AGENTIC SECURITY·dev-tools·Scan 2026-06-30 to 2026-06-30·Run 20260701080042
Attack-replay and step-up gate for AI support agents handling account recovery, refunds, and entitlement resets.
Customer-support and trust-and-safety teams are starting to let AI agents reset passwords, issue refunds, and restore digital entitlements inside live admin tools. That turns one bad agent decision from a QA bug into direct account takeover or revenue leakage, yet most controls still focus on prompts or generic permissions rather than the state-changing action itself.
By Bizidea Research/
Overall rating3.9/ 5.0
3
Market
A $330M TAM and $99M SAM ride 1.7x adoption growth, but five named rivals and embedded platform vendors keep the lane crowded.
4
Differentiation
A cross-stack replay corpus and runtime approval gate create a sharper wedge than horizontal AI security or native helpdesk tools.
4
Execution
A five-role build plan and clear 24-month milestones pair with 9.0x LTV/CAC, 7.4-month payback, and 72% gross margin.
5
Timeliness
Four same-day signals converge around Straiker's $64M round, 15x growth, a 20,000-account incident, and rising agent adoption.
Section
Why now
A $64 million Series A, 15x run-rate growth, and existing frontier-lab and Fortune 500 customers show that agent security is already a funded control-plane category.
The Reuters-reported Meta support-agent incident proves support automation can create mass account-takeover risk, turning safety theory into an immediate buyer pain.
Buyers now expect one system to cover launch readiness and live containment, not separate point tools for testing and runtime monitoring.
If enterprises are heading toward more than one billion internal AI agents by 2029, manual approvals and legacy controls will not scale to action-taking support workflows.
Catalyst.Straiker's financing, 15x revenue growth, and the cited Meta support-agent incident show that enterprises have moved from theoretical agent risk to paying for testing and runtime containment of action-taking support workflows.
Section
The idea
The product connects to support-agent builders, CRM and ticketing systems, customer-verification tools, and internal admin panels to create a catalog of every state-changing action an agent can take. Before launch, it replays historical tickets plus adversarial scenarios such as social-engineered recovery attempts, refund stacking, and entitlement abuse to show exactly where the agent would overstep. Teams approve an action policy by intent, amount, customer state, and verification strength instead of writing brittle prompt rules. In production, the runtime proxy can force a human review, trigger additional verification, or block the mutation entirely when the action falls outside the approved envelope. Every approved and blocked action becomes evidence for fraud, security, and compliance reviews, giving operators a kill switch without shutting down all automation.
What's different. Fraud systems score end-user behavior, generic agent-governance products watch prompts or permissions, and helpdesk vendors offer canned QA. This company owns the mutation layer where an AI agent actually changes customer identity, money, or entitlements. Its moat becomes a replay corpus of abuse patterns, approval policies, and safe-action baselines across support stacks that incumbents cannot assemble from static rules alone.
Startup thesis
Beachhead
Digital consumer apps with stored value or reversible entitlements, 2-20 million user accounts, a Zendesk or Salesforce support stack, and internal admin consoles for password resets, wallet refunds, and digital entitlement restoration.
Wedge
An adversarial release gate that replays real support tickets and abuse patterns against agent workflows, then enforces step-up approval or policy blocks on risky account, refund, and entitlement mutations at runtime.
Non-obvious insight
The first costly AI-agent failures will not look like bad chatbot answers; they will look like privileged support actions executed at machine speed. The control point that matters is the mutation boundary around account recovery, refunds, and entitlements, where product security, fraud, and CX budgets suddenly overlap.
Venture-scale path
Start with high-risk customer-support mutations, then expand into payments disputes, seller operations, workforce access changes, and any AI agent that can change money, identity, or entitlements across enterprise systems.
Target user
Primary user
Support-platform and product-security leaders at digital consumer platforms deploying action-taking service agents.
Secondary user
Trust and safety operations leads responsible for account recovery, refunds, and entitlement workflows.
Economic buyer
CISO, VP of Customer Platform Engineering, or Head of Trust and Safety Engineering.
Go-to-market seed
First customer
A gaming marketplace or subscription app with 10 million or more user accounts, a centralized Zendesk or Salesforce support organization, and a 2026 program to let AI agents approve password resets, refunds, or digital entitlement restoration.
Buying trigger
A production-readiness review for moving a support agent from reply drafting into live account-recovery, refund, or entitlement actions, especially after a fraud or account-takeover incident.
Current alternative
Read-only copilots, manual QA queues, homegrown rules engines, and generic fraud checks wrapped around human support workflows.
Switching reason
The first customer switches because this wedge combines adversarial pre- launch testing with runtime step-up controls on the exact mutations that can cause account takeover or revenue leakage, which is hard to stitch together from helpdesk tooling and fraud systems alone.
Pricing hypothesis
Annual platform subscription plus usage-based pricing per protected state-changing action or governed support workflow.
Jobs to be done
Job
Current alternative
Success metric
When we want an AI support agent to approve account recovery or refunds, help our security and support teams replay abuse cases and set safe action boundaries, so we can launch automation without creating account takeover or revenue leakage.
