Neo Security
Neo Security 尽调报告
Neo 是一家值得关注、资金充足的智能体安全创业公司,产品逻辑自洽;但客户验证和价格清晰度的公开记录仍太薄,最多支持继续观察。
封面要素
公司概况
Neo Security 于 2026 年 7 月从隐身状态公开亮相,是一家总部位于波士顿的网络安全公司,聚焦企业对 AI 智能体和 AI 增强软件的控制。公司由 Nick Warner、Shlomi Salem 和 Eran Shirazi 创立,将自身定位为“智能体软件控制”平台:盘点智能体软件,分析能力与风险,归因人类与非人类行为主体的动作,并在高风险行为扩散到企业工作流之前执行策略。公司亮相时宣布融资 $100 million,产品叙事也紧扣企业对自主软件嵌入已获批准工具的担忧。公开证据更能支撑品类紧迫性和创始人质量,对客户深度、商业指标或当前精确估值的支撑则弱得多。
- 成立时间
- 2024-01-01
- 创始人
- Nick Warner, Shlomi Salem, Eran Shirazi
- 创立地点
- Boston, Massachusetts, United States / Tel Aviv, Israel
- 总部
- Boston, Massachusetts, United States
- 产品
- Neo 销售一套企业平台,用于发现智能体软件,理解这些系统能访问什么、能做什么,归因人类和智能体的动作,并用策略控制实时放行、暂缓或阻断高风险动作。
- 客户
- 大型企业,尤其是安全成熟、受监管的组织;这些组织的 CISO、SecOps、治理、身份和安全架构团队需要看见并控制 AI 智能体。
- 商业模式
- 大概率是企业订阅软件,靠顾问式安全销售推进试点、演示和分阶段生产部署,而不是自助式产品驱动模型。
- 阶段
- Series A company with large 2026 financing and active commercialization buildout.
- 融资情况
- 公开证据强力支持 $100 million 总融资这一口径,也指向一笔规模较大的 2026 年 Series A 结构,但精确投后估值和完整轮次条款仍未解决。
执行摘要
主要优势
- 围绕企业 AI 智能体安全这一快速增长问题,产品叙事自洽。
- 顶级投资人背书,初始资本基础充足。
- 定位清晰,聚焦发现、归因和动作级策略控制。
主要风险
- 公开客户验证仍稀少,留存来源中没有具名参考客户。
- 精确估值和轮次经济性尚未被公开证据清晰验证。
- 在 Neo 建立持久切入点之前,更广义安全平台可能把重叠控制能力打包进套件。
未决问题
- 精确投后估值和轮次条款细节。
- 收入、ARR、留存和客户数量指标。
- 生产部署证据、基准测试和参考架构。
目录
01公司概览
1.1 身份、产品范围,以及公司实际在卖什么
Neo 于 2026 年 7 月公开发布,是一家围绕其所谓“智能体软件控制”打造的网络安全厂商。无论是发布新闻稿、官网首页还是平台页面,公司都反复把核心问题界定为:不是传统恶意软件拦截,也不是 API 态势管理,而是对已获批准企业工具内部运行的自主软件做实时治理。这个区分很关键。Neo 试图站在操作系统边界之上,进入软件层:智能体、浏览器扩展、MCP 服务器、嵌入式模型和 AI 增强应用都可以带着有效用户权限行动。因此,商业承诺不只是看见哪个二进制文件在运行,而是看见这类软件能做什么、能触碰哪些数据、此刻正试图执行什么动作。Neo 自身文案也强调原生执行、归因和态势分析,说明它要做的是面向 SecOps 买家的控制平面,而不是狭窄的开发者插件或可观测性小组件。[CO001, CO002, CO003, CO004, CO012, CO014]
| 指标 | 数值 / 状态 | 日期或来源时点 | 置信度 | 缺口或注意事项 |
|---|---|---|---|---|
| 发布日期 | 2026-07-20 | SO001 / SO026 | 高 | None |
| 总部 | Boston, MA | SO001 / SO016 / SO029 | 高 | 法律实体细节未披露 |
| 公开融资口径 | $100M 启动融资 | SO001 / SO028 / SO030 | 高 | 官方材料未拆分批次 |
| 另一种轮次口径 | $25M 种子轮 + $75M Series A | SO024 / SO025 / SO026 | 中 | 与单轮融资呈现冲突 |
| 领投方 | a16z 和 Bessemer | SO001 / SO008 / SO009 | 高 | 董事会权利未披露 |
| 员工数 | 11–50 或 ~50 | SO022 / SO026 | 中 | 跟踪器与新闻报道精度不同 |
| 开放职位 | 37 | SO006 | 中 | 仅为单一时点 |
| 具名客户 | 未公开披露 | SO010 | 中 | 提及试点但未具名 |
混合了公司直接声明、第三方跟踪器和媒体估算;轮次结构和员工人数在不同来源之间仍有部分不一致。
[CO001, CO002, CO010, CO017, CO018, CO019]Neo 的产品叙事把智能体软件发现,与运行时治理和策略执行连在一起。
[CO004, CO014, CO028, CO029]公开记录显示发布动能强,但关键运营披露很少。
第三方来源对员工数精度并不一致;该 KPI 以区间呈现,而不是单一审计数字。
[CO010, CO012, CO013, CO018, CO022]1.2 创始人、领导层与运营足迹
一家刚公开发布的公司,能讲出这样完整的公开领导层故事并不常见。Nick Warner 带来 SentinelOne 的 GTM 与规模化叙事,Shlomi Salem 带来深厚的检测工程和威胁研究可信度,Eran Shirazi 则补上企业软件和漏洞研究经验。这个组合让 Neo 的创始人-市场匹配看起来站得住,因为它切入的品类位于终端、身份和应用控制之间,而不是某个旧有孤岛内部。公开证据还显示,公司早期采用双足迹模式:波士顿似乎承担运营和公司职能,Neo 招聘页与 Calcalist 报道则都指向以特拉维夫为中心的以色列工程团队。截至报告运行日,同一招聘板显示 37 个开放岗位,覆盖研发、销售、运营、财务和市场,说明公司正从精英创始人主导的设计阶段,进入更宽的组织搭建阶段。仍然缺失的是公开董事会图谱、创始三人以下的接班深度,以及任何正式治理结构披露。[CO005, CO006, CO007, CO008, CO009, CO010]
| 人员 | 职位 | 相关背景 | 创始人-市场匹配 / 覆盖 | 关键人依赖 |
|---|---|---|---|---|
| Nick Warner | CEO / 联合创始人 | 前 SentinelOne 总裁兼 COO;早期任职于 McAfee、Cylance、Forcepoint | 企业 GTM、规模化、上市公司运营经验 | 高 |
| Shlomi Salem | CPO / 联合创始人 | 前 SentinelOne 研究副总裁和检测负责人 | 威胁研究、安全产品设计、攻击者思维 | 高 |
| Eran Shirazi | CTO / 联合创始人 | 前 EasySend 联合创始人 / CTO;Unit 8200 漏洞研究 | 架构、企业软件交付、技术执行 | 高 |
仅覆盖公开具名创始人;完整高管梯队或董事会委员会细节未公开披露。
[CO005, CO006, CO007, CO008]1.3 融资结构、投资方,以及经济利益归属
资本结构里最重要的尽调发现是:标题清楚,结构不清楚。Neo 官方发布稿以及多家转载称,公司在隐身期后携 $100M 融资亮相,投资方包括 Andreessen Horowitz 和 Bessemer Venture Partners,Craft Ventures 与 Merlin Ventures 参投。Calcalist、Fundraise Insider 和 Seedtable 的独立报道则把总额拆成 2025 年 $25 million 种子轮和 2026 年 7 月 $75 million Series A。总披露资本方向上可以对上,但形式并不一致;差异很重要,因为阶段标签会影响稀释预期、治理权,以及投资人如何激进地给 GTM 成熟度定价。股东图谱其余部分很强:a16z 和 BVP 提供品牌,Craft 补上企业软件模式识别,Merlin 带来网络安全渠道杠杆,Calcalist 还列出多位以色列网络安全生态的知名天使投资人。不过,留存公开来源没有披露精确投后估值、清算优先权、董事会权利或二级流动性。[CO017, CO018, CO019, CO020, CO021, CO025]
| 利益相关方 | 在公司叙事中的角色 | 控制权 / 经济重要性 | 证据 | 尽调问题 |
|---|---|---|---|---|
| Andreessen Horowitz | 领投方 | 传递信心,且可能带来董事会影响力 | SO001 / SO008 | 要求披露董事席位、按比例跟投权和治理权利 |
| Bessemer Venture Partners | 领投方 | 赛道背书和网络安全市场信号 | SO001 / SO007 | 要求披露董事会观察员或治理角色 |
| Craft Ventures | 参投方 | 企业软件 GTM 网络 | SO001 / SO009 | 确认配额和支持承诺 |
| Merlin Ventures | 参投方 | 网络安全分销和政府网络 | SO001 / SO026 | 澄清渠道杠杆和任何战略条款 |
| 天使投资人财团 | 品牌和网络支持 | 有用触达,但控制权不清 | SO026 | 要求披露股权结构明细和 SAFE / 种子轮转换细节 |
公开证据支持利益相关方名单,但不支持所有权比例、董事席位、清算顺位或二级交易部分。
[CO017, CO018, CO025, CO026]1.4 规模信号、里程碑,以及目前已被证明的内容
Neo 的发布基础设施强于典型隐身公司亮相,但证据仍远少于成熟品类领导者。官网已经有完整首页、平台叙事、关于页面、招聘板和发布新闻资料,显示公司有意包上一层企业 GTM 外壳,而不是只放一个“即将推出”的占位页。产品信息也比许多种子期 AI 安全公司更具体:盘点、风险情报、归因、策略控制和原生执行在留存材料中反复出现。独立来源还补充了几项方向性规模信号:Neo 称首次扫描部署不到 15 分钟,传感器很轻量,并强调知识库已编目超过 120 万个智能体工件。可是,公司仍缺少具名客户背书、收入或 ARR 披露、客户数量和独立效果基准。eWeek 提到 Neo 已与敏感行业组织测试但未点名,这有用;但相对于后续章节建立客户和财务信心所需的证据,它仍处在验证前阶段。[CO010, CO012, CO013, CO030, CO031, CO037]
| 日期 | 事件 | 类型 | 金额 / 状态 | 参与方 | 含义 |
|---|---|---|---|---|---|
| 2025-08-01 | Startup Nation Central 跟踪器将创立时间标为 2025 年 8 月 | 创立 | 跟踪器披露 | SO022 | 确定保留公开资料中的最早起点 |
| 2025-12-31 | Calcalist 称 Neo 在 2025 年完成 $25M 种子轮 | 融资 | $25M 种子轮(报道) | a16z、Merlin | 解释隐身期建设 |
| 2026-03-01 | Calcalist 称 Neo 在隐身期发布了关于一家会计师事务所数据泄露的研究 | 产品 | 研究产出 | Neo 团队 | 显示发布前市场信号 |
| 2026-05-01 | Calcalist 报道 Neo 在隐身期仍在募集超过 $50M | 融资 | 轮次进行中 | 报道称 Kraft / 投资人财团 | 暗示发布前需求强 |
| 2026-07-20 | Neo 公开走出隐身期 | 治理 | 发布事件 | 创始人和投资人 | 公开进入赛道 |
| 2026-07-20 | 官方发布稿以 $100M 融资为标题 | 融资 | $100M 口径 | a16z、BVP、Craft、Merlin 等投资人 | 为 GTM 和工程扩张提供资金 |
| 2026-07-20 | Calcalist 将融资拆成 $75M Series A 加此前 $25M 种子轮 | 融资 | 结构冲突 | a16z、BVP、Craft、Merlin 等投资人 | 产生核验精确轮次标签的尽调需求 |
| 2026-07-28 | 招聘页面显示在 Boston、Tel Aviv 和美国外勤岗位共开放 37 个职位 | 规模化 | 发布后招聘加速 | Neo 招聘 | 传递激进扩张信号 |
该时间线仅限保留公开证据可见事件,并包含一个需要线下确认的融资结构明确冲突。
[CO001, CO010, CO018, CO019, CO022, CO026]公开里程碑显示,Neo 从隐身期融资到完整企业级发布推进得异常快。
由于追踪平台和文章并不总是披露确切交割日期,部分日期使用月份级代理值。
[CO001, CO010, CO018, CO026, CO037]1.5 不利信号,以及仍然重要的事实缺口
空头逻辑从品类耐久性开始。Security Boulevard 的怀疑并不是说 Neo 没有真实问题,而是网络安全里的真实问题,一旦平台厂商反应过来,常会被压缩成一组功能。这个风险在这里尤其相关,因为 CyberArk、Microsoft、Palo Alto Networks 等既有厂商已经把身份、云和 AI 控制延伸到智能体行为。第二个风险是,公开证据里的硬运营事实仍然稀薄:客户名称、收入质量、董事会结构和精确估值,在留存一手来源中都缺席。就连人员规模和轮次结构,也会因追踪平台和新闻报道而不同。第三个风险是集中度。公开品牌高度绑定三位创始人,运营模式看起来又分布在波士顿领导层和以色列研发之间;这种组合可以很好运转,但也集中了承压执行和人才风险。因此,Neo 在战略上很容易理解,运营层面却仍披露不足。[CO020, CO021, CO022, CO030, CO033, CO034]
1.6 图表
02市场分析
2.1 市场边界、纳入支出,以及现状替代方案
Neo 并不处在最宽泛的“AI 安全”市场,而是落在一个更窄、但正在更快成型的层级:治理自主软件动作。留存来源一致指向一个品类,覆盖智能体和 AI 增强应用发现、身份或归属映射、最小权限访问、运行时授权、策略执行、审计轨迹,以及感知行为的防护。因此,边界应纳入智能体软件控制、非人类身份治理、提示词或工具滥用防御,以及以证据为核心的运行时控制;应排除通用效率助手、普通 EDR、传统 DLP 和模型托管基础设施,除非这些产品明确治理智能体行为。这个边界之所以仍然模糊,实际原因在于许多厂商把相邻能力放在同一标签下营销。Prompt Security 从员工 AI 使用延伸到自研应用和 MCP;Oasis 讲智能体访问管理;Zenity 讲决策路径治理;Palo Alto 讲端到端平台。买家因此是在重叠的控制哲学之间选择,而不是在一个标准化单一产品品类里采购。[CM001, CM002, CM003, CM015, CM019, CM021]
| 细分 / 类别 | 纳入支出 | 排除支出 | 买方 / 付费方 | 对 Neo 的意义 |
|---|---|---|---|---|
| Agentic 软件控制 | 运行时可见性、策略、审计、授权 | 通用 AI 聊天订阅 | CISO / 安全架构 | 核心切入点 |
| Agent 身份治理 | 所有权、凭证、最小权限 | 仅传统人工 IAM | IAM / 身份安全 | 重要相邻支出 |
| Agent 运行时保护 | 阻断 prompt / 工具误用、审批 | 仅静态源代码扫描 | SecOps / 平台安全 | 企业核心需求 |
| AI 态势与资产盘点 | 发现、风险分级、配置 | 独立模型托管 | 安全运营 | 常见切入并扩张路径 |
| AI 治理 / 合规证据 | 日志、报告、控制映射 | 没有控制能力的纯政策咨询 | 风险 / 治理办公室 | 预算放大器 |
边界受证据约束,且有意窄于宽泛的“AI security”伞形概念。
[CM001, CM002, CM003, CM015, CM019, CM021]多数企业会先从发现走到治理,再真正投入深度运行时执行。
[CM002, CM014, CM026, CM027]2.2 估算品类规模,但不假装精确
留存证据中最清晰的显性市场规模视角来自 MarketsandMarkets:其预计智能体 AI 安全市场将在 2026 年约为 $1.65 billion,到 2032 年增至 $13.52 billion,CAGR 约 42%。这是有用的方向性证据,但不应误认为 Neo 已可投资的完整 SAM。第二个视角是采用时点:Neo 和 Bessemer 引用 Gartner 估计,企业应用中的智能体能力将从 2025 年的 5% 扩大到 2026 年底的 40%。第三个视角是问题紧迫性:CyberArk 报告称,68% 的组织仍缺少 AI 系统身份控制。三者合在一起,支持预算正在快速形成这个判断。不过,它们没有解决多少支出会留在独立产品,又有多少会迁移进打包 IAM、云或 AI 平台套件。因此,Neo 更现实的 SOM 应框定为已经大规模运营智能体的大型企业,而不是整个理论 AI 安全 TAM。[CM004, CM005, CM006, CM007, CM024, CM034]
| 视角 | 年份 / 地区 | 数值 | 方法论 | 置信度 | 限制 |
|---|---|---|---|---|---|
| 明确分析师 TAM | 2026 年全球 | $1.65B | MarketsandMarkets 预测 | 中 | 单一发布方估算 |
| 更长期 TAM | 2032 年全球 | $13.52B | MarketsandMarkets 预测 | 中 | 包含宽泛供应商集合 |
| 采用视角 | 2026 年企业应用 | 年底前 40% 具备 agentic 能力 | 经 Neo/BVP 引用的 Gartner 说法 | 中 | 并非直接支出 |
| 问题视角 | 2026 年企业身份控制 | 68% 缺少 AI 系统控制 | CyberArk 研究 | 高 | 不必然等于近期预算 |
| Neo 式 SOM | 2026 年大型企业 | 狭窄的早期采用者子集 | 基于买方成熟度和披露限制推断 | 低 | 没有公开客户分母 |
由于没有保留来源提供精确的 Neo 专属 SAM,本表结合了已发布估算、采用度代理和问题强度代理。
[CM004, CM005, CM006, CM007, CM024, CM034]明示口径和代理口径都指向品类快速成形,但保留来源中只有一家发布方给出美元规模。
SOM 区间是对早期采用者支出池的推断,不是已披露的市场统计。
[CM004, CM005, CM024]许多企业会先意识到问题,再为运行时执行配置充分预算。
示意性漏斗基于证据支撑的市场成熟度,而非已披露的调查数据集。
[CM006, CM007, CM028, CM030, CM035]2.3 买家细分、预算归属与采用路径
最可能的早期买家,是大型企业里的 CISO、身份负责人、安全架构师和平台安全团队。Composio 的治理材料以及多家竞争厂商都强调认证、权限、可观测性、审批流和集中日志,这些不是业务线职责。日常用户大概率横跨 SecOps 分析师、IAM 工程师、AppSec 团队和治理职能;他们需要弄清谁发起了动作、调用了什么工具,以及该动作本应被允许还是拦下。采用路径看起来也会分阶段。发现和影子 AI 控制是最容易切入的楔子,因为它们能快速给出可见资产盘点。运行时授权、爆炸半径分析和工具调用治理,则是更难但更有战略价值的第二阶段,因为它们需要更深入的策略定义和更高的运营信任。预算常会分散在安全、身份、数据和 AI 治理项目之间,所以即使技术问题显而易见,销售周期也可能充满教育和政治协调。[CM011, CM012, CM013, CM014, CM016, CM025]
| 细分 | 买方 | 用户 | 付费方 | 工作流 / 触发因素 | 采用触发因素 |
|---|---|---|---|---|---|
| 正在推进 AI 的 Global 2000 | CISO / 安全架构师 | SecOps 和 IAM 团队 | 安全预算 | Shadow AI、可审计性、工具控制 | Agent 蔓延变得可见 |
| 受监管企业 | CISO / 合规负责人 | 治理和身份团队 | 安全 + 合规 | 审批关卡和证据链 | 监管审查 |
| 开发者密集型企业 | 平台安全负责人 | AppSec / 开发者平台 | 平台工程 + 安全 | 代码助手、MCP、工具调用 | 内部 agent 快速创建 |
| 云优先企业 | 身份或云安全负责人 | 身份 / 云运维 | 共享安全预算 | Agent 最小权限访问 | 权限过高的 agent |
| 中端市场早期采用者 | 安全负责人 | 精简安全团队 | IT / 安全混合预算 | 先发现、后控制的部署 | 完整控制前需要快速盘点 |
买方角色基于治理和竞品材料推断,而不是单一披露调查。
[CM011, CM012, CM013, CM014, CM025]企业需求集中在安全团队已经同时负责 AI 上线风险和审批工作流的地方。
[CM011, CM013, CM025, CM030]2.4 增长驱动、采用约束,以及市场仍可能令人失望的原因
多头逻辑很直接。AI 能力正嵌入已获批准的企业软件,制造出影子或半批准的智能体行为,传统控制读不懂。智能体可以调用工具、移动数据并自主行动,这让实时授权和事后可审计性远比静态策略文档更有价值。NIST、OWASP 和 EU AI Act 都在不同程度上强化治理、可追溯性和风险受控部署。不过,市场约束也很清楚。买家仍需要 ROI 证明,许多人会问 Microsoft、Palo Alto、CyberArk 或其他既有厂商能否在现有合同内解决“足够多”的问题。品类边界也很混乱:身份、DSPM、DLP、运行时测试、AI 网关和终端控制都触碰同一工作流的不同部分。因此,Security Boulevard 的空头观点很重要:真实问题仍可能变成一组非常昂贵的功能,而不是一个耐久的独立平台市场。[CM008, CM009, CM010, CM017, CM018, CM026]
| 驱动因素 / 约束 | 方向 | 时点 | 含义 | 尽调问题 |
|---|---|---|---|---|
| 已批准软件内嵌 agentic 功能 | 正向 | 近期 | 快速扩大可服务控制问题 | 衡量已批准应用漂移速度 |
| 运行时授权和审计轨迹需求 | 正向 | 近期 | 支撑高溢价控制平面产品 | 要求动作级使用证据 |
| NIST / OWASP / EU AI Act 治理压力 | 正向 | 中期 | 提升买方紧迫感和合规叙事 | 评估哪些行业最先感受到压力 |
| 既有厂商打包 | 负向 | 近期 | 可能压缩独立预算池 | 映射与 Microsoft / Palo Alto / CyberArk 的重叠 |
| ROI 不清和预算归属碎片化 | 负向 | 短期 | 即使风险很明显,也会拖慢采用 | 索取转化率和价值兑现周期数据 |
各行把硬性外部事实与有证据支撑的购买摩擦市场推断放在一起。
[CM009, CM010, CM017, CM018, CM026, CM027]2.5 这种结构对 Neo 意味着什么
Neo 的市场吸引力在于,需求出现得足够快,绿地设计胜利仍有机会。公司不需要赢下全部 AI 安全预算;它需要赢下那一部分已经看见智能体发现与动作级执行之间控制平面缺口的企业。话虽如此,市场拥挤且变化很快。评测清单已经列出数十家厂商,官方竞争页面也显示,运行时护栏、身份治理、发现和可审计性正变成标准话术。因此,Neo 的机会不是“没人看见这个问题”,而是许多买家仍缺少一款产品,能把盘点、归因和执行足够干净地绑在一起并落进运营。风险在于,同样的重叠让市场变大,也让防守更难。后续章节因此应强调 Neo 哪里真正差异化,哪里只是参与一个快速商品化的控制栈。[CM022, CM032, CM033, CM034, CM035]
