The Anti Job Board
Premium Drop
Live

$30M total ($25M Series A) · Cymphony + 2 more

3 startups with founder intel, hiring signals, and outreach playbooks.

Hiring SignalsFounder ContactsOutreach Playbooks
Big Round
01 of 3
Series AHot

Cymphony

cymphony.io · New York, USA · Workforce security for the AI era — one graph covering employees and agents

$30M total ($25M Series A)Backend / Graph Engineer (Tel Aviv — the identity-permission-activity graph is the core asset)Detection & Response Engineer (turning graph findings into ranked, actionable risk)

What they're building

Cymphony builds a workforce security graph. The premise is that enterprise security was designed around a human employee — a person with a badge, a manager, a joiner-mover-leaver lifecycle — and that model quietly broke the moment employees started connecting AI agents to internal systems. An agent is an identity that reads at machine speed, inherits whatever permissions its human creator had, and leaves no trail a conventional IAM tool was built to read. Cymphony's answer is to stop treating AI as one more application to secure and instead model the whole workforce, human and non-human, in a single graph. The graph unifies four signal types: identities, the systems they touch, the permissions they hold, and the data interactions they actually perform. On top of it sit four functional surfaces — AI tool discovery, data exposure detection, identity hygiene, and insider threat monitoring — plus a conversational investigation assistant called Maestro, which lets an analyst ask questions without learning a query language. The design bet is that the query syntax is the thing that stops security teams from investigating, not the data. The findings are what sell it. Cymphony surfaced roughly 85,000 files reachable by AI tools inside one large US public company and drove the remediation. At another customer it found an unsanctioned Claude instance scanning thousands of sensitive documents. Shy Dekel's favourite example is smaller and sharper: a customer who connected ChatGPT to SharePoint and, without noticing, exposed an incredibly sensitive litigation process to interns. None of these are model failures. They are permission-inheritance failures that nobody had a lens to see. Dekel's framing of the category is the clearest statement of the thesis: 'The security industry keeps treating AI as another application to secure, but that's the wrong model.' You cannot secure what you cannot see, so the product starts as visibility and earns the right to enforce.

Why this matters

The traction is unusually specific for a company that just left stealth. Double-digit enterprise customers and seven-figure ARR inside the first year of selling, with KKR, Syngenta, Cass Information Systems and Athennian named publicly. Sequoia runs Cymphony internally to manage its own exposure, which is a stronger signal than the cheque. The market timing argument is that the incumbents are arriving but have not landed. Microsoft, Okta, CyberArk, Wiz and Varonis are all extending toward agent identity, and Balkansky's own read is that Cymphony is currently complementary to those tools rather than displacing them. That is an honest description of a window, not a moat — which is exactly why the next twelve months of engineering matter more than the next twelve months of selling. The wider context is a funding wave: Cymphony was the third significant agent-security raise in three weeks, part of roughly $435M into the space over five months. The counterweight is that 88% of enterprises with agent initiatives never ship them to production. Read those two numbers together and the opportunity is not 'agents are everywhere' — it is that the shadow-agent problem is already real inside companies that have not officially deployed a single agent.

Unlock full intel

Get funding details, roles, outreach playbooks

View Plans
02 of 3
Series A

Paid drop

Subscribe to view full content

View Plans
03 of 3
Series A

Paid drop

Subscribe to view full content

View Plans