Sequoia doubles down on Cymphony as AI agents create new enterprise security risks
Sequoia Capital has led a $25 million Series A funding round for Cymphony, a New York- and Tel Aviv-based startup building security tools to manage the risks posed by AI agents operating inside enterprises. The investment, part of a $30 million total raise that values the two-year-old company at over $100 million, reflects growing concern that AI agents now have access to sensitive corporate systems and data much like human employees, but without the same identity and access controls, creating blind spots for security teams.
Cymphony's platform builds a "workforce graph" that gives companies a unified view of employees, AI agents and other non-human identities, tracking what systems and data each can reach. The startup says it has already uncovered significant exposures, including around 85,000 files left accessible to AI tools at one US public company, and a case where an external collaborator's unsanctioned Claude instance scanned thousands of sensitive files using existing access permissions. Sequoia's Bogomil Balkansky said the firm's original seed bet, made over two years ago before Cymphony had a defined product, was based on founders Shy Dekel, Idan Berkovits and Edi Gotlieb's backgrounds in Israel's Talpiot military programme; the Series A followed after the company built a product, signed enterprise customers and reached seven-figure annual recurring revenue within its first year of sales.
- Sequoia leads $25m Series A in AI-agent security startup Cymphony
- Cymphony valued at over $100m; total raise hits $30m
- Startup found 85,000 exposed files at one public company
New here? Start with this
AI agents are software programmes that can act on their own within a company's systems, doing tasks such as scanning documents, moving data or interacting with other software, in ways that resemble human employees. Businesses have increasingly given these agents access to internal files and tools to boost productivity, but many companies still lack the same checks, permissions and monitoring for AI agents that they apply to human staff, leaving gaps that could expose sensitive information.
Cymphony is a young security company, founded roughly two years ago and based in New York and Tel Aviv, that builds software to help businesses see and control what their AI agents and other automated systems can access. Its founders, Shy Dekel, Idan Berkovits and Edi Gotlieb, previously served in Talpiot, an Israeli military programme known for training people in technology and engineering. Sequoia Capital, a well-known venture capital firm that invests in early-stage technology companies, backed Cymphony from its earliest days and has continued to invest as the company has grown.
This story matters because it reflects a wider shift in how businesses think about security as AI tools become more deeply embedded in everyday operations. As companies hand more responsibility to AI agents, questions about who or what can see sensitive data, and how that access is tracked, are becoming a bigger part of corporate risk management.