Human-only queues plus manual QA and scattered fraud rules.
Share of eligible support tickets automated with zero high-severity security or fraud incidents.
When an agent attempts a risky customer mutation, help our trust and safety team require more verification or stop the action, so we can contain blast radius in minutes instead of after a public incident.
Post-hoc audits stitched together from Zendesk, CRM, and internal admin logs.
Mean time to block or step-up a risky support-agent action stays under five minutes.
Support agent action gate
flowchart LR
Buyer[Support security team] --> Pain[Risky account and refund actions]
Pain --> Product[Adversarial release and runtime gate]
Product --> Outcome[Safer autonomous support actions]
Idea scorecard — average4.8 / 5 · 5axes
Signal · 5/5The cluster combines a major financing, fast commercial traction, enterprise customers, and a concrete support-agent incident.
Pain · 5/5A single bad account-recovery or refund action can trigger direct account takeover, fraud loss, and brand damage.
Wedge · 5/5Attack replay plus runtime step-up on support-account mutations is a narrow, testable first product with a clear launch trigger.
Defense · 4/5Deep support-stack integrations and a growing corpus of abuse traces and approval policies can compound into a durable moat, though incumbents will respond.
Scale · 5/5The beachhead expands naturally into every AI agent workflow that can change identity, money, or entitlements across large enterprises.
Business model canvas
Key partners
Support automation vendors and system integrators
Fraud and identity-verification providers
CRM, ticketing, and helpdesk ecosystem partners
Key activities
Replaying historical tickets and adversarial scenarios
Maintaining policy packs for support actions
Enforcing runtime step-up and kill-switch controls
Key resources
Agent action replay engine
Support-stack connectors and runtime proxy
Fraud-pattern and policy-template dataset
Value propositions
Shadow-test support agents against fraud and abuse patterns before launch
Enforce step-up checks on risky account, refund, and entitlement mutations
Produce audit evidence for security, fraud, and compliance teams
Customer relationships
High-touch rollout on one protected workflow
Joint security and fraud policy tuning
Expansion into additional action types and business units
Channels
Direct enterprise sales to security, CX platform, and trust-and-safety teams
Design-partner pilots tied to one account-recovery or refund workflow
Partnerships with Zendesk, Salesforce, and support-automation integrators
Customer segments
Digital consumer platforms deploying action-taking support agents
Gaming marketplaces and subscription apps with stored value or entitlements
Neobanks and wallets automating account recovery and refund workflows
Cost structure
Integration and policy-engineering costs
Runtime logging and evidence storage
Enterprise sales and customer success
Revenue streams
Annual software subscription
Usage-based fee on protected state-changing actions
Premium evidence-retention and incident-response modules
Section
Market
Market sizing
Market sizing overview
TAM
$330MEstimate 3,000 global beachhead enterprises x 750 governed support mutations/day x 365 days x $0.40 per protected action (~40% of Fin’s public $0.99/outcome benchmark) = about $329M; cross-checked against visible AI-support adoption and platform spend.
SAM
$99MAssume 30% of TAM units are North America and Europe consumer platforms with enough AI-adoption and governance urgency for near-term buying: 900 accounts x $109.5k implied ARR each = about $98.6M.
SOM
$5.0MA realistic year-3 land-and-expand plan is 45 customers at roughly $110k ARR each for one protected workflow, which yields just under $5M in annual revenue.
Executive takeaways
Action-taking support AI is moving from pilot to production, which makes security risk attach to the mutation itself rather than to the chat response alone.
The sharpest wedge is a neutral control layer for password resets, refunds, and entitlement changes across CRM, help desk, and internal admin systems.
Native CX platforms and horizontal agent-security startups both validate demand, but neither side yet owns cross-stack support-specific replay testing plus runtime step-up control.
Public AI-service pricing and automation case studies show enough budget exists to fund a dedicated safety layer once buyers are close to go-live.
Market definition
The relevant market is support-action security for agentic customer service: software that replays risky workflows before launch and enforces approval or block policies when AI agents change account access, money, or digital entitlements in production.
Customer and buyer
Daily users are support-platform, product-security, and trust-operations leaders at consumer platforms using Salesforce, Zendesk, or similar stacks. The economic buyer is usually the CISO, VP of Customer Platform Engineering, or Head of Trust and Safety Engineering, with support leadership as an influential co-buyer.
Buying triggers
A support organization wants to move from assistive AI to autonomous account recovery, refund, or entitlement actions.[6][10][42]
A security or trust review follows account takeover, impersonation, or abuse of automated recovery workflows.[103][126][131]
Platform owners discover that prompt injection, delegated permissions, and weak logging make current go-live controls too brittle.[2][5][16][18][20]
Willingness to pay
Public price points already support a dedicated control-layer budget. Fin charges $0.99 per outcome, Agentforce sells usage through flex credits, Zendesk sells AI-ready suites from $55 per agent per month, and Intercom bundles Fin with paid seat plans. Case studies such as Best Egg show that support AI can already return material savings, making protection spend easier to justify.[43][48][53][72][94]
Category dynamics
Growth signal 1.7x YoY adoption growth in AI service agents (39% to 66%)
Tailwinds
Support teams are moving AI agents from pilot into measurable production use, with service leaders expecting larger case-share automation soon.
