Prevalent AI has raised $22 million in growth capital from Integrity Growth Partners (IGP), marking the first primary outside investment in the London-based company’s nine-year history. The funding comes as enterprises face a growing problem alongside the rapid adoption of artificial intelligence: AI systems may be becoming more capable, but their decisions are only as reliable as the organizational data and context available to them.
Founded in 2017, Prevalent AI has remained bootstrapped and, according to the company, profitable since securing its first customer. The company says annual recurring revenue has more than doubled over the past year. The new capital will be directed toward expanding its global commercial organization, accelerating its push into the U.S., strengthening its leadership team, and extending technology originally developed for cybersecurity into broader enterprise risk and AI applications.
First outside capital after nine years
The funding is notable partly because Prevalent AI took a relatively unusual route through the cybersecurity market. Rather than relying on repeated venture rounds to finance growth, the company spent nearly a decade building around revenue from large enterprise customers before raising primary institutional capital.
Prevalent AI was co-founded by CEO Paul Stokes and COO Arun Raj, with roots in the UK intelligence community. The company says its founding team includes alumni of Government Communications Headquarters (GCHQ), an experience that helped shape its focus on connecting fragmented information in environments where incomplete or inaccurate data can have significant operational consequences.
ISTARI, which is backed by Singapore investment company Temasek, became a minority shareholder in 2021 through a secondary transaction, but the new IGP investment represents the first primary capital going directly into the company.
Turning fragmented enterprise data into context
The central problem Prevalent AI is trying to address is not a shortage of enterprise data. It is that the data needed to make a decision often exists across dozens or even hundreds of systems that describe the same organization differently.
A security team, for example, may depend on vulnerability scanners, endpoint platforms, identity systems, cloud infrastructure, configuration management databases, ticketing software and operational tools. Each system contains a portion of the picture, with duplicated records, conflicting identifiers and incomplete relationships between assets.
Prevalent AI’s Security Data Fabric is designed to ingest information from these different systems, normalize it, resolve inconsistencies and map relationships between assets, identities, vulnerabilities, applications, controls and other operational information. The resulting data is maintained as a continuously updated knowledge graph rather than another isolated security database.
That distinction becomes increasingly important when AI agents enter the equation. Humans can sometimes recognize that two slightly different records refer to the same server, employee or application. An automated agent making decisions at machine speed needs those relationships to be established more reliably in advance.
How Prevalent AI’s technology works
At the integration layer, Prevalent AI uses DataBridge to connect cloud, Software-as-a-Service (SaaS), on-premises and operational systems. The platform then applies entity resolution to reconcile records and build a unified representation of the enterprise environment.
The knowledge graph adds another layer by connecting those entities through their relationships. Instead of treating a vulnerability as an isolated finding, for instance, the system can connect it with the affected asset, the asset’s business importance, its owner, associated identities, existing security controls and relevant threat information.
Prevalent’s exposure-management tools use this context to identify where risk is concentrated and prioritize remediation. The company’s platform can also correlate findings across tools to reduce duplicated vulnerability records and continuously monitor changes to assets, identities and infrastructure.
Generative AI is being added on top of that structured foundation rather than being asked to interpret raw enterprise data independently. Prevalent’s Navigator tool, for example, lets users query information held in the knowledge graph through a generative AI interface.
The company also offers DataForge, which generates synchronized synthetic datasets for AI development, model testing and quality assurance without requiring sensitive production data to be exposed during experimentation.
Moving beyond cybersecurity
Cybersecurity was a natural starting point because incomplete information can immediately affect decisions around vulnerabilities, identities, incidents and controls. But Prevalent AI increasingly sees its underlying technology as enterprise infrastructure rather than a security-specific product.
The company says customers have already extended the same data foundation into areas including financial crime analysis, operational intelligence, compliance, automation and AI-driven workflows without rebuilding the underlying architecture.
This broader opportunity is one of the main reasons behind the new funding.
For AI agents in particular, the challenge is increasingly shifting from whether a model is intelligent enough to perform a task toward whether it has access to accurate information about the organization in which it is operating. An agent may be capable of identifying a security vulnerability, investigating an account or triggering an automated workflow, but its usefulness drops quickly if it cannot reliably determine which systems exist, how they are connected, who owns them or which policies govern its actions.
Prevalent AI is effectively betting that enterprise context will become an important layer of the AI stack, particularly for organizations where agents are expected to take actions rather than simply generate answers.
Why enterprise AI raises the stakes
The timing of the funding reflects a wider shift in enterprise AI. Organizations are beginning to move beyond standalone copilots toward agents capable of interacting with infrastructure, applications and business processes.
That transition increases the consequences of bad underlying data.
Prevalent AI argues that its sovereign architecture is particularly relevant in these environments. Its platform is designed to operate within infrastructure controlled by the customer, keeping enterprise data under the organization’s control rather than requiring the operational knowledge graph to depend on shared infrastructure or a particular model provider.
For highly regulated sectors, this could become an important consideration as companies experiment with giving AI systems more access to sensitive internal information and greater authority to take actions.
Why trusted context could become critical for enterprise AI
As AI systems move from generating recommendations to taking actions inside businesses, the quality of the data surrounding those systems will become increasingly important. An agent tasked with investigating a security incident, approving a workflow or responding to an operational problem needs more than access to individual databases. It needs an accurate picture of how assets, identities, applications, policies and business processes relate to one another.
This creates a growing infrastructure challenge for enterprises. Many organizations have accumulated years of disconnected software platforms, duplicated records and inconsistent naming conventions. Large language models can make this information easier to query, but they do not automatically resolve contradictions or determine which source should be trusted. Without a reliable context layer, more autonomous AI could simply allow existing data problems to influence decisions at greater speed and scale.
Knowledge graphs and data fabrics could therefore become an important part of the emerging enterprise AI architecture. Rather than replacing databases or AI models, these systems can sit between them, continuously reconciling information and maintaining relationships that agents can use when deciding what actions to take.
The implications also extend well beyond cybersecurity. Similar problems exist in fraud detection, regulatory compliance, supply-chain management, IT operations and other areas where decisions depend on information distributed across multiple systems. As companies deploy agents across these functions, maintaining a consistent representation of the organization may become increasingly necessary.
This could also change how enterprises evaluate AI infrastructure. Model performance will remain important, but organizations may place greater emphasis on the provenance, freshness and relationships of the data feeding those models. In that environment, the competitive advantage may not come solely from having a more capable AI model, but from giving that model a more accurate understanding of the enterprise in which it operates.

