Zenity's $125M B-Round Is Not a Security Deal — It's a Sovereign Infrastructure Play for the Agent Economy
HOOK: The Data Tape Nobody Read Correctly
Read the raw tape. Not the press release. The tape says: $125 million. Series B. Three strategic investors. Zero American marquee VC.
SoftBank. Hitachi. LG.
Japan. Japan. Korea.
The A-round closed in January 2024 at $16.5 million, led by Insight Partners. Eighteen months later, the step-up is 7.6x. In a funding environment where global cybersecurity venture capital contracted for two consecutive years, where late-stage security startups cut burn and prayed for bridge rounds, Zenity printed a nine-figure check. The market was not generous. Something else happened.
Here is the detail the fast-takes buried: the investors are not financial sponsors. They are industrial operators. Hitachi runs industrial control systems across energy, rail, and manufacturing. LG ships AI agents into millions of consumer households through ThinQ. SoftBank is the single largest allocator of capital into AI infrastructure outside the United States. This is not a portfolio construction. This is a supply chain.
And the absence is louder than the presence. No Andreessen. No Sequoia. No Accel. In a category that supposedly represents the next $100 billion security market, Silicon Valley's top-tier platforms are standing on the sidewalk. Either they passed, or they were not invited. Both explanations carry information. I will unpack both.
The core insight: Zenity's $125 million is not a growth round. It is the purchase price for a seat at the table where the Agent economy's rulebook gets written — and the buyers are intentionally non-American.
The rest of this analysis is organized as a market surveillance report. We will move through the technical substrate, the commercial mechanics, the industrial impact surface, the competitive geometry, the valuation arithmetic, and the governance blind spots. Each section ends with the questions investors should be asking but are not.
Speed is the only currency that never depreciates. Let's move.
CONTEXT: From Citizen Developers to Autonomous Actors
Zenity was founded in 2021 in Israel. The original thesis was narrow: secure low-code and no-code applications. The security industry had ignored the citizen developer wave — business users building internal tools on Microsoft Power Apps, ServiceNow, and similar platforms without IT oversight. Zenity built discovery, governance, and protection for that shadow application layer.
That positioning looks quaint now. But it was the correct entry ticket.
Between 2024 and 2025, the threat surface mutated. Microsoft Copilot Studio, Google Vertex AI Agent Builder, and OpenAI's AgentKit put agent construction in the hands of the same business users who had been building shadow apps. The difference is the output. A low-code app executes a deterministic workflow. An AI agent makes autonomous decisions across tools, data sources, and external APIs. The blast radius is no longer a misconfigured spreadsheet. It is an autonomous actor moving capital, communicating with customers, and modifying production systems.
This is the structural break. Traditional network security monitored human users. The new reality requires monitoring machine actors — agents with credentials, permissions, and the capacity to chain actions. The security perimeter is not at the firewall. It is at the behavior layer.
The Gartner projection frames the urgency: by 2028, at least 15% of daily work decisions will be made by agentic AI systems autonomously. In 2024, that figure was under 1%. This is not a linear adoption curve. It is a hockey stick, and the security layer is the bottleneck constraining the slope.
Zenity's platform addresses three functional domains that emerged as the industry's working taxonomy for agent security: Machine Access and Behavior Protection (MAAP), AI Security Posture Management (AI-SPM), and AI Security Services and Risk Management (AI-SSRM). These are not marketing categories. They map to distinct failure modes. MAAP addresses what an agent is allowed to do. AI-SPM addresses how an agent's configuration drifts from policy. AI-SSRM addresses the audit trail when something goes wrong.
The bear market context matters here. In a bull narrative, this is a growth story about capturing a new category. In the current tape, it is a survival story about which institutions will control the plumbing beneath the agent economy. Bear markets do not reward speculation. They reward infrastructure. Zenity just raised infrastructure capital.
Resilience is built in the quiet before the crash. The crash for unguarded agent deployment is coming. Someone will sell the insurance.
