Tools

Startups build infrastructure for connected, auditable, and permissioned enterprise AI agents

At VB Transform 2026, five startups outlined how they are building the missing infrastructure for enterprise AI agents: orchestration, observability, secure connectivity, and governance.

Startups build infrastructure for connected, auditable, and permissioned enterprise AI agents

At VB Transform 2026, five startups presented components of the missing infrastructure for enterprise AI agents: orchestration, observability, connectivity, security and governance. Their offerings aim to enable agents to coordinate across platforms, speed up security response, audit and simulate agent behavior, run with least‑privilege access, and improve customer service automation while retaining human oversight.

BAND: a coordination layer for multi‑agent workflows

BAND is building a coordination infrastructure to enable multi‑agent AI systems, explained Vlad Luzin, BAND’s co‑founder and CTO. Luzin described a near future in which agents receive tasks, query registries, recruit other agents, delegate subtasks inside a “conversational space,” collect and share results, and return a summary to a human user.

Existing chat platforms such as Telegram, Slack or Discord were built for humans and don’t meet agents’ needs: agents must be onboarded manually, can’t see each other, and often operate in isolation. Stateless models and multiple parallel sessions also create friction. Luzin framed the core challenge as a distributed systems problem: the transport layer must be solved so agents can communicate in real time across channels, conversational spaces and platforms.

BAND provides an abstraction layer that lets agents discover, understand and collaborate with one another; humans can join these interactions. Luzin said BAND supports autonomous workflows that run for eight to twenty hours, is compatible with A2A and MCP protocols, and provides real‑time task recording and visibility.

Conifers: moving defenders to machine speed

Tom Findling, CEO and co‑founder of Conifers, argued that defenders operate at human speed while attackers have moved to machine speed by adopting agents. Attack campaigns that once took months can now succeed in hours or minutes; an attacker needs to be successful only once.

Conifers has turned defense components — private intelligence, hunting, detection, engineering, investigation and response — into agentic systems and broken down the silos between them so these systems can communicate and adapt. Findling claimed the platform reduces containment time from 7 hours to 12 minutes and enables complex cyber investigations to be completed in four minutes or less.

Integration with existing enterprise security tools (EDR, SIEM, posture management, etc.) is critical, he said: Conifers helps customers map security posture, identify which controls are effective, and prioritize investments for best ROI.

Raindrop AI: an audit log and pre‑deployment simulation for agents

Ben Hylak, CTO of Raindrop AI, described the problem of detecting critical failures in agents that run for hours or days. As models and agent complexity rise, issues can become more severe, particularly in healthcare or defense.

Raindrop’s platform detects critical issues in production and simulates fixes based on historical user behavior, allowing teams to verify a fix before it goes live. Its reinforcement‑learning platform optimizes test harnesses and trains models using Raindrop data. A pre‑deployment simulation engine predicts which fixes will impact production and live A/B testing demonstrates the changes.

Messages, tool calls, retries and errors are aggregated in one place and human users are notified (typically via Slack) when problems occur. Models are trained per customer and signals feed continual learning across models and harnesses, producing a navigable, verifiable view of agent behavior.

Arcade.dev: authorization, governance and observability for agents

Sam Partee, co‑founder and CTO of Arcade.dev, said agents need a new security architecture to act on behalf of real users with real permissions. Arcade’s secure agent runtime provides authentication and authorization, enabling agents to pass security reviews, and supplies observability so humans can monitor everything an agent does. Actions are attributable to precise timestamps with minimal privileged scopes.

Arcade ships as an installable plugin that can run on‑prem in a clean‑room environment while allowing enterprises to keep their existing sign‑in and security tools. All actions executed via Arcade are subject to the same RBAC, IDPS, policies and entitlement checks that the organization already uses. Partee emphasized that supply‑chain attacks have become rampant and that past abstractions for agent security and observability were inadequate.

Omilia: a pragmatic approach to customer experience automation

Claudio Rodrigues, CPO of Omilia, said enterprise CX is “not straightforward”: heuristic systems are controllable but slow; agentic systems are fast but unpredictable. Omilia’s platform is designed to combine control and speed.

Omilia’s agents observe real customer service operations: they ingest conversations, API specs, screen recordings and standard operating procedures, then map these inputs to customer support use cases. The AI generates insights, suggests improvements, auto‑creates conversational agents, pulls information from documents and APIs, and designs dialogue flows. Human experts test real and simulated interactions and deploy under supervision.

Rodrigues said Omilia handles more than 3 billion calls a year, with some deployments processing over 1 million voice calls per day, and reported 30–45% improvement in time to resolution (TTR). According to him, Omilia’s agents produce 21x more upsell revenue compared with human agents, and mature deployments can reach 80–90% automation, though human‑in‑the‑loop remains fundamental.

Why this matters

These startups address complementary pieces of the infrastructure stack that enterprises need to deploy AI agents safely and at scale: connectivity and orchestration, faster and agentic defensive operations, auditability and simulation for fixes, least‑privilege runtime and observability, and controlled CX automation. The metrics and claims presented at VB Transform 2026 suggest measurable efficiency and security gains, and the next phase will test how these layers integrate into enterprise security, compliance and operational practices.