Cymphony: Securing the Non-Human Workforce

A critical assessment of the $25M Series A — co-led by Sequoia and SMBC’s Fin Atlas Beyond Fund — for a tool that maps every AI agent’s reach into enterprise data, yet never says which LLM sees that map.

ProofStory Research September 9, 2026

$25M Series A, Co-Led by Sequoia & SMBC — September 9, 2026

Cymphony emerged publicly with a “Workforce Security Graph” that maps every human, AI agent, and non-human identity (NHI) to the systems and sensitive data they can reach. The $25M Series A brings total funding to $30M, including a prior undisclosed Sequoia seed. Post-money valuation is reported above $100M for a company roughly two years old.

$25M
Series A
$100M+
Post-Money Valuation
2
HQ Cities (NY + Tel Aviv)
85K
Files AI Could Reach, One Client

Three Core Questions

01

“Is It Really a $30M Series A?”

No. The Series A is $25M, co-led by Sequoia and SMBC’s Fin Atlas Beyond Fund; the $30M headline includes a prior undisclosed seed. TechCrunch, SiliconANGLE, and Forkast all report the round at $25M — the larger cumulative figure is allowed to lead.

02

“How Crowded Is This Category?”

Very. Non-human-identity security absorbed ~$435M in five months. Sequoia is funding Cymphony, Oasis, and Zenity — overlapping bets. Astrix, Aembit, Token, and Clutch already sell versions of “map the machine identities,” several with 2–3× the capital.

03

“What Powers Maestro?”

Unknown. Cymphony’s pitch opens with a rogue Claude instance scanning sensitive files — yet its own AI assistant’s model provider is undisclosed, and the privacy policy names no LLM sub-processor. The tool that maps everyone’s data access won’t say where the reasoning happens.

Key Finding: The problem Cymphony sells is real — AI agents and non-human identities now hold enterprise access no one is tracking. But every performance number originates with Cymphony (“seven-figure ARR,” “74% reduction,” “double-digit customers”), the category is crowded and better-capitalized, and the product itself becomes the single highest-value blast radius in any enterprise that deploys it — a concentration-of-privilege risk it has not addressed publicly.

The Numbers

Founded
~2024 (company describes itself as two years old)
Headquarters
Dual: New York + Tel Aviv, ~30 employees
Founders
Shy Dekel (CEO, ex-Unit 8200), Edi Gotlieb (CTO, ex-Apple + Israel MoD), Idan Berkovits (CPO) — all Talpiot graduates
Funding
$25M Series A co-led by Sequoia Capital + SMBC Fin Atlas Beyond Fund; $30M total incl. seed; >$100M post-money
Product
“Workforce Security Graph” unifying identity, data, and activity across humans, AI agents, and NHIs; modules for AI, Data, Identity, Threat Center, and the “Maestro” assistant
Customers
KKR, Syngenta, Cass Information Systems, Athennian; Sequoia internally — “double-digit” enterprises (company-stated)
Revenue
“Seven figures” ARR within first year of selling (claim; unaudited, deliberately vague)
Category
Non-human identity (NHI) / AI agent security — ~$435M raised sector-wide in five months

The Workforce Security Graph

Cymphony’s core claim is that identity security and data security have collapsed into one problem the moment AI agents joined the workforce. Its answer is a single graph. Here is how the company describes the pipeline.

From Identity to Remediation

01

Ingest Identities

Pulls in every human employee, AI agent, and non-human identity — service accounts, API keys, bots — across the enterprise.

02

Map Data Access

Ties each identity to the systems and sensitive data it can reach, exposing over-provisioned permissions and shadow access.

03

Correlate Activity

Overlays real behavior onto the graph — what each identity actually touched, versus what it theoretically could.

04

Investigate (Maestro)

An AI assistant surfaces and explains anomalies — e.g. an unsanctioned model scanning thousands of files before anyone noticed.

05

Remediate

Automates right-sizing of access and blast-radius reduction — claimed at “one-day” deployment with no endpoint installs.

The framing is genuinely sharp — but the moat is a positioning claim, not a demonstrated one. “One graph unifying human + NHI + data + activity” is nearly word-for-word how Oasis, Astrix, and Token describe themselves. On public evidence, Cymphony’s differentiation is narrative, not technology.

The Security Tool Is the Biggest Target It Creates

To map everyone’s blast radius, Cymphony must itself become a maximally-privileged non-human identity — ingesting the entire enterprise’s identity graph, permission map, and sensitive-data inventory. That makes it the single highest-value blast radius in any customer that deploys it. Yet the company never discloses which LLM powers Maestro, whether customer data transits a third-party model, or whether that data is used for training. Its privacy policy names AWS, Google Analytics, Meta Pixel, and LinkedIn Insights — and is silent on any AI sub-processor. A tool sold to catch a rogue Claude instance will not say what powers its own.

Non-Human Identity (NHI)

Service accounts, API keys, bots, and now AI agents — identities that hold access but aren’t people. The category Cymphony sells into.

Sequoia Capital

Led both seed and Series A. Also backs Oasis and Zenity — conviction, but not exclusive conviction, in this space.

SMBC Fin Atlas Beyond Fund

A ~$300M early-stage US fintech vehicle (with Fin Capital), co-leading the round — a strategic banking-sector signal.

