Skip to content
Tech News
← Back to articles

Sequoia doubles down on Cymphony as AI agents create new enterprise security risks

read original get Yubico YubiKey 5 NFC Security Key → more articles
Why This Matters

AI agents are being granted employee-level access to corporate systems and data without going through the identity and access controls built for humans, creating a new class of enterprise security blind spots. Sequoia's continued backing of Cymphony — now with $30M total and a $100M+ valuation — signals that investors see 'non-human identity' governance as a real enterprise budget line, not a niche. For companies deploying agents at scale, the question of who (or what) can see which files is becoming urgent.

Key Takeaways
Worth a Look

Yubico YubiKey 5 NFC Security Key — If identity is the new security perimeter — for humans and AI agents alike — a hardware security key is the simplest way to lock down your own accounts. The YubiKey 5 NFC plugs into USB-A or taps on your phone via NFC, and works with major password managers, cloud consoles, and work logins for phishing-resistant sign-in.

See Yubico YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

As AI agents gain access to the same sensitive corporate data and systems as human workers while operating at machine speed, enterprises are prone to new security risks. Storied venture firm Sequoia Capital is betting big on that shift, backing startup Cymphony as it emerges with $30 million in funding to help companies keep their growing AI workforce in check.

The funding includes a $25 million Series A co-led by Sequoia and SMBC Fin Atlas Beyond Fund, valuing the New York- and Tel Aviv-based startup at more than $100 million after investment. The round follows a previously undisclosed seed investment from Sequoia.

AI agents do not necessarily go through the same access and identity controls as employees, but they have access to multiple systems and handle large amounts of corporate data. This makes it hard for enterprises to track who has access to what.

Cymphony is trying to address that gap by giving security teams a single view of employees, AI agents, and other non-human identities, including the systems and sensitive data they can access. At the core of its platform, the two-year-old startup has built what it calls a “workforce graph”. This brings together identity, data, and activity signals.

“Enterprise security was designed for human employees,” Cymphony co-founder and CEO Shy Dekel (pictured above, center) said in an exclusive interview. “More and more, there start to be independent entities that are practically joining the workforce, but they’re no longer people.”

Cymphony says it is already finding those risks inside large companies. At one U.S. public company, the startup said it found about 85,000 files that had become accessible to AI tools and agents. Cymphony stated it helped close the exposure and verified that none of the files had been accessed through those AI systems.

In another case, Dekel told TechCrunch that an external collaborator had installed an unsanctioned instance of Anthropic’s Claude that used the collaborator’s existing access to scan thousands of sensitive files.

Beyond identifying risks, Cymphony uses AI agents to investigate incidents, prioritize what security teams should address, and automate some remediation, including correcting access permissions. The platform can operate largely automatically, Dekel said, adding that customers can also opt for a managed service that brings Cymphony’s security experts into the loop for more complex cases.

Why Sequoia doubled down

Sequoia’s initial bet on Cymphony came before the startup had settled on the problem it wanted to solve. When the venture firm led its seed round more than two years ago, Cymphony had no product or even a clear product direction, Sequoia partner Bogomil Balkansky told TechCrunch.

... continue reading