As AI agents gain access to the same sensitive corporate data and systems as human workers while operating at machine speed, enterprises are prone to new security risks. Storied venture firm Sequoia Capital is betting big on that shift, backing startup Cymphony as it emerges with $30 million in funding to help companies keep their growing AI workforce in check.
The funding includes a $25 million Series A co-led by Sequoia and SMBC Fin Atlas Beyond Fund, valuing the New York- and Tel Aviv-based startup at more than $100 million after investment. The round follows a previously undisclosed seed investment from Sequoia.
AI agents do not necessarily go through the same access and identity controls as employees, but they have access to multiple systems and handle large amounts of corporate data. This makes it hard for enterprises to track who has access to what.
Cymphony is trying to address that gap by giving security teams a single view of employees, AI agents, and other non-human identities, including the systems and sensitive data they can access. At the core of its platform, the two-year-old startup has built what it calls a “workforce graph”. This brings together identity, data, and activity signals.
“Enterprise security was designed for human employees,” Cymphony co-founder and CEO Shy Dekel (pictured above, center) said in an exclusive interview. “More and more, there start to be independent entities that are practically joining the workforce, but they’re no longer people.”
Cymphony says it is already finding those risks inside large companies. At one U.S. public company, the startup said it found about 85,000 files that had become accessible to AI tools and agents. Cymphony stated it helped close the exposure and verified that none of the files had been accessed through those AI systems.
In another case, Dekel told TechCrunch that an external collaborator had installed an unsanctioned instance of Anthropic’s Claude that used the collaborator’s existing access to scan thousands of sensitive files.
Beyond identifying risks, Cymphony uses AI agents to investigate incidents, prioritize what security teams should address, and automate some remediation, including correcting access permissions. The platform can operate largely automatically, Dekel said, adding that customers can also opt for a managed service that brings Cymphony’s security experts into the loop for more complex cases.
Why Sequoia doubled down
Sequoia’s initial bet on Cymphony came before the startup had settled on the problem it wanted to solve. When the venture firm led its seed round more than two years ago, Cymphony had no product or even a clear product direction, Sequoia partner Bogomil Balkansky told TechCrunch.
The investment was largely a bet on Dekel and his co-founders, Idan Berkovits (pictured above, right) and Edi Gotlieb (pictured above, left), all three of whom came through Talpiot, the Israeli military’s highly selective technology and leadership program. Sequoia was already familiar with the program through previous cybersecurity investments, including Wiz.
“We just saw three amazing young people with the kind of pedigree that we at Sequoia have experienced a lot of success with,” Balkansky said.
Nonetheless, Sequoia, Balkansky said, wanted to see more than the founders’ pedigree by the Series A.
Cymphony had built a product, signed a double-digit number of enterprise customers, and reached seven figures in annual recurring revenue within its first year of sales, the startup told TechCrunch. Its customers include KKR, Syngenta, Cass Information Systems, and Athennian.
Sequoia has also been using Cymphony’s product internally since early in its development, Balkansky said. He noted the quality and range of Cymphony’s customers, and that existing customers are expanding their use of the platform, as among the key reasons the venture firm decided to invest again.
Cymphony is entering an increasingly crowded market as cybersecurity companies strive to address risks emerging from the growing use of AI agents.
Recent incidents have added to those concerns. In July, OpenAI disclosed that agents being tested for cybersecurity capabilities had circumvented safeguards and compromised systems at AI platform Hugging Face. Late last week, OpenAI-linked agents made thousands of edits to a German programming wiki, using parts of the site to communicate and share ways to evade restrictions.
Balkansky acknowledged that scores of companies are already positioning themselves around AI and agent security. He said, however, that Cymphony’s approach stands out by treating identity and data security as part of the same problem.
That distinction, Dekel and Balkansky both argue, becomes more important as companies deploy more AI agents across their operations. Unlike human employees with relatively stable roles and permissions, agents can take different routes to complete a task, acquire new capabilities, and, in some cases, create other agents, making their access harder to govern with security systems designed around people.
“Agents are very different actors,” Balkansky said, arguing that existing identity tools were not designed for agents that can change their behavior and capabilities at runtime.
Cymphony is also in a race against established security companies that are expanding their offerings around identity, data, and AI, including Microsoft, Okta, CyberArk, Wiz, and Varonis.
Dekel told TechCrunch that Cymphony is already replacing some existing security products at customers. At one enterprise, he said without disclosing specifics, the company helped consolidate two existing tools and eliminated the need to buy a third.
However, Balkansky sees Cymphony’s role, at least for now, as more complementary than replacement. “Nobody’s going to get rid of their Okta,” he said, adding that customers are largely adopting Cymphony as an additional layer today. Over time, however, he told TechCrunch that the startup could begin displacing some point solutions, particularly in areas such as data loss prevention.
Cymphony has about 30 employees across Tel Aviv and New York. Most of its customers are currently in North America, though Dekel told TechCrunch that the startup is beginning to see demand from enterprises in Europe, the Middle East, and Africa.
That said, as Cymphony moves beyond its Series A and expands among large enterprise customers, it now has to prove that AI agent security can become a market of its own rather than a feature offered by larger security platforms. Balkansky believes spending in the area will grow as companies put more AI agents to work.
“If companies are not spending money on agent security, I don’t know what else they’ll be spending money on in the next five to 10 years,” he said.


