Zenity Raises $125 Million to Secure the Era of 1 Billion AI Agents

AI Agent Sprawl Is the Problem Runtime Security Has to Solve

M
Molly Bauer
Cover Image
Ask AI to

Key Takeaways

  • Zenity is recognized in Latio's 2026 AI Security report as an AI Security Platform Leader and named a vendor with broad alignment to Software Analyst Cyber Research's (SACR) ARISE framework for agentic runtime identity security.
  • Latio highlights Zenity's platform breadth, one of the largest sets of integrations and use cases the firm evaluated, spanning SaaS agents, hyperscaler platforms, and homegrown environments.
  • SACR names Zenity among vendors that combine MCP and tool governance, runtime behavior analysis, agent identity and delegation context, and audit evidence, the core requirements of its ARISE framework.
  • Both reports point to the same shift: security has to hold up while an agent is acting, not just before it starts or after it's done.

Enterprises aren't standardizing on one AI agent platform. Security teams are watching Copilot run alongside ChatGPT Enterprise, homegrown agents built on internal frameworks, and endpoint coding agents like Claude and Codex, often all inside the same organization. Each platform brings its own credentials, tool access, and blind spots, and none of them wait for a security review before taking an action. Legacy identity and access controls were built to authorize a login, not to evaluate the dozens of tool calls, credential reuses, and data pulls an agent can make in the seconds after a prompt lands. That gap, the space between whether an agent is authorized and whether it should be doing this right now, is exactly where runtime enforcement has to operate.

Two new analyst reports were just published examining exactly that gap, and Zenity was recognized in both. Latio's 2026 AI Security Report names Zenity an AI Security Platform Leader, evaluating Zenity for the breadth of our platform coverage across SaaS, hyperscaler, and homegrown agents.

Software Analyst Cyber Research (SACR) names Zenity a vendor with broad alignment to its new ARISE framework, short for Agentic Runtime Identity Security Enforcement, which defines the runtime checkpoint layer enterprises need as agents start acting with real credentials and delegated authority. SACR calls out Zenity’s unique position in the market, covering the full runtime-enforcement stack the report defines, rather than being a point solution addressing just one piece of it.

Platform Breadth Is Becoming a Security Requirement, Not a Feature

Latio's report calls out something specific: the number of integrations and use cases Zenity supports is among the largest the firm evaluated, spanning SaaS agents like Copilot and ChatGPT Enterprise to endpoint agents like Claude and Codex. For organizations whose agent sprawl already crosses SaaS, cloud, and endpoint boundaries, breadth like that matters more than any single feature.

The payoff is unified policy, not another silo. Instead of settling for one blunt global rule, security teams can govern agent-tool interactions per service, with a single view of behavior whether an agent lives in a SaaS platform, an automation suite, or cloud infrastructure through Zenity's agentic identity and delegation controls. Latio frames the hardest problem in agent security as a multi-provider one, and names Zenity as a solution built for that reality.

Runtime Enforcement Is What ARISE Is Built to Measure

SACR's ARISE framework asks a more pointed question of every vendor it evaluates: should this agent be allowed to take this action, with this tool, credential, data, and delegated authority, for this purpose, right now? That question only matters if a platform can answer it while the agent is mid-action, not after the fact.

SACR identifies Zenity among vendors that combine multiple agent security capabilities under that model: runtime behavior analysis, MCP and tool governance, agent identity and delegation context, and audit evidence. That's the difference between reviewing an agent's intent and controlling its action. The framework evaluates agent actions, tool calls, data access, credential use, and workflow steps before they complete, which is why runtime context is the harder problem to solve than build-time review alone. Intent is not control, and detection after exfiltration is not security.

The Throughline: Enterprises Need One Layer Across an Expanding Ecosystem

“Enterprises aren’t standardizing on a single AI platform, making visibility and control across the entire agent ecosystem essential,” said Ben Kliger, co-founder and CEO of Zenity. “As organizations deploy agents across SaaS applications, cloud platforms, and custom environments, security teams need a consistent way to discover, govern, and protect them.”

Read together, the two reports describe the same enterprise reality from different angles: agents are already running everywhere, across more providers than any one platform was designed to unify, and the controls that matter are the ones enforced while those agents are acting.

Latio's full AI Security report breaks down how Zenity and other vendors stack up across integrations, policy enforcement, and runtime incident response. Download the Latio AI Security report to see the complete evaluation.

All Articles

Secure Your Agents

We’d love to chat with you about how your team can secure and govern AI Agents everywhere.

Get a Demo