Support platforms now advertise autonomous actions, multichannel coverage, and dedicated testing flows, which lowers technical friction for buyers.
Agent-security funding and platform launches show that buyers already recognize control-plane gaps around autonomous AI.
Headwinds
Native platform vendors are bundling more observability, testing, and trust controls into the base stack.
Many organizations still have a deployment gap between basic AI use and high-stakes autonomous workflows.
Validation signals
Salesforce reports AI-service-agent adoption rose from 39% to 66% in one year, and 70% of adopters see value within 60 days.
Service leaders expect AI to resolve half of service cases by 2027, implying action volume and workflow authority will keep rising.
Fin’s public pricing and simulation tooling show that buyers already pay outcome-based AI fees and care about pre-launch testing.
Zendesk AI agents already act in authorized systems, and Best Egg reports 80% chat automation using Zendesk AI.
The Meta support-bot incident proves that weak recovery controls can turn support automation into direct account takeover risk.
Regulatory & technical constraints
Action-taking support agents inherit powerful delegated permissions, so least-privilege scoping is a product requirement rather than a later hardening step.
Indirect prompt injection can arrive through emails, documents, and external content, which means replay tests must include hostile-content scenarios, not just happy paths.
Account recovery and password-reset workflows need identity-proofing and authentication lifecycle policies strong enough for privileged mutations.
Deployers need human oversight, logging, and data-minimization controls around AI-supported account changes and customer-data handling.
Support-mutation security map
Section
Competition
Competition comes from two directions: native support platforms adding observability, testing, and trust features, and horizontal AI-security vendors adding discovery, red teaming, and runtime controls. The open space is a cross-stack mutation gate purpose-built for support workflows where a bad agent action becomes account takeover, refund leakage, or entitlement abuse.
Competitor
Stage
Wedge
Pricing
Strength
Weakness vs. us
Straiker
scale-up
Horizontal agentic-AI security spanning discovery, adversarial testing, and runtime protection.
Custom enterprise pricing; public pricing not listed.
Clear control-plane narrative plus discovery, red teaming, and runtime blocking across agent types.
Broad agent-security scope is not purpose-built around support-specific mutations like password resets, refunds, or entitlements.
Zenity
scale-up
AI security posture management, observability, and detection/response for enterprise AI ecosystems.
Custom enterprise pricing; public pricing not listed.
Strong cross-platform governance story across ecosystems such as Agentforce, Microsoft, and ServiceNow.
More horizontal posture and observability than workflow-specific replay and step-up control for support actions.
Noma Security
scale-up
AI security posture, agentic access control, red teaming, and runtime protection.
Custom enterprise pricing; public pricing not listed.
Security-depth positioning around access control and runtime enforcement.
Designed for the broader AI stack rather than a narrow support-operations mutation boundary with replayable ticket history.
Salesforce Agentforce
incumbent
Native autonomous service agents with platform observability, partner actions, and deep Salesforce data access.
Free builder tier plus $500 per 100k flex credits; Service Cloud starts at $25/user/month.
Owns the workflow, data, and action surface inside one of the dominant enterprise service stacks.
Stack-specific control does not solve neutral security policy across Zendesk, Intercom, mail, and off-platform admin tooling.
Zendesk AI agents
incumbent
Resolution-focused AI agents embedded in the Zendesk service platform with actions, analytics, and trust controls.
$55 per agent/month for Suite Team paid yearly, with higher tiers and add-ons for more advanced AI.
Strong support-domain data, actions in authorized systems, and native QA/trust tooling inside Zendesk.
Best inside Zendesk, but not designed as a cross-stack security gate for risky mutations spanning external admin tools and custom recovery flows.
Why incumbents do not win by default
CRM and help-desk platforms.Salesforce and Zendesk are embedding actions, trust, and pricing directly into their own stacks, but they do not win by default when a buyer needs one control layer across CRM, help desk, and off-platform admin tools.
Horizontal agent-security platforms.Straiker, Noma, Lakera, and Zenity validate spend on discovery, red teaming, and runtime controls, but their default product posture is horizontal AI security rather than support-mutation policy packs.
Fraud and identity vendors.Existing fraud and identity stacks help with risky recovery flows, yet they focus on end-user or transaction risk more than pre-launch agent replay and inline AI approval logic.
In-house QA and read-only copilots.Teams can keep agents assistive-only or build manual review queues, but once agents start updating external systems, simulation, boundary-setting, and evidence retention become too operationally heavy to stitch together ad hoc.
