Obsidian Security Raises $85 Million at $1.1 Billion Valuation
Obsidian Security raised $85 million in a Series D round at a $1.1 billion valuation, bringing total funding to over $200 million The company is expanding into agentic AI security, offering a runtime governance platform for AI agents operating within third-party SaaS applications The platform monitors and enforces policies on AI agents like Microsoft Copilot Studio, Salesforce Agentforce, Claude Code, and Cowork, preventing privilege escalation and over-broad data access Obsidian now adds native
Analysis
TL;DR
- Obsidian Security raised $85 million in a Series D round at a $1.1 billion valuation, bringing total funding to over $200 million
- The company is expanding into agentic AI security, offering a runtime governance platform for AI agents operating within third-party SaaS applications
- The platform monitors and enforces policies on AI agents like Microsoft Copilot Studio, Salesforce Agentforce, Claude Code, and Cowork, preventing privilege escalation and over-broad data access
- Obsidian now adds native governance controls for Claude Code and Cowork, enabling security teams to restrict permissions around production data and block unauthorized MCP server usage
- Only 13% of security teams can currently inspect and enforce policy on AI agent traffic in real time, representing a significant market gap
Why It Matters
As enterprises rapidly deploy AI agents across third-party SaaS ecosystems, the security governance gap is becoming a critical bottleneck for AI adoption. Obsidian's approach of runtime policy enforcement—rather than relying on perimeter-based security—addresses the reality that AI agents inherently need broad access to where data and work reside. This funding round signals strong investor confidence in the agentic AI security niche, which is expected to grow as more organizations move beyond experimental AI pilots into production agent deployments.
Technical Details
- Runtime Governance Layer: Obsidian's platform operates at the application layer, inspecting and enforcing policies on AI agent actions in real time as they interact with third-party enterprise systems (data warehouses, CRMs, developer tools, collaboration apps)
- OWASP-Aligned Risk Criteria: Enforcement rules are based on OWASP-aligned risk frameworks, targeting privilege escalation, over-broad data access, and policy violations before actions take effect
- MCP Server Inventory: The platform maintains a comprehensive inventory of Model Context Protocol (MCP) servers connected across an organization, mapped to the specific agents invoking them, enabling detection of unsanctioned connections and impact assessment of agent-to-backend links
- Native Agent Support: Recent expansion adds governance controls for Anthropic's Claude Code and Cowork, allowing restriction of production data access, sensitive file management, access right adjustments, and blocking of unauthorized MCP or tool usage
- Supported Agent Ecosystem: The platform covers major enterprise AI agents including Microsoft Copilot Studio, Salesforce Agentforce, n8n, and Anthropic's Claude Code and Cowork
Industry Insight
- Security governance will become a prerequisite for enterprise AI agent adoption: The 13% real-time policy enforcement statistic highlights a massive market opportunity. Organizations will increasingly require runtime governance before deploying agents at scale, making platforms like Obsidian essential infrastructure rather than optional add-ons.
- MCP server governance is an emerging security frontier: As the Model Context Protocol gains traction as a standard for agent-to-tool connectivity, the ability to inventory, monitor, and control MCP connections will become a critical security capability. Early movers in this space will define the security standards for the agentic ecosystem.
- The "agentic AI security" category is rapidly forming: The proliferation of funding rounds in this space (Obsidian, Balance Theory, DataBahn, Cantina, Discern Security) indicates investors are betting heavily on security and governance as the defining challenge for enterprise AI. Professionals should monitor this category closely, as consolidation and specialization are likely in the coming years.
Disclaimer: The above content is generated by AI and is for reference only.