AI Security AI安全 7h ago Updated 1h ago 更新于 1小时前 45

Obsidian Security Raises $85 Million at $1.1 Billion Valuation Obsidian Security以11亿美元估值完成8500万美元D轮融资

Obsidian Security raised $85 million in a Series D round at a $1.1 billion valuation, bringing total funding to over $200 million The company is expanding into agentic AI security, offering a runtime governance platform for AI agents operating within third-party SaaS applications The platform monitors and enforces policies on AI agents like Microsoft Copilot Studio, Salesforce Agentforce, Claude Code, and Cowork, preventing privilege escalation and over-broad data access Obsidian now adds native Obsidian Security完成8500万美元D轮融资,估值达11亿美元,累计融资超2亿美元 公司专注AI代理和SaaS应用的安全治理,新增对Claude Code和Cowork的原生控制支持 平台运行时治理层基于OWASP风险标准,可实时识别并阻止权限升级、过度数据访问和政策违规 维护组织内MCP服务器清单,追踪代理与后端的连接关系,帮助企业发现未授权MCP连接 CEO指出仅13%的安全团队能实时检查和执行AI代理策略,市场存在巨大空白

65
Hot 热度
60
Quality 质量
65
Impact 影响力

Analysis 深度分析

TL;DR

  • Obsidian Security raised $85 million in a Series D round at a $1.1 billion valuation, bringing total funding to over $200 million
  • The company is expanding into agentic AI security, offering a runtime governance platform for AI agents operating within third-party SaaS applications
  • The platform monitors and enforces policies on AI agents like Microsoft Copilot Studio, Salesforce Agentforce, Claude Code, and Cowork, preventing privilege escalation and over-broad data access
  • Obsidian now adds native governance controls for Claude Code and Cowork, enabling security teams to restrict permissions around production data and block unauthorized MCP server usage
  • Only 13% of security teams can currently inspect and enforce policy on AI agent traffic in real time, representing a significant market gap

Why It Matters

As enterprises rapidly deploy AI agents across third-party SaaS ecosystems, the security governance gap is becoming a critical bottleneck for AI adoption. Obsidian's approach of runtime policy enforcement—rather than relying on perimeter-based security—addresses the reality that AI agents inherently need broad access to where data and work reside. This funding round signals strong investor confidence in the agentic AI security niche, which is expected to grow as more organizations move beyond experimental AI pilots into production agent deployments.

Technical Details

  • Runtime Governance Layer: Obsidian's platform operates at the application layer, inspecting and enforcing policies on AI agent actions in real time as they interact with third-party enterprise systems (data warehouses, CRMs, developer tools, collaboration apps)
  • OWASP-Aligned Risk Criteria: Enforcement rules are based on OWASP-aligned risk frameworks, targeting privilege escalation, over-broad data access, and policy violations before actions take effect
  • MCP Server Inventory: The platform maintains a comprehensive inventory of Model Context Protocol (MCP) servers connected across an organization, mapped to the specific agents invoking them, enabling detection of unsanctioned connections and impact assessment of agent-to-backend links
  • Native Agent Support: Recent expansion adds governance controls for Anthropic's Claude Code and Cowork, allowing restriction of production data access, sensitive file management, access right adjustments, and blocking of unauthorized MCP or tool usage
  • Supported Agent Ecosystem: The platform covers major enterprise AI agents including Microsoft Copilot Studio, Salesforce Agentforce, n8n, and Anthropic's Claude Code and Cowork

Industry Insight

  • Security governance will become a prerequisite for enterprise AI agent adoption: The 13% real-time policy enforcement statistic highlights a massive market opportunity. Organizations will increasingly require runtime governance before deploying agents at scale, making platforms like Obsidian essential infrastructure rather than optional add-ons.
  • MCP server governance is an emerging security frontier: As the Model Context Protocol gains traction as a standard for agent-to-tool connectivity, the ability to inventory, monitor, and control MCP connections will become a critical security capability. Early movers in this space will define the security standards for the agentic ecosystem.
  • The "agentic AI security" category is rapidly forming: The proliferation of funding rounds in this space (Obsidian, Balance Theory, DataBahn, Cantina, Discern Security) indicates investors are betting heavily on security and governance as the defining challenge for enterprise AI. Professionals should monitor this category closely, as consolidation and specialization are likely in the coming years.

TL;DR

  • Obsidian Security完成8500万美元D轮融资,估值达11亿美元,累计融资超2亿美元
  • 公司专注AI代理和SaaS应用的安全治理,新增对Claude Code和Cowork的原生控制支持
  • 平台运行时治理层基于OWASP风险标准,可实时识别并阻止权限升级、过度数据访问和政策违规
  • 维护组织内MCP服务器清单,追踪代理与后端的连接关系,帮助企业发现未授权MCP连接
  • CEO指出仅13%的安全团队能实时检查和执行AI代理策略,市场存在巨大空白

为什么值得看

AI代理安全正成为企业大规模部署AI的关键障碍,Obsidian通过运行时治理解决这一痛点。随着Claude Code、Copilot等代理工具在企业中的普及,安全治理需求急剧增长,该轮融资反映了市场对AI代理安全解决方案的强烈需求。

技术解析

  • 平台支持Microsoft Copilot Studio、Salesforce Agentforce、n8n、Anthropic的Claude Code和Cowork等主流AI代理的权限治理
  • 运行时治理层基于OWASP对齐的风险标准,在代理操作时实时应用执行规则,防止特权升级和过度数据访问
  • 维护组织内所有MCP服务器的清单,并与调用它们的特定代理关联,帮助团队评估代理到后端的连接影响
  • 新增Claude Code和Cowork的原生治理控制,支持限制生产数据访问、管理敏感文件权限、调整过度访问权限和阻止未授权MCP或工具使用

行业启示

  • AI代理安全赛道快速升温,近期Balance Theory、DataBahn、Cantina、Discern Security等多家公司相继获得融资,反映资本对Agentic AI安全领域的看好
  • 运行时治理(Runtime Governance)正成为AI安全的新范式,从传统的静态策略转向实时监控和动态执行
  • MCP(Model Context Protocol)作为AI代理与后端系统交互的标准协议,其安全治理将成为下一个竞争焦点

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Funding 融资 Security 安全 Agent Agent