BREAKING: Zania closes $18M Series A led by NEA Shruti Gupta - Founder & CEO, Zania Revenue up 10x in six months Backed by Menlo Ventures & Anthropic via the Anthology Fund Customers: Plaid, Grant Thornton, Stanford Ex-CISO: Airbnb, Instacart, Brex AI teammates that finish compliance work start to finish BREAKING: Zania closes $18M Series A led by NEA Shruti Gupta - Founder & CEO, Zania Revenue up 10x in six months Backed by Menlo Ventures & Anthropic via the Anthology Fund Customers: Plaid, Grant Thornton, Stanford Ex-CISO: Airbnb, Instacart, Brex AI teammates that finish compliance work start to finish
Profile · Founders

She spent a decade inside security teams. Then she built the AI teammate that does the work.

Shruti Gupta was a CISO at Airbnb, Instacart and Brex before she started Zania. Her company builds AI agents that don't just organize compliance work - they finish it. In September 2025, NEA led an $18 million round to prove the point.

Ask Shruti Gupta what compliance actually feels like from the inside and you get an answer with no marketing gloss. Security work, she has said, runs in two modes at once - "proactive and reactive, always anticipating and responding to threats." She lived that contradiction for years, across four different companies, before she decided the fix was not a better dashboard. It was software that could do the job.

That is the whole idea behind Zania, the Palo Alto company she founded in 2023 and now runs as CEO. Zania builds what Gupta calls AI "teammates" - agents pointed at the least-loved corners of governance, risk and compliance. Evidence collection. Controls testing. Gap analysis. Vendor questionnaires. The paperwork that keeps auditors employed and everyone else awake. In September 2025, the venture firm NEA led an $18 million Series A into the bet, and a roster of investors that most seed-stage founders would frame and hang on a wall signed on with them.

The résumé is the thesis

Most founders have to guess at the problem they are solving. Gupta did not. She holds a master's in information security from Georgia Tech, and she spent the years after it embedded in security teams that operate at genuine scale. She led AI-driven work at Microsoft Identity, protecting what one profile described as "one of the world's largest and most targeted systems." Before and around that, she held founding security engineering and CISO roles at Airbnb, Instacart and Brex.

Read that list again, because it is the product roadmap in disguise. A consumer travel platform, a grocery marketplace, a fintech, and one of the biggest identity systems on the planet - four very different threat models, four different compliance regimes, and one person who had to answer for all of them. When she talks about which GRC tasks are soul-crushing, she is not theorizing. She filled out the questionnaires. She chased the evidence. She sat in the audits.

"We're transforming the space from tools that merely organize work into true AI teammates that execute highly complex and critical tasks from start to finish." Shruti Gupta, on the Series A

There is a quiet confidence in that line. Plenty of companies sell "AI for compliance" and mean a smarter search box or a friendlier form. Gupta drew a harder line. The measure of a teammate is not whether it helps you work - it is whether it finishes the work. A copilot suggests. A teammate hands back the completed audit.

What the agents actually do

The clearest window into that philosophy is Zania's Gap Assessment agent. Point it at a company's pile of policy documents and evidence files - thousands of them, across more than 80 languages - and it cross-references everything against hundreds of control requirements to find where the gaps are. Work that used to eat months of a compliance team's calendar collapses into minutes. That is not a productivity nudge. That is a different unit of time.

80+
Languages the gap agent reads
10x
Revenue growth in six months
$18M
Series A led by NEA

Around that core, Zania runs agents for continuous evidence collection, controls testing, full-lifecycle vendor assessments, internal risk evaluations, and precise responses to the security questionnaires that every enterprise deal drags along behind it. The frameworks they map to are the alphabet soup every security leader can recite in their sleep - SOC 2, ISO 27001, HIPAA, NIST CSF. The pitch to a buyer is blunt: the drudgery you staff a team to survive, an agent can own.

Manual GRC vs. an AI teammate — time to complete

Gap assessment
Months, by hand
With Zania
Minutes
Doc coverage
Thousands of files

Illustrative, based on Zania's public description of its Gap Assessment module.

