Obsidian Reaches $1.1B Valuation
Obsidian Security secures $85 million in Series D funding to grow its platform for governing AI agents within enterprise environments.
Obsidian Security announced on Tuesday that it has raised $85 million in a Series D funding round at a $1.1 billion valuation.
Funding and Total Capital
The latest investment, which brings the total raised by the company to more than $200 million, was led by Crescent Cove Advisors, with participation from Greylock Partners and Menlo Ventures. Obsidian will use the funds to accelerate its expansion into agentic AI security.
Platform for Agent Governance
Obsidian Security offers a platform for governing AI agents and SaaS applications, monitoring what agents like Microsoft Copilot Studio, Salesforce Agentforce, n8n, and Anthropic’s Claude Code and Cowork are permitted to access and execute within third-party enterprise systems such as data warehouses, developer tools, CRMs, and collaboration apps.
Runtime Security Mechanisms
The platform’s runtime governance layer is designed to identify and stop privilege escalation, over-broad data access, and policy violations as agents operate, applying enforcement rules based on OWASP-aligned risk criteria before those actions can take effect.
Inventory of Connected Servers
It also maintains an inventory of MCP servers connected across an organization, tied to the specific agents invoking them, so teams can spot unsanctioned MCP connections and gauge the potential impact of agent-to-backend links.
Expanding Governance Controls
With its newest expansion, Obsidian adds native governance controls for Claude Code and Cowork, letting security teams restrict agent permissions around production data, manage access to sensitive files, adjust overly broad access rights, and block unauthorized MCP or tool usage.
Industry Perspective on Risk
“AI agents gravitate toward third-party applications. That’s where the data lives, that’s where the work happens, and that’s exactly where the risk lives too,” said Hasan Imam, CEO of Obsidian.
— Hasan Imam, CEO of Obsidian
“Today, only 13% of security teams can inspect and enforce policy on that traffic in real time. We intend to be the platform that flips the number by governing what agents do inside third-party apps, so enterprises get the full return on every agent they deploy. That’s the future we’re building toward,” Imam added.
— Hasan Imam, CEO of Obsidian
Financial Context
- $85 million: The amount raised in the Series D funding round.
- $1.1 billion: The valuation of the company following the latest investment.
- $200 million: The total capital raised by the company to date.
- 13%: The percentage of security teams currently able to inspect and enforce policy on agent traffic in real time.
Strategic Implications
The significant valuation and funding for Obsidian Security suggest an increasing focus on the security challenges posed by the rapid adoption of autonomous AI agents within corporate ecosystems. As enterprises integrate tools that autonomously access third-party applications, the ability to manage and restrict those interactions could become a standard requirement for maintaining data hygiene and preventing unauthorized privilege escalation.
Sources
- SecurityWeek Original source
- Obsidian Security Also reporting
Continue Reading
Flowise Critical RCE Flaw Patched
A Unicode homoglyph bypass in Flowise allows attackers to execute arbitrary code on host systems by tricking the Python code validation engine.
CISA Warns of Exploited IBM Langflow Flaw
IBM Langflow users must act by August 7 to address a critical code injection vulnerability currently being exploited in the wild.
CISA Warns of Active N-able N-central Flaw
CISA has added an authentication bypass vulnerability in N-able N-central to its Known Exploited Vulnerabilities catalog, requiring immediate action.