Section
Business plan
Support Action Replay Gate is a release-control and runtime approval layer for digital consumer platforms moving AI support agents from drafting replies to executing password resets, refunds, and entitlement changes. The urgent pain is that one bad support mutation can become direct account takeover, fraud loss, or entitlement abuse, yet most current controls still focus on prompts, permissions, or post-hoc audits instead of the mutation boundary itself. The beachhead should be gaming marketplaces, subscription apps, and similar consumer platforms with 2-20 million accounts, centralized Zendesk or Salesforce support, and a live program to let agents take account-recovery or entitlement actions. The first product must stay narrow: replay historical tickets and abuse cases for one protected workflow, define an approval envelope by verification strength and customer state, and enforce step-up review or blocking at runtime. Research supports an estimated $330M TAM, $99M initial SAM, and about $5M year-3 SOM for this initial wedge, with expansion into adjacent agent actions that change money, identity, or access. Go to market should start with a paid launch-readiness pilot sold to security and customer-platform leaders through direct sales and support-stack integrators, then convert into an annual contract for one governed workflow plus protected-action usage. The biggest open questions are how quickly target teams will permit action-taking agents in the next 12-24 months and whether browser-only internal admin tools can be governed without brittle implementation. This is strong enough for pre-seed diligence because the incident-driven why now and workflow wedge are real, but the company must prove deployment speed, acceptable false-positive rates, and pilot-to-production conversion before assuming category scale.
Problem
Support teams can now let AI agents reset passwords, issue refunds, or restore entitlements before security teams can prove which state-changing actions are safe under which verification conditions.
Generic agent security, fraud rules, and help-desk QA do not provide cross-stack replay, inline step-up control, or evidence at the exact moment an AI agent mutates identity, money, or access.
Solution
Catalog each support-agent action across Zendesk or Salesforce, verification tools, and internal admin systems, then replay historical tickets and adversarial abuse cases against one high-risk workflow before go-live.
At runtime, enforce policy by intent, amount, customer state, and verification strength so the system can require human approval, invoke stronger identity checks, or block the mutation while retaining audit evidence.
Why we win
The wedge sits where budget and downside are sharpest: account-recovery and entitlement mutations where security, fraud, and CX leaders already need a go-live answer.
Each deployment compounds a proprietary replay corpus, cross-system action graph, and approved-versus-blocked policy history that single-stack vendors and generic governance tools do not natively own.
Strategic choices
Beachhead
Gaming marketplaces, subscription apps, and consumer platforms with stored value or reversible entitlements, 2-20 million user accounts, Zendesk or Salesforce support, and a 2026 plan to let AI agents execute account-recovery or entitlement-restoration actions.
Wedge rationale
This slice has the clearest buying trigger—a production-readiness review before live support mutations—and the highest cost of failure, so it creates faster proof than selling a horizontal AI-governance platform or pursuing lower-risk draft-only copilots.
Sequencing
Start with one workflow, shadow replay, and step-up approvals because buyers must trust evidence and precision before they accept hard blocks; package Zendesk or Salesforce plus one action system before adding more connectors; hire integration and policy talent before scaling partnerships or broad sales.
Not yet
Low-risk read-only copilots or generic response-quality tooling · Seller operations, payments disputes, and workforce-access mutations before the first support workflow converts repeatedly · A full horizontal AI-governance or compliance suite · Browser-only internal tools with no stable API or approval hook if they break the packaged deployment model
Go-to-market
Wedge
Sell a paid launch-readiness package for one account-recovery or entitlement-restoration workflow, starting in shadow replay and converting to runtime step-up enforcement when the customer is ready to let agents take live actions.
Channels
Founder-led direct sales to CISO, VP Customer Platform Engineering, and Head of Trust and Safety Engineering at gaming, subscription, and stored-value consumer platforms. · Salesforce, Zendesk, and support-automation implementation partners already redesigning the targeted workflow. · Identity-proofing, fraud, and account-recovery partners that get pulled in when support automation touches account access or stored value.
Funnel targets
Target qualified account→design partner 25-35%, design partner→paid pilot 40-60%, paid pilot→production 50%+, production→second workflow expansion 50%+ within 12 months.
Pricing
Charge a paid 6-8 week pilot, then annual subscription per governed workflow plus usage-based pricing per protected state-changing action, because value is tied to safe automation of high-risk tickets and incident avoidance rather than seats.
Product roadmap
MVP
MVP covers one workflow—ideally account recovery or entitlement restoration—across Zendesk or Salesforce, one identity-proofing signal, and one admin action endpoint. It must replay historical tickets plus abuse traces, generate approval policies by customer state and verification strength, and enforce step-up or block decisions with evidence logs, while excluding broader model observability and low-risk CX analytics.
6 months
Ship a packaged Zendesk or Salesforce plus identity-provider plus one admin-tool deployment for shadow replay, approval envelopes, step-up review, and evidence export on the first protected workflow.
12 months
Add reusable policy packs for refunds and entitlement restoration, production-grade inline enforcement, customer-specific false-positive tuning, and exports into SIEM, fraud, and governance systems.
