# The Two Words Every Security Startup Is Adding to Get Bought: Claude Code Just Made It Obvious _Open Claude Code and the skills marketplace lists 100+ cybersecurity installs. Read the descriptions and they are selling the same control-plane story._ **Published:** 2026-09-30 **Source:** https://www.startuphub.ai/cybersecurity/security-startups-agentic-control-plane-claude-code --- Open Claude Code today and check the skills marketplace. There are now 100+ cybersecurity skills you can install by default: Varonis, Rubrik, [Island](/startups/island), [Cyera](/startups/cyera), Torq, and dozens more. They all promise something different in the title. Read the description and they are selling the same thing. - Island: "Agentic Control Plane for Enterprises" - Cyera: "Trust Layer & Control Plane to Secure Agentic Endpoints" - Onyx: "Secure AI Control Plane" - LangGuard: "AI Control Plane" - Torq: "Agentic SOC" - Okta: "Identity is the control plane" - Palo Alto: "The network is the control plane" - Drata: "Compliance is the agentic control plane" Saying "control plane" is the new entry ticket. For three years the ticket was saying SASE, ZTNA, SOAR, or DSPM. That got you funded from 2020 to 2024. In 2025 and 2026, that money moved to AI infrastructure. If you still said SASE, you got a low multiple and got bundled for free. If you say "agentic control plane," you get AI budgets, AI valuations, and you get on the acquisition list. It has become code for "we are buyable." A hardened Chromium browser, a webhook runner, a database scanner, a low-code governance dashboard: all renamed as a control plane. Claude's marketplace makes the convergence visible in one screen. ## The pattern on the cap table | Company | Founded | What it was | Raised before 2026 | 2025-26 event | What it is now | Valuation | | --- | --- | --- | --- | --- | --- | --- | | Island | 2020 | Enterprise Browser / Endpoint DLP | ~$730M | $400M Series F Sep 2026 | Agentic Control Plane | $6.4B | | Cyera | 2021 | DSPM / Cloud DLP | ~$600M+ | $1.4B raised in 2026 alone ($400M Series G Ext Sep 2026) | Trust Layer & Control Plane | $12B | | Torq | 2020 | Any-code hyperautomation / SOAR | ~$192M | $140M Series D Jan 2026 | Agentic SOC | $1.2B | | Fiddler AI | 2018 | Explainable AI / MLOps | ~$70M | $30M Series C Jan 2026 | Neutral Control Plane for Compound AI | $120M-250M | | Zenity | 2021 | Low-code app security | ~$59.5M | $125M Series C Aug 2026 | Securing Agentic AI | undisclosed | | Onyx | 2024 | AI runtime defense | $40M | $113M Series B Jul 2026 | Secure AI Control Plane | undisclosed | ## Island: When your product becomes a free feature Island built a secure Chromium with DLP, clipboard isolation, and MFA. Great for hybrid work. $3B valuation in 2024, $4.8B in March 2025. Then Palo Alto bought Talon and gave enterprise browser features away for free inside Prisma SASE. If you are a feature in someone else's bundle, you have to rebrand. Island raised $400M in September 2026 and stopped calling it a browser. The new story: AI agents interact with apps through the browser via DOM and APIs, so the browser is the enforcement layer between agent tool calls and enterprise apps. Same Chromium fork, new job. ## Cyera: From scanner to agent police Cyera scanned S3, Snowflake, and Google storage for sensitive data. That got them to $3B in Nov 2024. Then cloud providers added free classification and competitors like Varonis and BigID built their own scanners. Pure DSPM got price compressed. Cyera bought Oasis Security for $1B in July 2026 for non-human identity, plus Trail for DLP and Otterize for network policy. And it raised $400M in Jan, $600M in June, $400M from Goldman Sachs Alternatives in September. Now it is not selling scans. It is selling "Agent Guardian" and "Endpoint": because those S3 queries are now done by Cursor or Claude Code agents at machine speed, so you need a unified data and identity control plane. Same API polling and regex for credit cards, but service accounts are now called "AI Agent Identities." ## Torq, Fiddler, Zenity: same movie, different layer Torq fixed SOAR. Old SOAR needed Python scripts, so Torq gave you drag-and-drop webhooks. Raised $70M Series C in Sep 2024. When LLMs got cheap, a static rules engine was not a moat anymore. So $140M Series D Jan 2026 at $1.2B as "Agentic SOC" with a product called Socrates that "autonomously reasons" about alerts. Underneath: still API calls to EDR, threat intel, and firewall. Fiddler explained credit scoring models with Shapley values. $32M Series B in 2021. That market died when everyone moved to LLMs. So $30M Series C Jan 2026 as "neutral control plane for compound AI": now it is prompt inspection, toxic output filtering, token budgeting, and redaction. Zenity protected citizen