Reco Raises $55M, Backed by AT&T Ventures, to Expand Agent-Identity and Data-Access Governance
Reco, the Israeli-founded SaaS and AI-agent security vendor, has raised an additional $55 million, bringing total funding to $140 million. The round includes a strategic investment from AT&T Ventures — notable because AT&T Ventures reportedly started out as a Reco customer before converting to an investor, a customer-to-cap-table trajectory that buyers tend to read as a credibility signal in a crowded agent-security market.
The product framing matters more than the round size for DLP/DSPM teams evaluating where Reco fits in their stack. Reco’s platform maps relationships between agents, human identities, applications, permissions, and data, giving security teams visibility into which AI agents are active, what credentials and scopes they’re using, and which systems and datasets they can reach. From there it supports identifying and revoking access that’s excessive or no longer justified. That’s squarely an access-governance and exposure-mapping function — closer to CIEM/identity governance extended into agent workloads than to classic content-inspection DLP.
Reco claims integration coverage across more than 280 applications and AI services, including OpenAI, Anthropic, Microsoft Copilot, Salesforce, ServiceNow, and Workday. That breadth is the pitch: as enterprises wire LLM agents into core SaaS systems, the blast radius of a single over-permissioned agent identity grows, and most existing DSPM or DLP tooling wasn’t built to track non-human agent identities as a first-class object.
For practitioners already running DSPM or insider-risk programs, the practical question isn’t whether Reco replaces those tools — it doesn’t, by its own positioning — but whether its agent/identity graph closes a gap that data-centric classification tools leave open: knowing not just where sensitive data lives, but which autonomous agents currently have standing permission to touch it.