CORE: The Technical Stack and the Real Moat
The Behavior-Layer Thesis
Here is the technical read. Zenity's value is not in foundational model capability. It does not train a frontier LLM. It does not run a massive inference cluster. Its technological center of gravity is the collection, normalization, and real-time analysis of agent behavioral telemetry.
The platform ingests API call logs, permission mutations, data access patterns, and tool-invocation sequences. It builds a behavioral baseline for every agent identity. It flags deviations. This is fundamentally a data engineering problem overlaid with an anomaly-detection layer. The defensibility does not come from a proprietary algorithm. It comes from the accumulated baseline corpus.
Let me be direct about what this means for competitive durability. An agent behavior baseline is not scrapable from the public internet. It is built inside enterprise environments, through deep integration, over months. The richer the corpus of normal agent behavior, the more accurate the anomaly detection. This creates a flywheel: each deployed customer improves detection for every other customer. But it also creates a dependency. Zenity needs customer environments to generate the data that makes its product defensible. That is why the balance sheet matters. Enterprises do not hand behavioral telemetry to a startup they suspect might die in eighteen months.
This is the hidden logic of the $125 million. It is not a product milestone. It is a balance-sheet-as-trust-certificate maneuver.
The Detection Rulebook, Not the Algorithm
My read on the actual technical moat: it is not the model. It is the rule library and the scenario coverage.
Agent security detection is fundamentally different from traditional endpoint detection. An agent's action chain — calling an internal API, reading a database, sending an email, invoking another agent — has semantic meaning. Detection requires understanding the intent and the legitimacy of a sequence, not just pattern-matching malicious signatures. This places enormous weight on the quality of the detection rulebook and the coverage of playbooks.
Consider the threat categories. A compromised agent that exfiltrates customer records. A misconfigured agent that escalates privileges through an inherited token. A prompt-injection attack that induces an agent to execute a transfer. A malicious agent that impersonates a legitimate service. Each of these requires a different detection logic. The platform that covers the most scenarios with the fewest false positives wins the enterprise procurement.
Here is the unresolved question. Zenity has not publicly disclosed its detection accuracy or false-positive rates. In enterprise security procurement, false positives are the silent killer of deployments. A security tool that fires 200 alerts per day gets muted by the SOC team within a week. The vendor's technology reads well in marketing collateral. The operational reality is brutal. Without published accuracy benchmarks validated by independent third parties, the technical superiority claim remains unproven.
Based on my market surveillance work, where I watch detection and alerting systems across cross-border capital flows, I can tell you this: synthetic alert fatigue is the primary failure mode of new security tooling. Every security startup promises precision. Few deliver operational signal-to-noise ratios that the analyst team will tolerate. This is the technical metric I am watching for Zenity. When they publish a false-positive benchmark, the market will have its first real data point.
The Multi-Agent Blind Spot
The most consequential technical gap in the current agent security narrative is agent-to-agent communication. Agents are increasingly invoking other agents. OpenAI's agent protocols, Microsoft's AutoGen, CrewAI's multi-agent orchestration — the architecture of the agent economy is inherently multi-agent. The security implications are poorly understood and barely covered.
A single compromised agent can propagate malicious instructions to downstream agents. The cascade potential is systemic. Traditional security models assume discrete asset boundaries. The multi-agent topology breaks that assumption. An agent call graph can resemble a contagion network.
Does Zenity's platform map agent-to-agent communication graphs? Does it model trust across agent chains? The public information is silent on this. The risk is that the industry's first-generation agent security tools are built for the single-agent world, and the multi-agent world arrives faster than the tooling evolves. This is exactly the pattern I observed in the Terra/Luna collapse — the interconnectedness of DeFi protocols turned a single stablecoin depeg into systemic contagion. The infrastructure was not designed for the dependency web. The agent economy is building the same architecture.