24 months
Expand from one support mutation into a broader control plane for money, identity, and entitlement changes across support, disputes, seller operations, and adjacent customer-ops workflows.
Key bets
Account recovery or entitlement restoration is the fastest path to urgent budget, not generic support-agent analytics. · Buyers will accept step-up approval and shadow mode before they trust fully automated hard blocking. · Historical ticket replay plus abuse-pattern libraries will materially improve pilot conversion and policy reuse. · A packaged Zendesk or Salesforce plus one action-system deployment can reach first value fast enough to avoid a services-heavy model.
Business model
Revenue streams
Annual subscription for each governed support workflow and action-policy environment · Usage-based fees for protected state-changing actions executed or stepped up under policy · Premium evidence-retention, incident-review, and compliance export modules · Partner-assisted deployment and policy-onboarding packages
Unit of value
Governed support workflow, measured by protected state-changing actions under policy
Target gross margin
70%
Expansion levers
Add more mutation types such as refunds, entitlement restores, and high-risk account changes within the same account · Expand from shadow-mode gating into inline enforcement, evidence retention, and incident analytics · Extend the same control layer into seller operations, disputes, and workforce-access changes after support proof · Distribute through implementation and identity partners already inside CX automation projects
Strategy map
North-star metric
Number of production support mutations executed within approved policy without a high-severity security or fraud incident
Input metrics
Days from kickoff to first replay result on a live customer workflow · Shadow-mode false-positive rate on legitimate protected actions · Paid pilot to production conversion rate · Step-up approval turnaround time for risky mutations · Second-workflow expansion rate in production accounts
Moats to build
Replay corpus of historical tickets, abuse attempts, and workflow-specific attack patterns · Cross-system action graph linking agent permissions, customer state, verification strength, and allowed mutations · Evidence base of approved, stepped-up, and blocked actions that improves policy precision and audit credibility
Kill criteria
Fewer than 8 of the first 20 qualified ICP interviews confirm a live plan to let AI agents execute account-recovery, refund, or entitlement mutations within 12 months. · Fewer than 2 of the first 4 paid pilots convert to annual production contracts above $100k because native controls or manual review remain sufficient. · Median time to first replay exceeds 45 days or shadow-mode false-positive rate stays above 10% across the first 3 deployments.
Milestones
0–12 months
Package Zendesk or Salesforce plus one identity provider plus one action-system deployment for the first protected workflow.
Sign 6-8 design partners and convert at least 3 into paid launch-readiness pilots.
Put 2 customers into production with shadow replay, step-up approval, evidence export, and emergency kill switch.
Prove first replay evidence in 30 days and production go-live in under 90 days on the packaged path.
12–24 months
Add reusable policy packs for refunds and entitlement restoration plus production-grade inline enforcement.
Grow to 12-15 production customers and expand at least half of them to a second governed workflow.
Make implementation and identity partners a material source of qualified pipeline.
Launch premium evidence-retention and incident-review modules.
24–36 months
Expand the mutation-control layer into disputes, seller operations, and workforce-access changes.
Build benchmark data on safe approval baselines and attack patterns across support workflows.
Reach category credibility as the neutral cross-stack control layer for customer-facing action-taking agents.
Strategy map
flowchart LR
Wedge[Account recovery launch gate] --> MVP[Replay engine plus step-up runtime]
MVP --> Proof[Safe go-live for one protected workflow]
Proof --> Expansion[More mutations and adjacent operations]
Founding team
Role
Start timing
Rationale
Founder/CEO
Month 0
Own founder-led sales, design-partner recruitment, and product positioning because the primary risk is customer timing and budget urgency.
Founding eng
Month 0
Build the replay engine, action graph, and first runtime step-up control path needed for a credible pilot.
Security/policy engineer
Month 3
Turn design-partner learnings into reusable abuse scenarios, approval policies, and evidence exports that customers trust.
Solutions and integration engineer
Month 3-6
Reduce deployment time across Zendesk or Salesforce, identity providers, and customer admin tools before GTM scales.
Partnerships and customer success lead
Month 9-12
Convert implementation and identity partners into channel leverage only after the packaged deployment path and pilot conversion model work.
Experiment roadmap
Horizon
Experiment
Hypothesis
Success metric
Owner
0–90 days
Interview 25 security, trust, and customer-platform leaders at gaming, subscription, wallet, and marketplace companies.
A meaningful share of beachhead accounts are planning action-taking support workflows now, not in a distant roadmap.
At least 10 qualified prospects name a live workflow, planned go-live window, and executive reviewer.
Founder/CEO
0–90 days
Collect historical ticket data and abuse cases from 3 design partners and benchmark password resets, refunds, and entitlement restoration.
One workflow shows a clearly better precision-to-ROI tradeoff for the first packaged product.
A ranked benchmark with one winning workflow and measurable false-positive and fraud-catch baselines across 3 data sets.
Founding eng
0–90 days
Ship the first Zendesk or Salesforce plus identity-provider plus admin-action replay prototype.
The initial integration path can produce replay evidence quickly enough to support a paid launch-readiness sale.
