Announcments

Tenet Emerges from Stealth with $6M to Secure Enterprise AI Agents

2 min read

Today, Tenet Security is emerging from stealth with $6 million in seed funding led by The Westly Group, an early investor in SentinelOne, and MizMaa Ventures. We’re advised by former CISOs of Robinhood and BNY, among other security and enterprise technology leaders.

Why We Built This

Before Tenet, Barak and Nevo led Cisco’s AI Defense research team. Their job was breaking AI systems and building defenses. That work, and the offensive security research that came before it, including disclosing a zero-day in Anthropic’s Claude Desktop, work presented at Black Hat and DEF CON, and recognition with the Israel Defense Prize, gave them an early, unfiltered view of how autonomous agents fail in production.

What they kept finding was a consistent blind spot: every layer of the existing security stack was built for a different threat model. EDR watches processes. IAM watches users. Guardrails watch prompts and outputs. None of them see what an agent actually does at runtime, the tool calls, the data it touches, the decisions it makes autonomously. That blind spot is where the attacks happen.

What We Built

Tenet is the Security Platform for the Agentic Layer. The platform is built around a sensor that sees all three layers simultaneously: OS, network and API, and LLM reasoning, without gateways, proxies, or SDKs. No code changes. Deploys in minutes. Developers never notice Tenet is there.

The platform’s core capability is Agent-Side Simulation (patent pending). When Tenet flags a suspicious action, it simulates the outcome of the agent’s next moves before they execute against real infrastructure, three steps ahead, every time. If the path leads somewhere dangerous, Tenet prevents it before it executes and produces a full trace that explains every block. No static rules for attackers to learn and work around. No false positives.

This matters because the alternative defenses don’t hold. A recent study testing guardrail-based defenses for coding agents found an over 80% bypass rate. Guardrails are suggestions. Tenet is enforcement.

A New Attack Class

Tenet Threat Labs documented a new class of attack called Agentjacking, where malicious instructions embedded in emails, documents, logs, or databases manipulate agents into executing attacker-controlled actions, operating entirely within their authorized permissions. We validated this across more than 100 enterprise environments and identified thousands of organizations with exposed attack paths that traditional controls never flagged.

In the Field

One $1B ARR enterprise scaled from two AI agent deployments to more than twenty over six months while Tenet blocked more than ten real attacks, including a critical XSS attempt. In a separate Fortune 1000 deployment, a runaway agent burned tens of thousands of dollars in token costs over a single weekend before it could scale further, caught during a proof of value before it became a much larger problem.

“AI agents may be the biggest productivity unlock enterprises have seen in decades, which is why organizations are moving so quickly to deploy them. But we’re also entering a world where autonomous agents are interacting with systems, data, and other agents in ways most security tools were never designed to understand. That creates an entirely new security layer that requires a fundamentally different approach to protection.”

— Barak Sternberg, co-founder and CEO, Tenet Security

“Attackers can manipulate agents to access sensitive data, abuse privileges, or take actions on their behalf in ways traditional security tools were never designed to detect. The challenge isn’t simply monitoring prompts or API traffic, it’s understanding and controlling agent behavior in real time. The only place left to catch these threats is at runtime, in the moment an agent decides to act.”

— Nevo Poran, co-founder and CTO, Tenet Security

Barak Sternberg
Co-Founder & CEO
Nevo Poran
Co-Founder & CTO
Table of Contents

More Articles

No data was found