Obsidian Security Hits Unicorn Status With $85M Round Targeting AI Agent Sprawl
Obsidian Security has closed an $85 million Series D at a $1.1 billion valuation, pushing its total funding past $200 million. Crescent Cove Advisors led the round, with Greylock Partners and Menlo Ventures also putting money in. The company plans to spend it on expanding into agentic AI security, which is where the real action is right now.
The pitch is straightforward enough: AI agents are increasingly being pointed at enterprise SaaS systems, and most security teams have no real visibility into what those agents are actually doing once they get in. Obsidian's platform tries to fix that by monitoring and governing what agents like Microsoft Copilot Studio, Salesforce Agentforce, n8n, and Anthropic's Claude Code are allowed to touch inside third-party systems, think data warehouses, CRMs, developer tools, and collaboration apps.
The runtime governance layer watches for the usual suspects: privilege escalation, overly permissive data access, and policy violations. Enforcement is based on OWASP-aligned risk criteria and is supposed to kick in before a problematic action completes, not after the damage is done.
The platform also tracks MCP server inventory across an organisation, mapping which agents are invoking which servers. That matters because unsanctioned MCP connections are exactly the kind of thing that slips through the cracks when nobody owns the problem.
The newest additions are native governance controls for Claude Code and Anthropic's Cowork, giving security teams the ability to restrict agent permissions around production data, pull back overly broad access rights, and block unauthorised tool or MCP usage.
CEO Hasan Imam made the case bluntly: agents go where the data and the work are, which means third-party apps, and that is precisely where the risk concentrates. He cited a fairly damning statistic: only 13% of security teams currently have the ability to inspect and enforce policy on that traffic in real time.
That gap is the business. Whether Obsidian can own it before the major cloud vendors decide to solve it themselves is the more interesting question.