security teams first inventory software, then inspect capabilities, then define or refine policies, then enforce actions. Medium SE001, SE003, SE006
CE030 The trust and quality story is currently stronger on governance framing than on independently measured product outcomes. Medium SE010, SE022, SE024
CE031 Public launch timing and Black Hat messaging imply the roadmap is still early and likely focused on core enterprise control loops rather than long-tail ecosystem breadth. Medium SE005, SE022
CE032 Because agentic AI deployment is moving quickly, the absence of public product docs beyond marketing pages is itself a diligence signal that documentation maturity may lag product ambition. Medium SE003, SE022, SE025
CE033 The company’s legal and privacy pages demonstrate basic enterprise readiness but do not substitute for public evidence of certifications such as SOC 2 or ISO 27001. Medium SE023, SE024
CE034 No retained public source confirms external audit certifications, model-evaluation benchmarks, or a reference architecture pack for customers. Medium SE001, SE023, SE024
CE035 The biggest open product question is not what nouns Neo can name, but how often real customers actually trust it to hold or block actions in production. Low
CU001 Neo’s public positioning targets enterprises coping with AI agents and agentic software rather than consumers or small businesses. High SU001, SU004
CU002 The likely first customer segment is large enterprise security teams trying to govern software that can act with valid user permissions. Medium SU001, SU003, SU006
CU003 Neo’s product framing implies adoption begins where sanctioned software is already gaining agentic features across browsers, SaaS, and tools. High SU001, SU003, SU011
CU004 The economic buyer is most plausibly the CISO or equivalent security executive because the product is framed as a control and governance layer. Medium SU004, SU006, SU007
CU005 SecOps, security architecture, identity, and governance teams are the most likely daily operators if Neo is deployed. Medium SU003, SU006
CU006 Business and engineering teams using AI agents are likely indirect beneficiaries rather than primary buyers. Medium SU001, SU020
CU007 Because the problem crosses security, IT, and business workflows, budget approval likely needs cross-functional sponsorship. Medium SU003, SU019
CU008 Investor materials indicate strong CISO concern around AI-agent risk, supporting demand-side urgency for Neo’s category. High SU006, SU007, SU008
CU009 Retained public sources do not disclose named Neo customers as of 2026-07-28. High SU001, SU004, SU005, SU011
CU010 The Black Hat page and demo CTA show active enterprise outreach, but not confirmed production-scale adoption. High SU005, SU023
CU011 Launch coverage consistently describes the company as selling to enterprises rather than hobbyist or prosumer users. Medium SU009, SU011, SU012
CU012 Public customer proof is currently stronger on buyer conversations and event motion than on case studies or reference accounts. Medium SU005, SU006, SU007, SU024
CU013 No retained public source provides renewal, retention, or customer-count metrics for Neo. High SU001, SU004, SU025
CU014 No retained public source provides price points, seat counts, or contract-value disclosures for Neo. High SU001, SU004, SU011
CU015 A plausible first deployment use case is discovering unknown or poorly governed agentic software already present in the environment. Medium SU001, SU003, SU006
CU016 The second stage of adoption likely involves limited policy deployment for high-risk actions, users, or workflows. Medium SU003, SU005, SU006
CU017 The product’s emphasis on attribution and policy suggests a consultative enterprise motion rather than a pure self-serve onboarding path. Medium SU003, SU005, SU023
CU018 Expansion inside an account likely depends on reducing policy noise while preserving business velocity for agent users. Medium SU003, SU019
CU019 Because enterprises are still early in production AI-agent deployment, Neo probably sells into both experimentation and control-readiness budgets. Medium SU020, SU021, SU022
