Obsidian Security has announced $85 million in Series D financing led by Crescent Cove Advisors, with participation from all existing investors including Greylock Partners and Menlo Ventures. The round values the company at $1.1 billion and follows accelerating customer growth with over 100 customers now spending over $100K annually and more than 14 customers spending over $1 million.
Obsidian raises $85M Series D at $1.1B valuation, achieving unicorn status.
Trusted by 60 of the Fortune 500 companies, including major financial institutions and top telecom providers.
Non-human identities outnumber human identities 144 to 1 inside third-party applications.
Over 70% of customers already let agents into third-party apps.
New capabilities include Agent Access Governance for Claude Code and Cowork, Runtime Protection, MCP Server Inventory, and LLM Inventory.
Funding will fuel R&D to secure enterprises against next-gen frontier models exploiting vulnerabilities in third-party applications.
Obsidian has spent years preparing for this moment. Non-human identities outnumber human identities 144 to 1 inside third-party applications, and agents built on frontier models are multiplying that gap further. As enterprises adopt agents from multiple AI ecosystems at once, agent misbehavior is becoming more common, and security teams need one durable control point across all of them. That need has driven Obsidian's growth among the world's largest organizations across the Fortune 500 and Global 2000, and that scale is now a strength in itself. As more enterprises adopt Obsidian, its network intelligence compounds, turning patterns spotted at one company into faster protection for every customer on the platform.
Enterprise AI agents increasingly reach into data warehouses, developer infrastructure, CRM systems, and collaboration tools. These applications hold source code, regulated data, and intellectual property, and an unsecured agent can leak, modify, or delete that data at machine speed. Security teams consistently report three top concerns: agents taking destructive or irreversible actions, unsanctioned agents connecting to critical systems, and agents reaching sensitive data they were never meant to access. Recent incidents underscore the stakes, from an AI agent that triggered a 13-hour cloud outage to one that deleted decades of personal files. Obsidian's runtime governance detects and blocks privilege escalation, excessive data access, and policy violations for agents built on platforms like Microsoft Copilot, n8n, Google Vertex, Amazon Bedrock, OpenAI, and others.
Obsidian extends its AI agent security to Anthropic's Claude platform with Agent Access Governance for Claude Code and Cowork, enabling discovery, governance, and enforcement of what agents can access and do inside third-party applications. Runtime Protection enforces real-time guardrails for agents built with Microsoft Copilot and Anthropic Claude, detecting and blocking privilege escalation and policy violations at execution time. MCP Server Inventory provides complete visibility into every MCP server mapped to the agents that invoke them. LLM Inventory tracks every large language model powering agents to ensure only sanctioned models drive enterprise agents.
"AI agents gravitate toward third-party applications. That's where the data lives, that's where the work happens, and that's exactly where the risk lives too," said Hasan Imam, CEO of Obsidian Security. "Frontier and open-source models alike are pushing agents deeper into these environments faster than most security teams can track. More than 70% of our customers already let agents into third-party apps, and that number is only going up. We intend to be the platform that protects enterprises from agents going rogue in third-party applications, so enterprises get the full return on every agent they deploy. That's the future we're building toward."
"AI is fundamentally changing how enterprises operate, creating new infrastructure challenges that legacy security models weren't designed to address," said Jun Hong Heng, Founder and Chief Investment Officer of Crescent Cove Advisors. "Obsidian recognized that shift early and is building the platform enterprises need to securely adopt AI at scale. The company embodies the kind of foundational technology we seek to back, and we are excited to support the team as they continue to define the future of AI security."
About Obsidian Security
Obsidian Security secures the AI-first enterprise, governing data, AI and agents inside third-party applications. Trusted by Fortune 1000 and Global 2000 enterprises, Obsidian gives security teams visibility into what's connected, controls to enforce what's allowed, and the runtime context to govern AI and agent activity before it causes damage inside critical business systems. Headquartered in Palo Alto, California, Obsidian is backed by Crescent Cove Advisors, Menlo Ventures, Norwest Venture Partners, IVP, Greylock, GV, and Wing.