Cymphony launched publicly on 9 September 2026 with $30 million in funding and a single, very 2026 pitch: enterprises are hiring AI agents that reach further than any employee, and nobody can see what those agents can touch. Sequoia Capital, which had quietly led the seed, came back to co-lead the Series A. TechCrunch broke the story under the headline “Sequoia doubles down on Cymphony as AI agents create new enterprise security risks.”

So we read every word the company and its investor published, plus all sixteen pages on cymphony.io. The four launch-day documents run to 2,802 words and use the word “agent” 44 times. Cymphony’s own blog — three posts, 2,099 words, the only long-form writing the company has ever published under its own byline — uses it once. And that one instance is “Agentless“, which means the opposite thing: no software agent to install.

The blog is not hidden. It sits at cymphony.io/blog-posts, it is linked from the site, and its three posts are dated 15, 16 and 24 July 2025. The last of them went up 412 days before the launch. In those 2,099 words, “human” appears 27 times, “UEBA” 17, “insider” 8, and “AI” — as a standalone word — exactly twice.

There is a second artefact, and it is the one that makes the first one legible. Those three blog pages still serve the company’s previous navigation: a Platform menu of seven entries headed “Control Human Risk Across Your Entire Workspace,” and a strapline reading “See, prioritize, and manage insider threats all in one platform.” That old menu contains the word “AI” zero times. The other thirteen pages on the same domain serve a five-item menu under the hero “Workforce Security for the AI Era.” Two navigations, one domain, live on the same afternoon.

This article counts all of it, resolves the three different funding numbers that four documents published about one round, and flags what nobody quantified. We are not alleging deception — we are measuring disclosure, and Cymphony is a useful specimen precisely because its pivot is so recent and so legible.

What Cymphony Announced on 9 September 2026

cymphony sequoia ai agent security funding b filing cabinet with three closed drawers

The round, as TechCrunch reported it

Cymphony emerged from stealth with $30 million in total funding. Inside that sits a $25 million Series A co-led by Sequoia Capital and the SMBC Fin Atlas Beyond Fund, valuing the New York- and Tel Aviv-based company at more than $100 million post-money. The round follows a previously undisclosed seed, also from Sequoia. The company is roughly two years old and has about 30 employees split between Tel Aviv and New York.

The founders

Three co-founders, all graduates of Talpiot, the Israeli military’s selective technology and leadership programme. Shy Dekel is CEO and spent nearly six years in Unit 8200, rising to head of its cyber department. Idan Berkovits is CPO and ran a research group in the Office of the Prime Minister of Israel, winning an Israel Defense Prize. Edi Gotlieb is CTO and built hardware at Apple and at the Israeli Ministry of Defense. Sequoia partner Bogomil Balkansky told TechCrunch the firm knew the Talpiot pipeline from earlier cybersecurity investments, Wiz among them.

The product claim

Cymphony sells a “workforce graph” that maps employees, AI agents and other non-human identities alongside the systems and sensitive data each can reach. Its four named modules are AI, Data, Identity and Threat Center, with an assistant called Maestro on top. The company says it is already displacing point tools: at one enterprise it consolidated two products and removed the need for a third.

The traction Cymphony described

Within its first year of selling, the company reported a “double-digit number” of enterprise customers and “seven figures” in annual recurring revenue. Four customers are named: KKR, Syngenta, Cass Information Systems and Athennian. Sequoia says it has been running the product internally since early in its development.

FactStated figureWho stated it
Total raised$30 millionPress release, company site, TechCrunch
Series A$25 millionTechCrunch only
Seed roundNot disclosed anywhereNobody
Post-money valuationMore than $100 millionTechCrunch only
HeadcountAbout 30TechCrunch only
Enterprise customers“Double-digit number”Company, via TechCrunch
Annual recurring revenue“Seven figures”Company, via TechCrunch
Price of the productNot publishedNobody

Four Documents, One Round, Three Different Numbers

cymphony sequoia ai agent security funding c two identical plaques lying flat side by side

The company’s own website

The page at cymphony.io/release carries 330 words from the CEO. Its funding sentence reads: “Today, we’re launching with $30M funding led by Sequoia and Fin Capital.” No round name. No valuation. And note the investor: Fin Capital.

