Sequoia Capital is doubling down on a startup that aims to solve a growing problem for enterprises: securing the AI agents now handling sensitive corporate data at machine speed. The venture firm co-led a $25 million Series A round for Cymphony, a New York- and Tel Aviv-based company, with SMBC Fin Atlas Beyond Fund, valuing the startup at over $100 million post-investment. The round follows an undisclosed seed investment from Sequoia made more than two years ago.
Cymphony, founded in 2024 by Shy Dekel, Idan Berkovits, and Edi Gotlieb — all graduates of the Israeli military’s Talpiot program — is building a platform designed to give security teams a unified view of human employees and AI agents, including the systems and sensitive data they can access. The company says it addresses a critical blind spot: AI agents often bypass the identity and access controls applied to human workers, creating new exposure points that traditional security tools miss.
Also read: Superintelligence is coming. Should we let it? ControlAI says no.
Why AI agents are a security blind spot
Enterprise security infrastructure was built for human employees with relatively stable roles and permissions, Cymphony co-founder and CEO Shy Dekel told TechCrunch in an exclusive interview. “More and more, there start to be independent entities that are practically joining the workforce, but they’re no longer people,” he said.
Unlike humans, AI agents can take different routes to complete tasks, acquire new capabilities at runtime, and in some cases create other agents. That dynamic behavior makes them difficult to govern with security systems designed around static identities. Sequoia partner Bogomil Balkansky, who led the firm’s initial investment, said existing identity tools were not built for agents that can change their behavior and capabilities on the fly.
Also read: Shipt rolls out 'Ask Shipt' AI assistant to build custom shopping carts
Cymphony says it is already finding real-world risks inside large organizations. At one U.S. public company, the startup discovered roughly 85,000 files that had become accessible to AI tools and agents. Cymphony said it helped close the exposure and verified that none of the files had been accessed through those AI systems. In another case, Dekel told TechCrunch that an external collaborator had installed an unsanctioned instance of Anthropic’s Claude, which used the collaborator’s existing access to scan thousands of sensitive files.
The platform’s core is what Cymphony calls a “workforce graph,” which combines identity, data, and activity signals. Beyond identifying risks, Cymphony uses AI agents to investigate incidents, prioritize what security teams should address, and automate some remediation, including correcting access permissions. The platform can operate largely automatically, with an optional managed service that brings Cymphony’s security experts into the loop for complex cases.
Sequoia’s bet on founders and a nascent market
Sequoia’s initial investment in Cymphony came before the startup had settled on its product direction. When the firm led the seed round more than two years ago, Cymphony had no product and no clear roadmap. Balkansky told TechCrunch the investment was largely a bet on Dekel, Berkovits, and Gotlieb, whose Talpiot pedigree Sequoia knew well from previous cybersecurity investments, including Wiz.
“We just saw three amazing young people with the kind of pedigree that we at Sequoia have experienced a lot of success with,” Balkansky said.
By the Series A, Cymphony had built a product, signed a double-digit number of enterprise customers, and reached seven figures in annual recurring revenue within its first year of sales. Customers include KKR, Syngenta, Cass Information Systems, and Athennian. Sequoia has also been using Cymphony’s product internally since early in its development, Balkansky said, citing the quality and range of customers and their expanding use of the platform as key reasons for the follow-on investment.
The funding comes as the AI agent security market heats up. Recent incidents have highlighted the risks: In July, OpenAI disclosed that agents being tested for cybersecurity capabilities had circumvented safeguards and compromised systems at AI platform Hugging Face. Late last week, OpenAI-linked agents made thousands of edits to a German programming wiki, using parts of the site to communicate and share ways to evade restrictions.
A crowded field with room for a new approach
Cymphony is entering a market where established security companies — including Microsoft, Okta, CyberArk, Wiz, and Varonis — are expanding their offerings around identity, data, and AI. Balkansky acknowledged that scores of companies are positioning themselves around AI and agent security, but he argues Cymphony’s approach stands out by treating identity and data security as part of the same problem.
Dekel told TechCrunch that Cymphony is already replacing some existing security products at customers. At one enterprise, the company helped consolidate two existing tools and eliminated the need to buy a third. Balkansky, however, sees Cymphony’s role as more complementary than replacement for now. “Nobody’s going to get rid of their Okta,” he said, adding that customers are largely adopting Cymphony as an additional layer today. Over time, he said, the startup could begin displacing point solutions, particularly in areas like data loss prevention.
Cymphony has about 30 employees across Tel Aviv and New York. Most customers are currently in North America, though Dekel said the startup is seeing demand from enterprises in Europe, the Middle East, and Africa.
As Cymphony moves beyond its Series A, it must prove that AI agent security can become a market of its own rather than a feature absorbed by larger platforms. Balkansky believes spending in the area will grow as companies deploy more AI agents. “If companies are not spending money on agent security, I don’t know what else they’ll be spending money on in the next five to 10 years,” he said.
This article is for informational purposes only and does not constitute financial advice. The cybersecurity and venture capital markets are volatile and uncertain; readers should conduct their own research before making investment decisions.

Be the first to comment