· investment-strategies  · 3 min read

Obsidian Security’s $85M Series D at $1.1B: SaaS Security Becomes Agent Identity Control

Crescent Cove led Obsidian’s $85M Series D at $1.1B with Menlo and Greylock returning — securing non-human identities and AI agents inside third-party enterprise apps.

Obsidian Security raised an $85 million Series D at a $1.1 billion valuation on August 4, 2026, led by Crescent Cove Advisors, with Menlo Ventures and Greylock Partners returning. This note is an August 11–12 gap-fill — the round sat in the same agent-security week as Zenity/Oligo but lacked a VCT explainer until now.

Key facts

FieldDetail
CompanyObsidian Security (Palo Alto)
Round$85M Series D · $1.1B valuation
DateAugust 4, 2026 (coverage refreshed Aug 12)
LeadCrescent Cove Advisors
ReturningMenlo Ventures, Greylock (+ existing bench)
Traction (company)100+ customers >$100K ACV; 14+ >$1M; 60 of Fortune 500
Total funding>$200M (press)
OriginFounded ~2017; earlier SSPM / SaaS posture thesis

Who uses the product — and for what job

Users: CISOs and SaaS security owners at large enterprises (financials, social, telecom cited).

Job: see what is connected in third-party apps, enforce what agents/non-humans may do, and get runtime context before a rogue agent exfiltrates or mis-changes production systems.

Company framing: ratio of non-human to human identities inside third-party apps can reach 144:1 — the control plane must follow identities that are not employees.

Why now

  • Enterprises deploy Copilot Studio / Agentforce / Claude-class agents into the same SaaS that holds CRM and HR data.
  • Prompt filters do not govern tool-using agents with OAuth.
  • Boards already funded model security; agent identity + SaaS blast radius is the next purchase.
  • Obsidian’s installed SSPM footprint is a distribution wedge into the agent layer.

Why Menlo / Greylock — portfolio fit

Menlo and Greylock re-upping at Series D is a category defense: keep ownership when the product thesis pivots from human SaaS misuse to agent governance, rather than lose the board seat to a pure AI-security newcomer.

Crescent Cove as new lead prices the unicorn mark and growth equity duration (company says cash should last to cash-flow positive).

Likely founder rationale: keep the investors who already diligenced SaaS connectors and enterprise sales, add a lead comfortable with AI-security multiples, avoid a full syndicate reset mid-pivot.

DimensionFit
StageSeries D unicorn scale
ThesisNon-human + AI agent identity in SaaS
ProofHigh-ACV customer concentration
RiskCategory crowded (Zenity, Neo, Oligo, etc.)

Competitive map

PlayerLane
ZenityAI-agent security/governance platform (Series C same week)
Neo / Straiker / OligoAdjacent agent/runtime security
Classic SSPM / CASBHuman + config posture; weaker agent runtime
IdP / PAM vendorsHuman identity strength; catching up on agents

When not to confuse the categories

  • Wrong if Obsidian is treated as only “old SSPM” — the Series D story is agent identity.
  • Wrong if one vendor is assumed to own the whole agent-security stack.
  • Wrong if Fortune-500 logos replace diligence on false-positive rates in production agents.

Practical takeaway

  • Founders (security): Pivot narratives only when you already own the integration surface buyers live in.
  • Investors: Underwrite competitive set (Zenity et al.) and ACV expansion into agent SKUs separately from legacy SSPM.
  • Operators: Inventory non-human identities in Salesforce/M365 before buying another model firewall.

Sources

  1. Obsidian (Aug 4, 2026): https://www.obsidiansecurity.com/news/unlocking-ai-potential-securely
  2. Reuters: https://www.reuters.com/technology/obsidian-security-raises-funding-11-billion-valuation-ai-security-demand-2026-08-04/
  3. Related: /2026-zenity-125m-series-c-norwest-ai-agent-security · /2026-august-11-12-investment-news-personal-ai-defense-health

Frequently Asked Questions

Common questions about this topic

Back to Blog

Related Posts

View All Posts »