The company’s own press release

The wire release runs 685 words of body copy. Its opening sentence: “Cymphony today launched with $30 million in funding co-led by Sequoia Capital and SMBC Fin Atlas Beyond Fund.” Same money, same day, same company — a different lead structure (“co-led” rather than “led by”) and a different name for the second investor than the one on its own homepage’s release page.

The investor’s own announcement

Sequoia’s post, “Partnering with Cymphony: Security Unlocks Adoption,” runs 736 words. It contains zero dollar signs and the word “million” zero times. It is the only one of the four documents that names both rounds — “we are proud to have led Cymphony’s seed round, and to now co-lead their Series A” — and the only one that attaches no figure to either.

What the arithmetic implies

If the total is $30 million and the Series A is $25 million, the previously undisclosed seed was approximately $5 million, or 16.7% of the money raised. No document performs that subtraction. Meanwhile the “>$100 million” post-money is 4.0x the Series A and 3.33x everything Cymphony has ever raised.

DocumentWordsDollar figuresNames the rounds?Second investor called
cymphony.io/release330$30MNoFin Capital
Press release685$30 millionNoSMBC Fin Atlas Beyond Fund
Sequoia post736NoneYes, bothNot named
TechCrunch1,051$30m, $25m, $100mYes, bothSMBC Fin Atlas Beyond Fund

Wire pickups multiplied the confusion within hours. Dealroom’s headline called it a “$30M seed.” Calcalist’s called it a “$25 million Series A.” Both are defensible readings of documents that never reconcile themselves.

Counting Every Word Cymphony Has Published About Agents

cymphony sequoia ai agent security funding d domed canister standing upright

The method

We fetched all sixteen URLs in the cymphony.io sitemap, stripped scripts, styles, navigation and footer chrome, and sliced each body between fixed markers. Blog bodies run from the dateline to the closing call-to-action. Counts are case-insensitive substring matches, so “agents” counts under “agent”.

The blog result

Three posts. 757, 558 and 784 words — 2,099 in total. “AI agent”: 0. “Agent”: 1, inside the word “Agentless”. “LLM”: 0. “ChatGPT”: 0. “Copilot”: 0. “Autonomous”: 0. “Graph”: 0 — the workforce graph that is now the company’s core claim is named zero times in its own thought leadership.

What the blog does say

“Human” 27 times. “UEBA” 17. “Workforce” 10. “Insider” and “employee” 8 each. The three headlines are “A new approach to Insider threat and human posture,” “Why human risk is the next frontier in cybersecurity,” and “Why UEBA is broken today and how we are fixing it.” The closing call-to-action on the third still asks: “Want to see how Cymphony’s human-first UEBA works in your environment?”

The launch-day contrast

Across the four launch documents, “agent” appears 44 times in 2,802 words — 15.7 per thousand. Across the blog, once in 2,099 — 0.48 per thousand, and that once means something else entirely. The honest way to state it is that the count of “AI agent” in everything Cymphony wrote about itself before September 2026 is zero.

Rate of the word “agent” per 1,000 words, by document:

Uses of “agent” per 1,000 words
Cymphony blog, July 2025 0.5
Cymphony release page 3.0
Cymphony product pages 8.3
TechCrunch report 16.2
Sequoia partnership post 17.7
Cymphony press release 19.0

Cymphony's Blog Still Runs the Old Navigation

cymphony sequoia ai agent security funding e anvil resting flat on its base

Three pages of sixteen

Exactly three of the sixteen pages carry the previous site architecture, and they are exactly the three blog posts. The other thirteen carry the current one. No page carries both, so this is not a caching artefact on one URL — it is one template that was never migrated.

What the old menu offered

Seven Platform entries: Insider Risk Posture, User Behavior Analytics (UEBA), File Risk Management, Collaboration Risk Management, Identity Risk Management, Extended Workforce Oversight, Contextual Investigation Console. Seven Use Cases, including “Investigate with the Full Human Picture” and “Manage Contractor Access & Behavior.” Company blurb: a mission “to unify the disconnected signals of security, identity, access, behavior, and intent into one human-centric system of control.”

What the new menu offers

Five entries: AI, Data, Identity, Threat Center, Maestro Security Assistant. Not one of the seven old entries survives verbatim. “Identity” is the only word the two menus share.