CU020 Regulated enterprises are especially likely targets because auditability and action attribution become more valuable where oversight burdens are high. Medium SU017, SU018, SU019
CU021 The land-and-expand path is vulnerable to pilot-to-production drop-off if enterprises cannot operationalize the controls broadly. Medium SU021, SU022, SU024
CU022 Public sources support a controlled rollout narrative better than they support immediate fleet-wide deployment claims. Medium SU005, SU017, SU021
CU023 If Neo has only a small number of influential early accounts, design-partner concentration risk could be meaningful. Low SU009, SU024
CU024 Customer quality matters more than raw logo count at this stage because the category still needs deep referenceable proof. Medium SU006, SU024
CU025 Incumbent bundling pressure could make account expansion harder unless Neo proves better action-level control than broader suites. Medium SU024, SU017
CU026 Referenceability risk is elevated because security-sensitive early customers may be reluctant to be named publicly. Low SU005, SU024
CU027 The absence of public deployment metrics should keep any customer-strength assessment in the medium-confidence range. Medium SU011, SU016, SU025
CU028 Neo’s customer story appears tailored to enterprises where AI agents intersect with endpoint, identity, and application governance. Medium SU001, SU006, SU018
CU029 Investor-backed CISO feedback is useful but not equivalent to verifiable customer contracts or production references. High SU006, SU007, SU008
CU030 Event-led visibility can accelerate pipeline creation, but by itself it does not prove high retention or expansion potential. Medium SU005, SU023
CU031 The most plausible adoption sequence is urgency creation, discovery, pilot control deployment, approval workflows, and then broader rollout. Medium SU003, SU005, SU023
CU032 Shared-budget ambiguity may slow deals because several internal teams benefit even if security owns the risk. Low SU019, SU020
CU033 Without named case studies, Neo cannot yet be underwritten as having strong public customer durability. Medium SU009, SU011, SU024
CU034 The public record is consistent with early enterprise interest, probable pilots, and incomplete referenceability rather than with scaled commercial maturity. Medium SU005, SU006, SU011, SU024
CU035 The best next diligence evidence would be deployment timelines, customer references, retention data, and proof that controls work with limited operational friction. Medium SU024, SU019
CR001 Neo’s category is exposed to expanding AI-governance obligations around inventory, oversight, logging, and accountability. High SR007, SR008, SR009
CR002 Public regulatory guidance increasingly expects organizations to document and govern high-impact or high-risk AI uses before incidents occur. High SR007, SR009, SR011
CR003 Neo’s positioning appears directionally aligned with those expectations because it emphasizes discovery, attribution, and policy control. High SR003, SR004, SR026
CR004 Regulated customers may still impose heavy diligence burdens because Neo has not publicly published comprehensive compliance mappings. Medium SR009, SR010, SR016
CR005 Liability questions remain unresolved if customers interpret Neo controls as broader compliance assurance than the platform can actually provide. High SR001, SR012, SR016
CR006 Privacy and monitoring sensitivity are real because endpoint or workflow visibility can trigger internal review even when the security goal is valid. High SR002, SR008, SR016
CR007 Joint government-aligned guidance on agentic AI adoption emphasizes least privilege, monitoring, and accountability rather than blind trust in autonomous systems. High SR012, SR013, SR014, SR015
CR008 Regulatory uncertainty cuts both ways for Neo: it creates demand for control tooling while also increasing buyer caution. Medium SR009, SR011, SR026
