· investment-strategies · 3 min read
Obsidian Security’s $85M Series D at $1.1B: SaaS Security Becomes Agent Identity Control
Crescent Cove led Obsidian’s $85M Series D at $1.1B with Menlo and Greylock returning — securing non-human identities and AI agents inside third-party enterprise apps.
Obsidian Security raised an $85 million Series D at a $1.1 billion valuation on August 4, 2026, led by Crescent Cove Advisors, with Menlo Ventures and Greylock Partners returning. This note is an August 11–12 gap-fill — the round sat in the same agent-security week as Zenity/Oligo but lacked a VCT explainer until now.
Key facts
| Field | Detail |
|---|---|
| Company | Obsidian Security (Palo Alto) |
| Round | $85M Series D · $1.1B valuation |
| Date | August 4, 2026 (coverage refreshed Aug 12) |
| Lead | Crescent Cove Advisors |
| Returning | Menlo Ventures, Greylock (+ existing bench) |
| Traction (company) | 100+ customers >$100K ACV; 14+ >$1M; 60 of Fortune 500 |
| Total funding | >$200M (press) |
| Origin | Founded ~2017; earlier SSPM / SaaS posture thesis |
Who uses the product — and for what job
Users: CISOs and SaaS security owners at large enterprises (financials, social, telecom cited).
Job: see what is connected in third-party apps, enforce what agents/non-humans may do, and get runtime context before a rogue agent exfiltrates or mis-changes production systems.
Company framing: ratio of non-human to human identities inside third-party apps can reach 144:1 — the control plane must follow identities that are not employees.
Why now
- Enterprises deploy Copilot Studio / Agentforce / Claude-class agents into the same SaaS that holds CRM and HR data.
- Prompt filters do not govern tool-using agents with OAuth.
- Boards already funded model security; agent identity + SaaS blast radius is the next purchase.
- Obsidian’s installed SSPM footprint is a distribution wedge into the agent layer.
Why Menlo / Greylock — portfolio fit
Menlo and Greylock re-upping at Series D is a category defense: keep ownership when the product thesis pivots from human SaaS misuse to agent governance, rather than lose the board seat to a pure AI-security newcomer.
Crescent Cove as new lead prices the unicorn mark and growth equity duration (company says cash should last to cash-flow positive).
Likely founder rationale: keep the investors who already diligenced SaaS connectors and enterprise sales, add a lead comfortable with AI-security multiples, avoid a full syndicate reset mid-pivot.
| Dimension | Fit |
|---|---|
| Stage | Series D unicorn scale |
| Thesis | Non-human + AI agent identity in SaaS |
| Proof | High-ACV customer concentration |
| Risk | Category crowded (Zenity, Neo, Oligo, etc.) |
Competitive map
| Player | Lane |
|---|---|
| Zenity | AI-agent security/governance platform (Series C same week) |
| Neo / Straiker / Oligo | Adjacent agent/runtime security |
| Classic SSPM / CASB | Human + config posture; weaker agent runtime |
| IdP / PAM vendors | Human identity strength; catching up on agents |
When not to confuse the categories
- Wrong if Obsidian is treated as only “old SSPM” — the Series D story is agent identity.
- Wrong if one vendor is assumed to own the whole agent-security stack.
- Wrong if Fortune-500 logos replace diligence on false-positive rates in production agents.
Practical takeaway
- Founders (security): Pivot narratives only when you already own the integration surface buyers live in.
- Investors: Underwrite competitive set (Zenity et al.) and ACV expansion into agent SKUs separately from legacy SSPM.
- Operators: Inventory non-human identities in Salesforce/M365 before buying another model firewall.
Sources
- Obsidian (Aug 4, 2026): https://www.obsidiansecurity.com/news/unlocking-ai-potential-securely
- Reuters: https://www.reuters.com/technology/obsidian-security-raises-funding-11-billion-valuation-ai-security-demand-2026-08-04/
- Related: /2026-zenity-125m-series-c-norwest-ai-agent-security · /2026-august-11-12-investment-news-personal-ai-defense-health