Illustration for: Sequoia Backs Cymphony's $30M AI Agent Security Bet

Sequoia Backs Cymphony's $30M AI Agent Security Bet

Cymphony launched with $30 million in total funding, including a $25 million Series A co-led by Sequoia, to give enterprises a single view of what data and systems their AI agents can access.

By the Numbers

$25M
Series A
$30M
Total funding
>$100M
Post-money valuation
~2024, NY & Tel Aviv
Founded
TC
By the AI Desk
Edited by Trace Cohen · Early-stage VC & angel · Founder, New York Venture Partners
2 min read
ShareXLinkedInEmail

THE RUNDOWN

1

A valuation above $100 million on seven-figure ARR prices Cymphony as the category's default layer rather than a point tool -- the seed-to-Series-A jump only pencils if enterprises standardize on the workforce graph.

2

Okta and CyberArk are already extending into non-human identity as a product line, which means Cymphony's competition can attach the capability to enterprise contracts that are already signed rather than sell a new one.

3

Sequoia wrote the previously undisclosed seed and then co-led the $25 million Series A with SMBC Fin Atlas Beyond Fund -- a doubling down that concentrates its exposure before any standard for agent-access governance exists.

4

KKR, Syngenta, Cass Information Systems and Athennian clearing procurement in year one is the real signal to test: a private equity firm's vendor security review is a harder bar than a typical mid-market logo.

TC

The VC Read · Trace's Take

Trace Cohen

Seven-figure ARR in year one with KKR and Syngenta as logos is a genuinely strong signal for a security seed-to-Series-A jump, and Dekel's Unit 8200 background is exactly the kind of technical credibility enterprise security buyers actually diligence. The real risk isn't product-market fit, it's platform risk: Okta or CrowdStrike bolting a 'non-human identity' module onto an existing enterprise contract could neutralize Cymphony's standalone pitch faster than a security startup this early usually has to worry about.

Analysis

Cymphony emerged from stealth with $30 million in total funding, anchored by a $25 million Series A co-led by Sequoia Capital and SMBC Fin Atlas Beyond Fund, TechCrunch reported September 9. The round follows a previously undisclosed Sequoia seed check, and values the New York- and Tel Aviv-based company at more than $100 million post-money.

Cymphony was founded by CEO Shy Dekel, who spent nearly six years heading the cyber department of Israel's Unit 8200, alongside CTO Edi Gotlieb, a former Apple and Israeli Ministry of Defense hardware engineer, and CPO Idan Berkovits, a former Israeli Prime Minister's Office research group manager -- all graduates of the Talpiot program. The company built what it calls a "workforce graph" giving security teams a single view of employees, AI agents and other non-human identities, including exactly what systems and sensitive data each can reach. In its first year of sales, Cymphony signed a double-digit number of enterprise customers, including KKR, Syngenta, Cass Information Systems and Athennian, and reached seven figures in annual recurring revenue.

The problem Cymphony is solving is specific and increasingly urgent: AI agents now routinely get provisioned with access to the same corporate systems and sensitive data as human employees, but without going through the identity and access controls -- background checks, role-based permissions, offboarding processes -- that govern human hires, while operating at machine speed and often across multiple systems simultaneously. Competing approaches include traditional identity-and-access-management vendors like Okta and CyberArk extending into "non-human identity" as a new product category, and earlier-stage pure-plays like AIR, which raised $50 million on September 1 for a related but distinct problem: vetting the skills and third-party add-ons AI agents use, rather than mapping what those agents can already access.

The AI-agent security category is young enough that no vendor has established a clear standard the way Okta did for human identity two decades ago, which is both the opportunity and the risk: Cymphony's $100 million-plus valuation on seven-figure ARR assumes it becomes the default layer enterprises adopt before a larger incumbent builds or buys a comparable capability into an existing enterprise contract that's already signed.

Analysts covering the identity-security market have started sizing "non-human identity" as a distinct category worth billions in annual spend within a few years, driven by the sheer multiplication of API keys, service accounts and now autonomous AI agents that each require some form of access governance -- a problem that barely existed five years ago when the primary non-human identity concern was service-account sprawl in cloud infrastructure, not agents capable of independently deciding which systems to query next. Talpiot, the elite Israeli military technology program all three Cymphony founders graduated from, has produced a disproportionate share of Israeli cybersecurity founders relative to its tiny class sizes, including alumni behind companies like Wiz and Orca Security, giving Cymphony's team a recruiting and credibility advantage in a crowded seed-to-Series-A security market.

The seven-figure ARR Cymphony disclosed in its first year of sales compares favorably to typical enterprise security seed-stage benchmarks, where six-figure ARR in year one is more common; landing KKR as a customer specifically signals the product has cleared the kind of rigorous vendor security review a private equity firm managing sensitive portfolio-company data would require, a harder bar than a typical mid-market enterprise logo.

ShareXLinkedInEmail

Key Sources

2 sources

Reported by TechCrunch · Analysis by Value Add Pulse.

← Back to Pulse

THE WIRE in your inbox— Tech, startup & VC news with Trace's take. Free, no spam.