Back to News
IndustryAI Understanding briefing

Serval acquires Ensignia to integrate security into AI agent platform

Serval has acquired software supply chain security startup Ensignia and appointed its founder, Sam Stewart, as Head of Security to govern its expanding AI automation agents.

4 min readRead the linked source
Source-provided image accompanying Serval acquires Ensignia to integrate security into AI agent platform
Source referenceSource recorded
Publisher
unite.ai
Source link
unite.aihttps://www.unite.ai/serval-acquires-ensignia-and-names-sam-stewart-head-of-security/
Source type
Linked source — primary-source status has not been established.
ContextUnderstand this in 60 seconds

Start here

Key terms

AI Agent
A software system that can observe, reason, and take actions to achieve a goal, often using tools and memory.
Guardrails
Rules, checks, and controls that limit unsafe or undesired model behavior.
Embedding
A numeric vector representation that captures semantic meaning of text, images, or other data.
Test yourselfAI Agents Quiz

What happened

Serval, an AI-native enterprise service management company, acquired Ensignia, a software supply chain security startup. As part of the transaction, Serval appointed Ensignia's founder and CEO, Sam Stewart, as its new Head of Security. Financial terms for the acquisition were not disclosed. Stewart will oversee detection and response, corporate security, application security, infrastructure security, and the specific permissions and audit trails governing Serval's automation agents. The move integrates Ensignia's expertise in trusted code, dependencies, and build pipelines directly into Serval's core product development, aligning security controls with the expansion of its AI agents across sensitive enterprise systems.

Serval has completed the acquisition of Ensignia, a startup focused on software supply chain security. The deal includes the appointment of Ensignia's founder and CEO, Sam Stewart, as Serval's Head of Security. While financial terms were not disclosed, the acquisition brings Ensignia's focus on trusted code, dependencies, and build pipelines into Serval's AI-native enterprise service management platform.

Stewart's role encompasses detection and response, corporate security, application security, and infrastructure security. Crucially, his remit also covers the permissions, audit trails, and controls that govern how Serval's automation agents interact with customer environments. This integration is designed to develop agent capabilities and their security controls as a unified system rather than separate layers.

Serval, which launched in 2024 and has grown to approximately 100 employees, positions its platform as an alternative to legacy IT service management tools. Its agents are designed to create automations and resolve employee requests across IT, HR, finance, legal, and security functions. The company recently closed a $75 million Series B led by Sequoia Capital in January 2026, reaching a reported $1 billion valuation.

The acquisition follows the introduction of Catalyst, an automation agent that can build and configure customer environments through natural-language interaction. Catalyst can author workflows, connect integrations, and configure access management. By acquiring Ensignia, Serval aims to ensure that as these agents touch more sensitive systems, the necessary and traceability are built into the core product.

Source details: unite.ai ↗

Why it matters

This acquisition addresses a critical gap in enterprise AI adoption: the governance of autonomous agents that interact with sensitive data and systems. By internalizing supply chain security expertise, Serval aims to ensure that its AI agents operate within strict for identity, authorization, and auditing. This shift signals that enterprise buyers are increasingly prioritizing security architecture and auditability alongside automation speed, particularly as AI agents take on higher-value workflows in finance, HR, and legal sectors.

As AI agents take on more consequential work in enterprise environments, the stakes for identity, authorization, and software integrity rise significantly. An automation agent may need to touch multiple enterprise systems to complete a request, making and traceability central product requirements rather than secondary controls.

This move reflects a broader shift in enterprise AI buying. Buyers are likely to evaluate security architecture, permission models, and auditability alongside model quality and automation speed. Vendors that treat these controls as part of the core product may be better positioned for deployments involving higher-value or regulated workflows.

Serval's co-founder and CTO, Alex McLeod, stated that the company was built on the premise that 'automation and security have to advance together.' He framed enterprise IT as the layer connecting some of a company's most sensitive systems, where a security failure can carry consequences well beyond an individual support ticket.

Stewart's appointment creates a single security mandate across corporate operations, applications, infrastructure, and customer-facing agent governance. This structure can shorten the distance between new agent capabilities and the controls needed to govern them, potentially increasing trust among enterprise customers.

Interactive Mechanism

Interactive Mechanism: How It Actually Works

Explore the underlying technology behind this development interactively.

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
Interactive Concept Check+10 Points
AI Agents Quiz

An agent must create a draft calendar event for Tuesday at 2 p.m. Which evidence would establish the requested result?

What to watch next

Monitor how Serval implements Ensignia's supply chain verification tools within its agent framework. Watch for updates on the specific security controls and audit trails available to enterprise customers, as well as any new partnerships or deployments that highlight the integrated security model. Additionally, observe if other AI-native service management vendors adopt similar strategies of security leadership directly into product development.

Observe how Serval integrates Ensignia's supply chain security tools into its existing agent framework, particularly regarding the verification of software and infrastructure used by its automation agents.

Watch for specific details on the audit trails and permission models that Serval will offer to enterprise customers, as these will be key differentiators in regulated industries.

Monitor the market reaction to this acquisition, particularly from other AI-native service management vendors, to see if this becomes a standard practice for securing deployments.

Look for updates on Serval's customer roster, including Fox, Live Nation, Notion, and Spotify, to see if the new security focus leads to expanded deployments in sensitive sectors.

Related guides & quizzes

AI AgentsAI EthicsFuture of AITest what you know — try a free AI quizLook up an AI term in our glossaryFollow the AI funding tracker
Found this useful?