Obsidian Security
by Obsidian Security
Governs what AI agents and non-human identities can access and do inside your SaaS apps
Obsidian Security is a SaaS and AI security platform that discovers, governs and enforces runtime controls on the non-human identities — AI agents, OAuth tokens, API keys and third-party integrations — reaching into enterprise business applications. It is built for CISOs and security operations teams that have approved agent rollouts into Microsoft 365, Salesforce, ServiceNow and Snowflake and cannot see what those agents actually do afterwards.
Obsidian Security is a SaaS and AI security platform that governs what non-human identities — AI agents, OAuth tokens, API keys and third-party integrations — can access and do inside enterprise business applications. Founded in 2017 in Palo Alto, California by veterans of Carbon Black and Cylance and led by CEO Hasan Imam, the company announced an $85 million Series D on 4 August 2026 led by Crescent Cove Advisors with participation from existing investors Greylock Partners, Menlo Ventures, Norwest Venture Partners, IVP, GV and Wing Ventures, taking total funding past $200 million at a roughly $1.1 billion valuation. The platform spans five areas: discovery of shadow AI and shadow SaaS, MCP servers, browser extensions and third-party integrations; posture management and compliance auditing for connected applications, including privilege minimisation and integration rightsizing; identity threat detection and response covering account takeover, session hijacking, insider risk and API or token compromise; runtime guardrails that detect and block privilege escalation, excessive data access and policy violations by agents after deployment; and AI-specific controls for prompt security and GenAI data leakage. It maintains inventories of the MCP servers and LLMs in use and maps them to the agents calling them. Connectors cover Amazon Bedrock, Google Vertex AI, Microsoft Foundry and Copilot, Anthropic Claude, OpenAI, Salesforce Agentforce and n8n on the AI side, and Microsoft 365, Google Workspace, Salesforce, ServiceNow, GitHub, Snowflake, Databricks and Workday on the SaaS side. Obsidian says more than 100 customers spend over $100,000 a year with it and 14 spend over $1 million, including 60 of the Fortune 500.
The CISO or SaaS security lead at a large enterprise that has already connected AI agents — Copilot, Agentforce, Bedrock, Claude, n8n — to production SaaS and now has to answer an auditor asking which agent touched which records, and prove it can stop one.
A single inventory of every agent, MCP server, LLM and OAuth token reaching your SaaS estate, plus runtime enforcement that blocks privilege escalation and excessive data access after deployment rather than only flagging it in a report.
At a Glance
- Category
- Governance & Security
- Pricing
- Subscription, Freemium, Contact for pricing
- Target Market
- CISOs, CIOs, Security Operations, IT Directors
- Deployment
- Cloud-only, API-based
- Founded
- 2017
- Headquarters
- Palo Alto, United States
- Customers
- 100+ customers spending over $100K annually, including 60 of the Fortune 500
Key Features
- ✓Shadow AI and shadow SaaS discovery
Continuously inventories unsanctioned agents, MCP servers, browser extensions and third-party integrations already connected to corporate applications, which is normally the first thing a security team cannot enumerate.
- ✓Agent runtime security
Detects and blocks privilege escalation, excessive data access and policy violations while an agent is executing, rather than only reporting the misconfiguration that allowed it.
- ✓MCP server and LLM inventory
Tracks which Model Context Protocol servers and which underlying models are in use and maps each back to the agents calling them, giving an auditable model supply chain.
- ✓Agent access governance
Rightsizes what each agent identity can reach across connected SaaS apps, including named support for Claude Code and Cowork alongside the major platform agents.
- ✓Identity threat detection and response (ITDR)
Covers account takeover, session hijacking, insider risk, data exposure and API or token compromise across SaaS, which is where non-human credential abuse actually lands.
- ✓Posture management and compliance auditing
Continuously assesses configuration drift and excessive privileges across connected apps and produces the audit evidence compliance teams need for SaaS controls.
- ✓Free discovery tier up to 1,000 users
App discovery including shadow AI and SaaS plus spear-phishing detection at no cost, which lets a security team quantify the problem before opening a budget line.
Capabilities
Use Cases
- •Inventorying agents before an audit
A security team enumerates every AI agent, MCP server and OAuth token reaching Microsoft 365 and Salesforce, then produces per-agent access evidence for the auditor.
- •Containing an over-permissioned Copilot rollout
After Copilot is switched on tenant-wide, Obsidian identifies excessive privileges and blocks the agent from reaching records outside its intended scope at runtime.
- •Detecting shadow AI adoption
The discovery tier surfaces unsanctioned agents and browser extensions employees connected to corporate SaaS without going through security review.
- •Investigating a SaaS account takeover
ITDR correlates session hijacking and token-compromise signals across connected apps to shorten a Microsoft 365 breach investigation from days to hours.
- •Rightsizing third-party integrations
Governance modules identify integrations holding far broader scopes than they use and reduce them, cutting the blast radius of a vendor compromise.
