AI security startup Reco announced Tuesday it has raised $55 million in new funding, capitalizing on surging demand from companies struggling to track and secure thousands of AI agents spreading across their networks. The funding round, which follows a $30 million Series B in February, was backed by AT&T's venture arm, Forestay, and Quadrille Capital. According to the company, which now serves more than 100 customers, the investment comes as enterprises race to deploy AI agents faster than they can monitor them, creating what industry observers call "AI sprawl."

Reco's platform has uncovered startling numbers of hidden agents at customer sites. At one Fortune 100 client, the software identified 21,000 agents the company didn't know existed. At a large financial services firm, Reco discovered an agent created by a former employee that could still access Salesforce and transmit that information to an external domain the organization couldn't monitor. The startup says its valuation has more than doubled since February, now reaching the "high hundreds of millions" of dollars, while annual recurring revenue sits in the "double-digit millions of dollars" and is expected to triple this year. Financial services firms make up roughly 40% of Reco's customer base.

Reco's co-founder and CEO, Ofer Klein, told TechCrunch that the biggest shift over the past year has been companies building and deploying agents at a pace that outstrips their ability to track them. "The market demand right now for agent security is not only about the agent itself; it's about the entire ecosystem end-to-end," Klein said. The startup, which originally focused on mapping and securing SaaS and AI platforms, has repositioned around a broader solution that uses a context graph connecting agents to applications, users, accounts, and permissions. The approach is designed to help security teams see what an agent can reach and revoke unnecessary access. Klein added that the platform relies on browser and network signals to find agents beyond the apps it directly integrates with, and it includes controls to inspect prompts and tool calls.

The funding surge reflects broader investor appetite for companies addressing what security leaders see as an urgent problem. A quick scan of public databases turns up at least two dozen vendors selling some version of AI agent security, according to the report, with offerings ranging from vetting the tools agents use to controlling data access, detecting unauthorized AI usage, and building device-level response controls. Many of these products promise similar capabilities involving knowledge graphs, continuous monitoring, runtime security, and tool access governance. Reco's edge, Klein argues, lies in its existing coverage of SaaS apps and the AI agents those platforms increasingly offer—the startup currently integrates with more than 280 applications and can add new integrations within days. The new capital will go toward hiring, sales, partnerships, and customer support, bringing Reco's total raised to $140 million. Companies betting on Reco's approach are wagering that centralized visibility into agent behavior will prove essential as enterprises contend with sprawling, often invisible, AI deployments that touch sensitive data and critical systems. The market's crowded state suggests this race will be won not just by discovery capabilities, but by the speed and breadth with which platforms can adapt to the agents companies build next.