A

AIR Security

by AIR

Governance & SecurityAI Agents & OrchestrationEnterprise Platform

A context firewall that vets every skill, plugin and MCP server an AI agent touches

Contact for pricing·Added Sep 2, 2026·Updated Sep 2, 2026
Share:
THE DAILY BRIEF
AIR Security

by AIR

Governance & SecurityAI Agents & OrchestrationEnterprise Platform

A context firewall that vets every skill, plugin and MCP server an AI agent touches

Contact for pricing

AIR Security is an enterprise platform that treats the plugin ecosystem around AI agents as a software supply chain. It discovers every agent running inside a company, continuously vets the skills, plugins, MCP servers and sub-agents those agents install, and blocks untrusted tools or injected instructions at runtime. It is built for CISOs whose employees are already installing agent add-ons faster than security can review them.

At a Glance

Category
Governance & Security
Pricing
Contact for pricing
Target Market
CISOs, CIOs, Security Engineers, AI Platform Teams, Enterprise Risk & Compliance
Deployment
Cloud-first
Founded
2026
Headquarters
New York, United States
Team Size
11-50
Customers
20+ (about 25% large enterprises)

Key Features

  • AIR Control
  • AIR Filter
  • AIR Defend
  • AIR Marketplace
  • Continuous add-on re-verification
  • Threat research on the public add-on ecosystem

Use Cases

  • Shadow agent discovery
  • MCP server supply-chain review
  • Runtime prompt-injection defence
  • Regulated-industry agent governance
  • Impersonation and typosquat blocking

Ideal For

Best For

  • Discovering shadow AI agents employees have stood up across endpoints, cloud accounts and SaaS apps
  • Vetting third-party MCP servers and agent skills before they are installed in a production environment
  • Blocking prompt injection and external instruction loading at agent runtime in financial services workflows
  • Giving a pharmaceutical or banking risk function an auditable allowlist of approved agent add-ons
  • Detecting typosquatted or impersonating agent skills that claim to be official Anthropic or OpenAI components

Not Ideal For

  • Teams that have not deployed agents yet — the platform governs an existing agent estate rather than helping you build one
  • Small businesses using one or two hosted assistants with no third-party plugins, where the add-on supply chain barely exists
  • Buyers who need a published price and a self-serve trial today; AIR sells enterprise-only through demos with no public pricing
  • Organisations that need a long production track record and reference customers at scale — the company is six months old with roughly 20 customers

Market Analysis

Enterprise-gradeSecurity-firstEarly-stage challenger

Pros

  • Addresses a genuinely new and under-covered attack surface: the third-party skill and MCP-server supply chain rather than the model itself
  • Backed by top-tier investors at unusual speed — $50M inside six months from Sequoia and Greenoaks — plus operator angels from Wiz, Eon, Clay and Cognition
  • Credible security leadership: two Unit 8200 offensive-security veterans as founders and a chief strategy officer who was CISO at both Disney and Costco
  • Published research is concrete rather than marketing — 17,800 add-ons analysed, a stated 27 percent reject rate, and named impersonation findings against Anthropic and OpenAI skills

Cons

  • Six months old with roughly 40 staff and 20-plus customers, so there is no long production track record and reference calls will be scarce
  • No published pricing, no free tier and no self-serve trial — evaluation requires a sales cycle before you can judge fit
  • No independent user reviews exist yet on G2, Capterra, TrustRadius or Peer Insights, and there is no Hacker News or Reddit practitioner thread to sanity-check the claims
  • The allowlist-plus-marketplace model makes coverage dependent on AIR's vetting cadence: a new or niche internal add-on is blocked until AIR gets to it, which can stall developer work
  • No public SOC 2, ISO 27001 or data-residency attestations were disclosed at launch, which is an awkward gap for a product sold to regulated banks and pharma
  • The category is crowded and better-funded in places — Zenity alone raised a $125M Series C — so durable differentiation is unproven

Pricing

Enterprise

Contact for pricing

  • AIR Control agent discovery and policy
  • AIR Filter pre-deployment vetting
  • AIR Defend runtime enforcement
  • AIR Marketplace of vetted add-ons

No list pricing is published anywhere on the site or in launch coverage: the only route is a booked demo, and every plan detail is gated behind sales. The company sells enterprise-first, with about 25 percent of its 20-plus customers being large enterprises, so expect a committed annual contract rather than self-serve. The one thing you can use without talking to anyone is the free add-on scanner at scan.air.security, which is a research tool rather than the product.