CR009 Neo’s biggest product risk is whether customers can trust the platform for live approval or blocking decisions in noisy enterprise environments. Medium SR003, SR006
CR010 False positives could slow legitimate workflows and reduce operator trust in the product. Medium SR017, SR019, SR020
CR011 False negatives could create a dangerous illusion of control if risky agent behavior is missed. Medium SR017, SR019, SR027
CR012 Public sources do not disclose benchmarks, false-positive rates, or deployment-time operating metrics for Neo. High SR003, SR004, SR025
CR013 Endpoint or telemetry-heavy architectures may create rollout friction that becomes visible only after pilots begin. Low SR005, SR029
CR014 Prompt injection and policy-bypass patterns remain fast-moving category risks for any agent-control platform. High SR017, SR018, SR019, SR020
CR015 Because Neo relies on a knowledge layer and policy logic, freshness and classification quality are likely important determinants of efficacy. Medium SR003, SR005
CR016 The absence of public reference architectures makes it harder to judge integration depth and operator overhead. Medium SR003, SR024
CR017 The company’s operational risk is evidence-limited rather than thesis-free; the architecture story is clear, but proof remains incomplete. Medium SR004, SR025, SR026
CR018 Sparse public customer proof is the most important commercial risk because it limits referenceability and reduces confidence in deployment depth. Medium SR006, SR024, SR025
CR019 Enterprise buying cycles may be long because Neo sells into a new category and likely needs education across several stakeholder groups. Medium SR005, SR022, SR029
CR020 Bundling pressure is serious because large vendors increasingly market overlapping AI-agent security or governance capabilities. High SR006, SR023, SR026
CR021 Budget ownership ambiguity can slow deals because risk ownership sits with security while productivity value may sit with business or engineering teams. Medium SR022, SR024
CR022 If early customers are mostly design partners, concentration and roadmap-capture risk rise. Low SR005, SR018
CR023 Strong financing buys time to refine product and GTM, but it also raises expectations for rapid commercial validation. Medium SR004, SR025, SR030
CR024 Market heat can help Neo open doors while also making it easier for competitors and incumbents to flood the space with adjacent messaging. Medium SR005, SR006, SR023
CR025 Operational failures would transmit quickly into longer cycles, weaker expansion, and lower-quality revenue. Medium SR018, SR021, SR022
CR026 The thesis is manageable only if Neo converts conceptual leadership into referenceable operational evidence within the next phase of commercialization. Medium SR006, SR025
CR027 Investors should treat customer proof and operational efficacy as the two highest-priority risks today. Medium SR012, SR018, SR025
CR028 The most valuable operational mitigants would be benchmarks, deployment data, and reference architectures. Medium SR012, SR024
CR029 The most valuable commercial mitigants would be named or anonymized customer references and clearer time-to-value evidence. Medium SR005, SR024
CR030 Kill criteria should include failure to produce credible customer references, failure to sustain differentiation, or evidence that deployment friction is too high. High SR006, SR012, SR026
CR031 Standard legal and privacy pages are necessary enterprise hygiene but not proof that complex AI-liability issues are solved. High SR001, SR002, SR016
CR032 The AI Act and related guidance make documentation quality more important for enterprise AI vendors, even when the vendor is not itself the system operator. High SR007, SR009, SR011
CR033 Public risk evidence is strongest on category threats and weakest on Neo-specific measured outcomes. Medium SR017, SR019, SR025
CR034 A category with real urgency can still disappoint commercially if proof gaps persist after large financing. Medium SR006, SR025, SR030
CR035 The absence of customer metrics means investors should avoid assuming healthy retention or fast expansion. Medium SR024, SR030
