Cymphony Raises $25M to Secure the Rise of Autonomous AI Agents
The cybersecurity startup is building a 'workforce graph' to manage non-human identities as AI agents bypass traditional enterprise security.
Cybersecurity startup Cymphony has raised $25 million in Series A funding to address the security gaps created by the deployment of autonomous AI agents in the enterprise. The round was co-led by Sequoia Capital and SMBC Fin Atlas Beyond Fund, pushing the company's total funding to $30 million and its valuation beyond $100 million.
Cymphony specializes in AI agent governance, providing a "workforce graph" that allows companies to track and secure access permissions for non-human identities. This infrastructure is designed to monitor AI agents that can operate independently and alter their behavior at runtime—capabilities that often allow them to bypass traditional security controls. The company has seen rapid early adoption, reaching seven figures in annual recurring revenue (ARR) within its first year of sales. Its current customer base includes firms such as KKR, Syngenta, Cass Information Systems, and Athennian.
The Gap in Identity Management
Traditional identity and access management (IAM) tools were built for human employees with stable roles and predictable patterns. However, the shift toward "agentic AI" introduces entities that function as independent workers but lack the oversight applied to people. This creates a critical vulnerability where machine-speed actors may possess broad access to sensitive data without adequate governance.
Cymphony's founders—Shy Dekel, Idan Berkovits, and Edi Gotlieb, all alumni of Israel's elite Talpiot technology program—aim to close this gap by integrating identity and data security into a single visibility layer. By treating AI agents as distinct identities, the platform prevents the "over-permissioning" that often occurs when agents are granted broad access to corporate environments to ensure they can complete tasks without friction.
Why Agent Security Matters
As AI agents move from simple chatbots to autonomous operators, they effectively join the corporate workforce. "Enterprise security was designed for human employees," said Cymphony co-founder and CEO Shy Dekel. "More and more, there start to be independent entities that are practically joining the workforce, but they’re no longer people."
For the broader market, this represents a fundamental shift in infrastructure. If AI agents are granted the power to execute tasks across various software environments, the potential for unauthorized data access or systemic failure increases exponentially. Bogomil Balkansky, a partner at Sequoia, emphasized the long-term necessity of this sector, stating that if companies are not investing in agent security, it is difficult to imagine where else they will be spending their security budgets over the next five to 10 years.
What's Next for AI Governance
Cymphony's growth suggests a growing corporate appetite for specialized AI governance tools as enterprises move past the experimentation phase of generative AI. The company's focus on the "workforce graph" positions it as a foundational layer for the safe adoption of autonomous agents. Future industry movement will likely center on whether these governance tools can keep pace with the rapid evolution of agentic capabilities and whether standard IAM frameworks can be adapted or must be entirely replaced by non-human-centric security models.