Security & Compliance

soc2
gdpr
hipaa
iso27001
sso
data residency

THE DAILY BRIEF

Enterprise AI insights for technology and business leaders, twice weekly.

beri.net

Subscribe at beri.net/subscribe for twice-weekly AI insights delivered to your inbox.

LinkedIn: linkedin.com/in/rberi  |  X: x.com/rajeshberi

© 2026 Rajesh Beri. All rights reserved.

AIR Security is an enterprise platform that treats the plugin ecosystem around AI agents as a software supply chain. It discovers every agent running inside a company, continuously vets the skills, plugins, MCP servers and sub-agents those agents install, and blocks untrusted tools or injected instructions at runtime. It is built for CISOs whose employees are already installing agent add-ons faster than security can review them.

AIR Security is an enterprise security platform that treats the plugin ecosystem around AI agents as a software supply chain and polices it end to end. It was founded in February 2026 by Unit 8200 veterans Yair Saban (CEO) and Niv Hoffman (CTO), and emerged from stealth on 1 September 2026 with $50 million raised across two rounds inside its first six months: a $10 million round led by Sequoia Capital, followed by a $40 million round led by Greenoaks Capital Partners, with Swish Ventures and Netz Capital also participating. The product ships as four modules. AIR Control discovers and inventories the agent fleet across endpoints, cloud accounts and SaaS applications, including shadow agents employees stood up themselves, and enforces policy on their configuration, identity and permissions. AIR Filter is a pre-deployment gate that vets skills, plugins, MCP servers and sub-agents before installation. AIR Defend applies runtime enforcement, detecting and blocking untrusted tools, external instruction loading and data exfiltration as agents execute. AIR Marketplace distributes pre-vetted external add-ons alongside certified internal ones as a trusted install source. The company says it has analysed more than 17,800 public AI add-ons representing 6.7 million installations and filters out roughly 27 percent as problematic, including skills impersonating Anthropic and OpenAI capabilities that were able to execute arbitrary code. AIR integrates with OpenAI, Anthropic Claude, Microsoft Copilot and Google Gemini agents as well as Salesforce, ServiceNow and Slack. It is headquartered in New York with roughly 40 staff in Israel, reports more than 20 customers of which about a quarter are large enterprises, and sees strongest demand in financial services and pharmaceuticals.

Ideal Buyer

The CISO or head of AI security at a regulated enterprise where business teams are already installing agent skills, plugins and MCP servers faster than security review can keep up.

Key Benefit

A single inventory of every agent and every add-on it depends on, with the untrusted ones blocked before installation and again at runtime.

At a Glance

Category
Governance & Security
Pricing
Contact for pricing
Target Market
CISOs, CIOs, Security Engineers, AI Platform Teams, Enterprise Risk & Compliance
Deployment
Cloud-first
Founded
2026
Headquarters
New York, United States
Team Size
11-50
Customers
20+ (about 25% large enterprises)

Key Features

  • AIR Control

    Discovers sanctioned and shadow agents across endpoints, cloud and SaaS, then enforces policy on their configuration, identity and permissions.

  • AIR Filter

    Pre-deployment firewall that vets skills, plugins, MCP servers and sub-agents before they are ever installed.

  • AIR Defend

    Runtime protection that detects and blocks harmful agent actions, injected instructions and unauthorised data exfiltration in flight.

  • AIR Marketplace

    A trusted install source of pre-vetted external add-ons plus certified internal ones, so teams have a sanctioned path.

  • Continuous add-on re-verification

    Components are re-checked after approval, so a maintainer pushing a malicious update does not silently retain trust.

  • Threat research on the public add-on ecosystem

    Over 17,800 public add-ons analysed, with roughly 27 percent filtered out as unsafe by the vetting pipeline.

Use Cases

  • Shadow agent discovery

    Security finds agents that business teams deployed without review, and maps what data and tools each one can reach.