The Industrial Extension Signal
The participation of Hitachi and LG is a technical signal disguised as a check. Hitachi operates in OT environments — industrial control systems, rail signaling, energy grid management. LG deploys agents in consumer electronics and smart home environments. Both are contexts where the security perimeter is not a server rack. It is a physical system.
If Zenity's platform is being extended to OT and IoT agent security, the technical requirements shift. Edge deployment, latency constraints, firmware-level integration, protocol diversity. This is a fundamentally harder engineering problem than SaaS agent monitoring. The inference is that Zenity's roadmap includes an edge or gateway component for industrial and embedded agent environments. The investment dollars from Hitachi and LG are effectively a down payment on a technical road map extension.
This would position Zenity in a competitive corridor that the American platform players have generally neglected. CrowdStrike and Palo Alto Networks focus on the enterprise endpoint and cloud workloads. The industrial agent security layer is a white space.
CORE: The Commercial Mechanics — Selling Insurance for Irreversible Deployments
The Business Model as Underwriting
Strip away the security language and examine the commercial essence. Zenity sells insurance. Not actuarial insurance in the legal sense, but economic insurance. Enterprises are deploying agents. Agent deployment, once embedded in workflows and granted credentials, is effectively irreversible in the short term. Rollback is costly. The enterprise needs a counterparty that absorbs the tail risk of autonomous action. Zenity is that counterparty — a monitoring and enforcement layer that reduces the probability and magnitude of agent-caused losses.
This framing explains the pricing logic. Security tooling historically priced as a per-seat cost — a headcount tax. Agent security disrupts that model. The natural pricing unit is the agent itself. Per-agent pricing transforms the enterprise cost structure from a fixed security staff expense into a variable cost tied to automation volume. If Zenity introduces per-agent consumption pricing, it becomes a direct beneficiary of agent adoption — every new agent is incremental revenue automatically.
I consider this the sleeper commercial insight of the entire funding event. The market reads Zenity as a security company. The correct read is an infrastructure tollbooth that charges per machine actor.
The ARR and Valuation Inference
Let's do the arithmetic. Public information does not disclose Zenity's ARR. We work with inference.
Public security SaaS companies at the growth stage typically command 10-15x forward ARR multiples in the current environment. Applying a 12x multiple to a $125 million raise implies a post-money valuation in the $600 million to $1 billion range, supporting an ARR estimate of $60-85 million. That is high for a company eighteen months past a $16.5 million A-round. A more conservative read: ARR is in the $20-30 million range, and the round embeds a meaningful AI-category premium, pushing the effective multiple above 20x.
The truth matters for the next buyer. At 20x-plus for a company with a credible trajectory, the valuation is a bet on the category's compound growth, not on current fundamentals. The enterprise security market has historically punished high multiple entrants when the growth narrative cracked. The 2021-2022 crop of high-multiple security SaaS saw multiples compress by 50-70%.
Here is the risk signal from my vantage point: the funding round's announcement emphasized the investor lineup, not product milestones. In my surveillance work, I see this pattern recur at the top of the cycle. When a company leads with its cap table rather than its metrics, the metrics are insufficient to speak for themselves.
The hidden variable is secondary volume. In large security B-rounds, it is common for early investors to sell a portion of their stake — de-risking while the valuation is attractive. If the round includes significant secondary share purchases, it signals that early backers estimate the exit window at 3-4 years. The strategic question is whether the exit path is a public listing or a trade sale. Given the investor composition, a strategic sale into the SoftBank ecosystem or an industrial conglomerate is a serious possibility.
The SoftBank Channel Effect
Do not underestimate the distribution implications of SoftBank's participation.
SoftBank is not just an investor. It is a channel. The SoftBank group maintains deep relationships with enterprise customers across Japan and, through its portfolio companies, across Asia. If Zenity is packaged into SoftBank's enterprise AI solution bundles, the company's Japanese revenue trajectory changes entirely. This is the CrowdStrike-AWS dynamic. Platform distribution accelerates independent product adoption.
