Sequoia backs Cymphony with $30M to tame AI agent security risks

The startup's platform gives enterprises a unified view of human and non-human identities accessing corporate systems

edit
By LineZotpaper
Published
Read Time2 min
Sources3 outlets
Sequoia Capital is doubling down on Cymphony, a two-year-old startup that raises $30 million to help enterprises manage the security risks posed by AI agents that access sensitive corporate data. The Series A round, co-led by Sequoia and SMBC Fin Atlas Beyond Fund, values the New York- and Tel Aviv-based company at over $100 million.

As AI agents increasingly gain access to the same sensitive corporate data and systems as human employees—but operating at machine speed—enterprises face new security blind spots. Cymphony aims to close that gap with a platform that gives security teams a single view of employees, AI agents, and other non-human identities, including the systems and sensitive data they can access.

“Enterprise security was designed for human employees,” Cymphony co-founder and CEO Shy Dekel told TechCrunch in an exclusive interview. “More and more, there start to be independent entities that are practically joining the workforce, but they’re no longer people.”

The startup says it has already uncovered risks inside large organisations. At one U.S. public company, Cymphony found approximately 85,000 files that had become accessible to AI tools and agents. It helped close the exposure and confirmed that no files had been accessed through those AI systems. In another case, Dekel said an external collaborator had installed an unauthorised instance of Anthropic’s Claude that used existing access rights to scan thousands of sensitive files.

Beyond detection, Cymphony uses AI agents themselves to investigate incidents, prioritise fixes, and automate remediation such as correcting permissions. The platform can operate largely automatically, or customers can opt for a managed service involving Cymphony’s security experts for complex cases.

Sequoia partner Bogomil Balkansky said the firm led Cymphony’s seed round more than two years ago, when the startup had no product or clear direction, betting on co-founders Dekel, Idan Berkovits and Edi Gotlieb—all graduates of the Israeli military’s Talpiot program, which Sequoia knew through investments including Wiz. By the Series A, Cymphony had built a product, signed a double-digit number of enterprise customers, and reached seven figures in annual recurring revenue within its first year of sales. Customers include KKR, Syngenta, Cass Information Systems, and Athennian.

§

Analysis

Why This Matters

  • As enterprises deploy more AI agents with broad system access, traditional identity and access controls designed for humans no longer suffice. Cymphony’s funding signals that VCs see this as a major emerging market.
  • The $30 million raise and $100 million+ valuation suggest the problem is already acute enough to attract both investors and blue-chip enterprise customers.
  • Sequoia’s willingness to invest pre-product and double down on traction indicates the firm believes this category will grow rapidly.

Background

AI agents—software entities that can act autonomously on behalf of users—are proliferating in enterprise settings. They can interact with internal tools, databases, and communication platforms, often inheriting broad permissions. This creates a new attack surface: agents may access files they shouldn’t, or be manipulated to exfiltrate data. Existing security tools like identity and access management (IAM) and data loss prevention (DLP) were not built to handle machine-speed, non-human entities.

Key Perspectives

Cymphony: Argues that enterprise security must evolve to treat AI agents as distinct identities with their own access patterns, and that its workforce graph can proactively detect and close exposure gaps. Sequoia Capital: Views this as a natural next step in cybersecurity investing, backing experienced founders from a proven talent pipeline (Talpiot) who have demonstrated product-market fit. Enterprise Customers: Companies like KKR and Syngenta that adopt Cymphony presumably see value in reducing the risk of data leaks from AI agents, but the startup must prove it can scale without creating false positives or operational overhead.

What to Watch

  • How quickly Cymphony expands its customer base beyond the double-digit figure disclosed, and whether it can maintain its ARR growth rate.
  • The broader response from incumbent security vendors (e.g., CrowdStrike, Palo Alto Networks) as they integrate AI agent visibility into their platforms.
  • Regulatory developments around AI governance that could mandate agent identity controls, potentially accelerating adoption.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.