This week's issue is backed by Token Security and Minimal.
Hope you had a great weekend!
Not sure about you, but I’m still digging out of the hole from Black Hat and traveling around so much. I’m hoping to get back to normal by 2030 at this rate. ¯\_(ツ)_/¯
You’re probably running behind just like me, so let’s get to it.
PARTNER
Finding risky AI agents is easy. Fixing them is the hard part.
Identity-first AI agent security, built for remediation at scale.
Your team ships AI agents in days, but your remediation queue moves in quarters. Token Security closes the gap. Token maps every agent, identity, secret, and permission into a single identity graph, so you can see the blast radius before you act, right-size access without breaking production, and trigger automated remediation at real risk thresholds. Detection was never the bottleneck.
Table of Contents
😎 Vibe Check
Click the options below to vote on whether you are a practitioner, founder, or investor. Leave a comment, and I'll anonymously feature the best takes in the next issue!
Is the "give every defender an agent" thesis the real security unlock, or is it the wrong bottleneck?
Last issue’s vibe check:
Where's the actual blind spot when an AI agent goes rogue?
🟨🟨🟨⬜️⬜️⬜️ Sandboxing monitoring
🟩🟩🟩🟩🟩🟩 Agent action/chain of thought logging
🟨🟨⬜️⬜️⬜️⬜️ Network egress monitoring
🟨⬜️⬜️⬜️⬜️⬜️ Behavioral baselining (UEBA)
⬜️⬜️⬜️⬜️⬜️⬜️ Other (tell me)
An interesting mix of results from last week’s vibe check. While most people voted for agent action and chain-of-thought logging, there were still strong votes for network egress and sandboxing monitoring. Those last two seem to fit into the “should an agent even be doing that?” category.
As more AI models follow the same kinds of escape and damage paths, the industry will have to learn to deal with this new normal. Perhaps that will take the form of things we haven’t really seen before, but my suspicion is that we need to operate under the assumption that it will happen, so we need as much prevention and observability as possible. Assume everything will be bypassed unless explicitly prevented (and even then, it still might not be enough if they find 0-days).
Some of the top comments from last week’s vibe check:
💬 "Agent actions or chain-of-thought will be too reactive and after the fact, and they could just learn to evade this kind of monitoring with ease.”
💬 “I think all are needed (and broadly all starting to happen more! Yay!) - but I think this is more of a prevention need than a detection one at the minute. The prominent reports recently are almost all about agents breaking out of supposedly locked-down environments, often because the environments weren’t properly locked down. That’s cyber 101. Or finding 0days in the component used to lock it down. A cascading series of locked-down containers + limiting deterministic proxies feels more essential than monitoring right now.”
💰 Market Summary
Private Markets
8 companies from 3 countries raised $38.2M across 7 unique categories
Average disclosed deal size was $6.4M (median: $4.6M)
88% of funded companies were product companies
8 companies from 2 countries were acquired for $795.5M across 5 unique categories
62% of acquired companies were service companies
Public Markets
No public cyber companies raised funding
No public cyber companies had an earnings report

📸 YoY Snapshot
Rolling 13-week charts that compare funding and acquisitions week over week, year over year, comparing 2025 to 2026

$8.8B across 148 deals over the past rolling quarter, down 21% from the same timeframe a year ago.

80 acquisitions over the past rolling quarter, down 23% from the same timeframe a year ago.
PARTNER
--dangerously-skip-permissions is a lifestyle now
Agent isolation, without the headaches.
Every agent running on a dev laptop inherits everything: SSH keys, cloud creds, dotfiles, prod access. YOLO mode is the default now, and nobody's pretending otherwise. Minimal lets you run agents in isolated, reproducible environments. The same environment for humans, agents, and CI. Give your agent a computer, just not yours.
🧩 Funding By Product Category

$20.0M for Continuous Threat Exposure Management (CTEM) across 1 deal
$13.3M for AI Governance across 2 deals
$3.4M for Managed Security Services Provider (MSSP) across 1 deal
$1.4M for Security and Compliance Automation across 1 deal
$50.0K for Professional Services across 1 deal
An undisclosed amount for Operational Technology (OT) Security across 1 deal
An undisclosed amount for Security Analytics across 1 deal
🏢 Funding By Company
» Interact with all the data in real-time on The Signal dashboard or via the MCP.
Product Companies:
Prevalent AI, a United Kingdom-based threat exposure management platform, raised $20.0M in private equity from Integrity Growth Partners. (more)
Xpander.ai, a United States-based agentic AI governance and orchestration platform, raised a $7.5M Seed from PICO Venture Partners. (more)
Velatir, a Denmark-based agentic AI governance platform, raised a $5.8M Seed from Spintop Ventures and Ugly Duckling Ventures. (more)
Loom Security, a United States-based managed security services provider (MSSP) focused on cloud security, raised a $3.4M seed round. (SEC Filing - may be incomplete)
Strike Graph, a United States-based security and compliance automation platform, raised a $1.4M Venture Round. (SEC Filing - may be incomplete)
Tophat Security, a United States-based operational technology security platform, raised an undisclosed Series A from Landolt Securities. (more)
WitFoo, a United States-based security analytics and incident response platform, raised an undisclosed seed round. (SEC Filing - may be incomplete)
Service Companies:
ProSentra, a United States-based professional services firm focused on cyber risk management, raised a $50.0K Seed. (SEC Filing - may be incomplete)
SEC filings may reflect partial or interim fundraising and can understate the final round numbers.
🌎 Funding By Country

$20.0M for the United Kingdom across 1 deal
$12.4M for the United States across 6 deals
$5.8M for Denmark across 1 deal
🤝 Mergers & Acquisitions
Product Companies:
Radiant Security, a United States-based AI-agent-enabled security operations center support platform, was acquired by Cribl for an undisclosed amount. Radiant Security had previously raised $15.0M in funding. (more)
Service Companies:
MicroAge, a United States-based managed security services provider, was acquired by ScanSource for $220.5M. MicroAge has not previously disclosed funding. (more)
Ark ICT Solutions, a United Kingdom-based managed security services provider, was acquired by Redsquid for an undisclosed amount. Ark ICT Solutions has not previously disclosed funding. (more)
ARO Technology, a United Kingdom-based managed security services provider, merged with TalkTalk Business for an undisclosed amount. ARO Technology has not previously disclosed funding. (more)
Loyal IT, a United States-based managed security services provider, was acquired by Nexus IT Consultants for an undisclosed amount. Loyal IT has not previously disclosed funding. (more)
🤘 IPO-h Yeah
None
🪦 Stop, Drop, Shut’em Down…
None 😮💨
❌ Layoffs
None 😮💨
📚 Great Reads
Where are all the prompt injection damages? - Joshua Saxe shares an interesting breakdown of the disconnect between how the industry has focused so much on protecting AI models from prompt injection, while attacker data shows it has barely been used.
Separating AI’s Technological Problems from Its Capitalism Problems - Integrating a technology as disruptive as AI responsibly requires structural reforms, and we should decouple the social and technological aspects of AI to design those reforms.
*Sponsored
🧪 Labs
Stay frosty out there, folks 🫡
🫡 Signing Off
Have questions, comments, or feedback? Just reply back directly, I’d love to hear from you.
If you find this newsletter useful and know others who would, I'd really appreciate it if you'd forward it to them!
Mike P
P.S. Feel free to connect with me on LinkedIn.