The Japanese angle is essential. Japan's industrial digitization push, combined with the national AI strategy, positions the country as an early adopter of agentic workflows. Hitachi's involvement adds credibility in the industrial segment.
The Pricing Anchor
CrowdStrike and Zscaler enterprise-level contracts typically range from $50,000 to $200,000 per year. Zenity, positioning as agent security infrastructure, likely anchors between $100,000 and $300,000 per year for mid-market to enterprise deployments. The commercial risk is that agent security budgets are not yet a distinct line item. They compete with existing security spend. Selling a new tool requires either budget expansion or cannibalization of a legacy line.
In the current bear market procurement environment, CFOs approve new security spending only in the presence of acute, quantified risk. Zenity's sales cycle depends on the customer recognizing that unmonitored agent deployment is a liability event waiting to happen. That recognition is asymmetric — it occurs after a public incident. Until a major enterprise suffers a high-profile agent-caused loss, the budget friction will persist.
CORE: The Industrial Impact — The Agent Security Enabling Layer
The Last-Mile Trust Bottleneck
The AI industry has solved, at least partially, the model capability problem. The bottleneck for enterprise agent deployment is no longer accuracy. It is trust and governance.
The Menlo Ventures enterprise AI report identified security concern as the second-largest barrier to expanded agent usage, trailing only data privacy. Capital is flowing to the blocker. The $125 million round is a direct response to a systemic constraint: enterprises will not move agents into high-stakes workflows — customer service, supply chain orchestration, financial transactions — without a credible governance layer.
This is the enabling-layer thesis. Agent security is not a vertical application. It is horizontal infrastructure upon which the agent economy runs. Every agent deployment in every industry generates the same security requirements. The company that establishes itself as the default layer captures exponential demand as the agent population grows.
The Market Sizing Arithmetic
Let's build the TAM estimate with transparent assumptions.
Gartner projects agentic AI to automate 15% of daily work decisions by 2028. Estimates for global agentic AI spending by 2030 range from $1.5 trillion to $2 trillion annually. Security budgets typically represent 5-10% of AI project spend. That yields an addressable market of $75-200 billion per year by the end of the decade.
Even at the conservative end of that range, this is a market larger than the entire current endpoint security industry. The resource allocation is justified by the scale of the prize.
The funding winter creates a divergence. Traditional network security has matured into single-digit growth. AI-native security is compounding above 50% annually. Capital reallocation follows the growth differential. Zenity's clean raise accelerates the category — every security startup with an AI angle will now show this round to justify a higher valuation.
The Regulatory Tailwind
The global regulatory environment is a hidden accelerant.
The EU AI Act imposes transparency and human oversight requirements on high-risk AI systems. China's AI content labeling regulations mandate disclosure. The NIST AI Risk Management Framework is being adopted by US enterprises as a voluntary baseline. Every regulation creates the same commercial requirement: evidence. Enterprises must demonstrate they can monitor, audit, and explain agent behavior.
Zenity's audit-trail and behavioral-monitoring capabilities map directly to regulatory compliance obligations. The enterprise does not need to buy a security product. It needs to pass a compliance review. The distinction matters. Compliance-driven procurement is less price sensitive and more defensible against budget cuts.
The Geopolitical Undercurrent
The investor composition carries an understated geopolitical signal.
The three lead investors are all non-American. In the context of global digital sovereignty initiatives — Europe's push for independent cloud infrastructure, Japan's strategic autonomy in digital systems, Korea's digital rights framework — the choice of an Israeli-founded security company backed by Japanese and Korean industrial capital is conspicuous.
Enterprises in Asia Pacific are increasingly evaluating whether American security infrastructure is structurally aligned with their geopolitical interests. The pressure does not come from an overt decision to exclude American suppliers. It comes from a preference for vendors whose ownership structure does not create jurisdictional conflicts. Zenity's investor base embeds the company in the Asian industrial ecosystem in a way that a purely American VC-backed startup cannot replicate.
