Neo Security
Last updated: Jul 20, 2026
Neo Security is an American-Israeli cybersecurity company, founded by former SentinelOne leaders, that provides an endpoint-based 'agentic software control' layer to discover, monitor, and govern the actions of AI agents, MCP servers, extensions, and traditional software across enterprise environments in real time.
Visit WebsiteCompany Overview
**Product and the concrete problem it solves.** Neo Security (branded simply "Neo," at neo.ai) is attacking a control gap that has opened almost overnight as enterprises deploy autonomous and semi-autonomous AI software. The concrete problem: AI agents, copilots, Model Context Protocol (MCP) servers, browser extensions, and "skills" now take real actions on real endpoints — reading files, calling APIs, moving data, invoking tools, and chaining workflows — but most security stacks were built to govern *humans* and *static applications*, not autonomous non-human actors whose behavior is probabilistic and whose permissions are frequently over-broad. Neo's stated mission is "agentic software control," captured in its tagline: "Reveal, understand, and control every human and non-human action on every endpoint in real time." In practice, Neo answers three operational questions for a security team: (1) *what* agentic and traditional software is actually running (agents, models, extensions, MCP servers, skills); (2) *how* it is configured, flagging excessive access privileges and misconfigurations; and (3) *what happens when it runs*, enforcing policy at the moment of action. The pitch is that you cannot secure autonomous software you cannot see, and you cannot govern it with tools that only observe posture after the fact.
**Core technology and how it actually works.** Neo's architecture is deliberately endpoint-centric rather than cloud-log-centric, which is its most important technical bet. The company describes an on-device agent that performs local analysis with "no kernel module, no reboot" — a lightweight deployment posture that lowers adoption friction and keeps sensitive analysis on the endpoint for data-privacy reasons. At the core is **Neoverse**, a continuously updated knowledge base that maps the capabilities, risks, and behavioral patterns of agentic software so that a novel agent or MCP server can be characterized rather than treated as an opaque process. The enforcement mechanism is the differentiator: Neo says it *intercepts* an agent's actions at the endpoint and can **allow, block, or hold for approval** before the action reaches sensitive data or systems — a real-time control point, not merely a dashboard. Around that sit a continuous catalog/inventory of active elements (agents, models, extensions, MCP servers), **real-time attribution** that traces a given software action back to a specific human user or application, granular policy enforcement over tool calls, data movement, agentic workflows, and API access, and audit trails that record both human and AI actions. The combination — discover, characterize via Neoverse, attribute, and enforce inline — is what Neo means by a "control layer" as opposed to the discovery-and-posture approach common in early AI-security tooling.
**Market, customers, and go-to-market.** Neo sells into enterprise security operations teams — the same buyers who already run endpoint detection and response (EDR), identity, and data-security programs — and positions "agentic software control" as a new adjacent category rather than a feature of an existing one. The go-to-market thesis rides a genuine wave: as of 2026 enterprises are rapidly piloting AI agents and MCP-based integrations, and CISOs are visibly anxious about non-human identities, agent sprawl, and the blast radius of an over-permissioned autonomous workflow. Neo's endpoint-first, privacy-preserving deployment ("no kernel module, no reboot," local analysis) is tuned to reduce the procurement and rollout friction that slows security-tool adoption. The company emerged from stealth on July 20, 2026, so named marquee customers, pricing, and revenue are not yet public and should be treated as unconfirmed; the go-to-market motion (enterprise direct, security-operations buyer, land-and-expand from endpoint visibility toward inline enforcement) is inferable from the product and team but not yet evidenced by disclosed logos.
**Traction, funding, and third-party validation.** Neo's strongest external validation is the caliber of its capital and backers relative to its age. The company launched from stealth with **$100 million in total funding** — a **$25 million seed round completed in 2025** and a **~$75 million Series A** — led by **Andreessen Horowitz (a16z)** and **Bessemer Venture Partners**, with participation from **Craft Ventures** and **Merlin Ventures**. Reporting also lists a notable angel roster including **Wiz CEO Assaf Rappaport** and former Wiz executive **Merav Bahat**, among others — an unusually strong cybersecurity-operator syndicate for a company at emergence. As of the July 2026 launch, Neo reported roughly **50 employees, about 40 of them in Israel**, indicating an Israel-centered R&D base with a U.S. commercial footprint. What remains unverified and should be diligenced directly: paying customers, ARR, retention, the depth and independence of the Neoverse knowledge base, and any third-party security evaluations or design partners. In short, the validation here is investor- and operator-driven rather than customer-proven — appropriate for a stealth-exit stage, but not yet market proof.