2.6 图表
03竞争格局
3.1 谁真正与 Neo 竞争
Neo 的竞争集合比一张 AI 安全初创公司名单更宽。独立格局来源、厂商清单和官方竞品页面都显示,今天至少有三类玩家相互重叠。第一类是 Prompt Security、Noma、Zenity、Oasis 和 Astrix 等初创专精玩家,它们直接面向 AI 智能体安全或相邻的非人类身份控制营销。第二类是 Microsoft、Palo Alto Networks,以及很可能包括 CyberArk 和 CrowdStrike 的大型平台,它们能把既有遥测和分发延伸到同一预算讨论。第三类是出现在评测清单里的更广义 AI 安全或测试厂商,但它们未必会在每一笔控制平面交易中正面竞争。这意味着,比较 Neo 时应按功能,而不只是按标签。它最直接属于运行时治理和控制平面子群,而不是整个 AI 安全宇宙。这个细微差别很重要,因为宽泛厂商数量会让市场看起来比 Fortune 500 CISO 实际使用的短名单更拥挤。[CP001, CP011, CP012, CP013, CP030, CP031]
| 竞争对手 | 类别 | 规模 / 融资信号 | 目标客群 | 差异化 | 局限 |
|---|---|---|---|---|---|
| Neo | 初创型控制平面 | $100M 启动融资披露 | 企业 SecOps | 端点原生清单 + 归因 + 控制 | 公开证据有限 |
| Prompt Security | 泛 AI 安全创业公司 | 官网首页已有企业客户背书 | 员工 AI、应用、代码、MCP | 覆盖多个 AI 场景 | 覆盖面可能稀释深度 |
| Noma Security | AI 智能体运行时创业公司 | 围绕首个智能体方案的强势发布话术 | 企业 AI 智能体 | 爆炸半径 + 运行时护栏 | 仍是创业公司规模 |
| Zenity | AI 智能体治理创业公司 | 研究驱动定位很强 | 企业 AI 环境 | 聚焦决策路径和意图 | 分发不够清晰 |
| Palo Alto Networks | 既有平台 | 全球安全平台 | 大型企业 | 统一控制平面和既有装机基础 | 可能偏广而不够专精 |
| Microsoft | 既有平台 | 嵌入 E5 / Defender 生态 | Microsoft 栈较重的企业 | 内建智能体自动化和分发 | 最适配场景可能偏向 Microsoft 技术栈 |
仅使用公开定位信号;不同供应商披露融资、客户和部署规模的程度并不一致。
[CP002, CP003, CP004, CP005, CP006, CP009]赛道最清晰的分野在于平台广度和运行时控制深度。
该象限图是基于公开信息做出的方向性综合,并非实测基准。
[CP014, CP015, CP016, CP018]3.2 初创专精玩家:广度、深度,以及 Neo 的位置
在初创专精玩家中,Neo 最强的相对主张是围绕终端锚定拦截和动作控制的深度。Prompt Security 展示的是更宽的 AI 安全伞,覆盖员工使用、自研 AI 应用、代码助手、MCP 和智能体 AI,这可能打开更多门,也可能分散焦点。Noma 在运行时和护栏话术上更接近 Neo,尤其是爆炸半径分析和生产执行。Zenity 同样聚焦智能体决策路径,主张这个安全问题不能被压缩进一个旧品类。Oasis 和 Astrix 则更偏身份中心,映射非人类身份、权限和最小权限访问。这让它们在身份主导的采购动作中成为有意义的替代方案,但与 Neo 所说的软件控制闭环略有不同。总体看,Neo 既不孤单,也不泛泛;它位于一组试图把运行时治理和归因做到足够可运营、可企业部署的初创公司之中。[CP002, CP003, CP004, CP007, CP008, CP009]
| 购买标准 | Neo | Prompt | Noma | Oasis | Zenity | Palo Alto |
|---|---|---|---|---|---|---|
| 发现 / 清单 | 是 | 是 | 是 | 是 | 是 | 是 |
| 运行时护栏 / 动作控制 | 是 | 是 | 是 | 部分 | 是 | 是 |
| 身份 / 归属映射 | 是 | 部分 | 是 | 是 | 是 | 是 |
| 审计轨迹 / 归因 | 是 | 部分 | 是 | 是 | 是 | 是 |
| 跨员工 AI / 代码 / 应用的覆盖广度 | 部分 | 是 | 部分 | 部分 | 部分 | 部分 |
单元格基于公开营销页面,只能视为方向性判断,而非实验室验证的功能等同。
[CP002, CP003, CP004, CP005, CP007, CP009]初创公司和既有厂商覆盖的概念有重叠,但落到运营深度上并不总是同一水平。
对比评级由公开产品页面推断得出,仍需在真实演示中压测。
[CP003, CP004, CP005, CP007, CP022, CP029]3.3 既有厂商、打包,以及分发问题
最大的竞争威胁可能来自分发,而不只是产品优雅度。Palo Alto Networks 已经营销一个统一控制平面,覆盖发现、供应链扫描、身份和运行时策略;Microsoft 则把 Security Copilot 智能体直接嵌入 Defender、Entra、Intune 和 Purview。这些既有厂商起步时就有已安装遥测、企业信任和合同杠杆,初创公司很难匹配。CyberArk 的身份话术和 CrowdStrike 的 AI 安全材料显示,相邻平台也在教育同一批买家。Cisco 在 2026 年收购 Astrix,进一步证明大型厂商打算整合这个品类,而不是忽视它。这对 Neo 意味着,好产品是必要条件,但不够。公司必须证明,其控制深度或部署模型解决了打包套件仍会暴露的问题,尤其是在平台理性化很重要的大型受监管客户中。[CP005, CP006, CP010, CP018, CP019, CP021]
| 供应商 | 公开价格 / 单位 | 合同模式 | 包含能力 | 未知项 | 含义 |
|---|---|---|---|---|---|
| Neo | unknown | 可能是企业订阅 | 清单、归因、策略控制 | ACV、席位、部署费 | 商业验证仍不透明 |
| Prompt Security | unknown | 企业平台 | 员工 AI + 应用 + 代码 + MCP | 用量定价不清楚 | 覆盖广度可能支撑更大的平台型销售 |
| Noma | unknown | 企业平台 | 发现 + 运行时防护 | 模块打包方式不清楚 | 需要生产环境深度的证据 |
| Palo Alto | unknown | 平台 / 套件销售动作 | 更大套件中的智能体安全 | 增量定价未公开 | 捆绑杠杆可能很强 |
| Microsoft | 除 Security Copilot 容量框架外,公开企业定价未知 | 捆绑 + 按计算量计费 | Microsoft 安全栈内的智能体 | 相对 E5 的净有效成本不清楚 | 捆绑可能压低独立采购支出 |
公开定价能见度极低,因此本表比较的是打包方式的不透明度,而非精确商业条款。
[CP020, CP018, CP024, CP035]竞争风险主要来自赛道拥挤、分销势能不对称,以及品类整合速度。
[CP019, CP020, CP021, CP023]3.4 定价不透明、护城河逻辑,以及空头逻辑落点
公开网页研究对这个品类的商业机制意外薄弱。留存来源中很少有价格,几乎没有披露合同模型、部署费用、ACV 或竞争替换数据。这迫使比较转向架构、买家匹配和可能的部署深度,而不是标价。Neo 最好的护城河主张是,终端原生拦截可以提供仅身份或仅 API 产品无法匹配的控制。但这条护城河有条件。如果既有厂商足够快地合并终端遥测、身份图谱和智能体编排,同样的功能可能进入更大套件。Security Boulevard 的批评抓住了核心空头逻辑:真实产品仍可能变成一个功能。因此,评估 Neo 的竞争耐久性,应看生产深度证明、客户紧迫性、背书密度,以及竞争对手多快收敛到类似运行时控制叙事。实践中,最有价值的下一步尽调不是再做一次网页搜索,而是拿到近期企业评估中的真实赢单 / 输单证据,尤其是 Fortune 500 比选中那些打包套件替代方案看起来表面上已经足够好的场景。[CP020, CP022, CP023, CP025, CP026, CP027]
| 护城河主张 | 威胁 | 严重性 | 缓解方式 / 尽调追问 |
|---|---|---|---|
| 端点原生拦截 | 既有厂商补上类似控制深度 | 高 | 要求提供动作确实被拦截或治理的生产环境证据 |
| 控制平面简洁性 | 平台捆绑足够多的重叠能力 | 高 | 跟踪企业是否愿意单独购买一层 |
| 创始人与投资方品牌 | 赛道拥挤削弱可信度 | 中 | 验证标杆客户成交和试点 |
| 运行时治理聚焦 | 身份主导型买家转向 Oasis/Astrix/CyberArk | 中 | 厘清 Neo 是否能赢下身份主导型交易 |
| 早期赛道时点 | Neo 做大前,市场先整合 | 高 | 密切跟踪并购和平台合作 |
本风险登记表把公开定位转化为耐久度问题,而非下定论的竞争结果。
[CP019, CP026, CP027, CP028, CP033, CP034]3.5 图表
04财务状况
4.1 收入模型:真正能推断什么
公开证据没有披露收入、ARR、预订额或客户数量。即便如此,Neo 的商业表面并不随机。公司面向 SecOps 团队营销,提供演示,运行 ROI 计算器,并使用企业治理话术,而不是消费级产品采用语言。这一组合强烈指向企业订阅模型:通过高接触评估销售,而不是自助 SaaS。模型里也可能包含实施、集成或策略调优服务,尤其是运行时控制常常需要贴合客户特定工作流和审批。不过,公开记录没有披露服务收入是否有意义,还是只是支持性部分。因此,核心结论是方向性的:Neo 看起来像一家有企业合同野心的安全软件公司,而不是纯按用量计费的 API 产品。订阅、服务和任何消耗型元素之间的精确平衡,仍是影响收入质量、利润率结构和续约行为的尽调缺口。[CI004, CI005, CI006, CI014, CI015, CI016]
| 收入来源 | 机制 | 计价单位 | 当前数值 / 状态 | 质量 | 尽调追问 |
|---|---|---|---|---|---|
| 核心平台订阅 | 年度企业软件合同 | 合同 / 席位 / 端点未知 | 未披露 | 若粘性强,质量可能较高 | 索取定价模型和平均合同规模 |
| 实施 / 部署服务 | 设置、策略调优、集成 | 项目费或捆绑未知 | 未披露 | 若占比大,可能稀释利润率 | 索取服务附加率 |
| 支持 / 客户成功 | 持续企业支持 | 订阅附加项或捆绑未知 | 未披露 | 可能提升留存 | 索取支持服务打包方式 |
| 培训 / 治理咨询 | 可能是早期赋能 | Unknown | 未披露 | 可能非核心 | 厘清是否重要 |
| 用量组件 | 工具调用 / 事件 / 智能体数量 | Unknown | 未见公开证据 | 不清楚 | 询问是否存在任何用量定价 |
各行区分可能的变现机制和已披露事实;几乎所有数值仍未公开。
[CI005, CI006, CI016, CI026]| 信号 | 观察到的事实 | 标价 vs 实际成交价 | 未知项 | 来源 |
|---|---|---|---|---|
| 演示驱动销售动作 | 演示和联系 CTA 非常醒目 | 实际成交价未知 | ACV、最低金额、打包方式 | SI004 / SI005 |
| ROI 叙事 | 有 ROI 计算器 | 未披露定价 | ROI 模型背后的假设 | SI011 |
| 企业合同 | 有法律页面 | 无公开商业条款表 | 订单表、安全附录、试点 | SI008 / SI009 |
| 自助结账 | 未找到证据 | N/A | 是否有小团队套餐 | SI003 / SI004 |
| 捆绑用量模型 | 未见公开证据 | Unknown | 事件 / 端点 / 席位口径 | SI003 / SI005 |
公开材料能看出销售姿态,但看不到实际价格点或成交折扣。
[CI014, CI015, CI028, CI029]Neo 公开呈现的销售姿态指向企业合同,而不是自助式变现。
这是基于公开 GTM 素材推断的企业销售流程,并非公司披露的销售打法。
[CI005, CI006, CI015, CI016]4.2 单位经济性:大多未知,而这很重要
投资人会想看的几乎所有承销指标都没有披露。没有公开毛利率,没有披露净收入留存,没有席位数量,没有合同金额区间,也没有说明每次部署需要多少持续服务工作。同样,也没有收入分母可用来负责任地估算人均收入或销售效率。这意味着,目前财务故事主要由缺口而不是矛盾主导。公司可能已经具备有吸引力的订阅经济性,也可能仍在投入大量部署工作来验证新品类;公开来源无法区分这两种情况。最稳妥的解读是,Neo 对公开网页单位经济性分析而言还太早、太私密,而不是默认指标很弱。本章应被读作后续尽调的证据受限框架,而不是完整模型。签署的客户合同会立刻改变信心水平。[CI017, CI018, CI024, CI032, CI035]
| 指标 | 数值 / null | 置信度 | 重要性 | 尽调追问 |
|---|---|---|---|---|
| 毛利率 | 低 | 决定软件质量和服务负担 | 索取 GAAP/non-GAAP 利润率桥表 | |
| 净收入留存率 | 低 | 体现扩张和产品价值密度 | 索取队列瀑布图 | |
| 回本周期 | 低 | 衡量销售效率 | 索取 CAC 和毛利回本周期 | |
| 人均收入 | 低 | 快速生产率信号 | 先需要收入分母 | |
| 服务占比 | 低 | 影响可扩展性和利润率 | 索取服务与订阅拆分 |
null 是有意保留,因为现有来源未披露这些数值。
[CI017, CI018, CI024, CI035]| 缺失指标 | 影响 | 重要性 | 具体尽调路径 |
|---|---|---|---|
| ARR / 收入运行率 | 高 | 估值和销售效率判断都需要 | 索取月度经常性收入桥表 |
| 毛利率 | 高 | 判断软件质量需要 | 索取收入成本明细 |
| 客户数和队列扩张 | 高 | 留存和定价权分析需要 | 索取客户台账和续约数据 |
| 账上现金和月度烧钱速度 | 高 | 现金跑道分析需要 | 索取董事会材料包或财务摘要 |
| 股权结构表和估值条款 | 高 | 稀释和下行情景分析需要 | 索取融资文件 |
本表有意标出公开网页尽调无法补齐的缺口。
[CI004, CI017, CI018, CI032, CI035]财务模型卡在分母缺失,而不是某个指标互相矛盾。
[CI017, CI018, CI032, CI035]只有资本和员工数能给出有证据支撑的区间;多数运营指标还做不到。
融资区间反映的是公开融资结构描述互相冲突,而不是现金余额不同。
[CI001, CI002, CI009, CI010]4.3 资本充足性、招聘强度与烧钱方向
最清晰的正向财务事实是已宣布资本规模。无论把发布融资视为单一 $100 million 事件,还是视为 $25 million 种子轮加 $75 million Series A,Neo 进入公开市场时的资本都显著高于典型种子期网络安全初创公司。话虽如此,宣布资本不等于剩余现金。同一公开记录显示,公司处在积极扩张模式:37 个开放岗位横跨产品、GTM、法务、财务和 HR,外部证据还显示当前员工约 50 人。这个组合意味着烧钱在上行,而不是下降。公司似乎在利用资本加速市场捕获,趁品类仍在成型时抢占位置。如果产品市场匹配真实、部署深度也被证明可防守,这样做可以理性;但如果客户转化落后于招聘节奏,或打包既有厂商比预期更快压平定价权,风险就会上升。[CI001, CI002, CI003, CI007, CI008, CI009]
| 指标 | 数值 / 状态 | 置信度 | 含义 | 尽调追问 |
|---|---|---|---|---|
| 已宣布启动融资 | $100M 披露口径 | 高 | 融资基础强 | 确认分批结构和净到账资金 |
| 另一种轮次表述 | $25M 种子轮 + $75M Series A 轮 | 中 | 可能已经消耗过早期现金 | 确认各批次交割日期和用途 |
| 当前员工数 | 据报道 ~50 | 中 | 只能作为烧钱速度代理 | 索取实际 HRIS 快照 |
| 开放岗位 | 37 | 中 | 烧钱速度可能上升 | 索取按季度划分的招聘计划 |
| 现金跑道(月) | 低 | 无法从公开信息推导 | 索取现金余额和基准 / 增长烧钱速度 | |
| 下一轮触发条件 | 由牵引力驱动,而非故事驱动 | 低 | 未来融资可能绑定客户验证 | 索取董事会计划和融资备忘录 |
区分已披露资本事实,以及未知的账上现金和现金跑道指标。
[CI001, CI002, CI003, CI007, CI009, CI019]公开证据显示资本实力强,但开支强度在上升,披露质量偏低。
[CI007, CI011, CI019, CI024, CI030]4.4 多头、空头,以及最关键的财务问题
多头逻辑是,Neo 借助出色创始人履历和品类时点,在需求完全释放前完成融资,拿到足够跑道去激进招聘、拿下标杆客户,并在既有厂商完全适应之前塑造新市场。按这个解读,缺少公开指标只是普通私营公司的不透明,而不是警讯。空头逻辑是,同样的事实也可能只说明公司背负昂贵预期,却几乎没有公开证据证明货币化质量。Security Boulevard 关于“产品变成功能”的警告,在财务上很重要,因为品类耐久性被压缩,会同时打击定价权和退出倍数,即便底层产品真实存在。尽调最重要的下一批文件不是更多营销材料,而是签署的客户合同、群组行为、续约数据和真实股权表。在这些进入证据之前,财务姿态仍是:融资标题强、扩张认真、对当下运营效率信心低。[CI021, CI022, CI023, CI027, CI033, CI034]
4.5 图表
05产品与技术
5.1 产品模块,以及 Neo 试图解决的用户任务
Neo 的产品页面对平台要完成的任务讲得异常明确。核心闭环从盘点开始:智能体、模型、技能、MCP 服务器、扩展以及其他软件工件都在范围内。随后进入态势和能力分析,回答这些工件能访问什么、配置是否安全。接着 Neo 强调归因,这很重要,因为自主软件可能通过有效用户会话行动,看起来像正常行为。最后,系统在数据移动之前执行策略:放行、阻断或暂缓动作以待审批。落到实践中,这个平台是为 SecOps 和治理团队打造的,他们既想让采用继续推进,又不想交出控制。因此,这个产品不像提示词防火墙,更像企业智能体工作流的运营控制层。同一套语言在多个公开页面中保持一致,本身就是有用的成熟度信号。[CE001, CE002, CE003, CE004, CE009, CE010]
| 模块 / 资产 | 主要用户 | 状态 / 成熟度 | 差异化 | 尽调缺口 |
|---|---|---|---|---|
| 软件清单 | SecOps | 公开材料已有描述 | 覆盖智能体、技能、MCP 和扩展 | 需要证明检测深度 |
| 能力与风险情报 | SecOps / 治理 | 公开材料已有描述 | 映射软件可访问的对象和可执行的动作 | 需要评分方法 |
| 归因引擎 | 安全运营 | 公开材料已有描述 | 区分人类与非人类动作 | 需要生产环境案例 |
| 策略控制 | 安全架构 | 公开材料已有描述 | 按组和身份定制控制 | 需要规则编写细节 |
| 原生执行 | 安全运营 | 公开材料已有描述 | 数据移动前拦截 / 暂停 | 需要基准测试数据 |
本表映射 Neo 在发布和平台材料中明确点名的模块。
[CE002, CE003, CE009, CE010]| 用户任务 | 现有工作流痛点 | Neo 方案 | 可衡量收益 | 限制 |
|---|---|---|---|---|
| 发现影子智能体软件 | 传统工具看到的是二进制文件,不是行为 | 构件级发现和信息补充 | 可见性更好 | 覆盖深度未做基准验证 |
| 理解权限和配置 | 自主工具继承的访问权限不透明 | 能力与风险情报 | 风险分诊更快 | 评分证据未公开 |
| 判定实际操作者 | 人和智能体共用同一会话 | 跨人类与非人类行动方归因 | 可审计性更好 | 无公开案例研究 |
| 阻止危险工具使用 | 日志事后才到 | 允许 / 阻止 / 暂停控制 | 实时阻断 | 误报未知 |
| 在团队间扩展护栏 | 规则编写繁琐 | LLM 辅助策略编写 | 策略推出更快 | 需要证明策略质量 |
用例根据公开文案推断,并非来自具名客户部署。
[CE004, CE008, CE009, CE010, CE029]运营闭环从发现开始,以受治理的行动收尾。
[CE003, CE009, CE010, CE029]5.2 架构、工作流,以及为何终端押注重要
最独特的技术主张是架构性的,而不只是品类性的。Bessemer 称,Neo 选择了更难的终端驻留传感器路线,因为仅 API 可见性无法拦截智能体在可信软件内部实际做的事。Neo 自己的材料也用原生执行、实时动作控制,以及已获批准应用内部软件行为等表述支撑这个观点。可能的控制链条是:终端遥测捕捉现有软件和智能体组件;Neoverse 用上下文知识增强这些观察;能力和风险分析浮现软件能做什么;策略逻辑映射允许、阻断或暂缓的动作;归因与路由为下游 SOC 工作流保留证据。这个模型与围绕工具使用、权限继承和已批准应用内隐藏动作的智能体风险高度匹配。它在生产中是否运营上更优,公开证据尚未证明,但设计论点很清楚。[CE005, CE006, CE007, CE008, CE010, CE011]
| 层 / 组件 | 作用 | 依赖 | 风险 |
|---|---|---|---|
| 端点传感器 | 观察软件和动作 | 端点部署 | 覆盖范围或性能取舍 |
| Neoverse 知识库 | 丰富对构件的理解 | 持续更新的数据 | 数据过期或分类缺口 |
| 策略引擎 | 把决策落到动作 | 规则、用户组和身份上下文 | 策略噪声或漂移 |
| 归因层 | 将动作关联到行动方 | 可靠身份和遥测 | 归属链条不清 |
| SOC / 工作流路由 | 向外部工具发送证据和动作 | 既有企业工具 | 集成深度不清楚 |
架构根据公开产品和投资人描述综合而成,不是官方参考图。
[CE005, CE007, CE011, CE025, CE027]Neo 的设计可理解为一套从遥测到执行的分层控制栈。
该概念架构由公开材料拼出,并非官方技术白皮书。
[CE005, CE007, CE008, CE027]该架构依赖高质量遥测、增强数据、策略逻辑和企业工作流集成。
[CE007, CE011, CE025, CE027]5.3 信任、质量与成熟度信号
Neo 的公开信任故事体面但不完整。公司有法律和隐私页面,产品文案扎根治理语言,叙事也能很好映射到 NIST 和 OWASP 风格框架。这说明公司理解企业买家如何思考 AI 风险。但这不等于公开记录证明了质量。留存来源没有披露公开认证、基准测试结果、误报率、策略调优平均耗时或真实生产性能数据,也没有展示公开集成目录、公开 API 参考或参考架构包。这种不对称很重要。早期网络安全公司常先带着出色的概念框架发布,然后才积累足够现场证据来支撑每一项运营主张。因此,Neo 看起来已成熟到可以销售和演示,但从证据角度仍处早期。缺失的证明并不致命,却应压低相对于既有厂商的就绪度说法,并让尽调继续聚焦实施深度。[CE012, CE013, CE014, CE022, CE023, CE024]
| 控制或质量信号 | 状态 | 范围 | 缺口 |
|---|---|---|---|
| NIST / 治理对齐 | 方向性 | 仅叙事层面对齐 | 无正式鉴证 |
| OWASP / 智能体风险相关性 | 方向性 | 威胁模型对齐 | 无公开映射包 |
