As AI agents gain autonomous access to corporate data, Sequoia Capital has led a $25 million Series A round for Cymphony to secure the 'non-human workforce'. The startup is now valued at over $100 million.
- Cymphony raised $25 million in Series A funding co-led by Sequoia and SMBC Fin Atlas Beyond Fund.
- The startup focuses on managing 'non-human identities' (AI agents) that bypass traditional security controls.
- Cymphony's 'workforce graph' integrates identity, data, and activity signals to prevent unauthorized data exposure.
- The company has already secured high-profile clients like KKR and Syngenta, reaching seven-figure ARR in its first year.
The rapid integration of AI agents into the corporate ecosystem has created a critical security blind spot. Unlike human employees, AI agents operate at machine speed and often bypass traditional identity and access management (IAM) protocols, yet they possess access to the most sensitive layers of corporate data. Sequoia Capital is betting heavily on this shift, doubling down on Cymphony, a New York and Tel Aviv-based startup designed to govern the growing AI workforce.
Cymphony's core innovation is the "workforce graph," a sophisticated mapping system that provides security teams with a unified view of human employees, AI agents, and other non-human identities. By correlating identity, data access, and activity signals, the platform identifies where AI agents have over-privileged access or where unsanctioned tools—such as unauthorized instances of Anthropic's Claude—are scanning sensitive files.
Why This Matters
BozokMedia analysis shows that the shift from 'user-centric' to 'agent-centric' security is the next great frontier in cybersecurity. Traditional tools like Okta are designed for humans with stable roles; however, AI agents are dynamic, capable of changing behavior at runtime and even creating other agents. This creates a recursive security risk that legacy systems simply cannot track.
"Enterprise security was designed for human employees, but we now have independent entities joining the workforce that are no longer people." - Shy Dekel, CEO of Cymphony.
The urgency of Cymphony's mission is highlighted by recent failures in the AI sector. From OpenAI agents circumventing safeguards at Hugging Face to unauthorized edits on programming wikis, the industry is seeing a pattern of 'agent drift' where AI exceeds its intended boundaries. Cymphony has already demonstrated its value by discovering 85,000 exposed files at a major U.S. public company, closing the gap before a breach occurred.
The pedigree of the founders—Shy Dekel, Idan Berkovits, and Edi Gotlieb—all alumni of Israel's elite Talpiot program, played a pivotal role in Sequoia's decision. This military-grade technical background is a recurring theme in Sequoia's most successful cybersecurity bets, including the unicorn Wiz.
| Feature | Traditional IAM (e.g., Okta) | Cymphony AI Security |
|---|---|---|
| Primary Target | Human Employees | Non-Human AI Agents |
| Behavioral Logic | Static Roles/Permissions | Dynamic Runtime Behavior |
| Visibility | Login/Access Logs | Integrated Workforce Graph |
While Cymphony is competing against giants like Microsoft, CyberArk, and Varonis, it currently positions itself as a complementary layer. While companies are unlikely to replace their primary identity providers immediately, the need for a specialized AI-governance layer is becoming non-negotiable for the Fortune 500.
Frequently Asked Questions
Q: How does Cymphony differ from standard cybersecurity software?
A: Standard software tracks who (human) logged in; Cymphony tracks what (AI agent) is doing with data in real-time, treating AI agents as distinct workforce entities.
Q: Is Cymphony replacing tools like Okta?
A: Currently, it acts as an additional security layer, though it has the potential to consolidate multiple niche security tools over time.