**Founders and team background.** Neo's team is its most defensible asset. CEO **Nick Warner** was previously **President and COO of SentinelOne**, where he built the go-to-market organization and helped carry the company through its 2021 IPO, with earlier senior roles at **Cylance, McAfee, and Forcepoint** — a rare profile of someone who has scaled an endpoint-security business from growth stage to public-company scale. CPO **Shlomi Salem** led **SentinelOne's detection engineering for roughly a decade** and co-led internal threat research, giving Neo deep endpoint-detection and adversary-behavior expertise precisely where the product must be strong. CTO **Eran Shirazi** co-founded the software company **EasySend** and, per reporting, previously **led a vulnerability-research group in the IDF's Unit 8200** — the elite signals-intelligence unit that is a canonical source of Israeli cyber founders. The pairing of a proven endpoint-security operator (Warner), a career detection engineer (Salem), and an offensive-research and product builder (Shirazi) is well-matched to "control every action on every endpoint." The principal open question is organizational maturity beyond the founding trio — sales leadership, customer-success, and channel — which is normal for a company weeks out of stealth.
**Competitive dynamics.** Neo is entering one of the most contested arenas in security, where incumbents and startups are converging on "AI/agent security" from multiple directions. (1) **Endpoint incumbents** — CrowdStrike and Neo's own alma mater SentinelOne — can extend EDR toward agentic control and enjoy installed-base distribution. (2) **Cloud/AI-security platforms** — Wiz (whose CEO is a Neo angel), Palo Alto Networks (Prisma AIRS), and Microsoft — are folding AI and agent security into broad suites. (3) **Non-human / machine-identity players** — CyberArk, Okta, Silverfort, and AuthMind — attack the identity-and-privilege side of the same problem. (4) **A wave of agent/LLM-security startups** — including Noma Security, Zenity, Aim Security, Prompt Security, and Lasso Security — compete directly on securing agents, MCP, and LLM workflows, several with a head start. Neo's plausible edges are: (i) **inline endpoint enforcement** (allow/block/hold at the moment of action) rather than discovery-and-posture only; (ii) an **on-device, privacy-preserving, no-kernel-module** deployment that eases adoption; (iii) the **Neoverse** behavioral knowledge base as a data moat if it compounds; and (iv) a founding team that has already built and scaled category-defining endpoint software. The countervailing risk is that "agent security" is consolidating fast and the largest incumbents can bundle a "good enough" capability into platforms customers already own.
**Defense, security, and resilience dual-use relevance.** Neo's dual-use relevance should be stated with calibration: it is an enterprise cybersecurity company, and its defense/resilience weight is an adjacency, not a fielded government capability. The credible thesis is that governing autonomous AI agents and non-human identities is becoming a **critical-infrastructure and national-security resilience problem**: as government agencies, defense organizations, and operators of energy, finance, and telecom infrastructure adopt agentic AI into workflows and even command-support systems, the ability to inventory, attribute, and inline-control every autonomous action — and to pause or block a compromised or misbehaving agent before it touches sensitive systems — maps directly onto the emerging attack surface those institutions face. The Unit 8200 pedigree on the founding team and the endpoint-enforcement design are consistent with security-grade requirements. Honest calibration: there is no public evidence of defense contracts, government deployments, or accreditations (e.g., FedRAMP/IL), and the roadmap is enterprise-first; dual-use here is a real and strategically-timely adjacency that would only become a fielded capability with government customers, accreditation, and hardened deployment that the public record does not yet show.
**Growth stage, trajectory, and key diligence risks.** Neo reads as an **early-stage** company with an unusually strong launch: founded in 2025, emerged from stealth in July 2026 with $100M and elite backers, product publicly described but not yet market-validated. The trajectory is promising precisely because the team has done this before, but the risks are concentrated and real. (1) **Category crowding and incumbency:** agent security is filling with well-funded startups and platform incumbents (CrowdStrike, SentinelOne, Wiz, Palo Alto Networks, Microsoft) who can bundle. (2) **Product-maturity risk:** inline endpoint interception of arbitrary agentic actions is technically hard to do reliably without breaking legitimate workflows, and Neoverse's value depends on breadth and accuracy that must be earned over time. (3) **Metric opacity:** customers, revenue, retention, precise HQ, and evaluation results are undisclosed. (4) **Expectation and burn risk:** a $100M launch sets a high bar and a fast clock. (5) **Dual-use is adjacency, not fielded**, so the strategic-defense case is prospective. Progression signals to track: named enterprise customers and design partners, disclosed ARR and net retention, independent security evaluations of the enforcement layer, MCP/agent-ecosystem partnerships, and any move toward government accreditation that would convert the resilience thesis into a fielded capability.