CR036 If Neo demonstrates low-friction deployment and credible control efficacy, several major risks fall at once. Low SR005, SR029
CR037 If incumbents flatten the feature wedge before Neo establishes references, valuation risk rises materially. Medium SR006, SR023
CR038 If regulated customers adopt Neo with explicit documentation wins, the legal-risk narrative improves substantially. Medium SR009, SR010, SR026
CR039 If enterprises conclude Neo’s scope is too narrow relative to bundled suites, the company may struggle to justify standalone spend. Medium SR006, SR023
CR040 Capital adequacy reduces financing urgency, but execution evidence still determines whether the risk-adjusted investment case improves. Medium SR004, SR025
CV001 The most defensible public recommendation on Neo is watch rather than invest or pass outright. Medium SV001, SV028
CV002 Retained public sources strongly support Neo’s $100M aggregate funding headline. High SV001, SV007, SV011, SV013
CV003 Several retained third-party sources point to a large 2026 Series A structure, but they do not establish a single fully verified valuation mark. Medium SV008, SV009, SV010
CV004 The exact current valuation is not cleanly confirmed in retained public evidence. High SV001, SV009, SV010
CV005 Because the public record does not resolve price precisely, investors need private diligence on terms and cap table before underwriting a premium mark. High SV003, SV004, SV010
CV006 Neo’s team quality, investor base, and category timing all support sustained market attention. High SV001, SV002, SV005
CV007 Public narrative precision on company quality is higher than precision on current valuation. Medium SV001, SV004, SV028
CV008 A positive investment case therefore depends more on confirming proof and price privately than on public hype. Medium SV001, SV028
CV009 AI-native cyber outliers in 2026 can still attract very large rounds and premium interest. High SV015, SV020, SV021
CV010 Agentic AI security is a strategically hot subcategory in 2026, which supports premium investor attention. High SV015, SV018, SV029
CV011 Cyber funding in 2026 appears concentrated in fewer, stronger companies rather than broadly distributed across the field. High SV020, SV021, SV022, SV023
CV012 Top-tier investor sponsorship can support ambitious pricing by signaling access, conviction, and category relevance. High SV002, SV005, SV006
CV013 Later-stage strategic premiums and public comp commentary suggest upside for differentiated leaders but should not be copied directly onto Neo. Medium SV018, SV024, SV025
CV014 The market is willing to pay more for genuine AI-native security differentiation than for generic AI-washing. Medium SV020, SV023, SV024
CV015 If Neo truly owns a differentiated action-control layer, a premium early-stage price could be supportable in principle. High SV002, SV004, SV005
CV016 Premium interest is easier to justify when a company sits at the intersection of identity, application control, and governance pain. Medium SV004, SV006, SV029
CV017 No retained public source discloses Neo ARR, revenue, or gross margin. High SV001, SV009, SV010
CV018 Without revenue disclosure, any revenue-multiple valuation logic is hypothetical rather than evidence-based. Medium SV017, SV024, SV028
CV019 Comparable sets are noisy because many 2026 AI-security market maps mix different stages, models, and commercialization profiles. Medium SV015, SV017, SV018
CV020 Later-stage or strategic M&A marks are informative for sector heat but are not direct valuation anchors for Neo. Medium SV018, SV024, SV025
CV021 Bundling pressure from broader platforms can compress future valuation upside if Neo’s wedge is not durable. Medium SV023, SV028
CV022 An unverified rumor or aspirational mark should not be treated as investable truth when company-specific proof is still limited. Medium SV010, SV016, SV028
CV023 The underwriting case is most sensitive to customer proof, price clarity, and differentiation durability. Medium SV015, SV024, SV028
