Reco raises $55 million as it shifts from SaaS security to AI agent access controls
The AMW Read
The financing and agent-security repositioning incrementally update an enterprise cybersecurity player, with impact concentrated in access governance rather than a demonstrated broader market shift.
Reco raises $55 million as it shifts from SaaS security to AI agent access controls
Reco has raised $55 million in additional financing following its $30 million Series B in February, bringing total funding to $140 million. AT&T's investment arm, Forestay and Quadrille Capital participated. Previously focused on SaaS security, Reco now positions its platform around AI agent security, linking applications, employee accounts and permissions through a relationship graph. The company reports more than 100 customers and integrations with more than 280 applications. Funding will support hiring across sales, partnerships and customer support.
The shift places Reco within enterprise operations software, where security teams buy visibility and control over systems accessing business data. Agent adoption extends that problem beyond employee accounts: automated tools can retain permissions, reach sensitive records and operate without centralized oversight. Reco says it discovered 21,000 previously unknown agents at one Fortune 100 customer and an agent configured by a former employee at a financial-services customer. These are vendor-reported examples, but they illustrate why existing SaaS integrations could provide an entry point into agent governance. They do not establish that Reco has a durable advantage in a crowded market.
For enterprise buyers and investors, the concrete test is whether Reco's relationship graph can turn discovery into enforceable access restrictions. Its application integrations offer a distribution foothold, while the reported ability to inspect prompts and tool calls broadens its control surface. Evaluation should focus on coverage of embedded agents, removal of unnecessary permissions and measurable reductions in unauthorized access; customer counts alone do not demonstrate security effectiveness.