Where the Money Is in VPN Works: One Policy and One Log for Every AI Agent a Company Runs
VPN Works is a prototype today, so its business case is a plan to test with customers. Here is the short answer to where the money is. The engine that seals one agent on one machine is the part that earns trust. The money comes from companies that run many agents and need one policy and one log across all of them, on every laptop, CI runner and server, plus exits they control. That’s worth a monthly fee per developer. There’s also a faster route: over the past year, security and network vendors paid between $180 million and $400 million each for AI and agent security startups.
The timing has a reason behind it. Gartner expects 40% of enterprise applications to include task-specific AI agents by the end of 2026, up from less than 5% in 2025. And agents on developer machines have already been turned against their owners. In August 2025 a poisoned release of the Nx build tool drove the AI command-line tools it found on developers’ computers, Claude Code, Gemini CLI and Amazon Q among them, to search the machine for secrets. It leaked 2,349 of them.
The platforms have noticed. GitHub gives its own Copilot cloud agent a firewall with an allow list, and since April 2026 organizations can manage it centrally. Anthropic has published an open-source sandbox for Claude Code that limits both files and network access. Each of these fences covers one vendor’s agent.

One Fence Per Vendor Is the Gap
A typical engineering team in 2026 doesn’t run one agent. It runs a coding agent in the editor, another one in CI, a few tool servers the agents call, and whatever a developer installed last week. Each vendor’s fence has its own allow-list format and its own logs, or none at all. After an incident the security team can’t answer the question that matters: which agent sent what, where, and was it allowed?
That’s the product VPN Works would sell. One policy and one record across every agent and every machine, whoever made the agent. Companies already buy this shape of product elsewhere. They use one identity provider for all their apps and one network-access tool for all their staff, instead of trusting each app to do its own. vpnw sits in the same spot for agents: in the network path, which every agent has to pass through.
Who Pays, and for What
| Buyer | The problem | What they’d pay for | How it’s priced |
|---|---|---|---|
| Engineering teams using coding agents | Agents holding tokens on laptops and CI runners, with no shared rules | One shared policy, one log, ready-made CI steps, help reviewing learned policies | Per developer, per month |
| Security and compliance teams | No record of where an agent sent data | Log retention and search, export to the security tools they already use, alerts | Part of an enterprise plan |
| Companies that host agents for customers | Each customer wants known exit addresses and proof its agents are contained | Managed exits and a policy per customer | By usage: per agent or per exit |
| Security and network vendors | They need agent coverage in their products, fast | A license for the engine, or the company itself | A license fee, or an acquisition |
A Price List to Test
None of these prices has been tried on a buyer yet. They’re starting points for conversations with design partners during the Beta.
- The engine, free. run, trace, guard and learn on one machine, with local policies and logs. The license is still to be chosen, but trying vpnw should cost nothing either way.
- Team, about $8 to $12 per developer a month. One policy and one log for every agent the team runs, CI steps, and help reviewing the policies learn drafts.
- Enterprise, about $20 to $30 per developer a month. Single sign-on, log retention and search, settings pushed to every machine, and support.
- Platforms, by usage. Managed exit addresses and a policy per customer for companies that host agents, or a license to build the engine into their own product.
The anchors come from tools companies already pay for. Tailscale, which gives staff network access to company systems, charges $8 per user a month on its Standard plan and $18 on Premium. GitHub’s paid individual Copilot plans run from $10 to $100 a month. Pricing the Team plan close to a network-access seat, and well below the cost of the agent it protects, is a sensible first guess.
Rough Arithmetic
Illustrative only, with the Team plan at $10 per developer a month:
| Paying customers | Developers each | Revenue a year |
|---|---|---|
| 20 early teams | 50 | $120,000 |
| 100 companies | 100 | $1.2 million |
| 500 companies | 200 | $12 million |
Enterprise seats, managed exits and platform licenses come on top. The table is about scale: a few hundred paying companies would make this a real software business. For comparison, Reco, one of the companies selling AI agent security, says its annual recurring revenue is in the double-digit millions and expected to triple this year. Its latest round, a $55 million raise in September 2026, valued it in the high hundreds of millions of dollars.
The Faster Route: Being Bought
Security companies have been buying their way into AI and agent security:
| Buyer | Company | What it does | Price | When |
|---|---|---|---|---|
| SentinelOne | Prompt Security | Security for AI tools and agents at work | $250 million | August 2025 |
| F5 | CalypsoAI | Security for generative and agentic AI | $180 million | September 2025 |
| CrowdStrike | Pangea | AI detection and response | $260 million | September 2025 |
| Check Point | Lakera | Security for agentic AI applications | Not disclosed | September 2025 |
| Cato Networks | Aim Security | AI security, added to Cato’s network platform | Not disclosed | September 2025 |
| Cisco | Astrix Security | Security for non-human identities, AI agents included | About $400 million | May 2026 |
| SailPoint | Entro | Finding and watching AI agents inside a company | About $200 million, as reported | June 2026 |
Two things stand out. The buyers include network companies (F5, Cato Networks, Cisco), and that’s where a network-level control like vpnw fits most naturally. And the targets were young. Prompt Security was two years old when SentinelOne bought it.
Those companies had customers, revenue and teams. VPN Works has a tested prototype and a name that says what it does. To become worth buying it needs what the Beta is built to produce: real agents running under it, teams lined up to try it, and a first paying customer. Clean ownership helps too. The engine has no third-party code in it, and its license is still the owner’s decision.
What Could Stop the Money
- The platforms give fences away. GitHub and Anthropic already ship them for their own agents, free. That raises the floor. VPN Works has to stay the one layer that covers every vendor’s agents, and be clearly better at the record and at reviewing policies.
- A crowded field. TechCrunch counts at least two dozen companies selling AI agent security. Most of the companies bought so far watch identities, permissions or prompts. Controlling each agent’s network path is a narrower job. That’s VPN Works’ niche, and the niche still has to prove it’s big enough on its own.
- Security buyers stick with vendors they know. A small company selling to security teams faces long sales cycles. Licensing the engine to a larger vendor may reach customers faster than selling direct.
- Agent projects may stall. Gartner also expects over 40% of agentic AI projects to be canceled by the end of 2027. Fewer agents in production means fewer buyers.
- Linux only, for now. Many developers run agents on Macs. Until guard works on macOS, the product covers servers and CI better than laptops.
What the Beta Has to Prove
The Beta runs about 14 weeks, and it’s where the business case gets its first real numbers:
- Three real coding agents work under vpnw every working day for four weeks, and the policy rarely gets in the way of real work.
- A handful of teams agree to pilot it on their own machines after the Beta, and at least one says what it would pay.
- The Team price survives those conversations, or gets corrected by them.
If those hold, there are two ways forward. Raise a seed round to build the team layer, or open talks with the security and network vendors already buying in this market. Either way, the money follows the proof.