As enterprises give AI agents broader access to internal systems, a nascent software supply chain is emerging around the tooling these agents use—skills, plugins, MCP servers and other add-ons that enable internet interaction. AI security startup AIR says companies will need continuous oversight of that supply chain, and the firm has left stealth with $50 million raised across two seed rounds to build such a product.
Founders, funding and staffing
AIR was founded by Yair Saban (CEO) and Niv Hoffman (CTO), both veterans of Israel’s Unit 8200 where they worked on offensive cybersecurity. The two seed rounds totaled $50 million: $10 million in the first round led by Sequoia and $40 million in the second led by Greenoaks, according to Saban. Additional participants include Swish, Netz, Zach Frankel (president of Cognition), Yinon Costica (co-founder of Wiz), Ofir Erlich (co-founder of Eon), Anne Neuberger, Omer Adam, Varun Anand (co-founder of Clay) and other angel investors.
AIR currently has about 40 employees. Saban said the new capital will mainly be used to hire researchers and to expand go-to-market efforts in the U.S. and Europe.
What the platform does
AIR’s product combines three capabilities:
- Discovery: locate AI agents running across a company’s environment and identify employees using unapproved AI tools or personal accounts.
- Continuous vetting and enforcement: an enforcement layer hooks into agents to intercept and analyze actions—such as loading a skill or fetching internet content—and block activity that fails security criteria.
- Whitelist and marketplace: AIR maintains a continuously updated whitelist and offers a marketplace of vetted add-ons and skills for agents.
Saban argues that skills and plugins currently lack the kinds of signature and approval controls common for device drivers, despite similar security implications. AIR evaluates publicly available skills and add-ons for changes or malicious behavior because a previously approved package can become risky if its dependencies change or a developer account is compromised. The company says its platform currently filters out about 27% of the add-ons and skills it finds online.
Customers, industries and competitors
AIR says it has more than 20 customers, roughly a quarter of which are large enterprises. The strongest demand so far has come from heavily regulated sectors, particularly financial services and pharmaceutical companies.
AIR is not alone. Noma Security offers discovery, access controls and runtime monitoring for agents, MCP servers and skills; Zenity sells security and governance tools that operate similarly; Astrix Security’s identity platform allows discovery and control of agents and MCP servers; and Operant AI provides agent protections and an MCP gateway. Venture funding in the category is substantial: Zenity raised a $125 million Series C in August, and Noma raised a $100 million Series B last year.
AIR’s stated moat
AIR positions continuous re-verification of the skills and plugin ecosystem as its competitive advantage. As Saban puts it, you need more than a one-time scan—skills and plugin sites change frequently, so constant re-inspection is required. Bogomil Balkansky, a partner at Sequoia, told TechCrunch that building the infrastructure to inspect every skill, plugin, MCP server and sub-agent in real time across an enterprise’s agent fleet is an infrastructure problem as much as a security one, and AIR has spent the past year building that pipeline.
Saban acknowledged that AI labs and platform providers may eventually implement built-in security checks, but he believes organizations will still prefer an independent product that operates across multiple vendors.
Bottom line
AIR has entered the market with $50 million to address the growing security challenge posed by an expanding, loosely regulated ecosystem of AI-agent add-ons. The company combines discovery, continuous vetting and enforcement with a vetted marketplace, and plans to use the funding to grow its research and commercial footprint amid strong competition in the space.



