Cymphony
by Cymphony
Workforce security graph that maps what employees and AI agents can reach, then remediates the exposure
Cymphony is an AI-era workforce security platform that maps employees, AI agents and other non-human identities to the systems, permissions and sensitive data they can reach. It is built for CISOs and security teams who need to find and fix AI-driven data exposure, over-privilege and insider risk quickly, without installing endpoint agents.
Cymphony is a New York- and Tel Aviv-based security company founded in 2024 by Shy Dekel (CEO), who spent nearly six years at Israel's Unit 8200 and rose to head its cyber department, Idan Berkovits (CPO) and Edi Gotlieb (CTO), a former Apple hardware engineer; all three are graduates of Israel's Talpiot programme. The company emerged from stealth on 9 September 2026 with $30 million: a $25 million Series A co-led by Sequoia Capital and the SMBC Fin Atlas Beyond Fund (a Sumitomo Mitsui Banking Corp. and Fin Capital vehicle), following an earlier, previously undisclosed seed round from Sequoia, at a reported valuation above $100 million. The core of the product is a workforce security graph that unifies identity, permission, data and activity signals, so a security team can see which employees, AI agents and other non-human identities can reach which applications and sensitive files, and what a compromised identity could actually do. The platform is split into an AI module (which AI tools staff use and what data they feed them), a data module (overshared or exposed information), an identity module (stale admin accounts, missing MFA and over-privilege) and a Threat Center for insider signals such as bulk downloads. Maestro, a natural-language assistant, handles investigation, automated employee outreach and remediation. Deployment is agentless, and the company says the platform goes live within a day. Named customers include KKR, Syngenta, Cass Information Systems and Athennian. TechCrunch reported roughly 30 employees, a double-digit enterprise customer count and seven-figure ARR within the first year of sales. In one customer case the platform found about 85,000 files accessible to AI tools; in another it uncovered an unsanctioned Claude instance scanning thousands of sensitive files. Cymphony positions itself as complementary to identity and data-security incumbents such as Microsoft, Okta, CyberArk, Wiz and Varonis.
A CISO or identity/data-security lead at an enterprise where employees are connecting ChatGPT, Claude and other AI agents to SharePoint, Box, Snowflake or Salesforce faster than access reviews can keep up.
One graph showing what every employee and AI agent can reach, with prioritised, partly automated remediation of the exposure it finds.
At a Glance
- Category
- Governance & Security
- Pricing
- Contact for pricing
- Target Market
- CISOs, Security Operations Teams, Identity & Access Management Teams, CIOs
- Deployment
- Cloud-first
- Founded
- 2024
- Headquarters
- New York, United States
- Team Size
- 11-50
- Customers
- Double-digit number of enterprise customers (TechCrunch, Sep 2026)
Key Features
- ✓Workforce security graph
Unifies identities, permissions, sensitive data and activity into one graph, showing what each human or AI identity can actually reach.
- ✓AI module
Shows which AI tools employees use and what data they send or connect, surfacing shadow AI and risky connections.
- ✓Data module
Finds overshared or exposed sensitive data and helps block unauthorised AI access before assistants can index it.
- ✓Identity module
Flags stale admin accounts, missing multifactor authentication and over-privileged human and machine identities for cleanup.
- ✓Threat Center
Detects insider-risk activity such as large or bulk file downloads in real time so analysts can investigate quickly.
- ✓Maestro security assistant
Natural-language assistant that investigates risks, contacts employees automatically and drives remediation workflows without complex query syntax.
Capabilities
Use Cases
- •AI assistant rollout readiness
Before connecting ChatGPT to SharePoint, map and remove oversharing so that interns cannot surface sensitive litigation documents through the assistant.
- •Shadow AI discovery
Identify unsanctioned AI agents, such as an external collaborator's Claude instance scanning thousands of sensitive files, and shut down their access.
- •Exposure measurement at scale
Quantify how many files AI tools can reach (one public company found about 85,000) and verify whether any were accessed without authorisation.
- •Continuous access remediation
Replace weekly or monthly permission scans with continuous monitoring that prioritises fixes and automates outreach to account and file owners.
Ideal For
Best For
- ✓Discovering which AI tools employees use and what sensitive data those tools can reach
- ✓Cleaning up oversharing in SharePoint and similar repositories before connecting enterprise AI assistants
- ✓Identity hygiene across human and non-human identities: stale admins, missing MFA and over-privilege
- ✓Insider-risk detection such as unusual bulk file downloads
- ✓Security teams that want an agentless deployment live within about a day
Not Ideal For
- ✗Buyers who require a long track record or third-party reviews: the company emerged from stealth in September 2026 with about 30 employees and has no public user reviews
- ✗Organisations looking to replace their IAM, PAM or data-security stack outright, since Cymphony positions itself as complementary to vendors such as Okta, CyberArk and Varonis, at least initially
- ✗Teams that need published list pricing for budgeting, because pricing is only available through sales
Deployment
Market & Ratings
Double-digit number of enterprise customers (TechCrunch, Sep 2026)
Market Analysis
Pros
- ✓Backed by Sequoia in both the seed and the Series A, at a reported valuation above $100M
- ✓Named enterprise customers including KKR and Syngenta, plus reported seven-figure ARR in its first year of sales
- ✓Agentless deployment reported to go live within one day
- ✓SOC 2 certified and GDPR compliant
Cons
- ✗Very young vendor: it emerged from stealth in September 2026 with about 30 employees, and TechCrunch notes that Sequoia's seed investment came before a product or a clear direction existed
- ✗Crowded market: TechCrunch cautions that success depends on AI-agent security holding up as a standalone category rather than a feature bundled by larger platforms such as Microsoft, Okta, CyberArk, Wiz or Varonis
- ✗Headline outcomes (a 74% cut in AI-driven data exposure and a 45% blast-radius reduction) are vendor-reported, and we found no Hacker News discussion or independent user reviews
- ✗No published pricing
Pricing
Enterprise
Contact for pricing
- ✓Workforce security graph
- ✓AI, data and identity modules
- ✓Threat Center
- ✓Maestro security assistant
- ✓Optional managed service with security experts
Cymphony does not publish list pricing and sells enterprise contracts through its sales team, so metering units are not public. The company says every proof of concept gets an actionable risk-reduction plan within one week, and TechCrunch reports an optional managed service staffed by security experts.
Security & Compliance
Sources
This page was written from 6 sources, 5 on domains other than cymphony.io.
- 1.cymphony.io — cymphony.iovendor
- 2.pr-inside.com — cymphony launches with 30 million to secure ai agents access
- 3.techcrunch.com — sequoia doubles down on cymphony as ai agents create new ent
- 4.siliconangle.com — cymphony launches with 30m to track what ai agents can reach
- 5.bankinfosecurity.com — cymphony raises 30m to turn access data into remediation a 3
- 6.fintech.global — cymphony lands 30m as ai agents test data access limits
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
Mate Security
Open agentic SOC platform powered by a security context graph built for each organisation
MintMCP
Enterprise MCP gateway that gives every AI agent its own identity, scoped tools and audit trail
JFrog AI Catalog
Govern the models, MCP servers, skills and plugins your AI coding agents consume
Alice (formerly ActiveFence)
AI red teaming and real-time guardrails for models, apps and agents, built on a decade of adversarial data