| 法务和隐私页面 | 可见 | 企业就绪基线 | 不能证明安全有效性 |
| 独立基准测试结果 | 未公开 | Unknown | 需要误报和执行数据 |
| 公开认证 | 本次保留来源未发现 | Unknown | 需要 SOC 2 / ISO 状态 |
本表将治理对齐叙事与独立证明的保障分开。
[CE012, CE013, CE014, CE030, CE033, CE034]公开证据在架构上较强,在实测质量上较弱。
评估仅基于已留存的公开材料。
[CE022, CE024, CE030, CE034]5.4 路线图重点、相邻竞争与空头逻辑
Neo 发布时讲的是一个聚焦故事,而不是铺开一张庞杂平台地图,这大概率是正确选择。Black Hat 页面、活动动作和发布叙事都暗示,当前路线图围绕证明企业控制闭环:盘点、归因、策略和动作级执行。不过,外部来源也显示,许多同行和既有厂商现在都在说类似的话。Prompt、Noma、Zenity、Palo Alto、Akto 等都描述了发现、护栏、治理和运行时防护的组合。因此,空头逻辑不是 Neo 没有产品,而是产品语言在 Neo 证明生产深度之前就迅速拥挤。如果更大平台吸收足够多同类能力,Neo 的差异化就必须落在运营结果上——尤其是客户是否信任它在真实环境中实际暂缓或阻断高风险动作。在广泛公开的生产部署证据商业化出现之前,这仍是今天投资人面前最核心的未解产品问题。[CE015, CE016, CE017, CE018, CE019, CE020]
| 日期 / 阶段 | 功能或里程碑 | 状态 | 含义 | 来源 |
|---|---|---|---|---|
| 2026-07 发布 | 五项核心平台能力 | 已公开宣布 | 核心平台已进入市场叙事 | SE005 |
| 2026-07 发布 | Neoverse 知识库 | 已公开宣布 | 差异化叙事依赖数据层 | SE004 |
| 2026-07 发布 | 端点原生执行主张 | 已公开宣布 | 架构是投资逻辑核心 | SE006 |
| 2026-07 发布 | 以演示驱动的 GTM 动作 | 公开可见 | 产品开始进入企业评估周期 | SE022 |
| 2026-07 报告生成日 | 公开文档仍主要停留在营销层 | 已观察到 | 文档成熟度可能跟不上野心 | SE003 / SE022 |
仅跟踪保留公开来源可见的里程碑。
[CE003, CE005, CE007, CE015, CE031, CE032]5.5 图表
06客户
6.1 Neo 看起来卖给谁,以及谁真正感到痛
Neo 的公开材料一致指向一个狭窄的初始客户画像:已经在浏览器、SaaS 平台、开发者工具和内部工作流中部署或评估 AI 智能体的大型企业。经济买家很可能是 CISO 或高级安全负责人,因为产品被定位为风险、归因和策略的控制层。日常运营者大概率是 SecOps、安全架构、身份和治理团队。终端用户则是已经在试验智能体软件的业务和工程团队。这个买家-用户-付款方分裂很重要,因为 Neo 卖的不是通用效率软件;它试图把一个新兴治理问题转化成企业安全预算中的一条项目。如果痛点真实,这应会提升交易规模,但也意味着评估周期长,并且部署在账户内扩大前需要强有力的高层支持。换句话说,在商业化最初几年,企业内部的客户质量和政治背书可能比漏斗顶部宽度更重要。[CU001, CU002, CU003, CU004, CU005, CU006]
| 客群 | 买方 / 用户 / 付款方 | 主要用例 | 战略价值 | 公开证据缺口 |
|---|---|---|---|---|
| Fortune 1000 安全团队 | 买方:CISO;用户:SecOps / 安全架构;付款方:安全预算 | 盘点并治理 AI 智能体 | 预算潜力大,控制需求紧迫 | 无具名客户背书 |
| 受监管企业 | 买方:安全 + 合规;用户:治理和身份团队;付款方:安全 / 风险预算 | 可审计性、归因、策略执行 | 对证据和问责要求更高 | 无公开合规案例研究 |
| 技术领先的软件公司 | 买方:平台安全负责人;用户:工程安全和 IT | 管控内部和第三方智能体使用 | 快速试验可能提前创造需求 | 转化节奏未知 |
| 开发工具重度组织 | 买方:安全负责人;用户:AppSec / 平台 / IT | 看见并管理浏览器和工具里的智能体活动 | 契合 Neo 关于智能体软件蔓延的叙事 | 无公开部署指标 |
| 重视董事会观感的转型项目 | 买方:CIO/CISO 联盟;用户:项目治理团队 | 在不叫停采用的前提下展示企业控制 | 可能支撑战略性高 ACV 交易 | 预算归属可能共享或有争议 |
由于 Neo 未发布客户名单,客群根据发布、投资人和市场材料推断。
[CU001, CU002, CU003, CU005, CU028]| 角色 | 可能职责 | Neo 为何重要 | 待解问题 |
|---|---|---|---|
| CISO | 负责企业 AI 智能体风险态势 | 需要向董事会和安全项目讲清控制叙事 | 预算审批能有多快? |
| SecOps 负责人 | 运营检测、审批和响应工作流 | 需要更好的归因和动作控制 | 实际使用中噪声有多大? |
| 安全架构师 / 身份团队 | 定义策略、权限和治理模式 | 需要面向智能体的最小权限和审批逻辑 | 与 IAM 和工作流工具集成有多深? |
| 使用智能体的业务或工程团队 | 想要生产力和自动化收益 | 需要护栏,但不能挡住有用自动化 | 控制会被视为阻力还是赋能? |
买方图谱根据 Neo 定位和投资人对问题归属方的解释综合而成。
[CU004, CU006, CU007, CU017]Neo 可能的客户路径始于发现智能体软件暴露面,之后才扩展到策略标准化和账户增长。
这一路径由 Neo 定位、投资人评论和企业安全采购模式推断得出,并非公司发布的 GTM 图。
[CU003, CU015, CU016, CU018, CU020, CU031]6.2 公开记录证明了什么,又没有证明什么
Neo 的需求叙事可信,但证据表面很薄。公司、投资人和发布报道反复把智能体软件描述为快速升级的企业问题,投资人文章也暗示与 CISO 的多轮交流影响了公司论点。这是有用的方向性证据,说明品类能引起买家共鸣。但它没有给出具名客户验证。留存公开来源没有列出参考客户、已发布案例、部署数量、合同金额或续约指标。即便 Black Hat 动作,也更像高管简报和管线搭建,而不是公开生产规模证明。实际结论不是 Neo 没有客户;而是当前证据更能支持早期企业兴趣和可能试点,不足以支撑广泛、耐久采用的说法。这个区分是客户尽调的核心,因为品类热度会掩盖底层商业证据仍有多早。[CU008, CU009, CU010, CU011, CU012, CU013]
| 信号 | 公开信息 | 日期 | 置信度 | 含义 |
|---|---|---|---|---|
| 携大额融资走出隐身 | 公司发布时主打 $100M 融资和企业控制叙事 | 2026-07 | 中 | 资金可能支持快速企业销售 |
| 投资人 CISO 反馈循环 | 投资人称 CISO 对 AI 智能体风险高度担忧 | 2026-07 | 中 | 即便缺少客户名称,品类痛点看起来真实 |
| 高管简报动作 | Black Hat 页面宣传私密会谈和演示 | 2026-07 | 中 | 建管线、做试点是当前重点 |
| 具名客户案例研究 | 本次保留来源未发现 | 2026-07-28 | 高 | 采用深度仍缺少公开验证 |
| 续约 / 留存数据 | 本次保留来源未发现 | 2026-07-28 | 高 | 客户持续性还不足以支撑承销判断 |
采用轨迹依据公开 GTM 信号,而非已披露的客户、合同或席位数量。
[CU008, CU010, CU011, CU013, CU014]| 证明维度 | 观察状态 | 证据质量 | 重要性 |
|---|---|---|---|
| 具名客户标识 | 未发现 | 低 | 没有客户标识,买方验证更弱 |
| 已发布案例研究 | 未发现 | 低 | 缺少部署或 ROI 结果证据 |
| 投资人渠道客户信号 | 存在 | 中 | 说明有买方对话,但不是合同证明 |
| 活动 / 演示 | 存在 | 中 | 显示销售动作活跃 |
| 公开留存或扩张指标 | 未发现 | 低 | 持续性和增购质量仍未知 |
本表区分方向性需求信号和硬客户证明。
[CU009, CU010, CU012, CU024, CU033]公开证据在问题紧迫性上最强,在具名客户结果上最弱。
评估仅反映已留存的公开来源。
[CU009, CU012, CU013, CU024, CU033]6.3 采用如何可能从发现走向受控扩张
客户动作很可能从发现和风险框定开始,而不是自助试用。企业首先需要理解智能体软件已经在哪里存在,这些系统继承了哪些身份和权限,哪些动作需要审批或阻断。这让 Neo 的初始用例偏诊断和治理。如果平台能快速浮现影子智能体软件或高风险动作,下一阶段就是在一组受限用户、业务组或工作流上部署有限策略。扩张随后取决于产品能否在保住业务速度的同时降低噪音。这是典型的网络安全先落地、再扩张动作,但依赖强部署纪律。因为产品触碰策略和工作流执行,扩张很可能要求安全、IT 和业务利益相关方信任同一控制模型,而不只是一个单一拥护者。也就是说,试点阶段的价值实现速度,会不成比例地影响早期账户能否变成耐久背书。[CU015, CU016, CU017, CU018, CU019, CU020]
| 风险 | 可能原因 | 证据 | 影响 | 缓解措施 |
|---|---|---|---|---|
| 设计伙伴集中 | 早期阶段可能只有少数有影响力账户 | 未披露客户数量 | 高 | 扩大垂直行业组合并发布客户背书 |
| 试点到生产流失 | 很多企业会在全面推广前测试智能体 | 市场来源显示,生产采用落后于试验 | 高 | 证明快速见效且部署摩擦低 |
| 捆绑压力 | 现有厂商可能把相邻控制并入更大套件 | 竞争格局章显示功能快速趋同 | 中 | 靠动作级控制质量取胜 |
| 共享预算不清 | 安全、IT 和业务团队都可能参与支出决策 | 买方图谱跨职能 | 中 | 把价值绑定到风险归属和审计结果 |
| 可背书性瓶颈 | 敏感的早期客户可能抗拒公开披露 | 未发现具名客户背书 | 中 | 打磨匿名证明材料包和指标 |
风险表聚焦客户质量和扩张约束,而不是单纯市场规模。
[CU021, CU023, CU025, CU026, CU035]公开证据指向一条顾问式企业销售路径:先制造紧迫感,再受控上线,而不是纯自助漏斗。
该流程抽象自发布和活动材料中可见的可能步骤。
[CU008, CU011, CU017, CU019, CU022]6.4 耐久性、集中度,以及为什么客户质量比客户标识数量更重要
短期内,Neo 的客户质量比原始客户标识数量更重要。少数几个受监管企业中的深度参与设计伙伴,可能比大量浅试点更有价值,因为产品品类仍在被定义。下行风险是集中度。如果早期采用局限于一小群成熟客户,路线图影响力、定价杠杆和可背书性都可能集中。耐久性也未被证明。公开来源没有披露合同结构、部署时间、使用频率、策略命中率或净留存。此外,既有厂商可能把相邻 AI 治理功能打包进更大平台,抬高 Neo 必须跨过的门槛,才能保住账户内扩张。在 Neo 发布更强客户证据之前,投资人应假设采用存在,但仍早期、选择性强,并容易受证据缺口影响。直到这些证明点出现,任何乐观客户叙事都应被视为方向性判断,而不是定论。[CU023, CU024, CU025, CU026, CU027, CU032]
近期最大的客户风险不是理论需求不足,而是证据缺口和早期账户集中。
评分是方向性判断,不是量化运营指标。
[CU023, CU025, CU026, CU035]6.5 图表
07风险
7.1 监管、法律与问责风险
Neo 所在品类正好处在政策环境收紧之中。使用自主软件的企业越来越需要盘点、监督、日志、问责和最小权限控制,这让 Neo 与 EU AI Act、NIST 风格治理以及政府关于智能体 AI 采用的联合指南方向上高度一致。不过,一致不等于免疫。如果公司夸大其控制能证明什么,或客户把平台当作更广泛合规项目的替代品,一旦发生事故,责任争议可能很快浮出水面。Neo 也发布了标准隐私和条款页面,但这些只是基础法律卫生,并不能证明公司已经解决关于代理、责任或受监管行业部署的复杂问题。由于智能体 AI 的法律框架仍在流动,Neo 面临双重风险:买家正因为规则演化而需要帮助,但演化中的规则也会扩大尽调负担、拉长采购,并提高产品主张和文档标准。[CR001, CR002, CR003, CR004, CR005, CR006]
| 规则 / 事项 | 司法辖区 | 状态 | 可能性 | 严重性 | 缓解措施 | 剩余风险敞口 | 尽调路径 |
|---|---|---|---|---|---|---|---|
| AI 问责与文档负担 | 欧盟 / 跨国 | 已生效且在收紧 | 中 | 高 | 盘点、日志、监督,并谨慎限定产品边界 | 客户可能仍期待比 Neo 当前覆盖更宽的合规支持 | 要求提供合规映射、审计轨迹和客户部署手册 |
| 隐私与监控敏感性 | 美国 / 欧盟 / 全球 | 持续存在 | 中 | 高 | 隐私政策、清晰数据处理、限定范围遥测 | 端点和工作流可见性仍可能触发审查 | 要求提供数据流图和留存控制 |
| 自主软件事故后的责任归属 | 多司法辖区 | 正在成形 | 中 | 高 | 谨慎设定产品宣称和审批工作流 | 造成损害后,责任归属仍可能争议不断 | 审查合同、赔偿条款和事件响应假设 |
| 行业特定采购审查 | 金融 / 医疗 / 公共部门 | 持续存在 | 高 | 中 | 优先瞄准安全成熟度高的客户 | 周期更长,文档需求更多 | 要求提供受监管客户就绪证据 |
本清单根据公开材料和现行 AI 治理指引中可见的风险排序,而非基于 Neo 的合同披露。
[CR001, CR002, CR003, CR004, CR005, CR031]公开证据有限、客户依赖仍可能较高的地方,剩余风险最高。
热度等级是基于已留存公开来源得出的分析评级。
[CR001, CR009, CR018, CR026]7.2 运营、产品与安全失效风险
最重要的产品风险不是 Neo 有没有连贯故事;它有。风险在于,面向智能体软件的控制平面能否在真实企业环境中足够准确地工作,以至于可以被信任来做审批和阻断决策。误报可能拖慢业务工作流,漏报则可能制造危险的控制幻觉。终端驻留或重遥测架构也可能带来部署摩擦、性能担忧或集成复杂度,这些问题只有试点之后才会显现。公开证据尚未披露基准、调优工作量、检测覆盖或大规模参考架构,因此投资人无法独立验证产品在压力下如何表现。提示词注入、策略绕过和过度授权智能体模式也意味着,威胁面会和客户采用一样快地移动。实践中,Neo 必须证明,即便底层软件生态快速变化,它也能保持覆盖最新、决策可理解、运营者负担可控。[CR009, CR010, CR011, CR012, CR013, CR014]
| 失效模式 | 可能性 | 严重性 | 缓释成熟度 | 剩余暴露 | 未解决缺口 |
|---|---|---|---|---|---|
| 误报阻断合法工作流 | 中 | 高 | 公开来源无法判断 | 高 | 未披露操作噪声指标 |
| 漏报造成虚假的控制感 | 中 | 高 | 公开来源无法判断 | 高 | 未披露基准化有效性 |
| 端点或遥测阻力拖慢部署 | 中 | 中 | 概念上已有应对,但尚未证明 | 中 | 缺少部署期证据 |
| 提示注入或策略绕过超出控制能力 | 高 | 高 | 类别层面已有指引;产品证据有限 | 高 | 没有公开红队结果数据 |
| 知识库新鲜度下降,拉低检测质量 | 中 | 中 | 公司称会持续更新 | 中 | 更新质量缺少独立验证 |
运营风险按类别威胁模型和 Neo 目前披露的产品暴露面排序。
[CR009, CR010, CR011, CR012, CR013, CR014]多项运营和法律风险会直接传导到采用、收入质量和估值。
该图展示方向性因果关系,而不是实测概率。
[CR010, CR012, CR020, CR025]客户证据和运营有效性是近期影响最大的两项风险。
分数是方向性排序,不是概率。
[CR011, CR018, CR020, CR027]7.3 商业、采用与 GTM 风险
商业上,Neo 暴露在热门但不成熟品类的典型问题中。买家紧迫性看起来真实,但公开客户证明仍稀疏,这意味着公司可能需要先赢下漫长的企业周期,市场才会完全接受新的预算项。如果早期客户主要是成熟设计伙伴,集中度和路线图被捕获的风险会上升。安全、IT、工程和合规团队共同拥有问题,也可能拖慢采购。与此同时,更广泛的网络安全厂商可以把许多相邻能力包装成身份、SaaS 治理、应用安全或 AI 运行时安全的延伸。这不会抹去 Neo 的差异化,但会压缩专精厂商定义品类的窗口。强融资买来时间;它不保证 Neo 能把关注转化成耐久、可背书的客户。在客户证据加深之前,商业风险较少是需求不存在,更多是证明不足、部署摩擦和打包压力让收入规模明显低于投资人当下预期。[CR018, CR019, CR020, CR021, CR022, CR023]
| 风险 | 可能性 | 严重性 | 证据 | 缓释 |
|---|---|---|---|---|
| 公开客户证据稀少 | 高 | 高 | 保留来源中没有具名客户背书 | 发布证据包和部署成果 |
| 企业评估周期长 | 高 | 中 | 跨职能采购与新品类教育 | 缩窄初始用例,快速证明价值 |
| 既有厂商捆绑销售 | 高 | 高 | 多家覆盖更广的厂商已开始推销相邻 AI 智能体控制能力 | 靠精度和动作级强制执行取胜 |
| 设计伙伴集中 | 中 | 中 | 客户数量不透明 | 扩大客户标识基础和垂直行业组合 |
| 预算归属不清 | 中 | 中 | 安全、IT 和业务团队都受益 | 把价值绑定到明确的风险负责人 KPI |
商业风险反映强市场叙事与仍有限客户证据之间的错配。
[CR018, CR019, CR020, CR021, CR022, CR023]| 主题 | 最佳情景缓释因素 | 否决标准 | 改变判断的因素 |
|---|---|---|---|
| 客户证据 | 可供背书的部署和更清晰 ROI 证据 | 重投入期后仍没有可信背书 | 具名或匿名生产环境证据 |
| 产品有效性 | 基准测试、低摩擦部署、可管理调优 | 不能放心把实时审批或阻断交给控制措施 | 第三方验证和操作员指标 |
| 差异化 | 证明动作级控制优于平台厂商 | 既有厂商吸收足够能力,压平 Neo 的切入口 | 持续证明执行质量更优 |
| 监管定位 | 清晰角色边界和合规映射 | 客户认为 Neo 的宣称不足以支撑审计 | 已发布映射和面向行业的就绪文档 |
本表把原始风险转成投资决策阈值。
[CR026, CR027, CR028, CR029, CR030, CR036]只有当 Neo 把概念领先转化为可背书的运营证据,投资论证才会改善。
流程总结的是尽调逻辑,而不是公司发布的流程。
[CR028, CR029, CR036, CR040]7.4 战略风险排序、缓释措施与否决标准
尽调视角下,只有 Neo 尽快把概念层面的领先变成可运营的证据,风险才算可控。最直接的缓释动作很清楚:发布更扎实的参考架构,补上具名或匿名客户证明,展示可量化的部署结果,并划清平台能力与客户合规义务之间的边界。投资人还应提前设定止损条件。如果公司拿不出可信客户背书,如果既有套件复制出足够功能、压平 Neo 的差异化,或监管与责任负担让企业部署过于笨重,投资逻辑就应明显降温。反过来,如果 Neo 证明部署摩擦低、控制效果有分量,并在受监管或安全成熟的组织里形成持续采用,投资逻辑会增强。公司的资本储备给了执行空间,但这应被视为验证论点的机会,而不是论点已经成立的证据。[CR026, CR027, CR028, CR029, CR030, CR036]
7.5 附录图表
08估值
8.1 建议框架:赛道强,价格发现仍不完整
Neo 满足许多通常支撑私人市场溢价定价的条件:创始人强、投资人顶级、披露融资规模大,所处赛道也直指企业围绕 AI agent 的紧迫焦虑。如果这些要素再叠加可见客户证据和清晰核验过的估值标记,公司完全可能站在早期网络安全估值上沿。问题在价格发现。保留的公开资料更明确支撑 $100 million 累计融资这个口径,而不是任何精确的当前估值。一些第三方跟踪和报道暗示 Series A 结构较大,但无法在完全可核验条款或已确认 post-money 估值上收敛。这带来实际投资问题:Neo 仍可能是有吸引力的公司,但估值结论的精度必须低于赛道和团队叙事的精度。因此,建议取决于投资人能否私下验证商业证据和进入价格,而不是只看公开叙事。[CV001, CV002, CV003, CV004, CV005, CV006]
| 建议 | 置信度 | 风险评级 | 估值立场 | 决策含义 |
|---|---|---|---|---|
| 观察 | 中 | 高 | 无法验证 | 密切跟踪,投资前要求客户、有效性和轮次条款的私有证据 |
建议仅基于公开证据,不应替代获取公司私有材料。
[CV001, CV025, CV026, CV027, CV040]| 证据点 | 公开信息 | 置信度 | 含义 |
|---|---|---|---|
| 累计融资 | 多个保留来源支持累计融资 $100M 的说法 | 高 | 资本实力确实存在 |
| Series A 规模 | 多个第三方来源指向 2026 年一轮较大的 Series A | 中 | 轮次规模相对阶段可能偏高 |
| 确切投后估值 | 保留的公开证据未清晰确认 | 低 | 精确估值立场必须保持谨慎 |
| 收入基础 | 未发现 ARR 或收入披露 | 高 | 传统倍数分析偏推测 |
| 条款细节 | 未发现可靠的公开条款清单细节 | 高 | 价格纪律取决于私有尽调 |
区分公开记录能支撑的内容和仍无法验证的内容。
[CV002, CV003, CV004, CV005, CV017, CV018]建议更取决于价格核验和客户证据,而不是单靠品类热度。
流程总结的是投资逻辑,而不是公司发布的流程。
[CV001, CV006, CV025, CV026, CV027]8.2 哪些因素仍能支撑溢价估值
即便公开运营数据有限,市场仍有真实理由给 Neo 溢价倍数或战略溢价。2026 年,网络安全资本仍集中押注被视为离群值的公司,agentic AI 安全也格外吸引投资人和收购方注意。Neo 还吃到时点红利:企业才刚开始理解嵌入已批准工具的自主软件风险,公司就在此时推出。如果公司掌握差异化控制点,并能成为归因和策略执行的标准,它的估值就可能显著高于传统种子轮或早期 Series A 基准。可比市场评论也显示,投资人愿意为站在 AI 与网络安全交汇处的公司支付更高价格,尤其当可解决痛点横跨身份、应用控制和治理时。这些都是有分量的估值支撑。只是它们不能抹掉对产品效果、客户深度和本轮实际条款的核验需求。[CV009, CV010, CV011, CV012, CV013, CV014]
| 论点 | 改变判断的因素 |
|---|---|
| Neo 可能掌握企业 AI 智能体的关键控制点 | 若有明确证据显示客户信任该平台用于实时控制,投资逻辑会增强 |
| 顶级投资人与时点支撑溢价兴趣 | 若确认价格落在前十分位但缺少证据,上行空间会变弱 |
| 智能体 AI 安全可能成为大型独立预算项 | 如果相邻套件吸收这一切入口,反向逻辑会增强 |
| 执行证据能把叙事转成有防御力的价值 | 试点转化慢或客户背书弱,会加重反向逻辑 |
本表将核心看多理由与最能改变信心的证据配对。
[CV009, CV013, CV021, CV028, CV033, CV037]| 参照指标 | 指向什么 | 注意事项 |
|---|---|---|
| 2026 年网络安全融资集中度 | 异常值公司能拿到大额融资 | 大额融资不能证明价值可持续 |
| 智能体 AI 安全市场图谱 | 品类战略热度高 | 图谱常混合不同阶段和商业模式 |
