ThreatLocker has raised $190 million in a Series F round led by Elephant, with a significant new investment from Koch Disruptive Technologies, the Orlando-based Zero Trust security company said on July 29, 2026. Existing backers D. E. Shaw Ventures and Arthur Ventures also took part.
The company says the capital will fund continued development of the controls it already sells against AI-related security risk, further work on its Zero Trust Platform, and an international push that starts with an office in Reading, in the UK.
Where the money goes
ThreatLocker sells an inversion of the usual security model. Rather than identifying malicious activity once it is inside an environment, the platform denies anything that has not been explicitly permitted. That approach maps onto the AI-agent problem more directly than detection-based tooling does, and it is the argument the round is funding.
Two products already in the catalogue carry most of that weight. ThreatLocker Allowlisting blocks unauthorized AI tools and AI-generated code from executing at all. Ringfencing, the containment layer, governs what an approved application or agent can reach, modify, and interact with once it is running. Further controls cover which AI websites employees can use and what data is allowed to leave the environment.
“We are living in a world where new agents are constantly being introduced and granted access to sensitive resources, which makes our mission more urgent,” said Danny Jenkins, ThreatLocker’s CEO and co-founder.
That is a live buying trigger rather than a projection. IBM’s most recent breach research put AI inside roughly one in four malicious breaches, and security teams now have to account for both agents acting inside their estates and attackers using AI to accelerate exploitation.
The AI work sits on a platform that widened considerably five months ago. On March 5, 2026, ThreatLocker launched Zero Trust Network Access and Zero Trust Cloud Access, which require a connection to originate from a device the platform has approved before it reaches a network or a SaaS application such as Microsoft 365, Salesforce (CRM ), or GitHub. Stolen credentials plus a phished multi-factor code no longer clear the bar. That gave the company one control surface spanning endpoints, networks, and cloud resources, which is the base the agent-specific controls extend.
Elephant back in the lead seat
The investor lineup tells its own story. Elephant, a Boston firm, led ThreatLocker’s $20 million Series B in May 2021, then ceded the lead to General Atlantic, which fronted both the Series C and the $115 million Series D announced on April 24, 2024. Elephant is now back at the front of a round five years after its first lead, with Jeremiah Daly, the partner who signed the Series B, again speaking for the firm.
“As more organizations seek prevention-based security and practical approaches to Zero Trust, ThreatLocker is uniquely positioned to capture that demand,” Daly said.
Koch Disruptive Technologies is the genuinely new name on the cap table. KDT is the venture and growth investment arm of Koch, the privately held industrial group whose annual revenues the firm puts above $125 billion, and it writes cheques from seed through late-stage growth. It says it will put its partner network and its Koch Labs unit to work alongside the ThreatLocker team. For a vendor whose customers skew toward managed service providers and midmarket IT departments, an investor wired into a global industrial group is a distribution channel as much as a source of capital.
BofA Securities acted as exclusive placement agent on the round, and Latham & Watkins was legal counsel.
The scale behind the round
ThreatLocker says its platform now protects more than 70,000 organizations. At the Series D the company put that number above 50,000, and it says it has appeared on the Inc. 5000 ranking of fast-growing US private companies in each of the past two years. Its footprint has moved with the customer count: offices in Brisbane and Dubai now sit alongside the Orlando headquarters and the Dublin operation that covers Europe, and Reading adds direct coverage of the UK.
The round lands in the busiest corner of security financing. Capital has been moving steadily toward companies whose pitch is governing what autonomous software is permitted to do. Hush Security raised $30 million to manage machine and agent identities, Mate Security raised $35 million to build an open base for AI security operations, and Geordie AI raised a $30 million Series A on the same agent-control thesis. Most of those companies are building the category from scratch.
ThreatLocker’s position is that it reaches the same market by widening a deny-by-default policy engine that already ships to 70,000 customers, which is a shorter path to revenue than a new product line. The Reading office is the first item the $190 million buys, and the next tranche of platform work is where that argument meets a market filling up with agents.

