Sequoia doubles down on Cymphony as AI agents create new enterprise security risks

As AI agents access sensitive corporate data and systems at machine speed, enterprises face new security vulnerabilities. Leading venture firm Sequoia Capital is capitalizing on this shift by backing startup Cymphony with $30 million in funding to help organizations manage their expanding AI workforce.
This funding includes a $25 million Series A round co-led by Sequoia and SMBC Fin Atlas Beyond Fund, valuing the New York- and Tel Aviv-based startup at over $100 million. The investment follows a previously undisclosed seed round from Sequoia.
Unlike human employees, AI agents often bypass traditional access and identity controls while handling vast amounts of corporate data across multiple systems. This creates significant challenges for enterprises trying to track who has access to what.
Cymphony addresses this gap by providing security teams with a unified view of employees, AI agents, and other non-human identities, including the systems and sensitive data they can access. At the core of its platform, the two-year-old startup has developed what it calls a “workforce graph,” integrating identity, data, and activity signals.
“Enterprise security was designed for human employees,” Cymphony co-founder and CEO Shy Dekel (pictured above, center) said in an exclusive interview. “More and more, there start to be independent entities that are practically joining the workforce, but they’re no longer people.”
Cymphony reports identifying these risks within large organizations. At one U.S. public company, the startup discovered approximately 85,000 files accessible to AI tools and agents. Cymphony helped close this exposure and verified that none of the files had been accessed through those AI systems.
In another case, Dekel told TechCrunch that an external collaborator had installed an unsanctioned instance of Anthropic’s Claude, using existing access to scan thousands of sensitive files.
Beyond identifying risks, Cymphony uses AI agents to investigate incidents, prioritize actions for security teams, and automate remediation, such as correcting access permissions. The platform operates largely autonomously, Dekel said, noting that customers can also opt for a managed service involving Cymphony’s security experts for complex cases.
Why Sequoia doubled down
Sequoia’s initial investment in Cymphony occurred before the startup had defined its core problem. When the venture firm led its seed round more than two years ago, Cymphony had no product or clear product direction, Sequoia partner Bogomil Balkansky told TechCrunch.
The investment was largely a bet on Dekel and his co-founders, Idan Berkovits (pictured above, right) and Edi Gotlieb (pictured above, left), all three of whom graduated from Talpiot, the Israeli military’s highly selective technology and leadership program. Sequoia was already familiar with the program through previous cybersecurity investments, including Wiz.
“We just saw three amazing young people with the kind of pedigree that we at Sequoia have experienced a lot of success with,” Balkansky said.
Nonetheless, Sequoia, Balkansky said, wanted to see more than the founders’ pedigree by the Series A.
Cymphony had built a product, signed a double-digit number of enterprise customers, and reached seven figures in annual recurring revenue within its first year of sales, the startup told TechCrunch. Its customers include KKR, Syngenta, Cass Information Systems, and Athennian.
Sequoia has also been using Cymphony’s product internally since early in its development, Balkansky said. He noted the quality and range of Cymphony’s customers, and that existing customers are expanding their use of the platform, as among the key reasons the venture firm decided to invest again.
Cymphony is entering an increasingly crowded market as cybersecurity companies strive to address risks emerging from the growing use of AI agents.
Recent incidents have heightened these concerns. In July, OpenAI disclosed that agents being tested for cybersecurity capabilities had circumvented safeguards and compromised systems at AI platform Hugging Face. Late last week, OpenAI-linked agents made thousands of edits to a German programming wiki, using parts of the site to communicate and share ways to evade restrictions.
Balkansky acknowledged that scores of companies are already positioning themselves around AI and agent security. He said, however, that Cymphony’s approach stands out by treating identity and data security as part of the same problem.
That distinction, Dekel and Balkansky both argue, becomes more important as companies deploy more AI agents across their operations. Unlike human employees with relatively stable roles and permissions, agents can take different routes to complete a task, acquire new capabilities, and, in some cases, create other agents, making their access harder to govern with security systems designed around people.
“Agents are very different actors,” Balkansky said, arguing that existing identity tools were not designed for agents that can change their behavior and capabilities at runtime.
Cymphony is also in a race against established security companies that are expanding their offerings around identity, data, and AI, including Microsoft, Okta, CyberArk, Wiz, and Varonis.