Dual-Use Assessment
Neo's dual-use relevance is a real but adjacency-grade thesis, not a fielded government capability. (1) The core problem it governs — autonomous AI agents, MCP servers, extensions, and non-human identities taking real actions on endpoints — is rapidly becoming a critical-infrastructure and national-security resilience concern as government, defense, and operators of energy/finance/telecom adopt agentic AI into workflows and command-support systems. (2) Neo's inline enforcement model (allow / block / hold an agent action at the moment of execution, with real-time attribution back to a human or application) maps directly onto the security requirements of institutions that cannot tolerate a compromised or over-permissioned autonomous agent touching sensitive systems. (3) The founding team's Unit 8200 vulnerability-research and endpoint-detection pedigree is consistent with security-grade design. Calibration: there is no public evidence of defense contracts, government deployments, or accreditations (e.g., FedRAMP/IL levels); the roadmap is explicitly enterprise-first. Dual-use is therefore a strategically-timely adjacency that would become a fielded capability only with government customers, accreditation, and hardened deployment not yet evidenced in the public record.
Strategic Fit Assessment
Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.
Neo is a rare early-stage cybersecurity play whose appeal rests on an elite founding team and top-tier capital pointed at a genuinely emerging category, tempered by crowding and unproven traction. (1) Exceptional team: CEO Nick Warner was President/COO of SentinelOne through its 2021 IPO; CPO Shlomi Salem led SentinelOne detection engineering for roughly a decade; CTO Eran Shirazi co-founded EasySend and reportedly led an IDF Unit 8200 vulnerability-research group — a combination of proven endpoint-security operating experience, detection depth, and offensive research. (2) Top-tier validation: a $100M launch ($25M seed in 2025 plus a ~$75M Series A) led by Andreessen Horowitz and Bessemer Venture Partners, with Craft Ventures and Merlin Ventures and an operator angel roster including Wiz CEO Assaf Rappaport — an unusually strong syndicate at emergence. (3) Timely category: agentic AI security and non-human identity governance is one of the fastest-forming security categories of 2026, and Neo's inline endpoint-enforcement model (allow/block/hold) is differentiated from discovery-and-posture-only tools. (4) Adoption-friendly design: on-device, no-kernel-module, privacy-preserving deployment lowers procurement friction. Counterweights that should dominate assessment: (a) the market is crowding fast with both incumbents (CrowdStrike, SentinelOne, Wiz, Palo Alto Networks, Microsoft) who can bundle and startups (Noma, Zenity, Aim, Prompt, Lasso) with head starts; (b) no disclosed customers, ARR, or independent evaluations; (c) inline interception of arbitrary agent actions is technically hard to do without breaking workflows; and (d) the strongest strategic (defense/critical-infra) uplift is adjacency, not fielded. This is a priority-signal assessment of team and category fit, not an investment recommendation.
Strategic Value to U.S.-Israel Alliance
Neo's strategic value sits in the governance-and-resilience layer for autonomous AI rather than in a defense product. (1) Emerging control point: as agentic AI becomes embedded in enterprise, government, and critical-infrastructure workflows, a real-time layer that inventories, attributes, and inline-controls every autonomous action is a high-leverage, horizontal capability. (2) Resilience thesis: the ability to pause or block a compromised or misbehaving agent before it touches sensitive systems addresses a well-recognized and fast-growing attack surface that spans commercial and public-sector operators alike. (3) Israeli cyber pedigree: an Israel-centered R&D base (roughly 40 of 50 employees) with Unit 8200 and SentinelOne DNA contributes to the allied cybersecurity talent and capability base. (4) Category-defining potential: if Neoverse compounds into a broad, accurate behavioral knowledge base for agentic software, it could become an infrastructural dependency for AI security. The realized strategic weight depends on Neo converting an elite launch into named customers, proven enforcement reliability, and — for the defense axis specifically — government customers and accreditation. Absent those, its strategic value is a strong, timely commercial-security adjacency rather than a fielded national-security capability.
