Obsidian Security Raises $85 Million to Watch What AI Agents Do Inside Your Company's Apps

The startup, now valued at $1.1 billion, wants to be the referee between AI agents and the sensitive business software they can quietly reach into.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
A security operations center wall of screens showing AI agent activity across enterprise applications, with each screen highlighting different sensitive systems
Share

Key points

  • Obsidian Security raised $85 million in a Series D round, announced Tuesday, pushing total funding past $200 million.
  • The round values the company at $1.1 billion and was led by Crescent Cove Advisors, with Greylock Partners and Menlo Ventures also participating.
  • Only 13% of security teams can currently inspect and enforce policy on AI agent traffic in real time, according to Obsidian CEO Hasan Imam.
  • The fresh capital will fund expanded controls for Anthropic's Claude Code and Cowork AI agents inside enterprise software.

AI agents are software programs that act on your behalf: booking meetings, querying databases, writing code, pulling customer records. They're also, increasingly, being handed the keys to a company's most sensitive systems without anyone watching what they do next.

Obsidian Security thinks that's a problem worth a billion dollars.

What does Obsidian actually do?

The company sits between an AI agent and the business software it's allowed to touch, watching every action in real time and stopping anything that looks wrong.

Think of it as a security guard stationed at the door between Microsoft Copilot Studio or Salesforce Agentforce and a company's customer database. If an agent tries to read files it has no business reading, or quietly expands its own permissions (a technique called privilege escalation, where a program grants itself more access than it was originally given), Obsidian blocks the move before it lands.

The platform also keeps a running inventory of MCP servers. MCP, short for Model Context Protocol, is a standard that lets AI agents connect to external tools and data sources. Tracking which agents are plugged into which servers lets a security team spot any connection nobody officially approved.

Why does the funding matter to ordinary workers?

Most employees don't choose which AI tools their company buys. The tools arrive, get wired into payroll systems, CRMs (customer relationship management software) and collaboration apps, and start acting. The danger isn't that the AI is malicious. It's that a poorly configured agent has been given far too much access, or gets manipulated into doing something harmful.

Obsidian's CEO Hasan Imam put the gap plainly, telling SecurityWeek: "Today, only 13% of security teams can inspect and enforce policy on that traffic in real time."

We covered a similar dynamic three days ago when Onyx Security closed a $113 million round on the same premise, and our piece on shadow AI agents staff install without telling IT lays out exactly how that exposure begins.

The new funding lets Obsidian add specific controls for Claude Code and Cowork agents, letting security teams cap what those agents can reach inside production systems.

Round Amount Lead investor Total raised Valuation
Series D (2025) $85 million Crescent Cove Advisors $200+ million $1.1 billion

For now, Obsidian is a business-to-business product. Individuals won't download it. But if your employer runs AI agents across its software stack, a platform like this, or the absence of one, will shape how safely your personal work data is handled.

The honest watch-this: vendor claims about real-time governance sound good until you ask how enforcement rules are actually applied. Obsidian references OWASP-aligned risk criteria, a published open standard for web security risks, which is at least a verifiable benchmark rather than a proprietary black box. Whether that holds up under production load is the question worth asking.

Common questions

Should employees be worried about AI agents accessing their work files?

Not alarmed, but aware. AI agents connected to company systems can read and act on data they were never meant to touch if access controls are set too loosely. Ask your IT team what agents are running and what data they can reach.

Does adding more funding to an AI security startup actually make companies safer?

Money funds engineering, which funds better controls. It doesn't, by itself, fix a badly configured system. Governance tools like Obsidian's only help if companies actually deploy and configure them.

© 2026 Threat Vectr