Cymphony has raised $30 million to build security controls for a problem becoming more visible inside large companies: AI agents are gaining access to sensitive data and enterprise systems, often without fitting neatly into the identity and access-management processes built for employees.
The New York- and Tel Aviv-based startup’s funding includes a $25 million Series A co-led by Sequoia Capital and SMBC Fin Atlas Beyond Fund. The company said it is valued at more than $100 million after the investment. Sequoia also led an earlier, undisclosed seed round.
The access-governance gap
The core issue is not simply whether an organization permits use of a particular AI model. It is whether security teams can see what an agent can reach, what data it has handled, which permissions enable that activity, and whether its behavior remains within intended boundaries.
Cymphony’s platform brings together signals around identities, data and activity in what it calls a “workforce graph.” Its aim is to provide one view of employees, AI agents and other non-human identities, along with their accessible systems and sensitive information.
That framing matters operationally. An agent may use a human or service account’s existing permissions, call several connected systems to complete a task, or change the tools and capabilities it uses over time. Controls based on relatively stable employee roles can struggle to model those paths.
Cymphony says it found roughly 85,000 files accessible to AI tools and agents at one U.S. public company. It said the exposure was closed and that no files had been accessed through those systems. In a separate example, the company said an external collaborator installed an unsanctioned instance of Anthropic’s Claude that scanned thousands of sensitive files using the collaborator’s existing access.
More than inventory
Visibility is only the first step. Cymphony says it uses AI agents to investigate incidents, prioritize risks and automate certain remediation actions, such as correcting permissions. Customers can also use a managed service involving Cymphony security staff for more complicated cases.
For security leaders, the practical test will be whether this approach reduces investigation and remediation time without creating another high-privilege automation layer that itself must be tightly controlled. Procurement teams should ask how the platform integrates with existing identity, data-loss-prevention and security-operations systems; what changes it can make autonomously; and what approval, audit and rollback controls are available.
A crowded category, with incumbents close behind
Cymphony is not entering an empty market. Microsoft, Okta, CyberArk, Wiz and Varonis are among the larger security vendors expanding work across identity, data and AI-related security. Sequoia partner Bogomil Balkansky characterized Cymphony as an additional layer for customers today, rather than a wholesale replacement for core identity platforms such as Okta.
Cymphony argues that joining identity and data security is its differentiation. Its founders say that becomes more important as agents take variable paths through enterprise environments and may acquire capabilities at runtime.
The startup says it has signed a double-digit number of enterprise customers and reached seven figures in annual recurring revenue in its first year of sales. Named customers include KKR, Syngenta, Cass Information Systems and Athennian. It has about 30 employees, with most customers currently in North America.
What to watch next
The investment is a vote of confidence in agent security as a standalone budget category, but that premise is still being tested. Enterprises may buy specialized tools if agent deployments expose risks their existing stacks cannot surface or remediate. They may instead expect incumbent platforms to add comparable capabilities.
The nearer-term takeaway for operators is simpler: treat AI agents, copilots and connected AI tools as governed identities. Maintain an inventory, map their data and system access, apply least-privilege controls, and monitor activity continuously. The organizations that do this early will be better positioned to scale AI automation without losing track of who—or what—is acting inside their environment.




