---
title: "Cymphony’s $25M Series A: Sequoia Doubles Down on AI Agent Workforce Security"
description: "NYC–Tel Aviv Cymphony emerged Sep 9, 2026 with a $25M Series A co-led by Sequoia and SMBC Fin Atlas at >$100M post — securing humans and AI agents as one workforce graph."
date: 2026-09-10T00:00:00.000Z
tags: ["2026-vc-news", "startup-funding", "venture-capital", "cybersecurity", "ai-security"]
source: https://venturecapitaltracker.com/2026-cymphony-25m-series-a-sequoia-ai-agent-security
---

# Cymphony’s $25M Series A: Sequoia Doubles Down on AI Agent Workforce Security

> NYC–Tel Aviv Cymphony emerged Sep 9, 2026 with a $25M Series A co-led by Sequoia and SMBC Fin Atlas at >$100M post — securing humans and AI agents as one workforce graph.

**[Cymphony](/startup/cymphony)** announced a **$25 million** Series A on **September 9, 2026**, co-led by [Sequoia Capital](/fund/sequoia) and **SMBC Fin Atlas Beyond Fund**, at **more than $100 million** post-money (TechCrunch). Combined with a previously undisclosed Sequoia seed, total funding is about **$30 million**. The company also framed the day as a **launch with $30M** (Newswire).

**Spine:** Security stacks were designed for human employees. Agents now touch more systems than any one person — Sequoia is buying the graph that treats that new workforce as first-class.

## Key facts

| Field | Detail |
| --- | --- |
| Company | [Cymphony](/startup/cymphony) ([cymphony.io](https://cymphony.io)) |
| Round | **$25M** Series A (~**$30M** total capital) |
| Lead | [Sequoia](/fund/sequoia) + SMBC Fin Atlas Beyond (co-lead) |
| Valuation | **>$100M** post (TechCrunch) |
| HQ | New York and Tel Aviv; ~**30** employees |
| Traction (company → TC) | Double-digit enterprise customers; **seven-figure ARR** in first sales year |
| Named customers | KKR, Syngenta, Cass Information Systems, Athennian |

## Who uses the product — and for what job

**Users:** enterprise security / identity / data-protection teams governing SaaS, files, and AI tools as agents proliferate.

**Job:** see every human and AI agent, what they can reach, and what they did → prioritize risk → investigate and remediate (including automated permission fixes), optionally with Cymphony’s managed service.

Company anecdotes (TechCrunch): ~**85,000** files newly reachable by AI tools at one U.S. public company; an unsanctioned Claude instance scanning thousands of sensitive files via a collaborator’s access. Treat as **case studies**, not audited benchmarks.

## Why now

- Agents bypass classic access assumptions while moving at machine speed.
- OpenAI-linked agent mishaps in 2026 (Hugging Face test compromise; wiki edit swarm) made “agent security as a category” board-visible.
- Gartner’s agentic-AI commentary (cited in Cymphony’s release) flags governance as a top adoption barrier — buyers will fund control planes even when models are cheap.

## Why Sequoia — portfolio fit

[Sequoia](/fund/sequoia) led the seed when Cymphony had **no product** — a classic **Talpiot / Unit 8200** team bet (same talent pool as Wiz). Partner Bogomil Balkansky told TechCrunch the Series A required product, logos, and expansion motion; Sequoia also **dogfoods** the platform.

That pattern matches Sequoia’s cyber franchise: back Israeli technical founders early, re-up when enterprise proof appears, and argue the category is **foundational** (Balkansky: if enterprises are not spending on agent security, “I don’t know what else they’ll be spending money on”).

*SMBC Fin Atlas Beyond Fund has no `/fund/` page here.*

## Competitive map

| Approach | Tradeoff |
| --- | --- |
| Okta / CyberArk identity stacks | Strong for humans; weak agent runtime semantics |
| Wiz / CNAPP / DSPM / DLP point tools | Deep in one slice; fragmented for agent+data+identity |
| Microsoft / platform AI security | Bundle distribution; may lag specialist graphs |
| Cymphony workforce graph | Unified agent+human view; still proving category vs feature |

Balkansky’s near-term view: complementary to Okta today; potential to displace some DLP-style point solutions later.

## What is not proven

- Exact ARR and customer count beyond “seven figures” / “double-digit.”
- Whether agent security stays a standalone budget vs. a checkbox on Wiz/Microsoft.
- How fast Europe/EMEA demand converts vs. North America concentration.

## Practical takeaway

- **Founders (AI security):** Sell **workforce graph** (humans + agents + data), not another model firewall.
- **Investors:** Diligence expansion revenue inside KKR-class accounts and displacement vs. add-on spend.
- **CISOs:** Relevant if shadow AI and nonhuman identities already outrun IAM playbooks.

### Sources

1. [TechCrunch — Sequoia / Cymphony](https://techcrunch.com/2026/09/09/sequoia-doubles-down-on-cymphony-as-ai-agents-create-new-enterprise-security-risks/)
2. [Newswire — Cymphony launch](https://www.newswire.com/news/cymphony-launches-with-30-million-to-secure-ai-agents-access-to-22857048)
3. [Cymphony](https://cymphony.io)

**By:** [Venture Capital Tracker](https://venturecapitaltracker.com/editorial-policy)

**Editorial note:** AI tools assisted with research, structure, or drafting. Venture Capital Tracker retains human editorial responsibility for factual accuracy, relevance, and source quality before publication.