| 网络安全估值报告 | 溢价细分赛道可高于市场均值交易 | 公开市场定价和私募估值不能互换 |
| AI 原生安全 M&A 评论 | 稀缺性可能制造战略溢价 | 缺少证据时,不能假设初创公司能拿到 M&A 溢价 |
| 投资人品牌信号 | 顶级资方能支撑激进定价 | 品牌不能替代客户证据 |
使用市场背景做框架,而不是直接定价公式。
[CV010, CV011, CV012, CV014, CV019, CV020]市场环境仍有利于 AI-native 安全融资,但资金挑选度很高。
指标总结的是已留存市场评论,应按方向性理解。
[CV010, CV011, CV013, CV014]8.3 哪些因素压低估值信心并抬高买贵风险
最清楚的限制在于,Neo 的公开证据仍更多证明赛道热度,而不是公司自身结果。保留公开资料没有披露 ARR、客户数量、净留存、毛利率或使用深度。因此,任何收入倍数逻辑都只能是假设。第二个限制是可比性。许多 2026 年市场地图和估值评论把不同类型的 AI 安全公司、成熟阶段和商业化状态混在一起。给一家已经跑出规模的后期公司支付的溢价,不会自动转移到刚公开亮相的创业公司身上,即便两者落在同一个大主题下。第三个限制是竞争压缩。如果大型平台在 Neo 建立可引用证明前吸收了足够多的差异化,今天的溢价叙事可能很快过时。合在一起,这些因素都反对把未经核验的估值传闻或愿景式估值当作可投资事实。至少,投资人应要求私下尽调把客户证明、商业动能和轮次条款对齐之后,再接受前十分位价格。[CV017, CV018, CV019, CV020, CV021, CV022]
| 检查点 | 若为正面 | 若为负面 |
|---|---|---|
| 具名或匿名生产环境客户背书 | 支撑溢价信心 | 立场保持谨慎 |
| 低摩擦部署证据 | 提高扩张概率 | 抬高 GTM 和估值风险 |
| 经验证的商业动能 | 支撑为品类领导地位付费 | 溢价估值更难证明 |
| 更清晰的轮次条款和价格 | 支持有纪律的投资测算 | 入场经济性仍不透明 |
| 相比捆绑方案的持久差异化 | 改善上行不对称性 | 提高倍数压缩风险 |
这些检查点定义公开观察立场升级前必须改善的事项。
[CV023, CV024, CV028, CV029, CV030, CV038]公开证据只能支撑宽泛的情景区间,不能支撑精确的当前估值标记。
区间是以 $M 股权价值表示的分析情景带,不是观察到的市场估值标记。
[CV004, CV017, CV018, CV029]只有证据和价格纪律一起改善,上行空间才高。
矩阵是由公开证据推导出的决策辅助工具。
[CV021, CV025, CV027, CV030]8.4 决策逻辑、敏感性与价格纪律
公开层面最稳妥的结论不是给出硬估值目标,而是保持有纪律的姿态。如果潜在投资人能私下确认强试点转化、真实生产控制,以及尚未把近乎完美执行计入价格的股权结构,Neo 仍值得密切跟踪,也可能值得参与。如果要价在客户验证可见之前就假设赛道领导地位,正确姿态就是谨慎。简单说,这笔投资有几条成立路径:出色的产品证明、受监管企业的快速采用,或 agentic security 的战略稀缺性。失败路径也有几条:转化慢、客户背书弱、既有厂商激进打包,或进入价格几乎不给执行风险留空间。鉴于精确估值缺少充分公开证据,理性建议是观察,而不是直接放弃或投资。只有私下尽调同时提升对证据和价格的信心,投资人才应加码推进。[CV025, CV026, CV027, CV028, CV029, CV030]
承保判断对证据、价格和差异化耐久性最敏感。
数值是方向性敏感度分数,不是建模回报。
[CV023, CV024, CV028, CV038]8.5 附录图表
免责声明
本建议仅基于公开证据。任何投资决定都应依赖私下尽调,覆盖客户背书、部署质量、安全有效性、法律范围和实际轮次条款。
证据索引
| 编号 | 陈述 | 可信度 | 来源 |
|---|---|---|---|
| CO001 | Neo emerged from stealth on 2026-07-20 and publicly launched as a cybersecurity company focused on agentic software control. | 高 | SO001, SO026, SO028 |
| CO002 | Neo is headquartered in Boston, Massachusetts in its public launch materials and later coverage. | 高 | SO001, SO016, SO029 |
| CO003 | Neo describes itself as the Agentic Software Control company for modern AI-driven enterprises. | 高 | SO001, SO002, SO029 |
| CO004 | Neo says its platform governs AI agents, AI-enabled applications, browsers, digital identities, and traditional software that is becoming agentic. | 高 | SO001, SO002, SO004 |
| CO005 | Neo's public founder roster consists of Nick Warner, Shlomi Salem, and Eran Shirazi. | 高 | SO001, SO003, SO026 |
| CO006 | Nick Warner is CEO and co-founder and previously served as SentinelOne's President and COO through its 2021 IPO. | 高 | SO001, SO003, SO026 |
| CO007 | Shlomi Salem is CPO and co-founder and previously led detection engineering and threat research at SentinelOne. | 高 | SO001, SO003, SO026 |
| CO008 | Eran Shirazi is CTO and co-founder and previously co-founded EasySend after earlier Unit 8200 vulnerability-research work. | 高 | SO001, SO003, SO026 |
| CO009 | Neo's public material shows a dual geography of Boston-based operations plus a large Tel Aviv engineering footprint. | 中 | SO003, SO006, SO026 |
| CO010 | Neo's careers page listed 37 open roles on 2026-07-28. | 中 | SO006 |
| CO011 | The posted roles cluster around Boston operations, U.S. field go-to-market roles, and Tel Aviv R&D functions. | 中 | SO006 |
| CO012 | Neo says customers can deploy its sensor in under 15 minutes for first scan, under one hour for full deployment, and with a 25MB agent footprint. | 高 | SO002, SO005 |
| CO013 | Neo says Neoverse catalogs more than 1.2 million agentic artifacts and risk profiles. | 中 | SO005 |
| CO014 | Neo's core control loop combines software inventory, posture or risk intelligence, real-time attribution, policy control, and native enforcement. | 高 | SO001, SO004, SO028 |
| CO015 | Investor and company materials repeat Gartner's estimate that enterprise applications with agentic capabilities will rise from 5% in 2025 to 40% by end-2026. | 中 | SO001, SO007, SO029 |
| CO016 | CyberArk reported that 68% of organizations do not yet have identity-security controls for AI systems, supporting Neo's category urgency. | 高 | SO017, SO007 |
| CO017 | Andreessen Horowitz and Bessemer Venture Partners are the lead investors named across the launch materials, with Craft Ventures and Merlin Ventures also participating. | 高 | SO001, SO008, SO009 |
| CO018 | Neo's official launch announcement describes the financing as $100 million without publicly breaking out round tranches. | 高 | SO001, SO028, SO030 |
| CO019 | Calcalist, Fundraise Insider, and Seedtable each describe the financing as a $75 million Series A following a previously undisclosed $25 million seed round. | 中 | SO024, SO025, SO026 |
| CO020 | Third-party datasets therefore disagree on whether Neo should be underwritten as a single $100 million launch round or as $25 million seed plus $75 million Series A. | 中 | SO001, SO024, SO025, SO026 |
| CO021 | Public sources reviewed do not disclose Neo's exact post-money valuation, making unicorn status directionally plausible but not directly verifiable from retained evidence. | 低 | |
| CO022 | Startup Nation Central describes Neo as founded in August 2025 with 11–50 employees, while Calcalist reports 50 employees with 40 in Israel by July 2026. | 中 | SO022, SO026 |
| CO023 | Calcalist reports that Neo currently employs 50 people, including roughly 40 in Israel. | 中 | SO026 |
| CO024 | Startup Nation Central describes Neo as operating with 11–50 employees and raising $75 million across two rounds, which is directionally consistent on scale but not on total disclosed capital. | 中 | SO022 |
| CO025 | Named angel backers disclosed by Calcalist include Assaf Rappaport, Merav Bahat, Ofir Ehrlich, Ofer Ben-Noon, Omar Adam, and Zaza Pachulia. | 中 | SO026 |
| CO026 | Calcalist's May 2026 pre-launch coverage said Neo had already raised a $25 million seed led by a16z and Merlin and was then raising more than $50 million in a new round. | 中 | SO027 |
| CO027 | Both the launch press release and later coverage say Neo will use the new capital mainly to expand engineering and go-to-market capacity. | 高 | SO001, SO024, SO029 |
| CO028 | Neo frames the main threat as autonomous software acting with valid user permissions, chaining tools and workflows in ways legacy controls treat as legitimate. | 高 | SO001, SO005, SO026 |
| CO029 | BVP argues Neo chose an endpoint sensor architecture because API-only visibility cannot intercept or govern agent actions in real time. | 中 | SO007 |
| CO030 | eWeek says Neo is still early and has not yet disclosed independent performance data or detailed customer results. | 中 | SO010 |
| CO031 | eWeek says Neo has tested its approach with organizations in sensitive sectors such as finance and energy but has not named reference customers. | 中 | SO010 |
| CO032 | The careers page and launch copy together imply Neo is in a rapid post-launch buildout rather than a mature scaling phase with fully stabilized functions. | 中 | SO001, SO006 |
| CO033 | Security Boulevard argues the biggest strategic risk is that agentic-security controls could compress into features inside larger endpoint, identity, or cloud suites rather than persist as a standalone platform category. | 中 | SO013 |
| CO034 | BARC frames Neo's governance pitch as increasingly relevant to enterprises preparing for AI-governance obligations such as the EU AI Act. | 中 | SO012, SO021 |
| CO035 | NIST's AI Risk Management Framework reinforces the need for traceability, governance, and controls around AI behavior, aligning with Neo's audit-trail and policy narrative. | 中 | SO020, SO001 |
| CO036 | MarketsandMarkets forecasts the agentic AI security market to expand from about $1.65 billion in 2026 to $13.52 billion by 2032, which supports investor interest but also raises competition risk. | 中 | SO018, SO019 |
| CO037 | Neo's public web presence was broad enough by late July 2026 to include a homepage, platform explainer, about page, careers board, and launch news, indicating it launched with a full enterprise go-to-market wrapper rather than only a stealth landing page. | 高 | SO001, SO002, SO003, SO006 |
| CO038 | No public board composition, customer count, or revenue run-rate was disclosed in retained evidence, so later diligence chapters must treat those as unresolved. | 中 | SO001, SO003, SO010 |
| CM001 | The agentic-software security market spans visibility, policy, identity, runtime protection, and audit controls for AI agents and AI-enabled applications rather than only model safety or content filtering. | 高 | SM004, SM010, SM023 |
| CM002 | Composio argues that enterprises increasingly need a management layer, not just a proxy, to handle authentication, permissions, observability, and kill-switches for agents. | 中 | SM004, SM005 |
| CM003 | Agent Security segments the category around identity and access, posture, runtime protection, runtime authorization, and compliance. | 中 | SM010, SM011 |
| CM004 | MarketsandMarkets sizes the agentic AI security market at about $1.65 billion in 2026 and $13.52 billion by 2032. | 中 | SM001, SM002 |
| CM005 | The same MarketsandMarkets forecast implies roughly 42% CAGR through 2032, making the category one of the faster-growing adjacent security segments. | 中 | SM001, SM002 |
| CM006 | Neo and BVP both cite Gartner's estimate that agentic capabilities will appear in 40% of enterprise applications by end-2026 versus 5% in 2025. | 高 | SM023, SM024 |
| CM007 | CyberArk reports that 68% of organizations still lack identity-security controls for AI systems, supporting a real control gap rather than a purely aspirational market. | 高 | SM003, SM024 |
| CM008 | OWASP's 2026 agentic applications material formalizes distinct risks such as goal hijacking, tool misuse, identity abuse, and memory poisoning. | 高 | SM008, SM009 |
| CM009 | NIST's AI Risk Management Framework emphasizes governance, traceability, and ongoing monitoring, which map directly to enterprise demand for agent controls. | 高 | SM006, SM004 |
| CM010 | The EU AI Act increases buyer interest in auditability and governance for high-impact AI deployments, even when a vendor is not selling directly into Europe. | 中 | SM007, SM012 |
| CM011 | Primary buyers are typically CISOs, security architecture leaders, and identity or platform security teams rather than line-of-business AI teams. | 中 | SM004, SM010, SM024 |
