Cymphony Raises $30M—Its First Proof Is 85,000 AI-Visible Files

Cymphony launched on September 9, 2026, with $30 million to build enterprise security software that connects identities, data permissions and AI activity. In its official September 9 release, Cymphony states that Sequoia and Fin Capital led the funding and that its platform unifies data, identity and behavior in a single context graph.
The first detailed proof point is a vendor claim, not an independent benchmark. In a TechCrunch profile of the funding, the New York- and Tel Aviv-based startup attributed the discovery of about 85,000 AI-accessible files at one US public company, the subsequent closure of that exposure and the finding that none had been accessed through the relevant AI systems to its own work; the profile also identifies a $25 million Series A within the $30 million total.
What the financing covers

The financing combines the new Series A with an earlier seed investment that had not previously been disclosed. Sequoia participated at both stages, while SMBC Fin Atlas Beyond Fund co-led the latest round. Public materials do not specify when every portion of the cumulative funding closed.
The investment backs a product thesis broader than identifying unauthorized AI applications. Cymphony is attempting to place employees, AI agents, machine accounts, permissions, sensitive information and subsequent activity in one model, so security teams can trace a route from an identity to the data it can reach.
That combination puts the startup at the intersection of identity security, data security and AI governance. It also creates a demanding proof standard: customers must be able to determine whether the platform merely finds risky access, changes the underlying permissions or supplies specialists who complete the remediation.
How employee access can become agent access

Consider a conditional permission path. An employee has authorized access to a collaboration service and connects an AI assistant using that identity. If an obsolete group membership or mistaken entitlement exposes a sensitive folder to the employee, the assistant may inherit a route to the same material even though nobody separately approved that folder for AI use.
Cymphony’s launch account uses an unnamed early customer that connected ChatGPT to SharePoint. A permissions mistake within the customer’s legal organization left interns able to query material from a sensitive litigation process. The anecdote is supplied by the vendor and does not establish that information was removed, disclosed externally or used maliciously.
The agent changes the practical consequences of an existing entitlement. A person generally opens files selectively, while software can search, summarize and combine material across connected systems during one task. The underlying access may be technically authorized, yet its speed, breadth and purpose can differ from the employee activity for which the permission was originally granted.
This is why the risk cannot always be reduced to a separate “AI permission.” The relevant chain may begin with a human account, pass through a connected assistant and end at data exposed by an old or overly broad entitlement. Cymphony’s central proposition is that identity and data controls need to be evaluated along that entire path.
What the 85,000-file case does—and does not—prove

The public-company case supports a narrow conclusion: the platform identified a large set of files that the relevant AI tools could potentially reach, after which the access route was closed. It does not demonstrate that the files were stolen, exported or opened. The vendor’s own investigation concluded that the relevant AI systems had not accessed them.
The exposure count and remediation outcome remain evidence supplied by Cymphony. The customer is unnamed, and no public material provides the file categories, sensitivity distribution, testing method for prior access or an independent audit of the fix. “AI-visible” therefore means potentially reachable through the identified permission path, not compromised.
The distinction matters because discovery, remediation and verification answer different questions. A scanner can map an unsafe route; a remediation function can alter an entitlement or configuration; verification must then establish that the route is closed and remains closed as identities and permissions change. One case cannot yet show how consistently Cymphony performs all three jobs across different enterprise environments.
One platform, three distinct services
Cymphony’s discovery layer maps AI use, human and nonhuman identities, permissions, sensitive data and activity. Its investigation and remediation functions prioritize findings and can automate certain access corrections. Customers may also choose a managed service that brings the company’s security specialists into complex cases, so an outcome involving remediation should not automatically be credited to software alone.
A SiliconANGLE account of the launch lists four product areas—AI usage, exposed data, identity hygiene and a threat center—and names KKR, Syngenta, Cass Information Systems and Athennian as early customers, with Sequoia also using the product internally.
Those names establish early enterprise adoption but reveal little about deployment depth. Public information does not separate limited evaluations from broad production use, disclose contract values or provide comparable measurements of risks found and durably corrected at each customer.
Cymphony also enters a market where identity vendors, data-security companies and AI-governance startups increasingly overlap. Other specialists are developing identity controls for enterprise agents, while established platforms can extend products already deployed by large customers. The unresolved question is whether buyers will favor Cymphony’s combined graph and service model over separate controls or incumbent suites.
As of the launch, the financing and named customers are public, while the headline exposure case remains vendor evidence from an unidentified enterprise. The next meaningful proof would be attributable customer data that separates detection, automated correction, specialist intervention and the durability of each fix as permissions evolve.
Also read:
Subscribe to our newsletter
Get the latest Web3, AI, and crypto news delivered straight to your inbox.