Obsidian Security, the platform securing non-human identities and AI agents inside third-party business applications, has closed an $85m Series D funding round led by Crescent Cove Advisors.
The financing drew participation from all of Obsidian’s existing investors, including Greylock Partners and Menlo Ventures, and arrives as the company’s customer base scales quickly. More than 100 organisations now spend over $100,000 a year on the platform, and more than 14 customers pay in excess of $1m annually.
Enterprises are increasingly building AI agents on frontier models such as Anthropic’s Claude, OpenAI’s ChatGPT and Microsoft Copilot Studio, and are turning to Obsidian to control how those agents behave once they sit inside the third-party systems that run core business functions.
The company points to a widening gap between human and non-human identities, which it says already outnumber people 144 to 1 inside third-party applications, a ratio it argues is being stretched further as agentic AI spreads across environments where closing an exposure can already take months. With enterprises running agents from multiple AI ecosystems at once, misbehaviour is becoming more common, pushing security teams to look for a single point of control spanning every platform.
Obsidian plans to use the new capital to extend its reach across the Fortune 500 and Global 2000, aiming to become the standard for governing what AI agents can access and do. The company also argues that its growing customer base strengthens its own product, since patterns identified at one organisation feed back into faster protection for every other client on the network.
Obsidian’s core offering is runtime governance that identifies and blocks privilege escalation, excessive data access and policy breaches carried out by agents built on platforms including Microsoft Copilot, n8n, Google Vertex, Amazon Bedrock and OpenAI. That sits alongside a full inventory of every agent, MCP server and large language model running inside third-party systems, giving security teams visibility over what is connected before problems arise.
Agents built on tools such as Microsoft Copilot Studio, Salesforce Agentforce and n8n, together with autonomous coding agents such as Anthropic’s Claude Code and Cowork, are reaching into data warehouses including Databricks and Snowflake, developer infrastructure such as GitHub and GitLab, customer platforms including Salesforce and HubSpot, and collaboration tools such as Notion and Slack. Obsidian argues that agents left unchecked in these systems can expose, alter or delete sensitive data almost instantly.
Security teams tell Obsidian their biggest concerns are agents taking irreversible action, unapproved agents connecting to critical systems, and agents reaching data they were never meant to see.
The company cites recent cases including an agent that caused a 13-hour cloud outage after being handed overly broad permissions, one that erased years of personal files, and another that bypassed an application’s built-in safeguards to wipe a company’s production database and its backups.
Alongside the funding, Obsidian is introducing four new capabilities: access governance extended to Claude Code and Cowork, real-time runtime protection for agents built on Microsoft Copilot and Anthropic Claude aligned to OWASP standards, a complete inventory of MCP servers mapped to the agents that call them, and continuous tracking of every large language model powering agents so teams are alerted if a model is switched without approval.
Obsidian Security CEO Hasan Imam said, “AI agents gravitate toward third-party applications. That’s where the data lives, that’s where the work happens, and that’s exactly where the risk lives too.
“Frontier and open-source models alike are pushing agents deeper into these environments faster than most security teams can track. More than 70% of our customers already let agents into third-party apps, and that number is only going up. We intend to be the platform that protects enterprises from agents going rogue in third-party applications, so enterprises get the full return on every agent they deploy. That’s the future we’re building toward.”
Copyright © 2026 RegTech Analyst
Copyright © 2018 RegTech Analyst


