Baselayer Raises $35M Series A to Secure Autonomous Agent Identity and Verification
On September 22, 2026, San Francisco-based startup Baselayer announced it raised $35 million in Series A funding led by M13, with backing from Picus Capital, Torch Capital, Afore Capital, and Socure executive Matt Thompson. The raise brings Baselayer's total funding to approximately $40 million since its 2023 founding. While the platform initially focused on automated Know Your Business (KYB) compliance, fraud assessment, and credit data aggregation for more than 2,000 financial institutions, the fresh capital is explicitly earmarked to extend identity and verification infrastructure to autonomous AI agents.
For DevOps, platform engineering, and security architects, this shift addresses a critical operational blind spot: identity assertion in automated, multi-agent systems. Modern enterprise architectures increasingly provision autonomous agents capable of making programmatic API calls, signing contracts, negotiating pricing, and initiating payments. Traditional IAM (Identity and Access Management) and onboarding pipelines assume an accountable human operator behind every credential or KYC/KYB flow. When agents perform actions autonomously, legacy fraud-detection engines and static authorization mechanisms either trigger excessive false positives or fail to detect agent hijacking and malicious prompt compromise.
This funding fits into the broader enterprise shift toward zero-trust agentic infrastructure. As agent frameworks evolve from simple retrieval-augmented generation (RAG) loops into execution pipelines that trigger write operations across external banking and corporate APIs, security controls must transition from static API keys and OAuth tokens to contextual, behavioral validation. Infrastructure providers are learning that scaling autonomous agents requires the same rigor around machine provenance and fraud scoring that governed the transition to containerized microservices and service mesh mTLS a decade ago.
In practice, engineering leaders building agentic workflows must audit how non-human identities authenticate with third-party APIs and downstream services. Teams should begin decoupling traditional service-account credentials from dynamic agent tasks, implementing verifiable risk scoring before allowing autonomous agents to execute financial or contract-binding transactions. Relying purely on legacy KYB tools will create security gaps as agent-to-agent transactions become standard enterprise traffic.
Read original source