The edge lies in the data others ignore. The data point being ignored is the cap table's geography.
CORE: The Competitive Geometry — A Three-Tier War
The Three Competitive Layers
The agent security market is forming into three competitive tiers.
Tier One: Pure-play agent security startups. Zenity, Legit Security, and a handful of others. These companies are singularly focused on the agent problem. Their advantage is focus and speed. Their disadvantage is scale and channel.
Tier Two: Platform security giants. CrowdStrike, Palo Alto Networks, Zscaler. These companies are layering AI security posture management onto their existing platforms. They possess established enterprise relationships. More importantly, they possess existing agents — the sales teams, the integration ecosystems, the compliance certifications. Their strategic play is to bundle agent security as a module within a broader platform, pricing it as an affordable add-on.
Tier Three: Cloud providers. Microsoft, Google, Amazon. Microsoft's Purview and Defender for AI, Google's Security AI Workbench. The cloud giants have the deepest infrastructure integration points. They control the runtimes where agents execute. Their security tools are preinstalled by default. The independent security vendor's existential risk is that the cloud provider ships adequate native security, and the enterprise never purchases a third-party tool.
The platform collision is the defining structural dynamic of the next three years. Independent security companies live and die by establishing a category wedge before the platform vendors absorb the functionality.
The Wiz Precedent
Consider the Wiz template. Wiz entered the cloud security market as a pure-play specialist. It grew to a $23 billion valuation in four years before Google's acquisition. The path relied on a security category being big enough and distinct enough to justify independent classification — before the incumbents could bundle the functionality.
The acquisition outcome is the relevant template for Zenity's investors. A $125 million B-round at a reported valuation near $1 billion sets up a potential exit in the $1.5-3 billion range within 2-3 years if the platform adoption path plays out. The strategic acquirer could be a major security platform acquiring category entry, a cloud provider filling a gap, or an industrial player seeking an in-house capability.
The CrowdStrike Outage Opening
The July 2024 CrowdStrike global outage — which disrupted millions of endpoints — created a structural opening for security startups. Enterprise procurement teams reassessed the risk of single-platform dependence. The doctrine of a single dominant security provider went out of fashion. Multi-vendor strategies gained budget allocation.
Zenity's positioning benefits from this mood. A pure-play agent security vendor does not threaten the incumbent relationship. It is complementary. The enterprise can maintain CrowdStrike for endpoint, and add Zenity for the agent layer without a platform migration.
The Open-Source Compression Risk
Open-source tooling is entering the agent security space. OpenAI's agent safety evaluation tools, LangChain's LangSmith observability features, Meta's Purple Llama security benchmarks — the bottom layer of agent security is being commoditized.
The strategic implication: Zenity's differentiation cannot remain at the detection layer. It must move up the stack to compliance reporting, enterprise integration, workflow orchestration, and the operational services layer. If the detection capability converges toward free, the commercial value shifts to the enterprise workload around it.
This is a brutal competitive dynamic. The open-source foundation improves, and the commercial vendor's differentiation compresses to brand, integration, and support. The companies that win are those that build the enterprise-grade wrapper before the open-source alternative matures.
Based on my audit experience, where I examined compliance infrastructure across five non-US exchanges for MiCA readiness, I observed exactly this pattern. The protocol and tooling layers commoditized quickly. The durable value was in the compliance wrapper — the reporting, the audit trails, the certifications. The same logic applies to agent security.
CORE: The Valuation and Investment Logic — A Cap Table Reading
The Missing American VC
Let's return to the absent American VC.
Reading one: Zenity deliberately structured the round with strategic investors rather than financial sponsors. Industrial capital brings relationships, distribution, and channel access in the Asian market. American VC would bring valuation maximization and M&A connections. Zenity chose growth infrastructure over valuation optics.
