Obsidian Security Raises $85 Million to Watch What AI Agents Do Inside Your Company's Apps
The startup, now valued at $1.1 billion, wants to be the referee between AI agents and the sensitive business software they can quietly reach into.

Key points
- Obsidian Security raised $85 million in a Series D funding round, announced Tuesday, pushing its total funding past $200 million.
- The company is valued at $1.1 billion after the round, led by Crescent Cove Advisors with participation from Greylock Partners and Menlo Ventures.
- Only 13% of security teams can currently inspect and enforce policy on AI agent traffic in real time, according to Obsidian CEO Hasan Imam.
- The fresh capital will fund expanded controls for Anthropic's Claude Code and Cowork AI agents inside enterprise software.
AI agents are software programs that can act on your behalf: booking meetings, querying databases, writing code, pulling customer records. They are useful. They are also, increasingly, being handed the keys to a company's most sensitive systems without anyone watching what they do next.
Obsidian Security thinks that is a problem worth a billion dollars.
What does Obsidian actually do?
The company sits between an AI agent and the business software it is allowed to touch, watching every action in real time and stopping anything that looks wrong.
Think of it as a security guard stationed at the door between, say, Microsoft Copilot Studio or Salesforce Agentforce and a company's customer database or file storage. If the agent tries to read files it has no business reading, or quietly expands its own permissions (a technique security teams call privilege escalation, where a program grants itself more access than it was originally given), Obsidian blocks the move before it lands.
The platform also keeps a running list of MCP servers. MCP, short for Model Context Protocol, is a technical standard that lets AI agents connect to external tools and data sources. Obsidian tracks which agents are plugged into which servers, so a security team can spot any connection that nobody officially approved.
Why does the funding matter to ordinary workers?
Most employees do not choose which AI tools their company buys. The tools arrive, get connected to payroll systems, CRMs (customer relationship management software), code repositories, and collaboration apps, and start acting. The risk is not that the AI is malicious. The risk is that it has been given too much access, or that a poorly configured agent gets manipulated into doing something harmful.
Obsidian's CEO Hasan Imam put the gap plainly: "Today, only 13% of security teams can inspect and enforce policy on that traffic in real time."
The new funding addresses this directly, with Obsidian adding specific controls for Anthropic's Claude Code and Cowork agents, letting security teams cap what those agents can reach inside production systems.
| Round | Amount | Lead investor | Total raised | Valuation |
|---|---|---|---|---|
| Series D (2025) | $85 million | Crescent Cove Advisors | $200+ million | $1.1 billion |
For now, Obsidian is a business-to-business product. Individuals will not download it. But if your employer uses AI agents across its software stack, there is a reasonable chance a platform like this, or the absence of one, will shape how safely your personal work data is handled.
Common questions
Should employees be worried about AI agents accessing their work files?
Not alarmed, but aware. AI agents connected to company systems can read and act on data they were never meant to touch if access controls are set too loosely. Ask your IT team what agents are running and what data they can reach.
Does adding more funding to an AI security startup actually make companies safer?
Money funds engineering, which funds better controls. It does not, by itself, fix a badly configured system. Governance tools like Obsidian's only help if companies actually deploy and configure them.