| CM012 | Day-to-day users include SecOps analysts, identity engineers, application-security teams, and governance personnel who need visibility into tool calls and approvals. | 中 | SM004, SM005, SM011 |
| CM013 | Budget ownership is likely fragmented across security operations, identity, data security, and emerging AI governance programs, which slows category scaling. | 中 | SM004, SM010, SM025 |
| CM014 | Adoption commonly starts with discovery or shadow-AI control before expanding into runtime enforcement and least-privilege policy. | 中 | SM016, SM018, SM020 |
| CM015 | Prompt Security positions the market as covering employee AI use, homegrown AI apps, code assistants, MCP, and agentic AI, implying broad adjacencies but also product sprawl. | 中 | SM016 |
| CM016 | Noma emphasizes deep discovery, contextual risk analysis, blast-radius visualization, and runtime guardrails, showing that runtime governance is a core buying criterion. | 中 | SM017, SM011 |
| CM017 | Palo Alto Networks markets a unified control plane for agent identity, supply-chain scanning, behavior testing, and runtime policies, signaling rapid incumbent entry. | 中 | SM018, SM015 |
| CM018 | Microsoft Security Copilot embeds agents and agentic automation inside existing Microsoft security workflows, raising the risk that some buyer demand is satisfied by bundled platforms. | 中 | SM019 |
| CM019 | Oasis frames a distinct subsegment around agentic access management and non-human identity governance. | 中 | SM020, SM010 |
| CM020 | Astrix frames AI agent security through the lens of non-human identities, least-privileged access, and audit trails, but its June 2026 Cisco acquisition also signals early consolidation. | 中 | SM021 |
| CM021 | Zenity argues that agent security requires simultaneous discovery, policy, identity, and runtime defense because no legacy category captures the full decision path of an agent. | 中 | SM022 |
| CM022 | General Analysis, Mindgard, and Akto all publish long vendor lists in 2026, indicating the category is crowded and still searching for a durable leaderboard. | 中 | SM013, SM014, SM015 |
| CM023 | Because many review and benchmark lists mix AI testing, posture management, runtime protection, and governance tools, the practical market boundary remains fluid. | 中 | SM013, SM014, SM015 |
| CM024 | The near-term SOM for a company like Neo is narrower than the headline TAM because the first buyers are mostly large enterprises with active agent deployments and security teams able to sponsor a new control layer. | 中 | SM004, SM024, SM025 |
| CM025 | Regulated sectors such as finance, healthcare, and critical infrastructure are likely early adopters because auditability and action-level approvals matter more there. | 中 | SM004, SM007, SM023 |
| CM026 | One major growth driver is that AI capabilities are being embedded inside already approved SaaS and security tools, making shadow or semi-approved agentic behavior harder to govern. | 高 | SM023, SM024, SM016 |
| CM027 | A second driver is the shift from passive copilots to agents that can invoke tools, move data, and act autonomously, which increases the need for real-time authorization. | 高 | SM004, SM008, SM018 |
| CM028 | A major adoption constraint is proof-of-ROI: buyers can understand the risk narrative yet still struggle to justify a standalone spend before incidents or compliance pressure force action. | 中 | SM025, SM013 |
| CM029 | Another constraint is overlap with existing IAM, DSPM, DLP, EDR, and cloud-security programs, which can turn evaluations into platform rationalization debates. | 中 | SM022, SM025 |
| CM030 | A third constraint is that runtime governance is operationally harder than discovery or dashboarding, so buyers may pilot broadly but deploy narrowly. | 中 | SM017, SM018, SM022 |
| CM031 | Security Boulevard's critique that today's product can become tomorrow's feature is a direct adverse argument against rich standalone market assumptions. | 中 | SM025 |
| CM032 | For Neo specifically, the market is attractive because the problem is real, timing is strong, and the category is early enough that a new control-plane vendor can still earn design wins. | 中 | SM004, SM023, SM024 |
| CM033 | For Neo specifically, the market is also risky because incumbents and adjacent startups are already covering most of the same nouns: identity, runtime, posture, audit, and policy. | 中 | SM017, SM018, SM019, SM020, SM021, SM022 |
| CM034 | Public evidence is strong enough to support a bullish market-growth narrative but not precise enough to calculate a company-specific SAM or SOM from disclosed customer counts. | 中 | SM001, SM023 |
| CM035 | The cleanest diligence posture is to treat 2026 as category-creation year for agentic-security budgets, not as proof that long-term spend pools are already stable. | 中 | SM012, SM025 |
| CP001 | The relevant competitive set spans startup specialists and large incumbents rather than a single homogeneous peer group. | 中 | SP011, SP014, SP015 |
| CP002 | Neo positions around endpoint or software-layer control, inventory, attribution, and native enforcement for agentic applications. | 高 | SP001, SP002 |
| CP003 | Prompt Security positions around employee AI use, homegrown AI apps, code assistants, MCP, and agentic AI, giving it a broad AI-security footprint. | 中 | SP003 |
| CP004 | Noma emphasizes deep discovery, blast-radius analysis, and runtime guardrails tailored to AI agents. | 高 | SP004, SP018, SP019 |
| CP005 | Palo Alto Networks markets Prisma AIRS as a unified control plane spanning discovery, supply-chain scanning, behavior testing, identity, and runtime policies. | 中 | SP005 |
| CP006 | Microsoft embeds Security Copilot agents into its existing Defender, Entra, Intune, and Purview workflows, making distribution a key advantage. | 高 | SP006, SP024 |
| CP007 | Oasis frames a distinct identity-centric wedge around agentic access management and non-human identities. | 中 | SP007 |
| CP008 | Astrix frames AI agent security through non-human identities, least-privileged access, and audit trails. | 中 | SP008 |
| CP009 | Zenity positions around discovery, policy, identity, and runtime defense focused on the decision path of agents. | 中 | SP009 |
| CP010 | CyberArk research and messaging reinforce identity-security urgency, making it a likely adjacent incumbent rather than a direct point-solution peer. | 中 | SP010, SP011 |
| CP011 | Agent Security benchmarks the market around identity, posture, runtime protection, runtime authorization, and compliance. | 中 | SP011, SP013 |
| CP012 | MarketsandMarkets includes Microsoft, Palo Alto, CrowdStrike, Noma, Mindgard, Zenity, Astrix, and many others, confirming a crowded field. | 中 | SP014, SP016, SP017 |
| CP013 | Review lists from General Analysis, Mindgard, Akto, and Agent Security all show different vendor orderings, suggesting the leaderboard is not settled. | 中 | SP012, SP015, SP016, SP017 |
| CP014 | Neo’s strongest apparent differentiation is its endpoint-anchored control narrative rather than a pure API, governance, or identity-only stance. | 中 | SP002, SP003, SP007, SP009 |
| CP015 | Noma and Palo Alto are closest to Neo on runtime-governance language because both emphasize action-level controls and guardrails. | 中 | SP004, SP005, SP018 |
| CP016 | Oasis and Astrix skew more identity-centric than Neo, focusing on permissions and non-human identities rather than full software control loops. | 中 | SP007, SP008, SP020 |
| CP017 | Prompt Security is broader than Neo across employee AI, application AI, and code assistants, which can be an advantage in platform breadth but a dilution risk in depth. | 中 | SP003, SP002 |
| CP018 | Microsoft and Palo Alto benefit from pre-existing distribution, adjacent telemetry, and bundling leverage that startups cannot match. | 中 | SP005, SP006, SP024 |
| CP019 | Astrix’s acquisition by Cisco in June 2026 is direct evidence that incumbents are buying their way into the category. | 高 | SP020, SP021 |
| CP020 | No retained source provides clean public pricing for Neo or most direct competitors, so packaging comparisons are more about architecture than sticker price. | 中 | SP003, SP004, SP005, SP006 |
| CP021 | CrowdStrike’s AI-security material underscores that broader security platforms are also educating the same budget holders Neo wants to reach. | 中 | SP023 |
| CP022 | Buying criteria consistently center on visibility, runtime control, identity or ownership, compliance evidence, and safe production deployment. | 中 | SP011, SP013, SP018 |
| CP023 | The field is crowded enough that distribution and trust may matter as much as any one feature checklist. | 中 | SP014, SP015, SP019 |
| CP024 | Neo has a credible founder and investor brand but less public proof than incumbents on customer scale and ecosystem breadth. | 中 | SP001, SP006, SP005 |
| CP025 | Prompt Security, Noma, and Zenity each market themselves as enterprise AI security leaders, indicating category claims are easy to make and hard to verify comparatively. | 中 | SP003, SP004, SP009 |
| CP026 | Neo’s moat claim is strongest if endpoint-native interception really yields enforcement depth that API-only or identity-only products cannot replicate. | 中 | SP002, SP009, SP011 |
| CP027 | That moat weakens if incumbents can combine endpoint telemetry, identity, and agent orchestration quickly enough to offer “good enough” controls inside larger suites. | 中 | SP005, SP006, SP025 |
| CP028 | The most plausible near-term competitive wedge for Neo is fast, enterprise-grade runtime control for approved software already becoming agentic. | 中 | SP001, SP002, SP011 |
| CP029 | The least differentiated part of the market is inventory or visibility alone, because many vendors now claim some form of discovery. | 中 | SP004, SP005, SP008, SP009 |
| CP030 | A serious competitor matrix must separate platform breadth from deployment depth, because the vendors are not all solving the same problem at the same layer. | 中 | SP011, SP013, SP015 |
| CP031 | MarketsandMarkets and third-party lists include many more companies than a realistic enterprise shortlist, so shortlists will likely be narrowed by existing stack fit and trust. | 中 | SP014, SP017, SP023 |
| CP032 | The category is early enough that acquisitions, partnership announcements, and platform integrations may matter more than published win rates in 2026. | 中 | SP019, SP020, SP024 |
| CP033 | Neo should expect its hardest competition in Fortune 500 accounts to come from incumbents and well-funded control-plane startups, not from generic security software vendors. | 中 | SP005, SP006, SP018, SP021 |
| CP034 | The strongest adverse case is that the market converges on suites where agent controls are one module among many, compressing standalone valuations. | 中 | SP019, SP020, SP025 |
| CP035 | Public-web competitor research still cannot reveal actual pricing, retention, displacement rates, or side-by-side win-loss data, leaving major underwriting gaps. | 中 | SP003, SP004, SP005, SP006 |
| CI001 | Neo's public financing headline is $100 million as of its July 2026 launch. | 高 | SI001, SI018, SI020 |
| CI002 | Calcalist, Fundraise Insider, and Seedtable describe the financing as a $75 million Series A after a $25 million seed round. | 中 | SI012, SI014, SI015 |
| CI003 | The discrepancy between a single $100 million launch round and a $25M seed plus $75M Series A remains unresolved in retained public evidence. | 中 | SI001, SI012, SI014, SI015 |
| CI004 | Public sources reviewed do not disclose revenue, ARR, gross margin, NRR, or cash balance. | 中 | SI001, SI003, SI012 |
| CI005 | Neo presents itself as an enterprise software platform for SecOps teams, implying a subscription-driven software model rather than a consumer or ad-supported model. | 中 | SI001, SI003, SI004 |
| CI006 | The product narrative around demos, ROI tooling, and sales engineering suggests revenue is expected to come through enterprise contracts with evaluation and rollout phases. | 中 | SI004, SI005, SI011 |
| CI007 | The careers page shows 37 open roles, supporting the view that Neo is in an investment-heavy buildout phase. | 中 | SI002 |
| CI008 | Open roles span GTM, finance, legal, product, and engineering, implying rapid opex expansion across both revenue and corporate functions. | 中 | SI002 |
| CI009 | Calcalist reports Neo has about 50 employees, with roughly 40 in Israel, providing the clearest headcount-based burn proxy in retained evidence. | 中 | SI012 |
| CI010 | Startup Nation Central lists Neo at 11–50 employees, which is directionally consistent but less precise than Calcalist. | 中 | SI016 |
| CI011 | The combination of 50 employees and 37 open roles implies Neo is planning a substantial step-up in payroll and hiring spend after launch. | 中 | SI002, SI012 |
| CI012 | Both company and third-party sources say the new capital will be used mainly to expand engineering and go-to-market teams. | 高 | SI001, SI014, SI019 |
| CI013 | The presence of finance controller, sales operations manager, human resources, and corporate attorney roles indicates infrastructure spending beyond pure product build. | 中 | SI002 |
| CI014 | No retained source discloses list pricing or minimum contract value for Neo. | 中 | SI003, SI004, SI005 |
| CI015 | Neo’s public site markets demos and ROI messaging rather than self-serve checkout, implying high-touch enterprise sales motion. | 中 | SI004, SI011 |
| CI016 | Because Neo sells into security operations and governance workflows, its revenue quality is more likely to depend on annual or multi-year enterprise subscriptions than usage-only spend. | 中 | SI001, SI003, SI022 |
| CI017 | Public evidence is insufficient to estimate gross margin with confidence because there is no disclosed mix of software, services, support, or cloud inference cost. | 中 | SI001, SI003, SI004 |
| CI018 | Public evidence is insufficient to estimate net revenue retention because there is no disclosed customer cohort or expansion data. | 中 | SI001, SI003, SI006 |
| CI019 | A $100 million launch capital base materially reduces near-term financing pressure even without public revenue disclosure. | 中 | SI001, SI018, SI024 |
| CI020 | If the round truly comprised $25 million seed plus $75 million Series A, Neo may already have consumed substantial stealth build capital before public launch. | 中 | SI012, SI013, SI014 |
| CI021 | The next financing trigger is more likely to be customer traction and production deployments than mere category narrative, because the narrative was already priced into the launch round. | 中 | SI021, SI022, SI023 |
| CI022 | Security Boulevard’s critique implies that if the category becomes a feature, Neo’s pricing power and exit multiple could compress before IPO readiness. | 中 | SI021 |
| CI023 | Craft and BVP both emphasize the speed of agentic adoption, which supports aggressive GTM hiring but does not prove monetization quality. | 中 | SI022, SI023 |
| CI024 | Neo’s financial disclosure profile remains private-undisclosed based on retained public evidence. | 中 | SI001, SI006, SI007 |
| CI025 | The news, blog, and event pages show marketing investment around launch but do not reveal monetization metrics. | 中 | SI006, SI007, SI010 |
| CI026 | A reasonable revenue-stream hypothesis is core platform subscription plus services for deployment, policy tuning, and integrations, but the services share is not disclosed. | 低 | SI003, SI004, SI005 |
| CI027 | Because Neo is targeting regulated, high-stakes workflows, successful deals could carry higher ACVs than commodity AI-assistant governance tools, but no public contract data confirms that yet. | 低 | SI003, SI022, SI025 |
| CI028 | The ROI calculator implies Neo is trying to articulate quantified value before the company has publicly disclosed its own operating metrics. | 中 | SI011 |
| CI029 | The legal pages suggest Neo is already standing up enterprise contracting infrastructure rather than operating only as a research project. | 中 | SI008, SI009 |
| CI030 | The financial model is currently easiest to underwrite as capital-backed product build with uncertain revenue timing rather than as an already efficient growth machine. | 中 | SI001, SI002, SI012 |
| CI031 | The strongest public balance-sheet fact is the size of announced capital, not the size of current cash on hand. | 中 | SI001, SI018, SI019 |
| CI032 | Without customer count or ARR, it is impossible to derive revenue per employee responsibly from retained sources. | 中 | SI001, SI012, SI016 |
| CI033 | If Neo closes large reference accounts quickly, the same headcount base could become a sign of ahead-of-demand investment rather than overspending. | 低 | SI002, SI021 |
| CI034 | If Neo fails to convert the current hiring and marketing push into production customers, the large launch round could turn from strength into an expectation burden. | 中 | SI002, SI021, SI023 |
| CI035 | Public-web financial diligence remains dominated by evidence gaps rather than contradictions on operating results, because the company has disclosed almost none of those results. | 中 | SI001, SI006, SI007 |
| CE001 | Neo’s public product narrative centers on real-time protection for the “agentic enterprise.” | 高 | SE001, SE005 |
| CE002 | The platform claims to reveal, understand, and control human and non-human activity across devices, browsers, identities, and applications. | 高 | SE001, SE003, SE005 |
| CE003 | Neo presents five core product capabilities: software inventory, capability and risk intelligence, attribution, granular software control, and native enforcement. | 高 | SE005, SE003 |
| CE004 | Neo inventories agents, models, skills, MCP servers, extensions, and other software artifacts rather than only top-level application binaries. | 高 | SE001, SE003, SE004 |
| CE005 | Neo says Neoverse is a continuously updated knowledge base covering more than 1.2 million agentic artifacts and risks. | 中 | SE004 |
| CE006 | Neo claims its sensor can deliver first scan in under 15 minutes, full deployment in under one hour, and a 25MB endpoint footprint. | 高 | SE001, SE004 |
| CE007 | BVP’s writeup says Neo made a deliberate architectural bet on an endpoint sensor because API-only visibility cannot intercept and govern agent actions in real time. | 中 | SE006 |
| CE008 | Neo’s policy engine is described as LLM-assisted and able to propose or refine policy after observing traffic. | 中 | SE006, SE003 |
| CE009 | Neo emphasizes attribution that ties actions back to the human, agent, application, or identity responsible. | 高 | SE005, SE003 |
| CE010 | The product is meant to allow, block, or hold actions for approval before sensitive data or systems are touched. | 高 | SE001, SE003 |
| CE011 | Composio’s MCP governance material highlights centralized identity, policy, and audit control as key enterprise requirements around tool-calling agents. | 中 | SE012 |
| CE012 | OWASP’s 2026 agentic applications material reinforces the need to defend against tool misuse, identity abuse, memory poisoning, and cascading failures. | 高 | SE011, SE017 |
| CE013 | NIST AI RMF reinforces requirements around governance, traceability, and monitoring that match Neo’s attribution and policy story. | 高 | SE010, SE005 |
| CE014 | Neo’s privacy policy and terms of service show that the company is already presenting enterprise legal surfaces beyond marketing pages. | 中 | SE023, SE024 |
| CE015 | The Black Hat 2026 event page indicates Neo is already packaging demos and field education around the product. | 中 | SE022 |
| CE016 | Prompt Security, Noma, and Zenity each emphasize overlapping discovery, runtime, and governance capabilities, confirming Neo is not alone in product direction. | 中 | SE007, SE008, SE009 |
| CE017 | Palo Alto’s AIRS 3.0 press and docs show incumbents are moving toward full lifecycle agent security including discovery, identity, behavior testing, and runtime control. | 高 | SE013, SE014, SE015 |
| CE018 | Akto’s guidance treats runtime guardrails, posture management, discovery, and governance as standard parts of an enterprise AI agent security program. | 中 | SE016, SE017, SE018 |
| CE019 | CrowdStrike’s Charlotte AI page shows that adjacent security vendors increasingly mix AI assistants, investigation workflows, and broader security automation into the same conversation. | 中 | SE019 |
| CE020 | IBM’s 2026 control-gap study supports Neo’s premise that enterprise deployment is outpacing governance readiness. | 中 | SE020 |
| CE021 | Microsoft’s 2026 Work Trend narrative suggests enterprises are redesigning work around agents, which increases demand for operational guardrails rather than one-time code reviews. | 中 | SE021 |
| CE022 | Neo does not publicly disclose independent benchmark results, false-positive rates, or production-scale performance metrics. | 中 | SE001, SE003, SE005 |
