Back to Blogs

Partnering with Neo to Secure Agentic Software

As Neo emerges from stealth, we're excited to share Craft’s investment in the $100M round alongside Andreessen Horowitz, Bessemer Venture Partners, and Merlin Ventures. Neo is building the Agentic Software Control platform, a real-time control layer to secure organizations' software environments that are becoming agentic. We are proud to have backed Neo from the earliest stage and look forward to deepening our partnership this round with a significant investment.

Our conviction in Neo began with Nick Warner. Three years ago, Nick became a cybersecurity advisor to Craft. Since then, he has been an extraordinary partner to our firm and portfolio. Nick deeply understands how the most consequential cyber categories are won and lost. That knowledge was earned after a decade in the EDR market, one of most unforgiving and competitive battlegrounds in cybersecurity. He held senior roles at McAfee and Cylance and went on to build the go-to-market machine that took SentinelOne from $1 million to $500 million of ARR and led them through IPO as COO and President. 

When Nick was ready to start a company, we were eager to partner with him and his co-founders, Shlomi Salem and Eran Shirazi. Shlomi led detection engineering at SentinelOne for over a decade and Eran built EasySend, the customer experience company. The three of them held a shared view around how software capabilities were expanding with AI and how quickly that was going to overwhelm security teams. According to Gartner, only 5% of enterprise applications featured agentic capabilities in 2025, but 40% will by the end of 2026. Everyday apps that enterprises already use and trust are gaining the ability to reason, reach into other systems, call tools, and carry out actions with legitimate credentials. 

Security teams are spending tens of billions of dollars per year securing their software, but none of it covers this new layer of agentic capabilities. After spending months speaking with CISOs in our community about this challenge, it became obvious that this is a critical gap they need to fill in order to enable broad AI adoption in their organizations. Neo addresses this by providing a real-time control plane that covers all the software running across the enterprise. Neo sees what agentic software can do, understands how it behaves, and enforces policy inside the software layer before risky activity happens.

The velocity at which Neo builds is remarkable. They began by developing a scanner that generates an organization's full agentic software inventory in minutes. They then enrich those inventories with their proprietary “Neoverse,” a knowledge base of the real capabilities and risks of the entire agentic software landscape, covering over 1.2 million skills, binaries, MCP packages, and third-party AI models. The Neo platform is powered by their advanced endpoint sensor, which captures every prompt and action on the device and understands the intent behind it. That architecture enables them to enforce guardrails natively inside the software layer without handoffs to other tools. They also developed an LLM-powered policy creation engine that creates guardrails autonomously for SecOps teams. In a crowded and often confusing AI security market, the Neo team is very clear and explicit on solving the agentic software control problem and building a deep platform there. 

The market potential for agentic software control is similar in size and scope to the cloud security market, which was at its infancy a decade ago and is now a $20 billion opportunity. The key difference is that the adoption curve for AI-enabled software will be much steeper than it was for cloud. Traditional software is rolling out these capabilities fast, without express permission from security teams, and employees are adopting AI-native tools en-masse. 

Some of the largest enterprises have already deployed Neo to secure their agentic software layer. They realize the agentic train has left the station and managing the inevitable risk associated with that will require endpoint-based visibility and control that covers all agentic software capabilities. Every week we are seeing developments in agentic capabilities, which is simply too fast for the largest cyber vendors to keep up with their platforms. 

We are excited to partner with Neo as they become the go-to agentic software control company. They have an experienced team that has built and scaled enterprise-grade sensor-based platforms before, and they are quickly becoming critical infrastructure for agentic software adoption. 

A new layer of agentic software deserves a new layer of control. That's Neo.

Why We Invested
Michael Robinson
Kevin Gabura
Dan Moor

Partnering with Ent to Protect Work as It Happens

Ent is an AI-powered, on-device workspace security platform that helps enterprises shift from reactive detection to real-time threat prevention, backed by a $100M funding round.

Why We Invested
Michael Robinson
Zao Chen

All in on Supabase: the Default Backend for Software Development

AI is causing an explosion in software creation and Supabase has become the default backend for this new era.

Why We Invested
Michael Robinson
Kevin Gabura
Dan Moor

Our Partnership with Oasis Security: Securing Access for the Agentic Era

Craft Ventures leads Oasis Security's $120M Series B for Agentic Access Management platform, securing non-human identities as machine identities outnumber humans 82:1, with ARR growing 5x year-over-year among Fortune 500 customers.