Reading two: American VCs passed, or the valuation exceeded their internal thresholds.
The second reading is the bearish interpretation, and it must be weighed seriously. American security VCs are the most sophisticated evaluators of security technology in the world. Their absence from the round could indicate skepticism about the company's US market traction, the competitive position, or the valuation.
In my surveillance work, I have learned to treat absence as data. The American security investment community has a strong consensus engine. When a marquee round closes without their participation, the marginal investor's due diligence becomes the dispositive test.
The LG Technology Ventures Nuance
LG's participation deserves particular scrutiny. LG Technology Ventures, the firm's venture arm, typically invests where a technical synergy with LG's product roadmap exists. The consumer electronics angle is not incidental.
LG is deploying AI agents into the home. The ThinQ platform controls appliances, manages connectivity, and increasingly makes autonomous decisions about home operations. The consumer-facing agent is the largest untested deployment surface in the agent economy. The investor hypothesis: LG's strategic investment indicates a joint development effort on consumer IoT agent security. If Zenity's platform extends to embedded consumer environments, the market expansion potential is dramatic — but the technical complexity and privacy requirements are disproportionate.
A consumer agent security breach involves not just data loss but physical safety within the home. The liability regime is entirely different from the enterprise context. Zenity's consumer-jurisdiction product design remains unproven.
The Insurance Market Precursor
The most speculative and potentially most significant angle is the insurance derivative.
The cyber insurance market emerged as an institutional response to the proliferation of cyber risk. The agent economy is producing a new risk class: principal-agent liability, automated decision damages, algorithmic negligence. Insurance products require actuarial data. Actuarial data requires monitoring infrastructure. The security platform that generates the behavioral data sets becomes the actuarial foundation for agent liability insurance.
Zenity, by being the surveillance layer for agent behavior, is positioned to become the data source that underwriters rely on. This is not a security business. It is the collection infrastructure for a nascent insurance industry. LG's and Hitachi's participation could represent a forward position on this derivative market.
This reads as speculative at present. I mark the confidence level as moderate at best. But the pattern echoes the early days of cyber insurance, where the security vendors that controlled telemetry data became the most valuable partners of the underwriters.

The Regulatory Comparison — The MiCA Lesson
I have written extensively about MiCA's impact on the European stablecoin market. My comparative audit of five non-US exchanges found a 12% discrepancy in reserve transparency reporting. The pattern: regulation rewards well-capitalized entities and eliminates small competitors who cannot absorb compliance costs.
The same dynamic applies to agent security. The EU AI Act compliance burden will be substantial — documentation, risk management processes, incident reporting mechanisms, continuous monitoring. Only vendors with significant war chests will be able to build and maintain compliant platforms across the EU, Japan, Korea, and the United States simultaneously. Zenity's $125 million is a compliance war chest. The funding is the barrier to entry working exactly as the incumbents would want.
Small agent security startups will struggle to meet multi-jurisdictional compliance demands. The category will consolidate toward the well-funded. This is not an organic market evolution. It is a regulatory subsidy to the companies that raised early.
CONTRARIAN: The Blind Spots No One Is Discussing
The Legitimization Loop
The most uncomfortable truth about the agent security narrative is that it functions as a legitimization engine.
The industry's central pitch is the following: agents will become fully autonomous; therefore, comprehensive security is essential; therefore, enterprises should deploy agents rapidly with our security platform. The security vendor's commercial incentive would not accelerate agent deployment without the agent security layer — but it also accelerates agent deployment with the agent security layer. The security narrative does not constrain the agent economy. It enables it.
The question that should be asked: is it socially optimal for every enterprise to accelerate autonomous agent deployment at this pace? The security industry has a structural conflict of interest. It profits not only from making the agent economy safe, but from making the agent economy bigger. A faster, larger, riskier deployment generates more security spend.
The Surveillance Overhang
Agent security requires monitoring agent interactions with employees and users. The enterprise's surveillance capacity expands to the entire reasoning and action trail of the agent — which means the records of human interactions with agents become visible and auditable.
