Zenity Raises $125 Million to Secure the Era of 1 Billion AI Agents

From Triage to Full Coverage: The Shift AI Agent Security Took in August

Portrait of Tomer Teller
Tomer Teller
Cover Image
Ask AI to

Key Takeaways

  • Guardian Agents launched their first member, Blue Agent, now triaging AI security findings in early access with the reasoning behind every verdict shown, not hidden.
  • Boundaries got easier to author, with an AI assistant that tests draft rules against production history and a new command-line interface (CLI) that lets coding agents manage policy as version-controlled code.
  • Boundaries also got more precise, with granular system taints and Prevent/Detect labels that replace brittle pattern matching with rules tied to what an action actually does.
  • Platform coverage widened to GitHub Copilot, OpenAI Codex, and the new Microsoft Foundry, and any agent emitting OpenTelemetry (OTel) or gen_ai spans can now connect to Zenity without a dedicated integration.

Security teams evaluating an AI agent security platform tend to ask the same question after the first demo: will this keep up? Agentic AI changes shape every few weeks, with new frameworks, new coding agents, and new ways for an agent to reach a tool or a credential. A platform that covers today's stack and stalls on next quarter's isn't much of a bet.

Zenity shipped its first Guardian Agent, extended Boundaries into new authoring and enforcement modes, and widened platform coverage across coding agents, Microsoft's new Foundry, and any agent that emits standard telemetry. Here's what changed and what it means for a team evaluating the platform.

Guardian Agents Take Their First Shift

Most security tools hand a team more alerts, not more capacity. Guardian Agents take the opposite approach: they're AI agents built to do the security work a stretched team doesn't have time for.

Blue Agent, the first Guardian Agent, is now live. It triages every new finding exactly the way your organization triages: reading the finding, gathering context, and checking guidelines that are generated at onboarding and automatically suggested for redefinition whenever the agent detects a need to update the guidelines. It suggests a verdict (benign true positive, false positive, or true positive) with its reasoning, confidence level, and full trace attached, and starts in suggest mode, so nothing gets applied without a human's approval.

For a security team drowning in triage or skeptical of AI-generated alerts, Blue Agent turns "what's your AI story?" into a working queue, not a slide.

Boundaries Get Easier to Write and Harder to Get Wrong

Writing and maintaining runtime boundaries is where security teams often lose momentum, stuck between spreadsheets and Slack threads. August closed that gap from two directions: authoring got faster, and enforcement got more precise.

An assistant that tests its own work

The Boundaries AI assistant can now create a required custom taint while drafting a rule, with approval before it applies, and run the rule against recent production activity on command. A team can move from "block this pattern" to a validated boundary, complete with the actions it would have caught, without leaving the authoring flow.

Policy as code

The new Boundaries command-line interface (CLI) lets teams manage boundaries, custom taints, and reusable values as version-controlled files, with coding agents like Claude Code and Codex authoring policy against Zenity's schema. Changes get validated, tested, and reviewed before a single push deploys the approved state, giving security teams the Git-native audit trail their AppSec workflows already expect.

Rules tied to what an action does, not what it's called

New system taints classify tool calls as read or mutative operations (write, update, delete, execute), so a boundary can allow benign writes while blocking irreversible deletes without matching on command strings or tool names that change every release. Every taint in the manager now also carries a Prevent or Detect label, so a team knows at a glance whether a rule blocks in real time or only flags after the fact. No more rules that quietly fail to prevent.

Coverage Widens Across the Agent Ecosystem

GitHub Copilot and OpenAI Codex reached general availability, with inventory, activity monitoring, and inline prevention served through hooks. The new Microsoft Foundry, the rebuilt agent stack that replaced Azure AI Foundry at Ignite 2025, is now fully covered too: every Foundry agent and everything it can reach lands in inventory and the graph, with runtime activity and AI detection and response (AIDR) findings alongside it, ahead of Foundry classic's retirement in March 2027. And for enterprises running Microsoft Agent 365, Zenity's runtime risk signal now surfaces directly inside it, next to Entra, Purview, and Defender.

Any Agent, Any Telemetry, One Policy Layer

If a customer's agentic application emits OTel or gen_ai spans, it can now connect to Zenity without a dedicated connector, through a new Custom Agents integration that supports both visibility (OTel) and inline enforcement (the Evaluate API). New step-by-step guides make that even more concrete for Cribl, LiteLLM, and Kong, letting a team see its own agent activity in the Zenity portal before committing to full onboarding. Rounding out the month, audit log events can now be streamed to Splunk or Microsoft Sentinel in near real time, so Zenity's activity sits in the same security information and event management (SIEM) tool a security operations center (SOC) already lives in.

See Our Latest Product Releases in Action

A platform that ships a new Guardian Agent, a policy-as-code CLI, and coverage for three more agent ecosystems in a single month is one built to keep pace with agentic AI, not catch up to it. Book a demo to see Guardian Agents, the Boundaries CLI, and the platform's latest coverage in action.

All Articles

Secure Your Agents

We’d love to chat with you about how your team can secure and govern AI Agents everywhere.

Get a Demo