Key Technologies
- Endpoint-based 'agentic software control' layer that intercepts AI-agent and software actions in real time to allow, block, or hold them for approval before they reach sensitive data or systems
- Neoverse knowledge base that continuously maps the capabilities, risks, and behavioral patterns of agentic software (agents, models, MCP servers, extensions, skills)
- Continuous discovery and inventory of both agentic and traditional software running across enterprise endpoints
- Real-time attribution tracing each software action back to a specific human user or application
- Granular policy enforcement over tool calls, data movement, agentic workflows, and API access, with audit trails of human and AI actions
- On-device / local analysis deployment ('no kernel module, no reboot') that preserves data privacy and lowers rollout friction
- Configuration and privilege analysis that flags excessive access rights and misconfigurations of AI agents and applications
Use Cases & Applications
- Discovering and inventorying shadow AI agents, MCP servers, and browser extensions running unmonitored across an enterprise fleet
- Blocking or holding an over-permissioned or compromised AI agent before it exfiltrates data or invokes a sensitive tool/API
- Enforcing least-privilege and granular action policies on autonomous agentic workflows
- Generating audit trails and real-time attribution for AI-driven actions to satisfy compliance and incident-response needs
- Governing non-human / machine identities as agentic software proliferates alongside human users
- Securing MCP-based integrations and third-party agent 'skills' at the point of execution
- Protecting AI-enabled security-operations and IT workflows in regulated or critical-infrastructure enterprises
- Providing a control point for enterprises piloting agentic AI who need visibility and enforcement before broad rollout
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.
This record lists 5 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- Neo — Official Website (neo.ai) Company site confirming the name 'Neo Security, Inc.,' the 'agentic software control' positioning and tagline, the endpoint control model (intercept agent actions to allow/block/hold), the Neoverse knowledge base, on-device 'no kernel module, no reboot' deployment, and the $100M backing from Andreessen Horowitz, Bessemer Venture Partners, Craft Ventures, and Merlin Ventures.
- Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software (SecurityWeek, July 2026) Verifies the July 20, 2026 stealth exit, $100M total funding across seed and Series A, lead investors (a16z, Bessemer, Craft, Merlin), founders Nick Warner (ex-SentinelOne President/COO; Cylance/McAfee/Forcepoint), Shlomi Salem (ex-SentinelOne detection engineering lead), and Eran Shirazi (EasySend co-founder), the neo.ai domain, and the product's control-layer capabilities (catalog of agents/models/extensions/MCP servers, real-time attribution, granular policy enforcement).
- SentinelOne veterans raise $100 million to secure the rise of AI agents (Calcalist / CTech) Corroborates the $100M total ($25M seed 2025 + $75M Series A led by a16z and Bessemer, with Craft and Merlin), ~50 employees (about 40 in Israel), founder backgrounds including Eran Shirazi's IDF Unit 8200 vulnerability-research leadership, the angel roster (Wiz CEO Assaf Rappaport, Merav Bahat, and others), and the real-time control-layer product for AI agents and AI-enabled software.
- Former SentinelOne leaders secure $50 million for stealth cyber startup (Calcalist / CTech, exclusive) Earlier exclusive verifying Neo Security as a stealth startup founded in 2025 by former SentinelOne leaders (Nicholas Warner CEO, Shlomi Salem, Eran Shirazi), raising in the tens of millions on top of a $25M seed (a16z, Merlin) and bridging endpoint, network, and identity security — establishing the company's Israeli-founder cyber lineage prior to the full stealth exit.
- Weekly Firgun Newsletter – July 17, 2026 (VC Cafe) Independent Israeli-tech newsletter listing Neo Security's stealth-stage raise and describing its platform as bridging endpoint, network, and identity security — third-party corroboration of the company's category and Israeli-ecosystem placement.
- Profile update timestamp Last updated in the Claw & Talon database on Jul 20, 2026.
Investor Lens
What this entry is
Private startup
Why it may matter
Neo Security may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.
How an independent investor should read this
Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.
Evidence to verify
- Verify current status
- Verify traction
- Verify cap table/funding
- Verify technical claims
- Verify regulatory/export-control issues
- Verify customer concentration
Main investor questions
- Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
- What customer, revenue, product, and technical evidence supports the company story?
- What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
- Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
- What evidence would change the thesis or show that the profile is stale?
What not to infer
- Inclusion does not imply endorsement.
- Inclusion does not imply allocation availability or current fundraising.
- Scores do not indicate investment suitability or expected returns.
- Strategic importance does not automatically imply venture return potential.
Diligence questions
- What evidence verifies Neo Security's current customer traction, deployment status, and revenue concentration?
- Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
- Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
- How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
- What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.
Related companies
Need a diligence readout?
Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.