One design partner sees replay results, policy recommendations, and evidence logs within 30 days of kickoff.
Founding eng
90–180 days
Convert 3 design partners into paid pilots with explicit production-go-live criteria.
Prospects will pay for launch-readiness and step-up control before full category standards are set.
3 paid pilots signed at $35k+ each with agreed success criteria and named budget owner.
Founder/CEO
90–180 days
Run shadow mode and step-up approval on the first live protected workflow.
Step-up control can reduce perceived launch risk without breaking support operations.
At least 2 pilots show false-positive rate below 10% and median step-up resolution under 5 minutes on legitimate actions.
Security/policy lead
6–12 months
Launch 2 implementation or identity partners and test second-workflow expansion in production accounts.
Channel partners can source qualified pilots and existing customers will expand from one workflow to a second mutation type.
2 partner-sourced pilots and 2 production customers adding a second governed workflow within 12 months.
Partnerships lead
Risk assessment
Business plan risks — 5 mapped
Impact →
High
R2
R3
R4
R1
Medium
R5
Low
Low
Medium
High
Likelihood →
R1Salesforce, Zendesk, or horizontal agent-security vendors close enough of the control gap to compress standalone demand. · Highlikelihood / Highimpact — Differentiate on support-specific replay, neutral cross-stack policy control, and evidence portability across mixed environments.
R2Target support teams keep agents in assistive mode longer than expected, delaying launch-readiness budgets. · Mediumlikelihood / Highimpact — Sell only into accounts with named go-live programs, keep shadow-mode value high, and avoid scaling sales spend until action-taking timelines are verified.
R3Internal admin tools lack stable APIs or approval hooks, turning deployments into brittle custom integrations. · Mediumlikelihood / Highimpact — Start with API-accessible workflows, require one supported action hook in the pilot, and reject accounts that break the packaged model.
R4Overblocking or slow step-up approvals reduce support productivity and erode champion support. · Mediumlikelihood / Highimpact — Begin in shadow mode, tune on historical tickets, and make step-up the default before hard blocks for most customers.
R5Budget ownership stays split across security, CX, fraud, and trust teams, stretching procurement cycles. · Mediumlikelihood / Mediumimpact — Package the product around one production-readiness decision and require a named economic buyer before moving from discovery into pilot.
Risk
Likelihood
Impact
Mitigation
Salesforce, Zendesk, or horizontal agent-security vendors close enough of the control gap to compress standalone demand.
High
High
Differentiate on support-specific replay, neutral cross-stack policy control, and evidence portability across mixed environments.
Target support teams keep agents in assistive mode longer than expected, delaying launch-readiness budgets.
Medium
High
Sell only into accounts with named go-live programs, keep shadow-mode value high, and avoid scaling sales spend until action-taking timelines are verified.
Internal admin tools lack stable APIs or approval hooks, turning deployments into brittle custom integrations.
Medium
High
Start with API-accessible workflows, require one supported action hook in the pilot, and reject accounts that break the packaged model.
Overblocking or slow step-up approvals reduce support productivity and erode champion support.
Medium
High
Begin in shadow mode, tune on historical tickets, and make step-up the default before hard blocks for most customers.
Budget ownership stays split across security, CX, fraud, and trust teams, stretching procurement cycles.
Medium
Medium
Package the product around one production-readiness decision and require a named economic buyer before moving from discovery into pilot.
First customer
Title
Head of Trust and Safety Engineering at a gaming marketplace
Profile
A consumer platform with 10+ million user accounts, centralized Zendesk or Salesforce support, stored-value or digital-entitlement workflows, and a roadmap to let AI agents approve account recovery or entitlement restoration.
Trigger
A production-readiness review or post-incident security escalation as the company moves one support workflow from reply drafting to live state-changing actions.
Buyer
CISO
Initial contract
Paid 6-8 week launch-readiness pilot around $35k-$60k for one workflow, credited toward a $100k-$150k annual production contract that expands as more mutations go under policy.
What must be true
At least 40% of qualified beachhead accounts must plan to let AI agents execute account-recovery, refund, or entitlement actions within 12 months.
At least half of qualified prospects must identify a cross-stack control gap that native Salesforce, Zendesk, or existing fraud tooling does not solve.
The packaged first deployment must produce replay evidence and approval recommendations within 30-45 days using Zendesk or Salesforce plus one action system.
Shadow-mode policies must keep false positives below 10% on legitimate mutations and median step-up latency under 5 minutes.
Paid pilots must convert to $100k+ production contracts often enough that at least half of early production customers expand to a second protected workflow within 12 months.
Open diligence questions
Which first workflow produces the best precision-to-ROI tradeoff: password resets, refunds, or digital entitlement restoration?
How many target accounts have API-accessible admin tools versus browser-only internal consoles that would slow deployment?
Who owns the budget after pilot approval: CISO, VP Customer Platform Engineering, or trust and fraud leadership?
What false-positive and approval-latency thresholds will support operations accept before runtime blocking goes live?
