Sequoia Backs Cymphony's $30M Series A as AI Agents Reshape Enterprise Security Risks

As AI agents gain access to the same sensitive corporate data and systems as human employees—but operate at machine speed—enterprises face a new class of security risks. Renowned venture firm Sequoia Capital is betting heavily on this shift, backing startup Cymphony as it emerges with $30 million in funding to help companies manage their growing AI workforce.


The funding includes a $25 million Series A co-led by Sequoia and SMBC Fin Atlas Beyond Fund, valuing the New York- and Tel Aviv-based startup at over $100 million post-investment. This round follows a previously undisclosed seed investment from Sequoia.


AI agents don't necessarily pass through the same access and identity controls as employees, yet they have access to multiple systems and handle large volumes of corporate data. This makes it challenging for enterprises to track who—or what—has access to sensitive information.


Cymphony addresses this gap by giving security teams a unified view of employees, AI agents, and other non-human identities, including the systems and data they can access. At the core of its platform, the two-year-old startup has built what it calls a “workforce graph,” which integrates identity, data, and activity signals.


“Enterprise security was designed for human employees,” Cymphony co-founder and CEO Shy Dekel said in an exclusive interview. “More and more, there are independent entities effectively joining the workforce, but they're no longer people.”


Cymphony says it's already identifying such risks inside large organizations. At one U.S. public company, the startup found approximately 85,000 files that had become accessible to AI tools and agents. Cymphony helped close the exposure and verified that none of the files had been accessed through those AI systems.


In another case, Dekel told TechCrunch that an external collaborator had installed an unsanctioned instance of Anthropic's Claude, which used the collaborator's existing access to scan thousands of sensitive files.


Beyond identifying risks, Cymphony uses AI agents to investigate incidents, prioritize responses, and automate some remediation, including correcting access permissions. The platform can operate largely autonomously, Dekel said, though customers can also choose a managed service that brings Cymphony's security experts into the loop for more complex cases.


Why Sequoia Doubled Down


Sequoia's initial bet on Cymphony came before the startup had settled on its specific problem. When the firm led its seed round over two years ago, Cymphony had no product or clear product direction, according to Sequoia partner Bogomil Balkansky.


The investment was largely a bet on Dekel and his co-founders, Idan Berkovits and Edi Gotlieb, all of whom came through Talpiot, the Israeli military's highly selective technology and leadership program. Sequoia was already familiar with the program through previous cybersecurity investments, including Wiz.


“We just saw three amazing young people with the kind of pedigree that we at Sequoia have experienced a lot of success with,” Balkansky said, adding that the firm's confidence in the team has been vindicated as Cymphony pivoted to address a pressing, emerging need in enterprise security.


As AI adoption accelerates into 2026, the challenge of governing AI agents is no longer theoretical. With agentic systems becoming standard across enterprises, Cymphony's workforce graph approach offers a practical framework for securing this new digital workforce—a need Sequoia believes is only beginning to scale.

via TechCrunch AI

Related