Zenity Wants to Watch Every Step Your AI Agents Take

Zenity Wants to Watch Every Step Your AI Agents Take

AI Security
What Zenity secures, who founded it, and where it sits among the other companies racing to govern AI agents.
By Shashi Bellamkonda · August 6, 2026
$185M
Total Funding Raised
2021
Year Founded
230+
Employees Worldwide
$125M
Series C, Aug. 2026

Zenity secures what AI agents do after they are built and deployed, not just the model or the prompt underneath them. Two Unit 8200 veterans founded the company in 2021, and its research team disclosed the first indirect prompt injection attack against Microsoft Copilot. It now competes with both purpose-built rivals and platform-native alternatives for the same enterprise budget.

Knowledge, memory, tool access, the model connection underneath it, autonomy. Each is a pillar that makes something an agent instead of a script, and each is a pillar Zenity has built a company around watching.

What Zenity Does

Zenity's platform tracks an agent's full lifecycle: how it was built, what configuration it runs, what data and tools it can reach, and then every action it takes once it is live. The company organizes agent risk into three categories. An outside attacker can hijack an agent through indirect prompt injection, often by burying instructions inside something an agent will read automatically, such as a calendar invite. An agent can act on its own in a way nobody intended, pursuing a goal by the easiest available path, which can include escalating its own permissions. An employee can also route sensitive data through an agent built for a legitimate task without realizing where that data ends up.

Prompt injection is not going away.

The platform tracks every step from the trigger, whether a user prompt or an incoming email, through to the final action, then blocks the action, alters it, or raises a flag before it completes. Zenity's coverage spans Microsoft Copilot, ChatGPT Enterprise, and Gemini, coding agents including Claude, Codex, and Cursor, and custom agents built on AWS Bedrock and AgentCore, Microsoft Foundry, and Google Vertex AI.

Two Unit 8200 Veterans, One Pivot

Ben Kliger and Michael Bargury founded Zenity in 2021. Both served in Unit 8200, the Israel Defense Forces' signals intelligence unit, and both had previously built cloud and operational technology security products together at Microsoft. Zenity launched with a low-code and no-code security governance platform aimed at the automations business users were quietly building outside of IT's view. In 2023, that risk gave way to a larger one: enterprise AI copilots, then agents built on top of them.

Zenity Labs, the company's research arm, disclosed what it describes as the first indirect prompt injection attack against Microsoft Copilot. That research pipeline now feeds four to five talks across Black Hat and DEF CON in a single week.

The company has raised roughly $185 million since founding, including a $125 million Series C led by Norwest Venture Partners in August 2026, with participation from SoftBank Vision Fund 2, Hitachi Ventures, LG Technology Ventures, and existing backers Third Point Ventures, DTCP, Vertex Ventures, and Intel Capital. Headcount has passed 230, with research and development based in Tel Aviv and go-to-market run from New York.

Who Zenity Serves

Zenity's customers are Fortune 500 and Global 2000 enterprises in financial services, healthcare, pharmaceuticals, manufacturing, and technology. The company built its product for security teams first, though the data it collects, a full record of what an agent accessed and did, extends naturally to operations teams troubleshooting agent performance and governance, risk, and compliance teams documenting agent activity for regulators.

A Crowded Runtime Layer

Zenity sits in a specific slice of a market filling in fast from more than one direction. Platform vendors have built their own agent control towers directly into the infrastructure enterprises already run, a category I covered in a July piece on ServiceNow, Boomi, and AWS Bedrock AgentCore. Those towers discover and govern agents across a company's existing footprint, but they are native to the platform that built them.

Purpose-built rivals compete on the same ground as Zenity. Onyx Security, founded in 2024 by Maxim Bar Kogan and Gil Elbaz, launched publicly in March 2026 with $40 million in funding. Its Guardian Agent performs a similar runtime interception, with the ability to block, mask, steer, or route an action to a human for approval. Both companies pitch cross-platform enforcement, coverage that holds regardless of which agent-building tool a business unit adopted on its own.

Established security vendors are extending into adjacent ground from a different direction. Qualys has built TotalAI for testing large language models during development, and separately introduced a capability it calls scanless scanning through a new detection engine, aimed at closing the gap between a vulnerability disclosure and its detection across an organization's existing software inventory. That capability sits closer to traditional vulnerability management than to agent runtime enforcement, but it signals where an established vendor's AI ambitions are heading next.

Three types of vendor now compete for the same agent governance budget: platform-native control towers, purpose-built specialists like Zenity and Onyx, and established security vendors extending into AI from adjacent categories like vulnerability management.

CIO/CTO Viability Question

If a control tower already ships with the platform you run, what does a purpose-built layer like Zenity cover that the native tower does not, and does that gap justify running a second system?


Bellamkonda, Shashi. "ServiceNow, Microsoft, and Boomi Build the Control Tower Enterprises Didn't Know They Needed." shashi.co, July 2026, https://www.shashi.co/2026/07/servicenow-microsoft-and-boomi-build.html.

CTech. "Zenity Raises $125 Million Series C as AI Agent Security Startup Accelerates Global Expansion." Calcalist, 3 Aug. 2026, https://www.calcalistech.com.

FinTech Global. "Zenity Lands $125m as AI Agent Security Race Heats Up." FinTech Global, 4 Aug. 2026, https://fintech.global.

Businesswire. "Onyx Security Launches with $40M in Funding to Build the Secure AI Control Plane for the Agentic Era." Businesswire, 11 Mar. 2026, https://www.businesswire.com.

Qualys. "Say Hello to Agent Insta: Scanless Detection at AI Speed." Qualys, Aug. 2026, https://www.qualys.com.

Zenity. "Zenity Joins CoSAI: Building Agentic AI Security Standards." Zenity, 14 Apr. 2026, https://zenity.io.

Disclaimer: This blog reflects my personal views only. Content does not represent the views of my employer, Info-Tech Research Group. AI tools may have been used for brevity, structure, or research support. Please independently verify any information before relying on it.