How often do prospects require neutral cross-stack coverage across help desk, CRM, and off-platform admin tools rather than native vendor controls alone?
Investor verdict
Call
Meet / investigate further
Conviction
Strong wedge and timing signal, but conviction depends on proving that action-taking support workflows are moving now and that a neutral overlay beats native controls.
Why believe
The company targets a specific mutation boundary where a visible support-automation incident and existing AI-support adoption create immediate budgetable pain.
Why doubt
Native CX platforms, generic agent-security vendors, and assistive-only workflows can still delay or absorb spend unless the startup proves faster deployment and better cross-stack control.
Next diligence
Verify 3-5 design-partner opportunities, confirm one workflow can reach replay evidence in under 45 days, and show that paid pilots convert to $100k+ production contracts.
Section
Financial model
3-year totals
Year 1 revenue
$230KEBITDA $-748K · Cash EOP $2.25M
Year 2 revenue
$935KEBITDA $-1.15M · Cash EOP $1.10M
Year 3 revenue
$3.24MEBITDA $-442K · Cash EOP $663K
Unit economics
ARPU (annual)
$135K
Gross margin
72%
CAC
$60KPayback 7.4 months
LTV / CAC
9.0xLTV $540K
Funding ask
Round
pre-seed · $3.0M
Runway
24 months
Milestone
Reach 13 production customers, prove second-workflow expansion, and enter the next raise with partner-sourced pipeline plus 6 months of cash buffer.
Model sanity
Revenue engine. Base-case Y3 revenue comes from converting three Y1 pilots into a 13-customer Y2 base and then adding partner-assisted production customers plus second-workflow upsell to reach 32 customers by Q4Y3.
Must go right. The packaged deployment path has to keep the sales cycle near six months because sales-cycle slippage is the biggest combined hit to Y3 revenue and cash in the sensitivity table.
Model breaks if. If action-taking support programs stay assistive-only and production customers stall near 20, the downside scenario drives cash below zero before the next round.
Next-round proof. The next financing is justified if the company exits Q4Y2 with roughly 13 production customers, visible second-workflow attach, and enough pipeline from partners to support the Y3 ramp.
Revenue, cash, and EBITDA — 12-month Y1 + 8-quarter Y2/Y3
Revenue (line, area)
Cash EOP (dashed)
EBITDA (bars, gray = loss)
Use of funds — $3.0M pre-seedHeadcount build by role — peak14 FTE
Founder/Exec
Engineering
Security/Policy
Solutions/Integration
Customer Success/Partnerships
Sales/GTM
G&A/Ops
Year-3 scenarios — base / downside / upside
Y3 revenue
Y3 EBITDA
Cash low point
Description
Downside
$1.79M
-$1.33M
-$459K
Buyer adoption of action-taking support workflows slips by roughly two quarters, so production-customer growth and expansion attach both lag the base case.
Base
$3.24M
-$442K
$624K
Three paid pilots land in Y1, the packaged deployment path produces 13 production customers by Q4Y2, and partner-assisted expansion lifts the company to 32 by Q4Y3.
Upside
$4.48M
$546K
$1.31M
Pilot conversion, partner sourcing, and expansion attach all outperform, creating a faster jump from workflow one into repeatable multi-workflow land-and-expand.
Sensitivity — Y3 cash and revenue impact, sorted by magnitude
Variable
Downside
Upside
Cash impact
Revenue impact
sales cycle
9-month enterprise cycle with slower production approvals
4.5-month cycle after packaged deployment proof
-$520K
-$650K
CAC
$80K CAC because channel leverage arrives late
$45K CAC with partner-sourced deals
-$380K
-$180K
ARPU
$115K steady-state ARR per production customer
$150K steady-state ARR per production customer
-$330K
-$470K
hiring pace
Pull two hires forward before packaged deployment is repeatable
Delay two noncritical hires until Q4Y2 if pilots slip
-$320K
$0K
churn
2.5% monthly production churn
1.0% monthly production churn
-$210K
-$290K
gross margin
70% Y3 gross margin because custom integrations stay high
75% Y3 gross margin with cleaner packaging
-$130K
$0K
Scenarios
Scenario
Y3 revenue
Y3 EBITDA
Cash low point
Description
Key changes
Downside
$1.79M
$-1.33M
$-459K
Buyer adoption of action-taking support workflows slips by roughly two quarters, so production-customer growth and expansion attach both lag the base case.
Q4Y2 production customers land at about 10 instead of 13 and Q4Y3 lands near 20 instead of 32 because the sales cycle stretches toward 9 months.
Steady-state ARPU falls toward $110K as second-workflow attach and premium evidence modules arrive later.
Gross margin tops out near 70% because deployments stay more services-heavy.
Base
$3.24M
$-442K
$624K
Three paid pilots land in Y1, the packaged deployment path produces 13 production customers by Q4Y2, and partner-assisted expansion lifts the company to 32 by Q4Y3.
Two of the first three paid pilots convert inside Y1 and the third converts at the start of Y2.
