When Eno Thereska left his role as a Distinguished Engineer at Alcion (later acquired by Veeam), he wasn't chasing another incremental improvement in cloud infrastructure. He'd spent years at AWS and Confluent building systems that needed to scale. This time, the challenge felt different—maybe more urgent.
On January 28, 2025, Thereska and two co-founders incorporated Trent AI in London, betting that the next wave of artificial intelligence wouldn't just need better models. It would need an entirely new category of security tools.
On April 7, the company emerged from stealth with $13 million in seed funding—roughly €11 million or £9.7 million, depending which side of the Channel you're counting from. LocalGlobe and Cambridge Innovation Capital led the round, with a supporting cast that reads like a who's-who of AI infrastructure: operator-angels from OpenAI, Spotify, Databricks, and Stripe.
The timing, as they say, isn't accidental.
The Problem No One Saw Coming (Until Now)
Consider the numbers. Deloitte's 2026 State of AI report found that 74% of enterprises plan to deploy what the industry calls "agentic AI systems"—autonomous software that doesn't just answer questions but makes decisions, accesses tools, executes code. The catch? Only 21% of those same companies have governance frameworks ready.
That gap is what Trent is banking on. Literally.
"Traditional security vendors like Snyk, Wiz, and Semgrep weren't designed for systems where AI agents make autonomous decisions without human approval," Thereska explained in the company's launch announcement. It's a pitch that sounds almost obvious in hindsight—of course you can't secure autonomous agents with tools built for static applications—but it's the kind of obvious that only becomes clear once the problem is staring you in the face.
And the problem, it seems, has arrived. In February, Tom's Hardware reported malicious skills uploaded to ClawHub, OpenClaw's marketplace for agent capabilities, targeting cryptocurrency users. Axios and TechRadar both covered similar risks around third-party tool access in late March and early April. Palo Alto Networks, hardly a company prone to overreaction, added enhanced AI red teaming for multi-agent systems to its Prisma AIRS documentation.
Perhaps the foundations for agentic security are being laid just in time. Or perhaps, as is often the case in enterprise tech, just a bit late.
Credentials That Matter (When Everyone Claims Expertise)

The founding team brings the kind of technical depth that tends to quiet skepticism in investor meetings. Thereska holds a Ph.D. from Carnegie Mellon and clocked time as a Principal Engineer at AWS—roles that don't typically go to people who can't ship code at scale.
His co-founder and Chief Scientist, Neil Lawrence, holds the DeepMind Professorship of Machine Learning at Cambridge. Before that, he directed machine learning at Amazon, where he presumably saw enough production AI systems to know which ones break and how. The third co-founder, CTO Zhenwen Dai, ran ML teams at AWS and Spotify, including work on reinforcement learning—the kind of experience that maps neatly to the challenge of securing agents that learn and adapt.
The investor roster functions as a secondary validation layer. Joaquin Quiñonero Candela, now a Member of Technical Staff at OpenAI, joined the round. So did Tony Jebara, Spotify's former VP of Engineering and Head of AI/ML. Avinash Bhat, who built data infrastructure at Stripe before moving to AWS, participated. Ippokratis Pandis, a Distinguished Engineer at Databricks, came in as well.
"There is an emerging category need for the governance, observability, and enforcement of these autonomous workflows," said Ian Lane, Partner at Cambridge Innovation Capital, in language that manages to sound both precise and carefully non-committal.
What the Product Actually Does

Trent's pitch centers on a relatively straightforward insight: if AI agents are going to act autonomously, you need security agents watching them.
The company integrates into agentic platforms through the Model Context Protocol (MCP), a standard that's gained traction as a way for AI systems to share context across tools. For users of Claude Code, Trent connects via MCP and feeds security tasks back into the development loop. In Lovable, it provides automated security advice and executes mitigations directly within the workflow. For OpenClaw, it delivers security assessments as a skill inside the agent runtime.
The company has lined up design partners including Canopy, Commscentre, ML@Cam, Qbeast, and Weblogic—though it's worth noting these are design partners, not necessarily paying customers yet. Trent has also joined OWASP as a partner startup and became part of Carnegie Mellon's CyLab Venture Network, affiliations that lend credibility if not revenue.
The Timing Question

Saul Klein, Co-founder and Executive Chairman of Phoenix Court/LocalGlobe, framed the investment around timing: the foundations for agentic security are being laid now, as the technology moves from research labs to production environments.
That's the optimistic read. The more skeptical version asks whether the 74% of enterprises claiming they'll deploy agents will actually follow through—and whether they'll hit the security problems Trent is positioning to solve before the market moves on to the next thing.
The $13 million will fund continued development of Trent's security agents, expand the engineering team, and grow the design partner and customer base. According to LinkedIn, the company currently lists somewhere between 2 and 10 employees and has just over 1,000 followers—numbers that place it firmly in the early stage category.
Valuation was not disclosed, which is standard for seed rounds and also conveniently sidesteps questions about price expectations in a market where AI valuations have been, to put it mildly, volatile.
What happens next probably depends less on Trent's technology—which, based on the team's credentials, is likely sound—and more on whether enterprises actually deploy autonomous agents at scale. And whether those agents start breaking things in ways that scare CFOs into approving security budgets.
If they do, Thereska and his team will have timed it well. If they don't, $13 million buys you enough runway to figure out what comes next.
