business

Where the Money Is in VPN Works: One Policy and One Log for Every AI Agent a Company Runs

VPN Works is a prototype today, so its business case is a plan to test with customers. Here is the short answer to where the money is. The engine that seals one agent on one machine is the part that earns trust. The money comes from companies that run many agents and need one policy and one log across all of them, on every laptop, CI runner and server, plus exits they control. That’s worth a monthly fee per developer. There’s also a faster route: over the past year, security and network vendors paid between $180 million and $400 million each for AI and agent security startups.

The timing has a reason behind it. Gartner expects 40% of enterprise applications to include task-specific AI agents by the end of 2026, up from less than 5% in 2025. And agents on developer machines have already been turned against their owners. In August 2025 a poisoned release of the Nx build tool drove the AI command-line tools it found on developers’ computers, Claude Code, Gemini CLI and Amazon Q among them, to search the machine for secrets. It leaked 2,349 of them.

The platforms have noticed. GitHub gives its own Copilot cloud agent a firewall with an allow list, and since April 2026 organizations can manage it centrally. Anthropic has published an open-source sandbox for Claude Code that limits both files and network access. Each of these fences covers one vendor’s agent.

Where the revenue would come from, with prices as hypotheses to test. The engine is free: run, trace, guard and learn on one machine, so developers try it and trust it. Team, at about $8 to $12 per developer a month, gives one shared policy and one log across every agent. Enterprise, at about $20 to $30 per developer a month, adds single sign-on, log retention and settings pushed to every machine. Platforms pay by usage for managed exits and per-customer policies. Below, the faster route: F5 bought CalypsoAI for $180 million, SailPoint bought Entro for about $200 million, SentinelOne bought Prompt Security for $250 million, CrowdStrike bought Pangea for $260 million and Cisco bought Astrix Security for about $400 million.

One Fence Per Vendor Is the Gap

A typical engineering team in 2026 doesn’t run one agent. It runs a coding agent in the editor, another one in CI, a few tool servers the agents call, and whatever a developer installed last week. Each vendor’s fence has its own allow-list format and its own logs, or none at all. After an incident the security team can’t answer the question that matters: which agent sent what, where, and was it allowed?

That’s the product VPN Works would sell. One policy and one record across every agent and every machine, whoever made the agent. Companies already buy this shape of product elsewhere. They use one identity provider for all their apps and one network-access tool for all their staff, instead of trusting each app to do its own. vpnw sits in the same spot for agents: in the network path, which every agent has to pass through.

Who Pays, and for What

Buyer The problem What they’d pay for How it’s priced
Engineering teams using coding agents Agents holding tokens on laptops and CI runners, with no shared rules One shared policy, one log, ready-made CI steps, help reviewing learned policies Per developer, per month
Security and compliance teams No record of where an agent sent data Log retention and search, export to the security tools they already use, alerts Part of an enterprise plan
Companies that host agents for customers Each customer wants known exit addresses and proof its agents are contained Managed exits and a policy per customer By usage: per agent or per exit
Security and network vendors They need agent coverage in their products, fast A license for the engine, or the company itself A license fee, or an acquisition

A Price List to Test

None of these prices has been tried on a buyer yet. They’re starting points for conversations with design partners during the Beta.

  • The engine, free. run, trace, guard and learn on one machine, with local policies and logs. The license is still to be chosen, but trying vpnw should cost nothing either way.
  • Team, about $8 to $12 per developer a month. One policy and one log for every agent the team runs, CI steps, and help reviewing the policies learn drafts.
  • Enterprise, about $20 to $30 per developer a month. Single sign-on, log retention and search, settings pushed to every machine, and support.
  • Platforms, by usage. Managed exit addresses and a policy per customer for companies that host agents, or a license to build the engine into their own product.

The anchors come from tools companies already pay for. Tailscale, which gives staff network access to company systems, charges $8 per user a month on its Standard plan and $18 on Premium. GitHub’s paid individual Copilot plans run from $10 to $100 a month. Pricing the Team plan close to a network-access seat, and well below the cost of the agent it protects, is a sensible first guess.

Rough Arithmetic

Illustrative only, with the Team plan at $10 per developer a month:

Paying customers Developers each Revenue a year
20 early teams 50 $120,000
100 companies 100 $1.2 million
500 companies 200 $12 million

Enterprise seats, managed exits and platform licenses come on top. The table is about scale: a few hundred paying companies would make this a real software business. For comparison, Reco, one of the companies selling AI agent security, says its annual recurring revenue is in the double-digit millions and expected to triple this year. Its latest round, a $55 million raise in September 2026, valued it in the high hundreds of millions of dollars.

The Faster Route: Being Bought

Security companies have been buying their way into AI and agent security:

Buyer Company What it does Price When
SentinelOne Prompt Security Security for AI tools and agents at work $250 million August 2025
F5 CalypsoAI Security for generative and agentic AI $180 million September 2025
CrowdStrike Pangea AI detection and response $260 million September 2025
Check Point Lakera Security for agentic AI applications Not disclosed September 2025
Cato Networks Aim Security AI security, added to Cato’s network platform Not disclosed September 2025
Cisco Astrix Security Security for non-human identities, AI agents included About $400 million May 2026
SailPoint Entro Finding and watching AI agents inside a company About $200 million, as reported June 2026

Two things stand out. The buyers include network companies (F5, Cato Networks, Cisco), and that’s where a network-level control like vpnw fits most naturally. And the targets were young. Prompt Security was two years old when SentinelOne bought it.

Those companies had customers, revenue and teams. VPN Works has a tested prototype and a name that says what it does. To become worth buying it needs what the Beta is built to produce: real agents running under it, teams lined up to try it, and a first paying customer. Clean ownership helps too. The engine has no third-party code in it, and its license is still the owner’s decision.

What Could Stop the Money

  • The platforms give fences away. GitHub and Anthropic already ship them for their own agents, free. That raises the floor. VPN Works has to stay the one layer that covers every vendor’s agents, and be clearly better at the record and at reviewing policies.
  • A crowded field. TechCrunch counts at least two dozen companies selling AI agent security. Most of the companies bought so far watch identities, permissions or prompts. Controlling each agent’s network path is a narrower job. That’s VPN Works’ niche, and the niche still has to prove it’s big enough on its own.
  • Security buyers stick with vendors they know. A small company selling to security teams faces long sales cycles. Licensing the engine to a larger vendor may reach customers faster than selling direct.
  • Agent projects may stall. Gartner also expects over 40% of agentic AI projects to be canceled by the end of 2027. Fewer agents in production means fewer buyers.
  • Linux only, for now. Many developers run agents on Macs. Until guard works on macOS, the product covers servers and CI better than laptops.

What the Beta Has to Prove

The Beta runs about 14 weeks, and it’s where the business case gets its first real numbers:

  1. Three real coding agents work under vpnw every working day for four weeks, and the policy rarely gets in the way of real work.
  2. A handful of teams agree to pilot it on their own machines after the Beta, and at least one says what it would pay.
  3. The Team price survives those conversations, or gets corrected by them.

If those hold, there are two ways forward. Raise a seed round to build the team layer, or open talks with the security and network vendors already buying in this market. Either way, the money follows the proof.