Production customers scale from 13 at Q4Y2 to 32 at Q4Y3 with moderate second-workflow attach.
Gross margin improves from 65% in Y1 to 72% in Y3 as integrations package and services intensity falls.
Upside
$4.48M
$546K
$1.31M
Pilot conversion, partner sourcing, and expansion attach all outperform, creating a faster jump from workflow one into repeatable multi-workflow land-and-expand.
Q4Y2 production customers reach about 17 and Q4Y3 reaches about 40 as sales cycles compress toward 4-5 months.
Steady-state ARPU rises toward $150K as second-workflow and evidence-module attach happen earlier.
Gross margin reaches about 74% because the packaged path removes more custom integration work.
Sensitivity
Variable
Downside
Base
Upside
ARPU
$115K steady-state ARR per production customer
$135K steady-state ARR per production customer
$150K steady-state ARR per production customer
CAC
$80K CAC because channel leverage arrives late
$60K CAC
$45K CAC with partner-sourced deals
churn
2.5% monthly production churn
1.5% monthly production churn
1.0% monthly production churn
sales cycle
9-month enterprise cycle with slower production approvals
6-month cycle from pilot to annual contract
4.5-month cycle after packaged deployment proof
gross margin
70% Y3 gross margin because custom integrations stay high
72% Y3 gross margin
75% Y3 gross margin with cleaner packaging
hiring pace
Pull two hires forward before packaged deployment is repeatable
Current milestone-gated hiring plan
Delay two noncritical hires until Q4Y2 if pilots slip
Key assumptions (25)
ID
Name
Value
Unit
Source
A1
Starting cash at model start
3000
K USD
[BP fundingAsk targetFundingRangeUsd $2.5-4.0M and runwayMonths 18]; base case uses a $3.0M pre-seed close before 2026-07.
A2
Starting paying customers
0
accounts
[BP milestones and firstCustomer]; no existing paying accounts are assumed at model start.
A3
Paid pilot fee
50
K USD per pilot
[BP firstCustomer.initialContract $35k-$60k paid pilot]; midpoint rounded to $50k.
[BP firstCustomer.initialContract $100k-$150k annual production contract]; base case uses a conservative midpoint-ish $120k.
A6
Expansion ARR uplift
25
K USD per expanded customer-year
[BP businessModel.revenueStreams plus milestones for second workflow and premium evidence modules]; conservative add-on per expanded account.
A7
Expansion attach rate
15 by Q4Y2; 35 by Q4Y3
pct of production customers
[BP milestones says at least half of production customers should expand within 12 months]; model uses a lower blended attach rate because newer cohorts have not aged into second-workflow expansion yet.
A8
Gross margin progression
65 Y1; 70 Y2; 72 Y3
pct
[BP businessModel targetGrossMarginPct 70]; base case assumes packaged integrations lift margin slightly above target by Y3.
A9
Monthly production churn
1.5
pct
Startup-finance heuristic for sticky but early enterprise security software; intentionally higher than mature infrastructure benchmarks.
A10
Paid pilot to production conversion in first year
67
pct
[BP milestones target 3 paid pilots and 2 production deployments in the first 12 months]; modeled as 2 of the first 3 pilots converting inside Y1.
A11
Y1 paying-customer schedule
M6 1; M8 2; M11 3; M12 3
accounts
[BP milestones]; Y1 customersEop counts paying pilot or production accounts because pilots are the first billed state.
Flags: Y1 revenue is intentionally lumpy because the model follows the BP sequence of paid pilots converting into annual contracts rather than assuming straight-line SaaS MRR from day one. · The base case depends on API-accessible admin tools and packaged integrations; browser-only back-office workflows would slow deployment and compress gross margin. · Q4Y3 still reaches only modest positive quarterly EBITDA, so the company should raise the next round from Q4Y2 to Q2Y3 proof points rather than waiting for cash to run lower. · Rule of 40 looks unusually high because Y2 revenue starts from a small base; investors should focus more on conversion proof, gross margin progress, and burn multiple.
Section
Top risks
Incumbent workflow vendors. Helpdesk, CRM, or agent-builder vendors could add lightweight approval gates and try to absorb the category. Mitigation: Win on cross-system attack replay, fraud-specific policy packs, and runtime evidence across heterogeneous stacks that single vendors do not control.
Slow move to action-taking agents. Some enterprises may keep support agents in draft-only mode longer than expected, delaying budget for enforcement. Mitigation: Sell shadow-mode testing first to teams already under pressure to automate account recovery or refunds, then expand into runtime controls at go-live.
Integration and false-positive burden. Connecting internal admin tools and overblocking legitimate actions could slow support operations if deployment is too broad too early. Mitigation: Start with one workflow such as password resets or refunds, learn approval baselines in observe mode, and expand only after precision targets are met.
FBI IC3. Internet Crime Complaint Center (IC3) | Account Takeover Fraud via Impersonation of Financial Institution Support · https://www.ic3.gov/PSA/2025/PSA251125