TLDRocket
Sign in

Sequoia doubles down on Cymphony as AI agents create new enterprise security risks

TechCrunch Jagmeet Singh

Sequoia put $30M into Cymphony to help firms control AI agents. The bet: agents are acting like workers, but most security tools still treat them like users.

Based on reporting by TechCrunch, Jagmeet Singh — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Sequoia Capital is making a bigger bet on a problem that’s starting to feel inevitable: AI agents are getting access to the same corporate systems and sensitive data as employees, but they don’t fit neatly into the security tools companies already use. That gap is what Cymphony is selling into. The New York- and Tel Aviv-based startup has now raised $30 million total, including a $25 million Series A co-led by Sequoia and SMBC Fin Atlas Beyond Fund, and the round values it at more than $100 million after investment.

Cymphony’s pitch is simple enough to explain and messy enough to matter. It gives security teams one place to see employees, AI agents, and other non-human identities, plus the systems and sensitive data they can reach. Under the hood, it uses what it calls a “workforce graph” that blends identity, data, and activity signals. The company says that helps teams understand who, or what, has access to what when access is moving at machine speed.

The risks are not theoretical. Cymphony says it found about 85,000 files at one U.S. public company that had become accessible to AI tools and agents, then helped close the exposure and verified that none of the files were accessed through those systems. In another case, an external collaborator had installed an unsanctioned instance of Anthropic’s Claude that used existing access to scan thousands of sensitive files. That’s the kind of sentence that makes security teams sit up straighter.

Sequoia’s backstory here is unusually candid. Bogomil Balkansky said the firm led Cymphony’s seed round before the startup even had a product or a clear direction; the bet was mainly on co-founders Shy Dekel, Idan Berkovits, and Edi Gotlieb, all Talpiot alumni. By the Series A, Cymphony said it had a product, a double-digit number of enterprise customers, and seven figures in annual recurring revenue within its first year of sales. Customers include KKR, Syngenta, Cass Information Systems, and Athennian, and Sequoia has been using the product internally since early development.

The market is getting crowded fast, with Microsoft, Okta, CyberArk, Wiz, and Varonis all pushing into adjacent territory. But Cymphony is arguing that identity and data security are really the same fight now, especially when agents can change behavior, gain new capabilities, and even create other agents while doing a job. That’s a sharper thesis than “AI security” as a catch-all slogan, and it may be the more durable one.

My take — AI-written commentary, not fact-checked reporting

This is the kind of security startup that makes sense because the mess already exists. The industry spent years bolting controls onto human workers, and now it’s discovering that AI agents are happy to wander through the same doors with less supervision and more speed. Sequoia backing a company that treats identity and data as one problem feels less like hype and more like admission that the old model is already creaking.

Read more about this at: TechCrunch

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.