(UPDATED: June 11, 2025)
XOOMAR Intelligence
Analyst Take
Ent exited stealth Tuesday with $100 million in seed funding, a strikingly large opening check for a workplace cybersecurity startup built around one urgent claim: AI makes attacks move too fast for old detection-first defenses. The Ent seed funding was announced Tuesday, June 11, 2025, according to a company press release, and puts immediate pressure on the company to prove prevention can happen before human users or AI agents trigger incidents.
Ent’s thesis is blunt. The company says AI “compresses the time between compromise and impact,” so “prevention must once again become the primary objective of security.” Its platform is designed to help companies understand and interrupt risky actions by humans and AI agents “before they become incidents.”
Ent seed funding gives builders $100 million to ship prevention-first endpoint security
The $100 million seed round gives Ent room to hire across engineering and go-to-market teams while funding work in AI governance, threat prevention, security integrations and multimodal endpoint intelligence. That is the buildout Ent now has to turn from stealth pitch into deployed product.
The builder question is direct: can Ent make real-time intervention work without slowing down employees, AI agents and business applications?
The round was led by Decibel Partners, with Sequoia Capital, Crosspoint Capital, Craft Ventures, Shield Capital, Felicis Ventures and In-Q-Tel also investing. The company was founded by cybersecurity veterans Elias Manousos and Brandon Dixon, who previously created RiskIQ, later acquired by Microsoft.
Ent is positioning its technology as a new layer for workspace security. Its stated target is the gap between behavior that looks legitimate and behavior that can still create risk, especially when AI agents and assistants are acting with increasing autonomy inside corporate environments.
“AI is changing both how people work and how quickly attackers can act. What once took days now happens in seconds,” Manousos said in the launch announcement.
He added: “By the time traditional security systems detect a problem, it is too late. We believe the future of security lies in understanding intent in real time across people and AI agents and stopping risk before it becomes an incident.”
That is the core claim behind the Ent seed funding story. Ent isn’t pitching another post-incident alert machine. It is pitching intent detection and proactive enforcement at the precise moment a risky action is being taken.
Security buyers get an AI-agent pitch, not just another alert console
Ent says its platform watches for risky actions by both people and AI agents at the point of use. The company states the product is delivered as software-as-a-service and runs through a lightweight endpoint agent across Windows, macOS, Linux and browser-extension deployments.
The buyer question is sharper: will Ent reduce incidents, or just add another complex policy layer teams have to tune?
According to launch materials, Ent says the platform is already deployed with Global 2000 customers in hospitality, financial services and defence. Those early adopters are reportedly using it for real-time insider risk detection, AI governance and compliance, data loss prevention, and threat prevention.
That customer detail matters because Ent’s pitch depends on deep contextual awareness. The company argues that many modern risks can resemble normal work, especially when autonomous or semi-autonomous AI agents execute multi-step workflows across devices, applications and data. A blocked action only helps if the system understands why the action is uniquely risky in that specific business setting.
For CISOs evaluating where a new prevention layer would fit, the integration question will be as important as the AI story. XOOMAR readers comparing adjacent stack decisions may want to revisit Your SOC Budget Hinges on SOAR vs SIEM vs XDR Choices and 60-Tool Sprawl Trap Forces Security Platform Consolidation for context on how security teams weigh overlapping tools.
Ent claims it is designed to work with existing EDR, SIEM, SOAR and IAM systems. That sounds buyer-friendly, but the proof will come in deployment details: how policies are written and managed, how interventions are explained to the user or agent, how false positives are handled, and whether the product gives investigators a clear, actionable record of what was about to happen and why it was stopped.
Existing security stacks now face Ent’s prevention-first challenge
Ent is not entering a blank space. Enterprise security teams already run endpoint detection and response (EDR/XDR), identity controls, logging systems, automation tools and cloud security products. Ent’s argument is that those systems are often optimized for investigation and response—they see compelling evidence only after the action, while AI-speed work requires reasoning before completion.
The competitor question is practical: if existing tools already touch endpoint, identity and workflow data, what makes Ent’s pre-execution intent layer hard to copy or build internally?
Ent’s answer, based on supplied materials, is a mix of architectural placement, real-time AI reasoning, and adaptive policy enforcement. The company says its platform applies customer-defined policies and intervenes in real time before an incident occurs, at the point where a user or agent initiates a risky action.
That creates a clear technical burden. Ent must show it can distinguish between a strange but legitimate action and a genuinely dangerous one while the user or agent is still in motion. The company also has to avoid turning every unusual but benign workflow into a frustrating security interruption—a key adoption risk.
Its team gives the company immediate credibility with enterprise buyers. Ent’s advisors reportedly include former cybersecurity executives from Google, Aetna, MassMutual and Microsoft, as well as a former NSA director.
Still, advisor names and funding won’t settle the product question. Security teams will want proof inside messy, distributed corporate environments, where complex permissions, SaaS apps, local files, browser sessions, and AI tools collide every day.
Investors have made Ent’s next proof point painfully clear
The Ent seed funding round gives the company a loud, well-capitalized entrance. It also removes the excuse of moving slowly.
The market signal is not subtle: prominent investors are willing to back security companies that can compellingly explain how generative AI and agentic workflows fundamentally change the timing and nature of risk. Ent now has to translate that narrative into measurable enterprise traction and risk reduction.
Several key details remain undisclosed from the launch. Pricing was not made public. Ent has not yet named the specific Global 2000 customers cited in its materials. The announcement did not include details on major technology or channel partnerships, nor independent performance benchmarks from early deployments.
That leaves a focused watch list for the coming months:
- Customer Proof: Whether Ent names flagship enterprise deployments beyond broad industry categories.
- Product Evidence: Whether it demonstrates, via detailed case studies, how real-time interventions work in practice without crippling productivity.
- Integration Depth: Whether integrations with existing EDR, SIEM, SOAR and IAM tools prove to be deep and bidirectional, providing useful context rather than becoming another source of alert noise.
- AI Governance Adoption: Whether buyers adopt it as critically for AI-agent oversight and compliance as for conventional insider threat prevention.
If Ent can prove that intent-aware prevention works at AI speed and scale, it has a shot at defining a new category in workplace security. If the product creates more operational friction than clear incident reduction, the $100 million round will look less like validation and more like a very expensive, high-profile test of a timely thesis.
The Bottom Line
- Ent's $100 million seed round signals strong investor confidence in a prevention-centric approach to AI-era workplace security.
- The company is betting that proactive enforcement must replace detection-first defenses as AI compresses attack timelines.
- With the stealth launch complete, Ent now faces intense pressure to turn a well-funded thesis into a proven, scalable product for complex enterprises.
Ent's Security Approach vs. Traditional Detection-First Defense
| Traditional Detection-First Security | Ent's Prevention-First Platform |
|---|---|
| Focuses on identifying threats after suspicious activity appears | Aims to interrupt risky human and AI-agent actions before incidents occur |
| May struggle as AI accelerates the time from compromise to impact | Built around the claim that AI-speed attacks require real-time prevention |
| Relies heavily on response after detection | Targets AI governance, threat prevention, integrations and endpoint intelligence |
Ent Seed Funding
Primary Sources & Disclosures
Written by
XOOMAR Insights Team
Research and Editorial Desk
The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.










