Cybersecurity Funding 2026: AI Security, Agent Identity and Enterprise Browser Startups
A 2026 cybersecurity funding map focused on AI security, cloud security, agent identity and enterprise browsers, linking major rounds to permanent company profiles.
TL;DR: Cybersecurity funding in 2026 is increasingly concentrated around AI-agent identity, runtime controls, cloud security, vulnerability operations and enterprise-browser enforcement. VCT's permanent company pages make it possible to track those themes across multiple financing rounds instead of treating each announcement as disposable news.
Companies to watch
| Company | 2026 funding signal | Focus |
|---|---|---|
| Island | $400M Series F at $6.4B | Enterprise browser |
| Cyera | Major 2026 funding | Data security |
| Upwind | Major 2026 funding | Cloud runtime security |
| Reco | $55M additional funding | Agentic security |
| Hackuity | $19M Series B | Vulnerability operations |
| Rig Security | $12M seed disclosed at launch | AI-agent identity |
| Outerlimit | $16M pre-seed | Agent authorization |
| HelmGuard | $7.3M seed | Agentic GRC and assurance |
| Kontext | $4M | Agent runtime policy |
| Humanos | $3.2M seed | AI-agent risk scoring |
| HiddenLayer | 2026 financing | AI model security |
The category shift
Traditional enterprise security was organized around users, endpoints, workloads and applications.
AI agents introduce a new problem: software identities can now initiate actions, call APIs and move through business workflows with far more autonomy.
That is pushing funding toward products that answer questions such as:
- Which agent is acting?
- Which human or service account authorized it?
- What data can it access?
- Which actions can it perform?
- Can those actions be audited or blocked in real time?
- Can risk be continuously verified rather than assessed once a year?
Vulnerability operations is consolidating scanner data
Hackuity represents a different but adjacent security problem: enterprises already generate huge volumes of vulnerability data, but struggle to prioritize and remediate it.
Its platform manages more than one billion findings across more than two million assets, according to the company.
That moves the funding conversation beyond "more scanners" toward orchestration, prioritization and exposure management.
Enterprise browsers are becoming security infrastructure
Island's $400M Series F at a $6.4B valuation shows that the browser itself can become a control plane.
If employees and agents increasingly work through browser-based applications, policy enforcement at that layer can complement endpoint and cloud controls.
Agent identity and assurance are still early
Rig Security, Reco, Outerlimit, Kontext, HelmGuard and Humanos are attacking overlapping parts of the AI-agent risk problem.
Their products are not identical:
- Reco maps identities, permissions and agent activity across enterprise apps;
- Rig focuses on identity relationships and blind spots;
- Outerlimit focuses on authorization at the action layer;
- Kontext focuses on runtime policy enforcement;
- HelmGuard focuses on continuously verified risk and agent assurance;
- Humanos assigns dynamic risk scores and risk passports to agents.
The market is likely to consolidate as platform boundaries become clearer.
What to track beyond round size
For security companies, VCT should increasingly capture:
- enterprise customer count;
- annual recurring revenue;
- expansion rates;
- breach-prevention evidence;
- integrations;
- agent/workload coverage; and
- strategic customer-investors.
Reco's AT&T relationship is a useful example because the investor is also a customer.
Why VCT uses a hub
The earlier May–June cybersecurity roundup remains useful as a historical snapshot. This page is the evergreen 2026 index and should be updated as new rounds arrive, reducing keyword cannibalization from dozens of near-identical funding posts.
Editorial note: AI tools assisted with research, structure, or drafting. Venture Capital Tracker retains human editorial responsibility for factual accuracy, relevance, and source quality before publication.