CV024 Named or anonymized production references would do more than additional narrative coverage to improve valuation confidence. Medium SV002, SV006, SV030
CV025 Watch is better than pass because the company may still compound meaningfully if private proof validates the public thesis. High SV001, SV002, SV005
CV026 Watch is better than invest because the public record still leaves too much uncertainty about price and commercial depth. Medium SV004, SV017, SV028
CV027 A public invest recommendation would require stronger evidence that entry price leaves room for execution risk. Medium SV003, SV024
CV028 Investors should upgrade the stance only if private diligence confirms referenceable customers, credible deployment quality, and disciplined terms. High SV003, SV006, SV030
CV029 A public pass recommendation would become more compelling if private diligence found weak conversion, poor references, or price that assumes near-perfect execution. Medium SV016, SV028
CV030 Because the exact current valuation is unclear publicly, price discipline remains central to risk-adjusted returns. High SV003, SV004, SV024
CV031 The funding headline itself is meaningful because it gives Neo time to attempt category leadership and customer validation. High SV001, SV011, SV013
CV032 Capital adequacy reduces financing urgency but does not substitute for commercial evidence. High SV001, SV021
CV033 Strong category timing is a support for valuation, but not a license to ignore company-specific execution proof. Medium SV010, SV015, SV028
CV034 Investor-brand signal helps open the premium narrative, yet lasting valuation support still depends on customer outcomes. Medium SV005, SV006, SV028
CV035 Overpayment risk is elevated whenever category heat outruns company-specific proof. Medium SV016, SV028
CV036 If competitors or incumbents flatten Neo’s differentiation, today’s premium narrative could rerate quickly. Medium SV023, SV028
CV037 The best upside case is that Neo becomes a scarce strategic control point for enterprise AI agents before larger suites close the gap. Medium SV002, SV005, SV015
CV038 The best downside case to avoid is paying a top-decile price before customer validation is visible. Medium SV016, SV028
CV039 Private diligence should focus on customer references, pilot conversion, deployment friction, and round mechanics rather than only on market size narratives. Medium SV003, SV030
CV040 On public evidence alone, Neo looks like a company to monitor aggressively rather than a valuation to underwrite confidently. Medium SV001, SV028
Sources
IDPublisherTitleQuote
SO001 Neo Neo Launches With $100M for AI Software Security
SO002 Neo Neo | Agentic Software Control
SO003 Neo About Neo | Agentic Software Security Team
SO004 Neo Agentic Software Control Platform | Neo
SO005 Neo Why Neo
SO006 Neo Careers at Neo
SO007 Bessemer Venture Partners Neo: securing AI agents at the endpoint
SO008 Andreessen Horowitz Investing in Neo
SO009 Craft Ventures Partnering with Neo to Secure Agentic Software
SO010 eWeek Neo Launches With $100M as AI Agents Test Enterprise Identity Controls
SO011 New Tech Europe Neo Launches with $100M to Secure AI Software Across the Enterprise
SO012 BARC Neo raises $100M. AI agent governance meets EU AI Act
SO013 Security Boulevard Today's Product, Tomorrow's Feature: What Neo's $100 Million Really Tells Us
SO014 Enterprise DNA Neo Security Raises $100M to Lock Down Enterprise AI Agents
SO015 The Robotics Media Neo Raises $100M To Secure Agentic Enterprise Software
SO016 Crowdfund Insider Neo Launches with $100M to Secure AI Software Across the Enterprise
SO017 CyberArk Machine Identities Outnumber Humans by More Than 80 to 1
SO018 MarketsandMarkets Agentic AI Security Market Report 2026-2032
SO019 MarketsandMarkets Agentic AI Security Market worth $13.52 billion by 2032
SO020 NIST AI Risk Management Framework
SO021 European Commission Regulatory framework proposal on artificial intelligence
SO022 Startup Nation Central Neo Security company page
SO023 Parsers VC Neo Security – Funding, Valuation, Investors, News
