As AI agents increasingly gain access to the same sensitive corporate data and systems as human employees—but operating at machine speed—enterprises face new security blind spots. Cymphony aims to close that gap with a platform that gives security teams a single view of employees, AI agents, and other non-human identities, including the systems and sensitive data they can access.
“Enterprise security was designed for human employees,” Cymphony co-founder and CEO Shy Dekel told TechCrunch in an exclusive interview. “More and more, there start to be independent entities that are practically joining the workforce, but they’re no longer people.”
The startup says it has already uncovered risks inside large organisations. At one U.S. public company, Cymphony found approximately 85,000 files that had become accessible to AI tools and agents. It helped close the exposure and confirmed that no files had been accessed through those AI systems. In another case, Dekel said an external collaborator had installed an unauthorised instance of Anthropic’s Claude that used existing access rights to scan thousands of sensitive files.
Beyond detection, Cymphony uses AI agents themselves to investigate incidents, prioritise fixes, and automate remediation such as correcting permissions. The platform can operate largely automatically, or customers can opt for a managed service involving Cymphony’s security experts for complex cases.
Sequoia partner Bogomil Balkansky said the firm led Cymphony’s seed round more than two years ago, when the startup had no product or clear direction, betting on co-founders Dekel, Idan Berkovits and Edi Gotlieb—all graduates of the Israeli military’s Talpiot program, which Sequoia knew through investments including Wiz. By the Series A, Cymphony had built a product, signed a double-digit number of enterprise customers, and reached seven figures in annual recurring revenue within its first year of sales. Customers include KKR, Syngenta, Cass Information Systems, and Athennian.