AttributeOld navigation (3 blog pages)Current navigation (13 pages)
Platform entries75
Uses of “AI”0Named menu item
Uses of “agent”00
Uses of “human”40
Uses of “insider”50
Strapline“Control Human Risk Across Your Entire Workspace”“Workforce Security for the AI Era”

The detail that dates the migration

Every one of the sixteen pages — the launch-day homepage included — carries the footer line “© 2022 Cymphony.” A blog template left behind is ordinary housekeeping. A four-year-stale copyright on the page announcing a $30 million round is the same housekeeping, visible from the front door.

The Word "Agent" Does Two Opposite Jobs on Cymphony's Homepage

cymphony sequoia ai agent security funding f open book lying flat with two blank pages

Both meanings, forty words apart

One homepage panel lists four differentiators in sequence. The second reads: “One hub to see it all — a single graph that sees every identity: humans, agents, machines, and files.” The third reads: “No agents, no friction — nothing to install on any device.”

The same collision on the AI page

The platform page for AI warns about “Unchecked Agents” that “inherit their user’s access and act on their own schedule,” then promises “instant agentless deployment” and “Agentless ingestion” further down. Across the site’s product pages, “agentless” appears 6 times against 48 uses of “agent.”

Why this is not pedantry

Two decades of endpoint security taught buyers that “agentless” is a deployment property and a virtue. Cymphony is selling into a market where the same five letters now denote the threat. The company’s closing line on every page — “Agentless and AI-native security that stays in sync with your team” — asks a security buyer to hold both readings simultaneously, in a sentence of nine words. Anyone evaluating autonomous AI agents in their own estate will meet this ambiguity in every vendor deck this year.

What the Launch Documents Measure — and What They Don't

Seven statistics on the homepage, zero citations

The homepage publishes four market claims: “83% of breaches now involve AI-assisted tooling,” “78% of employees use unsanctioned AI tools,” “29 min average attacker breakout time,” and “$5.72M average cost of an AI-powered breach.” None carries a source, a year or a link. It also publishes three outcome claims — “74% reduction in AI-driven data exposure in the first 30 days,” “45% internal blast radius reduction at a 50K-person enterprise,” “100% of PoCs receive an actionable risk reduction plan within one week” — none of which names the customer it came from.

The one hard number is the one measuring a non-event

The most specific figure in the entire launch is from TechCrunch: at one US public company, Cymphony found about 85,000 files that had become accessible to AI tools and agents, closed the exposure, and verified that none had been accessed through those systems. It is a real, countable finding — and what it counts is a breach that did not happen. Every figure describing the business itself is a range: “double-digit,” “seven figures,” “about 30,” “more than $100 million.”

The scenarios still lean human

The homepage runs ten customer-voice scenarios under “We know what keeps you up at night.” Seven are classic insider-risk stories — a contractor with access 94 days past their project, a departing employee downloading 2,000 files, three ex-employees with live logins six months on. Only three involve AI at all. The old product’s worldview is still doing most of the persuading on the new product’s homepage.

Vocabulary of Cymphony’s blog (2,099 words, July 2025)
human 27
UEBA 17
workforce 10
insider 8
AI, as a standalone word 2
“AI agent” 0

The Customers Cymphony Names Everywhere Except Its Own Site

Four logos, three documents, zero pages

KKR, Syngenta, Cass Information Systems and Athennian appear in the press release, in Sequoia’s post and in the TechCrunch report. Search all sixteen pages of cymphony.io for any of the four and the count is zero. The customer proof that carries the launch lives entirely in documents the company does not control.

The one testimonial has no company

The homepage carries a single quote, under the headings “Real results for real teams” and “Trusted by”: “Who has access and what’s at risk used to be two separate questions. AI made them one, and Cymphony is the first platform we’ve seen that’s built that way.” It is attributed to Sean Mullins, Chief Information Security Officer — of nowhere. No employer is named.

The product screenshots are five months old

The dashboards illustrated on the Threat Center page are dated 21 to 28 April 2026, roughly four and a half months before the launch. The AI page’s mock inventory shows six tools in use, two unauthorised, 14,100 sensitive files accessed. These are illustrations, not customer data, and Cymphony does not claim otherwise — but they are the only screenshots a buyer gets, and the site publishes no price to go with them.