SO024 Fundraise Insider Neo Security Raises $75M Series A to Govern AI Agents
SO025 Seedtable Neo Security Raises 75.0M USD in Series A Funding
SO026 Calcalist CTech SentinelOne veterans raise $100 million to secure the rise of AI agents
SO027 Calcalist CTech Former SentinelOne leaders secure $50 million for stealth cyber startup
SO028 Markets Insider Neo Launches with $100M to Secure AI Software Across the Enterprise
SO029 Pulse 2.0 Neo Raises $100 Million To Secure Agentic AI Software Across Enterprises
SO030 The SaaS News Neo Raises $100M in Funding
SM001 MarketsandMarkets Agentic AI Security Market Report 2026-2032
SM002 MarketsandMarkets Agentic AI Security Market worth $13.52 billion by 2032
SM003 CyberArk Machine Identities Outnumber Humans by More Than 80 to 1
SM004 Composio Enterprise AI Agent Management: Governance, Security & Control Guide (2026)
SM005 Composio MCP Gateway Governance: The Invisible Layer That Makes Enterprise AI Governable
SM006 NIST AI Risk Management Framework
SM007 European Commission Regulatory framework proposal on artificial intelligence
SM008 OWASP GenAI Security Project OWASP Top 10 for Agentic Applications 2026
SM009 OWASP GenAI Security Project Agentic Security Initiative
SM010 Agent Security Agent Security Competitive Landscape Analysis
SM011 Agent Security Features to Look for in AI Agent Security platforms
SM012 Agent Security Why 2026 is the Year of AI Agents
SM013 General Analysis Best AI Security Platforms in 2026
SM014 Mindgard Best AI Security Companies in 2026 (27 Compared)
SM015 Akto Top 15 AI Security Vendors | Companies in 2026
SM016 Prompt Security Prompt Security home
SM017 Noma Security Security Solution for AI Agents
SM018 Palo Alto Networks Prisma AIRS Agent Security
SM019 Microsoft Microsoft Security Copilot
SM020 Oasis Security Oasis Security home
SM021 Astrix Security Astrix Security home
SM022 Zenity Zenity home
SM023 Neo Neo Launches With $100M for AI Software Security
SM024 Bessemer Venture Partners Neo: securing AI agents at the endpoint
SM025 Security Boulevard Today's Product, Tomorrow's Feature: What Neo's $100 Million Really Tells Us
SP001 Neo Neo Launches With $100M for AI Software Security
SP002 Bessemer Venture Partners Neo: securing AI agents at the endpoint
SP003 Prompt Security Prompt Security home
SP004 Noma Security Security Solution for AI Agents
SP005 Palo Alto Networks Prisma AIRS Agent Security
SP006 Microsoft Microsoft Security Copilot
SP007 Oasis Security Oasis Security home
SP008 Astrix Security Astrix Security home
SP009 Zenity Zenity home
SP010 CyberArk Machine Identities Outnumber Humans by More Than 80 to 1
SP011 Agent Security Agent Security Competitive Landscape Analysis
SP012 Agent Security Top 10 AI Agent Security platforms
SP013 Agent Security Features to Look for in AI Agent Security platforms
SP014 MarketsandMarkets Leading Agentic AI Security Companies
SP015 General Analysis Best AI Security Platforms in 2026
SP016 Mindgard Best AI Security Companies in 2026 (27 Compared)
SP017 Akto Top 15 AI Security Vendors | Companies in 2026
SP018 Noma Security Noma Security launches first agentic AI security solution
SP019 Noma Security Press release: Noma Security launches industry’s first comprehensive AI agent security solution
SP020 Cisco Cisco announces intent to acquire Astrix Security
SP021 Cisco Acquisitions by Year
SP022 Akto Akto home
SP023 CrowdStrike State of AI in Cybersecurity
SP024 Microsoft Introducing Microsoft Security Copilot agents
SP025 Security Boulevard Today's Product, Tomorrow's Feature: What Neo's $100 Million Really Tells Us
SI001 Neo Neo Launches With $100M for AI Software Security
SI002 Neo Careers at Neo
SI003 Neo Neo | Agentic Software Control
SI004 Neo Get a Demo | Agentic Software Control | Neo
SI005 Neo Contact Us | Neo
SI006 Neo Neo news index
SI007 Neo Neo blog index
SI008 Neo Neo privacy policy
SI009 Neo Neo terms of service
SI010 Neo Neo Black Hat 2026 page
SI011 Neo Neo ROI calculator
SI012 Calcalist CTech SentinelOne veterans raise $100 million to secure the rise of AI agents
