Founderland Logofounderland
the ★ top ★ 100 ★ marketers ★
SavedSearch
FoundersFounders
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Product Launches
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Investment News
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Research & Innovation
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
FoundersFounders
Return

Recommended Articles

SaaS iconSaaSOctober 5, 2026

Maven Robotics raises $100M for industrial robots

Maven Robotics raises $100M for industrial robots
RoboticsSeries A+3
SaaS iconSaaSOctober 5, 2026

OneByZero raises $20M to embed AI engineers in enterprises

OneByZero raises $20M to embed AI engineers in enterprises
Enterprise AiAi Governance+3
SaaS iconSaaSMay 18, 2026

YC-Backed Minicor Launches Self-Healing Desktop Automation for AI Firms

YC-Backed Minicor Launches Self-Healing Desktop Automation for AI Firms
YcAutomation+3
SaaS iconSaaSMay 18, 2026

LawX Raises €7.5M Seed to Build AI Operating System for Law Firms

LawX Raises €7.5M Seed to Build AI Operating System for Law Firms
Legal TechB2b Saas+3

Founders Mentioned

Zain Rizavi

Cimento AI

saas icon
SaaS

Zain Rizavi

Cimento AI

saas icon
SaaS
SaaS iconSaaS
May 18, 2026
Ai AgentsEnterprise SecurityCybersecurityAi GovernanceStartup Funding

Cimento AI Raises $3M to Score Human and AI Agent Security Risk

Ex-Cloudflare and Palo Alto Networks founders build AI-native platform to score security risk from employees and autonomous AI agents as enterprises deploy more agentic systems.

Cimento AI Raises $3M to Score Human and AI Agent Security Risk

The pitch was straightforward, if a bit unsettling: what if your company's chatbot posed as much security risk as the intern who clicks phishing links?

That's the premise behind Cimento AI, which says it closed roughly $3 million in pre-seed funding in what the company describes as a May 2026 raise. Led by Bowery Capital, with Indie VC joining and a cluster of security veterans writing angel checks, the round represents a bet that enterprises are about to face a compliance crisis they haven't quite named yet—one where autonomous AI agents sit alongside humans on the corporate attack surface.

A note on timing: The funding date and several references throughout this piece cite events positioned in 2026. Readers should treat forward-looking claims with appropriate caution; details may reflect projections or preliminary announcements rather than finalized outcomes.

The investor lineup alone suggests the thesis has traction. Angels include Alex Dyner, an SVP at Cloudflare; Nick Sullivan, Cloudflare's former head of research; Dave Cole, who previously held product chief roles at CrowdStrike and Tenable; Shiven Ramji, president at Okta; and Naresh Guntupalli, formerly CTO of data security at Palo Alto Networks. When a cap table reads like a who's-who of enterprise security, it's usually a signal that something structural is shifting.

The Human Element Isn't Going Away—It's Multiplying

Security awareness training has long been the industry's least-loved ritual. Employees sit through annual videos, click through fake phishing tests, and everyone pretends the problem is solved. Verizon's 2024 Data Breach Investigations Report put a number on the futility: 68% of breaches involved what it called a "non-malicious human element"—a term of art for someone who made a mistake, not a deliberate saboteur. More recent findings suggest the problem persists, though specific percentages continue to evolve.

Cimento's answer is continuous risk scoring, not annual compliance theater. The platform connects to the usual enterprise stack—HR systems, security information and event management (SIEM) tools, endpoint agents like CrowdStrike, cloud data lakes—and uses Bayesian modeling to assign each employee a real-time risk score. Then it runs them through adaptive phishing simulations: email, SMS, voice calls, even AI-generated deepfake attacks. When someone slips, they get a 60- to 90-second micro-lesson tailored to their role and recent behavior.

That much is evolutionary, not revolutionary. Where Cimento diverges: it extends the same scoring model to AI agents.

When the Bot Has Root Access

Digital illustration for article section "When the Bot Has Root Access" in "Cimento AI Raises $3M to Score Human and AI Agent Security Risk" - A minimalist, Japanese-inspired illustration depicting the concept of an autonomous AI agent gaining...