developers building in Power Apps and Zapier. $5M Seed 2021, $16.5M Series A 2023. When VC moved to Copilot Studio and Agentforce, Zenity followed. Same engine that flagged insecure Power Automate flows now intercepts "promptware" and governs Model Context Protocol permissions. $38M Series B late 2024 on copilots, $125M Series C Aug 2026 on Agentic AI. ## The land grab: 100 vendors, one phrase The early pure-plays never used old words. They launched as control planes: - **Onyx Security:** Stealth with $40M, $113M Series B Jul 2026 from Bessemer. Inline reverse proxy that intercepts agent execution before it hits prod. Called itself Secure AI Control Plane from day one. - **LangGuard, Helixar, Aperion, Moring:** Published blueprints calling the AI Control Plane the mandatory layer between foundation models and enterprise data. The incumbents could not let startups own it: - **Palo Alto:** Our AI Gateway and AI Runtime Security is the control plane. We inspect prompts at the firewall, you do not need a new point product. - **Okta:** Identity is the real control plane. Agents have credentials and OAuth tokens, so agent governance is IAM. Direct shot at Cyera buying Oasis. - **Drata:** Compliance is the control plane. We track whether agents stay within audit boundaries. Boston Consulting Group now publishes frameworks on "how to govern AI agents at scale through a control plane." Once consultants bless it, every vendor has to say it. ## Same tech, new name The primitives change much slower than the pitch: | Layer | 2018-2023 name | 2025-2026 name | What it actually is | | --- | --- | --- | --- | | Network inspection | Forward Proxy / SWG | AI Gateway / Prompt Firewall | Man-in-the-middle TLS termination, regex, DLP scanning | | Workstation | Remote Browser Isolation / VDI | Enterprise Browser as Agentic Control Plane | Sandboxed Chromium, DOM hooking | | Orchestration | SOAR Playbooks (Python + webhooks) | Agentic SOC / Agentic Builder | Event-driven workflow execution | | Data & Identity | CSPM / DSPM / Service Account Auditing | Trust Layer / Non-Human Identity Control Plane | Scheduled JSON API polling, crawling datastores for regex | | Observability | MLOps Drift / Shapley values | Neutral Control Plane for Compound AI | Log aggregation, token usage counters | That is why 100 skills in Claude Code look the same. Whether it is Varonis extending Atlas to Claude Code and Cowork in July 2026 or a new startup skill, the action is: intercept a JSON string, check it with regex or a small model, block it. ## Why everyone is doing it **1. VC math.** A browser or a cloud scanner is crowded. It trades at low SaaS multiples. An "agentic control plane" trades at AI infra multiples. That is how Cyera went $3B to $12B in less than a year and Island went $3B to $6.4B. **2. CISO budgets.** General security budgets are being cut and consolidated. AI enablement budgets are protected because boards are telling CISOs to enable AI without getting breached. If you sell "preventing prompt injection," you get AI budget. If you sell "DLP," you get squeezed. ## The problem If every layer is THE control plane, the term means nothing. - Island says the browser is the control plane. - Cyera says data and non-human identity is. - Okta says IAM is. - Palo Alto says the firewall is. - Drata says compliance is. - Torq says the workflow canvas is. You cannot have six single panes of glass. And we are funding fantasy. Most enterprises today have a chatbot, RAG over SharePoint, and Copilot writing emails. VCs are pricing companies at $12B to govern autonomous multi-agent meshes that do not exist in production yet. A lot of "autonomous" is also just old automation with an LLM label. Checking VirusTotal when an alert fires used to be a script. Now the same API call, triggered by an LLM prompt, is called a "cognitive loop." That justifies a price hike. Meanwhile 98% of security teams say they drown in alerts and 79% say they have too many tools. The answer is to buy an AI Control Plane, an Agentic Browser, an AISPM, and an Agentic Trust Layer on top. ## What happens next This follows the old pattern. Microsoft, Palo Alto, Okta, and Cato will build prompt filtering, agent identity, and token governance into the platforms you already pay for. Standalone proxies get commoditized again. The point solutions get bought (Aim Security by Cato Networks, Oasis by Cyera for $1B) or they have to rebrand again. Until the incentive changes, security will keep doing this: take a 15-year-old primitive, rename it for the current wave, and sell it to an exhausted CISO as a new category you cannot live without. Say "control plane" and you are in the league. --- Original analysis from [startuphub.ai](https://www.startuphub.ai), the #1 AI startup directory.