SI013 Calcalist CTech Former SentinelOne leaders secure $50 million for stealth cyber startup
SI014 Fundraise Insider Neo Security Raises $75M Series A to Govern AI Agents
SI015 Seedtable Neo Security Raises 75.0M USD in Series A Funding
SI016 Startup Nation Central Neo Security company page
SI017 Parsers VC Neo Security – Funding, Valuation, Investors, News
SI018 Markets Insider Neo Launches with $100M to Secure AI Software Across the Enterprise
SI019 Pulse 2.0 Neo Raises $100 Million To Secure Agentic AI Software Across Enterprises
SI020 The SaaS News Neo Raises $100M in Funding
SI021 Security Boulevard Today's Product, Tomorrow's Feature: What Neo's $100 Million Really Tells Us
SI022 Bessemer Venture Partners Neo: securing AI agents at the endpoint
SI023 Craft Ventures Partnering with Neo to Secure Agentic Software
SI024 Crowdfund Insider Neo Launches with $100M to Secure AI Software Across the Enterprise
SI025 MarketsandMarkets Agentic AI Security Market Report 2026-2032
SE001 Neo Neo | Agentic Software Control
SE002 Neo About Neo | Agentic Software Security Team
SE003 Neo Agentic Software Control Platform | Neo
SE004 Neo Why Neo
SE005 Neo Neo Launches With $100M for AI Software Security
SE006 Bessemer Venture Partners Neo: securing AI agents at the endpoint
SE007 Prompt Security Prompt Security home
SE008 Noma Security Security Solution for AI Agents
SE009 Zenity Zenity home
SE010 NIST AI Risk Management Framework
SE011 OWASP GenAI Security Project OWASP Top 10 for Agentic Applications 2026
SE012 Composio MCP Gateway Governance
SE013 Palo Alto Networks Palo Alto Networks Secures Agentic AI with Prisma AIRS 3.0
SE014 Palo Alto Networks Prisma AIRS docs
SE015 Palo Alto Networks Agentic Identity Security
SE016 Akto AI Agent Security Program: Complete Enterprise Guide
SE017 Akto Best AI Security Frameworks for Enterprises
SE018 Akto Top 15 AI Security Tools for Enterprises in 2026
SE019 CrowdStrike Charlotte AI
SE020 IBM AI control gap study
SE021 Microsoft 2026 Work Trend Index report
SE022 Neo Neo Black Hat 2026 page
SE023 Neo Neo privacy policy
SE024 Neo Neo terms of service
SE025 Security Boulevard Today's Product, Tomorrow's Feature: What Neo's $100 Million Really Tells Us
SU001 Neo Neo | Agentic Software Control
SU002 Neo About Neo | Agentic Software Security Team
SU003 Neo Agentic Software Control Platform | Neo
SU004 Neo Neo Launches With $100M for AI Software Security
SU005 Neo Neo at Black Hat USA 2026
SU006 Bessemer Venture Partners Neo: securing AI agents at the endpoint
SU007 Craft Ventures Partnering with Neo to Secure Agentic Software
SU008 Andreessen Horowitz Investing in Neo
SU009 NCFA Canada Neo Raises US$100M For Enterprise AI Agent Security
SU010 Ventureburn Neo Raises $100M to Secure AI Agent Enterprise Software
SU011 SiliconANGLE Neo Security bags $100M to build the secure control layer for enterprise AI agents
SU012 The Next Web Neo exits stealth with $100M from a16z and Bessemer to build a control layer for AI
SU013 FinTech Global Neo lands $100m as agentic AI outpaces security teams
SU014 Under30CEO AI Agent Security: Neo Launches With $100M to Lock It Down
SU015 Cyber Ivy Neo launches with $100M for AI agent security
SU016 Enterprise DNA Neo Security Raises $100M to Lock Down Enterprise AI Agents
SU017 BARC Neo raises $100M. AI agent governance meets EU AI Act
SU018 CyberArk Machine identities outnumber humans by more than 80 to 1
SU019 IBM New IBM study finds CIOs and CTOs face growing AI control gap
SU020 Microsoft 2026 Work Trend Index: Agents, human agency and the opportunity for every organization
SU021 Paul Okhrem Enterprise AI Agent Stats 2026: 80% Embed, 31% Deploy
SU022 Neontri Enterprise AI Agents: 2026 Strategy & Deployment Guide
SU023 Neo Get a Demo | Neo
SU024 Security Boulevard Today’s Product, Tomorrow’s Feature? What Neo’s $100 Million Really Tells Us
SU025 Pulse 2.0 Neo: Company Raises $100 Million To Secure Agentic AI Software Across Enterprises
SR001 Neo Terms of Service | Neo
SR002 Neo Privacy Policy | Neo
SR003 Neo Agentic Software Control Platform | Neo