  • MCP server supply-chain review

    Before an engineering team wires in a third-party MCP server, AIR checks it for hidden behaviour and excessive permissions.

  • Runtime prompt-injection defence

    An agent reading an untrusted document is prevented from acting on instructions embedded in that document at execution time.

  • Regulated-industry agent governance

    A bank or pharma company evidences to auditors which agent add-ons are approved, who approved them and what each can access.

  • Impersonation and typosquat blocking

    Skills falsely presenting themselves as official Anthropic or OpenAI components are identified and blocked before installation.

Ideal For

Best For

  • Discovering shadow AI agents employees have stood up across endpoints, cloud accounts and SaaS apps
  • Vetting third-party MCP servers and agent skills before they are installed in a production environment
  • Blocking prompt injection and external instruction loading at agent runtime in financial services workflows
  • Giving a pharmaceutical or banking risk function an auditable allowlist of approved agent add-ons
  • Detecting typosquatted or impersonating agent skills that claim to be official Anthropic or OpenAI components

Not Ideal For

  • Teams that have not deployed agents yet — the platform governs an existing agent estate rather than helping you build one
  • Small businesses using one or two hosted assistants with no third-party plugins, where the add-on supply chain barely exists
  • Buyers who need a published price and a self-serve trial today; AIR sells enterprise-only through demos with no public pricing
  • Organisations that need a long production track record and reference customers at scale — the company is six months old with roughly 20 customers

Deployment

On-Premise

Market & Ratings

Estimated Customers

20+ (about 25% large enterprises)

Market Analysis

Enterprise-gradeSecurity-firstEarly-stage challenger

Pros

  • Addresses a genuinely new and under-covered attack surface: the third-party skill and MCP-server supply chain rather than the model itself
  • Backed by top-tier investors at unusual speed — $50M inside six months from Sequoia and Greenoaks — plus operator angels from Wiz, Eon, Clay and Cognition
  • Credible security leadership: two Unit 8200 offensive-security veterans as founders and a chief strategy officer who was CISO at both Disney and Costco
  • Published research is concrete rather than marketing — 17,800 add-ons analysed, a stated 27 percent reject rate, and named impersonation findings against Anthropic and OpenAI skills

Cons

  • Six months old with roughly 40 staff and 20-plus customers, so there is no long production track record and reference calls will be scarce
  • No published pricing, no free tier and no self-serve trial — evaluation requires a sales cycle before you can judge fit
  • No independent user reviews exist yet on G2, Capterra, TrustRadius or Peer Insights, and there is no Hacker News or Reddit practitioner thread to sanity-check the claims
  • The allowlist-plus-marketplace model makes coverage dependent on AIR's vetting cadence: a new or niche internal add-on is blocked until AIR gets to it, which can stall developer work
  • No public SOC 2, ISO 27001 or data-residency attestations were disclosed at launch, which is an awkward gap for a product sold to regulated banks and pharma
  • The category is crowded and better-funded in places — Zenity alone raised a $125M Series C — so durable differentiation is unproven

Pricing

Enterprise

Contact for pricing

  • AIR Control agent discovery and policy
  • AIR Filter pre-deployment vetting
  • AIR Defend runtime enforcement
  • AIR Marketplace of vetted add-ons

No list pricing is published anywhere on the site or in launch coverage: the only route is a booked demo, and every plan detail is gated behind sales. The company sells enterprise-first, with about 25 percent of its 20-plus customers being large enterprises, so expect a committed annual contract rather than self-serve. The one thing you can use without talking to anyone is the free add-on scanner at scan.air.security, which is a research tool rather than the product.

Security & Compliance

soc2
gdpr
hipaa
iso27001
sso
data residency

Sources

This page was written from 5 sources, 4 on domains other than air.security.

  1. 1.techcrunch.comair raises 50m to help companies vet the skills and add ons
  2. 2.siliconangle.comair security launches with 50m to build a firewall for ai ag
  3. 3.pymnts.comai agent security startup air raises 50 million to guard ent
  4. 4.calcalistech.comr13apdnugg
  5. 5.air.securityair.securityvendor
Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe