Kiteworks, which empowers organizations to effectively manage risk in every send, share, receive, and use of private data, has announced a strategic partnership with Reco, a leader in Agent Ecosystem Security. The collaboration is intended to give enterprises greater visibility and control across their agent and application ecosystems while addressing a growing governance challenge created by the rapid adoption of AI agents.
The partnership brings together Reco’s agent and identity risk intelligence with the Kiteworks control plane, providing enterprises with a governed approach that spans agent discovery, risk identification, data access, and policy enforcement. As organizations deploy AI agents faster than security teams can assess them, the combined approach is designed to help enterprises identify where agent risk exists and control what those agents can access, modify, and exchange through a unified, auditable policy framework.
Reco continuously discovers and maps SaaS applications, human and non-human identities, and AI agents operating throughout an enterprise environment. This visibility helps identify application sprawl, misconfigurations, and excessive permissions. Under the partnership, Reco’s identity and risk intelligence is designed to feed into the Kiteworks control plane, which manages how sensitive data accessible to those identities is accessed, modified, shared, and exchanged across email, file sharing, APIs, and AI agent workflows.
Kiteworks Data Policy Engine can respond to those risk signals in real time by applying view-only permissions, SafeEDIT possessionless editing, encryption, or blocking access altogether. Kiteworks Secure MCP Server extends these governance capabilities to AI agents built using the Model Context Protocol. As a result, AI agents can be governed using the same policies, encryption controls, and audit trails applied to human users, providing security teams with a unified enforcement layer for both human and non-human identities.
The partnership comes as a growing gap between AI risk visibility and enforcement continues to challenge enterprises. According to Kiteworks’ research, fewer than 31% of organizations have implemented any form of AI containment control. At the same time, 65% reported discovering employees using unauthorized AI tools with organizational data during the past year, while fewer than half subsequently implemented technical controls designed to prevent similar activity. The findings underscore the need to combine identity and AI agent discovery with effective data-level enforcement.
For organizations operating in regulated sectors, the partnership is also designed to support compliance requirements by connecting risk discovery with evidence of actual data activity. Kiteworks is FedRAMP High In Process, FedRAMP Moderate Authorized, FIPS 140-3, among numerous others, and maps to frameworks including HIPAA, CMMC 2.0, GDPR, and PCI DSS. This enables joint customers to maintain audit-ready evidence that extends from identity discovery through the underlying data event rather than relying solely on a risk score.
“Security teams don’t have a visibility problem anymore. Tools like Reco have solved that,” said Sean Kelley, Global Director of Strategic Alliances, Kiteworks. “What they’ve had is an enforcement gap – specifically, knowing an agent exists and what it can reach is not the same as governing what it does with sensitive data. This partnership connects those two halves. Reco tells you where the risk is, and the Kiteworks control plane makes sure that risk is governed the moment it touches sensitive data, whether the identity behind it is a person or an agent.”
“Enterprises are adopting agents across their third-party ecosystem faster than they can govern them, and that’s exactly the gap Reco was built to close,” said Zoe Hillenmeyer, Chief Operating Officer, Reco. “Partnering with Kiteworks lets us extend that value further. Our customers get complete visibility into every agent and identity touching their ecosystem, and now a direct path to enforce data governance on what those agents can access and do. Together, we’re giving joint customers a single, connected answer to agentic AI risk.”
Additional information about the Kiteworks and Reco partnership is available in the solution brief here.
Kiteworks is also addressing the data security and compliance challenges associated with AI and highlighting how Kiteworks Compliant AI can help organizations manage those risks at AI4 2026. The company will be at Booth #1141 at The Venetian in Las Vegas, where Craig Pfister, Global VP, Solutions Architect at Kiteworks, will deliver “Controlling Data Access and Use by AI Agents for Compliant AI” on Wednesday, August 5, from 2:25–2:45 PM in Delfino Ballroom 4104. Reco will additionally exhibit at Black Hat USA at Booth #1644.
Kiteworks’ mission is to empower organizations to effectively manage risk in every send, share, receive, and use of private data. The Kiteworks platform provides customers with a secure data exchange that delivers data governance, compliance, and protection in a unified control plane. Kiteworks unifies, tracks, controls, and secures sensitive data moving within, into, and out of their organization, significantly improving risk management and ensuring regulatory compliance on all private data exchanges. Headquartered in Silicon Valley, Kiteworks protects over 100 million end-users and thousands of global enterprises and government agencies.
Reco secures the ecosystem so enterprises can enable agents with confidence. The Reco Platform runs on three components: Reco Factory builds deep third-party agent and app integrations in hours, not weeks. Reco Library is the largest agent and app catalog in the market, giving security teams pre-classified risk profiles from day one instead of a blank slate, with over 260 agent and app integrations available to-date. Reco Graph maps every agent, app, and connection in your ecosystem across four dimensions (identity, permissions, connectivity, and activity), so nothing runs unmonitored. Reco is backed by top-tier investors, including Insight Partners, Quadrille, SentinelOne Ventures, Workday Ventures, TIAA Ventures, Zeev Ventures, boldstart, and Angular Ventures. Reco was named a Global Infosec Awards winner in 2024 and 2026, a CRN® Stellar Startup in 2024 and 2025, and a 2025 SINET16 Innovator. Learn more or book a demo at www.reco.ai.
