Cymphony Raises 30 Million to Answer a Question Most CIOs Cannot Answer Yet
Data Engineering

Cymphony Raises 30 Million to Answer a Question Most CIOs Cannot Answer Yet

A Sequoia-backed startup founded by three Israeli military-intelligence veterans just raised a 25 million dollar Series A to map exactly which sensitive data every AI agent, employee, and machine account can reach inside your company.

PublishedSeptember 10, 2026
Read time6 min read
Share

What Cymphony actually built

Cymphony launched out of stealth this week with a platform that tracks what AI agents, human employees, and machine accounts can access across a company's systems. The core of the product is what the company calls a workforce security graph, a live map connecting identities, the permissions attached to them, the sensitive data those permissions expose, and the activity that follows. The pitch is deployment without endpoint agents: point Cymphony at your identity and data systems and it builds the graph without installing software on every laptop and server, with the company claiming customers can be live within a day.

The platform organizes its work around four areas: tracking how employees and agents actually use AI tools, detecting when sensitive data is exposed to accounts that should not reach it, cleaning up identity hygiene issues like stale permissions and orphaned accounts, and watching for insider threat patterns. A conversational assistant called Maestro sits on top, letting security teams investigate an alert and kick off remediation without writing a query language or filing a ticket to a separate access-management team.

The funding and who is behind it

The company announced a 25 million dollar Series A co-led by Sequoia Capital and the SMBC Fin Atlas Beyond Fund, a 300 million dollar vehicle that Sumitomo Mitsui Banking Corp and Fin Capital launched in July 2025. Combined with an earlier, undisclosed seed round, Cymphony has raised roughly 30 million dollars and now carries a valuation above 100 million dollars. Sequoia partner Alex Balkansky framed the bet around a structural shift: as agents join the workforce alongside humans, enterprises need the same visibility and control tools for machine identities that they built for human ones over the last decade.

The founding team's background is a big part of the pitch. Chief executive Shy Dekel spent six years in Israel's Unit 8200 signals intelligence unit, most recently heading its cyber department. Chief technology officer Edi Gotlieb was a hardware engineer at Apple and at Israel's Ministry of Defense, and chief product officer Idan Berkovits managed a research group inside the Office of the Prime Minister. All three came up through Talpiot, Israel's elite military technology training program, before founding a roughly 30-person company split between New York and Tel Aviv.

The problem this is actually solving

Dekel's example of the failure mode is specific enough to be useful: at one prospective customer, any intern could query documents tied to an incredibly sensitive litigation process, simply because nobody had ever audited who could reach that data once it landed in a shared system. That is not a hypothetical about AI models going rogue. It is a much older and more mundane problem, permission sprawl, that AI agents make dramatically more dangerous because agents can query, summarize, and act on whatever they can reach at machine speed and without the hesitation a human employee might have before opening a folder marked confidential.

This is exactly the gap that shows up when enterprises try to move AI pilots into production and stall out. The usual blocker is the inability to say with confidence which systems and documents a given agent is allowed to touch, and to prove that to an auditor or a regulator after the fact, well before the model itself becomes the limiting factor. Cymphony's graph approach treats that as a data problem as much as a security problem, since answering it requires cataloging where sensitive data actually lives before you can decide who or what gets to see it.

Early traction and what it signals

Cymphony counts Syngenta, KKR & Co., Cass Information Systems, Athennian, and even Sequoia Capital itself among its early customers, and says it reached seven-figure annual recurring revenue within its first year, a fast ramp for a company still operating largely in stealth until now. That customer list skews toward financial services and other regulated, data-dense industries, which tracks with where the pain is most acute: firms that hold enormous volumes of sensitive client and deal information and are under the most pressure to prove they know exactly who and what can reach it.

The fast revenue ramp also says something about market timing. A year ago, a pitch built entirely around governing AI agent access would have been ahead of most buyers' actual deployments, competing for budget against more urgent, better-understood security priorities. Now enough enterprises have agents touching production systems, reading contracts, querying databases, and summarizing internal documents, that a product mapping exactly what those agents can see has an obvious, immediate buyer with a line item already open, rather than a hypothetical future one still waiting for a business case.

Where this sits in a crowded field

Cymphony is entering a market that already includes identity governance incumbents and a wave of newer AI-agent security startups, several of which have raised comparable rounds in recent months chasing the same thesis. What differentiates a workforce security graph from a conventional identity and access management tool is scope: it explicitly treats AI agents and machine accounts as first-class citizens in the graph alongside humans, rather than bolting agent visibility onto a product built for a world where every account had a person behind it.

Whether that framing holds up against well-funded competitors and the identity giants' own agent-security roadmaps is an open question the market will answer over the next year. What is not in question is the underlying demand. Every enterprise running agents against real data now has a governance gap that used to be theoretical and is now a board-level liability question, and that gap is what is pulling venture capital toward this exact category.

The question this puts to every CIO

Before evaluating Cymphony or any competitor, run the exercise it is selling a solution to: pick one AI agent already in production at your company and try to produce, today, a complete list of every data source, document repository, and system it can reach. Most security and data leaders cannot do this quickly, and that gap is the actual product category forming around this problem, not a specific vendor's feature set.

If you can produce that list, the next question is whether it matches what you intended when you provisioned the agent, or whether it has quietly grown the way human permissions always do, through inherited group memberships and forgotten access grants nobody ever revoked. That mismatch is where the next serious data incident is most likely to originate, and it is worth an honest audit before a new AI initiative expands the blast radius further.

Tagged#news#data#data-engineering#databases#analytics#lakehouse#streaming#ai-agents#data-governance#identity-security#venture-capital