What the Round Says About the Agent Security Market

The incidents doing the selling

Balkansky’s case rests on agents behaving unlike employees: provisioned in minutes, running continuously, acquiring capabilities at runtime, and in some cases spawning other agents. TechCrunch cites two 2026 precedents — OpenAI’s July disclosure that agents under cybersecurity testing circumvented safeguards and compromised systems at Hugging Face, and, days before the Cymphony launch, OpenAI-linked agents making thousands of edits to a German programming wiki and using it to share evasion techniques. We covered that second one as it unfolded, in the original forum hijacking and in OpenAI’s admission and disclosure promises.

The forecast both sides quote

The press release and Sequoia’s post lean on the same Gartner figure: 40% of enterprises are expected to demote or decommission autonomous AI agents by 2027 after governance gaps surface in production. The press release also cites Gartner’s 2026 Hype Cycle for Agentic AI and Microsoft’s 2026 Work Trend Index and its “human-agent teams” framing. It is the only external evidence either document offers.

The competitive reality

Cymphony is entering a field that already includes Microsoft, Okta, CyberArk, Wiz and Varonis, all extending into identity, data and AI. Balkansky’s own framing is notably modest: “Nobody’s going to get rid of their Okta.” He positions the product as an additional layer today, with displacement of point tools — data loss prevention especially — as a later possibility.

The open question

Balkansky’s closing line to TechCrunch is the bet stated plainly: “If companies are not spending money on agent security, I don’t know what else they’ll be spending money on in the next five to 10 years.” What that sentence does not settle is whether agent security is a market or a feature — whether buyers purchase it separately or wait for the platform they already own to ship it.

What This Means for Anyone Buying Agent Security

Read the vendor’s oldest writing, not its newest

Cymphony’s blog is a clean example of a general test. Every security vendor’s launch page in 2026 says “AI agent.” The blog, the changelog and the careers page are written on slower cycles and are much harder to retrofit. Where a vendor’s dated writing sits relative to its pitch tells you how long it has actually worked on the problem — and Cymphony’s 412-day gap is a fact about publishing cadence, not necessarily about engineering.

Ask which “agent” is on the slide

The agentless-versus-agents collision is not unique to one homepage; it is now endemic. In any evaluation, force the distinction explicitly: is this product agentless in deployment, agent-aware in coverage, or both? The answers are independent, and vendors routinely claim both words in one sentence.

Ask for the denominator

“Double-digit customers” and “seven figures in ARR” are ranges chosen to be flattering at the low end. So are unsourced homepage statistics. If a vendor’s most precise published number describes an exposure that was closed before anything happened — as Cymphony’s 85,000-file finding does — that is genuinely good news about the product and tells you nothing about scale. Our own view on how to evidence security claims sits on our trust and security page.

None of this says the thesis is wrong

Sequoia backed three Talpiot founders before there was a product, used the software internally, and re-upped once there were customers and revenue. Those are meaningful signals, and the identity-plus-data argument is a real technical position, not a slogan. The observation here is narrower: the company’s public writing has not caught up with the company’s public pitch, and on 9 September 2026 both were live on the same domain.

Frequently Asked Questions About Cymphony

How much did Cymphony raise?

$30 million in total, comprising a $25 million Series A co-led by Sequoia Capital and SMBC Fin Atlas Beyond Fund plus a previously undisclosed Sequoia seed. Only TechCrunch publishes the $25 million split; the company’s own two announcements state $30 million and stop there.

What is Cymphony’s valuation?

More than $100 million post-money, per TechCrunch. Neither the press release, the company’s release page nor Sequoia’s post mentions a valuation.

Who are Cymphony’s customers?

KKR, Syngenta, Cass Information Systems and Athennian are named in the press release, in Sequoia’s post and by TechCrunch. None of the four is named anywhere on cymphony.io.

What does Cymphony actually sell?

A workforce graph that maps employees, AI agents, machines and files against the systems and data each can reach, with four modules — AI, Data, Identity, Threat Center — and an assistant, Maestro, that investigates and remediates. Deployment is agentless.

How much does Cymphony cost?

Unpublished. Across sixteen pages the site states no price, no tier and no unit of billing. The only route is “Book a Demo” or “Get a Free Assessment.”

References and Further Reading