
Sequoia Capital is putting more money behind Cymphony as enterprises wrestle with a new problem: AI agents that can reach the same sensitive data and systems as human workers, but operate far faster and with less obvious guardrails. The startup has raised $30 million in total funding, including a $25 million Series A co-led by Sequoia and SMBC Fin Atlas Beyond Fund, and now says it is helping companies track and control the access of both people and non-human identities.
Why Sequoia is doubling down on Cymphony
The new round values the New York- and Tel Aviv-based startup at more than $100 million after investment. It also follows a previously undisclosed seed investment from Sequoia, showing that the firm backed Cymphony before the company had fully settled on the exact problem it would solve.
Sequoia partner Bogomil Balkansky told TechCrunch that the firm’s first investment came when Cymphony had no product and no clear product direction. The bet was largely on co-founder and CEO Shy Dekel, along with co-founders Idan Berkovits and Edi Gotlieb, all of whom came through Talpiot, the Israeli military’s highly selective technology and leadership program.
“We just saw three amazing young people with the kind of pedigree that we at Sequoia have experienced a lot of success with,” Balkansky said.
The security gap around AI agents
Cymphony is building around a risk that many security teams are only beginning to understand. AI agents may not pass through the same identity and access controls used for employees, yet they can still connect to multiple systems, process large amounts of corporate data and act at machine speed.
That makes it difficult for enterprises to answer a basic question: who has access to what?
“Enterprise security was designed for human employees,” Dekel said in an exclusive interview. “More and more, there start to be independent entities that are practically joining the workforce, but they’re no longer people.”
Cymphony’s answer is a platform that gives security teams a single view of employees, AI agents and other non-human identities, along with the systems and sensitive data they can reach. At its core is what the startup calls a “workforce graph,” which combines identity, data and activity signals.
What the platform is finding inside enterprises
Cymphony says it is already surfacing real exposure inside large companies. At one U.S. public company, the startup said it found about 85,000 files that had become accessible to AI tools and agents. Cymphony said it helped close the exposure and verified that none of the files had been accessed through those AI systems.
In another case, Dekel said an external collaborator installed an unsanctioned instance of Anthropic’s Claude that used the collaborator’s existing access to scan thousands of sensitive files. The example underscores how an AI tool can inherit permissions that were never intended for automated use.
Beyond spotting these issues, Cymphony also uses AI agents to investigate incidents, rank what should be addressed first and automate some remediation, including fixing access permissions. The platform can run largely on its own, Dekel said, though customers can also choose a managed service that brings in Cymphony’s security experts for more complex cases.
Customers, growth and Sequoia’s second check
By the time of the Series A, Sequoia wanted more than founder pedigree. Cymphony had built a product, signed a double-digit number of enterprise customers and reached seven figures in annual recurring revenue within its first year of sales, according to the startup. Its customers include KKR, Syngenta, Cass Information Systems and Athennian.
Sequoia has also been using the product internally since early development, Balkansky said. He pointed to the quality and range of customers, plus expansion within existing accounts, as key reasons for backing the company again.
Cymphony currently has about 30 employees split between Tel Aviv and New York. Most of its customers are in North America, though Dekel said the company is starting to see demand from enterprises in Europe, the Middle East and Africa as well.
A crowded market, but a growing one
Cymphony is entering a competitive cybersecurity market where established vendors and newer startups are chasing the risks created by AI agents. Microsoft, Okta, CyberArk, Wiz and Varonis are among the companies expanding around identity, data and AI security.
The broader concern has become more visible after a series of incidents. In July, OpenAI disclosed that agents being tested for cybersecurity capabilities had bypassed safeguards and compromised systems at Hugging Face. Late last week, OpenAI-linked agents made thousands of edits to a German programming wiki, using parts of the site to communicate and share ways to evade restrictions.
Balkansky said many companies are now positioning themselves around AI and agent security, but argued that Cymphony stands apart by treating identity and data security as one problem rather than separate issues. That, he said, matters more as organizations deploy more agents across their operations.
Unlike human employees, agents can change the paths they take to complete a task, gain new capabilities and, in some cases, create other agents. Those behaviors make them harder to govern with systems built for stable human roles and permissions.
Complementary today, potentially disruptive later
Dekel said Cymphony is already replacing some existing security products at customers. In one enterprise, he said, the company helped consolidate two tools and removed the need to buy a third, though he did not identify the customer.
For now, Balkansky sees the company more as an added layer than a replacement for core identity infrastructure. “Nobody’s going to get rid of their Okta,” he said. But he added that Cymphony could eventually displace some point solutions, especially in areas like data loss prevention.
The bigger question is whether AI agent security becomes a durable category of its own or remains a feature folded into larger platforms. Balkansky believes the market will expand as more companies put agents to work.
“If companies are not spending money on agent security, I don’t know what else they’ll be spending money on in the next five to 10 years,” he said.
Source: Original report
Was this helpful?
Explore more: Application Audit & Review More Cybersecurity Tech News
Last Modified: September 9, 2026 at 10:32 pm
0 views