“74% Reduction”

Cymphony’s claim of AI-driven data-exposure reduction in 30 days. Appears only on its own site; no methodology, baseline, or sample disclosed.

Talpiot / Unit 8200

Elite Israeli military-tech pedigree shared by all three founders — strong technical signal, common to many rivals in this space.

Launch-Cycle Coverage

Every outlet’s numbers echo one company press narrative on one day. No independent customer reference or product benchmark exists yet.

A Crowded Graph

Cymphony enters a category that was already well-funded before its Series A — and whose lead investor is simultaneously backing its rivals.

01

Better-Capitalized Rivals

Astrix Security (~$85M) and Oasis Security (~$75M+, itself Sequoia-backed) lead the NHI-governance field. Token Security, Aembit (~$44M), and Clutch have shipped machine-identity products longer. Incumbents Okta and CyberArk (the latter in a ~$25B agreed acquisition by Palo Alto) own the identity layer Cymphony must displace. Competitor funding figures are estimates from pre-2026 reporting and warrant re-verification.

02

The Conflicted Lead

Sequoia is funding Cymphony, Oasis, and Zenity — three adjacent-to-overlapping bets, described by Forkast as its third agent-security investment in three weeks. That is a bet on the category, not a moat for any one company in it. Capital here signals thesis conviction, not that Cymphony has won.

The differentiation problem in one line: when your lead investor also funds two of your closest competitors, and your product framing is interchangeable with theirs, the durable question isn’t whether the market is real — it’s whether this team wins it. On public evidence, that’s unproven.

Weaknesses & Threat Vectors

Six structural risks the $25M Series A does not resolve.

High

Undisclosed LLM Dependency

The most-privileged tool in the enterprise won’t name the model behind Maestro, whether graph data transits a third party, or whether it’s used for training. Exactly the opacity Cymphony sells against.

High

Concentration of Privilege

Cymphony holds the entire access graph, permission map, and data inventory. A compromise of Cymphony is a compromise of the customer’s whole enterprise — a single point of catastrophic failure.

High

Crowded, Conflicted Category

Sequoia backs three overlapping NHI/agent-security startups; several rivals carry 2–3× the capital and longer enterprise track records. Capital is not exclusive conviction.

High

All Metrics Self-Reported

“Seven-figure ARR,” “double-digit customers,” and the 74%/45% reduction stats have no third-party validation, methodology, or sample. Uniformly positive launch coverage is not verification.

Medium

Category-Demand Risk

Gartner forecasts >40% of agentic-AI projects canceled by end-2027, and most enterprises never ship agents to production. If agents don’t reach production, agent-security spend softens.

Medium

Consumer-Grade Legal Posture

The public privacy policy carries Meta Pixel / LinkedIn trackers and generic “payment facilitator” language — unhardened for an enterprise security buyer, implying the real data-processing terms live in an unpublished document.

Assessment Matrix

Market Timing
High
The “what can this agent reach” problem is real and urgent; buyer and investor attention are peaking now
Technical Moat
Low-Medium
A workforce graph is defensible in principle but unproven; identical framing exists at Oasis, Astrix, Token
Competitive Defensibility
Low
Well-funded incumbents and better-capitalized startups occupy the same space; Sequoia hedges across rivals
Business Model
Medium
Seven-figure year-one ARR is a genuine signal, but tiny base, undisclosed pricing, and cancellation risk cap it
Data-Governance Risk
High
Undisclosed model dependency in a super-privileged tool is the central diligence question
Team Signal
High
Unit 8200 / Talpiot founders with intelligence-grade security depth — genuine, if common to the field
Investor Thesis
Agent Security
Securing the non-human workforce as AI agents gain enterprise access — a category bet, not a company bet

Cymphony is selling a real problem to real buyers with a real team. The open questions are whether a “workforce graph” is a moat or a category norm, whether a tool that concentrates every enterprise’s access map can be trusted with it — and why the vendor that hunts rogue models won’t disclose its own. Any enterprise buyer should resolve the LLM sub-processor and data-training questions before granting Cymphony the keys to everything.

Research Sources

Based on publicly available information as of the TechCrunch announcement of September 9, 2026. All performance figures are company-stated and unaudited; competitor funding levels are estimates from pre-2026 reporting and warrant re-verification.

  1. TechCrunch — “Sequoia doubles down on Cymphony as AI agents create new enterprise security risks” (September 9, 2026)
  2. SiliconANGLE — “Cymphony launches with $30M to track what AI agents can reach” (September 9, 2026)
  3. Forkast — “Cymphony raises $25M as the agent-identity security stack keeps forming” (September 9, 2026)
  4. The AI Insider — “Sequoia leads $30M round for Cymphony to secure enterprise AI agents” (September 9, 2026)
  5. Yahoo Finance — syndicated coverage of the Cymphony round
  6. Sequoia Capital — Cymphony company page and investment thesis
  7. Cymphony — company homepage (cymphony.io), product modules, and performance claims
  8. Cymphony — privacy policy (sub-processor and tracker disclosures)
  9. Founder profiles — Shy Dekel, Edi Gotlieb, Idan Berkovits (LinkedIn / public bios)
  10. Competitive reference — Astrix, Oasis, Token, Aembit, Clutch, Zenity, CyberArk, Okta (public reporting, figures estimated)