Cymphony founders.

Cymphony raises $25 million Series A to secure the growing overlap between employees and AI agents

The Israeli cybersecurity startup has raised $30 million to date as it builds a platform that maps identities, permissions, information and behavior in a single graph. 

Cybersecurity company Cymphony has raised $25 million in a Series A round co-led by Sequoia Capital and SMBC Fin Atlas Beyond Fund, following a $5 million seed round led by Sequoia Capital. The company currently employs about 23 people across Israel and the U.S. and has raised $30 million to develop a platform designed to help enterprises understand and govern how employees and AI agents access sensitive data and interact with critical systems.
The company was founded about two years ago by Shy Dekel, co-founder and CEO; Idan Berkovits, co-founder and chief product officer; and Edi Gotlieb, co-founder and chief technology officer. All three are graduates of Israel’s Talpiot program, where they met during their military service. Dekel served for nearly six years in Unit 8200 and rose to become head of its Cyber Department. Berkovits served as a research group manager in the Office of the Prime Minister, while Gotlieb, an electrical engineer by training, worked at Apple and subsequently held technological positions at Israel’s Ministry of Defense.
1 View gallery
מייסדי חברת הסייבר סימפוני Cymphony שי דקל מייסד-שותף ומנכ״ל עידן ברקוביץ מייסד שותף ומנהל המוצר אדי גוטליב מייסד שותף וסמנכ״ל טכנולוגיות
מייסדי חברת הסייבר סימפוני Cymphony שי דקל מייסד-שותף ומנכ״ל עידן ברקוביץ מייסד שותף ומנהל המוצר אדי גוטליב מייסד שותף וסמנכ״ל טכנולוגיות
Cymphony founders.
(Photo: Shay Hanseb)
In a conversation with Calcalist, Dekel said the company initially focused on securing employees and their access to organizational systems.
“We built the company initially to secure employees. The biggest risks in an organization stem from employee access, and this is the most complicated attack surface,” Dekel said. “We mapped the identities and permissions together and knew what each employee was allowed to do.”
The rapid adoption of AI tools and agents, however, has created a new layer of complexity. As organizations introduce large numbers of AI systems into their operations, those systems can gain access to corporate resources, sensitive information and capabilities that were previously associated primarily with employees.
“When AI tools and entities joined in very large quantities, very large gaps were created,” Dekel said. “We create a connection that is special and different.”
Cymphony has developed a platform that connects identities, information and behavior in a single graph. Dekel said the company already has a large paying customer that replaced two leading products with Cymphony’s platform and had experienced a case involving exposed information that he believes could have been prevented.
“The ability to connect identities, information and behavior in one graph is unique, and the AI agents have made this a very urgent problem,” he said.
The three founders identified a broader shift in the way organizations need to protect their information. Employees have traditionally been the main users of corporate systems, but AI agents can now act on behalf of employees, use their permissions and interact with large numbers of systems and information sources.
An individual AI agent can potentially access a much wider range of information and systems than a single employee, making broad or incorrectly configured permissions more consequential. As companies move toward what Microsoft has described as “human-agent teams,” security teams increasingly need to understand not only which people have access to corporate information, but what autonomous systems can do with that access.
Cymphony has developed a platform that connects two areas that have largely been treated separately until now, identities and organizational information. The platform continuously maps employees and AI agents across an organization and builds a graph connecting them to the systems, permissions and information they can access.
By combining identity, SaaS, AI and data signals, the platform is designed to show security teams not only who has a particular permission, but what information that employee or agent can actually access, how they interact with it and what the business context of that activity is.
The system also prioritizes the risks it identifies and can recommend or automate remediation where possible. When human intervention is required, Cymphony can engage the relevant employees, track progress and coordinate the remaining security work through a single platform.
“The security industry keeps treating AI as another application to secure, but that's the wrong model to use,” Dekel said. “AI agents are becoming active participants in the business. Companies need to know what they're doing, what they can access, and how they're interacting with employees before they can secure them.”
The shift is becoming a significant challenge for enterprises adopting AI. Gartner has identified governance and security as major barriers to enterprise AI adoption and has forecast that 40% of enterprises will demote or decommission autonomous AI agents by 2027 after governance gaps emerge in production.
Cymphony has already been adopted by enterprise customers including Syngenta, KKR, Cass Information Systems and Athennian. The company said the new funding will accelerate product development, expand its engineering and go-to-market teams and help more enterprises deploy AI securely at scale.
Dekel said Cymphony is already generating seven-figure revenue from sales of its platform. The new funding will be used in part to significantly expand sales, with Dekel moving to the U.S. to establish an office and build the company’s customer base there.
“We raised the money to sell significantly more,” he said. “It’s really important for me to sell and prove that we have a stable base of large customers. It’s time to double capacity, and we have customers who pay high amounts.”
Dekel said the company is aiming to build a full infrastructure product rather than a security feature that could simply be incorporated into an existing platform.
“I want to be a company that sells, and therefore we built a product that is not a feature but a complete infrastructural product,” he said.