Sequoia backs Cymphony's $25M Series A as AI agents strain enterprise security
Sequoia Capital is doubling down on Cymphony, a two-year-old startup that helps companies track what their AI agents can access, as the firm bets that machine-speed software workers are creating a new class of enterprise security risk. Cymphony announced $30 million in total funding, including a $25 million Series A co-led by Sequoia and SMBC Fin Atlas Beyond Fund that values the New York- and Tel Aviv-based company at more than $100 million after investment. The round follows a previously undisclosed seed investment from Sequoia, which is why the firm describes this as doubling down.
AI agents increasingly reach the same sensitive corporate data and systems as human employees, but they do not necessarily pass through the same access and identity controls, and they operate at machine speed. That makes it hard for enterprises to track who, or what, has access to which systems and data. Cymphony's answer is a platform that gives security teams a single view of employees, AI agents, and other non-human identities, built around what it calls a "workforce graph" that combines identity, data, and activity signals.
"Enterprise security was designed for human employees," co-founder and CEO Shy Dekel said in an interview. "More and more, there start to be independent entities that are practically joining the workforce, but they're no longer people."
Cymphony says it is already surfacing those risks inside large companies. At one U.S. public company, the startup said it found roughly 85,000 files that had become accessible to AI tools and agents, helped close the exposure, and verified that none of the files had been accessed through those AI systems. In another case, Dekel said an external collaborator had installed an unsanctioned instance of Anthropic's Claude that used the collaborator's existing access to scan thousands of sensitive files.
Beyond flagging problems, Cymphony uses AI agents to investigate incidents, prioritize what security teams should address, and automate some remediation, including correcting access permissions. The platform can run largely automatically, Dekel said, and customers can also choose a managed service that brings Cymphony's security experts in for more complex cases.
The funding arrives as enterprises deploy AI agents at scale without identity and access controls built for them, a gap Cymphony is positioning itself to fill. The company's pitch rests on the claim that legacy security was architected around named human users, leaving autonomous software entities to accumulate permissions invisibly. Sequoia's follow-on investment signals conviction that the problem is broad enough to support a standalone vendor rather than a feature bolted onto existing identity tools.
What remains unclear is how quickly enterprises will treat AI agent access as a distinct security category worth dedicated spending, and how Cymphony's workforce graph approach holds up against larger identity and security platforms moving into the same territory. The company has not disclosed customer names beyond the U.S. public company it cited, and its revenue trajectory is not public.
As AI agents gain access to corporate data without the identity controls built for human employees, Cymphony's funding signals a new security category forming around tracking non-human identities.