Partnering with Cymphony: Security Unlocks Adoption

Controlling what AI agents can reach is one of the biggest constraints on enterprise AI adoption. Cymphony is building the governance and security layer that removes it.

Controlling what AI agents can reach is one of the biggest constraints on enterprise AI adoption. Cymphony is building the governance and security layer that removes it.

Every large enterprise now has an AI mandate. Very few know exactly what happens when an agent is granted access to enterprise systems and data. What exactly will it be able to reach? How will we know what it did with it? These questions — not model quality, not cost, not talent — are the reason so many enterprise AI programs stay stuck in pilots. Cymphony was built to answer them.

Agent data access is the constraint

Employees increasingly work together with AI agents to execute day-to-day work. But the typical agent is nothing like an employee. It can be provisioned in minutes rather than hired over weeks. It works continuously. And it can reach across far more systems, data, and capability than an individual person. Every one of those properties is what makes an AI agent worth deploying — and every one of them is what makes a security team say no.

Governance and security are already major barriers to AI adoption, with 40% of enterprises expected to demote or decommission autonomous AI agents over governance concerns by next year. That is not a prediction about AI failing to work. It’s about enterprises pulling back working agents because they cannot see or control what those agents reaching. The fundamental challenge is not utility, but accountability.

For decades, security teams have built tools around two separate concerns: where sensitive data lives, and who has access. The first produced the tools that watch files, inboxes, and databases for leaks. The second produced the identity industry. But both assume the "who"s are human employees.

AI broke that assumption. An identity tool can tell you an agent exists. A data tool can tell you a file is sensitive. Neither can tell you that a given agent, acting on behalf of a given employee, can reach that file right now. Identity security and data security are no longer separable.

Cymphony is the solution

Cymphony continuously maps both employees and agents across an enterprise, graphing who and what can reach which systems and information. It is a difficult engineering problem: the same person routinely holds a dozen different accounts scattered across systems that were never designed to talk to each other, and agents inherit access from the humans and applications that spawned them. Stitching all of that back into one accurate picture requires more than a dashboard that aggregates alerts.

What we love about working with co-founders Shy Dekel, Idan Berkovits, and Edi Gotlieb is their instinct to build not for the alert but for the workflow. Instead of stopping at detection and leaving a security analyst to figure out what to do next, Cymphony pushes further — recommending and even automating remediation, and coordinating with the people who need to take action. 

Enterprise customers including Syngenta, KKR, Cass Information Systems, and Athennian are already seeing results. Sequoia is also a happy customer. We are proud to have led Cymphony’s seed round, and to now co-lead their Series A.

Why we partnered

We met Shy, Idan, and Edi through Sequoia's Israel network, introduced separately by two people in our orbit who each said some version of the same thing: these three had spent their careers on hard, unglamorous security problem many founders avoid, and they were building something different around it. All three came out of Israel's elite Talpiot program. All three have deep experience in this space: Shy led the cyber department for Unit 8200, Idan ran a research group in the Office of the Prime Minister and won an Israel Defense Prize, and Edi built hardware at Apple and at the Israeli Ministry of Defense. Every large enterprise software company has been built on a transition: the underlying unit of work changes, and the old categories are no longer the right shape. Cloud changed where software ran, and security rebuilt itself around it. Mobile changed what an endpoint was, and it rebuilt itself again. Each time, the companies that offered visibility and control over what came next eventually became infrastructure everyone else took for granted.

AI is no exception, albeit the first shift where the new unit of work can act on its own. The company that lets an enterprise say yes to agents — confidently, at scale, with a record of what they did — will be not just a feature inside the AI stack, but a precondition for it. We think Cymphony is building that layer, and we are glad to be part of it.

share