AI agents now access the same sensitive corporate data as human workers, but they operate at machine speed without going through standard identity controls. This gap creates new security risks for enterprises. Sequoia Capital is backing a startup called Cymphony with $30 million to help companies manage this shift.
In this article
The funding includes a $25 million Series A co-led by Sequoia and SMBC Fin Atlas Beyond Fund. This round values the New York and Tel Aviv-based startup at more than $100 million. It follows an earlier seed investment from Sequoia that was not disclosed at the time.
The identity gap
Human employees face access and identity checks. AI agents do not necessarily go through those same steps. They still handle large amounts of corporate data and connect to multiple systems. This makes it hard for security teams to track who has access to what.
Cymphony addresses this by giving security teams a single view of employees, AI agents, and other non-human identities. The platform shows the systems and sensitive data these identities can access. At the core of its software is a graph that brings together identity, data, and activity signals.
“Enterprise security was designed for human employees,” Cymphony co-founder and CEO Shy Dekel said. “More and more, there start to be independent entities that are practically joining the workforce, but they’re no longer people.”
Real-world risks
Cymphony has found these risks inside large companies. At one US public company, the startup found about 85,000 files that had become accessible to AI tools. Cymphony helped close that exposure and verified that none of the files were accessed through those AI systems.
In another case, Dekel told TechCrunch that an external collaborator installed an unsanctioned instance of Anthropic‘s Claude. The tool used the collaborator’s existing access to scan thousands of sensitive files.
Beyond identifying risks, Cymphony uses AI agents to investigate incidents and prioritise what security teams should address. The platform can also automate some remediation, including correcting access permissions. The software can operate largely automatically, Dekel said. Customers can also opt for a managed service that brings Cymphony’s security experts into the loop for more complex cases.
Why Sequoia doubled down
Sequoia’s initial bet on Cymphony came before the startup had settled on the problem it wanted to solve. When the venture firm led its seed round more than two years ago, Cymphony had no product or even a clear product direction. Sequoia partner Bogomil Balkansky told TechCrunch.
The investment was largely a bet on Dekel and his co-founders, Idan Berkovits and Edi Gotlieb. All three came through Talpiot, the Israeli military’s highly selective technology and leadership program. Sequoia was already familiar with the program through previous cybersecurity investments, including Wiz.
“We just saw three amazing young people with the kind of pedigree that we at Sequoia have experienced a lot of success with,” Balkansky said.
Nonetheless, Sequoia wanted to see more than the founders’ pedigree by the Series A. Cymphony had built a product, signed a double-digit number of enterprise customers, and reached seven figures in annual recurring revenue within its first year of sales. Its customers include KKR, Syngenta, Cass Information Systems, and Athennian.
Sequoia has also been using Cymphony’s product internally since early in its development. Balkansky noted the quality and range of Cymphony’s customers, and that existing customers are expanding their use of the platform. These factors were key reasons the venture firm decided to invest again.
A crowded market
Cymphony is entering an increasingly crowded market as cybersecurity companies strive to address risks emerging from the growing use of AI agents. Recent incidents have added to those concerns. In July, OpenAI disclosed that agents being tested for cybersecurity capabilities had circumvented safeguards and compromised systems at AI platform Hugging Face. Late last week, OpenAI-linked agents made thousands of edits to a German programming wiki, using parts of the site to communicate and share ways to evade restrictions.
Balkansky acknowledged that scores of companies are already positioning themselves around AI and agent security. He said, however, that Cymphony’s approach stands out by treating identity and data security as part of the same problem.
That distinction becomes more important as companies deploy more AI agents across their operations. Unlike human employees with relatively stable roles and permissions, agents can take different routes to complete a task, acquire new capabilities, and, in some cases, create other agents. This makes their access harder to govern with security systems designed around people.
“Agents are very different actors,” Balkansky said. “Existing identity tools were not designed for agents that can change their behavior and capabilities at runtime.”
Cymphony is also in a race against established security companies that are expanding their offerings around identity, data, and AI. These include Microsoft, Okta, CyberArk, Wiz, and Varonis.
Dekel told TechCrunch that Cymphony is already replacing some existing security products at customers. At one enterprise, he said without disclosing specifics, the company helped consolidate two existing tools and eliminated the need to buy a third.
Balkansky sees Cymphony’s role, at least for now, as more complementary than replacement. “Nobody’s going to get rid of their Okta,” he said. Customers are largely adopting Cymphony as an additional layer today. Over time, he told TechCrunch that the startup could begin displacing some point solutions, particularly in areas such as data loss prevention.
Cymphony has about 30 employees across Tel Aviv and New York. Most of its customers are currently in North America, though Dekel told TechCrunch that the startup is beginning to see demand from enterprises in Europe, the Middle East, and Africa.
What it means
Cymphony must prove that AI agent security can become a market of its own rather than a feature offered by larger security platforms. Balkansky believes spending in the area will grow as companies put more AI agents to work.
“If companies are not spending money on agent security, I don’t know what else they’ll be spending money on in the next five to 10 years,” he said.




