Why We Built Ent: Rethinking the Architecture that Makes Prevention Possible
$100 million seed round backs the industry’s first intent-aware Workspace Security platform.
For most of the last decade, security vendors gave up on prevention. The industry concluded that breaches were inevitable and poured its energy into detection and response. Logs were collected across every kind of telemetry, shipped to the cloud, and analyzed to understand what happened after the fact. EDR and SIEM became the center of gravity, and they became very good at triaging incidents and rather slow at stopping them, they just had to be somewhat faster than the human advisory at the other end.
AI has changed the equation, and that tradeoff no longer holds at the speed work now moves. Organizations are moving faster than ever. Employees work across more applications, while AI assistants and agents are becoming part of everyday workflows. As work changes, so does the risk.
AI has collapsed the time between compromise and impact. An attack that once unfolded over days now completes in minutes, faster than a human can respond. It starts with a single action: a copy, a paste, a prompt, a click, or a handoff of remote control to someone outside the business. By the time EDR fires anything, the damage is already underway. Every CISO we talk to feels this today. The time-to-damage window is closing faster than the time-to-respond window their existing tooling can deliver.
The question is no longer how quickly you can investigate. It is whether you can prevent the incident from happening in the first place.
We are building a new security platform that returns prevention to its rightful place, as security tools originally intended to, designed for where work actually happens.
The news
Today, we are excited to share a milestone. Ent is emerging from stealth with $100 million in funding led by Decibel, with participation from Sequoia, Crosspoint Capital Partners, Craft Ventures, Shield Capital, Felicis, and In-Q-Tel (IQT)l. We are grateful for it, and it reflects the scale of the opportunity ahead of us.
“We have entered a new era defined by AI-powered attacks, one that demands a return to prevention and resilience. The level of inference required to stop threats before they materialize must now live directly on the endpoint. Ent is leading this fundamental shift in endpoint protection.” - said Greg Clark, Co-Founder and Managing Partner, Crosspoint Capital Partners.

Why prevention is possible again
Prevention failed for a practical reason. To stop something before it happens, you have to see and understand it in real time, at the moment of decision. With traditional cloud-based tools that was not possible. The processing power lived in the cloud, and a round trip was needed from the endpoint to instrument the action.
With AI, this has changed. We run small AI models locally on the endpoint, moving reasoning and action to the edge without the round-trip latency. A decision can be made in sub-seconds, before the incident occurs. For the first time, a system can observe what is happening, understand with full context whether it should continue, and intervene before the moment passes.
This is the shift left that security has wanted for years: prevention close to where work happens, with an architecture you can actually deploy.
Workspace security is the new control plane
Modern work does not happen at the layers where EDR and SIEM are watching. It is spread across the apps, browsers, collaboration tools, and AI assistants a person moves through in a day, alongside the AI agents acting on their behalf.
That is where risk now lives, looking like legitimate work, and that is where the traditional stack is blind. EDR can tell you a process is running. SIEM can collect information around it. Neither can tell you that a user just handed control of their machine via RMM (Remote monitoring and management) to someone outside the organization, or pasted sensitive data into an unsanctioned AI tool, or the intent behind either action. The instrumentation sits at the wrong layer, arrives too late, and lacks the context of the human and the agent activities.

It requires a new layer: a control plane at the endpoint, where behavioral telemetry is collected, intent is inferred to tell normal work from risky action, and interventions happen at the moment of decision.
That's why we're excited to introduce Ent and share our vision for the future of workspace security. Organizations need a better way to secure human and AI-driven work.
Our mission is simple: protect work as it happens.
Foundation starts with a complete record of work
Here is the part we strongly believe in.
Securing modern work starts with a complete, faithful record of it: application use, browser, chat, AI use, workflows, runtime execution, and data movement. Today that record lives in fragmented tools, never in one place, which is why security teams spend their days reconstructing events from pieces scattered across a dozen systems.
Ent creates that record at every endpoint, a comprehensive log of what is actually happening across the business. Intent is derived from the same telemetry, adding the why behind a human or agent action to the what. With behavioral baselining, Ent learns what is normal for each role and each workflow. Because the record is complete and lives at the right layer, it becomes the foundation for action. We intervene in the moment to prevent threats, misuse, and mistakes.
With this new layer in place, security teams operate at a different speed. What used to take hours or days takes minutes. And many incidents simply never happen, because the platform steps in to take action before they can.
Built Alongside Our Customers
The challenges we are describing are not future problems. They are what security teams are managing right now: embracing AI while keeping control of sensitive data, navigating insider risk, responding to social engineering that looks exactly like legitimate work, and investigating incidents that span applications and workflows. All this while being asked to enable innovation and move faster than ever before.
We built Ent alongside customers living these realities every day. Their feedback and insights have shaped both the platform and our vision. Organizations use Ent to detect insider risk, govern AI usage, prevent data loss, stop last-mile threats, and accelerate investigations with complete behavioral context. More than any single feature, what they get is clarity in environments where the old approach left too many questions open.
As one customer told us:
"Ent is the first tool where I felt like an expert on day one. Reading exactly what happened took the guesswork out of my job and let me scale my team." — Insider Threat Lead, Public Financial Institution
We are proud to support Global 2000 organizations across hospitality, financial services, and defense as they navigate human and AI-driven work. Their partnership continues to shape how we build and innovate.
What comes next
The way work happens will continue to evolve. So will the challenges facing security teams.
We believe the future of workspace security will be defined by the return to prevention, because for the first time the architecture exists to make it real: AI-powered intelligence at the edge, a complete record of work, and the context to understand intent and act before risk becomes an incident. While detection and response will continue to exist, modern workplace security needs a new approach to bring back prevention.
We built Ent for what comes next.To learn more about Ent and our vision for securing human and AI-driven work, visit ent.ai.
Follow us on X and LinkedIn. To talk to us and see our product in action, schedule a demo.