Obsidian Security Raises $85M Series D at $1.1B Valuation, Doubling Down on AI Agent Governance
Obsidian Security announced an $85 million Series D at a $1.1 billion valuation, led by Crescent Cove Advisors with participation from Greylock Partners and Menlo Ventures. The round brings Obsidian’s total funding past $200 million and lands the company squarely in a fast-emerging category: governance for AI agents and non-human identities operating inside SaaS environments.
Obsidian’s platform monitors what agents — think Microsoft Copilot Studio, Salesforce Agentforce, n8n, and Anthropic’s Claude — actually do once they’re granted access to enterprise data. That’s a meaningfully different problem than classic SSPM misconfiguration alerting or even traditional DSPM data classification. As agentic tooling gets write and delete permissions inside CRM records, ticketing systems, and file stores, the question shifts from “who can see this data” to “what is an autonomous process doing with it, and can it be revoked mid-action.”
For practitioners tracking the DSPM and insider-risk space, the timing matters as much as the number. This round lands in the same stretch as Zenity’s reported $125 million Series C and Onyx Security’s $113 million raise — both also focused on securing AI agent behavior rather than static data-at-rest classification. Three sizable raises in adjacent-but-distinct agent-security plays in a matter of weeks is a reasonable signal that “agent-to-data” governance is being underwritten as its own category, not folded into existing DSPM or ITDR line items.
Worth watching for teams evaluating DSPM or insider-risk tooling: if agent identity and action-level governance become a separate purchasing decision, expect DSPM vendors to either acquire into this space or ship agent-monitoring modules of their own within the next few product cycles. Obsidian says the new capital will go toward platform expansion and consolidating its position ahead of that shift — and frames its mission as making AI adoption “unstoppable” by governing identity, access, and data across every third-party application running the business.