Breaking
SecurityDeveloping Story

Obsidian Reaches $1.1B Valuation

Obsidian Security secures $85 million in Series D funding to grow its platform for governing AI agents within enterprise environments.

··2 hours ago·2 min read
black android smartphone turned on screen
Photo by Marga Santoso on Unsplash

Obsidian Security announced on Tuesday that it has raised $85 million in a Series D funding round at a $1.1 billion valuation.

Funding and Total Capital

The latest investment, which brings the total raised by the company to more than $200 million, was led by Crescent Cove Advisors, with participation from Greylock Partners and Menlo Ventures. Obsidian will use the funds to accelerate its expansion into agentic AI security.

Platform for Agent Governance

Obsidian Security offers a platform for governing AI agents and SaaS applications, monitoring what agents like Microsoft Copilot Studio, Salesforce Agentforce, n8n, and Anthropic’s Claude Code and Cowork are permitted to access and execute within third-party enterprise systems such as data warehouses, developer tools, CRMs, and collaboration apps.

Runtime Security Mechanisms

The platform’s runtime governance layer is designed to identify and stop privilege escalation, over-broad data access, and policy violations as agents operate, applying enforcement rules based on OWASP-aligned risk criteria before those actions can take effect.

Inventory of Connected Servers

It also maintains an inventory of MCP servers connected across an organization, tied to the specific agents invoking them, so teams can spot unsanctioned MCP connections and gauge the potential impact of agent-to-backend links.

Expanding Governance Controls

With its newest expansion, Obsidian adds native governance controls for Claude Code and Cowork, letting security teams restrict agent permissions around production data, manage access to sensitive files, adjust overly broad access rights, and block unauthorized MCP or tool usage.

Industry Perspective on Risk

“AI agents gravitate toward third-party applications. That’s where the data lives, that’s where the work happens, and that’s exactly where the risk lives too,” said Hasan Imam, CEO of Obsidian.

— Hasan Imam, CEO of Obsidian

“Today, only 13% of security teams can inspect and enforce policy on that traffic in real time. We intend to be the platform that flips the number by governing what agents do inside third-party apps, so enterprises get the full return on every agent they deploy. That’s the future we’re building toward,” Imam added.

— Hasan Imam, CEO of Obsidian

Financial Context

  • $85 million: The amount raised in the Series D funding round.
  • $1.1 billion: The valuation of the company following the latest investment.
  • $200 million: The total capital raised by the company to date.
  • 13%: The percentage of security teams currently able to inspect and enforce policy on agent traffic in real time.

Strategic Implications

The significant valuation and funding for Obsidian Security suggest an increasing focus on the security challenges posed by the rapid adoption of autonomous AI agents within corporate ecosystems. As enterprises integrate tools that autonomously access third-party applications, the ability to manage and restrict those interactions could become a standard requirement for maintaining data hygiene and preventing unauthorized privilege escalation.

#obsidian security#funding#ai security#saas

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted with AI assistance from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our AI Policy →

← Back to all stories