Reco
by Reco
AI agent security and SaaS security platform that discovers, governs and secures every agent, app and identity
Reco is an AI agent security and SaaS security platform for enterprise CISOs and security teams. It discovers sanctioned and shadow AI agents and SaaS apps, maps what each agent can reach through a context graph, and flags over-permissioned agents, misconfigurations and identity threats across 270+ connected applications.
Reco began as a SaaS security vendor covering SaaS security posture management (SSPM), shadow SaaS and AI discovery, identity and access governance and identity threat detection and response (ITDR), and has since repositioned its platform around securing AI agents. Its core is a context graph that links each agent to the apps, people, accounts and permissions it touches. Security teams can see an agent's owner, its reach and its risk score, and catch cases where an agent has more access than the human who created it. Reco connects through APIs to 270+ applications, including OpenAI, Claude, Microsoft Copilot, Cursor, Salesforce, Workday, Okta, Microsoft 365, Google Workspace, ServiceNow and Slack. It adds browser and network signals to find agents outside those direct integrations, and its no-code 'Reco Factory' engine adds support for a new app in 3-5 days. The ITDR module ships 1,000+ pre-built detection controls with auto-remediation, and newer controls inspect prompts and tool calls. CEO Ofer Klein told TechCrunch that one Fortune 100 customer found 21,000 unknown agents. Reco raised a $30M Series B in February 2026 led by Zeev Ventures, then a $55M extension in September 2026 from AT&T Ventures, Forestay and Quadrille Capital, bringing total funding to $140M. It reports 100+ customers, roughly 40% of them in financial services, and double-digit-million ARR. It competes in a crowded field of agent-security vendors including Zenity, CrowdStrike Falcon Guardian, AIR and Cymphony, and with SSPM specialists such as AppOmni and Grip Security.
A CISO or SaaS/identity security lead at a 1,000+ employee enterprise (especially financial services) who has lost track of the AI agents and copilots employees are connecting to Salesforce, Microsoft 365 and other core SaaS.
A continuously updated inventory of every AI agent and SaaS app, showing who owns it, what data and permissions it can reach, and which access to revoke.
At a Glance
- Category
- Governance & Security
- Pricing
- Subscription, Contact for pricing
- Target Market
- CISOs, CIOs, Security Teams, Identity & Access Management Teams
- Deployment
- Cloud-only, API-based
- Headquarters
- Tel Aviv, Israel
- Customers
- 100+ (September 2026, per TechCrunch)
Key Features
- ✓AI agent discovery and inventory
Maps every AI agent across the environment with its owner, permissions, lineage and a risk score, so security teams can see agents nobody registered.
- ✓Context graph
Links agents to the apps, people, accounts and permissions they touch, exposing over-permissioned agents and access to revoke.
- ✓SaaS security posture management (SSPM)
Continuously monitors SaaS configurations and flags permission sprawl, misconfigurations and policy violations against compliance frameworks.
- ✓Identity threat detection and response
Ships 1,000+ pre-built detection controls with auto-remediation across human and non-human identities in connected SaaS apps.
- ✓Reco Factory integration engine
No-code engine that adds support for a new SaaS application in 3-5 days, extending coverage beyond the 270+ built-in integrations.
- ✓Browser and network agent signals
Detects agents operating outside direct API integrations by using browser and network signals, closing gaps in API-only discovery.
Capabilities
Use Cases
- •Agent sprawl audit
A Fortune 100 customer used Reco to discover 21,000 previously unknown AI agents running across its environment.
- •Offboarding risk
A large financial services customer identified an agent built by a former employee that was still accessing Salesforce after they left.
- •Shadow AI governance
Security teams detect unsanctioned AI tools such as ChatGPT, Claude or Cursor connected to corporate SaaS and decide what to allow or revoke.
- •SaaS compliance posture
Compliance teams continuously check Microsoft 365, Google Workspace and Salesforce configurations against policy and fix drift before audits.
Ideal For
Best For
- ✓Discovering shadow AI agents and unsanctioned AI tools connected to corporate SaaS
- ✓Finding AI agents that hold more access than their human creators
- ✓SaaS security posture management and compliance across Salesforce, Workday, Microsoft 365 and Google Workspace
- ✓Identity threat detection and response across human and non-human SaaS identities
- ✓Regulated financial services and healthcare organisations that need agent governance evidence
Not Ideal For
- ✗Small businesses with only a handful of SaaS apps; the entry tier on AWS Marketplace lists at $18,000/year
- ✗Teams looking for network, firewall, EDR or malware protection; Reco is API-based SaaS and agent security, not endpoint or network security
- ✗Buyers who need transparent self-serve pricing before a demo; direct pricing is quote-based
- ✗Organisations that cannot grant privileged API access to their SaaS tenants, which the platform requires
Deployment
Market & Ratings
100+ (September 2026, per TechCrunch)
Market Analysis
Pros
- ✓Reviewers on G2 and AWS Marketplace praise its visibility, ease of use and simple onboarding
- ✓Strong discovery of hidden integrations, shadow AI and unknown agents
- ✓Agentless, API-based deployment avoids endpoint rollout friction
- ✓Holds SOC 2 Type II, ISO 27001 and ISO 42001 certifications
Cons
- ✗Connector depth varies by application, so coverage quality is uneven across the 270+ integrations (AWS Marketplace reviews; work-management.org review)
- ✗Reviewers want more flexibility in alerts, dashboards and reporting, and G2 reviewers flag limited remediation features
- ✗No transparent direct pricing, and the published AWS tiers start at $18,000/year
- ✗Requires privileged API access to SaaS tenants and can overlap with existing SSPM, CASB or identity tools
Pricing
Reco Essential (AWS Marketplace)
$18,000/year
- ✓SSPM posture management and compliance
- ✓Up to 3 integrations
- ✓12-month contract
Reco Advanced (AWS Marketplace)
$90,000/year
- ✓SaaS detection and response
- ✓Identity and access governance
- ✓Unlimited integrations
Direct / custom
Contact for pricing
- ✓Quote based on users, integrations and modules
- ✓Proof of value available
Reco publishes no list pricing on its own site, and direct deals are quoted on users, integrations and modules. AWS Marketplace does list 12-month contracts: Essential (SSPM, up to 3 integrations) at $18,000/year and Advanced (detection and response plus identity governance, unlimited integrations) at $90,000/year. 24-month contracts save up to 3% and 36-month contracts up to 11%. Capterra lists no free trial, only a proof of value.
Security & Compliance
Connect
Sources
This page was written from 8 sources, 6 on domains other than reco.ai.
- 1.reco.ai — reco.aivendor
- 2.reco.ai — about usvendor
- 3.techcrunch.com — reco raises 55m as ai agent security startups crowd the mark
- 4.securityweek.com — reco raises 30 million to enhance ai saas security
- 5.theaiinsider.tech — reco announces 55m in funding to tackle ai agent sprawl acro
- 6.aws.amazon.com — prodview hu5uzgbfbbeoc
- 7.work-management.org — reco review
- 8.capterra.com — Reco
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
Ascerta
Enterprise AI management: measure the ROI, cost and adoption of every AI initiative, agent and coding tool
Arcjet
Runtime security for AI agents: observe, enforce and audit agent tool calls, with prompt-injection, PII and abuse controls in code
Exaforce
Agentic SOC and MDR platform whose Exabot AI agents detect, triage, investigate and respond, now with an AI-agent kill switch
Vals AI
Independent AI benchmarking on private test sets, plus custom evals built from your own code, for legal, finance, healthcare and coding workloads