| CE023 | Neo also does not publicly disclose named integrations with SIEMs, IdPs, or ticketing platforms in retained sources, though the product messaging implies those workflows. | 中 | SE001, SE003 |
| CE024 | The product looks broad enough to cover discovery, control, and attribution, but not yet documented enough publicly to prove deployment depth versus peers. | 中 | SE001, SE003, SE025 |
| CE025 | Neo’s most distinctive architectural claim remains endpoint-native interception for agentic software already running inside trusted applications. | 中 | SE004, SE006 |
| CE026 | If the category shifts toward control planes embedded inside broader suites, Neo’s product differentiation will need to come from operational depth rather than vocabulary. | 中 | SE013, SE025 |
| CE027 | The likely operating architecture includes endpoint telemetry, knowledge-base enrichment, policy evaluation, attribution, and response routing to existing SOC processes. | 中 | SE001, SE003, SE006 |
| CE028 | The product is built for enterprise operators rather than end users, as shown by its language around SecOps, group-specific policy, and governed approvals. | 高 | SE001, SE003, SE005 |
| CE029 | Neo’s public materials imply a workflow in which security teams first inventory software, then inspect capabilities, then define or refine policies, then enforce actions. | 中 | SE001, SE003, SE006 |
| CE030 | The trust and quality story is currently stronger on governance framing than on independently measured product outcomes. | 中 | SE010, SE022, SE024 |
| CE031 | Public launch timing and Black Hat messaging imply the roadmap is still early and likely focused on core enterprise control loops rather than long-tail ecosystem breadth. | 中 | SE005, SE022 |
| CE032 | Because agentic AI deployment is moving quickly, the absence of public product docs beyond marketing pages is itself a diligence signal that documentation maturity may lag product ambition. | 中 | SE003, SE022, SE025 |
| CE033 | The company’s legal and privacy pages demonstrate basic enterprise readiness but do not substitute for public evidence of certifications such as SOC 2 or ISO 27001. | 中 | SE023, SE024 |
| CE034 | No retained public source confirms external audit certifications, model-evaluation benchmarks, or a reference architecture pack for customers. | 中 | SE001, SE023, SE024 |
| CE035 | The biggest open product question is not what nouns Neo can name, but how often real customers actually trust it to hold or block actions in production. | 低 | |
| CU001 | Neo’s public positioning targets enterprises coping with AI agents and agentic software rather than consumers or small businesses. | 高 | SU001, SU004 |
| CU002 | The likely first customer segment is large enterprise security teams trying to govern software that can act with valid user permissions. | 中 | SU001, SU003, SU006 |
| CU003 | Neo’s product framing implies adoption begins where sanctioned software is already gaining agentic features across browsers, SaaS, and tools. | 高 | SU001, SU003, SU011 |
| CU004 | The economic buyer is most plausibly the CISO or equivalent security executive because the product is framed as a control and governance layer. | 中 | SU004, SU006, SU007 |
| CU005 | SecOps, security architecture, identity, and governance teams are the most likely daily operators if Neo is deployed. | 中 | SU003, SU006 |
| CU006 | Business and engineering teams using AI agents are likely indirect beneficiaries rather than primary buyers. | 中 | SU001, SU020 |
| CU007 | Because the problem crosses security, IT, and business workflows, budget approval likely needs cross-functional sponsorship. | 中 | SU003, SU019 |
| CU008 | Investor materials indicate strong CISO concern around AI-agent risk, supporting demand-side urgency for Neo’s category. | 高 | SU006, SU007, SU008 |
| CU009 | Retained public sources do not disclose named Neo customers as of 2026-07-28. | 高 | SU001, SU004, SU005, SU011 |
| CU010 | The Black Hat page and demo CTA show active enterprise outreach, but not confirmed production-scale adoption. | 高 | SU005, SU023 |
| CU011 | Launch coverage consistently describes the company as selling to enterprises rather than hobbyist or prosumer users. | 中 | SU009, SU011, SU012 |
| CU012 | Public customer proof is currently stronger on buyer conversations and event motion than on case studies or reference accounts. | 中 | SU005, SU006, SU007, SU024 |
| CU013 | No retained public source provides renewal, retention, or customer-count metrics for Neo. | 高 | SU001, SU004, SU025 |
| CU014 | No retained public source provides price points, seat counts, or contract-value disclosures for Neo. | 高 | SU001, SU004, SU011 |
| CU015 | A plausible first deployment use case is discovering unknown or poorly governed agentic software already present in the environment. | 中 | SU001, SU003, SU006 |
| CU016 | The second stage of adoption likely involves limited policy deployment for high-risk actions, users, or workflows. | 中 | SU003, SU005, SU006 |
| CU017 | The product’s emphasis on attribution and policy suggests a consultative enterprise motion rather than a pure self-serve onboarding path. | 中 | SU003, SU005, SU023 |
| CU018 | Expansion inside an account likely depends on reducing policy noise while preserving business velocity for agent users. | 中 | SU003, SU019 |
| CU019 | Because enterprises are still early in production AI-agent deployment, Neo probably sells into both experimentation and control-readiness budgets. | 中 | SU020, SU021, SU022 |
| CU020 | Regulated enterprises are especially likely targets because auditability and action attribution become more valuable where oversight burdens are high. | 中 | SU017, SU018, SU019 |
| CU021 | The land-and-expand path is vulnerable to pilot-to-production drop-off if enterprises cannot operationalize the controls broadly. | 中 | SU021, SU022, SU024 |
| CU022 | Public sources support a controlled rollout narrative better than they support immediate fleet-wide deployment claims. | 中 | SU005, SU017, SU021 |
| CU023 | If Neo has only a small number of influential early accounts, design-partner concentration risk could be meaningful. | 低 | SU009, SU024 |
| CU024 | Customer quality matters more than raw logo count at this stage because the category still needs deep referenceable proof. | 中 | SU006, SU024 |
| CU025 | Incumbent bundling pressure could make account expansion harder unless Neo proves better action-level control than broader suites. | 中 | SU024, SU017 |
| CU026 | Referenceability risk is elevated because security-sensitive early customers may be reluctant to be named publicly. | 低 | SU005, SU024 |
| CU027 | The absence of public deployment metrics should keep any customer-strength assessment in the medium-confidence range. | 中 | SU011, SU016, SU025 |
| CU028 | Neo’s customer story appears tailored to enterprises where AI agents intersect with endpoint, identity, and application governance. | 中 | SU001, SU006, SU018 |
| CU029 | Investor-backed CISO feedback is useful but not equivalent to verifiable customer contracts or production references. | 高 | SU006, SU007, SU008 |
| CU030 | Event-led visibility can accelerate pipeline creation, but by itself it does not prove high retention or expansion potential. | 中 | SU005, SU023 |
| CU031 | The most plausible adoption sequence is urgency creation, discovery, pilot control deployment, approval workflows, and then broader rollout. | 中 | SU003, SU005, SU023 |
| CU032 | Shared-budget ambiguity may slow deals because several internal teams benefit even if security owns the risk. | 低 | SU019, SU020 |
| CU033 | Without named case studies, Neo cannot yet be underwritten as having strong public customer durability. | 中 | SU009, SU011, SU024 |
| CU034 | The public record is consistent with early enterprise interest, probable pilots, and incomplete referenceability rather than with scaled commercial maturity. | 中 | SU005, SU006, SU011, SU024 |
| CU035 | The best next diligence evidence would be deployment timelines, customer references, retention data, and proof that controls work with limited operational friction. | 中 | SU024, SU019 |
| CR001 | Neo’s category is exposed to expanding AI-governance obligations around inventory, oversight, logging, and accountability. | 高 | SR007, SR008, SR009 |
| CR002 | Public regulatory guidance increasingly expects organizations to document and govern high-impact or high-risk AI uses before incidents occur. | 高 | SR007, SR009, SR011 |
| CR003 | Neo’s positioning appears directionally aligned with those expectations because it emphasizes discovery, attribution, and policy control. | 高 | SR003, SR004, SR026 |
| CR004 | Regulated customers may still impose heavy diligence burdens because Neo has not publicly published comprehensive compliance mappings. | 中 | SR009, SR010, SR016 |
| CR005 | Liability questions remain unresolved if customers interpret Neo controls as broader compliance assurance than the platform can actually provide. | 高 | SR001, SR012, SR016 |
| CR006 | Privacy and monitoring sensitivity are real because endpoint or workflow visibility can trigger internal review even when the security goal is valid. | 高 | SR002, SR008, SR016 |
| CR007 | Joint government-aligned guidance on agentic AI adoption emphasizes least privilege, monitoring, and accountability rather than blind trust in autonomous systems. | 高 | SR012, SR013, SR014, SR015 |
| CR008 | Regulatory uncertainty cuts both ways for Neo: it creates demand for control tooling while also increasing buyer caution. | 中 | SR009, SR011, SR026 |
| CR009 | Neo’s biggest product risk is whether customers can trust the platform for live approval or blocking decisions in noisy enterprise environments. | 中 | SR003, SR006 |
| CR010 | False positives could slow legitimate workflows and reduce operator trust in the product. | 中 | SR017, SR019, SR020 |
| CR011 | False negatives could create a dangerous illusion of control if risky agent behavior is missed. | 中 | SR017, SR019, SR027 |
| CR012 | Public sources do not disclose benchmarks, false-positive rates, or deployment-time operating metrics for Neo. | 高 | SR003, SR004, SR025 |
| CR013 | Endpoint or telemetry-heavy architectures may create rollout friction that becomes visible only after pilots begin. | 低 | SR005, SR029 |