Why the smart money showed up

The Series A tells you who is paying attention. NEA led. The Anthology Fund - backed by Menlo Ventures and Anthropic - joined, which is a notable signal on its own: when the people building the frontier reasoning models put money into a compliance startup, it is worth asking what they see. Palm Drive Capital came in too, alongside a syndicate of senior operators from Amazon, Airbnb, PayPal, ByteDance, Reddit, Roblox and PwC.

That last group matters more than the logos suggest. These are people who have personally lived the enterprise security and audit grind. They are, in a sense, the customer and the investor at once. Gupta said the round was oversubscribed, and the plan for the money is unglamorous in the best way: triple the engineering and go-to-market teams, expand the library of agents, and invest in proprietary models built for the multi-step reasoning that real compliance work demands.

The cap table, briefly

  • NEA — lead investor on the $18M Series A
  • Anthology Fund — backed by Menlo Ventures & Anthropic
  • Palm Drive Capital — participating investor
  • Operator angels — from Amazon, Airbnb, PayPal, ByteDance, Reddit, Roblox, PwC

The early customer list backs the confidence. Zania has named the fintech infrastructure company Plaid, the advisory firm Grant Thornton, Stanford University, and one of the Big Four accounting firms among its users. None of those are easy to win. A Big Four firm does not run experimental software against its own audit work unless the output survives scrutiny. Landing them a year or so out of founding is the kind of proof no pitch deck can manufacture.

A year from idea to production

The timeline is worth sitting with. Zania was founded in 2023. Its first AI agents went live in late 2024. By the time of the Series A announcement in September 2025, annual recurring revenue had grown tenfold in six months. That is roughly a year from founding to shipping, and then a very steep curve after that.

Pre-2023Inside the trenches. Founding security engineering and CISO roles at Airbnb, Instacart and Brex; AI-driven identity security at Microsoft.
2023Zania is founded in Palo Alto, California.
Late 2024First agents ship. Zania's initial AI compliance agents go into production.
202510x in six months. Annual recurring revenue grows tenfold as enterprise logos land.
Sep 2025$18M Series A led by NEA, with plans to triple the team.

Speed like that usually comes from clarity, not luck. Gupta was not learning the domain on the job. She was building for the version of herself that used to sign off on controls at 11pm, and that shortcut - founder as former customer - is hard to fake and harder to compete with.

The honest read on the stress she automated

In an interview before Zania took off, Gupta was asked to rate the stress of the CISO job on a scale of one to ten. She landed on "around 7." Daunting, she allowed, but rewarding - because you know you are protecting critical assets. It is a very engineer answer: measured, specific, no drama. She has also pointed to organizational silos as the real enemy of good security, and to a "security-first mindset" as the thing that has to spread across a company rather than sit in one team's corner.

"The core tension is balancing the need for robust security with the operational efficiency and innovation of the organization." Shruti Gupta

That tension - security as the thing that either protects the business or slows it down - is exactly the seam Zania is trying to close. If an agent can absorb the tedious, high-stakes work, the human security leaders get to spend their attention on the parts that genuinely need judgment. The stress does not vanish. It gets redistributed to where it earns its keep.

What she is actually building toward

Gupta's stated ambition is not a single killer feature. It is coverage - an agent for every meaningful step of the governance, risk and compliance lifecycle, so that the whole thing can run end to end with people supervising rather than grinding. The investment in proprietary reasoning models is the tell. Compliance is not a lookup problem; it is a chain-of-reasoning problem, where one control implies another and evidence has to be weighed, not just retrieved. Solving that well is the difference between a demo and a company.

There is a broader wager underneath all of it. The market is crowded with AI copilots that make knowledge workers a little faster. Gupta is betting that the durable value is in agents that carry a task all the way to done - that the future org chart has AI teammates on it, not just AI tools in the sidebar. Whether that reshapes GRC on the timeline she is chasing is still an open question. But she has arranged the pieces the way someone does when they mean it: the right domain, the right backers, the right early customers, and a founder who knows the work in her hands.

The most telling detail might be the simplest one. Gupta did not pick a problem because a market map told her it was big. She picked the one she had personally spent years enduring - and then built the thing she wishes had existed when she was the one on the hook.

Diagram: from tool to teammate, organize to assist to execute
The Zania worldview in one line - most compliance software stops at "organize." Gupta is aiming for "execute."
zaniaai compliance agentsgrc automationagentic aicisoai securitynea series afounderenterprise saassoc 2iso 27001vendor risk