Security

Cymphony raises $30M to secure AI agents with enterprise access

Sequoia Capital backs startup addressing security gaps as autonomous AI systems gain access to sensitive corporate data and systems.

Omega Editorial· September 9, 2026· 4 min read

AI agents create identity and access control blind spots

As enterprises deploy AI agents that operate with the same system access as human employees but at machine speed, a fundamental security gap has emerged: these autonomous systems often bypass traditional identity and access controls designed for people.

Cymphony, a two-year-old startup based in New York and Tel Aviv, has raised $30 million in Series A funding to address this problem. The round was co-led by Sequoia Capital and SMBC Fin Atlas Beyond Fund, valuing the company at more than $100 million post-money, according to details first reported by TechCrunch. The funding follows a previously undisclosed seed investment from Sequoia.

The company has built what it calls a "workforce graph" that provides security teams with unified visibility across human employees, AI agents, and other non-human identities, tracking which systems and sensitive data each can access. The platform aggregates identity, data, and activity signals to identify exposure risks that traditional security tools miss.

Real-world exposures already surfacing

Cymphony reports finding significant security gaps at customer sites. At one U.S. public company, the startup discovered approximately 85,000 files that had become accessible to AI tools and agents. The company helped close the exposure and verified none of the files had been accessed through those AI systems.

In another case, CEO Shy Dekel told TechCrunch that an external collaborator installed an unauthorized instance of Anthropic's Claude that used the collaborator's existing permissions to scan thousands of sensitive files.

Beyond detection, Cymphony uses its own AI agents to investigate incidents, prioritize remediation tasks, and automate fixes including correcting access permissions. Customers can choose between largely automated operation or a managed service that brings Cymphony's security experts into the loop for complex cases.

Why it matters

Unlike human employees with relatively stable roles and permissions, AI agents can dynamically change their behavior, acquire new capabilities, and in some cases spawn other agents—making their access patterns fundamentally harder to govern with identity systems designed around people. As enterprises accelerate AI agent deployment across operations, this security gap will only widen. The $30 million bet from Sequoia signals venture capital's view that agent security could become a distinct market category rather than just a feature in existing platforms.

Betting on founders before product

Sequoia's investment thesis evolved significantly between rounds. Partner Bogomil Balkansky told TechCrunch the firm's initial seed investment came before Cymphony had a product or clear direction—it was primarily a bet on the three co-founders: Dekel, Idan Berkovits, and Edi Gotlieb, all alumni of Talpiot, the Israeli military's elite technology program. Sequoia had previously backed other Talpiot graduates, including the team behind Wiz.

By the Series A, however, Sequoia wanted proof beyond pedigree. Cymphony had built its platform, signed a double-digit number of enterprise customers including KKR, Syngenta, Cass Information Systems, and Athennian, and reached seven figures in annual recurring revenue within its first year of sales. Sequoia has also used Cymphony's product internally since early development.

Balkansky said the quality and range of customers, plus expansion within existing accounts, drove the decision to lead the Series A. He acknowledged the crowded field of companies positioning around AI and agent security but argued Cymphony's approach—treating identity and data security as a unified problem—differentiates it from competitors.

Competing against established platforms

Cymphony faces competition from both startups and established security vendors expanding into AI agent security, including Microsoft, Okta, CyberArk, Wiz, and Varonis. Dekel said Cymphony is already replacing some existing security products at customers, with one enterprise consolidating two tools and avoiding a third purchase.

Balkansky sees the current role as more complementary than replacement, noting that customers won't abandon core identity platforms like Okta. Over time, however, he suggested Cymphony could displace point solutions in areas such as data loss prevention.

With about 30 employees across Tel Aviv and New York, Cymphony serves primarily North American enterprises but is beginning to see demand from Europe, the Middle East, and Africa. The startup now faces the challenge of proving agent security can sustain a standalone market rather than becoming a feature absorbed by larger platforms.

Details of the funding and customer examples were first reported by TechCrunch.

#ai agents#enterprise security#sequoia capital#identity management#cybersecurity#series a funding

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

US Intelligence Accuses Six Chinese AI Firms of IP Theft

NSA, FBI, and CISA allege DeepSeek, Alibaba, and others conducted systematic knowledge distillation campaigns against American AI models.

Via AI Watch · Sep 9, 2026
Security· 3 min read

FBI: AI Accelerates Cyber Attacks but Basic Security Still Works

New bureau cyber strategy emphasizes continuous patching and AI-powered defense as threat actors leverage machine learning at scale.

Via AI Watch · Sep 9, 2026
Security· 3 min read

LTM Partners with IBM on Lightwell for AI-Driven Vulnerability Fixes

The collaboration targets enterprise-scale remediation of open-source software vulnerabilities as AI accelerates discovery rates.

Via AI Watch · Sep 9, 2026