Cymphony lands $30m as AI agents test data access limits

Cymphony

Cymphony, an AI security startup built to close the access gaps that artificial intelligence tools are exposing across corporate systems, has come out of stealth with $30m in funding.

The round was led by Sequoia and Fin Capital, and accompanies the company’s public launch. The raise gives Cymphony capital to build out a platform aimed at helping security teams keep pace with a threat landscape that the founders argue has shifted dramatically since AI tools began connecting to core business systems.

According to the company, the rise of AI has intensified a problem security teams have faced for years: balancing the pressure to keep the business moving with the need to guard sensitive systems and data.

Platforms such as SharePoint, Box, Snowflake and Salesforce are increasingly being connected to AI tools, and Cymphony argues that the same technology giving the business new capabilities is also best placed to exploit any weaknesses in how access to that data is controlled.

Access, the company says, is now being tested continuously by a mix of sanctioned and unsanctioned AI tools, as well as internal and external machines and agents, leaving security teams needing to respond far faster than before.

Cymphony describes itself as an AI security platform designed for this new way of working. Its approach is to unify data, identity and behaviour within a single context graph, rather than treating each as a separate problem to monitor. The company positions itself less as a standalone tool and more as an ongoing partner in an organisation’s AI security efforts, extending to working directly alongside customer teams on live projects.

The company points to one early customer as an example of the risks it is trying to prevent. After connecting ChatGPT to SharePoint, an intern’s honest mistake meant that every intern at the company could query documents relating to a highly sensitive litigation matter.

Cymphony says this kind of incident illustrates the gap between having a strong security stack and actually controlling what AI tools can reach once connected. The company also draws a distinction between simply cataloguing an organisation’s data and actively identifying and reducing risky access, arguing that many existing tools stop at the former.

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoying the stories?

Subscribe to our daily FinTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.