The pattern is familiar. What begins as a security requirement becomes a management precedent. The tool that monitors agents for safety can be repurposed to monitor employees for productivity or loyalty. Zenity's data collection practices, retention policies, and access controls are the determining factors. Public information does not disclose whether the platform implements data minimization as a default or an opt-in feature.
The Permission Inheritance Question
When an agent acts, it does so with permissions. The unresolved design question is whether the agent inherits the full permission set of its human creator or operates under an independent least-privilege model.
The decision is not merely technical. It shapes organizational power. An agent that inherits full employee permissions has effectively the same authority as the employee, but with the capacity for parallel execution and scale. Errors multiply. An agent operating under least privilege is structurally safer but requires the organization to redesign its authorization architecture.
The security vendor's default settings will shape which of these regimes becomes the de facto standard. If Zenity's platform defaults to delegation, it optimizes for ease of deployment. If it defaults to least privilege, it optimizes for safety at the cost of friction. The default choice is a normative decision presented as a technical configuration.
The NFT blue-chip lesson applies here. The market once assumed that labels — BAYC, Azuki — created durable value. When liquidity dried up, the labels dissolved. The agent security category's "leading startup" label is similarly fragile. It will survive until the platform giants package the capability into a bundle at a fraction of the price. Zenity's true defense is not the label. It is the data corpus, the enterprise relationships, and the behavioral baselines — the infrastructure that cannot be replicated in a quarter.
Chaos is just data waiting for a pattern. The agent economy is generating chaos in real time. The market will pay for the pattern. The question is whether the pattern belongs to an independent infrastructure company or a platform's feature set.
THE GOVERNANCE GAP: Agent-to-Agent Cascade Liability
No analysis of this funding is complete without addressing the liability framework gap.
When an agent causes harm — a data breach, an erroneous financial transaction, a defamatory response — legal attribution defaults to the deploying enterprise. The enterprise carries the full liability regardless of the agent's autonomy level. The security platform provides evidence and monitoring capabilities, but it does not solve the fundamental attribution problem.
The governance gap widens in multi-agent scenarios. If Agent A instructs Agent B, which causes the loss, who is liable? The creator of Agent A? The operator of Agent B? The platform that enabled the interaction? There is no settled legal framework. Corporate counsel is unprepared. Insurers have no underwriting standard.
This creates an urgent market opportunity: an "agent liability" regime backed by auditable behavior trails. This is the report every procurement officer should be requesting. The security platform that validates the agent's action chain up to the accountability boundary becomes an essential risk-management tool. Zenity's forensic capability, if it exists, is the relevant differentiator. If it does not yet exist, that is the development spending priority.
TAKEAWAY: The 12-Month Rulebook Race
Read the tape. $125 million. Three Asian industrial investors. A category at its definitional moment. A bear market demanding survival-grade infrastructure.
The coming 12 months determine the category's shape. I am watching three specific signals.
First: Does Zenity publish a client-validated agent security benchmark report? This is the standard-setting move. The company that defines the measurement framework controls the procurement criteria.
Second: Do the platform giants bundle agent security as a free module? CrowdStrike's and Palo Alto's pricing decisions are the existential threat. If the module lands at zero marginal cost, independent pricing collapses.
Third: Does the first agent liability insurance product reach the market? The insurance arrival is the category maturation signal. It will confirm that security telemetry has achieved underwriting-grade reliability.
The question for the market: will Zenity be the Wiz of the agent security layer, or will its capability become a footnoted feature in a platform's annual release? The valuation math barely matters. The category definition matters. The non-American strategic capital is a deliberate bet that the agent economy's security infrastructure will not be owned by the American platform oligopoly.
Speed is the only currency that never depreciates. Zenity bought speed. The question is whether they bought it in time.
The next surveillance cycle will tell. I will be watching the data.";Core