Sequoia Capital quietly deployed Cymphony internally before the product even existed.
Now it just led a $25M Series A, pushing Cymphony past a $100M valuation.
The reason is simple. Cymphony scanned one U.S. public company and found 85,000 files accessible to AI tools and agents. No one at that company knew.
In another case, an external collaborator installed an unsanctioned instance of Anthropic's Claude. It used the collaborator's existing access to scan thousands of sensitive files.
This is not a hypothetical risk. This is what happens when you give agents the same access as employees but none of the governance.
65% of organizations experienced an AI agent security incident in the past year. 82% discovered agents operating without their security team's knowledge. Only 21% had a process for shutting agents down when their job was done.
Your agents are not employees. They don't quit. They don't get fired. They keep running until someone remembers to kill them.
Cymphony builds a "workforce graph" — a single map of every human and nonhuman identity, what they can access, and what they've touched. KKR and Syngenta are already using it.
If you deployed agents in the last 12 months and haven't audited what they can reach, you are already exposed.
Audit your agent inventory today. Map every nonhuman identity to its permissions. If you can't do that in under an hour, your security posture has a hole you haven't found yet.
SOURCE: https://techcrunch.com/2026/09/09/sequoia-doubles-down-on-cymphony-as-ai-agents-create-new-enterprise-security-risks/
VERIFIED: TechCrunch (Sept 9, 2026), SiliconANGLE (Sept 9, 2026), Calcalistech (Sept 9, 2026)
SIGNAL: Sequoia is treating AI agent security as infrastructure, not a feature. The $435M pouring into this sector in 5 months tells you the market agrees.
Sequoia just found 85,000 files exposed to AI agents at one company. Then it funded the fix.
AI-Assisted Content — Produced with AI assistance and human editorial review.
Learn more
0 Comments