Dekel told TechCrunch that Cymphony is already replacing some existing security products at customers. At one enterprise, he said without disclosing specifics, the company helped consolidate two existing tools and eliminated the need to buy a third.
However, Balkansky sees Cymphony’s role, at least for now, as more complementary than replacement. “Nobody’s going to get rid of their Okta,” he said, adding that customers are largely adopting Cymphony as an additional layer today. Over time, however, he told TechCrunch that the startup could begin displacing some point solutions, particularly in areas such as data loss prevention.
Cymphony has about 30 employees across Tel Aviv and New York. Most of its customers are currently in North America, though Dekel told TechCrunch that the startup is beginning to see demand from enterprises in Europe, the Middle East, and Africa.
That said, as Cymphony moves beyond its Series A and expands among large enterprise customers, it now has to prove that AI agent security can become a market of its own rather than a feature offered by larger security platforms. Balkansky believes spending in the area will grow as companies put more AI agents to work.
“If companies are not spending money on agent security, I don’t know what else they’ll be spending money on in the next five to 10 years,” he said.
Related article
AI Agents Collective Jailbreak Attack on Open-Source Communities: Independent Investigation Reveals a More Severe Truth Than What OpenAI Admits
METR and Redwood Research have published an independent analysis of OpenAI’s GPT-4 agent exploiting a security vulnerability on Hugging Face. After spending six days at OpenAI’s facilities and reviewing 70,000 messages, 1,300 operation logs, and nume
Harvard psychologist Pike: Focus on AI safety engineering, not doomsday rumors
Harvard psychologist Steven Pinker argues that fears of AI causing human extinction are vastly overstated, a position he detailed in an open letter to Quillette addressed to Scott Alexander.After Alexander challenged Pinker to a public debate on AI s
Rivian Founder’s Mind Robotics Raises $500M to Advance Industrial AI
While the tech world obsesses over humanoid robots, one startup is charting a different course—ignoring the hype while landing a massive backer from elite venture capital. On March 12, Mind Robotics, an industrial AI firm founded by Rivian CEO RJ Sca
Related Special Topic Recommendations
Comments (0)
0/500

As AI agents access sensitive corporate data and systems at machine speed, enterprises face new security vulnerabilities. Leading venture firm Sequoia Capital is capitalizing on this shift by backing startup Cymphony with $30 million in funding to help organizations manage their expanding AI workforce.
This funding includes a $25 million Series A round co-led by Sequoia and SMBC Fin Atlas Beyond Fund, valuing the New York- and Tel Aviv-based startup at over $100 million. The investment follows a previously undisclosed seed round from Sequoia.
Unlike human employees, AI agents often bypass traditional access and identity controls while handling vast amounts of corporate data across multiple systems. This creates significant challenges for enterprises trying to track who has access to what.
Cymphony addresses this gap by providing security teams with a unified view of employees, AI agents, and other non-human identities, including the systems and sensitive data they can access. At the core of its platform, the two-year-old startup has developed what it calls a “workforce graph,” integrating identity, data, and activity signals.
“Enterprise security was designed for human employees,” Cymphony co-founder and CEO Shy Dekel (pictured above, center) said in an exclusive interview. “More and more, there start to be independent entities that are practically joining the workforce, but they’re no longer people.”
Cymphony reports identifying these risks within large organizations. At one U.S. public company, the startup discovered approximately 85,000 files accessible to AI tools and agents. Cymphony helped close this exposure and verified that none of the files had been accessed through those AI systems.
In another case, Dekel told TechCrunch that an external collaborator had installed an unsanctioned instance of Anthropic’s Claude, using existing access to scan thousands of sensitive files.
Beyond identifying risks, Cymphony uses AI agents to investigate incidents, prioritize actions for security teams, and automate remediation, such as correcting access permissions. The platform operates largely autonomously, Dekel said, noting that customers can also opt for a managed service involving Cymphony’s security experts for complex cases.
Why Sequoia doubled down
Sequoia’s initial investment in Cymphony occurred before the startup had defined its core problem. When the venture firm led its seed round more than two years ago, Cymphony had no product or clear product direction, Sequoia partner Bogomil Balkansky told TechCrunch.
