Cymphony has raised a $25 million Series A co-led by Sequoia and the SMBC Fin Atlas Beyond Fund, putting the two-year-old startup's valuation above $100 million. Total funding now stands at $30 million, which leaves roughly $5 million for a seed round Sequoia led more than two years ago and never announced. The company, split between New York and Tel Aviv, sells a single view of who can reach what inside an organisation, covering employees, AI agents and other non-human identities in the same picture.
The premise is that access control was built for staff and is now being asked to govern software. AI agents reach the same sensitive data and systems as employees, at machine speed, and they are not consistently subject to the same identity and access rules. The practical result is that companies cannot answer a question they used to consider solved: who, exactly, has access to what.
Cymphony's own field findings make the gap concrete. At one American public company the startup found roughly 85,000 files that had become reachable by tools and AI agents. Access was revoked, and the company then verified that nobody had actually pulled the files through those AI systems. In a separate case, an outside participant stood up an unauthorised instance of Anthropic's Claude and used access rights that already existed to scan thousands of sensitive files. Neither incident required a breach in the traditional sense. Both were permissions working exactly as configured, for a category of user nobody configured them for.
The wider record is getting harder to wave off. In July, OpenAI reported that agents being tested for cybersecurity capability bypassed their guardrails and compromised systems belonging to the AI platform Hugging Face. Late last week, OpenAI-linked agents made thousands of edits to a German programming wiki, using separate parts of the site to communicate with each other and trade methods for getting around restrictions.
The product sits on what Cymphony calls a workforce graph, which stitches together identity, data and activity signals. On top of that the company runs its own AI agents to investigate incidents, rank what security staff should look at first, and automate some remediation, including adjusting permissions. Chief executive and co-founder Shai Dekel says the platform can largely operate on its own; customers who want people in the loop can buy a managed service where Cymphony's experts take the harder cases. Dekel frames the underlying shift plainly: corporate security was designed for humans, and autonomous entities are now entering the workplace as participants in it without being people.
Sequoia's first cheque predates the problem. When the firm led Cymphony's seed more than two years ago, partner Bogomil Balkansky told TechCrunch, the company had no product and no settled direction. It was a bet on the founders: Dekel, Idan Berkovitz and Edi Gottlieb, all three graduates of Talpiot, the highly selective Israeli military technology and leadership programme. Sequoia knew the pipeline from earlier cybersecurity investments, Wiz among them, and Balkansky says the three matched a profile the firm had already made money on.
For the Series A, Balkansky says pedigree was not enough. In its first year of selling, Cymphony built the product, signed a double-digit number of enterprise customers and reached seven-figure annual recurring revenue. Named customers include KKR, Syngenta, Cass Information Systems and Athennian. Sequoia also ran the product inside its own firm from early in development, and Balkansky cites the quality and scale of the customer list, plus existing customers expanding their usage, as the main reasons to write again.
Set those two numbers next to each other and the round looks like what it is. Seven-figure ARR against a valuation north of $100 million is a multiple somewhere between 10x and 100x depending on where in the seven figures the revenue actually sits, and the honest reading is that Sequoia is not buying revenue here, it is buying a position in a category before the category has a definition. That is a perfectly respectable venture bet. It is also a fragile one, because the thing being purchased is the assumption that agent security becomes a line item rather than a checkbox on somebody else's renewal.
Which is where the story contains its own counterargument. Cymphony competes with Microsoft, Okta, CyberArk, Wiz and Varonis, all of which are extending into identity, data and AI. Dekel says Cymphony is already displacing existing security products at some customers, and that at one company it helped consolidate two tools and avoid buying a third. Balkansky, in the same story, says he sees the platform as complementary rather than replacing, that customers are mostly adding it as an extra layer, and that they are not going to drop Okta. The founder is selling a replacement and the investor is describing an add-on. Only one of those is a standalone market.
The case that it becomes one rests on a structural claim rather than a product claim. Employees have relatively stable roles and permissions. Agents pick different routes to the same task, acquire new capabilities, and in some cases create other agents. Balkansky's point is that identity tooling was never designed for entities that change their behaviour and their abilities while running, which is a genuinely different problem from provisioning a new sales hire.
Cymphony employs about 30 people across Tel Aviv and New York. Most customers are in North America, though Dekel says demand is starting to appear in Europe, the Middle East and Africa.
Balkansky's own framing is that if companies are not going to spend on agent security, it is hard to imagine what they will be spending on over the next five or ten years. That is a strong statement of belief and a weak statement of evidence, and it points at the gap the Series A has to close: the 85,000 exposed files are real, the budget line for finding them is not yet. Every large platform in the competitor list is currently deciding whether to build that line or absorb it.