Ideal For
Best For
- ✓Discovering shadow AI — unsanctioned agents, MCP servers and browser extensions already connected to corporate SaaS
- ✓Governing what Microsoft Copilot, Salesforce Agentforce, Amazon Bedrock and n8n agents are permitted to reach in third-party apps
- ✓Runtime enforcement that blocks privilege escalation and excessive data access by an agent mid-session
- ✓SaaS security posture management and compliance audit evidence across Microsoft 365, Salesforce, ServiceNow and Workday
- ✓Identity threat detection and response for account takeover, session hijacking and OAuth token compromise
Not Ideal For
- ✗Teams needing cloud infrastructure posture management — Obsidian's documentation shows no native CSPM for Azure or Google Cloud infrastructure, so it complements rather than replaces a cloud security platform
- ✗Small organisations under 1,000 users, who can run the free discovery tier but will find the enterprise-priced Foundations and Advanced modules hard to justify
- ✗Buyers who want published list pricing or a self-serve path to the paid product: only the free tier has a price, everything else is contact-sales
- ✗Shops whose agents run entirely on self-hosted infrastructure with no third-party SaaS reach, since the platform's value is concentrated in the app-to-agent boundary
Deployment
Market & Ratings
100+ customers spending over $100K annually, including 60 of the Fortune 500
Market Analysis
Pros
- ✓Runtime enforcement, not just posture reporting — it can block privilege escalation and excessive data access while an agent is running
- ✓Unusually broad AI-platform connector list covering Bedrock, Vertex AI, Foundry, Copilot, Claude, OpenAI, Agentforce and n8n in one inventory
- ✓Strong compliance posture for a security vendor: SOC 2, ISO 27001, ISO 27701 and ISO 42001, the last being the AI management-system standard
- ✓Verifiable enterprise traction — 60 of the Fortune 500, 100+ accounts over $100K a year and 14 over $1M, with named references including T-Mobile, Databricks, S&P Global, Snowflake and Seagate
- ✓Free tier up to 1,000 users makes the discovery step genuinely zero-cost
Cons
- ✗No native posture management for Azure or Google Cloud infrastructure, so it does not replace a CSPM or cloud-native application protection platform
- ✗Integration depth varies by connected platform, and reviewers report a real learning curve during initial setup
- ✗A PeerSpot reviewer asks for more automated integrations, interface refinement and deeper cross-log correlation in incident response
- ✗Everything beyond the free tier is contact-sales with no published rate, and the modular structure means the useful runtime controls sit in the top Advanced tier
- ✗Independent review volume is thin and hard to verify — G2 and Gartner Peer Insights both block unattended access, and PeerSpot carries a single review
Pricing
Free
$0
- ✓Up to 1,000 users
- ✓App discovery including shadow AI and shadow SaaS
- ✓Spear-phishing detection
Foundations
Contact for pricing
- ✓Discovery of shadow apps, AI agents, integrations, browser extensions
- ✓Access violation and third-party access tracking
- ✓Governance: privilege minimisation, compliance audits, agent access optimisation, integration rightsizing
Advanced
Contact for pricing
- ✓Detection: account takeover, session hijacking, insider risk, data exposure, API/token compromise
- ✓Proactive defence: runtime guardrails and AI security controls
- ✓Incident response: threat triage and forensics
Only the Free tier carries a published price: $0 for up to 1,000 users, covering app discovery including shadow AI and spear-phishing detection. Foundations and Advanced are contact-sales with no list rate, and Obsidian markets a modular 'no bloated bundles' structure, so detection, runtime defence and incident response are separately purchasable rather than bundled into one SKU. The customer disclosures give a rough sense of enterprise scale — over 100 accounts above $100,000 a year and 14 above $1 million — so expect six-figure annual commitments once past the free tier. Budget for connector-by-connector scoping, since coverage and value both track how many SaaS and AI platforms you integrate.
Security & Compliance
Sources
This page was written from 7 sources, 4 on domains other than obsidiansecurity.com.
- 1.obsidiansecurity.com — unlocking ai potential securelyvendor
- 2.obsidiansecurity.com — obsidiansecurity.comvendor
- 3.obsidiansecurity.com — pricingvendor
- 4.siliconangle.com — obsidian security raises 85m ai agents create cybersecuritys
- 5.peerspot.com — obsidian security reviews
- 6.unite.ai — obsidian security raises 85 million series d at unicorn valu
- 7.fintech.global — obsidian security lands 85m to police rogue ai agents
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
Ceros
Bind every AI agent session to a real person on a verified device — and block what policy forbids
Noma Security
Discover, govern and defend every AI agent and MCP server in the enterprise — from inventory to runtime enforcement
NVIDIA OpenShell
Open-source, kernel-isolated sandbox runtime for autonomous AI agents
OpenAI Daybreak
Vetted-access frontier AI for cyber defenders, with a purpose-built offensive-security model