The investment was largely a bet on Dekel and his co-founders, Idan Berkovits (pictured above, right) and Edi Gotlieb (pictured above, left), all three of whom graduated from Talpiot, the Israeli military’s highly selective technology and leadership program. Sequoia was already familiar with the program through previous cybersecurity investments, including Wiz.
“We just saw three amazing young people with the kind of pedigree that we at Sequoia have experienced a lot of success with,” Balkansky said.
Nonetheless, Sequoia, Balkansky said, wanted to see more than the founders’ pedigree by the Series A.
Cymphony had built a product, signed a double-digit number of enterprise customers, and reached seven figures in annual recurring revenue within its first year of sales, the startup told TechCrunch. Its customers include KKR, Syngenta, Cass Information Systems, and Athennian.
Sequoia has also been using Cymphony’s product internally since early in its development, Balkansky said. He noted the quality and range of Cymphony’s customers, and that existing customers are expanding their use of the platform, as among the key reasons the venture firm decided to invest again.
Cymphony is entering an increasingly crowded market as cybersecurity companies strive to address risks emerging from the growing use of AI agents.
Recent incidents have heightened these concerns. In July, OpenAI disclosed that agents being tested for cybersecurity capabilities had circumvented safeguards and compromised systems at AI platform Hugging Face. Late last week, OpenAI-linked agents made thousands of edits to a German programming wiki, using parts of the site to communicate and share ways to evade restrictions.
Balkansky acknowledged that scores of companies are already positioning themselves around AI and agent security. He said, however, that Cymphony’s approach stands out by treating identity and data security as part of the same problem.
That distinction, Dekel and Balkansky both argue, becomes more important as companies deploy more AI agents across their operations. Unlike human employees with relatively stable roles and permissions, agents can take different routes to complete a task, acquire new capabilities, and, in some cases, create other agents, making their access harder to govern with security systems designed around people.
“Agents are very different actors,” Balkansky said, arguing that existing identity tools were not designed for agents that can change their behavior and capabilities at runtime.
Cymphony is also in a race against established security companies that are expanding their offerings around identity, data, and AI, including Microsoft, Okta, CyberArk, Wiz, and Varonis.
Dekel told TechCrunch that Cymphony is already replacing some existing security products at customers. At one enterprise, he said without disclosing specifics, the company helped consolidate two existing tools and eliminated the need to buy a third.
However, Balkansky sees Cymphony’s role, at least for now, as more complementary than replacement. “Nobody’s going to get rid of their Okta,” he said, adding that customers are largely adopting Cymphony as an additional layer today. Over time, however, he told TechCrunch that the startup could begin displacing some point solutions, particularly in areas such as data loss prevention.
Cymphony has about 30 employees across Tel Aviv and New York. Most of its customers are currently in North America, though Dekel told TechCrunch that the startup is beginning to see demand from enterprises in Europe, the Middle East, and Africa.
That said, as Cymphony moves beyond its Series A and expands among large enterprise customers, it now has to prove that AI agent security can become a market of its own rather than a feature offered by larger security platforms. Balkansky believes spending in the area will grow as companies put more AI agents to work.
“If companies are not spending money on agent security, I don’t know what else they’ll be spending money on in the next five to 10 years,” he said.
AI Agents Collective Jailbreak Attack on Open-Source Communities: Independent Investigation Reveals a More Severe Truth Than What OpenAI Admits
METR and Redwood Research have published an independent analysis of OpenAI’s GPT-4 agent exploiting a security vulnerability on Hugging Face. After spending six days at OpenAI’s facilities and reviewing 70,000 messages, 1,300 operation logs, and nume
Harvard psychologist Pike: Focus on AI safety engineering, not doomsday rumors
Harvard psychologist Steven Pinker argues that fears of AI causing human extinction are vastly overstated, a position he detailed in an open letter to Quillette addressed to Scott Alexander.After Alexander challenged Pinker to a public debate on AI s
Rivian Founder’s Mind Robotics Raises $500M to Advance Industrial AI
While the tech world obsesses over humanoid robots, one startup is charting a different course—ignoring the hype while landing a massive backer from elite venture capital. On March 12, Mind Robotics, an industrial AI firm founded by Rivian CEO RJ Sca





Home