SR004 Neo Neo Launches With $100M for AI Software Security
SR005 Bessemer Venture Partners Neo: securing AI agents at the endpoint
SR006 Security Boulevard Today’s Product, Tomorrow’s Feature? What Neo’s $100 Million Really Tells Us
SR007 European Commission Regulatory framework proposal on artificial intelligence
SR008 NIST AI Risk Management Framework
SR009 GLACIS EU AI Act compliance: complete June 2026 guide
SR010 Enzai EU AI Act: Enterprise Implementation Guide
SR011 European Parliament Think Tank Enforcement of the AI Act
SR012 Mayer Brown Multi-Agency Guidance on Securing Agentic AI Systems
SR013 Global Policy Watch CISA Releases Guidance on the Careful Adoption of Agentic AI Services
SR014 Cloud Security Alliance Five Eyes Issues First Joint Agentic AI Security Guidance
SR015 Cloud Security Alliance Five Eyes Issue First Joint Agentic AI Security Guidance
SR016 Venable Agentic AI Is Here—Legal, Compliance, and Governance Risks You Need to Know
SR017 OWASP Agentic Security Initiative
SR018 OWASP State of Agentic AI Security and Governance 2.01
SR019 Help Net Security Prompt injection still drives most agentic AI security failures in 2026
SR020 Straiker AI Agents Take Center Stage at Black Hat USA 2026
SR021 CyberArk Machine identities outnumber humans by more than 80 to 1
SR022 IBM New IBM study finds CIOs and CTOs face growing AI control gap
SR023 Microsoft Introducing Microsoft Security Copilot agents
SR024 eWeek Neo: AI Agent Security Startup Overview
SR025 SiliconANGLE Neo Security bags $100M to build the secure control layer for enterprise AI agents
SR026 BARC Neo raises $100M. AI agent governance meets EU AI Act
SR027 The Agentic Protocol Black Hat 2026 AI Agents: Critical Trust Warning
SR028 Novee Security Top 8 Black Hat 2026 Briefings for AI Offensive Security Leaders
SR029 Neo Neo at Black Hat USA 2026
SR030 Pulse 2.0 Neo raises $100 million to secure agentic AI software across enterprises
SV001 Neo Neo Launches With $100M for AI Software Security
SV002 Bessemer Venture Partners Neo: securing AI agents at the endpoint
SV003 Neo Terms of Service | Neo
SV004 Neo Agentic Software Control Platform | Neo
SV005 Andreessen Horowitz Investing in Neo
SV006 Craft Ventures Partnering with Neo to Secure Agentic Software
SV007 NCFA Canada Neo Raises US$100M For Enterprise AI Agent Security
SV008 Fundraise Insider Neo Security Raises $75M Series A to Govern AI Agents
SV009 Seedtable Neo Security Raises 75.0M USD in Series A Funding
SV010 Parsers VC Neo Security – Funding, Valuation, Investors, News
SV011 SiliconANGLE Neo Security bags $100M to build the secure control layer for enterprise AI agents
SV012 The Next Web Neo exits stealth with $100M from a16z and Bessemer to build a control layer for AI
SV013 FinTech Global Neo lands $100m as agentic AI outpaces security teams
SV014 Under30CEO AI Agent Security: Neo Launches With $100M to Lock It Down
SV015 AgentMarketCap The Agent Security Market Map 2026
SV016 AgentMarketCap The Agentic AI Valuation Cliff 2026
SV017 AI Funding Tracker Top AI Agent Startups 2026
SV018 Software Strategies Blog $3.6 Billion in Crunchbase Funding, $96 Billion in M&A, and 10 Agentic AI Security Startups
SV019 Build MVP Fast AI Cybersecurity Funding Boom 2026
SV020 SG Analytics 2026 Cybersecurity Funding Trends: AI-Native & SecOps Lead
SV021 Crunchbase News So Far, 2026 Is A Solid Year For Cybersecurity Startup Funding
SV022 Crunchbase News Cybersecurity Funding Holds Up At Robust Levels
SV023 Datatribe Q4 2025 — Valuations Rising, AI Still Running the Show. The 2026 Outlook
SV024 Windsor Drake Cybersecurity Valuation Report 2026
SV025 Momentum Cyber Cybersecurity Quarterly Review - Q1 2026
SV026 Pinpoint Search Group Acquisitions for Security Vendors, Funding For Startups | Q1 2026
SV027 BARC Neo raises $100M. AI agent governance meets EU AI Act
SV028 Security Boulevard Today’s Product, Tomorrow’s Feature? What Neo’s $100 Million Really Tells Us
SV029 IBM New IBM study finds CIOs and CTOs face growing AI control gap
SV030 Neo Neo at Black Hat USA 2026