Software Changed. Security Didn't. So We Built Neo
Today, Neo comes out of stealth. Here is what we saw, why we started the company, and where we believe security is heading.
Nick, Shlomi & Eran
Nick Warner, Shlomi Salem & Eran Shirazi
Today, Neo comes out of stealth with $100M in funding from Bessemer Venture Partners and Andreessen Horowitz, with participation from Craft Ventures and Merlin Ventures. This is the first post on our blog, so we want to use it to explain what we saw, why we started this company, and where we believe security is heading.
Software is not installed anymore. It is extended.
Between the three of us, we have spent decades protecting organizations, building detection engines, and studying how attackers actually behave. So when we started Neo, we did not begin with a product idea. We began with a question: what does software actually look like now, and does anything defend it?
The answer surprised us, even though in hindsight it should not have. Software is barely being installed anymore. It is being extended.
In most enterprises today, you will not see a new application show up on a machine. You will see a plugin loaded into VS Code. You will see Claude installed, and then the real questions begin. What MCP servers are configured? What skills are loaded? What can they reach?
Someone extends Excel with an AI assistant, and suddenly Excel is agentic, possibly running on a personal account, possibly sending sensitive data somewhere nobody approved. The applications people depend on every day—browsers, IDEs, office suites, AI assistants—have quietly become platforms that host other software. A skill is software. An MCP server is software. A browser extension is software. That extensible layer is where the capability, and the risk, actually lives now.
This is the shift that broke the old model. Traditional endpoint security sits between the operating system and the application, and for twenty years that was the right place to sit. It is not enough anymore, because the most consequential things happening on a machine happen one layer up, inside the application, where an AI agent inherits a user's session, reaches production data, and acts on its own. EDR, SASE, and identity tools see nothing unusual, because every one of those actions uses legitimate credentials through sanctioned channels. The tools are not broken. They are looking at the wrong layer.
The moment we knew
Early in our research phase, we set out to define what a real posture issue looks like in one of the leading agentic platforms, since misconfigurations were already showing up in almost every account we talked to. So we did what security researchers did in 2025. We studied the app's configuration files by hand, mapped their structure, and defined exactly what our product needed to collect.
A few days later, the entire structure of those files changed, and all of that work had to be redone.
That was the final nail in the coffin for the manual approach. If software now changes weekly, sometimes daily, then no human-curated catalog and no static ruleset can keep up. We understood that the only solution for software moving this fast is a solution that is itself agentic.
What we built
That realization became Neoverse, the hive mind behind Neo. Neoverse powers our understanding of the agentic software universe, continuously mapping more than 1.2 million pieces of software across their capabilities, risks, and behaviors. When our system encounters something it has not seen before, whether a hosting application, an extension, an MCP server, or a skill, it researches it the way our own team would. What can it do? How is it extended? How is it configured? What is worth collecting next? Then it feeds that knowledge back into the product and does it again. Our knowledge of software is dynamic and huge in scale, because that is the only way to actually know something about software these days.
On top of that map, Neo answers three questions for our customers, in order.
First, should this software be here at all? We discover everything—native apps, extensions, plugins, MCP servers, skills, web apps—and help you decide what belongs in your environment.
Second, is it well configured? Approved software with a dangerous posture is still a risk. Agents that can act without a human in the loop, MCP connections authenticated with an API token sitting in plaintext on disk instead of OAuth, extensions with permissions nobody reviewed. Most of these issues are invisible today. We surface them and help fix them.
Third, what should it be allowed to do at runtime? This is where posture becomes protection. You might be fine with a browser agent doing browser work and still want a guarantee that it can never touch an internal asset. A coding agent session that ingested untrusted content from the internet should not be able to turn around and reach sensitive resources. Neo enforces these guardrails natively, from the endpoint, at the harness level, with a sensor light enough that you forget it is there.
What should run, how it should be configured, and what it should be allowed to do. Presence, posture, and runtime. That model holds whether the software in question is a Chrome extension, a Claude skill, or an agent nobody has invented yet.
Why us, and why now
We did not start Neo because AI security is a hot market. We started it because we have spent our careers in security, and we could see that software had fundamentally changed while the security stack had not. Between us, that includes building SentinelOne's detection engine, scaling it through the largest cybersecurity IPO in history, and founding and building EasySend. We have built security products at scale before, we have taken them to market before, and we know exactly where the old model ends.
The timing is not something we chose. Agentic software is being adopted faster than any enterprise technology we have witnessed, and security teams are being asked questions they cannot answer. Honestly, most teams we meet do not even know what questions to ask yet. That is not a criticism. It is the natural state of a market where the ground moves under everyone's feet. Our job is to give them the questions, the answers, and then the controls.
Where we are going
Our mission is to let organizations adopt agentic software with confidence instead of fear. Not to slow AI down, but to make it governable, so every company can say yes to the tools their people want, knowing exactly what those tools can do, how they are configured, and what they are permitted to touch.
Inventory and posture are the start. Next comes full runtime visibility into every agentic session: what harness ran it, how it was configured, what tools it called, and what it actually changed in the real world. From there, session-level policy that answers real risks like prompt injection by understanding behavior, not just blocking or allowing.
We believe this is the beginning of a new category, protection for the agentic endpoint. The endpoint has always been where work happens. Now it is where agents work too, and it deserves security built for that reality.
We are grateful to our investors, to the design partners who have shaped this product from the earliest days, and to the Neo team building it. If you are living this problem, we would love to build it with you.
Nick, Shlomi & Eran
Get started
Put NEO to Work on Your Hardest Problem
Bring a use case. We will show you a working loop on your data in the first session.