Skip to content

Rein Raises $25M To Stop AI Agents Acting Out Of Line

Glilot Capital and Sienna VC led the round for a 31-person company that launched in January as an application security tool, in a category where Check Point has paid a reported $300M for a rival.

Rein Raises $25M To Stop AI Agents Acting Out Of Line
Image courtesy: Rein Security

Rein Security, a company that watches what software agents do while they are running, has raised $25M. It has offices in New York and in Tel Aviv, Israel. Glilot Capital and Sienna Venture Capital led the round, which takes the total raised to $35M, with Corner Ventures, Atlacle and RNP Capital Advisors also taking part.

Rein adds a single line of code to an application, spends about a day learning what normal behaviour looks like there, then blocks anything that departs from it. The software sits inside the application rather than in front of it. The company says customer data never passes through a gateway or proxy, meaning a middleman server that traffic is routed through.

Rather than killing the process or the request, it isolates the particular resource being misused, a step the company says costs under a millisecond of delay.

Matan Bar-Efrat and Netanel Rubin founded the company in 2024, and Rubin served as a security researcher in Israeli military intelligence after working, at 15, as a penetration tester paid to break into banks' systems. Rubin splits the market into the agents a company builds for itself and the agents that come at it from outside, and says most rivals only guard against the incoming ones.

Customers named in the announcement include Dun & Bradstreet, Lemonade, Flex and Swimlane. Jay DePaul, chief cybersecurity and technology risk officer at Dun & Bradstreet, said the platform "helps us see and control what our agents do at scale."

From Apps To Agents In Nine Months

Rein launched publicly on 28 January 2026 with $8M from Glilot Capital, selling application security. Its pitch then was protecting software from the inside while it runs, rather than scanning its code beforehand, and the company this round funds is not quite the one that launched.

The same code that learns an application's normal behaviour and blocks deviations now watches what an AI agent executes and which resources it reaches. Little has changed underneath, and extending it this way is reasonable rather than novel.

Application security is a mature market with established buyers and incumbent suppliers, while agent security is new, undefined and attracting capital. Moving between them inside nine months tracks where the money went rather than where the engineering did.

That is not a criticism of the product, and the company's claims about its agentic AI research describe a direction of travel for a business that has been selling into this specific problem only since January. The engineering predates the label.

The Threat Comes With Receipts

Rein's own research team said at the Black Hat USA security conference in 2026 that it had compromised the AI shopping agent of a top-five American retailer, which it did not name.

A second example comes from a customer deployment. At a global enterprise the company has not identified, instructions hidden inside a PDF attempted to push an onboarding agent outside its assigned role. Rein says its platform detected and blocked the attempt.

Rein is the source for each account, and no independent write-up has been published. The attack itself is documented elsewhere, since hidden instructions in a document or a web page, which a model reads as commands, have been demonstrated repeatedly against agents that browse and act on a user's behalf.

Software that can act on its own needs a boundary, and a system with no enforced limit on what it may reach brings every deployment to the same point. That is the practical form of the question about where an agent's authority ends.

The Category Is Consolidating Fast

Demand is not what threatens a small company here. Large security vendors have decided this capability belongs inside their platforms, and they have been buying it rather than building it.

Check Point agreed in September 2025 to buy the Swiss AI security firm Lakera, in a deal reported at about $300M. On 5 August 2025, SentinelOne announced an agreement to acquire Prompt Security, without disclosing a price.

Prompt Security's product overlaps with part of what Rein describes. It gives visibility into which AI tools staff are using and blocks risky prompts. It also runs a gateway between AI applications and the servers they call, a setup that follows from opening enterprise systems to AI tools through shared interfaces.

Rein's technical distinction is that it refuses the gateway, running inside the customer's own cloud environment rather than routing traffic through a proxy. That is its engineering argument, and also its answer to a procurement team that does not want another intermediary holding its data.

What The Growth Figures Leave Out

Rein says revenue has grown eightfold and its customer base fivefold since the product launched in January 2026. That is roughly nine months, from a base of zero.

Thousands of agents executing millions of actions is how Rein describes its scale. That gives no customer count, no revenue and no way to compare the platform with anything else in the market.

The first $8M round and this $25M come to $33M, against a stated total of $35M. About $2M was therefore raised outside the announced rounds.

Gartner expects AI security spending to reach nearly $4.8B in 2027, up 68.7% on 2026, and almost $7.7B by 2028. Those are an analyst's estimate of a category that barely existed in 2024.

What Would Settle The Question

The question for a 31-person company is whether it stays independent long enough to matter. Its 31 employees are set against Check Point and SentinelOne, which are folding acquired AI security products into platforms enterprises already buy.

What the round establishes is that specialist investors will fund software that sits inside the application, while the platform vendors assemble their own agent security by acquisition. What it leaves open is whether running inside the customer's environment proves a durable difference, or becomes the next feature a larger company buys.

Add Morning Tick on Google