Jason Rebholz has spent two decades chasing digital threats through the corridors of corporate America—from Mandiant to Travelers Insurance. But when a deepfake candidate applied to his own startup earlier this year, the irony wasn't lost on him. Here was a company building defenses against rogue AI, nearly fooled by one.
That incident, which caught the attention of The Register in February, crystallizes the problem Rebholz and co-founder Jeff Chan are betting $4 million they can solve. On February 24, the pair announced a pre-seed round led by Crosspoint Capital Partners, with Red Cell Partners joining, to tackle what they're calling the "Shadow AI" crisis—a term that might sound alarmist if not for the data backing it up.
Their Washington, D.C.-based startup, Evoke Security, enters a market where enterprises are adopting AI agents faster than IT departments can track them. Which is to say: most organizations have no earthly idea how many autonomous agents are crawling through their systems, what data they're accessing, or what permissions they've been granted along the way.
"It's the wild west," Rebholz said, though the metaphor barely captures the scope. This isn't just about employees tinkering with ChatGPT plugins. Production systems are now running autonomous workflows, connecting to Model Context Protocol servers, executing tasks without human oversight. And security teams? They're essentially flying blind.
What Exactly Are They Securing?
The platform Evoke has built addresses three layers of the problem, though calling them "layers" suggests more order than actually exists in most enterprises.
First: discovery. The system inventories agents wherever they live—locally on employee devices, embedded in SaaS applications, or running in production environments. Evoke deploys an endpoint sensor for the first category, a browser extension for the second, and an SDK with proxy capabilities for the third. The architecture attempts to capture everything from experimental side projects to mission-critical automation.
Second: what they call AI-SPM, or AI agent security posture management. Think threat modeling, but for systems that can modify their own behavior. The platform tracks not just agents themselves but their connections to external servers and the specific "skills" each agent possesses—a capability set that can shift without warning.
Third, and perhaps most crucially: real-time intervention. Detection, prevention, response. The usual security triad, adapted for entities that operate at machine speed.
Chan, who previously served as CTO at MOXFIVE (where Rebholz also worked), has written extensively on the technical challenges in the company's blog. Anthropic's Model Context Protocol servers have vulnerabilities. Permissions are routinely over-broad. Multi-agent systems suffer from what Microsoft researchers delicately term "information flow control failures"—which is a polite way of saying these systems leak data like sieves.
A Crowded Field, Growing Fast

Evoke isn't alone in spotting the opportunity. The funding arrives amid a scramble for position in AI security that's starting to resemble the early cloud security land grab a decade ago.
Noma Security pulled in $100 million for a Series B last August, focused on agent monitoring. CyberArk, the identity management giant, launched its own AI agent identity solution in November. Check Point acquired Lakera for AI runtime protection late last year. Protect AI raised $60 million in August 2024—though that feels like ancient history given the sector's velocity.
The company secured a spot in the 2026 CrowdStrike, AWS, and NVIDIA Cybersecurity Startup Accelerator and holds membership in NVIDIA Inception. They'll present at RSA Conference's Demo Day on March 24, a stage that's become something of a proving ground for early-stage security ventures.
What Evoke hasn't disclosed: customers. The website invites enterprises to join early access programs, but named design partners remain conspicuously absent from the announcement. Crunchbase pegs the team at somewhere between one and ten employees, which means this is still very much a bet on the founders' track record rather than demonstrated market traction.
The Timing Question

Whether Evoke can carve out sustainable ground—or whether larger platforms simply absorb this functionality—remains the open question. Security tool sprawl is already a crisis in most enterprises. Convincing CISOs to add another dashboard requires either solving a problem painful enough to override that resistance, or integrating so seamlessly into existing workflows that the decision becomes trivial.
The founders are wagering that Shadow AI represents the former. Industry surveys they cite show enterprises racing to deploy agents while simultaneously admitting they lack basic visibility into what those agents are doing. Agents are taking unintended actions, they note, though the phrasing carries the careful understatement common to security vendors who don't want to alarm prospects too much before the sales call.
Still, the funding signal matters. Crosspoint Capital Partners doesn't write checks for imaginary problems, and Red Cell Partners brings national security credentials that suggest someone thinks this could matter beyond quarterly earnings reports.
Rebholz's deepfake story may have been an anecdote, but it pointed to something larger: the security infrastructure that worked reasonably well for a decade of cloud adoption wasn't designed for systems that act autonomously. And those systems are already here, multiplying quietly in enterprise environments while security teams scramble to even map the terrain.
Human error you can train against. An AI agent with over-broad permissions and a flawed prompt? That's a different category of threat entirely.
