Skip to content
StartupXO Startup ideas, news, talent
Funding Published: 2026-09-29 5 min read

Nvidia Open-Sourced the Agent Sandbox. The Open Gap Is Agents No One Tracks

In short

On Sept. 28 Nvidia open-sourced OpenShell to fence in AI agents. A day later Reco raised $55M to find agents companies didn't know they had.

Mr. Latte's take

Containing agents inside a sandbox is turning into shared infrastructure, set by a chipmaker and the large security vendors that signed on with it. Reco's numbers point at the part that sits outside that fence: agents built inside SaaS apps, sometimes by people who have since left, never pass through a company's sandbox at all. A new agent security startup has a better shot finding and mapping those agents than rebuilding a runtime that is now free.

Nvidia Shipped the Layer That Fences Agents In

On Sept. 28, Nvidia announced its Open Agent Safety Platform, meant to govern AI agents from testing through deployment. It has two main pieces. OpenShell is open-source runtime software that runs on CPUs and draws the boundary around what an autonomous agent can reach and do. Sentry is a reference system design: an out-of-band watchdog that runs on BlueField-4 DPUs, separate from the CPU and GPU, and keeps watching agent behavior.

According to SecurityWeek, OpenShell has three parts: a gateway that manages the lifecycles and policies of many sandboxes, a sandbox that applies kernel-level controls to filesystem and process activity, and a supervisor paired with each sandbox that checks outbound requests against policy. If an agent tries to move outside its software boundary, Sentry quarantines and stops it in silicon within milliseconds. OpenShell is out at version 0.1.0 through Nvidia's developer pages and GitHub, and Nvidia says it can be extended to Arm and Intel platforms.

More than 100 organizations are working with the technology. Security vendors CrowdStrike, Palo Alto Networks and Cisco are on the list, along with Anthropic, Microsoft, Salesforce, SAP and ServiceNow; Citi and JPMorganChase are collaborating from finance. Nvidia's case for the product rests on a pattern it sees across recent incidents: the agent got around security controls at the application layer in order to finish its task. Hence, Nvidia argues, enterprises need a boundary they can enforce outside the model and the agent harness.

21,000 Agents One Fortune 100 Company Didn't Know About

The next day, Sept. 29, New York-based Reco said it had raised $55 million, extending the $30 million Series B it announced in February. AT&T, a customer, invested through its venture arm, joined by Forestay and Quadrille Capital. Reco has now raised $140 million in total and says the money will go to hiring, sales, partnerships and customer support.

Until last year Reco mostly sold software to map and secure SaaS and AI platforms. It has since rebuilt the product around a "context graph" that links agents to apps, people, accounts and permissions, so a security team can see what an agent can reach and cut access it doesn't need.

CEO Ofer Klein told TechCrunch the biggest change of the past year is that companies now build and deploy agents faster than they can keep track of them. At one Fortune 100 customer, Reco found 21,000 agents the company didn't know about. At a large financial services customer, Reco says it identified an agent set up by a former employee that could access Salesforce and send that data to a domain the company couldn't see.

Klein put annual recurring revenue in the "double-digit millions of dollars" and said he expects it to triple this year. Reco has more than 100 customers, with financial services about 40% of the business. He would only say the valuation has more than doubled since February. Reco integrates with more than 280 apps, uses browser and network signals to find agents running outside the apps it connects to, and can inspect prompts and tool calls.

Two Dozen Vendors, Similar Promises

TechCrunch counted at least two dozen companies selling some form of AI agent security from public Crunchbase and PitchBook profiles alone. Some vet the tools agents use, some control what data agents can reach, CrowdStrike builds detection and response on the devices agents run on, and others hunt for unapproved AI use. The products differ, TechCrunch noted, but the pitches of knowledge graphs, continuous monitoring, runtime security, tool access and MCP vetting sound much alike.

The same piece carries the demand signals. HiddenLayer CEO Chris Sestito said more than 50 of his customers have agents in production touching critical systems and sensitive assets. Cymphony said it found about 85,000 files at one U.S. public company that had become reachable by AI tools and agents.

Nvidia's release changes one side of this market. Standing up sandboxes, blocking file and process activity at the kernel level, and checking outbound requests against policy overlaps with much of what startups have been selling as runtime security. A baseline version of that is now open source, and the largest security vendors are building on it. Any team selling the same capability now has to explain what it does better than the free baseline.

The Distance Between Version 0.1.0 and BlueField-4

That layer will not land in every enterprise tomorrow. OpenShell is at 0.1.0, and Nvidia's own release closes with a caveat that many of the products and features described remain at various stages and will be offered when and if available. Sentry's in-silicon watchdog needs a BlueField-4 DPU. SecurityWeek notes that every compute tray in an Nvidia Vera Rubin POD includes one, which means hardware-level policing arrives first in large data centers built on that gear.

The platforms are also moving toward visibility. Salesforce has wired OpenShell into Slack, so teams can review agent activity and audit events there and approve or reject an agent's request for more permissions. But what that view shows are agents running inside OpenShell. The boundary only covers agents a company chooses to run in its sandboxes. An agent a former employee built inside Salesforce never went through one. Containing agents and finding every agent a company has are separate problems.

The Question Agent Vendors Will Hear First

Founders in agent security should be able to say in one line which layer their product sits on. If it is sandboxing and runtime control, they are now competing with Nvidia's open source and the big security vendors riding on it. If it is discovering unknown agents and cleaning up their permissions, they are up against the ground Reco has already staked out with 280 integrations and customer case studies. Either way, "knowledge graph" and "runtime security" on a slide no longer set a company apart from two dozen others.

Teams selling agents into enterprises have work too. Before approving an agent, customer security teams will ask which apps and data it touches, who created it and who can shut it off. With open baselines like OpenShell, there is starting to be a standard shape for those answers. Declaring an agent's access scope up front, and letting the customer inspect and narrow it, can shave time off security review.

One more detail from Reco's round: AT&T, a customer, is in it. In a market where more than two dozen vendors make similar promises, a customer that used the product first and then wrote a check is evidence a competitor cannot copy with better wording.

#AI Agents#Security#Nvidia#Funding#Open Source

Listed companies in this story

See the price and money-flow signals on the InverseOne stock page.