The short version: on August 7, 2026, Israeli startup Arrakis Security left stealth with an $8M seed led by Hetz Ventures, built to solve what it calls the visibility illusion — you know an AI agent is running, but you have almost no idea what it's doing. The platform discovers every agent touching your systems, profiles how each normally behaves, monitors actions in real time, and can kill one that deviates. The round is early; the gap it names is not.
| Question the raise answers | Answer |
|---|---|
| Is runtime agent governance a real category? | Yes — a $125M Series C and a fresh seed in one month |
| Does my model vendor cover it? | No — they secure the model, not what your agent does with a tool |
| What's the minimum viable control? | Discover + profile + log + a kill switch on high-blast-radius tool calls |
The round, and why the people are the story#
Arrakis Security raised $8M at seed, led by Hetz Ventures, with an angel list that reads like a security-operator reunion: ElevenLabs CEO Mati Staniszewski, Torq CEO Ofer Smadari, Pentera founder and CEO Amitai Ratzon, and several senior Palantir executives (CTech, Dealroom). The three founders — Tal Baron, Omer Efrat, and Ron Shani — are veterans of Torq (security automation) and Palantir (data platforms enterprises actually run production on).
Read the cap table, not just the number. When the angels are the people who built the last generation of security-operations tooling, the bet isn't "AI is exciting" — it's "we've run this movie before, and the missing control is obvious to anyone who's operated at scale." That's a different, more grounded signal than a generalist AI seed.
One housekeeping note, because the search results collide: there are two companies named Arrakis in the news this summer. This is Arrakis Security, the agent-governance one. A separate, London-based Arrakis raised roughly $38M to push AI agents into industrial operations — opposite side of the same trend, different company (RuntimeWire).
The 'visibility illusion' is the phrase worth stealing#
Arrakis's framing is that organizations suffer a visibility illusion: they know an agent exists — it's in a slide, it has a name, someone owns it — but they have no detailed, live picture of what it's doing action to action. The platform's answer is four jobs, and they map cleanly onto how security teams already think:
- Discover the agents, copilots, and automations already running against your systems.
- Profile each one — learn what its normal behavior looks like.
- Monitor activity in real time and detect actions that deviate from that baseline.
- Kill — halt an agent mid-action when it steps outside the profile.
You cannot govern what you cannot see, and most teams have far more agents acting on their data than they can name.
If that sounds familiar, it should. It's the same shape Zenity raised $125M to build — understand intent, then allow, modify, or block the action — one rung earlier on the funding ladder. And it's the same category we first flagged when agent security became a funded layer and when a distinct set of players staked out the runtime-governance category itself.
Why a seed matters because Zenity already raised nine figures#
A category with exactly one well-funded player is a company. A category that pulls a $125M Series C and a fresh $8M seed in the same month is a market — one investors believe is big enough to hold several bets at different stages. Arrakis coming out of stealth this close behind Zenity, staffed by veteran operators, is the clearest signal yet that runtime agent governance is durable infrastructure to plan around, not a fad to wait out.
That matters even if you'll never buy either product. The direction of capital tells a founder where the un-owned gaps in the stack are hardening into paid layers — and this one sits exactly where your own agents already operate without a net.
What a team of one does this week — the DIY version of all four jobs#
You can't buy an enterprise runtime-governance platform as a solo founder, and you don't need to in order to close the worst of the gap. Every one of Arrakis's four jobs has a cheap, hand-built version:
- Discover → a list. Write down every agent, copilot, and script wired to a model that can touch your systems: its owner, and the exact tools and scopes it can call. A spreadsheet beats nothing, and the count will surprise you.
- Profile → a one-line spec per agent. For each agent, state the tools it's allowed to touch and a hard ceiling on each (spend, rows, emails). A baseline you wrote is auditable; a learned one you can't inspect is just another black box.
- Monitor → structured logs. Log every tool call with its arguments, keyed to an agent identity — not a shared service account. Deviation you never recorded is deviation you can never prove or reverse. (This is also why agent identity itself just drew a $60M seed.)
- Kill → a deny-by-default gate and a circuit breaker. Put high-blast-radius tools — payments, deletes, outbound email — behind an allowlist that requires a human, and a breaker that trips on abnormal volume. The stop has to live outside the model, because the model can be talked into wanting the wrong thing.
None of that is exotic. It's the same zero-trust posture for agents the funded players are productizing — and it's the exact posture that would have blunted this month's ChainDrop worm, which hunted AI-coding-agent credentials specifically. Arrakis's $8M says a category is forming. Your afternoon with a log and an allowlist says you don't have to wait for it.