As companies deploy agentic AI—systems that can autonomously browse the web, execute code, process transactions, or interact with customers—the traditional perimeter collapses in new ways. An agent with broad API access and poor guardrails can leak data, hallucinate instructions to customers, or spin up infrastructure no one authorized. Cimento runs adversarial tests on these deployed agents, scores their risk, and generates hardening recommendations.

It's a bet that agent governance will move from theoretical to mandatory faster than most enterprises expect. Cognizant, Cisco, and UiPath have all rolled out agentic security services recently, though the market is still sorting out what "agent risk management" even means.

Co-founders Zain Rizavi (CEO) and Eric Liu (CPO) come with résumés that read like a tour through cloud security's last decade: Cloudflare, Palo Alto Networks, Amazon, Microsoft, Palantir. Their advisory board includes a roster of CISOs and security heads—Derek Chamorro, Jake Schroeder, Atif Haque, Rohit Parchuri, Aaron Stanley, Justin Dolly, Ismail Mohammed—who presumably see gaps in their current tooling. Whether those gaps are urgent enough to rip and replace remains an open question.

Early Customers, With Caveats

Digital illustration for article section "Early Customers, With Caveats" in "Cimento AI Raises $3M to Score Human and AI Agent Security Risk" - A conceptual, minimalist illustration representing early-stage business partnerships and pilot deals...

Cimento lists Gemini, DigitalOcean, Tensorwave, Together AI, Aryaka, and Moveworks as early customers. The New Stack cited Together AI as an example in its May coverage. These are company-provided references without independent confirmation, and the usual caveats apply: pilot deals don't always translate to production deployments, and logos on a launch deck don't always signal deep integration.

Still, the customer list tilts toward AI-native companies—firms that are building or running agentic systems themselves. If you're deploying autonomous agents at scale, perhaps you're more inclined to treat them as potential risk vectors rather than magic productivity multipliers.

The Valuation Question

The company didn't disclose a valuation. Indie VC typically writes first checks between $250,000 and $2 million; Bowery Capital focuses on early-stage B2B software. The $3 million raise is on the smaller side for a team with this pedigree, which could mean the founders kept dilution tight or that the market for "AI agent risk scoring" is still speculative enough to warrant caution.

Rizavi framed the funding in familiar founder language: the company aims to build "the missing link: a system that treats human nature as a real-time security problem, not a periodic training exercise." It's a tidy soundbite. Whether it resonates with security buyers—who are already juggling vendor fatigue and shrinking budgets—will depend on whether Cimento can prove that continuous scoring actually reduces breach rates, not just generates more dashboards.

For now, the company is focused on proving the core thesis: that humans and the AI agents they deploy should be measured on the same risk continuum. If the customer references hold up and the platform moves beyond pilot deals, they might have a window before one of the incumbent security platforms bolts on a similar feature.

Assuming, of course, that the market decides agent governance is a category worth funding. In 2026, apparently, we're about to find out.

More stories

  • Maven Robotics raises $100M for industrial robots
  • OneByZero raises $20M to embed AI engineers in enterprises
  • YC-Backed Minicor Launches Self-Healing Desktop Automation for AI Firms
  • LawX Raises €7.5M Seed to Build AI Operating System for Law Firms
  • Inside the Passive Sensing Mesh Revolution Reshaping Drone Security
  • Kovva Launches AI Agents to Bridge Cross-Platform Marketing Data
fintech icon
climate-social-tech icon
saas icon
healthtech-biotech icon
ecommerce icon
media-entertainment icon
Loading...

About

Dreamwell AIContact UsOur Story

Articles

Product LaunchesInvestment NewsResearch & Innovation

founderland

We Use Cookies

We baked up some cookies – the digital kind. They help Draper run like a well-oiled mid-century machine. Some are essential to the experience, others help us tailor things to your taste. We promise, no crumbs on your blazer. Take a moment to choose what works for you.