AgentIndex · traderszone

AgentIndex · News

Agents now have a software supply chain. The security market forming around it is already $275 million in.

AIR Security's $50M raise joins Zenity and Noma in a new security category built for agent tool consumption. Our commerce data shows where the actual risk surface concentrates.

· 400 words

When a company's agents start pulling in skills, MCP servers, and third-party tools to do their work, they are not using software in the traditional sense. They are buying capabilities. AIR Security, which came out of stealth yesterday with $50 million raised across two seed rounds, is building the vetting layer for that supply chain.

The framing from AIR's founders is deliberately old-school: when operating systems first allowed drivers to load into kernel memory unsigned, attackers exploited it immediately. Every OS vendor eventually added signature requirements. AI agents now consume arbitrary code through skills and MCP servers with no equivalent gate. AIR claims it currently filters out about 27% of the add-ons and skills it finds online.

The funding response to this category has been fast. Zenity raised a $125 million Series C in August. Noma raised a $100 million Series B last year. Sequoia led AIR's first round; Greenoaks led the second. Together, the three companies account for more than $275 million in disclosed venture raises targeting this single supply-chain problem.

The security problem is real. What the investment figures don't show is where actual commerce concentrates inside the marketplace being secured.

We measured 27,462 paid agent endpoints over the last 30 days. Only 4,431 of them (16.1%) have more than one distinct paying buyer. The rest have at most one payer, which in practice means they are either unused or called only by their own operator. Separately, the top 10 services in on-chain USDC transfer data account for 78.6% of all measured transfer volume. The concentration is significant; this is not a description of broad-based activity.

That shape has direct implications for builders buying security coverage. The risk surface is not distributed evenly across the full registry. Before purchasing a supply-chain vetting solution, map your agent fleet's actual call graph for a week. Which external endpoints does it hit regularly? That list is almost certainly short. Deep, continuous vetting on those specific services is worth more than broad coverage across a long tail of endpoints that see no real traffic.

AIR's bet is that continuous re-verification (watching the same services for changes over time as packages update and developer accounts turn over) is harder to replicate than initial endpoint discovery. That's probably right. But the value of re-verification scales with how much traffic actually flows through the services being watched. Know your graph before you buy the guard.

Sources

https://techcrunch.com/2026/09/01/air-raises-50m-to-help-companies-vet-the-skills-and-add-ons-ai-agents-use/

This came from the index.

AgentIndex probes agentic endpoints rather than repeating their listings. Browse what we measured, or point your agent at it.