| CR014 | Prompt injection and policy-bypass patterns remain fast-moving category risks for any agent-control platform. | 高 | SR017, SR018, SR019, SR020 |
| CR015 | Because Neo relies on a knowledge layer and policy logic, freshness and classification quality are likely important determinants of efficacy. | 中 | SR003, SR005 |
| CR016 | The absence of public reference architectures makes it harder to judge integration depth and operator overhead. | 中 | SR003, SR024 |
| CR017 | The company’s operational risk is evidence-limited rather than thesis-free; the architecture story is clear, but proof remains incomplete. | 中 | SR004, SR025, SR026 |
| CR018 | Sparse public customer proof is the most important commercial risk because it limits referenceability and reduces confidence in deployment depth. | 中 | SR006, SR024, SR025 |
| CR019 | Enterprise buying cycles may be long because Neo sells into a new category and likely needs education across several stakeholder groups. | 中 | SR005, SR022, SR029 |
| CR020 | Bundling pressure is serious because large vendors increasingly market overlapping AI-agent security or governance capabilities. | 高 | SR006, SR023, SR026 |
| CR021 | Budget ownership ambiguity can slow deals because risk ownership sits with security while productivity value may sit with business or engineering teams. | 中 | SR022, SR024 |
| CR022 | If early customers are mostly design partners, concentration and roadmap-capture risk rise. | 低 | SR005, SR018 |
| CR023 | Strong financing buys time to refine product and GTM, but it also raises expectations for rapid commercial validation. | 中 | SR004, SR025, SR030 |
| CR024 | Market heat can help Neo open doors while also making it easier for competitors and incumbents to flood the space with adjacent messaging. | 中 | SR005, SR006, SR023 |
| CR025 | Operational failures would transmit quickly into longer cycles, weaker expansion, and lower-quality revenue. | 中 | SR018, SR021, SR022 |
| CR026 | The thesis is manageable only if Neo converts conceptual leadership into referenceable operational evidence within the next phase of commercialization. | 中 | SR006, SR025 |
| CR027 | Investors should treat customer proof and operational efficacy as the two highest-priority risks today. | 中 | SR012, SR018, SR025 |
| CR028 | The most valuable operational mitigants would be benchmarks, deployment data, and reference architectures. | 中 | SR012, SR024 |
| CR029 | The most valuable commercial mitigants would be named or anonymized customer references and clearer time-to-value evidence. | 中 | SR005, SR024 |
| CR030 | Kill criteria should include failure to produce credible customer references, failure to sustain differentiation, or evidence that deployment friction is too high. | 高 | SR006, SR012, SR026 |
| CR031 | Standard legal and privacy pages are necessary enterprise hygiene but not proof that complex AI-liability issues are solved. | 高 | SR001, SR002, SR016 |
| CR032 | The AI Act and related guidance make documentation quality more important for enterprise AI vendors, even when the vendor is not itself the system operator. | 高 | SR007, SR009, SR011 |
| CR033 | Public risk evidence is strongest on category threats and weakest on Neo-specific measured outcomes. | 中 | SR017, SR019, SR025 |
| CR034 | A category with real urgency can still disappoint commercially if proof gaps persist after large financing. | 中 | SR006, SR025, SR030 |
| CR035 | The absence of customer metrics means investors should avoid assuming healthy retention or fast expansion. | 中 | SR024, SR030 |
| CR036 | If Neo demonstrates low-friction deployment and credible control efficacy, several major risks fall at once. | 低 | SR005, SR029 |
| CR037 | If incumbents flatten the feature wedge before Neo establishes references, valuation risk rises materially. | 中 | SR006, SR023 |
| CR038 | If regulated customers adopt Neo with explicit documentation wins, the legal-risk narrative improves substantially. | 中 | SR009, SR010, SR026 |
| CR039 | If enterprises conclude Neo’s scope is too narrow relative to bundled suites, the company may struggle to justify standalone spend. | 中 | SR006, SR023 |
| CR040 | Capital adequacy reduces financing urgency, but execution evidence still determines whether the risk-adjusted investment case improves. | 中 | SR004, SR025 |
| CV001 | The most defensible public recommendation on Neo is watch rather than invest or pass outright. | 中 | SV001, SV028 |
| CV002 | Retained public sources strongly support Neo’s $100M aggregate funding headline. | 高 | SV001, SV007, SV011, SV013 |
| CV003 | Several retained third-party sources point to a large 2026 Series A structure, but they do not establish a single fully verified valuation mark. | 中 | SV008, SV009, SV010 |
| CV004 | The exact current valuation is not cleanly confirmed in retained public evidence. | 高 | SV001, SV009, SV010 |
| CV005 | Because the public record does not resolve price precisely, investors need private diligence on terms and cap table before underwriting a premium mark. | 高 | SV003, SV004, SV010 |
| CV006 | Neo’s team quality, investor base, and category timing all support sustained market attention. | 高 | SV001, SV002, SV005 |
| CV007 | Public narrative precision on company quality is higher than precision on current valuation. | 中 | SV001, SV004, SV028 |
| CV008 | A positive investment case therefore depends more on confirming proof and price privately than on public hype. | 中 | SV001, SV028 |
| CV009 | AI-native cyber outliers in 2026 can still attract very large rounds and premium interest. | 高 | SV015, SV020, SV021 |
| CV010 | Agentic AI security is a strategically hot subcategory in 2026, which supports premium investor attention. | 高 | SV015, SV018, SV029 |
| CV011 | Cyber funding in 2026 appears concentrated in fewer, stronger companies rather than broadly distributed across the field. | 高 | SV020, SV021, SV022, SV023 |
| CV012 | Top-tier investor sponsorship can support ambitious pricing by signaling access, conviction, and category relevance. | 高 | SV002, SV005, SV006 |
| CV013 | Later-stage strategic premiums and public comp commentary suggest upside for differentiated leaders but should not be copied directly onto Neo. | 中 | SV018, SV024, SV025 |
| CV014 | The market is willing to pay more for genuine AI-native security differentiation than for generic AI-washing. | 中 | SV020, SV023, SV024 |
| CV015 | If Neo truly owns a differentiated action-control layer, a premium early-stage price could be supportable in principle. | 高 | SV002, SV004, SV005 |
| CV016 | Premium interest is easier to justify when a company sits at the intersection of identity, application control, and governance pain. | 中 | SV004, SV006, SV029 |
| CV017 | No retained public source discloses Neo ARR, revenue, or gross margin. | 高 | SV001, SV009, SV010 |
| CV018 | Without revenue disclosure, any revenue-multiple valuation logic is hypothetical rather than evidence-based. | 中 | SV017, SV024, SV028 |
| CV019 | Comparable sets are noisy because many 2026 AI-security market maps mix different stages, models, and commercialization profiles. | 中 | SV015, SV017, SV018 |
| CV020 | Later-stage or strategic M&A marks are informative for sector heat but are not direct valuation anchors for Neo. | 中 | SV018, SV024, SV025 |
| CV021 | Bundling pressure from broader platforms can compress future valuation upside if Neo’s wedge is not durable. | 中 | SV023, SV028 |
| CV022 | An unverified rumor or aspirational mark should not be treated as investable truth when company-specific proof is still limited. | 中 | SV010, SV016, SV028 |
| CV023 | The underwriting case is most sensitive to customer proof, price clarity, and differentiation durability. | 中 | SV015, SV024, SV028 |
| CV024 | Named or anonymized production references would do more than additional narrative coverage to improve valuation confidence. | 中 | SV002, SV006, SV030 |
| CV025 | Watch is better than pass because the company may still compound meaningfully if private proof validates the public thesis. | 高 | SV001, SV002, SV005 |
| CV026 | Watch is better than invest because the public record still leaves too much uncertainty about price and commercial depth. | 中 | SV004, SV017, SV028 |
| CV027 | A public invest recommendation would require stronger evidence that entry price leaves room for execution risk. | 中 | SV003, SV024 |
| CV028 | Investors should upgrade the stance only if private diligence confirms referenceable customers, credible deployment quality, and disciplined terms. | 高 | SV003, SV006, SV030 |
| CV029 | A public pass recommendation would become more compelling if private diligence found weak conversion, poor references, or price that assumes near-perfect execution. | 中 | SV016, SV028 |
| CV030 | Because the exact current valuation is unclear publicly, price discipline remains central to risk-adjusted returns. | 高 | SV003, SV004, SV024 |
| CV031 | The funding headline itself is meaningful because it gives Neo time to attempt category leadership and customer validation. | 高 | SV001, SV011, SV013 |
| CV032 | Capital adequacy reduces financing urgency but does not substitute for commercial evidence. | 高 | SV001, SV021 |
| CV033 | Strong category timing is a support for valuation, but not a license to ignore company-specific execution proof. | 中 | SV010, SV015, SV028 |
| CV034 | Investor-brand signal helps open the premium narrative, yet lasting valuation support still depends on customer outcomes. | 中 | SV005, SV006, SV028 |
| CV035 | Overpayment risk is elevated whenever category heat outruns company-specific proof. | 中 | SV016, SV028 |
| CV036 | If competitors or incumbents flatten Neo’s differentiation, today’s premium narrative could rerate quickly. | 中 | SV023, SV028 |
| CV037 | The best upside case is that Neo becomes a scarce strategic control point for enterprise AI agents before larger suites close the gap. | 中 | SV002, SV005, SV015 |
| CV038 | The best downside case to avoid is paying a top-decile price before customer validation is visible. | 中 | SV016, SV028 |
| CV039 | Private diligence should focus on customer references, pilot conversion, deployment friction, and round mechanics rather than only on market size narratives. | 中 | SV003, SV030 |
| CV040 | On public evidence alone, Neo looks like a company to monitor aggressively rather than a valuation to underwrite confidently. | 中 | SV001, SV028 |